<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: pitch]]></title>
    <link>http://securityratty.com/tag/pitch</link>
    <description></description>
    <pubDate>Fri, 08 Aug 2008 10:31:54 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Mercenary Firm Offers to 'Detain Troublemakers' on Election Day]]></title>
      <link>http://securityratty.com/article/35bf8b0f576151dd122d375ea0f2ab07</link>
      <guid>http://securityratty.com/article/35bf8b0f576151dd122d375ea0f2ab07</guid>
      <description><![CDATA[CIA-linked private military contractor Evergreen Defense &amp; Security Services offered to post sentries at Oregon election offices on Tuesday, &quot;detaining troublemakers&quot; and making sure voters &quot;do not...]]></description>
      <content:encoded><![CDATA[CIA-linked private military contractor Evergreen Defense & Security Services offered to post sentries at Oregon election offices on Tuesday, "detaining troublemakers" and making sure voters "do not get out of control." But rest easy: the company struck out with its sales pitch.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=07474c6d517808a2edc1fce0b8b1d1b7" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=07474c6d517808a2edc1fce0b8b1d1b7" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=7hTcN"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=7hTcN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=n3STn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=n3STn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=es8Zn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=es8Zn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Wee7N"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Wee7N" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=wABiN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=wABiN" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=9Am5n"><img src="http://feeds.wired.com/~f/wired/politics/security?i=9Am5n" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=7sHen"><img src="http://feeds.wired.com/~f/wired/politics/security?i=7sHen" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=LBRIN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=LBRIN" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/441102487" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/441102496" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 03 Nov 2008 12:39:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oregon election offices">oregon election offices</category>
      <category domain="http://securityratty.com/tag/company struck">company struck</category>
      <category domain="http://securityratty.com/tag/security services">security services</category>
      <category domain="http://securityratty.com/tag/troublemakers">troublemakers</category>
      <category domain="http://securityratty.com/tag/post sentries">post sentries</category>
      <category domain="http://securityratty.com/tag/sales pitch">sales pitch</category>
      <category domain="http://securityratty.com/tag/military contractor">military contractor</category>
      <category domain="http://securityratty.com/tag/rest easy">rest easy</category>
      <category domain="http://securityratty.com/tag/defense">defense</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/441102496/spooky-defense.html">Mercenary Firm Offers to 'Detain Troublemakers' on Election Day</source>
    </item>
    <item>
      <title><![CDATA[Barak Obama Discusses Security Trade-Offs]]></title>
      <link>http://securityratty.com/article/66adeb7e03a72798a66d6a815c8cb26d</link>
      <guid>http://securityratty.com/article/66adeb7e03a72798a66d6a815c8cb26d</guid>
      <description><![CDATA[I generally avoid commenting on election politics -- that's not what this blog is about -- but this comment by Barak Obama is worth discussing: [Q] I have been collecting accounts of your meeting with...]]></description>
      <content:encoded><![CDATA[<p>I generally avoid commenting on election politics -- that's not what this blog is about -- but <a href="http://www.time-blog.com/swampland/2008/10/the_full_obama_interview.html">this comment</a> by Barak Obama is worth discussing:</p>

<blockquote>[Q] I have been collecting accounts of your meeting with David Petraeus in Baghdad. And you had [inaudible] after he had made a really strong pitch [inaudible] for maximum flexibility. A lot of politicians at that moment would have said [inaudible] but from what I hear, you pushed back.

<p>[BO] I did. I remember the conversation, pretty precisely. He made the case for maximum flexibility and I said you know what if I were in your shoes I would be making the exact same argument because your job right now is to succeed in Iraq on as favorable terms as we can get. My job as a potential commander in chief is to view your counsel and your interests through the prism of our overall national security which includes what is happening in Afghanistan, which includes the costs to our image in the middle east, to the continued occupation, which includes the financial costs of our occupation, which includes what it is doing to our military. So I said look, I described in my mind at list an analogous situation where I am sure he has to deal with situations where the commanding officer in [inaudible] says I need more troops here now because I really think I can make progress doing x y and z. That commanding officer is doing his job in Ramadi, but Petraeus's job is to step back and see how does it impact Iraq as a whole. My argument was I have got to do the same thing here. And based on my strong assessment particularly having just come from Afghanistan were going to have to make a different decision. But the point is that hopefully I communicated to the press my complete respect and gratitude to him and Proder who was in the meeting for their outstanding work. Our differences don't necessarily derive from differences in sort of, or my differences with him don't derive from tactical objections to his approach. But rather from a strategic framework that is trying to take into account the challenges to our national security and the fact that we've got finite resources.</blockquote></p>

<p>I have made this general point again and again -- about airline security, about terrorism, about a lot of things -- that the person in charge of the security system can't be the person who decides what resources to devote to that security system.  The analogy I like to use is a company: the VP of marketing wants all the money for marketing, the VP of engineering wants all the money for engineering, and so on; and the CEO has to balance all of those needs and do what's right for the company.  So of course the TSA wants to spend all this money on new airplane security systems; that's their job.  Someone above the TSA has to balance the risks to airlines with the other risks our country faces and allocate budget accordingly.  Security is a trade-off, and that trade-off has to be made by someone with responsibility over all aspects of that trade-off.</p>

