<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: movie-plot]]></title>
    <link>http://securityratty.com/tag/movie-plot</link>
    <description></description>
    <pubDate>Wed, 13 Aug 2008 14:49:36 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Type II Reverse Engineering]]></title>
      <link>http://securityratty.com/article/9884f2c366b5ecac07330be322cdd122</link>
      <guid>http://securityratty.com/article/9884f2c366b5ecac07330be322cdd122</guid>
      <description><![CDATA[There's reverse engineering to understand, and then there's reverse engineering to copy. Counterfeiting is a very old human temptation, but it is keeping up with the digital world very well indeed....]]></description>
      <content:encoded><![CDATA[There's reverse engineering to understand, and then there's reverse engineering to copy. Counterfeiting is a very old human temptation, but it is keeping up with the digital world very well indeed. Putting aside ordinary movie piracy, we thought that for this issue we'd just compare some counterfeiting metrics, old and new. Putting the punchline right up front, counterfeiting matters in information technology (IT)—and IT might soon be where counterfeiting matters most.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=7d873897bcb39b16222116abf0eb6acd" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=7d873897bcb39b16222116abf0eb6acd" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:42:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/reverse">reverse</category>
      <category domain="http://securityratty.com/tag/ordinary movie piracy">ordinary movie piracy</category>
      <category domain="http://securityratty.com/tag/matters">matters</category>
      <category domain="http://securityratty.com/tag/digital world">digital world</category>
      <category domain="http://securityratty.com/tag/human temptation">human temptation</category>
      <category domain="http://securityratty.com/tag/information technology">information technology</category>
      <category domain="http://securityratty.com/tag/compare">compare</category>
      <category domain="http://securityratty.com/tag/punchline">punchline</category>
      <category domain="http://securityratty.com/tag/front">front</category>
      <source url="http://www.pheedo.com/click.phdo?i=7d873897bcb39b16222116abf0eb6acd">Type II Reverse Engineering</source>
    </item>
    <item>
      <title><![CDATA[Amazon plugs hole in free-movie offerings]]></title>
      <link>http://securityratty.com/article/1526ea57732025eda2a6314d9ce21ad4</link>
      <guid>http://securityratty.com/article/1526ea57732025eda2a6314d9ce21ad4</guid>
      <description><![CDATA[Adobe Systems is disputing reports that flaws in its Flash server software let pirates grab movies and TV shows streamed from Amazon.com's new Video On Demand...]]></description>
      <content:encoded><![CDATA[Adobe Systems is disputing reports that flaws in its Flash server software let pirates grab movies and TV shows streamed from Amazon.com's new Video On Demand service.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:979183d01cfdc42e1cda0acfed98285c:T7qCPjMUKlkZA17n91OhrxXzaKfYOXe5gwicE5o3dva7MdFPV026oo0WdwIbvu%2FkVEiN6YpAe9Uk'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c9294c3e4d5ca9b4ad615ee5b1021113:G8d8kBZlTupQeyN9eS%2B39WSUED2cuDYIZaWRutL3PSiiPj1e691lH2ENHJrAJ6qMw9spNQRy7x29kA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:9c4b0c1df693bc44169842b378108668:7KMG5ZoQGOjAkg9a2fbwRNTj7L33oaMwSbf9PXHSLUWzhhsuUClty5e8x99JMzjOA9%2BslJ4stttZNA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:abc50572e0dbf4cf05d01da4a027b298:T3deGM708NDvXia%2BM26%2BwjMayLubS1u7S4h2toewHxwWF%2FVqxFXyviKihj7%2BrRmkVqDC2SKcq3mJBQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=4db04969c5fc24e589b496af8e6d4ce7" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=4db04969c5fc24e589b496af8e6d4ce7" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flash server software">flash server software</category>
      <category domain="http://securityratty.com/tag/grab movies">grab movies</category>
      <category domain="http://securityratty.com/tag/demand service">demand service</category>
      <category domain="http://securityratty.com/tag/adobe systems">adobe systems</category>
      <category domain="http://securityratty.com/tag/amazon">amazon</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/flaws">flaws</category>
      <category domain="http://securityratty.com/tag/reports">reports</category>
      <category domain="http://securityratty.com/tag/tv">tv</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=4db04969c5fc24e589b496af8e6d4ce7">Amazon plugs hole in free-movie offerings</source>
