<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: msn]]></title>
    <link>http://securityratty.com/tag/msn</link>
    <description></description>
    <pubDate>Thu, 31 Jul 2008 09:19:33 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Fear not, no wait, you should fear.]]></title>
      <link>http://securityratty.com/article/62970ace259302e46fc33f22f86e9c5e</link>
      <guid>http://securityratty.com/article/62970ace259302e46fc33f22f86e9c5e</guid>
      <description><![CDATA[Ever get the feeling that the bow of the ship is slipping under the waves


clipped from www.msnbc.msn.com

U.S. Cybersecurity Is Weak, GAO Says



Five years after the Homeland Security Dept. took...]]></description>
      <content:encoded><![CDATA[<div > Ever get the feeling that the bow of the ship is slipping under the waves? </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/3EFCAA8A-BF2C-497A-8513-A48D6844A0AD/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/ad915f0a-26dc-4cc3-8945-0ed58ccf8ec1/3EFCAA8A-BF2C-497A-8513-A48D6844A0AD/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.msnbc.msn.com/id/26738121/" href="http://www.msnbc.msn.com/id/26738121/" style="font-size: 11px;">www.msnbc.msn.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">
U.S. Cybersecurity Is Weak, GAO Says
</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ --><P class="textBodyBlack"><SPAN id="byLine"></SPAN><br />
Five years after the Homeland Security Dept. took charge of the team as a critical safeguard against threats to national security, US-CERT &#8220;still does not exhibit aspects of the attributes essential to having a truly national capability,&#8221; according to the draft report.<br />
</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ --><P class="textBodyBlack"><SPAN id="byLine"></SPAN><br />
Vulnerable to Foreign Adversaries</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ --><P class="textBodyBlack"><SPAN id="byLine"></SPAN><br />
Goals Not Being Met</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ --><P class="textBodyBlack"><SPAN id="byLine"></SPAN><br />
Actions Are Inadequate</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ --><P class="textBodyBlack"><SPAN id="byLine"></SPAN><br />
Weak Warning Capabilities</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/3EFCAA8A-BF2C-497A-8513-A48D6844A0AD/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_180908012351"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=180908012351&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=180908012351&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=180908012351&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_180908012351" /></a></P>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 09:23:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/homeland security dept">homeland security dept</category>
      <category domain="http://securityratty.com/tag/exhibit aspects">exhibit aspects</category>
      <category domain="http://securityratty.com/tag/critical safeguard">critical safeguard</category>
      <category domain="http://securityratty.com/tag/attributes essential">attributes essential</category>
      <category domain="http://securityratty.com/tag/national capability">national capability</category>
      <category domain="http://securityratty.com/tag/draft report">draft report</category>
      <category domain="http://securityratty.com/tag/weak">weak</category>
      <category domain="http://securityratty.com/tag/national security">national security</category>
      <category domain="http://securityratty.com/tag/foreign adversaries">foreign adversaries</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=623">Fear not, no wait, you should fear.</source>
    </item>
    <item>
      <title><![CDATA[Skype Spamming Tool in the Wild - Part Two]]></title>
      <link>http://securityratty.com/article/2f4b287e34b2a08136f91837e197028e</link>
      <guid>http://securityratty.com/article/2f4b287e34b2a08136f91837e197028e</guid>
      <description><![CDATA[The less technologically sophisticated lone cybercriminals have always enjoyed the benefits of stand alone DIY applications. From DIY exploit embedding tools in a Cybercrime 1.0 world , maturing to...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SMqdKYNwv9I/AAAAAAAACKE/hHcsAQOFSi8/s1600-h/skype_spamming_tool_02.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SMqdKYNwv9I/AAAAAAAACKE/sy6IR6q_hyE/s200-R/skype_spamming_tool_02.jpg" /></a>The less technologically sophisticated lone cybercriminals have always enjoyed the benefits of stand alone DIY applications. From <a href="http://ddanchev.blogspot.com/2007/09/diy-exploits-embedding-tools.html">DIY exploit embedding tools</a> in a <a href="http://ddanchev.blogspot.com/2008/04/diy-exploit-embedding-tool-proprietary.html">Cybercrime 1.0 world</a>, maturing to today's <a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">web malware exploitation kits</a> and their <a href="http://ddanchev.blogspot.com/2008/09/copycat-web-malware-exploitation-kits.html">copycat alternatives</a>, to plain simple spamming tools that matured into <a href="http://blogs.zdnet.com/security/?p=1899">today's managed spamming services</a> already starting to offer spamming services beyond email, stand alone spamming applications remain pretty popular.<br />
