<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: simplistic]]></title>
    <link>http://securityratty.com/tag/simplistic</link>
    <description></description>
    <pubDate>Thu, 08 May 2008 09:26:03 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Fake Windows XP Activation Trojan Wants Your CVV2 Code]]></title>
      <link>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</link>
      <guid>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</guid>
      <description><![CDATA[In a self-contradicting social engineering attempt, a malware author is offering to sale a ( updated version of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/YNDy4vo817c/s1600-h/fake_windows_xp_activation1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/BYpcW4rkU0o/s200-R/fake_windows_xp_activation1.png" /></a>In a self-contradicting social engineering attempt, a malware author is offering to sale a (<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-042705-0108-99">updated version</a> of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it claims "<i>We will ask for your billing details, but your credit card will NOT be charged</i>", is requesting and remotely uploading all the credit card details required for a successfully credit card theft.<br />
<br />
Perhaps among the main reasons why such simplistic social engineering attempts never scaled in a "malicious economies of scale" approach, is because sophisticated crimeware kits capable of obtaining the very same data automatically, started leaking for everyone to start taking advantage of - including yesterday's cybercriminals using such DIY fake message builders. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div>Moreover, according to <a href="http://news.ncsu.edu/news/2008/09/wmswogalterfakemessage.php">recently reseased survey results</a>, end users cannot distinguish between fake popups and real ones, and on their way to continue doing what they were doing, click OK on that pesky warning message telling them that they're about to get infected with malware. Taking into consideration the fact that the popup windows the researchers used look like cheap creative compared to the average fake security software's layout high quality GUIs, it is perhaps worth restating your research questions with something in the lines of - <b>What motivates end users to install an antivirus application going under the name of Super Antivirus 2009 or Mega Virus Cleaner 2008?</b> The fact that the fake status bar is telling them that they're infected with 47 spyware cookies, or the fact that they ended up at the fake site while browsing their trusted web services? <br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/6uvXj2AuS_A/s1600-h/fake_windows_xp_activation2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/fa1jUBjFGOU/s200-R/fake_windows_xp_activation2.png" /></a>The increase of <a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">rogue security software domains</a> is happening due to the high payout affiliation based model, the standardized creative allowing the participants to come up with their own fake names if they want to, and due to the fact that the fake security threats scareware approach seems to be perfectly taking advantage of the overall suspicion on the effectiveness of their legitimate security software.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mw30M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mw30M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WJFzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WJFzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jNfpm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jNfpm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9lodm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9lodm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6go3M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6go3M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TLsPM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TLsPM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JuYBm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JuYBm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413264124" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 15:01:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/credit card details">credit card details</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/credit card theft">credit card theft</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware author">malware author</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <category domain="http://securityratty.com/tag/mega virus cleaner">mega virus cleaner</category>
      <category domain="http://securityratty.com/tag/creative">creative</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413264124/fake-windows-xp-activation-trojan-wants.html">Fake Windows XP Activation Trojan Wants Your CVV2 Code</source>
    </item>
    <item>
      <title><![CDATA[More Details on McAfee's Artemis]]></title>
      <link>http://securityratty.com/article/3ef62fbfbd2bb374f1c20b9b41dc0c41</link>
      <guid>http://securityratty.com/article/3ef62fbfbd2bb374f1c20b9b41dc0c41</guid>
      <description><![CDATA[I spoke with McAfee recently, following my column about its Artemis technology . I learned a few things. Artemis kicks in when the local anti-virus scanner sees, through behavioral methods, if the...]]></description>
      <content:encoded><![CDATA[I spoke with McAfee recently, following <a href="http://www.eweek.com/c/a/Security/McAfee-Putting-Malware-Signatures-in-the-Cloud/">my column about its Artemis technology</a>. I learned a few things.

Artemis kicks in when the local anti-virus scanner sees, through behavioral methods, if the file is suspicious. Then it sends a fingerprint of the file up to the Artemis servers for further analysis.

I had assumed that this fingerprint was a hash of some kind, but that was a simplistic assumption. The fingerprint includes characteristics of the file, including the ones that the scanner used to determine that the file was suspicious: Is it packed? Using certain packers in particular? Is it compressed (not the same thing)? Is it a certain size? In case I was unclear before, none of this involves signatures in the conventional sense.

It occurs to me that this could lower false-positives, compared with conventional behavioral analysis, because it subjects suspicious threats to more extensive analysis in the cloud. It all depends on how aggressive McAfee is at that stage.

