<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: rhode]]></title>
    <link>http://securityratty.com/tag/rhode</link>
    <description></description>
    <pubDate>Tue, 08 Jan 2008 00:07:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Friday Squid Blogging: Rising Squid Populations off the Coast of Rhode Island]]></title>
      <link>http://securityratty.com/article/6678bf171098e683769808c9d9813894</link>
      <guid>http://securityratty.com/article/6678bf171098e683769808c9d9813894</guid>
      <description><![CDATA[It's due to rising sea...]]></description>
      <content:encoded><![CDATA[It's due to <a href="http://news.nationalgeographic.com/news/2008/06/080630-lobsters-warming.html">rising sea temperatures</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=x3hI7J"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=x3hI7J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=yAm4PJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=yAm4PJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Sun, 13 Jul 2008 03:21:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sea temperatures">sea temperatures</category>
      <category domain="http://securityratty.com/tag/due">due</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/friday_squid_bl_135.html">Friday Squid Blogging: Rising Squid Populations off the Coast of Rhode Island</source>
    </item>
    <item>
      <title><![CDATA[Fake Porn Sites Serving Malware]]></title>
      <link>http://securityratty.com/article/5dacf1e5b6c84c1bed4515dca8fc1199</link>
      <guid>http://securityratty.com/article/5dacf1e5b6c84c1bed4515dca8fc1199</guid>
      <description><![CDATA[Ah, that RBN with its centralization mentality for the sake of ease of management and 99.999% uptime. In this very latest example of using malicious doorways redirecting to fake porn sites, consisting...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SGJTBaqN1yI/AAAAAAAAB1k/b9O7PupnB8E/s1600-h/porn_codecs.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SGJTBaqN1yI/AAAAAAAAB1k/b9O7PupnB8E/s200/porn_codecs.JPG" alt="" id="BLOGGER_PHOTO_ID_5215822602249819938" border="0" /></a>Ah, that RBN with its centralization mentality for the sake of ease of management and 99.999% uptime. In this very latest example of using malicious doorways redirecting to fake porn sites, consisting of over twenty different domains serving the usual Zlob malware variants, we have a decent abuse of a template for a porn site.<br /><br />The easy of management of such domain farms and the availability of templates for high trafficked topic segments such as celebrities and pornography, continue contributing to the increasing number of Zlob variants served through fake codecs. Moreover, once set up, the malicious infrastructure starts attracting now just generic search traffic, but also traffic coming from affiliates with whom revenue is shared on the basis of the number of people that downloaded the codec.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGJsP6kwvTI/AAAAAAAAB1s/b0lRo5htJtE/s1600-h/fake_porn_sites_ATRIVO.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGJsP6kwvTI/AAAAAAAAB1s/b0lRo5htJtE/s200/fake_porn_sites_ATRIVO.JPG" alt="" id="BLOGGER_PHOTO_ID_5215850339125738802" border="0" /></a>In this campaign, the malicious doorway that expands the entire ecosystem is located at <span style="font-weight: bold;">search-</span><span style="font-weight: bold;">top.com/in.cgi?5&amp;parameter=drs</span> (66.96.85.113). A redirector that appears to <a href="http://www.lavasoftsupport.com/index.php?showtopic=2662">have been operating since 2006</a>, according to this forum posting.<br /><br />What follows on-the-fly, are all the fake porn sites whose legitimately looking videos attempt to download a Zlob malware variant from a single location - <span style="font-weight: bold;">vipcodec.net</span>. Here are all the fake porn sites, and the associated campaigns in this redirection :<br /><br /><span style="font-weight: bold;">watchnenjoy .com</span>/index.php?id=1287&amp;style=white<br /><span style="font-weight: bold;">craziestclips .com</span>/index.php?id=1287&amp;q=<br /><span style="font-weight: bold;">immensevids .com</span><br /><span style="font-weight: bold;">planetfreepornmovies .com</span>/?t=1&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/edmund/16551689/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/rosalyn/1742941675/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/emiline/108846601/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/inde/964842117/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/elnora/648311952/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/verge/1734135233/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/dal/1663381205/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .ne</span><span style="font-weight: bold;">t</span>/gretchen/515268975/1/&amp;id=1219<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SGJ2DJRJgoI/AAAAAAAAB10/0pUS4GVInf4/s1600-h/porn_domainfarm_codecs_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SGJ2DJRJgoI/AAAAAAAAB10/0pUS4GVInf4/s200/porn_domainfarm_codecs_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5215861114847986306" border="0" /></a><span