<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: translation]]></title>
    <link>http://securityratty.com/tag/translation</link>
    <description></description>
    <pubDate>Mon, 14 Jul 2008 07:20:34 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Localizing Cybercrime - Cultural Diversity on Demand Part Two]]></title>
      <link>http://securityratty.com/article/6fa5c311a11504a21120c6a907e03041</link>
      <guid>http://securityratty.com/article/6fa5c311a11504a21120c6a907e03041</guid>
      <description><![CDATA[It's where you advertise your services, and how you position yourself that speak for your intentions, of course, &quot;between the lines&quot;. There's a common misunderstanding that in order for a malware...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SSv52TmaA2I/AAAAAAAACec/W3ErlbR-fSo/s1600-h/translation_service_cybercrime.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SSv52TmaA2I/AAAAAAAACec/W3ErlbR-fSo/s200/translation_service_cybercrime.JPG" /></a> It's where you advertise your services, and how you position yourself that speak for your intentions, of course, "between the lines". There's a common misunderstanding that in order for a malware campaigner or scammer to launch a localized attack speaking the native language of their potential victims, they need to speak the local language. This misconception is largely based on the fact that a huge number of people remain unaware on how core strategic business practices have been in operation across the cybercrime underground for the last couple of years.<br />
<br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Outsourcing the localization process</a> (translation services for spam/phishing/malware campaigns) has been happening for a while, courtsy of DIY servics ensuring complete anonymity of their customers. Interestingly, the translators may in fact be unaware that the advertising channels the service is using is directly attracting everyone from the bottom to the top of the cybercriminal food chain as a customer. Sometimes, it's services like this that open a new market segment covering an untapped opportunity, with this particular service already pointing out that it's charging cheaper than their competitors.<br />
<br />
"<i>We offer our services in translation. We are only competent translators profile higher education. Service is working with all types of texts. Languages available at this time of Russian, English, German. Average translation of the text takes up to 10 hours (usually much faster) through the full automation of the order and payment. <b>Just want to note that we do not keep any logs on IP and does not require registration</b>. In addition you can remove your order from the database after his execution. In addition to running more than 1000 translations already, we can use all the lessons learned to be more effective in our services. Prices vary depending on the complexity of the topic covered.</i><br />
<br />
<i><b>Prices and deadlines:  </b><br />
* Standard - the deadline is not more than 24 hours. Prices depend on the direction and guidance from the 'Order'.&nbsp;</i><br />
<i>* Term - work on your translation begins precedence. The price of the 50% more than the standard translation. Prices also depend on the direction and guidance from the 'Order'. <br />
<br />
The cost of the transfer depends on the amount of work. The workload is measured in symbols. In calculating the characters are shown letters and numbers. Punctuation do not count. Minimum order 100 characters.</i>"<br />
<br />
I'm particularly curious how is a contractor(translator) going to react to a situation when a large scale malware campaign speaking several different languages tell a fake story that the contractor might have recently translated for them. With the employer positioning itself as a fully legitimate company, whereas its customers requesting localized version of texts for the spam/phishing/malware campaigns are the "usual suspects", the contractors would continue allowing cybercriminals the opportunity to build more authenticity within their campaigns.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">MPack and IcePack Localized to Chinese</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/icepack-exploitation-kit-localized-to.html">The Icepack Exploitation Kit Localized to French</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">The FirePack Exploitation Kit Localized to Chinese</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/localizing-open-source-malware.html">Localizing Open Source Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/localized-bankers-malware-campaign.html">A Localized Bankers Malware Campaign</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/lonely-polinas-secret.html">Lonely Polina's Secret</a> (Localized malware campaign)<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jtrxN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jtrxN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MlKUN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MlKUN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=x6kTn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=x6kTn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NtZ5n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NtZ5n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=11AEN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=11AEN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KL4TN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KL4TN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BB2Un"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BB2Un" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/465119206" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 05:55:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/translation">translation</category>
      <category domain="http://securityratty.com/tag/standard translation">standard translation</category>
      <category domain="http://securityratty.com/tag/average translation">average translation</category>
      <category domain="http://securityratty.com/tag/translation services">translation services</category>
      <category domain="http://securityratty.com/tag/malware campaign">malware campaign</category>
      <category domain="http://securityratty.com/tag/bankers malware campaign">bankers malware campaign</category>
      <category domain="http://securityratty.com/tag/prices">prices</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/prices vary">prices vary</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/465119206/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand Part Two</source>
    </item>
    <item>
      <title><![CDATA[Links List 11.24.08]]></title>
      <link>http://securityratty.com/article/f209f4653ec3034a29d9cf1ff2ca5cd8</link>
      <guid>http://securityratty.com/article/f209f4653ec3034a29d9cf1ff2ca5cd8</guid>
