<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: sale]]></title>
    <link>http://securityratty.com/tag/sale</link>
    <description></description>
    <pubDate>Mon, 06 Oct 2008 15:01:01 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Yet Another Web Malware Exploitation Kit in the Wild]]></title>
      <link>http://securityratty.com/article/5caa05f53942f1ddb87a74f20c2c3599</link>
      <guid>http://securityratty.com/article/5caa05f53942f1ddb87a74f20c2c3599</guid>
      <description><![CDATA[With business-minded malicious attackers embracing basic marketing practices like branding, it is becoming increasingly harder, if not pointless to keep track of all XYZ-Packs currently in...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/STR4MhsqHZI/AAAAAAAACfY/EnFEn5S9XMY/s1600-h/5Qqp497mdd.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/STR4MhsqHZI/AAAAAAAACfY/EnFEn5S9XMY/s200/5Qqp497mdd.png" /></a>With business-minded malicious attackers embracing basic marketing practices like branding, it is becoming increasingly harder, if not pointless to keep track of all XYZ-Packs currently in circulation. How come? Due to their open source nature allowing modifications, claiming copyright over the modified and re-branded kit, the source code of core web malware exploitation kits continue representing the foundation source code for each and every newly released kit.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/STSLw4XodgI/AAAAAAAACfg/0WZInEH3pD4/s1600-h/gPdiZb9b7u_.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/STSLw4XodgI/AAAAAAAACfg/0WZInEH3pD4/s200/gPdiZb9b7u_.PNG" /></a>In fact, the practice is becoming so evident, that anecdotal evidence in the form of monitoring ongoing communications between sellers and buyers reveals actual attempts of intellectual property enforcement in the form of&nbsp; exchange of flames between an author of a original kit, and a newly born author who seems to have copied over 80% of his source code, changed the layout, re-branded it, added several more exploits and started pitching it as the most exclusive kit there is available in the underground marketplace.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/STSL6Yo0fFI/AAAAAAAACfo/7OQAGGmvwHg/s1600-h/9CtxtBWp6S_.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/STSL6Yo0fFI/AAAAAAAACfo/7OQAGGmvwHg/s200/9CtxtBWp6S_.PNG" /></a>What's new about this particular kit anyway? Changed iframe and js obfuscation techniques, doesn't require MySQL to run, with several modified Adobe Acrobat and Flash exploits - all patched and publicly obtainable. This is precisely where the marketing pitch ends for the majority of malware kits released during the last quarter. <br />
<br />
As always, there are noticable exceptions to the common wisdom that time-to-underground market isn't allowing them to innovate, but thankfully, these exceptions aren't yet going mainstream. What is going to change in the upcoming 2009? Web malware exploitation kits are slowly maturing into multi-user cybercrime platforms, where traffic management coming from the SQL injected or malware embedded sites is automatically exploited with access to the infected hosts or to the traffic volume in general offered for sale under a flat rate, or on a volume basis.<br />
<br />
Converging traffic management with drive-by exploitation and offering the output for sale, all from a single web interface, is precisely what <a href="http://ddanchev.blogspot.com/2007/07/malware-embedded-sites-increasing.html">malicious economies of scale</a> is all about.<br />
<br />
<b>Related posts:</b><br />
<a href="http://blogs.zdnet.com/security/?p=2217">Cybercriminals release Christmas themed web malware exploitation kit</a><cite></cite><b></b><br />
<a href="http://ddanchev.blogspot.com/2008/11/new-web-malware-exploitation-kit-in.html">New Web Malware Exploitation Kit in the Wild</a><b></b><br />
<a href="http://ddanchev.blogspot.com/2008/11/modified-zeus-crimeware-kit-gets.html">Modified Zeus Crimeware Kit Gets a Performance Boost</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/11/zeus-crimeware-kit-gets-carding-layout.html">Zeus Crimeware Kit Gets a Carding Layout</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/web-based-malware-emphasizes-on-anti.html">Web Based Malware Emphasizes on Anti-Debugging Features</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/copycat-web-malware-exploitation-kit.html">Copycat Web Malware Exploitation Kit Comes with Disclaimer</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/web-based-malware-eradicates-rootkits.html">Web Based Malware Eradicates Rootkits and Competing Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/two-copycat-web-malware-exploitation.html">Two Copycat Web Malware Exploitation Kits in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/copycat-web-malware-exploitation-kits.html">Copycat Web Malware Exploitation Kits are Faddish</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</a> <br />