<p>I don't think I've ever heard a politician make this point so explicitly.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=DBjNM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=DBjNM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=WeT5M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=WeT5M" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 27 Oct 2008 03:31:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/airline security">airline security</category>
      <category domain="http://securityratty.com/tag/national security">national security</category>
      <category domain="http://securityratty.com/tag/security system">security system</category>
      <category domain="http://securityratty.com/tag/strong pitch inaudible">strong pitch inaudible</category>
      <category domain="http://securityratty.com/tag/inaudible">inaudible</category>
      <category domain="http://securityratty.com/tag/job">job</category>
      <category domain="http://securityratty.com/tag/airplane security systems">airplane security systems</category>
      <category domain="http://securityratty.com/tag/maximum flexibility">maximum flexibility</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/barak_obama_dis.html">Barak Obama Discusses Security Trade-Offs</source>
    </item>
    <item>
      <title><![CDATA[Information security in bad economy]]></title>
      <link>http://securityratty.com/article/724237a8203417ab862d25e018912170</link>
      <guid>http://securityratty.com/article/724237a8203417ab862d25e018912170</guid>
      <description><![CDATA[Economy looks grim. The headlines are very discouraging. Capitalism does not guarantee wealth and success all the time. The talking heads on TV blame the greed in the stock market. I wish stock market...]]></description>
      <content:encoded><![CDATA[<P>Economy looks grim. The headlines are very discouraging. Capitalism does not guarantee wealth and success all the time. The talking heads on TV blame the&nbsp;greed in the stock market. I wish stock market is made of just computers that are not greedy human beings. These are bound to happen when there are human beings that participate! Money flows will eventually correct itself&nbsp; I hope, capitalism will be healthy again. This will take time. I am not an economist, but I do understand that people part with money for a period of time to collect higher return in the horizon based on their aptitude for risk.&nbsp; Simple is it not! But, all these complex financial instruments and its machinations seem to blur the reality and make even the brainiest act dumb - or are they just plain greedy?</P>
<P>Setting the context for this post, it is a tough economic situation all over the world. IT spending has reduced and will reduce significantly. In one of earlier posts, I&nbsp;had referred&nbsp;to information security as an overhead of an overhead (IT).&nbsp;What is a good approach for&nbsp;security practice in this type of economy? </P>
<P>I don't have a magic wand to pull a rabbit out of a hat. I have always been told&nbsp;that: tough economy is the time for&nbsp;real smart people to&nbsp;make money. Coming back to information security topic,&nbsp;with a bit of common sense, it is wise for&nbsp;information security professionals to offer services in&nbsp;those&nbsp;areas&nbsp;that does not involve capital expenditure. As a Security Manager, you may be already aware that your people are willing to&nbsp;go&nbsp;an extra mile in the current economic times.</P>
<P>- No budget or lack of budget,&nbsp;means no&nbsp;new capital expenditure. Spend time wisely in building a future technology strategy and keep it in the back pocket when the economy turns around.</P>
<P>- This is a good time to create roles/responsibilities and ownership for various areas. Create operating procedures.&nbsp;Make your team to automate tasks. This will help your operations become more efficient.</P>
<P>- This is time for security awareness&nbsp; education. Create pamphlets/brochures/presentations for an online or classroom training. Engage your and your team's time to impart training.</P>
<P>- Leverage already invested&nbsp;technology platforms. Leverage utilized features that reduce costs. If you have already invested in technology such as VMware, this is the time to get the best out of it. You can use VMware's toolkit to build your lab and staging&nbsp;environment and optimize on hardware cost.</P>
<P>- Off shoring has been the mantra of senior executives, this is the time to revisit those services and measure their performance closely&nbsp;and assess&nbsp;your satisfaction level. This is a good time to build a case for not off shoring if it makes sense.</P>
<P>- Companies are more vulnerable in bad economic times. You are in a better position&nbsp;to&nbsp;influence senior management about information security risks under these circumstances and drive home the value of protecting your intellectual property under these kinds of circumstances. management will be all ears&nbsp;for such a pitch.</P>
<P>- Time to engage your architect to optimize your security architecture, revisit standards and optimize design for cost efficiency.</P>
<P>- Revisit various controls and see if there are some risks that you could optimize spending on.</P>
<P>- Training budget&nbsp;is an unfortunate victim of&nbsp;this type of economy. Encourage employees to take free webinars offered by various security vendors and encourage them to share the summary across the team. This will put your employees in touch with latest happenings in security at the same time there is some learning that is imparted&nbsp;despite&nbsp;zero training budget.</P>
<P>- Since there are very few projects in action, this is a good time to have conversations with cross functional teams and educate them about your services and solicit feedback on how to do better.</P>
<P>- Revisit your vendor logistics and identify whether you can renegotiate some of your already existing contracts.</P>
<P>The above are some good&nbsp;ways by which you can optimize costs, this will also enhance&nbsp;your team's competence level in the long run. And this approach is better than letting people go, if you can pull this.</P>
<P>&nbsp;</P>]]></content:encoded>
      <pubDate>Sun, 26 Oct 2008 16:37:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information security risks">information security risks</category>
      <category domain="http://securityratty.com/tag/risks">risks</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/information security professionals">information security professionals</category>
      <category domain="http://securityratty.com/tag/security manager">security manager</category>
