<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: prolific]]></title>
    <link>http://securityratty.com/tag/prolific</link>
    <description></description>
    <pubDate>Sun, 03 Feb 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Linux experiences 'prolific' growth, says Linux Foundation's Zemlin]]></title>
      <link>http://securityratty.com/article/8405dbdb8edb5d41554ad942141593fe</link>
      <guid>http://securityratty.com/article/8405dbdb8edb5d41554ad942141593fe</guid>
      <description><![CDATA[From mobile applications to high-performance computing. Linux has become increasingly central to all kinds of computing, says the Linux Foundation's Jim Zemlin. But is it really a two-horse race...]]></description>
      <content:encoded><![CDATA[From mobile applications to high-performance computing. Linux has become increasingly central to all kinds of computing, says the Linux Foundation's Jim Zemlin. But is it really a two-horse race between Linux and Microsoft?<img src="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~4/323510085" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 12:29:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/linux foundation">linux foundation</category>
      <category domain="http://securityratty.com/tag/linux">linux</category>
      <category domain="http://securityratty.com/tag/mobile applications">mobile applications</category>
      <category domain="http://securityratty.com/tag/jim zemlin">jim zemlin</category>
      <category domain="http://securityratty.com/tag/increasingly central">increasingly central</category>
      <category domain="http://securityratty.com/tag/two-horse race">two-horse race</category>
      <category domain="http://securityratty.com/tag/kinds">kinds</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <source url="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~3/323510085/0,289142,sid39_gci1319455,00.html">Linux experiences 'prolific' growth, says Linux Foundation's Zemlin</source>
    </item>
    <item>
      <title><![CDATA[Linux experiences 'prolific' growth, says Linux Foundation's Zemlin]]></title>
      <link>http://securityratty.com/article/80e1ad2612b3e808bafaf4a8b7335e06</link>
      <guid>http://securityratty.com/article/80e1ad2612b3e808bafaf4a8b7335e06</guid>
      <description><![CDATA[From mobile applications to high-performance computing. Linux has become increasingly central to all kinds of computing, says the Linux Foundation's Jim Zemlin. But is it really a two-horse race...]]></description>
      <content:encoded><![CDATA[From mobile applications to high-performance computing. Linux has become increasingly central to all kinds of computing, says the Linux Foundation's Jim Zemlin. But is it really a two-horse race between Linux and Microsoft?<img src="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~4/323988890" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 12:29:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/linux foundation">linux foundation</category>
      <category domain="http://securityratty.com/tag/linux">linux</category>
      <category domain="http://securityratty.com/tag/mobile applications">mobile applications</category>
      <category domain="http://securityratty.com/tag/jim zemlin">jim zemlin</category>
      <category domain="http://securityratty.com/tag/increasingly central">increasingly central</category>
      <category domain="http://securityratty.com/tag/two-horse race">two-horse race</category>
      <category domain="http://securityratty.com/tag/kinds">kinds</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <source url="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~3/323988890/0,289142,sid39_gci1319455,00.html">Linux experiences 'prolific' growth, says Linux Foundation's Zemlin</source>
    </item>
    <item>
      <title><![CDATA[EU bloggers under assault by the European Parliament - they need your help]]></title>
      <link>http://securityratty.com/article/42471dd2ecc3d3795053ea76949e5eeb</link>
      <guid>http://securityratty.com/article/42471dd2ecc3d3795053ea76949e5eeb</guid>
      <description><![CDATA[One of the nice things about having started the SBN was that I have gotten to meet (mostly virtually) many security bloggers from around the world. Some of the most prolific contributors to the...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>One of the nice things about having started the <a href="http://networks.feedburner.com/Security-Bloggers-Network/feed" target="_blank">SBN</a> was that I have gotten to meet (mostly virtually) many security <a class="zem_slink" title="Blog" href="http://en.wikipedia.org/wiki/Blog" rel="wikipedia">bloggers</a> from around the world.&nbsp; Some of the most prolific contributors to the content of the SBN has been the members of the <a href="http://pipes.yahoo.com/pipes/pipe.run?_id=ViJDI2KQ3BGXtQrlnkartA&amp;_render=rss" target="_blank">Belgian Security Bloggers Network</a>.&nbsp; I received word today from one of the authors of one of the blogs, <a href="http://belsec.skynetblogs.be/post/5962674/alarm--european-parliament-wants-to-take-on-b" target="_blank">belsec</a>, that they are under assault by the EU government.&nbsp; It seems in their wisdom, the <a href="http://www.europarl.europa.eu/meetdocs/2004_2009/documents/pr/712/712320/712320en.pdf" target="_blank">European Parliament has decided</a> that in the interests of &quot;media pluralism&quot;, all blog owners should declare their ownership, affiliations and status of weblog authors.</p>

