<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: researcher]]></title>
    <link>http://securityratty.com/tag/researcher</link>
    <description></description>
    <pubDate>Thu, 06 Nov 2008 02:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Rock Phish-ing in December]]></title>
      <link>http://securityratty.com/article/d1eddfe52ced7cf231d9526475837380</link>
      <guid>http://securityratty.com/article/d1eddfe52ced7cf231d9526475837380</guid>
      <description><![CDATA[Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware infected hosts as infrastructure provider. What is...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s1600-h/rock_phishing_december_2008_4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s200/rock_phishing_december_2008_4.png" /></a>Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware&nbsp; infected hosts as infrastructure provider. What is this assessment of currently active Rock Phish campaign aiming to achieve? In short, prove that the people that were Rock Phish-ing at the beginning of the year, are exactly the same people that continue Rock Phish-ing at the end of the year, thereby pointing out that as long as they're not where they're supposed to be, they are not going to stop innovating and working on a higher average online time for their campaigns.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s1600-h/rock_phishing_december_2008.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s200/rock_phishing_december_2008.png" /></a>What's particularly interesting about this campaign, is that compared to previous ones targeting multiple brands, the thousands of malware infected hosts and domains are targeting Alliance &amp; Leicester and Abbey National only.<br />
<br />
Active Rock Phish Domains in fast-flux :<br />
<b>stgsfw7sr .com<br />
q06ciwt60 .com<br />
jnlyf96v4 .com<br />
neegzlh35 .com<br />
7azwmrsg5 .com<br />
pn3ekq976 .com<br />
2coxi8sb6 .com<br />
d8ri1iz5d .com<br />
&nbsp;</b><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s1600-h/rock_phishing_december_2008_5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s200/rock_phishing_december_2008_5.png" /></a><b>ki7wvgauf .com<br />
5nt5r3keh .com<br />
5nt29884j .com<br />
bgoryomek .com<br />
a725jv8ik .com<br />
fke5nnp8m .com<br />
stgsfw7sr .com<br />
10c0ka49t .com<br />
zp304ju3z .com<br />
j0rykafwn .cn<br />
2j1f .net<br />
<br />
confirm-updates .com<br />
paypal.confirm-updates .com<br />
user-data-confirmation .com<br />
paypal.user-data-confirmation .com<br />
capitalone.updating-informations .com</b><br />
<br />
Sample sub-domain structure :<br />
<b>mybank.alliance-leicester.co.uk.7azwmrsg5 .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.5nt29884j .com<br />
mybank.aliance-leicester.co.uk.bgoryomek .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.aliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
myonlineaccounts2.abbeynational.co.uk.pn3ekq976 .com<br />
myonlineaccounts1.abeynational.com.pn3ekq976 .com</b><br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s1600-h/rock_phishing_december_2008_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s200/rock_phishing_december_2008_3.png" /></a>DNS servers for the campaigns :<br />
<b>ns1.thecherrydns .com<br />
ns2.thecherrydns .com <br />
ns3.thecherrydns .com <br />
ns4.thecherrydns .com <br />
ns5.thecherrydns .com <br />
ns6.thecherrydns .com <br />
<br />
ns10.realgoodnameserver .com<br />
ns1.realgoodnameserver .com<br />
rens2.realgoodnameserver .com<br />
rns3.realgoodnameserver .com<br />
ns4.realgoodnameserver .com<br />
ns8.realgoodnameserver .com<br />
<br />
ns6.myboomdns .com<br />
ns4.myboomdns .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s1600-h/rock_phishing_december_2008_7.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s200/rock_phishing_december_2008_7.png" /></a><b>Domains registrant :</b><br />
Name : Pan Wei wei<br />
Organization : Pan Wei wei<br />
Address : BaoChun Rd. 27, No. 3, 1F, Apt. 1903<br />
City : Bejing<br />
Province/State : Beijing<br />
Country : CN<br />
Postal Code : 100176<br />
Phone Number : 010-010-58022118-58022118<br />
Fax : 86-010-58022118-58022118<br />
Email : 127@126.com<br />
<br />
These well known Rock Phish campaigners, have been naturally multitasking on several different underground fronts throughout the year. For instance, their <b>2j1f .net</b> is known to have been <a href="http://www.bobbear.co.uk/morganinvestment.html">hosting money mule company's site</a>, and also, it was used in a previously analyzed <a href="http://ddanchev.blogspot.com/2008/06/phishing-campaign-spreading-across.html">phishing campaign that was spreading across Facebook</a> in June. Need more evidence on the consolidation that's been ongoing for over an year and half now? An infamous money mule recruiting company (<b>Cash-Transfers Inc.</b>) was also taking advantage of the <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">fast-flux network offered by the ASProx botnet masters</a> in July.<br />
