<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: registration]]></title>
    <link>http://securityratty.com/tag/registration</link>
    <description></description>
    <pubDate>Mon, 21 Jul 2008 04:16:30 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Digital Cash in Iraq]]></title>
      <link>http://securityratty.com/article/84493590b736c33ff0c22bfa1fc5590a</link>
      <guid>http://securityratty.com/article/84493590b736c33ff0c22bfa1fc5590a</guid>
      <description><![CDATA[Smart cards have still never quite taken off across the US, and at this point its fair to wonder if they will or if they will be eclipsed by phones or some such, but smart cards sure are big outside...]]></description>
      <content:encoded><![CDATA[<p>Smart cards have still never quite taken off across the US, and at this point its fair to wonder if they will or if they will be eclipsed by phones or some such, but smart cards sure are big outside the US. One of the most interesting applications is of course digital cash and transaction processing. <a href="http://www.aplitec.co.za/">Net1 UEPS</a>&#160;(ticker: <a href="http://finance.google.com/finance?q=ueps">UEPS</a>) out of South Africa appears to be the leader here having built a $1.2B business out of this model. there are lots of regions in the world where people are underbanked or unbanked altogether and where its dangerous to have too much cash. I blogged about this earlier on <a href="http://1raindrop.typepad.com/1_raindrop/2007/08/beer-shotguns-a.html">Beer, Shotguns and Digital Cash</a>.&#160;</p><br /><div>Now <a href="http://biz.yahoo.com/iw/080804/0421781.html">Net1 UEPS is in Iraq as well</a>:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">The first UEPS transaction was performed on Sunday, August 3, 2008, in Baghdad, Iraq, during the official launch of the UEPS smart card technology with the two state banks namely, Rafidain Bank and Rasheed Bank.</span></p></blockquote><div><span style="font-family: arial; line-height: normal;"><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">The official launch, attended by invitees from Rafidain Bank, Rasheed Bank, the Iraqi Government, War Victim Ministry and Martyrdom Ministry, demonstrated smart card registration, biometric enrolment and issuing of UEPS cards, offline loading of wage payments and government grants to the UEPS cards and dispensing of cash.</span><br /><span style="font-family: arial; line-height: normal; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">The pilot project involving 100,000 beneficiaries is now ready for implementation across selected bank branches and will enable the distribution and payment of government grants to war victims and martyrdom beneficiaries, as well as salary and wage distribution and payment to employees of the two state banks.</span><br /><span style="font-family: arial; line-height: normal; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">Brenda Stewart, Net1 Senior Vice President Sales and Marketing, said, &quot;From the entire team at Net1, we congratulate the Iraqi consortium on this historic achievement and look forward to the successful implementation of the various projects already identified for implementation, as well as the projects currently in business development. Net1 is proud that the development of its core technology, from which it creates end-user products that satisfy the requirements of its customers, can change the way business is conducted leading to the improvement of people&#39;s lives. We share the belief of our Iraqi partners that our technology can play a fundamental role in the upliftment of the economy. The success of any technology should be measured, not only by the profits it generates for its inventors, suppliers and users, but also by the difference that it makes to the lives of people,&quot; Stewart concluded.</span></p></blockquote><div><span style="font-family: arial; line-height: normal;"><p>I think there are lessons to be learned here wrt data and message level security. Net1 UEPS is a good example a of system carrying valuable assets across hostile terrain, web security architecture can learn a lot from this model.</p><p>P.S. If you are a <a href="http://en.wikipedia.org/wiki/Joel_Greenblatt">Joel Greenblatt</a> geek - UEPS is a <a href="http://www.magicformulainvesting.com/">magic formula stock</a>&#160;(meaning they make cash and are priced cheaply) last time I checked.</p><p></p></span></div>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 08:53:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ueps cards">ueps cards</category>
      <category domain="http://securityratty.com/tag/ueps">ueps</category>
      <category domain="http://securityratty.com/tag/digital cash">digital cash</category>
      <category domain="http://securityratty.com/tag/cash">cash</category>
      <category domain="http://securityratty.com/tag/net1 ueps">net1 ueps</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/net1">net1</category>
      <category domain="http://securityratty.com/tag/rafidain bank">rafidain bank</category>
      <category domain="http://securityratty.com/tag/ueps transaction">ueps transaction</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/digital-cash-in-iraq.html">Digital Cash in Iraq</source>
    </item>
    <item>
      <title><![CDATA[Live from the ?Configuresoft? Conference]]></title>
      <link>http://securityratty.com/article/c90d6f13a0a2aa8e072233f1e19eaa33</link>
      <guid>http://securityratty.com/article/c90d6f13a0a2aa8e072233f1e19eaa33</guid>
      <description><![CDATA[I thought I'd share a quick story from Black Hat
So, I went Caesar's and headed back to the conference area to register and get my badge. As I neared the escalators, I started seeing a lot of folks...]]></description>
      <content:encoded><![CDATA[<p><a href="http://blogs.technet.com/blogfiles/security/WindowsLiveWriter/LivefromtheConfiguresoftConference_10672/bh2008news_2.png"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="124" alt="bh2008news" src="http://blogs.technet.com/blogfiles/security/WindowsLiveWriter/LivefromtheConfiguresoftConference_10672/bh2008news_thumb.png" width="180" align="left" border="0"></a> I thought I'd share a quick story from Black Hat.</p> <p>So, I went Caesar's and headed back to the conference area to register and get my badge.&nbsp; As I neared the escalators, I started seeing a lot of folks with badges on that said "Configuresoft."</p> <p>I thought, hmm, there must be another conference going on here at the same time - which would be weird, since Black Hat filled the areas last year.</p> <p>Anyway, I trudged on, found registration and got my badge for Black Hat.&nbsp; Here is a picture:</p> <p align="center"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="260" alt="IMG_8820" src="http://blogs.technet.com/blogfiles/security/WindowsLiveWriter/LivefromtheConfiguresoftConference_10672/IMG_8820_3.jpg" width="200" border="0"> </p> <p>Duh.&nbsp; Look for more updates as the conference progresses.&nbsp; ~Jeff</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3101731" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 21:47:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/conference">conference</category>
