<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: service]]></title>
    <link>http://securityratty.com/tag/service</link>
    <description></description>
    <pubDate>Thu, 02 Oct 2008 08:39:01 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Is Google Using Chrome to Index Password Protected Web?]]></title>
      <link>http://securityratty.com/article/8a63a597e63a81e80a36c5703b5f3e7a</link>
      <guid>http://securityratty.com/article/8a63a597e63a81e80a36c5703b5f3e7a</guid>
      <description><![CDATA[An interesting theory we heard recently is that Google will use Chrome to index the password protected Web. Right now the Chrome Terms of Service prevents Google from indexing private data. But when...]]></description>
      <content:encoded><![CDATA[An interesting theory we heard recently is that Google will use Chrome to index the password protected Web. Right now the Chrome Terms of Service prevents Google from indexing private data. But when you consider that Chrome was initially presented as a browser for applications, instead of just web pages, this theory begins to make more sense.]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 07:20:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/chrome">chrome</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/service prevents google">service prevents google</category>
      <category domain="http://securityratty.com/tag/chrome terms">chrome terms</category>
      <category domain="http://securityratty.com/tag/theory">theory</category>
      <category domain="http://securityratty.com/tag/theory begins">theory begins</category>
      <category domain="http://securityratty.com/tag/web pages">web pages</category>
      <category domain="http://securityratty.com/tag/index">index</category>
      <source url="http://digg.com/security/Is_Google_Using_Chrome_to_Index_Password_Protected_Web">Is Google Using Chrome to Index Password Protected Web?</source>
    </item>
    <item>
      <title><![CDATA[TriCipher launches hosted identity federation service]]></title>
      <link>http://securityratty.com/article/32106da905a4d380d6b3bebff87edb37</link>
      <guid>http://securityratty.com/article/32106da905a4d380d6b3bebff87edb37</guid>
      <description><![CDATA[Identity management vendor TriCipher this week rolled out a hosted service that lets companies pass-on the complexity of sharing identities with...]]></description>
      <content:encoded><![CDATA[Identity management vendor TriCipher this week rolled out a hosted service that lets companies pass-on the complexity of sharing identities with partners.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:1795cc1b118603b4392c56de05b1756c:CpmAFRiKdku59qwTT2mLecFHHYae4OSNZNJd%2FvdgDxVHwnTWsXRv%2BNQZ%2BVUAFygwoTcDLqeFc00N'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:73a0e803ed6f4495d0298129380808f4:5f7vNBhZci07zlSIy8mnl0VBlD4GokVT3k0flS0OIpf7q2gd%2B6lfY5eWDA%2BHD9W5A4SVPLuztK0DYw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:5ac30fe43447e75f88e341d00c992a9d:nrv2dzxe9WdRtEsUAfMrqVc66Il84ZZ88Bd2YeIqFQOvLlG6S5hc%2FZ8FX5DIvP5W%2FhWH%2FBa74HkdnA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:3b915af431918cca61a0c7ade9d45bb9:L21Se927huCUrJGUhUX0UqKyalSW6D%2BECaJPgC4YvlIR4qlVC33mFNtgJKQWDUZo1oIbyms4%2FQkwVQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/click.phdo?s=a47ba9880b31bb330d4899ceca328588"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=a47ba9880b31bb330d4899ceca328588"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=a47ba9880b31bb330d4899ceca328588" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/companies pass-on">companies pass-on</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/complexity">complexity</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/identities">identities</category>
      <category domain="http://securityratty.com/tag/partners">partners</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=a47ba9880b31bb330d4899ceca328588">TriCipher launches hosted identity federation service</source>
    </item>
    <item>
      <title><![CDATA[Hackers Use Neosploit To Infect Around 80,000 Sites, Including BBC And US Postal Service]]></title>
      <link>http://securityratty.com/article/186b56f8545276fcbddd00f834c8f8ee</link>
      <guid>http://securityratty.com/article/186b56f8545276fcbddd00f834c8f8ee</guid>
      <description><![CDATA[According to Ian Amit, director of security research at Aladdin Knowledge Systems, cybercriminals have used the latest version of Neosploit to booby-trap an estimated 80,000 legitimate sites with...]]></description>