<br />
As a firm believer in that "the whole is greater than the sum of its parts", the popular "sitting duck" cybercrime infrastructure hosting model will be either replaced by a cybercrime infrastructure relying entirely on legitimate services, or one where the average malware infected Internet user would be temporarily used as a hosting provider.<br />
<br />
If millions were made by using the "sitting duck" hosting model, how many would be made using the others, given that they would inevitably increase the average online time for a malicious campaign?<br />
<br />
<b>Related Rock Phish research :</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/209-host-locked.html">209 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/2091-host-locked.html">209.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/661-host-locked.html">66.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/confirm-your-gullibility.html">Confirm Your Gullibility</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/assessing-rock-phish-campaign.html">Assessing a Rock Phish Campaign</a><br />
<br />
<b>Related fast-flux research : </b><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast-Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Scam</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/managed-fast-flux-provider-part-two.html">Managed Fast Flux Provider - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kNW2O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kNW2O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zUymO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zUymO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gesYo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gesYo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RrC8o"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RrC8o" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=w0L7O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=w0L7O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hj0KO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hj0KO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=P9KQo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=P9KQo" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/472451974" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 04:12:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast-flux spam">fast-flux spam</category>
      <category domain="http://securityratty.com/tag/fast-flux">fast-flux</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/mybank">mybank</category>
      <category domain="http://securityratty.com/tag/fast-flux research">fast-flux research</category>
      <category domain="http://securityratty.com/tag/rock phish-ing">rock phish-ing</category>
      <category domain="http://securityratty.com/tag/provider">provider</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/472451974/rock-phish-ing-in-december.html">Rock Phish-ing in December</source>
    </item>
    <item>
      <title><![CDATA[Apple's antivirus advice 'big to-do about nothing,' says researcher]]></title>
      <link>http://securityratty.com/article/78f18923bc9ddc1dc575c5d25853b644</link>
      <guid>http://securityratty.com/article/78f18923bc9ddc1dc575c5d25853b644</guid>
      <description><![CDATA[Apple recently recommended that Mac users consider running antivirus software -- a move some see as a change of heart by a company that has poked fun at rival Windows for being susceptible to...]]></description>
      <content:encoded><![CDATA[Apple recently recommended that Mac users consider running antivirus software -- a move some see as a change of heart by a company that has poked fun at rival Windows for being susceptible to attacks.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d3000a1dc0875449692f1f812a4aae3c:f1CkqyGiBaa5Ot7ccoJy9F8%2FR4l3xaE9L0XdvgAtg8DVFpIaepRzROiv4ZAAovXqg%2F0oTMq9ZxAY'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:fc3910d7b0dae77e144c856031e25358:54n5HaLMYv31zCAINpKPD2rrWqKxJPSCQ%2BEmJeOFjmlrzsK2oTYzj2WmEw0xfxgqXqznzQGe358bgA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:cd3af90754f2714e767f98ff77ebd882:H7EX%2F2oZTDR9hXdzIOFhHnMeM0uLx6N6QgkGDzIZVNh00NyBMMUDBnto8WXO2pis0bXM9utjMr0iug%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d777b1af896172e3a2e88dd59d5a9d9c:j1gU6WU7ZeFlFN8tcaLbRvCtw3Vt91sumbMzAeqm8XPjh4u6aoCcQkRCWWyHGQgaJz5lTpbPogiJFg%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=58e0909d25eaf09eb2e8c64ca3149a83&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=58e0909d25eaf09eb2e8c64ca3149a83&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=58e0909d25eaf09eb2e8c64ca3149a83" style="display: none;" border="0" height="1" width="1" alt=""/>
