<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: player]]></title>
    <link>http://securityratty.com/tag/player</link>
    <description></description>
    <pubDate>Thu, 18 Sep 2008 10:57:04 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Highly Critical Vulnerabilities In VLC Media Player]]></title>
      <link>http://securityratty.com/article/df80f724a122bf22b9cec14e533334e6</link>
      <guid>http://securityratty.com/article/df80f724a122bf22b9cec14e533334e6</guid>
      <description><![CDATA[Two highly critical vulnerabilities in the cross-platform VLC Media Player could put users at risk of remote code execution attacks, according to a warning from security researchers. An error in the...]]></description>
      <content:encoded><![CDATA[Two “highly critical” vulnerabilities in the cross-platform VLC Media Player could put users at risk of remote code execution attacks, according to a warning from security researchers. An error in the CUE demuxer can be exploited to cause a stack-based buffer overflow via a specially crafted CUE image file. In second vulnerability, an error in [...]]]></content:encoded>
      <pubDate>Fri, 07 Nov 2008 22:20:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/highly critical vulnerabilities">highly critical vulnerabilities</category>
      <category domain="http://securityratty.com/tag/cue image file">cue image file</category>
      <category domain="http://securityratty.com/tag/buffer overflow">buffer overflow</category>
      <category domain="http://securityratty.com/tag/cue demuxer">cue demuxer</category>
      <category domain="http://securityratty.com/tag/error">error</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <source url="http://cyberinsecure.com/highly-critical-vulnerabilities-in-vlc-media-player/">Highly Critical Vulnerabilities In VLC Media Player</source>
    </item>
    <item>
      <title><![CDATA[Six Security Vulnerabilities Updated By Adobe In Flash Player 9]]></title>
      <link>http://securityratty.com/article/86fa944e76baa9f405fe667870f911f2</link>
      <guid>http://securityratty.com/article/86fa944e76baa9f405fe667870f911f2</guid>
      <description><![CDATA[Adobe has released another Flash Player 9 update to cover at least six documented security vulnerabilities that could expose users to a wide range of hacker attacks. The patch, rated critical by...]]></description>
      <content:encoded><![CDATA[Adobe has released another Flash Player 9 update to cover at least six documented security vulnerabilities that could expose users to a wide range of hacker attacks.
The patch, rated “critical” by Adobe, affects Flash Player 9.0.124.0 on all platforms. The latest Flash Player vulnerabilities include:
CVE-2008-4818: This update includes a change to the way Flash Player [...]]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 20:24:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flash player">flash player</category>
      <category domain="http://securityratty.com/tag/affects flash player">affects flash player</category>
      <category domain="http://securityratty.com/tag/security vulnerabilities">security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/adobe">adobe</category>
      <category domain="http://securityratty.com/tag/wide range">wide range</category>
      <category domain="http://securityratty.com/tag/expose users">expose users</category>
      <category domain="http://securityratty.com/tag/hacker attacks">hacker attacks</category>
      <category domain="http://securityratty.com/tag/platforms">platforms</category>
      <category domain="http://securityratty.com/tag/change">change</category>
      <source url="http://cyberinsecure.com/six-security-vulnerabilities-updated-by-adobe-in-flash-player-9/">Six Security Vulnerabilities Updated By Adobe In Flash Player 9</source>
    </item>
    <item>
      <title><![CDATA[Adobe fixes 6 flaws in Flash]]></title>
      <link>http://securityratty.com/article/8e338676db24d29aac50f06e673b2772</link>
      <guid>http://securityratty.com/article/8e338676db24d29aac50f06e673b2772</guid>
      <description><![CDATA[For the second time in two days, Adobe Systems has issued a security update to fix multiple vulnerabilities in one of its most-popular programs, Flash...]]></description>
