<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: trial]]></title>
    <link>http://securityratty.com/tag/trial</link>
    <description></description>
    <pubDate>Wed, 30 Jul 2008 09:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[High court narrows penalty against Qualcomm]]></title>
      <link>http://securityratty.com/article/71afe084027e80a4a19b571596de4fa9</link>
      <guid>http://securityratty.com/article/71afe084027e80a4a19b571596de4fa9</guid>
      <description><![CDATA[A federal appeals court on Monday narrowed the penalty against Qualcomm for misleading a standards body and committing misconduct during a...]]></description>
      <content:encoded><![CDATA[A federal appeals court on Monday narrowed the penalty against Qualcomm for misleading a standards body and committing misconduct during a trial.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:5808febbd6d4427f3cd1c5a945049eba:MNPqQbJtj8Eu7iSSHADYIJAdx6QiXwoHX2Z%2BsA8CTNhORwdKyHl40%2BNpNqAg9ahSQRkKuuvlEHCN'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:be6a3cf7156e4666e9c45d06ace5db16:kRsXX7aeg68xNDhAz%2B8caZ9HJMSQUtNTnlV5EOzQmy1WhTcOP%2BM1ijECi1dOzcks1CfJz5vEP%2FY4DA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:2caafa53871c67d4abfdaf9239e5bcb2:ylxTlUAgIPoXjfrFe7zHcUVYpxecCJvgA4X%2Fcts7vhUrtOo%2BJeIPRZQqjE7GY6H%2BRVEsWqHME1WdFw%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:3e56919010941a60d8e5636de2ffc9cd:e%2B3VhEeytxWhDljYUKMp1%2FVuCqgh9QdZCS1HF90ma4Qx5lqEp2B%2Be%2FqCW4BCQV6uipCaGCYJjb6MMQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=4c0dd3a94288e777d5504adfe2cc411c&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=4c0dd3a94288e777d5504adfe2cc411c&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=4c0dd3a94288e777d5504adfe2cc411c" style="display: none;" border="0" height="1" width="1" alt=""/>
]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/federal appeals court">federal appeals court</category>
      <category domain="http://securityratty.com/tag/penalty">penalty</category>
      <category domain="http://securityratty.com/tag/standards body">standards body</category>
      <category domain="http://securityratty.com/tag/qualcomm">qualcomm</category>
      <category domain="http://securityratty.com/tag/trial">trial</category>
      <category domain="http://securityratty.com/tag/misconduct">misconduct</category>
      <category domain="http://securityratty.com/tag/monday">monday</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=4c0dd3a94288e777d5504adfe2cc411c">High court narrows penalty against Qualcomm</source>
    </item>
    <item>
      <title><![CDATA[Schoolteacher Julie Amero Released, Felony Charges Dropped]]></title>
      <link>http://securityratty.com/article/611d98bfbfc8499b8666035962d050e9</link>
      <guid>http://securityratty.com/article/611d98bfbfc8499b8666035962d050e9</guid>
      <description><![CDATA[One of the real danger of technology, the reason for so much IT-Insecurity, is that many people dont understand it well
Case in point is the jury trial of Julie Amero, a schoolteacher who was charged...]]></description>
      <content:encoded><![CDATA[<p>One of the real danger of technology, the reason for so much IT-Insecurity, is that many people don&#8217;t understand it well.</p>
<blockquote><p>Case in point is the jury trial of <a rel="nofollow" target="_blank" href="http://voices.washingtonpost.com/securityfix/2008/11/ct_drops_felony_spywareporn_ch.html">Julie Amero, </a>a schoolteacher who was charged with felony for allegedly showing porn to her class&#8211;when in fact the porn sites were popups caused by malware on the classroom computers that popped up <a rel="nofollow" target="_blank" href="http://techbuddha.wordpress.com/2008/11/22/injustice-served-the-julie-amero-case-is-finally-over/">while she was teaching</a>:</p></blockquote>
<blockquote><p>a series of incompetent computer experts and overzealous prosecutors tried to claim that the pornography that appeared on the school computer browser was deliberately viewed. In reality the computer was infected with a browser hijack or other form of malware nastiness that launched a flood of porn pop-ups. There was an outpouring of support and some technical folks like Alex Eckleberry, who led an effort to prove that Julie was innocent of the charges</p></blockquote>
<p>After a long trial, Amero has finally been vindicated. But she has still lost those years of her life spent on the case, her teaching credential, and is being charged a $100 fine. While her trial might be over, her personal troubles aren&#8217;t.</p>]]></content:encoded>
