<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: movie]]></title>
    <link>http://securityratty.com/tag/movie</link>
    <description></description>
    <pubDate>Wed, 30 Jul 2008 03:05:48 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Holy Media Codecs, Batman!]]></title>
      <link>http://securityratty.com/article/3d984264f929456ea8e4f274d55394ef</link>
      <guid>http://securityratty.com/article/3d984264f929456ea8e4f274d55394ef</guid>
      <description><![CDATA[Batman is still in full swing at the box office - I'm sure me seeing it seven times probably didn't hurt - so with that in mind (and thoughts of the Zango / Dark Knight issue still rattling around my...]]></description>
      <content:encoded><![CDATA[
        Batman is still in full swing at the box office - I'm sure me seeing it seven times probably didn't hurt - so with that in mind (and thoughts of the <a href="http://www.theregister.co.uk/2008/08/18/dark_knight_zango_affiliate_gateway/">Zango / Dark Knight issue</a> still rattling around my brain) I thought it would be fun to see exactly how quickly it can all go wrong when looking for Dark Knight material online.<br /><br />The answer is: extremely quickly.<br /><br />There's a lot of sites out there claiming to carry "full versions" of The Dark Knight, and although they don't offer Zango, they <i>do</i> offer fake media codecs (which usually do all sorts of horrible things to a computer). Let's pull one of these sites apart as an example of how the scam fits together.<br /><br />Here's a typical site pushing what they claim to be The Dark Knight:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman000.html" onclick="window.open('http://blog.spywareguide.com/images/dbman000.html','popup','width=717,height=564,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman000-thumb-317x249.jpg" alt="dbman000.jpg" class="mt-image-none" style="" height="249" width="317" /></a></span><br />Click to Enlarge<br /></div><br />Dijgg(dot)com, an obvious Digg.com knockoff apparently hosting a large streaming window - the movie quality will be awesome, won't it? Well, actually, no it won't.<br /><br />In the middle of the video window is a popup:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman0.jpg" src="http://blog.spywareguide.com/images/dbman0.jpg" class="mt-image-none" style="" height="145" width="399" /></span></div><br /><br /> <div>Install the "codec", and this won't end well. The EXE comes from a site called Favoritetube(dot)com:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman1.jpg" src="http://blog.spywareguide.com/images/dbman1.jpg" class="mt-image-none" style="" height="203" width="348" /></span></div><br /><br />A quick check for the <a href="http://www.siteadvisor.com/sites/favoritetube.net/postid?p=1063293">safety</a> <a href="http://safeweb.norton.com/report/show?name=favoritetube.net">ratings</a> of that website should be enough to tell you this is a scam. Indeed, there isn't even a movie being streamed here (despite it saying "Connecting" at the bottom of the movie player) - because if you right click on the player itself:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman0000.jpg" src="http://blog.spywareguide.com/images/dbman0000.jpg" class="mt-image-none" style="" height="370" width="418" /></span></div><br /></div><div><br />You can see the "player" is actually just a static image (because I'm given the option to "Copy Image Location"). The image is hosted at Favoritetube, just like the "codecs":<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman2.html" onclick="window.open('http://blog.spywareguide.com/images/dbman2.html','popup','width=655,height=570,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman2-thumb-355x308.jpg" alt="dbman2.jpg" class="mt-image-none" style="" height="308" width="355" /></a></span><br /><br />Click to Enlarge<br /></div><br />There are quite a lot of these sites floating around out there at present:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman3.html" onclick="window.open('http://blog.spywareguide.com/images/dbman3.html','popup','width=738,height=532,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman3-thumb-338x243.jpg" alt="dbman3.jpg" class="mt-image-none" style="" height="243" width="338" /></a></span><br /><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman4.html" onclick="window.open('http://blog.spywareguide.com/images/dbman4.html','popup','width=599,height=533,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman4-thumb-399x355.jpg" alt="dbman4.jpg" class="mt-image-none" style="" height="355" width="399" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman100.html" onclick="window.open('http://blog.spywareguide.com/images/dbman100.html','popup','width=625,height=516,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman100-thumb-325x268.jpg" alt="dbman100.jpg" class="mt-image-none" style="" height="268" width="325" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />At this point, it's a given that I'm going to show you what happens if you install one of the files typically pushed from the above sites, right? Well, wait no longer - this....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman7.jpg" src="http://blog.spywareguide.com/images/dbman7.jpg" class="mt-image-none" style="" height="81" width="84" /></span></div><br /></div><div><br />...will deposit a rogue antispyware tool on your desktop (one of more more obnoxious ones that refuses to leave you alone):<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/antispycheck1.html" onclick="window.open('http://blog.spywareguide.com/images/antispycheck1.html','popup','width=877,height=668,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/antispycheck1-thumb-377x287.jpg" alt="antispycheck1.jpg" class="mt-image-none" style="" height="287" width="377" /></a></span><br /><br />Click to Enlarge<br /></div><br />Strange and annoying icons will start to creep across your desktop:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman8.jpg" src="http://blog.spywareguide.com/images/dbman8.jpg" class="mt-image-none" style="" height="82" width="245" /></span></div><br /></div><div><br />....and you'll have more fake system alerts than you can shake a very large stick at:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="antispycheck22.jpg" src="http://blog.spywareguide.com/images/antispycheck22.jpg" class="mt-image-none" style="" height="304" width="273" /></span></div><br /><br />This concludes my public safety announcement. I'm off to see Dark Knight again...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 06:10:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dark knight issue">dark knight issue</category>
      <category domain="http://securityratty.com/tag/dark knight">dark knight</category>
      <category domain="http://securityratty.com/tag/movie player">movie player</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/player">player</category>
      <category domain="http://securityratty.com/tag/enlarge">enlarge</category>
      <category domain="http://securityratty.com/tag/image">image</category>