<br />
With yet another <a href="http://ddanchev.blogspot.com/2008/04/skype-spamming-tool-in-wild.html">Skype spamming tool</a> released in the wild, which just like the previous one I discussed a couple of months relies on Skype's support for wildcast searches, and is spamming with authorization request messages until the user adds the contact, malicious parties seems to be more interested into supplying the desired services, than emphasizing on the quality assurance process.<br />
<br />
Despite the possibilities for localized targeted attacks delivering messages with malicious URLs into the user's native language, benchmarking this tool's features next to the ones offered by certain bots taking advantage of social engineering by spamming the infected host's contacts, is positioning it far behind even the most primitive IM spreading bot modules, whose extra layer of social engineering personalization makes their IM malware campaigns much more effective ones.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/05/harvesting-youtube-usernames-for.html">Harvesting Youtube Usernames for Spamming</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/uncovering-msn-social-engineering-scam.html">Uncovering a MSN Social Engineering Scam</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/msn-spamming-bot.html">MSN Spamming Bot</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/diy-fake-msn-client-stealing-passwords.html">DIY Fake MSN Client Stealing Passwords</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/thousands-of-im-screen-names-in-wild.html">Thousands of IM Screen Names in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/yahoo-messenger-controlled-malware.html">Yahoo Messenger Controlled Malware</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DnpcL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DnpcL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JdbNL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JdbNL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WyKQl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WyKQl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gjRhl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gjRhl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MFoXL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MFoXL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cB2ML"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cB2ML" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XFyul"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XFyul" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/393258731" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 05:28:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/social">social</category>
      <category domain="http://securityratty.com/tag/msn social">msn social</category>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/skype">skype</category>
      <category domain="http://securityratty.com/tag/wild">wild</category>
      <category domain="http://securityratty.com/tag/bot">bot</category>
      <category domain="http://securityratty.com/tag/msn">msn</category>
      <category domain="http://securityratty.com/tag/malware campaigns">malware campaigns</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/393258731/skype-spamming-tool-in-wild-part-two.html">Skype Spamming Tool in the Wild - Part Two</source>
    </item>
    <item>
      <title><![CDATA[Summarizing Zero Day's Posts for August]]></title>
      <link>http://securityratty.com/article/760771fee674333ebf23f7a9adc16291</link>
      <guid>http://securityratty.com/article/760771fee674333ebf23f7a9adc16291</guid>
      <description><![CDATA[Here's a concise summary of all of my posts at Zero Day for August. If interested, consider going through July's summary , subscribe yourself to my personal feed , or Zero Day's main feed , and stay...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SL_Sx5a39YI/AAAAAAAACJs/GbK1dWvgJFs/s1600-h/zeroday_august.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SL_Sx5a39YI/AAAAAAAACJs/5TbgDFTdET4/s200-R/zeroday_august.png" /></a>Here's a concise summary of all of my posts at <a href="http://blogs.zdnet.com/security">Zero Day</a> for August. If interested, consider going through <a href="http://ddanchev.blogspot.com/2008/08/summarizing-zero-days-posts-for-july.html">July's summary</a>, subscribe yourself to <a href="http://updates.zdnet.com/tags/dancho+danchev.html?t=0&amp;s=0&amp;o=1&amp;mode=rss">my personal feed</a>, or <a href="http://feeds.feedburner.com/zdnet/security">Zero Day's main feed</a>, and stay informed.<br />
