<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: mps]]></title>
    <link>http://securityratty.com/tag/mps</link>
    <description></description>
    <pubDate>Thu, 03 Jan 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Listening to the evidence]]></title>
      <link>http://securityratty.com/article/cb3684b9bd257e429791aaa34c5339e3</link>
      <guid>http://securityratty.com/article/cb3684b9bd257e429791aaa34c5339e3</guid>
      <description><![CDATA[Last week the House of Commons Culture, Media and Sport Select Committee published a report of their inquiry into Harmful content on the Internet and in video games . They make a number of...]]></description>
      <content:encoded><![CDATA[<p>Last week the <a href="http://www.parliament.uk/parliamentary_committees/culture__media_and_sport.cfm">House of Commons Culture, Media and Sport Select Committee</a> published a report of their inquiry into &#8220;<a href="http://www.publications.parliament.uk/pa/cm200708/cmselect/cmcumeds/353/353.pdf">Harmful content on the Internet and in video games</a>&#8220;. They make a number of recommendations including a self-regulatory body to set rules for Internet companies to force them to protect users; that sites should provide a &#8220;watershed&#8221; so that grown-up material cannot be viewed before 9pm; that YouTube should screen material for forbidden content; that &#8220;<a href="http://www.spiked-online.com/index.php?/site/article/4633/">suicide websites</a>&#8221; should be blocked; that ISPs should be forced to block child sexual abuse image websites whatever the cost, and that blocking of bad content was generally desirable.</p>
<p>You will discern a certain amount of enthusiasm for blocking, and for a &#8220;<a href="http://www.yes-minister.com/polterms.htm#Politicians">something must be done</a>&#8221; approach. However, in coming to their conclusions, they do not, in my view, seem to have listened too hard to the evidence, or sought out expertise elsewhere in the world&#8230;<br />
<span id="more-351"></span><br />
Google/YouTube told them that 10 hours of video was posted every minute, and the amount is increasing. In the oral evidence session an MP helpfully suggested: &#8220;That video content is tagged. You do not need to look at every single minute of video content. Surely you could have people who would look at the video content which is tagged with labels which suggest it could be inappropriate.&#8221; Of course &#8220;<a href="http://lostria.blogspot.com/2008/01/fertility-slaps.html">happy_slapping.wmv</a>&#8221; or &#8220;<a href="http://www.phrases.org.uk/meanings/bunny-boiler.html">fluffy_bunnies.avi</a>&#8221; must always contain exactly what it says on the tin (<a href="http://en.wikipedia.org/wiki/Not%21">not!</a>) but unaccountably Google said it was a &#8220;fair suggestion&#8221;, so perhaps my cynicism is misplaced.</p>
<p>However, back to blocking.</p>
<p>I submitted <a href="http://www.cl.cam.ac.uk/~rnc1/080129-cms.pdf">some evidence of my own</a>, which the committee summarised, reasonably accurately:</p>
<blockquote><p>Dr Richard Clayton, a researcher in the Security Group of the Computer Laboratory at Cambridge University and author of several academic papers on methods for blocking access to Internet content, pointed out that there was no single blocking method which was both inexpensive and discerning enough to block access to only one part of a large website (such as FaceBook). In his view, the fatal flaw of all network-level blocking schemes was the ease with which they could be overcome, either by encrypting content or by the use of proxy services hosted outside the UK.</p></blockquote>
<p>The committee&#8217;s conclusion, having read this was:</p>
<blockquote><p>At a time of rapid technological change, it is difficult to judge whether blocking access to Internet content at network level by Internet service providers is likely to become ineffective in the near future. However, this is not a reason for not doing so while it is still effective for the overwhelming majority of users.</p></blockquote>
<p>which I suppose logically means that the committee thinks that blocking should now be discarded as a policy option &#8212; but somehow I think that isn&#8217;t their intended meaning.</p>
<p>The Committee should perhaps have a look at <a href="http://www.acma.gov.au/webwr/_assets/main/lib310554/isp-level_internet_content_filtering_trial-report.pdf">this Australian report</a>, which found that ISP level content filtering (and in Australia the politicians want to use ISP level filtering to provide a child-friendly Internet) did work (up to a point) at Tier 3 (the smallest) ISPs. The <a href="http://en.wikiquote.org/wiki/Evelyn_Waugh#Scoop_.281938.29">up-to-a-point</a> is that unlike previous tests the systems didn&#8217;t completely wreck the browsing experience by slowing it down. However, the systems blocked only 85-98% of illegal material and similar percentages of material suitable for adults but not for younger children. Interestingly some products were better at different categories.</p>
