<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: plain]]></title>
    <link>http://securityratty.com/tag/plain</link>
    <description></description>
    <pubDate>Tue, 30 Sep 2008 12:35:15 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Opinion: Obama's Blackberry Is No Security Threat]]></title>
      <link>http://securityratty.com/article/e87ac9b85b1440c70317a2e3c99bc69a</link>
      <guid>http://securityratty.com/article/e87ac9b85b1440c70317a2e3c99bc69a</guid>
      <description><![CDATA[A lot of the stories about President-Elect Barack Obama possibly having to relinquish his BlackBerry when he takes office Jan. 20 are, for a variety of reasons, just plain dumb
Presented By
Expedition...]]></description>
      <content:encoded><![CDATA[A lot of the stories about President-Elect Barack Obama possibly having to relinquish his BlackBerry when he takes office Jan. 20 are, for a variety of reasons, just plain dumb.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:ec05a75c51a0c57bf749dc34de320338:9saJDFUNixvCt9W%2FnAURKdwA2cqnMddIgJicBm8aa7XRGqSr3d0tP4bmhbLQU11krWw1pJd5zPcU'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:ee597d2c1bb98b27efdcaefe8ebb3f75:EF6STR8ij2QRJ8xF4MBcoSPj2lJwQex7OGQm3R4yzLgsLbUdOaDqd300xLdPMY8UCWy9otIBA7UvIQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d51c69caef3a79fa989b3a7574d817cb:uzyMPJwsArJb1adLPnID9o%2BjzBNZTeavL38C94JxNqfi1Cu7ClBDRM2SRcEXd0Rorv8gufvurWb2Vw%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:42f0cd0844493e4e350b139fc5b4aac4:MXMK2lz0WWHJX0PP4CSpEs7sIpFYH2zP5xNyh3ZAJhafvgGgWMApfnlvI1ecgN6drJ%2B6%2B12av%2F4TCA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<hr />
<div style="font-size:xx-small;color:gray;padding-bottom:.5em">Presented By:</div>
<div><a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=f38edf875ae6f3723280e92fea392c4c&amp;p=1">Expedition Week Continues Tonight</a></div>
<table border="0" cellpadding="0" cellspacing="0">
<tr><td valign="top"><embed src="http://services.brightcove.com/services/viewer/federated_f8/1902560944" bgcolor="#FFFFFF" flashVars="playerId=1902560944&viewerSecureGatewayURL=https://console.brightcove.com/services/amfgateway&servicesURL=http://services.brightcove.com/services&cdnURL=http://admin.brightcove.com&domain=embed&autoStart=false&" base="http://admin.brightcove.com" name="flashObj" width="300" height="250" seamlesstabbing="false" type="application/x-shockwave-flash" swLiveConnect="true" pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"></embed><br />
<br /><img src="http://images.pheedo.com/g/ngc/natgeologo_80x60.jpg"><br />
<font size="2" face="helvetica" >Seven nights of one great discovery after another continues tonight at 9P e/p only on National Geographic Channel.  From the ancient pyramids to the ocean depths, from lost cities to outer space, travel with the latest generation of intrepid explorers as they make one great discovery after another.  Expedition Week, only on National Geographic Channel.</font><br />
<a href="http://www.pheedo.com/click.phdo?a=v3%3Ac1abad0b6daa4d28e9a527be56ca4e2f%3As2rmGnBOH62ZTX7YSZtUtsuGGEa8BJPlu%2FnPAP5iBIxxx5lnUHVgxgWtXjRC%2BL9X6noRAJMryZFAD1poPIhkf6cQxJS8bBfGwQlOn880Zw7JEF%2BMyg8FaI55gEz%2FwsMAIsKOYGloldTlO7L2E7%2FRMBd5jFHoF%2BTSxltqVyVuyH%2BRkxk%3D" target="_blank">www.natgeotv.com/expedition</font><br />
</a></td></tr>
<tr><td>&nbsp;</td></tr>
</table>
<div style="font-size:xx-small; padding-top: 1em;"><span style="border-top: 1px solid">
<br style="display:none"/>
<a href="http://www.pheedo.com/">Ads by Pheedo</a>
</span><img alt="" style="border: 0; height: 1px; width: 1px;" border="0" height="1" width="1" src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=f38edf875ae6f3723280e92fea392c4c&amp;p=1"/>
<br/>
</div>
]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/national geographic channel">national geographic channel</category>
      <category domain="http://securityratty.com/tag/takes office jan">takes office jan</category>
      <category domain="http://securityratty.com/tag/plain dumb">plain dumb</category>
      <category domain="http://securityratty.com/tag/continues tonight">continues tonight</category>
      <category domain="http://securityratty.com/tag/blackberry">blackberry</category>
      <category domain="http://securityratty.com/tag/intrepid explorers">intrepid explorers</category>
      <category domain="http://securityratty.com/tag/expedition week">expedition week</category>
      <category domain="http://securityratty.com/tag/discovery">discovery</category>
      <category domain="http://securityratty.com/tag/ancient pyramids">ancient pyramids</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=f38edf875ae6f3723280e92fea392c4c">Opinion: Obama's Blackberry Is No Security Threat</source>
    </item>
    <item>
      <title><![CDATA[Microsoft Begins the MS08-067 Post-Mortem]]></title>
      <link>http://securityratty.com/article/8b1a636e03c8882d65a7f324bcded81f</link>
      <guid>http://securityratty.com/article/8b1a636e03c8882d65a7f324bcded81f</guid>
      <description><![CDATA[It's finger-pointing time. Who let the infamous MS08-067 RPC bug through? Did the vaunted Microsoft Security Development Lifecycle fail? Did people approve the code when they shouldn't have? Microsoft...]]></description>
      <content:encoded><![CDATA[It's finger-pointing time.

