<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: sunbelt]]></title>
    <link>http://securityratty.com/tag/sunbelt</link>
    <description></description>
    <pubDate>Thu, 12 Jun 2008 03:12:58 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[AOL Hosted Sites Distribute Malware]]></title>
      <link>http://securityratty.com/article/4a3128ea8d000bf53012678213df0d24</link>
      <guid>http://securityratty.com/article/4a3128ea8d000bf53012678213df0d24</guid>
      <description><![CDATA[Malware on AOL hosted pages has been recently reported by Alex Eckelberry from Sunbelt. It seems that it is not new and AOL is actually neglecting this issue, allowing visitors to get infected with...]]></description>
      <content:encoded><![CDATA[Malware on AOL hosted pages has been recently reported by Alex Eckelberry from Sunbelt. It seems that it is not new and AOL is actually neglecting this issue, allowing visitors to get infected with rogue software.
AOL’s German Hometown page has a number of pages that redirect to rogue antivirus programs like Antivirus XP (Do NOT [...]]]></content:encoded>
      <pubDate>Mon, 13 Oct 2008 23:21:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/aol">aol</category>
      <category domain="http://securityratty.com/tag/rogue antivirus programs">rogue antivirus programs</category>
      <category domain="http://securityratty.com/tag/antivirus">antivirus</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/alex eckelberry">alex eckelberry</category>
      <category domain="http://securityratty.com/tag/rogue software">rogue software</category>
      <category domain="http://securityratty.com/tag/pages">pages</category>
      <category domain="http://securityratty.com/tag/recently">recently</category>
      <category domain="http://securityratty.com/tag/visitors">visitors</category>
      <source url="http://cyberinsecure.com/aol-hosted-sites-distribute-malware/">AOL Hosted Sites Distribute Malware</source>
    </item>
    <item>
      <title><![CDATA[Current List Of Zlob Distributiuon Sites And Rogue Anti-virus Products Domains]]></title>
      <link>http://securityratty.com/article/920dcaaf490ddab376b087b9f06c94ac</link>
      <guid>http://securityratty.com/article/920dcaaf490ddab376b087b9f06c94ac</guid>
      <description><![CDATA[Sunbelt, a developer of protection software known for its Kerio firewall, has been publishing a list of domains which are involved in spreading of Zlob trojan and fake malware anti-virus known as...]]></description>
      <content:encoded><![CDATA[Sunbelt, a developer of protection software known for it&#8217;s Kerio firewall, has been publishing a list of domains which are involved in spreading of Zlob trojan and fake malware anti-virus known as Antivirus XP 2008 (and its clones). Domains from this list might infect visitors, considered malicious and should be added as untrusted into filters.
There [...]]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 12:35:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/fake malware anti-virus">fake malware anti-virus</category>
      <category domain="http://securityratty.com/tag/infect visitors">infect visitors</category>
      <category domain="http://securityratty.com/tag/zlob trojan">zlob trojan</category>
      <category domain="http://securityratty.com/tag/kerio firewall">kerio firewall</category>
      <category domain="http://securityratty.com/tag/protection software">protection software</category>
      <category domain="http://securityratty.com/tag/filters">filters</category>
      <category domain="http://securityratty.com/tag/clones">clones</category>
      <source url="http://cyberinsecure.com/current-list-of-zlob-distributiuon-sites-and-rogue-anti-virus-products-domains/">Current List Of Zlob Distributiuon Sites And Rogue Anti-virus Products Domains</source>
    </item>
    <item>
      <title><![CDATA[EstDomains & Intercage: A Perfect Couple in Crime]]></title>
      <link>http://securityratty.com/article/8490240982532919695d5c4c9231e15f</link>
      <guid>http://securityratty.com/article/8490240982532919695d5c4c9231e15f</guid>
      <description><![CDATA[If you track malware issues as readily as I do, you're likely aware of the failings of clownpacks like EstDomains and their hosting buddies Atrivo/Intercage. You need only follow Sunbelt's take on the...]]></description>
