<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: past]]></title>
    <link>http://securityratty.com/tag/past</link>
    <description></description>
    <pubDate>Wed, 05 Nov 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The "A"]]></title>
      <link>http://securityratty.com/article/1b9ddda67145b0350bba4d9bf6a096a3</link>
      <guid>http://securityratty.com/article/1b9ddda67145b0350bba4d9bf6a096a3</guid>
      <description><![CDATA[Information Security sits in a strange area somewhere between Business and IT in a little space that really hasn't been properly defined. It is exciting here

Generally, most people in Information...]]></description>
      <content:encoded><![CDATA[Information Security sits in a strange area somewhere between Business and IT in a little space that really hasn't been properly defined. It is exciting here.<br /><br />Generally, most people in Information Security today did not start out as pure Information Security people, they evolved. And where they evolved from gives one a clue as to their mindset and how they see themselves.<br /><br />Some come from an Audit background and you'll recognise these guys from their love of lists and frameworks - they dream of Cobit controls and little boxes that are waiting for ticks. Somehow they have tons of documentation and they know it all and can find it all. They generally drive Volvo's and like order.<br /><br />But most InfoSec guys come from an IT background and it shows. I guess that, having said that, most hackers come from an IT background too. And it shows.<br /><br />Now, lets consider the C-I-A triangle thingum. Quick lesson for those who don't know it - there are three aspects of information that Information Security wishes to preserve - the <span style="font-weight: bold;">C</span>onfidentiality, the <span style="font-weight: bold;">I</span>ntegrity and the <span style="font-weight: bold;">A</span>vailability. From my experience, most IT people are governed by Availability - the "A". In fact, when an IT contract is drawn up - there is no SLI or SLC but there will always be an SLA. With very specific terms, measurements and penalties.<br /><br />If the Firewall crashes and has to be rebuilt. What will the IT manager be most interested in? The A - how fast can you get the traffic moving again?<br /><br />So we have tools to measure uptime in 99.999999999999999s and such and anything that can cause network downtime (or if the network is up and the services such as mail are down - same difference) is taken care of. Spam, worms, viruses etc.<br /><br />I guess that hackers (those that define what we do) are also IT background people. They seem to be more concerned with big-bang, widely deployed DoS attacks and stealing IT resources. At least, they used to be, until they discovered that they could make money from stealing information. Actually, I may be naive but I don't believe that the hackers we have today are the same as those we had in the past... I believe that we have a new generation of hackers - criminals who merely use the Internet to steal money because that it where the money is easiest to steal.<br /><br />The problem is that we were lucky in a way that our old tools worked against the threats that we had - firewalls, antiviruses, etc etc. They don't work against people breaking into our networks and stealing information. For that we need a new generation of Information Security people (or the old generation to update their game)...<br /><br />Here is a quick poll to see which generation you are in:<br /><br />1. What is the one piece of information on your network that your competitors would love to see?<br />2. What is the percentage of mails coming into your network that are spam?<br />3. What mail is going to competitors?<br />4. What is the process for someone to order a pencil?<br />5. What is a blog?<br />6. Who in your organisation uses facebook for business?<br />7. How many of your PCs have up-to-date antivirus?<br />8. What is the worst virus out at the moment?<br />9. Do you believe that your Firewall is configured correctly?<br /><br />The answers are as follows:<br />1. This is ESSENTIAL to know if you want to be in the next generation. And you can't guess this. You may think that it is something financial but most financial information can be guessed by your competitors anyhow. You may think it is a recipe or special way of doing something but any established company has had their recipe ripped off anyhow and can beat any new competitor by competitive pricing. It may be new product information. It may be staff information. It may be the CEO's contact list. Don't guess - find out.<br /><br />2. Who cares? Certainly not the CEO. Maybe the CIO. "We are saving you x amount of bandwidth and your users x amount of time" is nice but won't save the business from closing down due to data loss. Operationalise this and get on with your job.<br /><br />3. Good to know. I'm sure that if you told your CEO/CIO "Last week we detected 5 large emails going to our competitors from inside our R&amp;D department" you'd have his full attention.