<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: two-part]]></title>
    <link>http://securityratty.com/tag/two-part</link>
    <description></description>
    <pubDate>Mon, 24 Nov 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Yet Another Web Malware Exploitation Kit in the Wild]]></title>
      <link>http://securityratty.com/article/5caa05f53942f1ddb87a74f20c2c3599</link>
      <guid>http://securityratty.com/article/5caa05f53942f1ddb87a74f20c2c3599</guid>
      <description><![CDATA[With business-minded malicious attackers embracing basic marketing practices like branding, it is becoming increasingly harder, if not pointless to keep track of all XYZ-Packs currently in...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/STR4MhsqHZI/AAAAAAAACfY/EnFEn5S9XMY/s1600-h/5Qqp497mdd.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/STR4MhsqHZI/AAAAAAAACfY/EnFEn5S9XMY/s200/5Qqp497mdd.png" /></a>With business-minded malicious attackers embracing basic marketing practices like branding, it is becoming increasingly harder, if not pointless to keep track of all XYZ-Packs currently in circulation. How come? Due to their open source nature allowing modifications, claiming copyright over the modified and re-branded kit, the source code of core web malware exploitation kits continue representing the foundation source code for each and every newly released kit.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/STSLw4XodgI/AAAAAAAACfg/0WZInEH3pD4/s1600-h/gPdiZb9b7u_.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/STSLw4XodgI/AAAAAAAACfg/0WZInEH3pD4/s200/gPdiZb9b7u_.PNG" /></a>In fact, the practice is becoming so evident, that anecdotal evidence in the form of monitoring ongoing communications between sellers and buyers reveals actual attempts of intellectual property enforcement in the form of&nbsp; exchange of flames between an author of a original kit, and a newly born author who seems to have copied over 80% of his source code, changed the layout, re-branded it, added several more exploits and started pitching it as the most exclusive kit there is available in the underground marketplace.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/STSL6Yo0fFI/AAAAAAAACfo/7OQAGGmvwHg/s1600-h/9CtxtBWp6S_.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/STSL6Yo0fFI/AAAAAAAACfo/7OQAGGmvwHg/s200/9CtxtBWp6S_.PNG" /></a>What's new about this particular kit anyway? Changed iframe and js obfuscation techniques, doesn't require MySQL to run, with several modified Adobe Acrobat and Flash exploits - all patched and publicly obtainable. This is precisely where the marketing pitch ends for the majority of malware kits released during the last quarter. <br />
<br />
As always, there are noticable exceptions to the common wisdom that time-to-underground market isn't allowing them to innovate, but thankfully, these exceptions aren't yet going mainstream. What is going to change in the upcoming 2009? Web malware exploitation kits are slowly maturing into multi-user cybercrime platforms, where traffic management coming from the SQL injected or malware embedded sites is automatically exploited with access to the infected hosts or to the traffic volume in general offered for sale under a flat rate, or on a volume basis.<br />
<br />
Converging traffic management with drive-by exploitation and offering the output for sale, all from a single web interface, is precisely what <a href="http://ddanchev.blogspot.com/2007/07/malware-embedded-sites-increasing.html">malicious economies of scale</a> is all about.<br />
<br />
<b>Related posts:</b><br />
<a href="http://blogs.zdnet.com/security/?p=2217">Cybercriminals release Christmas themed web malware exploitation kit</a><cite></cite><b></b><br />
<a href="http://ddanchev.blogspot.com/2008/11/new-web-malware-exploitation-kit-in.html">New Web Malware Exploitation Kit in the Wild</a><b></b><br />
<a href="http://ddanchev.blogspot.com/2008/11/modified-zeus-crimeware-kit-gets.html">Modified Zeus Crimeware Kit Gets a Performance Boost</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/11/zeus-crimeware-kit-gets-carding-layout.html">Zeus Crimeware Kit Gets a Carding Layout</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/web-based-malware-emphasizes-on-anti.html">Web Based Malware Emphasizes on Anti-Debugging Features</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/copycat-web-malware-exploitation-kit.html">Copycat Web Malware Exploitation Kit Comes with Disclaimer</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/web-based-malware-eradicates-rootkits.html">Web Based Malware Eradicates Rootkits and Competing Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/two-copycat-web-malware-exploitation.html">Two Copycat Web Malware Exploitation Kits in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/copycat-web-malware-exploitation-kits.html">Copycat Web Malware Exploitation Kits are Faddish</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</a> <br />
