<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: rights]]></title>
    <link>http://securityratty.com/tag/rights</link>
    <description></description>
    <pubDate>Tue, 16 Sep 2008 03:52:18 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[No Court Order Needed to Spy on Americans Overseas, Appeals Court Rules]]></title>
      <link>http://securityratty.com/article/f122524e53ae750bfb90e8d1242de99b</link>
      <guid>http://securityratty.com/article/f122524e53ae750bfb90e8d1242de99b</guid>
      <description><![CDATA[The government does not need a judge's approval to wiretap Americans overseas, an appeals court ruled, rejecting the appeal of an American convicted of helping plan the 1998 East Africa embassy...]]></description>
      <content:encoded><![CDATA[The government does not need a judge's approval to wiretap Americans overseas, an appeals court ruled, rejecting the appeal of an American convicted of helping plan the 1998 East Africa embassy bombings. The ruling comes as rights groups challenge the government's warrantless wiretapping program and newly granted powers to set up electronic dragnets inside the United States.<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=f8839069d601fd60cba8ceeee8211737&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=f8839069d601fd60cba8ceeee8211737&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=f8839069d601fd60cba8ceeee8211737" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=UlQ2N"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=UlQ2N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=AMMgn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=AMMgn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=cGhvn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=cGhvn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=feHjN"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=feHjN" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=6cYYN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=6cYYN" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=C8VOn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=C8VOn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=ywbxn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=ywbxn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=AiHKN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=AiHKN" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/466638136" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/466638137" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 26 Nov 2008 16:58:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wiretap americans overseas">wiretap americans overseas</category>
      <category domain="http://securityratty.com/tag/electronic dragnets inside">electronic dragnets inside</category>
      <category domain="http://securityratty.com/tag/appeals court ruled">appeals court ruled</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/rights">rights</category>
      <category domain="http://securityratty.com/tag/appeal">appeal</category>
      <category domain="http://securityratty.com/tag/program">program</category>
      <category domain="http://securityratty.com/tag/powers">powers</category>
      <category domain="http://securityratty.com/tag/challenge">challenge</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/466638137/no-court-order.html">No Court Order Needed to Spy on Americans Overseas, Appeals Court Rules</source>
    </item>
    <item>
      <title><![CDATA[News Report on Non Vulnerability in Windows Vista]]></title>
      <link>http://securityratty.com/article/3a7950aaea1375ea46dc4f0439559b20</link>
      <guid>http://securityratty.com/article/3a7950aaea1375ea46dc4f0439559b20</guid>
      <description><![CDATA[Are editors so excited to use the headline Vulnerability in Windows Vista in their SEO URLs that they will have their reporters write a story on a non-issue
IDG News has published a news report...]]></description>
      <content:encoded><![CDATA[<p>Are editors so excited to use the headline &#8220;Vulnerability in Windows Vista&#8221; in their SEO URLs that they will have their reporters write a story on a non-issue? </p>
<p>IDG News has published a news report titled, &#8220;<a href="http://www.itworld.com/windows/58144/researchers-find-vulnerability-windows-vista">Researchers find vulnerability in Windows Vista</a>&#8220;. The report says:</p>
<blockquote><p>An Austrian security vendor has found a vulnerability in Windows Vista that it says could possibly allow an attacker to run unauthorized code on a PC.</p>
<p>The problem is rooted in the Device IO Control, which handles internal device communication. Researchers at Phion have found two different ways to cause a buffer overflow that could corrupt the memory of the operating system&#8217;s kernel.</p>
