<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: lone]]></title>
    <link>http://securityratty.com/tag/lone</link>
    <description></description>
    <pubDate>Fri, 09 May 2008 03:00:15 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[MI5 on Terrorist Profiling]]></title>
      <link>http://securityratty.com/article/bb80acbf5bcef69e830e8c656c41335c</link>
      <guid>http://securityratty.com/article/bb80acbf5bcef69e830e8c656c41335c</guid>
      <description><![CDATA[There's no profile : MI5 has concluded that there is no easy way to identify those who become involved in terrorism in Britain, according to a classified internal research document on radicalisation...]]></description>
      <content:encoded><![CDATA[<p>There's <a href="http://www.guardian.co.uk/uk/2008/aug/20/uksecurity.terrorism1">no profile</a>:</p>

<blockquote>MI5 has concluded that there is no easy way to identify those who become involved in terrorism in Britain, according to a classified internal research document on radicalisation seen by the Guardian.

<p><br />
[...]</p>

<p>The main findings include: </p>

<p>• The majority are British nationals and the remainder, with a few exceptions, are here legally. Around half were born in the UK, with others migrating here later in life. Some of these fled traumatic experiences and oppressive regimes and claimed UK asylum, but more came to Britain to study or for family or economic reasons and became radicalised many years after arriving.</p>

<p>• Far from being religious zealots, a large number of those involved in terrorism do not practise their faith regularly. Many lack religious literacy and could actually be regarded as religious novices. Very few have been brought up in strongly religious households, and there is a higher than average proportion of converts. Some are involved in drug-taking, drinking alcohol and visiting prostitutes. MI5 says there is evidence that a well-established religious identity actually protects against violent radicalisation. </p>

<p>• The "mad and bad" theory to explain why people turn to terrorism does not stand up, with no more evidence of mental illness or pathological personality traits found among British terrorists than is found in the general population.</p>

<p>• British-based terrorists are as ethnically diverse as the UK Muslim population, with individuals from Pakistani, Middle Eastern and Caucasian backgrounds. MI5 says assumptions cannot be made about suspects based on skin colour, ethnic heritage or nationality. </p>

<p>• Most UK terrorists are male, but women also play an important role. Sometimes they are aware of their husbands', brothers' or sons' activities, but do not object or try to stop them.</p>

<p>• While the majority are in their early to mid-20s when they become radicalised, a small but not insignificant minority first become involved in violent extremism at over the age of 30.</p>

<p>• Far from being lone individuals with no ties, the majority of those over 30 have steady relationships, and most have children. MI5 says this challenges the idea that terrorists are young men driven by sexual frustration and lured to "martyrdom" by the promise of beautiful virgins waiting for them in paradise. It is wrong to assume that someone with a wife and children is less likely to commit acts of terrorism.</p>

<p>• Those involved in British terrorism are not unintelligent or gullible, and nor are they more likely to be well-educated; their educational achievement ranges from total lack of qualifications to degree-level education. However, they are almost all employed in low-grade jobs.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=GwMQnK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=GwMQnK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=nvC4JK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=nvC4JK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 02:18:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mi5">mi5</category>
      <category domain="http://securityratty.com/tag/terrorism">terrorism</category>
      <category domain="http://securityratty.com/tag/british terrorism">british terrorism</category>
      <category domain="http://securityratty.com/tag/british terrorists">british terrorists</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/violent radicalisation">violent radicalisation</category>
      <category domain="http://securityratty.com/tag/majority">majority</category>
      <category domain="http://securityratty.com/tag/individuals">individuals</category>
      <category domain="http://securityratty.com/tag/internal research document">internal research document</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/mi5_on_terroris.html">MI5 on Terrorist Profiling</source>
    </item>
    <item>
      <title><![CDATA[Virginia Tech intros another emergency notification system]]></title>
      <link>http://securityratty.com/article/1cc1a31909fa60cd278c4fc81af0b55e</link>
      <guid>http://securityratty.com/article/1cc1a31909fa60cd278c4fc81af0b55e</guid>
      <description><![CDATA[When Virginia Tech's 28,000 students return to classes for the fall on Monday, they will benefit from another emergency mass notification system added over the summer in response to the April 2007...]]></description>
      <content:encoded><![CDATA[When Virginia Tech's 28,000 students return to classes for the fall on Monday, they will benefit from another emergency mass notification system added over the summer in response to the April 2007 campus killings of 32 people by a lone gunman.]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virginia tech">virginia tech</category>
      <category domain="http://securityratty.com/tag/students return">students return</category>
      <category domain="http://securityratty.com/tag/campus killings">campus killings</category>
      <category domain="http://securityratty.com/tag/lone gunman">lone gunman</category>
      <category domain="http://securityratty.com/tag/classes">classes</category>
      <category domain="http://securityratty.com/tag/response">response</category>
      <category domain="http://securityratty.com/tag/summer">summer</category>
      <category domain="http://securityratty.com/tag/monday">monday</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://www.networkworld.com/news/2008/082008-virginia-tech-intros-another-emergency.html?fsrc=rss-security">Virginia Tech intros another emergency notification system</source>
    </item>
    <item>
      <title><![CDATA[Guerilla Marketing for a Conspiracy Site]]></title>
      <link>http://securityratty.com/article/2b117e772809f4fc08e74e3a0ec176ee</link>
      <guid>http://securityratty.com/article/2b117e772809f4fc08e74e3a0ec176ee</guid>
      <description><![CDATA[An image is worth a thousand words they say, especially when it's creative enough to count as a decent guerrilla marketing campaign for Alex Jones' infowars.com