<br /><br />4. Good to know. Who does the ordering? Who does the okaying? Who does the paying? If you know all of this then you know how business works. And when things go wrong - you'll be able to help.<br /><br />5. And do you want your staff to use them? And if they do, what can they put on them? What are they puting on them?<br /><br />6. This is an interesting question because Facebook is usually an issue of "The A" (productivity). But it can be an issue of C and I.<br /><br />7. Who cares? Again, this is an operational issue. Viruses that jump onto your radar are usually ones that attack "the A" but its the ones that are pushing information out of your organisation that are sneaky enough not to have sgnatures and not to be discovered. You will have PCs without up-to-date antivirus and you will have viruses. The trick is not to let your information be stolen by viruses. Also, keep backups so if a PC does get wiped out - you can get the information back again (but this is an operational issue again).<br /><br />8. Trick question - the answer is - the one you don't know about. Old generation InfoSec guys can rattle off names of viruses that are all in the top 10 at the moment.. New generation viruses are targetted and usually do their worst before a pattern is out.<br /><br />9. Old generation answer - yes. New generation answer - who cares? Information flows all over including in and out of the Firewall. Firewalls also usually rely on port security but most everything runs on port 80 anyhow so the Firewall should be configured but it doesn't kep us safe - more work needs to be done for that.<br /><br />I find that it is not very easy to move from old generation to new generation InfoSec. The main difference is that old generation was very technical and appealed to the technical nature of computer geeks. The new generation is business oriented and requires more interaction with people, more meetings, more time with people. Ouch.<br /><br />There will always be a place for technical people in Information Security but as the tools mature and "just work" there is less demand. And a background in technology is very useful when the technical guys try to "BS" you.<br /><br />And "the A" is very important too. Protecting your network from being brought down. Protecting information from disappearing. Stopping viruses. Etc. But the new generation will need to consider "the I" and "the C" as well because the attacks against these and the importance of protecting information against disclosure or manipulation will increase.<br /><br />This post was done to add my voice to what Rich says so quickly and concisely in the <a href="http://securosis.com/2008/11/10/the-two-kinds-of-security-threats-and-how-they-affect-your-life/">securosis blog</a>.<img src="http://feeds.feedburner.com/~r/SecurityThoughts/~4/471338550" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 10:57:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/financial information">financial information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/generation infosec guys">generation infosec guys</category>
      <category domain="http://securityratty.com/tag/infosec guys">infosec guys</category>
      <category domain="http://securityratty.com/tag/information security people">information security people</category>
      <category domain="http://securityratty.com/tag/guys">guys</category>
      <category domain="http://securityratty.com/tag/staff information">staff information</category>
      <category domain="http://securityratty.com/tag/technical guys">technical guys</category>
      <source url="http://feeds.feedburner.com/~r/SecurityThoughts/~3/471338550/a.html">The "A"</source>
    </item>
    <item>
      <title><![CDATA[Communications During Terrorist Attacks are Not Bad]]></title>
      <link>http://securityratty.com/article/e01f90607bd82b3c845f42de9a92f9b5</link>
      <guid>http://securityratty.com/article/e01f90607bd82b3c845f42de9a92f9b5</guid>
      <description><![CDATA[Twitter was a vital source of information in Mumbai: News on the Bombay attacks is breaking fast on Twitter with hundreds of people using the site to update others with first-hand accounts of the...]]></description>
      <content:encoded><![CDATA[<p>Twitter was a vital <a href="http://technology.timesonline.co.uk/tol/news/tech_and_web/article5245059.ece">source of information</a> in Mumbai:</p>

<blockquote>News on the Bombay attacks is breaking fast on Twitter with hundreds of people using the site to update others with first-hand accounts of the carnage. 

<p>The website has a stream of comments on the attacks which is being updated by the second, often by eye-witnesses and people in the city. Although the chatter cannot be verified immediately and often reflects the chaos on the streets, it is becoming the fastest source of information for those seeking unfiltered news from the scene.</blockquote></p>

<p>But we simply have to be smarter than this:</p>

<blockquote>In the past hour, people using Twitter reported that bombings and attacks were continuing, but none of these could be confirmed. Others gave details on different locations in which hostages were being held. 