      <category domain="http://securityratty.com/tag/black hat">black hat</category>
      <category domain="http://securityratty.com/tag/conference progresses">conference progresses</category>
      <category domain="http://securityratty.com/tag/quick story">quick story</category>
      <category domain="http://securityratty.com/tag/badge">badge</category>
      <category domain="http://securityratty.com/tag/configuresoft">configuresoft</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/registration">registration</category>
      <source url="http://blogs.technet.com/security/archive/2008/08/07/live-from-the-configuresoft-conference.aspx">Live from the ?Configuresoft? Conference</source>
    </item>
    <item>
      <title><![CDATA[Think "liability" if you want to stay out of trouble.]]></title>
      <link>http://securityratty.com/article/d9485be5d4b45a749942f44d816889ae</link>
      <guid>http://securityratty.com/article/d9485be5d4b45a749942f44d816889ae</guid>
      <description><![CDATA[I speak a lot about liability, but not everyone gets it

I have seen medical doctors, dentists, business people of all walks of life and lawyers (it is surprising how many lawyers disregard...]]></description>
      <content:encoded><![CDATA[I speak a lot about liability, but not everyone gets it.<br /><span id="fullpost"><br />I have seen medical doctors, dentists, business people of all walks of life and lawyers (it is surprising how many lawyers disregard liability)pay little attention to potential lawsuits.  The latest category to leave themselves open, have been auctioneers. <br /></span><br />The current foreclosure crisis has meant that many properties are being auctioned off.  We have been providing security officers at some of the properties in order to make sure that people do not try to steal or commit vandalism when viewing the houses.  There was an incident recently in which a bidder decided to withdraw his offer after his bid became the winning bid.  He probaly got cold feet.<br /><br />While he should not have reneged on his offer to buy the property, it was a civil matter best left to civil remedy.  Unfortunately, the auctioneers involved decided to take the law into their own hands and would not let the man leave the property.  The man became anxious and informed them that he was having difficulty breathing and needed to go to his car for his asthma medication.  <br /><br />Was this true?  Maybe, maybe not - but would it be wise to gamble with a person's health when you already had their personal details and you could easily have obtained his vehicle registration if he decided to leave?<br />Thankfully, our security officer knew better that to get involved with blocking the man's way.  The auctioneers stood in front of his vehicle and yelled at him.  Eventually the man drove off.     <br /><br />If you represent a financial institution, a law firm or an auctioneering firm, you need to think twice before you act inappropriately.  I have no doubt that had that man had a serious attack and if he died as a result, his next of kin would have sued for umpteen millions.  When it comes to situations like this, you need to think rationally and realize what is involved.  What was the worse thing that could have happened when the person decided to renege on his offer?  <br /><br />Apparently, he would have signed forms and the like and most probably he could be sued civilly for not fulfilling his obligations after delivering the winning bid.  At the end of the day, the note holder would be in a strong position.  Even if the person had given false information and could not be subsequently located, all they had to do was to put the property back on the market.  What could that have cost, a couple of thousand in extra advertising and the like?  That would have been much better than having to pay the next of kin many millions - not to mention the bad publicity.<br /><br />We talk a lot about liability because it is a very real threat.  Think "threat mitigation".  Those who do not, may pay a very high price.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 03 Aug 2008 21:12:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/liability">liability</category>
      <category domain="http://securityratty.com/tag/lawyers disregard liability">lawyers disregard liability</category>
      <category domain="http://securityratty.com/tag/law firm">law firm</category>
      <category domain="http://securityratty.com/tag/auctioneers stood">auctioneers stood</category>
      <category domain="http://securityratty.com/tag/auctioneers">auctioneers</category>
      <category domain="http://securityratty.com/tag/law">law</category>
      <category domain="http://securityratty.com/tag/lawyers">lawyers</category>
      <category domain="http://securityratty.com/tag/property">property</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://www.thebulletproofblog.com/2008/08/think-liability-if-you-want-to-stay-out.html">Think "liability" if you want to stay out of trouble.</source>
    </item>
    <item>
      <title><![CDATA[Summarizing July's Threatscape]]></title>
      <link>http://securityratty.com/article/2860027a1eaa69350d814429c3bf6070</link>
      <guid>http://securityratty.com/article/2860027a1eaa69350d814429c3bf6070</guid>
      <description><![CDATA[July's threatscape -- consider going through June's summary as well -- once again demonstrated that nothing is impossible, the impossible just takes a little longer where the incentive would be the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJLdSTaizDI/AAAAAAAAB_E/WogqT88LBdc/s1600-h/ddanchev_july.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJLdSTaizDI/AAAAAAAAB_E/Bb9z-K3ib7c/s200-R/ddanchev_july.jpg" style="border: 0pt none ;" /></a>July's threatscape -- consider going through <a href="http://ddanchev.blogspot.com/2008/07/summarizing-junes-threatscape.html">June's summary</a> as well -- once again demonstrated that nothing is impossible, the impossible just takes a little longer where the incentive would be the ultimate monetization of the process.<br />
