<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: services]]></title>
    <link>http://securityratty.com/tag/services</link>
    <description></description>
    <pubDate>Fri, 03 Oct 2008 07:20:32 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Cybercriminals Abusing Lycos Spain To Serve Malware]]></title>
      <link>http://securityratty.com/article/fabff11bf2453e9de90b96225f66ceab</link>
      <guid>http://securityratty.com/article/fabff11bf2453e9de90b96225f66ceab</guid>
      <description><![CDATA[Spanish cybercriminals have recently started taking advantage of the bogus accounts at Lycos Spain, which they seem to be registering on their own, by releasing a do-it-yourself malicious link...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SO3K1YNzr7I/AAAAAAAACRg/Few0-Tx3rNw/s1600-h/lycos_spain_fake_video_generator2.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SO3K1YNzr7I/AAAAAAAACRg/iAII9VuZa4c/s200-R/lycos_spain_fake_video_generator2.PNG" /></a>Spanish cybercriminals have recently started taking advantage of the bogus accounts at Lycos Spain, which they seem to be registering on their own, by releasing a do-it-yourself malicious link generator redirecting to fake YouTube and Adobe Flash video pages. Whereas the concept of abusing legitimate web services for infection and propagation isn't new, what's new is the fact that <a href="http://ddanchev.blogspot.com/2008/03/embedding-malicious-iframes-through.html">the FTP access is efficiently abused</a>.&nbsp; <br />
<br />
Here's a description of the link generator : <br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SO0tM6_O7ZI/AAAAAAAACRI/nmOCnp413_4/s1600-h/lycos_spain_fake_video_generator1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SO0tM6_O7ZI/AAAAAAAACRI/eipfSy4XHQA/s200-R/lycos_spain_fake_video_generator1.png" /></a>"<i>Download the program and run it asks for an ID (identifier), then copy it and paste it there, then press' Create Installer 'and the program will create the Installer! (this program to run a simulation that is installing the Adobe Flash and indicates to our page that "has been installed Adobe Flash," in order to show the video when YouVideo refresh the page, this you must file tie it in with your server! and what flames or Installer Setup (simulating being an installer)!&nbsp; Now you need to upload that file you've joined an FTP, click Next and put the path of that file in the next step!</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SO0tdIn5AuI/AAAAAAAACRY/MxLdkIGeP-k/s1600-h/lycos_spain_fake_video_generator6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SO0tdIn5AuI/AAAAAAAACRY/Ajrlsv2pXY8/s200-R/lycos_spain_fake_video_generator6.png" /></a>Whereas the tool is exclusively relying on Lycos Spain to host the binaries and the campaign itself, the recent <a href="http://ddanchev.blogspot.com/2008/10/syndicating-google-trends-keywords-for.html">blackhat SEO campaign relying on pre-registered Windows Live Spaces and AOL Journals</a> syndicating hot Google Trends keywords, further indicates the malicious attacker's capabilities of efficiently abusing legitimate services. And with the process of <a href="http://ddanchev.blogspot.com/2008/08/exposing-indias-captcha-solving-economy.html">bogus accounts registration</a> performed automatically, or <a href="http://blogs.zdnet.com/security/?p=1835">outsourced entirely</a>, malicious services aiming to automate the abuse process are only going to get more efficient.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=k5GGM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=k5GGM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Z15BM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Z15BM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=G192m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=G192m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Moy2m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Moy2m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Dp6KM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Dp6KM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Ysa5M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Ysa5M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=S6Dhm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=S6Dhm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/415620254" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 00:28:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lycos spain">lycos spain</category>
      <category domain="http://securityratty.com/tag/installer setup">installer setup</category>
      <category domain="http://securityratty.com/tag/installer">installer</category>
      <category domain="http://securityratty.com/tag/bogus accounts">bogus accounts</category>