<p>And this morning, Twitter users said that Indian authorities was asking users to stop updating the site for security reasons.</p>

<p>One person wrote: "Police reckon tweeters giving away strategic info to terrorists via Twitter".</blockquote></p>

<p><a href="http://stephensonstrategies.com/2008/11/26/us-officials-must-monitor-learn-from-use-of-web-20-in-mumbai/">Another link</a>:</p>

<blockquote>I can't stress enough: people can and will use these devices and apps in a terrorist attack, so it is imperative that officials start telling us what kind of information would be relevant from Twitter, Flickr, etc. (and, BTW, what shouldn't be spread: one Twitter user in Mumbai tweeted me that people were sending the exact location of people still in the hotels, and could tip off the terrorists) and that they begin to monitor these networks in disasters, terrorist attacks, etc.</blockquote>

<p>This fear is exactly backwards.  During a terrorist attack -- during any crisis situation, actually -- the one thing people can do is exchange information.  It helps people, calms people, and actually reduces the thing the terrorists are trying to achieve: terror.  Yes, there are specific movie-plot scenarios where certain public pronouncements might help the terrorists, but those are rare.  I would much rather err on the side of more information, more openness, and more communication.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=slTEO"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=slTEO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=BvXZO"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=BvXZO" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 09:02:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/calms people">calms people</category>
      <category domain="http://securityratty.com/tag/twitter user">twitter user</category>
      <category domain="http://securityratty.com/tag/twitter">twitter</category>
      <category domain="http://securityratty.com/tag/helps people">helps people</category>
      <category domain="http://securityratty.com/tag/terrorist attacks">terrorist attacks</category>
      <category domain="http://securityratty.com/tag/twitter users">twitter users</category>
      <category domain="http://securityratty.com/tag/exchange information">exchange information</category>
      <source url="http://www.schneier.com/blog/archives/2008/12/communications.html">Communications During Terrorist Attacks are Not Bad</source>
    </item>
    <item>
      <title><![CDATA[CISSPs Lend me your ears]]></title>
      <link>http://securityratty.com/article/2f51be6dbed18127b772146d8ca86adc</link>
      <guid>http://securityratty.com/article/2f51be6dbed18127b772146d8ca86adc</guid>
      <description><![CDATA[Art of Information Security endorses Dan Houser for(ISC)²Board of Directors
The CISSP isundoubtablyone of the most, if not the most, important professional certifications in Information Security....]]></description>
      <content:encoded><![CDATA[<p><strong>Art of Information Security endorses Dan Houser for (ISC)² Board of Directors</strong></p>
<p>The CISSP is undoubtably one of the most, if not the most, important professional certifications in Information Security. Many organizations and practitioners rely on it as evidence of a solid foundation and track record in Information Security. But the CISSP is only one of the many ways that the (ISC)² attempts to fulfill its mission of developing the Information Security profession.</p>
<p>Board membership is a role of governance, guidance, and passion. Let&#8217;s briefly explore how Dan&#8217;s track record and past contributions demonstrate his qualification for this post, and possibly your vote.</p>
<p><strong>Passion</strong></p>
<p>Dan is someone who has a passion for promoting and developing the talent needed to continue to grow and mature our profession. Anyone who has seen Dan speak at conferences, local chapter meetings, or in one of his classes knows how passionate Dan is! But anyone who takes the time to approach him knows that he is no ideologue or zealot; Dan is always interested in improving his own understanding, and then sharing that knowledge with others.</p>
<p>Dan has a long track record as a contributor - as a &#8220;giver&#8221; - to the profession. In addition to teaching over a dozen CISSP review courses, he has also served on multiple (ISC)² committees, is one of the authors of the ISSAP Body of Knowledge (cryptography), and has published primary research on professional certifications. He is also the founder of the monthly Columbus, Ohio Information Security MBA (Masters of Beer Appreciation) meeting - a professional roundtable that attracts practitioners from across the state.</p>
<p><strong>Governance and Guidance <br />
</strong></p>
<p>In addition to past experience serving on (ISC)² committees, which I assume led to the current board&#8217;s nomination, Dan has served on numerous Boards of Directors including local and regional community organizations, ISSA chapters,and several Toastmasters clubs. </p>
<p><strong>Personal Experiences</strong></p>