<p>In one of the scenarios, a person would already have to have administrative rights to the PC. In general, vulnerabilities that require that level of access somewhat undermine the risk since the attacker already has permission to use to the PC.</p></blockquote>
<p>Somewhat undermine the risk? If you need admin rights to exercise a bug it is not a security issue since you could already run any code with whatever privilege you wanted.  Microsoft is not issuing a patch, but creating a bug fix in a service pack, yet this is newsworthy?  This story has no comment from anyone but the finder of the bug.  Let&#8217;s see if other news outlets pick up on this one.</p>
]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 15:41:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows vista">windows vista</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/news report">news report</category>
      <category domain="http://securityratty.com/tag/report">report</category>
      <category domain="http://securityratty.com/tag/bug fix">bug fix</category>
      <category domain="http://securityratty.com/tag/bug">bug</category>
      <category domain="http://securityratty.com/tag/headline vulnerability">headline vulnerability</category>
      <category domain="http://securityratty.com/tag/austrian security vendor">austrian security vendor</category>
      <category domain="http://securityratty.com/tag/news outlets pick">news outlets pick</category>
      <source url="http://www.veracode.com/blog/2008/11/news-report-on-non-vulnerability-in-windows-vista/">News Report on Non Vulnerability in Windows Vista</source>
    </item>
    <item>
      <title><![CDATA[Zeus Crimeware Kit Gets a Carding Layout]]></title>
      <link>http://securityratty.com/article/2dadca90df89c26f3f517a1e2b237afd</link>
      <guid>http://securityratty.com/article/2dadca90df89c26f3f517a1e2b237afd</guid>
      <description><![CDATA[With cybercriminals clearly expressing their nostalgia for several notorious and already shut down credit card fraud communities, they seem to have found a way to once again give their self-esteem a...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgXkf4easI/AAAAAAAACbU/eTHcGM--Oww/s1600-h/zeus_new_layout_22.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgXkf4easI/AAAAAAAACbU/eTHcGM--Oww/s200/zeus_new_layout_22.GIF" /></a>With cybercriminals clearly expressing their nostalgia for several notorious and already shut down credit card fraud communities, they seem to have found a way to once again give their self-esteem a boost. Following the <a href="http://ddanchev.blogspot.com/2008/11/modified-zeus-crimeware-kit-gets.html">ongoing modification</a> of open source <a href="http://ddanchev.blogspot.com/2008/09/modified-zeus-crimeware-kit-comes-with.html">crimeware kits</a> and the inevitable innovation introduced <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">by third parties</a>, last week a new layout was introduced for Zeus, once again courtesy of a group that's piggybacking on Zeus popularity.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div>It's particularly interesting to see how a one-man operation evolves into a group of third-party developers starting to claim ownership rights over the modified versions despite that they're basically brandjacking the Zeus brand and building business models on the top of it.<br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgZzIlf-eI/AAAAAAAACbc/YsBowySVmSk/s1600-h/zeus_new_layout_11.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgZzIlf-eI/AAAAAAAACbc/YsBowySVmSk/s200/zeus_new_layout_11.GIF" /></a>Open source crimeware and web malware exploitation kits on the other hand undermine the business model of a great number of "<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">malware/spyware for hire</a>" vendors, which surprisingly doesn't stop them from continuing offering their services and products which are often using the de facto crimeware kits as the foundations for their propositions. Are the buyers even aware of this fact? From a buyer's perspective in times when most of the output is sold in bulk form, or access to the botnet rented for a specific period of time, the buyer doesn't care about the cybercrime platform of use, but is looking for transparent ways to justify the investment he's made into renting the service.<br />
<br />
Now that Zeus administrators and their cybercrime clerks in the face of those managing the campaigns knowingly or unknowingly knowing the type of campaigns and the data that they manage, can <a href="http://ddanchev.blogspot.com/2008/09/modified-zeus-crimeware-kit-comes-with.html">listen to their favorite music within Zeus</a> and choose different layouts for the command and control interfaces while commiting cybercrime, what's next?<br />