<p>The explanatory notes of the proposed regulation says this:</p><blockquote><p><em>In this context the report points out that the undetermined and unindicated status of authors and publishers of weblogs causes uncertainties regarding impartiality, reliability, source protection, applicability of ethical codes and the assignment of liability in the event of lawsuits.<br />It recommends clarification of the legal status of different categories of weblog authors and publishers as well as disclosure of interests and voluntary labelling of weblogs.</em></p></blockquote><p>As the belsec author points out, disclosure of their identities would effectively silence their voices.&nbsp; There is no first amendment freedom of speech or <a class="zem_slink" title="Freedom of the press" href="http://en.wikipedia.org/wiki/Freedom_of_the_press" rel="wikipedia">freedom of press</a> constitutional right in Europe. Of course if forced to do so, the Belgian authors could take up blogs based here in the US and escape the disclosure laws of the EU, but why should they have too.&nbsp; The EU is a democratic, progressive entity.&nbsp; Forcing these bloggers to make their &quot;status and identity&quot; public should not be mandatory here.</p>

<p>Blogs are todays pamphlets.&nbsp; Basic <a class="zem_slink" title="Freedom of speech" href="http://en.wikipedia.org/wiki/Freedom_of_speech" rel="wikipedia">freedom of expression</a>, speech and press have been protected for hundreds of years. Forcing these bloggers to identify themselves is a violation of their rights.&nbsp; What would <a class="zem_slink" title="Thomas Paine" href="http://en.wikipedia.org/wiki/Thomas_Paine" rel="wikipedia">Thomas Paine</a> and others like him think of this restriction? </p>

<p>If you feel that this is an unfair and unjust restriction on bloggers rights, blog about it. It is our right and to do so and we should use the medium to do so.&nbsp; If you are a EU citizen write to your representative and demand that this proposed regulation does not go into effect!</p>

<p>Do not take your right to blog lightly.&nbsp; If you don't stand up for it, it can be taken away from you.</p>

<p><em>&quot;The world is my country, all mankind are my brethren, and to do good is my religion.&quot; - </em>Thomas Paine </p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/4f5ed85c-539c-4c67-8e62-8644ef78190e/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_a.png?x-id=4f5ed85c-539c-4c67-8e62-8644ef78190e" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 05:38:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bloggers">bloggers</category>
      <category domain="http://securityratty.com/tag/weblog authors">weblog authors</category>
      <category domain="http://securityratty.com/tag/authors">authors</category>
      <category domain="http://securityratty.com/tag/bloggers rights">bloggers rights</category>
      <category domain="http://securityratty.com/tag/freedom">freedom</category>
      <category domain="http://securityratty.com/tag/legal status">legal status</category>
      <category domain="http://securityratty.com/tag/blog owners">blog owners</category>
      <category domain="http://securityratty.com/tag/basic freedom">basic freedom</category>
      <category domain="http://securityratty.com/tag/status">status</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/eu-bloggers-und.html">EU bloggers under assault by the European Parliament - they need your help</source>
    </item>
    <item>
      <title><![CDATA[EU bloggers under assault by the European Parliament - they need your help]]></title>
      <link>http://securityratty.com/article/495d89a1106383a495fba74b3adf8fdb</link>
      <guid>http://securityratty.com/article/495d89a1106383a495fba74b3adf8fdb</guid>
