<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: thirty-eight]]></title>
    <link>http://securityratty.com/tag/thirty-eight</link>
    <description></description>
    <pubDate>Thu, 07 Feb 2008 17:14:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA["New Attack" Against Encrypted Images]]></title>
      <link>http://securityratty.com/article/d53a9071459b26f731fbd3ec643dbde8</link>
      <guid>http://securityratty.com/article/d53a9071459b26f731fbd3ec643dbde8</guid>
      <description><![CDATA[In a blatant attempt to get some PR : In a new paper, Bernd Roellgen of Munich-based encryption outfit PMC Ciphers, explains how it is possible to compare an encrypted backup image file made with...]]></description>
      <content:encoded><![CDATA[<p>In a blatant attempt to get some <a href="http://www.techworld.com/security/news/index.cfm?newsid=105263">PR</a>:</p>

<blockquote>In a new paper, Bernd Roellgen of Munich-based encryption outfit PMC Ciphers, explains how it is possible to compare an encrypted backup image file made with almost any commercial encryption program or algorithm to an original that has subsequently changed so that small but telling quantities of data 'leaks'.</blockquote>

<p><a href="http://www.turbocrypt.com/vpics/9a8f098c615a425eab6d17c804dd67ae/whitepapers/backup_attack.pdf">Here's</a> the paper.  Turns out that if you use a block cipher in Electronic Codebook Mode, identical plaintexts encrypt to identical ciphertexts.</p>

<p>Yeah, we already knew that.</p>

<p>And -1 point for a security company requiring the use of Javascript, and not failing gracefully for a browser that doesn't have it enabled.</p>

<p>And -- ahem -- what is it with that photograph in the paper?  Couldn't the researchers have found something a little less adolescent?</p>

<p>For the record, I <a href="http://www.schneier.com/crypto-gram-0303.html#4">doghoused</a> PMC Ciphers back in 2003:</p>

<blockquote>PMC Ciphers. The theory description is so filled with pseudo-cryptography that it's funny to read. Hypotheses are presented as conclusions. Current research is misstated or ignored. The first link is a technical paper with four references, three of them written before 1975. Who needs thirty years of cryptographic research when you have polymorphic cipher theory?</blockquote>

<p>EDITED TO ADD (10/9):  I didn't realize it, but last year PMC Ciphers <a href="http://www.ciphers.de/eng/content/Backround-Info/Bruce-Schneiers-comments.html">responded</a> to my doghousing them.  Funny stuff.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=oYuwM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=oYuwM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=jkURM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=jkURM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 02:44:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pmc ciphers">pmc ciphers</category>
      <category domain="http://securityratty.com/tag/paper">paper</category>
      <category domain="http://securityratty.com/tag/technical paper">technical paper</category>
      <category domain="http://securityratty.com/tag/commercial encryption program">commercial encryption program</category>
      <category domain="http://securityratty.com/tag/polymorphic cipher theory">polymorphic cipher theory</category>
      <category domain="http://securityratty.com/tag/funny">funny</category>
      <category domain="http://securityratty.com/tag/backup image file">backup image file</category>
      <category domain="http://securityratty.com/tag/identical plaintexts encrypt">identical plaintexts encrypt</category>
      <category domain="http://securityratty.com/tag/funny stuff">funny stuff</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/new_attack_agai.html">"New Attack" Against Encrypted Images</source>
    </item>
    <item>
      <title><![CDATA[How to minimize the impact of a data breach]]></title>
      <link>http://securityratty.com/article/c754b9931a3f1eb85cfee0b8095edf8f</link>
      <guid>http://securityratty.com/article/c754b9931a3f1eb85cfee0b8095edf8f</guid>
      <description><![CDATA[Thirty-one percent of customers--nearly one-third of a company's client base and revenue source--are terminating their relationship with organizations following a data breach, according to a recent...]]></description>
      <content:encoded><![CDATA[Thirty-one percent of customers--nearly one-third of a company's client base and revenue source--are terminating their relationship with organizations following a data breach, according to a recent study by the Ponemon Institute.]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data breach">data breach</category>
      <category domain="http://securityratty.com/tag/revenue source">revenue source</category>
      <category domain="http://securityratty.com/tag/ponemon institute">ponemon institute</category>
      <category domain="http://securityratty.com/tag/client base">client base</category>
      <category domain="http://securityratty.com/tag/recent study">recent study</category>
      <category domain="http://securityratty.com/tag/thirty-one percent">thirty-one percent</category>
      <category domain="http://securityratty.com/tag/relationship">relationship</category>
      <category domain="http://securityratty.com/tag/organizations">organizations</category>
      <category domain="http://securityratty.com/tag/one-third">one-third</category>
      <source url="http://www.networkworld.com/news/2008/093008-how-to-minimize-the-impact.html?fsrc=rss-security">How to minimize the impact of a data breach</source>
    </item>
    <item>
      <title><![CDATA[Links List 8.29.08]]></title>
      <link>http://securityratty.com/article/f1038682e1a7f7e06f6d230b158bd8a3</link>
      <guid>http://securityratty.com/article/f1038682e1a7f7e06f6d230b158bd8a3</guid>
      <description><![CDATA[ChangeWave Research released a survey of 1,947 people responsible for IT spending. Thirty percent of the respondents reported that third-quarter IT spending was lower than previously planned while 12...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="240" alt="michaelphelps" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/michaelphelps.jpg" width="174" align="left" border="0" /> ChangeWave Research released a survey of 1,947 people responsible for IT spending. Thirty percent of the respondents <a href="http://www.infoworld.com/article/08/08/27/Grim_outlook_for_US_IT_spending_1.html?source=NLC-DAILY&amp;cgd=2008-08-28" target="_blank">reported that third-quarter IT spending was lower</a> than previously planned &#8211; while 12 percent spent more than planned. Thirty-five percent cited higher energy costs as the top factor for spending slowdown. </p>
<p>Parlez-vous open source? While wide-spread open source usage is still debated in many companies, the French have been advocating for <a href="http://www.infoworld.com/article/08/08/28/35NF-open-source-france-lessons_1.html" target="_blank">all open source all the time in government and education</a>. French President Nicolas Sarkozy set up an economic commission that recommended tax benefits to stimulate more open source development. Lesson learned from France: start &#8216;em early. &#8220;All students in France use open source.&#8221;</p>
<p>Just in time for Labor Day, John Edwards (no, not that one) comes out with an informative guide on &#8220;<a href="http://www.infoworld.com/article/08/08/27/35NF-cloud-providers_1.html" target="_blank">Who provides what in the cloud</a>&#8221;. No doubt, this will be a rapidly expanding list, but what&#8217;s really interesting is the comment on the article. People have very strong opinions on the cloud&#8230;</p>
<p>Research firm Aberdeen Group reports that <a href="http://www.cio.com/article/445863/Network_Management_Tips_for_Managing_Costs?page=1" target="_blank">network costs will increase</a> slightly more than 5 percent over 2007. Contributing factors: &#8220;need for speed&#8221;, shift from standard to mobile PCs (more end points of connectivity), and the ever-expanding network. And of course the hidden costs of multiple tools with multiple management consoles &#8211; if you&#8217;re not smart enough to choose say a comprehensive network management solution that is vendor agnostic&#8230;One tool to monitor them all&#8230;</p>
<p>And just because I miss the Olympics already, here&#8217;s an irreverent take on what it&#8217;s like to lose to Michael Phelps. <a href="http://www.thetechstop.net/?p=1503">http://www.thetechstop.net/?p=1503</a></p>
<p>Enjoy your long Labor Day Weekend!</p>
]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 10:00:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/percent">percent</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/source development">source development</category>
      <category domain="http://securityratty.com/tag/thirty percent">thirty percent</category>
      <category domain="http://securityratty.com/tag/labor day">labor day</category>
      <category domain="http://securityratty.com/tag/source usage">source usage</category>
      <category domain="http://securityratty.com/tag/costs">costs</category>
      <category domain="http://securityratty.com/tag/energy costs">energy costs</category>
      <category domain="http://securityratty.com/tag/thirty-five percent cited">thirty-five percent cited</category>
      <source url="http://blog.sciencelogic.com/links-list-82908/08/2008">Links List 8.29.08</source>
    </item>
    <item>
      <title><![CDATA[Please dont ever die guys, we need you!]]></title>
      <link>http://securityratty.com/article/70b1ab66729a84ab1c09551b80112df9</link>
      <guid>http://securityratty.com/article/70b1ab66729a84ab1c09551b80112df9</guid>
      <description><![CDATA[Sadly, we have very few heroes nowadays. This time in our lives is sure different