      <content:encoded><![CDATA[According to Ian Amit, director of security research at Aladdin Knowledge Systems, cybercriminals have used the latest version of Neosploit to booby-trap an estimated 80,000 legitimate sites with malicious code. Victims of the attack include government, Fortune 500, and a weapons manufacturing firm. Victims of the attack also included the US Postal Service, which has [...]]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 17:39:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attack include government">attack include government</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/postal service">postal service</category>
      <category domain="http://securityratty.com/tag/aladdin knowledge systems">aladdin knowledge systems</category>
      <category domain="http://securityratty.com/tag/neosploit">neosploit</category>
      <category domain="http://securityratty.com/tag/victims">victims</category>
      <category domain="http://securityratty.com/tag/malicious code">malicious code</category>
      <category domain="http://securityratty.com/tag/security research">security research</category>
      <category domain="http://securityratty.com/tag/ian amit">ian amit</category>
      <source url="http://cyberinsecure.com/hackers-use-neosploit-to-infect-around-80000-sites-including-bbc-and-us-postal-service/">Hackers Use Neosploit To Infect Around 80,000 Sites, Including BBC And US Postal Service</source>
    </item>
    <item>
      <title><![CDATA[Inside a Managed Spam Service]]></title>
      <link>http://securityratty.com/article/6ce6bddf4ee3d480d2e75b538f882e90</link>
      <guid>http://securityratty.com/article/6ce6bddf4ee3d480d2e75b538f882e90</guid>
      <description><![CDATA[A managed spam vendor always has to raise the stakes during its introduction period on the market. But what happens when a market follower starts using the market leader's proprietary managed spamming...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOTsz3SyMdI/AAAAAAAACPI/w97lHPkkz7o/s1600-h/managed_spamming_service_2008.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOTsz3SyMdI/AAAAAAAACPI/iBd96sIzD2o/s200-R/managed_spamming_service_2008.jpg" /></a>A <a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">managed spam vendor</a> always has to raise the stakes during its introduction period on the market. But what happens when a market follower starts using the market leader's proprietary <a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">managed spamming system</a>, and is able to provide better spamming rates at a cheaper prices?&nbsp; Market forces and unethical competition at its best.<br />
<br />
So, what is this market challenger using the monopolist's -- in respect to managed spamming services not spam in general -- proprietary system (<a href="http://blogs.zdnet.com/security/?p=1899">Spamming vendor launches managed spamming service</a>) up to anyway? Promising and delivering, 1, 400,000 emails daily, 60,000 mails per hour, and 100 emails per minute. What we've got here are the spam metrics out of 5 already finished spam campaigns that has managed to sent out a million spam emails using only 2000 malware infected hosts. Also, CC-ing and BCC-ing made it possible to multiple the effect of the campaign and increase the total number of emails spammed. Talking about benchmarks, 789 emails per minute at a rate of 12/13 emails per second is a pretty good one, considering it's only 2k bots that they were using. What they also promise is automatic rotation of IPs upon automatically checking them against public blacklists, and a mix rotation of IPs from their own netblocks located in Russia and Germany with the fresh IPs coming from the newly infected hosts.<br />
<br />
Earlier this month, I discussed the market leader's <a href="http://blogs.zdnet.com/security/?p=1899">managed spamming system</a>, access to which they also offer for rent :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SORDqN1mkHI/AAAAAAAACPA/nSP61RrjgSg/s1600-h/spamming_appliance_stats.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SORDqN1mkHI/AAAAAAAACPA/0eV8S8Gv3NA/s200-R/spamming_appliance_stats.jpg" /></a>"<i>An inside look of the system obtained on 2008-08-12 indicates that they are indeed capable of delivering what they promise - speed, simplicity and 5000 malware infected hosts. Moreover, the attached screenshot demonstrates that 20 different email databases can be simultaneously used resulting in 16,523,247 emails about to get spammed using 52 different macroses. Furthermore, what they refer to as a dynamic set of regional servers aiming to ensure that the central server never gets exposed, is in fact fast-flux which depending on how many bots they are willing to put into “rtsegional server mode” shapes the size of the fast-flux network at a later stage.</i>"<br />
<br />