      <pubDate>Mon, 24 Nov 2008 10:35:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/julie amero">julie amero</category>
      <category domain="http://securityratty.com/tag/julie">julie</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/incompetent computer experts">incompetent computer experts</category>
      <category domain="http://securityratty.com/tag/amero">amero</category>
      <category domain="http://securityratty.com/tag/porn sites">porn sites</category>
      <category domain="http://securityratty.com/tag/porn">porn</category>
      <category domain="http://securityratty.com/tag/trial">trial</category>
      <category domain="http://securityratty.com/tag/jury trial">jury trial</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/464364814/">Schoolteacher Julie Amero Released, Felony Charges Dropped</source>
    </item>
    <item>
      <title><![CDATA[OAuth for Secure Mashups]]></title>
      <link>http://securityratty.com/article/f0ebee1b88f03cd2b1ad9ff61f4608ac</link>
      <guid>http://securityratty.com/article/f0ebee1b88f03cd2b1ad9ff61f4608ac</guid>
      <description><![CDATA[Posted by Eric Sachs, Senior Product Manager, Google Security

A year ago, a number of large and small websites announced a new open standard called OAuth . This standard is designed to provide a...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Posted by Eric Sachs, Senior Product Manager, Google Security</span><br /><br />A year ago, a number of large and small websites announced a new open standard called <a href="http://oauth.net/" id="hz33" title="OAuth">OAuth</a>. This standard is designed to provide a secure and privacy-preserving technique for enabling specific private data on one site to be accessed by another site.  One popular reason for that type of cross-site access is data portability in areas such as personal health records (such as Google Health or Microsoft Healthvault), as well as social networks (such as OpenSocial enabled sites). I originally became involved in this space in the summer of 2005, when Google started developing a feature called <a href="http://code.google.com/apis/accounts/docs/AuthSub.html" id="e3yh" title="AuthSub">AuthSub</a>, which was one of the pre-cursors of OAuth. That was a proprietary protocol, but one that has been used by hundreds of websites to provide add-on services to Google Account users by getting permission from users to access data in their Google Accounts.  In fact, that was the key feature that a few of us used to start the Google Health portability effort back when it was only a prototype project with a few dedicated Googlers.  <div id="zq.s" style="margin-top: 0px; margin-bottom: 0px;"><br /></div>  <div id="zq.s1" style="margin-top: 0px; margin-bottom: 0px;"> However, with the development of a common Internet standard in OAuth, we see much greater potential for data portability and secure mash-ups. Today we <a href="http://igoogledeveloper.blogspot.com/2008/11/sign-in-to-myspace-aol-mail-and-google.html">announced</a> that the gadget platform now supports OAuth, and the interoperability of this standard was demonstrated by new iGoogle gadgets that AOL and MySpace both built to enable users to see their respective AOL or MySpace mailboxes (and other information) while on iGoogle. However, to ensure the user's privacy, this only works after the user has authorized AOL or MySpace to make their data available to the gadget running on iGoogle.  We also previously <a href="http://googledataapis.blogspot.com/2008/10/whats-that-google-data-gadgets.html" id="w6.8" title="announced">announced</a> that third-party developers can build their own iGoogle gadgets that access the OAuth-enabled APIs for Google applications such as Calendar, Picasa, and Docs. In fact, since both the gadget platform and OAuth technology are open standards, we are working to help other companies who run services similar to iGoogle to enhance them with support for these standards. Once that is in place, these new OAuth-powered gadgets that are available on iGoogle will also work on those other sites, including many of the gadgets that Google offers for its own applications. This provides a platform for some interesting mash-ups.  For example, a third-party developer could create a single gadget that uses OAuth to access both Google OAuth-enabled APIs (such as a Gmail user's <a href="http://code.google.com/apis/contacts/" id="v05v" title="address book">address book</a>) and <a href="http://developer.myspace.com/community/myspace/dataavailability.aspx" id="lewp" title="MySpace OAuth enabled APIs">MySpace OAuth-enabled APIs</a> (such as a user's friend list) and display a mashup of the combination.  </div>  <div id="d23k" style="margin-top: 0px; margin-bottom: 0px;"><br /></div>  <div id="ivuk" style="margin-top: 0px; margin-bottom: 0px;"> While the combination of OAuth with gadgets is an exciting new use of the technology, most of the use of OAuth is between websites, such as to enable a user of Google Health to allow a clinical trial matching site to access his or her health profile.  I previously mentioned that one privacy control provided by OAuth is that it defines a standard way for users to authorize one website to make their data accessible to another website. In addition, OAuth provides a way to do this without the first site needing to reveal the identity of the user -- it simply provides a different opaque security token to each additional website the user wants to share his or her data with.  It would allow a mutual fund, for example, to provide an iGoogle gadget to their customers that would run on iGoogle and show the user the value of his or her mutual fund, but without giving Google any unique information about the user, such as a social security number or account number.  In the future, maybe we will even see industries like banks use standards such as OAuth to allow their customers to authorize utility companies to perform direct debit from the user's bank account without that person having to actually share his or her bank account number with the utility vendor. </div>  <div id="pvsw" style="margin-top: 0px; margin-bottom: 0px;"><br /></div>  <div id="odub" style="margin-top: 0px; margin-bottom: 0px;"> The OAuth community is continuing to enhance this standard and is very interested in having more companies engaged with its development. The <a href="http://oauth.net/" id="q6e4" title="OAuth">OAuth.net</a> website has more details about the current standard, and I maintain a <a href="http://sites.google.com/site/oauthgoog/" id="uw8z" title="website">website</a> with advanced information about Google's use of OAuth, including work on integrating OAuth with desktop apps, and integrating with federation standards such as OpenID and SAML.  If you're interested in engaging with the OAuth community, please get in touch with us. </div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=LcHtN"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=LcHtN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=7jAKn"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=7jAKn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/458667878" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 14:41:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oauth">oauth</category>
      <category domain="http://securityratty.com/tag/oauth community">oauth community</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/google accounts">google accounts</category>
      <category domain="http://securityratty.com/tag/oauth technology">oauth technology</category>
      <category domain="http://securityratty.com/tag/google security">google security</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/bank account">bank account</category>
      <category domain="http://securityratty.com/tag/gadget">gadget</category>
      <source url="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~3/458667878/oauth-for-secure-mashups.html">OAuth for Secure Mashups</source>
    </item>
    <item>
      <title><![CDATA[OAuth for Secure Mashups]]></title>
      <link>http://securityratty.com/article/dce22eb7ff2c1aceec169c6236231696</link>
      <guid>http://securityratty.com/article/dce22eb7ff2c1aceec169c6236231696</guid>
      <description><![CDATA[Posted by Eric Sachs, Senior Product Manager, Google Security