<br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Convergence</a> and improved monetization.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fQb6N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fQb6N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Rhj0N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Rhj0N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9MADn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9MADn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Kqtmn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Kqtmn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Cqo2N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Cqo2N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pkhEN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pkhEN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=i9tYn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=i9tYn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/448333234" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 02:53:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/zeus">zeus</category>
      <category domain="http://securityratty.com/tag/zeus administrators">zeus administrators</category>
      <category domain="http://securityratty.com/tag/zeus popularity">zeus popularity</category>
      <category domain="http://securityratty.com/tag/source crimeware kits">source crimeware kits</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/cybercrime clerks">cybercrime clerks</category>
      <category domain="http://securityratty.com/tag/source crimeware">source crimeware</category>
      <category domain="http://securityratty.com/tag/zeus brand">zeus brand</category>
      <category domain="http://securityratty.com/tag/cybercrime platform">cybercrime platform</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/448333234/zeus-crimeware-kit-gets-carding-layout.html">Zeus Crimeware Kit Gets a Carding Layout</source>
    </item>
    <item>
      <title><![CDATA[Windows 7 UAC changes just 'lipstick,' argues vendor]]></title>
      <link>http://securityratty.com/article/c6885fc34bd69f3b73e671d887f16ded</link>
      <guid>http://securityratty.com/article/c6885fc34bd69f3b73e671d887f16ded</guid>
      <description><![CDATA[Microsoft's plans to change the controversial User Account Control security feature in Windows 7 represent only cosmetic changes, a developer of enterprise rights management tools said...]]></description>
      <content:encoded><![CDATA[Microsoft's plans to change the controversial User Account Control security feature in Windows 7 represent only cosmetic changes, a developer of enterprise rights management tools said today.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:b74db08e6797d42016115bed77ee7d84:7KDf2AjIQ8FH9dAbOmLb7vthObypIe17NIIORmSwBKciTGCuMDKT7K6tC%2Fg58ADlSDlANWiRiWGz'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:2bf1dd3082bbe632af9bfd1d9529d6d2:GrTBRSz0uVenqEnlkPrBCONRiOZ2EAhvVoZ%2Fzg4SU8Z4a2kHYoSIC2X4xZFDoRR1RJCDTL7sCVvU5w%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:bc829a800822e3e130ed9c2088078812:y8PxuH5WVBq6EAdAvjSLJV%2BAtqHLMqVSdq7ghpuT7pR705l1HvJFBjvSpYJr3vXyhW26vhfjxsGN0Q%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:085ac6e773cbefe2c45344fc9f5e40b9:nxVQ5Ee6XTpDF%2BqXWEzk%2BX3MY5Kotibi9OUsgd%2Bsxuo4bONZ0rbAsHBdeAmpPRh4bsvGKiDCUGu0RQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=dc9050f0e13388bd9a576d7c8504126a" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=dc9050f0e13388bd9a576d7c8504126a" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 01:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/plans">plans</category>
      <category domain="http://securityratty.com/tag/change">change</category>
      <category domain="http://securityratty.com/tag/developer">developer</category>
      <category domain="http://securityratty.com/tag/represent">represent</category>
      <category domain="http://securityratty.com/tag/cosmetic">cosmetic</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=dc9050f0e13388bd9a576d7c8504126a">Windows 7 UAC changes just 'lipstick,' argues vendor</source>
    </item>
    <item>
      <title><![CDATA[Massive SQL Injection Attacks - the Chinese Way]]></title>
      <link>http://securityratty.com/article/42e493c2424af4f8ef6cc5dd581317bf</link>
      <guid>http://securityratty.com/article/42e493c2424af4f8ef6cc5dd581317bf</guid>