Alex Jones is considered by many to be...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKR8gmsdi5I/AAAAAAAACCk/7pb6K-ZlId8/s1600-h/infowars_echelon_guerilla_marketing.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKR8gmsdi5I/AAAAAAAACCk/PY2_yw9n2-8/s200-R/infowars_echelon_guerilla_marketing.jpg" style="border: 0pt none ;" /></a>An image is worth a thousand words they say, especially when it's creative enough to count as a decent guerrilla marketing campaign for <a href="http://infowars.com/alexjones.html">Alex Jones' infowars.com</a> :<br />
<br />
"<i>Alex Jones is considered by many to be the grandfather of what has come to be known as the 9/11 Truth Movement. <b>Jones predicted the 9/11 attack in a July 2001 television taping when he warned that the Globalists were going to attack New York and blame it on their asset Osama bin Laden.</b> Since 9/11 Jones has broken many of the stories which later became the foundation of the evidence that the government was involved.</i>"<br />
<br />
Sorry to disappoint, but as always, <a href="http://killtown.911review.org/lonegunmen.html">The Lone Gunmen were first to predict 9/11 in their "Pilot" episode</a>, originally aired on 03/04/2001, obviously <a href="http://www.youtube.com/watch?v=rIZ205ccX8M">several months before Alex Jones did</a>. How did they do it? By having a firm grasp of the obvious I guess.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hvjPGK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hvjPGK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TBCXkK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TBCXkK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rLOaMk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rLOaMk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6k2N4k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6k2N4k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ld6AqK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ld6AqK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TNX2FK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TNX2FK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=E43dXk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=E43dXk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/365022639" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 09:58:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/alex jones">alex jones</category>
      <category domain="http://securityratty.com/tag/jones">jones</category>
      <category domain="http://securityratty.com/tag/asset osama bin">asset osama bin</category>
      <category domain="http://securityratty.com/tag/decent guerrilla">decent guerrilla</category>
      <category domain="http://securityratty.com/tag/truth movement">truth movement</category>
      <category domain="http://securityratty.com/tag/firm grasp">firm grasp</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/thousand words">thousand words</category>
      <category domain="http://securityratty.com/tag/predict">predict</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/365022639/guerilla-marketing-for-conspiracy-site.html">Guerilla Marketing for a Conspiracy Site</source>
    </item>
    <item>
      <title><![CDATA[The Russia vs Georgia Cyber Attack]]></title>
      <link>http://securityratty.com/article/8a00d5d19f0f12447cb8a837ccb009d4</link>
      <guid>http://securityratty.com/article/8a00d5d19f0f12447cb8a837ccb009d4</guid>
      <description><![CDATA[Last month's lone gunman DDoS attack against Georgia President's web site seemed like a signal shot for the cyber siege to come a week later. Here's the complete coverage of the coordination phrase,...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKDOBJ48vsI/AAAAAAAACBc/ZBksCc1a5m8/s1600-h/georgia_ddos1.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKDOBJ48vsI/AAAAAAAACBc/5HAQ-5aIlmE/s200-R/georgia_ddos1.JPG" style="border: 0pt none ;" /></a>Last month's lone gunman <a href="http://blogs.zdnet.com/security/?p=1533">DDoS attack against Georgia President's web site</a> seemed like a signal shot for the cyber siege to come a week later. Here's the complete coverage of the coordination phrase, the execution and the actual impact of the cyber attack so far - "<a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a>" : <br />
<br />
"<i>Who’s behind it? The infamous Russian Business Network, or literally every Russian supporting Russia’s actions? How coordinated and planned the cyber attack is, and do we actually have a relatively decent example of cyber warfare combining PSYOPs (psychological operations), and self-mobilization of the local Internet users by spreading “<i>For our motherland, brothers!</i>” or “<i>Your country is calling you!</i>” hacktivist messages across web forums. Let’s find out, in-depth. With the attacks originally starting to take place several weeks before the actual “intervention” with <a href="http://blogs.zdnet.com/security/?p=1533" title="Georgia President’s web site under DDoS attack from Russian hackers">Georgia President’s web site coming under DDoS attack from Russian hackers in July</a>, followed by active discussions across the Russian web on whether or not DDoS attacks and web site defacements should in fact be taking place, which would inevitably come as a handy tool to be used against Russian from Western or Pro-Western journalists, the peak of <a href="http://www.telegraph.co.uk/news/worldnews/europe/georgia/2539157/Georgia-Russia-conducting-cyber-war.html" title="Russia 'conducting cyber war' ">DDoS attack and the actual defacements started taking place as of Friday</a></i>."<br />
<br />
<b>Some of the tactics used :</b><br />
distributing a static list of targets, eliminate centralized coordination of the attack, engaging the average internet users, empower them with DoS tools; distributing lists of remotely SQL injectable Georgian sites; abusing public lists of email addresses of Georgian politicians for spamming and targeted attacks; destroy the adversary’s ability to communicate using the usual channels -- Georgia's most popular hacking portal is under DDoS attack from Russian hackers. <br />
<br />
Some of the parked domains acting as command and control servers for one of the botnets at <b>79.135.167.22</b> :<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKDZ2YYVwKI/AAAAAAAACBk/k6L5IVraZek/s1600-h/georgia_ddos11.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKDZ2YYVwKI/AAAAAAAACBk/7CE4qNNjNNo/s200-R/georgia_ddos11.JPG" style="border: 0pt none ;" /></a><b>emultrix .org<br />
yandexshit .com<br />
ad.yandexshit .com<br />
a-nahui-vse-zaebalo-v-pizdu .com<br />
killgay .com<br />
ns1.guagaga .net<br />
ns2.guagaga .net<br />
ohueli .net<br />
pizdos .net<br />
googlecomaolcomyahoocomaboutcom.net</b><br />
<br />
Actual command and control locations :<br />
<b>a-nahui-vse-zaebalo-v-pizdu .com/a/nahui/vse/zaebalo/v/pizdu/</b><br />
<b>prosto.pizdos .net/_lol/</b><br />
<br />
<a href="http://blogs.zdnet.com/security/?p=1670">Consider going through the complete coverage</a> of what's been happening during the weeked. Considering the combination of tactics used, unless the conflict gets solved, more attacks will definitely take place during the week.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6byBHK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6byBHK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7Vs5oK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7Vs5oK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ynPNFk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ynPNFk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wRwGhk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wRwGhk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uJkrTK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uJkrTK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=tisqjK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=tisqjK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wHSnQk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wHSnQk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/362442602" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 15:35:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgia cyber attack">georgia cyber attack</category>
