<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: universal]]></title>
    <link>http://securityratty.com/tag/universal</link>
    <description></description>
    <pubDate>Mon, 14 Jul 2008 13:08:21 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Q&A: Mobile Forensics]]></title>
      <link>http://securityratty.com/article/c7d727a3b91a8938627ace61f54c7d52</link>
      <guid>http://securityratty.com/article/c7d727a3b91a8938627ace61f54c7d52</guid>
      <description><![CDATA[Aviad Ofrat is the CEO of Cellebrite and in this interview discusses mobile forensics as well as the Universal Forensic Extraction Device. In your opinion, how important is a mobile forensics...]]></description>
      <content:encoded><![CDATA[Aviad Ofrat is the CEO of Cellebrite and in this interview discusses mobile forensics as well as the Universal Forensic Extraction Device.
 
 In your opinion, how important is a mobile forensics capab...]]></content:encoded>
      <pubDate>Mon, 27 Oct 2008 16:44:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mobile forensics capab">mobile forensics capab</category>
      <category domain="http://securityratty.com/tag/aviad ofrat">aviad ofrat</category>
      <category domain="http://securityratty.com/tag/opinion">opinion</category>
      <category domain="http://securityratty.com/tag/ceo">ceo</category>
      <category domain="http://securityratty.com/tag/cellebrite">cellebrite</category>
      <source url="http://www.net-security.org/article.php?id=1184">Q&amp;A: Mobile Forensics</source>
    </item>
    <item>
      <title><![CDATA[Remotely Eavesdropping on Keyboards]]></title>
      <link>http://securityratty.com/article/ce6b4f5ae267c442104b3483854d3c78</link>
      <guid>http://securityratty.com/article/ce6b4f5ae267c442104b3483854d3c78</guid>
      <description><![CDATA[Clever work : The researchers from the Security and Cryptography Laboratory at Ecole Polytechnique Federale de Lausanne are able to capture keystrokes by monitoring the electromagnetic radiation of...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.theregister.co.uk/2008/10/20/keyboard_sniffing_attack/">Clever</a> <a href="http://news.bbc.co.uk/2/hi/technology/7681534.stm">work</a>:</p>

<blockquote>The researchers from the Security and Cryptography Laboratory at Ecole Polytechnique Federale de Lausanne are able to capture keystrokes by monitoring the electromagnetic radiation of PS/2, universal serial bus, or laptop keyboards. They've outline four separate attack methods, some that work at a distance of as much as 65 feet from the target.

<p>In one video demonstration, researchers Martin Vuagnoux and Sylvain Pasini sniff out the the keystrokes typed into a standard keyboard using a large antenna that's about 20 to 30 feet away in an adjacent room.</blockquote></p>