      <description><![CDATA[The hunt for the nations first CTO continues . Although names have been suggested, such as standout nominees include Bruce Schneier, founder of Counterpane and now chief security technology officer at...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/11/markcuban.jpg" border="0" alt="markcuban" width="240" height="164" align="left" /> The hunt for the <a href="http://weblog.infoworld.com/robertxcringely/archives/2008/11/the_once_and_fu.html?source=NLC-NOTES&amp;cgd=2008-11-17" target="_blank">nation’s first CTO continues</a>. Although names have been suggested, such as standout nominees include Bruce Schneier, founder of Counterpane and now chief security technology officer at BT; Mark Cuban for his obvious business sense – and in spite of the <a href="http://www.huffingtonpost.com/2008/11/17/mark-cuban-insider-tradin_n_144320.html" target="_blank">insider trading indictment</a> – and Carly Fiorina, former controversial CEO of HP, the next question is what policies should this CTO pursue? Visit <a href="http://obamacto.org/" target="_blank">ObamaCTO.org</a> to view and vote for policies.</p>
<p>SaaS is taking a bite out of the $18 billion IT management market. A <a href="http://www.informationweek.com/blog/main/archives/2008/11/will_it_managem.html?cid=RSSfeed_IWK_ALL" target="_blank">new Forrester Research report forecasts SaaS-based IT management accounts will be 10%</a> of the market by 2013. The reason: high level of interest from medium-sized and large enterprises. Forrester also predicts that enterprises with 1,000 or more employees will account for 50% of SaaS installations in 2009. We’ve seen this on the service desk side with the <a href="http://www.redmonk.com/cote/2007/01/17/service-nowcom-briefing-itil-saas/" target="_blank">rapid growth of upstart Service-now.com</a>. Companies are looking for easier and rapid deployment, lower upfront and capital costs and rapid time to value – all benefits of SaaS as well as our own <a href="http://www.sciencelogic.com/appliancebenefits.htm" target="_blank">appliance model</a>.</p>
<p><a href="http://chucksblog.emc.com/chucks_blog/2008/11/the-speculation-game-ibm-buys-transitive.html" target="_blank">IBM snapped up Transitive</a> this week. Their QuickTransit software dynamically translates native code <a href="http://arstechnica.com/news.ars/post/20081120-ibm-to-buy-transitive.html" target="_blank">between architectures</a>, enabling apps compiled for one processor to be run on another without any modification. Apple was the first licensee and used it to build Rosetta, a translation system that allowed users of Intel Macs to seamlessly run legacy PowerPC apps. IBM plans to use the technology to move workloads onto IBM systems without recompiling, allowing customers to “save on energy costs due to hardware consolidation and reduced TCO.”</p>
<p>At CA World, CA announced a partnership with Amazon to provide “<a href="http://stage.vambenepe.com/archives/442" target="_blank">management capabilities around Amazon’s EC2</a> utility computing platform, potentially including discovery of software running on EC2 instances, performance monitoring, configuration management, software deployment capabilities and provisioning”. John Willis, in spite of some pretty funny potshots and stories about CA (don’t we all have them), writes that “<a href="http://www.johnmwillis.com/amazon/what-color-is-your-cloud/" target="_blank">CA is the first of the Big Four to take the cloud serious</a>”.</p>
]]></content:encoded>
      <pubDate>Mon, 24 Nov 2008 11:15:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software deployment capabilities">software deployment capabilities</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/ibm plans">ibm plans</category>
      <category domain="http://securityratty.com/tag/ibm">ibm</category>
      <category domain="http://securityratty.com/tag/apps">apps</category>
      <category domain="http://securityratty.com/tag/legacy powerpc apps">legacy powerpc apps</category>
      <category domain="http://securityratty.com/tag/saas">saas</category>
      <category domain="http://securityratty.com/tag/saas installations">saas installations</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <source url="http://blog.sciencelogic.com/links-list-112408/11/2008">Links List 11.24.08</source>
    </item>
    <item>
      <title><![CDATA[Another link spammer]]></title>
      <link>http://securityratty.com/article/4dd72baf5933c49893c38cadde935c82</link>
      <guid>http://securityratty.com/article/4dd72baf5933c49893c38cadde935c82</guid>
      <description><![CDATA[Yet another link spammer is cluttering up my in-box. Youd think that after exposing this one , and this one , and this one , theyd know better
The latest set of miscreants operates under the brand...]]></description>
      <content:encoded><![CDATA[<p>Yet another link spammer is cluttering up my in-box. You&#8217;d think that after exposing <a href="http://www.lightbluetouchpaper.org/2007/01/07/human-rights-and-biophysics-strange-similarities/">this one</a>, and <a href="http://www.lightbluetouchpaper.org/2007/08/30/the-interns-of-privila/">this one</a>, and <a href="http://www.lightbluetouchpaper.org/2007/12/20/fatal-wine-waiters/">this one</a>, they&#8217;d know better.</p>
<p>The latest set of miscreants operates under the brand &#8220;<a href="http://www.goodeyeforlinks.com" rel="nofollow">goodeyeforlinks.com</a>&#8221; and claim to &#8220;use white hat SEO techniques in order to get high quality, do-follow links to your website&#8221;. They also claim to be &#8220;professional&#8221; which in this case must mean you pay for their services, since sending out bulk unsolicited email is anything but professional.</p>
<p>Nevertheless, although their long term aim may indeed be to make money from legitimate, albeit foolish, businesses seeking a higher profile, the sites they have been promoting so far are anything but legitimate. In fact they&#8217;ve been fake sites covered with Google adverts (so-called &#8220;<a href="http://www.sabahan.com/2006/06/26/how-mfa-made-for-adsense-sites-make-money/">Made for AdSense</a>&#8221; (MFA) sites).</p>
<p>They started by asking me to link to &#8220;<a href="http://www.entovation.net" rel="nofollow">entovation.net</a>&#8221; which they claim is &#8220;page rank 3&#8243;. In fact it is page rank 3 (!) and a blatant copy of <a href="http://www.acentesolutions.com/">http://www.acentesolutions.com</a> which appears entirely genuine (albeit only page rank 1). They have also been promoting &#8220;<a href="http://www.poland-translation-services.com" rel="nofollow">poland-translation-services.com</a>&#8220;, which claims to be a site offering &#8220;A large team of 2,500 translators specializing in each sector, located in over 30 countries&#8221; &#8230;</p>
<p>However, this site is clearly fake as well. I haven&#8217;t tracked down where it all comes from, but much of <a href="http://poland-translation-services.com/Translate-a-Document.html" rel="nofollow">this page</a> comes from <a href="http://www.intowords.com.ar/espanol/traducciones/traducciones-de-espanol-ingles.html">this Argentinian page</a>, the text of which has been pushed through <a href="http://www.google.com/language_tools?hl=en">Google&#8217;s Spanish to English translation tools</a>&#8230;  which sadly (for example) renders </p>
<blockquote><p>
Comentarios: Se considera foja al equivalente a 500 palabras. Si el documento a traducir es menor a una foja, se lo considerará como una foja.
</p></blockquote>
<p>into </p>
<blockquote><p>
Comments: foja is considered the equivalent of 500 words. If the document is translated to a lesser foja, we will consider as a foja.