With cutting edge managed spam services like the ones currently in circulation, it remains to be seen whether or not spammers would migrate to this outsourcing model, or continue coming up with adaptive ways to send out their scams and malware on their own.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1n6HM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1n6HM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=69CPM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=69CPM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JSXmm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JSXmm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UqH8m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UqH8m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rsD3M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rsD3M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=myLSM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=myLSM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PFEmm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PFEmm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/410205990" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 07:20:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/spam services">spam services</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/market follower starts">market follower starts</category>
      <category domain="http://securityratty.com/tag/emails daily">emails daily</category>
      <category domain="http://securityratty.com/tag/emails">emails</category>
      <category domain="http://securityratty.com/tag/spam campaigns">spam campaigns</category>
      <category domain="http://securityratty.com/tag/million spam emails">million spam emails</category>
      <category domain="http://securityratty.com/tag/market challenger">market challenger</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/410205990/inside-managed-spam-service.html">Inside a Managed Spam Service</source>
    </item>
    <item>
      <title><![CDATA[Grand jury indicts two Europeans over denial-of-service attacks in 2003]]></title>
      <link>http://securityratty.com/article/746ea869cb23e52f443868e7e8ddec4f</link>
      <guid>http://securityratty.com/article/746ea869cb23e52f443868e7e8ddec4f</guid>
      <description><![CDATA[A federal grand jury has indicted two European men for allegedly orchestrating denial-of-service attacks against a pair of U.S.-based Web sites in...]]></description>
      <content:encoded><![CDATA[A federal grand jury has indicted two European men for allegedly orchestrating denial-of-service attacks against a pair of U.S.-based Web sites in 2003.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:f85d136f3c383fcc0bb6cef7ba9ee9ae:TrVdwOzJ%2BXZk4RgsHL8bBLAuBfkaUILcaLXZ8ehJQ44fn%2BQjbNFzDCieyDWtMkINdsqDg31SSPMo'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:f840a05c9f30e6fe170bd39fd3551e4b:0St0BMx0VLvl2n23HvIXfVH0yoQcjfb13vo87SH%2Bnphc%2B9H6eWGb%2F%2B4PV2MQfKMh6HiEJ0Pi%2FjSA3Q%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c93e9d6076b4f6880572da02c83bb360:sKJCDqZTyQqC8oGliOwKGnETpY1aFhjcABSgwqzeEDSJSqxCNFhNhHZlmYs7raBFu3SOI4RtnB2CGQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:a7e72d9e85acd5a116649b0e399297f8:5vR%2FYBwkJYIKDzW5RVSCLx35HjlJqofFX4xGhhDsN6SCRdmapAJW%2BgnDol%2FRReeCgtOWqoUcLtcuMA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=c8ede97a6557e2e70e7f0aca3b2a2704"><img src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=c8ede97a6557e2e70e7f0aca3b2a2704" border="0" /></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=c8ede97a6557e2e70e7f0aca3b2a2704" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/federal grand jury">federal grand jury</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/pair">pair</category>
      <category domain="http://securityratty.com/tag/european">european</category>
      <category domain="http://securityratty.com/tag/allegedly">allegedly</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=c8ede97a6557e2e70e7f0aca3b2a2704">Grand jury indicts two Europeans over denial-of-service attacks in 2003</source>
    </item>
    <item>
      <title><![CDATA[Two Europeans charged in U.S. over DDoS attacks]]></title>
      <link>http://securityratty.com/article/50344ed7143e5c88fdce42097172b5ee</link>
      <guid>http://securityratty.com/article/50344ed7143e5c88fdce42097172b5ee</guid>
      <description><![CDATA[Two European men have been indicted for allegedly orchestrating cyberattacks against two Web sites, a continuation of the first successful U.S. investigation ever into distributed denial-of-service...]]></description>
      <content:encoded><![CDATA[Two European men have been indicted for allegedly orchestrating cyberattacks against two Web sites, a continuation of the first successful U.S. investigation ever into distributed denial-of-service attacks, according to the U.S. Department of Justice.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=17978?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=17978?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/cyberattacks">cyberattacks</category>