      <description><![CDATA[From copycats and &quot;localizers&quot; of Russian web malware exploitation kits , to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP46U3HSQHI/AAAAAAAACUY/QH40puDsgXY/s1600-h/security_company_hacking_tools.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP46U3HSQHI/AAAAAAAACUY/QO3L0OWKJcY/s200-R/security_company_hacking_tools.JPG" /></a>From <a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">copycats</a> and <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">"localizers" of Russian web malware exploitation kits</a>, to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the obvious insecurities on a large scale, and so is either filling the niches left open by other international communities, or coming up with tools setting new benchmarks for massive SQL injection attacks, like the case with this one :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5DX0GzAtI/AAAAAAAACUg/3GOnK2TsSRk/s1600-h/search_engines_mass_SQL_injection.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5DX0GzAtI/AAAAAAAACUg/pdCwjwri7LM/s200-R/search_engines_mass_SQL_injection.JPG" /></a>"<i>A professional web site vulnerability scanning, use of tools, SQL injection is a new generation of tools to help Web developers and site of the station quickly find vulnerabilities in order to be able to effectively prepare Security work. At the same time, the tool to Web developers to demonstrate the ways in which hackers are using these vulnerabilities, hackers, as well as through the loopholes to do things, can effectively raise the safety awareness of relevant personnel.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DkEEtbqI/AAAAAAAACUo/Mm7pCwd7LT4/s1600-h/search_engines_mass_SQL_injection2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DkEEtbqI/AAAAAAAACUo/qMaY93_QOvY/s200-R/search_engines_mass_SQL_injection2.JPG" /></a>Nothing's wrong with the marketing pitch at the first place, but going through the features, the "massive SQL injections through search engine reconnaissance" and automatic page rank verification which you can see in the attached screenshots, ruin the "security auditing" marketing pitch. The tool not only allows easy integration of potentially vulnerable sites obtained through <a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">search engines reconnaissance</a>, but also, is prioritizing the results based on the probability for successful injection, next to the page rank of the domains in question. A simple demonstration offered by the company is also, directly enticing its users to "localize" the search engine reconnaissance, by filtering the search results for a particupar country, in this case they used French sites for one of the demos. Here are some excerpts from its CHANGE log speaking for themselves :<br />
<br />
"<i><b>2008.7.15 release version 1.3 </b><br />
&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DyBXVu7I/AAAAAAAACUw/37LsW8yh_AE/s1600-h/chinese_SQL_injector.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DyBXVu7I/AAAAAAAACUw/ub8OVgeWC6Y/s200-R/chinese_SQL_injector.png" /></a><i>- New powerful "automatic machine cycle" feature&nbsp;</i><br />
<i>- Automatic machine cycle is to provide assistance to the advanced user manual into the use of a very&nbsp;</i><br />
<i>- powerful and flexible module, the main sites used for some special filtering into the hand, is almost a&nbsp;</i><br />
<i>- universal tool, you can achieve the following: <br />
&nbsp;</i><br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SP5D-g3FyAI/AAAAAAAACU4/xYACViJuVn4/s1600-h/chinese_SQL_injector2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SP5D-g3FyAI/AAAAAAAACU4/oPVCur3PMgI/s200-R/chinese_SQL_injector2.png" /></a><i>1. In support of GET / POST / COOKIES in a variety of ways, such as the injection.&nbsp;</i><br />
<i>2. Scan the key to the page (background, upload, WebShell, databases, backup files, etc.).&nbsp;</i><br />
<i>3. According to the dictionary to violence landing back-guess solution WebShell password and password (required to verify that the code can not guess solution).&nbsp;</i><br />
<i>4. Page language does not limit the types and databases (to provide specific statements into the database).&nbsp;</i><br />
<i>5. At the same time, support for the circulation of the two variables and two dictionaries, fast running and violent content of the database solution to guess a password.</i>"<br />
<br />
It gets even more interesting in terms of the massive SQL injection attacks mentality which is pretty evident on all fronts :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5ELiLoBiI/AAAAAAAACVA/0fb6Epapby0/s1600-h/chinese_SQL_injector3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5ELiLoBiI/AAAAAAAACVA/nmrC87TeCxo/s200-R/chinese_SQL_injector3.png" /></a>"<i>- The use of the three search engine sites scans to invade the side to complete<br />
- in scanning probe into the Web site ranking points<br />
- added, "VBS upload to download", "upload directory Web site viewer," "FTP upload to download configuration file" function to make it more convenient for the sa rights to use the site. <br />
- New "sequence document scanners" <br />
- What is the sequence document scanners role? Upload to find loopholes, some of the procedures to upload the file after the upload will be renamed, rename the way the system is usually based on time or incremental increase in the number prefix code for the upload process, if not to return after the file name, Upload files to know the url is usually very difficult to sequence the use of paper scanner can be scanned out</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5FUvl0FhI/AAAAAAAACVY/Y5mM2l7Q6K4/s1600-h/chinese_SQL_injector4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5FUvl0FhI/AAAAAAAACVY/DU7feV1pnjU/s200-R/chinese_SQL_injector4.png" /></a><i><br />