      <category domain="http://securityratty.com/tag/information security topic">information security topic</category>
      <category domain="http://securityratty.com/tag/security architecture">security architecture</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <source url="http://ravichar.blogharbor.com/blog/_archives/2008/10/26/3948897.html">Information security in bad economy</source>
    </item>
    <item>
      <title><![CDATA[Massive SQL Injection Attacks - the Chinese Way]]></title>
      <link>http://securityratty.com/article/42e493c2424af4f8ef6cc5dd581317bf</link>
      <guid>http://securityratty.com/article/42e493c2424af4f8ef6cc5dd581317bf</guid>
      <description><![CDATA[From copycats and &quot;localizers&quot; of Russian web malware exploitation kits , to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP46U3HSQHI/AAAAAAAACUY/QH40puDsgXY/s1600-h/security_company_hacking_tools.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP46U3HSQHI/AAAAAAAACUY/QO3L0OWKJcY/s200-R/security_company_hacking_tools.JPG" /></a>From <a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">copycats</a> and <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">"localizers" of Russian web malware exploitation kits</a>, to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the obvious insecurities on a large scale, and so is either filling the niches left open by other international communities, or coming up with tools setting new benchmarks for massive SQL injection attacks, like the case with this one :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5DX0GzAtI/AAAAAAAACUg/3GOnK2TsSRk/s1600-h/search_engines_mass_SQL_injection.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5DX0GzAtI/AAAAAAAACUg/pdCwjwri7LM/s200-R/search_engines_mass_SQL_injection.JPG" /></a>"<i>A professional web site vulnerability scanning, use of tools, SQL injection is a new generation of tools to help Web developers and site of the station quickly find vulnerabilities in order to be able to effectively prepare Security work. At the same time, the tool to Web developers to demonstrate the ways in which hackers are using these vulnerabilities, hackers, as well as through the loopholes to do things, can effectively raise the safety awareness of relevant personnel.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DkEEtbqI/AAAAAAAACUo/Mm7pCwd7LT4/s1600-h/search_engines_mass_SQL_injection2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DkEEtbqI/AAAAAAAACUo/qMaY93_QOvY/s200-R/search_engines_mass_SQL_injection2.JPG" /></a>Nothing's wrong with the marketing pitch at the first place, but going through the features, the "massive SQL injections through search engine reconnaissance" and automatic page rank verification which you can see in the attached screenshots, ruin the "security auditing" marketing pitch. The tool not only allows easy integration of potentially vulnerable sites obtained through <a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">search engines reconnaissance</a>, but also, is prioritizing the results based on the probability for successful injection, next to the page rank of the domains in question. A simple demonstration offered by the company is also, directly enticing its users to "localize" the search engine reconnaissance, by filtering the search results for a particupar country, in this case they used French sites for one of the demos. Here are some excerpts from its CHANGE log speaking for themselves :<br />
<br />
"<i><b>2008.7.15 release version 1.3 </b><br />
&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DyBXVu7I/AAAAAAAACUw/37LsW8yh_AE/s1600-h/chinese_SQL_injector.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DyBXVu7I/AAAAAAAACUw/ub8OVgeWC6Y/s200-R/chinese_SQL_injector.png" /></a><i>- New powerful "automatic machine cycle" feature&nbsp;</i><br />
<i>- Automatic machine cycle is to provide assistance to the advanced user manual into the use of a very&nbsp;</i><br />
<i>- powerful and flexible module, the main sites used for some special filtering into the hand, is almost a&nbsp;</i><br />
<i>- universal tool, you can achieve the following: <br />
&nbsp;</i><br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SP5D-g3FyAI/AAAAAAAACU4/xYACViJuVn4/s1600-h/chinese_SQL_injector2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SP5D-g3FyAI/AAAAAAAACU4/oPVCur3PMgI/s200-R/chinese_SQL_injector2.png" /></a><i>1. In support of GET / POST / COOKIES in a variety of ways, such as the injection.&nbsp;</i><br />
<i>2. Scan the key to the page (background, upload, WebShell, databases, backup files, etc.).&nbsp;</i><br />
<i>3. According to the dictionary to violence landing back-guess solution WebShell password and password (required to verify that the code can not guess solution).&nbsp;</i><br />
<i>4. Page language does not limit the types and databases (to provide specific statements into the database).&nbsp;</i><br />
<i>5. At the same time, support for the circulation of the two variables and two dictionaries, fast running and violent content of the database solution to guess a password.</i>"<br />
<br />
It gets even more interesting in terms of the massive SQL injection attacks mentality which is pretty evident on all fronts :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5ELiLoBiI/AAAAAAAACVA/0fb6Epapby0/s1600-h/chinese_SQL_injector3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5ELiLoBiI/AAAAAAAACVA/nmrC87TeCxo/s200-R/chinese_SQL_injector3.png" /></a>"<i>- The use of the three search engine sites scans to invade the side to complete<br />
- in scanning probe into the Web site ranking points<br />
- added, "VBS upload to download", "upload directory Web site viewer," "FTP upload to download configuration file" function to make it more convenient for the sa rights to use the site. <br />
- New "sequence document scanners" <br />
- What is the sequence document scanners role? Upload to find loopholes, some of the procedures to upload the file after the upload will be renamed, rename the way the system is usually based on time or incremental increase in the number prefix code for the upload process, if not to return after the file name, Upload files to know the url is usually very difficult to sequence the use of paper scanner can be scanned out</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5FUvl0FhI/AAAAAAAACVY/Y5mM2l7Q6K4/s1600-h/chinese_SQL_injector4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5FUvl0FhI/AAAAAAAACVY/DU7feV1pnjU/s200-R/chinese_SQL_injector4.png" /></a><i><br />
- The best reverse domain name query engine, and quasi-wide <br />
- in scanning the database of basic information, an increase of the database of information related to the process, the link has information on the database server user login (sa need permission) <br />