<br />
Russian hacktivists attacking Lithuania and Georgia, several Storm Worm campaigns, a couple of new malware tools, Neosploit team abandoning support for their web malware exploitation kit, CAPTCHA for several of the most popular free email providers getting efficiently attacked in order to resell the bogus accounts registered in the process, several copycat SQL injects next to the evasion techniques applied by the copycats, botnets continuing to commit click fraud and generate revenue for those who own or have rented them, an infamous money mule recruitment service taking advantage of the fast-fluxed network provided by the ASProx botnet - pretty interesting month indeed.<br />
<br />
<b>01.</b> <a href="http://ddanchev.blogspot.com/2008/07/decrypting-and-restoring-gpcode.html">Decrypting and Restoring GPcode Encrypted Files</a> -<br />
The GPcode authors read the news too, and are catching up with the major weaknesses pointed out in their previous release in order to come with a virtually unbreakable algorithm. And since more evidence of <a href="http://ddanchev.blogspot.com/2008/06/whos-behind-gpcode-ransomware.html">who's behind the GPcode ransomware</a> was gathered, vendors and independent researchers realized that the latest release is also susceptible to a plain simple flaw, namely the encrypted files were basically getting deleting and not securely erased making them fairly easy to recover.<br />
<br />
<b>02.</b> <a href="http://ddanchev.blogspot.com/2008/07/chinese-bloggers-bypassing-censorship.html">Chinese Bloggers Bypassing Censorship by Blogging Backward</a> -<br />
When you know how it works, you can either improve, abuse or destroy it in that very particular order. Chinese bloggers are always very adaptive in respect to spreading their message by obfuscating their messages in a way that common keywords filtering software wouldn't be able to pick them.<br />
<br />
<b>03.</b> <a href="http://ddanchev.blogspot.com/2008/07/gmail-yahoo-and-hotmails-captcha-broken.html">Gmail, Yahoo and Hotmail’s CAPTCHA Broken</a> -<br />
This has been an urban legend for a while, but with more services starting to offer hundreds of thousands of pre-registered accounts at these providers, it's surprising that <a href="http://blogs.zdnet.com/security/?p=1514">spam and phishing emails coming from legitimate email providers is increasing</a>. The "vendors" behind these propositions are naturally starting to "vertically integrate" by offering value-added services for extra payments, namely, scripts to automatically abuse the pre-registered accounts for automatic registration of splogs and anything else malicious or blackhat SEO related.<br />
<br />
<b>04.</b> <a href="http://ddanchev.blogspot.com/2008/07/antivirus-industry-in-2008.html">The Antivirus Industry in 2008</a> -<br />
If it were anyone else but a security vendor to come up with such a realistic cartoon aiming to stimulate innovation by emphasizing on how prolific and sophisticated malware groups have become, it would have been a biased cartoon. However, this one is courtesy of a security vendor, and it's pretty objective.<br />
<br />
<b>05.</b> <a href="http://ddanchev.blogspot.com/2008/07/lithuania-attacked-by-russian.html">Lithuania Attacked by Russian Hacktivists, 300 Sites Defaced</a> -<br />
This attack is a good example of a decent PSYOPS operation. Of course they have already build the capabilities to deface and even execute DDoS attacks against Lithuania, so why not put them in a "stay tuned" mode, by speculating on the upcoming attack and then executing it making it look like they delived what they've promised? This a lone gunman mass defacement given that the sites were all hosted on a single ISP, with no indication of any kind of coordination whatsoever. The same for the <a href="http://blogs.zdnet.com/security/?p=1533">Georgia President’s web site which was under DDoS attack from Russian hackers</a> later this month. Despite that the hacktivists behind it dedicated a separate C&amp;C for the attack, one that hasn't been used in any type of previous attacks so far, they did a minor mistake by using a secondary command and control location that's known to have been connected with a particular "botnet on demand" service in the past. The second attack once again proves that you don't need to build capacity when you can basically outsource the process to someone else.<br />
<br />
<b>06.</b> <a href="http://ddanchev.blogspot.com/2008/07/icann-responds-to-dns-hijacking-its.html">The ICANN Responds to the DNS Hijacking, Its Blog Under Attack</a> -<br />
The ICANN finally issued a statement concerning the DNS hijacking of some of their domains, which is in fact what Comcast.net and Photobucket.com should have done as well, next to stating it was a "glitch". The ICANN also took advantage of the moment and also pointed out that their blog has also been under attack during the month. There's no better example of how the combination of <a href="http://ddanchev.blogspot.com/2008/06/icann-and-ianas-domain-names-hijacked.html"> tactics can result in the hijacking of the domains</a> of the organizations implementing procedures aiming to protect against these very same attacks. And while Photobucket.com remained silent during the entire incident, the hosting provider that was used by the Netdevilz team in the two attacks, since they were also responsible for the ICANN and IANA DNS hijackings, <a href="http://ddanchev.blogspot.com/2008/06/update-to-photobuckets-dns-hijacking.html">technological and social engineeringissued a statement</a>.<br />
<br />
<b>07.</b> <a href="http://ddanchev.blogspot.com/2008/07/risks-of-outdated-situational-awareness.html">The Risks of Outdated Situational Awareness</a> -<br />
Security vendors are often in a "catch-up mode" and if I were an average Internet user not knowing that real-time situational awareness speaks for the degree to which my vendor knows what going on online, I'd be pretty excited. However, I'm not. <a href="http://blogs.zdnet.com/security/?p=1085">Prevx were catching up with a service which I covered approximately two months ago</a>, I even had the chance to constructively confront with one of the affected sites on how despite their security measures in place, this attack was still possible. Recently <a href="http://www.theregister.co.uk/2008/07/18/limbo_trojan/">Prevx have once again demonstrated an outdated situational awareness</a> by coming across a banking malware in July 2008, whereas the malware has been around since July 2007, and earlier depending on which version you're referring to.<br />