- The best reverse domain name query engine, and quasi-wide <br />
- in scanning the database of basic information, an increase of the database of information related to the process, the link has information on the database server user login (sa need permission) <br />
- control of the interface had a big adjustment, the interface process easier to understand and operate. <br />
- based on a significant site of the wrong mode of access to a comprehensive code optimization and more accurate access to the content, accuracy and access to show progress. <br />
- added, "VBS upload to download", "upload directory Web site viewer," "FTP upload to download configuration file" function to make it more convenient for the sa rights to use the site.&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FgfdkSbI/AAAAAAAACVg/R77obP_vxig/s1600-h/chinese_SQL_injector5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FgfdkSbI/AAAAAAAACVg/ORo853Aicy4/s200-R/chinese_SQL_injector5.png" /></a><i><br />
- point into the types of improved detection order to improve the efficiency of detection. <br />
- improved automatic keyword detection, automatic keyword detection more accurate. <br />
- probe into the points the way to improve and increase the use of automatic detection of the keyword detection. <br />
- type of database to improve the detection, the use of the contents of the length of the failure to detect the type of database automatically switch to the probe through the keyword. <br />
- automatically save and load solution has been to guess the tree structure of the database, guess Solutions has been the content and structure of the database will automatically save and open the next time the injection point will be automatically made available, the solutions do not have to guess again, the continuity of work Greatly increased.&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FrcWctII/AAAAAAAACVo/DcQNU5crc5k/s1600-h/chinese_SQL_injector6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="131" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FrcWctII/AAAAAAAACVo/9zGp4bsPB2U/s200-R/chinese_SQL_injector6.png" width="200" /></a><i><br />
- solved from the database to read large amounts of data (on hundreds of thousands or millions of records), the half-way card program will die. <br />
- increased significantly on the wrong model of ASP.NET and SQL Server2005 significant mode of dealing with mistakes, error messages can be extracted from a Web directory! <br />
- significant amendments to the wrong mode, some of the injected one by one point in the field or access to the contents of the issue can not be successful (error code in hand); for increased access to specific points table and into the field.&nbsp;</i><br />
<i><br />
- amendments to the text of a significant error patterns to detect and correct use of loopholes in the system can be used more to expand. (Text significantly in the wrong mode in version 1.1 already supported, but in the version 1.2 upgrade in the process of scanning to improve the performance of the Gaodiao careless. -_-#) <br />
- on a variety of encoded text can be significantly wrong in the right-compatible, able to correctly handle the ASP.NET page of the text marked wrong. Through custom error keyword, truly compatible with any language, any coding error message. <br />
- crack anti-improvement and enhancement. <br />
- An increase of auto-detection feature keywords.&nbsp;</i><br />
<i><br />
- Mssql database specifically for significant points into the wrong mode of detection and the use of up and down the hard work, and many other software can not detect the point of injection can also be used. <br />
- Automatic save and load access to the database, to allow manual known to add tables and fields for solutions to guess. <br />
- Can be used to amend the degree of accuracy; optimize the code to reduce memory footprint; enhance the stability of multi-threading. <br />
- Significant amendments to the wrong mode solution guess the contents of the database must be checked first field defects.</i>"<br />
<br />
