<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: net]]></title>
    <link>http://securityratty.com/tag/net</link>
    <description></description>
    <pubDate>Tue, 24 Jun 2008 02:08:15 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Meet ratproxy, our passive web security assessment tool]]></title>
      <link>http://securityratty.com/article/bc78dd4116c64ea5b3a05fa82e188ff7</link>
      <guid>http://securityratty.com/article/bc78dd4116c64ea5b3a05fa82e188ff7</guid>
      <description><![CDATA[Posted by Michal Zalewski

We're happy to announce that we've just open-sourced ratproxy , a passive web application security assessment tool that we've been using internally at Google. This utility,...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Posted by Michal Zalewski</span><br /><br />We're happy to announce that we've just open-sourced <a href="http://code.google.com/p/ratproxy">ratproxy</a>, a passive web application security assessment tool that we've been using internally at Google. This utility, developed by our information security engineering team, is designed to transparently analyze legitimate, browser-driven interactions with a tested web property and automatically pinpoint, annotate, and prioritize potential flaws or areas of concern.  <br /><br />The proxy analyzes problems such as cross-site script inclusion threats, insufficient cross-site request forgery defenses, caching issues, cross-site scripting candidates, potentially unsafe cross-domain code inclusion schemes and information leakage scenarios, and much more. (A more-detailed discussion of these features and information on securing vulnerable applications is provided <a href="http://code.google.com/p/ratproxy/wiki/RatproxyDoc">here</a>.) Compared with more-traditional active crawlers, or with fully manual request inspection and modification frameworks, this approach offers several significant advantages in terms of minimized overhead; marginalized risk of site disruptions; high coverage of complex, client-driven application states in web 2.0 solutions; and insight into dynamic cross-domain trust models.<br /><br />We decided to make this tool freely available as open source because we feel it will be a valuable contribution to the information security community, helping advance the community's understanding of security challenges associated with contemporary web technologies. We believe that responsible security research brings a net overall benefit to the safety of the Web as a whole, and have released this tool explicitly to support that kind of research.<br /><br />To download the proxy, please visit this <a href="http://ratproxy.googlecode.com/files/ratproxy-1.50.tar.gz">page</a>. Also, please keep in mind that the proxy is designed solely to highlight interesting patterns in web applications, and a further analysis by a security professional is often required to interpret the results and their significance for the tested platform.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=cTCU6J"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=cTCU6J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=K3C5fj"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=K3C5fj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/324447250" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 12:49:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information leakage scenarios">information leakage scenarios</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/contemporary web technologies">contemporary web technologies</category>
      <category domain="http://securityratty.com/tag/information security community">information security community</category>
      <category domain="http://securityratty.com/tag/web property">web property</category>
      <category domain="http://securityratty.com/tag/community">community</category>
      <category domain="http://securityratty.com/tag/web applications">web applications</category>
      <source url="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~3/324447250/meet-ratproxy-our-passive-web-security.html">Meet ratproxy, our passive web security assessment tool</source>
    </item>
    <item>
      <title><![CDATA[Montgomery Ward breached, no notification obligation?]]></title>
      <link>http://securityratty.com/article/d0a7010fb8fd83b7750424b96154c42b</link>
      <guid>http://securityratty.com/article/d0a7010fb8fd83b7750424b96154c42b</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/27/08

Organization
Direct Marketing Services Inc

Contractor/Consultant/Branch
Montgomery Ward
HomeVisions.com
SearsHomeCenter.com
SearsShowPlace.com...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/wards.jpg" width="200" align="right" height="50"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/27/08<br><br><span style="font-weight: bold;">Organization: </span><br>Direct Marketing Services Inc.<br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.wards.com/wards/default.asp">Montgomery Ward</a> <br><a href="http://www.homevisions.com/hvprod/Default.asp">HomeVisions.com</a> <br><a href="http://www.searshomecenter.com/homecenter/default.asp">SearsHomeCenter.com</a> <br><a href="http://www.searsshowplace.com/showplace/default.asp">SearsShowPlace.com</a> <br><a href="http://www.searsroomforkids.com/roomforkids/default.asp?partner=0">SearsRoomForKids.com</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>"at least 51,000 records"<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses, phone numbers, card numbers, "security codes", and expiration dates<br><br><span style="font-weight: bold;">Breach Description:</span><br>"NEW YORK (AP) -- The parent company of Montgomery Ward is admitting that it was hit with a credit card hack, but it didn't inform the customers affected."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://ap.google.com/article/ALeqM5hMgFbRpfc74PW0CvbF3kFbWFkHsAD91IJCHG2">The Associated Press</a> <br><a href="http://www.wztv.com/template/inews_wire/wires.national/2c50aedd-www.fox17.com.shtml">The Associated Press via WZTV Channel 17 News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The Associated Press<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>At least 51,000 records were exposed in the breach at the parent company of Montgomery Ward.<br><br>The venerable Wards chain that began in 1872 went out of business in 2001, but in 2004 a catalog company, Direct Marketing Services Inc., bought the brand name out of bankruptcy.<br><br>Direct Marketing Services' CEO, David Milgrom, said the financial company Citigroup detected the computer invasion in December.<br><br>By going through HomeVisions.com, another Direct Marketing Services site, hackers had plundered the database that holds account information for all the company's retail properties.<br><span style="font-style: italic;">[Evan] The AP story names five of the six Direct Marketing Services retail properties (See Above).&nbsp; I don't know what the sixth is.</span><br style="font-style: italic;"><br>It now runs a Wards.com Web site along with six other sites, including three with Sears brands it has acquired: SearsHomeCenter.com, SearsShowplace.com and SearsRoomforKids.com<br><br>Milgrom said Direct Marketing Services immediately informed its payment processor and Visa and MasterCard.<br><br>Direct Marketing Services closely followed a set of guidelines, issued by Visa, on how to respond to a security breach.<br><span style="font-style: italic;">[Evan] This is sad.&nbsp; The Visa documentation regarding breach response is way too narrowly focused to be used as an organizational incident response.&nbsp; Every organization that creates, collects, uses, stores, and/or transfers confidential information should have an incident response policy and accompanying procedures.&nbsp; Take a look at the Visa "</span><a style="font-style: italic;" href="http://usa.visa.com/download/merchants/cisp_what_to_do_if_compromised.pdf?it=r%7C/merchants/risk_management/cisp_if_compromised.html%7CWhat%20to%20Do%20If%20Compromised">What To Do if Compromised</a><span style="font-style: italic;">" procedures, and judge for yourself.</span><br style="font-style: italic;"><br>That included a report to the U.S. Secret Service.<br><br>He said he believed by the end of December that Direct Marketing Services had met its obligations.<br><span style="font-style: italic;">[Evan] Mr. Milgrom is the president of the company.&nbsp; He really thought that his company had met all of its obligations with respect to this breach?