      <category domain="http://securityratty.com/tag/bogus accounts registration">bogus accounts registration</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/malicious services">malicious services</category>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/adobe flash">adobe flash</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/415620254/cybercriminals-abusing-lycos-spain-to.html">Cybercriminals Abusing Lycos Spain To Serve Malware</source>
    </item>
    <item>
      <title><![CDATA[Managed security services: Outsourcing threat management]]></title>
      <link>http://securityratty.com/article/0bc9ade236ccca33fbf3894e7e867ff3</link>
      <guid>http://securityratty.com/article/0bc9ade236ccca33fbf3894e7e867ff3</guid>
      <description><![CDATA[As prices fall, managed security services from such companies as SecureWorks and Perimeter eSecurity entice enterprises looking to offload the tedious work of monitoring intrusion-detection,...]]></description>
      <content:encoded><![CDATA[As prices fall, managed security services from such companies as SecureWorks and Perimeter eSecurity entice enterprises looking to offload the tedious work of monitoring intrusion-detection, intrusion-prevention and other security systems.]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security services">security services</category>
      <category domain="http://securityratty.com/tag/security systems">security systems</category>
      <category domain="http://securityratty.com/tag/secureworks">secureworks</category>
      <category domain="http://securityratty.com/tag/tedious">tedious</category>
      <category domain="http://securityratty.com/tag/offload">offload</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/prices">prices</category>
      <source url="http://www.networkworld.com/supp/2008//100908-trendwatch-mssp.html?fsrc=rss-security">Managed security services: Outsourcing threat management</source>
    </item>
    <item>
      <title><![CDATA[MSP Snapshot Monitoring with EM7]]></title>
      <link>http://securityratty.com/article/5288692e82e0f23665e5086e43db9ed4</link>
      <guid>http://securityratty.com/article/5288692e82e0f23665e5086e43db9ed4</guid>
      <description><![CDATA[Between the fifth anniversary for ScienceLogic and the Inc 500 milestone, weve become very nostalgic about the beginnings of the company and EM7. For instance, did you know that EM7 was originally...]]></description>
      <content:encoded><![CDATA[<p>Between the <a href="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008" target="_blank">fifth anniversary for ScienceLogic</a> and the Inc 500 milestone, we’ve become very nostalgic about the beginnings of the company and EM7. For instance, did you know that EM7 was originally designed with managed service providers in mind? Not so surprising when 5 of the first 6 employees (including all 3 founders) came from hosting and MSP backgrounds and had first-hand experience with the daily trials and tribulations of MSP operations – and the tools that didn’t quite work for them.
<p><a href="http://blog.sciencelogic.com/wp-content/uploads/2008/10/john-at-interop-vegas.jpg"><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="184" alt="John at Interop Vegas" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/john-at-interop-vegas-thumb.jpg" width="244" align="left" border="0"></a>Here we talk to John Proctor, who started out as one of our first customers (and the first MSP customer). And he believed in it so much, he eventually became part of the ScienceLogic team. (Remember &#8220;I&#8217;m not only the President, I&#8217;m also a client&#8221; from <a href="http://www.hairclub.com/inthenews_article1.php" target="_blank">the Hair Club for Men</a>?)
<p>John shares his perspectives about the service provider world and why he took a chance on a little-known product called EM7.
<p><strong>ScienceLogic:</strong> What is your background? How many years have you worked as a service provider and for what types of companies?
<p><strong>John Proctor:</strong> I have been working with Service providers for over twelve years. I worked at a major regional service provider for six years and before that I designed and built national and international networks for ISP’s and Fortune 500 companies as a consultant for PriceWaterhouseCoopers and WorldComm.
<p><strong>ScienceLogic:</strong> You were one of the first customers of EM7 – why did you choose it and how did you get over the hurdles associated with using a start-up company’s product?
<p><strong>John Proctor:</strong> We were actually customer number five. Back in 2004 when we evaluated and purchased EM7 we could see that EM7 provided about 80% of what we were looking for in one integrated solution right out of the box. One of the things that sold us on EM7 was that the ScienceLogic founders had all previously worked for a service provider, so we knew they understood our business and our challenges. But in the end, it comes down to features. Once we compared EM7 functionality to the alternatives, it was clearly a “no brainer.”