      <content:encoded><![CDATA[If you track malware issues as readily as I do, you're likely aware of the failings of clownpacks like EstDomains and their hosting buddies Atrivo/Intercage. You need only follow Sunbelt's <a href="http://www.google.com/search?hl=en&q=site%3Asunbeltblog.blogspot.com+estdomains+atrivo+intercage&btnG=Search" target="_blank">take</a> on the topic, or <a href="http://www.emergingthreats.net/index.php?searchword=intercage&option=com_search&Itemid=5" target="_blank">search</a> Emergingthreats to come up to speed.<br />Yesterday, EstDomains posted the most inept, ridiculous <a href="http://www.domainnews.com/en/general/estdomains-denies-links-to-malware-distribution.html" target="_blank">response</a> ever issued to the endless and worthy criticism, largely <a href="http://technewsreview.com.au/article.php?article=5882" target="_blank">leveled</a> by Brian Krebs at the Washington Post. <br />Not only can't these morons from EstDomains write, they're either so deeply clueless or flagrantly malicious (likely both), it's beyond laughable. This section sums it up best:<br /><span style="font-style:italic;">"The company also has a reliable ally in its battle against malware in a face of Intercage, Inc which provides company with the hosting services of the highest quality. But the outstanding performance of hosting services is not the sole reason why EstDomains, Inc appreciates this partnership so greatly. Intercage, Inc generously provides EstDomains, Inc specialists with reports regarding discovered malware vehicles. As the main database for additional domain name management services is located in Intercage Data Center, EstDomains, Inc has the perfect opportunity to get notifications of the slightest mark of malware presence in the shortest time and take measures in advance."</span><br /><span style="font-weight:bold;">What? Really?</span> <br />Again, aside from the absolute butchery of the language, did they just say <span style="font-style:italic;">"The company also has a reliable ally in its battle against malware in a face of Intercage, Inc which provides company with the hosting services of the highest quality."</span>? SIGH...yes, they did.<br /><br />Allow me to exemplify just how ridiculous a claim that is.<br />Following is content from a packet capture I took during a recent Storm worm analysis.<br /><br />Using the ip2asn module included in <a href="http://writequit.org/projects/nsm-console/" target="_blank">NSM-console</a> availabe in <a href="http://www.rawpacket.org/projects/hex" target="_blank">HeX</a>, we find:<br />27595   | 216.255.189.211  | INTERCAGE - InterCage, Inc.<br /><br />Using Etherape, also included in <a href="http://www.rawpacket.org/projects/hex" target="_blank">HeX</a>, we see:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SM880rNW5JI/AAAAAAAAACs/dWY8MUgSMUU/s1600-h/etherape_intercage.png"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SM880rNW5JI/AAAAAAAAACs/dWY8MUgSMUU/s320/etherape_intercage.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5246478966559532178" /></a><br /><br />Using <a href="http://networkminer.wiki.sourceforge.net/NetworkMiner" target="_blank">Eric Hjelmvik's</a> <a href="http://holisticinfosec.org/toolsmith/docs/august2008.pdf" target="_blank">NetworkMiner</a>, we see:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_kVOWaY1TAF0/SM8-JQvlEKI/AAAAAAAAAC0/vjYvpHAoFDw/s1600-h/NetworMiner_intercage.png"><img style="cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_kVOWaY1TAF0/SM8-JQvlEKI/AAAAAAAAAC0/vjYvpHAoFDw/s320/NetworMiner_intercage.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5246480419744190626" /></a><br /><br />See the recurring theme? Intercage, EstDomain's <span style="font-style:italic;">"reliable ally in its battle against malware"</span>.<br />Nice work, guys...keep it up.<br /><br />I'm submitting this to <a href="http://thedailywtf.com/" target="blank">The Daily WTF</a> as we speak.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html&title=EstDomains%20&%20Intercage:%20A%20Perfect%20Couple%20in%20Crime " title="EstDomains & Intercage: A Perfect Couple in Crime ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html" title="EstDomains & Intercage: A Perfect Couple in Crime ">digg</a>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 17:32:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/intercage">intercage</category>
      <category domain="http://securityratty.com/tag/estdomains">estdomains</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware presence">malware presence</category>
      <category domain="http://securityratty.com/tag/intercage data center">intercage data center</category>
      <category domain="http://securityratty.com/tag/track malware issues">track malware issues</category>
      <category domain="http://securityratty.com/tag/reliable ally">reliable ally</category>