    </item>
    <item>
      <title><![CDATA[Hole in Adobe software allows free movie downloads ]]></title>
      <link>http://securityratty.com/article/2b98216ff0e66746f89b19ec6be7805c</link>
      <guid>http://securityratty.com/article/2b98216ff0e66746f89b19ec6be7805c</guid>
      <description><![CDATA[A security hole in Adobe Systems Inc software, used to distribute movies and TV shows over the Internet, is giving users free access to record and copy from Amazon.com Inc's video streaming...]]></description>
      <content:encoded><![CDATA[A security hole in Adobe Systems Inc software, used to distribute movies and TV shows over the Internet, is giving users free access to record and copy from Amazon.com Inc's video streaming service.]]></content:encoded>
      <pubDate>Sat, 27 Sep 2008 14:10:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/users free access">users free access</category>
      <category domain="http://securityratty.com/tag/distribute movies">distribute movies</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/adobe systems">adobe systems</category>
      <category domain="http://securityratty.com/tag/security hole">security hole</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/copy">copy</category>
      <source url="http://digg.com/security/Hole_in_Adobe_software_allows_free_movie_downloads_3">Hole in Adobe software allows free movie downloads </source>
    </item>
    <item>
      <title><![CDATA[Adobe Software Flaw Allows Free Movie Downloads]]></title>
      <link>http://securityratty.com/article/df568481dc580e4e180e14c9baaa5fde</link>
      <guid>http://securityratty.com/article/df568481dc580e4e180e14c9baaa5fde</guid>
      <description><![CDATA[A security hole in Adobe Systems Inc software, used to distribute movies and TV shows over the Internet, is giving users free access to record and copy from Amazon.com Incs video streaming service....]]></description>
      <content:encoded><![CDATA[A security hole in Adobe Systems Inc software, used to distribute movies and TV shows over the Internet, is giving users free access to record and copy from Amazon.com Inc&#8217;s video streaming service. The flaw rests in Adobe&#8217;s Flash video servers that are connected to the company&#8217;s players installed in nearly all of the world&#8217;s [...]]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 20:58:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/users free access">users free access</category>
      <category domain="http://securityratty.com/tag/flaw rests">flaw rests</category>
      <category domain="http://securityratty.com/tag/distribute movies">distribute movies</category>
      <category domain="http://securityratty.com/tag/companys players">companys players</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/incs video">incs video</category>
      <category domain="http://securityratty.com/tag/adobe systems">adobe systems</category>
      <category domain="http://securityratty.com/tag/security hole">security hole</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <source url="http://cyberinsecure.com/adobe-software-flaw-allows-free-movie-downloads/">Adobe Software Flaw Allows Free Movie Downloads</source>
    </item>
    <item>
      <title><![CDATA[Video: Solar Sunrise, the Best FBI-Produced Hacker Flick Ever]]></title>
      <link>http://securityratty.com/article/b257db146426c2603b2608bc49f730e1</link>
      <guid>http://securityratty.com/article/b257db146426c2603b2608bc49f730e1</guid>
      <description><![CDATA[With Ehud &quot;The Analyzer&quot; Tenenbaum back in legal hot water, we've dug up the old FBI training video Solar Sunrise: Dawn of a New Threat dramatizing his 1998 hack attacks against the Pentagon. It's not...]]></description>
      <content:encoded><![CDATA[With Ehud "The Analyzer" Tenenbaum back in legal hot water, we've dug up the old FBI training video Solar Sunrise: Dawn of a New Threat dramatizing his 1998 hack attacks against the Pentagon. It's not the most exciting movie in history, but it still beats Die Hard 4.