A year ago, a number of large and small websites announced a new open standard called OAuth . This standard is designed to provide a...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Posted by Eric Sachs, Senior Product Manager, Google Security</span><br /><br />A year ago, a number of large and small websites announced a new open standard called <a href="http://oauth.net/" id="hz33" title="OAuth">OAuth</a>. This standard is designed to provide a secure and privacy-preserving technique for enabling specific private data on one site to be accessed by another site.  One popular reason for that type of cross-site access is data portability in areas such as personal health records (such as Google Health or Microsoft Healthvault), as well as social networks (such as OpenSocial enabled sites). I originally became involved in this space in the summer of 2005, when Google started developing a feature called <a href="http://code.google.com/apis/accounts/docs/AuthSub.html" id="e3yh" title="AuthSub">AuthSub</a>, which was one of the pre-cursors of OAuth. That was a proprietary protocol, but one that has been used by hundreds of websites to provide add-on services to Google Account users by getting permission from users to access data in their Google Accounts.  In fact, that was the key feature that a few of us used to start the Google Health portability effort back when it was only a prototype project with a few dedicated Googlers.  <div id="zq.s" style="margin-top: 0px; margin-bottom: 0px;"><br /></div>  <div id="zq.s1" style="margin-top: 0px; margin-bottom: 0px;"> However, with the development of a common Internet standard in OAuth, we see much greater potential for data portability and secure mash-ups. Today we <a href="http://igoogledeveloper.blogspot.com/2008/11/sign-in-to-myspace-aol-mail-and-google.html">announced</a> that the gadget platform now supports OAuth, and the interoperability of this standard was demonstrated by new iGoogle gadgets that AOL and MySpace both built to enable users to see their respective AOL or MySpace mailboxes (and other information) while on iGoogle. However, to ensure the user's privacy, this only works after the user has authorized AOL or MySpace to make their data available to the gadget running on iGoogle.  We also previously <a href="http://googledataapis.blogspot.com/2008/10/whats-that-google-data-gadgets.html" id="w6.8" title="announced">announced</a> that third-party developers can build their own iGoogle gadgets that access the OAuth-enabled APIs for Google applications such as Calendar, Picasa, and Docs. In fact, since both the gadget platform and OAuth technology are open standards, we are working to help other companies who run services similar to iGoogle to enhance them with support for these standards. Once that is in place, these new OAuth-powered gadgets that are available on iGoogle will also work on those other sites, including many of the gadgets that Google offers for its own applications. This provides a platform for some interesting mash-ups.  For example, a third-party developer could create a single gadget that uses OAuth to access both Google OAuth-enabled APIs (such as a Gmail user's <a href="http://code.google.com/apis/contacts/" id="v05v" title="address book">address book</a>) and <a href="http://developer.myspace.com/community/myspace/dataavailability.aspx" id="lewp" title="MySpace OAuth enabled APIs">MySpace OAuth-enabled APIs</a> (such as a user's friend list) and display a mashup of the combination.  </div>  <div id="d23k" style="margin-top: 0px; margin-bottom: 0px;"><br /></div>  <div id="ivuk" style="margin-top: 0px; margin-bottom: 0px;"> While the combination of OAuth with gadgets is an exciting new use of the technology, most of the use of OAuth is between websites, such as to enable a user of Google Health to allow a clinical trial matching site to access his or her health profile.  I previously mentioned that one privacy control provided by OAuth is that it defines a standard way for users to authorize one website to make their data accessible to another website. In addition, OAuth provides a way to do this without the first site needing to reveal the identity of the user -- it simply provides a different opaque security token to each additional website the user wants to share his or her data with.  It would allow a mutual fund, for example, to provide an iGoogle gadget to their customers that would run on iGoogle and show the user the value of his or her mutual fund, but without giving Google any unique information about the user, such as a social security number or account number.  In the future, maybe we will even see industries like banks use standards such as OAuth to allow their customers to authorize utility companies to perform direct debit from the user's bank account without that person having to actually share his or her bank account number with the utility vendor. </div>  <div id="pvsw" style="margin-top: 0px; margin-bottom: 0px;"><br /></div>  <div id="odub" style="margin-top: 0px; margin-bottom: 0px;"> The OAuth community is continuing to enhance this standard and is very interested in having more companies engaged with its development. The <a href="http://oauth.net/" id="q6e4" title="OAuth">OAuth.net</a> website has more details about the current standard, and I maintain a <a href="http://sites.google.com/site/oauthgoog/" id="uw8z" title="website">website</a> with advanced information about Google's use of OAuth, including work on integrating OAuth with desktop apps, and integrating with federation standards such as OpenID and SAML.  If you're interested in engaging with the OAuth community, please get in touch with us. </div><div class="feedflare">