<p>I have known Dan for almost three yeas. Dan and I have collaborated on a number or projects, including a half-day Cryptographic Controls Seminar and a full-day Identity Management Architecture class. It is my feeling that when you collaborate, work closely, and travel with someone, you really get to know them. You get to do more than hear about their College Sweethearts (which, for Dan, is Rebecca, his wife of 21 years), but you also get to understand their ethics, how they really conduct themselves, how they deal with stress, etc.</p>
<p>Given the entire picture, the understanding that I have of Dan Houser, I can think of no one better suited to representing, guiding and developing the (ISC)². I have voted for Dan, and I hope that you will consider doing the same.</p>
<p>Here is the voting link for (ISC)²: <a href="https://webportal.isc2.org/custom/votenow.aspx%20" onclick="javascript:pageTracker._trackPageview('/outbound/article/https://webportal.isc2.org/custom/votenow.aspx%20');" target="_blank">https://webportal.isc2.org/custom/votenow.aspx</a></p>
<p>Cheers, Erik</p>
<p></p>
<p><a href="http://artofinfosec.com/105/cissps-lend-me-your-ears/" >CISSPs&#8230; Lend me your ears&#8230;</a></p>
<img src="http://feeds.feedburner.com/~r/artofinfosec/~4/456765137" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 01:15:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dan">dan</category>
      <category domain="http://securityratty.com/tag/dan houser">dan houser</category>
      <category domain="http://securityratty.com/tag/dan foralmostthree yeas">dan foralmostthree yeas</category>
      <category domain="http://securityratty.com/tag/dans track record">dans track record</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/track record">track record</category>
      <category domain="http://securityratty.com/tag/information security profession">information security profession</category>
      <category domain="http://securityratty.com/tag/isc">isc</category>
      <category domain="http://securityratty.com/tag/profession">profession</category>
      <source url="http://feeds.feedburner.com/~r/artofinfosec/~3/456765137/">CISSPs Lend me your ears</source>
    </item>
    <item>
      <title><![CDATA[Deleting your digital past -- for good]]></title>
      <link>http://securityratty.com/article/0a8c48863c92641d59461a5bd6384772</link>
      <guid>http://securityratty.com/article/0a8c48863c92641d59461a5bd6384772</guid>
      <description><![CDATA[Can you erase your tracks online? We tried to get a few bad mentions off the Net forever. Here's how we...]]></description>
      <content:encoded><![CDATA[Can you erase your tracks online? We tried to get a few bad mentions off the Net forever. Here's how we did.<img src="http://feedproxy.google.com/~r/digg/topic/security/popular/~4/sgu-S40CAf8" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 16:50:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/net forever">net forever</category>
      <category domain="http://securityratty.com/tag/bad mentions">bad mentions</category>
      <category domain="http://securityratty.com/tag/tracks online">tracks online</category>
      <category domain="http://securityratty.com/tag/erase">erase</category>
      <source url="http://feeds.digg.com/~r/digg/topic/security/popular/~3/sgu-S40CAf8/Deleting_your_digital_past_for_good">Deleting your digital past -- for good</source>
    </item>
    <item>
      <title><![CDATA[Deleting your digital past -- for good]]></title>
      <link>http://securityratty.com/article/b16812bafb8af4eb041e829a3351de9e</link>
      <guid>http://securityratty.com/article/b16812bafb8af4eb041e829a3351de9e</guid>
      <description><![CDATA[Whether it's a youthful indiscretion or a bit of malicious gossip, many of us have an unsavory mention or two online that we'd like to see expunged. We tried to get a few such bits off the Net...]]></description>
      <content:encoded><![CDATA[Whether it's a youthful indiscretion or a bit of malicious gossip, many of us have an unsavory mention or two online that we'd like to see expunged. We tried to get a few such bits off the Net forever. Here's how we did.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:fe9866d61aab1ea934d2963a1d4a4179:DBrr0Jq5Mh728O5Hh3tWwKRzvHVIjJied%2FpQzFcYAHhwldklmruLjXj4IODh8NThRBbZq%2FGc2DkC'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:7489329d83583ec26e0a4dda56f4b709:2UcTE1oHOP5Z44zgwSECO4iRs3vNERF2PXU2L4WqDvZ6iTgeAz5rKBldWcCe7w3SifsUwSeKXCkUiA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:777be67289075f64cd87c73c79c9f984:z5Brhyqug%2BUwbFMHTGUZh18UszxPz%2FozbgDya4H%2B%2FLXDDE9tPgMNOdTw1Zj%2B4stGtsxhNa3%2BG5dCIQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:eb81fa1c98232155a01e49cb2f519328:r66aHGjzOzbbio5%2FU85rz%2FpmKr14%2BoBAZ9zu0IGLRKd17xVKXXjdhzya0jlR4tPEmNfhXQXiGFAc%2FA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=9ca5dae168b00cae6d65781f5c4439df" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=9ca5dae168b00cae6d65781f5c4439df" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Sun, 16 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malicious gossip">malicious gossip</category>
      <category domain="http://securityratty.com/tag/youthful indiscretion">youthful indiscretion</category>