<p>Getting that many sites wrong is really quite significant, so it&#8217;s difficult to see this as a ringing endorsement for blocking the web. Additionally, the Australian report found that the blocking was useless on &#8220;non-web&#8221; protocols (such as peer-to-peer) and their report specifically didn&#8217;t consider cost, or ease of circumvention &#8212; so it&#8217;s not just UK politicians not wanting to consider evidence on that topic!</p>
<p>Finally, I should note that the Culture Media and Sport Committee has also ignored some rather more recent academic work. The MPs have put into their report that they were horrified to discover that child sexual abuse images took 24 hours to remove in the UK. What (should they ever learn of it) will they make of the recent discovery by <a href="http://people.seas.harvard.edu/~tmoore/">Tyler Moore</a> and myself that shows that if the website is hosted abroad then <a href="http://www.lightbluetouchpaper.org/2008/06/11/slow-removal-of-child-sexual-abuse-image-websites/">a month is more to be expected</a>?</p>
]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 20:24:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/isp level content">isp level content</category>
      <category domain="http://securityratty.com/tag/video games">video games</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/bad content">bad content</category>
      <category domain="http://securityratty.com/tag/video content">video content</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/evidence">evidence</category>
      <category domain="http://securityratty.com/tag/child-friendly internet">child-friendly internet</category>
      <source url="http://www.lightbluetouchpaper.org/2008/08/08/listening-to-the-evidence/">Listening to the evidence</source>
    </item>
    <item>
      <title><![CDATA[Smells Like a Copycat SQL Injection In the Wild]]></title>
      <link>http://securityratty.com/article/ae553b37ba0ec150b5a4c344ba27652b</link>
      <guid>http://securityratty.com/article/ae553b37ba0ec150b5a4c344ba27652b</guid>
      <description><![CDATA[In between the massive SQL injections , that as a matter of fact remain ongoing, copycats taking advantage of the very same SQL injection tools using public search engine's indexes as a reconnaissance...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/SI2ac7mO18I/AAAAAAAAB9c/usiNWVgrooU/s1600-h/chinese_sql_injection.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SI2ac7mO18I/AAAAAAAAB9c/97ckqqWaQ14/s200-R/chinese_sql_injection.JPG" style="border: 0pt none ;" /></a>In between the <a href="http://ddanchev.blogspot.com/2008/07/ayyildiz-turkish-hacking-group-vs.html">massive SQL injections</a>, that as a matter of fact remain ongoing, copycats taking advantage of the very same SQL injection tools using public search engine's indexes as a reconnaissance tools, are also starting to take advantage of <a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">localized and targeted attacks</a>, attacking specific online communities. Among these is <b>mx.content-type.cn /day.js </b>using <b>day.js</b> to attempt multiple exploitation using publicly obtainlable exploits such as Adodb.Stream, MPS.StormPlayer, DPClient.Vod, IERPCtl.IERPCtl.1, GLIEDown.IEDown.1, and targeting primarily Chinese web communities.<br />
<br />
Compared to a bit more sophisticated <a href="http://ddanchev.blogspot.com/2008/04/diy-exploit-embedding-tool-proprietary.html">attack tactics applied by Chinese hackers</a>, taking advantage of <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">localized versions</a> of the <a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">de facto web malware exploitation kits</a>, those who don't have access to such continue using cybercrime 1.0 <a href="http://ddanchev.blogspot.com/2007/09/diy-exploits-embedding-tools.html">DIY exploit embedding tools</a> at large. The rest of the SQL injected domains as well as the exploits themselves are parked on the same plaee - <b>222.216.28.25</b>, also responding to :<br />
<br />
<b>down.goodnetads .org<br />
ads.goodnetads .org<br />
real.kav2008 .com<br />
hk.www404 .cn<br />
err.www404 .cn<br />
mx.content-type .cn<br />
sun.63afe561 .info<br />
ads.633f94d3 .info<br />
ads.1234214 .info<br />
ad.50db34d5 .info<br />
ads.50db34d5 .info<br />
ad.8d77b42a .info<br />
web.adsidc .info<br />
free.idcads .info<br />
free.cjads .info<br />
ads.adslooks .info<br />
list.adslooks .info<br />
ad.5iyy .info</b><br />
<br />
The SQL injected domains :<br />
<b>ads.633f94d3.info/day .js<br />
ad.8d77b42a.info/day .js<br />
ad.5iyy.info/day .js<br />
free.idcads.info/day .js<br />
efreesky.com/day .js<br />
v.freefl.info/day .js</b><br />
<br />
The internal structure :<br />
<b>free.idcads.info/f/index .htm<br />
free.idcads.info/014 .htm<br />
free.idcads.info/real11 .htm<br />
free.idcads.info/real10 .htm<br />
free.idcads.info/lz .htm<br />
free.idcads.info/bf .htm<br />
free.idcads.info/kong .htm<br />
free.idcads.info/f/swfobject .js<br />
ad.50db34d5.info//rm%5C/rm .exe</b><br />
<br />
Parked domains responding to the command and control locations, <b>60.191.223.76 </b>and <b>222.216.28.100</b> :<br />