<a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=RbYKY1QI"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?d=41" border="0"></img></a> <a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=livMlZFo"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?i=livMlZFo" border="0"></img></a>
</div><img src="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~4/bEpTg1dntxU" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 14:41:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oauth">oauth</category>
      <category domain="http://securityratty.com/tag/oauth community">oauth community</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/google accounts">google accounts</category>
      <category domain="http://securityratty.com/tag/oauth technology">oauth technology</category>
      <category domain="http://securityratty.com/tag/google security">google security</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/bank account">bank account</category>
      <category domain="http://securityratty.com/tag/gadget">gadget</category>
      <source url="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/bEpTg1dntxU/oauth-for-secure-mashups.html">OAuth for Secure Mashups</source>
    </item>
    <item>
      <title><![CDATA[Judge delays trial of accused Palin e-mail hacker]]></title>
      <link>http://securityratty.com/article/d52677b2a4442562984a1693d81f32f3</link>
      <guid>http://securityratty.com/article/d52677b2a4442562984a1693d81f32f3</guid>
      <description><![CDATA[David Kernell, the Tennessee college student indicted a month ago for allegedly breaking into the e-mail account of former Republican vice presidential candidate Sarah Palin, will face trial next May,...]]></description>
      <content:encoded><![CDATA[David Kernell, the Tennessee college student indicted a month ago for allegedly breaking into the e-mail account of former Republican vice presidential candidate Sarah Palin, will face trial next May, according to court documents.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:75ca0e1b2679abdc8e80e5c04af6a7c1:FEsT5%2Bl42HIIOpJv5TLGUGh418ngBUPLgQUGqDI56ivRF5Dedt8X5fQDn5nGFOLrZ7ztkCiHHKFn'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:912d0323f156b79dc504eb94eec41651:y49LZU3y03lRUchaYpONNawBrfptSu8ql94QVUO20MSKQ3jqdJj2na4yScmu2MNXeRW2O%2BhauSw8Tw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:02624b5cc90a1c55fe9ba385f37ede12:Y6I2m0f3BQAdR73O1zTHa98zFJ5pnTrmrySEtfdB1mLH8a1ubp396tupsMPonfYq%2BsaOL2INFw8lew%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:f69c9add5cb853b5d220d8bc79a9c74c:schohYltx26WnFfsYtvXfEeUKBL8E3S3thp2bH4CydbInBgGC4tBBjzy5Ij3sBMCAtYC94EBIWGhnQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=58c56c44f9aecaeb7e89af14b6ac5853" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=58c56c44f9aecaeb7e89af14b6ac5853" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tennessee college student">tennessee college student</category>
      <category domain="http://securityratty.com/tag/republican vice presidential">republican vice presidential</category>
      <category domain="http://securityratty.com/tag/trial">trial</category>
      <category domain="http://securityratty.com/tag/e-mail account">e-mail account</category>
      <category domain="http://securityratty.com/tag/david kernell">david kernell</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/month ago">month ago</category>
      <category domain="http://securityratty.com/tag/court documents">court documents</category>
      <category domain="http://securityratty.com/tag/allegedly">allegedly</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=58c56c44f9aecaeb7e89af14b6ac5853">Judge delays trial of accused Palin e-mail hacker</source>
    </item>
    <item>
      <title><![CDATA[Judge delays trial of accused Palin e-mail hacker]]></title>
      <link>http://securityratty.com/article/e75c336d986a975f6543b085214939aa</link>
      <guid>http://securityratty.com/article/e75c336d986a975f6543b085214939aa</guid>