      <category domain="http://securityratty.com/tag/cyber attack">cyber attack</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <category domain="http://securityratty.com/tag/georgia president">georgia president</category>
      <category domain="http://securityratty.com/tag/russian">russian</category>
      <category domain="http://securityratty.com/tag/russian web">russian web</category>
      <category domain="http://securityratty.com/tag/ddos attack">ddos attack</category>
      <category domain="http://securityratty.com/tag/russian hackers">russian hackers</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/362442602/russia-vs-georgia-cyber-attack.html">The Russia vs Georgia Cyber Attack</source>
    </item>
    <item>
      <title><![CDATA[The Twitter Malware Campaign Wants to Bank With You]]></title>
      <link>http://securityratty.com/article/0a86c9e6b40c8995b8c3f84a2d12480a</link>
      <guid>http://securityratty.com/article/0a86c9e6b40c8995b8c3f84a2d12480a</guid>
      <description><![CDATA[In what appears to be a lone gunman malware campaign -- where the malware spreader even left his email address within the binary - the now down Twitter malware campaign managed to attract only 69...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SJgk-RghwII/AAAAAAAAB_c/xbrYBDO4K9Q/s1600-h/twitter_malware1.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJgk-RghwII/AAAAAAAAB_c/om2-uxKUmR4/s200-R/twitter_malware1.JPG" style="border: 0pt none ;" /></a>In <a href="http://www.twitpwn.com/2008/08/coming-up-malware-on-twitter.html">what appears to</a> be a lone gunman <a href="http://www.viruslist.com/en/weblog?weblogid=208187551">malware campaign</a> -- where the malware spreader even left his email address within the binary - the now down <a href="http://blogs.guardian.co.uk/technology/2008/08/05/twiters_trojan_problem.html">Twitter malware campaign</a> managed to attract only 69 followers before it has shut down, <a href="http://www.techcrunch.com/2008/07/27/who-is-johng77536-and-how-did-he-game-twitter/">using a trivial approach</a> for launching an XSS worm - <a href="http://en.wikipedia.org/wiki/Cross-site_request_forgery">Cross-site request forgery</a> (CSRF). More info :<br />
<br />
"<i>This week it’s Twitter’s turn to host an attack - one that is targeting both Twitter users and the Internet community at large. In this case it's a malicious Twitter profile twitter.com/[skip]/ with a name that is Portuguese for ‘pretty rabbit’ which has a photo advertising a video with girls posted.&nbsp;</i><br />
<br />
<i>This profile has obviously been created especially for infecting users, as there is no other data except the photo, which contains the link to the video. If you click on the link, you get a window that shows the progress of an automatic download of a so-called new version of Adobe Flash which is supposedly required to watch the video. You end up with a file labeled Adobe Flash (it’s a fake) on your machine; a technique that is currently very popular.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SJg7qxrXS-I/AAAAAAAAB_k/X5JjQEBfcgc/s1600-h/twitter_malware.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJg7qxrXS-I/AAAAAAAAB_k/tnrV5eIbz1M/s200-R/twitter_malware.JPG" style="border: 0pt none ;" /></a>Let's analyze the campaign before it was shut down. The original Twitter account used <b>twitter.com/video_kelly_key</b> basically included a link to <b>player-video-youtube.sytes.net</b> (204.16.252.98) which was using a URL shortening service <b>fly2.ws/NilOMN3</b> in order to redirect to the banker malware located at <b>freewebtown.com/construimagens/ Play-video-youtube.kelly-key.com</b>. It's detection rate is as follows :<br />
<br />
<b>Scanners Result</b>: 14/36 (38.89%)<br />
Trojan-Spy.Win32.Banker.caw <br />
<b>File size</b>: 88064 bytes<br />
<b>MD5</b>...: 25600af502758ca992b9e7fff3739def<br />
<b>SHA1</b>..: 9262ca501ef388e0fe42c50a3d002ddbd6e254f2<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJg8dgf3PnI/AAAAAAAAB_s/zemAG6fn3rM/s1600-h/xss_csrfworm.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJg8dgf3PnI/AAAAAAAAB_s/lOjia4dpUaw/s200-R/xss_csrfworm.png" style="border: 0pt none ;" /></a>Twitter isn't an exception to the realistic potential for <a href="http://0x000000.com/index.php?i=512&amp;bin=1000000000">XSS worms though CSRF that could affect each and every Web 2.0 service</a>, which as a matter of fact have all suffered such attempts, namely, <a href="http://ha.ckers.org/blog/20071220/orkut-xss-worm" title="Orkut XSS Worm">Orkut</a>, <a href="http://en.wikipedia.org/wiki/Samy_%28XSS%29" title="Samy MySpace XSS Worm">MySpace</a> (as well as the <a href="http://securitylabs.websense.com/content/Alerts/1319.aspx" title="MySpace QuickTime XSS Flaw">QuickTime XSS flaw</a>), <a href="http://blogs.securiteam.com/index.php/archives/786" title="GaiaOnline XSS Worm">GaiaOnline</a>, <a href="http://sirdarckcat.blogspot.com/2007/12/making-social-network-xss-worm-hi5com.html" title="Hi5 XSS Worm">Hi5</a>, and most recently the <a href="http://blogs.zdnet.com/security/?p=1487">XSS worm at Justin.tv</a>, demonstrate that trivial vulnerabilities come handy for what's to turn into a major security incident if not taken care of promptly.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/05/xss-planet.html">XSS The Planet</a><br />
<a href="http://ddanchev.blogspot.com/2007/02/xss-vulnerabilities-in-e-banking-sites.html">XSS Vulnerabilities in E-banking Sites</a><br />
<a href="http://ddanchev.blogspot.com/2006/05/current-state-of-web-application-worms.html">The Current State of Web Application Worms</a><br />
<a href="http://ddanchev.blogspot.com/2007/06/g0t-xssed.html">g0t XSSed?</a><br />
<a href="http://ddanchev.blogspot.com/2006/06/web-application-email-harvesting-worm.html">Web Application Email Harvesting Worm </a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=oWAtgK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=oWAtgK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=L5UJoK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=L5UJoK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dlgqak"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dlgqak" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3uAsZk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3uAsZk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YHdd5K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YHdd5K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AezGSK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AezGSK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JZQeBk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JZQeBk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/356281978" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 03:14:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/twitter">twitter</category>
      <category domain="http://securityratty.com/tag/twitter malware campaign">twitter malware campaign</category>
      <category domain="http://securityratty.com/tag/xss">xss</category>
      <category domain="http://securityratty.com/tag/xss vulnerabilities">xss vulnerabilities</category>
      <category domain="http://securityratty.com/tag/original twitter account">original twitter account</category>
      <category domain="http://securityratty.com/tag/xss worms">xss worms</category>
      <category domain="http://securityratty.com/tag/xss worm">xss worm</category>
      <category domain="http://securityratty.com/tag/twitter users">twitter users</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/356281978/twitter-malware-campaign-wants-to-bank.html">The Twitter Malware Campaign Wants to Bank With You</source>