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=36fb816901008a69e5ef3ac51676079b" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=36fb816901008a69e5ef3ac51676079b" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=UhnRL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=UhnRL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Xmhxl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Xmhxl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=8loal"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=8loal" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=lMfML"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=lMfML" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=oP6bL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=oP6bL" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=VOP3l"><img src="http://feeds.wired.com/~f/wired/politics/security?i=VOP3l" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=USvOl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=USvOl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=UJH8L"><img src="http://feeds.wired.com/~f/wired/politics/security?i=UJH8L" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/401064241" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/401064256" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 14:20:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/video solar sunrise">video solar sunrise</category>
      <category domain="http://securityratty.com/tag/beats die hard">beats die hard</category>
      <category domain="http://securityratty.com/tag/legal hot water">legal hot water</category>
      <category domain="http://securityratty.com/tag/fbi">fbi</category>
      <category domain="http://securityratty.com/tag/hack attacks">hack attacks</category>
      <category domain="http://securityratty.com/tag/pentagon">pentagon</category>
      <category domain="http://securityratty.com/tag/dawn">dawn</category>
      <category domain="http://securityratty.com/tag/history">history</category>
      <category domain="http://securityratty.com/tag/threat">threat</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/401064256/video-solar-sun.html">Video: Solar Sunrise, the Best FBI-Produced Hacker Flick Ever</source>
    </item>
    <item>
      <title><![CDATA[Holy Media Codecs, Batman!]]></title>
      <link>http://securityratty.com/article/3d984264f929456ea8e4f274d55394ef</link>
      <guid>http://securityratty.com/article/3d984264f929456ea8e4f274d55394ef</guid>
      <description><![CDATA[Batman is still in full swing at the box office - I'm sure me seeing it seven times probably didn't hurt - so with that in mind (and thoughts of the Zango / Dark Knight issue still rattling around my...]]></description>
      <content:encoded><![CDATA[
        Batman is still in full swing at the box office - I'm sure me seeing it seven times probably didn't hurt - so with that in mind (and thoughts of the <a href="http://www.theregister.co.uk/2008/08/18/dark_knight_zango_affiliate_gateway/">Zango / Dark Knight issue</a> still rattling around my brain) I thought it would be fun to see exactly how quickly it can all go wrong when looking for Dark Knight material online.<br /><br />The answer is: extremely quickly.<br /><br />There's a lot of sites out there claiming to carry "full versions" of The Dark Knight, and although they don't offer Zango, they <i>do</i> offer fake media codecs (which usually do all sorts of horrible things to a computer). Let's pull one of these sites apart as an example of how the scam fits together.<br /><br />Here's a typical site pushing what they claim to be The Dark Knight:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman000.html" onclick="window.open('http://blog.spywareguide.com/images/dbman000.html','popup','width=717,height=564,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman000-thumb-317x249.jpg" alt="dbman000.jpg" class="mt-image-none" style="" height="249" width="317" /></a></span><br />Click to Enlarge<br /></div><br />Dijgg(dot)com, an obvious Digg.com knockoff apparently hosting a large streaming window - the movie quality will be awesome, won't it? Well, actually, no it won't.<br /><br />In the middle of the video window is a popup:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman0.jpg" src="http://blog.spywareguide.com/images/dbman0.jpg" class="mt-image-none" style="" height="145" width="399" /></span></div><br /><br /> <div>Install the "codec", and this won't end well. The EXE comes from a site called Favoritetube(dot)com:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman1.jpg" src="http://blog.spywareguide.com/images/dbman1.jpg" class="mt-image-none" style="" height="203" width="348" /></span></div><br /><br />A quick check for the <a href="http://www.siteadvisor.com/sites/favoritetube.net/postid?p=1063293">safety</a> <a href="http://safeweb.norton.com/report/show?name=favoritetube.net">ratings</a> of that website should be enough to tell you this is a scam. Indeed, there isn't even a movie being streamed here (despite it saying "Connecting" at the bottom of the movie player) - because if you right click