<br />
Some of the notable articles are - <a href="http://blogs.zdnet.com/security/?p=1649">Today's assignment : Coding an undetectable malware</a> ; <a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a> and <a href="http://blogs.zdnet.com/security/?p=1835">Inside India's CAPTCHA solving economy</a>.<br />
<br />
<b>01.</b> <a href="http://blogs.zdnet.com/security/?p=1620">Cuil's stance on privacy - "We have no idea who you are"</a><br />
<b>02. </b><a href="http://blogs.zdnet.com/security/?p=1641">Phishers increasingly scamming other phishers</a><br />
<b>03.</b> <a href="http://blogs.zdnet.com/security/?p=1649">Today's assignment : Coding an undetectable malware</a><br />
<b>04.</b> <a href="http://blogs.zdnet.com/security/?p=1655">Consumer Reports urges Mac users to dump Safari, cites lack of phishing protection</a><br />
<b>05.</b> <a href="http://blogs.zdnet.com/security/?p=1657">Fake CNN news items malware campaign spreading rapidly</a><br />
<b>06.</b> <a href="http://blogs.zdnet.com/security/?p=1664">CNET's Clientside developer blog serving Adobe Flash exploits</a><br />
<b>07.</b> <a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a><br />
<b>08.</b> <a href="http://blogs.zdnet.com/security/?p=1712">Researcher discovers Nokia S40 security vulnerabilities, demands 20,000 euros to release details</a><br />
<b>09.</b> <a href="http://blogs.zdnet.com/security/?p=1717">Intel proactively fixes security flaws in its chips</a><br />
<b>10.</b> <a href="http://blogs.zdnet.com/security/?p=1723">1.5m spam emails sent from compromised University accounts</a><br />
<b>11.</b> <a href="http://blogs.zdnet.com/security/?p=1741">Fortune 500 companies use of email spoofing countermeasures declining</a><br />
<b>12.</b> <a href="http://blogs.zdnet.com/security/?p=1743">China busts hacking ring, managed to penetrate 10 gov't databases</a><br />
<b>13.</b> <a href="http://blogs.zdnet.com/security/?p=1750">Scammers caught backdooring chip and PIN terminals</a><br />
<b>14.</b> <a href="http://blogs.zdnet.com/security/?p=1754">SpamZa - opt in spamming service fighting to remain online</a><br />
<b>15.</b> <a href="http://blogs.zdnet.com/security/?p=1765">FEMA's PBX network hacked, over 400 calls made to the Middle East</a><br />
<b>16.</b> <a href="http://blogs.zdnet.com/security/?p=1782">Typosquatting the U.S presidential election - a security risk?</a><br />
<b>17.</b> <a href="http://blogs.zdnet.com/security/?p=1788">Hundreds of Dutch web sites hacked by Islamic hackers</a><br />
<b>18.</b> <a href="http://blogs.zdnet.com/security/?p=1796">Twitter's "me too" anti-spam strategy</a><br />
<b>19.</b> <a href="http://blogs.zdnet.com/security/?p=1806">Malware detected at the International Space Station</a><br />
<b>20.</b> <a href="http://blogs.zdnet.com/security/?p=1814">Taiwan busts hacking ring, 50 million personal records compromised</a><br />
<b>21.</b> <a href="http://blogs.zdnet.com/security/?p=1815">MSN Norway serving Flash exploits through malvertising</a><br />
<b>22.</b> <a href="http://blogs.zdnet.com/security/?p=1835">Inside India's CAPTCHA solving economy</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=q40d6L"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=q40d6L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7EXTjL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7EXTjL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=E4X5Il"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=E4X5Il" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZxvQTl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZxvQTl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8PfjsL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8PfjsL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bOWuvL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bOWuvL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RGgc1l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RGgc1l" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/383219682" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 03:40:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgia cyber attack">georgia cyber attack</category>
      <category domain="http://securityratty.com/tag/adobe flash exploits">adobe flash exploits</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/flash exploits">flash exploits</category>