<br />
<b>08.</b> <a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a> -<br />
Yet another domain portfolio of fake porn sites serving rogue codecs and live exploit URLs, just the tip of the iceberg as usual, however their centralization is greatly assisting in tracking them down.<br />
<br />
<b>09.</b> <a href="http://ddanchev.blogspot.com/2008/07/storm-worms-us-invasion-of-iran.html">Storm Worm's U.S Invasion of Iran Campaign</a> -<br />
Stormy Wormy is once again making the headlines with their ability to actually make up the headlines on their own.<br />
<br />
<b>10.</b> <a href="http://ddanchev.blogspot.com/2008/07/mobile-malware-scam-isexplayer-wants.html">Mobile Malware Scam iSexPlayer Wants Your Money</a> -<br />
The best scams are the ones to which you've personally agreed to be scammed with without even knowing it. Like this one, which was tracked down and analyzed a couple of hours once a uset tipped on it.<br />
<br />
<b>11.</b> <a href="http://ddanchev.blogspot.com/2008/07/template-ization-of-malware-serving.html">The Template-ization of Malware Serving Sites</a> -<br />
The increase of fake porn and celebrity sites is due to the overall template-ization of these, with the people behind them basically implementing several malicious doorways to ensure that the domains get rotated on the fly. Despite that they all look the same, they all sever different type of malware, and zero porn of celebrity content at all except the thumbnails.<br />
<br />
<b>12.</b> <a href="http://ddanchev.blogspot.com/2008/07/violating-opsec-for-increasing.html">Violating OPSEC for Increasing the Probability of Malware Infection</a> -<br />
No better way to expose your affiliations and several unknown bad netblocks so far, by adding the netblocks and the malicious domains as trusted sites upon infecting a PC with the malware. Of course, the usual suspects lead the "trusted netblocks".<br />
<br />
<b>13.</b> <a href="http://ddanchev.blogspot.com/2008/07/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</a> -<br />
Several years ago, a script kiddie would install Apache on a mail server, they claim that they defaced it. Today, these amusing situations are replaced by monetization of the compromised sites, by reselling the access to them to blackhat SEO-ers, malware authors, phishers, or personally starting to manage a scammy infrastructure on them, by earning money on an affiliate based model, like this particular attack.<br />
<br />
<b>14.</b> <a href="http://ddanchev.blogspot.com/2008/07/malware-and-office-documents-joining.html">Malware and Office Documents Joining Forces</a> -<br />
A recent DIY malware kit, sold as a proprietary tool basically crunching out malware infected office documents, whose built-in obfuscation makes them harder to detect. It will sooner or later leak out, turning into a commodity tool, a process that's been pretty evident for web malware exploitation kits as well.<br />
<br />
<b>15.</b> <a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</a> -<br />
Depends on who you're buying them from, and whether or not they offer discounts on a volume basis, namely the more you buy the cheaper the price of a card is supposed to get. With the current oversupply of stolen credit card details, what used to be an exclusive good once where they could enjoy a higher profit-margin, is today's commodity good.<br />
<br />
<b>16.</b> <a href="http://ddanchev.blogspot.com/2008/07/neosploit-malware-kit-updated-with.html">The Neosploit Malware Kit Updated with Snapshot ActiveX Exploit</a> -<br />
Since alll the web malware exploitation kits are open source, and leaked in the wild at large, their modularity allows everyone to easily embed any type of exploit that they want to, resulting in Neosploit's single most beneficial feature, the fact that certain versions include all the publicly available exploits targeting Internet Explorer, Firefox and Opera. Moreover, the open source nature of the kit is resulting in a countless number of modified versions yet to be detected and analyzed, therefore keeping track of the exploits included in a malware kit can only be realistic if you take into considered the exploits that come with the default installation.<br />
<br />
<b>17.</b> <a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast-fluxed SQL Injected Domains</a> -<br />
Now that's a very good example of different tactics combined to attack, ensure survivability, and apply a certain degree of evasion in between.<br />
<br />
<b>18.</b> <a href="http://ddanchev.blogspot.com/2008/07/unbreakable-captcha.html">The Unbreakable CAPTCHA</a> -<br />
There's never been a shortage of ideas, there's always been an issue of usability.<br />
<br />
<b>19.</b> <a href="http://ddanchev.blogspot.com/2008/07/ayyildiz-turkish-hacking-group-vs.html">The Ayyildiz Turkish Hacking Group VS Everyone</a> -<br />
That's a pretty inspiring mission if you are to ensure your future in the next couple of years, by targeting everyone, everywhere that has ever publicly stated their disagreement with the Turkish foreign policy.<br />
<br />
<b>20.</b> <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">Money Mule Recruiters use ASProx's Fast Fluxing Services</a> -<br />
A true multitasking in action with a botnet that's been crunching out phishing emails, SQL injecting and now hosting a well known money mule recruitment service. <br />
<br />
<b>21.</b> <a href="http://ddanchev.blogspot.com/2008/07/sql-injecting-malicious-doorways-to.html">SQL Injecting Malicious Doorways to Serve Malware</a> -<br />
Constantly switching tactics and combining different ones to achive an objective that used to be accomplished by plain simple techniques, is only starting to take place. In this case, instead of a hard coded SQL injected domain, we have the typical malicious doorways the result of the converging traffic management tools with web malware exploitation kits.<br />
<br />
<b>22.</b> <a href="http://ddanchev.blogspot.com/2008/07/impersonating-stopbadwareorg-to-serve.html">Impersonating StopBadware.org to Serve Fake Security Warnings</a> -<br />
Typosquatting popular security vendors and services is nothing new, by having HostFresh providing the hosting for the parked domains promoting the rogue security software, is a privilege and flattery for the success of the Stopbadware initiative.<br />