      <description><![CDATA[One of the nice things about having started the SBN was that I have gotten to meet (mostly virtually) many security bloggers from around the world. Some of the most prolific contributors to the...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>One of the nice things about having started the <a href="http://networks.feedburner.com/Security-Bloggers-Network/feed" target="_blank">SBN</a> was that I have gotten to meet (mostly virtually) many security bloggers from around the world.&nbsp; Some of the most prolific contributors to the content of the SBN has been the members of the <a href="http://pipes.yahoo.com/pipes/pipe.run?_id=ViJDI2KQ3BGXtQrlnkartA&amp;_render=rss" target="_blank">Belgian Security Bloggers Network</a>.&nbsp; I received word today from one of the authors of one of the blogs, <a href="http://belsec.skynetblogs.be/post/5962674/alarm--european-parliament-wants-to-take-on-b" target="_blank">belsec</a>, that they are under assault by the EU government.&nbsp; It seems in their wisdom, the <a href="http://www.europarl.europa.eu/meetdocs/2004_2009/documents/pr/712/712320/712320en.pdf" target="_blank">European Parliament has decided</a> that in the interests of "media pluralism", all blog owners should declare their ownership, affiliations and status of weblog authors.</p> <p>The explanatory notes of the proposed regulation says this:</p> <blockquote> <p><em>In this context the report points out that the undetermined and unindicated status of authors<br>and publishers of weblogs causes uncertainties regarding impartiality, reliability, source<br>protection, applicability of ethical codes and the assignment of liability in the event of<br>lawsuits.<br>It recommends clarification of the legal status of different categories of weblog authors and<br>publishers as well as disclosure of interests and voluntary labelling of weblogs.</em></p></blockquote> <p>As the belsec author points out, disclosure of their identities would effectively silence their voices.&nbsp; There is no first amendment freedom of speech or freedom of press constitutional right in Europe. Of course if forced to do so, the Belgian authors could take up blogs based here in the US and escape the disclosure laws of the EU, but why should they have too.&nbsp; The EU is a democratic, progressive entity.&nbsp; Forcing these bloggers to make their "status and identity" public should not be mandatory here.&nbsp; </p> <p>If you feel that this is a restriction on bloggers rights, blog about it. It is our right and to do so and we should use the medium to do so.&nbsp; If you are a EU citizen write to your representative and demand that this proposed regulation does not go into effect!</p> <p>Do not take your right to blog lightly.&nbsp; If you don't stand up for it, it can be taken away from you.</p> <p><em>"The world is my country, all mankind are my brethren, and to do good is my religion." - </em>Thomas Paine </div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=RZd6mh"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=RZd6mh" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=cFCkbI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=cFCkbI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=2okMgI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=2okMgI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=YN5ouI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=YN5ouI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ApS9WI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ApS9WI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=oYLcIi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=oYLcIi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ebgmPi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ebgmPi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/310405700" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 04:38:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bloggers">bloggers</category>
      <category domain="http://securityratty.com/tag/weblog authors">weblog authors</category>
      <category domain="http://securityratty.com/tag/authors">authors</category>
      <category domain="http://securityratty.com/tag/legal status">legal status</category>
      <category domain="http://securityratty.com/tag/blog owners">blog owners</category>
      <category domain="http://securityratty.com/tag/status">status</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/bloggers rights">bloggers rights</category>
      <category domain="http://securityratty.com/tag/european parliament">european parliament</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/310405700/eu-bloggers-und.html">EU bloggers under assault by the European Parliament - they need your help</source>
    </item>
    <item>
      <title><![CDATA[Detection Rates for Malware in the Wild]]></title>
      <link>http://securityratty.com/article/6c1f7d34659a1e926821a4fa36eeaf9a</link>
      <guid>http://securityratty.com/article/6c1f7d34659a1e926821a4fa36eeaf9a</guid>
