<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: track-able]]></title>
    <link>http://securityratty.com/tag/track-able</link>
    <description></description>
    <pubDate>Mon, 27 Oct 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Yet Another Web Malware Exploitation Kit in the Wild]]></title>
      <link>http://securityratty.com/article/5caa05f53942f1ddb87a74f20c2c3599</link>
      <guid>http://securityratty.com/article/5caa05f53942f1ddb87a74f20c2c3599</guid>
      <description><![CDATA[With business-minded malicious attackers embracing basic marketing practices like branding, it is becoming increasingly harder, if not pointless to keep track of all XYZ-Packs currently in...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/STR4MhsqHZI/AAAAAAAACfY/EnFEn5S9XMY/s1600-h/5Qqp497mdd.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/STR4MhsqHZI/AAAAAAAACfY/EnFEn5S9XMY/s200/5Qqp497mdd.png" /></a>With business-minded malicious attackers embracing basic marketing practices like branding, it is becoming increasingly harder, if not pointless to keep track of all XYZ-Packs currently in circulation. How come? Due to their open source nature allowing modifications, claiming copyright over the modified and re-branded kit, the source code of core web malware exploitation kits continue representing the foundation source code for each and every newly released kit.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/STSLw4XodgI/AAAAAAAACfg/0WZInEH3pD4/s1600-h/gPdiZb9b7u_.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/STSLw4XodgI/AAAAAAAACfg/0WZInEH3pD4/s200/gPdiZb9b7u_.PNG" /></a>In fact, the practice is becoming so evident, that anecdotal evidence in the form of monitoring ongoing communications between sellers and buyers reveals actual attempts of intellectual property enforcement in the form of&nbsp; exchange of flames between an author of a original kit, and a newly born author who seems to have copied over 80% of his source code, changed the layout, re-branded it, added several more exploits and started pitching it as the most exclusive kit there is available in the underground marketplace.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/STSL6Yo0fFI/AAAAAAAACfo/7OQAGGmvwHg/s1600-h/9CtxtBWp6S_.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/STSL6Yo0fFI/AAAAAAAACfo/7OQAGGmvwHg/s200/9CtxtBWp6S_.PNG" /></a>What's new about this particular kit anyway? Changed iframe and js obfuscation techniques, doesn't require MySQL to run, with several modified Adobe Acrobat and Flash exploits - all patched and publicly obtainable. This is precisely where the marketing pitch ends for the majority of malware kits released during the last quarter. <br />
<br />
As always, there are noticable exceptions to the common wisdom that time-to-underground market isn't allowing them to innovate, but thankfully, these exceptions aren't yet going mainstream. What is going to change in the upcoming 2009? Web malware exploitation kits are slowly maturing into multi-user cybercrime platforms, where traffic management coming from the SQL injected or malware embedded sites is automatically exploited with access to the infected hosts or to the traffic volume in general offered for sale under a flat rate, or on a volume basis.<br />
<br />
Converging traffic management with drive-by exploitation and offering the output for sale, all from a single web interface, is precisely what <a href="http://ddanchev.blogspot.com/2007/07/malware-embedded-sites-increasing.html">malicious economies of scale</a> is all about.<br />
<br />
<b>Related posts:</b><br />
<a href="http://blogs.zdnet.com/security/?p=2217">Cybercriminals release Christmas themed web malware exploitation kit</a><cite></cite><b></b><br />
<a href="http://ddanchev.blogspot.com/2008/11/new-web-malware-exploitation-kit-in.html">New Web Malware Exploitation Kit in the Wild</a><b></b><br />
<a href="http://ddanchev.blogspot.com/2008/11/modified-zeus-crimeware-kit-gets.html">Modified Zeus Crimeware Kit Gets a Performance Boost</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/11/zeus-crimeware-kit-gets-carding-layout.html">Zeus Crimeware Kit Gets a Carding Layout</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/web-based-malware-emphasizes-on-anti.html">Web Based Malware Emphasizes on Anti-Debugging Features</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/copycat-web-malware-exploitation-kit.html">Copycat Web Malware Exploitation Kit Comes with Disclaimer</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/web-based-malware-eradicates-rootkits.html">Web Based Malware Eradicates Rootkits and Competing Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/two-copycat-web-malware-exploitation.html">Two Copycat Web Malware Exploitation Kits in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/copycat-web-malware-exploitation-kits.html">Copycat Web Malware Exploitation Kits are Faddish</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</a> <br />