<b>ftp.gggjjj .info<br />
live.ads002 .net<br />
log.goodnetads .org<br />
dat.goodnetads .org<br />
root.51113 .com<br />
sun.update999 .cn<br />
abb.633f94d3 .info<br />
up.50db34d5 .info</b><br />
<b>web.cn3721 .org&nbsp;&nbsp;&nbsp; <br />
dat.goodnetads .org<br />
cs.rm510 .com<br />
sb.sb941 .com<br />
k.sb941 .com<br />
info.sb941 .com<br />
day.sb941 .com<br />
post.ad9178 .com<br />
v.91tg .net</b><br />
<br />
Centralizing their scammy ecosystem always makes it easier to monitor, keep track of, and of course, expose. <br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/sql-injecting-malicious-doorways-to.html">SQL Injecting Malicious Doorways to Serve Malware </a><br />
<a href="http://ddanchev.blogspot.com/2008/05/yet-another-massive-sql-injection.html">Yet Another Massive SQL Injection Spotted in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/malware-domains-used-in-sql-injection.html">Malware Domains Used in the SQL Injection Attacks</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">SQL Injection Through Search Engines Reconnaissance</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/google-hacking-for-vulnerabilities.html">Google Hacking for Vulnerabilities</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><br />
<a href="http://blogs.zdnet.com/security/?p=1394">Sony PlayStation's site SQL injected, redirecting to rogue security software</a><br />
<a href="http://blogs.zdnet.com/security/?p=1118">Redmond Magazine Successfully SQL Injected by Chinese Hacktivists</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9XdgSJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9XdgSJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3nv7jJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3nv7jJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3DXSvj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3DXSvj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=exadYj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=exadYj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kp9u0J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kp9u0J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=y5pfDJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=y5pfDJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Lkbwwj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Lkbwwj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/348288922" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 28 Jul 2008 01:51:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sql">sql</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/sql injection tools">sql injection tools</category>
      <category domain="http://securityratty.com/tag/massive sql injections">massive sql injections</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/sql injection attacks">sql injection attacks</category>
      <category domain="http://securityratty.com/tag/sql injection">sql injection</category>
      <category domain="http://securityratty.com/tag/massive sql injection">massive sql injection</category>
      <category domain="http://securityratty.com/tag/site sql">site sql</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/348288922/smells-like-copycat-sql-injection-in.html">Smells Like a Copycat SQL Injection In the Wild</source>
    </item>
    <item>
      <title><![CDATA[42 Days In A Hole?]]></title>
      <link>http://securityratty.com/article/cca674dee75b546491e9846bc571c44c</link>
      <guid>http://securityratty.com/article/cca674dee75b546491e9846bc571c44c</guid>
      <description><![CDATA[Jeebus. The UK govt has apparently been into the Bush White Houses private stash of recreational horticulture
Being commanded about by the child-monster has slowed down my news consumption. So, big...]]></description>
      <content:encoded><![CDATA[<p>Jeebus. The UK gov&#8217;t has apparently been into the Bush White House&#8217;s private stash of recreational horticulture. </p>
<p>Being commanded about by the child-monster has slowed down my news consumption. So, big thanks to Portswigger for the heads up. Apparently the UK gov&#8217;t wants to set the new detention limit without charges to 42 days. This has triggered a firestorm.</p>
<p>From BBC:</p>
<blockquote><p>Shadow home secretary David Davis has resigned as an MP.</p>
<p>He is to force a by-election in his Haltemprice and Howden constituency which he will fight on the issue of the new 42-day terror detention limit.</p>
<p>Mr Davis told reporters outside the House of Commons he believed his move was a &#8220;noble endeavour&#8221; to stop the erosion of British civil liberties.</p>
<p>The 59-year-old is one of the best known Tory MPs and his resignation came as a complete surprise in Westminster.</p>
<p>He told reporters outside the Commons: &#8220;I will argue in this by-election against the slow strangulation of fundamental British freedoms by this government.&#8221;</p>
<p>BBC Political Editor Nick Robinson said it was an extraordinary move which was almost without precedent in British politics. </p></blockquote>