<br />
<b>23.</b> <a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a> -<br />
Customerization -- not customization -- has been taking place for a while, that's the process of tailoring your upcoming products to the needs of your future customers, compared to the product concept myopia where the malware coder would code something that he believes would be valuable to the potential customers. End user agreements, issuing licenses for the malware tool, as well as forbidding the reverse engineering of the malware so that no remotely exploitable flaws could be, are among the requirements the coder assists on.<br />
<br />
<b>24. </b><a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><b> -</b><br />
Taking a random snapshot of the current malicious activity at a well known provider of hosting services for rogue security applications, live exploit URLs and botnet command&amp;control locations, always provides an insight into what are their customers up to. In this case, centralization of their scammy ecosystem, and parking a countless number of rogue domains on the same server.<br />
<br />
<b>25. </b><a href="http://ddanchev.blogspot.com/2008/07/email-hacking-going-commercial.html">Email Hacking Going Commercial</a> -<br />
Cybercrime is in fact getting easier to outsource, and while the number of scammers trying to offer non-existent services, or at least services where they cannot deliver the goods, the business model of this service that is that you only pay once they show you a proof that they've managed to hack the email address you game them. How are they doing it? Social engineering and enticing the user to click on live exploit URL from where they'll infect the PC and obtain the email password, of course, next to definitely abusing it for many other purposes in the process.<br />
<br />
<b>26.</b> <a href="http://ddanchev.blogspot.com/2008/07/vulnerabilities-in-antivirus-software.html">Vulnerabilities in Antivirus Software - Conflict of Interest</a> -<br />
You can easily twist the number of vulnerabilities found in your antivirus solution, but not recognizing them as vulnerabilities at the first place. It's all a matter of what you define as a vulnerability, or perhaps what you admit as a serious vulnerability - remote code execution through a security software, or a flaw that's allowing malware to bypass the security solution itself.<br />
<br />
<b>27. </b><a href="http://ddanchev.blogspot.com/2008/07/counting-bullets-on-malware-front.html">Counting the Bullets on the (Malware) Front</a> -<br />
Emphasizing on the number of malware/threats/viruses/worms/slugs your solution detects may be marketable in the short-term, but is damaging the end user's understanding of the threatscape in the long-term. So, by the time he catches up with what exactly is going on, he'll recall the moment in time where he was using the number of threats his solution was detecting as the main benchmark for its usefulness. In reality through, the number is irrelevant from a pro-active point of view, with zero day malware like the one coded for hire undermining the signatures based scanning model.<br />
<br />
<b>28. </b><a href="http://ddanchev.blogspot.com/2008/07/smells-like-copycat-sql-injection-in.html">Smells Like a Copycat SQL Injection In the Wild</a> -<br />
It was pretty obvious that copycats seeing the success of SQL injections the the huge number of sites susceptible to exploitation, would also starting taking advantage of the practice. Some are, however, targeting local communities and trying to avoid detection by using targeted SQL injections.<br />
<br />
<b>29. </b><a href="http://ddanchev.blogspot.com/2008/07/click-fraud-botnets-and-parked-domains.html">Click Fraud, Botnets and Parked Domains - All Inclusive</a> -<br />
The scheme is nothing new, what's new is that the botnet masters are trying to limit the revenues that used to go out to affiliate networks they were participating in, and are trying to own or rent the entire infrastructure on their own.<br />
<br />
<b>30. </b><a href="http://ddanchev.blogspot.com/2008/07/over-80-percent-of-storm-worm-spam-sent.html">Over 80 percent of Storm Worm Spam Sent by Pharmaceutical Spam Kings</a><b> -</b><br />
With access to Storm Worm sold and resold, and new malware introduced on Storm Worm infected hosts used as foundation for the propagation of the new malware in this case, it's questionable whether or not the Storm Worm-ers themselves are sending out the junk emails, or are they people who've rented access to the botnet doing it. <br />
<br />
<b>31. </b><a href="http://ddanchev.blogspot.com/2008/07/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</a> -<br />
Pretty surprising at the first place, but in reality it clearly demonstrates that when you cannot enforce the end user agreement on your crimeware kit, but continue seeing it used in a very profitable malware operations, you basically shut down the support for the public version. The team is not going to stop innovating for their own purposes, and in the long-term they may in fact re-appear with an updated malware kit that's converging different services next to the product itself.<br />
<br />
<b>32. </b><a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a> - <br />
Managed spamming services using botnets as the foundation for the campaigns are starting to introduce improved metrics for the delivery, as well as experienced customer support ensuring the spam messages make it through spam filters, or at least increase the probability of making the happen. This is an example of a random service emphasizing on the improved metrics they're capable of delivering.<br />
<br />
<b>33. </b><a href="http://ddanchev.blogspot.com/2008/07/storm-worms-lazy-summer-campaigns.html">Storm Worm's Lazy Summer Campaigns</a> -<br />