<p>Website <a href="http://lasecwww.epfl.ch/keyboard/">here</a>. </p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=nR9FM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=nR9FM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=kZp9M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=kZp9M" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 23 Oct 2008 08:48:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <category domain="http://securityratty.com/tag/researchers martin vuagnoux">researchers martin vuagnoux</category>
      <category domain="http://securityratty.com/tag/universal serial bus">universal serial bus</category>
      <category domain="http://securityratty.com/tag/ecole polytechnique federale">ecole polytechnique federale</category>
      <category domain="http://securityratty.com/tag/sylvain pasini sniff">sylvain pasini sniff</category>
      <category domain="http://securityratty.com/tag/keystrokes typed">keystrokes typed</category>
      <category domain="http://securityratty.com/tag/attack methods">attack methods</category>
      <category domain="http://securityratty.com/tag/electromagnetic radiation">electromagnetic radiation</category>
      <category domain="http://securityratty.com/tag/feet">feet</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/remotely_eavesd.html">Remotely Eavesdropping on Keyboards</source>
    </item>
    <item>
      <title><![CDATA[Massive SQL Injection Attacks - the Chinese Way]]></title>
      <link>http://securityratty.com/article/42e493c2424af4f8ef6cc5dd581317bf</link>
      <guid>http://securityratty.com/article/42e493c2424af4f8ef6cc5dd581317bf</guid>
      <description><![CDATA[From copycats and &quot;localizers&quot; of Russian web malware exploitation kits , to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP46U3HSQHI/AAAAAAAACUY/QH40puDsgXY/s1600-h/security_company_hacking_tools.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP46U3HSQHI/AAAAAAAACUY/QO3L0OWKJcY/s200-R/security_company_hacking_tools.JPG" /></a>From <a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">copycats</a> and <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">"localizers" of Russian web malware exploitation kits</a>, to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the obvious insecurities on a large scale, and so is either filling the niches left open by other international communities, or coming up with tools setting new benchmarks for massive SQL injection attacks, like the case with this one :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5DX0GzAtI/AAAAAAAACUg/3GOnK2TsSRk/s1600-h/search_engines_mass_SQL_injection.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5DX0GzAtI/AAAAAAAACUg/pdCwjwri7LM/s200-R/search_engines_mass_SQL_injection.JPG" /></a>"<i>A professional web site vulnerability scanning, use of tools, SQL injection is a new generation of tools to help Web developers and site of the station quickly find vulnerabilities in order to be able to effectively prepare Security work. At the same time, the tool to Web developers to demonstrate the ways in which hackers are using these vulnerabilities, hackers, as well as through the loopholes to do things, can effectively raise the safety awareness of relevant personnel.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DkEEtbqI/AAAAAAAACUo/Mm7pCwd7LT4/s1600-h/search_engines_mass_SQL_injection2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DkEEtbqI/AAAAAAAACUo/qMaY93_QOvY/s200-R/search_engines_mass_SQL_injection2.JPG" /></a>Nothing's wrong with the marketing pitch at the first place, but going through the features, the "massive SQL injections through search engine reconnaissance" and automatic page rank verification which you can see in the attached screenshots, ruin the "security auditing" marketing pitch. The tool not only allows easy integration of potentially vulnerable sites obtained through <a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">search engines reconnaissance</a>, but also, is prioritizing the results based on the probability for successful injection, next to the page rank of the domains in question. A simple demonstration offered by the company is also, directly enticing its users to "localize" the search engine reconnaissance, by filtering the search results for a particupar country, in this case they used French sites for one of the demos. Here are some excerpts from its CHANGE log speaking for themselves :<br />
<br />
"<i><b>2008.7.15 release version 1.3 </b><br />
&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DyBXVu7I/AAAAAAAACUw/37LsW8yh_AE/s1600-h/chinese_SQL_injector.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DyBXVu7I/AAAAAAAACUw/ub8OVgeWC6Y/s200-R/chinese_SQL_injector.png" /></a><i>- New powerful "automatic machine cycle" feature&nbsp;</i><br />
<i>- Automatic machine cycle is to provide assistance to the advanced user manual into the use of a very&nbsp;</i><br />
<i>- powerful and flexible module, the main sites used for some special filtering into the hand, is almost a&nbsp;</i><br />
<i>- universal tool, you can achieve the following: <br />
&nbsp;</i><br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SP5D-g3FyAI/AAAAAAAACU4/xYACViJuVn4/s1600-h/chinese_SQL_injector2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SP5D-g3FyAI/AAAAAAAACU4/oPVCur3PMgI/s200-R/chinese_SQL_injector2.png" /></a><i>1. In support of GET / POST / COOKIES in a variety of ways, such as the injection.&nbsp;</i><br />
<i>2. Scan the key to the page (background, upload, WebShell, databases, backup files, etc.).&nbsp;</i><br />
<i>3. According to the dictionary to violence landing back-guess solution WebShell password and password (required to verify that the code can not guess solution).&nbsp;</i><br />
<i>4. Page language does not limit the types and databases (to provide specific statements into the database).&nbsp;</i><br />
<i>5. At the same time, support for the circulation of the two variables and two dictionaries, fast running and violent content of the database solution to guess a password.</i>"<br />
<br />
It gets even more interesting in terms of the massive SQL injection attacks mentality which is pretty evident on all fronts :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5ELiLoBiI/AAAAAAAACVA/0fb6Epapby0/s1600-h/chinese_SQL_injector3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5ELiLoBiI/AAAAAAAACVA/nmrC87TeCxo/s200-R/chinese_SQL_injector3.png" /></a>"<i>- The use of the three search engine sites scans to invade the side to complete<br />
- in scanning probe into the Web site ranking points<br />
- added, "VBS upload to download", "upload directory Web site viewer," "FTP upload to download configuration file" function to make it more convenient for the sa rights to use the site. <br />
- New "sequence document scanners" <br />
- What is the sequence document scanners role? Upload to find loopholes, some of the procedures to upload the file after the upload will be renamed, rename the way the system is usually based on time or incremental increase in the number prefix code for the upload process, if not to return after the file name, Upload files to know the url is usually very difficult to sequence the use of paper scanner can be scanned out</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5FUvl0FhI/AAAAAAAACVY/Y5mM2l7Q6K4/s1600-h/chinese_SQL_injector4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5FUvl0FhI/AAAAAAAACVY/DU7feV1pnjU/s200-R/chinese_SQL_injector4.png" /></a><i><br />
- The best reverse domain name query engine, and quasi-wide <br />
- in scanning the database of basic information, an increase of the database of information related to the process, the link has information on the database server user login (sa need permission) <br />
- control of the interface had a big adjustment, the interface process easier to understand and operate. <br />
- based on a significant site of the wrong mode of access to a comprehensive code optimization and more accurate access to the content, accuracy and access to show progress. <br />
- added, "VBS upload to download", "upload directory Web site viewer," "FTP upload to download configuration file" function to make it more convenient for the sa rights to use the site.&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FgfdkSbI/AAAAAAAACVg/R77obP_vxig/s1600-h/chinese_SQL_injector5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FgfdkSbI/AAAAAAAACVg/ORo853Aicy4/s200-R/chinese_SQL_injector5.png" /></a><i><br />
- point into the types of improved detection order to improve the efficiency of detection. <br />
- improved automatic keyword detection, automatic keyword detection more accurate. <br />
- probe into the points the way to improve and increase the use of automatic detection of the keyword detection. <br />
- type of database to improve the detection, the use of the contents of the length of the failure to detect the type of database automatically switch to the probe through the keyword. <br />
- automatically save and load solution has been to guess the tree structure of the database, guess Solutions has been the content and structure of the database will automatically save and open the next time the injection point will be automatically made available, the solutions do not have to guess again, the continuity of work Greatly increased.&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FrcWctII/AAAAAAAACVo/DcQNU5crc5k/s1600-h/chinese_SQL_injector6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="131" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FrcWctII/AAAAAAAACVo/9zGp4bsPB2U/s200-R/chinese_SQL_injector6.png" width="200" /></a><i><br />
- solved from the database to read large amounts of data (on hundreds of thousands or millions of records), the half-way card program will die. <br />
- increased significantly on the wrong model of ASP.NET and SQL Server2005 significant mode of dealing with mistakes, error messages can be extracted from a Web directory! <br />
- significant amendments to the wrong mode, some of the injected one by one point in the field or access to the contents of the issue can not be successful (error code in hand); for increased access to specific points table and into the field.&nbsp;</i><br />
<i><br />
- amendments to the text of a significant error patterns to detect and correct use of loopholes in the system can be used more to expand. (Text significantly in the wrong mode in version 1.1 already supported, but in the version 1.2 upgrade in the process of scanning to improve the performance of the Gaodiao careless. -_-#) <br />
- on a variety of encoded text can be significantly wrong in the right-compatible, able to correctly handle the ASP.NET page of the text marked wrong. Through custom error keyword, truly compatible with any language, any coding error message. <br />
- crack anti-improvement and enhancement. <br />
- An increase of auto-detection feature keywords.&nbsp;</i><br />
<i><br />
- Mssql database specifically for significant points into the wrong mode of detection and the use of up and down the hard work, and many other software can not detect the point of injection can also be used. <br />