<p>Read on.</p>
<p><a href="http://news.bbc.co.uk/2/hi/uk_news/politics/7450627.stm">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=VYFdtX"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=VYFdtX" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=wECTXI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=wECTXI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=MCOcRi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=MCOcRi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=VDLfni"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=VDLfni" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=gym2Ri"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=gym2Ri" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=YWzh7i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=YWzh7i" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/310417717" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 09:58:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/move">move</category>
      <category domain="http://securityratty.com/tag/british civil liberties">british civil liberties</category>
      <category domain="http://securityratty.com/tag/extraordinary move">extraordinary move</category>
      <category domain="http://securityratty.com/tag/bush white houses">bush white houses</category>
      <category domain="http://securityratty.com/tag/fundamental british freedoms">fundamental british freedoms</category>
      <category domain="http://securityratty.com/tag/recreational horticulture">recreational horticulture</category>
      <category domain="http://securityratty.com/tag/news consumption">news consumption</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <category domain="http://securityratty.com/tag/detention limit">detention limit</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/310417717/">42 Days In A Hole?</source>
    </item>
    <item>
      <title><![CDATA[Parliament, Spy Agency Contracts Exempted From Ombudsmans Gaze]]></title>
      <link>http://securityratty.com/article/0317ed628b327ca4495ddc4bee31d829</link>
      <guid>http://securityratty.com/article/0317ed628b327ca4495ddc4bee31d829</guid>
      <description><![CDATA[From the Canadian Press
Prime Minister Stephen Harper and his cabinet have exempted contracts with Parliament and Canadas spy agency from oversight by a new ombudsmans post that was central to the...]]></description>
      <content:encoded><![CDATA[<p><center><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2008/05/impotence.jpg" alt="impotence" title="impotence" width="350" height="466" /></center></p>
<p>From the Canadian Press:</p>
<blockquote><p>Prime Minister Stephen Harper and his cabinet have exempted contracts with Parliament and Canada&#8217;s spy agency from oversight by a new ombudsman&#8217;s post that was central to the 2006 Conservative election campaign.</p>
<p>The government slipped the exemptions through last week in regulations that empower the contract procurement ombudsman under the Accountability Act - flagship legislation the government introduced as its first bill soon after taking office.</p>
<p>Opposition MPs were taken by surprise at the exemptions, saying they were unaware the Senate, the House of Commons and the Canadian Security Intelligence Service would be excluded from the ombudsman&#8217;s statutory duty to review contracts for &#8220;fairness, openness and transparency.&#8221;</p>
<p>The exemptions also mean anyone who has a complaint about contracts to supply goods or services to Parliament - including contracts with offices of MPs, senators or CSIS, will be unable to have them reviewed by the ombudsman.</p></blockquote>
<p>Hey, now that seems reasonable. (insert <b><i>heavy</i></b> sarcasm)</p>
<p><a href="http://canadianpress.google.com/article/ALeqM5hJS90PcsLEdcvOpNpQ7UeeFE3E3g">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=sVUfWP"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=sVUfWP" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=J3mkvH"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=J3mkvH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=JDcMQh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=JDcMQh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=CZll9h"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=CZll9h" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=50H8gh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=50H8gh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=XO40Kh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=XO40Kh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/293942369" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 19 May 2008 22:54:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/contracts">contracts</category>
      <category domain="http://securityratty.com/tag/review contracts">review contracts</category>
      <category domain="http://securityratty.com/tag/ombudsman">ombudsman</category>
      <category domain="http://securityratty.com/tag/parliament">parliament</category>
      <category domain="http://securityratty.com/tag/contract procurement ombudsman">contract procurement ombudsman</category>