      <category domain="http://securityratty.com/tag/successful">successful</category>
      <category domain="http://securityratty.com/tag/continuation">continuation</category>
      <category domain="http://securityratty.com/tag/justice">justice</category>
      <category domain="http://securityratty.com/tag/european">european</category>
      <category domain="http://securityratty.com/tag/investigation">investigation</category>
      <source url="http://www.networkworld.com/news/2008/100308-two-europeans-charged-in-us.html?fsrc=rss-security">Two Europeans charged in U.S. over DDoS attacks</source>
    </item>
    <item>
      <title><![CDATA[Researcher finds evidence of massive site compromise]]></title>
      <link>http://securityratty.com/article/d81e4009f2c14388fee11506aa494a40</link>
      <guid>http://securityratty.com/article/d81e4009f2c14388fee11506aa494a40</guid>
      <description><![CDATA[Several criminal gangs have acquired administrative log-in credentials for more than 200,000 Web sites -- including the one used by the U.S. Postal Service -- and have used the compromised domains to...]]></description>
      <content:encoded><![CDATA[Several criminal gangs have acquired administrative log-in credentials for more than 200,000 Web sites -- including the one used by the U.S. Postal Service -- and have used the compromised domains to attack unsuspecting users' PCs with a notorious hacker exploit kit, a researcher said today.]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/administrative log-in credentials">administrative log-in credentials</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/criminal gangs">criminal gangs</category>
      <category domain="http://securityratty.com/tag/researcher">researcher</category>
      <category domain="http://securityratty.com/tag/postal service">postal service</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/pcs">pcs</category>
      <source url="http://www.networkworld.com/news/2008/100308-researcher-finds-evidence-of-massive.html?fsrc=rss-security">Researcher finds evidence of massive site compromise</source>
    </item>
    <item>
      <title><![CDATA[TriCipher launches hosted identity federation service]]></title>
      <link>http://securityratty.com/article/eb96178aedf439964c49be69bc619a8f</link>
      <guid>http://securityratty.com/article/eb96178aedf439964c49be69bc619a8f</guid>
      <description><![CDATA[Identity management vendor TriCipher this week rolled out a hosted service that lets companies pass-on the complexity of sharing identities with...]]></description>
      <content:encoded><![CDATA[Identity management vendor TriCipher this week rolled out a hosted service that lets companies pass-on the complexity of sharing identities with partners.]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/companies pass-on">companies pass-on</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/complexity">complexity</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/identities">identities</category>
      <category domain="http://securityratty.com/tag/partners">partners</category>
      <source url="http://www.networkworld.com/news/2008/100308-tricipher-identity-federation.html?fsrc=rss-security">TriCipher launches hosted identity federation service</source>
    </item>
    <item>
      <title><![CDATA[Symantec tests a 'Net watchdog for kids]]></title>
      <link>http://securityratty.com/article/51ee6b1de17bd5e6b9452e823d937185</link>
      <guid>http://securityratty.com/article/51ee6b1de17bd5e6b9452e823d937185</guid>
      <description><![CDATA[Symantec has developed a new online service to protect children from Internet...]]></description>
      <content:encoded><![CDATA[Symantec has developed a new online service to protect children from Internet dangers.]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/online service">online service</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/internet dangers">internet dangers</category>
      <category domain="http://securityratty.com/tag/protect">protect</category>
      <source url="http://www.networkworld.com/news/2008/100308-symantec-tests-a-net-watchdog.html?fsrc=rss-security">Symantec tests a 'Net watchdog for kids</source>
    </item>
    <item>
      <title><![CDATA[Managed Fast Flux Provider - Part Two]]></title>
      <link>http://securityratty.com/article/210da9c1b19bf76a539ca28b24edc989</link>
      <guid>http://securityratty.com/article/210da9c1b19bf76a539ca28b24edc989</guid>
