<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: subscribers]]></title>
    <link>http://securityratty.com/tag/subscribers</link>
    <description></description>
    <pubDate>Wed, 13 Aug 2008 04:08:43 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Who's been reading my cell-phone records?]]></title>
      <link>http://securityratty.com/article/61a629c1b3a7c8a5848e18a686b03254</link>
      <guid>http://securityratty.com/article/61a629c1b3a7c8a5848e18a686b03254</guid>
      <description><![CDATA[If Verizon Wireless employees could snoop into then-U.S. Senator Barack Obama's cell-phone records, as the carrier acknowledged last week, then mobile subscribers may worry how well protected they...]]></description>
      <content:encoded><![CDATA[If Verizon Wireless employees could snoop into then-U.S. Senator Barack Obama's cell-phone records, as the carrier acknowledged last week, then mobile subscribers may worry how well protected they are. They should, according to some industry analysts and privacy lawyers.]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cell-phone records">cell-phone records</category>
      <category domain="http://securityratty.com/tag/senator barack obama">senator barack obama</category>
      <category domain="http://securityratty.com/tag/verizon wireless employees">verizon wireless employees</category>
      <category domain="http://securityratty.com/tag/privacy lawyers">privacy lawyers</category>
      <category domain="http://securityratty.com/tag/mobile subscribers">mobile subscribers</category>
      <category domain="http://securityratty.com/tag/industry analysts">industry analysts</category>
      <category domain="http://securityratty.com/tag/then-u">then-u</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/carrier">carrier</category>
      <source url="http://www.networkworld.com/news/2008/112608-whos-been-reading-my-cell-phone.html?fsrc=rss-security">Who's been reading my cell-phone records?</source>
    </item>
    <item>
      <title><![CDATA[Who's been reading my cell-phone records?]]></title>
      <link>http://securityratty.com/article/e3c9a30250e86cd61df8dcee8927c3a6</link>
      <guid>http://securityratty.com/article/e3c9a30250e86cd61df8dcee8927c3a6</guid>
      <description><![CDATA[If Verizon Wireless employees could snoop into then-U.S. Senator Barack Obama's cell-phone records, as the carrier acknowledged last week, then mobile subscribers may worry how well protected they...]]></description>
      <content:encoded><![CDATA[If Verizon Wireless employees could snoop into then-U.S. Senator Barack Obama's cell-phone records, as the carrier acknowledged last week, then mobile subscribers may worry how well protected they are. They should, according to some industry analysts and privacy lawyers.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:b5bff7b094bee1a10073df41944a1c42:urSjCSmrefF6KJC55Lne0YZXqdmHXF2ZQO77LY0aHtIlU9z86tOrn%2FOLCnE1sp3zU72n7MWdvlFc'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:fe47304bd402478bfc235225aca81c25:5rZNlgtAyS7ZOPjz9C2F94P13DSktdC3gYRXIS8%2FWbGgijKSWrUf4nkqVGmj0rCeLHO%2B%2FqlcaJhpQg%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:0386c575047e4896b76ae001c1664dca:H9mHKDOAJ8ZHlS7yykLm1MSJF2r0pn1c3YwroxZsCdBmeridiPJZV2XSsE8lsGpW0D2bO9DhkQY%2Bqw%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:0328ac826ce89c8b74f7ed370388d1ea:ao6ccTQxQZ%2FY44HEaDpNvLBVBHE0kyvh8VfHH1VogdRuB5gQbWVsRaW8id%2B7JK%2Bx5Vr7MRP7Q9VtrQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=54cbefad9599ad3897e68c5b32747300&amp;p=1"><img style="border:0;" src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=54cbefad9599ad3897e68c5b32747300&amp;p=1" border="0" /></a>
]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cell-phone records">cell-phone records</category>
      <category domain="http://securityratty.com/tag/senator barack obama">senator barack obama</category>
      <category domain="http://securityratty.com/tag/verizon wireless employees">verizon wireless employees</category>
      <category domain="http://securityratty.com/tag/privacy lawyers">privacy lawyers</category>
      <category domain="http://securityratty.com/tag/mobile subscribers">mobile subscribers</category>
      <category domain="http://securityratty.com/tag/industry analysts">industry analysts</category>
      <category domain="http://securityratty.com/tag/then-u">then-u</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/carrier">carrier</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=54cbefad9599ad3897e68c5b32747300">Who's been reading my cell-phone records?</source>
    </item>
    <item>
      <title><![CDATA[Bug allowed free access to Sirius radio service]]></title>
      <link>http://securityratty.com/article/6c9926b0dfff0e6c94047521fcc9165f</link>
      <guid>http://securityratty.com/article/6c9926b0dfff0e6c94047521fcc9165f</guid>
      <description><![CDATA[Sirius XM Radio has quietly fixed a bug in its satellite radio system that provided a way for former subscribers to gain free access to the Sirius service since 2002, according to security vendor...]]></description>
      <content:encoded><![CDATA[Sirius XM Radio has quietly fixed a bug in its satellite radio system that provided a way for former subscribers to gain free access to the Sirius service since 2002, according to security vendor TippingPoint Technologies.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=79078?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=79078?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Sun, 23 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/radio">radio</category>