      <description><![CDATA[The Tennessee college student indicted a month ago for allegedly breaking into the e-mail account of then-Republican vice presidential candidate Sarah Palin will face trial in May 2009, not next month...]]></description>
      <content:encoded><![CDATA[The Tennessee college student indicted a month ago for allegedly breaking into the e-mail account of then-Republican vice presidential candidate Sarah Palin will face trial in May 2009, not next month as originally scheduled, according to recent court documents.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=24395?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=24395?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Sun, 16 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/month">month</category>
      <category domain="http://securityratty.com/tag/recent court documents">recent court documents</category>
      <category domain="http://securityratty.com/tag/then-republican vice presidential">then-republican vice presidential</category>
      <category domain="http://securityratty.com/tag/tennessee college student">tennessee college student</category>
      <category domain="http://securityratty.com/tag/month ago">month ago</category>
      <category domain="http://securityratty.com/tag/trial">trial</category>
      <category domain="http://securityratty.com/tag/e-mail account">e-mail account</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/allegedly">allegedly</category>
      <source url="http://www.networkworld.com/news/2008/111708-judge-delays-trial-of-accused.html?fsrc=rss-security">Judge delays trial of accused Palin e-mail hacker</source>
    </item>
    <item>
      <title><![CDATA[Four Google officials likely to stand trial in Italy]]></title>
      <link>http://securityratty.com/article/587e13df8650eea41de19fe82e61cabf</link>
      <guid>http://securityratty.com/article/587e13df8650eea41de19fe82e61cabf</guid>
      <description><![CDATA[Google is awaiting confirmation that four employees will face charges in Italy for failing to stop the publishing of a video of a disabled teenager being...]]></description>
      <content:encoded><![CDATA[Google is awaiting confirmation that four employees will face charges in Italy for failing to stop the publishing of a video of a disabled teenager being bullied.]]></content:encoded>
      <pubDate>Wed, 05 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/italy">italy</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/stop">stop</category>
      <category domain="http://securityratty.com/tag/teenager">teenager</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/charges">charges</category>
      <category domain="http://securityratty.com/tag/confirmation">confirmation</category>
      <source url="http://www.networkworld.com/news/2008/110608-four-google-officials-likely-to.html?fsrc=rss-security">Four Google officials likely to stand trial in Italy</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Twelve]]></title>
      <link>http://securityratty.com/article/d462bee817ac892232f1b929608cd422</link>
      <guid>http://securityratty.com/article/d462bee817ac892232f1b929608cd422</guid>
      <description><![CDATA[These very latest rogue security software domains have been in circulation -- blackhat SEO, SQL injections, traffic redirection scripts -- since Friday and remain active

premium-pc-scan .com...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQ9py9LcidI/AAAAAAAACaU/fQfM4EAzuKo/s1600-h/rogue_security_software_portfolio_november.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQ9py9LcidI/AAAAAAAACaU/dLsxwtYrDik/s200-R/rogue_security_software_portfolio_november.png" /></a>These very latest rogue security software domains have been in circulation -- blackhat SEO, SQL injections, traffic redirection scripts -- since Friday and remain active : <br />
<br />
<b>premium-pc-scan .com</b> (78.159.118.217; 89.149.253.215; 91.203.92.47)<br />
<b>antivirus-pc-scan .com</b> (208.72.169.100)<br />
<b>securityfullscan .com</b> (84.243.197.184)<br />
<b>antivirus-live-scan .com</b> (84.243.196.136; 89.149.227.196)<br />
<b>windefender-2009 .com</b> - (200.63.45.55)<br />
<b>windefender2009 .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SQ9q3PPub7I/AAAAAAAACac/4qLyQ0P9_iY/s1600-h/rogue_security_software_portfolio_november_1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SQ9q3PPub7I/AAAAAAAACac/mxOldlIx5B4/s200-R/rogue_security_software_portfolio_november_1.png" /></a>What these domains have in common, excluding the last two WinDefender ones, is the domain registrant, the DNS servers used, and that despite the fact that it has already been featured in several malicious doorways, meaning these are receiving traffic already, they forgot to upload the binaries on all of the active domains : <br />
