<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: reconsider]]></title>
    <link>http://securityratty.com/tag/reconsider</link>
    <description></description>
    <pubDate>Thu, 28 Feb 2008 11:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Leave Your Webcam On 24/7? Might Want To Reconsider...]]></title>
      <link>http://securityratty.com/article/4d1de8afa43b141ff7ed90cd99cc3cb3</link>
      <guid>http://securityratty.com/article/4d1de8afa43b141ff7ed90cd99cc3cb3</guid>
      <description><![CDATA[It's nothing new that many hackers use programs that allow them to &quot;spy&quot; on their victims once they've compromised the PC (as long as they have a webcam switched on, of course). Similarly, hacking...]]></description>
      <content:encoded><![CDATA[
        It's nothing new that many hackers use programs that allow them to "spy" on their victims once they've compromised the PC (as long as they have a webcam switched on, of course). Similarly, hacking culture has always had a fascination for memes, <a href="http://blog.spywareguide.com/2008/05/memehacks_1.html">incorporating them</a> into part of the design of their latest DDoS tools.<br /><br />However, the strange obsession with <a href="http://en.wikipedia.org/wiki/Shock_sites">shock memes</a> has now spilled into a "fun" game currently doing the rounds on various hacking sites and forums.<br /><br />What this involves is hackers compromising a PC, ensuring the victim has a webcam switched on then opening up shock meme websites at the most inopportune moment, recording the moment of impact with the webcam feed. Or, as one guy put it:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="spinny1.jpg" src="http://blog.spywareguide.com/images/spinny1.jpg" class="mt-image-none" style="" height="86" width="451" /></span></div><br /><br />If you don't know what Meatspin is, you can probably count yourself lucky. If you still want to know, click <a href="http://answers.yahoo.com/question/index?qid=20060710001351AAMxYqY">here</a> (for an <i>explanation</i>. Not Meatspin itself, though the explanation might be classed NSFW anyway).<br /><br />Here's a real life example of one such incident, taken from a message board:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/spinny2.html" onclick="window.open('http://blog.spywareguide.com/images/spinny2.html','popup','width=929,height=192,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/spinny2-thumb-329x67.gif" alt="spinny2.gif" class="mt-image-none" style="" height="67" width="329" /></a></span><br />Click to Enlarge<br /></div><br />Typically, the shock meme website is opened up at full blast, which startles the victim (most sites of this nature loop a piece of music in the background while the, er, action takes place on screen). The bigger the shock, the better. Here's one guy who sounds like he shot about six feet in the air when the meme site fired up in his browser:<br /><br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/spinny3.html" onclick="window.open('http://blog.spywareguide.com/images/spinny3.html','popup','width=636,height=108,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/spinny3-thumb-336x57.jpg" alt="spinny3.jpg" class="mt-image-none" style="" height="57" width="336" /></a></span><br />Click to Enlarge<br /></div><br />This might all sound like fun and games - <i>sort of</i> - but note that the above individual did try to grab the victims credit card details. <br /><br />Generally, the attacker doesn't interact with the victim (because they want friends, relatives or others to think the victim actually brought the site up themselves) but here's a little trash talk anyway:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="spinny4.jpg" src="http://blog.spywareguide.com/images/spinny4.jpg" class="mt-image-none" style="" height="188" width="245" /></span></div><br /><br />At this point, the attacker may or may not grab a screenshot for posterity. I've seen quite a few galleries on sites comprised of people looking shocked at Tubgirl, or being spun round baby right round by Meatspin, and there's no doubt countless others out there floating around. Of course, not everybody is shocked (or indeed impressed) by a shockmeme site popping up on their computer. As an example of that, take this guy:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="spinny5.jpg" src="http://blog.spywareguide.com/images/spinny5.jpg" class="mt-image-none" style="" height="342" width="334" /></span></div><br /><br />Full credit to anyone that counters a shockmeme site appearing on their desktop by picking their nose for five minutes. At any rate, the golden rule with this is that the hackers only bother doing this when a webcam is present and left switched on. If there's no webcam, there's no point trying to elicit a response (because for all they know they're popping open 2 Girls and 1 Cup to an empty server room).<br /><br />Webcams can be a fun tool, but remember to switch them off every now and again or they could come back to haunt you. Of course, depending on the shock meme site deployed (and who happens to be in the room with you at the time), that could be the least of your worries...<br /><div><br /></div><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Mon, 01 Sep 2008 11:46:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/shockmeme site">shockmeme site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/meme site fired">meme site fired</category>