clipped from blog.wired.com

Commemorating the Ultimate Geek-Project: Apollo 11


Thirty-nine years ago, on July 20,...]]></description>
      <content:encoded><![CDATA[<div > Sadly, we have very few heroes nowadays. This time in our lives is sure different.  </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/9A5E035F-3FEE-4B71-BCAF-DD072D7215AA/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/5e6348d7-1770-4ff0-abb1-9a5e91d32fcf/9A5E035F-3FEE-4B71-BCAF-DD072D7215AA/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://blog.wired.com/geekdad/2008/07/commemorating-t.html" href="http://blog.wired.com/geekdad/2008/07/commemorating-t.html" style="font-size: 11px;">blog.wired.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://blog.wired.com/geekdad/2008/07/commemorating-t.html -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Commemorating the Ultimate Geek-Project: Apollo 11</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://blog.wired.com/geekdad/2008/07/commemorating-t.html --><P><IMG border="0" title="Aldrin" alt="Aldrin" src="http://blog.wired.com/photos/uncategorized/2008/07/19/aldrin.jpg" />Thirty-nine years ago, on July 20, 1969, two ultra-geeks landed upon Luna, Earth&#8217;s moon.? Their mission was called <A href="http://en.wikipedia.org/wiki/Apollo_11">Apollo 11.</A>? While the vast majority of the press at the time was devoted to Armstrong actually setting foot upon the Moon, the really crucial aspect of the landing on the <A href="http://en.wikipedia.org/wiki/Mare_Tranquillitatis">Sea of Tranquility</A> was just that, the landing.? This day commemorates the culmination of the science, technology, and massive national effort that went into the American Space Program.? In commemoration, we salute the second man to walk upon Luna, the Lunar Module Pilot of Apollo 11: <A href="http://en.wikipedia.org/wiki/Buzz_Aldrin">Edwin Eugene &#8220;Buzz&#8221; Aldrin, Jr</A>.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/9A5E035F-3FEE-4B71-BCAF-DD072D7215AA/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 15:54:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/american space program">american space program</category>
      <category domain="http://securityratty.com/tag/lunar module pilot">lunar module pilot</category>
      <category domain="http://securityratty.com/tag/massive national effort">massive national effort</category>
      <category domain="http://securityratty.com/tag/moon">moon</category>
      <category domain="http://securityratty.com/tag/apollo">apollo</category>
      <category domain="http://securityratty.com/tag/earths moon">earths moon</category>
      <category domain="http://securityratty.com/tag/heroes nowadays">heroes nowadays</category>
      <category domain="http://securityratty.com/tag/luna">luna</category>
      <category domain="http://securityratty.com/tag/crucial aspect">crucial aspect</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=507">Please dont ever die guys, we need you!</source>
    </item>
    <item>
      <title><![CDATA[Mission Statement for Federation]]></title>
      <link>http://securityratty.com/article/9794bcabb05d5a9a4ad01ef54236e5df</link>
      <guid>http://securityratty.com/article/9794bcabb05d5a9a4ad01ef54236e5df</guid>
      <description><![CDATA[Bruce Sterling (11/20/2001
You know what I want? I don't want a National ID Card. I want a Global Coalition Visa