&nbsp; It never occurred to him that he should notify customers, even if he weren't required to by law?&nbsp; Not only was the lack of notification illegal, but I think it is also unethical.</span><br style="font-style: italic;"><br>However, those guidelines from Visa are largely technical, and they do not cover a key additional step: that notification laws in nearly every state generally require organizations that have been hacked to come clean to the affected consumers, not just to the financial industry.<br><br>Companies that fail to comply can be hit with fines or be sued by affected customers, depending on the state<br><br>After being asked about those laws by The Associated Press, Milgrom said Direct Marketing Services now plans to contact consumers.<br><br>This hack might have stayed quiet except for online chatter detected in June by Affinion Group Inc.'s CardCops, a group of investigators who track payment-card theft for financial institutions.<br><br>In Internet chat rooms frequented by card thieves, CardCops spotted hackers touting the sale of 200,000 payment cards belonging to one merchant.<br><br>CardCops then intercepted several hundred of the records, along with the online handles belonging to hackers whose real names remain unknown.<br><br>Along with the card numbers, their three-digit "security codes" and expiration dates, the thieves had the cardholders' names, addresses and phone numbers.<br><br>The data had been organized in the same way, indicating the numbers likely came from the same database.<br><br>CardCops' president, Dan Clements, also noticed that the vast majority of the cardholders were women, a clue that the records came from a merchant catering to a certain demographic.<br><br>When he began calling them, the first eight said they had bought things online or through mail order from Montgomery Ward. At that point, Clements realized, "there's a high probability the entire database of Montgomery Ward was breached."<br><span style="font-style: italic;">[Evan] This is some good investigative work.</span><br><br>It is not clear to Clements, though, whether the hackers were inflating their claim when they offered 200,000 records or whether Milgrom's number of 51,000 is accurate.<br><span style="font-style: italic;">[Evan] According to the article, the "hackers" were able to compromise the information from all six Direct Marketing Services, Inc. properties.&nbsp; 51,000 may be Montgomery Wards customer accounts, and the remainder could be from the other five properties (just speculating).</span><br style="font-style: italic;"><br>A spokeswoman for Discover Financial Services LLC, Mai Lee Ua, said her company had addressed the problem by sending new cards to its cardholders who appeared in the compromised records.<br><br>Ua said they weren't told which merchant had been breached<br><br>Visa declined to comment.<br><span style="font-style: italic;">[Evan] Visa always declines to comment.&nbsp; No sense in even seeking one.</span><br><br>MasterCard issued a statement Friday acknowledging it was aware of the breach at Direct Marketing Services, and had notified the banks that issue MasterCards, telling them to monitor the accounts for suspicious charges.<br><span style="font-style: italic;">[Evan] Three different card companies, three entirely different responses.&nbsp; Of the three, I think I like the Discover one the best.</span><br style="font-style: italic;"><br>Such silence was the norm in the industry for years. But in response to fears of identity theft, 44 states have passed laws that generally require organizations holding consumer data to tell people when their information has leaked<br><br>Clements and other security analysts say that despite those laws, many breaches still are kept quiet, judging by the data being hawked in online black markets.<br><br>Avivah Litan, an analyst at Gartner Inc., believes unreported data breaches might still outnumber the ones that do get publicized.<br><span style="font-style: italic;">[Evan] I absolutely agree.&nbsp; You would be naïve to think that victim notifications go out in all breaches.&nbsp; Too many corporate leaders would rather not notify and hope that nobody notices.</span><br style="font-style: italic;"><br>Litan says it especially is the case with online merchants. She believes it happens because of a lack of pressure from credit card companies, which are not responsible for fraudulent charges in "card not present" transactions over the Web and mail order.<br><br>Until fraud actually appears on the card, they'd rather avoid the cost of voiding compromised cards and giving consumers new ones, she said.<br><br>"What it reveals is the convoluted banking system," she said. "If this had taken place at a grocery store, we all would have heard about it."<br><br>In fact, because of the silence that still sometimes follows data breaches, even people who have never been informed one of their records has leaked should assume their information is floating online, Litan said.<br><br>"Probably every one of our cards is up there somewhere now," she said.<br><span style="font-style: italic;">[Evan] I agree with all of the statements made by Avivah Litan except this one.&nbsp; This is a stretch.</span><br><br><span style="font-weight: bold;">On the Net:</span><br>Links to the <a href="http://www.ncsl.org/programs/lis/cip/priv/breachlaws.htm">44 state notification laws</a> <br><br><span style="font-weight: bold;">Commentary:</span><br>Is this a case of a company that was caught trying to cover up a breach, or was this a company that didn't know any better?&nbsp; </font><font size="2">I lean towards the former.&nbsp; </font><font size="2">Either way, is ignorance of the law any kind of valid excuse?&nbsp; <br><br>Let's assume for a second that company really didn't know that they were required to notify victims.&nbsp; If this were true, then this leads me to believe that the company doesn't govern information security well (due care?), probably has no formal information security program, lacks incident response policy and procedures, and doesn't manage risk well.<br><br>I could only guess how the "hack" took place.&nbsp; What vulnerability was exploited?&nbsp; Even in this, the company appears to have not detected the attack.&nbsp; </font><font size="2">Direct Marketing Services, Inc. had to be told of it by Citibank.&nbsp; </font><font size="2">Does this mean that the company did not use intrusion detection/prevention?&nbsp; <br><br>I could go on and on, but in the end I don't have much confidence here. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/27/wards.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 27 Jun 2008 19:45:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/card companies">card companies</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/services closely">services closely</category>
      <category domain="http://securityratty.com/tag/credit card companies">credit card companies</category>
      <category domain="http://securityratty.com/tag/services retail properties">services retail properties</category>
      <category domain="http://securityratty.com/tag/financial company citigroup">financial company citigroup</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/montgomery ward">montgomery ward</category>
      <source url="http://breachblog.com/2008/06/27/wards.aspx">Montgomery Ward breached, no notification obligation?</source>
    </item>
    <item>
      <title><![CDATA[Maybe the NAC used car salesman can claim them as a customer too? In NAC quality counts!]]></title>
      <link>http://securityratty.com/article/d80f68ce6e6808f9d06f6e7946e4e4a0</link>
      <guid>http://securityratty.com/article/d80f68ce6e6808f9d06f6e7946e4e4a0</guid>
      <description><![CDATA[Dark Reading had a good article today talking about GuideWorks , the TV Guide/Comcast joint venture's 2 year odyssey with NAC, which finds them finally starting to see some good results. I immediately...]]></description>