      <description><![CDATA[Yet another Early Warning Security Event System has been made available to the public, earlier this month. The Malware Threat Center is currently generating automated tracking reports in the following...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SBfkb9DpjPI/AAAAAAAABp4/EbaM8ey3Bdc/s1600-h/malware_detection_20th.jpg"><img id="BLOGGER_PHOTO_ID_5194871864092626162" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/SBfkb9DpjPI/AAAAAAAABp4/EbaM8ey3Bdc/s200/malware_detection_20th.jpg" border="0" /></a>Yet another <a href="http://ddanchev.blogspot.com/2007/06/early-warning-security-event-systems.html">Early Warning Security Event System</a> has been made available to the public, earlier this month. <a href="http://mtc.sri.com/">The Malware Threat Center</a> is currently generating automated tracking reports in the following sections :<br /><br />- Most Aggressive Malware Attack Source and Filters<br />- Most Effective Malware-Related Snort Signatures<br />- Most Prolific BotNet Command and Control Servers and Filters<br />- Most Observed Malware-Related DNS Names<br />- Most Effective Antivirus Tools Against New Malware Binaries<br />- Most Aggressively Spreading Malware Binaries<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SBflydDpjQI/AAAAAAAABqA/-u8DLem1CGk/s1600-h/malware_detection_29th.JPG"><img id="BLOGGER_PHOTO_ID_5194873350151310594" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SBflydDpjQI/AAAAAAAABqA/-u8DLem1CGk/s200/malware_detection_29th.JPG" border="0" /></a>I was particularly interested in the rankings in the "Most Effective Antivirus Tools Against New Malware Binaries" section, especially its emphasis on malware that's currently in the wild. Furthermore, to prove my point, you can see the top 10 list of Anti virus vendors as it were on the 20th, and the top 10 list of anti virus vendors as it were yesterday? Can you find the differences? Grisoft, Avira, Secure Computing and Quick Heal remain on the same<br />positions, whereas the rest of the vendors are in a different rank, although on the 20th they were exposed to 1030 binaries only, and on the 29th to 1759.<br /><br />So what? In respect to signatures based malware scanning, every vendor has its 15 minutes of fame, however, as <a href="http://ddanchev.blogspot.com/2006/08/virus-outbreak-response-time.html">I pointed out two years ago</a> :<br /><br />"<span style="font-style: italic;">Avoid the signatures hype and start rethinking the concept of malware on demand, open source malware, and the growing trend of malicious software to disable an anti virus scanner, or its ability to actually obtain the latest signatures available.</span>"<br /><br />What has changed? The <a href="http://ddanchev.blogspot.com/2008/04/new-diy-malware-in-wild.html">DIY nature of malware building</a>, the managed undetected binaries as a service coming with the purchase of proprietary malware tools, the fact that <a href="http://ddanchev.blogspot.com/2008/04/quality-and-assurance-in-malware.html">malware is tested against all the anti virus vendors</a> and the <a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">most popular personal firewalls </a>before it starts participating in a campaign, and is also getting <a href="http://ddanchev.blogspot.com/2006/09/benchmarking-and-optimising-malware.html">benchmarked and optimized</a> against the objectives set for its lifecycle. Moreover, with malware authors waging tactical warfare on the vendors infrastructure by supplying more malware variants than then can timely analyze, this tactical warfare on behalf of the malicious parties is only going to get more efficient.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RayZuG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RayZuG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RKlJgG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RKlJgG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5Qhmng"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5Qhmng" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qXkmFg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qXkmFg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4LmjWG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4LmjWG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=e4tfhG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=e4tfhG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OuE2Bg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OuE2Bg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/280690538" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 30 Apr 2008 00:58:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/signatures based malware">signatures based malware</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/source malware">source malware</category>
      <category domain="http://securityratty.com/tag/malware threat center">malware threat center</category>
      <category domain="http://securityratty.com/tag/malware binaries">malware binaries</category>
      <category domain="http://securityratty.com/tag/binaries">binaries</category>
      <category domain="http://securityratty.com/tag/vendors">vendors</category>
      <category domain="http://securityratty.com/tag/vendors infrastructure">vendors infrastructure</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/280690538/detection-rates-for-malware-in-wild.html">Detection Rates for Malware in the Wild</source>
    </item>
    <item>
      <title><![CDATA[Rock Phish gang adds second punch to phishing attacks]]></title>
      <link>http://securityratty.com/article/aed2d81782037816d0a6af49b0d2feb7</link>
      <guid>http://securityratty.com/article/aed2d81782037816d0a6af49b0d2feb7</guid>
