<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: receive]]></title>
    <link>http://securityratty.com/tag/receive</link>
    <description></description>
    <pubDate>Mon, 04 Aug 2008 06:23:13 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Technology Tales from Thailand: KBank Fraud Management]]></title>
      <link>http://securityratty.com/article/5f893d1cf14b7adbe58a329292652735</link>
      <guid>http://securityratty.com/article/5f893d1cf14b7adbe58a329292652735</guid>
      <description><![CDATA[In The Magical ATM Card and SMS Message in Thailand we talked about booking flights and securely paying using a SMS PayCode and ATM transfer, avoiding the possibility of on-line credit card fraud; and...]]></description>
      <content:encoded><![CDATA[<p>In <a title="The Magical ATM Card and SMS Message in Thailand" rel="bookmark" href="http://www.thecepblog.com/2008/08/03/the-magical-atm-card-and-sms-message-in-thailand/"><span style="color: #105cb6;">The Magical ATM Card and SMS Message in Thailand</span></a> we talked about booking flights and securely paying using a SMS PayCode and ATM transfer, avoiding the possibility of on-line credit card fraud; and in <a title="Keyloggers: Why Banks Need Two-Factor Authentication" rel="bookmark" href="http://www.thecepblog.com/2008/01/14/keyloggers-why-banks-need-two-factor-authentication/"><span style="color: #105cb6;">Keyloggers: Why Banks Need Two-Factor Authentication</span></a> I described how <a href="http://www.kasikornbank.com/portal/site/KBank/?" target="_blank">KBank</a> uses SMS-based one-time-passwords (OTP) to authenticate transactions.   </p>
<p>In addition to the above services, KBank offers a service that permits users to receive an SMS message that details any change in account balance and/or point-of-sale (POS) transaction with your debit card.   I really like this service and the feeling of security knowing when, where and by how much my balance changes or my debit card is used in a transaction.    The KBank POS SMS notification is so fast that when I present my card to a merchant I normally receive an SMS message detailing the transaction before the merchant returns for my signature.  (There is an unfortunate lag in the balance change notification that can run minutes to hours behind real-time, but the POS VISA debit card notification is real-time).</p>
<p>As the story goes,  I should have been using my KBank card and account a few weeks ago and not my US-based VISA debit dard.  Why?</p>
<p>My US-based VISA debit card was cloned sometime on or before August 8th.   I am really careful with this card, so I was surprised the magnetic strip was cloned at a POS merchant.   The fraudster made 7 fraudulent transactions beginning on August 8th for a total of around $2500 USD, mostly on August 11th, before I discovered the fraudulent transactions viewing my account on-line.</p>
<p>This would not have happened with KBank SMS-based transaction notification services.</p>
<p>The first transaction with my cloned VISA debit card was less than $50 USD (I assume the fraudster was &#8220;testing the water&#8221;).   If I was using my KBank card, I would have received an immediate SMS message detailing a POS transaction in Bangkok when I was physically far away from Bangkok in Chiang Mai.   I could have immediately called the bank (or logged in) and blocked the debit card, limiting potential losses to the bank or the merchant to one fraudulent transaction, not seven.</p>
<p>In addition, KBank offers what they call a Web-Shopping VISA card, where you can go into your on-line account (verified by SMS OTP as mentioned) and request a VISA debit card number (with expiration date, CCV etc).   You set the limit from 0 to 500,000 THB (Thai Baht) per day; and you can login to your account and change this anytime (authenticating your transaction with another SMS-based OTP). You can also block or cancel this number anytime and apply for another one.</p>
<p>I am amazed that in Thailand I receive much better anti-fraud prevention and detection services than with banks in the US.   I know of no bank or brokerage in the US that offers the same quality of service and security as KBank in Thailand.  </p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 03:16:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/visa debit card">visa debit card</category>
      <category domain="http://securityratty.com/tag/debit card">debit card</category>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/visa card">visa card</category>
      <category domain="http://securityratty.com/tag/kbank">kbank</category>
      <category domain="http://securityratty.com/tag/kbank card">kbank card</category>
      <category domain="http://securityratty.com/tag/transaction">transaction</category>
      <category domain="http://securityratty.com/tag/transaction notification services">transaction notification services</category>
      <category domain="http://securityratty.com/tag/fraudulent transaction">fraudulent transaction</category>
      <source url="http://www.thecepblog.com/2008/08/20/technology-tales-from-thailand/">Technology Tales from Thailand: KBank Fraud Management</source>
    </item>
    <item>
      <title><![CDATA[Why can't POP3 clients receive Exchange Server email?]]></title>
      <link>http://securityratty.com/article/2e398ebe1e1e54200cf3b7dfd8aad1f4</link>
      <guid>http://securityratty.com/article/2e398ebe1e1e54200cf3b7dfd8aad1f4</guid>
      <description><![CDATA[Get tips on how to download POP3 email to Microsoft Outlook mailboxes in a Microsoft Exchange Server...]]></description>
      <content:encoded><![CDATA[Get tips on how to download POP3 email to Microsoft Outlook mailboxes in a Microsoft Exchange Server setup.<img src="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~4/369642048" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/microsoft outlook mailboxes">microsoft outlook mailboxes</category>
      <category domain="http://securityratty.com/tag/download pop3 email">download pop3 email</category>
      <category domain="http://securityratty.com/tag/tips">tips</category>
      <source url="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~3/369642048/0,289625,sid43_gci1326076,00.html">Why can't POP3 clients receive Exchange Server email?</source>
    </item>
    <item>
      <title><![CDATA[VMware Big-Time Boo-Boo]]></title>
      <link>http://securityratty.com/article/f9466fc19dd83d3ab8c94a3fa2655f2a</link>
      <guid>http://securityratty.com/article/f9466fc19dd83d3ab8c94a3fa2655f2a</guid>
      <description><![CDATA[VMware needs some good press these days. What it certainly does not need is this VI 3.5 update snafu which can shutdown thousands of virtual infrastructures and breaks VMotion
Alert do not upgrade to...]]></description>
      <content:encoded><![CDATA[<p>VMware needs some good press these days. What it certainly does not need is this VI 3.5 update snafu which can <a href="http://www.virtualization.info/2008/08/vmware-mistake-shuts-down-thousands-of.html" target="_blank">shutdown “thousands of virtual infrastructures”</a> and breaks VMotion.