      <category domain="http://securityratty.com/tag/opposition mps">opposition mps</category>
      <category domain="http://securityratty.com/tag/ombudsmans statutory duty">ombudsmans statutory duty</category>
      <category domain="http://securityratty.com/tag/canadas spy agency">canadas spy agency</category>
      <category domain="http://securityratty.com/tag/insert heavy sarcasm">insert heavy sarcasm</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/293942369/">Parliament, Spy Agency Contracts Exempted From Ombudsmans Gaze</source>
    </item>
    <item>
      <title><![CDATA[The New Media Malware Gang - Part Four]]></title>
      <link>http://securityratty.com/article/b106bfe3b9ae8041676ee1a8e489ac20</link>
      <guid>http://securityratty.com/article/b106bfe3b9ae8041676ee1a8e489ac20</guid>
      <description><![CDATA[Sometimes patterns are just meant to be, and so is the process of diving into the semantics of RBN's ex/current customers base, in this case the New Media Malware Gang. The latest pack of this group...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/R9W9MU-0GAI/AAAAAAAABdA/9d4NW6dE_Jc/s1600-h/new_media_malware_4.jpg"><img id="BLOGGER_PHOTO_ID_5176251366220503042" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/R9W9MU-0GAI/AAAAAAAABdA/9d4NW6dE_Jc/s200/new_media_malware_4.jpg" border="0" /></a>Sometimes patterns are just meant to be, and so is the process of diving into the semantics of RBN's ex/current customers base, in this case the New Media Malware Gang. The latest pack of this group specific live exploit URLs :<br /><br /><strong>bentham-mps.org/mansoor/cgi/index.php</strong> (205.234.186.26)<br /><strong>5fera.cn/adp/index.php </strong>(72.233.60.90)<br /><strong>ls-al.biz/1/index.php </strong>(78.109.22.245)<br /><strong>iwrx.com/images/index.php </strong>(74.53.174.34)<br /><strong>pizda.cc/in.htm </strong>(78.109.19.226)<br /><strong>ugl.vrlab.org/www/index.php </strong>(91.123.28.32)<br /><strong>eastcourier.com/reff/index.php </strong>(91.195.124.20)<br /><strong>thelobanoff.com/myshop/test/index.php </strong>(64.191.78.229)<br /><strong>203.117.170.40/~whyme/my/index.php</strong><br /><strong>195.93.218.25/us/index.php</strong><br /><strong>195.93.218.25/kam/index.php</strong><br /><strong>85.255.116.206/ax5/index.php</strong><br /><br />Going through <a href="http://ddanchev.blogspot.com/2007/11/new-media-malware-gang.html">Part one</a>, <a href="http://ddanchev.blogspot.com/2007/12/new-media-malware-gang-part-two.html">Part two</a>, and <a href="http://ddanchev.blogspot.com/2008/02/new-media-malware-gang-part-three.html">Part three</a>, clearly indicates an ongoing migration.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nwNWNgF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nwNWNgF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CGb4XJF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CGb4XJF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6JFZUNf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6JFZUNf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xX1V1Vf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xX1V1Vf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MJdzosF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MJdzosF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8k9gU0F"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8k9gU0F" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=p0i6TUf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=p0i6TUf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/249832624" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 11 Mar 2008 16:50:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/media malware gang">media malware gang</category>
      <category domain="http://securityratty.com/tag/excurrent customers base">excurrent customers base</category>
      <category domain="http://securityratty.com/tag/orgwwwindex">orgwwwindex</category>
      <category domain="http://securityratty.com/tag/eastcourier">eastcourier</category>
      <category domain="http://securityratty.com/tag/ugl">ugl</category>
      <category domain="http://securityratty.com/tag/pizda">pizda</category>
      <category domain="http://securityratty.com/tag/5fera">5fera</category>
      <category domain="http://securityratty.com/tag/25kamindex">25kamindex</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/249832624/new-media-malware-gang-part-four.html">The New Media Malware Gang - Part Four</source>
    </item>
    <item>
      <title><![CDATA[U.K. launches first Internet Governance Forum]]></title>
      <link>http://securityratty.com/article/073b985f820013789bd489068fe726c6</link>
      <guid>http://securityratty.com/article/073b985f820013789bd489068fe726c6</guid>
      <description><![CDATA[The U.K. Internet Governance Forum (IGF) was held at the Houses of Parliament on Thursday, with representatives from Nominet, the Specialist Crime Directorate, MPs and a British...]]></description>