Looks like a "cybercrime intern" launched this campaign, lacking any of the usual Storm Worm evasive practices, no exploitation of client side vulnerabilities, as well as no survivability offered by their usual fast-flux nodes.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dMjxcK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dMjxcK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IC3AVK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IC3AVK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=d2XWZk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=d2XWZk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vRFZyk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vRFZyk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6ZdeKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6ZdeKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jVlXIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jVlXIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W4mAWk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W4mAWk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/352993637" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 12:08:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/profitable malware operations">profitable malware operations</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/malware tools">malware tools</category>
      <category domain="http://securityratty.com/tag/malware coder">malware coder</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <category domain="http://securityratty.com/tag/malware infection">malware infection</category>
      <category domain="http://securityratty.com/tag/neosploit malware kit">neosploit malware kit</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/352993637/summarizing-julys-threatscape.html">Summarizing July's Threatscape</source>
    </item>
    <item>
      <title><![CDATA[Random stuff on my to do list]]></title>
      <link>http://securityratty.com/article/8a6e0cf6a3383c5228b81f063f03348a</link>
      <guid>http://securityratty.com/article/8a6e0cf6a3383c5228b81f063f03348a</guid>
      <description><![CDATA[SQL injection in web apps is sooooo old. It still exists everywhere and security companies are still making good moolah by capturing 'crown jewels' by exploiting this - However, I'm not sure that SQL...]]></description>
      <content:encoded><![CDATA[SQL injection in web apps is sooooo old. It still exists everywhere and security companies are still making good moolah by capturing 'crown jewels' by exploiting this - However, I'm not sure that SQL injection testing for non web based applications/scenarios has caught on. Are they even worth trying ? For example: I'd really like to test the logic for the following (for starters) at some point in life :<br /><br />1. Cell phones - EMEA registration. Attempt to SQL inject the backend during registration and/or normal communication. Ditto with normal phone lines - would that work ? Before I even say "Only one way to find out.." I should really read up on cell phones to test the theory..<br /><br />2. Magstripes on cards - change data in the magstripe of ID cards , hotel access cards, credit cards, debit cards etc - to SQL inject the backend - Hmmm.. my name/cardnumber/PIN is now <em>' OR 1=1 -- ? </em><br />Something like  <a href="http://xkcd.com/327/">little bobby tables</a>.<br /><br />3. Checks - Change the account number on checks to SQL inject the backend. I'm almost certain this would fail because of the MICR E13b restrictions of characters.. ah well.. <br /><br />Ah well..I would need to get back into security consulting at some point if I want to test this out in a legal way..]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 12:46:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/credit cards">credit cards</category>
      <category domain="http://securityratty.com/tag/cards">cards</category>
      <category domain="http://securityratty.com/tag/hotel access cards">hotel access cards</category>
      <category domain="http://securityratty.com/tag/sql inject">sql inject</category>
      <category domain="http://securityratty.com/tag/debit cards">debit cards</category>
      <category domain="http://securityratty.com/tag/sql injection">sql injection</category>
      <category domain="http://securityratty.com/tag/cell phones">cell phones</category>
      <category domain="http://securityratty.com/tag/test">test</category>
      <category domain="http://securityratty.com/tag/backend">backend</category>
      <source url="http://securitycoin.blogspot.com/2008/07/random-stuff-on-my-to-do-list.html">Random stuff on my to do list</source>
    </item>
    <item>
      <title><![CDATA[Intruder Gaines Access To 128,000 Patients Database In Saint Marys Regional Medical Center Website Breach]]></title>
      <link>http://securityratty.com/article/c561f480beb8466a80cf3a1d4f74cd9a</link>
      <guid>http://securityratty.com/article/c561f480beb8466a80cf3a1d4f74cd9a</guid>
      <description><![CDATA[Saint Marys Regional Medical Center recently discovered that an intruder may have gained access to a proprietary database through the on-line registration area of Saint Marys public facing website....]]></description>
      <content:encoded><![CDATA[Saint Mary’s Regional Medical Center recently discovered that an intruder may have gained access to a proprietary database through the on-line registration area of Saint Mary’s public facing website. The database is used for health education classes and wellness programs and contains personal information including name, address, limited health information and some Social Security numbers. [...]]]></content:encoded>
      <pubDate>Sun, 27 Jul 2008 13:15:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/database">database</category>
      <category domain="http://securityratty.com/tag/saint marys public">saint marys public</category>
      <category domain="http://securityratty.com/tag/health education classes">health education classes</category>
      <category domain="http://securityratty.com/tag/proprietary database">proprietary database</category>
      <category domain="http://securityratty.com/tag/wellness programs">wellness programs</category>
      <category domain="http://securityratty.com/tag/website">website</category>
      <category domain="http://securityratty.com/tag/intruder">intruder</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/health information">health information</category>
      <source url="http://cyberinsecure.com/intruder-gaines-access-to-128000-patients-database-in-saint-mary%e2%80%99s-regional-medical-center-website-breach/">Intruder Gaines Access To 128,000 Patients Database In Saint Marys Regional Medical Center Website Breach</source>
    </item>
    <item>
      <title><![CDATA[Interop NY 2008 Hot Stage: A Tale of Two Cities]]></title>
      <link>http://securityratty.com/article/47273ded1435f902f1bd70d7c7bf36fc</link>
      <guid>http://securityratty.com/article/47273ded1435f902f1bd70d7c7bf36fc</guid>
      <description><![CDATA[For the past week Ive been in Freemont California (outside San Jose) with the InteropNet Team getting the network back up after Vegas so that its ready for New York. This Hot Stage has been...]]></description>