</p></blockquote>
<p>which makes the 2500 translators look more than a little bit <a href="http://www.cartoonbank.com/item/124224">foolish</a>!</p>
<p>The fake websites are hosted by <a href="http://www.euroaccess.nl/">EuroAccess Enterprises Ltd.</a> in The Netherlands (which is also where the email spam has been sent from). I&#8217;m not alone in receiving this type of email, further examples can be found <a href="http://archives.neohapsis.com/archives/openbsd/2008-09/1548.html">here</a>, and <a href="http://www.projecthoneypot.org/ip_89.248.172.66">here</a>, and <a href="http://dansdata.blogsome.com/2008/10/16/i-do-like-a-good-link-spam-in-the-morning/">here</a>, and <a href="http://avvoblog.com/2008/11/10/linkbrokers-gone-wild/">here</a>, and <a href="http://www.nabble.com/Link-exchange-with-page-rank-4--Hotel-site-td19973368.html">here</a>, and <a href="http://www.allvoices.com/contributed-news/1522559">here</a>, and even <a href="http://blogpintura.wordpress.com/#comment-5">here (in Spanish)</a>.</p>
<p>EuroAccess have a fine ticketing system for abuse complaints&#8230; so I&#8217;m able to keep track of what they&#8217;re doing about my emails drawing their attention to the fraudsters they are hosting. I am therefore fully aware that they&#8217;ve so far marked my missives as &#8220;Priority: Low&#8221;, and nothing else is recorded to have been done&#8230; However, the tickets are still &#8220;Status: Open&#8221;, so perhaps a little publicity will encourage them to reassess their prioritisation.</p>
]]></content:encoded>
      <pubDate>Sun, 23 Nov 2008 16:45:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/argentinian page">argentinian page</category>
      <category domain="http://securityratty.com/tag/page">page</category>
      <category domain="http://securityratty.com/tag/foja">foja</category>
      <category domain="http://securityratty.com/tag/lesser foja">lesser foja</category>
      <category domain="http://securityratty.com/tag/page rank">page rank</category>
      <category domain="http://securityratty.com/tag/considera foja">considera foja</category>
      <category domain="http://securityratty.com/tag/link spammer">link spammer</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/fake">fake</category>
      <source url="http://www.lightbluetouchpaper.org/2008/11/23/another-link-spammer/">Another link spammer</source>
    </item>
    <item>
      <title><![CDATA[VMWare is Better Than Microsoft]]></title>
      <link>http://securityratty.com/article/a030161b183f83f292761020fb04b7d9</link>
      <guid>http://securityratty.com/article/a030161b183f83f292761020fb04b7d9</guid>
      <description><![CDATA[After barely surviving the VMworld registration process, my first session was From Hypervisors to VMware Infrastructure What Matters? or as I would have called it why VMware is so much better than...]]></description>
      <content:encoded><![CDATA[<p>After barely surviving the <a href="http://www.vmworld.com/conferences/2008/" target="_blank">VMworld</a> registration process, my <a href="https://vmworld2008.wingateweb.com/scheduler/eventguide/publicScheduleByType.jsp?ts=1221517325133" target="_blank">first session</a> was “From Hypervisors to VMware Infrastructure – What Matters?” – or as I would have called it “why VMware is so much better than Microsoft…and if you don’t believe that we can help you make even more money on top of your already successful Microsoft business.” (I know, that title is way too long but quite descriptive.)</p>
<p>The session took place at the beginning of Partner Day. The “regular” conference sessions actually begin tomorrow. Today is spent focusing on partner issues and enablement.</p>
<p>The panel for this session included:</p>
<ul>
<li>Mark Chuang <small>Group Manager, Product Marketing, </small>VMware, Inc.</li>
<li>Kenon Owens <small>Staff Systems Engineer, </small>VMware, Inc.</li>
</ul>
<p>You have to remember that <a href="http://www.virtualization.info/2008/09/more-than-20-partners-announces-support.html" target="_blank">most of the Partners here</a> are not vendors like ScienceLogic, but big and small shops that are selling IT, networking and now virtualization solutions into end-customer environments. For these guys, understanding what virtualization partner programs and tools are at NetApp, for example, is very useful. And many of these companies are already selling Microsoft software and surrounding services for Microsoft products. So if you’re VMware, what’s the message to these partners in the face of the Microsoft juggernaut?</p>
<blockquote><p>Microsoft to partners: “You may not like to admit it, but you’re probably already in bed with us.”</p>
<p>VMware to partners: &#8220;Our hypervisor technology outperforms Hyper-V and Xen, especially at scale. And anyway, it’s not about the battle at the hypervisor. It’s about the V-services on top of the hypervisor – VMotion, Storage VMotion, DRS, etc.&#8221;</p></blockquote>
<p>Interesting and what we all already know, or think we know. The scale issue is an interesting one – too soon for <a href="http://blogs.technet.com/virtualization/archive/2008/09/12/pre-vmworld-check-out-hyper-v-server-and-live-migration-demos.aspx" target="_blank">Hyper-V</a> and who uses Xen? But also interestingly enough, no announcement or even talk about extending VMware management tools to other hypervisors. The point, as the VMware product marketing guy made a point of saying, is that the question they needed to answer used to be “Why Virtualization?” and now it’s “Why VMware?&#8221;.</p>
<p>One more tidbit – this survey run by VMware asking their customers:</p>
<p><strong>What are the top 6 apps you are running on VMware today</strong></p>
<ul>
<li>IIS</li>
<li><em>Apache</em></li>
<li>Active Directory</li>
<li>SQL Server</li>
<li>Sharepoint</li>
<li>Exchange</li>
<p><em></em></ul>
<p><strong>That means, 5 of 6 are Microsoft applications. </strong>Certainly it makes it even more challenging for VMware to navigate a path here.</p>
<p>The change since 2004 – would have talked about why virtualize. And now why VMware. (Duh.)</p>
<p>Talking to partners – many of which already have a successful Microsoft business. How VMware <a href="http://gigaom.com/2008/09/14/for-vmware-an-uncertain-future/" target="_blank">enhances your existing Microsoft business</a>.</p>
<p><strong>Top 6 apps running on VMware today (5 of 6 are Microsoft applications)</strong></p>
<ul>
<li>IIS</li>
<li><em>Apache</em></li>
<li>AD</li>
<li>Sql server</li>
<li>Sharepoint</li>
<li>Exchange</li>
</ul>
<p><em>Source: VMware survey</em></p>
<p>Esxi - VMware – true thin hypervisor; maximizes resources utilization (over 100% memory commitment – allows avg of 2:1 memory overcommit) – host system memory is usually the resource bottleneck – plus Advanced Scheduler runs VMs better under load and to a greater capacity (hard to show this part); performance acceleration – using binary translation (32bit), para-virtualization and Hardware Assist (for 64-bit)</p>
<p>(rvi – rapid virtualization indexing)</p>
<p>No parent partition that all hypervisors have to go through</p>
<p>Vs ms/xen</p>
<p>Parent partition – dom 0 =&gt; potentially problem at scale; i/o that could be a bottleneck</p>
<p>Hyper-v SPECjbb comparison</p>
<p>= 9 vms on VMware and hyper-v hypervisors</p>