<p><b>Alert – do not upgrade to Virtual Infrastructure 3.5 Update 2.</b>
<p>Apparently there’s some problem with the license expiration time and the workaround suggested by a Virtualization.Info reader is to set the date back to August 10 – which of course messes up your logs and any monitoring that you may be doing. No immediate solution forthcoming from VMware and in fact, good luck getting in touch with the company.
<p>“At the moment it seems that <strong>the entire VMware Knowledge Base collapsed</strong>. Calling the support line customers can just receive a brief message saying that <strong>the problem will be solved within 36 hours</strong>. <br />Additionally, <strong>VMware removed the capability to download any affected product</strong>.”</p>
]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 14:49:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/support line customers">support line customers</category>
      <category domain="http://securityratty.com/tag/license expiration time">license expiration time</category>
      <category domain="http://securityratty.com/tag/virtual infrastructures">virtual infrastructures</category>
      <category domain="http://securityratty.com/tag/breaks vmotion">breaks vmotion</category>
      <category domain="http://securityratty.com/tag/info reader">info reader</category>
      <category domain="http://securityratty.com/tag/shutdown thousands">shutdown thousands</category>
      <category domain="http://securityratty.com/tag/virtual infrastructure">virtual infrastructure</category>
      <category domain="http://securityratty.com/tag/luck">luck</category>
      <source url="http://blog.sciencelogic.com/vmware-big-time-boo-boo/08/2008">VMware Big-Time Boo-Boo</source>
    </item>
    <item>
      <title><![CDATA[Soldiers Receive All-in-One Nonlethal Warfare Kit]]></title>
      <link>http://securityratty.com/article/7ba162df0c65e1fc7a3e90c514512abe</link>
      <guid>http://securityratty.com/article/7ba162df0c65e1fc7a3e90c514512abe</guid>
      <description><![CDATA[There are many ways to skin a cat without killing him, apparently, as the U.S. Army demonstrates with an array of new, nonlethal weapons designed for everything from checkpoint control to quelling...]]></description>
      <content:encoded><![CDATA[There are many ways to skin a cat without killing him, apparently, as the U.S. Army demonstrates with an array of new, nonlethal weapons designed for everything from checkpoint control to quelling rioters.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=979a1dd8929fcd1d0fcc49a33453b65c" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=979a1dd8929fcd1d0fcc49a33453b65c" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=xPX3nK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=xPX3nK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=9HxIyk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=9HxIyk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=q98sik"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=q98sik" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=0KvFQK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=0KvFQK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=frUlEK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=frUlEK" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=xZg26k"><img src="http://feeds.wired.com/~f/wired/politics/security?i=xZg26k" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=l9vx8k"><img src="http://feeds.wired.com/~f/wired/politics/security?i=l9vx8k" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=10FyQK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=10FyQK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/359612262" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/359612263" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 10:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nonlethal weapons">nonlethal weapons</category>
      <category domain="http://securityratty.com/tag/checkpoint control">checkpoint control</category>
      <category domain="http://securityratty.com/tag/array">array</category>
      <category domain="http://securityratty.com/tag/apparently">apparently</category>
      <category domain="http://securityratty.com/tag/skin">skin</category>
      <category domain="http://securityratty.com/tag/cat">cat</category>
      <category domain="http://securityratty.com/tag/rioters">rioters</category>
      <category domain="http://securityratty.com/tag/army">army</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/359612263/us-army-deploys.html">Soldiers Receive All-in-One Nonlethal Warfare Kit</source>
    </item>
    <item>
      <title><![CDATA[Fake IE7 Downloads Advertised Via EMail]]></title>
      <link>http://securityratty.com/article/755f51ea3a49474a6d4b3ee71d21215c</link>
      <guid>http://securityratty.com/article/755f51ea3a49474a6d4b3ee71d21215c</guid>
      <description><![CDATA[There seem to be quite a few of these in circulation over the past day or so

Download the latest version

About this mailing
You are receiving this e-mail because you subscribed to
MSN Featured...]]></description>
      <content:encoded><![CDATA[
        There seem to be quite a few of these in circulation over the past day or so:<br /><br /><i>Download the latest version! &lt;URL Removed&gt; <br /><br />About this mailing: <br />You are receiving this e-mail because you subscribed to<br />MSN Featured Offers. Microsoft respects your privacy.<br />If you do not wish to receive this MSN Featured Offers e-mail,<br />please click the "Unsubscribe" link below. This will not<br />unsubscribe you from e-mail communications from third-party<br />advertisers that may appear in MSN Feature Offers.<br />This shall not constitute an offer by MSN. MSN shall<br />not be responsible or liable for the advertisers' content<br />nor any of the goods or service advertised. Prices and item<br />availability subject to change without notice.<br /><br />2008 Microsoft | Unsubscribe &lt;http://www.msn.com&gt;&nbsp; |<br />More Newsletters &lt;http://www.msn.com&gt;&nbsp; |<br />Privacy &lt;http://www.msn.com&gt; <br /><br />Microsoft Corporation, One Microsoft Way, Redmond, WA 98052</i><br /><br />As you might have guessed, it's fake. Microsoft don't send out EMails asking you to download files from random, non-Microsoft websites. This:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="ie71.jpg" src="http://blog.spywareguide.com/images/ie71.jpg" class="mt-image-none" style="" height="63" width="76" /></span></div><br /> <div>....is not what it appears to be. Run the file, and instead of IE7, you're actually more likely to see a fake antivirus program appear on your desktop:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/top106.html" onclick="window.open('http://blog.spywareguide.com/images/top106.html','popup','width=700,height=540,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/top106-thumb-300x231.jpg" alt="top106.jpg" class="mt-image-none" style="" height="231" width="300" /></a></span>