      <description><![CDATA[We're slowly entering into a stage where RBN bullet proof hosting franchises are vertically integrating, and due to the requests from their customers are starting to offer that they refer to as...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQymgVga0I/AAAAAAAACOw/geleqRWDOE0/s1600-h/pharma_spam_fastflux.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQymgVga0I/AAAAAAAACOw/8PTQr8G6mBM/s200-R/pharma_spam_fastflux.png" /></a>We're slowly entering into a stage where <a href="http://ddanchev.blogspot.com/2008/09/estdomains-and-intercage-vs-cybercrime.html">RBN bullet proof hosting franchises</a> are vertically integrating, and due to the requests from their customers are starting to offer that they refer to as "mirrored hosting" which in practice is plain simple fast flux network consisting of RBN-alike purchased netblocks, and naturally, botnet infected hosts.<br />
<br />
Managed fast-fluxing is only starting to go mainstream, for instance, in July I found evidence that <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">money mule recruiters were using ASProx's infected hosts as hosting infrastructure</a>, and in November, 2007, <a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">an infamous spamming software vendor</a> was also found to have been offering fast-flux services in the past.<br />
<br />
In this most recent fast-flux service, we have a known spammer and botnet master that in between self-serving himself on is way to ensure his portfolio of scammy domains remains online for a "little longer", is commercializing fast-fluxing and is offered a DIY service :<br />
<br />
"<i>Finally after hardwork and great appreciation from our normal bullet proof  hosting/server clients we are able to launch Mirrored hosting. What is </i><i>Mirrored hosting</i><i> ?</i><br />
<i><br />
================<br />
</i><i>Mirrored hosting</i><i> is a powerful mirrored  web hosting management, uses multiple Virtual servers to host  website with 100% uptime. </i><i>Mirrored hosting </i><i>is a combination of two things, which  are:<br />
<br />
1. Specially Designed Virtual Servers</i><br />
<i> 2. Powerful  Automated Control Panel</i><br />
<br />
<i>How does it work ?<br />
===============&nbsp;</i><br />
<br />
<i>Mirrored hosting</i><i> uses specially configured Virtual Servers making them link with the </i><i>Mirrored hosting</i><i> Control Panel  which is then controlled by our own control panel allowing us to provide smooth  streamline hosting with no downtime. No one is able to trace original IP of the  server or the place where the files are hosted so the websites/domains hosted  have a 100% Uptime. This is achieved by unique customisation of our Virtual Servers.<br />
<br />
<b>Actually, it takes ips around the world and our  powerful control panel just rotates the ips every 15 minutes. though all these  ips you will see will be fake no one can trace the orignal ip where files are  hosted. Sometimes the ip is from China, Korea, USA, UK, Japan, Lithuania etc.</b></i>"<br />
<br />
The concept has always been there for cybercriminals to take advantage of, but once it matures into a managed service it would undoubtedly lower down the entry barriers allowing yesterday's average phishers to take advantage of what only the "pros" were used to.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AO71M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AO71M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xZIrM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xZIrM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZGgOm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZGgOm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=e7OAm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=e7OAm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BVPbM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BVPbM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iS1HM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iS1HM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iQOUm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iQOUm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/409475392" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 08:39:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/recent fast-flux service">recent fast-flux service</category>
      <category domain="http://securityratty.com/tag/powerful control panel">powerful control panel</category>
      <category domain="http://securityratty.com/tag/control panel">control panel</category>
      <category domain="http://securityratty.com/tag/virtual servers">virtual servers</category>
      <category domain="http://securityratty.com/tag/multiple virtual servers">multiple virtual servers</category>
      <category domain="http://securityratty.com/tag/fast flux spam">fast flux spam</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/409475392/managed-fast-flux-provider-part-two.html">Managed Fast Flux Provider - Part Two</source>
    </item>
  </channel>
</rss>