- Automatic save and load access to the database, to allow manual known to add tables and fields for solutions to guess. <br />
- Can be used to amend the degree of accuracy; optimize the code to reduce memory footprint; enhance the stability of multi-threading. <br />
- Significant amendments to the wrong mode solution guess the contents of the database must be checked first field defects.</i>"<br />
<br />
The public version of the tool has been in the while for over an year, with a VIP version available to customers only.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PsITM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PsITM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JBO9M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JBO9M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=owYAm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=owYAm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LTzNm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LTzNm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LaPQM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LaPQM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=go5fM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=go5fM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rYJ9m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rYJ9m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/427878843" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 21 Oct 2008 12:18:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/keyword detection">keyword detection</category>
      <category domain="http://securityratty.com/tag/detection">detection</category>
      <category domain="http://securityratty.com/tag/database">database</category>
      <category domain="http://securityratty.com/tag/database solution">database solution</category>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/upload process">upload process</category>
      <category domain="http://securityratty.com/tag/text">text</category>
      <category domain="http://securityratty.com/tag/load solution">load solution</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/427878843/massive-sql-injection-attacks-chinese.html">Massive SQL Injection Attacks - the Chinese Way</source>
    </item>
    <item>
      <title><![CDATA[Privacy In the Cloud: Show Me The Money]]></title>
      <link>http://securityratty.com/article/2e805d07b3a60ac9d955f1ff811f3569</link>
      <guid>http://securityratty.com/article/2e805d07b3a60ac9d955f1ff811f3569</guid>
      <description><![CDATA[Privacy is a lot like universal healthcare. Many agree its a good idea in concept, but few people want to pay for it
Richard Stallman - the man that gave us GNU - doesnt trust Cloud providers with his...]]></description>
      <content:encoded><![CDATA[<p><img class="alignright" style="float: right; border: 0; margin: 3px;" src="http://farm3.static.flickr.com/2052/2404940312_e759c4030d_m_d.jpg" alt="Locker" width="180" height="240" />Privacy is a lot like universal healthcare.  Many agree its a good idea in concept, but few people want to pay for it.</p>
<p>Richard Stallman - the man that gave us <a href="http://www.gnu.org/">GNU</a> - <a href="http://www.guardian.co.uk/technology/2008/sep/29/cloud.computing.richard.stallman">doesn&#8217;t trust Cloud providers with his data</a> and says you shouldn&#8217;t either.  Richard believes we should store our private data on our own computers using &#8216;free&#8217; (as in <a href="http://www.gnu.org/gnu/thegnuproject.html">freedom</a>) software.  The ironic part for Richard is that a significant portion of the Cloud is powered by open source software which he indirectly created (think <a href="http://gcc.gnu.org/">gcc</a>).</p>
<p>Richard sees it as a question of control.  Control is important but it isn&#8217;t the only variable.  Rather, I see it as a question of control, competence and economics.</p>
<p>The quick rebuttal to Richards&#8217; view is this: the average computer user is <a href="http://www.stallman.org/photos/rms-full-size.jpg">not as smart as you</a>.  Control is not the same as competence.  Control is about exercising choice, not about requiring everyone in the world to develop sufficient skills to protect complex hardware and software systems (aka their computer) against <a href="http://ddanchev.blogspot.com/">ever increasing threats</a>.</p>
<p>My view is that privacy is not &#8216;free&#8217;.  It comes at a cost.  Whether you run your own systems or rely on someone else to do it, there is a cost.  There is cost in designing and implementing mechanisms to support privacy.  Beyond upfront costs there are ongoing expenditures to ensure privacy is maintained e.g. maintaining access control lists, testing and applying security patches, data leakage prevention etc.  None of these things are &#8216;free&#8217;.</p>
<p>If we agree that privacy costs money then how much is your privacy worth?</p>
<p>Stop for a second - think of a number&#8230;  </p>
<p>Now did we all think of the <a href="http://pbskids.org/sesame/coloring/images/07_grover.gif">same number</a>?</p>
<p>The problem with a one size fits all approach to privacy is that we each place a different value on it.</p>
<p>Checking in on the <a href="http://epic.org/">EPIC</a> site, I saw this:  </p>
<blockquote><p>A new report from <a href="http://www.pewinternet.org/">Pew Internet and American Life Project</a> indicates that &#8220;cloud computing&#8221; applications, such as web-based email and other web apps, are raising new privacy concerns. The report <a href="http://www.pewinternet.org/press_release.asp?r=306" target="_blank">Use of Cloud Computing: Applications and Services</a> found that 69% of online Americans use webmail services, store data online, or use software programs such as word processing applications whose functionality is located on the web. At the same time, &#8220;users report high levels of concern when presented with scenarios in which companies may put their data to uses of which they may not be aware.&#8221; For example, 90% of respondents said that they &#8220;would be very concerned if the company at which their data were stored sold it to another party,&#8221; 80% say &#8220;they would be very concerned if companies used their photos or other data in marketing campaigns,&#8221; and 68% of &#8220;users of at least one of the six cloud applications say they would be very concerned if companies who provided these services analyzed their information and then displayed ads to them based on their actions.&#8221;</p></blockquote>
<p>What does that tell us?</p>
<p>The average (American) Internet user finds Cloud services convenient but has concerns about how their privacy might be affected by Cloud providers actions (duh!).  The survey identifies a lack of awareness in how private data is used in some consumer based Cloud services (consistent with web advertising awareness surveys).  </p>
<p>Unfortunately, the results of this survey are not very actionable.  The survey doesn&#8217;t mention whether these are all &#8216;free&#8217; Cloud services (we can only assume they are) or ask the respondents what their expectations of privacy are and how much they would be willing to pay for different privacy assurance levels. </p>
<p>On a sidenote, respondents were not asked if they had actually read the privacy agreement for the services they signed up to.  But the providers know if they did or not&#8230;  Or at least, they have the data to figure it out.  At sign up time they can measure the time between displaying the privacy agreement and the user clicking &#8216;I accept&#8217;.  If its just a few seconds then its pretty obvious there was more scrolling than reading going on.  But I think we can probably guess the answer without the data ;-).</p>
<p>I believe we need to be able to link expectation of privacy with cost.</p>
<ul>
<li>How much are you willing to pay for privacy?  What level of privacy assurance do you need?</li>
<li>How much is your Cloud Provider paying to protect your privacy today?  What privacy services could they reasonably offer if they had customers willing to pay?  How might this compare with how you manage your private data on your home computer today?</li>
</ul>
<p>The cynical view is that we expect privacy but don&#8217;t want to pay for it.  Its a bit like uptime - there is a parallel universe out there, where internal IT departments allegedly meet their 99.999% uptime SLAs, but when Gmail goes down, the Sergey Brin witchcraft dolls come out.</p>
<p>From a provider perspective, the &#8220;cost&#8221; of privacy invariably gets bundled under that line item called &#8216;Information Security&#8217;.  And don&#8217;t be fooled, the cost of privacy in reality is more than the salary of the person employed to be the privacy advocate (if there is one).  If we can&#8217;t see how much our providers are spending on our privacy then how can we judge if they are spending enough?  And what is enough?  And what can I get if I&#8217;m willing to pay a little extra?</p>
<p>Personally, I would rather we get some transparency around privacy costs and assessment of offerings.  However, without a sufficiently sized market of customers willing to pay for privacy assurance and Cloud Providers willing to be more open, I won&#8217;t hold my breath.</p>
<p>What about you?  Would you be prepared to pay for privacy?  Should providers be more transparent about what they do and don&#8217;t do and how they do it?<br />
 <br />
 </p>
<p> </p>
<img src="http://feeds.feedburner.com/~r/CloudSecurity/~4/419000947" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 12 Oct 2008 19:49:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/cloud providers">cloud providers</category>
      <category domain="http://securityratty.com/tag/trust cloud providers">trust cloud providers</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/cloud providers actions">cloud providers actions</category>
      <category domain="http://securityratty.com/tag/cloud applications">cloud applications</category>
      <category domain="http://securityratty.com/tag/privacy costs money">privacy costs money</category>
      <category domain="http://securityratty.com/tag/privacy assurance levels">privacy assurance levels</category>
      <category domain="http://securityratty.com/tag/privacy assurance">privacy assurance</category>
      <source url="http://feeds.feedburner.com/~r/CloudSecurity/~3/419000947/">Privacy In the Cloud: Show Me The Money</source>
    </item>
    <item>
      <title><![CDATA[The More Things Change, the More They Stay the Same]]></title>
      <link>http://securityratty.com/article/12ab611c9b823e0e31278b582051d7cf</link>
      <guid>http://securityratty.com/article/12ab611c9b823e0e31278b582051d7cf</guid>
      <description><![CDATA[Guess the year: Murderous organizations have increased in size and scope; they are more daring, they are served by the most terrible weapons offered by modern science, and the world is nowadays...]]></description>
      <content:encoded><![CDATA[<p>Guess the year:</p>