<a href="http://ddanchev.blogspot.com/2008/02/blackenergy-ddos-bot-web-based-c.html">BlackEnergy  DDoS Bot Web Based</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/new-ddos-malware-kit-in-wild.html">A  New DDoS Malware Kit in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The  Small Pack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2006/11/nuclear-grabber-toolkit.html">The  Nuclear Grabber Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">The  Apophis Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/nuclear-malware-kit.html">Nuclear  Malware Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/random-js-malware-exploitation-kit.html">The  Random JS Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher  Malware Kit Spotted in the Wild</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gqSxO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gqSxO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kPWXO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kPWXO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IWaVo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IWaVo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AQnUo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AQnUo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=z4nXO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=z4nXO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=f162O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=f162O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zFrIo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zFrIo" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/472427816" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 03:24:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kit">kit</category>
      <category domain="http://securityratty.com/tag/malware exploitation kit">malware exploitation kit</category>
      <category domain="http://securityratty.com/tag/nuclear malware kit">nuclear malware kit</category>
      <category domain="http://securityratty.com/tag/zeus crimeware kit">zeus crimeware kit</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/exclusive kit">exclusive kit</category>
      <category domain="http://securityratty.com/tag/nuclear grabber kit">nuclear grabber kit</category>
      <category domain="http://securityratty.com/tag/apophis kit">apophis kit</category>
      <category domain="http://securityratty.com/tag/ddos malware kit">ddos malware kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/472427816/yet-another-web-malware-exploitation.html">Yet Another Web Malware Exploitation Kit in the Wild</source>
    </item>
    <item>
      <title><![CDATA[CISSPs Lend me your ears]]></title>
      <link>http://securityratty.com/article/2f51be6dbed18127b772146d8ca86adc</link>
      <guid>http://securityratty.com/article/2f51be6dbed18127b772146d8ca86adc</guid>
      <description><![CDATA[Art of Information Security endorses Dan Houser for(ISC)²Board of Directors
The CISSP isundoubtablyone of the most, if not the most, important professional certifications in Information Security....]]></description>
      <content:encoded><![CDATA[<p><strong>Art of Information Security endorses Dan Houser for (ISC)² Board of Directors</strong></p>
<p>The CISSP is undoubtably one of the most, if not the most, important professional certifications in Information Security. Many organizations and practitioners rely on it as evidence of a solid foundation and track record in Information Security. But the CISSP is only one of the many ways that the (ISC)² attempts to fulfill its mission of developing the Information Security profession.</p>
<p>Board membership is a role of governance, guidance, and passion. Let&#8217;s briefly explore how Dan&#8217;s track record and past contributions demonstrate his qualification for this post, and possibly your vote.</p>
<p><strong>Passion</strong></p>
<p>Dan is someone who has a passion for promoting and developing the talent needed to continue to grow and mature our profession. Anyone who has seen Dan speak at conferences, local chapter meetings, or in one of his classes knows how passionate Dan is! But anyone who takes the time to approach him knows that he is no ideologue or zealot; Dan is always interested in improving his own understanding, and then sharing that knowledge with others.</p>
<p>Dan has a long track record as a contributor - as a &#8220;giver&#8221; - to the profession. In addition to teaching over a dozen CISSP review courses, he has also served on multiple (ISC)² committees, is one of the authors of the ISSAP Body of Knowledge (cryptography), and has published primary research on professional certifications. He is also the founder of the monthly Columbus, Ohio Information Security MBA (Masters of Beer Appreciation) meeting - a professional roundtable that attracts practitioners from across the state.</p>