- control of the interface had a big adjustment, the interface process easier to understand and operate. <br />
- based on a significant site of the wrong mode of access to a comprehensive code optimization and more accurate access to the content, accuracy and access to show progress. <br />
- added, "VBS upload to download", "upload directory Web site viewer," "FTP upload to download configuration file" function to make it more convenient for the sa rights to use the site.&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FgfdkSbI/AAAAAAAACVg/R77obP_vxig/s1600-h/chinese_SQL_injector5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FgfdkSbI/AAAAAAAACVg/ORo853Aicy4/s200-R/chinese_SQL_injector5.png" /></a><i><br />
- point into the types of improved detection order to improve the efficiency of detection. <br />
- improved automatic keyword detection, automatic keyword detection more accurate. <br />
- probe into the points the way to improve and increase the use of automatic detection of the keyword detection. <br />
- type of database to improve the detection, the use of the contents of the length of the failure to detect the type of database automatically switch to the probe through the keyword. <br />
- automatically save and load solution has been to guess the tree structure of the database, guess Solutions has been the content and structure of the database will automatically save and open the next time the injection point will be automatically made available, the solutions do not have to guess again, the continuity of work Greatly increased.&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FrcWctII/AAAAAAAACVo/DcQNU5crc5k/s1600-h/chinese_SQL_injector6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="131" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FrcWctII/AAAAAAAACVo/9zGp4bsPB2U/s200-R/chinese_SQL_injector6.png" width="200" /></a><i><br />
- solved from the database to read large amounts of data (on hundreds of thousands or millions of records), the half-way card program will die. <br />
- increased significantly on the wrong model of ASP.NET and SQL Server2005 significant mode of dealing with mistakes, error messages can be extracted from a Web directory! <br />
- significant amendments to the wrong mode, some of the injected one by one point in the field or access to the contents of the issue can not be successful (error code in hand); for increased access to specific points table and into the field.&nbsp;</i><br />
<i><br />
- amendments to the text of a significant error patterns to detect and correct use of loopholes in the system can be used more to expand. (Text significantly in the wrong mode in version 1.1 already supported, but in the version 1.2 upgrade in the process of scanning to improve the performance of the Gaodiao careless. -_-#) <br />
- on a variety of encoded text can be significantly wrong in the right-compatible, able to correctly handle the ASP.NET page of the text marked wrong. Through custom error keyword, truly compatible with any language, any coding error message. <br />
- crack anti-improvement and enhancement. <br />
- An increase of auto-detection feature keywords.&nbsp;</i><br />
<i><br />
- Mssql database specifically for significant points into the wrong mode of detection and the use of up and down the hard work, and many other software can not detect the point of injection can also be used. <br />
- Automatic save and load access to the database, to allow manual known to add tables and fields for solutions to guess. <br />
- Can be used to amend the degree of accuracy; optimize the code to reduce memory footprint; enhance the stability of multi-threading. <br />
- Significant amendments to the wrong mode solution guess the contents of the database must be checked first field defects.</i>"<br />
<br />
The public version of the tool has been in the while for over an year, with a VIP version available to customers only.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PsITM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PsITM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JBO9M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JBO9M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=owYAm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=owYAm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LTzNm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LTzNm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LaPQM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LaPQM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=go5fM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=go5fM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rYJ9m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rYJ9m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/427878843" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 21 Oct 2008 12:18:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/keyword detection">keyword detection</category>
      <category domain="http://securityratty.com/tag/detection">detection</category>
      <category domain="http://securityratty.com/tag/database">database</category>
      <category domain="http://securityratty.com/tag/database solution">database solution</category>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/upload process">upload process</category>
      <category domain="http://securityratty.com/tag/text">text</category>
      <category domain="http://securityratty.com/tag/load solution">load solution</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/427878843/massive-sql-injection-attacks-chinese.html">Massive SQL Injection Attacks - the Chinese Way</source>
    </item>
    <item>
      <title><![CDATA[Blue Coat, partners pitch less expensive data-leak prevention ]]></title>
      <link>http://securityratty.com/article/487258bcbaeaf4c9e11c0a5b2ba3ff73</link>
      <guid>http://securityratty.com/article/487258bcbaeaf4c9e11c0a5b2ba3ff73</guid>
      <description><![CDATA[Blue Coat Systems says it and five partners can cut the cost of deploying data-leak prevention hardware by requiring fewer DLP devices to protect all sites in a corporate...]]></description>
      <content:encoded><![CDATA[Blue Coat Systems says it and five partners can cut the cost of deploying data-leak prevention hardware by requiring fewer DLP devices to protect all sites in a corporate network.]]></content:encoded>
      <pubDate>Sun, 12 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fewer dlp devices">fewer dlp devices</category>
      <category domain="http://securityratty.com/tag/blue coat systems">blue coat systems</category>
      <category domain="http://securityratty.com/tag/data-leak prevention hardware">data-leak prevention hardware</category>
      <category domain="http://securityratty.com/tag/partners">partners</category>