      <category domain="http://securityratty.com/tag/undetectable malware">undetectable malware</category>
      <category domain="http://securityratty.com/tag/inside india">inside india</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/million personal records">million personal records</category>
      <category domain="http://securityratty.com/tag/clientside developer blog">clientside developer blog</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/383219682/summarizing-zero-days-posts-for-august.html">Summarizing Zero Day's Posts for August</source>
    </item>
    <item>
      <title><![CDATA[VMware releases batch of updates]]></title>
      <link>http://securityratty.com/article/4378c97580462304969454b0e3b39083</link>
      <guid>http://securityratty.com/article/4378c97580462304969454b0e3b39083</guid>
      <description><![CDATA[VMware is out with a batch of fixes for its systems that includes a new ActiveX control update designed to quell security issues related to Internet Explorer and updates for a range of other issues....]]></description>
      <content:encoded><![CDATA[VMware is out with a batch of fixes for its systems that includes a new ActiveX control update designed to quell security issues related to Internet Explorer and updates for a range of other issues. Pidgin users should take heed and download the latest version of the open source IM client after the latest warning from The Zero Day Initiative about a flaw in the MSN chat protocol. And iPhone users will have to wait at least a few more days for a fix from Apple for the little flaw that allows locked iPhones to be opened with a few easy button pushes.]]></content:encoded>
      <pubDate>Sun, 31 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/issues">issues</category>
      <category domain="http://securityratty.com/tag/quell security issues">quell security issues</category>
      <category domain="http://securityratty.com/tag/easy button pushes">easy button pushes</category>
      <category domain="http://securityratty.com/tag/msn chat protocol">msn chat protocol</category>
      <category domain="http://securityratty.com/tag/pidgin users">pidgin users</category>
      <category domain="http://securityratty.com/tag/internet explorer">internet explorer</category>
      <category domain="http://securityratty.com/tag/flaw">flaw</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/day initiative">day initiative</category>
      <source url="http://www.networkworld.com/newsletters/bug/2008/090108bug1.html?fsrc=rss-security">VMware releases batch of updates</source>
    </item>
    <item>
      <title><![CDATA[Malware Served Through Flash Exploits By MSN Norway]]></title>
      <link>http://securityratty.com/article/c25b79517171b86fca0e1805e842d70e</link>
      <guid>http://securityratty.com/article/c25b79517171b86fca0e1805e842d70e</guid>
      <description><![CDATA[Morten Krakvik from the Norwegian Honeynet Project is reporting that MSN Norway is among the latest victims of malvertising, a practice where a bogus advertising provider tricks leading portals into...]]></description>
      <content:encoded><![CDATA[Morten Krakvik from the Norwegian Honeynet Project is reporting that MSN Norway is among the latest victims of malvertising, a practice where a bogus advertising provider tricks leading portals into accepting advertisements from its network, which often end up redirecting to live exploit URLs. The recent wave of malvertising that also targeted Digg, MSNBC and [...]]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 13:02:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/msn norway">msn norway</category>
      <category domain="http://securityratty.com/tag/norwegian honeynet project">norwegian honeynet project</category>
      <category domain="http://securityratty.com/tag/live exploit urls">live exploit urls</category>
      <category domain="http://securityratty.com/tag/recent wave">recent wave</category>
      <category domain="http://securityratty.com/tag/provider tricks">provider tricks</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/victims">victims</category>
      <category domain="http://securityratty.com/tag/msnbc">msnbc</category>
      <category domain="http://securityratty.com/tag/portals">portals</category>
      <source url="http://cyberinsecure.com/malware-served-through-flash-exploits-by-msn-norway/">Malware Served Through Flash Exploits By MSN Norway</source>
    </item>
    <item>
      <title><![CDATA[Fake IE 7 Update Spam Installs Malware]]></title>
      <link>http://securityratty.com/article/4a83e9491aa7f732cbdd0af9b8dec6fa</link>
      <guid>http://securityratty.com/article/4a83e9491aa7f732cbdd0af9b8dec6fa</guid>