<p><strong>Governance and Guidance <br />
</strong></p>
<p>In addition to past experience serving on (ISC)² committees, which I assume led to the current board&#8217;s nomination, Dan has served on numerous Boards of Directors including local and regional community organizations, ISSA chapters,and several Toastmasters clubs. </p>
<p><strong>Personal Experiences</strong></p>
<p>I have known Dan for almost three yeas. Dan and I have collaborated on a number or projects, including a half-day Cryptographic Controls Seminar and a full-day Identity Management Architecture class. It is my feeling that when you collaborate, work closely, and travel with someone, you really get to know them. You get to do more than hear about their College Sweethearts (which, for Dan, is Rebecca, his wife of 21 years), but you also get to understand their ethics, how they really conduct themselves, how they deal with stress, etc.</p>
<p>Given the entire picture, the understanding that I have of Dan Houser, I can think of no one better suited to representing, guiding and developing the (ISC)². I have voted for Dan, and I hope that you will consider doing the same.</p>
<p>Here is the voting link for (ISC)²: <a href="https://webportal.isc2.org/custom/votenow.aspx%20" onclick="javascript:pageTracker._trackPageview('/outbound/article/https://webportal.isc2.org/custom/votenow.aspx%20');" target="_blank">https://webportal.isc2.org/custom/votenow.aspx</a></p>
<p>Cheers, Erik</p>
<p></p>
<p><a href="http://artofinfosec.com/105/cissps-lend-me-your-ears/" >CISSPs&#8230; Lend me your ears&#8230;</a></p>
<img src="http://feeds.feedburner.com/~r/artofinfosec/~4/456765137" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 01:15:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dan">dan</category>
      <category domain="http://securityratty.com/tag/dan houser">dan houser</category>
      <category domain="http://securityratty.com/tag/dan foralmostthree yeas">dan foralmostthree yeas</category>
      <category domain="http://securityratty.com/tag/dans track record">dans track record</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/track record">track record</category>
      <category domain="http://securityratty.com/tag/information security profession">information security profession</category>
      <category domain="http://securityratty.com/tag/isc">isc</category>
      <category domain="http://securityratty.com/tag/profession">profession</category>
      <source url="http://feeds.feedburner.com/~r/artofinfosec/~3/456765137/">CISSPs Lend me your ears</source>
    </item>
    <item>
      <title><![CDATA[A late look at Interop NY 2008]]></title>
      <link>http://securityratty.com/article/a809cae08aacaa70769cecc5883f1d96</link>
      <guid>http://securityratty.com/article/a809cae08aacaa70769cecc5883f1d96</guid>
      <description><![CDATA[Boy, time flies when youre having fun. Ive just gotten my first opportunity to look back at the statistics from Interop NY 2008. Of all the statistics, the ticketing ones have proven to be the most...]]></description>
      <content:encoded><![CDATA[<p>Boy, time flies when you&#8217;re having fun.  I&#8217;ve just gotten my first opportunity to look back at the statistics from Interop NY 2008.  Of all the statistics, the ticketing ones have proven to be the most interesting - especially when you compare them to the Las Vegas show earlier in the year.  If you look back at the <a href="http://blog.sciencelogic.com/interop-vegas-2008-a-tale-of-user-error/06/2008" target="_blank">details of that ticketing review</a> the stats clearly showed that most tickets were opened due to user error.  In NY, while &#8220;user error&#8221; dominated the other categories, &#8220;facilities&#8221; came a close second.  The InteropNet Help Desk opened a total of 94 tickets during Interop NY.  Of these tickets, 42 turned out to be user error.  Coming in second, with 17 tickets were issues with the facilities, with the most common issue being cabling that had gotten damaged between installation and the time the exhibitor was trying to use it.   In Las Vegas, despite the show being significantly larger, we only saw 6 tickets of that type.  I guess you can chalk that up as yet another reason that doing shows at The Javits Center is so much fun! (Don&#8217;t ask Julia about dealing with the Javits Center. She&#8217;ll talk your ear off.)</p>
<p>After Interop Las Vegas you may have seen our analysis of the data that we collected and delivered in our NOC view.  I thought I&#8217;d recreate the same data for NY and do a short comparison.</p>