<a href="http://ddanchev.blogspot.com/2008/02/blackenergy-ddos-bot-web-based-c.html">BlackEnergy  DDoS Bot Web Based</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/new-ddos-malware-kit-in-wild.html">A  New DDoS Malware Kit in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The  Small Pack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2006/11/nuclear-grabber-toolkit.html">The  Nuclear Grabber Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">The  Apophis Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/nuclear-malware-kit.html">Nuclear  Malware Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/random-js-malware-exploitation-kit.html">The  Random JS Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher  Malware Kit Spotted in the Wild</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gqSxO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gqSxO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kPWXO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kPWXO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IWaVo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IWaVo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AQnUo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AQnUo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=z4nXO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=z4nXO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=f162O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=f162O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zFrIo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zFrIo" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/472427816" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 03:24:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kit">kit</category>
      <category domain="http://securityratty.com/tag/malware exploitation kit">malware exploitation kit</category>
      <category domain="http://securityratty.com/tag/nuclear malware kit">nuclear malware kit</category>
      <category domain="http://securityratty.com/tag/zeus crimeware kit">zeus crimeware kit</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/exclusive kit">exclusive kit</category>
      <category domain="http://securityratty.com/tag/nuclear grabber kit">nuclear grabber kit</category>
      <category domain="http://securityratty.com/tag/apophis kit">apophis kit</category>
      <category domain="http://securityratty.com/tag/ddos malware kit">ddos malware kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/472427816/yet-another-web-malware-exploitation.html">Yet Another Web Malware Exploitation Kit in the Wild</source>
    </item>
    <item>
      <title><![CDATA[Court halts sale of spyware program]]></title>
      <link>http://securityratty.com/article/a038bc36d735bfc5e31abf4f04ecc007</link>
      <guid>http://securityratty.com/article/a038bc36d735bfc5e31abf4f04ecc007</guid>
      <description><![CDATA[A federal court has ordered a software company to stop selling a program that secretly records keystrokes on a person's PC, the FTC...]]></description>
      <content:encoded><![CDATA[A federal court has ordered a software company to stop selling a program that secretly records keystrokes on a person's PC, the FTC said.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:401c7c769a7cf79464aa911c7e53b448:nlH%2BiI%2BsbRLT8flF7JQqsRLhVqV4yAcv%2FLP2nJG1%2Ffjc5TWH8iCGs%2BTrJlKlVbtRavCIHbZ5i8as'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:7de49897a2a14d38c5e0f82e50c1bfde:W0X7zkrmXzQlAbwg0YTksjLHU1w6ge1iuwOz2priQaSuABTz7sT5MrhHUqVpSz%2BVGeYA2CiDDKR9UQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:562ec24cd257bb6533bdcf768c60d31c:LiigMEwR%2FcFCozKMCUvf9vEN6IGnH4nDsdqOjniNh7OiQlLQeG2HILHyaiWARDF9D1EIaUVUn9y%2FIg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:5f72d15a6affed91a2169ddcb18f10ad:O1JkqUZr%2B9tMnEKeltNa2gaLQgy8fnoffHbdkjvOS7cxKt9p1LImXIply0S%2BV314q3IUGltL2tH%2Bow%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=9dfb7b4e85fdb33a37b82950bd931bb0" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=9dfb7b4e85fdb33a37b82950bd931bb0" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/secretly records keystrokes">secretly records keystrokes</category>
      <category domain="http://securityratty.com/tag/software company">software company</category>
      <category domain="http://securityratty.com/tag/federal court">federal court</category>