      <category domain="http://securityratty.com/tag/cost">cost</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/protect">protect</category>
      <category domain="http://securityratty.com/tag/cut">cut</category>
      <source url="http://www.networkworld.com/news/2008/101308-blue-coat-dlp.html?fsrc=rss-security">Blue Coat, partners pitch less expensive data-leak prevention </source>
    </item>
    <item>
      <title><![CDATA[The Buzzword Bandwagon: Lessons learned from a user conference]]></title>
      <link>http://securityratty.com/article/b2de28d251fac90363256f9f2c9f5355</link>
      <guid>http://securityratty.com/article/b2de28d251fac90363256f9f2c9f5355</guid>
      <description><![CDATA[Last week I was at a conference where security folks get together and vent their spleens about the problems they're facing. On day one, us vendors weren't allowed near the place, but on day two we got...]]></description>
      <content:encoded><![CDATA[<p>Last week I was at a conference where security folks get together and vent their spleens about the problems they're facing. On day one, us vendors weren't allowed near the place, but on day two we got to pitch our products to potential buyers, and they got to shoot arrows at us. The highlight of the day for me, though, was the roundtable discussion on log management and SIEM.<br />
  <br />
Different people in the room talked about some of their experiences with log management and SIEM &ndash; some were very positive, others not so much. Either way, though, <B>what struck me was the disparity between what people wanted to do with their SIEM products, and what they were actually managing to do...</b>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/products">products</category>
      <category domain="http://securityratty.com/tag/siem products">siem products</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/siem">siem</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/potential buyers">potential buyers</category>
      <category domain="http://securityratty.com/tag/security folks">security folks</category>
      <category domain="http://securityratty.com/tag/roundtable discussion">roundtable discussion</category>
      <category domain="http://securityratty.com/tag/conference">conference</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1347">The Buzzword Bandwagon: Lessons learned from a user conference</source>
    </item>
    <item>
      <title><![CDATA[Firefox SSL-certificate debate gets gnarly ]]></title>
      <link>http://securityratty.com/article/023407164e7a5784760656df276937fb</link>
      <guid>http://securityratty.com/article/023407164e7a5784760656df276937fb</guid>
      <description><![CDATA[Debate is reaching a fever pitch over a new security feature in Firefox 3.0 that throws out a warning page to users when a Web site's SSL certificate is expired or has not been issued by a trusted...]]></description>
      <content:encoded><![CDATA[Debate is reaching a fever pitch over a new security feature in Firefox 3.0 that throws out a warning page to users when a Web site's SSL certificate is expired or has not been issued by a trusted third party.]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ssl">ssl</category>
      <category domain="http://securityratty.com/tag/security feature">security feature</category>
      <category domain="http://securityratty.com/tag/fever pitch">fever pitch</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/firefox">firefox</category>
      <category domain="http://securityratty.com/tag/page">page</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/party">party</category>
      <category domain="http://securityratty.com/tag/throws">throws</category>
      <source url="http://www.networkworld.com/news/2008/082108-firefox-ssl-certificate.html?fsrc=rss-security">Firefox SSL-certificate debate gets gnarly </source>
    </item>
    <item>
      <title><![CDATA[Military trolling at Black Hat]]></title>
      <link>http://securityratty.com/article/b42b6ea1a5234bc5fa7e2e25cce7ec2d</link>
      <guid>http://securityratty.com/article/b42b6ea1a5234bc5fa7e2e25cce7ec2d</guid>
      <description><![CDATA[Forgot to post this yesterday. I was in the military and I came out OK


clipped from www.internetnews.com

Hackers: Uncle Sam Wants You


UPDATED: At Black Hat, agencies including the FBI, US-CERT,...]]></description>
      <content:encoded><![CDATA[<div > Forgot to post this yesterday. I was in the military and I came out OK. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/CD47EBF7-F736-4464-B836-CB93359AAEF4/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/b6ddfde9-f87e-4470-bcc1-63c6ff096c42/CD47EBF7-F736-4464-B836-CB93359AAEF4/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.internetnews.com/government/article.php/3763831/Hackers+Uncle+Sam+Wants+You.htm" href="http://www.internetnews.com/government/article.php/3763831/Hackers+Uncle+Sam+Wants+You.htm" style="font-size: 11px;">www.internetnews.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.internetnews.com/government/article.php/3763831/Hackers+Uncle+Sam+Wants+You.htm --><DIV>Hackers: Uncle Sam Wants You</DIV></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.internetnews.com/government/article.php/3763831/Hackers+Uncle+Sam+Wants+You.htm --><P class="tease"><B>UPDATED:</B> At Black Hat, agencies including the FBI, US-CERT, and the military make the pitch for assisting in the U.S.&#8217;s fight against cybercrime and cyberwar.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/CD47EBF7-F736-4464-B836-CB93359AAEF4/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 13:35:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/military">military</category>
      <category domain="http://securityratty.com/tag/black hat">black hat</category>
      <category domain="http://securityratty.com/tag/uncle sam">uncle sam</category>
      <category domain="http://securityratty.com/tag/fight">fight</category>
      <category domain="http://securityratty.com/tag/us-cert">us-cert</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/fbi">fbi</category>
      <category domain="http://securityratty.com/tag/internetnews">internetnews</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=551">Military trolling at Black Hat</source>
    </item>
    <item>
      <title><![CDATA[Let's Play Two]]></title>
      <link>http://securityratty.com/article/83bf8d018a7d0aa80e3dc49adab30013</link>
      <guid>http://securityratty.com/article/83bf8d018a7d0aa80e3dc49adab30013</guid>
      <description><![CDATA[Every year my Dad and I go to see a Red Sox series. Last weekend was this year's trip and we went to Chicago to see the World Champion Boston Red Sox (saying that never gets old) play the White Sox....]]></description>