      <content:encoded><![CDATA[For the second time in two days, Adobe Systems has issued a security update to fix multiple vulnerabilities in one of its most-popular programs, Flash Player.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:00394360bb6d248cc9baea02213db9cf:%2FCZN4eJtNRh8ra3AViblz3BSiPyP46KIqFB51dvYjhppJCUCdqwQGBZma5uyvxoiX1QnUNGWlBjY'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:e1aac51b5c10f1eb477b03a83ba52292:VzTNpyZJPXddORCj0snMZSkIRJN4%2FawAoZYtGSoKiM2xFfxJ3WquPwbporhtxalyVfdB7u2wS3YRig%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:72ae93ea24b1029f7edf23b212c1399d:juC6MeQaCuBEW%2Bt4xQGzdPaRtALS%2B4os6omPXZY0jE9%2Bx%2BZipYuie948LtNpqSid%2Fg0ukftcfVA5XA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:1f3f0b74bdad49a787d084f88ae975e6:dxfoGHh7UVdDmgvnImiHUSP7IBO4ZTm%2FKAzRBKsDpMrd%2BYOhkI%2BgW0vfOTOuPu6YryekUDTh7lrnUg%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=d728e0ef93ea8841799c41780e9a4747" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=d728e0ef93ea8841799c41780e9a4747" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fix multiple vulnerabilities">fix multiple vulnerabilities</category>
      <category domain="http://securityratty.com/tag/flash player">flash player</category>
      <category domain="http://securityratty.com/tag/adobe systems">adobe systems</category>
      <category domain="http://securityratty.com/tag/most-popular programs">most-popular programs</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/days">days</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=d728e0ef93ea8841799c41780e9a4747">Adobe fixes 6 flaws in Flash</source>
    </item>
    <item>
      <title><![CDATA[NBA Preview and Flashback]]></title>
      <link>http://securityratty.com/article/b7a6f4985a46dfec8a0d683b7d11b6f9</link>
      <guid>http://securityratty.com/article/b7a6f4985a46dfec8a0d683b7d11b6f9</guid>
      <description><![CDATA[NBA starts today, it is always good to have something to look forward to once the weather gets cold in Minnie. I follow two teams. The Celtics who have a decent chance at repeating as champs. KG and...]]></description>
      <content:encoded><![CDATA[<p>NBA starts today, it is always good to have something to look forward to once the weather gets cold in Minnie. I follow two teams. The Celtics who have a decent chance at repeating as champs. KG and Pierce should be back in full force, hopefully Ray Allen holds up. Perkins and Rondo may get a little better with experience. Biggest loss is Posey and we will miss him a lot more than people think. A real glue guy, defense, passing, rebounding, makes the smart plays and as a middleware guy myself I can relate. He will make CP3 even more dangerous.</p><div><br /><div>The other team I follow is the Timberwolves. I think they will be pretty good this year. Al Jefferson is a beast down low. Only four players averaged 20 and 10 last year and he is one. He is the best big man in the post after Duncan. Getting Love and Miller for OJ Mayo was a smart deal by McHale. I think McCants can be a decent instant offense 6th man. Would be good to see Foye step up this year. Weakness looks to be defense</div><br />

*Flashback*&#0160;
</div><div>I am biased but I think the 1980s was the most fun time to watch NBA. Everyone talks about Bird and Magic, but there were a lot of great players back then. Here is my all underrated 1980s team (no Celtics included due to conflict of interest and unobjectivity)</div><br /><div>C: <a href="http://www.youtube.com/results?search_query=moses+malone&amp;search_type=">Moses Malone</a> - beast of a big man, immovable force under the hoop with fantastic foot work for a big man. It is too bad he was traded by Portland because he and Bill Walton would have been the best big man combo of all time. &#0160;&#0160;</div><br /><div>PF: <a href="http://www.youtube.com/watch?v=CO1UvhQMnRk">Bobby Jones</a> - great defender, good rebounder, good passer for a big man. Typical Tar Heel -fundamentally sound. He would be the James Posey of this team. (Runner up: Calvin Natt)</div><br /><div>SF: <a href="http://www.youtube.com/results?search_query=bernard+king&amp;search_type=">Bernard King</a> - what a renaissance. Watch his moves on youtube, he was not that tall like say Alex English but he could go in the lane and score on anybody. Jordan of course is an all around better player but I think King was a better scorer and that is saying something. The playoffs when he was putting up 50 and 60 a night he was a terrifying force.&#0160;