<p>Outperform (CPU) by 50% - general purpose scheduler isn’t able to keep up? “got to be”</p>
<p>(cpu only test)</p>
<p>Also used VMmark – to demonstrate again that VMware is performance tuned and designed to run at scale vs Hyper-V</p>
<p>Size Does Matter:</p>
<p>Vmware ESXi: 32MB</p>
<p>Hyper-v – 2.6 GB</p>
<p>Xen – 1.2 GB</p>
<p>Hyper-V uses Microsoft Server Core – so the last two Patch Tuesdays had to make changes to Server Core (nothing to do with Hyper-V) but service interruption for Hyper-V.</p>
<p>VMware VMsafe – “Provides an unprecedented level of security” “virtual is more secure than Real” (uh oh – clearly didn’t read about the</p>
<p>*****************</p>
<p>VMware TEST:512 mb vms on server w/ 4gb ram –</p>
<p>7 vms - xensource (w/no memory overcommit)</p>
<p>6vms – hyper-v before error (w/no memory overcommit)</p>
<p>14vms - w/memory overcommit and management</p>
<p>Running sql io sim – heavy workloads</p>
<p>TCO – not just license; now ESXi is free – so hardware</p>
<p>809 - ESXi</p>
<p>871 – vi3 foundation ($995)</p>
<p>1168- vi3 enterprise ($5750)</p>
<p>1621 – hyper-v – 2x cost because of hw</p>
<p>Xen – 1618</p>
<p>Memory overcommit (89% in production vs. test/dev)</p>
<p>Survey – 37% of respondents at 2:1 RATIO OR HIGHER; real average is around 1.8: 1</p>
<p>*********************</p>
<p>This guy Mark sounds like a used car salesman:</p>
<p>“Always On, On Demand Data Center”</p>
<blockquote><p>Hypervisor is very important but what is more important are the v-services on top of this. Manage shared, pooled resources. “Value Above the Hypervisor”</p></blockquote>
<p>How does all this save “your customers” $$?</p>
<p><strong>VMotion – saves cost on planned maintenance: no more overtime, no more time scheduling maintenance windows (see cost framework below)</strong></p>
<p>10 (# of servers) x 6 (@ of updates) x [ (overtime cost 2hrs x $150/hr) + (scheduling downtime # of apps per server 15 x time spend scheduling per app 0.75 hr x $50/hr)] = $58,500</p>
<p>Same thing with using VMware Storage VMotion</p>
<p>Overtime cost + scheduling downtime + planning move + alternative tool cost - $68,750 (2.5 TeraBytes)</p>
<p><strong>The Value of High Availability</strong></p>
<p>- cost of lost business, lost work</p>
<p>- cost of lost productive time</p>
<p>4 hours of downtime x # of users per vm 10 x number of vms per host 15 x cost of user productive time $50/hr x failures per year in 10-host cluster 2 = $60K</p>
<p>(10 servers, 150 vms)</p>
<p><strong>SAVINGS (using enterprise version)</strong></p>
<p>Update management 149,760</p>
<p>HA 60K</p>
<p>DRS, VMotion Storage VMotion 187,250</p>
<p>808,259 – hw, power cooling, etc.</p>
]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 19:00:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/survey">survey</category>
      <category domain="http://securityratty.com/tag/vmware survey">vmware survey</category>
      <category domain="http://securityratty.com/tag/vmware enhances">vmware enhances</category>
      <category domain="http://securityratty.com/tag/vmware infrastructure">vmware infrastructure</category>
      <category domain="http://securityratty.com/tag/test">test</category>
      <category domain="http://securityratty.com/tag/vmware test">vmware test</category>
      <category domain="http://securityratty.com/tag/overtime cost 2hrs">overtime cost 2hrs</category>
      <source url="http://blog.sciencelogic.com/vmware-is-better-than-microsoft/09/2008">VMWare is Better Than Microsoft</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Indian Terror over Wi-Fi; Fastest Wireless; Health Fears; Wi-Fi Tub; and More]]></title>
      <link>http://securityratty.com/article/38100bf79f0cedd88c5f6a02e45c5a85</link>
      <guid>http://securityratty.com/article/38100bf79f0cedd88c5f6a02e45c5a85</guid>
      <description><![CDATA[Another terror message sent via open Wi-Fi in India: Credit for terrorist blasts in Delhi was sent by email minutes before the attack took place using a Wi-Fi network owned by a retired engineer's...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://www.telegraphindia.com/1080915/jsp/nation/story_9835144.jsp"><strong>Another terror message sent via open Wi-Fi in India:</strong></a> Credit for terrorist blasts in Delhi was sent by email minutes before the attack took place using a Wi-Fi network owned by a retired engineer's wife. Though articles keep saying the network was "hacked," the Telegraph also notes that the network was "unsecured."</p>

<p>Italian free space optics test hits 1.2 terabits per second (<a href="http://www.corriere.it/scienze_e_tecnologie/08_settembre_11/wifi_pisa_record_3a9bf132-801f-11dd-9f6f-00144f02aabc.shtml">in Italian</a>, <a href="http://translate.google.com/translate?u=http://www.corriere.it/scienze_e_tecnologie/08_settembre_11/wifi_pisa_record_3a9bf132-801f-11dd-9f6f-00144f02aabc.shtml&hl=en&ie=UTF-8&sl=it&tl=en">Google translation</a>): Researchers in Pisa, Italy, along with colleagues from two Japanese institutions, crossed 1.2 Tbps in a test. Free space optics typically uses infrared lasers, and can work over a distance of kilometers. </p>

<p><a href="http://www.canada.com/montrealgazette/news/story.html?id=2e090761-519c-4de6-9ace-4153d6dc71d2"><strong>More Canadian Wi-Fi health fears:</strong></a> This time in an island in Montr&eacute;al. One of the concerned citizens: "This is something that is really under the radar. People do not know that long-term health hazards are associated with wireless technology." They don't know that because all verifiable, repeatable, well-conducted, academic tests so far indicate that there's no such health hazard associated with EMF. The concerned folks are raising an alarm about Wi-Fi being broadcast island wide, but are not paying attention, obviously, to the AM/FM radio, satellite radio, cellular, cordless, and thousand other wireless uses that are bombarding them right now, often at far higher signal levels.</p>

<p><a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/09/13/AR2008091300340.html"><strong>Wi-Fi in a tub:</strong></a> I'm not going to say anything more.</p>

<p><a href="http://www.quickertek.com/products/expresscard.php"><strong>QuickerTek adds antenna to 300 mW ExpressCard for MacBook Pro:</strong></a> Users of Apple's higher-end laptops can drop $200 to get a 300 mW Draft N (802.11n) ExpressCard and 5 dBi external antenna with a mounting clip. That's a lot of power, and it's important to recall that have a louder signal doesn't mean that distant base stations can necessarily hear you better. Draft N devices typically pair better listening (receive sensitivity) with higher transmission power, however.</p>

<p><a href="http://networklocationapp.com/"><strong>Mac product ties location settings to Wi-Fi position:</strong></a> Centrix has updated its $29 Mac OS X location preferences program NetworkLocation to take advantage of Skyhook Wireless's Wi-Fi positioning data. You can now tie the package of settings that control what email account you use, iChat status, programs launched, disks mounted, and other factors, to where you're currently at.</p>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 06:03:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi network owned">wi-fi network owned</category>
      <category domain="http://securityratty.com/tag/wireless">wireless</category>