Another thought I had is that since Artemis kicks in as a result of behavioral analysis, the threat has already hit the system by the time Artemis is invoked. Presumably the process is asynchronous and Artemis could return its analysis some time after the submission. If this is the case, it could be awhile during which malware is running rampant on your system.
<p><a href="http://feedads.googleadservices.com/~a/gTm8XhZRINn6ceS8NEYjhBg8ZZo/a"><img src="http://feedads.googleadservices.com/~a/gTm8XhZRINn6ceS8NEYjhBg8ZZo/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/VyuqqR5FRAs" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 07:25:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/artemis">artemis</category>
      <category domain="http://securityratty.com/tag/analysis">analysis</category>
      <category domain="http://securityratty.com/tag/conventional behavioral analysis">conventional behavioral analysis</category>
      <category domain="http://securityratty.com/tag/artemis servers">artemis servers</category>
      <category domain="http://securityratty.com/tag/artemis kicks">artemis kicks</category>
      <category domain="http://securityratty.com/tag/extensive analysis">extensive analysis</category>
      <category domain="http://securityratty.com/tag/behavioral analysis">behavioral analysis</category>
      <category domain="http://securityratty.com/tag/artemis technology">artemis technology</category>
      <category domain="http://securityratty.com/tag/fingerprint">fingerprint</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/VyuqqR5FRAs/more_details_on_mcafees_artemis.html">More Details on McAfee's Artemis</source>
    </item>
    <item>
      <title><![CDATA[Modelling Air Traffic Control]]></title>
      <link>http://securityratty.com/article/7f9e569822e0521bce9615d70124032f</link>
      <guid>http://securityratty.com/article/7f9e569822e0521bce9615d70124032f</guid>
      <description><![CDATA[Today I will discussa general approach to model air traffic control (ATC)using our CEP/EP reference architecture which is an application of the mature JDL multisensor data fusion model
ATC is an...]]></description>
      <content:encoded><![CDATA[<p>Today I will discuss a general approach to model air traffic control (ATC) using our <a href="http://www.thecepblog.com/what-is-complex-event-processing/" target="_blank">CEP/EP reference architecture </a>which is an application of the mature <a href="http://www.data-fusion.org/article.php?sid=70" target="_blank">JDL multisensor data fusion model</a>.</p>
<p>ATC is an excellent working example of complex event processing.   Radar and GPS provide the basic sensory information to accurately track and trace the position of each aircraft in the area of responsibility (AOR) of a particular control tower/zone.     Naturally,  sensory information is preprocessed and formatted in such a way that the data can be processed upstream by multiple real-time applications.</p>
<p>Before we look at complex ATC scenarios, such as &#8220;potential collision&#8221; or &#8220;aircraft off approach vector&#8221; we must trace and trace individual objects, aircraft-objects, accurately with very high confidence.    In addition to tracking aircraft-objects, there is a database of information about the aircraft (ideally), such as make, model, age, range, passengers and other properties about the aircraft-object.      In addition, there is a state-model for each aircraft, for example the aircraft might be &#8220;on the ground&#8221;, &#8220;approaching the runway&#8221;, &#8220;cleared for takeoff&#8221;, &#8220;cruising altitude&#8221;, &#8220;approaching runway&#8221;, &#8220;final decent&#8221; etc.  </p>
<p>Tracking and tracing individual aircraft is what is generally referred to as &#8220;object refinement&#8221; in our CEP/EP reference architecture.   The reason we call this function &#8220;object refinement&#8221; is that system engineers are focused on optimizing the situational knowledge about individual objects.     Sometimes we refer to this function as &#8220;track and trace&#8221; because that is what we are doing to  each object in the model.  In Marc Adler&#8217;s recent <a href="http://www.thecepblog.com/2008/09/07/modelling-shoplifting/" target="_blank">shoplifting scenario</a>, Marc was interested in tracking and tracing people in a store using imaging processing techniques to estimate their behavioral patterns.  In the same way, before we can process for scenarios such as &#8220;potential shoplifter&#8221; or &#8220;suspicious criminal gang activity&#8221; we must be able to accurately process (track and trace) individual object, such as people or merchandise.</p>
<p>Back to aircraft and ATC, the &#8220;complex event processing&#8221; begins when we are looking about object-object relationships, in this model, aircraft-to-aircraft, but this is an overly simplistic model, as we have not yet added (to our model) ground features (towers, buildings, power lines), weather (storm cells, wind) and other flying objects (known migratory bird paths, swarms of insects) to our simple model.  </p>
<p>Complex event processing occurs when we are processing multiple objects in our model looking for threats in real-time.     Practically speaking, all ATC applications are CEP applications.  This means that vendors and integrators who build ATC applications are also CEP vendors.   </p>
<blockquote><p>Editorial Note: CEP/EP has been around for a long time and was not recently invented in the past decade as some &#8220;inventors&#8221; would like for us to believe. </p></blockquote>
<p>As you can imagine, there is considerable &#8220;complex event processing&#8221; that goes on &#8220;behind the scenes&#8221; to provide air traffic controllers and pilots situational knowledge into the &#8220;friendly skies&#8221;.   As you might further imagine, the situation is more complex when the skies are &#8220;not so friendly&#8221;, for example, in air combat situations.   </p>
<p>Processing myriad objects is not the end of the processing &#8220;chain&#8221;.  For example, decisions are being made constantly about potential damage, alternative airports, and more.    In our reference model, we refer to this, generally speaking, as &#8220;impact assessment&#8221; because we must take an estimated detected complex event, for example &#8220;aircraft collision,&#8221; and estimate potential damage based on numerous factors such as, the amount of jet fuel in the aircrafts and the location of the aircrafts (over a large city or rural area, near a hospital and emergency services).   Regardless of the scenario, an impact assessment is normally required before optimal decisions can be made.</p>
<blockquote><p>This is true, by the way, for our <a href="http://www.thecepblog.com/2008/09/07/modelling-shoplifting/" target="_blank">shoplifting example</a> (the impact is different if a piece of gum is stolen versus a $1,000,000 diamond necklace or weapons-grade nuclear material) and other scenarios and models.  Static data (information about objects) is required for accurate decision processing.  </p></blockquote>
<p>Impact assessment is not the end of the &#8220;knowledge chain&#8221;.    Decisions are constantly being made that effect resources.  For example, suggestion an alternative route for an aircraft is a resource management decision.    Turning on and off radar or switching to alternative tracking devices is a resource management function.  In our CEP/EP reference model (based on the JDL data fusion model), we call this &#8220;resource management&#8221;.   This function includes contacting emergency services and directing them to a potential crash location or sending out a message to instruct all aircraft to stay off a certain radio frequency.  Resource management is critical.</p>
<p>Our simple ATC model today is by no means complete, it just scratches the surface.  In fact, I have a very close friend, <a href="http://www.linkedin.com/pub/0/b45/b16" target="_blank">Mark Secrist</a>, who is a former Marine fighter pilot and currently a senior captain for <a href="http://www.aa.com" target="_blank">American Airlines</a>.   I have asked Mark to read this post and help me further refine this crude &#8220;laymans&#8221; ATC model (Thanks Mark!).</p>
]]></content:encoded>
      <pubDate>Mon, 08 Sep 2008 09:27:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/model">model</category>
      <category domain="http://securityratty.com/tag/crude laymansatc model">crude laymansatc model</category>
      <category domain="http://securityratty.com/tag/state-model">state-model</category>
      <category domain="http://securityratty.com/tag/simple atc model">simple atc model</category>
      <category domain="http://securityratty.com/tag/complex">complex</category>
      <category domain="http://securityratty.com/tag/isconsiderable complex event">isconsiderable complex event</category>
      <category domain="http://securityratty.com/tag/overly simplistic model">overly simplistic model</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/simple model">simple model</category>
      <source url="http://www.thecepblog.com/2008/09/08/modelling-air-traffic-control/">Modelling Air Traffic Control</source>
    </item>
    <item>
      <title><![CDATA[Copycat Web Malware Exploitation Kits are Faddish]]></title>
      <link>http://securityratty.com/article/ba56aabae03bad418cbbf5ae497d3769</link>
      <guid>http://securityratty.com/article/ba56aabae03bad418cbbf5ae497d3769</guid>
      <description><![CDATA[For the cheap cybercriminals not wanting to invest a couple of thousand dollars into purchasing a cutting edge web malware exploitation kit -- a pirated copy of which they would ironically obtained...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SL1mWgfY_TI/AAAAAAAACJU/u4h7TuozLDI/s1600-h/copycat_web_malware_exploitation_kit.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SL1mWgfY_TI/AAAAAAAACJU/H8HQ-QzSBfg/s200-R/copycat_web_malware_exploitation_kit.gif" /></a>For the cheap cybercriminals not wanting to invest a couple of thousand dollars into purchasing a cutting edge web malware exploitation kit -- a pirated copy of which they would ironically obtained several moths later -- with all the related and royalty free updates coming with it, there are always the copycat malware kits like this one offered for $100.<br />
<br />
Taking into consideration the proprietary nature of some of the kits, the business model of malware kits was mostly relying on their exclusive nature next to the number, and diversity of the exploits included in order to improve the infection rate. This simplistic assumption on behalf of the coders totally <a href="http://blogs.zdnet.com/security/?p=1598">ignored the possibility of their kits leaking to the general public</a>, or copies of the kits ending up as a bargain in particular underground deal where the once highly exclusive kit was offered as a bonus.<br />
<br />