style="font-weight: bold;">abc-adult .com</span>/lillah/1467790484/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/jenne/434165228/1/&amp;id=1219<br /><span style="font-weight: bold;">look-adult .net</span>/ette/681831796/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/mime/65729013/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/alfe/550398461/1/&amp;id=1219<br /><span style="font-weight: bold;">group-ad</span><span style="font-weight: bold;">ult .net</span>/demerias/867452637/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/rhode/167691118/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/hephsibah/1254235416/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/hence/1684651134/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/kendra/371598555/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/link/1334727639/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/flo/84660854/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/assene/875893411/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/charlotta/972714195/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/orlando/761508522/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/jemima/1405735776/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/obadiah/263904242/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/douglas/1110779475/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/lydde/1844064103/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/marcia/1627490290/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/cono/295680123/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/wes/1733468207/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/wib/648341815/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/greg/2064937302/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/maris/33184936/1/&amp;id=1219<br /><span style="font-weight: bold;">look-adult .net</span>/regina/1273816838/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/gwendolyn/869744046/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/carthaette/1021629112/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/ninell/1522355420/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/waldo/755290223/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/green/669090607/1/&amp;id=1219<br /><span style="font-weight: bold;">try-adult .com</span>/lula/447057398/1/&amp;id=1219<br /><span style="font-weight: bold;">visit-adult .net</span>/jay/1021153563/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/rosa/849017739/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/hannah/2111126283/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/robin/2114086747/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/geraldine/921262381/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/christine/1821111087/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/frederica/364993202/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/kerste/735582753/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/vine/715820953/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/newt/1835463160/1/&amp;id=1219<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SGJ6ha5cUzI/AAAAAAAAB18/wtJ3aPXos_Q/s1600-h/zlob_codec_setup.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SGJ6ha5cUzI/AAAAAAAAB18/wtJ3aPXos_Q/s200/zlob_codec_setup.png" alt="" id="BLOGGER_PHOTO_ID_5215866033022980914" border="0" /></a><span style="font-weight: bold;">try-adult .com</span>/max/602914725/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/cille/1420660046/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/phililpa/178057959/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/lise/1379126759/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/marianne/1083617952/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/emile/1173468576/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/patse/155685496/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/verna/625840253/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/aubrey/190928373/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .</span><span style="font-weight: bold;">net</span>/alphinias/1345158043/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/rosa/223743611/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/nerva/1509620489/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/leet/1619667733/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/roberta/887345003/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/tore/1032556395/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/bo/1963737386/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/karon/136085893/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/tense/1523522750/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/hopp/1955964399/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/vanne/350822489/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/deb/1451360694/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/moll/1511640690/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/obediah/562846948/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/tamarra/776122096/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/aristotle/1046422029/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/titia/158157566/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/gay/1297835054/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/katherine/2136357734/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/azubah/1197502147/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/claes/770105101/1/&amp;id=1219<br /><br />Associated fake porn sites :<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGJ7UYzaZJI/AAAAAAAAB2E/cy7Pijctw-8/s1600-h/fake_porn_sites_ATRIVO1.