      <category domain="http://securityratty.com/tag/management services">management services</category>
      <category domain="http://securityratty.com/tag/malware vehicles">malware vehicles</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html">EstDomains &amp; Intercage: A Perfect Couple in Crime</source>
    </item>
    <item>
      <title><![CDATA[Should You Install Messaging Security Software on Your Exchange Server?]]></title>
      <link>http://securityratty.com/article/11b169283ed84827dab06cd87ebe699c</link>
      <guid>http://securityratty.com/article/11b169283ed84827dab06cd87ebe699c</guid>
      <description><![CDATA[Source: Sunbelt Software) Osterman Research shares insights gleaned from a just completed survey that dispel the fears of employing server-based email security solutions. Read this white paper to help...]]></description>
      <content:encoded><![CDATA[<b>(Source:  Sunbelt Software)</b> Osterman Research shares insights gleaned from a just completed survey that dispel the fears of employing server-based email security solutions.  Read this white paper to help you understand the latest Exchange security risks and also learn about reasons why an installed security solution may be the best option for you in countering those challenges.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:4c2325713dd32016c18954ac278d0864:NFQXxHFMI5joATi8rb9XqG1wphiNoRddmISCypgry8gEDx2Kenb%2BwST2VWrGNREyFwdH5a2LrernMF3UzVyemXdU3bxFrh23RewQbJvsbuU%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:ae8b7af0edbdcbad40287f4417dc000e:fzsuOnQABO%2F8zb5KR73dVE95rbdex%2BnHTgnrI25OHes0WbXZDNfE9nFNPIILxlOYupKK7IkQgzmbRxlSncXrguiZ7MZAsL4%2FH5S1pQG82Pw%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:9c187aa78b037950ceedc32de289ca2a:oM6A8Agm%2F3STbmMJgABVmGsiNFyFOaEhlsz8Si9HGzhxFAyAewDxbjLhdwiEQuD0ypx4eY%2BBm21mHRQFzIJF9g8%2FNKkoh0hbbKprpRjTCWY%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:be6d95967a93a89dc81e7f6b60ac6416:ibgVPVeXQV%2FqsmmMgf4t8i5bA1sbwSydZxlubOrocwKd3AketgClxa1YazuQW6MMa1W2lTZwLFa1Y8zrp1bym0dpybbsmX4n87C8piBSqHs%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=27986667fa8fa86c25fb326572f03aad" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=27986667fa8fa86c25fb326572f03aad" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/email security solutions">email security solutions</category>
      <category domain="http://securityratty.com/tag/exchange security risks">exchange security risks</category>
      <category domain="http://securityratty.com/tag/white paper">white paper</category>
      <category domain="http://securityratty.com/tag/sunbelt software">sunbelt software</category>
      <category domain="http://securityratty.com/tag/security solution">security solution</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/challenges">challenges</category>
      <category domain="http://securityratty.com/tag/reasons">reasons</category>
      <category domain="http://securityratty.com/tag/dispel">dispel</category>
      <source url="http://www.pheedo.com/click.phdo?i=27986667fa8fa86c25fb326572f03aad">Should You Install Messaging Security Software on Your Exchange Server?</source>
    </item>
    <item>
      <title><![CDATA[Spammers Take A Cheap Shot...]]></title>
      <link>http://securityratty.com/article/2bd234de99d23ff4b013abce95e7d324</link>
      <guid>http://securityratty.com/article/2bd234de99d23ff4b013abce95e7d324</guid>
      <description><![CDATA[I'm on holiday this week, but thought I'd better give this a mention anyway (plus, when did being on holiday ever stop me from posting stuff on blogs, right

I was surprised to see this posted to the...]]></description>
      <content:encoded><![CDATA[
        I'm on holiday this week, but thought I'd better give this a mention anyway (plus, when did being on holiday ever stop me from posting stuff on blogs, right?)<br /><br />I was surprised to see this posted to the comments section of the <a href="http://sunbeltblog.blogspot.com/">Sunbelt Blog</a>:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="spgspam1.gif" src="http://blog.spywareguide.com/images/spgspam1.gif" class="mt-image-none" style="" height="144" width="359" /></span><br /> <div><br />I was about as surprised as The Dean was!<br /><br />To quote a further post from The Dean:<br /><br /><i>"Well, that's weird. Isn't spywareguide Paperghost's blog? I know he
wouldn't spam here. And, the link on the first comment goes to a 404