The public version of the tool has been in the while for over an year, with a VIP version available to customers only.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PsITM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PsITM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JBO9M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JBO9M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=owYAm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=owYAm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LTzNm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LTzNm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LaPQM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LaPQM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=go5fM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=go5fM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rYJ9m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rYJ9m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/427878843" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 21 Oct 2008 12:18:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/keyword detection">keyword detection</category>
      <category domain="http://securityratty.com/tag/detection">detection</category>
      <category domain="http://securityratty.com/tag/database">database</category>
      <category domain="http://securityratty.com/tag/database solution">database solution</category>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/upload process">upload process</category>
      <category domain="http://securityratty.com/tag/text">text</category>
      <category domain="http://securityratty.com/tag/load solution">load solution</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/427878843/massive-sql-injection-attacks-chinese.html">Massive SQL Injection Attacks - the Chinese Way</source>
    </item>
    <item>
      <title><![CDATA[Liberal Democrat leader visits our lab]]></title>
      <link>http://securityratty.com/article/a69300e89ab3d33e212394e88a14206b</link>
      <guid>http://securityratty.com/article/a69300e89ab3d33e212394e88a14206b</guid>
      <description><![CDATA[This week, Nick Clegg , leader of the UK Liberal Democrat Party, and David Howarth , MP for Cambridgeshire, visited our hardware security lab for a demonstration of Chip &amp; PIN fraud techniques
They...]]></description>
      <content:encoded><![CDATA[<p>This week, <a href="http://www.nickclegg.com/">Nick Clegg</a>, leader of the UK Liberal Democrat Party, and <a href="http://www.davidhowarth.org.uk/">David Howarth</a>, MP for Cambridgeshire, visited our <a href="http://www.cl.cam.ac.uk/research/security/tamper/">hardware security lab</a> for a demonstration of <a href="http://www.cl.cam.ac.uk/research/security/banking/">Chip &amp; PIN fraud techniques</a>.</p>

<a href='http://www.lightbluetouchpaper.org/2008/10/17/nick-clegg-visits/clegg-visit3/' title='clegg-visit3'><img src="http://www.lightbluetouchpaper.org/wp-content/uploads/2008/10/clegg-visit3.jpg" width="150" height="112" class="attachment-thumbnail" alt="" /></a>
<a href='http://www.lightbluetouchpaper.org/2008/10/17/nick-clegg-visits/clegg-visit1/' title='clegg-visit1'><img src="http://www.lightbluetouchpaper.org/wp-content/uploads/2008/10/clegg-visit1.jpg" width="150" height="112" class="attachment-thumbnail" alt="" /></a>
<a href='http://www.lightbluetouchpaper.org/2008/10/17/nick-clegg-visits/clegg-visit5/' title='clegg-visit5'><img src="http://www.lightbluetouchpaper.org/wp-content/uploads/2008/10/clegg-visit5.jpg" width="150" height="112" class="attachment-thumbnail" alt="" /></a>

<p>They used this visit to announce their new <a href="http://www.nickclegg.com/2008/10/new-protections-against-identity-fraud-needed-clegg/">party policy on protections against identity fraud</a>. At present, credit rating companies are exempt from aspects of the Data Protection Act and can forward personal information about an individual&#8217;s financial history to companies without the subject&#8217;s consent. Clegg proposes to give individuals the rights to &#8220;freeze&#8221; their credit records, making it more difficult for fraudsters to impersonate others.</p>
<p>See also the <a href="http://www.cambridge-news.co.uk/cn_news_home/DisplayArticle.asp?ID=358491">Cambridge Evening News article</a> and <a href="http://www.cambridge-news.co.uk/cn_video/media/16th_October_2008_Nick_Clegg_visit_to_Cambridge_Computer_Labs_DJ.wmv">video interview</a>.</p>
]]></content:encoded>
      <pubDate>Fri, 17 Oct 2008 15:05:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/individuals financial history">individuals financial history</category>
      <category domain="http://securityratty.com/tag/individuals">individuals</category>
      <category domain="http://securityratty.com/tag/data protection act">data protection act</category>
      <category domain="http://securityratty.com/tag/credit records">credit records</category>
      <category domain="http://securityratty.com/tag/forward personal information">forward personal information</category>
      <category domain="http://securityratty.com/tag/pin fraud techniques">pin fraud techniques</category>
      <category domain="http://securityratty.com/tag/liberal democrat party">liberal democrat party</category>
      <category domain="http://securityratty.com/tag/credit">credit</category>
      <category domain="http://securityratty.com/tag/hardware security lab">hardware security lab</category>