on the player itself:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman0000.jpg" src="http://blog.spywareguide.com/images/dbman0000.jpg" class="mt-image-none" style="" height="370" width="418" /></span></div><br /></div><div><br />You can see the "player" is actually just a static image (because I'm given the option to "Copy Image Location"). The image is hosted at Favoritetube, just like the "codecs":<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman2.html" onclick="window.open('http://blog.spywareguide.com/images/dbman2.html','popup','width=655,height=570,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman2-thumb-355x308.jpg" alt="dbman2.jpg" class="mt-image-none" style="" height="308" width="355" /></a></span><br /><br />Click to Enlarge<br /></div><br />There are quite a lot of these sites floating around out there at present:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman3.html" onclick="window.open('http://blog.spywareguide.com/images/dbman3.html','popup','width=738,height=532,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman3-thumb-338x243.jpg" alt="dbman3.jpg" class="mt-image-none" style="" height="243" width="338" /></a></span><br /><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman4.html" onclick="window.open('http://blog.spywareguide.com/images/dbman4.html','popup','width=599,height=533,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman4-thumb-399x355.jpg" alt="dbman4.jpg" class="mt-image-none" style="" height="355" width="399" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman100.html" onclick="window.open('http://blog.spywareguide.com/images/dbman100.html','popup','width=625,height=516,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman100-thumb-325x268.jpg" alt="dbman100.jpg" class="mt-image-none" style="" height="268" width="325" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />At this point, it's a given that I'm going to show you what happens if you install one of the files typically pushed from the above sites, right? Well, wait no longer - this....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman7.jpg" src="http://blog.spywareguide.com/images/dbman7.jpg" class="mt-image-none" style="" height="81" width="84" /></span></div><br /></div><div><br />...will deposit a rogue antispyware tool on your desktop (one of more more obnoxious ones that refuses to leave you alone):<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/antispycheck1.html" onclick="window.open('http://blog.spywareguide.com/images/antispycheck1.html','popup','width=877,height=668,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/antispycheck1-thumb-377x287.jpg" alt="antispycheck1.jpg" class="mt-image-none" style="" height="287" width="377" /></a></span><br /><br />Click to Enlarge<br /></div><br />Strange and annoying icons will start to creep across your desktop:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman8.jpg" src="http://blog.spywareguide.com/images/dbman8.jpg" class="mt-image-none" style="" height="82" width="245" /></span></div><br /></div><div><br />....and you'll have more fake system alerts than you can shake a very large stick at:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="antispycheck22.jpg" src="http://blog.spywareguide.com/images/antispycheck22.jpg" class="mt-image-none" style="" height="304" width="273" /></span></div><br /><br />This concludes my public safety announcement. I'm off to see Dark Knight again...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 06:10:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dark knight issue">dark knight issue</category>
      <category domain="http://securityratty.com/tag/dark knight">dark knight</category>
      <category domain="http://securityratty.com/tag/movie player">movie player</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/player">player</category>
      <category domain="http://securityratty.com/tag/enlarge">enlarge</category>
      <category domain="http://securityratty.com/tag/image">image</category>
      <category domain="http://securityratty.com/tag/copy image location">copy image location</category>
      <category domain="http://securityratty.com/tag/movie">movie</category>
      <source url="http://blog.spywareguide.com/2008/08/holy-media-codecs-batman.html">Holy Media Codecs, Batman!</source>
    </item>
    <item>
      <title><![CDATA[Music, movie lobbyists push to spy on your Net traffic]]></title>
      <link>http://securityratty.com/article/6252740240fa5ae4fb469691f603ce36</link>
      <guid>http://securityratty.com/article/6252740240fa5ae4fb469691f603ce36</guid>