    </item>
    <item>
      <title><![CDATA[Summarizing July's Threatscape]]></title>
      <link>http://securityratty.com/article/2860027a1eaa69350d814429c3bf6070</link>
      <guid>http://securityratty.com/article/2860027a1eaa69350d814429c3bf6070</guid>
      <description><![CDATA[July's threatscape -- consider going through June's summary as well -- once again demonstrated that nothing is impossible, the impossible just takes a little longer where the incentive would be the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJLdSTaizDI/AAAAAAAAB_E/WogqT88LBdc/s1600-h/ddanchev_july.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJLdSTaizDI/AAAAAAAAB_E/Bb9z-K3ib7c/s200-R/ddanchev_july.jpg" style="border: 0pt none ;" /></a>July's threatscape -- consider going through <a href="http://ddanchev.blogspot.com/2008/07/summarizing-junes-threatscape.html">June's summary</a> as well -- once again demonstrated that nothing is impossible, the impossible just takes a little longer where the incentive would be the ultimate monetization of the process.<br />
<br />
Russian hacktivists attacking Lithuania and Georgia, several Storm Worm campaigns, a couple of new malware tools, Neosploit team abandoning support for their web malware exploitation kit, CAPTCHA for several of the most popular free email providers getting efficiently attacked in order to resell the bogus accounts registered in the process, several copycat SQL injects next to the evasion techniques applied by the copycats, botnets continuing to commit click fraud and generate revenue for those who own or have rented them, an infamous money mule recruitment service taking advantage of the fast-fluxed network provided by the ASProx botnet - pretty interesting month indeed.<br />
<br />
<b>01.</b> <a href="http://ddanchev.blogspot.com/2008/07/decrypting-and-restoring-gpcode.html">Decrypting and Restoring GPcode Encrypted Files</a> -<br />
The GPcode authors read the news too, and are catching up with the major weaknesses pointed out in their previous release in order to come with a virtually unbreakable algorithm. And since more evidence of <a href="http://ddanchev.blogspot.com/2008/06/whos-behind-gpcode-ransomware.html">who's behind the GPcode ransomware</a> was gathered, vendors and independent researchers realized that the latest release is also susceptible to a plain simple flaw, namely the encrypted files were basically getting deleting and not securely erased making them fairly easy to recover.<br />
<br />
<b>02.</b> <a href="http://ddanchev.blogspot.com/2008/07/chinese-bloggers-bypassing-censorship.html">Chinese Bloggers Bypassing Censorship by Blogging Backward</a> -<br />
When you know how it works, you can either improve, abuse or destroy it in that very particular order. Chinese bloggers are always very adaptive in respect to spreading their message by obfuscating their messages in a way that common keywords filtering software wouldn't be able to pick them.<br />
<br />
<b>03.</b> <a href="http://ddanchev.blogspot.com/2008/07/gmail-yahoo-and-hotmails-captcha-broken.html">Gmail, Yahoo and Hotmail’s CAPTCHA Broken</a> -<br />
This has been an urban legend for a while, but with more services starting to offer hundreds of thousands of pre-registered accounts at these providers, it's surprising that <a href="http://blogs.zdnet.com/security/?p=1514">spam and phishing emails coming from legitimate email providers is increasing</a>. The "vendors" behind these propositions are naturally starting to "vertically integrate" by offering value-added services for extra payments, namely, scripts to automatically abuse the pre-registered accounts for automatic registration of splogs and anything else malicious or blackhat SEO related.<br />
<br />
<b>04.</b> <a href="http://ddanchev.blogspot.com/2008/07/antivirus-industry-in-2008.html">The Antivirus Industry in 2008</a> -<br />
If it were anyone else but a security vendor to come up with such a realistic cartoon aiming to stimulate innovation by emphasizing on how prolific and sophisticated malware groups have become, it would have been a biased cartoon. However, this one is courtesy of a security vendor, and it's pretty objective.<br />
<br />
<b>05.</b> <a href="http://ddanchev.blogspot.com/2008/07/lithuania-attacked-by-russian.html">Lithuania Attacked by Russian Hacktivists, 300 Sites Defaced</a> -<br />
This attack is a good example of a decent PSYOPS operation. Of course they have already build the capabilities to deface and even execute DDoS attacks against Lithuania, so why not put them in a "stay tuned" mode, by speculating on the upcoming attack and then executing it making it look like they delived what they've promised? This a lone gunman mass defacement given that the sites were all hosted on a single ISP, with no indication of any kind of coordination whatsoever. The same for the <a href="http://blogs.zdnet.com/security/?p=1533">Georgia President’s web site which was under DDoS attack from Russian hackers</a> later this month. Despite that the hacktivists behind it dedicated a separate C&amp;C for the attack, one that hasn't been used in any type of previous attacks so far, they did a minor mistake by using a secondary command and control location that's known to have been connected with a particular "botnet on demand" service in the past. The second attack once again proves that you don't need to build capacity when you can basically outsource the process to someone else.<br />
<br />
<b>06.</b> <a href="http://ddanchev.blogspot.com/2008/07/icann-responds-to-dns-hijacking-its.html">The ICANN Responds to the DNS Hijacking, Its Blog Under Attack</a> -<br />
The ICANN finally issued a statement concerning the DNS hijacking of some of their domains, which is in fact what Comcast.net and Photobucket.com should have done as well, next to stating it was a "glitch". The ICANN also took advantage of the moment and also pointed out that their blog has also been under attack during the month. There's no better example of how the combination of <a href="http://ddanchev.blogspot.com/2008/06/icann-and-ianas-domain-names-hijacked.html"> tactics can result in the hijacking of the domains</a> of the organizations implementing procedures aiming to protect against these very same attacks. And while Photobucket.com remained silent during the entire incident, the hosting provider that was used by the Netdevilz team in the two attacks, since they were also responsible for the ICANN and IANA DNS hijackings, <a href="http://ddanchev.blogspot.com/2008/06/update-to-photobuckets-dns-hijacking.html">technological and social engineeringissued a statement</a>.<br />
<br />
<b>07.</b> <a href="http://ddanchev.blogspot.com/2008/07/risks-of-outdated-situational-awareness.html">The Risks of Outdated Situational Awareness</a> -<br />
Security vendors are often in a "catch-up mode" and if I were an average Internet user not knowing that real-time situational awareness speaks for the degree to which my vendor knows what going on online, I'd be pretty excited. However, I'm not. <a href="http://blogs.zdnet.com/security/?p=1085">Prevx were catching up with a service which I covered approximately two months ago</a>, I even had the chance to constructively confront with one of the affected sites on how despite their security measures in place, this attack was still possible. Recently <a href="http://www.theregister.co.uk/2008/07/18/limbo_trojan/">Prevx have once again demonstrated an outdated situational awareness</a> by coming across a banking malware in July 2008, whereas the malware has been around since July 2007, and earlier depending on which version you're referring to.<br />
<br />
<b>08.</b> <a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a> -<br />
Yet another domain portfolio of fake porn sites serving rogue codecs and live exploit URLs, just the tip of the iceberg as usual, however their centralization is greatly assisting in tracking them down.<br />