Who let the infamous MS08-067 RPC bug through? Did the vaunted Microsoft Security Development Lifecycle fail? Did people approve the code when they shouldn't have?

<a href="http://www.webbuyersguide.com/company/66/Microsoft&kc=eweekarticle110308&src=eweekarticle110308">Microsoft</a> has already begun examining these questions in <a href="http://blogs.msdn.com/sdl/archive/2008/10/22/ms08-067.aspx" target="_blank">an entry on the SDL blog.</a> The problem, the blog seems to conclude, is the complexity of the code. It's just really hard to find bugs of this nature. To have found it would have been lucky. Michael Howard, the SDL guru and blogger, isn't really pointing fingers, although commenters on the blog are.

It's a prime example of what I wrote about not long ago when I said <a href="http://www.eweek.com/c/a/Security/Still-Overflowing-After-All-These-Years/">buffer overflows would never go away.</a> The examples we all see of what overflows are and how to stop them are fairly simple things: Allocate a buffer of size b, read 2*b bytes into it. In this case, there were two problems making the problem significantly more complex: The overflow happens inside a loop, during which pointer arithmetic is done. This alone makes it harder to identify for humans to identify the bug and perhaps impossible for tools to identify it without incurring a large incidence of false positives. Stack-checking also failed in this instance.

Howard called the code in question "reasonably complex" and said at a later date he would publish source code from the function. He said Microsoft's automated tools wouldn't find this bug in this type of code. Some comments on the blog asked him whether this complexity is, in and of itself, a problem. Perhaps manual code reviews should have rejected it. Howard didn't go this far, but I sense, in between the lines, that maybe he feels the same.

As a programmer I've seen this sort of code plenty of times and written it myself. The code may have seemed particularly efficient or just plain cool to the programmer, but complex loops with pointer arithmetic sound inherently like asking for trouble. I've written before that Microsoft has a long-term way of writing for the next generation of hardware, and CPU processing power is becoming absurdly cheap. Perhaps an implementation that is slower than necessary, but clear in its operation, is the better choice. Then leave the optimizing to compilers. It's actually an old argument.

Another thing Howard remarks on is the failure of Microsoft's fuzzing tools in this instance. All he says is they didn't find it and they'll work on that, and they are always working on their fuzzing tools. Fuzzing is cool and this episode shows how there's always more work to do in it. <a href="http://blogs.securiteam.com/index.php/archives/1151" target="_blank">Aviram on the SecuriTeam blog relates </a>how over two years ago famous researcher Dave Aitel said his fuzzer found no more bugs in the MS RPC code, so there must not be any. This was probably tongue-in-cheek, but even so, Aitel's probably biting his tongue now.

Even though many levels of tools and procedures put in place to prevent such vulnerabilities failed to do so, it would be a mistake to say the system failed altogether. This vulnerability, just about the worst class of bug we ever get, comes with significant mitigating factors, and is probably, as a practical matter, not exploitable on Windows Vista and Server 2008. Not everything failed.
<p><a href="http://feedads.googleadservices.com/~a/TOAsgjkEp3a_sBJoijuoWeC3U0s/a"><img src="http://feedads.googleadservices.com/~a/TOAsgjkEp3a_sBJoijuoWeC3U0s/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/yYUo7KKMw0Q" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 03 Nov 2008 10:41:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/code plenty">code plenty</category>
      <category domain="http://securityratty.com/tag/publish source code">publish source code</category>
      <category domain="http://securityratty.com/tag/manual code reviews">manual code reviews</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/rpc code">rpc code</category>
      <category domain="http://securityratty.com/tag/securiteam blog">securiteam blog</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/howard remarks">howard remarks</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/yYUo7KKMw0Q/microsoft_begins_the_ms08-067_post-mortem.html">Microsoft Begins the MS08-067 Post-Mortem</source>
    </item>
    <item>
      <title><![CDATA[NBA Preview and Flashback]]></title>
      <link>http://securityratty.com/article/b7a6f4985a46dfec8a0d683b7d11b6f9</link>
      <guid>http://securityratty.com/article/b7a6f4985a46dfec8a0d683b7d11b6f9</guid>
      <description><![CDATA[NBA starts today, it is always good to have something to look forward to once the weather gets cold in Minnie. I follow two teams. The Celtics who have a decent chance at repeating as champs. KG and...]]></description>
      <content:encoded><![CDATA[<p>NBA starts today, it is always good to have something to look forward to once the weather gets cold in Minnie. I follow two teams. The Celtics who have a decent chance at repeating as champs. KG and Pierce should be back in full force, hopefully Ray Allen holds up. Perkins and Rondo may get a little better with experience. Biggest loss is Posey and we will miss him a lot more than people think. A real glue guy, defense, passing, rebounding, makes the smart plays and as a middleware guy myself I can relate. He will make CP3 even more dangerous.</p><div><br /><div>The other team I follow is the Timberwolves. I think they will be pretty good this year. Al Jefferson is a beast down low. Only four players averaged 20 and 10 last year and he is one. He is the best big man in the post after Duncan. Getting Love and Miller for OJ Mayo was a smart deal by McHale. I think McCants can be a decent instant offense 6th man. Would be good to see Foye step up this year. Weakness looks to be defense</div><br />

*Flashback*&#0160;