      <category domain="http://securityratty.com/tag/net forever">net forever</category>
      <category domain="http://securityratty.com/tag/unsavory mention">unsavory mention</category>
      <category domain="http://securityratty.com/tag/bit">bit</category>
      <category domain="http://securityratty.com/tag/bits">bits</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=9ca5dae168b00cae6d65781f5c4439df">Deleting your digital past -- for good</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Thirteen]]></title>
      <link>http://securityratty.com/article/f98a08c6e830a559db2ccd85e32f048e</link>
      <guid>http://securityratty.com/article/f98a08c6e830a559db2ccd85e32f048e</guid>
      <description><![CDATA[What is the difference between a reactive and proactive threat intell? A reactive threat intell is assessing a campaign, individual, a group of individuals, how are they related to one another, and...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SRri0cTxwTI/AAAAAAAACb0/G9gmDkGawOk/s1600-h/fake_security_software_powerfull.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SRri0cTxwTI/AAAAAAAACb0/G9gmDkGawOk/s200/fake_security_software_powerfull.png" /></a>What is the difference between a reactive and proactive threat intell? A reactive threat intell is assessing a campaign, individual, a group of individuals, how are they related to one another, and what have they been doing in the past, based exclusively on a lead that's been found within the past couple of hours.<br />
<br />
Try the very latest rogue security domains courtesy of three domainers (<b>Fedor Ibragimov cndomainz@yahoo.com, Anton Golovayk gpdomains@yahoo.com</b> and <b>Ivan Durov idomains.admin@gmail.com</b> ) whose portfolios can always keep you updated about the latest releases of such popular software as The Best Antivirus Cleaner 2008.<br />
<br />
<b>powerfullantivirusscan .com</b> (78.159.118.217; 89.149.253.215; 208.72.168.185)<br />
<b>protection-update .com</b><br />
<b>updatepcprotection .com</b><br />
<b>updateyourprotection .com</b><br />
<b>mac-imunizator .net</b> (67.205.75.10)<br />
<b>avproinstall .com</b> (78.157.141.26)<br />
<b>winavpro .com</b> (92.241.163.30)<br />
<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SRtYLfJhw0I/AAAAAAAACcM/NIA5Cb8GMjI/s1600-h/fake_security_software_november_.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SRtYLfJhw0I/AAAAAAAACcM/NIA5Cb8GMjI/s200/fake_security_software_november_.png" /></a>As far as proactive threat intell is concerned, try the following "upcoming fake security software domains" :<br />
<br />
<b>spywaredefender2009 .com<br />
spywaredestroyer2009 .com<br />
spywareeliminator2009 .com<br />
spywareprotector2009 .com</b><br />
<br />
It would be interesting to monitor whether or not the well known non-existent security software brands we've monitoring throughout 2008, will be basically typosquatted in a 2009 like fashion, or would they simply introduce new brands. With their business model under pressure, I'm starting to see evidence of schemes involving the illegal advertisement of affiliate links to legitimate security software, where the cybercriminals are actual resellers of it. There's also no shortage of surreal situations, where a fake security software is taking advantage of blackhat SEO practices promising the removal of competing fake security software brands.<br />
<br />
Last week, the <b>noadware .net </b>(69.20.71.82; 69.20.104.139) software was persistently advertised in such a way, mostly by generating Wordpress accounts promising to remove competing software :<br />
<br />
<b>antiviruspro2009.wordpress .com<br />
ultraantivirus2009.wordpress .com<br />
smartantivirus.wordpress .com<br />
antiviruslab2009.wordpress .com<br />
antivirusvip.wordpress .com<br />
personaldefender2009.wordpress .com<br />
malwareremoval.wordpress .com</b><br />
<br />
Naturally, it didn't take long before blackhat SEO farms were created for the purpose, like these very latest ones :<br />
<br />
<b>removal-tool.blogspot .com<br />
cgidoctor .com<br />
spywareremoval .net<br />
spyware-adware-remover .com<br />
spywarestop .com<br />
zero-adware .net<br />
adware-remove .com<br />
antispywaresecrets .com<br />
protectyourcomputerfromspyware .info<br />
cleanpcfree .net<br />
spyware-bot&nbsp; .com<br />
spywarezapper.co .uk<br />
thepcsecurity .com<br />
noadware-official-site .com<br />
spywaredoctorfavor .cn<br />
removespywareedge .cn<br />
thespywareremover .com<br />
virusremovalguru .com<br />
virusremovalguide .org</b> <br />
<br />