<br /><br />Click to Enlarge<br /></div><br />This particular fake AV is also being pushed quite heavily via the recent <a href="http://blog.spywareguide.com/2008/08/cnn-daily-top-10-videos-spam.html">CNN videos scam</a>. You can see another example of these emails <a href="http://miekiemoes.blogspot.com/2008/08/beware-of-fake-email-from-microsoft.html">here</a>. There is more than one URL being used for this attack, so be alert!<br /></div>
        
    ]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 10:56:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/offers">offers</category>
      <category domain="http://securityratty.com/tag/offers e-mail">offers e-mail</category>
      <category domain="http://securityratty.com/tag/fake">fake</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/non-microsoft websites">non-microsoft websites</category>
      <category domain="http://securityratty.com/tag/msn feature offers">msn feature offers</category>
      <category domain="http://securityratty.com/tag/msn">msn</category>
      <category domain="http://securityratty.com/tag/microsoft corporation">microsoft corporation</category>
      <category domain="http://securityratty.com/tag/microsoft respects">microsoft respects</category>
      <source url="http://blog.spywareguide.com/2008/08/fake-ie7-downloads-advertised.html">Fake IE7 Downloads Advertised Via EMail</source>
    </item>
    <item>
      <title><![CDATA[Pinch Vulnerable to Remotely Exploitable Flaw]]></title>
      <link>http://securityratty.com/article/8cbf69361bdc83216c6de0e5e5d551a0</link>
      <guid>http://securityratty.com/article/8cbf69361bdc83216c6de0e5e5d551a0</guid>
      <description><![CDATA[In the very same way a cybercrime analyst is reverse engineering and sandboxing a particular piece of malware in order to get a better understanding of who's being it, and how successful the campaign...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SJr2wBCCcbI/AAAAAAAACAU/4ibYnLwvG5E/s1600-h/olly_pinch1.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://3.bp.blogspot.com/_wICHhTiQmrA/SJr2wBCCcbI/AAAAAAAACAU/vIpz-Oz9m-I/s200-R/olly_pinch1.jpg" style="border: 0pt none ;" /></a>In the very same way a cybercrime analyst is reverse engineering and sandboxing a particular piece of malware in order to get a better understanding of who's being it, and how successful the campaign is once access to the command and control interface is obtained, cybercriminals themselves are actively reverse engineering the most popular crimeware kits, looking, and actually finding remotely exploitable vulnerabilities allowing them to competely hijack someone's command and control, and consequently, their botnet. <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus crimeware kit</a>, which I've been discussing and analyzing for a while, is the perfect example of how once a popular underground kit start acting as the default crimeware kit, cybercriminals themselves start looking for vulnerabilities that they could take advantage of. And those who look, usually end up finding.<br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SJr4tst_etI/AAAAAAAACAc/CS74dFmlSnI/s1600-h/olly_pinch2.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SJr4tst_etI/AAAAAAAACAc/bsEI2r8i-pQ/s200-R/olly_pinch2.jpg" style="border: 0pt none ;" /></a>A remotely exploitable flaw allowing cybercriminals to remotely inject a web shell within another cybercriminal's web command and control interface of the popular Pinch crimeware that's been around VIP underground forums since June, 2007, is starting to receive the necessary attention from script kiddies catching up with the possibility of hijacking someone's malware campaign due to misconfigured command and control servers.<br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SJsF-ZurkWI/AAAAAAAACAs/LVKZqt0ByJ8/s1600-h/pinchy_xploit_2007.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SJsF-ZurkWI/AAAAAAAACAs/QG5JJkQkpdA/s200-R/pinchy_xploit_2007.jpg" style="border: 0pt none ;" /></a>With the exploit now in the wild, retro cybercriminals still taking advantege of the ubiqutous command and control interface that could be easily used by other malware rathar than Pinch, "cybercriminals are advised" to randomize the default file name of the gate, and apply the appropriate directory permissions.<br />
&nbsp; <br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SJr8JNV5sSI/AAAAAAAACAk/11YT40IAhXY/s1600-h/pinchy.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SJr8JNV5sSI/AAAAAAAACAk/uR5fQjtRtb4/s200-R/pinchy.jpg" style="border: 0pt none ;" /></a>Monocultural insecurities are ironically started to emerge in the IT underground with the increasing commoditization of what used to be a proprietary web exploitation malware kit or a banker malware kit, allowing easy entry into the malware industry through the unregulated use of what some would refer to as an "advanced technology" that only a few cybercriminals used to have access to an year ago.&nbsp; Just like legitimate software vendors, <a href="https://forums.symantec.com/syment/blog/article?message.uid=319059">authors of crimeware kits are also trying to enforce their software licenses</a> and forbidding any reverse engineering of their kits in order to enjoy the false feeling of security provided by the security through obscurity. The result? <a href="http://blogs.zdnet.com/security/?p=1598">Cybercrime groups filing for bankruptcy unable to achieve a positive return on investment</a> due to their intellectual property getting pirated and their inability to enforce the licenses that they issue to their customers.<br />