      <category domain="http://securityratty.com/tag/sirius">sirius</category>
      <category domain="http://securityratty.com/tag/satellite radio system">satellite radio system</category>
      <category domain="http://securityratty.com/tag/gain free access">gain free access</category>
      <category domain="http://securityratty.com/tag/sirius service">sirius service</category>
      <category domain="http://securityratty.com/tag/quietly fixed">quietly fixed</category>
      <category domain="http://securityratty.com/tag/bug">bug</category>
      <category domain="http://securityratty.com/tag/subscribers">subscribers</category>
      <source url="http://www.networkworld.com/news/2008/112408-bug-allowed-free-access-to.html?fsrc=rss-security">Bug allowed free access to Sirius radio service</source>
    </item>
    <item>
      <title><![CDATA[Sierra Leone minister calls for SIM card registration]]></title>
      <link>http://securityratty.com/article/040160ab87dca47520e8a102065fc164</link>
      <guid>http://securityratty.com/article/040160ab87dca47520e8a102065fc164</guid>
      <description><![CDATA[Sierra Leone Information and Communication Minister Alhaji Ibrahim Ben Kargbo called on mobile-phone companies to register subscribers' SIM (Subscriber Identity Module) cards at a press briefing last...]]></description>
      <content:encoded><![CDATA[Sierra Leone Information and Communication Minister Alhaji Ibrahim Ben Kargbo called on mobile-phone companies to register subscribers' SIM (Subscriber Identity Module) cards at a press briefing last week.]]></content:encoded>
      <pubDate>Mon, 03 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/subscriber identity module">subscriber identity module</category>
      <category domain="http://securityratty.com/tag/sierra leone information">sierra leone information</category>
      <category domain="http://securityratty.com/tag/sim">sim</category>
      <category domain="http://securityratty.com/tag/register subscribers">register subscribers</category>
      <category domain="http://securityratty.com/tag/mobile-phone companies">mobile-phone companies</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/kargbo">kargbo</category>
      <category domain="http://securityratty.com/tag/cards">cards</category>
      <category domain="http://securityratty.com/tag/press">press</category>
      <source url="http://www.networkworld.com/news/2008/110408-sierra-leone-minister-calls-for.html?fsrc=rss-security">Sierra Leone minister calls for SIM card registration</source>
    </item>
    <item>
      <title><![CDATA[FoxNews Commentator`s BillOreilly.com Website Hacked, Subscribers Personal Details Published]]></title>
      <link>http://securityratty.com/article/ce650ea91dc6b6d3885bd71073872bdf</link>
      <guid>http://securityratty.com/article/ce650ea91dc6b6d3885bd71073872bdf</guid>
      <description><![CDATA[Unknown intruders have hacked the website of conservative commentator Bill OReilly and posted personal details of more than 200 of its subscribers. The breach into BillOreilly.com came as retaliation...]]></description>
      <content:encoded><![CDATA[Unknown intruders have hacked the website of conservative commentator Bill O&#8217;Reilly and posted personal details of more than 200 of its subscribers. The breach into BillOreilly.com came as retaliation for remarks O&#8217;Reilly made on FoxNews condemning the attack on Palin&#8217;s Yahoo email account, according to Wikileaks, a site that makes it easy for hackers and [...]]]></content:encoded>
      <pubDate>Sat, 20 Sep 2008 17:53:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/personal details">personal details</category>
      <category domain="http://securityratty.com/tag/website">website</category>
      <category domain="http://securityratty.com/tag/billoreilly">billoreilly</category>
      <category domain="http://securityratty.com/tag/unknown intruders">unknown intruders</category>
      <category domain="http://securityratty.com/tag/remarks oreilly">remarks oreilly</category>
      <category domain="http://securityratty.com/tag/foxnews">foxnews</category>
      <category domain="http://securityratty.com/tag/subscribers">subscribers</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <source url="http://cyberinsecure.com/foxnews-commentator-billoreilly-website-hacked-subscribers-personal-details-published/">FoxNews Commentator`s BillOreilly.com Website Hacked, Subscribers Personal Details Published</source>
    </item>
    <item>
      <title><![CDATA[AT&T Extends Free Wi-Fi to Cheapest DSL Plans]]></title>
      <link>http://securityratty.com/article/856e4c3817e07dfbb28fe42f32fd57e9</link>
      <guid>http://securityratty.com/article/856e4c3817e07dfbb28fe42f32fd57e9</guid>
      <description><![CDATA[AT&amp;T seems to have added free Wi-Fi for its lowest-priced DSL customers: The Atlanta Journal-Constitution is the only one with this story, and they've garbled a few of the details, but checking AT&amp;T's...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.ajc.com/business/content/business/stories/2008/09/16/att_internet_service.html"><strong>AT&T seems to have added free Wi-Fi for its lowest-priced DSL customers:</strong></a> The Atlanta Journal-Constitution is the only one with this story, and they've garbled a few of the details, but checking AT&T's public sites seems to confirm it. Previously, AT&T customers had to either have a fiber-optic U-Verse subscription, or a DSL line running at 1.5 Mbps downstream or faster to get free Wi-Fi Basic. The Basic pool covers most of the 17,000 U.S. hotspots, excluding some hotels and premium locations.</p>