      <description><![CDATA[A notorious online gang known for its prolific phishing operations has expanded its means of attack, potentially putting more PC users at risk of losing personal...]]></description>
      <content:encoded><![CDATA[A notorious online gang known for its prolific phishing operations has expanded its means of attack, potentially putting more PC users at risk of losing personal data.]]></content:encoded>
      <pubDate>Sun, 20 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/notorious online gang">notorious online gang</category>
      <category domain="http://securityratty.com/tag/personal data">personal data</category>
      <category domain="http://securityratty.com/tag/operations">operations</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/prolific">prolific</category>
      <source url="http://www.networkworld.com/news/2008/042108-rock-phish-gang-adds-second.html?fsrc=rss-security">Rock Phish gang adds second punch to phishing attacks</source>
    </item>
    <item>
      <title><![CDATA[UNICEF Too IFRAME Injected and SEO Poisoned]]></title>
      <link>http://securityratty.com/article/452a90ccfc35d6ad6a998c60113508e2</link>
      <guid>http://securityratty.com/article/452a90ccfc35d6ad6a998c60113508e2</guid>
      <description><![CDATA[The very latest, and hopefully very last, high profile site to successfully participate in the recently exposed massive SEO poisoning , is UNICEF's official site. In fact the campaign is so...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/R_IhMF281II/AAAAAAAABhQ/ZQqcx7ujQQ0/s1600-h/UNICEF_iframe_SEO1.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/R_IhMF281II/AAAAAAAABhQ/ZQqcx7ujQQ0/s200/UNICEF_iframe_SEO1.jpg" alt="" id="BLOGGER_PHOTO_ID_5184242612671665282" border="0" /></a>The very latest, and hopefully very last, high profile site to successfully participate in the recently exposed <a href="http://ddanchev.blogspot.com/2008/03/%20massive-iframe-seo-poisoning-attack.html">massive SEO poisoning</a>, is UNICEF's official site. In fact the campaign is so successful, where successful means that each and every poisoned result loads the injected IFRAME using UNICEF.org as a doorway to pharmaceutical spam and scams, that one of the most prolific domains within the IFRAMES (<span style="font-weight: bold;">highjar.info</span>) is already returning "<span style="font-style: italic;">Bandwidth Limit Exceeded. The server is temporarily unable to service your request due </span><span style="font-style: italic;">to the site owner reaching his/her bandwidth limit. Please try again later</span>" messages.<br /><br /><span style="font-weight: bold;">This is the perfect moment to point out that as of yesterday's afternoon the search engines that were indexing the SEO poisoned pages have implemented filters so that the malicious pages no longer appear in their indexes, thereby undermining the critical success factor for this campaign - hijacking search traffic</span>. Case closed? At least for now, and even though the black hat SEO is taken care of the last time I checked, some of the sites originally mentioned, and many others still need to take care of the web application vulnerabilities.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/R_Il4V281JI/AAAAAAAABhY/X04F34wws-A/s1600-h/UNICEF_iframe_SEO_poison.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/R_Il4V281JI/AAAAAAAABhY/X04F34wws-A/s200/UNICEF_iframe_SEO_poison.jpg" alt="" id="BLOGGER_PHOTO_ID_5184247770927387794" border="0" /></a>Tracking this campaign in a detailed manner inevitably results in a quality actionable intelligence data, in between the added value out of the historical preservation of evidence. The malicious parties behind this know what they're doing, they've been doing it in the past, and will continue doing it, therefore it's extremely important to document what was going on at a particular moment in time. It's all a matter of perspective, some care about the type of vulnerability exploited, others care who's hosting the rogue security applications and the malware, others want to establish the RBN connection, and others want to know who's behind this. <a href="http://ddanchev.blogspot.com/2006/09/cyber-intelligence-cyberint.html">Virtual situational awareness through CYBERINT</a> is what I care about.<br /><br />Let's close the case by assessing UNICEF.org's IFRAME injection state as of yesterday's afternoon. What is <span style="font-weight: bold;">highjar.info/error</span> (75.127.104.26) anyway? Before it felt the "UNICEF effect" in terms of traffic, it used to be a "<span style="font-style: italic;">Easy SEO | A Coaching Site For BEGINNING webmasters</span>". And the last time it was active, the injected redirect was forwarding to <span style="font-weight: bold;">ravepills.com/?TOPQUALITY</span> (69.50.196.63) and RavePills is what looks like a "legal alternative to Ecstasy" :<br /><br />"<span style="font-style: italic;">On the other hand, Rave is the safest option available to you without the fear of nasty side-effects or a long time in jail. Rave gives you the same buzz that the illegal ones do but without any proven side-effects. It's absolutely non-addictive &amp; is legal to possess in every country. Rave gives you the freedom to carry it anywhere you go as it also comes in a mini-pack of 10 capsules.