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGJ7UYzaZJI/AAAAAAAAB2E/cy7Pijctw-8/s200/fake_porn_sites_ATRIVO1.JPG" alt="" id="BLOGGER_PHOTO_ID_5215866908634145938" border="0" /></a><span style="font-weight: bold;">pornbrake .com</span> <span style="font-weight: bold;"><br />sexnitro .net</span> <span style="font-weight: bold;"><br />brakesex .net</span> <span style="font-weight: bold;"><br />pornnitro .net</span> <span style="font-weight: bold;"><br />adultbookings .com</span> <span style="font-weight: bold;"><br />qazsex .com</span><br /><span style="font-weight: bold;">lightporn .net</span> <span style="font-weight: bold;"><br />delfiporn .net</span> <span style="font-weight: bold;"><br />pornqaz .com</span> <span style="font-weight: bold;"><br />megazporn .com</span> <span style="font-weight: bold;"><br />uinsex .com</span><br /><span style="font-weight: bold;">xerosex .com</span> <span style="font-weight: bold;"><br />serviceporn .com</span> <span style="font-weight: bold;"><br />aboutadultsex .com</span> <span style="font-weight: bold;"><br />superliveporn .com</span> <span style="font-weight: bold;"><br />bestpriceporn .com</span> <span style="font-weight: bold;"><br />contactporn .net</span> <span style="font-weight: bold;"><br />relatedporn .com</span> <span style="font-weight: bold;"><br />landporno .com</span> <span style="font-weight: bold;"><br />adultsper .com</span> <span style="font-weight: bold;"><br />plus-porn .com</span> <span style="font-weight: bold;"><br />adultstarworld .com</span><br /><span style="font-weight: bold;">cutadult .com</span> <span style="font-weight: bold;"><br />moviexxxhotel .com</span> <span style="font-weight: bold;"><br />porno-go .com</span> <span style="font-weight: bold;"><br />pornxxxfilm .com</span> <span style="font-weight: bold;"><br />porn-sea .com</span> <span style="font-weight: bold;"><br />review-sex .com</span> <span style="font-weight: bold;"><br />sureadult .com</span> <span style="font-weight: bold;"><br />browseadult .com</span> <span style="font-weight: bold;"><br />network-adult .com</span> <span style="font-weight: bold;"><br />timeadult .com</span> <span style="font-weight: bold;"><br />virtual-sexy .net</span><br /><span style="font-weight: bold;">funxxxporn .com</span> <span style="font-weight: bold;"><br />loweradult .com</span> <span style="font-weight: bold;"><br />adultfilmsite .com</span> <span style="font-weight: bold;"><br />xxxallvideo .com</span> <span style="font-weight: bold;"><br />custom-sex .com</span> <span style="font-weight: bold;"><br />g</span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SGJ8FOk2RhI/AAAAAAAAB2M/scnBizNZUOA/s1600-h/fake_porn_sites_ATRIVO2.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SGJ8FOk2RhI/AAAAAAAAB2M/scnBizNZUOA/s200/fake_porn_sites_ATRIVO2.JPG" alt="" id="BLOGGER_PHOTO_ID_5215867747702294034" border="0" /></a><span style="font-weight: bold;">allerypictures .net</span> <span style="font-weight: bold;"><br />usaadultvideo .com</span><br /><span style="font-weight: bold;">adultmovieplus .com</span> <span style="font-weight: bold;"><br />porn-cruise .com</span> <span style="font-weight: bold;"><br />clubxxxvideo .com</span> <span style="font-weight: bold;"><br />mitadult .com</span> <span style="font-weight: bold;"><br />galleryalbum .net</span> <span style="font-weight: bold;"><br />xxxteenfilm .com</span> <span style="font-weight: bold;"><br />hardcorevideosite .com</span> <span style="font-weight: bold;"><br />helpadult .com</span> <span style="font-weight: bold;"><br />portaladult .net</span> <span style="font-weight: bold;"><br />service-sex .com</span> <span style="font-weight: bold;"><br />driveadult .com</span> <span style="font-weight: bold;"><br />access-porno .com</span> <span style="font-weight: bold;"><br />time-sex .com</span> <span style="font-weight: bold;"><br />plus-adult .com</span> <span style="font-weight: bold;"><br />worldadultvideo .com</span><br /><span style="font-weight: bold;">key-adult .com</span><br /><span style="font-weight: bold;">estatesex .com</span> <span style="font-weight: bold;"><br />superadultfriend .com</span><br /><span style="font-weight: bold;">superporncity .com</span> <span style="font-weight: bold;"><br />zero-porno .com</span> <span style="font-weight: bold;"><br />scanadult .com</span> <span style="font-weight: bold;"><br />adultsexpro .com</span> <span style="font-weight: bold;"><br />adultzoneworld .com</span> <span style="font-weight: bold;"><br />porntimeguide .com</span> <span style="font-weight: bold;"><br />usbestporn .com</span> <span style="font-weight: bold;"><br />adulttow .com</span> <span style="font-weight: bold;"><br />look-porn .com</span><br /><span style="font-weight: bold;">galleryclick .net</span><br /><span style="font-weight: bold;">micro-sex .com</span> <span style="font-weight: bold;"><br />estatesex .com</span> <span style="font-weight: bold;"><br />try-sex .com</span> <span style="font-weight: bold;"><br />0bucksforpornmovie .com</span> <span style="font-weight: bold;"><br />gays-video-xxx .com</span> <span style="font-weight: bold;"><br />hackthegrid .com</span> <span style="font-weight: bold;"><br />savetop .info</span> <span style="font-weight: bold;"><br />vidsplanet .net</span> <span style="font-weight: bold;"><br />freexxxhere .com</span> <span style="font-weight: bold;"><br />gestkoeporno .com</span><br /><span style="font-weight: bold;">tv-adult .info</span> <span style="font-weight: bold;"><br />gays-adult-video .com</span> <span style="font-weight: bold;"><br />matures-video .com</span> <span style="font-weight: bold;"><br />analcekc .com</span> <span style="font-weight: bold;"><br />tabletskard .in</span> <span style="font-weight: bold;"><br />molodiedevki .com</span> <span style="font-weight: bold;"><br />dom-porno .com</span> <span style="font-weight: bold;"><br />pornoaziatki .com</span> <span style="font-weight: bold;"><br />latinosvideo .com</span> <span style="font-weight: bold;"><br />geiporno .com</span> <span style="font-weight: bold;"><br />sweetfreeporn .com</span><br /><br />If exposing a huge domains portfolio of currently active redirectors has the potential to ruin someone's vacation, then consider someone's vacation ruined already.<br /><br /><span style="font-weight: bold;">Related posts:<br /></span><a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br /><a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br /><a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XlaQvI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XlaQvI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cI4v2I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cI4v2I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=U4oTAi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=U4oTAi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LbooCi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LbooCi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MITw1I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MITw1I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nqHRRI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nqHRRI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2sf0Xi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2sf0Xi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/319853315" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 08:16:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/about-adult">about-adult</category>
      <category domain="http://securityratty.com/tag/scan-porn">scan-porn</category>
      <category domain="http://securityratty.com/tag/zlob malware variant">zlob malware variant</category>
      <category domain="http://securityratty.com/tag/name-adult">name-adult</category>
      <category domain="http://securityratty.com/tag/useporn">useporn</category>
      <category domain="http://securityratty.com/tag/porn-the">porn-the</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/319853315/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</source>
    </item>
    <item>
      <title><![CDATA[LPL Financial reports eighteen compromised logons]]></title>
      <link>http://securityratty.com/article/cacd9aa988fd370cb50e60d379a7975a</link>
      <guid>http://securityratty.com/article/cacd9aa988fd370cb50e60d379a7975a</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
5/6/08

Organization
LPL Financial

Contractor/Consultant/Branch
None

Victims
Customers

Number Affected
10,219

Types of Data
names, addresses, phone...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/lpl.jpg" align="right" height="60" width="200"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>5/6/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.lpl.com/">LPL Financial</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>10,219<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, addresses, phone numbers, account numbers, Social Security numbers, and dates of birth"<br><br><span style="font-weight: bold;">Breach Description:</span><br>LPL Financial recently notified the Maryland State Attorney General of a breach in which "hackers compromised the logon passwords of fourteen financial advisors and four assistants of LPL Financial ("LPL")."&nbsp; The "hackers used these passwords to gain access to customer accounts in order to "pump and dump" penny stocks."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.oag.state.md.us/idtheft/Breach%20Notices/ITU-152079.pdf">Maryland State Attorney General breach notification</a>&nbsp; <br><br><span style="font-weight: bold;">Report Credit:</span><br>Maryland State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>We write to advise you of incidents in which hackers compromised the logon passwords of fourteen financial advisors and four assistants of LPL Financial ("LPL").<br><span style="font-style: italic;">[Evan] How does a "hacker" compromise usernames and passwords of eighteen people working for the same company?