"Me too" web malware kits were a faddish way to enjoy the popularity of web malware kits like MPack and Icepack and try to cash in on that popularity by coming up average kits lacking any significant differentiation factors in the process. But just like the original and proprietary kits, whose authors didn't envision the long term growth strategy of integrating different services into their propositions or the kits themselves, the authors of copycat malware kits didn't bother considering the lack of long-term growth strategy for their releases. Branding in respect to releasing a Firepack malware kit to compete with Icepack which was originally released to compete with Mpack, has failed to achieve the desired results as well.<br />
<br />
And with malware kits now a commodity, and underground vendors excelling in a particular practice with the long term objective to vertically integrate in their area of expertise -- think spammers offering localization of messages into different languages and segmented email databases from a specific country -- would we witness the emergence of <a href="http://ddanchev.blogspot.com/2008/08/76service-cybercrime-as-service-going.html">managed cybercrime services</a> charging a premium for providing fresh dumps of credit card numbers, PayPal, Ebay accounts or whatever the buyer is requesting?<br />
<br />
That may well be the case in the long term.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diy-botnet-kit-promising-eternal.html">DIY Botnet Kit Promising Eternal Updates</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The Small Pack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">Crimeware in the Middle - Zeus</a><br />
<a href="http://ddanchev.blogspot.com/2006/11/nuclear-grabber-toolkit.html">The Nuclear Grabber Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">The Apophis Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">The FirePack Exploitation Kit Localized to Chinese</a><span style="font-weight: bold;"><br />
</span><a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">MPack and IcePack Localized to Chinese</a><br />
<span style="font-weight: bold;"><span style="font-weight: bold;"></span></span><a href="http://ddanchev.blogspot.com/2008/05/icepack-exploitation-kit-localized-to.html">The Icepack Exploitation Kit Localized to French</a> <br />
<a href="http://ddanchev.blogspot.com/2008/04/firepack-exploitation-kit-part-two.html">The FirePack Exploitation Kit - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/firepack-web-malware-exploitation-kit.html">The FirePack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/webattacker-in-action.html">The WebAttacker in Action</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/nuclear-malware-kit.html">Nuclear Malware Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/random-js-malware-exploitation-kit.html">The Random JS Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher Malware Kit Spotted in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_7672.html">The Black Sun Bot</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_20.html">The Cyber Bot</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/google-hacking-for-mpacks-zunkers-and.html">Google Hacking for MPacks, Zunkers and WebAttackers</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/icepack-malware-kit-in-action.html">The IcePack Malware Kit in Action</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jUilFL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jUilFL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LiAKxL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LiAKxL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GnpH1l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GnpH1l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bjjwel"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bjjwel" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NAlZrL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NAlZrL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ybk3ML"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ybk3ML" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0j6X0l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0j6X0l" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/382290326" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 03:18:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware kits">malware kits</category>
      <category domain="http://securityratty.com/tag/web malware kits">web malware kits</category>
      <category domain="http://securityratty.com/tag/kits">kits</category>
      <category domain="http://securityratty.com/tag/copycat malware kits">copycat malware kits</category>
      <category domain="http://securityratty.com/tag/proprietary kits">proprietary kits</category>
      <category domain="http://securityratty.com/tag/term">term</category>
      <category domain="http://securityratty.com/tag/long-term growth strategy">long-term growth strategy</category>
      <category domain="http://securityratty.com/tag/icepack">icepack</category>
      <category domain="http://securityratty.com/tag/icepack exploitation kit">icepack exploitation kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/382290326/copycat-web-malware-exploitation-kits.html">Copycat Web Malware Exploitation Kits are Faddish</source>
    </item>
    <item>
      <title><![CDATA[Decrypting and Restoring GPcode Encrypted Files]]></title>
      <link>http://securityratty.com/article/e39ad499bbe55c20aca17c7ba23989b4</link>
      <guid>http://securityratty.com/article/e39ad499bbe55c20aca17c7ba23989b4</guid>
      <description><![CDATA[The futile attempt to directly attack the encryption algorithm used by the GPcode ransomware, is prompting Kaspersky Labs to invest in a more pragmatic solutions to the problem , with a new version of...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SGotTuyTE5I/AAAAAAAAB3U/gWdSWKjyPK0/s1600-h/gpcode_initiative.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SGotTuyTE5I/AAAAAAAAB3U/zT9QFXjWmFE/s200-R/gpcode_initiative.jpg" style="border: 0pt none ;" /></a>The futile attempt to directly attack the encryption algorithm used by the GPcode ransomware, is prompting Kaspersky Labs to invest in a more <a href="http://www.viruslist.com/en/weblog?weblogid=208187538">pragmatic solutions to the problem</a>, with <a href="http://www.viruslist.com/en/viruses/encyclopedia?virusid=313444#doc2">a new version of the StopGpcode tool</a> released last week. More info :<br />
<br />
"<i>It turns out that if a user has files that are encrypted by Gpcode and versions of those same files that are unencrypted, then the pairs of files (the encrypted and corresponding unencrypted file) can be used to restore other files on the victim machine. This is the method that the StopGpcode2 tool uses.</i><br />
<br />
<i>Where can these unencrypted files be found? They may be the result of using PhotoRec. Moreover, these files may be found in a backup storage or on removable media (e.g., the original files of photographs copied to the hard disk of a computer that has been attacked by Gpcode may still be on a camera’s memory card). Unencrypted files may also have been saved somewhere on a network resource (e.g., films or video clips on a public server) that the Gpcode virus has not reached.</i>"<br />
<br />
As <a href="http://www.securityfocus.com/news/11523/2">the customer support desk behind GPcode pointed out in an interview</a>, the malware is prone to evolve, and the simplistic file deletion process will be replaced by secure file deletion in order to render all data recovery tols useless, unless of course backups of the affected data are available. They often aren't, and depending on the importance of the files encrypted, the successful ransom is all a matter of the momentum. <br />
<br />
<span class="body">"<i>A person, presumably the author of Gpcode, contacted at <a href="http://ddanchev.blogspot.com/2008/06/whos-behind-gpcode-ransomware.html" target="_blank">one of the e-mail addresses</a> left behind by the program stated that future development efforts will likely increase the key size to 4,096 bits, "if AV companies or other (people) crack the current key, but (that's) impossible. </i></span><i><span class="body">The self-proclaimed author, who used the name "Daniel Robertson," also said that other standard techniques to defeat antivirus will be added, including polymorphic encryption, anti-heuristic features and the ability to self propagate, turning the program into a computer virus.</span><span class="body"> </span>It well pays back itself," he said</i>"<br />
<br />
There are even more pragmatic approaches to dealing with this problem, next to backups undermining their business model. <a href="http://blogs.zdnet.com/security/?p=1259">Try following the virtual money for instance</a>.<br />
<span class="body"> </span><span class="body"></span><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4JuTFJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4JuTFJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CtTuIJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CtTuIJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UH6vhj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UH6vhj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rZfGRj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rZfGRj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=602SKJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=602SKJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XhBjBJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XhBjBJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9PpNFj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9PpNFj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/324045050" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 04:26:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/files">files</category>
      <category domain="http://securityratty.com/tag/gpcode">gpcode</category>
      <category domain="http://securityratty.com/tag/original files">original files</category>
      <category domain="http://securityratty.com/tag/gpcode virus">gpcode virus</category>
      <category domain="http://securityratty.com/tag/gpcode ransomware">gpcode ransomware</category>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/secure file deletion">secure file deletion</category>
      <category domain="http://securityratty.com/tag/computer virus">computer virus</category>
      <category domain="http://securityratty.com/tag/key">key</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/324045050/decrypting-and-restoring-gpcode.html">Decrypting and Restoring GPcode Encrypted Files</source>
    </item>
    <item>
      <title><![CDATA[Dickson County School District employee information stolen]]></title>
      <link>http://securityratty.com/article/c547b25ca5d443005c23b781eb42d2ae</link>
      <guid>http://securityratty.com/article/c547b25ca5d443005c23b781eb42d2ae</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/11/08