The day when fake security software sites start attracting traffic by promising to remove other fake security software, is the day when we have clear evidence that an ecosystem has emerged.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/11/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Twelve</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_28.html">A Diverse Portfolio of Fake Security Software - Part Eleven</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_22.html">A Diverse Portfolio of Fake Security Software - Part Ten</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_16.html">A Diverse Portfolio of Fake Security Software - Part Nine</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Eight</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">A Diverse Portfolio of Fake Security Software - Part Seven</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html">A Diverse Portfolio of Fake Security Software - Part Six</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Five</a> <br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A  Diverse Portfolio of Fake Security Software - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A  Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse  Portfolio of Fake Security Software</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AqTIN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AqTIN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GqbtN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GqbtN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AwMMn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AwMMn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wYg3n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wYg3n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xmYvN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xmYvN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=lK1GN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=lK1GN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uEj3n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uEj3n" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/451194751" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 13:57:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security software">security software</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/popular software">popular software</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/wordpress">wordpress</category>
      <category domain="http://securityratty.com/tag/wordpress accounts">wordpress accounts</category>
      <category domain="http://securityratty.com/tag/proactive threat intell">proactive threat intell</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/451194751/diverse-portfolio-of-fake-security_12.html">A Diverse Portfolio of Fake Security Software - Part Thirteen</source>
    </item>
    <item>
      <title><![CDATA[Distributed DoS attacks surging in scale, ISPs report]]></title>
      <link>http://securityratty.com/article/0acc84c0605fb6b02c60adf600e04d33</link>
      <guid>http://securityratty.com/article/0acc84c0605fb6b02c60adf600e04d33</guid>
      <description><![CDATA[Massive distributed denial-of-service attacks against Internet service providers and their customers doubled in intensity over the past year, according to a security survey of 66 global...]]></description>
      <content:encoded><![CDATA[Massive distributed denial-of-service attacks against Internet service providers and their customers doubled in intensity over the past year, according to a security survey of 66 global ISPs.]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/internet service providers">internet service providers</category>
      <category domain="http://securityratty.com/tag/security survey">security survey</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/global isps">global isps</category>
      <category domain="http://securityratty.com/tag/massive">massive</category>
      <category domain="http://securityratty.com/tag/past">past</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/intensity">intensity</category>
      <source url="http://www.networkworld.com/news/2008/111108-arbor.html?fsrc=rss-security">Distributed DoS attacks surging in scale, ISPs report</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up October 2008]]></title>
      <link>http://securityratty.com/article/425e8bb2014656857a1c215075620790</link>
      <guid>http://securityratty.com/article/425e8bb2014656857a1c215075620790</guid>
      <description><![CDATA[As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see today . These monthly round-ups is an attempt to remind...]]></description>
      <content:encoded><![CDATA[<p>As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. These <a href="http://chuvakin.blogspot.com/search/label/Monthly">monthly round-ups</a> is an attempt to remind people of useful content from the past month!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>OF COURSE, the news of my “transition” is the item #1, by far. “<a href="http://chuvakin.blogspot.com/2008/10/change.html">Change!!!</a>” and “<a href="http://www.qualys.com/solutions/pci_compliance/">Qualys</a>” posts rule the list.</li>    <li>Last month I posted a bunch of my presentations on logs, security, etc on the blog.&#160; “<a href="http://www.slideshare.net/anton_chuvakin/logs-for-incident-response-and-forensics-key-issues-for-govcertnl-2008-presentation-620704">Presentation from GOVCERT.NL 2008: Log Forensics</a>” takes one of the tops spots; and so do “<a href="http://www.slideshare.net/anton_chuvakin/application-logging-good-bad-ugly-beautiful-presentation">Presentation on Application Logging, Done Wrong or Very Wrong</a>” and “<a href="http://www.slideshare.net/anton_chuvakin/logs-vs-insiders-presentation">Presentation on Optimizing Your Logging for Insider Attack Tracking</a>.”