      <category domain="http://securityratty.com/tag/copy image location">copy image location</category>
      <category domain="http://securityratty.com/tag/movie">movie</category>
      <source url="http://blog.spywareguide.com/2008/08/holy-media-codecs-batman.html">Holy Media Codecs, Batman!</source>
    </item>
    <item>
      <title><![CDATA[Music, movie lobbyists push to spy on your Net traffic]]></title>
      <link>http://securityratty.com/article/6252740240fa5ae4fb469691f603ce36</link>
      <guid>http://securityratty.com/article/6252740240fa5ae4fb469691f603ce36</guid>
      <description><![CDATA[Recording industry and motion picture lobbyists are renewing their push to convince broadband providers to monitor customers and detect copyright infringements, claiming the concept is working abroad...]]></description>
      <content:encoded><![CDATA[Recording industry and motion picture lobbyists are renewing their push to convince broadband providers to monitor customers and detect copyright infringements, claiming the concept is working abroad and should be adopted in the United States. ]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 11:30:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/detect copyright infringements">detect copyright infringements</category>
      <category domain="http://securityratty.com/tag/convince broadband providers">convince broadband providers</category>
      <category domain="http://securityratty.com/tag/motion picture lobbyists">motion picture lobbyists</category>
      <category domain="http://securityratty.com/tag/push">push</category>
      <category domain="http://securityratty.com/tag/monitor customers">monitor customers</category>
      <category domain="http://securityratty.com/tag/abroad">abroad</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <category domain="http://securityratty.com/tag/concept">concept</category>
      <source url="http://digg.com/security/Music_movie_lobbyists_push_to_spy_on_your_Net_traffic">Music, movie lobbyists push to spy on your Net traffic</source>
    </item>
    <item>
      <title><![CDATA[Spammers Take A Cheap Shot...]]></title>
      <link>http://securityratty.com/article/2bd234de99d23ff4b013abce95e7d324</link>
      <guid>http://securityratty.com/article/2bd234de99d23ff4b013abce95e7d324</guid>
      <description><![CDATA[I'm on holiday this week, but thought I'd better give this a mention anyway (plus, when did being on holiday ever stop me from posting stuff on blogs, right

I was surprised to see this posted to the...]]></description>
      <content:encoded><![CDATA[
        I'm on holiday this week, but thought I'd better give this a mention anyway (plus, when did being on holiday ever stop me from posting stuff on blogs, right?)<br /><br />I was surprised to see this posted to the comments section of the <a href="http://sunbeltblog.blogspot.com/">Sunbelt Blog</a>:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="spgspam1.gif" src="http://blog.spywareguide.com/images/spgspam1.gif" class="mt-image-none" style="" height="144" width="359" /></span><br /> <div><br />I was about as surprised as The Dean was!<br /><br />To quote a further post from The Dean:<br /><br /><i>"Well, that's weird. Isn't spywareguide Paperghost's blog? I know he
wouldn't spam here. And, the link on the first comment goes to a 404
page."</i><br /><br />So, we have someone spamming with broken English, dropping links to 404 pages on Spywareguide. Curious.<br /><br />Now, I did have some suspicions on this - for starters, the recent blogs regarding the pirate movie websites that pop Zango installers just hit a few <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=privacy&amp;articleId=9112881&amp;taxonomyId=84&amp;intsrc=kc_top">news</a> <a href="http://www.theregister.co.uk/2008/08/18/dark_knight_zango_affiliate_gateway/">websites</a>. As <a href="http://blog.spywareguide.com/2008/08/another-site-hiding-pirate-mov.html">this article</a> mentions, a lot of the sites involved in this are from Asian regions - China, Indonesia etc. I couldn't help but notice the name of the poster was "Tam" - a common name in certain parts of Asia.<br /><br />Coincidence? Or a possible affiliate not too happy about this being highlighted? Well, a quick email later and the results for the spammer are in:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="spgspam2.gif" src="http://blog.spywareguide.com/images/spgspam2.gif" class="mt-image-none" style="" height="185" width="430" /></span>
<br /><br />A potentially forged Reverse DNS aside, it's a strange thing indeed that they just happen to resolve to Vietnam given that a good portion of these sites are in Asia, isn't it?<br /><br />I think I'll see if any are owned by someone called "Tam".<br /><br />When I return from my holiday, of course....<br /></div><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 10:24:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/holiday">holiday</category>
      <category domain="http://securityratty.com/tag/pop zango installers">pop zango installers</category>
      <category domain="http://securityratty.com/tag/sunbelt blog">sunbelt blog</category>
      <category domain="http://securityratty.com/tag/blogs">blogs</category>
      <category domain="http://securityratty.com/tag/spywareguide paperghost">spywareguide paperghost</category>
      <category domain="http://securityratty.com/tag/recent blogs">recent blogs</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/spywareguide">spywareguide</category>
      <category domain="http://securityratty.com/tag/news websites">news websites</category>
      <source url="http://blog.spywareguide.com/2008/08/spammers-take-a-cheap-shot.html">Spammers Take A Cheap Shot...</source>
    </item>
    <item>
      <title><![CDATA[Another Site Hiding Pirate Movies Behind a Zango Installer Prompt]]></title>
      <link>http://securityratty.com/article/503b43d35c6104929785ac82ff1128b5</link>
      <guid>http://securityratty.com/article/503b43d35c6104929785ac82ff1128b5</guid>
      <description><![CDATA[A few days ago, I wrote about a site asking you to install Zango before you could view the site content (which happens to be pirated movies ). Well, another site has come to light doing a similar...]]></description>
      <content:encoded><![CDATA[