&nbsp; Compromised logon server, spear phishing, malware?</span><br><br>To our knowledge, the hackers used these passwords to gain access to customer accounts in order to "pump and dump" penny stocks.<br><br>Attempted transactions were intercepted and either rejected or reversed.<br><br>No losses were passed on to customers<br><br>Hackers compromised the logon passwords of fourteen financial advisors and four assistants in branch offices located in New Jersey, Illinois, Rhode Island, Pennsylvania, Colorado, Texas, California, Georgia and Connecticut over the course of several months.<br><br>These incidents affected approximately 10,219 individuals<br><br>The information that was potentially accessible included unencrypted names, addresses and Social Security numbers of customers and non-customer beneficiaries.<br><span style="font-style: italic;">[Evan] I don't know the architecture of LPL's network or other infrastructure components, but I question why customers or financial advisors need access to Social Security numbers as part of a trading system.&nbsp; I know that LPL needs to store Social Security numbers for tax and other reporting purposes, but financial advisors, traders and customers don't need access to them.</span><br><br>At this time, LPL has no specific knowledge that any customer information was accessed or misused as a consequence of the breach<br><br>We also are unaware of any personal instance of identity theft related to these incidents.<br><br>LPL learned of the first incident on July 16, 2007 and took the following actions: (1) notified law enforcement; (2) notified our primary regulator, the Financial Industry Regulatory Authority; (3) investigated the situation; (4) determined what information had been compromised; and (5) notified and offered solutions to the affected individuals.<br><br>LPL has taken several important steps to improve its level of data security and compliance<br><br>LPL has increased the profile of data security issues within the company at all levels, up to and including senior management.<br><br>In March 2008, LPL hired Marc Loewenthal as SVP - Chief Security/Privacy Officer, a newly created position at LPL.<br><span style="font-style: italic;">[Evan] This is the first breach notification that I have read that included this type of information.&nbsp; I don't know Mr. Loewenthal (which doesn't say too much), but I do know that he is stepping into a pressure situation.</span><br><br>Mr. Loewenthal has extensive experience in the area of data protection.&nbsp; As a member of senior management, he reports directly to the Chief Risk Officer of LPL.<br><span style="font-style: italic;">[Evan] I like when I read about information security personnel occupying "senior management" positions.&nbsp; Effective information security management needs to be as "senior" as possible in order to effect change in the organization.&nbsp; Information security governance is NOT an IT issue, but an organizational issue.&nbsp; There needs to be more good CISOs and CSOs.</span><br><br>In addition, LPL has developed a new, comprehensive information privacy and security program with new policies and procedures that were implemented in April 2008.<br><br>In August 2007, LPL engaged the services of Kroll Inc. ("Kroll"), a risk consulting company, to provide various services<br><br>In addition, LPL has commenced a project to enhance security on its advisor facing trading and operations systems in September 2007 and expects the project to complete in December 2008.<br><span style="font-style: italic;">[Evan] Details are not available, but I would be interested in knowing more.&nbsp; Maybe removal of SSNs from the advisor facing trading systems and two-factor authentication are part of the mix.</span><br><br>Finally, LPL recently engaged the services of Edwards Angell Palmer &amp; Dodge LLP to advise Mr. Loewenthal and LPL's in-house counsel as needed on information privacy and security issues.<br><br>LPL Financial is providing affected individuals with credit protection services from Kroll, Inc.<br><br>If you have any questions or feel you have an identity theft issue, please call ID TheftSmart at 1-800-588-9839 between 9:00 a.m. and 6:00 p.m. (Eastern Time), Monday through Friday.<br><br>If you want to talk to someone at LPL Financial to clarify or discuss the contents of this letter, please call us 1-800-558-7567, option 3 - Customer Service, between 9:00 a.m. and 6:00 p.m. (Eastern Time), Monday through Friday.<br><br>We apologize for any inconvenience or concern this situation may cause.<br><br>We at LPL Financial believe it is important for you to be fully informed of any potential risk resulting from this incident.<br><br>We remain committed to maintaining customer privacy as a key priority and will continue to take the needed steps to protect your information.<br><br><span style="font-weight: bold;">Commentary:</span><br>What makes this breach so interesting to me is the fact that there were at least 18 points of attack.&nbsp; I don't get the feeling that this was some sophisticated high-tech "hack" of LLP Financial's systems.&nbsp; It is much easier to craft an email or call someone and convince them to give you their login information.&nbsp; <br><br>Good luck Mr. Loewenthal, I'm sure you'll do fine! <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/20/lpl.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 20 May 2008 04:56:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lpl financial">lpl financial</category>