</div><div>I am biased but I think the 1980s was the most fun time to watch NBA. Everyone talks about Bird and Magic, but there were a lot of great players back then. Here is my all underrated 1980s team (no Celtics included due to conflict of interest and unobjectivity)</div><br /><div>C: <a href="http://www.youtube.com/results?search_query=moses+malone&amp;search_type=">Moses Malone</a> - beast of a big man, immovable force under the hoop with fantastic foot work for a big man. It is too bad he was traded by Portland because he and Bill Walton would have been the best big man combo of all time. &#0160;&#0160;</div><br /><div>PF: <a href="http://www.youtube.com/watch?v=CO1UvhQMnRk">Bobby Jones</a> - great defender, good rebounder, good passer for a big man. Typical Tar Heel -fundamentally sound. He would be the James Posey of this team. (Runner up: Calvin Natt)</div><br /><div>SF: <a href="http://www.youtube.com/results?search_query=bernard+king&amp;search_type=">Bernard King</a> - what a renaissance. Watch his moves on youtube, he was not that tall like say Alex English but he could go in the lane and score on anybody. Jordan of course is an all around better player but I think King was a better scorer and that is saying something. The playoffs when he was putting up 50 and 60 a night he was a terrifying force.&#0160;

</div><br /><div>SG: <a href="http://www.youtube.com/results?search_query=andrew+toney&amp;search_type=">Andrew Toney</a> - they called him the Boston strangler and as Celtics fan there was no one I was more afraid of. Its a real shame his career got cut short. (Runner up: George Gervin) &#0160;</div><br /><div>PG: <a href="http://www.youtube.com/results?search_query=tiny+archibald&amp;search_type=">Tiny Archibald</a> - Ok, one Celtic, but he is seriously underrated - would go flying into the lane, disappear in the trees, Tiny would fly out the bottom of the pile, and the ball would pop out the top and drop in. Probably the last great player to come out of NYC. (Runner up: Mo Cheeks)</div><br /><div>Sixth Man - <a href="http://www.youtube.com/watch?v=sxpu6cFF2B0">World B. Free</a> - no doubt about this one, he was great as a sixth man. And this guy was plain fun to watch. He would bomb it from 30 feet, when he was on he was a force. He would kick his leg into the defender when he was shooting a j to draw the foul. (Runner up: Michael Cooper)</div>]]></content:encoded>
      <pubDate>Tue, 28 Oct 2008 20:42:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/guy">guy</category>
      <category domain="http://securityratty.com/tag/real glue guy">real glue guy</category>
      <category domain="http://securityratty.com/tag/nba">nba</category>
      <category domain="http://securityratty.com/tag/1980s team">1980s team</category>
      <category domain="http://securityratty.com/tag/immovable force">immovable force</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/force">force</category>
      <category domain="http://securityratty.com/tag/celtics fan">celtics fan</category>
      <category domain="http://securityratty.com/tag/celtics">celtics</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/nba-preview-and-flashback.html">NBA Preview and Flashback</source>
    </item>
    <item>
      <title><![CDATA[Information security in bad economy]]></title>
      <link>http://securityratty.com/article/724237a8203417ab862d25e018912170</link>
      <guid>http://securityratty.com/article/724237a8203417ab862d25e018912170</guid>
      <description><![CDATA[Economy looks grim. The headlines are very discouraging. Capitalism does not guarantee wealth and success all the time. The talking heads on TV blame the greed in the stock market. I wish stock market...]]></description>
      <content:encoded><![CDATA[<P>Economy looks grim. The headlines are very discouraging. Capitalism does not guarantee wealth and success all the time. The talking heads on TV blame the&nbsp;greed in the stock market. I wish stock market is made of just computers that are not greedy human beings. These are bound to happen when there are human beings that participate! Money flows will eventually correct itself&nbsp; I hope, capitalism will be healthy again. This will take time. I am not an economist, but I do understand that people part with money for a period of time to collect higher return in the horizon based on their aptitude for risk.&nbsp; Simple is it not! But, all these complex financial instruments and its machinations seem to blur the reality and make even the brainiest act dumb - or are they just plain greedy?</P>
<P>Setting the context for this post, it is a tough economic situation all over the world. IT spending has reduced and will reduce significantly. In one of earlier posts, I&nbsp;had referred&nbsp;to information security as an overhead of an overhead (IT).&nbsp;What is a good approach for&nbsp;security practice in this type of economy? </P>
<P>I don't have a magic wand to pull a rabbit out of a hat. I have always been told&nbsp;that: tough economy is the time for&nbsp;real smart people to&nbsp;make money. Coming back to information security topic,&nbsp;with a bit of common sense, it is wise for&nbsp;information security professionals to offer services in&nbsp;those&nbsp;areas&nbsp;that does not involve capital expenditure. As a Security Manager, you may be already aware that your people are willing to&nbsp;go&nbsp;an extra mile in the current economic times.</P>
<P>- No budget or lack of budget,&nbsp;means no&nbsp;new capital expenditure. Spend time wisely in building a future technology strategy and keep it in the back pocket when the economy turns around.</P>
<P>- This is a good time to create roles/responsibilities and ownership for various areas. Create operating procedures.&nbsp;Make your team to automate tasks. This will help your operations become more efficient.</P>
<P>- This is time for security awareness&nbsp; education. Create pamphlets/brochures/presentations for an online or classroom training. Engage your and your team's time to impart training.</P>
<P>- Leverage already invested&nbsp;technology platforms. Leverage utilized features that reduce costs. If you have already invested in technology such as VMware, this is the time to get the best out of it. You can use VMware's toolkit to build your lab and staging&nbsp;environment and optimize on hardware cost.</P>
<P>- Off shoring has been the mantra of senior executives, this is the time to revisit those services and measure their performance closely&nbsp;and assess&nbsp;your satisfaction level. This is a good time to build a case for not off shoring if it makes sense.</P>