      <description><![CDATA[Another round of fake authority email has been launched, this time it is a bogus Internet Explorer 7 (IE7) update spam. Here is a current version of the email (it will probably change a bit soon):...]]></description>
      <content:encoded><![CDATA[Another round of fake &#8220;authority&#8221; email has been launched, this time it is a bogus Internet Explorer 7 (IE7) update spam. Here is a current version of the email (it will probably change a bit soon):
From: admin@microsoft.com
Subject: Internet Explorer 7
Message: You are receiving this e-mail because you subscribed to MSN Featured Offers. Microsoft respects your [...]]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 06:00:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/internet explorer">internet explorer</category>
      <category domain="http://securityratty.com/tag/bogus internet explorer">bogus internet explorer</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/fake authority email">fake authority email</category>
      <category domain="http://securityratty.com/tag/microsoft respects">microsoft respects</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/current version">current version</category>
      <category domain="http://securityratty.com/tag/bit">bit</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <source url="http://cyberinsecure.com/fake-ie-7-update-spam-installs-malware/">Fake IE 7 Update Spam Installs Malware</source>
    </item>
    <item>
      <title><![CDATA[Automated Spim on Microblogging Site Via MSN Messenger]]></title>
      <link>http://securityratty.com/article/e5a1fb1ee8285e5dda0e9ae590ea20f2</link>
      <guid>http://securityratty.com/article/e5a1fb1ee8285e5dda0e9ae590ea20f2</guid>
      <description><![CDATA[There's been a fair amount of Twitter coverage recently, but it's worth noting that other countries have their own versions of Twittering and some of them have seem to be a little easier to use in...]]></description>
      <content:encoded><![CDATA[
        There's been a fair amount of <a href="http://blogs.zdnet.com/security/?p=1640">Twitter coverage</a> recently, but it's worth noting that other countries have their own versions of Twittering and some of them have seem to be a little easier to use in conjunction with Instant Messaging, whereas Twitter still seems to have a need for <a href="http://www.twittermsn.com/">third party services</a>, <a href="http://kunal.kundaje.net/twessenger/">add-ins</a> and <a href="http://www.theyagar.com/2008/01/30/twitter-bot-for-yahoo/">other tools</a> to get the job done if the service used is something other than Google Talk, Livejournal Chat or Jabber (if it's now more straightforward for other clients too, please let me know!)<br /><br />Either way, the below illustrates why adding Instant Messaging features to services such as Twitter can cause problems in the long run and needs to be considered carefully.<br /><br />We were alerted to the fact that a large amount of Spam seemed to be coming out of China in the last day or two (indeed, one contact mentioned to me that this particular message had been sent to their Honeypot around 29,000+ times, which is a lot of spamming for one URL however you look at it). The spam in question seemed to have been sent via a Spambot, and the only mentions of this URL so far in search engines seems to be related to China - shall we take a look?<br /><br />The URL in question (with part of it redacted) is<br /><br />http: //5834******/ ;)<br /><br />You'll notice the spam is short, snappy and also includes a little smiley-face thing at the end. In fact, it looks a little bit like the kind of link people send to their contacts on Twitter, doesn't it?<br /><br />Well, let's see - a quick search and we find this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fanf1.html" onclick="window.open('http://blog.spywareguide.com/images/fanf1.html','popup','width=780,height=584,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fanf1-thumb-380x284.jpg" alt="fanf1.jpg" class="mt-image-none" style="" height="284" width="380" /></a></span>
<br /><br />Click to Enlarge<br /></div><br />A page from Fanfou.com, which I believe is a Chinese site "<a href="http://www.twittown.com/fanfou">inspired</a>" by Twitter with much of the same features and functionality. In fact, it has one feature working straight off the bat that Twitter users previously had to rely on <a href="http://kunal.kundaje.net/twessenger/">plugins</a> for - the ability to send messages to their page via MSN Messenger updates.<br /><br />http: //5834****** doesn't actually resolve anywhere - however, a quick Ping to that address and we have an IP:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fanf3.html" onclick="window.open('http://blog.spywareguide.com/images/fanf3.html','popup','width=452,height=212,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fanf3-thumb-352x165.jpg" alt="fanf3.jpg" class="mt-image-none" style="" height="165" width="352" /></a></span>