]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mac users">mac users</category>
      <category domain="http://securityratty.com/tag/rival windows">rival windows</category>
      <category domain="http://securityratty.com/tag/antivirus software">antivirus software</category>
      <category domain="http://securityratty.com/tag/apple recently">apple recently</category>
      <category domain="http://securityratty.com/tag/poked fun">poked fun</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/heart">heart</category>
      <category domain="http://securityratty.com/tag/change">change</category>
      <category domain="http://securityratty.com/tag/move">move</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=58e0909d25eaf09eb2e8c64ca3149a83">Apple's antivirus advice 'big to-do about nothing,' says researcher</source>
    </item>
    <item>
      <title><![CDATA[New Windows worm builds massive botnet]]></title>
      <link>http://securityratty.com/article/3a6eabe3fabdc02381335e9da62f9f3f</link>
      <guid>http://securityratty.com/article/3a6eabe3fabdc02381335e9da62f9f3f</guid>
      <description><![CDATA[The worm exploiting a critical Windows bug that Microsoft patched with an emergency fix in late October is now being used to build a new botnet, a security researcher said...]]></description>
      <content:encoded><![CDATA[The worm exploiting a critical Windows bug that Microsoft patched with an emergency fix in late October is now being used to build a new botnet, a security researcher said today.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:753364ef47c74d5e69be8f8ff63e9d77:rde4Po9039fWcggFZ1G8PbQ%2Bd6mSgWoR%2FUOvasM5LMqDnlAf71ww6R90gLinDnkYy7zr2RVCI0I6'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:2de0db9a64431a81309c4805ed784482:AtY%2FMEt%2Bu4ouWTXinleDNIfv5hNEPpYqNE8pQzWdzCQkXK1PbS3l%2Bts7dWzFo3gi8t%2BLvskAoGkctA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:40f43b44006f17602cfa5d12ae84e460:P%2BokPYTg4msl2qjE%2FOcc2t7NBh1DSbEJMRiUjUEAkYyhmvatpavBWKD%2Fu2KuQAcmE0uuOWKu3ECZZw%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:cedbebdbcb9b59b9690ac576872a4b48:vX0M0WCroINEP2tASBnOlWg0tZuAfey6VcDhtkDF1WguwTltglyI%2BK2qoEFPhk0uxQ2fwqIbUoXswA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=676088a1c97128f5533c7ae7d1a32ed7&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=676088a1c97128f5533c7ae7d1a32ed7&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=676088a1c97128f5533c7ae7d1a32ed7" style="display: none;" border="0" height="1" width="1" alt=""/>
]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/critical windows bug">critical windows bug</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/security researcher">security researcher</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <category domain="http://securityratty.com/tag/emergency fix">emergency fix</category>
      <category domain="http://securityratty.com/tag/october">october</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=676088a1c97128f5533c7ae7d1a32ed7">New Windows worm builds massive botnet</source>
    </item>
    <item>
      <title><![CDATA[Hosting firm takedown bags 500,000 bots]]></title>
      <link>http://securityratty.com/article/2aa44764005da16b59081934c3d8d457</link>
      <guid>http://securityratty.com/article/2aa44764005da16b59081934c3d8d457</guid>
      <description><![CDATA[The shutdown last week of Web hosting company McColo crippled more than half a million bots, which can no longer receive commands from criminals, a security researcher said...]]></description>
      <content:encoded><![CDATA[The shutdown last week of Web hosting company McColo crippled more than half a million bots, which can no longer receive commands from criminals, a security researcher said today.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:720d222e1e248951db2f0ffc1d8ec5cd:BZWzGOi2sYq99fGf1qQixRUHYm4kfgzz4C1XBAM26BvXD6LYaK%2FmlavtoaoGG7JUoLnbwJ5jD5jW'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c186dbc6f51362d57ff523944b0e12e7:RusZPMuJurQPDMHc7X7o%2FJznzRxUlTv7UhzptW8e2AkTRcvlNeTwc6hCOPVCjmWetFDj%2Feo3KgApdw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:14455ea9acd776a6fb8021cfde7d7ede:EFWVRxbGDG99buAbkP%2Fn%2B5n5NQHXaet6D3%2BFma%2FEyaZ9qUa8kmSK1t%2FzlnNzpaY8qoCY91fpsCGj3Q%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:55a8a0982f5c5217923fb9ead96a05bd:d1svRJ0Ls4i7qsofossJT%2F5irnD2pFfDlCy1Ahwue9Gmd%2B4SS9LN2PMmhh13VPbobUvtauQ96RJELQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=e13dfce99aa28e495299b2b0c607fe5c"><img src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=e13dfce99aa28e495299b2b0c607fe5c" border="0" /></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=e13dfce99aa28e495299b2b0c607fe5c" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/company mccolo">company mccolo</category>