      <description><![CDATA[Recording industry and motion picture lobbyists are renewing their push to convince broadband providers to monitor customers and detect copyright infringements, claiming the concept is working abroad...]]></description>
      <content:encoded><![CDATA[Recording industry and motion picture lobbyists are renewing their push to convince broadband providers to monitor customers and detect copyright infringements, claiming the concept is working abroad and should be adopted in the United States. ]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 11:30:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/detect copyright infringements">detect copyright infringements</category>
      <category domain="http://securityratty.com/tag/convince broadband providers">convince broadband providers</category>
      <category domain="http://securityratty.com/tag/motion picture lobbyists">motion picture lobbyists</category>
      <category domain="http://securityratty.com/tag/push">push</category>
      <category domain="http://securityratty.com/tag/monitor customers">monitor customers</category>
      <category domain="http://securityratty.com/tag/abroad">abroad</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <category domain="http://securityratty.com/tag/concept">concept</category>
      <source url="http://digg.com/security/Music_movie_lobbyists_push_to_spy_on_your_Net_traffic">Music, movie lobbyists push to spy on your Net traffic</source>
    </item>
    <item>
      <title><![CDATA[Spammers Take A Cheap Shot...]]></title>
      <link>http://securityratty.com/article/2bd234de99d23ff4b013abce95e7d324</link>
      <guid>http://securityratty.com/article/2bd234de99d23ff4b013abce95e7d324</guid>
      <description><![CDATA[I'm on holiday this week, but thought I'd better give this a mention anyway (plus, when did being on holiday ever stop me from posting stuff on blogs, right

I was surprised to see this posted to the...]]></description>
      <content:encoded><![CDATA[
        I'm on holiday this week, but thought I'd better give this a mention anyway (plus, when did being on holiday ever stop me from posting stuff on blogs, right?)<br /><br />I was surprised to see this posted to the comments section of the <a href="http://sunbeltblog.blogspot.com/">Sunbelt Blog</a>:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="spgspam1.gif" src="http://blog.spywareguide.com/images/spgspam1.gif" class="mt-image-none" style="" height="144" width="359" /></span><br /> <div><br />I was about as surprised as The Dean was!<br /><br />To quote a further post from The Dean:<br /><br /><i>"Well, that's weird. Isn't spywareguide Paperghost's blog? I know he
wouldn't spam here. And, the link on the first comment goes to a 404
page."</i><br /><br />So, we have someone spamming with broken English, dropping links to 404 pages on Spywareguide. Curious.<br /><br />Now, I did have some suspicions on this - for starters, the recent blogs regarding the pirate movie websites that pop Zango installers just hit a few <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=privacy&amp;articleId=9112881&amp;taxonomyId=84&amp;intsrc=kc_top">news</a> <a href="http://www.theregister.co.uk/2008/08/18/dark_knight_zango_affiliate_gateway/">websites</a>. As <a href="http://blog.spywareguide.com/2008/08/another-site-hiding-pirate-mov.html">this article</a> mentions, a lot of the sites involved in this are from Asian regions - China, Indonesia etc. I couldn't help but notice the name of the poster was "Tam" - a common name in certain parts of Asia.<br /><br />Coincidence? Or a possible affiliate not too happy about this being highlighted? Well, a quick email later and the results for the spammer are in:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="spgspam2.gif" src="http://blog.spywareguide.com/images/spgspam2.gif" class="mt-image-none" style="" height="185" width="430" /></span>
<br /><br />A potentially forged Reverse DNS aside, it's a strange thing indeed that they just happen to resolve to Vietnam given that a good portion of these sites are in Asia, isn't it?<br /><br />I think I'll see if any are owned by someone called "Tam".<br /><br />When I return from my holiday, of course....<br /></div><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 10:24:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/holiday">holiday</category>
      <category domain="http://securityratty.com/tag/pop zango installers">pop zango installers</category>
      <category domain="http://securityratty.com/tag/sunbelt blog">sunbelt blog</category>
      <category domain="http://securityratty.com/tag/blogs">blogs</category>