<br /><br />Click to Enlarge<br /></div><br />Type the IP address into the browser, and via some geolocational technology, you'll see a region specific version of the following dating website:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fanf4.html" onclick="window.open('http://blog.spywareguide.com/images/fanf4.html','popup','width=780,height=564,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fanf4-thumb-380x274.jpg" alt="fanf4.jpg" class="mt-image-none" style="" height="274" width="380" /></a></span>
<br /><br />Click to Enlarge<br /></div><br />Go back to the page on Fanfou.com, scroll down and select any of the clickable links and surprise - the same page appears. This particular account on Fanfou has something like 30+ pages devoted to endless Spim links via MSN. They link to placeholder pages, sites that look as though they've been suspended and / or deleted with no way to determine what content was there previously - all interspersed with "Twitter" style messages throughout such as this:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fanf5.jpg" src="http://blog.spywareguide.com/images/fanf5.jpg" class="mt-image-none" style="" height="27" width="208" /></span>
<br /><br />Again, note everything is coming via MSN. By this point, you're probably wondering exactly how they allow you to send messages to their Twitter-style pages. Well, the solution is quite clever - check out the <a href="http://help.fanfou.com/im.html">IM page</a>. You enter your MSN address, and when you login to your MSN account, you'll suddenly find you have a new IM buddy who wants to be a contact:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fanf6.jpg" src="http://blog.spywareguide.com/images/fanf6.jpg" class="mt-image-none" style="" height="189" width="475" /></span>
<br /><br />Add it, and whenever you want to put a message on your page, send it an <a href="http://blog.spywareguide.com/image/fanf7.jpg">instant message</a> and, lo and behold, your Tweet-style message has appeared on your page:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fanf8.html" onclick="window.open('http://blog.spywareguide.com/images/fanf8.html','popup','width=541,height=241,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fanf8-thumb-341x151.jpg" alt="fanf8.jpg" class="mt-image-none" style="" height="151" width="341" /></a></span><br /><br />Click to Enlarge<br /></div><br />In conclusion, the steps here appear to be<br /><br /><b>1)</b> Create a Spambot that infects users via MSN Messenger<br /><b>2)</b> Tailor the messages it sends to be short and sweet, just like a Twitter-style message<br /><b>3)</b> Set up an account on a service such as Fanfou.com that makes it easy to send messages to your page via MSN Messenger (or other IM services affected by your bot)<br /><b>4)</b> Infect the PC running your MSN Messenger account then watch as it spams the userpage with whatever messages you want it to send.<br /><br />Of course, the links can be anything from dating sites and ringtone adverts to infection files and exploits - all made so much more easier (and far less time consuming than manually typing in URLs to your userpage) by the functionality built into the site you happen to be using. It's also worth noting that the accounts sending the Spim don't <i>have</i> to be set up by the spammer - they could be compromised accounts that had been hijacked when clicking a rogue IM link, which is a great way of filling out the spamming ranks very quickly.<br /><br />This is definitely something Twitter - and any other site out there involved in <a href="http://en.wikipedia.org/wiki/Micro-blogging">microblogging</a> - need to keep an eye out for, and consider carefully when thinking of adding integration with popular Instant Messaging clients.<br /><br />We detect the file sending the weblinks via MSN as <a href="http://www.spywareguide.com/product_show.php?id=32320">Foubot</a>.<br /><br />Research and Writeup: Christopher Boyd, Director of Malware Research<br />Additional Research: Chris Mannon, Senior Threat Researcher<br /><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 17:12:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/msn messenger">msn messenger</category>
      <category domain="http://securityratty.com/tag/msn">msn</category>
      <category domain="http://securityratty.com/tag/message">message</category>
      <category domain="http://securityratty.com/tag/msn messenger account">msn messenger account</category>
      <category domain="http://securityratty.com/tag/twitter-style message">twitter-style message</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/msn account">msn account</category>