      <category domain="http://securityratty.com/tag/million bots">million bots</category>
      <category domain="http://securityratty.com/tag/receive commands">receive commands</category>
      <category domain="http://securityratty.com/tag/security researcher">security researcher</category>
      <category domain="http://securityratty.com/tag/half">half</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/criminals">criminals</category>
      <category domain="http://securityratty.com/tag/shutdown">shutdown</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=e13dfce99aa28e495299b2b0c607fe5c">Hosting firm takedown bags 500,000 bots</source>
    </item>
    <item>
      <title><![CDATA[Hosting firm takedown bags 500,000 bots]]></title>
      <link>http://securityratty.com/article/dc228a654506a197a89cb9beb7bd29b9</link>
      <guid>http://securityratty.com/article/dc228a654506a197a89cb9beb7bd29b9</guid>
      <description><![CDATA[The shutdown last week of a U.S.-based Web hosting company crippled more than 500,000 bots, or compromised computers, which no longer are able to receive commands from criminals, a security researcher...]]></description>
      <content:encoded><![CDATA[The shutdown last week of a U.S.-based Web hosting company crippled more than 500,000 bots, or compromised computers, which no longer are able to receive commands from criminals, a security researcher said Tuesday.]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/receive commands">receive commands</category>
      <category domain="http://securityratty.com/tag/bots">bots</category>
      <category domain="http://securityratty.com/tag/security researcher">security researcher</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <category domain="http://securityratty.com/tag/computers">computers</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/criminals">criminals</category>
      <category domain="http://securityratty.com/tag/shutdown">shutdown</category>
      <source url="http://www.networkworld.com/news/2008/111808-hosting-firm-takedown-bags-500000.html?fsrc=rss-security">Hosting firm takedown bags 500,000 bots</source>
    </item>
    <item>
      <title><![CDATA[Credit for Researchers]]></title>
      <link>http://securityratty.com/article/408b969da73a95cd64bb6d0b550aa038</link>
      <guid>http://securityratty.com/article/408b969da73a95cd64bb6d0b550aa038</guid>
      <description><![CDATA[Computer security researchers are much like scientific researchers in several ways. We build on the research of those who come before us, we sometimes rediscover the same things independently, and...]]></description>
      <content:encoded><![CDATA[<p>Computer security researchers are much like scientific researchers in several ways.  We build on the research of those who come before us, we sometimes rediscover the same things independently, and other times we forget where we learned things and sometimes claim them as our own.  We also occasionally take an engineer&#8217;s approach and implement research discovered by others and not credit them as it&#8217;s the implementation into a tool that matters to us.</p>
<p>The latest Microsoft patch <a href="http://www.microsoft.com/technet/security/bulletin/ms08-068.mspx">MS08-68</a> is a great example. It is a problem with NTLM authentication where the attacker can force a client to authenticate to him and the credentials, while not exposed in cleartext, can be relayed to another server or brute forced to obtain the cleartext.  This is a very classic crypto protocol vulnerability.  It&#8217;s not the crypto algorithms that are the problem, but the protocol implementation.</p>
<p>Microsoft recently fixed the problem, perhaps due to the availability of exploit code, the availability of an easy to use Metasploit implementation, or perhaps Microsoft&#8217;s changed tolerance for vulnerabilities. We can sum it up as a change in the threat space that made it worth fixing.  But make no mistake, this is a very old problem.</p>
<p>News reports have been citing Sir Dystic&#8217;s SMBrelay tool, which was published in March, 2001, as the first knowledge of this vulnerability. Eric Shultze who worked at MSRC in 2001 just yesterday is quoted as saying, &#8220;I have been holding my breath since 2001 for this patch.&#8221; Obviously it is a long time coming.  But this wasn&#8217;t the first publication of the problem.  In 2000, one of my collegues on the research team at @stake, Christian Rioux (aka Dildog) published the <a href="http://packetstormsecurity.org/advisories/atstake/A091400-1">telnet NTLM authentication vulnerability</a>.</p>