<P>- Companies are more vulnerable in bad economic times. You are in a better position&nbsp;to&nbsp;influence senior management about information security risks under these circumstances and drive home the value of protecting your intellectual property under these kinds of circumstances. management will be all ears&nbsp;for such a pitch.</P>
<P>- Time to engage your architect to optimize your security architecture, revisit standards and optimize design for cost efficiency.</P>
<P>- Revisit various controls and see if there are some risks that you could optimize spending on.</P>
<P>- Training budget&nbsp;is an unfortunate victim of&nbsp;this type of economy. Encourage employees to take free webinars offered by various security vendors and encourage them to share the summary across the team. This will put your employees in touch with latest happenings in security at the same time there is some learning that is imparted&nbsp;despite&nbsp;zero training budget.</P>
<P>- Since there are very few projects in action, this is a good time to have conversations with cross functional teams and educate them about your services and solicit feedback on how to do better.</P>
<P>- Revisit your vendor logistics and identify whether you can renegotiate some of your already existing contracts.</P>
<P>The above are some good&nbsp;ways by which you can optimize costs, this will also enhance&nbsp;your team's competence level in the long run. And this approach is better than letting people go, if you can pull this.</P>
<P>&nbsp;</P>]]></content:encoded>
      <pubDate>Sun, 26 Oct 2008 16:37:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information security risks">information security risks</category>
      <category domain="http://securityratty.com/tag/risks">risks</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/information security professionals">information security professionals</category>
      <category domain="http://securityratty.com/tag/security manager">security manager</category>
      <category domain="http://securityratty.com/tag/information security topic">information security topic</category>
      <category domain="http://securityratty.com/tag/security architecture">security architecture</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <source url="http://ravichar.blogharbor.com/blog/_archives/2008/10/26/3948897.html">Information security in bad economy</source>
    </item>
    <item>
      <title><![CDATA[Compromised Portfolios of Legitimate Domains for Sale]]></title>
      <link>http://securityratty.com/article/5b1e0d15dd199fd7476dbd877e605255</link>
      <guid>http://securityratty.com/article/5b1e0d15dd199fd7476dbd877e605255</guid>
      <description><![CDATA[Is the demand for access to compromised legitimate portfolios of domains -- where the price is based on the pagerank and is shaped by the number of domains in question -- the main growth factor for...]]></description>
      <content:encoded><![CDATA[<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQHOMySS3JI/AAAAAAAACWQ/Hs8QGER1I60/s1600-h/compromised_web_hosting_portfolio.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img alt="" border="0" id="BLOGGER_PHOTO_ID_5260712558797708434" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQHOMySS3JI/AAAAAAAACWQ/Hs8QGER1I60/s200/compromised_web_hosting_portfolio.jpg" style="cursor: pointer; float: left; height: 103px; margin: 0pt 10px 10px 0pt; width: 200px;" /></a>Is the demand for access to <a href="http://ddanchev.blogspot.com/2008/08/compromised-cpanel-accounts-for-sale.html">compromised legitimate portfolios of domains</a> -- where the price is based on the pagerank and is shaped by the number of domains in question -- the main growth factor for the increasing supply of such stolen accounting data, or is it the result of cybercriminals data mining their botnets for accounting data that would provide them with access to such <a href="http://ddanchev.blogspot.com/2008/09/adult-network-of-1448-domains.html">portfolios of high trafficked domains with clean reputation</a>? Moreover, would such a data mining approach made easily possible due to the availability of botnet parsing services and stolen accounting data dumps streaming directly from a botnet, would in fact be the more efficient approach in injecting their malicious presence on as many hosts as possible, next to the plain simple <a href="http://ddanchev.blogspot.com/2008/10/massive-sql-injection-attacks-chinese.html">massive SQL injection approach</a>?<br />
<br />
As always, it's a matter of who you're dealing with, and their understanding of the exclusiveness of a particular underground item at a given period of time. This exclusiveness is inevitably going to increase due to the fact that they're several "vendors" that are already purchasing access to such portfolios, as well as compromised Cpanel accounts as a core business, the access to which they would later on either resell at a higher price enjoying the underground market's lack of transparency, or directly monetize and break-even immediatelly. As for this particular proposition for an account with 404 domains in it, it's interesting to monitor how the seller is soliciting bids from multiple sources by leaving the price an open topic, clearly indicating his low profile into the underground ecosystem. How come? An experienced seller or buyer would be offering or requesting page rank verification respectively.<br />
<br />
With nearly each and every aspect of cybercrime already available as a service, or literally outsourced as a process to those supposidely excelling into a particular practice, building capabilities for data mining botnets is no longer a requirement, with the people behind the botnets monetizing all the data coming from it by soliciting deals of accounting data dumps based on a particular country only.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KaXaM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KaXaM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5JUrM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5JUrM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iASQm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iASQm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=H5nPm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=H5nPm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OsSgM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OsSgM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WgfUM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WgfUM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=o6U7m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=o6U7m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/430818024" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 24 Oct 2008 06:24:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data dumps based">data dumps based</category>