<p>AT&T <a href="http://www.att.com/gen/general?pid=5949"><strong>now says</strong></a> that any "FastConnect" subscription, even its DSL Lite offering of 768 Kbps down/128 Kbps up, qualifies for Wi-Fi Basic. The new statement reads: "AT&T Wi-Fi Basic service is FREE and already included if you subscribe to AT&T High Speed Internet, AT&T U-verseSM High Speed Internet, or AT&T FastAccess&reg; DSL&mdash;all speed plans included.</p>

<p>There's still a $10 per month fee to upgrade to Wi-Fi Premier, which includes over 70,000 locations worldwide, along with the missing U.S. hotspots, but their Web site says that you have to have a 1.5 Mbps or faster connection to get the $10 per month upgrade. That may be out of date. That ordering page also says you need 1.5 Mbps or faster for free Wi-Fi, so that tends to confirm it hasn't been fixed. (It's even hosted at sbc.com, so perhaps that's part of the vestige of an older system, harder to update.)</p>

<p>Please note that iPhone subscribers still don't get free Wi-Fi on AT&T's Basic network.</p>]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 09:30:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <category domain="http://securityratty.com/tag/free wi-fi basic">free wi-fi basic</category>
      <category domain="http://securityratty.com/tag/att">att</category>
      <category domain="http://securityratty.com/tag/att customers">att customers</category>
      <category domain="http://securityratty.com/tag/att u-versesm">att u-versesm</category>
      <category domain="http://securityratty.com/tag/wi-fi basic">wi-fi basic</category>
      <category domain="http://securityratty.com/tag/speed internet">speed internet</category>
      <category domain="http://securityratty.com/tag/faster">faster</category>
      <source url="http://wifinetnews.com/archives/008445.html">AT&amp;T Extends Free Wi-Fi to Cheapest DSL Plans</source>
    </item>
    <item>
      <title><![CDATA[Zune Owners Get Free Wi-Fi at McDonald's]]></title>
      <link>http://securityratty.com/article/2afb17aca42cecdef0eb17c5e5e72ced</link>
      <guid>http://securityratty.com/article/2afb17aca42cecdef0eb17c5e5e72ced</guid>
      <description><![CDATA[Microsoft signs three-year deal with Wayport for old and new Zune owners alike: This is a nice win for Zune users, Wayport, and McDonald's, each in their own way, and it's something Microsoft can...]]></description>
      <content:encoded><![CDATA[<p><strong>Microsoft signs three-year deal with Wayport for old and new Zune owners alike:</strong> This is a nice win for Zune users, Wayport, and McDonald's, each in their own way, and it's something Microsoft can simply write off as useful marketing--and a way to get people to try the latest models of their music player, which are being released on 16-September.</p>