      <content:encoded><![CDATA[<p>Dark Reading had a <a href="http://www.darkreading.com/document.asp?doc_id=157719&amp;f_src=darkreading_section_296">good article today</a> talking about <a class="zem_slink" title="GuideWorks" href="http://en.wikipedia.org/wiki/GuideWorks" rel="wikipedia">GuideWorks</a>, the TV Guide/Comcast joint venture's 2 year odyssey with NAC, which finds them finally starting to see some good results. I immediately went to the website of the <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/the-used-car-sa.html">NAC used car salesman</a> to see if they claimed them as a NAC customer too, but didn't see anything yet. But with those guys you never know. <br><br>Seriously though folks, this story is a classic NAC story. GuideWorks had guests and unmanaged users visiting their offices all the time. When they would ask to plug in they were told sorry, wait till you get back to your hotel. Over time this answer became unacceptable and they realized they needed a way to give these people a way to get on the net and get their email while keeping their network secure. This very same need drives many initial NAC deployments.<br><br>Like many other NAC customers they wanted something easy, not add major overhead or network changes and easy to administer. Again straight out of the NAC playbook. In the Summer of '06 they began a pilot of the Tipping Point NAC product which is based on the old Roving Planet technology. Now Roving Planet was more of a wireless security company, but near the end they rebranded themselves as NAC and Tipping Point uses that with their IPS devices to enforce. Best of all for GuideWorks the price was sub 10k. <br><br>Here is where the other side of NAC comes in. This is what the article says:</p><blockquote><p><em><p>While NAC tools are often advertised as plug-and-play, GuideWorks found that the NAC setup required a high level of networking expertise. Fortunately, the Inglewood site had plenty of technical expertise because that’s where many of the company’s developers are stationed. In addition, GuideWorks put one of its front-desk employees in charge of setting up new accounts. But because her technical background was limited, the company had to walk her through a learning curve. </p>

<p>Now the company is planning to deploy the system at its Radnor office, which will be a bit more challenging since there’s less technical expertise there, and that office gets a greater number of visitors. So GuideWorks has been on the search for employees to support the NAC system there. The company expects to have NAC up and running there by the end of the summer. </p></em></p>

</blockquote><p>So 2 years after trial they are rolled out in one office and have to hire employees to support the NAC system at the next office. This was a problem with many of the failed NAC companies over the last few years and I think the problem with this Tipping Point solution. Just providing guest access should not be that hard! Yes the StillSecure Safe Access solution would have been much easier and faster to implement, but to be fair, any of the leading NAC solutions would have been up and running easier as well. </p>

<p>While this article was supposed to serve as reference and case study for the Tipping Point NAC solution, it is far from inspiring. If I were a customer looking into NAC, I don't think this would make run out and look at the Tipping Point solution. Moral of the story is, just because you made a good IPS doesn't mean you have a very good NAC product. When it comes to something like NAC, quality counts and buying a 2nd tier solution can cost you in time to implementation and total cost of ownership.</p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/2c864e8d-b43a-4e14-9fdc-9ac4835bc27b/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_a.png?x-id=2c864e8d-b43a-4e14-9fdc-9ac4835bc27b" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none"></img></a></div>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=ia7VDL"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=ia7VDL" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=bjKsGI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=bjKsGI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=DxCrYI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=DxCrYI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=YQ1SAI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=YQ1SAI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=wD2I6I"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=wD2I6I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=FSLeNi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=FSLeNi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=2QntYi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=2QntYi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/321785853" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 27 Jun 2008 19:36:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/customer">customer</category>
      <category domain="http://securityratty.com/tag/nac solution">nac solution</category>
      <category domain="http://securityratty.com/tag/nac solutions">nac solutions</category>
      <category domain="http://securityratty.com/tag/nac tools">nac tools</category>
      <category domain="http://securityratty.com/tag/nac setup">nac setup</category>
      <category domain="http://securityratty.com/tag/initial nac deployments">initial nac deployments</category>
      <category domain="http://securityratty.com/tag/nac playbook">nac playbook</category>
      <category domain="http://securityratty.com/tag/nac companies">nac companies</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/321785853/maybe-the-nac-u.html">Maybe the NAC used car salesman can claim them as a customer too? In NAC quality counts!</source>
    </item>
    <item>
      <title><![CDATA[Hackers Hijack ICANN And IANAs Domains]]></title>
      <link>http://securityratty.com/article/626c885d9a2c4cb63c71eff35cf382a2</link>
      <guid>http://securityratty.com/article/626c885d9a2c4cb63c71eff35cf382a2</guid>
      <description><![CDATA[The official domains of ICANN, the Internet Corporation for Assigned Names and Numbers, and IANA, the Internet Assigned Numbers Authority were hijacked earlier today, by the NetDevilz Turkish hacking...]]></description>
      <content:encoded><![CDATA[The official domains of ICANN, the Internet Corporation for Assigned Names and Numbers, and IANA, the Internet Assigned Numbers Authority were hijacked earlier today, by the NetDevilz Turkish hacking group which also hijacked Photobucket domain on the 18th of June.
The domains that were hijacked are icann.net, icann.com, iana-servers.com, internetassignednumbersauthority.com, iana.com.
ICANN is responsible for the global [...]]]></content:encoded>
      <pubDate>Fri, 27 Jun 2008 08:03:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/icann">icann</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/iana-servers">iana-servers</category>
      <category domain="http://securityratty.com/tag/iana">iana</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/official domains">official domains</category>
      <category domain="http://securityratty.com/tag/internet corporation">internet corporation</category>
      <category domain="http://securityratty.com/tag/netdevilz turkish">netdevilz turkish</category>
      <category domain="http://securityratty.com/tag/photobucket domain">photobucket domain</category>
      <source url="http://cyberinsecure.com/hackers-hijack-icann-and-iana%e2%80%99s-domains/">Hackers Hijack ICANN And IANAs Domains</source>
    </item>
    <item>
      <title><![CDATA[Sun Is A Magic Formula Stock]]></title>
      <link>http://securityratty.com/article/da46fde2d833408a245a9676ecdb7060</link>
      <guid>http://securityratty.com/article/da46fde2d833408a245a9676ecdb7060</guid>
      <description><![CDATA[http://www.magicformulainvesting.comIn his book &quot;The Little Book that Beats t he Market&quot;, Joel Greenblatt presents a formula for investing in companies based on two factors. The factors are from two...]]></description>
      <content:encoded><![CDATA[<p><a style="float: left;" href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e5538f07588834-pi"><img  class="at-xid-6a00d83451c75869e200e5538f07588834 " alt="Buy_book" src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e5538f07588834-120wi" style="margin: 0px 5px 5px 0px;"></a>