<br />
We're definitely going to see more trivial, but then again, remotely exploitable vulnerabilities within popular crimeware kits, which can assist both the cybercrime analysts and naturally the cybercriminals themselves. For the time being, even the most sophisticated malware campaigns aren't fully taking advantage of the evasive and stealth tactics that the kits, or their common sense allows them to - let's see for how long.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/12/russias-fsb-vs-cybercrime.html">Russia's FSB vs Cybercrime </a><b><br />
</b><a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">Crimeware in the Middle - Zeus </a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a><b><b><br />
</b></b><br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=D62EBK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=D62EBK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mvg6vK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mvg6vK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GZqrpk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GZqrpk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iQ5kkk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iQ5kkk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3Od80K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3Od80K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=063dRK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=063dRK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=v5CZlk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=v5CZlk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/358495127" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 06:22:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/popular crimeware kits">popular crimeware kits</category>
      <category domain="http://securityratty.com/tag/crimeware kits">crimeware kits</category>
      <category domain="http://securityratty.com/tag/pinch">pinch</category>
      <category domain="http://securityratty.com/tag/crimeware">crimeware</category>
      <category domain="http://securityratty.com/tag/zeus crimeware kit">zeus crimeware kit</category>
      <category domain="http://securityratty.com/tag/popular pinch crimeware">popular pinch crimeware</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/banker malware kit">banker malware kit</category>
      <category domain="http://securityratty.com/tag/default crimeware kit">default crimeware kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/358495127/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</source>
    </item>
    <item>
      <title><![CDATA[Cross-site scripting CAN be used to hack a server]]></title>
      <link>http://securityratty.com/article/731632e92c0fca2d6e043211ca4b8c08</link>
      <guid>http://securityratty.com/article/731632e92c0fca2d6e043211ca4b8c08</guid>
      <description><![CDATA[Likely you remember when Joseph Pierini at McAfee Secure / Hacker Safe said XSS wasn't important because &quot;cross-site scripting can't be used to hack a server. You may be able to do other things with...]]></description>
      <content:encoded><![CDATA[Likely you remember when Joseph Pierini at McAfee Secure / Hacker Safe said XSS wasn't important because <span style="font-style:italic;">"cross-site scripting can't be used to hack a server. You may be able to do other things with it. You may be able to do things that affect the end-user or the client. But the customer data protected with the server, in the database, isn't going to be compromised by a cross-site scripting attack, not directly."</span><br />That gem has made McAfee <a href="http://pwnie-awards.org/2008/awards.html#lamestvendor" target="_blank">Pwnie</a> worthy (winners announced tomorrow!); may the Lamest Vendor win. <br />That said, anyone with a clue knows that XSS attacks are ideal for credential theft, and if you can steal credentials, you can hack a server.<br />Looking for a textbook example? Check out <a href="http://skeptikal.org/static.php?page=about_mckt" target="_blank">mckt's</a> new blog, <a href="http://skeptikal.org/" target="_blank">skeptikal.org</a>.<br /><span style="font-weight:bold;">Here's a highlight:</span><br /><span style="font-style:italic;">"Every cPanel user's account contains a file titled .contactemail in its home directory. This is used to tell the server and administrators who to email when things go south, and can be changed by the user through the cPanel interface, the file manager tool, FTP, or through local scripts. It's only a text file, after all. Assuming we set our email address to:<br />"onmouseover="alert(1337)<br />When the friendly system administrator tries to reset our email address (because we forgot our password, obviously), he will receive an alert box in his browser.<br />But an alert box doesn't really demonstrate anything. Fortunately the WHM (Web Hosting Manager) interface has enough functionality that we can perform just about any system-level task we want. This one will reset the root password to 'owned':<br />"onmouseover="f=document.forms[0];f.action='/scripts/passwd';f.user.value='root';<br />f.removeChild(f.domain);d=document.createElement('input');f.appendChild(d);<br />d.name='password';d.value='owned';d=document.createElement('input');f.appendChild(d);<br />d.name='password2';d.value='owned';f.submit()<br />Of course, the only limit is your imagination- WHM can set up cron jobs, add and delete users, send full backups to a server of your choice, and reformat hard drives."</span><br /><br />Hmm...I'd say that would be a server hack. ;-)<br />Welcome, Mike...keep up the good work.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/08/cross-site-scripting-can-be-used-to.html&title=Cross-site%20scripting%20can%20be%20used%20to%20hack%20a%20server " title="Cross-site scripting can be used to hack a server ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/08/cross-site-scripting-can-be-used-to.html" title="Cross-site scripting can be used to hack a server ">digg</a>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 18:06:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/server hack">server hack</category>