<p>1) Like in Vegas, uptime for the network 100%.  This is no small feat considering that we introduced a new wrinkle in NY, taking down the primary NOC while the education portion of the show was still going on.  This was a forced failover to the backup systems, and it went flawlessly.  I&#8217;d like to give a little credit to EM7 on the 100% uptime as it caught a failover to battery power that allowed AC to be restored before a series of critical equipment would have gone down.</p>
<p>2) Again like Vegas, the average monitored device in the show network didn&#8217;t even hit 10% CPU utilization.  Still lots of computing overhead availabe in the show network.</p>
<p>3) The NY show network wasn&#8217;t nearly as busy as in Las Vegas, sustaining an average of only 27Mbps of usage (versus 56 Mbps) in Vegas.</p>
<p>4) Power consumption for the network and NOC in NY clocked in at 445kwh per day, about 25% less than the Las Vegas show.  This wasn&#8217;t because the equipment was any more power efficient, but instead because the show was smaller and therefore there was less network gear.</p>
<p>5) Finally, a stat we didn&#8217;t track too carefully in Las Vegas, but that I find interesting.  During show hours the wireless network average 1,100 users attached.  That&#8217;s a lot of people and a lot of wireless devices.</p>
<p>The good news is there was nothing too unexpected in the data, overall the smaller show led to a smaller number of tickets and smaller consumption of resources across the board.  We hope to have the opportunity to work with the InteropNet team again next year and take a look at this data year-over-year for each show.</p>
]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 18:41:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vegas">vegas</category>
      <category domain="http://securityratty.com/tag/interop las vegas">interop las vegas</category>
      <category domain="http://securityratty.com/tag/las vegas">las vegas</category>
      <category domain="http://securityratty.com/tag/wireless network average">wireless network average</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <category domain="http://securityratty.com/tag/network gear">network gear</category>
      <category domain="http://securityratty.com/tag/user error">user error</category>
      <category domain="http://securityratty.com/tag/tickets">tickets</category>
      <source url="http://blog.sciencelogic.com/a-late-look-at-interop-ny-2008/11/2008">A late look at Interop NY 2008</source>
    </item>
    <item>
      <title><![CDATA[Feds can track cellphones without consulting providers]]></title>
      <link>http://securityratty.com/article/ba9357d04148437b7fd39834deed742f</link>
      <guid>http://securityratty.com/article/ba9357d04148437b7fd39834deed742f</guid>
      <description><![CDATA[Documents obtained by civil liberties groups under a Freedom of Information Act request suggest that &quot;triggerfish&quot; technology can be used to pinpoint cell phones without involving cell phone providers...]]></description>
      <content:encoded><![CDATA[Documents obtained by civil liberties groups under a Freedom of Information Act request suggest that "triggerfish" technology can be used to pinpoint cell phones without involving cell phone providers at all.<img src="http://feedproxy.google.com/~r/digg/topic/security/popular/~4/zYe_LYZgGco" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 18:00:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pinpoint cell phones">pinpoint cell phones</category>
      <category domain="http://securityratty.com/tag/cell phone providers">cell phone providers</category>
      <category domain="http://securityratty.com/tag/civil liberties">civil liberties</category>
      <category domain="http://securityratty.com/tag/information act">information act</category>
      <category domain="http://securityratty.com/tag/triggerfish">triggerfish</category>
      <category domain="http://securityratty.com/tag/documents">documents</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/freedom">freedom</category>
      <source url="http://feeds.digg.com/~r/digg/topic/security/popular/~3/zYe_LYZgGco/Feds_can_track_cellphones_without_consulting_providers">Feds can track cellphones without consulting providers</source>
    </item>
    <item>
      <title><![CDATA[Anyone Play PGR4 ?]]></title>
      <link>http://securityratty.com/article/af88328c7793ccf222699ccd1dd64353</link>
      <guid>http://securityratty.com/article/af88328c7793ccf222699ccd1dd64353</guid>
      <description><![CDATA[and wants to race let me know! Grid looks awesome..I tried the demo and the track racing is excellent. I just got the wireless steering wheel. Its an incredible design. I really wish all of our...]]></description>
      <content:encoded><![CDATA[&#8230;..and wants to race let me know!
&#160;
Grid looks awesome&#8230;..I tried the demo and the track racing is excellent. 
I just got the wireless steering wheel. It&#8217;s an incredible design. I really wish all of our software was as usable and cool as the XBox 360. 