page."</i><br /><br />So, we have someone spamming with broken English, dropping links to 404 pages on Spywareguide. Curious.<br /><br />Now, I did have some suspicions on this - for starters, the recent blogs regarding the pirate movie websites that pop Zango installers just hit a few <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=privacy&amp;articleId=9112881&amp;taxonomyId=84&amp;intsrc=kc_top">news</a> <a href="http://www.theregister.co.uk/2008/08/18/dark_knight_zango_affiliate_gateway/">websites</a>. As <a href="http://blog.spywareguide.com/2008/08/another-site-hiding-pirate-mov.html">this article</a> mentions, a lot of the sites involved in this are from Asian regions - China, Indonesia etc. I couldn't help but notice the name of the poster was "Tam" - a common name in certain parts of Asia.<br /><br />Coincidence? Or a possible affiliate not too happy about this being highlighted? Well, a quick email later and the results for the spammer are in:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="spgspam2.gif" src="http://blog.spywareguide.com/images/spgspam2.gif" class="mt-image-none" style="" height="185" width="430" /></span>
<br /><br />A potentially forged Reverse DNS aside, it's a strange thing indeed that they just happen to resolve to Vietnam given that a good portion of these sites are in Asia, isn't it?<br /><br />I think I'll see if any are owned by someone called "Tam".<br /><br />When I return from my holiday, of course....<br /></div><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 10:24:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/holiday">holiday</category>
      <category domain="http://securityratty.com/tag/pop zango installers">pop zango installers</category>
      <category domain="http://securityratty.com/tag/sunbelt blog">sunbelt blog</category>
      <category domain="http://securityratty.com/tag/blogs">blogs</category>
      <category domain="http://securityratty.com/tag/spywareguide paperghost">spywareguide paperghost</category>
      <category domain="http://securityratty.com/tag/recent blogs">recent blogs</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/spywareguide">spywareguide</category>
      <category domain="http://securityratty.com/tag/news websites">news websites</category>
      <source url="http://blog.spywareguide.com/2008/08/spammers-take-a-cheap-shot.html">Spammers Take A Cheap Shot...</source>
    </item>
    <item>
      <title><![CDATA[Beware of Rogue Anti-Malware]]></title>
      <link>http://securityratty.com/article/56bc0c383527b10009c2841b8cf095c1</link>
      <guid>http://securityratty.com/article/56bc0c383527b10009c2841b8cf095c1</guid>
      <description><![CDATA[Rogue anti-virus and anti-spyware products are not a new story, but they are a relatively growing threat. One of these threats made some news this week and taught some lessons about just how...]]></description>
      <content:encoded><![CDATA[Rogue anti-virus and anti-spyware products are not a new story, but they are a relatively growing threat. One of these threats made some news this week and taught some lessons about just how suspicious you have to be of them.

We had heard of <i>XP Antivirus</i>&#151;also known by a plethora of name variants, including <i>Antivirus XP</i> and year variants like <i>Antivirus XP 2008</i>. <a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Antivirus XP 2008 (Winifixer)&threatid=310434"target="_blank">Click here for a description from Sunbelt Software.</a> Last week, <a href="http://blogs.pcmag.com/securitywatch/2008/08/googlesyndicated_malware_ads_h.php"target="_blank">advertisements for this product started appearing on CNET</a> (specifically their Download.com service) through syndicated Google ads. Not to pick on CNET specifically; Google ads are likely to be appearing elsewhere, but we were referred to them on that site.

The hallmark of such malware is to start with a free version. This version conducts a fake malware scan that finds lots of malware on the system, and the user is told to pay for the "premium" version in order to remove the malware that doesn't really exist in the first place. Often rogue anti-malware software such as this is not strictly malicious in the sense of spreading itself to other systems or hiding any functions; it is simply a scam. Of course, by buying the product you may also expose personal and credit card details to untrustworthy people.

Later last week, GlobalSign, the certificate authority that had issued a code signing certificate for use with Antivirus XP 2008, <a href="http://www.theregister.co.uk/2008/08/16/certified_malware/"target="_blank">revoked that certificate after complaints that the software was malicious</a>. They verified that the company existed but couldn't contact them. The investigation is ongoing.