      <category domain="http://securityratty.com/tag/wi-fi position">wi-fi position</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/skyhook wireless">skyhook wireless</category>
      <category domain="http://securityratty.com/tag/broadcast island wide">broadcast island wide</category>
      <category domain="http://securityratty.com/tag/island">island</category>
      <category domain="http://securityratty.com/tag/dbi external antenna">dbi external antenna</category>
      <source url="http://wifinetnews.com/archives/008439.html">Wee-Fi: Indian Terror over Wi-Fi; Fastest Wireless; Health Fears; Wi-Fi Tub; and More</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Meraki Modifies, Drops Standard; Tempe's Phoenix?; Remote Wake, Wi-Fi Need Not Apply]]></title>
      <link>http://securityratty.com/article/a930349b033e6f56c6098e0b152daddf</link>
      <guid>http://securityratty.com/article/a930349b033e6f56c6098e0b152daddf</guid>
      <description><![CDATA[Meraki reworks product line, drops new sales of community flavor: The cheap mesh router company has mutated slightly once again. The partly-Google-backed firm founded by MIT RoofNet &quot;graduates&quot; built...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://meraki.com/"><strong>Meraki reworks product line, drops new sales of community flavor:</strong></a> The cheap mesh router company has mutated slightly once again. The partly-Google-backed firm founded by MIT RoofNet "graduates" built the company on the notion that they could sell $50 routers that could mesh with each other, and use a robust central management system they developed. Over time, the $50 price didn't hold up for commercial networks of scale. Last October, the <a href="http://wifinetnews.com/archives/007973.html"><strong>company mishandled a change</strong></a> in its business model when they abruptly announced a $100 increase in price for newly purchased nodes under their Meraki Pro level for any network that wanted to control whether or not ads appeared, have user accounts, and charge for service. (They eventually <a href="http://wifinetnews.com/archives/007979.html"><strong>recovered, apologized, and reworked</strong></a> some of the transition details.) <img src="http://wifinetnews.com//images/2008/meraki_indoor.jpg" alt="meraki_indoor.jpg" border="0" width="175" height="111" align="right" />The company continued to offer a $50 indoor and $100 outdoor Standard level nodes for networks that required ads and had other limits. As of a few days ago, Standard is dead, and the Meraki mini has been upgraded to the <a href="http://meraki.com/products_services/hardware/indoor/"><strong>Meraki Indoor</strong></a> ($150). The Indoor has signal strength LEDs on the side for better help in placing units, an internal antenna, and better resilience against power fluctuations. The company <a href="http://meraki.com/support/faq/"><strong>explains its move</strong></a> in eliminating Standard by noting that most customers moved to Pro. It's not precisely the end of idealism (nor did that happen last October), as Meraki is still one of the major commercial mesh vendors, and their products are still vastly easier and a fraction of the cost of higher-end competitors.<br clear="all"></p>

<p><a href="http://www.eastvalleytribune.com/story/123037"><strong>New life for dead Tempe network?</strong></a> Another firm has expressed interest in buying the pennies on the dollar assets that remain of the former Kite Networks installation in Tempe from the firm that financed the venture as long as they can negotiate a new, more favorable deal with the city for mounting and removal rights. CTC, Inc., which the East Valley Tribune reports runs networks in the Kansas City, Mo., area, thinks there's an opportunity. The article notes that reception problems were due in part to the prevalence of stucco in Tempe, common in the southwest. Stucco walls layer plaster or other materials on a wire mesh for strength that turns a house into a bit of an accidental <a href="http://en.wikipedia.org/wiki/Faraday_cage"><strong>Faraday cage</strong></a>, partially shielding the home from electromagnetic radiation. (Could I go so far to say that Tempe's network could be a phoenix? Ouch.)</p>

<p><a href="http://www.usatoday.com/tech/products/2008-08-14-intel-wake-up-pcs_N.htm"><strong>Wake up, you darn computer:</strong></a> Intel's new Remote Wake motherboards won't work with Wi-Fi, it's important to note. The feature, announced today, will let an incoming VoIP call (the articles all say "phone call over the Internet") to wake a computer, as long as the call comes from a particular source. Of course, the standard SIP protocol for VoIP doesn't have the kind of security and integrity that would allow this; Intel has to overcome the problem with network address translation that renders most computer unreachable from outside the local network without a separate service like GoToMyPC or LogMeIn; and it will only work for computers connected via Ethernet to a local network, because Wi-Fi is off when a computer sleeps, while Ethernet can remain lightly active. I don't have the protocol details yet, but there's long been a <a href="http://en.wikipedia.org/wiki/Wake-on-LAN"><strong>Wake on LAN protocol</strong></a> that required support in a router, operating system, and Ethernet card; Intel may be leveraging this.</p>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 06:32:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/meraki">meraki</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network address translation">network address translation</category>
      <category domain="http://securityratty.com/tag/dead tempe network">dead tempe network</category>
      <category domain="http://securityratty.com/tag/dead">dead</category>
      <category domain="http://securityratty.com/tag/tempe">tempe</category>
      <category domain="http://securityratty.com/tag/standard">standard</category>
      <category domain="http://securityratty.com/tag/meraki indoor">meraki indoor</category>
      <category domain="http://securityratty.com/tag/meraki mini">meraki mini</category>
      <source url="http://wifinetnews.com/archives/008420.html">Wee-Fi: Meraki Modifies, Drops Standard; Tempe's Phoenix?; Remote Wake, Wi-Fi Need Not Apply</source>
    </item>
    <item>
      <title><![CDATA[Frequent Flyers Have More to Fear than Terrorists]]></title>
      <link>http://securityratty.com/article/4f0de09022ef86598ef36907bcbcdfd1</link>
      <guid>http://securityratty.com/article/4f0de09022ef86598ef36907bcbcdfd1</guid>
      <description><![CDATA[The last international flight I took, I was frisked carefully when the security realized I had a laptop with me. At the time I was a student on a 6-month trip for foreign study. Today Im taking...]]></description>
      <content:encoded><![CDATA[<p>The last international flight I took, I was frisked carefully when the security realized I had a laptop with me. At the time I was a student on a 6-month trip for foreign study. Today I&#8217;m taking another flight but it&#8217;s only down to LA for a friend&#8217;s wedding. I&#8217;ve been researching how much luggage I can take on board, and it&#8217;s not much, considering I regularly carry a few heavy items everywhere with me - my laptop, and my dslr camera, and naturally a book and purse.</p>