http://www.magicformulainvesting.comIn his book <a href="http://www.magicformulainvesting.com">"The Little Book that Beats t</a>he Market", Joel Greenblatt presents a formula for investing in companies based on two factors. The factors are from two of the most influential people in teaching investors how to think about investing - Ben Graham and Warren Buffett. From Graham, Greenblatt takes the concept of price, specifically looking for cheap stocks not necessarily great companies, just a great price (Graham famously called these "cigar butts"); from Buffett &amp; Munger, Greenblatt uses the concept of looking for good companies.</p><br><div>The stocks are evaluated on price via an inverse P/E calculation; and "good" companies are defined as those earning a high return on capital. Then in true value investing style (i.e. not over-complicated), Greenblatt combines the two factors using a simple 50/50 format. So all companies are rated by price and quality, if your company comes up 11 on price and 27 on quality then it gets a 38. His book goes into more details, and you can use this <a href="http://www.magicformulainvesting.com">website</a> to screen for companies.</div><br><div><blockquote><p>What do you think would happen if we simply decided to buy shares in companies that had <span style="font-style: italic;">both</span> a high earnings yield and a high return on capital? In other words, <span style="font-style: italic;">what would happen if we decided to only buy shares in good businesses (ones with high returns on capital) but only when they were available at bargain prices (priced to give us a high earnings yield)</span>? What would happen? Well, I'll tell you what would happen: <span style="font-style: italic;">We would make a lot of money!</span> (Or as Graham might put it, "The profits would be <span style="font-style: italic;">quite satisfactory!</span>")</p></blockquote></div><br><div>A lot of the time you find pretty boring companies doing something profitable and necessary, but not too exciting. There are generally not very many tech companies on the list - Microsoft is there now because of the Yahoo stuff, Microstrategy has been there for awhile, and now we have Sun (<a href="http://finance.google.com/finance?q=java">JAVA</a>) there as well.</div><br><div>Being on the Magic Formula list is not necessarily a good thing for your present stock price. It means you are being beat up, fairly on unfairly going forward is the question. Greenblatt's formula suggests its worth looking at Sun's potential going forward. Their P/E is 15 (for comparison <a href="http://finance.google.com/finance?q=orcl&amp;hl=en">Oracle's</a> is 22 and <a href="http://finance.google.com/finance?q=rht">Red Hat's</a> in 59!), good news for Sun shareholders is the company continues to make money. One problem seems to be margins - Sun is earning 4.6% net profit margins whereas Oracle and Red Hat are at 24% and 14% respectively. Of course, in general margins on hardware are not generally as good and Oracle and Red Hat are software plays. </div><br><div>In any case Schwartz seems to be doing some smart things and positioning Sun for quite satisfactory returns. Sun's Price/Book ratio is just above 1.5 which makes a value investor sit up and take notice. A pretty impressive <a href="http://www.gurufocus.com/StockBuy.php?symbol=JAVA">list</a> of investors, notably Mason Hawkins, has been buying in. As much as Sun has struggled with its post-dotcom identity, it is rare to see a company with this much upside on the Greenblatt list.</div><br><div>Anyhow, Sun's residency on the Greenblatt is not a good thing for the company this instant. It could mean good opportunities for them and investors going forward - after all its a list of good companies selling at cheap prices. I have no position in any of the companies mentioned, and I have no business giving people investing advice, but I am interested observer. If you are thinking of buying JAVA based on Greenblatt's quantitative methods, read his book first to understand how to manage risk in his methodology. In any case I wholeheartedly recommend Greenblatt's book, its short, and packed with good stuff.</div>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 14:29:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/greenblatt">greenblatt</category>
      <category domain="http://securityratty.com/tag/greenblatt list">greenblatt list</category>
      <category domain="http://securityratty.com/tag/sun">sun</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/companies based">companies based</category>
      <category domain="http://securityratty.com/tag/greenblatt takes">greenblatt takes</category>
      <category domain="http://securityratty.com/tag/formula">formula</category>
      <category domain="http://securityratty.com/tag/tech companies">tech companies</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/06/sun-is-a-magic-formula-stock.html">Sun Is A Magic Formula Stock</source>
    </item>
    <item>
      <title><![CDATA[Right Wing Israeli Hackers Deface Hamas's Site]]></title>
      <link>http://securityratty.com/article/71489cb3d193dd4338009c34bae2a95e</link>
      <guid>http://securityratty.com/article/71489cb3d193dd4338009c34bae2a95e</guid>
      <description><![CDATA[Compared to historical hacktivism tensions between different nations, Israeli and Palestinian hacktivists seem to be most sensitive to &quot;virtual fire exchange&quot; like this one, and consequently, just...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGPh9XRJWOI/AAAAAAAAB2c/i3FUgSZgHWg/s1600-h/hamas_hacked.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGPh9XRJWOI/AAAAAAAAB2c/i3FUgSZgHWg/s200/hamas_hacked.png" alt="" id="BLOGGER_PHOTO_ID_5216261237759367394" border="0" /></a>Compared to historical hacktivism tensions between different nations, <a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Israeli and Palestinian hacktivists</a> seem to be most sensitive to "virtual fire exchange" like this one, and consequently, just like in real-life, always look and find for an excuse to engage in a conflict. <a href="http://www.ynetnews.com/articles/0,7340,L-3560756,00.html">Israeli hackers penetrate Hamas website</a> :<br /><br />"<span style="font-style: italic;">Israeli hackers boasted Thursday about breaking into the website of Izz al-Din al-Qassam, Hamas’ military wing, which now displays a white screen and words in Arabic announcing technical difficulties. The hacker group, which calls itself Fanat al-Radical (the fanatical radicals), also said that it broke into additional terror organizations’ sites and those of various leftist movements.  In a Ynet interview, a group representative who refused to reveal his name said, “We searched for relevant sites with the criteria we look for, whether leftist or anti-Zionist, and looked for loopholes. Our emphasis was always on the al-Qassam site. "The criteria are defined as anti-Zionist or anti-Jewish sites that support or assist in harming Zionism and the existence of Israel as a Zionistic, Jewish state.</span>"<br /><br />The message they left :<br /><br />"<span style="font-style: italic;">Hacked by XcxooXL and FENiX from Fanat Al Radical Greets: Sn4k3 Contact: Fanat.al.Radical@gmail.com </span>"<br /><br />These script kiddies using SQL injection vulnerabilities within the affected sites, since they indeed managed to deface several other as well, seem to have also participated in the 2006 cyber conflict sparkled due to the <a href="http://www.mfa.gov.il/MFA/MFAArchive/2000_2009/2004/1/Israeli%20MIAs">the kidnapping of three soldiers</a>. One of their defacements remains still active (<span style="font-weight: bold;">aviv.perffect-x.net/deface.html</span>)<br /><br />"<span style="font-style: italic;">We will stand against the Islam until the kidnapped soldiers, Gilad Shalit, Eldad Regev and Ehod Goldvaser will be return, We will attack arabic servers and site which support the Islam and protest against the zionism</span>"<br /><br />What if every script kiddie with a SQL injection scanners goes into politics? It's a mess already.