      <category domain="http://securityratty.com/tag/program">program</category>
      <category domain="http://securityratty.com/tag/stop">stop</category>
      <category domain="http://securityratty.com/tag/person">person</category>
      <category domain="http://securityratty.com/tag/ftc">ftc</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=9dfb7b4e85fdb33a37b82950bd931bb0">Court halts sale of spyware program</source>
    </item>
    <item>
      <title><![CDATA[U.S. court halts sale of spyware program]]></title>
      <link>http://securityratty.com/article/7d515ef2ca6d58df07926d5c3635ff09</link>
      <guid>http://securityratty.com/article/7d515ef2ca6d58df07926d5c3635ff09</guid>
      <description><![CDATA[A U.S. court has ordered a software company to stop selling a program that secretly records keystrokes on a person's PC, the U.S. Federal Trade Commission said...]]></description>
      <content:encoded><![CDATA[A U.S. court has ordered a software company to stop selling a program that secretly records keystrokes on a person's PC, the U.S. Federal Trade Commission said Monday.]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/secretly records keystrokes">secretly records keystrokes</category>
      <category domain="http://securityratty.com/tag/federal trade commission">federal trade commission</category>
      <category domain="http://securityratty.com/tag/court">court</category>
      <category domain="http://securityratty.com/tag/software company">software company</category>
      <category domain="http://securityratty.com/tag/program">program</category>
      <category domain="http://securityratty.com/tag/stop">stop</category>
      <category domain="http://securityratty.com/tag/person">person</category>
      <category domain="http://securityratty.com/tag/monday">monday</category>
      <source url="http://www.networkworld.com/news/2008/111808-us-court-halts-sale-of.html?fsrc=rss-security">U.S. court halts sale of spyware program</source>
    </item>
    <item>
      <title><![CDATA[BlackBerry Storm goes on sale from Verizon on Nov. 21]]></title>
      <link>http://securityratty.com/article/2e92475549702063fd3444accdb36a3f</link>
      <guid>http://securityratty.com/article/2e92475549702063fd3444accdb36a3f</guid>
      <description><![CDATA[Verizon Wireless said the BlackBerry Storm smart phone will go on sale Nov. 21 for $200 after a $50 mail-in...]]></description>
      <content:encoded><![CDATA[Verizon Wireless said the BlackBerry Storm smart phone will go on sale Nov. 21 for $200 after a $50 mail-in rebate.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c63acc180c4799ae35dad7445d9627bd:CA56kc1aBzWeV3BhswKFh2OQTXsqZuJvUTqizc79WONr5Yl7Y%2BMMSkvApO5HztYVRrGZ4GN3xQqF'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:fe3419f24082d19fdf43cb8d61216f01:uzHdLBG0WCoV6TwOPaK78KInq%2BlijKwwl9BIgZ6gR3qV%2FjQ8dqriYBrUsIa0aHnL6j36CyfVGQaJFg%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d69cc0a1e0a17938815aa2f181dc7f8f:QphyUaYAyULVKfNC4T6eqREkY3y93VyTE93TYvbIlDutgDn6yLwg5T6vplts8pP0OGSZmLGpSOVOaw%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:1bafcf65fc88bbbaa1fe22f5c00564ff:BhQpS9kkflJ9rwQtl%2F12Idj42hEZM8UcAkPwZ%2BtnFCILO2X9lOJKN%2FcTJXbaEwGlVoAzKFpkw4MG0Q%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=5533c2b867dde1c4408108a71e051258" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=5533c2b867dde1c4408108a71e051258" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/verizon wireless">verizon wireless</category>
      <category domain="http://securityratty.com/tag/sale nov">sale nov</category>
      <category domain="http://securityratty.com/tag/mail-in">mail-in</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=5533c2b867dde1c4408108a71e051258">BlackBerry Storm goes on sale from Verizon on Nov. 21</source>
    </item>
    <item>
      <title><![CDATA[More Compromised Portfolios of Legitimate Domains for Sale]]></title>
      <link>http://securityratty.com/article/bcff82f1aa67decaa815360ef91ed3a7</link>
      <guid>http://securityratty.com/article/bcff82f1aa67decaa815360ef91ed3a7</guid>