      <source url="http://www.lightbluetouchpaper.org/2008/10/17/nick-clegg-visits/">Liberal Democrat leader visits our lab</source>
    </item>
    <item>
      <title><![CDATA[EFF, ACLU slam carrier immunity law]]></title>
      <link>http://securityratty.com/article/644527098fb8a2b3f5fb0e535ccabda4</link>
      <guid>http://securityratty.com/article/644527098fb8a2b3f5fb0e535ccabda4</guid>
      <description><![CDATA[A U.S. law that allows telecom carriers to be granted immunity in some suits alleging illegal government surveillance is unconstitutional, two civil-rights groups argued late...]]></description>
      <content:encoded><![CDATA[A U.S. law that allows telecom carriers to be granted immunity in some suits alleging illegal government surveillance is unconstitutional, two civil-rights groups argued late Thursday.]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/illegal government surveillance">illegal government surveillance</category>
      <category domain="http://securityratty.com/tag/law">law</category>
      <category domain="http://securityratty.com/tag/immunity">immunity</category>
      <category domain="http://securityratty.com/tag/telecom carriers">telecom carriers</category>
      <category domain="http://securityratty.com/tag/suits">suits</category>
      <category domain="http://securityratty.com/tag/thursday">thursday</category>
      <category domain="http://securityratty.com/tag/civil-rights">civil-rights</category>
      <source url="http://www.networkworld.com/news/2008/101708-eff-aclu-slam-carrier-immunity.html?fsrc=rss-security">EFF, ACLU slam carrier immunity law</source>
    </item>
    <item>
      <title><![CDATA[Privacy groups praise bill curbing warrantless laptop searches]]></title>
      <link>http://securityratty.com/article/3e5c86703fcd723be1c09d323e7eba39</link>
      <guid>http://securityratty.com/article/3e5c86703fcd723be1c09d323e7eba39</guid>
      <description><![CDATA[Privacy and civil rights groups are welcoming legislation that proposes tough new standards for conducting searches of laptops and other electronic devices at U.S....]]></description>
      <content:encoded><![CDATA[Privacy and civil rights groups are welcoming legislation that proposes tough new standards for conducting searches of laptops and other electronic devices at U.S. borders.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d75e7e7574e820f215bcef0d3e650a14:wRVNlK0s2lTjz4UitRm7ygudfOic8tUIcj7XEGbgChJeoGiVX2W66ct33zVR4wv8zIwiRbyhc6UX'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:a0d63ce0da45e5423c2e4f7697b7f8ad:ttIl5mjn5fLoRCxRCgJncx%2Fe5OADE4893%2FmUTlJ688WbK7nHBIsBIDf0EqGo%2FHGU8Np9quPs0%2B%2FCog%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:cfad8daef69c39380f7bea6b8020bdd6:dIZwcZ5PDbTf9supUSQZhmrI3O8BdTBwHsrXaZZXR4OOTg2auGFCvncZ7Ok4Kt8DHzIPaBXfSjJtnA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:ed26b5c25cb776693b9c17c2bfec6fff:ADiL6RFEzLVYkwwzmei3DpZPb7uffvx2JVZPC94kdmmWLxIT7roOYLfAiVBPdOhSpct7DfId7xNP3w%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=b74bfde27100ef4a76987c5cd5a9973f" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=b74bfde27100ef4a76987c5cd5a9973f" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/electronic devices">electronic devices</category>
      <category domain="http://securityratty.com/tag/proposes tough">proposes tough</category>
      <category domain="http://securityratty.com/tag/civil rights">civil rights</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/laptops">laptops</category>
      <category domain="http://securityratty.com/tag/borders">borders</category>
      <category domain="http://securityratty.com/tag/standards">standards</category>
      <category domain="http://securityratty.com/tag/legislation">legislation</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=b74bfde27100ef4a76987c5cd5a9973f">Privacy groups praise bill curbing warrantless laptop searches</source>
    </item>
    <item>
      <title><![CDATA[The NSA Teams Up with the Chinese Government to Limit Internet Anonymity]]></title>
      <link>http://securityratty.com/article/503f5010550f387cf3db2d9c00072cbb</link>
      <guid>http://securityratty.com/article/503f5010550f387cf3db2d9c00072cbb</guid>
      <description><![CDATA[Definitely strange bedfellows : A United Nations agency is quietly drafting technical standards, proposed by the Chinese government, to define methods of tracing the original source of Internet...]]></description>
      <content:encoded><![CDATA[<p>Definitely <a href="http://news.cnet.com/8301-13578_3-10040152-38.html">strange bedfellows</a>:</p>

<blockquote>A United Nations agency is quietly drafting technical standards, proposed by the Chinese government, to define methods of tracing the original source of Internet communications and potentially curbing the ability of users to remain anonymous.