      <category domain="http://securityratty.com/tag/twitter-style pages">twitter-style pages</category>
      <category domain="http://securityratty.com/tag/pages">pages</category>
      <source url="http://blog.spywareguide.com/2008/08/automated-spim-on-microbloggin.html">Automated Spim on Microblogging Site Via MSN Messenger</source>
    </item>
    <item>
      <title><![CDATA[Fake IE7 Downloads Advertised Via EMail]]></title>
      <link>http://securityratty.com/article/755f51ea3a49474a6d4b3ee71d21215c</link>
      <guid>http://securityratty.com/article/755f51ea3a49474a6d4b3ee71d21215c</guid>
      <description><![CDATA[There seem to be quite a few of these in circulation over the past day or so

Download the latest version

About this mailing
You are receiving this e-mail because you subscribed to
MSN Featured...]]></description>
      <content:encoded><![CDATA[
        There seem to be quite a few of these in circulation over the past day or so:<br /><br /><i>Download the latest version! &lt;URL Removed&gt; <br /><br />About this mailing: <br />You are receiving this e-mail because you subscribed to<br />MSN Featured Offers. Microsoft respects your privacy.<br />If you do not wish to receive this MSN Featured Offers e-mail,<br />please click the "Unsubscribe" link below. This will not<br />unsubscribe you from e-mail communications from third-party<br />advertisers that may appear in MSN Feature Offers.<br />This shall not constitute an offer by MSN. MSN shall<br />not be responsible or liable for the advertisers' content<br />nor any of the goods or service advertised. Prices and item<br />availability subject to change without notice.<br /><br />2008 Microsoft | Unsubscribe &lt;http://www.msn.com&gt;&nbsp; |<br />More Newsletters &lt;http://www.msn.com&gt;&nbsp; |<br />Privacy &lt;http://www.msn.com&gt; <br /><br />Microsoft Corporation, One Microsoft Way, Redmond, WA 98052</i><br /><br />As you might have guessed, it's fake. Microsoft don't send out EMails asking you to download files from random, non-Microsoft websites. This:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="ie71.jpg" src="http://blog.spywareguide.com/images/ie71.jpg" class="mt-image-none" style="" height="63" width="76" /></span></div><br /> <div>....is not what it appears to be. Run the file, and instead of IE7, you're actually more likely to see a fake antivirus program appear on your desktop:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/top106.html" onclick="window.open('http://blog.spywareguide.com/images/top106.html','popup','width=700,height=540,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/top106-thumb-300x231.jpg" alt="top106.jpg" class="mt-image-none" style="" height="231" width="300" /></a></span>
<br /><br />Click to Enlarge<br /></div><br />This particular fake AV is also being pushed quite heavily via the recent <a href="http://blog.spywareguide.com/2008/08/cnn-daily-top-10-videos-spam.html">CNN videos scam</a>. You can see another example of these emails <a href="http://miekiemoes.blogspot.com/2008/08/beware-of-fake-email-from-microsoft.html">here</a>. There is more than one URL being used for this attack, so be alert!<br /></div>
        
    ]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 10:56:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/offers">offers</category>
      <category domain="http://securityratty.com/tag/offers e-mail">offers e-mail</category>
      <category domain="http://securityratty.com/tag/fake">fake</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/non-microsoft websites">non-microsoft websites</category>
      <category domain="http://securityratty.com/tag/msn feature offers">msn feature offers</category>
      <category domain="http://securityratty.com/tag/msn">msn</category>
      <category domain="http://securityratty.com/tag/microsoft corporation">microsoft corporation</category>
      <category domain="http://securityratty.com/tag/microsoft respects">microsoft respects</category>
      <source url="http://blog.spywareguide.com/2008/08/fake-ie7-downloads-advertised.html">Fake IE7 Downloads Advertised Via EMail</source>
    </item>
    <item>
      <title><![CDATA[An "Aw3s0me" Offer?]]></title>
      <link>http://securityratty.com/article/a01a803d8e6e34d9dd9658cbc7dd24b9</link>
      <guid>http://securityratty.com/article/a01a803d8e6e34d9dd9658cbc7dd24b9</guid>
      <description><![CDATA[Yes, it's time for our regular &quot;sites to avoid&quot; update with regards URLs related to this ring of sites asking for MSN login details. Yesterday evening, I received this via MSN




Interestingly, this...]]></description>
      <content:encoded><![CDATA[