<br />
"<i>Not Found. The requested URL /2009/download/trial/A9installer_.exe was not found on this server.</i>"<br />
<br />
<i>Registrant:&nbsp;</i><br />
<i>Vladimir Polilov&nbsp;</i><br />
<i>Email: gpdomains@yahoo.com</i><br />
<i>Organization: Private person</i><br />
<i>Address: ul. Bauma 13-76</i><br />
<i>City: Moskva</i><br />
<i>State: Moskovskaya oblast</i><br />
<i>ZIP: 112621</i><br />
<i>Country: RU</i><br />
<i>Phone: +7.9031609536 </i><br />
<br />
DNS servers used - <i>ns1.freefastdns.com; ns2.freefastdns.com</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SQ9uoEsQJ9I/AAAAAAAACak/3NBPR8SZ5q0/s1600-h/rogue_security_software_portfolio_november_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SQ9uoEsQJ9I/AAAAAAAACak/rpBUB4rPmgI/s200-R/rogue_security_software_portfolio_november_2.png" /></a>Moreover, the following domains are also parked at the same IPs, but are currently in stand-by mode, yet they're also using the same DNS servers with the only difference in the registrant who seems to have been running a very extensive portfolio of bogus domains, potentially making hundreds of thousands in the process :<br />
<br />
<b>save-my-pc-now .com<br />
real-antivirus .com<br />
liveantivirustest .com<br />
antiviruspctest .com<br />
premium-live-scan .com<br />
liveantivirustest .com<br />
antiviruspersonaltest .com<br />
mysecuritysupport .com<br />
updateyourprotection .com<br />
antivirus-premiumscan .com<br />
securitylivescan .com<br />
security-full-scan .com<br />
secured-liveupdate .com<br />
livepcupdate .com<br />
protection-update .com<br />
antivirus-scan-online .com<br />
xpsoftupgrade .com<br />
live-virus-defence .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQ9xN8GkbcI/AAAAAAAACas/ebLo_gyI2Mg/s1600-h/rogue_software_phones_back_home.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQ9xN8GkbcI/AAAAAAAACas/olFP5HLvCFg/s200-R/rogue_software_phones_back_home.JPG" /></a><i>Registrant:<br />
Shestakov Yuriy <br />
alexey@cocainmail.com/alexeyvas@safe-mail.net <br />
+7.9218839910<br />
Lenina 21 16<br />
Mirniy,MSK,RU 102422</i><br />
<br />
The sampled WinDefender binaries phone back to <b>megauplinkbindinstaller .com/cfg1.php</b> (91.203.92.99) with the entire netblock clearly a bad neighborhood. Here are some sample command and control locations :<br />
<br />
<b>91.203.92.101 /admin/cd.php?userid=19102008_184429_260953 <br />
91.203.92.25 /dmn/domen.txt<br />
91.203.92.135 /alligator/cfg.bin<br />
91.203.92.132 /c.bin</b><br />
<br />
This operation is being monitored, results will be posted as they emerge.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_28.html">A Diverse Portfolio of Fake Security Software - Part Eleven</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_22.html">A Diverse Portfolio of Fake Security Software - Part Ten</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_16.html">A Diverse Portfolio of Fake Security Software - Part Nine</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Eight</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">A Diverse Portfolio of Fake Security Software - Part Seven</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html">A Diverse Portfolio of Fake Security Software - Part Six</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Five</a> <br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A  Diverse Portfolio of Fake Security Software - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A  Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse  Portfolio of Fake Security Software</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KFegN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KFegN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uDICN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uDICN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=g1W6n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=g1W6n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=V2Qnn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=V2Qnn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HZkbN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HZkbN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1Md6N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1Md6N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IxBRn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IxBRn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/441437574" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 03 Nov 2008 13:11:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/windefender binaries phone">windefender binaries phone</category>