<a href="http://ddanchev.blogspot.com/2008/02/blackenergy-ddos-bot-web-based-c.html">BlackEnergy  DDoS Bot Web Based</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/new-ddos-malware-kit-in-wild.html">A  New DDoS Malware Kit in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The  Small Pack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2006/11/nuclear-grabber-toolkit.html">The  Nuclear Grabber Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">The  Apophis Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/nuclear-malware-kit.html">Nuclear  Malware Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/random-js-malware-exploitation-kit.html">The  Random JS Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher  Malware Kit Spotted in the Wild</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gqSxO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gqSxO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kPWXO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kPWXO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IWaVo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IWaVo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AQnUo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AQnUo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=z4nXO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=z4nXO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=f162O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=f162O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zFrIo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zFrIo" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/472427816" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 03:24:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kit">kit</category>
      <category domain="http://securityratty.com/tag/malware exploitation kit">malware exploitation kit</category>
      <category domain="http://securityratty.com/tag/nuclear malware kit">nuclear malware kit</category>
      <category domain="http://securityratty.com/tag/zeus crimeware kit">zeus crimeware kit</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/exclusive kit">exclusive kit</category>
      <category domain="http://securityratty.com/tag/nuclear grabber kit">nuclear grabber kit</category>
      <category domain="http://securityratty.com/tag/apophis kit">apophis kit</category>
      <category domain="http://securityratty.com/tag/ddos malware kit">ddos malware kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/472427816/yet-another-web-malware-exploitation.html">Yet Another Web Malware Exploitation Kit in the Wild</source>
    </item>
    <item>
      <title><![CDATA[Updated Microsoft Security Assessment Tool]]></title>
      <link>http://securityratty.com/article/b22bf798fdddd9574ca6b43e5006fd66</link>
      <guid>http://securityratty.com/article/b22bf798fdddd9574ca6b43e5006fd66</guid>
      <description><![CDATA[Greetings. In case you havent already read about it, we recently updated the Microsoft Security Assessment Tool (MSAT). Version 4.0 hit the web on 31 October. Its been four years since the initial...]]></description>
      <content:encoded><![CDATA[<p>Greetings. In case you haven’t already read about it, we recently updated the Microsoft Security Assessment Tool (MSAT). Version 4.0 hit the web on 31 October. It’s been four years since the initial release, and two years since the prior version. Between then and now your security world has evolved a lot, and the tool now reflects that.</p>  <p>Read more: <a title="http://technet.microsoft.com/en-us/security/cc185712.aspx" href="http://technet.microsoft.com/en-us/security/cc185712.aspx">http://technet.microsoft.com/en-us/security/cc185712.aspx</a></p>  <p>Download now: <a title="http://www.microsoft.com/downloads/details.aspx?FamilyId=CD057D9D-86B9-4E35-9733-7ACB0B2A3CA1&amp;displaylang=en" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=CD057D9D-86B9-4E35-9733-7ACB0B2A3CA1&amp;displaylang=en">http://www.microsoft.com/downloads/details.aspx?FamilyId=CD057D9D-86B9-4E35-9733-7ACB0B2A3CA1&amp;displaylang=en</a></p>  <p>Take a few moments and give yourself a security checkup. If you have any comments or feedback on the tool, feel free to leave them here on my blog—I’ll make sure the right people see it.