Organization
Dickson County School District

Contractor/Consultant/Branch
None

Victims
employees who worked for Dickson County schools in the...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/dickson.jpg" align="right" height="153" width="200"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/11/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.dicksoncountyschools.org/index.html">Dickson County School District</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>"employees who worked for Dickson County schools in the 2006-2007 school year"<br><br><span style="font-weight: bold;">Number Affected:</span><br>850<br><br><span style="font-weight: bold;">Types of Data:</span><br>Payroll information including names, addresses and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>"DICKSON, Tenn. -- A laptop computer containing personal employee information disappeared over the weekend from the office of Dickson County's top school official."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.wsmv.com/news/16573465/detail.html">WSMV Channel 4 News</a> <br><a href="http://www.wztv.com/newsroom/top_stories/vid_1944.shtml">WZTV Channel 17 News</a> <br><a href="http://www.tennessean.com/apps/pbcs.dll/article?AID=/20080612/COUNTY03/806120370">The Tennessean</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Chris Tatum, WSMV Channel 4 News<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>A laptop computer containing the Social Security numbers and payroll information of all the employees of the Dickson County school system has been stolen, and authorities are warning school officials to watch their bank accounts.<br><span style="font-style: italic;">[Evan] Is a physically and technically unsecure mobile device a good place to store confidential information?&nbsp; You probably know the answer to this already.</span><br><br>The computer belongs to the new director of schools and was loaded with the name and Social Security number of every school employee from the 2006-2007 school year, a total of 850.<br><br>"It's all public record except for the Social Security numbers," Johnny Chandler<br><span style="font-style: italic;">[Evan] Well yeah, except for the Social Security numbers!&nbsp; What the &amp;@*#?</span><br><br>"It came up missing over the weekend, sometime between Friday until Monday," said Dickson County school superintendent Johnny Chandler.<br><br>Chandler became the district's school superintendent last week and said that the laptop was on this desk when the office closed Friday evening.<br><span style="font-style: italic;">[Evan] I couldn't find any mention of whether or not the office itself was locked or secured.&nbsp; I presume that it was not.&nbsp; This is not a very good start to Mr. Chandler's tenure.</span><br><br>Police have launched an investigation, but found no signs of a break-in and haven't ruled out someone within the building being the cause of the theft.<br><br>Employees at the Board of Education and police investigators believe the person who stole the laptop walked right through the door without forced entry. <br><br>Chandler admits that a cleaning crew, several staff and students for a retirement party came into the building over the weekend.<br><br>He has warned all school employees to keep a close eye on their credit reports.<br><br>We sent letters to everyone that was on that database in '06 and '07<br><br>Chandler assures school employees that he'll make sure this never happens again.<br><span style="font-style: italic;">[Evan] How?</span><br><br>"All of our laptop computers will not be allowed to have any personal information concerning any employee or student," said Chandler.<br><span style="font-style: italic;">[Evan] This is one good step.&nbsp; Will this be in policy?&nbsp; Will employees be trained and made periodically aware of this mandate?&nbsp; How will this be enforced?&nbsp; Will this mandate include other mobile devices and media such as CDs, thumb drives, etc.?</span><br><br>He said the laptop is double password protected.<br><span style="font-style: italic;">[Evan] Sounds impressive, doesn't it.</span><br><br>"It has a double password so it would take a computer genius to get into it."<br><span style="font-style: italic;">[Evan] I am certainly no genius, but I am pretty sure I could get into it!</span><br><br>Chandler said he plans to upgrade the security system at the school board building.<br><br>In the meantime, workers will lock up any equipment that contains sensitive information when they're not using it.<br><br>Dickson police said they are notifying local pawn shops to be on the lookout for the stolen laptop.<br><br>Director Vivian McCord says, "I really wish they would return it."<br><br>"The office it was taken from was next to the computer office and there were multiple computers next door in that room. So I really feel like it was just a quick little taking of a computer."<br><br>Anyone with information should call the Dickson Police Department at (615) 441-9592<br><br><span style="font-weight: bold;">Commentary:</span><br>We see these kinds of breaches all the time, but why?&nbsp; It is frustrating.<br><br>Too many people collect and store personal information and are oblivious to the risks.&nbsp; A laptop computer + confidential information + unlocked office - encryption = unacceptable risk for most prudent people.&nbsp; A simplistic point, but you get it. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/12/dickson.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 07:52:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/school">school</category>
      <category domain="http://securityratty.com/tag/store personal information">store personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/dickson county">dickson county</category>
      <category domain="http://securityratty.com/tag/dickson police">dickson police</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/store confidential information">store confidential information</category>
      <category domain="http://securityratty.com/tag/school board">school board</category>
      <source url="http://breachblog.com/2008/06/12/dickson.aspx">Dickson County School District employee information stolen</source>
    </item>
    <item>
      <title><![CDATA[Stolen laptop affects thousands of current and former Stanford employees]]></title>
      <link>http://securityratty.com/article/6ccc71f840f261739703c07112ae5cb2</link>
      <guid>http://securityratty.com/article/6ccc71f840f261739703c07112ae5cb2</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/6/08