<br />
<b>09.</b> <a href="http://ddanchev.blogspot.com/2008/07/storm-worms-us-invasion-of-iran.html">Storm Worm's U.S Invasion of Iran Campaign</a> -<br />
Stormy Wormy is once again making the headlines with their ability to actually make up the headlines on their own.<br />
<br />
<b>10.</b> <a href="http://ddanchev.blogspot.com/2008/07/mobile-malware-scam-isexplayer-wants.html">Mobile Malware Scam iSexPlayer Wants Your Money</a> -<br />
The best scams are the ones to which you've personally agreed to be scammed with without even knowing it. Like this one, which was tracked down and analyzed a couple of hours once a uset tipped on it.<br />
<br />
<b>11.</b> <a href="http://ddanchev.blogspot.com/2008/07/template-ization-of-malware-serving.html">The Template-ization of Malware Serving Sites</a> -<br />
The increase of fake porn and celebrity sites is due to the overall template-ization of these, with the people behind them basically implementing several malicious doorways to ensure that the domains get rotated on the fly. Despite that they all look the same, they all sever different type of malware, and zero porn of celebrity content at all except the thumbnails.<br />
<br />
<b>12.</b> <a href="http://ddanchev.blogspot.com/2008/07/violating-opsec-for-increasing.html">Violating OPSEC for Increasing the Probability of Malware Infection</a> -<br />
No better way to expose your affiliations and several unknown bad netblocks so far, by adding the netblocks and the malicious domains as trusted sites upon infecting a PC with the malware. Of course, the usual suspects lead the "trusted netblocks".<br />
<br />
<b>13.</b> <a href="http://ddanchev.blogspot.com/2008/07/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</a> -<br />
Several years ago, a script kiddie would install Apache on a mail server, they claim that they defaced it. Today, these amusing situations are replaced by monetization of the compromised sites, by reselling the access to them to blackhat SEO-ers, malware authors, phishers, or personally starting to manage a scammy infrastructure on them, by earning money on an affiliate based model, like this particular attack.<br />
<br />
<b>14.</b> <a href="http://ddanchev.blogspot.com/2008/07/malware-and-office-documents-joining.html">Malware and Office Documents Joining Forces</a> -<br />
A recent DIY malware kit, sold as a proprietary tool basically crunching out malware infected office documents, whose built-in obfuscation makes them harder to detect. It will sooner or later leak out, turning into a commodity tool, a process that's been pretty evident for web malware exploitation kits as well.<br />
<br />
<b>15.</b> <a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</a> -<br />
Depends on who you're buying them from, and whether or not they offer discounts on a volume basis, namely the more you buy the cheaper the price of a card is supposed to get. With the current oversupply of stolen credit card details, what used to be an exclusive good once where they could enjoy a higher profit-margin, is today's commodity good.<br />
<br />
<b>16.</b> <a href="http://ddanchev.blogspot.com/2008/07/neosploit-malware-kit-updated-with.html">The Neosploit Malware Kit Updated with Snapshot ActiveX Exploit</a> -<br />
Since alll the web malware exploitation kits are open source, and leaked in the wild at large, their modularity allows everyone to easily embed any type of exploit that they want to, resulting in Neosploit's single most beneficial feature, the fact that certain versions include all the publicly available exploits targeting Internet Explorer, Firefox and Opera. Moreover, the open source nature of the kit is resulting in a countless number of modified versions yet to be detected and analyzed, therefore keeping track of the exploits included in a malware kit can only be realistic if you take into considered the exploits that come with the default installation.<br />
<br />
<b>17.</b> <a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast-fluxed SQL Injected Domains</a> -<br />
Now that's a very good example of different tactics combined to attack, ensure survivability, and apply a certain degree of evasion in between.<br />
<br />
<b>18.</b> <a href="http://ddanchev.blogspot.com/2008/07/unbreakable-captcha.html">The Unbreakable CAPTCHA</a> -<br />
There's never been a shortage of ideas, there's always been an issue of usability.<br />
<br />
<b>19.</b> <a href="http://ddanchev.blogspot.com/2008/07/ayyildiz-turkish-hacking-group-vs.html">The Ayyildiz Turkish Hacking Group VS Everyone</a> -<br />
That's a pretty inspiring mission if you are to ensure your future in the next couple of years, by targeting everyone, everywhere that has ever publicly stated their disagreement with the Turkish foreign policy.<br />
<br />
<b>20.</b> <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">Money Mule Recruiters use ASProx's Fast Fluxing Services</a> -<br />
A true multitasking in action with a botnet that's been crunching out phishing emails, SQL injecting and now hosting a well known money mule recruitment service. <br />
<br />
<b>21.</b> <a href="http://ddanchev.blogspot.com/2008/07/sql-injecting-malicious-doorways-to.html">SQL Injecting Malicious Doorways to Serve Malware</a> -<br />
Constantly switching tactics and combining different ones to achive an objective that used to be accomplished by plain simple techniques, is only starting to take place. In this case, instead of a hard coded SQL injected domain, we have the typical malicious doorways the result of the converging traffic management tools with web malware exploitation kits.<br />
<br />
<b>22.</b> <a href="http://ddanchev.blogspot.com/2008/07/impersonating-stopbadwareorg-to-serve.html">Impersonating StopBadware.org to Serve Fake Security Warnings</a> -<br />
Typosquatting popular security vendors and services is nothing new, by having HostFresh providing the hosting for the parked domains promoting the rogue security software, is a privilege and flattery for the success of the Stopbadware initiative.<br />
<br />
<b>23.</b> <a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a> -<br />
Customerization -- not customization -- has been taking place for a while, that's the process of tailoring your upcoming products to the needs of your future customers, compared to the product concept myopia where the malware coder would code something that he believes would be valuable to the potential customers. End user agreements, issuing licenses for the malware tool, as well as forbidding the reverse engineering of the malware so that no remotely exploitable flaws could be, are among the requirements the coder assists on.<br />
<br />
<b>24. </b><a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><b> -</b><br />
Taking a random snapshot of the current malicious activity at a well known provider of hosting services for rogue security applications, live exploit URLs and botnet command&amp;control locations, always provides an insight into what are their customers up to. In this case, centralization of their scammy ecosystem, and parking a countless number of rogue domains on the same server.<br />
<br />
<b>25. </b><a href="http://ddanchev.blogspot.com/2008/07/email-hacking-going-commercial.html">Email Hacking Going Commercial</a> -<br />
Cybercrime is in fact getting easier to outsource, and while the number of scammers trying to offer non-existent services, or at least services where they cannot deliver the goods, the business model of this service that is that you only pay once they show you a proof that they've managed to hack the email address you game them. How are they doing it? Social engineering and enticing the user to click on live exploit URL from where they'll infect the PC and obtain the email password, of course, next to definitely abusing it for many other purposes in the process.<br />
<br />