<blockquote>Murderous organizations have increased in size and scope; they are more daring, they are served by the most terrible weapons offered by modern science, and the world is nowadays threatened by new forces which, if recklessly unchained, may some day wreck universal destruction. The Orsini bombs were mere children's toys compared with the later developments of infernal machines. Between 1858 and 1898 the dastardly science of destruction had made rapid and alarming strides...</blockquote>

<p>No, that wasn't a typo.  "Between 1858 and 1898...."  This quote is from Major Arthur Griffith, <a href="http://query.nytimes.com/mem/archive-free/pdf?res=9907E7D8153DE633A25757C0A9659C94689ED7CF"><i>Mysteries of Police and Crime</i></a>, London, 1898, II, p. 469.  It's quoted in: Walter Laqueur, <a href="http://www.amazon.com/History-Terrorism-Walter-Laqueur/dp/0765807998/ref=pd_bbs_sr_1?ie=UTF8&s=books&qid=1223482236&sr=8-1"><i>A History of Terrorism</i></a>, New Brunswick/London, Transaction Publishers, 2002.  </p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=3iuIM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=3iuIM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=YTBGM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=YTBGM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 08:30:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/major arthur griffith">major arthur griffith</category>
      <category domain="http://securityratty.com/tag/orsini bombs">orsini bombs</category>
      <category domain="http://securityratty.com/tag/murderous organizations">murderous organizations</category>
      <category domain="http://securityratty.com/tag/infernal machines">infernal machines</category>
      <category domain="http://securityratty.com/tag/transaction publishers">transaction publishers</category>
      <category domain="http://securityratty.com/tag/terrible weapons">terrible weapons</category>
      <category domain="http://securityratty.com/tag/dastardly science">dastardly science</category>
      <category domain="http://securityratty.com/tag/walter laqueur">walter laqueur</category>
      <category domain="http://securityratty.com/tag/modern science">modern science</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/the_more_things.html">The More Things Change, the More They Stay the Same</source>
    </item>
    <item>
      <title><![CDATA[The NSA Teams Up with the Chinese Government to Limit Internet Anonymity]]></title>
      <link>http://securityratty.com/article/503f5010550f387cf3db2d9c00072cbb</link>
      <guid>http://securityratty.com/article/503f5010550f387cf3db2d9c00072cbb</guid>
      <description><![CDATA[Definitely strange bedfellows : A United Nations agency is quietly drafting technical standards, proposed by the Chinese government, to define methods of tracing the original source of Internet...]]></description>
      <content:encoded><![CDATA[<p>Definitely <a href="http://news.cnet.com/8301-13578_3-10040152-38.html">strange bedfellows</a>:</p>

<blockquote>A United Nations agency is quietly drafting technical standards, proposed by the Chinese government, to define methods of tracing the original source of Internet communications and potentially curbing the ability of users to remain anonymous.