      <content:encoded><![CDATA[<p>Every year my Dad and I go to see a Red Sox series. Last weekend was this year&#39;s trip and we went to Chicago to see the World Champion Boston Red Sox (saying that never gets old) play the White Sox. Of course, while you are in Chicago you have to see Wrigley Field, and we really lucked out. This weekend was Red Sox versus the White Sox (the battle of the Soxes they used to call it on Channel 38) on the southside and northside featured Cubs versus Cardinals! The last four World Series winners in town on the same weekend (Red Sox 04, 07, White Sox 05, Cards 06).</p><br /><div>We learned several things- first in heaven the Cubs play the Red Sox in the World Series. Those ballparks are true gems. (In hell its probably the Yankees versus Phillies). Also, the people on the southside and northside *really* have a rivalry going. Its basically Boston v NY but they live in the same town! Here is one example from the southside</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0c9d8834-pi" style="display: inline;"><img alt="IMG_0597" border="0" class="at-xid-6a00d83451c75869e200e553fc0c9d8834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0c9d8834-800wi" title="IMG_0597" /></a>
<br /></div><br /><div>One of the great things about Wrigley (and there are many despite what southsiders say), is that its in the middle of a real neighborhood</div><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bbb38833-pi" style="display: inline;"><img alt="IMG_0486" border="0" class="at-xid-6a00d83451c75869e200e553e0bbb38833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bbb38833-800wi" title="IMG_0486" /></a>
<br /></div><br /><div>Epicenter of Cub universe</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bbf68833-pi" style="display: inline;"><img alt="IMG_0487" border="0" class="at-xid-6a00d83451c75869e200e553e0bbf68833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bbf68833-800wi" title="IMG_0487" /></a>&#160;</div><br /><div>Lots of action before and after game time, lots of people wandering around with gloves catching batting practices homers outside the stadium...err Field. Key point - Wrigley is a field, not a Stadium. Also Fenway is a Park. The Greek root of the word &quot;paradise&quot;, means &quot;enclosed green space&quot;, not concreteopolis</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0ed98834-pi" style="display: inline;"><img alt="IMG_0489" border="0" class="at-xid-6a00d83451c75869e200e553fc0ed98834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0ed98834-800wi" title="IMG_0489" /></a>
<br /></div><br /><div>Wrigley is baseball Mecca</div><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc15338834-pi" style="display: inline;"><img alt="IMG_0507" border="0" class="at-xid-6a00d83451c75869e200e553fc15338834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc15338834-800wi" title="IMG_0507" /></a>
<br /></div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bebd8833-pi" style="display: inline;"><img alt="IMG_0515" border="0" class="at-xid-6a00d83451c75869e200e553e0bebd8833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bebd8833-800wi" title="IMG_0515" /></a>
<br /></div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bef48833-pi" style="display: inline;"><img alt="IMG_0533" border="0" class="at-xid-6a00d83451c75869e200e553e0bef48833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bef48833-800wi" title="IMG_0533" /></a>
<br /></div><br /><div><span style="color: #0000ff; text-decoration: underline;"><br /></span></div><div>The greatest Cub of all, Ernie Banks, was our touchstone for the day - &quot;Let&#39;s Play Two.&quot; we started at Wrigley for the day game (Zambrano got shelled) and then got crosstown for the night game.</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bce68833-pi" style="display: inline;"><img alt="IMG_0496" border="0" class="at-xid-6a00d83451c75869e200e553e0bce68833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bce68833-800wi" title="IMG_0496" /></a>
<br /></div><div>To pull this off the L is your friend. As several Chicagoans pointed out, they are the only city that can have a true subway series, because the Red Line services both the White Sox and Cubs, whereas Mets-Yankees involves numerous transfers and so on.</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0e988834-pi" style="display: inline;"><img alt="IMG_0488" border="0" class="at-xid-6a00d83451c75869e200e553fc0e988834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0e988834-800wi" title="IMG_0488" /></a>
<br /></div><br /><div>We got to US Cellular Field which is fine but a shadow of Wrigley and absolutely nothing good to <a href="http://www.nytimes.com/interactive/2008/06/08/travel/20080608_BALLPARK_GRAPHIC.html">eat</a>. Luckily we had Daisuke Matsuzaka on the hill</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc187a8834-pi" style="display: inline;"><img alt="IMG_0569" border="0" class="at-xid-6a00d83451c75869e200e553fc187a8834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc187a8834-800wi" title="IMG_0569" /></a>
<br /></div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc18a88834-pi" style="display: inline;"><img alt="IMG_0573" border="0" class="at-xid-6a00d83451c75869e200e553fc18a88834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc18a88834-800wi" title="IMG_0573" /></a>
<br /></div><br /><div>Before every game, Big Papi holds court in center with some players from the other team, he is to be a very popular guy. Ozzie Guillen told him before the series that with Manny gone, he wouldn&#39;t see a pitch to hit all weekend (ps. he did and crushed a bases loaded double)</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bfa78833-pi" style="display: inline;"><img alt="IMG_0581" border="0" class="at-xid-6a00d83451c75869e200e553e0bfa78833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bfa78833-800wi" title="IMG_0581" /></a>
<br /></div><br /><br /><div>The question we got most was - what about the Manny trade? His replacement strikes out a lot, but is otherwise a promising player</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bb978833-pi" style="display: inline;"><img alt="IMG_0468" border="0" class="at-xid-6a00d83451c75869e200e553e0bb978833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bb978833-800wi" title="IMG_0468" /></a>
<br /></div><br /><div>The Red Sox and White Sox share a little history, most especially Pudge Fisk who hit the famous homer in the 75 world series for the Red Sox and then had a great career for the White Sox (actually played more games for Chicago than Boston, but went into Cooperstown with a B on his hat)</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bb778833-pi" style="display: inline;"><img alt="IMG_0456" border="0" class="at-xid-6a00d83451c75869e200e553e0bb778833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bb778833-800wi" title="IMG_0456" /></a></div><div>