<p>The Zune doesn't include a Web browser or any Internet focused features; it's not an iPod touch. But you can use Wi-Fi to browse the Zune Marketplace for music and games, and download new songs in programmed channels, music selections created by a variety of artists and stations. Zune offers both music purchases and a subscription for unlimited music listening. The new models range from $149 for an 8 GB flash model to $249 for a 120 GB hard drive-based player.</p>

<p>The feature I'm most interested in is Buy from FM, which leverages the built-in FM tuner and very low-bandwidth data that's already pushed over analog AM/FM. (See <strong><a href="http://wifinetnews.com/archives/008432.html">my write-up of this feature</a></strong> from last week.) With Buy from FM, when you're listening to radio stations that participate, you'll be able to click a button and buy the song you're listening to if you're connected to a Wi-Fi network. Zune Pass subscribers can download the song at no additional charge. If there's no Wi-Fi network, the song download or purchase is queued.</p>

<p><img src="http://wifinetnews.com//images/2008/new_zune.jpg" alt="new_zune.jpg" border="0" width="137" height="256" align="right" />Wayport's marketing head Dan Lowden said, "Obviously, it's cool because folks who already own a Zune device and just need to do an upgrade will be able to use this just as with any of the new Zune devices that they start selling as soon as possible." (Microsoft may have a little accounting work to do: Sarbanes-Oxley doesn't let you enhance a product in the market without a fee if you realize the revenue all at once.)</p>

<p>The benefit for Wayport is to have yet another hefty but undisclosed fixed sum underlying its fixed infrastructure costs. In the past, Wayport has done deals with Nintendo, ZipIt, and Eye-Fi to allow all devices in a category unlimited access at McDonald's locations. McDonald's obviously gets more customers, or existing customers who spend more time or visit more frequently.</p>

<p>A partnership with a hotspot operator means that Microsoft doesn't have to provide tools and their users endure frustration in joining a network. "We're experts enabling one click to get this network connected," Lowden said. He noted that Wayport has opened test labs to work with manufacturers in Japan, San Francisco, San Diego, and Seattle. "We're working with these guys from day 1 to make sure it's one click to get connected," he said. I'd also note that San Diego happens to be where Qualcomm's headquarters are located, not that Lowden gave me any tip-off there. </p>

<p>And I have to just say: burn, burn, burn on Apple. Despite Apple partnership with AT&T, which relies on Wayport to operate the AT&T-branded hotspot network and resells access to Wayport's own network, iPhone and iPod touch users have no inclusive Wi-Fi service. AT&T slipped a few times and ostensibly opened up their network or released details that iPhone users would gain free hotspot access--like all AT&T's fiber and all its standard and premium DSL customers. </p>

<p>As Wi-Fi becomes an expected part of any handheld gadget, the venues in which Wi-Fi is used multiply beyond cafes and hotels. Lifestyle locations--which could be clothing stores, nightclubs, ski resorts, and the tops of mountains suddenly become places where people want the same kind of access they have at home. Ultima thule is already unwired.</p>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 23:01:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/zune">zune</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/zune pass subscribers">zune pass subscribers</category>
      <category domain="http://securityratty.com/tag/inclusive wi-fi service">inclusive wi-fi service</category>
      <category domain="http://securityratty.com/tag/zune offers">zune offers</category>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <category domain="http://securityratty.com/tag/zune devices">zune devices</category>
      <category domain="http://securityratty.com/tag/wi-fi network">wi-fi network</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <source url="http://wifinetnews.com/archives/008440.html">Zune Owners Get Free Wi-Fi at McDonald's</source>
    </item>
    <item>
      <title><![CDATA[Cablevision Activates Major Areas of Its Wi-Fi Network]]></title>
      <link>http://securityratty.com/article/40a07e9654a39fb5503761a8d723e3f9</link>
      <guid>http://securityratty.com/article/40a07e9654a39fb5503761a8d723e3f9</guid>
      <description><![CDATA[New York area cable operator Cablevision flips switch for high-traffic areas of Long Island: They're announcing Thursday that they've turned on the initial phases of their network in Nassau and...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/muni_icon.jpg" align="right" border="0" hspace="5" /><strong>New York area cable operator Cablevision flips switch for high-traffic areas of Long Island:</strong> They're announcing Thursday that they've turned on the initial phases of their network in Nassau and Suffolk counties, as well as at commuter rail platforms and station parking lots throughout Long Island. The service offers 1.5 Mbps in each direction, the company claims. Detailed site maps for their previous much smaller activated areas are up at <a href="http://www.optimumwifi.com/"><strong>their Wi-Fi information site</strong></a>, and I expect to see these updated soon.</p>