      <category domain="http://securityratty.com/tag/data dumps">data dumps</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/cybercriminals data">cybercriminals data</category>
      <category domain="http://securityratty.com/tag/portfolios">portfolios</category>
      <category domain="http://securityratty.com/tag/based">based</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/botnets">botnets</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/430818024/compromised-portfolios-of-legitimate.html">Compromised Portfolios of Legitimate Domains for Sale</source>
    </item>
    <item>
      <title><![CDATA[Are Business Risk and Technical Security Part of a Natural Fourier Series?]]></title>
      <link>http://securityratty.com/article/182f28cd8f2b1713858ac5296e2607ca</link>
      <guid>http://securityratty.com/article/182f28cd8f2b1713858ac5296e2607ca</guid>
      <description><![CDATA[Decade after decade politics moves from regulated economies to de-regulated economies. Changes are usually are triggered by unpredictable events (in political speak). We are almost certainly about to...]]></description>
      <content:encoded><![CDATA[Decade after decade politics moves from regulated economies to de-regulated economies. Changes are usually are triggered by &#8220;unpredictable events&#8221; (in political speak). We are almost certainly about to go onto a period of heavy government regulation of the financial services industry where &#8220;unpredictable events&#8221; or &#8220;failure&#8221; in plain English is blamed on inadequate of regulation. [...]]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 06:25:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/unpredictable events">unpredictable events</category>
      <category domain="http://securityratty.com/tag/regulation">regulation</category>
      <category domain="http://securityratty.com/tag/decade">decade</category>
      <category domain="http://securityratty.com/tag/heavy government regulation">heavy government regulation</category>
      <category domain="http://securityratty.com/tag/decade politics moves">decade politics moves</category>
      <category domain="http://securityratty.com/tag/financial services industry">financial services industry</category>
      <category domain="http://securityratty.com/tag/plain english">plain english</category>
      <category domain="http://securityratty.com/tag/economies">economies</category>
      <category domain="http://securityratty.com/tag/period">period</category>
      <source url="http://securitybuddha.com/2008/10/08/are-business-risk-and-technical-security-part-of-a-natural-fourier-series/">Are Business Risk and Technical Security Part of a Natural Fourier Series?</source>
    </item>
    <item>
      <title><![CDATA[Web Based Malware Emphasizes on Anti-Debugging Features]]></title>
      <link>http://securityratty.com/article/64ebe557625edfe9bcc0cbdc14885fe7</link>
      <guid>http://securityratty.com/article/64ebe557625edfe9bcc0cbdc14885fe7</guid>
      <description><![CDATA[Following the ongoing development of a particular web based malware, always comes handy in terms of assessing the commoditization of anti-debugging features within modern malware. With plain simple,...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqvOQBBJ4I/AAAAAAAACPw/fmDkcbMwPSs/s1600-h/web_based_malware_cc1_.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqvOQBBJ4I/AAAAAAAACPw/1HWDayNG6dU/s200-R/web_based_malware_cc1_.JPG" /></a>Following the ongoing development of a particular web based malware, always comes handy in terms of assessing <a href="http://ddanchev.blogspot.com/2008/09/commoditization-of-anti-debugging.html">the commoditization</a> of <a href="http://ddanchev.blogspot.com/2008/09/commercialization-of-anti-debugging.html">anti-debugging features</a> within modern malware. With plain simple, "managed binary crypting and firewall bypassing verification" on demand in February, to August's overall anti antivirus software mentality as a key differentiation factor of the malware.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqymqusJ9I/AAAAAAAACP4/oRig4C4IWHo/s1600-h/web_based_malware_cc3_.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqymqusJ9I/AAAAAAAACP4/FyZQV_azx1o/s200-R/web_based_malware_cc3_.JPG" /></a>So what are they working on? Anti tracing and emulation protection, PeiD and PESniffer protection, as well as anti heuristic scanning with a simple junk data adding feature in order to maintain a smaller binary size.<i> <br />
</i><br />
Here's a translated description :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqzT_QNxpI/AAAAAAAACQA/vMxRy0XpiTc/s1600-h/web_based_malware_cc_new_version1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqzT_QNxpI/AAAAAAAACQA/WCAOc2P-dV8/s200-R/web_based_malware_cc_new_version1.jpg" /></a>"<i>- The binary works under admin and under normal user</i><br />
<i>- The binary is always run as the "current user"</i><br />
<i>- An unlimited number of bots can be loaded and integrated within the command and control, and with the geolocation feature, filters can be applied for a particular country</i><br />
<i>-After successful infection, the binary which is tested against popular firewall and proactive protection security ensures that the actions it takes and their order do not trigger protactive protection mechanisms in place</i><br />
<i>- binary file size is 25k, the size can be reduced once it's crypted<br />
</i><br />
<i></i> <br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SOqzZmhHaLI/AAAAAAAACQI/PD09GhFmXi4/s1600-h/web_based_malware_cc_new_version2.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SOqzZmhHaLI/AAAAAAAACQI/6VE-Clw7bNk/s200-R/web_based_malware_cc_new_version2.jpg" /></a><i>- Doesn't take advantage of BITS protocol </i><br />
<i>- Doesn't allow an infected host to be infected twice</i><br />
<i>- Bypassing NAT and supporting "always-on" connections</i><br />
<i>- A simple, easy to configure web based admin panel</i>" <br />
<br />