        A few days ago, I wrote about a site asking you to install Zango before you could view the site content (which happens to be <a href="http://blog.spywareguide.com/2008/08/a-dark-knight-for-zango.html">pirated movies</a>). Well, another site has come to light doing a similar thing - I'm starting to wonder how many of these are actually out there. It's also served to highlight what I feel is a particularly confusing popup box, but we'll get to that later. First off, here's the website in question:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/bc0.html" onclick="window.open('http://blog.spywareguide.com/images/bc0.html','popup','width=846,height=676,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/bc0-thumb-346x276.jpg" alt="bc0.jpg" class="mt-image-none" style="" height="276" width="346" /></a></span><br /> </div><div><div align="center">Click to Enlarge<br /></div><br />Bestcinemaonline(dot)com. As you can see, the site is similar to the last one (except that site is registered <a href="http://whois.domaintools.com/movietvonline.com">anonymously</a> to an individual in China, whereas this one is registered to <a href="http://whois.domaintools.com/bestcinemaonline.com">someone in Indonesia</a>). Also, the format is different - the last site was more of a "movie repository", whereas this one takes the shape and style of a blog with each individual entry pointing to a film. And what films they are!<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="bc5.jpg" src="http://blog.spywareguide.com/images/bc5.jpg" class="mt-image-none" style="" height="228" width="309" /></span><br /></div></div><div><div align="center">Batman!<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="bc6.jpg" src="http://blog.spywareguide.com/images/bc6.jpg" class="mt-image-none" style="" height="244" width="363" /></span><br /></div></div><div><div align="center">X-Files!<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/bc2.html" onclick="window.open('http://blog.spywareguide.com/images/bc2.html','popup','width=672,height=649,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/bc2-thumb-372x359.jpg" alt="bc2.jpg" class="mt-image-none" style="" height="359" width="372" /></a></span><br />Click to Enlarge<br /></div><br /></div><div>Hellboy! (Is that even out yet?)<br /><br />As you might have expected, a lot of the movies end up looking like this when attempting to watch them:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/bc3.html" onclick="window.open('http://blog.spywareguide.com/images/bc3.html','popup','width=771,height=573,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/bc3-thumb-371x275.jpg" alt="bc3.jpg" class="mt-image-none" style="" height="275" width="371" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />.....whoops.<br /><br />I must also give a special mention to one of the most confusing popup warnings I've ever seen - it really threw me, and I admit I nearly installed Zango accidentally after seeing it. If (when prompted with the Zango installer box) you click "Cancel", this appears in the middle of your screen:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="bc1.jpg" src="http://blog.spywareguide.com/images/bc1.jpg" class="mt-image-none" style="" height="126" width="476" /></span><br /></div><div><br /><i>"Click <b>OK to Cancel </b>or<b> Click "Cancel" to continue </b>the installation".</i><br /><br />.....Whaaaaaa? That's a bit of a brain bender, right there. I hope this set of writeups doesn't become a Trilogy...<br /><br /><br /></div>
        
    ]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 03:44:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/zango">zango</category>
      <category domain="http://securityratty.com/tag/site content">site content</category>
      <category domain="http://securityratty.com/tag/zango installer box">zango installer box</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/movies">movies</category>
      <category domain="http://securityratty.com/tag/individual">individual</category>
      <category domain="http://securityratty.com/tag/cancel">cancel</category>
      <category domain="http://securityratty.com/tag/install zango">install zango</category>
      <source url="http://blog.spywareguide.com/2008/08/another-site-hiding-pirate-mov.html">Another Site Hiding Pirate Movies Behind a Zango Installer Prompt</source>
    </item>
    <item>
      <title><![CDATA[A Dark Knight For Zango?]]></title>
      <link>http://securityratty.com/article/61b33df0818a09cde982b57d42eb49e7</link>
      <guid>http://securityratty.com/article/61b33df0818a09cde982b57d42eb49e7</guid>
      <description><![CDATA[Here's a site - movietvonline(dot)com - that requires you to install Zango in order to view the content




Click to Enlarge

Nothing unusual there, though I did think the owners of the website were...]]></description>
      <content:encoded><![CDATA[
        Here's a site - movietvonline(dot)com - that requires you to install Zango in order to view the content.<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/joker1.html" onclick="window.open('http://blog.spywareguide.com/images/joker1.html','popup','width=968,height=590,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/joker1-thumb-368x224.jpg" alt="joker1.jpg" class="mt-image-none" style="" height="224" width="368" /></a></span><br /><br />Click to Enlarge<br /></div><br />Nothing unusual there, though I did think the owners of the website were pushing things a <i>little</i>, perhaps, to ask you to install something to view content you could view for free on the <a href="http://thedarkknight.warnerbros.com/">official website</a>.<br /><br />Anyway.<br /><br />Turns out I was somewhat wrong, because they're not asking you to download Zango in order to watch <i>trailers</i>:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="joker2.jpg" src="http://blog.spywareguide.com/images/joker2.jpg" class="mt-image-none" style="" height="300" width="529" /></span><br /><br />They want you to agree to install Zango in order to view whole <i>movies</i>, some streamed on the movietvonline website from other sources, others in the form of broken up downloads hosted on file-downloading sites.<br /><br />Here's a shot of what appears to be a badly made camcorder (complete with people talking and scrunching up paper in the background) streamed on the website:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="joker3.jpg" src="http://blog.spywareguide.com/images/joker3.jpg" class="mt-image-none" style="" height="460" width="522" /></span>
<br /><br />Clearly, the Joker isn't asking Batman "Why so serious" - he's asking him why the camcorder rip is so seriously bad. In fact, the whole site appears to be nothing more than a mass repository of dubiously acquired movie copies:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/joker4.html" onclick="window.open('http://blog.spywareguide.com/images/joker4.html','popup','width=897,height=720,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/joker4-thumb-397x318.jpg" alt="joker4.jpg" class="mt-image-none" style="" height="318" width="397" /></a></span><br /><br />Click to Enlarge<br /></div><br />...Holy Pirated Content, Batman!<br />
        
    ]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 14:49:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/view">view</category>
      <category domain="http://securityratty.com/tag/view content">view content</category>
      <category domain="http://securityratty.com/tag/website">website</category>
      <category domain="http://securityratty.com/tag/official website">official website</category>
      <category domain="http://securityratty.com/tag/movietvonline website">movietvonline website</category>
      <category domain="http://securityratty.com/tag/install">install</category>