      <category domain="http://securityratty.com/tag/lpl">lpl</category>
      <category domain="http://securityratty.com/tag/lpl financial recently">lpl financial recently</category>
      <category domain="http://securityratty.com/tag/lpl recently">lpl recently</category>
      <category domain="http://securityratty.com/tag/login information">login information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information security governance">information security governance</category>
      <category domain="http://securityratty.com/tag/information privacy">information privacy</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <source url="http://breachblog.com/2008/05/20/lpl.aspx">LPL Financial reports eighteen compromised logons</source>
    </item>
    <item>
      <title><![CDATA[Rhode Island Dept. of Administration can't find HR disk]]></title>
      <link>http://securityratty.com/article/5ee225fec9bcaa77ca557691607a56b7</link>
      <guid>http://securityratty.com/article/5ee225fec9bcaa77ca557691607a56b7</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
3/21/08

Organization
State of Rhode Island

Contractor/Consultant/Branch
Department of Administration

Victims
State employees

Number Affected
1,400
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/ridoa.jpg" align="right" height="33" width="200"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>3/21/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.ri.gov/">State of Rhode Island</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.admin.ri.gov/">Department of Administration</a> <br><br><span style="font-weight: bold;">Victims:</span><br>State employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>~1,400<br><br><span style="font-weight: bold;">Types of Data:</span><br>Human resources records including Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>"A state computer disk containing the social security numbers of nearly 1,400 people has been reported missing."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.southcoasttoday.com/apps/pbcs.dll/article?AID=/20080321/NEWS/803210414/-1/NEWS01">SouthCoast Today</a> <br><a href="http://www.wpri.com/Global/story.asp?S=8051471">WPRI Eyewitness News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Associated Press<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>A state computer disk containing the Social Security numbers of nearly 1,400 people is missing, the state Department of Administration announced Friday.<br><br>The department said there was no evidence that any number had been misused or that the disk had fallen into the hands of an unauthorized person.<br><br>It was working with the Rhode Island State Police to find the disk.<br><br>"We do not believe that it was stolen, we just believe it was misplaced at this point in time," said Melanie Marcaccio, the department's deputy personnel director. "We don't believe that individuals outside of the organization had any access to that data at any point in that time."<br><span style="font-style: italic;">[Evan] Eventually the lost disk will be found.&nbsp; The question is by who and what will they do with it?&nbsp; The sad thing is that the information could cause damage if the answers are wrong.</span><br><br>The majority of the 1,400 people affected are state employees whose Social Security numbers were kept in human resources records<br><br>The information was discovered missing within the last two weeks when human resources staff members who had relocated from Providence to Cranston could not find the data on the server<br><br>The DOA sent a letter Thursday to all those affected, telling them the disk was missing and urging them to put a fraud alert on their credit file so creditors would contact them before any new accounts opened or any existing accounts changed.<br><br><span style="font-weight: bold;">Commentary:</span><br>Has anyone seen a disk lying around labeled "<span style="font-style: italic;">State of Rhode Island, Department of Administration - CONFIDENTIAL</span>"?<br><br>Sensitive personal information requires more control than this.&nbsp; Was the disk encrypted? <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/03/24/ridoa.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 24 Mar 2008 12:36:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/disk">disk</category>
      <category domain="http://securityratty.com/tag/rhode island">rhode island</category>
      <category domain="http://securityratty.com/tag/lost disk">lost disk</category>
      <category domain="http://securityratty.com/tag/computer disk">computer disk</category>
      <category domain="http://securityratty.com/tag/social security">social security</category>
      <category domain="http://securityratty.com/tag/administration">administration</category>
      <category domain="http://securityratty.com/tag/human resources records">human resources records</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/wpri eyewitness news">wpri eyewitness news</category>