<p>I also came across this tidbit online &#8212; the government has granted themselves the right to take any traveler&#8217;s laptops away on international flights, even if they have no reason for suspicion. Apparently this has been in place a while but they&#8217;re finally publicizing it.</p>
<blockquote><p>Federal agents may take a traveler&#8217;s laptop computer or other electronic device to an off-site location for an unspecified period of time without any suspicion of wrongdoing, as part of border search policies the <a rel="nofollow" target="_blank" href="http://www.washingtonpost.com/ac2/related/topic/U.S.+Department+of+Homeland+Security?tid=informline">Department of Homeland Security</a> recently disclosed.</p>
<p>Also, officials may share copies of the laptop&#8217;s contents with other agencies and private entities for language translation, data decryption or other reasons, according to the policies, dated July 16 and issued by two DHS agencies, <a rel="nofollow" target="_blank" href="http://www.washingtonpost.com/ac2/related/topic/U.S.+Customs+and+Border+Protection?tid=informline">U.S. Customs and Border Protection</a> and <a rel="nofollow" target="_blank" href="http://www.washingtonpost.com/ac2/related/topic/U.S.+Bureau+of+Immigration+and+Customs+Enforcement?tid=informline">U.S. Immigration and Customs Enforcement</a>.</p></blockquote>
<p>Read the<a rel="nofollow" target="_blank" href="http://www.washingtonpost.com/wp-dyn/content/article/2008/08/01/AR2008080103030.html"> full article</a> here.</p>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 11:12:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/travelers laptop computer">travelers laptop computer</category>
      <category domain="http://securityratty.com/tag/homeland security recently">homeland security recently</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/customs enforcement">customs enforcement</category>
      <category domain="http://securityratty.com/tag/border protection">border protection</category>
      <category domain="http://securityratty.com/tag/international flight">international flight</category>
      <category domain="http://securityratty.com/tag/customs">customs</category>
      <category domain="http://securityratty.com/tag/agencies">agencies</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/353066110/">Frequent Flyers Have More to Fear than Terrorists</source>
    </item>
    <item>
      <title><![CDATA[U.S. Government Policy for Seizing Laptops at Borders]]></title>
      <link>http://securityratty.com/article/644821439b7605896de17d8ca6d3a3de</link>
      <guid>http://securityratty.com/article/644821439b7605896de17d8ca6d3a3de</guid>
      <description><![CDATA[Amazing. The U.S. government has published its policy : they can take you laptop anywhere they want, for as long as they want, and share the information with anyone they want
Here's the actual policy:...]]></description>
      <content:encoded><![CDATA[<p>Amazing.  The U.S. government has <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/08/01/AR2008080103030.html">published its policy</a>: they can take you laptop anywhere they want, for as long as they want, and share the information with anyone they want.</p>

<p><a href="http://www.cbp.gov/linkhandler/cgov/travel/admissability/search_authority.ctt/search_authority.pdf">Here's</a> the actual policy:</p>

<blockquote>Federal agents may take a traveler's laptop or other electronic device to an off-site location for an unspecified period of time without any suspicion of wrongdoing, as part of border search policies the Department of Homeland Security recently disclosed. Also, officials may share copies of the laptop's contents with other agencies and private entities for language translation, data decryption, or other reasons, according to the policies, dated July 16 and issued by two DHS agencies, US Customs and Border Protection and US Immigration and Customs Enforcement... DHS officials said that the newly disclosed policies — which apply to anyone entering the country, including US citizens — are reasonable and necessary to prevent terrorism... The policies cover 'any device capable of storing information in digital or analog form,' including hard drives, flash drives, cell phones, iPods, pagers, beepers, and video and audio tapes. They also cover 'all papers and other written documentation,' including books, pamphlets and 'written materials commonly referred to as "pocket trash..."</blockquote>

<p>It's not the policy that's amazing; it's the fact that the government has actually made it public.</p>

<p>Slashdot <a href="http://yro.slashdot.org/yro/08/08/01/0958242.shtml">thread</a>.  My previous <a href="http://www.schneier.com/essay-217.html">essay</a> on crossing borders with laptops, and how to protect yourself.</p>

<p>Although honestly, the best thing is probably to keep your encrypted archives on some network drive somewhere, and download what you need after you cross the border.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=xpja3K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=xpja3K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=vWPUNK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=vWPUNK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 08:21:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/policy">policy</category>
      <category domain="http://securityratty.com/tag/cover">cover</category>
      <category domain="http://securityratty.com/tag/policies cover">policies cover</category>
      <category domain="http://securityratty.com/tag/policies">policies</category>
      <category domain="http://securityratty.com/tag/actual policy">actual policy</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/border protection">border protection</category>
      <category domain="http://securityratty.com/tag/border">border</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/us_government_p.html">U.S. Government Policy for Seizing Laptops at Borders</source>
    </item>
    <item>
      <title><![CDATA[Links List 7.25.08]]></title>
      <link>http://securityratty.com/article/630a1fc26c11310563527f51eaebf464</link>
      <guid>http://securityratty.com/article/630a1fc26c11310563527f51eaebf464</guid>
      <description><![CDATA[The Wall Street Journal reports that the military is taking Tech Lessons . It seems that over the last few years, the DISA CIO has been visiting different tech companies to learn about cutting-edge...]]></description>
      <content:encoded><![CDATA[<p>The Wall Street Journal reports that the military is taking “<a href="http://blogs.wsj.com/biztech/2008/07/24/the-military-takes-tech-lessons/?mod=djemTECH" target="_blank">Tech Lessons</a>”. It seems that over the last few years, the DISA CIO has been visiting different tech companies to learn about cutting-edge technologies that might be able to help soldiers in the battlefield. CIO Garing identified social networks and mashups as great technologies for smaller projects with potentially more immediate impact than the traditional years-long IT projects of the past. He should check out NAPA and the Collaboration Project [link to Dan Munz Q&amp;A] which highlights just how government agencies and orgs are already doing what he’s talking about.