<p>The U.S. National Security Agency is also participating in the "IP Traceback" drafting group, named Q6/17, which is meeting next week in Geneva to work on the traceback proposal. Members of Q6/17 have declined to release key documents, and meetings are closed to the public.</p>

<p>[...]</p>

<p>A second, <a href="http://politechbot.com/docs/itu.traceback.use.cases.requirements.091108.txt">apparently leaked ITU document</a> offers surveillance and monitoring justifications that seem well-suited to repressive regimes:</p>

<blockquote>A political opponent to a government publishes articles putting the government in an unfavorable light. The government, having a law against any opposition, tries to identify the source of the negative articles but the articles having been published via a proxy server, is unable to do so protecting the anonymity of the author.</blockquote></blockquote>

<p>This is being sold as a way to go after the bad guys, but it won't help.  Here's Steve Bellovin <a href="http://www.cs.columbia.edu/~smb/blog/2008-09/2008-09-04.html">on that issue</a>:</p>

<blockquote>First, very few attacks these days use spoofed source addresses; the real IP address already tells you where the attack is coming from. Second, in case of a DDoS attack, there are too many sources; you can't do anything with the information. Third, the machine attacking you is almost certainly someone else's hacked machine and tracking them down (and getting them to clean it up) is itself time-consuming.</blockquote>

<p>TraceBack is most useful in monitoring the activities of large masses of people.  But of course, that's why the Chinese and the NSA are so interested in this proposal in the first place.</p>

<p>It's hard to figure out what the endgame is; the U.N. doesn't have the authority to impose Internet standards on anyone.  In any case, this idea is counter to the U.N. Universal Declaration of Human Rights, Article 19:  "Everyone has the right to freedom of opinion and expression; this right includes freedom to hold opinions without interference and to seek, receive and impart information and ideas through any media and regardless of frontiers."   In the U.S., it's counter to the First Amendment, which has long permitted anonymous speech.  On the other hand, basic human and constitutional rights have been jettisoned left and right in the years after 9/11; why should this be any different?</p>