</div><br /><div>SG: <a href="http://www.youtube.com/results?search_query=andrew+toney&amp;search_type=">Andrew Toney</a> - they called him the Boston strangler and as Celtics fan there was no one I was more afraid of. Its a real shame his career got cut short. (Runner up: George Gervin) &#0160;</div><br /><div>PG: <a href="http://www.youtube.com/results?search_query=tiny+archibald&amp;search_type=">Tiny Archibald</a> - Ok, one Celtic, but he is seriously underrated - would go flying into the lane, disappear in the trees, Tiny would fly out the bottom of the pile, and the ball would pop out the top and drop in. Probably the last great player to come out of NYC. (Runner up: Mo Cheeks)</div><br /><div>Sixth Man - <a href="http://www.youtube.com/watch?v=sxpu6cFF2B0">World B. Free</a> - no doubt about this one, he was great as a sixth man. And this guy was plain fun to watch. He would bomb it from 30 feet, when he was on he was a force. He would kick his leg into the defender when he was shooting a j to draw the foul. (Runner up: Michael Cooper)</div>]]></content:encoded>
      <pubDate>Tue, 28 Oct 2008 20:42:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/guy">guy</category>
      <category domain="http://securityratty.com/tag/real glue guy">real glue guy</category>
      <category domain="http://securityratty.com/tag/nba">nba</category>
      <category domain="http://securityratty.com/tag/1980s team">1980s team</category>
      <category domain="http://securityratty.com/tag/immovable force">immovable force</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/force">force</category>
      <category domain="http://securityratty.com/tag/celtics fan">celtics fan</category>
      <category domain="http://securityratty.com/tag/celtics">celtics</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/nba-preview-and-flashback.html">NBA Preview and Flashback</source>
    </item>
    <item>
      <title><![CDATA[Flash 10 Fixes Clickjacking Flaw]]></title>
      <link>http://securityratty.com/article/7466eca5f91107c96844d79b2e110ddd</link>
      <guid>http://securityratty.com/article/7466eca5f91107c96844d79b2e110ddd</guid>
      <description><![CDATA[Not long after &quot;clickjacking&quot; attacks appeared several weeks ago it became clear that the culprit was Adobe's Flash. And the problem, as we say in the software biz, wasn't a bug, it was a feature....]]></description>
      <content:encoded><![CDATA[Not long after <a href="http://securitywatch.eweek.com/vulnerability_research/clickjacking_browser_attack_details_emerge.html">"clickjacking" attacks appeared several weeks ago</a> it became clear that the culprit was Adobe's Flash. And the problem, as we say in the software biz, wasn't a bug, it was a feature. This feature has been modified in <a href="http://www.eweek.com/c/a/Application-Development/Adobe-Releases-Flash-Player-10/">the new Flash 10 player</a> to address the problem.

The problem is clipboard access. By default, Flash 9 allowed a Flash program to read and write to the clipboard. "Clickjacking" attacks took advantage of this to persistently stuff a value. usually a malicious URL, into the clipboard, in the hope the user would visit it. The attack is as cross-platform as Flash, working on Macs as well as Windows.

In Flash 10 the clipboard methods will only work when called through ActionScript which originates with a user action, like pressing a button. No longer will a silent Flash app be able to hijack the clipboard completely without the user noticing.

This change was just one of <a href="http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html">many security changes in the Flash 10 player</a>. Changes in how Flash handles policy files means that developers will have to address their use of them. Errors on socket connect() calls will be handled differently. And much in the same philosophy as with clipboards, file uploads and downloads may only occur in script that begins with a user action. There are other changes as well.