<p>Just what I was waiting for, <a href="http://news.cnet.com/8301-13505_3-9996318-16.html" target="_blank">open source takes on cloud computing</a>. <img src='http://blog.sciencelogic.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />
<p>We had a very interesting call this week with analyst firm, <a href="http://www.the451group.com/report_view/report_view.php?entity_id=54199" target="_blank">The 451 Group</a>, about the cloud and who is really doing what in this space now. Trying to separate the hype from reality, just like everyone else.
<p><a href="http://vmblog.com/archive/2008/07/23/forbes-interviews-vmware-ceo-paul-maritz-after-financial-analyst-call.aspx" target="_blank">After a disappointing (to analysts and the street) financial analyst call on Tuesday, VMware&#8217;s stock reached an all time low, almost back to the IPO stage</a>. In a follow-up interview, Forbes asked the new CEO what he thinks about the stock price, the analysts saying VMware doesn&#8217;t have a solid or innovative growth plan for the future, and whether <a href="http://vmware.com/" target="_blank">VMware</a> should be <a href="http://www.forbes.com/2008/07/22/vmware-maritz-qa-tech-intel-cx_wt_0722techvmware.html" target="_blank">part of EMC or not</a> (their backhand way of bringing up the whole Diane Greene thing…he didn’t fall for it).&nbsp;
<p>Wait for it…wait for it…we have been waiting for it. VMware announced plans to <a href="http://www.eweek.com/c/a/Infrastructure/VMwares-ESXi-Hypervisor-for-Free/?kc=EWKNLNAV07242008STR1" target="_blank">launch a free version of its ESXI hypervisor</a> starting July 28. I have to question the timing on this one. <a href="http://redmondmag.com/news/rss.asp?editorialsid=10067" target="_blank">Why didn’t they do this before Hyper-v came out</a> and try to at least undercut the Microsoft announcement? VMware is and should be the leader in this space but they act like they’re playing from behind. And to Wall Street, perception counts for a lot.
<p>Surprisingly, there hasn’t been a lot of coverage after the June 2008 OMB mandate on IPv6 readiness. But one interesting follow-up, <a href="http://www.networkworld.com/news/2008/072108-ipv6nat.html" target="_blank">a feature is set to be added to IPv6 which the upgrade was supposed to eliminate</a>. One of the <a href="http://www.circleid.com/posts/nat_just_say_no/">design goals</a> for IPv6 was that it would rid the Internet of network address translation (NAT), gateways that match increasingly scarce public IPv4 addresses with private IPv4 addresses used inside corporations, government agencies and other organizations.&nbsp; NAT adds complexity and cost, but due to the length of time it’s taken to migrate from IPv4 to IPv6, engineers may create special NAT devices to translate between IPv4-only and IPv6-only hosts and hopefully nudge along the transition to IPv6. IEEE is all set to meet on this topic later this month.</p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Links+List+7.25.08&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Flinks-list-72508%2F07%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Fri, 25 Jul 2008 08:28:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ipv6-only hosts">ipv6-only hosts</category>
      <category domain="http://securityratty.com/tag/ipv6">ipv6</category>
      <category domain="http://securityratty.com/tag/ipv6 readiness">ipv6 readiness</category>
      <category domain="http://securityratty.com/tag/nat">nat</category>
      <category domain="http://securityratty.com/tag/special nat devices">special nat devices</category>
      <category domain="http://securityratty.com/tag/financial analyst call">financial analyst call</category>
      <category domain="http://securityratty.com/tag/government agencies">government agencies</category>
      <category domain="http://securityratty.com/tag/ipv4 addresses">ipv4 addresses</category>
      <category domain="http://securityratty.com/tag/ipv4">ipv4</category>
      <source url="http://blog.sciencelogic.com/links-list-72508/07/2008">Links List 7.25.08</source>
    </item>
    <item>
      <title><![CDATA[Malware and Office Documents Joining Forces]]></title>
      <link>http://securityratty.com/article/dee3d028ca8134c75e2aec7f397d1493</link>
      <guid>http://securityratty.com/article/dee3d028ca8134c75e2aec7f397d1493</guid>
      <description><![CDATA[Common office files as documents, presentations, spreadsheets and PDF files, are the most widely abused ones in targeted attacks, which when backed up with enough personal information and take into...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHtuv_mJSwI/AAAAAAAAB6M/X83g6Zkr9hg/s1600-h/screen1.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHtuv_mJSwI/AAAAAAAAB6M/b0YAu_NWEQk/s200-R/screen1.jpg" style="border: 0pt none ;" /></a>Common office files as documents, presentations, spreadsheets and PDF files, are the most widely abused ones in targeted attacks, which when backed up with enough personal information and take into consideration the time of their attack if the social engineering campaign is either going to be based on a current/upcoming event, or on an event anticipated due to information gathered through open source intelligence, often make it through common signature based scanning solutions.<br />
<br />
Despite the relatively easy to obtain, point'n'click <a href="http://www.f-secure.com/weblog/archives/00001450.html">DIY tools for backdooring common office files</a> are available for the script kiddies to take advantage of, some are <a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">naturally remaining proprietary tools</a>, making them harder to analyze unless a copy is obtained. Like this one, generating "undetected" by signatures based scanning, office documents and spreadsheets that would drop the actual malware on the PC.<br />
<br />
Automatic translation of its description and core features :<br />
<br />
<i>"The program represents a generator OfficeJoiner macros in the language Visual Basic for Application (VBA), for introduction in the document Microsoft Office Word / Microsoft Office Excel executable file (win32 exe), followed by fully automatic recovery and launch, without any&nbsp; additional action by the user. The only requirement that formed in such a way xls / doc files is to support&nbsp; VBA macros on the computer end-user formed file and permission to launch macros.</i><br />
<br />
<i>The program uses NOT a vulnerability (exploit) or macro-virus tools for the introduction, extraction or running embedded files. This means that it has generated macros compatible with ALL versions of Microsoft Office products starting with Microsoft Office 97 package, with any established "patches" and the service pack. Macros generated by this program not detected antivirus, for the simple reason that they are not viruses or macro viruses. The program uses only "established" means products built into Microsoft Excel VBA language to achieve their goals.</i><br />