Like it or not, we've got a huge global diaspora now. It is a fact of life. Nations...]]></description>
      <content:encoded><![CDATA[<p><span style="font-family: &#39;times new roman&#39;; font-size: 16px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "></span></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "><a href="http://www.viridiandesign.org/notes/251-300/00283_geeks_and_spooks.html">Bruce Sterling</a> (11/20/2001):</p><blockquote><p>You know what I want? I don&#39;t want a National ID Card. I want a Global Coalition Visa.</p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>Like it or not, we&#39;ve got a huge global diaspora now. It is a fact of life. Nations with stupid and corrupt politics have seen their clever people brain- drained away, to places where the cops don&#39;t shake you down twice a day. And jet-setters go everywhere. And properly so. If you&#39;re in a true global society, then you spend a lot of your time among aliens. Quite often you are the alien. You might notice that even Al Qaeda is a genuinely multinational group. They gravitated to wicked, lawless places like Sudan, Chechnya and Afghanistan, where the locals shoot you if you ask for a badge.</p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>But what about all us bright, shiny, world-trading jet setters, huh? There are thirty percent fewer Yankees in Europe this Christmas, and that is bad. Let me pose the problem this way. If I am going into a Japanese restaurant in Japan, I would rather like to be able to haul out some gizmo and flash it at my fellow civilians, and have these kindly people understand with a high degree of likelihood that I am not a mass murderer. On the contrary, I am quite civilized, and I should be brought a beer immediately.</p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>A platinum VISA card and a five-hundred-dollar suit will almost do that, but those are too easy to forge and steal, plus they are not very democratic. The UN should get together on this. We should have a high level summit about digital hardware support for the crippled tourist economy. Fear and ill treatment shut down tourism faster than anything short of open warfare. That is bad for all of us. Killing off tourism harms our civilization and impoverishes our cultures. People in civilized states shouldn&#39;t routinely treat one another as criminal suspects. I don&#39;t want to get done-over for three hours every time I get off a plane in London. When I go to London, I go with empty suitcases. I don&#39;t plan to stay, but I am better news for the London economy than a lot of the people who live there.</p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>They should know all that that&#0160;<span style="font-weight: bold; ">before<span style="font-weight: normal; ">&#0160;I get off the plane. My arrival is excellent news for Britain, so I should be treated that way. If this is a new kind of war, I don&#39;t want to be the evil guy hunkered down in the bunker; I want to fly with the boys from Air Assault. I want one of those handy crypto-style Friend-or-Foe IDs.</span></span></p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>These people who normally meet me whenever I am an alien, they don&#39;t need to know my nationality, my home address or my shoe size. They just need to know that, despite being alien, I&#39;m sort-of okay.</p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>I want a democratic, citizen-to-citizen device that will bridge those social barriers and language barriers. I think we could invent devices and means of verification that would strengthen the global social fabric that terrorism wants to rip. It wouldn&#39;t be easy or simple, but it&#39;s not beyond our ingenuity. Our social capital sustains all civilized societies, and it is all about trust. <span style="font-weight: bold;">So let&#39;s invent new methods of trust.</span></p></blockquote><p>I added bold to the last sentence because I think this is the mission statement for building out federation systems.</p><p></p><p></p>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 06:35:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/clever people brain-">clever people brain-</category>
      <category domain="http://securityratty.com/tag/kindly people">kindly people</category>
      <category domain="http://securityratty.com/tag/platinum visa card">platinum visa card</category>
      <category domain="http://securityratty.com/tag/london">london</category>
      <category domain="http://securityratty.com/tag/mission statement">mission statement</category>
      <category domain="http://securityratty.com/tag/london economy">london economy</category>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/true global society">true global society</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/06/mission-statement-for-federation.html">Mission Statement for Federation</source>
    </item>
    <item>
      <title><![CDATA[Your 419 Mail Roundup]]></title>
      <link>http://securityratty.com/article/2aa9ff3c4bf96550fcb31a394b91e2bc</link>
      <guid>http://securityratty.com/article/2aa9ff3c4bf96550fcb31a394b91e2bc</guid>
      <description><![CDATA[Are you ready for more 419 missives