</p>  <p>&#160;</p>  <p>From the download page:</p>  <p>The MSAT employs a holistic approach to measuring your security posture by covering topics across people, process, and technology. Findings are coupled with prescriptive guidance and recommended mitigation efforts, including links to more information for additional industry guidance. These resources may assist you in keeping you aware of specific tools and methods that can help change the security posture of your IT environment. </p>  <p>There are two assessments that define the Microsoft Security Assessment Tool: </p>  <ul>   <li>Business Risk Profile Assessment</li>    <li>Defense in Depth Assessment (UPDATED)</li> </ul>  <p>The questions identified in the survey portion of the tool and the associated answers are derived from commonly accepted best practices around security, both general and specific. The questions and the recommendations that the tool offers are based on standards such as ISO 17799 and NIST-800.x, as well as recommendations and prescriptive guidance from Microsoft’s Trustworthy Computing Group and additional security resources valued in the industry.</p>  <p>After completing an Assessment, you will gain access to a detailed report of your results. You may also compare your results with those of your peers (by industry and company size), provided that you upload your results anonymously to the secure MSAT Web server. When you upload your data the application will simultaneously retrieve the most recent data available. To be able to provide this comparative data, we need customers such as you to upload their information. All information is kept strictly confidential and no personally identifiable information whatsoever will be sent.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3162703" width="1" height="1">]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 01:13:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security world">security world</category>
      <category domain="http://securityratty.com/tag/additional security resources">additional security resources</category>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/security posture">security posture</category>
      <category domain="http://securityratty.com/tag/identifiable information whatsoever">identifiable information whatsoever</category>
      <category domain="http://securityratty.com/tag/assessment">assessment</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/tool offers">tool offers</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/12/01/updated-microsoft-security-assessment-tool.aspx">Updated Microsoft Security Assessment Tool</source>
    </item>
    <item>
      <title><![CDATA[ISP's secret opt-in advertising test draws the UK's ire]]></title>
      <link>http://securityratty.com/article/e6a0ea63c7bd059a41314bb9abb6373f</link>
      <guid>http://securityratty.com/article/e6a0ea63c7bd059a41314bb9abb6373f</guid>
      <description><![CDATA[It's no surprise that ISPs are aggressively pursuing new revenue streams, but UK ISP BT may have crossed the line. Two years ago it retained search records and information on some 18,000 users,...]]></description>
      <content:encoded><![CDATA[It's no surprise that ISPs are aggressively pursuing new revenue streams, but UK ISP BT may have crossed the line. Two years ago it retained search records and information on some 18,000 users, without informing them first.<img src="http://feedproxy.google.com/~r/digg/topic/security/popular/~4/X8HjqfRhxO4" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 15:50:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/revenue streams">revenue streams</category>
      <category domain="http://securityratty.com/tag/isp">isp</category>
      <category domain="http://securityratty.com/tag/isps">isps</category>
      <category domain="http://securityratty.com/tag/records">records</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/ago">ago</category>
      <category domain="http://securityratty.com/tag/surprise">surprise</category>
      <category domain="http://securityratty.com/tag/aggressively">aggressively</category>
      <source url="http://feeds.digg.com/~r/digg/topic/security/popular/~3/X8HjqfRhxO4/ISP_s_secret_opt_in_advertising_test_draws_the_UK_s_ire_2">ISP's secret opt-in advertising test draws the UK's ire</source>
    </item>
    <item>
      <title><![CDATA[Security Manager's Journal: When is a patch not really a patch?]]></title>
      <link>http://securityratty.com/article/9fed4ae526e10d7a29a204613fd1b161</link>
      <guid>http://securityratty.com/article/9fed4ae526e10d7a29a204613fd1b161</guid>
      <description><![CDATA[When patches are dutifully installed but the servers aren't rebooted -- for as long as two years, in this case -- it's the same as not installing the patches at...]]></description>