What if the buyer doesn't care about the quality assurance practices applied? <a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Managed lower AV detection and firewall bypassing service</a> comes into play.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W8uJM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W8uJM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3ilgM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3ilgM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TZaTm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TZaTm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=msyxm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=msyxm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YpECM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YpECM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1sBzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1sBzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pqSlm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pqSlm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413578893" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 22:42:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/web based malware">web based malware</category>
      <category domain="http://securityratty.com/tag/binary file">binary file</category>
      <category domain="http://securityratty.com/tag/binary">binary</category>
      <category domain="http://securityratty.com/tag/simple">simple</category>
      <category domain="http://securityratty.com/tag/plain simple">plain simple</category>
      <category domain="http://securityratty.com/tag/anti">anti</category>
      <category domain="http://securityratty.com/tag/simple junk data">simple junk data</category>
      <category domain="http://securityratty.com/tag/firewall">firewall</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413578893/web-based-malware-emphasizes-on-anti.html">Web Based Malware Emphasizes on Anti-Debugging Features</source>
    </item>
    <item>
      <title><![CDATA[Clickjacking]]></title>
      <link>http://securityratty.com/article/d0ea1f000cff44a5f2bfc35ef78afadf</link>
      <guid>http://securityratty.com/article/d0ea1f000cff44a5f2bfc35ef78afadf</guid>
      <description><![CDATA[Good Q&amp;A on clickjacking: In plain English, clickjacking lets hackers and scammers hide malicious stuff under the cover of the content on a legitimate site. You know what happens when a carjacker...]]></description>
      <content:encoded><![CDATA[<p>Good <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9115818&source=NLT_SEC&nlid=38">Q&A</a> on clickjacking:</p>

<blockquote>In plain English, clickjacking lets hackers and scammers hide malicious stuff under the cover of the content on a legitimate site. You know what happens when a carjacker takes a car? Well, clickjacking is like that, except that the click is the car.</blockquote>

<p>"Clickjacking" is a stunningly sexy name, but the vulnerability is really just a variant of cross-site scripting.  We don't know how bad it really is, because the details are still being withheld.  But the name alone is causing dread.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=iifBM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=iifBM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=q9UeM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=q9UeM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 09:45:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/stunningly sexy">stunningly sexy</category>
      <category domain="http://securityratty.com/tag/plain english">plain english</category>
      <category domain="http://securityratty.com/tag/cross-site">cross-site</category>
      <category domain="http://securityratty.com/tag/car">car</category>
      <category domain="http://securityratty.com/tag/carjacker takes">carjacker takes</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/dread">dread</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/clickjacking.html">Clickjacking</source>
    </item>
    <item>
      <title><![CDATA[Managed Fast Flux Provider - Part Two]]></title>
      <link>http://securityratty.com/article/210da9c1b19bf76a539ca28b24edc989</link>
      <guid>http://securityratty.com/article/210da9c1b19bf76a539ca28b24edc989</guid>
      <description><![CDATA[We're slowly entering into a stage where RBN bullet proof hosting franchises are vertically integrating, and due to the requests from their customers are starting to offer that they refer to as...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQymgVga0I/AAAAAAAACOw/geleqRWDOE0/s1600-h/pharma_spam_fastflux.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQymgVga0I/AAAAAAAACOw/8PTQr8G6mBM/s200-R/pharma_spam_fastflux.png" /></a>We're slowly entering into a stage where <a href="http://ddanchev.blogspot.com/2008/09/estdomains-and-intercage-vs-cybercrime.html">RBN bullet proof hosting franchises</a> are vertically integrating, and due to the requests from their customers are starting to offer that they refer to as "mirrored hosting" which in practice is plain simple fast flux network consisting of RBN-alike purchased netblocks, and naturally, botnet infected hosts.<br />
<br />
Managed fast-fluxing is only starting to go mainstream, for instance, in July I found evidence that <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">money mule recruiters were using ASProx's infected hosts as hosting infrastructure</a>, and in November, 2007, <a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">an infamous spamming software vendor</a> was also found to have been offering fast-flux services in the past.<br />
<br />
In this most recent fast-flux service, we have a known spammer and botnet master that in between self-serving himself on is way to ensure his portfolio of scammy domains remains online for a "little longer", is commercializing fast-fluxing and is offered a DIY service :<br />
<br />
"<i>Finally after hardwork and great appreciation from our normal bullet proof  hosting/server clients we are able to launch Mirrored hosting. What is </i><i>Mirrored hosting</i><i> ?</i><br />
<i><br />
================<br />
</i><i>Mirrored hosting</i><i> is a powerful mirrored  web hosting management, uses multiple Virtual servers to host  website with 100% uptime. </i><i>Mirrored hosting </i><i>is a combination of two things, which  are:<br />
<br />
1. Specially Designed Virtual Servers</i><br />
<i> 2. Powerful  Automated Control Panel</i><br />
<br />
<i>How does it work ?<br />