Of course you are. Plenty of winning lottery tickets, fictitious banks, a wonderfully sick &quot;Robert Mugabe&quot; themed mail and, er, someone called &quot;Captain Frank Bojo&quot;...]]></description>
      <content:encoded><![CDATA[
        Are you ready for more 419 missives?<br /><br />Of course you are. Plenty of winning lottery tickets, fictitious banks, a wonderfully sick "Robert Mugabe" themed mail and, er, someone called "Captain Frank Bojo" after the jump...<br /> 
        Subject:<br />HELLO DEAR<br />From:<br />"abavanagift13 Gazeta.pl" &lt;abavanagift13@gazeta.pl&gt;<br />Date:<br />Sat, 21 Jun 2008 12:26:24 +0000<br />BCC:<br /><br />Hello Dear,<br />&nbsp;<br />&nbsp;My name is Blessing Abavana, the elder daughter of Mr. paul Abavana of Zimbabwe, I am 17 years old with my younger brother (Micheal), we are in Ghana as refuge/asylum since we lost our parents because of the recent war that occurred in our country.please do go through this web page for better understanding with full details:<br />&nbsp;<br />&nbsp;http://www.rte.ie/news/2000/0418/zimbabwe.html<br />&nbsp;<br />&nbsp;I am looking for one&nbsp; who will honestly assist my younger brother and I to realize our inherited funds into your account and as well as invest it into a lucrative business.<br />&nbsp;<br />During the recent war against the farmers in Zimbabwe from the supporters of our President, Robert Mugabe to claim all the white -owned farms to his party members and his followers, he ordered all the white farmers to surrender all their farms to his party members and his followers.<br />&nbsp;<br />&nbsp;My father being one of the few rich and successful black farmers in our country was also victimized because of his opposition to Mugabe's policies. And because he did not support Mugabe's ideas, Mugabe's supporters invaded my father's farm and burnt everything in the farm, killed my father and made away with a lot of items in my father's farm. This action was taken because my late father felt the growing tension on the farm issue, but I guess he never anticipated the tragedy that brought their brutal and sudden death.<br />&nbsp;<br />&nbsp;However with the benefit of hindsight, owing to the looming but deteriorating crisis in my country, Zimbabwe, my father, before his unfortunate death deposited with International Commercial Bank (ICB) here in Accra Ghana the sum of US$ 35MUsd (Thirty Five Million United States Dollars), with the sole aim of acquiring and buying some dredging equipments in setting up of a dredging firm with his partner. With his death and all his assets seized at home and accounts frozen, the family is now in a very difficult situation.<br />&nbsp;<br />&nbsp;After the death of my father, my brother and I escaped to the Republic of Ghana where he had deposited the money in the Bank . And we were permitted to reside here as Political Refugees.<br />&nbsp;<br />&nbsp;So Because of our present and unpleasant status here we decided to contact an overseas firm / individual that can assist us to move this money out Of Ghana because, as asylum seekers, we are not allowed to operate any financial transaction of such amount within Ghana and also to assist in providing me and my brother a permanent residential permit in your country after the money must have been transferred to your account.<br />&nbsp;<br />We have agreed to offer you 30% of the total sum for your assistance, and the rest will be for my brother and I, to Invest in your country under your assistant<br />&nbsp;<br />All I want you to do is to furnish me with the below information including your readiness to assist me achieve this transaction for investment purposes in your country under your supervision. Kindly re-confirm to me the followings:<br /><br />1) Your Full Name:<br />2) Phone, Fax and Mobile<br />3) Profession, Age and Marital Status.<br />4) Nationality<br />&nbsp;<br />&nbsp;I have to re-assure you that this transaction is 100% risk free and should be treated with absolute confidentiality. All the vital documentation/certification that has to do with the origin of the fund is with me for the security reasons.And I will send them to you when we progress.And I guarantee you that this fund is not government fund, drug money, or from arms deals.<br />&nbsp;<br />&nbsp;I will detail you more about&nbsp; the bank&nbsp; immediately I receive your acceptance response. I hope this is the beginning of a prosperous relationship between us.Thanks and God bless you<br />&nbsp;<br />Regards<br /><br />Blessing/Micheal Abavana<br /><br /><b>(Wow, spectacularly sick. Not that we're expecting scammers to have any morals, of course).</b><br /><br />*********************************************************************************************<br /><br /><br />Subject:<br />Lycos Online Lottery Notification<br />From:<br />"LHOUTY MOHAMMED HASSANE" &lt;mhlhouty@menara.ma&gt;<br />Date:<br />Sun, 22 Jun 2008 02:42:53 -0000<br />BCC:<br /><br />LYCOS LOTTERY ONLINE<br />8th Floor<br />1 Stephen Street<br />London<br />W1T 1AL<br />&nbsp;<br />WINNING NOTIFICATION<br />This is to inform you that your email address has won the Lycos Lottery for the year 2008. your email has won you the sum of ?952,350.00 (Nine Hundred And Fifty Two Thousand, Three Hundred And Fifty pounds sterling).<br />You are advised to keep this notice confidential to avoid misinterpretation of funds and unauthorize claims, cheating or fraud.<br />To claim your funds please contact us with the information below.<br />Name: Dr. George Stevenson<br />Tel:+447031991681<br />Email:lycosclaimsdpt@gmail.com<br />&nbsp;<br />It is mandatory that you send us your full names, address, phone number,<br />age, sex and occupation to enable us arrange your claim.<br />&nbsp;<br />Note: Winners were selected through a computer ballot system drawn from Microsoft users from company and individual email addresse users. All winning must be claimed not later than 21 working days from the time of notification. After this date all unclaimed funds will be returned to European Union Treasury as unclaimed funds.<br />&nbsp;<br />Congratulations from mambers and staff of Lycos<br />Lhouty Mohammed Hassane.<br />Lycos Lottery Co-ordinator<br /><br /><b>(A "Lycos Lottery" and they're using a GMail address? Doh).</b><br /><br />*********************************************************************************************<br /><br />Subject:<br />Yukos Oil<br />From:<br />Mr. Timinskiy Vladimir &lt;grooves@bellnet.ca&gt;<br />Date:<br />Wed, 25 Jun 2008 5:38:17 -0400<br />To:<br />&lt;info@yukos.org&gt;<br /><br />I have a profiling amount in an excess of US$100.5M, which I seek you in accommodating for me. You will be rewarded with 4% .If intrested, please reply me for moredetails...&lt;tvlad4@gmail.com&gt;<br />Regards<br />Mr. Timinskiy Vladimir<br /><br /><b>(Short. Sweet. Pointlessly fake).</b><br /><br />*******************************************************************************<br /><br />Subject:<br />Immediate Release of Your FUND Via ATM CARD<br />From:<br />"Mr. Mark Louis" &lt;francois.lapeyronie@wanadoo.fr&gt;<br />Date:<br />Wed, 25 Jun 2008 01:45:09 -0700<br />To:<br />undisclosed-recipients:;<br /><br />SUBJECT: Immediate Release of Your FUND Via ATM CARD<br /><br />Attention: ATM Card Beneficiary,<br /><br />I wish to use this medium to inform you that your CONTRACT/INHERITANCE Paymen of USD$10,000,000.00 (Ten Million United States Dollars) from CENTRAL BANK<br />OF NIGERIA have been RELEASED and APPROVED for onward transfer to you via an ATM CARD which you will use to withdraw all the USD$10,000,000.00 in any<br />ATM SERVICE MACHINE in any part of the world, but the maximum you can withdraw in a day is USD$10,000.00 Only.<br /><br />We have mandated IBTC CHARTERED BANK PLC, to send you the ATM CARD and PIN NUMBER which you will use to withdraw all your USD$10 Million Dollars in<br />any ATM SERVICE MACHINE in any part of the world. You are therefore advice to contact the Head of ATM CARD Department of IBTC CHARTERED BANK PLC;<br /><br />Contact Person: Dr. Olu James<br />Office email address:&nbsp;&nbsp; pcfc_nigeria@yahoo.com<br />Private: +2347084501007<br />Office:018969906<br /><br />Tell Dr. Olu James that you received a message from the CENTRAL BANK OF NIGERIA. Instructing him to send you the ATM CARD and PIN NUMBER which you will use<br />to withdraw your USD$10 Million Dollars in any ATM SERVICE MACHINE in any part of the world, also send him your direct phone number and contact address<br />where you want him to send the ATM CARD and PIN NUMBER to you. We are very sorry for the plight you have gone through in the past years. Thanks for adhering to this instruction and once again accept our congratulations.<br /><br />Best Regards.<br />Mr. Mark Louis.<br />Executive Governor,<br /><br />Central Bank of Nigeria {CBN}.<br /><br /><b>(Ah, the old "Let's lure them in with the magical bank card" trick).