      <content:encoded><![CDATA[<p class="MsoNormal">For the past week I’ve been in Freemont California (outside San Jose) with the InteropNet Team getting the network back up after Vegas so that it’s ready for New York.<span> </span>This Hot Stage has been interesting because it really has been about the difference in the shows in Las Vegas and New York.<span> </span>The show in New York is a bit smaller, but because access to the venue (Javitz Center) is more restrictive than the access the team gets in Vegas (<a href="http://www.mandalaybay.com/Conventions/" target="_blank">Mandalay Bay</a>), things need to be done differently.<span> </span></p>
<p class="MsoNormal">The big difference between the two cities is the amount of time that the InteropNet team gets to produce a live, fully operational and redundant network.<span> </span>In Las Vegas, this was nearly a full week of time - a tight timeframe across 17 different vendors, but now we&#8217;re looking back at that timeframe as a luxury. In NY, we’ll be getting started Saturday morning, and the network needs to be delivered on Sunday morning for the registration desk and exhibitor move-in to begin.<span> </span>If you’re keeping score, that’s about <strong>24 hours to deliver a working network</strong>. Sounds hard, but it’s even harder when you consider that this means four DS-3s from two different locations, 17 full and 7 half racks of network gear, all the fiber and copper that the network is delivered over, etc all have to get done.<span> Good thing that with 2 and 3/4 kids, </span>I’m not planning on much sleep, and I don’t think the rest of the team is either.<span> </span></p>
<p class="MsoNormal">
<p class="MsoNormal">In order to try and get the network delivered in that short timeframe, we worked hard at Hot Stage to assure that everything is ready to go.<span> </span>With some luck, the work that we’ve done here will allow us simply to roll the network gear into place, run the cables, fire up and go.<span> </span></p>
<p class="MsoNormal">Now, things never really work out that way but that’s what EM7 is going to be there for.<span> </span>We’ll watch in real time as the network elements come live and be able to let the other <a href="http://interop.com/newyork/event-highlights/interopnet/sponsors.php" target="_blank">InteropNet vendors</a> know if their gear isn’t behaving<span> </span>as expected or is not visible for all the areas of the network that it should<span> </span>be.<span> We&#8217;ll keep track of all of this in the EM7 ticketing system so that after the show we&#8217;ll be able to analyze the behavior of the network and systems <a href="http://blog.sciencelogic.com/interop-las-vegas-2008-some-interesting-stats/06/2008" target="_blank">as we did after Vegas</a>. </span></p>
<p class="MsoNormal">
<p class="MsoNormal">I&#8217;m looking forward to the show and once again working with some of the top engineers in the country on a complex and rapidly deployed network.  Speaking of which, we&#8217;re still looking for <a href="http://www.networkworld.com/news/2007/052207-interop-networking-religion.html" target="_blank">volunteers</a> to help in the NOC.  Volunteers get to work with some really smart people, get an education that would be hard to get anywhere else, and get a trip to NY <a href="http://www.interop.com/newyork/event-highlights/interopnet/volunteers2.php" target="_blank">where your expenses</a> (for things like hotel accommodations and food provided by the show) are taken care of.  Sound interesting?  Be sure and check out <a href="http://www.networkops.net/vrms/" target="_blank">the application.</a></p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Interop+NY+2008+Hot+Stage%3A+A+Tale+of+Two+Cities&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Finterop-ny-2008-hot-stage-a-tale-of-two-cities%2F07%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 18:01:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/redundant network">redundant network</category>
      <category domain="http://securityratty.com/tag/network gear">network gear</category>
      <category domain="http://securityratty.com/tag/gear">gear</category>
      <category domain="http://securityratty.com/tag/network elements">network elements</category>
      <category domain="http://securityratty.com/tag/hot stage">hot stage</category>
      <category domain="http://securityratty.com/tag/las vegas">las vegas</category>
      <category domain="http://securityratty.com/tag/vegas">vegas</category>
      <category domain="http://securityratty.com/tag/interopnet team">interopnet team</category>
      <source url="http://blog.sciencelogic.com/interop-ny-2008-hot-stage-a-tale-of-two-cities/07/2008">Interop NY 2008 Hot Stage: A Tale of Two Cities</source>
    </item>
    <item>
      <title><![CDATA[Speaking of Security Podcast #114]]></title>
      <link>http://securityratty.com/article/ec60f9a9867a5ba85716c819cc65402e</link>
      <guid>http://securityratty.com/article/ec60f9a9867a5ba85716c819cc65402e</guid>
      <description><![CDATA[Click to Download/Listen (05:51

New co-host Amanda Van Veen interviews Linda Lynch, RSA Conference Europe Manager, about this year's Conference in October. Learn about the early bird registration...]]></description>
      <content:encoded><![CDATA[<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1312">Click to Download/Listen</a> (05:51)<br>
<br />
New co-host Amanda Van Veen interviews Linda Lynch, RSA&reg; Conference Europe Manager, about this year's Conference in October. Learn about the early bird registration special as well as other helpful travel hints and session highlights. Register today: <a href="http://www.rsaconference.com/2008/Europe" target="_blank">www.rsaconference.com/2008/europe</a>.<br /><br />]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 13:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/helpful travel hints">helpful travel hints</category>
      <category domain="http://securityratty.com/tag/co-host amanda van">co-host amanda van</category>
      <category domain="http://securityratty.com/tag/interviews linda lynch">interviews linda lynch</category>
      <category domain="http://securityratty.com/tag/bird registration special">bird registration special</category>
      <category domain="http://securityratty.com/tag/session highlights">session highlights</category>
      <category domain="http://securityratty.com/tag/october">october</category>