      <category domain="http://securityratty.com/tag/hack">hack</category>
      <category domain="http://securityratty.com/tag/manager">manager</category>
      <category domain="http://securityratty.com/tag/file manager tool">file manager tool</category>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/root password">root password</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/cpanel user">cpanel user</category>
      <source url="http://holisticinfosec.blogspot.com/2008/08/cross-site-scripting-can-be-used-to.html">Cross-site scripting CAN be used to hack a server</source>
    </item>
    <item>
      <title><![CDATA[Compromised Web Servers Serving Fake Flash Players]]></title>
      <link>http://securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</link>
      <guid>http://securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</guid>
      <description><![CDATA[The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/SSFpGnP3wvA/s1600-h/fake_flash1.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/qKqvrWeAN3s/s200-R/fake_flash1.png" style="border: 0pt none ;" /></a>The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so much confidence in this risk-forwarding process of hosting their campaigns, that they would start actively spamming the links residing within low-profile legitimate sites across the web.<br />
<br />
This campaign serving fake flash players is getting so prevalent these days due to the multiple spamming approaches used, that it's hard not to notice it - and expose it. From a strategic perspective, having a legitimate low-profile site -- of course with the obvious exceptions being on purposely registered for malicious purposes within the participating sites -- hosting your malicious campaign is pretty creative in terms of forwarding the responsibility, and the eventual blocking of a legitimate site to the its owner. As far as the owner's are concerned, it appears that some of them are already seeing the malware page popping-up on the top of their daily traffic stats, and have taken measures to remove it.<br />
<br />
Moreover, <a href="http://blogs.adobe.com/psirt/2008/08/verifying_installers.html">Adobe's Product Security Incident Response Team (PSIRT) issued a warning notice about the attack yesterday</a>, which could come handy if the <a href="http://www.infoworld.com/article/08/08/05/Adobe_warns_of_bogus_Flash_Player_installers_1.html">attackers weren't taking advantage of client-side vulnerabilities</a>, putting the unware end user is a situation where he <a href="http://blogs.stopbadware.org/articles/2008/08/05/same-dogs-new-tricks">wouldn't even receive a download dialog</a> :<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/LuFjz3rFLAc/s1600-h/fake_flash3_exploit.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/GXwA3Ai1LLY/s200-R/fake_flash3_exploit.jpg" style="border: 0pt none ;" /></a>"<i>We have seen coverage from the security community of a worm on popular social networking sites that is using social engineering lures to get users to install a piece of malware. According to the reports, the worm posts comments on these sites that include links to a fake site. If the link is followed, users are told they need to update their Flash Player. The installer, posted on a malicious site, of course installs malware instead of Flash Player.We’d like to take this opportunity to reiterate the importance of validating installers and updates before installing them. First off, do not download Flash Player from a site other than adobe.com – you can find the link for downloading Flash Player here. This goes for any piece of software (Reader, Windows Media Player, Quicktime, etc.) – if you get a notice to update, it’s not a bad idea to go directly to the site of the software vendor and download the update directly from the source. If the download is from an unfamiliar URL or an IP address, you should be suspicious.</i>"<br />
<br />
<a href="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/6PfKZxTNQao/s1600-h/fake_flash2.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/ADBheDs2hkk/s200-R/fake_flash2.png" style="border: 0pt none ;" /></a>The structure of the malware campaign is pretty static, with several exceptions where they also take advange of client-side vulnerabilities (Real player exploit) attempting to automatically deliver the fake flash update or player depending on the campaign. On each and every site, there are <b>dnd.js</b> and <b>master.js</b> scripts shich serve the rogue download window, and another .html file, where an IFRAME attempts to access the traffic management command and control, in a random URL it was <b>207.10.234.217/cgi-bin/index.cgi?user200</b>. A sample list of participating URLs, most of which are still active and running :<br />
<br />
<div style="text-align: left;"><b>joseantoniobaltanas .com</b></div><b>automoviliaria .es/hotnews.html<br />
risasnc .it/fresh.html<br />
carpe-diem .com.mx/fresh.html<br />
kotilogullari .com.tr/hotnews.html<br />
ferrariclubpesaro .it/hotnews.html<br />
imobiliariacom .com.br/default.html<br />
misoares .com<br />
osniehus .de/fresh.html<br />
mydirecttube .com/1/5098/<br />
madosma .com/default.html<br />
tutotic .com/checkit.html<br />
veit-team .si/default.html<br />
antigewaltkurse .de/stream.html<br />
kwhgs .ca/topnews.html<br />
vorgo .com/stream.html<br />
ankaraspor .com.tr/default.html<br />
xxxdnn0314 .locaweb.com.br/watchit.html<br />
ossuzio .com/watchit.html<br />
cit-inc .net/default.html<br />
negocioindependiente .biz/default.html<br />
ambermarketing .com/topnews.html<br />
web27 .login-7.loginserver.ch/stream.html<br />
moretewebdesign .br-web.com/stream.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/hotnews.html<br />
campodifiori .it/topnews.html<br />
212.50.55.81 /stream.html<br />
logisigns .net/fresh.html<br />
intimaescorts .com/default.html<br />
ghioautotre .it/live.html<br />