</b><br /><br /><br />******************************************************************************************<br /><br />Subject:<br />CONTACT THE FEDEX COMPANY FOR YOUR FUNDS<br />From:<br />"SAMUEL DUNBAR" &lt;samuel_dunbar0013@ig.com.br&gt;<br />Date:<br />Fri, 20 Jun 2008 12:33:43 +0100<br />BCC:<br /><br />Dear Friend,<br /><br />Compliment of the new year, I have been waiting for you since to come down here and pick your Bank Draft which my boss left with me before he travelled to England but I did not hear from you since that time till today. I went to the bank to confirm whether the draft is getting close to expire as it had been long time my boss issued the draft. The director of the bank told me that before the draft will get to you, that it will expire. Then I told him to help me and cash the cashier bank draft of $1,500.000.00 to cash payment.<br /><br />However, I have successfully cashed the draft and packaged it in a box and have registered it in the Fedex Express Company Service here in Benin Republic because I will travell to see my boss in England and will not come back till August 20th 2008. You have to contact the Fedex Express Company Service to know when they will deliver your package to your address. I have paid for the delivering charges and insurance fees. The only money you have to send to them is their security keeping feeswhich is USD$135.00 USD to receive your package. Don't be deceived by any body.<br /><br />This is their Contact Address;<br />Attn: Cheif Mr. George Kobra (Director)<br />Tel:&nbsp; +229-9799 2240<br />E-mail: fc.bj@sify.com<br /><br />Send them your contacts information to enable them locate you<br />&nbsp;immediately they arrived in your country with your package.<br /><br />This is the information they needed from you.<br /><br />1. Your full name:.....<br />2. Your shipping/home address:.....<br />3. Your tel no #......<br />4. Your current office tel no #<br />5. A copy of your passport.<br /><br />Try to contact them as soon as possible to avoid increasement of the security keeping fees Note; I didn't tell the Fedex Express Company Service that it's money inside the box, I registered it as a church of a Church Minister Materials. This is to avoid delay or any upfront problem during the delivery. So, do not let them know that the package contents money. Do let me know as soon as you received your package. You will contact&nbsp; me only through e-mail as my phone is no longe available now that I am out from our country. Contact me at samdunbar1986@yahoo.com and I will reply as soon as I can.<br />I wish you and your family Long Life,<br />Prosperity and Happy 2008.<br /><br />Thanks and Remain Blessed.<br /><br />Yours sincerely,<br />Mr.Samuel Dunbar<br />(Secretary)<br /><br /><b>(Honestly, if you contact FedEx they'll give you tons of money....)</b><br /><br />****************************************************************************************<br /><br />That's your lot for another week....<br />
    ]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 09:29:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/central bank">central bank</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/magical bank card">magical bank card</category>
      <category domain="http://securityratty.com/tag/bank draft">bank draft</category>
      <category domain="http://securityratty.com/tag/email address">email address</category>
      <category domain="http://securityratty.com/tag/office email address">office email address</category>
      <category domain="http://securityratty.com/tag/bank immediately">bank immediately</category>
      <category domain="http://securityratty.com/tag/lycos lottery">lycos lottery</category>
      <category domain="http://securityratty.com/tag/office">office</category>
      <source url="http://blog.spywareguide.com/2008/06/your-419-mail-roundup.html">Your 419 Mail Roundup</source>
    </item>
    <item>
      <title><![CDATA[Security Briefing: May 28th]]></title>
      <link>http://securityratty.com/article/a5cde5e5f863854a7a1377528d1d47db</link>
      <guid>http://securityratty.com/article/a5cde5e5f863854a7a1377528d1d47db</guid>
      <description><![CDATA[Insert pithy note about how much fun Im having and how I enjoy the struggle of reading/collating/loving the links at 0-early-thirty in the frakkin morning. Thanks to all of our new subscribers that...]]></description>
      <content:encoded><![CDATA[<p><center><img src='http://www.liquidmatrix.org/blog/wp-content/uploads/2007/09/newspapera.jpg' alt='newspapera.jpg' /></center></p>
<p>Insert pithy note about how much fun I&#8217;m having and how I enjoy the struggle of reading/collating/loving the links at 0-early-thirty in the frakkin morning. Thanks to all of our new subscribers that joined us yesterday. Welcome! And bunnies. <b>Magic Bunnies!</b></p>
<p>Click here to <a href="http://feeds.feedburner.com/Liquidmatrix">subscribe to Liquidmatrix Security Digest!</a></p>
<p>And now, the news&#8230;</p>
<ol>
<li><a href="http://blog.wired.com/27bstroke6/2008/05/man-allegedly-b.html">Man Allegedly takes a penny from the cup belonging to E-Trade and Schwab</a> <i>then gives the money back to Lumberg just before Milton burns the place to the ground.</i></li>
<li><a href="http://www.securityfocus.com/brief/743?ref=rss">Get Kraken on your botnet</a> <i>You want the original title or the funny title?</i></li>
<li><a href="http://www.securityfocus.com/columnists/472">Haberdashery!</a> <i>Or, how to tell an Aitel fanboi from a mile away</i></li>
<li><a href="http://www.eweek.com/c/a/Security/HP-Application-Security-Goes-SaaS/">HP SPIs SaaS appsec glory</a> <i>hey - if you think you&#8217;re so much smarter than me - comment! (not you CJ, you&#8217;re scary)</i></li>
<li><a href="http://www.zdnetasia.com/techguide/smb/0,3800010798,62041802,00.htm">Singapore firm claims to own patent on clicking an image to go to a different site</a> <i>does prior art from 1993 count against a patent issued in 2004?</i></li>
<li><a href="http://canadianpress.google.com/article/ALeqM5g4mVFQK1aH2SwCc9SKKHck3Hz_iA">And the Gold goes to RFID - Olympic Tickets to contain details on legitimate holder</a> <i>What is the relevance of the Olympics these days anyways?</i></li>
<li><a href="http://blogs.zdnet.com/security/?p=1189">Flash Pants! - Flash 0day vuln pwns you</a>
<li><a href="http://www.wikihow.com/Protect-a-Stolen-Mobile-Phone">Consumer Alert - you&#8217;re keeping too much data in your phone</a> <i>Your drinking phone should look like you&#8217;re at a retro party</i></li>
<li><a href="http://www.theregister.co.uk/2008/05/27/fcc_may_auction_aws_iii_band/">Prepare for <strike>Jesus-Net</strike> <i>Family-friendly broadband</i> - Nanny-state sez free-Wifi is walled garden</a></li>
</ol>
<p> Tags: <a href="http://technorati.com/tag/News" rel="tag">News</a>, <a href="http://technorati.com/tag/Daily+Links" rel="tag"> Daily Links</a>, <a href="http://technorati.com/tag/Security+Blog" rel="tag"> Security Blog</a>, <a href="http://technorati.com/tag/Information+Security" rel="tag"> Information Security</a>, <a href="http://technorati.com/tag/Security+News" rel="tag"> Security News</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=shTLBJ"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=shTLBJ" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=14ubPH"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=14ubPH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=mYFkOh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=mYFkOh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=6vYizh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=6vYizh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=zBwbbh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=zBwbbh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=cHVIbh"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=cHVIbh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/299822745" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 28 May 2008 08:49:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security news">security news</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/jesus-net family-friendly broadband">jesus-net family-friendly broadband</category>
      <category domain="http://securityratty.com/tag/links">links</category>
      <category domain="http://securityratty.com/tag/bunnies">bunnies</category>
      <category domain="http://securityratty.com/tag/insert pithy note">insert pithy note</category>
      <category domain="http://securityratty.com/tag/singapore firm claims">singapore firm claims</category>
      <category domain="http://securityratty.com/tag/magic bunnies">magic bunnies</category>
      <category domain="http://securityratty.com/tag/daily links">daily links</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/299822745/">Security Briefing: May 28th</source>
    </item>
    <item>
      <title><![CDATA[Almost too sad to read]]></title>
      <link>http://securityratty.com/article/82deade805e53c223916a95cc44218da</link>
      <guid>http://securityratty.com/article/82deade805e53c223916a95cc44218da</guid>
      <description><![CDATA[I dont think I have any words to say for this comment