      <category domain="http://securityratty.com/tag/install zango">install zango</category>
      <category domain="http://securityratty.com/tag/movietvonline">movietvonline</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <source url="http://blog.spywareguide.com/2008/08/a-dark-knight-for-zango.html">A Dark Knight For Zango?</source>
    </item>
    <item>
      <title><![CDATA[Compromised Web Servers Serving Fake Flash Players]]></title>
      <link>http://securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</link>
      <guid>http://securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</guid>
      <description><![CDATA[The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/SSFpGnP3wvA/s1600-h/fake_flash1.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/qKqvrWeAN3s/s200-R/fake_flash1.png" style="border: 0pt none ;" /></a>The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so much confidence in this risk-forwarding process of hosting their campaigns, that they would start actively spamming the links residing within low-profile legitimate sites across the web.<br />
<br />
This campaign serving fake flash players is getting so prevalent these days due to the multiple spamming approaches used, that it's hard not to notice it - and expose it. From a strategic perspective, having a legitimate low-profile site -- of course with the obvious exceptions being on purposely registered for malicious purposes within the participating sites -- hosting your malicious campaign is pretty creative in terms of forwarding the responsibility, and the eventual blocking of a legitimate site to the its owner. As far as the owner's are concerned, it appears that some of them are already seeing the malware page popping-up on the top of their daily traffic stats, and have taken measures to remove it.<br />
<br />
Moreover, <a href="http://blogs.adobe.com/psirt/2008/08/verifying_installers.html">Adobe's Product Security Incident Response Team (PSIRT) issued a warning notice about the attack yesterday</a>, which could come handy if the <a href="http://www.infoworld.com/article/08/08/05/Adobe_warns_of_bogus_Flash_Player_installers_1.html">attackers weren't taking advantage of client-side vulnerabilities</a>, putting the unware end user is a situation where he <a href="http://blogs.stopbadware.org/articles/2008/08/05/same-dogs-new-tricks">wouldn't even receive a download dialog</a> :<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/LuFjz3rFLAc/s1600-h/fake_flash3_exploit.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/GXwA3Ai1LLY/s200-R/fake_flash3_exploit.jpg" style="border: 0pt none ;" /></a>"<i>We have seen coverage from the security community of a worm on popular social networking sites that is using social engineering lures to get users to install a piece of malware. According to the reports, the worm posts comments on these sites that include links to a fake site. If the link is followed, users are told they need to update their Flash Player. The installer, posted on a malicious site, of course installs malware instead of Flash Player.We’d like to take this opportunity to reiterate the importance of validating installers and updates before installing them. First off, do not download Flash Player from a site other than adobe.com – you can find the link for downloading Flash Player here. This goes for any piece of software (Reader, Windows Media Player, Quicktime, etc.) – if you get a notice to update, it’s not a bad idea to go directly to the site of the software vendor and download the update directly from the source. If the download is from an unfamiliar URL or an IP address, you should be suspicious.</i>"<br />
<br />
<a href="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/6PfKZxTNQao/s1600-h/fake_flash2.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/ADBheDs2hkk/s200-R/fake_flash2.png" style="border: 0pt none ;" /></a>The structure of the malware campaign is pretty static, with several exceptions where they also take advange of client-side vulnerabilities (Real player exploit) attempting to automatically deliver the fake flash update or player depending on the campaign. On each and every site, there are <b>dnd.js</b> and <b>master.js</b> scripts shich serve the rogue download window, and another .html file, where an IFRAME attempts to access the traffic management command and control, in a random URL it was <b>207.10.234.217/cgi-bin/index.cgi?user200</b>. A sample list of participating URLs, most of which are still active and running :<br />
<br />
<div style="text-align: left;"><b>joseantoniobaltanas .com</b></div><b>automoviliaria .es/hotnews.html<br />
risasnc .it/fresh.html<br />
carpe-diem .com.mx/fresh.html<br />
kotilogullari .com.tr/hotnews.html<br />
ferrariclubpesaro .it/hotnews.html<br />
imobiliariacom .com.br/default.html<br />
misoares .com<br />
osniehus .de/fresh.html<br />
mydirecttube .com/1/5098/<br />
madosma .com/default.html<br />
tutotic .com/checkit.html<br />
veit-team .si/default.html<br />
antigewaltkurse .de/stream.html<br />
kwhgs .ca/topnews.html<br />
vorgo .com/stream.html<br />
ankaraspor .com.tr/default.html<br />
xxxdnn0314 .locaweb.com.br/watchit.html<br />
ossuzio .com/watchit.html<br />
cit-inc .net/default.html<br />
negocioindependiente .biz/default.html<br />
ambermarketing .com/topnews.html<br />
web27 .login-7.loginserver.ch/stream.html<br />
moretewebdesign .br-web.com/stream.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/hotnews.html<br />
campodifiori .it/topnews.html<br />
212.50.55.81 /stream.html<br />
logisigns .net/fresh.html<br />
intimaescorts .com/default.html<br />
ghioautotre .it/live.html<br />
geckert .de/stream.html<br />
yuricardinali .com/watchit.html<br />
retder .com/fresh.html<br />
valdaran .es/default.html<br />
getadultaccess .com/movie/?aff=5274<br />
bauelemente-giering .de/stream.html<br />
newyork-hebergement .com/watchit.html<br />
allevatoritrotto .it/live.html<br />
exoss2 .com/hotnews.html<br />
soundandlightkaraoke .com/stream.html<br />
land-kan .com/stream.html<br />
grimaldi.nexenservices .com/watchit.html<br />
inconstancia .com.br/watchit.html <br />
gretelstudio .com/stream.html<br />
sumacyl .com/watchit.html<br />
mysna .net/fresh.html<br />
gimnasioyx .com.ar/watchit.html<br />
lagalbana .com/watchit.html<br />
bielizna.tgory .pl/topnews.html<br />
bcs92.imingo .net/stream.html<br />
lapiramidecoslada .es/topnews.html<br />
raulortega .com/stream.html<br />
go-art-morelli .de/hotnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
dianagraf .es/default.html<br />
komma10-thueringen .de/hotnews.html<br />
miavassilev .com/stream.html<br />
swampgiants .com/watchit.html<br />
compagniedephalsbourg .com/fresh.html<br />
arla-rc .net/hotnews.html<br />
salacopernico .es/watchit.html<br />
drfinster .de/checkit.html<br />
healthylifehypnotherapy .com/stream.html<br />
ecotrike-bg .com/fresh.html<br />
paoepalavra .org/watchit.html<br />
jureplaninc-sp .com/topnews.html<br />
fichte-lintfort .de/default.html<br />
hergert-band .de/checkit.html<br />
izliyorum .org/topnews.html<br />
lideka .com/stream.html<br />