<p>Cablevision will ultimately spend about $300m in building a Wi-Fi network exclusively for its customers; 2.4m of these customers qualify to use the service at no cost. There's no pay as you go option, no monthly subscription; you're either a subscriber of theirs, or not. It's a fascinating strategy, because they're leveraging all these dollars as a tool to crack its competitors in the market. With increasing competition from telephone companies that are offering television service, cable companies need to compete on voice, data, and video, as well as well as on mobile offerings. When the network is built, Cablevision can conceivably offer Wi-Fi telephony service, too.</p>

<p>I'm dying to know what the reduced churn rate and increase in subscriptions will be in six months. Given that hotspot access costs $10 to $30 per month depending on the network, Cablevision is delivering something of value. It's great honey for new subscribers and glue to keep current subscribers.</p>

<p>The company is claiming that with this latest activation, they have the largest Wi-Fi network for consumers in the U.S. They're likely correct. The only other public access network of scale that's being used by large numbers is in Minneapolis, and based on what I know about both networks, Cablevision probably deserves bragging rights. The network in Taipei, Taiwan, is likely still larger, but I haven't heard any usage number in nearly two years; at that point, subscription rates were 10 percent of what had been projected.</p>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 17:01:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wi-fi network">wi-fi network</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/wi-fi network exclusively">wi-fi network exclusively</category>
      <category domain="http://securityratty.com/tag/cablevision">cablevision</category>
      <category domain="http://securityratty.com/tag/public access network">public access network</category>
      <category domain="http://securityratty.com/tag/service offers">service offers</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/hotspot access costs">hotspot access costs</category>
      <category domain="http://securityratty.com/tag/television service">television service</category>
      <source url="http://wifinetnews.com/archives/008429.html">Cablevision Activates Major Areas of Its Wi-Fi Network</source>
    </item>
    <item>
      <title><![CDATA[A Change of Plan For Your Spam]]></title>
      <link>http://securityratty.com/article/20c092cee1e4a4187f4915c282e35789</link>
      <guid>http://securityratty.com/article/20c092cee1e4a4187f4915c282e35789</guid>
      <description><![CDATA[Someone really has to reign me in with these titles. Anyway, you may or may not have heard that the CNN spam mails have now morphed into mails that appear to come from Msnbc.com instead. The titles of...]]></description>
      <content:encoded><![CDATA[
        Someone really has to reign me in with these titles. Anyway, you may or may not have heard that the <a href="http://blog.spywareguide.com/2008/08/cnn-daily-top-10-videos-spam.html">CNN spam mails</a> have now morphed into mails that appear to come from Msnbc.com instead. The titles of the emails are still as insane as ever:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="msb1.jpg" src="http://blog.spywareguide.com/images/msb1.jpg" class="mt-image-none" style="" height="37" width="395" /></span></div><br /> <div><br />......uh, wow. The email will take you to a fake Flash download, just like the previous efforts:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/msb2.html" onclick="window.open('http://blog.spywareguide.com/images/msb2.html','popup','width=949,height=534,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/msb2-thumb-349x196.jpg" alt="msb2.jpg" class="mt-image-none" style="" height="196" width="349" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />Obviously, they haven't gotten around to making fake Msnbc pages so for now we're still stuck with the fake CNN pages.<br /><br />An odd side-effect of these emails is that they're likely lowering subscriber numbers for CNN and Msnbc, because the emails contain genuine unsubscribe links at the bottom:<br /><br /><div align="left"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="msb3.jpg" src="http://blog.spywareguide.com/images/msb3.jpg" class="mt-image-none" style="" height="209" width="555" /></span></div><br /></div><div><br />I doubt the creators of these scam mails intended that - they're just wanting to make the mails look realistic - but I could imagine disgruntled subscribers wondering why CNN and Msnbc keep sending them these things then reaching for the "no more, please!" link...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 11:42:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cnn spam mails">cnn spam mails</category>
      <category domain="http://securityratty.com/tag/mails">mails</category>