Organization
Stanford University

Contractor/Consultant/Branch
None

Victims
current and former employees hired before September 28, 2007

Number...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/stanford.jpg" align="right" height="150" width="98"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/6/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.stanford.edu/">Stanford University</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>current and former employees hired before September 28, 2007<br><br><span style="font-weight: bold;">Number Affected:</span><br>as many as 72,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>Some or all of the following; First and last name, gender, birthdate, Social Security Number, Business title and office location, Work and home phone numbers, Home address, Salary, Stanford email address, Stanford ID card number and Stanford employee number<br><br><span style="font-weight: bold;">Breach Description:</span><br>"Stanford University determined yesterday that a university laptop, which was recently stolen, contained confidential personnel data. The university is not disclosing details about the theft as an investigation is under way."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://news-service.stanford.edu/news/2008/june11/laprelease-061108.html">Stanford News Service</a> <br><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/06/08/BAR9115907.DTL">San Francisco Chronicle</a> <br><a href="http://cbs5.com/local/stanford.stolen.laptop.2.742945.html">KPIX Channel 5 News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Stanford News Service<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>STANFORD (BCN) ? The personal information of as many as 72,000 people working for, or formerly employed by, Stanford University could be at risk after officials determined a recently stolen laptop contained confidential personnel data.<br><span style="font-style: italic;">[Evan] Even a prestigious school like Stanford University is not immune.&nbsp; 72,000 confidential personal records on a laptop that appears to have not been encrypted is not representative of good information security practice.</span><br><br>The computer contained personal records of Stanford employees hired before Sept. 28, 2007<br><br>data on the laptop included some or all of the following: employees' names, birth dates, Social Security numbers, business titles, work and home phone numbers, home addresses, salaries, and Stanford e-mail addresses and employee identification numbers.<br><br>While the university does not believe the thief was aware of the records' existence on the machine, it is taking steps to assist anyone whose information might be misused.<br><span style="font-style: italic;">[Evan] How many times have we read this in a breach notification?&nbsp; It is almost like a breach notification isn't a breach notification without it.</span><br><br>"We believe that the perpetrator of the crime was not seeking the records on the computer or even aware of them,"<br><br>"Often, such thefts are property crimes in which the laptop's hard drive is erased before the laptop is resold."<br><span style="font-style: italic;">[Evan]&nbsp; Robert Richardson, director of the San Francisco-based Computer Security Institute responds "In the past, if a laptop was stolen from a cafe, it was reasonable to think it would be reformatted and sold as a new machine," "Now I wouldn't make that assumption. Even the dumbest criminals out there are on to the fact that the data is where the money is."&nbsp; I have stated this numerous times on The Breach Blog.&nbsp; Now you don't have to take my word for it.&nbsp; Check out the </span><a style="font-style: italic;" href="http://www.gocsiblog.com/">CSI blog</a><span style="font-style: italic;">.</span><br><br>While there is no evidence that any of the information on the stolen laptop has been accessed, the University is committed to taking steps to assist individuals whose personal data may be misused<br><br>The university is not disclosing the details of the crime, as an investigation is still under way.<br><br>This matter has been reported to law enforcement.<br><br>Stanford sent out an e-mail message Friday to all the current and former employees it could reach, advising them of the theft.<br><br>The university is sending e-mails and letters to current and former employees whose personal information may be at risk, as well as posting information on the Stanford homepage at: <a href="http://www.stanford.edu,">www.stanford.edu,</a> and notifying the media.<br><br>The university said it will provide additional credit monitoring to help employees respond to the possible data breach and protect their identities from fraud.<br><br>"We will have services in place next week and Stanford is committed to assuming this cost,"<br><br>It is also looking at how to protect employee data better in the future.<br><span style="font-style: italic;">[Evan] I hope that mobile device encryption is in the mix.</span><br><br>While the university has rigorous policies and guidelines designed to protect confidential information, events such as this demonstrate the need for heightened vigilance in this area.<br><span style="font-style: italic;">[Evan] Information security always requires a "heightened vigilance".&nbsp; It is a continuous effort.</span><br><br>Vice President for Business Affairs and Chief Financial Officer Randy Livingston will lead a task force to review policies and practices regarding the safety and security of sensitive data.<br><br>Livingston said: "The university has guidelines that prohibit keeping sensitive information on unsecured computers. This effort will be redoubled after this incident."<br><br>We sincerely apologize for this incident.<br><br>You can call (650) 736-0099 and leave your contact information for a return call. You can also go to the Stanford home page for updates or email privacyquestions@stanford.edu with your full name and date of birth.<br><br><span style="font-weight: bold;">Commentary:</span><br>If an organization employs laptops and other mobile devices, it is only a matter of time that one (or more) will be lost or stolen.&nbsp; It is a fact of life, and it really doesn't matter how aware the users are.&nbsp; We either need to make sure that confidential information does not get stored on mobile devices, encrypt them (with secure key management) or preferably both.&nbsp; This is a simplistic view, but you get the point.<br><br>Breaches like this get old, but they still tick me off. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/08/stanford.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sun, 08 Jun 2008 19:12:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/stanford">stanford</category>
      <category domain="http://securityratty.com/tag/university laptop">university laptop</category>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/stanford university">stanford university</category>
      <category domain="http://securityratty.com/tag/stanford email address">stanford email address</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/information security practice">information security practice</category>