The flip side of this fix is that it is not implemented in Flash 9. This means that the only way to escape clickjacking attacks is to upgrade to Flash 10.
<p><a href="http://feedads.googleadservices.com/~a/FtymtK-1YQe4YgTHIvGH8JR05Ck/a"><img src="http://feedads.googleadservices.com/~a/FtymtK-1YQe4YgTHIvGH8JR05Ck/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/58cVGsWzlbk" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 10:07:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flash">flash</category>
      <category domain="http://securityratty.com/tag/silent flash app">silent flash app</category>
      <category domain="http://securityratty.com/tag/flash program">flash program</category>
      <category domain="http://securityratty.com/tag/clipboard">clipboard</category>
      <category domain="http://securityratty.com/tag/clipboard methods">clipboard methods</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <category domain="http://securityratty.com/tag/user action">user action</category>
      <category domain="http://securityratty.com/tag/clipboard access">clipboard access</category>
      <category domain="http://securityratty.com/tag/clipboard completely">clipboard completely</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/58cVGsWzlbk/flash_10_fixes_clickjacking_flaw.html">Flash 10 Fixes Clickjacking Flaw</source>
    </item>
    <item>
      <title><![CDATA[Adobe Fixes Clickjacking Vulnerability In Flash Player 10]]></title>
      <link>http://securityratty.com/article/8b01469e54c8d27b80b8d75dbd1e6bdf</link>
      <guid>http://securityratty.com/article/8b01469e54c8d27b80b8d75dbd1e6bdf</guid>
      <description><![CDATA[Adobe has released Flash Player 10 with numerous major security improvements, including patches and mitigation for at least five serious security vulnerabilities. According to Adobe, the...]]></description>
      <content:encoded><![CDATA[Adobe has released Flash Player 10 with numerous major security improvements, including patches and mitigation for at least five serious security vulnerabilities. According to Adobe, the vulnerabilities covered with Flash Player 10 could allow an attacker to bypass the software’s security controls.
Potential vulnerabilities have been identified in Adobe Flash Player 9.0.124.0 and earlier that could [...]]]></content:encoded>
      <pubDate>Wed, 15 Oct 2008 18:33:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/adobe">adobe</category>
      <category domain="http://securityratty.com/tag/flash player">flash player</category>
      <category domain="http://securityratty.com/tag/adobe flash player">adobe flash player</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/security vulnerabilities">security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/potential vulnerabilities">potential vulnerabilities</category>
      <category domain="http://securityratty.com/tag/softwares security controls">softwares security controls</category>
      <category domain="http://securityratty.com/tag/mitigation">mitigation</category>
      <category domain="http://securityratty.com/tag/bypass">bypass</category>
      <source url="http://cyberinsecure.com/adobe-fixes-clickjacking-vulnerability-in-flash-player-10/">Adobe Fixes Clickjacking Vulnerability In Flash Player 10</source>
    </item>
    <item>
      <title><![CDATA[Adobe fixes 'clickjacking' flaw]]></title>
      <link>http://securityratty.com/article/5dd3d0b126531b39adb6d56fd4964659</link>
      <guid>http://securityratty.com/article/5dd3d0b126531b39adb6d56fd4964659</guid>
      <description><![CDATA[Adobe Systems has released a new version of its Flash Player software, fixing a critical security bug that could make the Internet a dangerous place for Web...]]></description>
      <content:encoded><![CDATA[Adobe Systems has released a new version of its Flash Player software, fixing a critical security bug that could make the Internet a dangerous place for Web surfers.]]></content:encoded>
      <pubDate>Tue, 14 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flash player software">flash player software</category>
      <category domain="http://securityratty.com/tag/critical security bug">critical security bug</category>
      <category domain="http://securityratty.com/tag/adobe systems">adobe systems</category>
      <category domain="http://securityratty.com/tag/web surfers">web surfers</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/version">version</category>
      <category domain="http://securityratty.com/tag/dangerous">dangerous</category>
      <source url="http://www.networkworld.com/news/2008/101508-adobe-fixes-clickjacking.html?fsrc=rss-security">Adobe fixes 'clickjacking' flaw</source>
    </item>
    <item>
      <title><![CDATA[PC Webcams Might Be Abused Through Clickjacking To Silently Spy On Users]]></title>
      <link>http://securityratty.com/article/f402048be80afa0d975aa76a5393c0ed</link>
      <guid>http://securityratty.com/article/f402048be80afa0d975aa76a5393c0ed</guid>
      <description><![CDATA[An Israeli security researcher has released a demo of a clickjacking attack, using a JavaScript game to turn every browser into a surveillance zombie. The proof-of-concept game uses a PCs video cam...]]></description>
      <content:encoded><![CDATA[An Israeli security researcher has released a demo of a “clickjacking” attack, using a JavaScript game to turn every browser into a surveillance zombie. The proof-of-concept game uses a PC&#8217;s video cam and microphone to secretly spy on the player.