<br /><br /><span style="font-weight: bold;">Related posts:</span><br /><a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">Monetizing Web Site Defacements</a><br /><a href="http://ddanchev.blogspot.com/2008/05/pro-serbian-hacktivists-attacking.html">Pro-Serbian Hacktivists Attacking Albanian Web Sites</a><br /><a href="http://ddanchev.blogspot.com/2008/04/rise-of-kosovo-defacement-groups.html">The Rise of Kosovo Defacement Groups</a><br /><a href="http://ddanchev.blogspot.com/2008/04/commercial-web-site-defacement-tool.html">A Commercial Web Site Defacement Tool</a><br /><a href="http://ddanchev.blogspot.com/2008/04/phishing-tactics-evolving.html">Phishing Tactics Evolving</a><br /><a href="http://ddanchev.blogspot.com/2008/04/web-site-defacement-groups-going.html">Web Site Defacement Groups Going Phishing</a><br /><a href="http://ddanchev.blogspot.com/2006/02/hacktivism-tensions.html">Hacktivism Tensions</a><br /><a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a><br /><a href="http://ddanchev.blogspot.com/2007/11/mass-defacement-by-turkish-hacktivists.html">Mass Defacement by Turkish Hacktivists</a><br /><a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">Overperforming Turkish Hacktivists</a><br /><a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html"></a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ryWbnI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ryWbnI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=frccjI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=frccjI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Yec9Yi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Yec9Yi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZdpmYi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZdpmYi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BOanxI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BOanxI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XjskfI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XjskfI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MXrvxi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MXrvxi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/320791816" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 11:36:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/israeli">israeli</category>
      <category domain="http://securityratty.com/tag/israeli hackers">israeli hackers</category>
      <category domain="http://securityratty.com/tag/anti-jewish sites">anti-jewish sites</category>
      <category domain="http://securityratty.com/tag/al-qassam site">al-qassam site</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/web site defacement">web site defacement</category>
      <category domain="http://securityratty.com/tag/hacktivism tensions">hacktivism tensions</category>
      <category domain="http://securityratty.com/tag/historical hacktivism tensions">historical hacktivism tensions</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/320791816/right-wing-israeli-hackers-deface.html">Right Wing Israeli Hackers Deface Hamas's Site</source>
    </item>
    <item>
      <title><![CDATA[New Security Tools for IIS and SQL]]></title>
      <link>http://securityratty.com/article/b3892fbd49dab930356750501023c0df</link>
      <guid>http://securityratty.com/article/b3892fbd49dab930356750501023c0df</guid>
      <description><![CDATA[In cast you didn't see it, the Microsoft Security Response Center (MSRC) team just announced the release of three tools to help customers fend off SQL injection attacks
UrlScan 3.0 Beta ( see Wade...]]></description>
      <content:encoded><![CDATA[<p>In cast you didn't see it, the Microsoft Security Response Center (MSRC) team just <a href="SQL Injection Attacks Exploiting Unverified User Data Input" target="_blank">announced</a> the release of three tools to help customers fend off SQL injection attacks: <ul> <li>UrlScan 3.0 Beta (<a href="http://blogs.iis.net/wadeh/archive/2008/06/24/urlscan-v3-0-beta-release.aspx" target="_blank">see Wade Hilmo's blog for more</a>), a security tool that restricts the types of HTTP requests that Internet Information Services (IIS) will process. By blocking specific HTTP requests, the UrlScan helps prevent potentially harmful requests.</li> <li>Microsoft Source Code Analyzer for SQL Injection (MSCASI) CTP (<a href="http://blogs.msdn.com/sqlsecurity/archive/2008/06/24/microsoft-source-code-analyzer-for-sql-injection-june-2008-ctp.aspx" target="_blank">see the SQL Security blog for more</a>), a tool that can be used to detect ASP code susceptible to SQL injection attacks. </li> <li>Scrawlr (<a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2008/06/23/finding-sql-injection-with-scrawlr.aspx" target="_blank">see HP's security blog for more</a>), a free scanner, developed by HP Web Security Research Group in conjunction with Microsoft, which will allow customers to identify whether their Web sites might be susceptible to SQL injection.</li></ul> <p>There are already a lot of resources out there available already for these tools.&nbsp; Let me point you to a few of them: <ul> <li>The new Microsoft <a href="http://www.microsoft.com/technet/security/advisory/954462.mspx">Security Advisory 954462</a> announcing the tools, with guidance</li> <ul> <li><a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2008/06/23/finding-sql-injection-with-scrawlr.aspx">Finding SQL Injection with Scrawlr</a> at the <a href="http://www.communities.hp.com/securitysoftware/">HP Security Center</a></li> <li><a href="http://learn.iis.net/page.aspx/473/using-urlscan">URLScan Tool 3.0 Beta</a> page, including download links &amp; docs</li> <li>MSCASI download and reference kb: <a href="http://support.microsoft.com/kb/954476">Microsoft Knowledge Base Article 954476</a></li></ul> <li>A good <a href="http://blogs.msdn.com/sdl/archive/2008/05/15/giving-sql-injection-the-respect-it-deserves.aspx" target="_blank">discussion of Injection Attacks by Michael Howard</a> on the SDL Blog</li> <li><a href="http://blogs.technet.com/swi/archive/2008/05/29/sql-injection-attack.aspx">Security Vulnerability Research &amp; Defense Blog on SQL Injection Attack</a></li> <li>SDL blog post on the new tools: <a href="http://blogs.msdn.com/sdl/archive/2008/06/24/sql-injection-defense-tools.aspx">SQL Injection Defense Tools</a>&nbsp;</li></ul> <p>and some best practice guidance for developers:</p> <ul> <li><a href="http://msdn.microsoft.com/en-us/library/ms998271.aspx">How To: Protect from SQL Injection in ASP.NET</a></li> <li><a href="http://msdn.microsoft.com/en-us/library/cc676512.aspx" target="_blank">Preventing SQL Injections in ASP</a>, by Bala Neerumalla </li> <li><a href="http://forums.asp.net/t/1254125.aspx">Coding Techniques for protecting against SQL Injection in ASP.NET</a></li> <li><a href="http://blogs.iis.net/nazim/archive/2008/04/28/filtering-sql-injection-from-classic-asp.aspx">Filtering SQL Injection from Classic ASP</a></li></ul> <p>Best regards ~ Jeff</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3078096" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 17:45:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sdl blog post">sdl blog post</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/sql injection">sql injection</category>
      <category domain="http://securityratty.com/tag/sql injection attack">sql injection attack</category>
      <category domain="http://securityratty.com/tag/injection attacks">injection attacks</category>
      <category domain="http://securityratty.com/tag/sql injection attacks">sql injection attacks</category>
      <category domain="http://securityratty.com/tag/security blog">security blog</category>
      <category domain="http://securityratty.com/tag/defense blog">defense blog</category>
      <category domain="http://securityratty.com/tag/sdl blog">sdl blog</category>
      <source url="http://blogs.technet.com/security/archive/2008/06/25/new-security-tools-for-iis-and-sql.aspx">New Security Tools for IIS and SQL</source>
    </item>
    <item>
      <title><![CDATA[Fake Porn Sites Serving Malware]]></title>
      <link>http://securityratty.com/article/5dacf1e5b6c84c1bed4515dca8fc1199</link>
      <guid>http://securityratty.com/article/5dacf1e5b6c84c1bed4515dca8fc1199</guid>