<b>26.</b> <a href="http://ddanchev.blogspot.com/2008/07/vulnerabilities-in-antivirus-software.html">Vulnerabilities in Antivirus Software - Conflict of Interest</a> -<br />
You can easily twist the number of vulnerabilities found in your antivirus solution, but not recognizing them as vulnerabilities at the first place. It's all a matter of what you define as a vulnerability, or perhaps what you admit as a serious vulnerability - remote code execution through a security software, or a flaw that's allowing malware to bypass the security solution itself.<br />
<br />
<b>27. </b><a href="http://ddanchev.blogspot.com/2008/07/counting-bullets-on-malware-front.html">Counting the Bullets on the (Malware) Front</a> -<br />
Emphasizing on the number of malware/threats/viruses/worms/slugs your solution detects may be marketable in the short-term, but is damaging the end user's understanding of the threatscape in the long-term. So, by the time he catches up with what exactly is going on, he'll recall the moment in time where he was using the number of threats his solution was detecting as the main benchmark for its usefulness. In reality through, the number is irrelevant from a pro-active point of view, with zero day malware like the one coded for hire undermining the signatures based scanning model.<br />
<br />
<b>28. </b><a href="http://ddanchev.blogspot.com/2008/07/smells-like-copycat-sql-injection-in.html">Smells Like a Copycat SQL Injection In the Wild</a> -<br />
It was pretty obvious that copycats seeing the success of SQL injections the the huge number of sites susceptible to exploitation, would also starting taking advantage of the practice. Some are, however, targeting local communities and trying to avoid detection by using targeted SQL injections.<br />
<br />
<b>29. </b><a href="http://ddanchev.blogspot.com/2008/07/click-fraud-botnets-and-parked-domains.html">Click Fraud, Botnets and Parked Domains - All Inclusive</a> -<br />
The scheme is nothing new, what's new is that the botnet masters are trying to limit the revenues that used to go out to affiliate networks they were participating in, and are trying to own or rent the entire infrastructure on their own.<br />
<br />
<b>30. </b><a href="http://ddanchev.blogspot.com/2008/07/over-80-percent-of-storm-worm-spam-sent.html">Over 80 percent of Storm Worm Spam Sent by Pharmaceutical Spam Kings</a><b> -</b><br />
With access to Storm Worm sold and resold, and new malware introduced on Storm Worm infected hosts used as foundation for the propagation of the new malware in this case, it's questionable whether or not the Storm Worm-ers themselves are sending out the junk emails, or are they people who've rented access to the botnet doing it. <br />
<br />
<b>31. </b><a href="http://ddanchev.blogspot.com/2008/07/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</a> -<br />
Pretty surprising at the first place, but in reality it clearly demonstrates that when you cannot enforce the end user agreement on your crimeware kit, but continue seeing it used in a very profitable malware operations, you basically shut down the support for the public version. The team is not going to stop innovating for their own purposes, and in the long-term they may in fact re-appear with an updated malware kit that's converging different services next to the product itself.<br />
<br />
<b>32. </b><a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a> - <br />
Managed spamming services using botnets as the foundation for the campaigns are starting to introduce improved metrics for the delivery, as well as experienced customer support ensuring the spam messages make it through spam filters, or at least increase the probability of making the happen. This is an example of a random service emphasizing on the improved metrics they're capable of delivering.<br />
<br />
<b>33. </b><a href="http://ddanchev.blogspot.com/2008/07/storm-worms-lazy-summer-campaigns.html">Storm Worm's Lazy Summer Campaigns</a> -<br />
Looks like a "cybercrime intern" launched this campaign, lacking any of the usual Storm Worm evasive practices, no exploitation of client side vulnerabilities, as well as no survivability offered by their usual fast-flux nodes.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dMjxcK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dMjxcK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IC3AVK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IC3AVK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=d2XWZk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=d2XWZk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vRFZyk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vRFZyk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6ZdeKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6ZdeKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jVlXIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jVlXIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W4mAWk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W4mAWk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/352993637" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 12:08:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/profitable malware operations">profitable malware operations</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/malware tools">malware tools</category>
      <category domain="http://securityratty.com/tag/malware coder">malware coder</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <category domain="http://securityratty.com/tag/malware infection">malware infection</category>
      <category domain="http://securityratty.com/tag/neosploit malware kit">neosploit malware kit</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/352993637/summarizing-julys-threatscape.html">Summarizing July's Threatscape</source>
    </item>
    <item>
      <title><![CDATA[Who Pays?]]></title>
      <link>http://securityratty.com/article/fb3394af481487a063b652f5913105db</link>
      <guid>http://securityratty.com/article/fb3394af481487a063b652f5913105db</guid>
      <description><![CDATA[Frankly Speaking: Frank Hayes observes that the lesson learned from a rogue network administrators actions is an old one: The best IT is built by teams not lone...]]></description>
      <content:encoded><![CDATA[Frankly Speaking: Frank Hayes observes that the lesson learned from a rogue network administrators actions is an old one: The best IT is built by teams not lone wolves.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=GFuSBk"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=GFuSBk" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/341182883" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 00:31:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/frank hayes observes">frank hayes observes</category>
      <category domain="http://securityratty.com/tag/lone wolves">lone wolves</category>
      <category domain="http://securityratty.com/tag/teams">teams</category>
      <category domain="http://securityratty.com/tag/lesson">lesson</category>
      <category domain="http://securityratty.com/tag/frankly">frankly</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/341182883/article.do">Who Pays?</source>
    </item>
    <item>
      <title><![CDATA[Clever Museum Theft]]></title>
      <link>http://securityratty.com/article/6a56823b5152f1872fe26e870cf20b38</link>
      <guid>http://securityratty.com/article/6a56823b5152f1872fe26e870cf20b38</guid>
      <description><![CDATA[Some expensive and impressive stuff was stolen from the University of British Columbia's Museum of Anthropology: A dozen pieces of gold jewelry designed by prominent Canadian artist Bill Reid were...]]></description>
      <content:encoded><![CDATA[<p>Some <a href="http://www.canada.com/vancouversun/news/story.html?id=fc613f5f-3f35-467f-bf9d-0259586bf634">expensive and impressive</a> stuff was stolen from the University of British Columbia's Museum of Anthropology:</p>