athena-digitaldesign .com.tw/hotnews.html<br />
e-paso .pl/stream.html<br />
colombeblanche .org/stream.html<br />
teatromalasa .es/watchit.html<br />
mesporte.digiweb.com .br/stream.html<br />
bistrodavila.com .br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
jbhumet .com/default.html<br />
gruppouni .com/hotnews.html<br />
francex .net/fresh.html<br />
galvatoledo .com/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
kroenert .name/default.html<br />
textilhogarnovadecor .com/topnews.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
neticon .pl/hotnews.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
easterstreet .de/fresh.html<br />
piogiovannini .com.ar/watchit.html<br />
ser-all .com/topnews.html<br />
petzold-dieter .de/checkit.html<br />
beatmung-brandenburg .de/checkit.html<br />
ossuzio .com/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
zelenaratolest .cz/pornotube/index1.htm<br />
ambulatoriovirtuale .it/topnews.html<br />
10a3 .ru/index1.php<br />
izliyorum .org/topnews.html<br />
collectedthoughts .co.uk/index12.html<br />
afg .es/topnews.html<br />
albertruiz .net/topnews.html<br />
bielizna.tgory .pl/topnews.html<br />
blueseven.com .br/topnews.html<br />
bollettinogiuridicosanitario .it/topnews.html<br />
caprilchamonix.com .br/topnews.html<br />
carlolongarini .it/topnews.html<br />
champimousse .com/topnews.html<br />
cheviot.org .nz/topnews.html<br />
contrapie .com/topnews.html<br />
gruppouni .com/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
herbatele .com/topnews.html<br />
houseincostaricaforsale .com/topnews.html<br />
alim.co .il/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
amafe .org/topnews.html<br />
ambulatoriovirtuale .it/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
automoviliaria .es/topnews.html<br />
autoreserve .fr/topnews.html<br />
izliyorum .org/topnews.html<br />
jureplaninc-sp .com/topnews.html<br />
kwhgs .ca/topnews.html<br />
lapiramidecoslada .es/topnews.html<br />
last-minute-reisen-4u .de/topnews.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
corradiproject .info/topnews.html<br />
dantealighieriasturias .es/topnews.html<br />
deliriuslaspalmas .com/topnews.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/topnews.html<br />
fonavistas .com/topnews.html<br />
fraemma .com/topnews.html<br />
fundmyira .com/topnews.html<br />
galvatoledo .com/topnews.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
markmaverick .com/topnews.html<br />
micela .info/topnews.html<br />
motoclubnosvamos .com/topnews.html<br />
nebottorrella .com/topnews.html<br />
negozistore .it/topnews.html<br />
neticon .pl/topnews.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
segelclub-honau .de/topnews.html<br />
snmobilya .com/topnews.html<br />
splashcor .com.br/topnews.html<br />
stephanmager .gmxhome.de/topnews.html<br />
svcanvas .com/topnews.html<br />
tautau.web .simplesnet.pt/topnews.html<br />
textilhogarnovadecor .com/topnews.html<br />
theflorist4u .com/topnews.html<br />
thewindsorhotel .it/topnews.html<br />
vuelosultimahora .com/topnews.html<br />
aliarzani .de/topnews.html<br />
ambermarketing .com/topnews.html<br />
arnold82.gmxhome .de/topnews.html<br />
ocoartefatos.com .br/topnews.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
projetsoft .net/topnews.html<br />
rbc.gmxhome .de/topnews.html<br />
beatmung-sachsen .eu/topnews.html<br />
campodifiori .it/topnews.html<br />
clickjava .net/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
dammer .info/topnews.html<br />
embedded-silicon .de/topnews.html<br />
ferrariclubpesaro .it/topnews.html<br />
fgwiese .de/topnews.html<br />
fswash.site .br.com/topnews.html<br />
fytema .es/topnews.html<br />
gildas-saliou. com/topnews.html<br />
go-art-morelli .de/topnews.html<br />
go-siegmund .de/topnews.html<br />
guerrero-tuning .com/topnews.html<br />
gut-barbarastein .de/topnews.html<br />
japansec .com/topnews.html<br />
komma10-thueringen .de/topnews.html<br />
koon-design .de/topnews.html<br />
lanz-volldiesel .de/topnews.html<br />
lauscher-staat .de/topnews.html<br />
losnaranjos.com .es/topnews.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
nepi.si/topnews .html<br />
radieschenhein. de/topnews.html<br />
residenceflora .it/topnews.html<br />
sabuha .de/topnews.html<br />
ser-all .com/topnews.html<br />
siemieniewicz .de/topnews.html<br />
viajesk .es/topnews.html<br />
allevatoritrotto .it/live.html<br />
bollettinogiuridicosanitario .it/live.html<br />
carlolongarini .it/topnews.html<br />
maremax .it/topnews.html<br />
negozistore .it/topnews.html<br />
parapendiolestreghe .it/live.html<br />
www.donlisander .it/stream.html<br />
aerogenesis .net/watchit.html<br />
allevatoritrotto .it/live.html<br />
atelier-de-loulou .fr/topnews.html<br />
bistrodavila.com .br/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
caprilchamonix.com .br/topnews.html<br />
cheviot.org .nz/live.html<br />
condorautocenter .com.br/watchit.html<br />
dantealighieriasturias .es/live.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/live.html<br />
fonavistas .com/topnews.html<br />
fundmyira .com/topnews.html<br />
g6esporte .com.br/stream.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
gretelstudio .com/stream.html<br />
gutierrezymoralo .com/watchit.html<br />
healthylifehypnotherapy .com/stream.html<br />
herbatele .com/live.html<br />
jureplaninc-sp .com/topnews.html<br />
lacomercialsrl .com.ar/stream.html<br />
lagalbana .com/watchit.html<br />
lapuertaestrecha .com.es/watchit.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
myadultcube .com/flash//aff=5176<br />
myadultcube .com/flash//aff=5810<br />
myadultcube .com/movie//aff=5155<br />
newyork-hebergement .com/watchit.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
omdconsulting .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
parapendiolestreghe .it/live.html<br />
regesh. co.il/watchit.html<br />
rikkeroenneberg .dk/watchit.html<br />
s215847279 .onlinehome.fr/stream.html<br />
salacopernico .es/watchit.html<br />
seekzones .com/watchit.html<br />
seicomsl .es/watchit.html<br />
sigma-lux .ro/watchit.html<br />
soundandlightkaraoke .com/stream.html<br />
stephanmager.gmxhome .de/topnews.html<br />
tartuinstituut .ca/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
aliarzani .de/topnews.html<br />
ambermarketing. com/live.html<br />
bilbondo .com/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
colombeblanche .org/stream.html<br />
donlisander .it/stream.html<br />
fgwiese .de/topnews.html<br />
geckert .de/stream.html<br />
helene-taucher .de/watchit.html<br />
lanz-volldiesel .de/topnews.html<br />
mairie-margnylescompiegne .fr/watchit.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
ossuzio .com/watchit.html<br />
piogiovannini .com.ar/watchit.html<br />
sabuha .de/topnews.html<br />
sumacyl .com/watchit.html<br />
swampgiants .com/watchit.html<br />
xn--glland-3ya .de/stream.html<br />
yuricardinali .com/watchit.html</b><br />
<b>nepi .si/topnews.html<br />
dammer .info/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