      <description><![CDATA[Ah, that RBN with its centralization mentality for the sake of ease of management and 99.999% uptime. In this very latest example of using malicious doorways redirecting to fake porn sites, consisting...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SGJTBaqN1yI/AAAAAAAAB1k/b9O7PupnB8E/s1600-h/porn_codecs.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SGJTBaqN1yI/AAAAAAAAB1k/b9O7PupnB8E/s200/porn_codecs.JPG" alt="" id="BLOGGER_PHOTO_ID_5215822602249819938" border="0" /></a>Ah, that RBN with its centralization mentality for the sake of ease of management and 99.999% uptime. In this very latest example of using malicious doorways redirecting to fake porn sites, consisting of over twenty different domains serving the usual Zlob malware variants, we have a decent abuse of a template for a porn site.<br /><br />The easy of management of such domain farms and the availability of templates for high trafficked topic segments such as celebrities and pornography, continue contributing to the increasing number of Zlob variants served through fake codecs. Moreover, once set up, the malicious infrastructure starts attracting now just generic search traffic, but also traffic coming from affiliates with whom revenue is shared on the basis of the number of people that downloaded the codec.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGJsP6kwvTI/AAAAAAAAB1s/b0lRo5htJtE/s1600-h/fake_porn_sites_ATRIVO.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGJsP6kwvTI/AAAAAAAAB1s/b0lRo5htJtE/s200/fake_porn_sites_ATRIVO.JPG" alt="" id="BLOGGER_PHOTO_ID_5215850339125738802" border="0" /></a>In this campaign, the malicious doorway that expands the entire ecosystem is located at <span style="font-weight: bold;">search-</span><span style="font-weight: bold;">top.com/in.cgi?5&amp;parameter=drs</span> (66.96.85.113). A redirector that appears to <a href="http://www.lavasoftsupport.com/index.php?showtopic=2662">have been operating since 2006</a>, according to this forum posting.<br /><br />What follows on-the-fly, are all the fake porn sites whose legitimately looking videos attempt to download a Zlob malware variant from a single location - <span style="font-weight: bold;">vipcodec.net</span>. Here are all the fake porn sites, and the associated campaigns in this redirection :<br /><br /><span style="font-weight: bold;">watchnenjoy .com</span>/index.php?id=1287&amp;style=white<br /><span style="font-weight: bold;">craziestclips .com</span>/index.php?id=1287&amp;q=<br /><span style="font-weight: bold;">immensevids .com</span><br /><span style="font-weight: bold;">planetfreepornmovies .com</span>/?t=1&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/edmund/16551689/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/rosalyn/1742941675/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/emiline/108846601/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/inde/964842117/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/elnora/648311952/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/verge/1734135233/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/dal/1663381205/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .ne</span><span style="font-weight: bold;">t</span>/gretchen/515268975/1/&amp;id=1219<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SGJ2DJRJgoI/AAAAAAAAB10/0pUS4GVInf4/s1600-h/porn_domainfarm_codecs_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SGJ2DJRJgoI/AAAAAAAAB10/0pUS4GVInf4/s200/porn_domainfarm_codecs_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5215861114847986306" border="0" /></a><span style="font-weight: bold;">abc-adult .com</span>/lillah/1467790484/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/jenne/434165228/1/&amp;id=1219<br /><span style="font-weight: bold;">look-adult .net</span>/ette/681831796/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/mime/65729013/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/alfe/550398461/1/&amp;id=1219<br /><span style="font-weight: bold;">group-ad</span><span style="font-weight: bold;">ult .net</span>/demerias/867452637/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/rhode/167691118/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/hephsibah/1254235416/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/hence/1684651134/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/kendra/371598555/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/link/1334727639/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/flo/84660854/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/assene/875893411/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/charlotta/972714195/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/orlando/761508522/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/jemima/1405735776/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/obadiah/263904242/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/douglas/1110779475/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/lydde/1844064103/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/marcia/1627490290/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/cono/295680123/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/wes/1733468207/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/wib/648341815/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/greg/2064937302/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/maris/33184936/1/&amp;id=1219<br /><span style="font-weight: bold;">look-adult .net</span>/regina/1273816838/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/gwendolyn/869744046/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/carthaette/1021629112/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/ninell/1522355420/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/waldo/755290223/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/green/669090607/1/&amp;id=1219<br /><span style="font-weight: bold;">try-adult .com</span>/lula/447057398/1/&amp;id=1219<br /><span style="font-weight: bold;">visit-adult .net</span>/jay/1021153563/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/rosa/849017739/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/hannah/2111126283/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/robin/2114086747/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/geraldine/921262381/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/christine/1821111087/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/frederica/364993202/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/kerste/735582753/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/vine/715820953/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/newt/1835463160/1/&amp;id=1219<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SGJ6ha5cUzI/AAAAAAAAB18/wtJ3aPXos_Q/s1600-h/zlob_codec_setup.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SGJ6ha5cUzI/AAAAAAAAB18/wtJ3aPXos_Q/s200/zlob_codec_setup.png" alt="" id="BLOGGER_PHOTO_ID_5215866033022980914" border="0" /></a><span style="font-weight: bold;">try-adult .com</span>/max/602914725/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/cille/1420660046/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/phililpa/178057959/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/lise/1379126759/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/marianne/1083617952/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/emile/1173468576/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/patse/155685496/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/verna/625840253/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/aubrey/190928373/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .</span><span style="font-weight: bold;">net</span>/alphinias/1345158043/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/rosa/223743611/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/nerva/1509620489/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/leet/1619667733/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/roberta/887345003/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/tore/1032556395/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/bo/1963737386/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/karon/136085893/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/tense/1523522750/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/hopp/1955964399/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/vanne/350822489/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/deb/1451360694/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/moll/1511640690/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/obediah/562846948/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/tamarra/776122096/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/aristotle/1046422029/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/titia/158157566/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/gay/1297835054/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/katherine/2136357734/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/azubah/1197502147/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/claes/770105101/1/&amp;id=1219<br /><br />Associated fake porn sites :<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGJ7UYzaZJI/AAAAAAAAB2E/cy7Pijctw-8/s1600-h/fake_porn_sites_ATRIVO1.