&#160;&#160;&#160;&#160;&#160;&#160;     ]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 13:13:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/incredible design">incredible design</category>
      <category domain="http://securityratty.com/tag/grid">grid</category>
      <category domain="http://securityratty.com/tag/track">track</category>
      <category domain="http://securityratty.com/tag/demo">demo</category>
      <category domain="http://securityratty.com/tag/usable">usable</category>
      <category domain="http://securityratty.com/tag/cool">cool</category>
      <category domain="http://securityratty.com/tag/excellent">excellent</category>
      <category domain="http://securityratty.com/tag/wireless">wireless</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <source url="http://securitybuddha.com/2008/11/17/anyone-play-pgr4/">Anyone Play PGR4 ?</source>
    </item>
    <item>
      <title><![CDATA[America's CTO]]></title>
      <link>http://securityratty.com/article/7370017881b0de9957b3253bdde1e5eb</link>
      <guid>http://securityratty.com/article/7370017881b0de9957b3253bdde1e5eb</guid>
      <description><![CDATA[I hope this message gets through to the Obama people - Bill Joy would be an amazingly good pick for the newly created CTO cabinet post. A grand slam to the upper deck. You can count the people with as...]]></description>
      <content:encoded><![CDATA[<p>I hope <a href="http://bits.blogs.nytimes.com/2008/11/05/john-doerrs-advice-for-barack-obama-hire-bill-joy/">this message</a> gets through to the Obama people - Bill Joy would be an amazingly good pick for the newly created CTO cabinet post. A grand slam to the upper deck. You can count the people with as a good a track record in technology on one hand.</p><br /><div>Also, I could not agree more with John Doerr on these points:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; ">The next question from the president-elect was what single policy issue he could focus on that would most help entrepreneurs.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px;"><br /></span><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; ">“The most important thing he’s got to do is kick-start a huge amount of research and innovation in energy,” said Mr. Doerr, who backed Google and Amazon.com and has invested heavily in clean energy technology for the last few years.</span><br /><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; ">The nation now invests less than $1 billion a year in renewable energy versus $32 billion a year in health care, Mr. Doerr said. “I think we’ve just scratched the surface in terms of clean ways to use energy, to produce energy. It’s the challenge of our generation.”</span><br /><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; ">How to do that? Double the number of engineers who graduate from American universities each year to 60,000, Mr. Doerr said. Bring more women into the field, and encourage foreigners who study engineering here to stay here.</span><br /><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; ">“What we do is bring foreign nationals to the world’s greatest universities. We train them, invest in them and make them go home,” he said. “What kind of national strategy is that? So I would staple a green card to the diploma.”</span></p></blockquote><p><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px;"><br /></span></p><div><span style="color: #333333; font-family: georgia; font-size: 10px; "><p style="margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1.4em; line-height: 1.5em; "><span id="more-1803"></span></p></span></div><div><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px;">While it is amazing that it took until 2009 for the US to have a CTO as a cabinet level position, it is very cool to think about all the things that could happen going forward. As Neal Stephenson said the US is only world class at three things - 1. Movies, 2. High speed pizza delivery and 3. Software development.</span></div><div><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px;"><br /></span></div><div><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px;">If you read your </span><a href="http://edgeperspectives.typepad.com/edge_perspectives/">John Hagel</a><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px;"> and </span><a href="http://www.johnseelybrown.com/">JSB</a><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px;">, then you know that innovation is the only sustainable edge. Luckily its hard wired into our system, but it will be helpful to have a seat at the table for certain things. &#0160;</span></div>]]></content:encoded>
      <pubDate>Sat, 08 Nov 2008 13:08:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/energy">energy</category>
      <category domain="http://securityratty.com/tag/produce energy">produce energy</category>
      <category domain="http://securityratty.com/tag/renewable energy versus">renewable energy versus</category>
      <category domain="http://securityratty.com/tag/cto">cto</category>
      <category domain="http://securityratty.com/tag/clean energy technology">clean energy technology</category>
      <category domain="http://securityratty.com/tag/clean">clean</category>
      <category domain="http://securityratty.com/tag/doerr">doerr</category>