geckert .de/stream.html<br />
yuricardinali .com/watchit.html<br />
retder .com/fresh.html<br />
valdaran .es/default.html<br />
getadultaccess .com/movie/?aff=5274<br />
bauelemente-giering .de/stream.html<br />
newyork-hebergement .com/watchit.html<br />
allevatoritrotto .it/live.html<br />
exoss2 .com/hotnews.html<br />
soundandlightkaraoke .com/stream.html<br />
land-kan .com/stream.html<br />
grimaldi.nexenservices .com/watchit.html<br />
inconstancia .com.br/watchit.html <br />
gretelstudio .com/stream.html<br />
sumacyl .com/watchit.html<br />
mysna .net/fresh.html<br />
gimnasioyx .com.ar/watchit.html<br />
lagalbana .com/watchit.html<br />
bielizna.tgory .pl/topnews.html<br />
bcs92.imingo .net/stream.html<br />
lapiramidecoslada .es/topnews.html<br />
raulortega .com/stream.html<br />
go-art-morelli .de/hotnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
dianagraf .es/default.html<br />
komma10-thueringen .de/hotnews.html<br />
miavassilev .com/stream.html<br />
swampgiants .com/watchit.html<br />
compagniedephalsbourg .com/fresh.html<br />
arla-rc .net/hotnews.html<br />
salacopernico .es/watchit.html<br />
drfinster .de/checkit.html<br />
healthylifehypnotherapy .com/stream.html<br />
ecotrike-bg .com/fresh.html<br />
paoepalavra .org/watchit.html<br />
jureplaninc-sp .com/topnews.html<br />
fichte-lintfort .de/default.html<br />
hergert-band .de/checkit.html<br />
izliyorum .org/topnews.html<br />
lideka .com/stream.html<br />
athena-digitaldesign .com.tw/hotnews.html<br />
e-paso .pl/stream.html<br />
colombeblanche .org/stream.html<br />
teatromalasa .es/watchit.html<br />
mesporte.digiweb.com .br/stream.html<br />
bistrodavila.com .br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
jbhumet .com/default.html<br />
gruppouni .com/hotnews.html<br />
francex .net/fresh.html<br />
galvatoledo .com/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
kroenert .name/default.html<br />
textilhogarnovadecor .com/topnews.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
neticon .pl/hotnews.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
easterstreet .de/fresh.html<br />
piogiovannini .com.ar/watchit.html<br />
ser-all .com/topnews.html<br />
petzold-dieter .de/checkit.html<br />
beatmung-brandenburg .de/checkit.html<br />
ossuzio .com/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
zelenaratolest .cz/pornotube/index1.htm<br />
ambulatoriovirtuale .it/topnews.html<br />
10a3 .ru/index1.php<br />
izliyorum .org/topnews.html<br />
collectedthoughts .co.uk/index12.html<br />
afg .es/topnews.html<br />
albertruiz .net/topnews.html<br />
bielizna.tgory .pl/topnews.html<br />
blueseven.com .br/topnews.html<br />
bollettinogiuridicosanitario .it/topnews.html<br />
caprilchamonix.com .br/topnews.html<br />
carlolongarini .it/topnews.html<br />
champimousse .com/topnews.html<br />
cheviot.org .nz/topnews.html<br />
contrapie .com/topnews.html<br />
gruppouni .com/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
herbatele .com/topnews.html<br />
houseincostaricaforsale .com/topnews.html<br />
alim.co .il/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
amafe .org/topnews.html<br />
ambulatoriovirtuale .it/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
automoviliaria .es/topnews.html<br />
autoreserve .fr/topnews.html<br />
izliyorum .org/topnews.html<br />
jureplaninc-sp .com/topnews.html<br />
kwhgs .ca/topnews.html<br />
lapiramidecoslada .es/topnews.html<br />
last-minute-reisen-4u .de/topnews.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
corradiproject .info/topnews.html<br />
dantealighieriasturias .es/topnews.html<br />
deliriuslaspalmas .com/topnews.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/topnews.html<br />
fonavistas .com/topnews.html<br />
fraemma .com/topnews.html<br />
fundmyira .com/topnews.html<br />
galvatoledo .com/topnews.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
markmaverick .com/topnews.html<br />
micela .info/topnews.html<br />
motoclubnosvamos .com/topnews.html<br />
nebottorrella .com/topnews.html<br />
negozistore .it/topnews.html<br />
neticon .pl/topnews.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
segelclub-honau .de/topnews.html<br />
snmobilya .com/topnews.html<br />
splashcor .com.br/topnews.html<br />
stephanmager .gmxhome.de/topnews.html<br />
svcanvas .com/topnews.html<br />
tautau.web .simplesnet.pt/topnews.html<br />
textilhogarnovadecor .com/topnews.html<br />
theflorist4u .com/topnews.html<br />
thewindsorhotel .it/topnews.html<br />
vuelosultimahora .com/topnews.html<br />
aliarzani .de/topnews.html<br />
ambermarketing .com/topnews.html<br />
arnold82.gmxhome .de/topnews.html<br />
ocoartefatos.com .br/topnews.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
projetsoft .net/topnews.html<br />
rbc.gmxhome .de/topnews.html<br />
beatmung-sachsen .eu/topnews.html<br />
campodifiori .it/topnews.html<br />
clickjava .net/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
dammer .info/topnews.html<br />
embedded-silicon .de/topnews.html<br />
ferrariclubpesaro .it/topnews.html<br />
fgwiese .de/topnews.html<br />
fswash.site .br.com/topnews.html<br />
fytema .es/topnews.html<br />
gildas-saliou. com/topnews.html<br />
go-art-morelli .de/topnews.html<br />
go-siegmund .de/topnews.html<br />
guerrero-tuning .com/topnews.html<br />
gut-barbarastein .de/topnews.html<br />
japansec .com/topnews.html<br />
komma10-thueringen .de/topnews.html<br />
koon-design .de/topnews.html<br />
lanz-volldiesel .de/topnews.html<br />
lauscher-staat .de/topnews.html<br />
losnaranjos.com .es/topnews.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
nepi.si/topnews .html<br />
radieschenhein. de/topnews.html<br />
residenceflora .it/topnews.html<br />
sabuha .de/topnews.html<br />
ser-all .com/topnews.html<br />
siemieniewicz .de/topnews.html<br />
viajesk .es/topnews.html<br />
allevatoritrotto .it/live.html<br />
bollettinogiuridicosanitario .it/live.html<br />
carlolongarini .it/topnews.html<br />
maremax .it/topnews.html<br />
negozistore .it/topnews.html<br />
parapendiolestreghe .it/live.html<br />
www.donlisander .it/stream.html<br />
aerogenesis .net/watchit.html<br />