      <category domain="http://securityratty.com/tag/cnn">cnn</category>
      <category domain="http://securityratty.com/tag/fake cnn pages">fake cnn pages</category>
      <category domain="http://securityratty.com/tag/msnbc">msnbc</category>
      <category domain="http://securityratty.com/tag/fake msnbc pages">fake msnbc pages</category>
      <category domain="http://securityratty.com/tag/scam mails">scam mails</category>
      <category domain="http://securityratty.com/tag/genuine unsubscribe links">genuine unsubscribe links</category>
      <category domain="http://securityratty.com/tag/fake flash download">fake flash download</category>
      <source url="http://blog.spywareguide.com/2008/08/a-change-of-plan-for-your-spam.html">A Change of Plan For Your Spam</source>
    </item>
    <item>
      <title><![CDATA[76Service - Cybercrime as a Service Going Mainstream]]></title>
      <link>http://securityratty.com/article/35bdaf104e9aecf7703834d959f39050</link>
      <guid>http://securityratty.com/article/35bdaf104e9aecf7703834d959f39050</guid>
      <description><![CDATA[Disintermediating the intermediaries in the cybercrime ecosystem, ultimately results in more profitable operations. Controversial to the concept of outsourcing, some cybercriminals are in fact so...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKKs5L3ihpI/AAAAAAAACBs/vEaSMC2S8nI/s1600-h/76service.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKKs5L3ihpI/AAAAAAAACBs/qhgjQh39ej8/s200-R/76service.JPG" style="border: 0pt none ;" /></a>Disintermediating the intermediaries in the cybercrime ecosystem, ultimately results in more profitable operations. Controversial to the concept of outsourcing, some cybercriminals are in fact so self-sufficient, that the stereotype of a mysterious 76service server offered for rent could in fact easily cease to exist in an ecosystem so vibrant that literally everyone can partion their botnet and start offering access to it on a multi-user basis. Evil? Obviously. Extending the lifecycle of a proprietary malware tool? Definitely.<br />
<br />
<a href="http://www.youtube.com/watch?v=lw9IeuKkNbc">The infamous 76service</a>, a cybercrime as a service web interface where customers basically collect the final output out of the banking malware botnet during the specific period of time for which they've purchases access to the service, is going mainstream, with 76Service's Spring Edition apparently leaking out, and cybercriminals enjoying its interoperability potential by introducing different banking trojans in their campaigns. <br />
<br />
In this post, I'll discuss the 76service's spring.edition that has been combined with a <a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher banking malware</a>, an a popular <a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">web malware exploitation kit</a>, with two campaigns currently hosting 5.51GB of stolen banking data based on over 1 million compromised hosts 59% of which are based in Russia. Screenshots courtesy of an egocentric underground show-off.<br />
<br />
<a href="http://www.cio.com/article/print/135500">Some general info on the 76service</a> :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKyWAXgYGI/AAAAAAAACB0/JXHZFuBb6Rs/s1600-h/76service1.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKyWAXgYGI/AAAAAAAACB0/2qZfVy6YfU8/s200-R/76service1.JPG" style="border: 0pt none ;" /></a>"<i>Subscribers could log in with their assigned user name and     password any time during the 30-day project. They’d be     met with a screen that told them which of their bots was     currently active, and a side bar of management options. For     example, they could pull down the latest drops—data     deposits that the Gozi-infected machines they subscribed to     sent to the servers, like the 3.3 GB one Jackson had     found. A project was like an investment portfolio. Individual     Gozi-infected machines were like stocks and subscribers bought     a group of them, betting they could gain enough personal     information from their portfolio of infected machines to make a     profit, mostly by turning around and selling credentials on the     black market. (In some cases, subscribers would use a few of     the credentials themselves). Some machines, like some stocks, would under perform and     provide little private information. But others would land the     subscriber a windfall of private data. The point was to     subscribe to several infected machines to balance that risk,     the way Wall Street fund managers invest in many stocks to     offset losses in one company with gains in another.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKy5q1ebVI/AAAAAAAACB8/uGe8GuhDvRg/s1600-h/76service2.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKy5q1ebVI/AAAAAAAACB8/88IxypeBf74/s200-R/76service2.JPG" style="border: 0pt none ;" /></a>The 76service empowers everyone who is either not willing to spend time and resources for building and maintaining a botnet, launching campaigns, and SQL injecting hundreds of thousands of sites in order to take advantage of the long tail of malware infected sites that theoretically can outpace the traffic that could come from a SQL injected high-profile site.<br />