      <description><![CDATA[The ongoing supply of access to compromised portfolios consisting of hundreds, sometimes thousands of legitimate domains , is continuing to produce anecdotal situations. For instance, in one of the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SRrfVTQpfpI/AAAAAAAACbs/Z4srmR_Btfo/s1600-h/compromised_legitimate_domains_1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SRrfVTQpfpI/AAAAAAAACbs/Z4srmR_Btfo/s200/compromised_legitimate_domains_1.jpg" /></a>The <a href="http://ddanchev.blogspot.com/2008/08/compromised-cpanel-accounts-for-sale.html">ongoing supply</a> of access to <a href="http://ddanchev.blogspot.com/2008/09/adult-network-of-1448-domains.html">compromised portfolios</a> consisting of hundreds, sometimes <a href="http://ddanchev.blogspot.com/2008/10/compromised-portfolios-of-legitimate.html">thousands of legitimate domains</a>, is continuing to produce anecdotal situations. For instance, in one of the latest propositions, a cybercriminal has managed to hijack the blackhat SEO domains portfolio (<b>8,145 domains</b> plus another <b>100</b> legitimate ones) of another cybercriminal, and is now offering it for sale.<br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRsV6pzC25I/AAAAAAAACcE/ozrXIODHSMM/s1600-h/compromised_legitimate_domains_2.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRsV6pzC25I/AAAAAAAACcE/ozrXIODHSMM/s200/compromised_legitimate_domains_2.jpg" /></a>From an attacker's perspective, are remotely exploitable SQL injections, the insecure hosting provider's web interfaces, or the pragmatic possibility for data mining a botnet's accounting data for access to such portfolios the tactic of choice? In both of these propositions, the seller is citing vulnerabilities within the web hosting providers as an attack tactic.<br />
<br />
The continues supply of such access is, however, a great indicator for the upcoming development of this segment within the underground marketplace in 2009.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XaEgN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XaEgN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rzZlN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rzZlN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=lHrIn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=lHrIn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5aJJn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5aJJn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UcM0N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UcM0N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8SsqN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8SsqN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MALln"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MALln" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/451176516" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 13:19:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/portfolios">portfolios</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/produce anecdotal situations">produce anecdotal situations</category>
      <category domain="http://securityratty.com/tag/continues supply">continues supply</category>
      <category domain="http://securityratty.com/tag/web interfaces">web interfaces</category>
      <category domain="http://securityratty.com/tag/supply">supply</category>
      <category domain="http://securityratty.com/tag/attack tactic">attack tactic</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/451176516/more-compromised-portfolios-of.html">More Compromised Portfolios of Legitimate Domains for Sale</source>
    </item>
    <item>
      <title><![CDATA[Security at the point of sale]]></title>
      <link>http://securityratty.com/article/700176f504c9a4d12ae76cbeaa5283c9</link>
      <guid>http://securityratty.com/article/700176f504c9a4d12ae76cbeaa5283c9</guid>
      <description><![CDATA[Retailers often find themselves facing sophisticated networks of thieves intent on spoofing point-of-sale...]]></description>
      <content:encoded><![CDATA[Retailers often find themselves facing sophisticated networks of thieves intent on spoofing point-of-sale systems.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:eb5eacf56f4ed0740be42d8ebb5c1d70:OBvvu8djjs6SoKnCZIZ37aRPyDFLcXX6PdpxkGyM3NKk72GfCGGR3vNRBZSiSUAjNrNRprJOcO%2Bn'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c3ca818412586b17db4f3e2fa4a42953:6l7WE%2F1bXKw%2BngkV1lGYVxc1oYF4iWEJpKuQWvIMrq7jFHg7dl9Ew2DOYx5FHuRuPmhYdRr9nBN3FQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:011e1e11a556840a518f92dd23788356:SbSoSEgZV0K%2FtrXlZqCfIZhmo0k4sijDANUxlToB9uAsRVBa5I7lyj1ELjlyBDSQ1s%2FKj%2FoOWBPSVA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:9894b46c0d8dd44484d18c42b183a780:JyqEOrOXEkekoEbQ6KvPfpMNRXU3oK74z3zPsisUeNxsdIhNlrGJzPOC8GHsqP08FlZ2A2%2Fmk2bBAA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=37ad9fc371590cd8280f7fee19eef457" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=37ad9fc371590cd8280f7fee19eef457" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Tue, 04 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/point-of-sale systems">point-of-sale systems</category>
      <category domain="http://securityratty.com/tag/thieves intent">thieves intent</category>