<br /></div><div>Red Sox won, hanging out in Wrigley was an even bigger highlight, and Chicago is a beautiful city to visit, by far the most accessible of the big US cities. Also, lots of good places to eat courtesy of <a href="http://www.matasano.com/log/">Thomas Ptacek</a>.</div><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0c08f8833-pi" style="display: inline;"><img alt="IMG_0591" border="0" class="at-xid-6a00d83451c75869e200e553e0c08f8833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0c08f8833-800wi" title="IMG_0591" /></a>
<br /></div>]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 08:47:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/world series winners">world series winners</category>
      <category domain="http://securityratty.com/tag/world series">world series</category>
      <category domain="http://securityratty.com/tag/red sox versus">red sox versus</category>
      <category domain="http://securityratty.com/tag/red sox">red sox</category>
      <category domain="http://securityratty.com/tag/red sox series">red sox series</category>
      <category domain="http://securityratty.com/tag/series">series</category>
      <category domain="http://securityratty.com/tag/white sox">white sox</category>
      <category domain="http://securityratty.com/tag/white sox share">white sox share</category>
      <category domain="http://securityratty.com/tag/play">play</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/lets-play-two.html">Let's Play Two</source>
    </item>
    <item>
      <title><![CDATA[Email Hacking Going Commercial - Part Two]]></title>
      <link>http://securityratty.com/article/403816e80242e85ea676f8d2be0684b6</link>
      <guid>http://securityratty.com/article/403816e80242e85ea676f8d2be0684b6</guid>
      <description><![CDATA[Malware authors seeking financial gains from releasing their trojans often promote them as Remote Access Tools , which if we exclude the built-in anti-sandboxing and antivirus software killing...]]></description>
      <content:encoded><![CDATA[<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SJtd4DC75_I/AAAAAAAACBE/No0eDRtdb8s/s1600-h/hire_to_hack.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SJtd4DC75_I/AAAAAAAACBE/BK1B_uN_Iew/s200-R/hire_to_hack.png" style="border: 0pt none ;" /></a>Malware authors seeking financial gains from releasing their trojans often promote them as <a href="http://ddanchev.blogspot.com/2007/07/shark2-rat-or-malware.html">Remote Access Tools</a>, which if we exclude the built-in anti-sandboxing and antivirus software killing capabilities, <a href="http://ddanchev.blogspot.com/2007/08/rats-or-malware.html">could pass for a RAT</a>. In a similar deceptive fashion, <a href="http://ddanchev.blogspot.com/2008/07/email-hacking-going-commercial.html">email hacking services are pitched as email password recovery services</a>. <br />
<br />
Hacking as a Service sites seems to be popping out like mushrooms these days, thanks primarily due to the fact that yesterday's script kiddies are today's entrepreneurs trying to even monetize the process of bruteforcing. Here's their pitch :<br />
<br />
"<i>Well.. There is nothing different in our       services. Like other group, we simply crack email addresses       , and provide you the current password used by the victim to       you for a suitable price. Nothing unique that we can brag       about....&nbsp; We don't hack NASA or CIA , we cannot hack a       bank and steal a million dollars.. We just crack email       password .. AND WE DO A HECK OF A JOB IN IT !! We cannot be as presentable as the other       groups, trying to look as formal and corporate, as if they       are running a Major Corporate Office. However they present       it...password retrieval, online investigation.. access       recovery...blah blah blah..&nbsp; the most simplest way to       put it is.. : Email Password Cracking: !! And since everyone else is busy faking       it, or trying to be more presentable, we utilize our skills       to get you what you want.. i.e. THE EMAIL PASSWORD. No       buttering up, no marketing skills..&nbsp; plain hardcore       hacking !! So, since you now know what we do , and       want us to do the job for you, please proceed to the order       page for your relevant TARGET EMAIL and submit your request.       All said and done, we will get the elusive password &amp; send       you a couple of proofs. You decide upon the authenticity of       the proofs, and let us know if you are comfortable going       ahead with the payment. PAY US, AND YOU GET THE PASSWORD !And as they say.......</i>"<br />
<br />
How much are they charging for the bruteforcing? $150 for starters, which is prone to increase due to their bla bla bla about how sophisticated it was to obtain the password - given they actually manage to deliver the goods :&nbsp; <br />
<br />
<div class="separator" style="text-align: center; clear: both;"><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SJyWntxCJWI/AAAAAAAACBU/aVdgDf7K46o/s1600-h/hire_to_hack1.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img height="160" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SJyWntxCJWI/AAAAAAAACBU/wsy8qQ3XtGQ/s200-R/hire_to_hack1.png" style="border: 0pt none ;" width="200" /></a></div>"<i>Many groups charge a fixed price for an email cracking. We undertake more kinds of projects than anyone else. Frankly, each email is a different project in itself. We cannot charge you $100, for something which we can do for $50. Subsequently, we cannot charge you $100, for something which should be priced at $200. But we charge a minimum of $150 USD so that we end up taking orders from ONLY those who really need it. It is a small amount for the level of satisfaction, facts/truth and relief that you would ultimately achieve from this.It depends upon the nature of the job, the accessibility factor. and many other reasons likes:-<br />
<br />
1- The email service provider<br />
2- The target itself. How net-savvy he/she is.<br />
3- Complexity of the password<br />
4- Urgency of job and many other things collectively.<br />
<br />
We will let you know our charges once we have the desired results only. Be assured, we wont charge you the moon. We charge only what we deserve, and is acceptable by you. Trust us !!</i>"<br />
<br />
Some of their answers to the frequently asked questions :<br />
<br />
" <i>- <b>Who are you? Where are you from</b>?<br />
We are Hire2Hack Group. Member of our group are students in information technology, at some university in England, France, Italy, Japan, Australia, Canada, Brasilia and at United States of America.<br />
<br />
- <b>What services do you provide?</b><br />
We can hack ANY EMAIL password for you very fast, reliable, secure and worldwide for a suitable price.<br />
<br />
- <b>Can you really hack password or just a making a shit scam?</b><br />