The bottom line and moral of the story is that rogue anti-malware vendors are merciless and shameless when it comes to masquerading as legit software. Ads on legit sites don't prove anything, and code-signing certificates don't prove anything. You still need to use common sense and exercise precautions, like running well-known and respected anti-malware, like Sunbelt Software's. They have a lot of special in-house expertise on rogue products like this.<img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/r_W79eeC5GM" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 06:16:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/anti-malware">anti-malware</category>
      <category domain="http://securityratty.com/tag/rogue anti-malware vendors">rogue anti-malware vendors</category>
      <category domain="http://securityratty.com/tag/legit software">legit software</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/sunbelt software">sunbelt software</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/rogue anti-malware software">rogue anti-malware software</category>
      <category domain="http://securityratty.com/tag/fake malware scan">fake malware scan</category>
      <category domain="http://securityratty.com/tag/google ads">google ads</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/r_W79eeC5GM/beware_of_rogue_antimalware_1.html">Beware of Rogue Anti-Malware</source>
    </item>
    <item>
      <title><![CDATA[Should You Install Messaging Security Software on Your Exchange Server?]]></title>
      <link>http://securityratty.com/article/d6f642838ae869200ed8a6b770b5bcf1</link>
      <guid>http://securityratty.com/article/d6f642838ae869200ed8a6b770b5bcf1</guid>
      <description><![CDATA[Source: Sunbelt Software) Security is the most single critical task for any email administrator. Starting with a foundation of anti-spam and anti-virus capabilities, organizations should focus on...]]></description>
      <content:encoded><![CDATA[<b>(Source:  Sunbelt Software)</b>  Security is the most single critical task for any email administrator. Starting with a foundation of anti-spam and anti-virus capabilities, organizations should focus on other capabilities, as well, including policy management and a variety of other tasks designed to protect the network and the company from external and internal threats.<br><br>There are a number of ways to deploy messaging security, including appliances, software installed on dedicated servers, hosted or managed services and installation of softwaredirectly on the email server itself. While there are proponents and opponents of these approaches, there seems to be relatively strong opposition to the last approach on the part of many email administrators. <br><br>Osterman Research shares insights gleaned from a just completed survey that dispel the fears of employing server-based email security solutions.  Read this white paper to help you understand the latest Exchange security risks and also learn about reasons why an installed security solution may be the best option for you in countering those challenges.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=IzQpY9"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=IzQpY9" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/355563690" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security solution">security solution</category>
      <category domain="http://securityratty.com/tag/email security solutions">email security solutions</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/exchange security risks">exchange security risks</category>
      <category domain="http://securityratty.com/tag/capabilities">capabilities</category>
      <category domain="http://securityratty.com/tag/sunbelt software">sunbelt software</category>
      <category domain="http://securityratty.com/tag/single critical task">single critical task</category>
      <category domain="http://securityratty.com/tag/anti-virus capabilities">anti-virus capabilities</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/355563690/whitepapers.do">Should You Install Messaging Security Software on Your Exchange Server?</source>
    </item>
    <item>
      <title><![CDATA[Customer Satisfaction with Email Archiving Systems]]></title>
      <link>http://securityratty.com/article/7e36018f72c647388fbbb0c2576b6241</link>
      <guid>http://securityratty.com/article/7e36018f72c647388fbbb0c2576b6241</guid>
      <description><![CDATA[Source: Sunbelt Software) Osterman Research conducted a primary survey asking organizations about a variety of archiving systems. The purpose of this research was simply to understand the level of...]]></description>
      <content:encoded><![CDATA[<b>(Source:  Sunbelt Software)</b>  Osterman Research conducted a primary survey asking organizations about a variety of archiving systems. The purpose of this research was simply to understand the level of satisfaction that customers of Sunbelt Exchange Archiver (SEA) and other email archiving offerings report on a variety of metrics related to product and vendor performance. Among the offerings to which the SEA offering are compared in this white paper are Symantec Enterprise Vault, Autonomy ZANTAZ EAS, Barracuda Message Archiver, EMC EmailXtender and a wide variety of other leading - and very capable - email archiving solutions.<br><br>The goal of this white paper is to provide a point of comparison between SEA and other offerings in order to help decision makers in their archiving system evaluation process.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=iuxlbB"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=iuxlbB" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/339044835" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/wide variety">wide variety</category>