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGJ7UYzaZJI/AAAAAAAAB2E/cy7Pijctw-8/s200/fake_porn_sites_ATRIVO1.JPG" alt="" id="BLOGGER_PHOTO_ID_5215866908634145938" border="0" /></a><span style="font-weight: bold;">pornbrake .com</span> <span style="font-weight: bold;"><br />sexnitro .net</span> <span style="font-weight: bold;"><br />brakesex .net</span> <span style="font-weight: bold;"><br />pornnitro .net</span> <span style="font-weight: bold;"><br />adultbookings .com</span> <span style="font-weight: bold;"><br />qazsex .com</span><br /><span style="font-weight: bold;">lightporn .net</span> <span style="font-weight: bold;"><br />delfiporn .net</span> <span style="font-weight: bold;"><br />pornqaz .com</span> <span style="font-weight: bold;"><br />megazporn .com</span> <span style="font-weight: bold;"><br />uinsex .com</span><br /><span style="font-weight: bold;">xerosex .com</span> <span style="font-weight: bold;"><br />serviceporn .com</span> <span style="font-weight: bold;"><br />aboutadultsex .com</span> <span style="font-weight: bold;"><br />superliveporn .com</span> <span style="font-weight: bold;"><br />bestpriceporn .com</span> <span style="font-weight: bold;"><br />contactporn .net</span> <span style="font-weight: bold;"><br />relatedporn .com</span> <span style="font-weight: bold;"><br />landporno .com</span> <span style="font-weight: bold;"><br />adultsper .com</span> <span style="font-weight: bold;"><br />plus-porn .com</span> <span style="font-weight: bold;"><br />adultstarworld .com</span><br /><span style="font-weight: bold;">cutadult .com</span> <span style="font-weight: bold;"><br />moviexxxhotel .com</span> <span style="font-weight: bold;"><br />porno-go .com</span> <span style="font-weight: bold;"><br />pornxxxfilm .com</span> <span style="font-weight: bold;"><br />porn-sea .com</span> <span style="font-weight: bold;"><br />review-sex .com</span> <span style="font-weight: bold;"><br />sureadult .com</span> <span style="font-weight: bold;"><br />browseadult .com</span> <span style="font-weight: bold;"><br />network-adult .com</span> <span style="font-weight: bold;"><br />timeadult .com</span> <span style="font-weight: bold;"><br />virtual-sexy .net</span><br /><span style="font-weight: bold;">funxxxporn .com</span> <span style="font-weight: bold;"><br />loweradult .com</span> <span style="font-weight: bold;"><br />adultfilmsite .com</span> <span style="font-weight: bold;"><br />xxxallvideo .com</span> <span style="font-weight: bold;"><br />custom-sex .com</span> <span style="font-weight: bold;"><br />g</span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SGJ8FOk2RhI/AAAAAAAAB2M/scnBizNZUOA/s1600-h/fake_porn_sites_ATRIVO2.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SGJ8FOk2RhI/AAAAAAAAB2M/scnBizNZUOA/s200/fake_porn_sites_ATRIVO2.JPG" alt="" id="BLOGGER_PHOTO_ID_5215867747702294034" border="0" /></a><span style="font-weight: bold;">allerypictures .net</span> <span style="font-weight: bold;"><br />usaadultvideo .com</span><br /><span style="font-weight: bold;">adultmovieplus .com</span> <span style="font-weight: bold;"><br />porn-cruise .com</span> <span style="font-weight: bold;"><br />clubxxxvideo .com</span> <span style="font-weight: bold;"><br />mitadult .com</span> <span style="font-weight: bold;"><br />galleryalbum .net</span> <span style="font-weight: bold;"><br />xxxteenfilm .com</span> <span style="font-weight: bold;"><br />hardcorevideosite .com</span> <span style="font-weight: bold;"><br />helpadult .com</span> <span style="font-weight: bold;"><br />portaladult .net</span> <span style="font-weight: bold;"><br />service-sex .com</span> <span style="font-weight: bold;"><br />driveadult .com</span> <span style="font-weight: bold;"><br />access-porno .com</span> <span style="font-weight: bold;"><br />time-sex .com</span> <span style="font-weight: bold;"><br />plus-adult .com</span> <span style="font-weight: bold;"><br />worldadultvideo .com</span><br /><span style="font-weight: bold;">key-adult .com</span><br /><span style="font-weight: bold;">estatesex .com</span> <span style="font-weight: bold;"><br />superadultfriend .com</span><br /><span style="font-weight: bold;">superporncity .com</span> <span style="font-weight: bold;"><br />zero-porno .com</span> <span style="font-weight: bold;"><br />scanadult .com</span> <span style="font-weight: bold;"><br />adultsexpro .com</span> <span style="font-weight: bold;"><br />adultzoneworld .com</span> <span style="font-weight: bold;"><br />porntimeguide .com</span> <span style="font-weight: bold;"><br />usbestporn .com</span> <span style="font-weight: bold;"><br />adulttow .com</span> <span style="font-weight: bold;"><br />look-porn .com</span><br /><span style="font-weight: bold;">galleryclick .net</span><br /><span style="font-weight: bold;">micro-sex .com</span> <span style="font-weight: bold;"><br />estatesex .com</span> <span style="font-weight: bold;"><br />try-sex .com</span> <span style="font-weight: bold;"><br />0bucksforpornmovie .com</span> <span style="font-weight: bold;"><br />gays-video-xxx .com</span> <span style="font-weight: bold;"><br />hackthegrid .com</span> <span style="font-weight: bold;"><br />savetop .info</span> <span style="font-weight: bold;"><br />vidsplanet .net</span> <span style="font-weight: bold;"><br />freexxxhere .com</span> <span style="font-weight: bold;"><br />gestkoeporno .com</span><br /><span style="font-weight: bold;">tv-adult .info</span> <span style="font-weight: bold;"><br />gays-adult-video .com</span> <span style="font-weight: bold;"><br />matures-video .com</span> <span style="font-weight: bold;"><br />analcekc .com</span> <span style="font-weight: bold;"><br />tabletskard .in</span> <span style="font-weight: bold;"><br />molodiedevki .com</span> <span style="font-weight: bold;"><br />dom-porno .com</span> <span style="font-weight: bold;"><br />pornoaziatki .com</span> <span style="font-weight: bold;"><br />latinosvideo .com</span> <span style="font-weight: bold;"><br />geiporno .com</span> <span style="font-weight: bold;"><br />sweetfreeporn .com</span><br /><br />If exposing a huge domains portfolio of currently active redirectors has the potential to ruin someone's vacation, then consider someone's vacation ruined already.<br /><br /><span style="font-weight: bold;">Related posts:<br /></span><a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br /><a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br /><a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XlaQvI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XlaQvI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cI4v2I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cI4v2I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=U4oTAi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=U4oTAi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LbooCi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LbooCi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MITw1I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MITw1I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nqHRRI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nqHRRI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2sf0Xi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2sf0Xi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/319853315" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 08:16:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/about-adult">about-adult</category>
      <category domain="http://securityratty.com/tag/scan-porn">scan-porn</category>
      <category domain="http://securityratty.com/tag/zlob malware variant">zlob malware variant</category>
      <category domain="http://securityratty.com/tag/name-adult">name-adult</category>
      <category domain="http://securityratty.com/tag/useporn">useporn</category>
      <category domain="http://securityratty.com/tag/porn-the">porn-the</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/319853315/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</source>
    </item>
    <item>
      <title><![CDATA[Shake-up For Internet Proposed]]></title>
      <link>http://securityratty.com/article/c93395204ded0b339cd5e662e3182ed2</link>
      <guid>http://securityratty.com/article/c93395204ded0b339cd5e662e3182ed2</guid>
      <description><![CDATA[From the BBC
The net could see its biggest transformation in decades if plans to open up the address system are passed
The nets regulators will vote on Thursday to decide if the strict rules on...]]></description>
      <content:encoded><![CDATA[<p>From the BBC:</p>
<blockquote><p>The net could see its biggest transformation in decades if plans to open up the address system are passed.</p>