Well, lot of people, lot of groups, companies do this service, but not guaranteed. This is only you can choose which group you want to Order. Be careful with these people. You can believe only on them who claims to provide proof before you really pay them.<br />
<br />
- <b>Is there any tool available to crack password?</b><br />
Yes there is. And we are not giving it to you.<br />
<br />
- <b>How long does it takes to crack a password?</b><br />
Each account is different and hacking time vary. On average, it might take about 1 to 3 days, but it may take anywhere from 24 hours to 30 days or more depending on how difficult is the hacking of each account.<br />
<br />
- <b>How can I believe you, that you got password?</b><br />
We will provide you some good proofs before requesting you to pay us. The proof can be anything, you can decide what kind proof you need.<br />
<br />
- <b>Is there person will know that his/her email id has been cracked?</b><br />
No, we provide you only the original password. That mean the current active password. Your victim/target will not realized that she/he has been hacked. NEVER, we said !<br />
<br />
- <b>How I will pay you, I do not have credit card or I do not want to give my credit card number on net?</b><br />
Well, you can use international money transfer service such as Western Union (www.westernunion.com) or Money Gram (www.moneygram.com). These services immediate transfer money on same day or same hour. You can locate their agents in yours area from their website.<br />
<br />
- <b>Do I have to give you my password?</b><br />
No. Any service which requires your password is simply trying to scam you out of access to your account.<br />
<br />
- <b>How will I know you really have the password?</b><br />
We will show you the proofs.. which are mostly convincing.<br />
<br />
- <b>Since you have the password anyway, will you give it to me?</b><br />
NO. Do not waste your time or ours. We will not release the password until full payment is made - no exceptions. We have had people request our service and once we recover the password, they reset the subject account then ask us for the original password so they can reset it back - the answer will be no. We have also had people ask if they could have the password since we've already recovered it and they cannot pay - the answer will be no. No password will be released until payment has been made in full - no exceptions.<br />
<br />
- <b>Will you recover more than one password? Can I request more than one email account?</b><br />
Yes, but a separate request must be filled out for each one as you will only be billed for each successful recovery. If we have previously recovered a password for you and you have not paid, we will not begin any new request for you until your previous request is paid in full with exceptions for our established clientele. We charge at minimum US $100 for each account hacked.<br />
<br />
- <b>Do you reset or change the current password?</b><br />
No. We do not try to guess the current password or the secret question's answer, we do not change their password. We give you only the Original password, which the victim is currently using.<br />
<br />
- <b>Is this confidential? Do you share my information with anyone else</b>?<br />
No, Not at all, Not in any case, its a trust between you and us. Your information will be respected as long as you abide by our Terms and Conditions and Privacy policy. We keep your personal records and requests confidential in our database but we respect your right to privacy and will not rent, share, sell, or trade any personal information unless required by law. <b>But, if you engage in any spamming or fraudulent actives, Your information will be given to the appropriate authorities.</b></i>"<br />
<br />
So you've got script kiddies cracking email addresses and probably engaging in the rest of the usual cybercrime activities, who are spam sensitive, and would expose their customers if they start spamming from the cracked emails? Now that's socially responsible, isn't it.<br />
<br />
Targeted attacks are sexy, but bruteforcing email accounts no matter the number of proxies and wordlists that they have access to is so irrelevant, that social engineering a potential victim into infecting herself with malware through a live exploit URL seems to be the method of choice, next to a plain simple phishing email of course. In this case, what they're asking for in respect to the victim's details is the victim's country and victim's language, so that a localized social engineering or phishing attack can take place. However, this particular group seems to be using a standard bruteforcing tool.<br />
<br />
One thing's for sure - cybercrime is getting easier to outsource, and with potential customers starting to have access to services they didn't a couple of years ago, <a href="http://ddanchev.blogspot.com/2008/08/phishers-backdooring-phishing-pages-to.html">fake scammers are also emerging in between the real ones</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Q4SazK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Q4SazK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=v68SQK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=v68SQK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fTxCfk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fTxCfk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=m5GSCk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=m5GSCk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rFpJlK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rFpJlK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hDloOK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hDloOK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kzNwqk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kzNwqk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/359698182" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 10:31:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/crack password">crack password</category>
      <category domain="http://securityratty.com/tag/crack">crack</category>
      <category domain="http://securityratty.com/tag/crack email password">crack email password</category>
      <category domain="http://securityratty.com/tag/email password">email password</category>
      <category domain="http://securityratty.com/tag/password">password</category>
      <category domain="http://securityratty.com/tag/original password">original password</category>
      <category domain="http://securityratty.com/tag/current password">current password</category>
      <category domain="http://securityratty.com/tag/password retrieval">password retrieval</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/359698182/email-hacking-going-commercial-part-two.html">Email Hacking Going Commercial - Part Two</source>
    </item>
  </channel>
</rss>