<br />
Next to the spring.edition, <a href="http://secureworks.com/research/threats/gozi/">the winter edition's price starts from $1000 and goes to $2000</a>, which is all a matter of who you're buying it from, unless of course you haven't come across leaked copies :<br />
<br />
"<i>Assuming that the dealer offering what he claimed was the 76service kit was correct, the profit is not only in the kit, but in selling value added services like exploitation, compromised servers/accounts, database configuration, and customization of the interface. Prices start between $1000 to $2000 and go up based on added services. The underground payment methods generally involve hard-to-track virtual currencies, whose central authority is in a jurisdiction where regulation is liberal to non-existent, and feature non-reversible transactions. The individual or group called "76service" was easy to track down on the Web, but not in person.</i>" <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKLUyA7g9LI/AAAAAAAACCE/nl-OA3FHPs0/s1600-h/76service3.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKLUyA7g9LI/AAAAAAAACCE/8zS6gcoEdvk/s200-R/76service3.JPG" style="border: 0pt none ;" /></a>It's interesting to monitor how services aiming to provide specific malicious services are vertically integrating by expanding their portfolio of related services -- taka a spamming vendor that will offer the segmented email databases, the advanced metrics, and the localization of the spam messages to different languages -- or letting the buyer have full control of anything that comes out of a particular botnet for a specific period of time in which he has bought access to it. For instance, DDoS for hire matured into botnet for hire, which evolved into today's "What type of stolen data do you want?" for hire mentality I'm starting to see emerging, next to the usual interest in improving the metrics and thereby the probability for a more succesful campaign. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKLa2TO4yAI/AAAAAAAACCM/4s3Mkgb-NOY/s1600-h/metafisher1_ukstories.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKLa2TO4yAI/AAAAAAAACCM/Bt7wKW7IPcE/s200-R/metafisher1_ukstories.jpg" style="border: 0pt none ;" /></a>Ironically, this cybercrime model is so efficient that the people behind it cannot seem to be able to process all of the stolen data, which like a great deal of underground assets loses its value if not sold as fast as possible. The result of this oversupply of stolen data are the increasing number of services selling raw logs segmented based on a particular country for a specific period of time.<br />
<br />
Time for a remotely exploitable vulnerability in yet another malware kit about to go mainstream? Definitely, unless of course backdooring it and releasing it doesn't achieve the obvious results of controlling someone else's cybercrime ecosystem.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Multiple Firewalls Bypassing Verification on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - The Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">Malware as a Web Service</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed "Spamming Appliances" - The Future of Spam</a><br />
<br />
<b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NWhwdK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NWhwdK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7zGnyK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7zGnyK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Rqgfok"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Rqgfok" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zA7GDk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zA7GDk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4r7WMK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4r7WMK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=880FjK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=880FjK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3wtOmk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3wtOmk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/363878623" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 04:08:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/76service">76service</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/malware botnet">malware botnet</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/mysterious 76service server">mysterious 76service server</category>
      <category domain="http://securityratty.com/tag/web service">web service</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/363878623/76service-cybercrime-as-service-going.html">76Service - Cybercrime as a Service Going Mainstream</source>
    </item>
  </channel>
</rss>