      <category domain="http://securityratty.com/tag/shock">shock</category>
      <category domain="http://securityratty.com/tag/shock meme websites">shock meme websites</category>
      <category domain="http://securityratty.com/tag/webcam">webcam</category>
      <category domain="http://securityratty.com/tag/shock meme site">shock meme site</category>
      <category domain="http://securityratty.com/tag/shock meme website">shock meme website</category>
      <category domain="http://securityratty.com/tag/webcam feed">webcam feed</category>
      <source url="http://blog.spywareguide.com/2008/09/leave-your-webcam-on-247-might.html">Leave Your Webcam On 24/7? Might Want To Reconsider...</source>
    </item>
    <item>
      <title><![CDATA[Stopbadware Scolds Apple Over Safari Carpet Bomb]]></title>
      <link>http://securityratty.com/article/51dfe6da4d28ed90c543246861077239</link>
      <guid>http://securityratty.com/article/51dfe6da4d28ed90c543246861077239</guid>
      <description><![CDATA[From Network World
An antimalware organization has called on Apple to beef up its Safari Web browser to protect users from exploits that could let attackers download malicious code to a Mac or Windows...]]></description>
      <content:encoded><![CDATA[<p>From Network World:</p>
<blockquote><p>An antimalware organization has called on Apple to beef up its Safari Web browser to protect users from exploits that could let attackers download malicious code to a Mac or Windows user&#8217;s desktop.</p>
<p>Stopbadware.org, a group founded by Google, Chinese computer maker Lenovo Group and Sun, on Monday asked Apple to reconsider its refusal to address the flaw as a security problem. </p>
<p>&#8220;StopBadware.org believes that users should have control over software being downloaded to their computers, and we encourage Apple to reconsider its stance and treat this as the security issue that it is,&#8221; Stopbadware.org said in an appeal posted to its Web site. </p></blockquote>
<p>Read on.<br />
<a href="http://www.networkworld.com/news/2008/052108-anti-malware-group-scolds-apple-over.html"><br />
Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=vKVm0s"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=vKVm0s" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=IC9bkH"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=IC9bkH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=m0F8Jh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=m0F8Jh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=yGgPUh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=yGgPUh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=3LlMQh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=3LlMQh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=XUwi7h"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=XUwi7h" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/296739019" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 23 May 2008 14:11:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/apple">apple</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/stopbadware">stopbadware</category>
      <category domain="http://securityratty.com/tag/windows users desktop">windows users desktop</category>
      <category domain="http://securityratty.com/tag/encourage apple">encourage apple</category>
      <category domain="http://securityratty.com/tag/security issue">security issue</category>
      <category domain="http://securityratty.com/tag/protect users">protect users</category>
      <category domain="http://securityratty.com/tag/safari web browser">safari web browser</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/296739019/">Stopbadware Scolds Apple Over Safari Carpet Bomb</source>
    </item>
    <item>
      <title><![CDATA[Employers loosen rules on camera phones]]></title>
      <link>http://securityratty.com/article/18fae6b8a43f18a94d38031232d8a44a</link>
      <guid>http://securityratty.com/article/18fae6b8a43f18a94d38031232d8a44a</guid>
      <description><![CDATA[Cameras are available on just about every kind of wireless handheld device, from inexpensive cell phones to high-end smart phones, putting pressure on IT managers to reconsider corporate security...]]></description>