      <category domain="http://securityratty.com/tag/john doerr">john doerr</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/americas-cto.html">America's CTO</source>
    </item>
    <item>
      <title><![CDATA[Weve reached the application security tipping point]]></title>
      <link>http://securityratty.com/article/6050b998309be3621b2e51a5698fa756</link>
      <guid>http://securityratty.com/article/6050b998309be3621b2e51a5698fa756</guid>
      <description><![CDATA[Its been a long road since the early 90s when people first started public sharing of vulnerability information. Back then there were flat LANs, no network filters, and world writeable NFS mounts...]]></description>
      <content:encoded><![CDATA[<p>It’s been a long road since the early 90’s when people first started public sharing of vulnerability information.  Back then there were flat LANs, no network filters, and world writeable NFS mounts hanging out on the internet. But with the spread of vulnerability information it all started to change. The first major shift in exploit targets was the move from network vulnerabilities to system vulnerabilities.  As organizations got better at firewalling, using switch technology and encryption, attackers started exploiting misconfigured hosts. The major second shift to operating system code level vulnerabilities came when OS vendors started locking down their systems out of the box and users started to get better at managing security configurations.  Now we are in the midst of the third major shift.  OS vendors such as Microsoft and Linux have scrubbed out most of the defects in the OS code.  Microsoft Windows went over a year without a remote unauthenticated “wormable” vulnerability.  Attackers have moved on to applications. </p>
<p>No longer are OS vendors and other large infrastructure technology providers the main source of vulnerabilities. It’s the thousands of applications, produced by thousands of software vendors, that make up this huge 3rd wave. ISS reported that in 2007 that the top five sources of vulnerabilities: Microsoft, Apple, Oracle,  IBM, and Cisco, had dropped to supplying us with only 13.6% of our vulnerabilities. 86.4% came from the other thousands of software vendors that supply our computers with a seemingly unending supply of vulnerabilities for attackers to exploit.</p>
<p><img alt="" src="http://www.iss.net/x-force_report_images/2008/images_for_vulnerabilities/vendors_accountability.gif" title="Top 5 Vendors Only Account for 13.6% of Vulnerabilities" class="alignnone" width="322" height="261" /></p>
<p>In a recent report Microsoft has congratulated itself on doing a good job securing Windows.  And by all accounts they have done a good job.  But then they state this:</p>
<blockquote><p>“Unless software development practices change throughout the industry, any improvements in the security of Windows would be meaningless.” </p></blockquote>
<p>Whoa.  Millions of dollars spent on securing the most prevalent piece of software and it could be meaningless? Yes, it’s true.  Since attackers typically only need one vulnerability, if it isn’t in the network, and it isn’t in the host configuration, and it isn’t in the OS, they will happily exploit a vulnerability in an application. </p>
<p>At every shift of exploit target the problem has gotten more difficult to solve.  Networks had choke points and could be centrally managed.  It took a while but eventually host configurations became centrally managed and automated tools could scan configurations.  Although OSes were huge and complex beasts with 10’s of millions of lines of code, with enough effort, their vulnerabilities have been largely tamed as Microsoft’s Windows and the Linux kernel track record shows.  This was a very substantial, over five year effort, which used some of the most talented security people anywhere.<br />
But now what to do?  Instead of a few OSes we now have thousands of applications with vulnerabilities. As Microsoft found out, the attackers don’t go away, they just move on to the next incrementally less juicy vulnerability.  In the world of exploits that typically means the vulnerability with the next smallest target population.</p>
<p>Attackers have started with the common client applications that can be found on almost every machine: Acrobat, Flash, RealPlayer, Quicktime, popular antivirus software.  And they will continue down the popularity slope until they get to application populations down in the thousands which is getting to fairly small software vendors.  Attackers can do this because they can bundle many vulnerabilities together, exploiting the statistical fact that you must have some vulnerable software installed.  Compromised web sites have been found attacking visitors with over ten client side exploits preying on multiple versions of vulnerable client software.</p>
<p>The solution to this problem is all software must be written securely, not just the software from the big guys.  Small vendors think they aren’t a target just like home users used to think they weren’t a target.  People thought, “Why would someone want to attack my home computer?”  Then they realized they did home banking, or had a fast internet connection that could be used for DDoS attacks or sending spam.  All software vendors need to get the same wakeup call.  Attackers don’t want to find a vulnerability in <em>your</em> software to make <em>you</em> look bad.  They want <em>any</em> vulnerability.  If the population of your software is small they will just bundle your vulnerability together with others in an exploit pack.  The days of the average software vendor not having to worry about application security are officially over.  </p>