The release of the demo follows last month’s partial disclosure of the cross-platform attack/threat, which affects [...]]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 19:32:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/israeli security researcher">israeli security researcher</category>
      <category domain="http://securityratty.com/tag/javascript game">javascript game</category>
      <category domain="http://securityratty.com/tag/pcs video cam">pcs video cam</category>
      <category domain="http://securityratty.com/tag/months partial disclosure">months partial disclosure</category>
      <category domain="http://securityratty.com/tag/game">game</category>
      <category domain="http://securityratty.com/tag/demo">demo</category>
      <category domain="http://securityratty.com/tag/secretly spy">secretly spy</category>
      <category domain="http://securityratty.com/tag/cross-platform attackthreat">cross-platform attackthreat</category>
      <category domain="http://securityratty.com/tag/surveillance zombie">surveillance zombie</category>
      <source url="http://cyberinsecure.com/pc-webcams-might-be-abused-through-clickjacking-to-silently-spy-on-users/">PC Webcams Might Be Abused Through Clickjacking To Silently Spy On Users</source>
    </item>
    <item>
      <title><![CDATA[Modified Zeus Crimeware Kit Comes With Built-in MP3 Player]]></title>
      <link>http://securityratty.com/article/b4e5929a51488e98a9fe58b74de94b94</link>
      <guid>http://securityratty.com/article/b4e5929a51488e98a9fe58b74de94b94</guid>
      <description><![CDATA[Modified versions of popular open source crimeware kits rarely make the headlines due to the fact that anyone can hijack a crimeware kit's brand, build and innovate using its foundations , and claim...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOFSuEL8pNI/AAAAAAAACMg/GaTGj9uQ9hA/s1600-h/zeus_modified_mp3_player.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="160" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOFSuEL8pNI/AAAAAAAACMg/vkspv62-OAY/s200-R/zeus_modified_mp3_player.jpg" width="200" /></a>Modified versions of popular <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">open source crimeware kits</a> rarely make the headlines due to the fact that anyone can hijack a crimeware kit's brand, build and <a href="http://ddanchev.blogspot.com/2007/09/custom-ddos-capabilities-within-malware.html">innovate using its foundations</a>, and claim it's a new version <a href="http://ddanchev.blogspot.com/2008/05/custom-ddos-attacks-within-popular.html">released by the original authors</a>. That's of course in between the tiny time frame until he's exposed as the fake author of Zeus that may have in fact came up with a unique feature that the original authors didn't include.<br />
<br />
This <a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">modified version of Zeus</a> is yet another example of how <a href="http://ddanchev.blogspot.com/2007/09/localizing-open-source-malware.html">cybercriminals are actively modifying crimeware kits</a>, literally making such practices as keeping version numbers irrelevant. While the administrator is managing his botnet, he can load local, or tunein the built-in online radio stations the author of this modification included, next to changing Zeus entire graphical layout.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOFXXUuuCcI/AAAAAAAACMo/amKui3kRUEU/s1600-h/pinchy_2008_modified_opensource.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOFXXUuuCcI/AAAAAAAACMo/6el-_eHnyQs/s200-R/pinchy_2008_modified_opensource.jpg" /></a>Let's take into consideration another example, the infamous Pinch DIY malware builder, that's been around for over 4 years. With <a href="http://ddanchev.blogspot.com/2007/12/russias-fsb-vs-cybercrime.html">the populist arrest of its authors in 2007</a>, cybercriminals are still innovating on the foundations offered by Pinch, and <a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">thanks to its publicly obtainable source code</a>. It's also worth pointing out that these two Zeus and Pinch modifications are courtesy of a single individual, that in between modifications of popular crimeware kits, seems to be busy porting different modules on different malware kits and web based malware, knowingly or unknowingly contributing to the convergence of spamming, DDoS, web based malware, and botnet management kits.<br />