      <content:encoded><![CDATA[Cameras are available on just about every kind of wireless handheld device, from inexpensive cell phones to high-end smart phones, putting pressure on IT managers to reconsider corporate security policies banning cameras.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=47952?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=47952?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Sun, 18 May 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/high-end smart phones">high-end smart phones</category>
      <category domain="http://securityratty.com/tag/wireless handheld device">wireless handheld device</category>
      <category domain="http://securityratty.com/tag/inexpensive cell phones">inexpensive cell phones</category>
      <category domain="http://securityratty.com/tag/security policies">security policies</category>
      <category domain="http://securityratty.com/tag/cameras">cameras</category>
      <category domain="http://securityratty.com/tag/pressure">pressure</category>
      <category domain="http://securityratty.com/tag/reconsider">reconsider</category>
      <category domain="http://securityratty.com/tag/managers">managers</category>
      <source url="http://www.networkworld.com/news/2008/051908-employers-loosen-rules-on-camera.html?fsrc=rss-security">Employers loosen rules on camera phones</source>
    </item>
    <item>
      <title><![CDATA[Microsoft's directory team forced to reconsider ignored standards]]></title>
      <link>http://securityratty.com/article/8aea0a4aab095c28229d21905fd449be</link>
      <guid>http://securityratty.com/article/8aea0a4aab095c28229d21905fd449be</guid>
      <description><![CDATA[Recent proclamations by Microsoft CEO Steve Ballmer that the company would move toward interoperability and support for standards is putting pressure on the head of the company's directory and...]]></description>
      <content:encoded><![CDATA[Recent proclamations by Microsoft CEO Steve Ballmer that the company would move toward interoperability and support for standards is putting pressure on the head of the company's directory and identity development to reconsider support for industry standards such as SAML that have been long ignored.]]></content:encoded>
      <pubDate>Mon, 03 Mar 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/standards">standards</category>
      <category domain="http://securityratty.com/tag/support">support</category>
      <category domain="http://securityratty.com/tag/reconsider support">reconsider support</category>
      <category domain="http://securityratty.com/tag/industry standards">industry standards</category>
      <category domain="http://securityratty.com/tag/identity development">identity development</category>
      <category domain="http://securityratty.com/tag/directory">directory</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/recent proclamations">recent proclamations</category>
      <category domain="http://securityratty.com/tag/head">head</category>
      <source url="http://www.networkworld.com/news/2008/030408-microsoft-directory-team-standards.html?fsrc=rss-security">Microsoft's directory team forced to reconsider ignored standards</source>
    </item>
    <item>
      <title><![CDATA[Rights groups seek court OK to intervene in Wikileaks case]]></title>
      <link>http://securityratty.com/article/26cd5da1206f8edc3ac965e4f7d4d8e0</link>
      <guid>http://securityratty.com/article/26cd5da1206f8edc3ac965e4f7d4d8e0</guid>
      <description><![CDATA[The Electronic Frontier Foundation and the ACLU are among a growing number of public interest groups trying to get a federal court judge to reconsider a decision shuttering a whistle-blower Web...]]></description>
      <content:encoded><![CDATA[The Electronic Frontier Foundation and the ACLU are among a growing number of public interest groups trying to get a federal court judge to reconsider a decision shuttering a whistle-blower Web site.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=t8rNSz"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=t8rNSz" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/242797319" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 28 Feb 2008 11:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/whistle-blower web site">whistle-blower web site</category>
      <category domain="http://securityratty.com/tag/federal court judge">federal court judge</category>
      <category domain="http://securityratty.com/tag/electronic frontier foundation">electronic frontier foundation</category>
      <category domain="http://securityratty.com/tag/aclu">aclu</category>
      <category domain="http://securityratty.com/tag/reconsider">reconsider</category>
      <category domain="http://securityratty.com/tag/public">public</category>
      <category domain="http://securityratty.com/tag/decision">decision</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/242797319/article.do">Rights groups seek court OK to intervene in Wikileaks case</source>
    </item>
  </channel>
</rss>