]]></content:encoded>
      <pubDate>Tue, 04 Nov 2008 16:06:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/vulnerable software">vulnerable software</category>
      <category domain="http://securityratty.com/tag/popular antivirus software">popular antivirus software</category>
      <category domain="http://securityratty.com/tag/software vendors">software vendors</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/application security">application security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/wormable vulnerability">wormable vulnerability</category>
      <source url="http://www.veracode.com/blog/2008/11/we%e2%80%99ve-reached-the-application-security-tipping-point/">Weve reached the application security tipping point</source>
    </item>
    <item>
      <title><![CDATA[Undetectable Sinowal/Torpig Trojan Steals More Than 300,000 Bank Accounts]]></title>
      <link>http://securityratty.com/article/3526509fda78c56c9b6d343cf188d78d</link>
      <guid>http://securityratty.com/article/3526509fda78c56c9b6d343cf188d78d</guid>
      <description><![CDATA[Security researchers at RSAs FraudAction Research Lab have uncovered how a banking Trojan may have stolen the login credentials of as many as 300,000 online bank accounts. The Sinowal (AKA Torpig or...]]></description>
      <content:encoded><![CDATA[Security researchers at RSA&#8217;s FraudAction Research Lab have uncovered how a banking Trojan may have stolen the login credentials of as many as 300,000 online bank accounts. The Sinowal (AKA Torpig or Mebroot) trojan has also stole email and FTP account login details. Previous attempts to track the source of the Trojan were unsuccessful.
The haul [...]]]></content:encoded>
      <pubDate>Fri, 31 Oct 2008 17:12:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/trojan">trojan</category>
      <category domain="http://securityratty.com/tag/online bank accounts">online bank accounts</category>
      <category domain="http://securityratty.com/tag/previous attempts">previous attempts</category>
      <category domain="http://securityratty.com/tag/aka torpig">aka torpig</category>
      <category domain="http://securityratty.com/tag/login credentials">login credentials</category>
      <category domain="http://securityratty.com/tag/sinowal">sinowal</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/haul">haul</category>
      <source url="http://cyberinsecure.com/undetectable-sinowaltorpig-trojan-steals-more-than-300000-bank-accounts/">Undetectable Sinowal/Torpig Trojan Steals More Than 300,000 Bank Accounts</source>
    </item>
    <item>
      <title><![CDATA[Money Mules Syndicate Actively Recruiting Since 2002]]></title>
      <link>http://securityratty.com/article/a33470c5ef01ff61333511853f9e63cc</link>
      <guid>http://securityratty.com/article/a33470c5ef01ff61333511853f9e63cc</guid>
      <description><![CDATA[Money mules have already been an inseparable part of the underground ecosystem. And while others try to hide their activities by outsourcing their hosting needs to botnet masters partitioning their...]]></description>
      <content:encoded><![CDATA[<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQcPr1E8aJI/AAAAAAAACYE/NAdxaAzEnw8/s1600-h/money_mules_syndicate_U.S_U.K.bmp" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQcPr1E8aJI/AAAAAAAACYE/6noTDuaSIow/s320-R/money_mules_syndicate_U.S_U.K.bmp" /></a>Money mules have already been an inseparable part of the underground ecosystem. And while others try to hide their activities by <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">outsourcing their hosting needs to botnet masters partitioning their botnets</a>, the experienced ones apply a decent level of OPSEC (operational security) by establishing a trust based model based on recommendations in order to even consider letting you register for their services. Their geographical location not only reflects the average time it would take to take action against their activities and expose yet another extensive network of fraudulent operations, but also, has the potential to increase or decrease the commissions that the mules take based on the risk factor of getting caught.<br />
<br />
There are several different types of money mules, those serving themselves, and those offering their services to others, in this particular case, we have a money mules syndicate that's been operating since 2002, and is only serving the high profile customers. What happens when such a money mule syndicate (naturally) starts vertically integrating by offering value-added services like credit card balance checking and date of birth lookups? Profits apparently increase, since the syndicate is actively recruiting and is currently looking for 20 to 30 mules -- their current staff is said to be approximately 100 people -- to cash out anything from bank account logins, Paypal accounts, to stolen credit card data. Here's a translated description of the service :<br />
<br />
<b>"<i>Who we are?</i></b><i><br />
</i><br />
<i>- First place at (cyber crime community) top list of trusted service providers for 2008</i><br />