<br />
From a sarcastic perspective - what's next? Perhaps a built-in slideshow of random screenshots taken from malware infected desktops in the botnet, or even a pink layout modification for female botnet masters. Customerization, and <a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">customer tailored services can make anything happen</a>, and naturally enjoy the higher profit margins.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NlAiL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NlAiL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JOcjL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JOcjL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iqcal"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iqcal" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8Mjyl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8Mjyl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9dQOL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9dQOL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MQJML"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MQJML" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4yQcl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4yQcl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/406690696" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 13:55:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/web based malware">web based malware</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/female botnet masters">female botnet masters</category>
      <category domain="http://securityratty.com/tag/popular crimeware kits">popular crimeware kits</category>
      <category domain="http://securityratty.com/tag/zeus">zeus</category>
      <category domain="http://securityratty.com/tag/crimeware kits">crimeware kits</category>
      <category domain="http://securityratty.com/tag/authors">authors</category>
      <category domain="http://securityratty.com/tag/original authors">original authors</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/406690696/modified-zeus-crimeware-kit-comes-with.html">Modified Zeus Crimeware Kit Comes With Built-in MP3 Player</source>
    </item>
    <item>
      <title><![CDATA[QuickTime Crashing Zero-day Attack Code Published, Malicious Code Execution Possible]]></title>
      <link>http://securityratty.com/article/1a95d120eb958da72b7c7860bf2126e9</link>
      <guid>http://securityratty.com/article/1a95d120eb958da72b7c7860bf2126e9</guid>
      <description><![CDATA[According to Aaron Adams, a Symantec Corp.s DeepSight threat notification network researcher, new attack code that exploits an unpatched vulnerability in Apple Inc.s QuickTime was published on...]]></description>
      <content:encoded><![CDATA[According to Aaron Adams, a Symantec Corp.&#8217;s DeepSight threat notification network researcher, new attack code that exploits an unpatched vulnerability in Apple Inc.&#8217;s QuickTime was published on milw0rm.com in Tuesday, just a week after the company updated the media player to plug nine other serious vulnerabilities.
The exploit takes advantage of a flaw in the &#8220;&#60;? [...]]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 10:57:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attack code">attack code</category>
      <category domain="http://securityratty.com/tag/exploit takes advantage">exploit takes advantage</category>
      <category domain="http://securityratty.com/tag/quicktime">quicktime</category>
      <category domain="http://securityratty.com/tag/aaron adams">aaron adams</category>
      <category domain="http://securityratty.com/tag/symantec corp">symantec corp</category>
      <category domain="http://securityratty.com/tag/media player">media player</category>
      <category domain="http://securityratty.com/tag/exploits">exploits</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/apple">apple</category>
      <source url="http://cyberinsecure.com/quicktime-crashing-zero-day-attack-code-published-malicious-code-execution-possible/">QuickTime Crashing Zero-day Attack Code Published, Malicious Code Execution Possible</source>
    </item>
  </channel>
</rss>