      <source url="http://breachblog.com/2008/03/24/ridoa.aspx">Rhode Island Dept. of Administration can't find HR disk</source>
    </item>
    <item>
      <title><![CDATA[Thieves steal four Diocese of Providence computers]]></title>
      <link>http://securityratty.com/article/8ad9d757579cc857b045427c5732a698</link>
      <guid>http://securityratty.com/article/8ad9d757579cc857b045427c5732a698</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
2/1/08

Organization
Roman Catholic Diocese of Providence

Contractor/Consultant/Branch
None

Victims
Current and former Catholic school employees
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/dop.jpg" align="right" height="69" width="198"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>2/1/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.dioceseofprovidence.org/index.php" target="_blank"> Roman Catholic Diocese of Providence</a><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Current and former Catholic school employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>about 5,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>Sometime during the weekend of January 27th, 2008 thieves broke into the Chancery of the Roman Catholic Diocese of Providence and stolen four desktop computers, one of which contained sensitive personal information belonging to current and former Catholic school employees.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.dioceseofprovidence.org/?id=212" target="_blank"> The Diocese of Providence online announcement</a> <br><a href="http://www.projo.com/news/content/catholic_identity_theft_02-02-08_BK8S2PA_v13.363690c.html" target="_blank"> The Providence Journal online story</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>The Diocese of Providence<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>An individual or individuals broke into the Diocesan Office Building (also known as the Chancery) located at One Cathedral Square in Providence.&nbsp; The perpetrator(s) gained access by breaking through an office window in the Catholic School Office suite.<br><br>Once in the building, the perpetrators forcibly entered through two locked office doors where they stole desktop computers and other equipment.<br><br>The office suite that was burglarized did not have an alarm system<br><span style="font-style: italic;">[Evan] It was reported that the Diocese does employ a security guard, but it is not known where he/she was at the time of the break-in.&nbsp; The fact that the timeframe in question is 8 hours (10 PM Friday - 6 AM Saturday) is interesting.&nbsp; Typically security guards are expected to make regular rounds (~ once every hour or two) throughout the area being guarded.&nbsp; Eight hours is a long time for a break-in to go undetected, so an alarm system would have been very beneficial as an alert if not a deterrent.</span><br><br>One of the stolen computers (a desktop computer, not a laptop) contained a substantial amount of data that included personnel information on present and former Catholic school employees throughout the Diocese of Providence. <br><br>The Rhode Island State Police have been notified of this incident.&nbsp; Additionally, the Providence Police Department has assumed responsibility for the investigation.<br><br>Thus far, the stolen equipment has not been recovered however, the Catholic Schools Office is fully cooperating with law enforcement who are investigating the situation.<br><br>Present and former employees of Rhode Island Catholic schools may be affected.<br><br>A number of safeguards are in place such as: locked offices, password protected computers, local administrator account password protected, guest accounts disabled.<br><span style="font-style: italic;">[Evan] These are all good security practices.</span><br><br>Employees have unique passwords that they are required to change every few weeks<br><span style="font-style: italic;">[Evan] Another good security practice, but every few weeks might be a little too often.&nbsp; If we make people change their passwords too often we increase the chances that they will write them down.</span><br><br>Additionally, personal information of students, teachers, parents and others associated with the Catholic Schools Office are prohibited from storage on lap top computers.<br><span style="font-style: italic;">[Evan] Yet another good security practice.</span><br><br>Personal information of students and their parents and or guardians was not stored on the stolen equipment.<br><br>In addition to notifying current and former employees by letters sent to last known addresses, the Catholic Schools Office has created this page on&nbsp; the web site and established a special phone number, 401/278-4678 to answer inquiries from those who feel they may have been affected<br><br>Another diocese office was broken into about a year ago and a computer stolen<br><br>“The Catholic schools office sincerely apologizes for any inconvenience this incident may cause its current and former employees,”<br><br><span style="font-weight: bold;">Commentary:</span><br>Judging from what the Diocese has told us about their security practices it is easy to see that they have made a conscience effort to secure confidential information.&nbsp; They put some sound information security practices to use, but now we understand that it wasn't enough.&nbsp; At least two vital information security controls were missed; data at rest encryption and adequate physical security (alarm system missing).&nbsp; There is no mention as to whether or not the Diocese or Chancery are surveilled. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br>