      <content:encoded><![CDATA[The U.K. Internet Governance Forum (IGF) was held at the Houses of Parliament on Thursday, with representatives from Nominet, the Specialist Crime Directorate, MPs and a British ambassador.]]></content:encoded>
      <pubDate>Fri, 07 Mar 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/internet governance forum">internet governance forum</category>
      <category domain="http://securityratty.com/tag/specialist crime">specialist crime</category>
      <category domain="http://securityratty.com/tag/british ambassador">british ambassador</category>
      <category domain="http://securityratty.com/tag/mps">mps</category>
      <category domain="http://securityratty.com/tag/parliament">parliament</category>
      <category domain="http://securityratty.com/tag/held">held</category>
      <category domain="http://securityratty.com/tag/houses">houses</category>
      <category domain="http://securityratty.com/tag/representatives">representatives</category>
      <category domain="http://securityratty.com/tag/thursday">thursday</category>
      <source url="http://www.networkworld.com/news/2008/030708-uk-launches-first-internet-governance.html?fsrc=rss-security">U.K. launches first Internet Governance Forum</source>
    </item>
    <item>
      <title><![CDATA[UK Two-Tier Tax Security System]]></title>
      <link>http://securityratty.com/article/2cc281d7463a5e05fbeac670a614a951</link>
      <guid>http://securityratty.com/article/2cc281d7463a5e05fbeac670a614a951</guid>
      <description><![CDATA[Poor security for everyone except the rich and powerful : The security of the online computer system used by more than three million people to file tax returns is in doubt after HM Revenue and Customs...]]></description>
      <content:encoded><![CDATA[<p>Poor security for <a href="http://www.telegraph.co.uk/news/main.jhtml?xml=/news/2008/01/26/ntax126.xml">everyone except the rich and powerful</a>:</p>

<blockquote>The security of the online computer system used by more than three million people to file tax returns is in doubt after HM Revenue and Customs admitted it was not secure enough to be used by MPs, celebrities and the Royal Family.

<p>Thousands of "high profile" people have been secretly barred from using the online tax return system amid concerns that their confidential details would be put at risk.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=rnd39FE"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=rnd39FE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=d4ImuQE"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=d4ImuQE" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 05 Feb 2008 11:38:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/poor security">poor security</category>
      <category domain="http://securityratty.com/tag/file tax returns">file tax returns</category>
      <category domain="http://securityratty.com/tag/online computer system">online computer system</category>
      <category domain="http://securityratty.com/tag/million people">million people</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/royal family">royal family</category>
      <category domain="http://securityratty.com/tag/confidential details">confidential details</category>
      <category domain="http://securityratty.com/tag/profile">profile</category>
      <source url="http://www.schneier.com/blog/archives/2008/02/uk_twotier_tax.html">UK Two-Tier Tax Security System</source>
    </item>
    <item>
      <title><![CDATA[U.K. politicians want losing data to be a crime]]></title>
      <link>http://securityratty.com/article/6a100039b13672cfc5614153d26e5cb6</link>
      <guid>http://securityratty.com/article/6a100039b13672cfc5614153d26e5cb6</guid>
      <description><![CDATA[A committee of MPs has called for tougher criminal penalties for data security breaches as incidents where the government or contractors have lost people's personal data continue to come to...]]></description>
      <content:encoded><![CDATA[A committee of MPs has called for tougher criminal penalties for data security breaches as incidents where the government or contractors have lost people's personal data continue to come to light.]]></content:encoded>
      <pubDate>Thu, 03 Jan 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data security breaches">data security breaches</category>
      <category domain="http://securityratty.com/tag/personal data continue">personal data continue</category>
      <category domain="http://securityratty.com/tag/tougher criminal penalties">tougher criminal penalties</category>
      <category domain="http://securityratty.com/tag/lost people">lost people</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/contractors">contractors</category>
      <category domain="http://securityratty.com/tag/mps">mps</category>
      <category domain="http://securityratty.com/tag/committee">committee</category>
      <category domain="http://securityratty.com/tag/light">light</category>
      <source url="http://www.networkworld.com/news/2008/010308-uk-politicians-want-losing-data.html?fsrc=rss-security">U.K. politicians want losing data to be a crime</source>
    </item>
  </channel>
</rss>