</span>"<br /><br />IFRAMES injected within UNICEF.org :<br /><br /><span style="font-weight: bold;">highjar.info</span> (<span class="ipaddr">75.127.104.26)</span><br /><span style="font-weight: bold;">viagrabest.info</span> (<span class="ipaddr">81.222.139.184)</span><br /><span style="font-weight: bold;">pharmacytop.net</span> (<span class="ipaddr">216.98.148.6)</span><br /><span style="font-weight: bold;">grabest.info</span><br /><br />Now that the entire campaign received the necessary attention and raised awareness on its impact, let's move onto the next one(s), shall we?<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sOaGdMG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sOaGdMG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jWtKlrG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jWtKlrG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Bg8sI4g"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Bg8sI4g" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DKhNQLg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DKhNQLg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ikmbV4G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ikmbV4G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9j24zkG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9j24zkG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=X99fvfg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=X99fvfg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/261944315" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Apr 2008 03:42:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/seo">seo</category>
      <category domain="http://securityratty.com/tag/unicef">unicef</category>
      <category domain="http://securityratty.com/tag/easy seo">easy seo</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/site owner">site owner</category>
      <category domain="http://securityratty.com/tag/iframe">iframe</category>
      <category domain="http://securityratty.com/tag/unicef effect">unicef effect</category>
      <category domain="http://securityratty.com/tag/massive seo">massive seo</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/261944315/unicef-too-iframe-injected-and-seo.html">UNICEF Too IFRAME Injected and SEO Poisoned</source>
    </item>
    <item>
      <title><![CDATA[The Continuing Slide Towards Thoughtcrime]]></title>
      <link>http://securityratty.com/article/b7d75e490b04e1212ea1dd6092ffd22b</link>
      <guid>http://securityratty.com/article/b7d75e490b04e1212ea1dd6092ffd22b</guid>
      <description><![CDATA[A suggestion from the UK of putting primary-school children in a DNA database &quot;exhibit behaviour indicating they may become criminals in later life.&quot; Pugh's call for the government to consider options...]]></description>
      <content:encoded><![CDATA[<p>A <a href="http://www.guardian.co.uk/society/2008/mar/16/youthjustice.children">suggestion</a> from the UK of putting primary-school children in a DNA database "exhibit behaviour indicating they may become criminals in later life."</p>

<blockquote>Pugh's call for the government to consider options such as placing primary school children who have not been arrested on the database is supported by elements of criminological theory. A well-established pattern of offending involves relatively trivial offences escalating to more serious crimes. Senior Scotland Yard criminologists are understood to be confident that techniques are able to identify future offenders.

<p>A recent report from the think-tank Institute for Public Policy Research (IPPR) called for children to be targeted between the ages of five and 12 with cognitive behavioural therapy, parenting programmes and intensive support. Prevention should start young, it said, because prolific offenders typically began offending between the ages of 10 and 13. Julia Margo, author of the report, entitled 'Make me a Criminal', said: 'You can carry out a risk factor analysis where you look at the characteristics of an individual child aged five to seven and identify risk factors that make it more likely that they would become an offender.' However, she said that placing young children on a database risked stigmatising them by identifying them in a 'negative' way.</blockquote></p>

<p>Thankfully, the article contains some reasonable reactions:</p>

<blockquote>Shami Chakrabarti, director of the civil rights group Liberty, denounced any plan to target youngsters. 'Whichever bright spark at Acpo thought this one up should go back to the business of policing or the pastime of science fiction novels,' she said. 'The British public is highly respectful of the police and open even to eccentric debate, but playing politics with our innocent kids is a step too far.'