<blockquote>A dozen pieces of gold jewelry designed by prominent Canadian artist Bill Reid were stolen from the museum sometime on May 23, along with three pieces of gold-plated Mexican jewelry. The pieces that were taken are estimated to be worth close to $2 million.</blockquote>

<p>Of course, it's not the museum's fault:</p>

<blockquote>But museum director Anthony Shelton said that elaborate computer program printouts have determined that the museum's security system did not fail during the heist and that the construction of the building's layout did not compromise security.</blockquote>

<p>Um, isn't having stuff get stolen the very definition of security failing?  And does anyone have any idea how "elaborate computer program printouts" can determine that security didn't fail?  What in the world is this guy talking about?</p>

<p>A few days later, we learned that <a href="http://www.cbc.ca/canada/british-columbia/story/2008/06/04/bc-ubc-security-ruse.html?ref=rss">security did indeed fail</a>:</p>

<blockquote>Four hours before the break-in on May 23, two or three key surveillance cameras at the Museum of Anthropology mysteriously went off-line.

<p>Around the same time, a caller claiming to be from the alarm company phoned campus security, telling them there was a problem with the system and to ignore any alarms that might go off.</p>

<p>Campus security fell for the ruse and ignored an automated computer alert sent to them, police sources told CBC News.</p>

<p>Meanwhile surveillance cameras that were still operating captured poor pictures of what was going on inside the museum because of a policy to turn the lights off at night.</p>

<p>Then, as the lone guard working overnight in the museum that night left for a smoke break, the thief or thieves broke in, wearing gas masks and spraying bear spray to slow down anyone who might stumble across them.</blockquote></p>