<p>But when the Chinese government and the NSA get together to enhance their ability to spy on the world, you have to wonder what's gone wrong with the world.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=ROw6L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=ROw6L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=dQUlL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=dQUlL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 02:34:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/chinese government">chinese government</category>
      <category domain="http://securityratty.com/tag/chinese">chinese</category>
      <category domain="http://securityratty.com/tag/articles">articles</category>
      <category domain="http://securityratty.com/tag/negative articles">negative articles</category>
      <category domain="http://securityratty.com/tag/government publishes articles">government publishes articles</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/proposal">proposal</category>
      <category domain="http://securityratty.com/tag/original source">original source</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/the_nsa_teams_u.html">The NSA Teams Up with the Chinese Government to Limit Internet Anonymity</source>
    </item>
    <item>
      <title><![CDATA[Apptis and USNS Mercy Monitoring on the High Seas]]></title>
      <link>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</link>
      <guid>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</guid>
      <description><![CDATA[Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="244" alt="mike2 (Small)" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/mike2-small.jpg" width="204" align="left" border="0"> Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several customers. We thought Mike would have an interesting perspective to share on EM7, having recently come from the “customer side” and already with a few deployments under his belt.
<p><b>ScienceLogic: Mike, what’s your background working with network and management system tools?</b>
<p><b>Mike Lawson: </b>Before joining Apptis, I worked for the Air Force, mainly in satellite communications for almost nine years. I’m probably most familiar with HP OpenView and BMC Remedy. I managed a team that used them but wasn’t involved in tool selection; like many other federal IT workers, we didn’t have a choice of tools because there were existing enterprise licenses and maintenance contracts.
<p>I also saw a large systems integrator do a full Remedy/Crystal Systems/OpenView installation. It took 6 weeks to stand up and customize to meet just the basic monitoring requirements, and it cost something like half a million dollars. At the time, I thought that wasn’t bad and was a pretty typical experience.
<p><b>ScienceLogic: Coming from where you did, what’s your take on EM7?</b>
<p><strong>Mike Lawson:</strong> Honestly, I didn’t believe that EM7 could really do all that it claimed. In many ways, it was the complete opposite of what I had seen first-hand with other monitoring solutions. Could it really cover that much functionality? At relatively much lower cost to the customer and without the licensing nightmare?
<p>That quickly changed when I needed to understand the system enough to run it at a customer’s site. I went back over the training docs I received during my initial training class and jumped in; now, 6 months later, I’m the EM7 expert and can tell you that it delivers on all those promises. (But I still need to show people to get them to believe it too)
<p>I preach the “EM7 gospel” and when anyone wants to talk monitoring, I ask about the universal pain points: cost, maintenance contracts and licensing, and then I explain EM7. The cost difference is real; the solution is based on capacity, so there’s no licensing and it’s easy to use. They are shocked to learn that they can buy multiple EM7 appliances and years of maintenance for what they paid for most other tools.
<p><b>ScienceLogic: Apptis won the contract for monitoring aboard the USNS Mercy. We love that you’re using EM7 for one of the Navy’s hospital ships. Can you tell us more?</b>
<p><strong>Mike Lawson:</strong> The USNS Mercy is a Military Sealift Command hospital ship. <a href="http://www.navy.mil/navydata/fact_display.asp?cid=4400&amp;tid=400&amp;ct=4" target="_blank">Some stats</a>:
<ul>
<li>849 feet long (nearly the size of a football field)
<li>12 fully-equipped operating rooms, a 1,000 bed hospital facility, digital radiological services, a diagnostic and clinical laboratory, a pharmacy, an optometry lab, a CAT scan and two oxygen producing plants
<li>Crew: 61 civilian mariners, 956 Naval medical staff, and 259 Naval support staff</li>
</ul>
<p>The USNS recently departed on a five-month humanitarian mission in the Western Pacific and Southeast Asia in support of Pacific Partnership 2008. The partnership provides international medical, dental and engineering teams this summer to provide humanitarian support and conduct joint, combined, and cooperative Civil-Military Operations in order to improve regional stability and build partner capacity to respond to natural disasters and pandemic.
<p>For the most part, the ship’s network is self-contained, but can also use a landline when docked. The network covers 400 devices, including Windows/Exchange servers and VMware for server virtualization. Prior to using EM7, none of the monitoring was integrated; each system was independently monitored through individual vendor-specific consoles.
<p>Out of the box, EM7 provided integrated systems, application and network management for all network gear, applications and virtual machines in one solution. We didn’t have to do a lot of customization – EM7 includes best-practice based thresholds, event and monitoring templates and this covered what USNS Mercy needed to monitor.
<p><b>ScienceLogic: You’re a systems integrator with a very useful “customer point of view” when it comes to looking at tools. From that perspective, can you share what you think are the biggest benefits that EM7 provides?</b>
<p><strong>Mike Lawson:</strong> First of all, EM7 stands up right away. We’re talking days, not weeks. In contrast to the lengthy installation of OpenView and Remedy I witnessed during my military career, I was able to configure, customize, and implement the EM7 solution for the USNS Mercy in three days.
<p>Second, it’s easy to train people on and the support is outstanding. This judgment is from first-hand experience. Right before the USNS Mercy departed on its latest voyage, the system administrator I had trained on EM7 left, so I had all of a day to train some new EM7 admins. I prepared a seven-page “cheat sheet” and over a 3-hour conference call, we walked through the entire EM7 solution; I haven’t gotten a support call since.
<p>And when a problem did crop up with a device being discovered incorrectly, ScienceLogic was very responsive. We contacted ScienceLogic support on a Saturday and they created and emailed us a video to help troubleshoot the same day. Within 30 seconds of watching the video, the problem was resolved.
<p>Finally, EM7 helps us be good stewards of the government’s money. This is very important to me personally and to Apptis as a company. Because EM7 is cheaper and deploys so quickly and easily, you might think that it’s just the opposite of what a system integrator would want to use. But that’s short-term thinking. We believe in deliver the most value for customers every time. It’s what creates trust and long-term relationships with our customers. Instead of that half million spent on standing up the solution and basic setup, I’d much rather (and I know the customer would rather) spend that on fine-tuning or extending the solution to do much, much more.
<p>As a former government employee, I know what it’s like to use a tool that doesn’t fit my needs. EM7 proves that the best solution can totally break the old model of costly, lengthy installations. EM7 has the right model: the right solution and the right price delivered as an appliance that is easy to deploy, train on and use. </p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Apptis+and+USNS+Mercy+%26ndash%3B+Monitoring+on+the+High+Seas&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fapptis-and-usns-mercy-monitoring-on-the-high-seas%2F08%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 11:59:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/entire em7 solution">entire em7 solution</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/em7 gospel">em7 gospel</category>
      <category domain="http://securityratty.com/tag/em7 proves">em7 proves</category>
      <category domain="http://securityratty.com/tag/em7 admins">em7 admins</category>
      <category domain="http://securityratty.com/tag/multiple em7 appliances">multiple em7 appliances</category>
      <category domain="http://securityratty.com/tag/em7 solution">em7 solution</category>
      <category domain="http://securityratty.com/tag/explain em7">explain em7</category>
      <source url="http://blog.sciencelogic.com/apptis-and-usns-mercy-monitoring-on-the-high-seas/08/2008">Apptis and USNS Mercy Monitoring on the High Seas</source>
    </item>
    <item>
      <title><![CDATA[Coding Spyware and Malware for Hire]]></title>
      <link>http://securityratty.com/article/1dbd4bddd9e4248009d0273ad7cae5dd</link>
      <guid>http://securityratty.com/article/1dbd4bddd9e4248009d0273ad7cae5dd</guid>
      <description><![CDATA[What type of antivirus evasion do you want today? For the past several years, we have been witnessing the emerging customerization applied in malware and spyware for hire services. What used to be a...]]></description>
      <content:encoded><![CDATA[<div class="separator" style="text-align: left; clear: both;"><a href="http://bp2.blogger.com/_wICHhTiQmrA/SIWJkocpGwI/AAAAAAAAB8U/_v3hJOM2k_s/s1600-h/preview_random.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SIWJkocpGwI/AAAAAAAAB8U/15Yc8N_lG74/s200-R/preview_random.jpg" style="border: 0pt none ;" /></a></div>What type of antivirus evasion do you want today? For the past several years, we have been witnessing the emerging customerization applied in malware and spyware for hire services. What used to be a situation where the malware authors would code and then start promoting a piece of malware including features that he thinks his potential customers would want by generalizing a cybercriminal's needs, is today's "listening to the customer" win-win situation that they've reached already. <br />
<br />
The whole maturity from a product concept to customerization is in fact so prevalent these days, that malware authors wanting to preserve their intellectual property are forbidding their customers from reverse engineering their malware modules, presumably fearing that <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">remotely exploitable flaws like this one in one of the most popular Ebanker malwares for the last two yers Zeus</a>, could be discovered due to the malware author's insecure coding practices. Moreover, limiting the distribution of a single license they are given to more than three people will result in the malware author ignoring any future business relationships with the party that ruined the exclusiveness of the malware, thereby leaking it to the public, something that's been happening and will continue happening with web malware exploitation kits.<br />
<br />
What would be the price of a custom malware module coded on demand? How much does it cost to have a built in email harvester that would sniff all the incoming and outgoing email addresses from the infected host to later on include them in upcoming spam and malware campaigns? Would the malware author also provide a managed hosting service for the command and control and the actual binaries on a revenue sharing <br />
<br />
Here's an automatically translated, and fairly easy to understand random proposition for coding spyware and malware for hire, aiming to answer many of these questions, clearly demonstrating that today's malware is coded in exactly the same way the customer wants it to : <br />
<br />
"<i>As you can see in the history of its development turned directly into the combine, while almost no raspuh in weight, full-size pack аж 18 kb and minialno 5 kb, for all nampomnyu again, all descriptions below can be done as otdelnym bot, and any combination of cross except for a few restrictions. This product is targeted at mass-user and will not be all prodavatsya row. So, you can choose from:</i><br />
<br />