<p>The net&#8217;s regulators will vote on Thursday to decide if the strict rules on so-called top level domain names, such as .com or .uk, can be relaxed.</p>
<p>If approved, it could allow companies to turn their brands into domain names while individuals could also carve out their own corner of the net.</p>
<p>The move could also see the launch of .xxx, after years of wrangling. </p></blockquote>
<p>The part I find funny is the number of politicians that think having a .xxx domain will cordon off sexually oriented websites from the rest of the web.</p>
<blockquote><p>The move could yet be blocked as the independent arbitration panel can reject domains based on &#8220;morality or public order&#8221; grounds.</p></blockquote>
<p>Morality on the Internet. Hmmm, ok.</p>
<p><a href="http://news.bbc.co.uk/2/hi/technology/7468855.stm">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=vaH0NO"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=vaH0NO" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=JjnUjI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=JjnUjI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=EOPxTi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=EOPxTi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=xNtv0i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=xNtv0i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=31hRji"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=31hRji" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=63ROmi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=63ROmi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/318799055" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 24 Jun 2008 06:45:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/xxx">xxx</category>
      <category domain="http://securityratty.com/tag/xxx domain">xxx domain</category>
      <category domain="http://securityratty.com/tag/independent arbitration panel">independent arbitration panel</category>
      <category domain="http://securityratty.com/tag/reject domains based">reject domains based</category>
      <category domain="http://securityratty.com/tag/move">move</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/morality">morality</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/318799055/">Shake-up For Internet Proposed</source>
    </item>
    <item>
      <title><![CDATA[An Update to Photobucket's DNS Hijacking]]></title>
      <link>http://securityratty.com/article/757643fcf70bd2fb75f32ac324bd9a6f</link>
      <guid>http://securityratty.com/article/757643fcf70bd2fb75f32ac324bd9a6f</guid>
      <description><![CDATA[With Photobuckets recently hijacked DNS records by Turkish hacking group , the second high profile DNS hijack for the past two months next to Comcast.net's DNS hijacking in May , domain registrant...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SGDNLcUG8WI/AAAAAAAAB1M/OHd6QoarHK4/s1600-h/atspace_DNS_hijacking.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SGDNLcUG8WI/AAAAAAAAB1M/OHd6QoarHK4/s200/atspace_DNS_hijacking.JPG" alt="" id="BLOGGER_PHOTO_ID_5215393964957823330" border="0" /></a>With <a href="http://blogs.zdnet.com/security/?p=1285">Photobucket’s recently hijacked DNS records by Turkish hacking group</a>, the second high profile DNS hijack for the past two months next to <a href="http://blogs.zdnet.com/security/?p=1213">Comcast.net's DNS hijacking in May</a>, domain <a href="http://blogs.zdnet.com/security/?p=1208">registrant impersonation attacks</a> seems to fully work, and Tier 1 domain registrars remain susceptible to them.<br /><br />So far, none of these DNS hijacks served any malware, live exploits, or bogus home pages aiming to steal accounting data. However, the DNS hijacking by itself resulted in a Denial of Service attack on Photobucket, one that would have required a great deal of bandwidth if it were executed in the old fashioned frontal attack approach.<br /><br />And with Photobucket still labeling the DNS hijacking as a "DNS error", their failure to admit what has actually happened is already sparkling quite a few negative comments across the Web - with a reason. Creating alternate realities when it comes to evidential proof of a hack isn't necessarily state of the art public relations. Photobucket.com's domain registrar, <a href="http://news.cnet.com/8301-10784_3-9973345-7.html">the Register.com comments on the DNS hijacking</a> :<br /><br />"<span style="font-style: italic;">The Photobucket site was down for a very short time and was restored immediately when we became aware of the issue." Roni Jacobson, general counsel of Register.com, said in a statement on Thursday. "We are currently investigating the source of the problem.</span>"<br /><br />As well as Atspace.com's (Zettahost.com) <a href="http://atspace.com/dedicated-web-server-hosting-domain-articles-news/">statement left on their site regarding the DNS hijacking</a> :<br /><br />"<span style="font-style: italic;">IMPORTANT! Photobucket.com problem read here: </span><span style="font-style: italic;">Last night Photobucket.com DNS at register.com was hacked by malicious people that are trying to compromise our business!  We are in no way affiliated with such bad deeds and cooperate with photobucket in capturing these individuals. They have pointed the domain photobucket.com to an account hosted on our systems! We have blocked that and photobucked techs have restored the domain pointing to its original location!ALL account information and pictures on photobucket.com are OK, please have patience! Unfortunately the complete DNS replication usually takes 24-48 hours and during this time caches DNS records might still point to us! </span><span style="font-style: italic;">The normal operation of Photobucket is restored and as soon as the replication is complete there should be no further such issues! We would like to emphasize that we are in now way responsible for what happens with photobucket and all users bumping across our systems! </span><span style="font-style: italic;">We are a legitimate web hosting company operating since 2003 and in no way tolerate such hacking attempts! If you have any questions please do not hesitate to contact us at abuse@zettahost.com! Thanks for your patience and understanding!</span>"<br /><br />When the affected company acts like nothing's happened, whereas multiple sources continue providing pieces of the puzzle, a statement on the measures taken to prevent that type of hijacking in the future would be better PR than denying the hijacking of the first place and the fact that they could have pointed Photobucket.com to anywhere they wanted to.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pMvT6I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pMvT6I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GoYjJI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GoYjJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QeP7ii"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QeP7ii" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mVn9wi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mVn9wi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=e9X9fI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=e9X9fI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=lWuZEI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=lWuZEI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TDB9oi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TDB9oi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/318813375" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 24 Jun 2008 02:08:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dns">dns</category>
      <category domain="http://securityratty.com/tag/photobucket">photobucket</category>
      <category domain="http://securityratty.com/tag/complete dns replication">complete dns replication</category>
      <category domain="http://securityratty.com/tag/dns records">dns records</category>
      <category domain="http://securityratty.com/tag/complete">complete</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/replication">replication</category>
      <category domain="http://securityratty.com/tag/photobucket site">photobucket site</category>
      <category domain="http://securityratty.com/tag/domain photobucket">domain photobucket</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/318813375/update-to-photobuckets-dns-hijacking.html">An Update to Photobucket's DNS Hijacking</source>
    </item>
  </channel>
</rss>