<p><strong>ScienceLogic:</strong> What other alternatives were being considered?
<p><strong>John Proctor:</strong> Well, we had started with a few point solutions, but as our business and product offerings matured, this resulted in a growing number of point solutions. What started with 3 or 4 ended up as 14 separate tools. They all had strengths but what they didn’t have was integration and because of this they could not scale. And, if the tools could not scale, our business could not grow.
<p>So, naturally we started looking at framework solutions, but they are expensive to buy, expensive to implement, and expensive to maintain. At one point, we even considered some open source projects. There were several that showed promise, but we would still be stuck with tools that were not integrated. So then we considered hiring developers to cobble something together that would work for our business. The only problem with this alternative was that we felt it would take 6 to 8 months before we could have something viable to work with.
<p><strong>ScienceLogic:</strong> What products were you using before EM7? What were your goals?
<p><strong>John Proctor:</strong> Before we purchased EM7 we used 14 different point solutions to deliver our products and services to the marketplace. Tools like NetCool, Openview, Argent, Heat, What’s Up Gold as well as several other point solutions, vendor specific applications and manually updated spreadsheets. And, as I mentioned before, this does not scale. This also adds a great deal of complexity when you begin to consider business continuity and disaster recovery. All these tools were vital to the delivery of our products and services. Any service provider will tell you it is all about uptime. So if the product is uptime, the tools used to deliver it have to be available 24&#215;7x365.
<p>Our goals were simple: scale and redundancy. As it turns out, the solution was simple as well. EM7 provided a tool that could replace the functionality of almost half of the existing point solutions and the applications that could not be replaced were integrated with EM7 to provide our staff with a “single pane of glass” to see the status and performance of each area of the business from one application. We had visibility into everything from facility systems to applications using EM7.
<p>ScienceLogic also delivers an extensible configuration that addressed uptime and redundancy. We deployed collectors throughout our network that reported back to a central pair of redundant database servers and with this configuration we were able to perform backups and add capacity without taking the system down.
<p><strong>ScienceLogic:</strong> Why are service providers different from enterprises? How are their needs different?
<p><strong>John Proctor:</strong> First and foremost, service providers face the same challenges that only the largest enterprises ever face and they also have many unique challenges that only service providers experience.
<p>One challenge we faced was that we had multiple datacenters in different states. They were all interconnected with plenty of bandwidth between each site, but the tools were not designed to be used across the WAN. Our staff in our remote data center did not have the same access as our staff in the corporate office. Since EM7 is web-based, it immediately eliminated this problem.
<p>Another challenge is that service providers must manage systems across multiple domains. Back in the early version of a specific tool we were using before EM7, the only way you could implement it across multiple domains was to put the same username and password on every computer that you monitored. Beyond the security concerns, maintenance was a nightmare. Anytime we had to change the password, we would get locked out of dozens upon dozens of systems. When the password was changed on the monitoring server, it would attempt to login to the remote machines and fail. Repeated attempts would result in the account getting locked. I think that vendor eventually addressed this issue, but service providers seldom find tools that were designed for their unique situations.
<p><strong>ScienceLogic:</strong> How is EM7 geared to service providers?
<p><strong>John Proctor:</strong> Enterprise IT is a trusted part of the business; they are one of the team. Service providers are outsiders that must earn trust by showing the customer exactly what they are doing.
<p>EM7 provides a multi-tenant environment that allows service providers to manage systems across many different customers while at the same time providing the customer access to see the same information but only what’s relevant to them.
<p>EM7 was built by service providers and even includes a few features just for them. Two of my favorites are bandwidth billing and the emergency notification system. Take bandwidth billing, for instance. EM7 provides a way to collect bandwidth utilization, store subscription information, and calculate a bill from any one of about 10 different methodologies. And at the end of the billing period, EM7 sends the completed report out to whomever you chose via email.
<p>Another unique service provider feature is the emergency notification system. EM7 allows the provider to track what customers used their unique infrastructure components. If they have to perform maintenance on the infrastructure component or have a problem they can send an email to all of the impacted customers in a matter of minutes.