      <content:encoded><![CDATA[When patches are dutifully installed but the servers aren't rebooted -- for as long as two years, in this case -- it's the same as not installing the patches at all.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c972198c04f845f36c0dd9454f23281e:Itfi7uqSRa%2B2W1vzCBHYFt77pwTcM0Ef0XaGQaVeASIrIC22ePbPs0APU%2Fr0OV15a0JlX0amytJx'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:a16f81a407f83b86adfb2f92ef7d6ce4:4D6SVBIacNXZv3cdi9DYZYVh9QyjOFmtcPF4SViUIzvzyQ10Bm%2F4Cv4SkVzxybyKbJ53%2Fiuz4ZZ%2F2A%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:fdb8dd41f8d779be5a8fa7feedeeee7f:sMl3lDCJkPpjcwoJeaYGSIyeoEvzhkV8KG5ZbwG2wixsgUVfPtBDYEcvq2OHQ13SH7igR0fHl0j2MA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:f35128cf58db8eb1bf5086711b2c9a09:vXG6Dmkj0x09Pt%2BtrHNXLUA2ELxstWV5hj4cvjdw71iRoAAyvERFmzzEbpKHAkaIQZcVgxRS8aDIow%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=34d3d1936eb7b8fe917f1f00d7f42d2e&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=34d3d1936eb7b8fe917f1f00d7f42d2e&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=34d3d1936eb7b8fe917f1f00d7f42d2e" style="display: none;" border="0" height="1" width="1" alt=""/>
]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/patches">patches</category>
      <category domain="http://securityratty.com/tag/servers">servers</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=34d3d1936eb7b8fe917f1f00d7f42d2e">Security Manager's Journal: When is a patch not really a patch?</source>
    </item>
    <item>
      <title><![CDATA[Online Finance Flaws: An Awareness Campaign]]></title>
      <link>http://securityratty.com/article/1aabc5edbe215010d8c71b5aa4aa7551</link>
      <guid>http://securityratty.com/article/1aabc5edbe215010d8c71b5aa4aa7551</guid>
      <description><![CDATA[Here begins a series regarding web application security inadequacies in online financial service offerings. The services to be discussed will include banks, credit unions, credit card companies, and...]]></description>
      <content:encoded><![CDATA[Here begins a series regarding web application security inadequacies in online financial service offerings. The services to be discussed will include banks, credit unions, credit card companies, and others. As the economy struggles profoundly, and much of the blame points at the financial sector, I believe it important to point out the false sense of security so many brand-name financial services wrongly instill in their customers.<br />Often this sense of security is coupled with a typical "security badge" provider, helping drive conversions rather than security, as we will also legitimize how often the badge providers miss the mark on their promises.<br />Accountability in loan making decisions and practices might have prevented the sub-prime market collapse and the subsequent credit crunch that has hogtied our economy. <br />Accountability with regard to web application security while providing online financial services is now all the more important as <a href="http://securitywatch.eweek.com/exploits_and_attacks/as_economy_dives_underground_thrives.html" target="_blank">cybercrime</a> will continue to increase at a pace proportionate to economic woes.<br />Each post relevant to this campaign will include Online Finance Flaw in its title for tracking purposes. <br />Look forward to surprising flaws in financial services brands you'll recognize.<br />Perhaps, the more attention we draw to services that should place security above all else, the more likely it is they'll commit to improving their security posture.<br />Feel free to comment or contribute; we'll begin in a day or two.]]></content:encoded>
      <pubDate>Sat, 29 Nov 2008 19:08:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/web application security">web application security</category>
      <category domain="http://securityratty.com/tag/financial services brands">financial services brands</category>
      <category domain="http://securityratty.com/tag/security badge">security badge</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/security posture">security posture</category>
      <category domain="http://securityratty.com/tag/online financial services">online financial services</category>
      <category domain="http://securityratty.com/tag/economy">economy</category>
      <category domain="http://securityratty.com/tag/economy struggles profoundly">economy struggles profoundly</category>
      <source url="http://holisticinfosec.blogspot.com/2008/11/online-finance-flaws-awareness-campaign_29.html">Online Finance Flaws: An Awareness Campaign</source>