      <category domain="http://securityratty.com/tag/white paper">white paper</category>
      <category domain="http://securityratty.com/tag/offerings">offerings</category>
      <category domain="http://securityratty.com/tag/variety">variety</category>
      <category domain="http://securityratty.com/tag/offerings report">offerings report</category>
      <category domain="http://securityratty.com/tag/autonomy zantaz eas">autonomy zantaz eas</category>
      <category domain="http://securityratty.com/tag/osterman research">osterman research</category>
      <category domain="http://securityratty.com/tag/symantec enterprise vault">symantec enterprise vault</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/339044835/whitepapers.do">Customer Satisfaction with Email Archiving Systems</source>
    </item>
    <item>
      <title><![CDATA[Good move for Sunbelt software]]></title>
      <link>http://securityratty.com/article/093c52abe01d0c7d6dd9c0de4c009a56</link>
      <guid>http://securityratty.com/article/093c52abe01d0c7d6dd9c0de4c009a56</guid>
      <description><![CDATA[This could work out well for both parties. Sunbelt products are widely used and customer satisfaction is at a high right now. Good luck to them both


clipped from www.webwire.com

Clearswift Partners...]]></description>
      <content:encoded><![CDATA[<div > This could work out well for both parties.<br/>Sunbelt products are widely used and customer satisfaction is at a high right now.<br/>Good luck to them both. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/A76A0675-7B7F-4045-99CE-DB9BFC03897B/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/170b6dbf-7d16-498a-8376-69042ecc4dbe/A76A0675-7B7F-4045-99CE-DB9BFC03897B/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.webwire.com/ViewPressRel.asp?aId=68639" href="http://www.webwire.com/ViewPressRel.asp?aId=68639" style="font-size: 11px;">www.webwire.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.webwire.com/ViewPressRel.asp?aId=68639 -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Clearswift Partners with Sunbelt Software to Offer Top Class Anti-spyware Solution</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.webwire.com/ViewPressRel.asp?aId=68639 -->This continual monitoring ensures spyware and the websites intentionally or inadvertently delivering malware are identified with a high degree of accuracy.<br />
<BR /><DIV>“The partnership with Clearswift seemed a natural step for both companies since the combination of the MIMEsweeper Web Appliance and our CounterSpy engine brings clear benefits to the end user,” commented Chad Loeven, vice president of business development, at Sunbelt Software. “With our technologies working hand in hand, I can comfortably say that you will not find a more comprehensive web security solution on the market today.”</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/A76A0675-7B7F-4045-99CE-DB9BFC03897B/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 10:07:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sunbelt software">sunbelt software</category>
      <category domain="http://securityratty.com/tag/clearswift partners">clearswift partners</category>
      <category domain="http://securityratty.com/tag/mimesweeper web appliance">mimesweeper web appliance</category>
      <category domain="http://securityratty.com/tag/clearswift">clearswift</category>
      <category domain="http://securityratty.com/tag/counterspy engine brings">counterspy engine brings</category>
      <category domain="http://securityratty.com/tag/vice president">vice president</category>
      <category domain="http://securityratty.com/tag/ensures spyware">ensures spyware</category>
      <category domain="http://securityratty.com/tag/sunbelt products">sunbelt products</category>
      <category domain="http://securityratty.com/tag/customer satisfaction">customer satisfaction</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=484">Good move for Sunbelt software</source>
    </item>
    <item>
      <title><![CDATA[Fake YouTube Site Serving Flash Exploits]]></title>
      <link>http://securityratty.com/article/05a0a3aecae41b8680c264c36b2e1800</link>
      <guid>http://securityratty.com/article/05a0a3aecae41b8680c264c36b2e1800</guid>
      <description><![CDATA[Originally mentioned by the folks at Sunbelt, this fake YouTube site happens to be a bit more interesting than it seems at the first place