galvatoledo .com/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
micela .info/topnews.html<br />
bistrodavila .com.br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
gruppouni .com/hotnews.html<br />
galvatoledo .com/topnews.html<br />
kroenert .name/default.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
dantealighieriasturias .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
89.19.29 .13/stream.html<br />
slobodandjakovic .com/fresh.html<br />
cqcs.com .br/stream.html<br />
seekzones .com/watchit.html<br />
pascosa .it/stream.html<br />
caprilchamonix .com.br/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
ferien-urlaub-lastminute .de/default.html<br />
mueggelpark .info/watchit.html<br />
hillner-online .de/fresh.html<br />
guiasaojose .net/default.html<br />
deliriuslaspalmas .com/topnews.html<br />
fraemma .com/topnews.html<br />
morsbaby .net/default.html<br />
vickywhite .com/fresh.html<br />
micela .info/topnews.html<br />
corradiproject .info/topnews.html<br />
liguehavraise .com/live.html<br />
capacitacaoemlideranca .com.br/fresh.html<br />
materialesyacabados .com.mx/stream.html<br />
208.112.7.68 /checkit.html<br />
152.10.1.37 /1.html<br />
carlolongarini .it/topnews.html<br />
splashcor.com .br/topnews.html<br />
lobpreisstrasse .org/1.html<br />
motoclubnosvamos .com/hotnews.html<br />
hk-rc.com /1.html<br />
taaf.re /stream.html<br />
dulceysalao .com/default.html<br />
amafe .org/topnews.html <br />
</b><br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/MTxnF1XLDCw/s1600-h/fake_flash3_rogue_software.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/3Dgh4x23dRs/s200-R/fake_flash3_rogue_software.png" style="border: 0pt none ;" /></a>Sample detection rate : <span id="status_nombre">flashupdate.exe</span><br />
<span id="status_nombre"><b>Scanners Result</b>: 35/36 (97.23%)</span><br />
<span id="status_nombre">Trojan-Downloader.Win32.Exchanger.hk; Troj/Cbeplay-A</span><br />
<b>File size</b>: 78848 bytes<br />
<b>MD5</b>...: c81b29a3662b6083e3590939b6793bb8<br />
<b>SHA1</b>..: d513275c276840cb528ce11dd228eae46a74b4b4<br />
<br />
The downloader then "phones back home" at <b>72.9.98.234 port 443 </b>which is responding to the rogue security software AntiSpy Spider (<b>antispyspider.net</b>) :<br />
<br />
"<i>AntiSpy Spider is a cutting-edge anti-spyware solution.This revolutionary anti-spyware program was created by the industry's top spyware experts in order to protect your computer and your privacy.html, while ensuring optimal system performance.With the ability to locate, eliminate and prevent the widest range of spyware threats, AntispyStorm is able to offer its users a safe, spyware-free computing experience; and with it's convenient automatic update feature, AntispyStorm ensures continuous up-to-date protection.</i>" <br />
<br />
Sample detection rate : antispyspider.msi<br />
<b>Scanners Result</b>: 11/35 (31.43%)<br />
FraudTool.Win32.AntiSpySpider.b;&nbsp; <br />
<b>File size</b>: 1851904 bytes<br />
<b>MD5</b>...: 2f1389e445f65e8a9c1a648b42a23827<br />
<b>SHA1</b>..: e32aa6aa791e98fe6fdef451bd3b8a45bad0acd8<br />
<br />
The bottom line - over a thousand domains are participating, with many other apparently joining the party proportionally with the web site owner's actions to get rid of the malware campaign hosted on their servers.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BvcTqK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BvcTqK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=onawHK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=onawHK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4fa1ek"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4fa1ek" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5nQAgk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5nQAgk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sqdHIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sqdHIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mq3LKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mq3LKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8zplkk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8zplkk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/356677080" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 10:50:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/html file">html file</category>
      <category domain="http://securityratty.com/tag/html">html</category>
      <category domain="http://securityratty.com/tag/comtopnews">comtopnews</category>
      <category domain="http://securityratty.com/tag/detopnews">detopnews</category>
      <category domain="http://securityratty.com/tag/windows media player">windows media player</category>
      <category domain="http://securityratty.com/tag/player">player</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/real player exploit">real player exploit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/356677080/compromised-web-servers-serving-fake.html">Compromised Web Servers Serving Fake Flash Players</source>
    </item>
    <item>
      <title><![CDATA[Coming Soon to a Movie Plot Near You]]></title>
      <link>http://securityratty.com/article/cb190ec3098a190d9aa05cdd5aa4e139</link>
      <guid>http://securityratty.com/article/cb190ec3098a190d9aa05cdd5aa4e139</guid>
      <description><![CDATA[The problem with most video surveillance is that it is not actively monitored. It is recorded so that events can be reconstructed at a later date. While this may prove to be an effective deterrent in...]]></description>
      <content:encoded><![CDATA[<p><a href="http://artofinfosec.com/wp-content/uploads/william_lamson_security_camera_hack.jpg" ><img class="size-medium wp-image-81 alignright" style="margin: 25px;" title="william_lamson_security_camera_hack" src="http://artofinfosec.com/wp-content/uploads/william_lamson_security_camera_hack-207x300.jpg" alt="" width="207" height="300" /></a>The problem with most video surveillance is that it is not actively monitored. It is recorded so that events can be reconstructed at a later date. While this may prove to be an effective deterrent in many situations, this does limit the effectiveness (and the cost of operation) of the surveillance system.</p>
<p>Of course, a major problem with that approach is that the &#8220;persons of interest&#8221; are long gone by the time the video shows that &#8220;yep, you can defiantly see some guy cutting off that lock and stealing that&#8230;&#8221;.</p>
<p>Another problem is that unless the equipment is being checked on a regular basis, it may be defeated (or just broken) for a long time before any problems are identified.</p>
<p>In the photo to the right, a <a href="http://http://www.williamlamson.com/#/work/intervention/works/1" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://http://www.williamlamson.com/#/work/intervention/works/1');" target="_blank">NYC artist  William Lamson</a>, has created an interesting photo of hacking (or blocking) a security camera with a helium balloon. This is such a simple and inexpensive attack on the video surveillance camera that I am shocked I haven&#8217;t seen this before. I am also certain that the appearance of this in a  TV or movie plot is imminent. It would have been pretty simple to use two balloons to block the camera without providing the nice tether to &#8220;fix&#8221; the problem.</p>