      <category domain="http://securityratty.com/tag/retailers">retailers</category>
      <category domain="http://securityratty.com/tag/networks">networks</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=37ad9fc371590cd8280f7fee19eef457">Security at the point of sale</source>
    </item>
    <item>
      <title><![CDATA[Security at the Point of Sale]]></title>
      <link>http://securityratty.com/article/a9296c05396f4536fb1f3474ddb874e2</link>
      <guid>http://securityratty.com/article/a9296c05396f4536fb1f3474ddb874e2</guid>
      <description><![CDATA[When thieves stole the PIN pads at a cash register in one of his company's stores, Daniel Marcotte was amazed. Not that they'd done it--such thefts can happen once a week during the holiday season....]]></description>
      <content:encoded><![CDATA[When thieves stole the PIN pads at a cash register in one of his company's stores, Daniel Marcotte was amazed. Not that they'd done it--such thefts can happen once a week during the holiday season. But watching it on videotape later, "I couldn't tell they had it with them when they left" the store, says Marcotte, director of systems and data security at La Senza, a Montreal retailer now owned by The Limited.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=62846?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=62846?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Sun, 02 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/marcotte">marcotte</category>
      <category domain="http://securityratty.com/tag/daniel marcotte">daniel marcotte</category>
      <category domain="http://securityratty.com/tag/data security">data security</category>
      <category domain="http://securityratty.com/tag/montreal retailer">montreal retailer</category>
      <category domain="http://securityratty.com/tag/pin pads">pin pads</category>
      <category domain="http://securityratty.com/tag/holiday season">holiday season</category>
      <category domain="http://securityratty.com/tag/cash register">cash register</category>
      <category domain="http://securityratty.com/tag/thefts">thefts</category>
      <category domain="http://securityratty.com/tag/director">director</category>
      <source url="http://www.networkworld.com/news/2008/110308-security-at-the-point-of.html?fsrc=rss-security">Security at the Point of Sale</source>
    </item>
    <item>
      <title><![CDATA[Compromised Portfolios of Legitimate Domains for Sale]]></title>
      <link>http://securityratty.com/article/5b1e0d15dd199fd7476dbd877e605255</link>
      <guid>http://securityratty.com/article/5b1e0d15dd199fd7476dbd877e605255</guid>
      <description><![CDATA[Is the demand for access to compromised legitimate portfolios of domains -- where the price is based on the pagerank and is shaped by the number of domains in question -- the main growth factor for...]]></description>
      <content:encoded><![CDATA[<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQHOMySS3JI/AAAAAAAACWQ/Hs8QGER1I60/s1600-h/compromised_web_hosting_portfolio.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img alt="" border="0" id="BLOGGER_PHOTO_ID_5260712558797708434" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQHOMySS3JI/AAAAAAAACWQ/Hs8QGER1I60/s200/compromised_web_hosting_portfolio.jpg" style="cursor: pointer; float: left; height: 103px; margin: 0pt 10px 10px 0pt; width: 200px;" /></a>Is the demand for access to <a href="http://ddanchev.blogspot.com/2008/08/compromised-cpanel-accounts-for-sale.html">compromised legitimate portfolios of domains</a> -- where the price is based on the pagerank and is shaped by the number of domains in question -- the main growth factor for the increasing supply of such stolen accounting data, or is it the result of cybercriminals data mining their botnets for accounting data that would provide them with access to such <a href="http://ddanchev.blogspot.com/2008/09/adult-network-of-1448-domains.html">portfolios of high trafficked domains with clean reputation</a>? Moreover, would such a data mining approach made easily possible due to the availability of botnet parsing services and stolen accounting data dumps streaming directly from a botnet, would in fact be the more efficient approach in injecting their malicious presence on as many hosts as possible, next to the plain simple <a href="http://ddanchev.blogspot.com/2008/10/massive-sql-injection-attacks-chinese.html">massive SQL injection approach</a>?<br />
<br />