        Yes, it's time for our regular "sites to avoid" update with regards URLs related to <a href="http://blog.spywareguide.com/2008/06/another-site-asking-for-msn-lo.html">this ring of sites</a> asking for MSN login details. Yesterday evening, I received this via MSN:<br /><br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="awesomeoffer1.jpg" src="http://blog.spywareguide.com/images/awesomeoffer1.jpg" class="mt-image-none" style="" height="164" width="394" /></span>
<br /><br />Interestingly, this is the first site I've seen promoted on MSN related to this where the site being pushed isn't asking for your login details. Instead, it cycles through a bunch of adverts &amp; promotions instead. Rather worryingly, the domain has been flagged for Phishing.<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/awesomeoffer2.html" onclick="window.open('http://blog.spywareguide.com/images/awesomeoffer2.html','popup','width=967,height=482,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/awesomeoffer2-thumb-367x182.jpg" alt="awesomeoffer2.jpg" class="mt-image-none" style="" height="182" width="367" /></a></span><br /> </div><div><div align="center"><br />Click to Enlarge<br /></div><br />In what might be a departure for these websites, there appears to be "real" <a href="http://whois.domaintools.com/aw3s0me-offer.com">Whois data</a> listed for the URL, as opposed the "privacy protected" details I seem to remember being used for all the others.<br /><br />Registrant Contact:<br />&nbsp;&nbsp; TST Management, Inc<br />&nbsp;&nbsp; Jeff Fisher <br />&nbsp;&nbsp; <br />&nbsp;&nbsp; Edificio Magna Corp. 5th Floor, Office 511<br />&nbsp;&nbsp; Ave. Manuel Maria Icaza y Calle 51<br />&nbsp;&nbsp; Panama City, Panama 0000<br />&nbsp;&nbsp; PA<br /><br />I'm sure there'll be another chapter in this ongoing saga soon.<br /></div><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 12:52:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/msn login details">msn login details</category>
      <category domain="http://securityratty.com/tag/login details">login details</category>
      <category domain="http://securityratty.com/tag/msn">msn</category>
      <category domain="http://securityratty.com/tag/manuel maria icaza">manuel maria icaza</category>
      <category domain="http://securityratty.com/tag/panama city">panama city</category>
      <category domain="http://securityratty.com/tag/panama">panama</category>
      <category domain="http://securityratty.com/tag/edificio magna corp">edificio magna corp</category>
      <category domain="http://securityratty.com/tag/tst management">tst management</category>
      <source url="http://blog.spywareguide.com/2008/08/an-aw3s0me-offer.html">An "Aw3s0me" Offer?</source>
    </item>
    <item>
      <title><![CDATA[Another Site Asking For MSN Login Credentials....]]></title>
      <link>http://securityratty.com/article/c889cbec565471888183b6a532f63e94</link>
      <guid>http://securityratty.com/article/c889cbec565471888183b6a532f63e94</guid>
      <description><![CDATA[Yep, here's another one of these things

This time round, the site is called

whosthatt(dot)com

and it popped up a message to one of my testing accounts a little earlier on. So there, there's nothing...]]></description>
      <content:encoded><![CDATA[
        Yep, here's another one of <a href="http://blog.spywareguide.com/2008/06/another-site-asking-for-msn-lo.html">these things</a>.<br /><br />This time round, the site is called<br /><br />whosthatt(dot)com<br /><br />and it popped up a message to one of my testing accounts a little earlier on. So there, there's nothing in Google save for <a href="http://translate.google.co.uk/translate?hl=en&amp;sl=it&amp;u=http://it.answers.yahoo.com/question/index%3Fqid%3D20080731032031AA2mYbY&amp;sa=X&amp;oi=translate&amp;resnum=2&amp;ct=result&amp;prev=/search%3Fq%3Dwhosthatt.com%26hl%3Den%26client%3Dfirefox-a%26rls%3Dorg.mozilla:en-US:official%26hs%3DJqs">this one entry</a>. Remember, kids - just say no...<br /> 
        
    ]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 09:19:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/time round">time round</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/google save">google save</category>
      <category domain="http://securityratty.com/tag/entry">entry</category>
      <category domain="http://securityratty.com/tag/kids">kids</category>
      <category domain="http://securityratty.com/tag/remember">remember</category>
      <category domain="http://securityratty.com/tag/whosthatt">whosthatt</category>
      <category domain="http://securityratty.com/tag/message">message</category>
      <category domain="http://securityratty.com/tag/yep">yep</category>
      <source url="http://blog.spywareguide.com/2008/07/another-site-asking-for-msn-lo-1.html">Another Site Asking For MSN Login Credentials....</source>
    </item>
  </channel>
</rss>