      <category domain="http://securityratty.com/tag/stanford employee">stanford employee</category>
      <source url="http://breachblog.com/2008/06/08/stanford.aspx">Stolen laptop affects thousands of current and former Stanford employees</source>
    </item>
    <item>
      <title><![CDATA[The Small Pack Web Malware Exploitation Kit]]></title>
      <link>http://securityratty.com/article/54ab82c46ea0dd7dd334397f243fcbc8</link>
      <guid>http://securityratty.com/article/54ab82c46ea0dd7dd334397f243fcbc8</guid>
      <description><![CDATA[Yet another proprietary web malware exploitation kit has been released at the beginning of this month, further indicating that the efficient supply of such kits is proportional to their simplistic...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SDE2UntDW9I/AAAAAAAABtw/4b-XGhjxUnc/s1600-h/small_pack_web_malware_exploitation_kit.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SDE2UntDW9I/AAAAAAAABtw/4b-XGhjxUnc/s200/small_pack_web_malware_exploitation_kit.png" alt="" id="BLOGGER_PHOTO_ID_5201998772472863698" border="0" /></a>Yet another proprietary web malware exploitation kit has been released at the beginning of this month, further indicating that the efficient supply of such kits is proportional to their simplistic nature. The only differentiation factor in the Small Pack is perhaps the inclusion of all known Opera exploits up to version 9.20, however, the rest of the features are the natural ones included in the majority of already known exploitation kits :<br /><br /><span style="font-style: italic;">- IE exploits included - Quick TIme Modified, PNG, MDAC, DX Media</span> <span style="font-style: italic;"><br />- Firefox exploits included - Quick Time, PNG, EMBED</span><br /><span style="font-style: italic;">- Opera - all exploits up to version 9.20</span> <span style="font-style: italic;"><br />- RC4 encryption</span> <span style="font-style: italic;"><br />- lifetime updates<br />- Geolocation </span><span style="font-style: italic;"><br />- opportunity to request additional functions</span><br /><br />Converging infection and distribution vectors, evasion and survivability, metrics and command and control in a single all-in-one web malware exploitation kits is, however, is definitely in the works considering the developments introduced in the rest of the kits currently available. For instance, despite that the ongoing waves of SQL injection attacks with multiple campaigns are injecting the malicious domains in its original form, certain attacks are starting to inject obfuscated URLs making it harder to assess the impact of the campaign using open source intelligence techniques.<br /><br />The bottom line, as long as webmasters continue participating in the so called "traffic exchange" revenue models, knowingly or unknowingly embedding links that would later on ultimately redirect to a malicious site, "traffic exchange" is receiving the most attention at the strategic level, next to "traffic acquisition" at the tactical level. Basically, the traffic inventory that could be supplied is the direct result of an ongoing SQL injection attack, or malware embedded through other means, with the traffic brokers directly undermining webmaster's unethical inclusion of exploits within their domains portfolio.<br /><br />One thing's for sure - web malware exploitation kits are not just getting localized, they're also being cloned.<br /><br /><span style="font-weight: bold;">Related posts:<br /><span style="font-weight: bold;"></span></span><a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">The FirePack Exploitation Kit Localized to Chinese</a><span style="font-weight: bold;"><br /></span><a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">MPack and IcePack Localized to Chinese</a><br /><span style="font-weight: bold;"><span style="font-weight: bold;"></span></span><a href="http://ddanchev.blogspot.com/2008/04/firepack-exploitation-kit-part-two.html">The FirePack Exploitation Kit - Part Two</a><br /><a href="http://ddanchev.blogspot.com/2008/02/firepack-web-malware-exploitation-kit.html">The FirePack Web Malware Exploitation Kit</a><br /><a href="http://ddanchev.blogspot.com/2007/05/webattacker-in-action.html">The WebAttacker in Action</a><br /><a href="http://ddanchev.blogspot.com/2007/08/nuclear-malware-kit.html">Nuclear Malware Kit</a><br /><a href="http://ddanchev.blogspot.com/2008/01/random-js-malware-exploitation-kit.html">The Random JS Malware Exploitation Kit</a><br /><a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher Malware Kit Spotted in the Wild</a><br /><a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_7672.html">The Black Sun Bot</a><br /><a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_20.html">The Cyber Bot</a><br /><a href="http://ddanchev.blogspot.com/2007/09/google-hacking-for-mpacks-zunkers-and.html">Google Hacking for MPacks, Zunkers and WebAttackers</a><br /><a href="http://ddanchev.blogspot.com/2007/07/icepack-malware-kit-in-action.html">The IcePack Malware Kit in Action</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JmT7cH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JmT7cH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vDfueH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vDfueH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kEVAWh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kEVAWh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OesNgh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OesNgh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Goa7eH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Goa7eH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fZrvyH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fZrvyH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=G6m5Rh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=G6m5Rh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/293340238" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 18 May 2008 23:41:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware exploitation kit">malware exploitation kit</category>
      <category domain="http://securityratty.com/tag/nuclear malware kit">nuclear malware kit</category>
      <category domain="http://securityratty.com/tag/opera exploits">opera exploits</category>
      <category domain="http://securityratty.com/tag/opera">opera</category>
      <category domain="http://securityratty.com/tag/metaphisher malware kit">metaphisher malware kit</category>
      <category domain="http://securityratty.com/tag/exploits">exploits</category>
      <category domain="http://securityratty.com/tag/firepack exploitation kit">firepack exploitation kit</category>
      <category domain="http://securityratty.com/tag/icepack malware kit">icepack malware kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/293340238/small-pack-web-malware-exploitation-kit.html">The Small Pack Web Malware Exploitation Kit</source>
    </item>
    <item>
      <title><![CDATA[Anton Security Tip of the Day #15: Fear and Loathing in Event 560 (and 562 and 567)]]></title>
      <link>http://securityratty.com/article/298d93d64c01d5a12de2d2c761a8ead4</link>