<p><strong>ScienceLogic:</strong> What trends do you see for service providers? What about big trends such as virtualization and cloud computing – how will they impact service providers?
<p><strong>John Proctor:</strong> Virtualization is really hot for service providers right now and for the same reasons as in the enterprise. Service providers run data centers and data centers must be powered and cooled. So, anytime they can use a virtual server instead of adding physical equipment it is a good thing. But then you add the complexity that multiple customers reside on the same host and you must track things like bandwidth utilizations by guest OS, and it all gets a little harder. Lucky for us this is not a problem for EM7.
<p>I still think it’s early days for cloud computing. Depending on who you talk to, much of what service providers (especially the big ones) have already been doing with SAAS offerings and hosted applications could be described as cloud computing already. In which case, service providers are ahead of the game. But whatever the “final” definition, cloud computing actually shares many similarities with virtualization – in that service providers (or enterprises) will need to be able to manage far more “devices” in real-time with “zero downtime” expectations by customers. What this really means is that you’re going to see much more automation in provisioning and IT monitoring tools to handle the scale and speed with which things can change in the data center given vm migration and the talked-about switching between “clouds” that can be used for high availability. </p>
]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 12:51:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/service providers">service providers</category>
      <category domain="http://securityratty.com/tag/service providers experience">service providers experience</category>
      <category domain="http://securityratty.com/tag/service providers seldom">service providers seldom</category>
      <category domain="http://securityratty.com/tag/impact service providers">impact service providers</category>
      <category domain="http://securityratty.com/tag/em7 functionality">em7 functionality</category>
      <category domain="http://securityratty.com/tag/em7 sends">em7 sends</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/service provider world">service provider world</category>
      <source url="http://blog.sciencelogic.com/msp-snapshot-monitoring-with-em7/10/2008">MSP Snapshot Monitoring with EM7</source>
    </item>
    <item>
      <title><![CDATA[Are Business Risk and Technical Security Part of a Natural Fourier Series?]]></title>
      <link>http://securityratty.com/article/182f28cd8f2b1713858ac5296e2607ca</link>
      <guid>http://securityratty.com/article/182f28cd8f2b1713858ac5296e2607ca</guid>
      <description><![CDATA[Decade after decade politics moves from regulated economies to de-regulated economies. Changes are usually are triggered by unpredictable events (in political speak). We are almost certainly about to...]]></description>
      <content:encoded><![CDATA[Decade after decade politics moves from regulated economies to de-regulated economies. Changes are usually are triggered by &#8220;unpredictable events&#8221; (in political speak). We are almost certainly about to go onto a period of heavy government regulation of the financial services industry where &#8220;unpredictable events&#8221; or &#8220;failure&#8221; in plain English is blamed on inadequate of regulation. [...]]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 06:25:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/unpredictable events">unpredictable events</category>
      <category domain="http://securityratty.com/tag/regulation">regulation</category>
      <category domain="http://securityratty.com/tag/decade">decade</category>
      <category domain="http://securityratty.com/tag/heavy government regulation">heavy government regulation</category>
      <category domain="http://securityratty.com/tag/decade politics moves">decade politics moves</category>
      <category domain="http://securityratty.com/tag/financial services industry">financial services industry</category>
      <category domain="http://securityratty.com/tag/plain english">plain english</category>
      <category domain="http://securityratty.com/tag/economies">economies</category>
      <category domain="http://securityratty.com/tag/period">period</category>
      <source url="http://securitybuddha.com/2008/10/08/are-business-risk-and-technical-security-part-of-a-natural-fourier-series/">Are Business Risk and Technical Security Part of a Natural Fourier Series?</source>
    </item>
    <item>
      <title><![CDATA[Finding listening ports on your Windows box using Netstat, Fport, Tcpview, IceSword and Current Ports]]></title>
      <link>http://securityratty.com/article/c45254a44427955d16e606148d540d82</link>
      <guid>http://securityratty.com/article/c45254a44427955d16e606148d540d82</guid>
      <description><![CDATA[New Video: Finding listening ports on your Windows box using Netstat, Fport, Tcpview, IceSword and Current Ports Host based firewalls are fine and dandy, but I'd rather turn off services I don't need...]]></description>