<p>Chris Davis, of the National Primary Headteachers' Association, said most teachers and parents would find the suggestion an 'anathema' and potentially very dangerous. 'It could be seen as a step towards a police state,' he said. 'It is condemning them at a very young age to something they have not yet done. They may have the potential to do something, but we all have the potential to do things. To label children at that stage and put them on a register is going too far.'</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=t3gA4vF"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=t3gA4vF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=qs07HfF"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=qs07HfF" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 18 Mar 2008 11:12:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/database">database</category>
      <category domain="http://securityratty.com/tag/dna database">dna database</category>
      <category domain="http://securityratty.com/tag/risk factor analysis">risk factor analysis</category>
      <category domain="http://securityratty.com/tag/individual child aged">individual child aged</category>
      <category domain="http://securityratty.com/tag/recent report">recent report</category>
      <category domain="http://securityratty.com/tag/public policy research">public policy research</category>
      <category domain="http://securityratty.com/tag/report">report</category>
      <category domain="http://securityratty.com/tag/whichever bright spark">whichever bright spark</category>
      <category domain="http://securityratty.com/tag/cognitive behavioural therapy">cognitive behavioural therapy</category>
      <source url="http://www.schneier.com/blog/archives/2008/03/the_continuing.html">The Continuing Slide Towards Thoughtcrime</source>
    </item>
    <item>
      <title><![CDATA[Russia becomes 'spam superpower': survey]]></title>
      <link>http://securityratty.com/article/2405c8ada9b9915a8db653bebd2d7fab</link>
      <guid>http://securityratty.com/article/2405c8ada9b9915a8db653bebd2d7fab</guid>
      <description><![CDATA[Russia has become a &quot;superpower&quot; of spam e-mail, becoming the second most prolific country after the United States in producing junk emails, a computer security firm said...]]></description>
      <content:encoded><![CDATA[Russia has become a "superpower" of spam e-mail, becoming the second most prolific country after the United States in producing junk emails, a computer security firm said Monday. ]]></content:encoded>
      <pubDate>Tue, 12 Feb 2008 08:11:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computer security firm">computer security firm</category>
      <category domain="http://securityratty.com/tag/russia">russia</category>
      <category domain="http://securityratty.com/tag/prolific country">prolific country</category>
      <category domain="http://securityratty.com/tag/junk emails">junk emails</category>
      <category domain="http://securityratty.com/tag/spam e-mail">spam e-mail</category>
      <category domain="http://securityratty.com/tag/superpower">superpower</category>
      <category domain="http://securityratty.com/tag/monday">monday</category>
      <source url="http://digg.com/security/Russia_becomes_spam_superpower_survey">Russia becomes 'spam superpower': survey</source>
    </item>
    <item>
      <title><![CDATA[Storm worm dethroned by sex botnet]]></title>
      <link>http://securityratty.com/article/fd5351907140bee12ee262a81e9db916</link>
      <guid>http://securityratty.com/article/fd5351907140bee12ee262a81e9db916</guid>
      <description><![CDATA[Romance is out and sex is in, according to security experts who said the Mega-Dik botnet has ousted the infamous Storm as the most prolific sender of...]]></description>
      <content:encoded><![CDATA[Romance is out and sex is in, according to security experts who said the Mega-Dik botnet has ousted the infamous Storm as the most prolific sender of spam.]]></content:encoded>
      <pubDate>Sun, 03 Feb 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mega-dik botnet">mega-dik botnet</category>
      <category domain="http://securityratty.com/tag/prolific sender">prolific sender</category>
      <category domain="http://securityratty.com/tag/infamous storm">infamous storm</category>
      <category domain="http://securityratty.com/tag/security experts">security experts</category>
      <category domain="http://securityratty.com/tag/sex">sex</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/romance">romance</category>
      <source url="http://www.networkworld.com/news/2008/020408-storm-worm-dethroned-by-sex.html?fsrc=rss-security">Storm worm dethroned by sex botnet</source>
    </item>
  </channel>
</rss>