    </item>
    <item>
      <title><![CDATA[In Mumbai, bloggers and Twitter offer help to relatives]]></title>
      <link>http://securityratty.com/article/af66bfff259eea6672f58a47a634c5c8</link>
      <guid>http://securityratty.com/article/af66bfff259eea6672f58a47a634c5c8</guid>
      <description><![CDATA[Bloggers pitched in offering information and other help to people worldwide as Indian police and commandos battled it out Thursday with armed terrorists in two top hotels and a residential complex in...]]></description>
      <content:encoded><![CDATA[Bloggers pitched in offering information and other help to people worldwide as Indian police and commandos battled it out Thursday with armed terrorists in two top hotels and a residential complex in south Mumbai.]]></content:encoded>
      <pubDate>Wed, 26 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/armed terrorists">armed terrorists</category>
      <category domain="http://securityratty.com/tag/bloggers">bloggers</category>
      <category domain="http://securityratty.com/tag/south mumbai">south mumbai</category>
      <category domain="http://securityratty.com/tag/indian police">indian police</category>
      <category domain="http://securityratty.com/tag/top hotels">top hotels</category>
      <category domain="http://securityratty.com/tag/people worldwide">people worldwide</category>
      <category domain="http://securityratty.com/tag/residential complex">residential complex</category>
      <category domain="http://securityratty.com/tag/commandos">commandos</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <source url="http://www.networkworld.com/news/2008/112708-in-mumbai-bloggers-and-twitter.html?fsrc=rss-security">In Mumbai, bloggers and Twitter offer help to relatives</source>
    </item>
    <item>
      <title><![CDATA[Massive botnet returns from the dead, starts spamming]]></title>
      <link>http://securityratty.com/article/eed42d7414affcf4e3fae91c61ab09c5</link>
      <guid>http://securityratty.com/article/eed42d7414affcf4e3fae91c61ab09c5</guid>
      <description><![CDATA[The spam-spewing 'Srizbi' botnet that was shut down two weeks ago has been resurrected, security researchers said today, and is again under criminal...]]></description>
      <content:encoded><![CDATA[The spam-spewing 'Srizbi' botnet that was shut down two weeks ago has been resurrected, security researchers said today, and is again under criminal control.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:ac95b035f83e4adaf16815a2a6b6fc89:zZb5a5rbEvUA4GkdKL4sxw%2FQchQj1%2BBiWnoisK1pXZDzd%2BKpo%2BMv08t68Q43g0g277exwzlPfwls'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:e2b0a66dbd278107141ebf9873adb181:Nfq5W7omRNsvrXoDJRj8%2B6j4WS8QILsZltCZDxT5uCmJz1N%2BfGVuZ2syAXdigG6sPRcUuork%2FMgrDA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:8868ea29c2c3fe4e5cd4d83661b1b9fb:kMs2ki8cudHJV7yy70mFv3PukMhAVaNSy%2BWMWR9dGrTCsCeosR5EDtBrnfA%2BoWNwR%2BpzujnzHN%2FkKw%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:acbcf8b0766eb2b951d70e7188ac639a:k0rEVSo8xYFP%2BqF9zpV0sqfa4ydc747Ttf6PNqsQ1%2Flhl4vVIUPnm9fR%2FgMaNV4PVNbE2wFpGQkhig%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=b9f48c7c1ff1dd0dc359e321b01b5bad&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=b9f48c7c1ff1dd0dc359e321b01b5bad&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=b9f48c7c1ff1dd0dc359e321b01b5bad" style="display: none;" border="0" height="1" width="1" alt=""/>
]]></content:encoded>
      <pubDate>Wed, 26 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/weeks ago">weeks ago</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/criminal control">criminal control</category>
      <category domain="http://securityratty.com/tag/srizbi">srizbi</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=b9f48c7c1ff1dd0dc359e321b01b5bad">Massive botnet returns from the dead, starts spamming</source>
    </item>
    <item>
      <title><![CDATA[Massive botnet returns from the dead, starts spamming]]></title>
      <link>http://securityratty.com/article/6cec5ac5e322d712af8cf88421706913</link>
      <guid>http://securityratty.com/article/6cec5ac5e322d712af8cf88421706913</guid>
      <description><![CDATA[A big spam-spewing botnet shut down two weeks ago has been resurrected, security researchers said Wednesday, and is again under the control of...]]></description>
      <content:encoded><![CDATA[A big spam-spewing botnet shut down two weeks ago has been resurrected, security researchers said Wednesday, and is again under the control of criminals.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=52127?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=52127?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/weeks ago">weeks ago</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/criminals">criminals</category>