&#160; BTW, all the presentations are <a href="http://chuvakin.blogspot.com/search/label/presentation">here</a>.</li>    <li>Shockingly, <a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">AGAIN</a> this month, the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as #1 most popular post (maybe driven by <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">my poll</a>).&#160; BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a> and my other “top 11” lists.</li>    <li>SIEM bashing reached a new high (eh…“low”? :-)), now that Richard is <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">helping too</a>;&#160; my “<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a> is on the top list. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a> and <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">here</a>.)</li>    <li>Somewhat predictably, PCI compliance is obviously still all the rage: <a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a> post was again propelled to a place in my monthly Top5 list.</li> </ol>  <p><a href="http://chuvakin.blogspot.com/search/label/Monthly">See you</a> in November.</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - September 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160; <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div></p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bZriN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bZriN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=8jskN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=8jskN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=haLRN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=haLRN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/448986147" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 13:35:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/monthly round-ups">monthly round-ups</category>
      <category domain="http://securityratty.com/tag/monthly top5 list">monthly top5 list</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/448986147/monthly-blog-round-up-october-2008.html">Monthly Blog Round-Up October 2008</source>
    </item>
    <item>
      <title><![CDATA[Opinion: Card breaches shake faith in e-payments]]></title>
      <link>http://securityratty.com/article/4c0e74621cbd78bc80d9ec32873aaab4</link>
      <guid>http://securityratty.com/article/4c0e74621cbd78bc80d9ec32873aaab4</guid>
      <description><![CDATA[In the past three months, all three of my payments cards -- one credit card and two debit cards -- have been...]]></description>
      <content:encoded><![CDATA[In the past three months, all three of my payments cards -- one credit card and two debit cards -- have been compromised.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:cf14745a464121e5bc5bafa87ab898f4:0V6akC251kOSEpW%2BrhM6MBztfPu%2Ba1R5DwnIP5GEQ%2B9CRzsp1ce6aN3PANHdu4om1c62iptfrCLc'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c885c439c4daea8db4e2651e120d8fca:3UNA7jUlJDOKwmlIfcy42tn9NmkKwQiUe5ZCsP5YsqwhfbNHr8DRxvaUgW1GsnENrjk6YDsIZL6ZDQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:bfcf64a7bc4c2111cd202622f7ea2624:SNJBrums5fSeyLCNQ2pFCBryjroF1JOmCxH8BZ4YsztH6Q4P5w9Duf4n8v1oSKxmrEbV3KQQ29aGag%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:e65ea5569ffd312b580bdde782fd5b84:PElyaeRNzSY6PRmb4sUvZMi4nc8tFC%2FwWK9GfUY0gbyKd5UrsNnMQ1MMduJ0dGMqJXHt5J8XrPmQiA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=116e0d5caae79031c4160f1d5fc198ac" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=116e0d5caae79031c4160f1d5fc198ac" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/payments cards">payments cards</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/debit cards">debit cards</category>
      <category domain="http://securityratty.com/tag/past">past</category>
      <category domain="http://securityratty.com/tag/months">months</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=116e0d5caae79031c4160f1d5fc198ac">Opinion: Card breaches shake faith in e-payments</source>
    </item>
    <item>
      <title><![CDATA[Card breaches shake faith in e-payments]]></title>
      <link>http://securityratty.com/article/cc93492288fd9647fdf17ef4a5f1f3b3</link>
      <guid>http://securityratty.com/article/cc93492288fd9647fdf17ef4a5f1f3b3</guid>
      <description><![CDATA[In the past three months, all three of my payments cards -- one credit card and two debit cards -- have been...]]></description>
      <content:encoded><![CDATA[In the past three months, all three of my payments cards -- one credit card and two debit cards -- have been compromised.]]></content:encoded>
      <pubDate>Wed, 05 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/payments cards">payments cards</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/debit cards">debit cards</category>
      <category domain="http://securityratty.com/tag/past">past</category>
      <category domain="http://securityratty.com/tag/months">months</category>
      <source url="http://www.networkworld.com/news/2008/110608-card-breaches-shake-faith-in.html?fsrc=rss-security">Card breaches shake faith in e-payments</source>
    </item>
  </channel>
</rss>