clipped from apnews.myway.com
Veterans burials nonstop at national cemeteries



An average of 1,800 veterans die each day, and 10 percent of...]]></description>
      <content:encoded><![CDATA[<div > I dont think I have any words to say for this comment. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/E572980C-22D5-4E35-9BC7-0C405ADD5B8E/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/eb442b44-952d-40c8-bff4-a6248be04d74/E572980C-22D5-4E35-9BC7-0C405ADD5B8E/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://apnews.myway.com/article/20080525/D90SFO280.html" href="http://apnews.myway.com/article/20080525/D90SFO280.html" style="font-size: 11px;">apnews.myway.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://apnews.myway.com/article/20080525/D90SFO280.html --><B>Veterans&#8217; burials nonstop at national cemeteries</B></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://apnews.myway.com/article/20080525/D90SFO280.html --><P><br />
An average of 1,800 veterans die each day, and 10 percent of them are buried in the country&#8217;s 125 national cemeteries, which are expected to set a record with 107,000 interments, including dependents, this year. And more national cemeteries are being built.</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://apnews.myway.com/article/20080525/D90SFO280.html --><P><br />
Thirty-four veterans groups volunteer for services. Every seventh Thursday members of American Legion Post 548 from Louisville, Ohio, dressed in black coats, ties and pants with white belts, gloves and shoulder cords, come to pay tribute to fellow veterans.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/E572980C-22D5-4E35-9BC7-0C405ADD5B8E/blog/" title="blog or email this clip"><img src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Mon, 26 May 2008 13:22:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/national cemeteries">national cemeteries</category>
      <category domain="http://securityratty.com/tag/american legion post">american legion post</category>
      <category domain="http://securityratty.com/tag/veterans burials nonstop">veterans burials nonstop</category>
      <category domain="http://securityratty.com/tag/fellow veterans">fellow veterans</category>
      <category domain="http://securityratty.com/tag/white belts">white belts</category>
      <category domain="http://securityratty.com/tag/shoulder cords">shoulder cords</category>
      <category domain="http://securityratty.com/tag/seventh thursday">seventh thursday</category>
      <category domain="http://securityratty.com/tag/veterans die">veterans die</category>
      <category domain="http://securityratty.com/tag/black coats">black coats</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=464">Almost too sad to read</source>
    </item>
    <item>
      <title><![CDATA[Phishing Emails Generating Botnet Scaling]]></title>
      <link>http://securityratty.com/article/caa4f5eb8aeecfeaf3f29dd2781e5b66</link>
      <guid>http://securityratty.com/article/caa4f5eb8aeecfeaf3f29dd2781e5b66</guid>
      <description><![CDATA[A bigger and much more detailed picture is starting to emerge, with yet another spammed malware campaign courtesy of the botnet that is so far responsible for a massive flood of fake Windows updates ,...]]></description>
      <content:encoded><![CDATA[<div><a href="http://bp2.blogger.com/_wICHhTiQmrA/SAj0b2ORGbI/AAAAAAAABko/5lHZN8L0gdc/s1600-h/id759_phishing_botnet.png"><img id="BLOGGER_PHOTO_ID_5190667329793497522" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/SAj0b2ORGbI/AAAAAAAABko/5lHZN8L0gdc/s200/id759_phishing_botnet.png" border="0" /></a>A bigger and much more detailed picture is starting to emerge, with yet another spammed malware campaign courtesy of the botnet that is so far responsible for a <a href="http://ddanchev.blogspot.com/2008/02/inside-botnets-phishing-activities.html">massive flood of fake Windows updates</a>, phishing emails targeting the usual diverse set of brands, <a href="http://ddanchev.blogspot.com/2008/04/fake-yahoo-greetings-malware-campaign.html">fake yahoo greeting cards</a>, and most recently delivering "executable news items", through Backdoor.Agent.AJU malware infected hosts.<br /><br />Within the first five minutes, thirty three (33) phishing emails attempted to be delivered out of a sample infected host, all of them targeting NatWest or The National Westminster Bank Plc. Here are some samples, that of course never made it out to their recipient :<br /><div><div><br /><div>-<span style="font-style: italic;"> Sender Address: "NatWest Internet Banking '2008" </span><customer-support_reference_94ue@natwest.com style="font-style: italic;"> to Recipient: <@fs1.ge.man.ac.uk>Subject: Natwest Bank Bankline: Confirm Your Login Email Content: //ver2.natwest-commercial3.com/customerupdate?tag=3D19ecygtKZDzrozrznhOzn These directives are to be sent and followed by all members of the NatWest Private and Corporate Natwest does apologize for any problems caused, and is very thankful for your cooperation. If you are not client of Natwest OnLine Banking please ignore this notice! *** This is robot generated message please do not reply *** (C) 2008 Natwest Bankline. All Rights Reserved. Attached File: "ods096.gif" (image/gif)</customer-support_reference_94ue@natwest.com></div><br /><div><br /></div><div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SAj15WORGcI/AAAAAAAABkw/ShMwD7YF1HI/s1600-h/id759_phishing_botnet_nameservers.png"><img id="BLOGGER_PHOTO_ID_5190668936111266242" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/SAj15WORGcI/AAAAAAAABkw/ShMwD7YF1HI/s200/id759_phishing_botnet_nameservers.png" border="0" /></a>- <span style="font-style: italic;">Sender Address: "NatWest Bank On-line Banking'2008" </span><customers-support-id-49eio@natwest.com style="font-style: italic;"> to Recipient: <@bbc.co.uk> Subject: Natwest OnLine Banking Important Notice From Technical Department Id: 9044 Email Content: //ver2.natwest-commercial3.com/customerupdate?tag=3D15urOBFDffkOkhOvp These directives are to be sent and followed by all members of the NatWest Private and Corporate Natwest does apologize for any problems caused, and is very thankful for your cooperation. If you are not client of Natwest OnLine Banking please ignore this notice! *** This is robot generated message please do not reply *** (C) 2008 Natwest Bankline. All Rights Reserved. Attached File: "ods096.gif" (image/gif)</customers-support-id-49eio@natwest.com></div><br />- <span style="font-style: italic;">Sender Address: "Natwest Bank Internet Banking Support" </span><customer-department-num_509auq@natwest.com style="font-style: italic;"> to Recipient: <@yahoo.co.uk> Subject: NatWest Private and Corporate: Confirm Your Login Password Email Content: //ver2.natwest-commercial3.com/customerupdate?tag=3D24ecyuczfscwzbDtcwhhOkhOvp These directives are to be sent and followed by all members of the NatWest Private and Corporate Natwest does apologize for any problems caused, and is very thankful for your cooperation. If you are not client of Natwest OnLine Banking please ignore this notice! *** This is robot generated message please do not reply *** (C) 2008 Natwest Bankline. All Rights Reserved.