<p>Rioux&#8217;s advisory has a great description of the credential relay and cracking weaknesses. I have talked to him and he says he discovered these problems independently, but he didn&#8217;t find them first.  Dominique Brezinski published exactly these NTLM vulnerabilities in the SMB protocol in 1996 in a paper titled, &#8220;A Weakness in CIFS Authentication&#8221;.  The earliest reference I can find on the paper on the net is <a href="http://mvb.saic.com/freeware/vmslt97b/security/cifs-mim.txt">here</a>  where it is included in another paper published in 1997.  Such is the ad-hoc world of independent security research of 12 years ago which still continues today.</p>
<p>It seems ridiculous that a field like security research, which is so important to the running of modern society is so ad-hoc.  Shouldn&#8217;t we know who discovered a vulnerability?  Shouldn&#8217;t all researchers and engineers know about it? More importantly if someone implements a tool that takes advantage of a vulnerability shouldn&#8217;t they credit the discoverer?  Don&#8217;t get me wrong.  Implementation takes a lot of work and sometimes makes all the difference in makeing people aware of a security problem.  After all when I was at the L0pht our slogan was, &#8220;Making the theoretical, practical&#8221;. I still think researchers should get credit when credit is due.</p>
<p>The security community has gotten better at documentating our research but I still see instances of independent discovery, misplaced credit, and tools giving no credit to researchers.  I hate to say it but getting a bit more academic is in order.  Credit is the currency of a researcher and placing it well will reward the right people and we will all benefit.</p>
]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 16:40:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security research">security research</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/independent security research">independent security research</category>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/credit">credit</category>
      <category domain="http://securityratty.com/tag/security community">security community</category>
      <category domain="http://securityratty.com/tag/scientific researchers">scientific researchers</category>
      <category domain="http://securityratty.com/tag/computer security researchers">computer security researchers</category>
      <source url="http://www.veracode.com/blog/2008/11/credit-for-researchers/">Credit for Researchers</source>
    </item>
    <item>
      <title><![CDATA[Hackers launch PDF attacks, exploit just-patched Reader bug]]></title>
      <link>http://securityratty.com/article/871aa5bed11241da2daf484eb1555e23</link>
      <guid>http://securityratty.com/article/871aa5bed11241da2daf484eb1555e23</guid>
      <description><![CDATA[A security researcher at the SANS Institute's Internet Storm Center warned Adobe Reader users to update their software as soon as possible now that attackers are exploiting a vulnerability in the...]]></description>
      <content:encoded><![CDATA[A security researcher at the SANS Institute's Internet Storm Center warned Adobe Reader users to update their software as soon as possible now that attackers are exploiting a vulnerability in the software patched earlier this week.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:f5af192390d108acb8ce91f03f6e4e26:NdKnUUH%2B7Rj14GfPmcdcoNOQAh685%2F7V24bmq4eLTIfSto14G458mYHPWs74N5930K2SWKa%2FWdkH'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:3a9b08ebadc02f16be1c0bae916ef398:dVdWijn%2FkeKhpJxJJOkQp5W5pWJgdUhHxKgWk7JeAoyo%2FLryZ5%2FadvrVhRktbqvYqsSs3kPEgvFsbg%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:1f9e1caa806fb463cd8e8ddf1b31ddae:Qkp9toKtmXI2UdHtorIUwDJ0o76Yg3mKMPbEOGVbppik%2FSUtvMbJFiBk5ytKg0zE3QFJ2T1sOAgakg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:4e908e379f5951ac534f52c89f47d55a:cLuRmRbeyYVlWRzMwE3jhy5rpIOlfHjOnYkQjmwpAp1aRoBw2gUZx7SFlABfpWwl4S9PkkmwmmSBow%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=85f73fda74f09636d3c14d4eb4f71f74" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=85f73fda74f09636d3c14d4eb4f71f74" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 07 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/adobe reader users">adobe reader users</category>
      <category domain="http://securityratty.com/tag/internet storm center">internet storm center</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/security researcher">security researcher</category>
      <category domain="http://securityratty.com/tag/sans institute">sans institute</category>
      <category domain="http://securityratty.com/tag/attackers">attackers</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=85f73fda74f09636d3c14d4eb4f71f74">Hackers launch PDF attacks, exploit just-patched Reader bug</source>
    </item>
    <item>