      <guid>http://securityratty.com/article/298d93d64c01d5a12de2d2c761a8ead4</guid>
      <description><![CDATA[Following the new &quot;tradition&quot; of posting a security tip of the week (mentioned here , here ; SANS jumped in as well ), I decided to follow along and join the initiative. One of the bloggers called it...]]></description>
      <content:encoded><![CDATA[<p>Following the new "tradition" of posting a security tip of the week (mentioned <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2006/08/pay_it_forward__1.html">here</a>, <a href="http://mcwresearch.com/archives/265">here </a>; <a href="http://isc.sans.org/diary.php?storyid=1530&amp;rss">SANS jumped in as well</a>), I decided to follow along and join the initiative. One of the bloggers called it <a href="http://mcwresearch.com/archives/255">"pay it forward</a>" to the community.</p> <p>So, Anton Security Tip of the Day #15: <strong>Fear and Loathing in Event 567</strong></p> <p>This tip digs into a seemingly simple, but really <strong>VERY</strong> esoteric subject: monitoring file access and modification via a Windows event log. Now, some people - who never studied this subject - tend to have a very simplistic view of this: just enable Object Access auditing, then right-click on a file or directory, click Security-&gt;Advanced-&gt;Auditing and then pick what types of events will be logged and by what accessing entities (i.e. users or computers). OK, so this will produce some logs, that is for sure. But are they useful?</p> <p>First, why are we doing this? We typically need to know the following when we audit file access in Windows (or any other OS for that matter) for security (monitoring and investigation) or compliance:</p> <ul> <li>Time/date  <li>Computer where it happened  <li>User who touched the file  <li>Application he used to access the file  <li>File name + location (directory, share, etc) <li>Type of access (read, write, create, delete, etc)  <li>Status (i.e. success or failure)</li></ul> <p>Can we get this from the above logs? <strong>No.</strong></p> <p>What? No!?! Really? </p> <p>Yes, really. We can get some of the above, some of the time, not all of the above, all of the time. Here is an example, we are looking at event ID 560 (picture) and then at an extract from its description field.</p> <p><strong>Event:</strong></p> <p><a href="http://lh3.ggpht.com/anton.chuvakin/SCNkpVJituI/AAAAAAAADsE/q69WO589Oi4/s1600-h/event_log-560_1%5B2%5D.jpg"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="244" alt="event_log-560_1" src="http://lh4.ggpht.com/anton.chuvakin/SCNkplJitvI/AAAAAAAADsQ/XLlhnpafFgM/event_log-560_1_thumb.jpg?imgmax=800" width="235" border="0"></a> </p> <p><strong>Description (selected field):</strong></p> <p><em>Object Server</em>: Security <p><em>Object Type</em>: File <p><em>Object Name</em>: C:\0\TestBed\simple_text_file.txt <p><em>Image File Name</em>: C:\WINDOWS\system32\notepad.exe <p><em>Primary User Name</em>: Anton <p><em>Primary Domain</em>: XXXXXX <p><em>Accesses</em>: READ_CONTROL  <p>SYNCHRONIZE  <p>ReadData (or ListDirectory)  <p>WriteData (or AddFile)  <p>AppendData (or AddSubdirectory or CreatePipeInstance)  <p>ReadEA  <p>WriteEA  <p>ReadAttributes  <p>WriteAttributes <p>&nbsp; <p>WTH is that? Well, we know that the user&nbsp; 'Anton' has successfully read? wrote? changed attributes? did something? with a file named "C:\0\TestBed\simple_text_file.txt" using a program named "C:\WINDOWS\system32\notepad.exe." <strong>That's the best we can get, in this case!</strong> We may try to look at event IDs 562 and 567, but this missing information (i.e. the exact action performed) will not be added. <p>BTW, there will be&nbsp; a few more dozen (sometime hundreds!) of the 560s, 562s and 567s&nbsp; produced - all from just opening the text file in a notepad. The above event is notable for having BOTH "notepad" and "simple_text_file.txt" in the same event; others will have either of the two. <p>Anything else gets in the way? Yes, lots! MS Office will write to all files, even just opened for reading (with no user modifications to the content whatsoever), which will screw up your log monitoring efforts. If the file is on a share, more information will be missing (e.g. username might be).</p> <p>So, how to use Windows event logs for file access tracking?</p> <ol> <li>Enable logging (as described above)</li> <li>Pick events 560 (most useful) and 562, 567 (useful too)</li> <li>Look for fun filenames that might be touched by the users (have a list of files and users handy)</li> <li>Figure out what programs were used to access them (this is called "Image File Name" in "WinLogSpeak")</li> <li>Ponder the <em>'Accesses'</em> section of each event until your brain turns blue :-) or until you decide whether such access is authorized or not...</li></ol> <p>Overall, this is still very useful for file access monitoring, but the process is paaaaaainful.</p> <p>BTW, I am tagging all the tips on <a href="http://del.icio.us/anton18">my del.icio.us feed</a>. Here is the link: <a href="http://del.icio.us/anton18/security+tips">All Security Tips of the Day</a>.</p> <p> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:54499c21-dd11-4ff7-9221-4cf2ec0c95fe" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/security" rel="tag">security</a>, <a href="http://technorati.com/tags/tips" rel="tag">tips</a>, <a href="http://technorati.com/tags/logging" rel="tag">logging</a>, <a href="http://technorati.com/tags/log%20management" rel="tag">log management</a></div></p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=9dUZiH"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=9dUZiH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Uo2SKH"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Uo2SKH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=WZBXTH"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=WZBXTH" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/286335291" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 08 May 2008 09:37:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/text file">text file</category>
      <category domain="http://securityratty.com/tag/0testbedsimple text file">0testbedsimple text file</category>
      <category domain="http://securityratty.com/tag/audit file access">audit file access</category>
      <category domain="http://securityratty.com/tag/file access">file access</category>
      <category domain="http://securityratty.com/tag/simple text file">simple text file</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/anton security tip">anton security tip</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/286335291/anton-security-tip-of-day-15-fear-and.html">Anton Security Tip of the Day #15: Fear and Loathing in Event 560 (and 562 and 567)</source>
    </item>
    <item>
      <title><![CDATA[Confidential information sent to PinPay.net and SoftCard.biz is exposed]]></title>
      <link>http://securityratty.com/article/27cbd575cc28534b9ca368f27ad75124</link>
      <guid>http://securityratty.com/article/27cbd575cc28534b9ca368f27ad75124</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/29/08