<p>It's a particular kind of security failure, but it's definitely a failure.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=YwAwhI"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=YwAwhI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Uvs3aI"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Uvs3aI" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 06 Jun 2008 01:04:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/compromise security">compromise security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/museum">museum</category>
      <category domain="http://securityratty.com/tag/campus security">campus security</category>
      <category domain="http://securityratty.com/tag/security failure">security failure</category>
      <category domain="http://securityratty.com/tag/security system">security system</category>
      <category domain="http://securityratty.com/tag/computer program printouts">computer program printouts</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/key surveillance cameras">key surveillance cameras</category>
      <source url="http://www.schneier.com/blog/archives/2008/06/clever_museum_t.html">Clever Museum Theft</source>
    </item>
    <item>
      <title><![CDATA[Redmond Magazine SQL Injected by Chinese Hacktivists]]></title>
      <link>http://securityratty.com/article/d89e68feff9268da5e09084f1290381e</link>
      <guid>http://securityratty.com/article/d89e68feff9268da5e09084f1290381e</guid>
      <description><![CDATA[Four Redmond related web properties appear to have been SQL injected by Chinese hacktivists , namely, Redmond - The Independent Voice of the Microsoft IT Community formerly known as Microsoft...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SC8MxntDW8I/AAAAAAAABto/eA_j8CKscKY/s1600-h/redmond_magazine_SQL_2.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SC8MxntDW8I/AAAAAAAABto/eA_j8CKscKY/s200/redmond_magazine_SQL_2.JPG" alt="" id="BLOGGER_PHOTO_ID_5201390141247282114" border="0" /></a>Four Redmond related web properties appear to have been <a href="http://blogs.zdnet.com/security/?p=1118">SQL injected by Chinese hacktivists</a>, namely, <span style="font-weight: bold;">Redmond - The Independent Voice of the Microsoft IT Community</span> formerly known as <span style="font-weight: bold;">Microsoft Certified Professional Magazine</span>, the <span style="font-weight: bold;">Redmond Developer News</span> as well as the <span style="font-weight: bold;">Redmond Channel Partner Online</span>.<br /><br />The lone hacktivist also left a message at the malicious domain (<span style="font-weight: bold;">wowyeye.cn</span>), which reads :<br /><br />“<span style="font-style: italic;">The invasion can not control bulk!!!!If the wrong target. Please forgive! Sorry if you are a hacker. send email to kiss117276@163.com my name is lonely-shadow TALK WITH ME! china is great! f**k france! f**k CNN! f**k ! HACKER have matherland!</span>”<br /><br />Go through <a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html">related posts</a> on the recent <a href="http://ddanchev.blogspot.com/2008/04/chinese-hacktivists-waging-peoples.html">Chinese Anti-CNN campaign</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rz9XGH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rz9XGH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4fbLFH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4fbLFH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=F6Puyh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=F6Puyh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UKeK4h"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UKeK4h" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dLNdFH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dLNdFH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MrtPQH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MrtPQH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xAetrh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xAetrh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/292396284" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 17 May 2008 08:00:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/redmond">redmond</category>
      <category domain="http://securityratty.com/tag/redmond developer news">redmond developer news</category>
      <category domain="http://securityratty.com/tag/chinese hacktivists">chinese hacktivists</category>
      <category domain="http://securityratty.com/tag/lone hacktivist">lone hacktivist</category>
      <category domain="http://securityratty.com/tag/professional magazine">professional magazine</category>
      <category domain="http://securityratty.com/tag/control bulk">control bulk</category>
      <category domain="http://securityratty.com/tag/malicious domain">malicious domain</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/wrong target">wrong target</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/292396284/redmond-magazine-sql-injected-by.html">Redmond Magazine SQL Injected by Chinese Hacktivists</source>
    </item>
    <item>
      <title><![CDATA[Skype Phishing Pages Serving Exploits and Malware]]></title>
      <link>http://securityratty.com/article/4df4197bb1a3121904fb08c91ddfa078</link>
      <guid>http://securityratty.com/article/4df4197bb1a3121904fb08c91ddfa078</guid>
      <description><![CDATA[Please, don't update your account information&quot;, at least not on recently spammed phishing pages which will not only aim at obtaining your accounting data, but will also infect with you malware through...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SCQbKRTncTI/AAAAAAAABr8/VVkeOGOVB6c/s1600-h/skype_phishing_exploits_malware.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SCQbKRTncTI/AAAAAAAABr8/VVkeOGOVB6c/s200/skype_phishing_exploits_malware.jpg" alt="" id="BLOGGER_PHOTO_ID_5198309733150716210" border="0" /></a>"Please, don't update your account information", at least not on recently spammed phishing pages which will not only aim at obtaining your accounting data, but will also infect with you malware through exploiting MS06-014. These phishing emails are a great example of blended threats, and while we're been witnessing the <a href="http://ddanchev.blogspot.com/2007/12/phishers-spammers-and-malware-authors.html">ongoing consolidation between phishers, spammers and malware authors</a> for the last two years, this particular phishing campaign looks like a lone gunman operation.<br /><br />Original message : "<span style="font-style: italic;">Dear valued skype member: It has come to our attention that your skype account informations needs to be  updated as part of our continuing commitment to protect your account and to reduce the instance of fraud on our website. If you could please take 5-10 minutes out of your online experience and update your personal records you will not run into any future problems with the online service. However, failure to update your records will result in account suspension. Please update your records on or before May 11, 2008. you are requested to update your account informations at the following link. To update your informations.</span>"<br /><br />Phishing URL : <span style="font-weight: bold;">alertskype.freehostia.com</span>, which is then forwarding to<span style="font-weight: bold;"> skypealert.ns8-wistee.fr/Secure.skype.com/store/member/login.html/Login.aspx/index/Sky</span><span style="font-weight: bold;">pe.Members/index.htmls/ </span>where the malware and the exploit are hosted.<br /><br />Scanners result : Result: 3/31 (9.68%)<br />VBS/Small.W.1; Exploit-MS06-014<br /><span style="font-weight: bold;">File size</span>: 13569 bytes<br /><span style="font-weight: bold;">MD5</span>...: 4d6a559adf0602f7fd58b884e00894dc<br /><span style="font-weight: bold;">SHA1</span>..: 056f75e0dd94d03daeb04ae83d1b4a1b7476c0f2<br /><span style="font-weight: bold;">SHA256</span>: 3f08427228489edffd57e927db571aea06716c192ec72f91ea8115c0c7f978eb<br /><br /><div id="status_porcentaje" style="display: inline;"><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SCQ48xTncUI/AAAAAAAABsE/M_m8zKLr5-A/s1600-h/skype_phishing_malware1.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SCQ48xTncUI/AAAAAAAABsE/M_m8zKLr5-A/s200/skype_phishing_malware1.JPG" alt="" id="BLOGGER_PHOTO_ID_5198342486571315522" border="0" /></a><span id="porcentaje">The phishing page wasn't created, but copied from Skype's original login page. The phisher even left an email within the VBS, in this case - ikbaman@gmail.com. Virtual greed or contact point optimization for fraudulent purposes, passive phishing attacks can sometimes be quite active and leave the curious clicker with a false feeling of security.<br /></span></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gJjraH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gJjraH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=lHkFQH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=lHkFQH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ib206h"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ib206h" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=yyId6h"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=yyId6h" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=H1H9QH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=H1H9QH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0gnpPH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0gnpPH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=tYQ2ch"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=tYQ2ch" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/286779517" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 09 May 2008 03:00:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/skype account informations">skype account informations</category>
      <category domain="http://securityratty.com/tag/account informations">account informations</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/skype">skype</category>
      <category domain="http://securityratty.com/tag/account information">account information</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/informations">informations</category>
      <category domain="http://securityratty.com/tag/original login page">original login page</category>
      <category domain="http://securityratty.com/tag/result">result</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/286779517/skype-phishing-pages-serving-exploits.html">Skype Phishing Pages Serving Exploits and Malware</source>
    </item>
  </channel>
</rss>