      <category domain="http://securityratty.com/tag/active domains">active domains</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/dns servers">dns servers</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/registrant">registrant</category>
      <category domain="http://securityratty.com/tag/domain registrant">domain registrant</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/441437574/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Twelve</source>
    </item>
    <item>
      <title><![CDATA[Minnesota woman fined $222,000 for music piracy gets new trial]]></title>
      <link>http://securityratty.com/article/b09b4ef38f104787606aae6eac832354</link>
      <guid>http://securityratty.com/article/b09b4ef38f104787606aae6eac832354</guid>
      <description><![CDATA[A federal judge has overturned a jury verdict that ordered a Minnesota woman to pay $222,000 to various record companies for illegally copying and distributing 24...]]></description>
      <content:encoded><![CDATA[A federal judge has overturned a jury verdict that ordered a Minnesota woman to pay $222,000 to various record companies for illegally copying and distributing 24 songs.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:391ec8f2ee9099dc23a8d6710f76f36c:wfNgUpvYKYWHwoLj4W7Gd1VrRxcM2GNPvbB5Cg%2BfBKKqhUb0BqNmKlfdb9wmvwoST3wx7oLQcZaq'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:0b72af8e720441b2fd2be6e0485a426c:0L3C5fRILuHysx3QoS9eJVwS22diQEPDlEDPU5V4kpug3daKYImjPj0mAcNeX2ZPA%2Fylqcv8Ognj4Q%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:b7b6138459eb999fbc21fde07c7538db:H0knlKnbi3Ospp1n7ackqaskdQfbF4zVIb7l5eLbBW9nng03PRjW%2BzKKgJ9JV9JYSR1cE311FJH4Dw%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:aba670347bb00836cac091470addb75f:py2IMJTur2OS44roGP%2FuHPu7c7vfpJqW1etFcchBzsJDyoOKh9geC2a6OWfp5pVyFisWF1irjbjm1A%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=e3cdb851c1352e4f7c3de7013df13de1" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=e3cdb851c1352e4f7c3de7013df13de1" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/minnesota woman">minnesota woman</category>
      <category domain="http://securityratty.com/tag/record companies">record companies</category>
      <category domain="http://securityratty.com/tag/jury verdict">jury verdict</category>
      <category domain="http://securityratty.com/tag/federal judge">federal judge</category>
      <category domain="http://securityratty.com/tag/songs">songs</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=e3cdb851c1352e4f7c3de7013df13de1">Minnesota woman fined $222,000 for music piracy gets new trial</source>
    </item>
    <item>
      <title><![CDATA[Extradition appeal for British hacker dismissed]]></title>
      <link>http://securityratty.com/article/6cc2c40ac1e835d88cfc6697408ed5e3</link>
      <guid>http://securityratty.com/article/6cc2c40ac1e835d88cfc6697408ed5e3</guid>
      <description><![CDATA[A British hacker who admitted breaking into U.S. military computers hoping to uncover evidence of UFOs looks set to head here for...]]></description>
      <content:encoded><![CDATA[A British hacker who admitted breaking into U.S. military computers hoping to uncover evidence of UFOs looks set to head here for trial.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=kU0G1v"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=kU0G1v" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/350401773" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/british hacker">british hacker</category>
      <category domain="http://securityratty.com/tag/uncover evidence">uncover evidence</category>
      <category domain="http://securityratty.com/tag/military computers">military computers</category>
      <category domain="http://securityratty.com/tag/trial">trial</category>
      <category domain="http://securityratty.com/tag/head">head</category>
      <category domain="http://securityratty.com/tag/ufos">ufos</category>
      <category domain="http://securityratty.com/tag/set">set</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/350401773/article.do">Extradition appeal for British hacker dismissed</source>
    </item>
  </channel>
</rss>