<br />
<i>- Fully automatic generation of macro for the introduction of documents word / excel any given exe-file with his persistence in the body and subsequent documents automatic recovery and launch, when opening a document word / excel.&nbsp;</i><br />
<br />
<i>- Generated macros are compatible with all versions of ms word / excel since version 97,&nbsp; employments and regardless of the presence / absence of any patches / servicepacs.&nbsp;</i><br />
<br />
<i>- Generated macros are not macro-viruses, exploits do not use and do not contain any malicious code, so do not be detected by any antivirus tools as viruses.&nbsp;</i><br />
<br />
<i>- Conversion body ex-file macro happening in such a way that while in doc / xls file it not detected any antivirus, and can be freely sent by mail safely passed all checks, even if in itself contains viral code defined antivirus. <br />
&nbsp;</i><br />
<i>- Sgenerirovanny and attached to the body of the document macro can be protected with a password or signed certificate, using funds established Microsoft Office, which does not affect him productivity or efficiency (macro, in any case remain fully workable).&nbsp;</i><br />
<br />
<i>- Box macro can be made both in the new document, and in any document containing data and-or other macros. Generated program code is fully compatible with any other embedded in the document macros or entering data, and will not interfere with their work, as well as maintain its efficiency.</i><br />
<br />
<div dir="ltr" id="result_box"><i>- Added auto-finding ways to extract exe-file; <br />
&nbsp;</i></div>
<div dir="ltr" id="result_box"><i>- Added possibility of a macro arbitrary text in the body of the instrument; <br />
&nbsp;</i></div>
<div dir="ltr" id="result_box"><i>- Optimized algorithm macro-generation code; <br />
</i></div>
<div dir="ltr" id="result_box"><i>&nbsp;</i> </div>
<div dir="ltr" id="result_box"></div>
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<div dir="ltr" id="result_box"><a href="http://bp1.blogger.com/_wICHhTiQmrA/SHt7EgPiRwI/AAAAAAAAB6U/BtNJaK_13LM/s1600-h/officedocs_malware_sample.PNG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHt7EgPiRwI/AAAAAAAAB6U/xhaiKacT-eM/s200-R/officedocs_malware_sample.PNG" style="border: 0pt none ;" /></a><i>Enabling this option will lead to the creation macro code, who himself will find a way to unpack and run embedded exe-file. Auto-search finds the current user folder and produces there extraction and launch embedded file. The peculiarity of this method is that this method will work on the computers of users with a limited account, because in its user folder in any case has the right to record / performance. Using this option is justified to improve the "punching" macro on computers with limited account or unknown file structure (let Windows installed on the disk is different from C). <br />
<br />
You can specify a name for final file independently, or leave blank, then the name will be generated automatically.</i> </div>
<div dir="ltr" id="result_box"><i><br />
</i></div>
<div dir="ltr" id="result_box"><i>On this possibility has asked for a user program, its essence is that after running a macro, retrieval and downloading exe-file the document with the introduction of exe-file will be withdrawn posed text. Perhaps in this way can improve the application of social engineering, designed to force the user to allow support for macros. For example, in the text of the document indicate: <br />
<br />
"This document contains hidden text (password, a system of calculation formulas, interactive components, etc.), Which can be viewed only after the inclusion of support macros. Please enable support for macros and re-opening this document ". <br />
<br />
After resolving support macros, and the implementation of embedded exe-file, the document will be withdrawn given a string containing probable "password" or any other textual information.</i>  " </div>
<br />
Despite that the tool is proprietary, the underground economy's leaks are largely driven by bargain hunters who would exchange proprietary tool, whose often biased exclusiveness may increase the profit margins, for a service or a good that may be worthless for them in general, but impossible to obtain and take advantage of in the present. It will not just leak in one way or another, someone will inevitably backdoor the backdooring tool and trick the novice bargain hunters into running it, by having both their host infected and money taken.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/yet-another-diy-proprietary-malware.html">Yet Another DIY Proprietary Malware Builder</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The Small Pack Web Malware Exploitation Kit - Proprietary</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/diy-exploit-embedding-tool-proprietary.html">DIY Exploit Embedding Tool - A Proprietary Release</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/skype-spamming-tool-in-wild.html">Skype Spamming Tool in the Wild - Proprietary Release</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mMDIJJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mMDIJJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vtGZUJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vtGZUJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Voeqqj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Voeqqj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QZJLHj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QZJLHj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4VmcIJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4VmcIJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rqLHKJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rqLHKJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LnaC8j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LnaC8j" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/335226251" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 14 Jul 2008 07:20:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/document">document</category>
      <category domain="http://securityratty.com/tag/document macros">document macros</category>
      <category domain="http://securityratty.com/tag/support">support</category>
      <category domain="http://securityratty.com/tag/enable support">enable support</category>
      <category domain="http://securityratty.com/tag/macro">macro</category>
      <category domain="http://securityratty.com/tag/macro viruses">macro viruses</category>
      <category domain="http://securityratty.com/tag/support vba macros">support vba macros</category>
      <category domain="http://securityratty.com/tag/exe-file">exe-file</category>
      <category domain="http://securityratty.com/tag/extract exe-file">extract exe-file</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/335226251/malware-and-office-documents-joining.html">Malware and Office Documents Joining Forces</source>
    </item>
  </channel>
</rss>