===============&nbsp;</i><br />
<br />
<i>Mirrored hosting</i><i> uses specially configured Virtual Servers making them link with the </i><i>Mirrored hosting</i><i> Control Panel  which is then controlled by our own control panel allowing us to provide smooth  streamline hosting with no downtime. No one is able to trace original IP of the  server or the place where the files are hosted so the websites/domains hosted  have a 100% Uptime. This is achieved by unique customisation of our Virtual Servers.<br />
<br />
<b>Actually, it takes ips around the world and our  powerful control panel just rotates the ips every 15 minutes. though all these  ips you will see will be fake no one can trace the orignal ip where files are  hosted. Sometimes the ip is from China, Korea, USA, UK, Japan, Lithuania etc.</b></i>"<br />
<br />
The concept has always been there for cybercriminals to take advantage of, but once it matures into a managed service it would undoubtedly lower down the entry barriers allowing yesterday's average phishers to take advantage of what only the "pros" were used to.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AO71M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AO71M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xZIrM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xZIrM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZGgOm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZGgOm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=e7OAm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=e7OAm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BVPbM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BVPbM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iS1HM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iS1HM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iQOUm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iQOUm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/409475392" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 08:39:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/recent fast-flux service">recent fast-flux service</category>
      <category domain="http://securityratty.com/tag/powerful control panel">powerful control panel</category>
      <category domain="http://securityratty.com/tag/control panel">control panel</category>
      <category domain="http://securityratty.com/tag/virtual servers">virtual servers</category>
      <category domain="http://securityratty.com/tag/multiple virtual servers">multiple virtual servers</category>
      <category domain="http://securityratty.com/tag/fast flux spam">fast flux spam</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/409475392/managed-fast-flux-provider-part-two.html">Managed Fast Flux Provider - Part Two</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Seven]]></title>
      <link>http://securityratty.com/article/51d3037b3c70ac0a110b0606415c4194</link>
      <guid>http://securityratty.com/article/51d3037b3c70ac0a110b0606415c4194</guid>
      <description><![CDATA[In case you haven't heard - Microsoft and the Washington state are suing a U.S based -- naturally -- &quot;scareware&quot; vendor Branch Software

We won't tolerate the use of alarmist warnings or deceptive...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOKKvX_5seI/AAAAAAAACMw/V5DqP_zsvuk/s1600-h/lawsuit_got_one.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="161" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOKKvX_5seI/AAAAAAAACMw/FVk3TrvBJIo/s200-R/lawsuit_got_one.gif" width="200" /></a>In case you haven't heard - <a href="http://voices.washingtonpost.com/securityfix/2008/09/microsoft_washington_state_tar.html">Microsoft and the Washington state</a> are suing a U.S based -- naturally -- "scareware" vendor Branch Software :<br />
<br />
"<i>We won't tolerate the use of alarmist warnings or deceptive 'free scans' to  trick consumers into buying software to fix a problem that doesn't even exist,"  Washington <b style="font-weight: normal;">Attorney General Rob McKenna</b> said. <b>"We've repeatedly  proven that Internet companies that prey on consumers' anxieties are within our  reach.</b></i><b>"</b><br />
<br />
Sadly, Branch Software is the tip of the iceberg on the top of the affiliates participating in different affiliation based programs, which similar to <a href="http://ddanchev.blogspot.com/2008/03/cybersquatting-security-vendors-for.html">IBSOFTWARE CYPRUS</a> and <a href="http://ddanchev.blogspot.com/2008/04/cybersquatting-symantecs-norton.html">Interactivebrands</a>, which I've been tracking down for a while, are the aggregators of scareware<b><span style="font-weight: normal;"> that popped up on the radars due to their extensive portfolios. These three companies offering software bundles or plain simple fake software, are somewhere in between the food chain of this ecosystem, with the real vendors paying out the commissions on a per installation basis slowly starting to issue invitation codes that they've distributed only across invite-only forums/sections of particular forums.</span></b><br />
<br />
Behind these brands is everyone that is participating in the franchise and is putting personal efforts into monetizing the high payout rates that the fake security software vendor is paying for successful installation. These high payout rates -- with the financing naturally coming straight from other criminal activities online -- are in fact so high, that I can easily say that the last two quarters we've witnesses the largest increase of such domains ever, and they're only heating up since the typosquatting possibilities are countless and they seem to know that as well.<br />
<br />
It's important to point out that their business model of acquiring traffic is outsourced to all the affiliates that do the blackhat SEO, SQL injections, web sessions hijacking of malware infected hosts in order to monetize, so basically, you have an affiliates network whose actions are directly driving the growth into all these areas. Throwing money into the underground marketplace as a "financial injection", is proving itself as a growth factor, and incentive for innovation on behalf of all the participants.<br />
<br />