      <content:encoded><![CDATA[New Video:<a href="http://www.irongeek.com/i.php?page=videos/finding-listening-ports-on-your-windows-box-using-netstat-fport-tcpview-icesword-and-current-ports">Finding listening ports on your Windows box using Netstat, Fport, Tcpview, IceSword and Current Ports</a><br/>Host based firewalls are fine and dandy, but I'd rather turn off services I don't need than to just block them. Host based firewalls are sort of a bandage, and while they can be useful for knowing what is connecting out (see egress filtering), it's better just not to have unneeded network services running in the first place. This video can be seen as a supplement to my article "<a href="http://www.irongeek.com/i.php?page=security/ipinfo#5">What can you find out from an IP?</a>"
<p><a href="http://feedads.googleadservices.com/~a/CNXtCJO8CcQDAk9fB9tE4S0hjUw/a"><img src="http://feedads.googleadservices.com/~a/CNXtCJO8CcQDAk9fB9tE4S0hjUw/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/5mRbbSK0tUc" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:41:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows box">windows box</category>
      <category domain="http://securityratty.com/tag/network services">network services</category>
      <category domain="http://securityratty.com/tag/host based firewalls">host based firewalls</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/fport">fport</category>
      <category domain="http://securityratty.com/tag/icesword">icesword</category>
      <category domain="http://securityratty.com/tag/netstat">netstat</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/tcpview">tcpview</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/5mRbbSK0tUc/i.php">Finding listening ports on your Windows box using Netstat, Fport, Tcpview, IceSword and Current Ports</source>
    </item>
    <item>
      <title><![CDATA[Fake Windows XP Activation Trojan Wants Your CVV2 Code]]></title>
      <link>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</link>
      <guid>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</guid>
      <description><![CDATA[In a self-contradicting social engineering attempt, a malware author is offering to sale a ( updated version of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/YNDy4vo817c/s1600-h/fake_windows_xp_activation1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/BYpcW4rkU0o/s200-R/fake_windows_xp_activation1.png" /></a>In a self-contradicting social engineering attempt, a malware author is offering to sale a (<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-042705-0108-99">updated version</a> of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it claims "<i>We will ask for your billing details, but your credit card will NOT be charged</i>", is requesting and remotely uploading all the credit card details required for a successfully credit card theft.<br />
<br />
Perhaps among the main reasons why such simplistic social engineering attempts never scaled in a "malicious economies of scale" approach, is because sophisticated crimeware kits capable of obtaining the very same data automatically, started leaking for everyone to start taking advantage of - including yesterday's cybercriminals using such DIY fake message builders. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div>Moreover, according to <a href="http://news.ncsu.edu/news/2008/09/wmswogalterfakemessage.php">recently reseased survey results</a>, end users cannot distinguish between fake popups and real ones, and on their way to continue doing what they were doing, click OK on that pesky warning message telling them that they're about to get infected with malware. Taking into consideration the fact that the popup windows the researchers used look like cheap creative compared to the average fake security software's layout high quality GUIs, it is perhaps worth restating your research questions with something in the lines of - <b>What motivates end users to install an antivirus application going under the name of Super Antivirus 2009 or Mega Virus Cleaner 2008?</b> The fact that the fake status bar is telling them that they're infected with 47 spyware cookies, or the fact that they ended up at the fake site while browsing their trusted web services? <br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/6uvXj2AuS_A/s1600-h/fake_windows_xp_activation2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/fa1jUBjFGOU/s200-R/fake_windows_xp_activation2.png" /></a>The increase of <a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">rogue security software domains</a> is happening due to the high payout affiliation based model, the standardized creative allowing the participants to come up with their own fake names if they want to, and due to the fact that the fake security threats scareware approach seems to be perfectly taking advantage of the overall suspicion on the effectiveness of their legitimate security software.