<i>Actually loader - is able to load a file from adminki, by country and other characteristics, such as the number of animals on board with a specific bot, a country group of countries, the availability of certain authors or Fire, sredenemu time online, etc. etc.. You can adjust the speed of shipping limits for each file, can load 1 as well as how files simultaneously<br />
300 €</i><br />
<br />
<i><b>FTP and not only Graber</b><br />
Analyzes user traffic and collects from the ftp acclamation, that is ftp acclamation would you regardless of how the customer uses ftp user, thus can be obtained most valuable ftp aka (even those to which the password is not saved), you can also grab other in a way not only acclamation acclamation and other tasty things more)<br />
150 €<b>&nbsp;</b></i><br />
<br />
<i><b>Assembler spam bases</b><br />
Analyzes user traffic and collects from all email, snifit http pop3 smtp protocols, keeps records unikallnosti locally on each boat to reduce the burden on the server as well as globally on a server has 2 mode of operation - ie passive with only collects user to please and active - the very beginning to download the entire inet) in search of soap<br />
220 €<br />
<br />
<b>Socks 4 / 5</b><br />
Normal soks with competently implemented multithreading, is activated only if the user real Ip, otherwise not. And also optional, depending on the connection type and speed ineta.<br />
70 €<br />
<br />
<b>Indicates</b><br />
The primitive method, contamination fleshek avtoranom gives 2-3% increase in the first week and up to 7% in the next, a pleasant trifle)<br />
35 €<br />
<br />
<b>Scripts</b><br />
Loader supports internal scripting language - jscript, to carry out arbitrary actions on the victim machine, whether recording data in the register, setting authentic hon-Pago, opening URL in your browser (it was done so to please with 90% punching)), apload arbitrary files on a server, even theoretically possible to form and grabing inzhekty in IE) has only to write the script zaebetes, vobschem lyuboye actions soul who wish)<br />
70 € basic functionality<br />
<br />
<b>Assembler passwords</b><br />
Collects data such as passwords pstorage IE, MSN, etc., will be added at the request of other sources of passwords<br />
70 €<br />
<br />
<b>Mini-AV</b><br />
When installing loadera wheelbarrows to remove BHO shaped three, zevso-shaped, the majority of shit from all avtoranov, render most keylogerov until all) forward proposals to improve<br />
70 €<br />
<br />
<b>File-default</b><br />
In exe loadera program URL (in adminke) to the file which once progruzit 1 and run at first start loadera on wheelbarrows, while simultaneously helping progruzke Trojan for example, in its entire botnet that does not paired with challenges in adminke, the module operates in 20 seconds after the mini - av which excludes the removal of your Trojan bot, after progruza this exe bot continues to normal activities.<br />
35 €<br />
<br />
<b>Form Graber</b><br />
While in beta version, robbed IE. Sends logs in adminku, folding country. Logs are like logs agent. It consists of:<br />
<br />
<b>Graber certificats</b><br />
On the idea is part formgrabera but could work and of itself, actually there is nothing to describe)<br />
<br />
<b>Injections</b><br />
Literacy sold inzhekty, did not begin work after full progruza pages (as in bolshistve three) and immediately supported injection yavaskript code, which allows avtozalivy and DC inzhekty for data collection. For example not to yuzat acclamation at all is not yet introduce the necessary number of Britain, after which inzhekt ceases to operate. Вобщем mdelat can be anything and in any form) rather than the meager request field pin) And also inzhektov subspecies - a substitute for the issuance of search enginee.<br />
<br />
<b>Graber balances</b><br />
Makes loot aka balances at the entrance to the user acclamation, detail added to the logs.<br />
<br />
<b>Screen</b><br />
Universal method to grab information from absolutely any species and varieties klaiviatur screens, in particular html, flash, in one picture, with a drop-down fields after choosing your encrypted, as well as information such as "enter 3 yu secret letter word" etc. as well as any information which is visible a user but not seen in the logs. Screen settings of adminki, set URL where do screen as well as the type of screen: for virtual keyboard (done several small images of areas around the clique) or to "enter 3 yu secret letter words" (makes 1 full shot). With the withdrawal screen recorded in the log entry with the name of the file to the screen this position.<br />
<br />
<b>Antiabuznost for botneta</b><br />
Feachem adminki, keep botnet enables fast, normal, bezglyuchnyh NEabuzoustoychivyh hosting, with features that you forget what abuzy, nohistory week saporta "abuzoustoychivogo" hosting inaccessibility host to half ineta etc., etc., also with the help of the supplement will be able to keep huge botnety (over SL) at 1 dedike with 512 Lake) and well on the price of hosting a savings, not $ 500 a month and 150. It may use this feature to stroronnim development, Trojans, bots, etc., actually is a separate product. And incidentally, if you do not understand the theory that nenado ask "and how does it work?" imagine that it works and point and neubivaemo in pritsnipe.<br />
600 € +<br />
&nbsp;</i><br />
<i>All prices are in euros, the calculation is made at the rate of CB on the day of purchase. ps I will not disappear as most authors after months of sales, I DONT how to please you get to the assembly ftp, I DONT how many soap collects soap-graber, I DONT what otstuk from loadera, I DONT soksov how many will be from 1 to downloads, and how best To work load a file is not dead quickly, if you are confused my ignorance - that my loader so you do not need more tries)<br />
<br />
Rules / Licence<br />
-- Customer has no right to transfer any of his three 3 persons except options for harmonizing with me<br />
-- Customer does not have the right to make any decompile, research, malicious modification of any three parts<br />
-- Customer has no right where either rasprostanyat information about three and a public discussion with the exception of three entries.<br />
-- For violating the rules - without any license denial manibekov and further conversations</i>" <br />
<br />
This malware coder seems to be participating in an affiliate program with a malicious ISP that is offering hosting services for the entire campaign, not just the malware binaries, so you have a rather good example that incentives and revenue-sharing models result in value-added services, a all-in-one shop for a customer to take advantage of without bothering to approach a third-party.<br />
<br />
Cybercrime is getting even more easier to outsource these days, and with the malicious parties improving their communication and incentives model, the resulting transparency in the underground market<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Multiple Firewalls Bypassing Verification on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - The Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/russias-fsb-vs-cybercrime.html">Russia's FSB vs Cybercrime</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">Malware as a Web Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/localizing-open-source-malware.html">Localizing Open Source Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/quality-and-assurance-in-malware.html">Quality and Assurance in Malware Attacks</a><br />
<a href="http://ddanchev.blogspot.com/2006/09/benchmarking-and-optimising-malware.html">Benchmarking and Optimising Malware</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CfEGOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CfEGOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZmZP2J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZmZP2J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3RDQbj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3RDQbj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uN1LUj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uN1LUj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=oSzTOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=oSzTOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KOIqZJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KOIqZJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8gh7xj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8gh7xj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/342366718" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 23:52:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware author">malware author</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/malware binaries">malware binaries</category>
      <category domain="http://securityratty.com/tag/malware attacks">malware attacks</category>
      <category domain="http://securityratty.com/tag/ftp">ftp</category>
      <category domain="http://securityratty.com/tag/ftp user">ftp user</category>
      <category domain="http://securityratty.com/tag/collects">collects</category>
      <category domain="http://securityratty.com/tag/malware industry">malware industry</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/342366718/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</source>
    </item>
    <item>
      <title><![CDATA[Game Controllers Driving Drones, Nukes]]></title>
      <link>http://securityratty.com/article/d7a3d7cafbc2cd8c635e15260c0162f4</link>
      <guid>http://securityratty.com/article/d7a3d7cafbc2cd8c635e15260c0162f4</guid>
      <description><![CDATA[War is getting more like a videogame, as hardware and software from the gaming industry is increasingly being adopted for military use. The latest sign of this appeared at the Farnborough air show...]]></description>
      <content:encoded><![CDATA[War is getting more like a videogame, as hardware and software from the gaming industry is increasingly being adopted for military use. The latest sign of this appeared at the Farnborough air show this week, where arms-maker Raytheon showed off its new Universal Control System for robotic aicraft.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=2a2bc930a3bfd74d5c313d2f00fc1654" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=2a2bc930a3bfd74d5c313d2f00fc1654" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Bni5HJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Bni5HJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=RPbjkj"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=RPbjkj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=nTajCj"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=nTajCj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=1SjhgJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=1SjhgJ" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=0A013J"><img src="http://feeds.wired.com/~f/wired/politics/security?i=0A013J" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=oTx4Qj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=oTx4Qj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=i6mvAj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=i6mvAj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=X7goRJ"><img src="http://feeds.wired.com/~f/wired/politics/security?i=X7goRJ" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/341048288" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/341048289" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 20 Jul 2008 17:30:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/universal control system">universal control system</category>
      <category domain="http://securityratty.com/tag/farnborough air">farnborough air</category>
      <category domain="http://securityratty.com/tag/robotic aicraft">robotic aicraft</category>
      <category domain="http://securityratty.com/tag/arms-maker raytheon">arms-maker raytheon</category>
      <category domain="http://securityratty.com/tag/videogame">videogame</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/military">military</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <category domain="http://securityratty.com/tag/increasingly">increasingly</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/341048289/wargames.html">Game Controllers Driving Drones, Nukes</source>
    </item>
    <item>
      <title><![CDATA[P2P-related breach affects high-profile clients from Wagner Resource Group]]></title>
      <link>http://securityratty.com/article/989cd0c39e1e8d8d99a391e92dc0fb1d</link>
      <guid>http://securityratty.com/article/989cd0c39e1e8d8d99a391e92dc0fb1d</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/9/08