Clicking on that link then redirects to a different site,...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SFEJJvf6l-I/AAAAAAAAByI/TqpRO54ISd0/s1600-h/fake_youtube_flash_exploits.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SFEJJvf6l-I/AAAAAAAAByI/TqpRO54ISd0/s200/fake_youtube_flash_exploits.png" alt="" id="BLOGGER_PHOTO_ID_5210956306818176994" border="0" /></a>Originally mentioned by the folks at Sunbelt, this <a href="http://sunbeltblog.blogspot.com/2008/06/dangerous-youtube-spoof.html">fake YouTube site</a> happens to be a bit more interesting than it seems at the first place :<br /><br />"<span style="font-style: italic;">Clicking on that link then redirects to a different site, youtube-s, which serves exploits to attempt to infect your system.  Then, if your browser hasn’t completely crashed at that point, you may ultimately get redirected to the real YouTube, displaying some idiotic video (he</span><span style="font-style: italic;">nce, possibly even helping to continue the infection, by having users forward the spam above)</span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SFEOU1gg68I/AAAAAAAAByQ/i2QPNRQY56U/s1600-h/fake_youtube_obfuscated.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SFEOU1gg68I/AAAAAAAAByQ/i2QPNRQY56U/s200/fake_youtube_obfuscated.JPG" alt="" id="BLOGGER_PHOTO_ID_5210961994968001474" border="0" /></a>Interesting mostly because it not just attempts to serve a online games password stealer through exploiting the ubiquitous MDAC exploit, but is <a href="http://ddanchev.blogspot.com/2008/05/malware-attack-exploiting-flash-zero.html">also serving a flash exploit</a> which when analyzed leads us to a web based C&amp;C of new malware kit. And although I've been aware of its existence for a while now, it's the first time I see it in action.<br /><br />Upon analyzing <span style="font-weight: bold;">yout</span><span style="font-weight: bold;">ube-r.com</span> (211.95.79.57) a couple of days ago, it's now returning a 403 forbidden message, however, copies of the malware have already been obtained and analyzed. In between attempting to infect with MDAC at <span style="font-weight: bold;">youtube-s.com/load.php?id=912</span>;  the flash exploit loads from <span style="font-weight: bold;">a9rhiwa.cn/update_files/1.swf</span>, and while this is happening the end user is redirected to the real YouTube site. Some sample detection rates :<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SFEOeW_qEyI/AAAAAAAAByY/3WrhqBeFukY/s1600-h/fake_youtube_deobfuscated.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SFEOeW_qEyI/AAAAAAAAByY/3WrhqBeFukY/s200/fake_youtube_deobfuscated.JPG" alt="" id="BLOGGER_PHOTO_ID_5210962158575817506" border="0" /></a>Scanners result : 7/32 (21.88%)<br /><span style="font-weight: bold;">TR/Crypt.ULPM.Gen; Mal/EncPk-CO</span><br />File size: 8704 bytes<br />MD5...: cb8611db343067e1fb663ab6ee671114<br />SHA1..: 4497715e0a365863d6ca41ab12254bf591118ed7<br /><br />Scanners result : 10/32 (31.25%)<br /><span style="font-weight: bold;">SWF:CVE-2007-0071; Exploit:Win32/APSB08-11.gen!A</span><br />File size: 593 bytes<br />MD5...: 5b6b28d4de3df92f48fbe5e8bd565cda<br />SHA1..: 3123d357d2080d1ee09ee67203275d51332e3397<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SFEPvXtqFmI/AAAAAAAAByg/6P2dXgo0944/s1600-h/web_based_malware_CC.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SFEPvXtqFmI/AAAAAAAAByg/6P2dXgo0944/s200/web_based_malware_CC.JPG" alt="" id="BLOGGER_PHOTO_ID_5210963550338160226" border="0" /></a>The password stealer than connects to the C&amp;C, from where an unknown for the time being number of campaigns are coordinated. What's a useless virtual good such as passwords for MMORPGs for malware gangs aiming to steal Ebanking details through banking malware for instance, is <a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">a precious and valuable good for others</a> operating on the other side of the world, where a virtual item is <a href="http://ddanchev.blogspot.com/2008/06/price-discrimination-in-market-for.html">more expensive than access to a Ebanking account</a>.<br /><span id="porcentaje"><span style="color:red;"></span></span><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7LxtgI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7LxtgI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9Rfx6I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9Rfx6I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=p6iizi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=p6iizi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mV3P0i"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mV3P0i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IJqqqI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IJqqqI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qrV0SI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qrV0SI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uiOjVi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uiOjVi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/310357579" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 03:12:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/fake youtube site">fake youtube site</category>
      <category domain="http://securityratty.com/tag/flash exploit loads">flash exploit loads</category>
      <category domain="http://securityratty.com/tag/flash exploit">flash exploit</category>
      <category domain="http://securityratty.com/tag/mdac">mdac</category>
      <category domain="http://securityratty.com/tag/ubiquitous mdac exploit">ubiquitous mdac exploit</category>
      <category domain="http://securityratty.com/tag/exploit">exploit</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/real youtube site">real youtube site</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/310357579/fake-youtube-site-serving-flash.html">Fake YouTube Site Serving Flash Exploits</source>
    </item>
  </channel>
</rss>