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mw30M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mw30M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WJFzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WJFzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jNfpm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jNfpm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9lodm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9lodm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6go3M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6go3M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TLsPM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TLsPM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JuYBm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JuYBm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413264124" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 15:01:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/credit card details">credit card details</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/credit card theft">credit card theft</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware author">malware author</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <category domain="http://securityratty.com/tag/mega virus cleaner">mega virus cleaner</category>
      <category domain="http://securityratty.com/tag/creative">creative</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413264124/fake-windows-xp-activation-trojan-wants.html">Fake Windows XP Activation Trojan Wants Your CVV2 Code</source>
    </item>
    <item>
      <title><![CDATA[The Results Are In: Real Savings with Deploying Global Telepresence & Multimedia Services]]></title>
      <link>http://securityratty.com/article/a70543fdfebfecce1ea619cd5382c0ae</link>
      <guid>http://securityratty.com/article/a70543fdfebfecce1ea619cd5382c0ae</guid>
      <description><![CDATA[WHEN: Thursday, October 30th10 AM PT / 1 PM ET Join us today!SPONSORED BY: Nortel-PolycomJoin this FREE webinar to see how leading enterprises are effectively deploying global Telepresence to...]]></description>
      <content:encoded><![CDATA[WHEN: Thursday, October 30th10 AM PT / 1 PM ET Join us today!SPONSORED BY: Nortel-PolycomJoin this FREE webinar to see how leading enterprises are effectively deploying global Telepresence to communi...]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 08:42:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/global telepresence">global telepresence</category>
      <category domain="http://securityratty.com/tag/october 30th10">october 30th10</category>
      <category domain="http://securityratty.com/tag/free webinar">free webinar</category>
      <category domain="http://securityratty.com/tag/communi">communi</category>
      <category domain="http://securityratty.com/tag/thursday">thursday</category>
      <category domain="http://securityratty.com/tag/enterprises">enterprises</category>
      <category domain="http://securityratty.com/tag/effectively">effectively</category>
      <category domain="http://securityratty.com/tag/join">join</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/413124564/">The Results Are In: Real Savings with Deploying Global Telepresence &amp; Multimedia Services</source>
    </item>
    <item>
      <title><![CDATA[Links List 10.3.08]]></title>
      <link>http://securityratty.com/article/bfa12b1f280cc26f4ffcd92a791acc11</link>
      <guid>http://securityratty.com/article/bfa12b1f280cc26f4ffcd92a791acc11</guid>
      <description><![CDATA[Well finally, an upside to the financial crisis more students in computer science. After the dot-com crash, enrollment went down in computer science, almost 50% since 2003. Many students shifted their...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/africa-map.jpg" border="0" alt="africa-map" width="204" height="240" align="left" /> Well finally, an upside to the financial crisis – more students in computer science. After the dot-com crash, <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9066659" target="_blank">enrollment went down</a> in computer science, almost 50% since 2003. Many students <a href="http://www.washingtontechnology.com/online/1_1/33584-1.html" target="_blank">shifted their interest from the technology field</a> to banking and finance because they thought they’d make more money. And now the financial crisis could scare them into <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9115616&amp;source=rss_news" target="_blank">choosing majors and careers that are “safer alternatives”</a>, like IT. And perhaps the trend is reversing for those already on Wall Street as well. Ben Worthen writes about the influx of resumes Kodiak Venture Partners has been getting: <a href="http://blogs.wsj.com/biztech/?s=wall+street+jobs" target="_blank">from financial-services vets who want to work at tech startups</a>, – not to “strike it rich” this time around, but just to make a living. And it’s not just the tech workers. Seems like the ones that don’t even have any real IT experience are looking too – for jobs as VPs of marketing (harrumph). (<a href="http://www.fas.org/irp/imint/docs/rst/Sect6/africa-map.jpg" target="_blank"><em>img from www.fas.org</em></a>)</p>