</customer-department-num_509auq@natwest.com><br /><br />- <span style="font-style: italic;">Sender Address: "Natwest Private and Corporate Support" </span><reference_ref-59gs@natwest.co.uk style="font-style: italic;"> to Recipient: <@yahoo.co.uk> Subject: Natwest Bankline Internet Banking Important: Submit Your Records id: 1191 Email Content: //pool32-nwolb20.com/customerupdate?cid=3D27kwszewcenzdFECKDtcwhhOkhOvp These directives are to be sent and followed by all customers of the Natwest On-line Banking NatWest Bank does apologize for the troubles caused to you, and is very thankful for your collaboration. If you are not user of NatWest Bank Digital Banking please delete this letter! *** This is automatically generated message please do not reply *** (C) 2008 Natwest Bank On-line Banking. All Rights Reserved. Attached File: "rwu909.gif" (image/gif)</reference_ref-59gs@natwest.co.uk></div><br /><div><br /><div><a href="http://bp1.blogger.com/_wICHhTiQmrA/SAj2ImORGdI/AAAAAAAABk4/px7As682AnU/s1600-h/id759_phishing_botnet_nameservers_2.png"><img id="BLOGGER_PHOTO_ID_5190669198104271314" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/SAj2ImORGdI/AAAAAAAABk4/px7As682AnU/s200/id759_phishing_botnet_nameservers_2.png" border="0" /></a>- <span style="font-style: italic;">Sender Address: "Natwest Private and Corporate Support" </span><dontreply_num_34lkz@natwest.co.uk style="font-style: italic;"> to Recipient: <@56bridgwater.fsnet.co.uk> Subject: Natwest Internet Banking: Please Update Your Internet Banking Details Email Content: //pool32-nwolb20.com/customerupdate?cid=3D37kwszewcnnhrrDRCfszlaucndsOoerdnOkhOvp These directives are to be sent and followed by all customers of the Natwest On-line Banking NatWest Bank does apologize for the troubles caused to you, and is very thankful for your collaboration. If you are not user of NatWest Bank Digital Banking please delete this letter! *** This is automatically generated message please do not reply *** (C) 2008 Natwest Bank On-line Banking. All Rights Reserved. Attached File: "rwu909.gif" (image/gif)</dontreply_num_34lkz@natwest.co.uk></div><br />What is making an impression besides the malicious economies of scale achieved on behalf of the malware infected hosts used for sending, and as we've already seen, hosting and phishing pages and the malware itslef? <a href="http://ddanchev.blogspot.com/2007/07/targeted-extortion-attacks-at.html">It's the</a> campaing's <a href="http://ddanchev.blogspot.com/2007/11/targeted-spamming-of-bankers-malware.html">targeted nature</a> in respect to the <a href="http://ddanchev.blogspot.com/2008/03/localized-bankers-malware-campaign.html">segmented emails</a> database used for achieving a better response rate. The National Westminster Bank Plcis a U.K bank, and 10 out of 15 email recepient are of U.K citizens, the rest are targeting Italian users. Malware variants signal their presence to <strong>66.199.241.98/forum.php</strong> and try to obtain campaigns to participate in, this is a sample detection rate for the latest fake news items one, and more details on the domains and nameservers used in the latest campaign :<br /><br /><div>news_report-pdf_content.exe</div>Scanners result : 14/31 (45.17%)<br /><div>Backdoor.Win32.Agent.gvk; Backdoor:Win32/Agent.ACG</div>File size: 45056 bytes<br /><div>MD5...: c4849207a94d1db4a0211f88e84b0b59</div>SHA1..: 32ef2a074d563370f46738565ecf9bb53c75909c<br /><div>SHA256: 12a124cc2352f3ef68ddf06e0ed111c617d95cffd807dc502ae474960a60411c</div><br /><div><a href="http://bp2.blogger.com/_wICHhTiQmrA/SAj3y2ORGeI/AAAAAAAABlA/w42Ct-k0dxM/s1600-h/phishing_botnet_subdomains.JPG"><img id="BLOGGER_PHOTO_ID_5190671023465372130" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/SAj3y2ORGeI/AAAAAAAABlA/w42Ct-k0dxM/s200/phishing_botnet_subdomains.JPG" border="0" /></a>An internal nameservers ecosystem within the botnet, active and resolving :</div><br /><strong>ns1.ns4.ns2.ns3.id759.com</strong><br /><div><strong>ns3.ns1.id759.com</strong></div><strong>ns1.ns2.ns1.ns4.ns2.ns3.id759.com</strong><br /><div><strong>ns1.ns2.ns3.id759.com</strong></div><strong>ns1.ns2.ns4.id759.com</strong><br /><div><strong>ns1.ns4.ns4.ns2.ns3.id759.com</strong></div><strong>ns2.id759.com</strong><br /><div><strong>ns2.ns1.ns2.ns3.id759.com</strong></div><strong>ns2.ns1.ns2.ns4.id759.com</strong><br /><div><strong>ns3.ns2.ns1.ns2.ns3.id759.com</strong></div><strong>ns4.ns1.ns1.ns2.ns3.id759.com</strong><br /><br /><div></div>Yet another internal nameservers ecosystem within the botnet :<br /><br /><div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SAj4VGORGfI/AAAAAAAABlI/7_gbSyw-cZ8/s1600-h/phishing_botnet_subdomains_2.JPG"><img id="BLOGGER_PHOTO_ID_5190671611875891698" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SAj4VGORGfI/AAAAAAAABlI/7_gbSyw-cZ8/s200/phishing_botnet_subdomains_2.JPG" border="0" /></a><strong>ns1.serial43.in</strong></div><strong>ns2.serial43.in</strong><br /><div><strong>ns3.serial43.in</strong></div><strong>ns4.serial43.in</strong><br /><div><strong>ns1.ns1.ns1.serial43.in</strong></div><strong>ns1.ns2.ns1.ns1.serial43.in</strong><br /><div><strong>ns1.ns2.ns2.serial43.in</strong></div><strong>ns1.ns4.ns1.ns1.serial43.in</strong><br /><div><strong>ns2.ns1.ns2.serial43.in</strong></div><strong>ns2.ns1.ns4.ns1.ns1.serial43.in</strong><br /><div><strong>ns2.ns2.ns1.ns1.serial43.in</strong></div><div> </div><br /><div> </div>To sum up - these are all of the domains currently active and used for the malware/spam/phishing campaigns on behalf of this botnet :<br /><div> </div><br /><div><strong>server52.org</strong></div><strong>set45.net</strong><br /><div><strong>site83.net</strong></div><strong>sid95.com</strong><br /><div><strong>shell54.com</strong></div><strong>siteid64.com</strong><br /><div><strong>setup36.com</strong></div><strong>share73.com</strong><br /><div><strong>service28.biz</strong></div><br /><div> </div>There are several scenarious related to this particular botnet. Despite that it's the same piece of malware that's successfully adding new zombies to the infected population, the diversity of the campaigns, as well as the fact that for instance share73.com is registered by casta4000 @ mail.ru and is into the "reklama uslug" business which translates to advertising services, in this case spam and phishing emails sending on demand, <a href="http://ddanchev.blogspot.com/2007/10/botnet-on-demand-service.html">access to the botnet could be either offered on demand</a>, or the service itself performed in a typical <a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">managed spamming appliance</a> outsourced business model. Are they also vertically integrating in respect to the fast-fluxing? Yes they are, since they're achieving it without the need to <a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">hire a managed fast-flux provider</a>, which isn't excluding the possibility that they aren't in fact one themselves, as it's evident they've got the capability to become one.</div></div></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UMu0XzG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UMu0XzG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ghlTsaG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ghlTsaG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=f0vCgsg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=f0vCgsg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pf6BKTg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pf6BKTg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rupM8OG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rupM8OG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gveeK5G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gveeK5G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hl5L8og"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hl5L8og" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/273112081" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 18 Apr 2008 10:57:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/bank digital">bank digital</category>
      <category domain="http://securityratty.com/tag/ns1">ns1</category>
      <category domain="http://securityratty.com/tag/bank bankline">bank bankline</category>
      <category domain="http://securityratty.com/tag/ns2">ns2</category>
      <category domain="http://securityratty.com/tag/bank internet">bank internet</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware variants signal">malware variants signal</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/273112081/phishing-emails-generating-botnet.html">Phishing Emails Generating Botnet Scaling</source>
    </item>
    <item>
      <title><![CDATA[The Checklist]]></title>
      <link>http://securityratty.com/article/fe4f934e33d82e7c6399c659a93681bb</link>