<br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/02/04/dop.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 04 Feb 2008 05:48:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/diocese">diocese</category>
      <category domain="http://securityratty.com/tag/providence">providence</category>
      <category domain="http://securityratty.com/tag/computers">computers</category>
      <category domain="http://securityratty.com/tag/roman catholic diocese">roman catholic diocese</category>
      <category domain="http://securityratty.com/tag/catholic school employees">catholic school employees</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/providence police department">providence police department</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/catholic schools office">catholic schools office</category>
      <source url="http://breachblog.com/2008/02/04/dop.aspx">Thieves steal four Diocese of Providence computers</source>
    </item>
    <item>
      <title><![CDATA[Blended Attacks and The Tiger Team]]></title>
      <link>http://securityratty.com/article/c87ddb6e3ecb4e72465b76b938fdf709</link>
      <guid>http://securityratty.com/article/c87ddb6e3ecb4e72465b76b938fdf709</guid>
      <description><![CDATA[The following caught my eye during a review of the Cisco 2007 Annual Security Report, on page 16
Blended Attacks Targeting Both Physical and IT Domains
In 2007, criminals demonstrated their evolving...]]></description>
      <content:encoded><![CDATA[<p>The following caught my eye during a review of the  Cisco 2007 Annual Security Report, on page 16:</p>
<blockquote><p><strong>Blended Attacks Targeting Both Physical and IT Domains</strong><br />
In 2007, criminals demonstrated their evolving ingenuity by employing blended attacks to obtain sensitive information and evade detection. The most significant example of this trend was a string of attacks on Stop &amp; Shop supermarkets in Rhode Island. Attackers broke into and vandalized supermarkets, leading police to believe the events were largely petty crimes. But during the break-ins, attackers tampered with the stores’ card readers to collect credit card information.</p></blockquote>
<p>Of course, upon reading this there was a stream of attack ideas that occurred to me such as using a break-in as a cover for things like installing WIFI access to networks, card skimmers, key loggers, etc. Shortly after reading the Cisco report, I ran into a post on <a href="http://www.toool.nl/blackbag/?p=156" target="_blank" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.toool.nl/blackbag/?p=156');">Black Bag</a> (a physical security blog) about a TV show called <a href="http://en.wikipedia.org/wiki/Tiger_Team_(TV_series)" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://en.wikipedia.org/wiki/Tiger_Team_(TV_series)');">Tiger Team</a>. The TV show is about a team of penetration testers who (in addition to being very impressed with themselves) test complex physical security systems. I reviewed the first two episodes (which I have to confess I enjoyed), which are <a href="http://www.trutv.com/video/?id=870&amp;link=" target="_blank" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://www.trutv.com/video/?id=870&amp;link=');">available via streaming video</a>.</p>
<p>Interestingly, in the first two episodes (which is all I have watched so far&#8230;) the team always used a blended attack. There is a social engineering and digital attack as a prelude to the actual &#8216;theft&#8217; in both episodes.</p>
<p>I think few people will face attackers of this sophistication, but the series is interesting nonetheless.</p>
<p>Cheers, Erik</p>
<p><a href="http://artofinfosec.com" >Art of Information Security</a> would <a href="http://artofinfosec.com/feedback/" >love your feedback</a> !</p>
<p><a href="http://artofinfosec.com/44/blended-attacks-and-the-tiger-team/" >Blended Attacks and &#8220;The Tiger Team&#8221;</a></p>
<img src="http://feeds.feedburner.com/~r/artofinfosec/~4/212945927" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 08 Jan 2008 00:07:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tiger team">tiger team</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/attack ideas">attack ideas</category>
      <category domain="http://securityratty.com/tag/physical security blog">physical security blog</category>
      <category domain="http://securityratty.com/tag/physical">physical</category>
      <category domain="http://securityratty.com/tag/cisco report">cisco report</category>
      <category domain="http://securityratty.com/tag/annual security report">annual security report</category>
      <source url="http://feeds.feedburner.com/~r/artofinfosec/~3/212945927/">Blended Attacks and The Tiger Team</source>
    </item>
  </channel>
</rss>