<p>I’m sure you already know about the other “network management” – where ISPs and carriers get their hands publicly slapped for limiting bandwidth to high-traffic offenders. But when is this kind of “network management” a good thing? At a panel sponsored by the FCC in DC, reps from carriers and ISPs discussed what steps they’ve been taking <a href="http://www.networkworld.com/news/2008/091808-telcos-pandemic.html?hpg1=bn" target="_blank">to prepare for a pandemic</a> or other major global crisis – that would force workers to stay at home or work from more remote locations to limit exposure.</p>
<p>Are people paying attention to ICANN? They’re saying that IPv4 will be fully <a href="http://blog.icann.org/?p=365" target="_blank">allocated in the next two or three years</a>. Does anyone care? In their bid to make people care, ICANN talks about the state of IPv6 adoption and <a href="http://www.thestandard.com/news/2008/09/30/africa-faster-adopting-ipv6-according-icann">touts Africa as the most rapid adopter</a>.</p>
<p><a href="http://blogs.zdnet.com/service-oriented/?p=1187" target="_blank">SOA soon part of the ‘cloud’</a>? No, please no.</p>
<p>Microsoft – The Silver Lining in Every Cloud. Joe Wilcox over at eWeek’s Microsoft Watch, has been <a href="http://www.microsoft-watch.com/content/corporate/steve_ballmer_sure_has_lots_to_say.html?kc=EWWHNEMNL10022008STR4" target="_blank">following Steve Ballmer</a> around and collecting some nice quotes on how the company is transitioning. “For many years, we had kind of what I would call the all-encompassing mission, vision and scorecard statement: a computer on every desk and in every home. …Well, our footprint and portfolio is broader than that. “ [In every hand and of course, in every cloud…] “So, as a vision statement we talk about creating seamless experiences that combine the magic of software, the power of the Internet across a world of devices.” The magic of software – something I haven’t thought about for a while. And:</p>
<blockquote><p>&#8220;You need a real platform in the cloud. When we wanted to go after the PC, we built an operating system. When we wanted to go after the phone, we built an operating system. When we wanted to go after the enterprise, we built an operating system. We&#8217;ll announce a new operating system, one that runs in the cloud and has a wide variety of capabilities.”</p></blockquote>
]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 16:55:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/computer science">computer science</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/people care">people care</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/financial crisis">financial crisis</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/care">care</category>
      <category domain="http://securityratty.com/tag/eweeks microsoft">eweeks microsoft</category>
      <source url="http://blog.sciencelogic.com/links-list-10308/10/2008">Links List 10.3.08</source>
    </item>
    <item>
      <title><![CDATA[Major Industries Drop The Ball On Data Security]]></title>
      <link>http://securityratty.com/article/efa5a2f9cc94e5e0494ddb6cafc56fae</link>
      <guid>http://securityratty.com/article/efa5a2f9cc94e5e0494ddb6cafc56fae</guid>
      <description><![CDATA[Verizon, recently analyzed &quot;four years of data from over 500 cases worked by the Verizon Business Investigative Response team,&quot; to produce a report that gives an in-depth look into how data breaches...]]></description>
      <content:encoded><![CDATA[Verizon, recently analyzed "four years of data from over 500 cases worked by the Verizon Business Investigative Response team," to produce a report that gives an in-depth look into how data breaches are occurring in four major industry groups: financial services, food and beverage, retail, and technology services. ]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 10:10:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data breaches">data breaches</category>
      <category domain="http://securityratty.com/tag/technology services">technology services</category>
      <category domain="http://securityratty.com/tag/financial services">financial services</category>
      <category domain="http://securityratty.com/tag/major industry">major industry</category>
      <category domain="http://securityratty.com/tag/recently">recently</category>
      <category domain="http://securityratty.com/tag/in-depth">in-depth</category>
      <category domain="http://securityratty.com/tag/produce">produce</category>
      <category domain="http://securityratty.com/tag/verizon">verizon</category>
      <source url="http://digg.com/security/Major_Industries_Drop_The_Ball_On_Data_Security">Major Industries Drop The Ball On Data Security</source>
    </item>
    <item>
      <title><![CDATA[Inside a Managed Spam Service]]></title>
      <link>http://securityratty.com/article/6ce6bddf4ee3d480d2e75b538f882e90</link>
      <guid>http://securityratty.com/article/6ce6bddf4ee3d480d2e75b538f882e90</guid>