      <category domain="http://securityratty.com/tag/spywareguide paperghost">spywareguide paperghost</category>
      <category domain="http://securityratty.com/tag/recent blogs">recent blogs</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/spywareguide">spywareguide</category>
      <category domain="http://securityratty.com/tag/news websites">news websites</category>
      <source url="http://blog.spywareguide.com/2008/08/spammers-take-a-cheap-shot.html">Spammers Take A Cheap Shot...</source>
    </item>
    <item>
      <title><![CDATA[Another Site Hiding Pirate Movies Behind a Zango Installer Prompt]]></title>
      <link>http://securityratty.com/article/503b43d35c6104929785ac82ff1128b5</link>
      <guid>http://securityratty.com/article/503b43d35c6104929785ac82ff1128b5</guid>
      <description><![CDATA[A few days ago, I wrote about a site asking you to install Zango before you could view the site content (which happens to be pirated movies ). Well, another site has come to light doing a similar...]]></description>
      <content:encoded><![CDATA[
        A few days ago, I wrote about a site asking you to install Zango before you could view the site content (which happens to be <a href="http://blog.spywareguide.com/2008/08/a-dark-knight-for-zango.html">pirated movies</a>). Well, another site has come to light doing a similar thing - I'm starting to wonder how many of these are actually out there. It's also served to highlight what I feel is a particularly confusing popup box, but we'll get to that later. First off, here's the website in question:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/bc0.html" onclick="window.open('http://blog.spywareguide.com/images/bc0.html','popup','width=846,height=676,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/bc0-thumb-346x276.jpg" alt="bc0.jpg" class="mt-image-none" style="" height="276" width="346" /></a></span><br /> </div><div><div align="center">Click to Enlarge<br /></div><br />Bestcinemaonline(dot)com. As you can see, the site is similar to the last one (except that site is registered <a href="http://whois.domaintools.com/movietvonline.com">anonymously</a> to an individual in China, whereas this one is registered to <a href="http://whois.domaintools.com/bestcinemaonline.com">someone in Indonesia</a>). Also, the format is different - the last site was more of a "movie repository", whereas this one takes the shape and style of a blog with each individual entry pointing to a film. And what films they are!<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="bc5.jpg" src="http://blog.spywareguide.com/images/bc5.jpg" class="mt-image-none" style="" height="228" width="309" /></span><br /></div></div><div><div align="center">Batman!<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="bc6.jpg" src="http://blog.spywareguide.com/images/bc6.jpg" class="mt-image-none" style="" height="244" width="363" /></span><br /></div></div><div><div align="center">X-Files!<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/bc2.html" onclick="window.open('http://blog.spywareguide.com/images/bc2.html','popup','width=672,height=649,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/bc2-thumb-372x359.jpg" alt="bc2.jpg" class="mt-image-none" style="" height="359" width="372" /></a></span><br />Click to Enlarge<br /></div><br /></div><div>Hellboy! (Is that even out yet?)<br /><br />As you might have expected, a lot of the movies end up looking like this when attempting to watch them:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/bc3.html" onclick="window.open('http://blog.spywareguide.com/images/bc3.html','popup','width=771,height=573,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/bc3-thumb-371x275.jpg" alt="bc3.jpg" class="mt-image-none" style="" height="275" width="371" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />.....whoops.<br /><br />I must also give a special mention to one of the most confusing popup warnings I've ever seen - it really threw me, and I admit I nearly installed Zango accidentally after seeing it. If (when prompted with the Zango installer box) you click "Cancel", this appears in the middle of your screen:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="bc1.jpg" src="http://blog.spywareguide.com/images/bc1.jpg" class="mt-image-none" style="" height="126" width="476" /></span><br /></div><div><br /><i>"Click <b>OK to Cancel </b>or<b> Click "Cancel" to continue </b>the installation".</i><br /><br />.....Whaaaaaa? That's a bit of a brain bender, right there. I hope this set of writeups doesn't become a Trilogy...<br /><br /><br /></div>
        