      <category domain="http://securityratty.com/tag/register">register</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/rsaconference">rsaconference</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1312">Speaking of Security Podcast #114</source>
    </item>
    <item>
      <title><![CDATA[ICANN Approves New .INFO Policy]]></title>
      <link>http://securityratty.com/article/cd6398fad5b32c821bfe8b24969e83a1</link>
      <guid>http://securityratty.com/article/cd6398fad5b32c821bfe8b24969e83a1</guid>
      <description><![CDATA[Last month Afilias , the domain registry for .INFO , proposed a new &quot;Abusive Domain Use Policy&quot; that would appear to give them arbitrary power to decide what is and is not acceptable. Consider the...]]></description>
      <content:encoded><![CDATA[Last month <a href="http://www.afilias.com/">Afilias</a>, the domain registry for <a href="http://www.info.info/">.INFO</a>, proposed <a href="http://www.icann.org/registries/rsep/afilias-request-20jun08.pdf">a new "Abusive Domain Use Policy"</a> that would appear to give them arbitrary power to decide what is and is not acceptable. Consider the following language:<blockquote><i>Pursuant to Section 3.6.5 of the RRA, Afilias reserves the right to deny, cancel or transfer any registration or transaction, or place any domain name(s) on registry lock, hold or similar status, that it deems necessary, in its discretion;</i></blockquote>
Now it appears (<a href="http://www.domainnamenews.com/icann-policy/icann-approves-new-info-policy/1740">thanks to Domain Name News for the tip</a>) that <a href="http://www.icann.org/registries/rsep/jones-to-afilias-18jul08.pdf">ICANN has approved the proposed policy and given the green light to implementation</a>. The ICANN letter states that they found no "...significant competition or security and stability issues" and asks Afilias to report on results of the changes. But ICANN did not explicitly solicit public comment on the change before approving it.

As DomainNameNews points out though, comments to any registry proposal can be submitted at any time by sending an email to registryservice (at) icann.org and are published <a href="http://forum.icann.org/lists/registryservice/">on the ICANN website</a>."<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=aafe57485cc6ab66b73f3d71762b6ff4" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=aafe57485cc6ab66b73f3d71762b6ff4" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/341492192" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 04:16:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/icann">icann</category>
      <category domain="http://securityratty.com/tag/icann website">icann website</category>
      <category domain="http://securityratty.com/tag/abusive domain">abusive domain</category>
      <category domain="http://securityratty.com/tag/domain">domain</category>
      <category domain="http://securityratty.com/tag/afilias reserves">afilias reserves</category>
      <category domain="http://securityratty.com/tag/afilias">afilias</category>
      <category domain="http://securityratty.com/tag/icann letter">icann letter</category>
      <category domain="http://securityratty.com/tag/domain registry">domain registry</category>
      <category domain="http://securityratty.com/tag/policy">policy</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/341492192/icann_approves_new_info_policy.html">ICANN Approves New .INFO Policy</source>
    </item>
    <item>
      <title><![CDATA[ICANN Approves New .INFO Policy]]></title>
      <link>http://securityratty.com/article/d5161f1ef550ab412bb9cc0a92fc9996</link>
      <guid>http://securityratty.com/article/d5161f1ef550ab412bb9cc0a92fc9996</guid>
      <description><![CDATA[Last month Afilias , the domain registry for .INFO , proposed a new &quot;Abusive Domain Use Policy&quot; that would appear to give them arbitrary power to decide what is and is not acceptable. Consider the...]]></description>
      <content:encoded><![CDATA[Last month <a href="http://www.afilias.com/">Afilias</a>, the domain registry for <a href="http://www.info.info/">.INFO</a>, proposed <a href="http://www.icann.org/registries/rsep/afilias-request-20jun08.pdf">a new "Abusive Domain Use Policy"</a> that would appear to give them arbitrary power to decide what is and is not acceptable. Consider the following language:<blockquote><i>Pursuant to Section 3.6.5 of the RRA, Afilias reserves the right to deny, cancel or transfer any registration or transaction, or place any domain name(s) on registry lock, hold or similar status, that it deems necessary, in its discretion;</i></blockquote>
Now it appears (<a href="http://www.domainnamenews.com/icann-policy/icann-approves-new-info-policy/1740">thanks to Domain Name News for the tip</a>) that <a href="http://www.icann.org/registries/rsep/jones-to-afilias-18jul08.pdf">ICANN has approved the proposed policy and given the green light to implementation</a>. The ICANN letter states that they found no "...significant competition or security and stability issues" and asks Afilias to report on results of the changes. But ICANN did not explicitly solicit public comment on the change before approving it.

As DomainNameNews points out, though, comments to any registry proposal can be submitted at any time by sending an e-mail to registryservice (at) icann.org and are published <a href="http://forum.icann.org/lists/registryservice/">on the ICANN Web site</a>."<img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/-r6XYAggbEo" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 04:16:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/icann">icann</category>
      <category domain="http://securityratty.com/tag/icann letter">icann letter</category>
      <category domain="http://securityratty.com/tag/abusive domain">abusive domain</category>
      <category domain="http://securityratty.com/tag/icann web site">icann web site</category>
      <category domain="http://securityratty.com/tag/domain">domain</category>
      <category domain="http://securityratty.com/tag/afilias reserves">afilias reserves</category>
      <category domain="http://securityratty.com/tag/afilias">afilias</category>
      <category domain="http://securityratty.com/tag/domain registry">domain registry</category>
      <category domain="http://securityratty.com/tag/policy">policy</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/-r6XYAggbEo/icann_approves_new_info_policy.html">ICANN Approves New .INFO Policy</source>
    </item>
  </channel>
</rss>