      <guid>http://securityratty.com/article/fe4f934e33d82e7c6399c659a93681bb</guid>
      <description><![CDATA[Brian Chess wrote about a great article in the New Yorker - &quot; The Checklist .&quot; The article is a fantastic read and I highly recommend it, even if you're not interested in medicine. It is well written...]]></description>
      <content:encoded><![CDATA[Brian Chess <a href="http://extra.fortifysoftware.com/blog/2008/01/the_checklist.html">wrote</a> about a great article in the New Yorker - "<a href="http://www.newyorker.com/reporting/2007/12/10/071210fa_fact_gawande">The Checklist</a>."   The article is a fantastic read and I highly recommend it, even if you're not interested in medicine.  It is well written and quite engaging about how doctors handle a ridiculously complex topic - intensive care.<br /><br />Like Brian, I was struck by how closely the article can parallel some of the problems we face in trying to develop secure software.  I agree with the basic premise of Brian's statement, that a checklist can help in the software development world just like it can in the ICU.  I've had great success providing checklists to developers of common areas of concern, areas they need to make sure the document, etc.<br /><ul><li>Document how you handle authentication.  if different from standard X, get a security reviews.</li><li>Document how you're handing input filtering. If not the standard library with declarative syntax, document and get a security review.....</li></ul>You get the picture.  You can do similar things with static analyzers for example, and even by tweaking compilers or compile environment to prevent the usage of certain easy to mess-up functions such as strcpy, messed up buffer sizes, etc.<br /><br />I want to focus on two other items from the article that are worth noting.<br /><ol><li>Metrics</li><li>Processe<span style="font-weight: bold;">s</span></li></ol><span style="font-weight: bold;">Metrics</span><br /><br />In the paper the author talks about following the checklist and how it reduced deaths.  One thing he never mentions is the cost of following the checklist.  I thought it interesting, but I can only assume based on the number of lives saved, and the cost of even a single infection, that the costs of following the checklist are far outweighed by the cost savings.  Still, it would have been nice to see a cost comparison between the two.<br /><br />What is also interesting though is that in the hospital setting its generally quite clear what an adverse event is.  We generally know when someone has an infection, we certainly know when someone dies.  We do root cause analysis in many cases (though not all) to understand the general cause of death, though when there is an infection for example we don't always get to root cause.<br /><br />One result of this sort of tracking, is that it occurs within a regulatory framework where hospitals must report their incident rates publicly, and there are agencies within government charged with collecting, monitoring, and even in some cases improving on these measurements and results.<br /><br />As a result of this public tracking, the key doctor from the paper, Pronovost, was able pretty clearly to tell whether his process changes were having a positive or negative effect.  He had lots of public data to draw from, and the incidence rate at any given hospital is large enough that we can start to make valid statistical judgments about the impact of our changes.<br /><br />Contrast this with software and the differences in both area, and maturity, are quite telling.  We don't have any standard measures of success/failure, we don't perform lots of root cause on adverse events, and we don't have public reporting of success and failure.  So, we don't have a general body of knowledge that allows us  to get better or at least measure how we're doing.<br /><br />Maybe we ought to have something like that? I <a href="http://securityretentive.blogspot.com/2007/05/analyzing-software-failures.html">wrote</a> about this last year when saying that we ought to have some sort of NTSB for security, or at least for security breaches.  Maybe its time we start taking that more seriously?<br /><br /><span style="font-weight: bold;">Processes</span><br /><br />I was also struck by one of Pronovost's comments about medicine that I think especially relevant to software security.  When asked whether we'd get to the point that checklists are as common as a stethoscope for a Dr, he replied:<br /><br /><blockquote>"At the current rate, it will never happen,” he said, as monitors beeped in the background. “The fundamental problem with the quality of American medicine is that we’ve failed to view delivery of health care as a science. The tasks of medical science fall into three buckets. One is understanding disease biology. One is finding effective therapies. And one is insuring those therapies are delivered effectively. That third bucket has been almost totally ignored by research funders, government, and academia. It’s viewed as the art of medicine. That’s a mistake, a huge mistake. And from a taxpayer’s perspective it’s outrageous.” We have a thirty-billion-dollar-a-year National Institutes of Health, he pointed out, which has been a remarkable powerhouse of discovery. But we have no billion-dollar National Institute of Health Care Delivery studying how best to incorporate those discoveries into daily practice.</blockquote>I was reminded of Gunnar's <a href="http://1raindrop.typepad.com/1_raindrop/2007/10/sacred-cow-gore.html">response</a> to the Spaf piece - "<a href="http://www.cerias.purdue.edu/weblogs/spaf/kudos-opinions-rants/post-124/solving-some-of-the-wrong-problems/">Solving the Wrong Problems</a>."   I think Gunnar hit it on the head with his criticism of Spaf's piece, and I think the situation is quite similar to the one Pronovost finds in medicine. <br /><br />For the most part we fail to treat the delivery/creation of software as a science.  We do lots of research on languages, we do lots of work on theories of security, and then it all breaks down because we have people implementing the processes, and we don't spend any time on that.  Well, at least not in measure to how much we spend on all sorts of other efforts that we don't measure, we aren't sure achieve results, etc.<br /><br />We know lots about how to theoretically secure things, but we don't know a whole lot about how to get large software development organizations to produce consistently high quality/"secure" software.  Heck, we don't even know how to do it if we aren't budget constrained, much less if we are.<br /><br />To be sure, medicine hasn't solved this problem either, and they aren't dealing with a huge installed base :)  They are better at measuring effectiveness, but again they are in a life/death world plus they have the added joy of strict liability.  Operating under those conditions they do manage to settle on newer/better techniques pretty quickly, because they are tracking how they are doing, lives are on the line, and they are pretty strongly incented to get it right.<img src="http://feeds.feedburner.com/~r/SecurityRetentive/~4/231381189" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 07 Feb 2008 17:14:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/develop secure software">develop secure software</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/software development organizations">software development organizations</category>
      <category domain="http://securityratty.com/tag/health">health</category>
      <category domain="http://securityratty.com/tag/health care delivery">health care delivery</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/checklist">checklist</category>
      <category domain="http://securityratty.com/tag/software development world">software development world</category>
      <source url="http://feeds.feedburner.com/~r/SecurityRetentive/~3/231381189/checklist.html">The Checklist</source>
    </item>
  </channel>
</rss>