allevatoritrotto .it/live.html<br />
atelier-de-loulou .fr/topnews.html<br />
bistrodavila.com .br/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
caprilchamonix.com .br/topnews.html<br />
cheviot.org .nz/live.html<br />
condorautocenter .com.br/watchit.html<br />
dantealighieriasturias .es/live.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/live.html<br />
fonavistas .com/topnews.html<br />
fundmyira .com/topnews.html<br />
g6esporte .com.br/stream.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
gretelstudio .com/stream.html<br />
gutierrezymoralo .com/watchit.html<br />
healthylifehypnotherapy .com/stream.html<br />
herbatele .com/live.html<br />
jureplaninc-sp .com/topnews.html<br />
lacomercialsrl .com.ar/stream.html<br />
lagalbana .com/watchit.html<br />
lapuertaestrecha .com.es/watchit.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
myadultcube .com/flash//aff=5176<br />
myadultcube .com/flash//aff=5810<br />
myadultcube .com/movie//aff=5155<br />
newyork-hebergement .com/watchit.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
omdconsulting .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
parapendiolestreghe .it/live.html<br />
regesh. co.il/watchit.html<br />
rikkeroenneberg .dk/watchit.html<br />
s215847279 .onlinehome.fr/stream.html<br />
salacopernico .es/watchit.html<br />
seekzones .com/watchit.html<br />
seicomsl .es/watchit.html<br />
sigma-lux .ro/watchit.html<br />
soundandlightkaraoke .com/stream.html<br />
stephanmager.gmxhome .de/topnews.html<br />
tartuinstituut .ca/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
aliarzani .de/topnews.html<br />
ambermarketing. com/live.html<br />
bilbondo .com/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
colombeblanche .org/stream.html<br />
donlisander .it/stream.html<br />
fgwiese .de/topnews.html<br />
geckert .de/stream.html<br />
helene-taucher .de/watchit.html<br />
lanz-volldiesel .de/topnews.html<br />
mairie-margnylescompiegne .fr/watchit.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
ossuzio .com/watchit.html<br />
piogiovannini .com.ar/watchit.html<br />
sabuha .de/topnews.html<br />
sumacyl .com/watchit.html<br />
swampgiants .com/watchit.html<br />
xn--glland-3ya .de/stream.html<br />
yuricardinali .com/watchit.html</b><br />
<b>nepi .si/topnews.html<br />
dammer .info/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
galvatoledo .com/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
micela .info/topnews.html<br />
bistrodavila .com.br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
gruppouni .com/hotnews.html<br />
galvatoledo .com/topnews.html<br />
kroenert .name/default.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
dantealighieriasturias .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
89.19.29 .13/stream.html<br />
slobodandjakovic .com/fresh.html<br />
cqcs.com .br/stream.html<br />
seekzones .com/watchit.html<br />
pascosa .it/stream.html<br />
caprilchamonix .com.br/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
ferien-urlaub-lastminute .de/default.html<br />
mueggelpark .info/watchit.html<br />
hillner-online .de/fresh.html<br />
guiasaojose .net/default.html<br />
deliriuslaspalmas .com/topnews.html<br />
fraemma .com/topnews.html<br />
morsbaby .net/default.html<br />
vickywhite .com/fresh.html<br />
micela .info/topnews.html<br />
corradiproject .info/topnews.html<br />
liguehavraise .com/live.html<br />
capacitacaoemlideranca .com.br/fresh.html<br />
materialesyacabados .com.mx/stream.html<br />
208.112.7.68 /checkit.html<br />
152.10.1.37 /1.html<br />
carlolongarini .it/topnews.html<br />
splashcor.com .br/topnews.html<br />
lobpreisstrasse .org/1.html<br />
motoclubnosvamos .com/hotnews.html<br />
hk-rc.com /1.html<br />
taaf.re /stream.html<br />
dulceysalao .com/default.html<br />
amafe .org/topnews.html <br />
</b><br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/MTxnF1XLDCw/s1600-h/fake_flash3_rogue_software.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/3Dgh4x23dRs/s200-R/fake_flash3_rogue_software.png" style="border: 0pt none ;" /></a>Sample detection rate : <span id="status_nombre">flashupdate.exe</span><br />
<span id="status_nombre"><b>Scanners Result</b>: 35/36 (97.23%)</span><br />
<span id="status_nombre">Trojan-Downloader.Win32.Exchanger.hk; Troj/Cbeplay-A</span><br />
<b>File size</b>: 78848 bytes<br />
<b>MD5</b>...: c81b29a3662b6083e3590939b6793bb8<br />
<b>SHA1</b>..: d513275c276840cb528ce11dd228eae46a74b4b4<br />
<br />
The downloader then "phones back home" at <b>72.9.98.234 port 443 </b>which is responding to the rogue security software AntiSpy Spider (<b>antispyspider.net</b>) :<br />
<br />
"<i>AntiSpy Spider is a cutting-edge anti-spyware solution.This revolutionary anti-spyware program was created by the industry's top spyware experts in order to protect your computer and your privacy.html, while ensuring optimal system performance.With the ability to locate, eliminate and prevent the widest range of spyware threats, AntispyStorm is able to offer its users a safe, spyware-free computing experience; and with it's convenient automatic update feature, AntispyStorm ensures continuous up-to-date protection.</i>" <br />
<br />
Sample detection rate : antispyspider.msi<br />
<b>Scanners Result</b>: 11/35 (31.43%)<br />
FraudTool.Win32.AntiSpySpider.b;&nbsp; <br />
<b>File size</b>: 1851904 bytes<br />
<b>MD5</b>...: 2f1389e445f65e8a9c1a648b42a23827<br />
<b>SHA1</b>..: e32aa6aa791e98fe6fdef451bd3b8a45bad0acd8<br />
<br />
The bottom line - over a thousand domains are participating, with many other apparently joining the party proportionally with the web site owner's actions to get rid of the malware campaign hosted on their servers.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BvcTqK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BvcTqK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=onawHK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=onawHK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4fa1ek"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4fa1ek" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5nQAgk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5nQAgk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sqdHIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sqdHIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mq3LKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mq3LKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8zplkk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8zplkk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/356677080" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 10:50:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/html file">html file</category>