As always, it's a matter of who you're dealing with, and their understanding of the exclusiveness of a particular underground item at a given period of time. This exclusiveness is inevitably going to increase due to the fact that they're several "vendors" that are already purchasing access to such portfolios, as well as compromised Cpanel accounts as a core business, the access to which they would later on either resell at a higher price enjoying the underground market's lack of transparency, or directly monetize and break-even immediatelly. As for this particular proposition for an account with 404 domains in it, it's interesting to monitor how the seller is soliciting bids from multiple sources by leaving the price an open topic, clearly indicating his low profile into the underground ecosystem. How come? An experienced seller or buyer would be offering or requesting page rank verification respectively.<br />
<br />
With nearly each and every aspect of cybercrime already available as a service, or literally outsourced as a process to those supposidely excelling into a particular practice, building capabilities for data mining botnets is no longer a requirement, with the people behind the botnets monetizing all the data coming from it by soliciting deals of accounting data dumps based on a particular country only.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KaXaM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KaXaM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5JUrM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5JUrM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iASQm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iASQm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=H5nPm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=H5nPm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OsSgM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OsSgM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WgfUM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WgfUM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=o6U7m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=o6U7m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/430818024" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 24 Oct 2008 06:24:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data dumps based">data dumps based</category>
      <category domain="http://securityratty.com/tag/data dumps">data dumps</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/cybercriminals data">cybercriminals data</category>
      <category domain="http://securityratty.com/tag/portfolios">portfolios</category>
      <category domain="http://securityratty.com/tag/based">based</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/botnets">botnets</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/430818024/compromised-portfolios-of-legitimate.html">Compromised Portfolios of Legitimate Domains for Sale</source>
    </item>
    <item>
      <title><![CDATA[BlackBerry Bold to hit stores Nov. 4]]></title>
      <link>http://securityratty.com/article/f9cd64dc4579f83ebb0cbc097a267d3d</link>
      <guid>http://securityratty.com/article/f9cd64dc4579f83ebb0cbc097a267d3d</guid>
      <description><![CDATA[AT&amp;T said its BlackBerry Bold smart phone will go on sale Nov. 4 starting at $299.99 with a two-year...]]></description>
      <content:encoded><![CDATA[AT&T said its BlackBerry Bold smart phone will go on sale Nov. 4 starting at $299.99 with a two-year contract.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:68ca718f89a17ca27ebfe593a0c6964a:Tut5HcZtAbdNb37LatgR1a8EG3xa0dOlcYo0mxR7Q%2B5AzggWVBoeiX4%2BY%2BKIjoh4pole7qF2Qj%2B3'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:b97b780df52bfceae97aaa05c60dfeb9:5u3G%2F9p8tyEp2ajOqGKp7eaOTJaEoSwr%2FwgtwHxR7WXVCKddtHNvBddNgzW4b3FxlKxgNg0sCum5VQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:baed12f72301e148b52b74c0455c6250:tHCge6nI%2FRsAd8A%2BFwy04f6h1GDDB0x%2BP1TzG1%2BYzbH2GTAQ6t%2F%2Fmq503an1OIG%2FSB3e9sDbfVxS0w%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:b414a8d578f7b34b78109149d60b8da4:oYt3%2B1uxfVs%2FMD4g6xiHh9NLtA7vja7bQ8d0esF8V0S8dEBnqoB88YjjElBWDZCBIyqI2Ymld9LBAQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=221483161b73bc8c7c584070bcdee0a2" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=221483161b73bc8c7c584070bcdee0a2" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 22 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sale nov">sale nov</category>
      <category domain="http://securityratty.com/tag/two-year contract">two-year contract</category>
      <category domain="http://securityratty.com/tag/att">att</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=221483161b73bc8c7c584070bcdee0a2">BlackBerry Bold to hit stores Nov. 4</source>
    </item>
    <item>