<p>Digital photography is a hobby of mine, and I have a mild obsession for photographing physical security faux pas (which to date has not resulted in any &#8216;Imperial Entanglements&#8217; <img src='http://artofinfosec.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> ). So I am going to use Mr. Lamson&#8217;s photo to kick off a new category (and series) on Art of Information Security, called &#8220;Security faux pas&#8221; - stay tuned&#8230;</p>
<p>Cheers, Erik</p>
<p></p>
<p><a href="http://artofinfosec.com/80/coming-soon-to-a-movie-plot-near-you/" >Coming Soon to a Movie Plot Near You&#8230;</a></p>
<img src="http://feeds.feedburner.com/~r/artofinfosec/~4/351945868" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 17:10:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/video surveillance camera">video surveillance camera</category>
      <category domain="http://securityratty.com/tag/camera">camera</category>
      <category domain="http://securityratty.com/tag/video surveillance">video surveillance</category>
      <category domain="http://securityratty.com/tag/movie plot">movie plot</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/photo">photo</category>
      <category domain="http://securityratty.com/tag/lamsons photo">lamsons photo</category>
      <category domain="http://securityratty.com/tag/security camera">security camera</category>
      <category domain="http://securityratty.com/tag/simple">simple</category>
      <source url="http://feeds.feedburner.com/~r/artofinfosec/~3/351945868/">Coming Soon to a Movie Plot Near You</source>
    </item>
    <item>
      <title><![CDATA[dont download DOM-x Media Player]]></title>
      <link>http://securityratty.com/article/1ff6e2512ec9fd8beb5b02a879518cb0</link>
      <guid>http://securityratty.com/article/1ff6e2512ec9fd8beb5b02a879518cb0</guid>
      <description><![CDATA[Good advice over at WebToolsandTips.com


clipped from webtoolsandtips.com
DOM-x Media Player - Dont Download this Malware


If you are not aware, DOM-x Player is a one of the many Rogue Malware...]]></description>
      <content:encoded><![CDATA[<div > Good advice over at WebToolsandTips.com<br/> </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/D7246833-D3C9-4E83-9BAF-FECC2032FD30/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/720fabf2-71f7-459f-b10a-86542815c327/D7246833-D3C9-4E83-9BAF-FECC2032FD30/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://webtoolsandtips.com/pc-security/malware/dom-player-malware-dont-search-for-it/" href="http://webtoolsandtips.com/pc-security/malware/dom-player-malware-dont-search-for-it/" style="font-size: 11px;">webtoolsandtips.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://webtoolsandtips.com/pc-security/malware/dom-player-malware-dont-search-for-it/ --><H2><A rel="bookmark" href="http://webtoolsandtips.com/pc-security/malware/dom-player-malware-dont-search-for-it/" title="Permanent Link to DOM-x Media Player - Don’t Download this Malware">DOM-x Media Player - Don’t Download this Malware</A></H2></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://webtoolsandtips.com/pc-security/malware/dom-player-malware-dont-search-for-it/ --><P>If you are not aware, DOM-x Player is a one of the many Rogue Malware programs, which are infecting more and more PCs nowadays. The mechanism of DOM-x Player installation is easy. It is generally spread through the various online file sharing sites like Rapidshare and various Torrent sites like BitTorrent. People who want to make a quick buck disguise a rogue file as a movie file. When you download it and try to run it, this gives you a link and asks you to download DOM-x Media Player. If you get into this trap to download and install DOM-x Media Player, then you may be in trouble.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/D7246833-D3C9-4E83-9BAF-FECC2032FD30/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 19:30:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dom-x media player">dom-x media player</category>
      <category domain="http://securityratty.com/tag/download">download</category>
      <category domain="http://securityratty.com/tag/dom-x player">dom-x player</category>
      <category domain="http://securityratty.com/tag/dom-x player installation">dom-x player installation</category>
      <category domain="http://securityratty.com/tag/rogue malware programs">rogue malware programs</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/torrent sites">torrent sites</category>
      <category domain="http://securityratty.com/tag/quick buck disguise">quick buck disguise</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=525">dont download DOM-x Media Player</source>
    </item>
    <item>
      <title><![CDATA[Meru Networks erects a "cone of silence"]]></title>
      <link>http://securityratty.com/article/2b9b51efaeb059be63332e84e9b51781</link>
      <guid>http://securityratty.com/article/2b9b51efaeb059be63332e84e9b51781</guid>
      <description><![CDATA[Who doesn't remember the cone of silence from the original Get Smart TV series. Whenever Max and the Chief had something important to discuss they would lower the cone of silence so that no one else...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><a onclick="window.open(this.href, '_blank', 'width=376,height=261,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://www.stillsecureafteralltheseyears.com/.shared/image.html?/photos/uncategorized/2008/07/30/coneofsilence.jpg"><img title="Coneofsilence" height="173" alt="Coneofsilence" src="http://www.stillsecureafteralltheseyears.com/ashimmy/images/2008/07/30/coneofsilence.jpg" width="249" border="0" style="FLOAT: right; MARGIN: 0px 0px 5px 5px" /></a> Who doesn't remember <a class="zem_slink" title="Cone of Silence" href="http://en.wikipedia.org/wiki/Cone_of_Silence" rel="wikipedia">the cone of silence</a> from the original Get Smart TV series.&nbsp; Whenever Max and the Chief had something important to discuss they would lower the cone of silence so that no one else could hear them or eavesdrop. So it is only fitting with the recent release of the <a class="zem_slink" title="Get Smart (film)" href="http://getsmartmovie.warnerbros.com/" rel="homepage">Get Smart movie</a>, <a href="http://news.zdnet.co.uk/communications/0,1000000085,39453788,00.htm">Meru Networks has released a wireless cone of silence</a>. </p>

<p>Meru is one of few stand alone wireless companies still hanging on out there.&nbsp; So they need to be innovative to survive.&nbsp; Their latest product, RF Barrier puts antennas around a physical plant to dampen and make it impossible to to listen in on wireless data exchanges.&nbsp; They claim this is a first of its kind.&nbsp; Thinking about it though, I don't see a big barrier to other companies having similar technology. I don't think you have to be a genius to broadcast traffic that puts out &quot;noise&quot; to hide legit traffic. I think the real special sauce is that this works in conjunction with Meru's other security products like wireless firewalls and secure access points.</p>