      <category domain="http://securityratty.com/tag/html">html</category>
      <category domain="http://securityratty.com/tag/comtopnews">comtopnews</category>
      <category domain="http://securityratty.com/tag/detopnews">detopnews</category>
      <category domain="http://securityratty.com/tag/windows media player">windows media player</category>
      <category domain="http://securityratty.com/tag/player">player</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/real player exploit">real player exploit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/356677080/compromised-web-servers-serving-fake.html">Compromised Web Servers Serving Fake Flash Players</source>
    </item>
    <item>
      <title><![CDATA[Library QUSRSYS not completely installed]]></title>
      <link>http://securityratty.com/article/c0d5da3aa505b996640c046d0cf98dd0</link>
      <guid>http://securityratty.com/article/c0d5da3aa505b996640c046d0cf98dd0</guid>
      <description><![CDATA[If you receive an error following a QUSRSYS install on the AS/400, you may need to reinstall while making sure to keep a back-up of the previous library because it contains user...]]></description>
      <content:encoded><![CDATA[If you receive an error following a QUSRSYS install on the AS/400, you may need to reinstall while making sure to keep a back-up of the previous library because it contains user data.<img src="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~4/355537411" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 09:31:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/previous library">previous library</category>
      <category domain="http://securityratty.com/tag/qusrsys install">qusrsys install</category>
      <category domain="http://securityratty.com/tag/user data">user data</category>
      <category domain="http://securityratty.com/tag/receive">receive</category>
      <category domain="http://securityratty.com/tag/reinstall">reinstall</category>
      <category domain="http://securityratty.com/tag/back-up">back-up</category>
      <category domain="http://securityratty.com/tag/as400">as400</category>
      <category domain="http://securityratty.com/tag/error">error</category>
      <source url="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~3/355537411/0,289625,sid3_gci1323858,00.html">Library QUSRSYS not completely installed</source>
    </item>
    <item>
      <title><![CDATA[VCsChoosing How to Invest]]></title>
      <link>http://securityratty.com/article/c4d8ac0dd426afdf9ac1d38d36dad4e8</link>
      <guid>http://securityratty.com/article/c4d8ac0dd426afdf9ac1d38d36dad4e8</guid>
      <description><![CDATA[Don Dodge has a series going on about VCs and why startups fail, and he says VCs say no to startups 99% of the time, yet still choose failing companies 33% of the time or so. Interestingly he compares...]]></description>
      <content:encoded><![CDATA[<p>Don Dodge has a series going on about VCs and why startups fail, and he says VC&#8217;s say no to startups 99% of the time, yet still choose failing companies 33% of the time or so. Interestingly he <a rel="nofollow" target="_blank" href="http://dondodge.typepad.com/the_next_big_thing/2008/08/why-vcs-say-no-99-of-the-time.html">compares </a>the selection process to the way investors choose their stocks &#8211;</p>
<blockquote><p>I would guess that every one of you reading this blog have a stock portfolio with 5 to 10 individual stocks or mutual funds. There are more than 5,000 publicly listed companies to choose from, and another 5,000 mutual funds. But, out of 10,000 possible companies you chose 10 to invest in. Why? Why did you reject the other 9,990 companies? Obviously there are more than 10 good companies to invest in. Other investors chose to invest their money in the other 9,990 companies&#8230;why not you?</p></blockquote>
<p>I suppose the difference must be that many investors aren&#8217;t actively involved in their investments (maybe entrepreneurs are more so, since they have to know a certain investment space quite well)&#8230;</p>
<p>It sounds to me a lot like the editorial selection process for book manuscripts, articles, and so forth &#8212; editors receive a ton of submissions and they have to be choosy. Sometimes they don&#8217;t pick winners; sometimes they pick losers. More importantly, each has a personal style, opinions, preferences, and they are trying to appeal to a certain audience. It&#8217;s interesting to think that VCs are similar but makes sense&#8211;the end question of &#8220;What will be successful&#8221; really depends on the consumer base and industry, and VCs are just people who probably know and prefer to interact with a certain type of consumer base or audience.</p>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 06:23:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/investors chose">investors chose</category>
      <category domain="http://securityratty.com/tag/chose">chose</category>
      <category domain="http://securityratty.com/tag/investors">investors</category>
      <category domain="http://securityratty.com/tag/editorial selection process">editorial selection process</category>
      <category domain="http://securityratty.com/tag/investors choose">investors choose</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/selection process">selection process</category>
      <category domain="http://securityratty.com/tag/choose">choose</category>
      <category domain="http://securityratty.com/tag/mutual funds">mutual funds</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/355545351/">VCsChoosing How to Invest</source>
    </item>
  </channel>
</rss>