      <title><![CDATA[Android may not need antivirus software, researcher says]]></title>
      <link>http://securityratty.com/article/a77b43c186011192ea5894238922d2ea</link>
      <guid>http://securityratty.com/article/a77b43c186011192ea5894238922d2ea</guid>
      <description><![CDATA[Antivirus developer SMobile released software this week to protect users of the G1 Android phone, although one security analyst wondered if people really need...]]></description>
      <content:encoded><![CDATA[Antivirus developer SMobile released software this week to protect users of the G1 Android phone, although one security analyst wondered if people really need it.]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/antivirus developer smobile">antivirus developer smobile</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/android phone">android phone</category>
      <category domain="http://securityratty.com/tag/protect users">protect users</category>
      <category domain="http://securityratty.com/tag/security analyst">security analyst</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <source url="http://www.networkworld.com/news/2008/110708-android-may-not-need-antivirus.html?fsrc=rss-security">Android may not need antivirus software, researcher says</source>
    </item>
    <item>
      <title><![CDATA[Hackers launch PDF attacks, exploit just-patched Reader bug]]></title>
      <link>http://securityratty.com/article/a8a73c4043b5fd076b5c2fc7c5571a15</link>
      <guid>http://securityratty.com/article/a8a73c4043b5fd076b5c2fc7c5571a15</guid>
      <description><![CDATA[Attackers are exploiting one of the vulnerabilities in Adobe Reader that was patched earlier this week, a security researcher warned Friday as he urged users to update as soon as...]]></description>
      <content:encoded><![CDATA[Attackers are exploiting one of the vulnerabilities in Adobe Reader that was patched earlier this week, a security researcher warned Friday as he urged users to update as soon as possible.]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/urged users">urged users</category>
      <category domain="http://securityratty.com/tag/security researcher">security researcher</category>
      <category domain="http://securityratty.com/tag/adobe reader">adobe reader</category>
      <category domain="http://securityratty.com/tag/attackers">attackers</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/friday">friday</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <source url="http://www.networkworld.com/news/2008/110708-hackers-launch-pdf-attacks-exploit.html?fsrc=rss-security">Hackers launch PDF attacks, exploit just-patched Reader bug</source>
    </item>
    <item>
      <title><![CDATA[Researcher: Android may not need antivirus software]]></title>
      <link>http://securityratty.com/article/af8a64fb93b85d177651b6eedd104656</link>
      <guid>http://securityratty.com/article/af8a64fb93b85d177651b6eedd104656</guid>
      <description><![CDATA[Antivirus developer SMobile released software this week to protect users of the G1 Android phone, but one analyst wondered if it's...]]></description>
      <content:encoded><![CDATA[Antivirus developer SMobile released software this week to protect users of the G1 Android phone, but one analyst wondered if it's needed.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:f8286785aa12b1fb4be2a322a4671371:vs%2BhEi2XYTqihKgWmHq38L9sipciLpCLl%2FK%2F68b4BSRmqGbTiuvMIf6OEXMOHxPFae%2BG2MYo%2F6En'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:385d329134448df198312eb5e3964015:jx%2BH200%2BxGePqWcZPwG%2BU4bmSVCMxbrsujuMBxfXfTLR5tQWg6ycOPg6w76yED6yBEzX5j5HeCUi%2Bw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:e62eb47c655085d22e9d3925857e099f:gxYquns2HMH2ZmUBFecba9ITCVjlYjrpJp9fwOhOYzw4Zqc%2FD1d13Wnwc5S3zYgRuk5CiQwwmgdh2A%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:6598d974eaa4f505689df5d2da22ef56:oAlp5C5j%2BbZ68VSETjMhCfCciCpYi%2B30Y6WusC%2FCuP2JsqHZHxIoP1t7q3vvMTGHX%2BUxRiPIKznpjw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=d2ed39af746b3a4bbed6911966c49b3f"><img src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=d2ed39af746b3a4bbed6911966c49b3f" border="0" /></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=d2ed39af746b3a4bbed6911966c49b3f" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/antivirus developer smobile">antivirus developer smobile</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/android phone">android phone</category>
      <category domain="http://securityratty.com/tag/protect users">protect users</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/analyst">analyst</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=d2ed39af746b3a4bbed6911966c49b3f">Researcher: Android may not need antivirus software</source>
    </item>
  </channel>
</rss>