    ]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 03:44:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/zango">zango</category>
      <category domain="http://securityratty.com/tag/site content">site content</category>
      <category domain="http://securityratty.com/tag/zango installer box">zango installer box</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/movies">movies</category>
      <category domain="http://securityratty.com/tag/individual">individual</category>
      <category domain="http://securityratty.com/tag/cancel">cancel</category>
      <category domain="http://securityratty.com/tag/install zango">install zango</category>
      <source url="http://blog.spywareguide.com/2008/08/another-site-hiding-pirate-mov.html">Another Site Hiding Pirate Movies Behind a Zango Installer Prompt</source>
    </item>
    <item>
      <title><![CDATA[A Dark Knight For Zango?]]></title>
      <link>http://securityratty.com/article/61b33df0818a09cde982b57d42eb49e7</link>
      <guid>http://securityratty.com/article/61b33df0818a09cde982b57d42eb49e7</guid>
      <description><![CDATA[Here's a site - movietvonline(dot)com - that requires you to install Zango in order to view the content




Click to Enlarge

Nothing unusual there, though I did think the owners of the website were...]]></description>
      <content:encoded><![CDATA[
        Here's a site - movietvonline(dot)com - that requires you to install Zango in order to view the content.<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/joker1.html" onclick="window.open('http://blog.spywareguide.com/images/joker1.html','popup','width=968,height=590,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/joker1-thumb-368x224.jpg" alt="joker1.jpg" class="mt-image-none" style="" height="224" width="368" /></a></span><br /><br />Click to Enlarge<br /></div><br />Nothing unusual there, though I did think the owners of the website were pushing things a <i>little</i>, perhaps, to ask you to install something to view content you could view for free on the <a href="http://thedarkknight.warnerbros.com/">official website</a>.<br /><br />Anyway.<br /><br />Turns out I was somewhat wrong, because they're not asking you to download Zango in order to watch <i>trailers</i>:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="joker2.jpg" src="http://blog.spywareguide.com/images/joker2.jpg" class="mt-image-none" style="" height="300" width="529" /></span><br /><br />They want you to agree to install Zango in order to view whole <i>movies</i>, some streamed on the movietvonline website from other sources, others in the form of broken up downloads hosted on file-downloading sites.<br /><br />Here's a shot of what appears to be a badly made camcorder (complete with people talking and scrunching up paper in the background) streamed on the website:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="joker3.jpg" src="http://blog.spywareguide.com/images/joker3.jpg" class="mt-image-none" style="" height="460" width="522" /></span>
<br /><br />Clearly, the Joker isn't asking Batman "Why so serious" - he's asking him why the camcorder rip is so seriously bad. In fact, the whole site appears to be nothing more than a mass repository of dubiously acquired movie copies:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/joker4.html" onclick="window.open('http://blog.spywareguide.com/images/joker4.html','popup','width=897,height=720,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/joker4-thumb-397x318.jpg" alt="joker4.jpg" class="mt-image-none" style="" height="318" width="397" /></a></span><br /><br />Click to Enlarge<br /></div><br />...Holy Pirated Content, Batman!<br />
        
    ]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 14:49:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/view">view</category>
      <category domain="http://securityratty.com/tag/view content">view content</category>
      <category domain="http://securityratty.com/tag/website">website</category>
      <category domain="http://securityratty.com/tag/official website">official website</category>
      <category domain="http://securityratty.com/tag/movietvonline website">movietvonline website</category>
      <category domain="http://securityratty.com/tag/install">install</category>
      <category domain="http://securityratty.com/tag/install zango">install zango</category>
      <category domain="http://securityratty.com/tag/movietvonline">movietvonline</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <source url="http://blog.spywareguide.com/2008/08/a-dark-knight-for-zango.html">A Dark Knight For Zango?</source>
    </item>
  </channel>
</rss>