<p>The U.S. National Security Agency is also participating in the "IP Traceback" drafting group, named Q6/17, which is meeting next week in Geneva to work on the traceback proposal. Members of Q6/17 have declined to release key documents, and meetings are closed to the public.</p>

<p>[...]</p>

<p>A second, <a href="http://politechbot.com/docs/itu.traceback.use.cases.requirements.091108.txt">apparently leaked ITU document</a> offers surveillance and monitoring justifications that seem well-suited to repressive regimes:</p>

<blockquote>A political opponent to a government publishes articles putting the government in an unfavorable light. The government, having a law against any opposition, tries to identify the source of the negative articles but the articles having been published via a proxy server, is unable to do so protecting the anonymity of the author.</blockquote></blockquote>

<p>This is being sold as a way to go after the bad guys, but it won't help.  Here's Steve Bellovin <a href="http://www.cs.columbia.edu/~smb/blog/2008-09/2008-09-04.html">on that issue</a>:</p>

<blockquote>First, very few attacks these days use spoofed source addresses; the real IP address already tells you where the attack is coming from. Second, in case of a DDoS attack, there are too many sources; you can't do anything with the information. Third, the machine attacking you is almost certainly someone else's hacked machine and tracking them down (and getting them to clean it up) is itself time-consuming.</blockquote>

<p>TraceBack is most useful in monitoring the activities of large masses of people.  But of course, that's why the Chinese and the NSA are so interested in this proposal in the first place.</p>

<p>It's hard to figure out what the endgame is; the U.N. doesn't have the authority to impose Internet standards on anyone.  In any case, this idea is counter to the U.N. Universal Declaration of Human Rights, Article 19:  "Everyone has the right to freedom of opinion and expression; this right includes freedom to hold opinions without interference and to seek, receive and impart information and ideas through any media and regardless of frontiers."   In the U.S., it's counter to the First Amendment, which has long permitted anonymous speech.  On the other hand, basic human and constitutional rights have been jettisoned left and right in the years after 9/11; why should this be any different?</p>

<p>But when the Chinese government and the NSA get together to enhance their ability to spy on the world, you have to wonder what's gone wrong with the world.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=ROw6L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=ROw6L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=dQUlL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=dQUlL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 02:34:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/chinese government">chinese government</category>
      <category domain="http://securityratty.com/tag/chinese">chinese</category>
      <category domain="http://securityratty.com/tag/articles">articles</category>
      <category domain="http://securityratty.com/tag/negative articles">negative articles</category>
      <category domain="http://securityratty.com/tag/government publishes articles">government publishes articles</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/proposal">proposal</category>
      <category domain="http://securityratty.com/tag/original source">original source</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/the_nsa_teams_u.html">The NSA Teams Up with the Chinese Government to Limit Internet Anonymity</source>
    </item>
    <item>
      <title><![CDATA[DRM In The Cloud]]></title>
      <link>http://securityratty.com/article/417f3d7b09bf5a1e25047ab2bb4745ea</link>
      <guid>http://securityratty.com/article/417f3d7b09bf5a1e25047ab2bb4745ea</guid>
      <description><![CDATA[This is a cross-post from Securosis**I have a well publicized love-hate opinion of Digital Rights Management. DRM can solve some security problems but will fail outright if applied in other areas,...]]></description>
      <content:encoded><![CDATA[**This is a cross-post from Securosis**I have a well publicized love-hate opinion of Digital Rights Management. DRM can solve some security problems but will fail outright if applied in other areas, most notably consumer media protection. I remain an advocate...]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 03:52:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/digital rights management">digital rights management</category>
      <category domain="http://securityratty.com/tag/fail outright">fail outright</category>
      <category domain="http://securityratty.com/tag/drm">drm</category>
      <category domain="http://securityratty.com/tag/remain">remain</category>
      <category domain="http://securityratty.com/tag/solve">solve</category>
      <category domain="http://securityratty.com/tag/cross-post">cross-post</category>
      <category domain="http://securityratty.com/tag/opinion">opinion</category>
      <category domain="http://securityratty.com/tag/securosisi">securosisi</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://infocentric.typepad.com/blog/2008/09/drm-in-the-cloud.html">DRM In The Cloud</source>
    </item>
  </channel>
</rss>