      <description><![CDATA[A managed spam vendor always has to raise the stakes during its introduction period on the market. But what happens when a market follower starts using the market leader's proprietary managed spamming...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOTsz3SyMdI/AAAAAAAACPI/w97lHPkkz7o/s1600-h/managed_spamming_service_2008.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOTsz3SyMdI/AAAAAAAACPI/iBd96sIzD2o/s200-R/managed_spamming_service_2008.jpg" /></a>A <a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">managed spam vendor</a> always has to raise the stakes during its introduction period on the market. But what happens when a market follower starts using the market leader's proprietary <a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">managed spamming system</a>, and is able to provide better spamming rates at a cheaper prices?&nbsp; Market forces and unethical competition at its best.<br />
<br />
So, what is this market challenger using the monopolist's -- in respect to managed spamming services not spam in general -- proprietary system (<a href="http://blogs.zdnet.com/security/?p=1899">Spamming vendor launches managed spamming service</a>) up to anyway? Promising and delivering, 1, 400,000 emails daily, 60,000 mails per hour, and 100 emails per minute. What we've got here are the spam metrics out of 5 already finished spam campaigns that has managed to sent out a million spam emails using only 2000 malware infected hosts. Also, CC-ing and BCC-ing made it possible to multiple the effect of the campaign and increase the total number of emails spammed. Talking about benchmarks, 789 emails per minute at a rate of 12/13 emails per second is a pretty good one, considering it's only 2k bots that they were using. What they also promise is automatic rotation of IPs upon automatically checking them against public blacklists, and a mix rotation of IPs from their own netblocks located in Russia and Germany with the fresh IPs coming from the newly infected hosts.<br />
<br />
Earlier this month, I discussed the market leader's <a href="http://blogs.zdnet.com/security/?p=1899">managed spamming system</a>, access to which they also offer for rent :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SORDqN1mkHI/AAAAAAAACPA/nSP61RrjgSg/s1600-h/spamming_appliance_stats.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SORDqN1mkHI/AAAAAAAACPA/0eV8S8Gv3NA/s200-R/spamming_appliance_stats.jpg" /></a>"<i>An inside look of the system obtained on 2008-08-12 indicates that they are indeed capable of delivering what they promise - speed, simplicity and 5000 malware infected hosts. Moreover, the attached screenshot demonstrates that 20 different email databases can be simultaneously used resulting in 16,523,247 emails about to get spammed using 52 different macroses. Furthermore, what they refer to as a dynamic set of regional servers aiming to ensure that the central server never gets exposed, is in fact fast-flux which depending on how many bots they are willing to put into “rtsegional server mode” shapes the size of the fast-flux network at a later stage.</i>"<br />
<br />
With cutting edge managed spam services like the ones currently in circulation, it remains to be seen whether or not spammers would migrate to this outsourcing model, or continue coming up with adaptive ways to send out their scams and malware on their own.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1n6HM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1n6HM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=69CPM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=69CPM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JSXmm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JSXmm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UqH8m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UqH8m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rsD3M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rsD3M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=myLSM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=myLSM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PFEmm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PFEmm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/410205990" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 07:20:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/spam services">spam services</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/market follower starts">market follower starts</category>
      <category domain="http://securityratty.com/tag/emails daily">emails daily</category>
      <category domain="http://securityratty.com/tag/emails">emails</category>
      <category domain="http://securityratty.com/tag/spam campaigns">spam campaigns</category>
      <category domain="http://securityratty.com/tag/million spam emails">million spam emails</category>
      <category domain="http://securityratty.com/tag/market challenger">market challenger</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/410205990/inside-managed-spam-service.html">Inside a Managed Spam Service</source>
    </item>
  </channel>
</rss>