<p>With Motorola's recent purchase of AirDefense is having wireless IPS soon going to be table stakes in the wireless provider game?&nbsp; I think it is and while Meru's RF barrier is a nice story, they are going to need to have some sort of IDS/IPS in their product line to keep up.</p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://www.itweek.co.uk/itweek/news/2222765/motorola-acquire-airdefense">Motorola to acquire AirDefense</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.itweek.co.uk/itweek/news/2222643/meru-locks-car-park-hackers">Meru locks out car park hackers</a></li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/5a77977d-6e3b-40f2-b9f2-737ba115b05b/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=5a77977d-6e3b-40f2-b9f2-737ba115b05b" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 04:05:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/meru">meru</category>
      <category domain="http://securityratty.com/tag/meru networks">meru networks</category>
      <category domain="http://securityratty.com/tag/cone">cone</category>
      <category domain="http://securityratty.com/tag/silence">silence</category>
      <category domain="http://securityratty.com/tag/meru locks">meru locks</category>
      <category domain="http://securityratty.com/tag/wireless cone">wireless cone</category>
      <category domain="http://securityratty.com/tag/product line">product line</category>
      <category domain="http://securityratty.com/tag/hide legit traffic">hide legit traffic</category>
      <category domain="http://securityratty.com/tag/wireless provider game">wireless provider game</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/meru-networks-e.html">Meru Networks erects a "cone of silence"</source>
    </item>
    <item>
      <title><![CDATA[Meru Networks erects a "cone of silence"]]></title>
      <link>http://securityratty.com/article/b76f30b52c9fc47905da9e8e714fa2b2</link>
      <guid>http://securityratty.com/article/b76f30b52c9fc47905da9e8e714fa2b2</guid>
      <description><![CDATA[Who doesn't remember the cone of silence from the original Get Smart TV series. Whenever Max and the Chief had something important to discuss they would lower the cone of silence so that no one else...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><a onclick="window.open(this.href, '_blank', 'width=376,height=261,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://www.stillsecureafteralltheseyears.com/.shared/image.html?/photos/uncategorized/2008/07/30/coneofsilence.jpg"><img title="Coneofsilence" height="173" alt="Coneofsilence" src="http://www.stillsecureafteralltheseyears.com/ashimmy/images/2008/07/30/coneofsilence.jpg" width="249" border="0" style="FLOAT: right; MARGIN: 0px 0px 5px 5px" /></a> Who doesn't remember <a class="zem_slink" title="Cone of Silence" href="http://en.wikipedia.org/wiki/Cone_of_Silence" rel="wikipedia">the cone of silence</a> from the original Get Smart TV series.&nbsp; Whenever Max and the Chief had something important to discuss they would lower the cone of silence so that no one else could hear them or eavesdrop. So it is only fitting with the recent release of the <a class="zem_slink" title="Get Smart (film)" href="http://getsmartmovie.warnerbros.com/" rel="homepage">Get Smart movie</a>, <a href="http://news.zdnet.co.uk/communications/0,1000000085,39453788,00.htm">Meru Networks has released a wireless cone of silence</a>. </p>

<p>Meru is one of few stand alone wireless companies still hanging on out there.&nbsp; So they need to be innovative to survive.&nbsp; Their latest product, RF Barrier puts antennas around a physical plant to dampen and make it impossible to to listen in on wireless data exchanges.&nbsp; They claim this is a first of its kind.&nbsp; Thinking about it though, I don't see a big barrier to other companies having similar technology. I don't think you have to be a genius to broadcast traffic that puts out &quot;noise&quot; to hide legit traffic. I think the real special sauce is that this works in conjunction with Meru's other security products like wireless firewalls and secure access points.</p>

<p>With Motorola's recent purchase of AirDefense is having wireless IPS soon going to be table stakes in the wireless provider game?&nbsp; I think it is and while Meru's RF barrier is a nice story, they are going to need to have some sort of IDS/IPS in their product line to keep up.</p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://www.itweek.co.uk/itweek/news/2222765/motorola-acquire-airdefense">Motorola to acquire AirDefense</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.itweek.co.uk/itweek/news/2222643/meru-locks-car-park-hackers">Meru locks out car park hackers</a></li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/06efb3dd-b510-48f6-9ae4-02c84dfa1733/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=06efb3dd-b510-48f6-9ae4-02c84dfa1733" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=SgUnLX"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=SgUnLX" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=wTWkpJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=wTWkpJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=lUKurJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=lUKurJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=dT8cBJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=dT8cBJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=FZVwRJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=FZVwRJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=D6AdHj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=D6AdHj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ZLCydj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ZLCydj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/350429290" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 03:05:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/meru">meru</category>
      <category domain="http://securityratty.com/tag/meru networks">meru networks</category>
      <category domain="http://securityratty.com/tag/cone">cone</category>
      <category domain="http://securityratty.com/tag/silence">silence</category>
      <category domain="http://securityratty.com/tag/meru locks">meru locks</category>
      <category domain="http://securityratty.com/tag/wireless cone">wireless cone</category>
      <category domain="http://securityratty.com/tag/product line">product line</category>
      <category domain="http://securityratty.com/tag/hide legit traffic">hide legit traffic</category>
      <category domain="http://securityratty.com/tag/wireless provider game">wireless provider game</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/350429290/meru-networks-e.html">Meru Networks erects a "cone of silence"</source>
    </item>
  </channel>
</rss>