Here are some of the most recent fake security software domains, a "deja vu" moment with a known RBN domain from a "previous life" that is also parked at one of the servers, and evidence that typosquatting for fraudulent purposes is still pretty active with a dozen of Norton Antivirus related domains, some of which have already started issuing "fake security notices" by brandjacking the vendor for traffic acquisition purposes.<br />
<br />
<b>Antivirus-Alert .com </b>(203.117.111.47) where<b> pepato .org</b> a domain that was used in the <a href="http://ddanchev.blogspot.com/2008/03/wiredcom-and-historycom-getting-rbn-ed.html">Wired.com and History.com IFRAME injections</a>, which back in March was also hosted at Hostfresh (58.65.238.59).<br />
<br />
<b>softload2008name .com</b> (78.157.143.250)<br />
<b>softload2008nm .com<br />
softload2008n .com<br />
softload2008jq .com</b><br />
<br />
<b>microantivir-2009 .com</b> (91.208.0.223)<br />
<b>scanner.microantivir-2009 .com<br />
microantivir2009 .com<br />
microantivirus-2009 .com<br />
microantivirus2009 .com</b><br />
<br />
<b>ms-scan .com</b> (91.208.0.228)<br />
<b>msscanner .com</b><br />
<b>ms-scanner .com</b><br />
<br />
<b>Personalantispy .com</b> (93.190.139.197)<br />
<b>freepcsecure .com<br />
quickinstallpack .com<br />
quickdownloadpro .com<br />
advancedcleaner .com<br />
performanceoptimizer .com<br />
internetanonymizer .com</b><br />
<br />
<b>ieprogramming .com</b> (92.62.101.83)<br />
<b>uptodatepage .com<br />
fileliveupdate .com<br />
qwertypages .com<br />
sharedupdates .com<br />
ierenewals .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOKZEpXlfhI/AAAAAAAACM4/eJI5I5BgGoQ/s1600-h/norton_alert.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOKZEpXlfhI/AAAAAAAACM4/Rpjz8LY4LEQ/s200-R/norton_alert.png" /></a><b>norton-antivirus-alert .com<br />
norton-anti-virus-2007 .com <br />
norton-antivirus-2007 .com <br />
norton-antivirus2007 .com <br />
nortonantivirus2007 .com <br />
norton-antivirus-2008 .com <br />
nortonantivirus2008 .com <br />
nortonantivirus2008freedownload .com <br />
norton-antivirus-2009 .com <br />
nortonantivirus2009 .com <br />
norton-antivirus-2010 .com <br />
nortonantivirus2010 .com <br />
nortonantivirus360 .com <br />
nortonantivirus8 .com <br />
nortonantivirusa .com <br />
nortonantivirusactivation .com <br />
norton-antivirus-alert .com <br />
nortonantivirusalerts .com <br />
norton--anti-virus .com <br />
norton-anti-virus .com <br />
norton-antivirus .com <br />
nortonanti-virus .com <br />
nortonantivirus.com <br />
nortonantiviruscom .com <br />
nortonantiviruscorporate .com <br />
nortonantiviruscorporateedition .com <br />
nortonantiviruscoupon .com <br />
nortonantivirusdefinition .com <br />
nortonantivirusdefinitions .com <br />
nortonantivirusdirect .com</b><br />
<br />
Fake Antivirus Inc. is not going away as long as the affiliate based model remains active. If the real vendors were greedy enough not to share the revenues with others, they would have been the one popping up on the radar, compared to the situation where it's the affiliate network's participations greed that's increasing their visibility online.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html">A Diverse Portfolio of Fake Security Software - Part Six</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Five</a> <br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A  Diverse Portfolio of Fake Security Software - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A  Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse  Portfolio of Fake Security Software</a> <br />
<a href="http://ddanchev.blogspot.com/2008/04/cybersquatting-symantecs-norton.html">Cybersquatting Symantec's Norton AntiVirus</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/cybersquatting-security-vendors-for.html">Cybersquatting Security Vendors for Fraudulent Purposes</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/fake-porn-sites-serving-malware-part.html">Fake  Porn Sites Serving Malware - Part Three</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake  Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake  Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/estdomains-and-intercage-vs-cybercrime.html">EstDomains  and Intercage VS Cybercrime</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/fake-security-software-domains-serving.html">Fake  Security Software Domains Serving Exploits</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized  Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">Got  Your XPShield Up and Running?</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/fake-pestpatrol-security-software.html">Fake  PestPatrol Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's  Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy  Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">Geolocating  Malicious ISPs</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">The  Malicious ISPs You Rarely See in Any Report</a><b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=88nnL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=88nnL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=F8uQL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=F8uQL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=T1xil"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=T1xil" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=eAF4l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=eAF4l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rdg2L"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rdg2L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nXveL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nXveL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=moMol"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=moMol" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/407645950" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 12:35:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/vendor branch software">vendor branch software</category>
      <category domain="http://securityratty.com/tag/vendor">vendor</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/software bundles">software bundles</category>
      <category domain="http://securityratty.com/tag/branch software">branch software</category>
      <category domain="http://securityratty.com/tag/norton antivirus">norton antivirus</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/407645950/diverse-portfolio-of-fake-security_30.html">A Diverse Portfolio of Fake Security Software - Part Seven</source>
    </item>
  </channel>
</rss>