Organization
ACAP Security Inc

Contractor/Consultant/Branch
PinPay
SoftCard

Victims
Merchants, Agents and customers

Number Affected
Unknown
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/pinpay.jpg" align="right" height="200" width="178"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/29/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.acapsecurity.com">ACAP Security Inc.</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.pinpay.net/index.html">PinPay</a> <br><a href="http://www.softcard.biz/indexaa.html">SoftCard</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Merchants, Agents and customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>Name, mailing address, phone number, email address, date of birth, city of birth, sex, and one or more of the following (chosen from drop-down):<br><br></font><ul><li><font size="2">Passport</font></li><li>Voting ID card</li><li>PAN card</li><li>Driving License card</li><li>Government issued ID card</li><li>Social Security Card</li><li>Military ID card</li><li>Consular ID card</li><li>Postal ID card</li><li>Government Employee ID Card</li><li>Credit Card</li><li>Debit Card<br></li></ul><font size="2"><br><span style="font-weight: bold;">Breach Description:</span><br>ACAP Security and affiliated sites are actively marketing a "secure payment system that allows Internet-based businesses to accept secure PIN-debit card payments and transactions at their online store."&nbsp; The PinPay and SoftCard sign-up pages and account access pages are not adequately secured with encryption, potentially exposing extremely sensitive personal information.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.merchant911.org/blog/index.php/2008/05/05/softcard-vendor-exposing-card-numbers/">Merchant 911 Blog</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Tom Mahoney, the Founder and Director of Merchant 911<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above and my own cursory investigation:<br><br>Back in January, I had short email dialog with a Kip Long, who claimed to be one of the principles of a company called Softcard out of Huntington Beach, CA. They are not to be confused with SoftCard Systems in Athens, GA. As far as I know, SoftCard Systems is a legitimate company with a legitimate product.<br><br>Mr. Long was rather aggressively, but not very successfully, trying to impress me with their product - from what I can make of it, a virtual PIN based card.<br><br>The company uses PinPay - to process transactions and both companies are a part of ACAP Security, Inc.. <br><br>I reviewed their site for possible inclusion in our website’s resource pages, but promptly rejected them.<br><br>their insecure sign-up form - was requesting “Identity Card Numbers” and issue dates. <br><span style="font-style: italic;">[Evan] The sign-up forms at SoftCard.biz and PinPay.net are not secure.&nbsp; Neither are their respected login pages.</span><br><br>“Identity cards” are selectable from a drop down menu and include such ID information as Passport, Driver’s license, SSN, and Credit Card. <br><br>The form also requires a full name and DOB.<br><br>I tried using the HTTPS URL but it appears that they do not have a security certificate tied to their site.<br><br>The fact that Mr. Long used a hotmail address to pitch the company made me wonder too, given that at Merchant911 we try to instill in our members that a free email address from a customer is a fraud alert.<br><br>If a company official can’t use his company’s domain for email, I’m not going to talk to him.<br><br>I called their attention to the insecure web form in January. They still have the form up there, happily collecting this information with an insecure form.<br><span style="font-style: italic;">[Evan] I also sent emails and heard nothing in return.</span><br><br>I have to wonder how much information has already been sniffed or otherwise compromised. You probably don’t want to fill out this form.<br><span style="font-style: italic;">[Evan] My advice would be to <span style="font-weight: bold;">NOT </span>fill out the form and <span style="font-weight: bold;">NOT </span>conduct business with a company that has not demonstrated a willingness to secure your information.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>Tom informed me about this vulnerability (and potentially a breach for anyone that signed-up/in) a couple of weeks ago.&nbsp; I've been a little busy lately, but was finally able to check it out.&nbsp; Let me recap what I found.<br><br>First, let's go to <a href="http://www.softcard.biz.%C2%A0">www.softcard.biz.</a> This is the site that Tom originally pointed out to me.<br><br><img src="http://images.quickblogcast.com/95781-88451/softcardhome.jpg" border="0" width="485"><br><br>The flash home page forwards visitors to a static index (indexaa.html) page.&nbsp; The first paragraph on the page informs visitors about PinPay.<br><br>"The PINPAY SoftCard is a wise way to carry and transfer money. It gives you the ability to purchase products at participating stores throughout the world (as well as at online shopping malls), with the security of a PIN that travels the internet via private encrypted tunnels. It also allows you the ability to load money to your card, pay bills, transfer money to merchants, transfer money between cards, and withdraw cash from your card at the store."<br><br><img src="http://images.quickblogcast.com/95781-88451/registerforfree.jpg" border="0" width="574"><br><br>See where the page says, "Register for your FREE card HERE!!"?&nbsp; This is a link to the sign-up page that Tom was referring to.<br><br><img src="http://images.quickblogcast.com/95781-88451/signupurl.jpg" border="0" width="304"><br><br>No "https" in the URL.&nbsp; Tom was right on that.&nbsp; The sign-up form asks for a personal information ranging from name and address to identity card information (even information for a "Second Identity Card").<br><br><img src="http://images.quickblogcast.com/95781-88451/form.jpg" border="0" width="431"><br><br>The "Select Identity Card" drop down menu displays the choices for the prospective customer, including Passport, Voting ID card, PAN card, Drivers License card, Government issued ID card, Social Security card, Military ID card, Consular ID card, Postal ID card, Government Employee ID Card, Credit Card and Debit Card<br><br><img src="http://images.quickblogcast.com/95781-88451/dropdown.jpg" border="0" width="459"><br><br>SoftCard (or PinPay or ACAP Security) are asking for some very sensitive personal information!&nbsp; First, this is quite a bit more information than they need to approve a person for a "PINPAY SoftCard".&nbsp; Second, no encryption?!&nbsp; Third, who is ACAP/SoftCard/PinPay and what will they do to secure my information once they have it supposing it wasn't intercepted on the way to them?<br><br>Let's dig a little (public) information about ACAP Security.&nbsp; According to <a href="http://www.entrepreneur.com/tradejournals/article/120829630.html">Entreprenuer.com</a>, ACAP launched "Personal Private Network" (ppn) technology, commercially available under the trade name ppnPRO, which is described as a "highly secure, and highly private" personal private network.&nbsp; ppnPRO uses "Government approved AES encryption, with strong personalized 256-bit encryption keys, and encrypting all information- network addresses, applications and ports, as well as the confidential data content".&nbsp; Sounds impressive, but it also sounds like the company should know a thing or two about securing web site transactions with encryption.&nbsp; <br><br>I want to discuss the risk of sending confidential private information over a public network such as the internet without encryption, in particular.&nbsp; This is not a new topic, but I will take some time to demonstrate the risk.<br><br>In order for my information to be compromised, someone (or something) will need to capture the traffic.&nbsp; In order for someone to capture my traffic, they will need to tap into the communication somewhere between me (my computer) and the destination (the web server).&nbsp; My information doesn't travel directly from my computer to the server.&nbsp; There are intermediaries (routers, switches, firewalls, etc.) that have to get (or forward) my information from my computer to the server.<br><br><img src="http://images.quickblogcast.com/95781-88451/trace.jpg" border="0" width="575"><br><br>As you can see depicted in the graphic above, there are at least 16 routers (or hops) between this example source and <a href="http://www.softcard.biz.%C2%A0">www.softcard.biz.&nbsp;</a> The final few hops are not reported due to filtering.&nbsp; So where could my traffic be captured?&nbsp; At the very least:<br><br></font><ul><li><font size="2">Between my computer and my router (or firewall)</font></li><li>Between my firewall and the ISP hand-off</li><li>Between all the traversed devices within my ISP's network</li><li>Between all the traversed devices through the internet</li><li>Between all the traversed devices within the destination ISP's network</li><li>Between all the traversed devices within the destination organization's network and the server itself.<br></li></ul><font size="2">Anyone in the communication path can use a simple protocol analyzer like <a href="http://www.wireshark.org">Wireshark</a> and capture the sensitive information:<br><br>txtfname=Billy&amp;txtmname=J&amp;txtlname=Madison&amp;txtaddress=123+Main+Street&amp;txtcity=Anywhere&amp;<br>txtstate=MA&amp;txtzip=87451&amp;txtcountry=United+States&amp;mob_phone=NONE&amp;txtphone=18006218200&amp;<br>txtemail=billymadison@honky.com&amp;txtdob=04%2F20%2F1988&amp;txtbirthcity=Boston&amp;<br>txtbirthcountry=United+States&amp;txtgender=M&amp;identity1=Social+Security+Card&amp;txtcardno1=123-45-6789&amp;<br>txtissuedate1=04%2F20%2F1988&amp;identity2=Driving+License+card&amp;txtcardno2=M-1234567890&amp;<br>txtissuedate2=04%2F20%2F2006&amp;submit=Accept+Card+Agreement-Submit<br><br>This is a very simplistic demonstration about why it is important to encrypt sensitive information.&nbsp; If the communication had been encrypted, none of the data would have been visible without access to the private key.<br><br>We could go deeper into the server application and SQL, but I think that this is enough.<br><br>A Quote from the ACAP Security CEO:<br></font>“The right of privacy is a fundamental
          and very important right of American society. A right our Nation’s
          founders fought the American Revolution to obtain and a right many
          brave American soldiers have fought and continue to fight and die
          to preserve. As this Nation continues to advance into cyberspace, we
          have
          expanded the right of privacy to include the right to electronic privacy.
          The elements of cyber-crime and cyber-vulnerabilities have begun to
          seriously erode and destroy this important right of electronic privacy.”<br><font size="2"><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/08/pinpay.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 08 May 2008 09:26:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/drivers license card">drivers license card</category>
      <category domain="http://securityratty.com/tag/license card">license card</category>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/free card">free card</category>
      <category domain="http://securityratty.com/tag/social security card">social security card</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/encrypt sensitive information">encrypt sensitive information</category>
      <source url="http://breachblog.com/2008/05/08/pinpay.aspx">Confidential information sent to PinPay.net and SoftCard.biz is exposed</source>
    </item>
  </channel>
</rss>