      <title><![CDATA[Fake Windows XP Activation Trojan Wants Your CVV2 Code]]></title>
      <link>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</link>
      <guid>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</guid>
      <description><![CDATA[In a self-contradicting social engineering attempt, a malware author is offering to sale a ( updated version of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/YNDy4vo817c/s1600-h/fake_windows_xp_activation1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/BYpcW4rkU0o/s200-R/fake_windows_xp_activation1.png" /></a>In a self-contradicting social engineering attempt, a malware author is offering to sale a (<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-042705-0108-99">updated version</a> of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it claims "<i>We will ask for your billing details, but your credit card will NOT be charged</i>", is requesting and remotely uploading all the credit card details required for a successfully credit card theft.<br />
<br />
Perhaps among the main reasons why such simplistic social engineering attempts never scaled in a "malicious economies of scale" approach, is because sophisticated crimeware kits capable of obtaining the very same data automatically, started leaking for everyone to start taking advantage of - including yesterday's cybercriminals using such DIY fake message builders. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div>Moreover, according to <a href="http://news.ncsu.edu/news/2008/09/wmswogalterfakemessage.php">recently reseased survey results</a>, end users cannot distinguish between fake popups and real ones, and on their way to continue doing what they were doing, click OK on that pesky warning message telling them that they're about to get infected with malware. Taking into consideration the fact that the popup windows the researchers used look like cheap creative compared to the average fake security software's layout high quality GUIs, it is perhaps worth restating your research questions with something in the lines of - <b>What motivates end users to install an antivirus application going under the name of Super Antivirus 2009 or Mega Virus Cleaner 2008?</b> The fact that the fake status bar is telling them that they're infected with 47 spyware cookies, or the fact that they ended up at the fake site while browsing their trusted web services? <br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/6uvXj2AuS_A/s1600-h/fake_windows_xp_activation2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/fa1jUBjFGOU/s200-R/fake_windows_xp_activation2.png" /></a>The increase of <a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">rogue security software domains</a> is happening due to the high payout affiliation based model, the standardized creative allowing the participants to come up with their own fake names if they want to, and due to the fact that the fake security threats scareware approach seems to be perfectly taking advantage of the overall suspicion on the effectiveness of their legitimate security software.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mw30M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mw30M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WJFzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WJFzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jNfpm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jNfpm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9lodm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9lodm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6go3M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6go3M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TLsPM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TLsPM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JuYBm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JuYBm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413264124" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 15:01:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/credit card details">credit card details</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/credit card theft">credit card theft</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware author">malware author</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <category domain="http://securityratty.com/tag/mega virus cleaner">mega virus cleaner</category>
      <category domain="http://securityratty.com/tag/creative">creative</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413264124/fake-windows-xp-activation-trojan-wants.html">Fake Windows XP Activation Trojan Wants Your CVV2 Code</source>
    </item>
  </channel>
</rss>