<i>- We serve the big guys only since 2002</i><br />
<i>- We never scam, in business since 2002 without a single scam complaint</i><br />
<i>- We look for you, you don't look for us</i><br />
<i>- We offer outstanding working conditions and high commissions<b>&nbsp;</b></i><br />
<br />
<i><b>Who you should be?</b></i><br />
<i>- Dedicated person with experience in the field</i><br />
<i>- Have been in the business for at least 6 months</i><br />
<i>- Have been recommended by at least 1 person from (cybercrime community) and from (cybercrime community)</i><br />
<i>- You take 45% commission of the processed check, minimal amount is $3000</i><br />
<i>- You pay a membership fee</i><br />
<br />
<i>In the next two months we draw the command of 20-30 people who will most satisfy our requirements. For the selected team will be Paradise conditions:</i><br />
<br />
<i>- Instant payment (a few hours after delivered)  <br />
- Large numbers to drop service in the USA and the UK (30)  <br />
- Individual drop in the number of large islands  <br />
- 3-5 fresh weekly drop<br />
- Round-the-clock support</i>"  <br />
<br />
In case some of their customers get scammed -- appreciate the irony here as scammers compensate the scammers getting scammed by the scammer's outsourced personnel -- by some of their money mules, the service is offering compensation for the stolen goods/amount of money, clearly speaking for the revenues it is to prone to be generating. OPSEC (Operational Security) has been taking place across high-profile cybercrime communities during the last quarter, mostly in response to their increasing awareness that in the very same way they keep track of the major anti-fraud features implemented across their services of (ab)use, those implementing them could be monitoring them as well.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fGWOM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fGWOM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=f3mhM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=f3mhM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Wr9Sm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Wr9Sm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=f0Zkm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=f0Zkm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=i6KYM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=i6KYM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7W3IM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7W3IM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sc0Km"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sc0Km" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/434724736" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 28 Oct 2008 05:44:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/money mules">money mules</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <category domain="http://securityratty.com/tag/mules">mules</category>
      <category domain="http://securityratty.com/tag/drop service">drop service</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service providers">service providers</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/scam">scam</category>
      <category domain="http://securityratty.com/tag/cybercrime community">cybercrime community</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/434724736/money-mules-syndicate-actively.html">Money Mules Syndicate Actively Recruiting Since 2002</source>
    </item>
    <item>
      <title><![CDATA[Speaking of Security Podcast #126]]></title>
      <link>http://securityratty.com/article/c8facd4cb501769126c5a011ee14e2ff</link>
      <guid>http://securityratty.com/article/c8facd4cb501769126c5a011ee14e2ff</guid>
      <description><![CDATA[Click to Download/Listen (07:52

At this week's RSA Conferece Europe we released a new survey to track wireless network security in London, Paris and New York. The survey shows strong growth in...]]></description>
      <content:encoded><![CDATA[<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1375">Click to Download/Listen</a> (07:52)<br><br />At this week's RSA Conferece Europe we released a new survey to track wireless network security in London, Paris and New York. The survey shows strong growth in wireless access points, both corporate and personal, but reveals that many are protected by the now discredited WEP encryption. RSA VP, <a href="http://www.rsa.com/blog/blog.aspx?author=curry">Sam Curry</a> goes over the numbers in our latest podcast.<br />]]></content:encoded>
      <pubDate>Mon, 27 Oct 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/rsa conferece europe">rsa conferece europe</category>
      <category domain="http://securityratty.com/tag/rsa">rsa</category>
      <category domain="http://securityratty.com/tag/wireless access">wireless access</category>
      <category domain="http://securityratty.com/tag/sam curry">sam curry</category>
      <category domain="http://securityratty.com/tag/wep encryption">wep encryption</category>
      <category domain="http://securityratty.com/tag/strong growth">strong growth</category>
      <category domain="http://securityratty.com/tag/survey">survey</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1375">Speaking of Security Podcast #126</source>
    </item>
  </channel>
</rss>