      <category domain="http://securityratty.com/tag/wednesday">wednesday</category>
      <category domain="http://securityratty.com/tag/control">control</category>
      <source url="http://www.networkworld.com/news/2008/112608-massive-botnet-returns-from-the.html?fsrc=rss-security">Massive botnet returns from the dead, starts spamming</source>
    </item>
    <item>
      <title><![CDATA[Spam levels fluctuate as crooks try to revive botnets]]></title>
      <link>http://securityratty.com/article/6898619aa3a97b2f0095f1e166d4812f</link>
      <guid>http://securityratty.com/article/6898619aa3a97b2f0095f1e166d4812f</guid>
      <description><![CDATA[Two weeks after McColo's shutdown sent global spam volumes plummeting, some researchers said junk mail rates remain dramatically down, while others said spam has already bounced...]]></description>
      <content:encoded><![CDATA[Two weeks after McColo's shutdown sent global spam volumes plummeting, some researchers said junk mail rates remain dramatically down, while others said spam has already bounced back.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:b0fed0ce5178f3587db4effbbdc8eed7:Lo%2FW5xpdBG%2FsznStumMGozfEojqBtLGIIXuNUFYZWl%2B5qvGzdJ%2BpQASooXQmgrG2oYHMZO9YiVDi'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:16fdd31edbefc269672d8a97a96c121f:b%2FZNtr7oyHtqVN7%2FilzZcuuykWH%2FRfO%2F30LJI1SNV3GqdJ3gZ%2FX%2Bp1yGp6%2BECWCv1ZDqqPZ7QeAVMA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:b6c12602f83177ff8c65b195f959c201:qas1ST%2BeSRE9hvUz8fiZ%2BmOdZsUHFST3Hp5Zbf4%2BCM%2BhKMztSXIw%2FhilOqXMTMKYZBjcbAPWa25WkA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:773d13ecfd32259359b55a2a0b0d31b2:iw0QTWJE%2FRz4m5R%2B0ig3NfDmOG%2Ffl0h4o1%2FoIDZ2UA8r6eWG3bpa8diMerKneYf1KBSPkbEtJyooxw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=f3ac179d37d16170c07fbfda45195466&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=f3ac179d37d16170c07fbfda45195466&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=f3ac179d37d16170c07fbfda45195466" style="display: none;" border="0" height="1" width="1" alt=""/>
]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/global spam volumes">global spam volumes</category>
      <category domain="http://securityratty.com/tag/junk mail">junk mail</category>
      <category domain="http://securityratty.com/tag/remain">remain</category>
      <category domain="http://securityratty.com/tag/shutdown">shutdown</category>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <category domain="http://securityratty.com/tag/mccolo">mccolo</category>
      <category domain="http://securityratty.com/tag/weeks">weeks</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=f3ac179d37d16170c07fbfda45195466">Spam levels fluctuate as crooks try to revive botnets</source>
    </item>
    <item>
      <title><![CDATA[Spam levels fluctuate as crooks try to revive botnets]]></title>
      <link>http://securityratty.com/article/56f12388b579b846be1e8a67255946c1</link>
      <guid>http://securityratty.com/article/56f12388b579b846be1e8a67255946c1</guid>
      <description><![CDATA[Two weeks after a hosting firm's shutdown sent global spam volumes plummeting, some researchers continue to claim that junk mail rates remain dramatically down, while others say spam has already...]]></description>
      <content:encoded><![CDATA[Two weeks after a hosting firm's shutdown sent global spam volumes plummeting, some researchers continue to claim that junk mail rates remain dramatically down, while others say spam has already bounced back.]]></content:encoded>
      <pubDate>Mon, 24 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/global spam volumes">global spam volumes</category>
      <category domain="http://securityratty.com/tag/junk mail">junk mail</category>
      <category domain="http://securityratty.com/tag/researchers continue">researchers continue</category>
      <category domain="http://securityratty.com/tag/remain">remain</category>
      <category domain="http://securityratty.com/tag/firm">firm</category>
      <category domain="http://securityratty.com/tag/claim">claim</category>
      <category domain="http://securityratty.com/tag/shutdown">shutdown</category>
      <category domain="http://securityratty.com/tag/weeks">weeks</category>
      <source url="http://www.networkworld.com/news/2008/112508-spam-levels-fluctuate-as-crooks.html?fsrc=rss-security">Spam levels fluctuate as crooks try to revive botnets</source>
    </item>
  </channel>
</rss>