Organization
Wagner Resource Group

Contractor/Consultant/Branch
None

Victims
Clients

Most notably Supreme Court Justice Stephen G. Breyer,...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/wagner.jpg" width="200" align="right" height="120"><font size="2"><b>Date Reported: </b><br>7/9/08<br><br><b>Organization: </b><br><a href="http://www.wagnerrg.com/new/invest-taxfree/gate.asp">Wagner Resource Group</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Clients*<br><br><font size="1">*Most notably Supreme Court Justice Stephen G. Breyer, which has been well publicized.</font><br><br><span style="font-weight: bold;">Number Affected:</span><br>~2,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, dates of birth and Social Security numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"The Washington Post today ran a story I wrote on a data breach of a local investment firm that exposed the names, birth dates and Social Security numbers of some of the Washington area's most powerful attorneys, including Supreme Court Justice Stephen Breyer."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://blog.washingtonpost.com/securityfix/">SecurityFix</a> <br><a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/07/08/AR2008070802997.html">Washington Post</a> <br><a href="http://www.upi.com/Top_News/2008/07/09/Justices_data_breached_in_file-sharing/UPI-14191215609364/">United Press International</a> <br><a href="http://www.nbc4.com/news/16832357/detail.html">NBC Universal, Inc</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Brian Krebs, Washington Post<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Sometime late last year, an employee of a McLean investment firm decided to trade some music, or maybe a movie, with like-minded users of the online file-sharing network LimeWire while using a company computer<br><span style="font-style: italic;">[Evan] P2P file sharing and other client software use can pose a very significant risk in most companies.&nbsp; It is typically an easy risk to address however.&nbsp; A mixture of any one or more of the following controls can help to mitigate the risk; information security training and awareness, egress traffic monitoring and filtering, intrusion detection/prevention, and hardened workstations (i.e. removal of administrative access) to name a few.</span><br style="font-style: italic;"><br>In doing so, he inadvertently opened the private files of his firm, Wagner Resource Group, to the public.<br><span style="font-style: italic;">[Evan] This is a common oversight.&nbsp; LimeWire and other P2P file sharing applications are wonderful tools for doing what they are designed to do.&nbsp; Before allowing their use (or any other software), an organization must evaluate the risks in doing so.&nbsp; If you intend to use or allow the use of LimeWire in your organization, understand how the software works and how it is configured.&nbsp; During the install you will be prompted for the "Save Folder and Shared Folders".&nbsp; Be careful what you choose, and be careful about what information you put in these locations in the future.&nbsp; Most organizations that are aware of risks just choose not to allow P2P use.</span><br><br><img src="http://images.quickblogcast.com/95781-88451/limewire.jpg" width="576" border="0"><br><br>That exposed the names, dates of birth and Social Security numbers of about 2,000 of the firm's clients, including a number of high-powered lawyers and Supreme Court Justice Stephen G. Breyer.<br><span style="font-style: italic;">[Evan] The high-profile nature of this breach is what has grabbed headlines all last week.</span><br><br>Of the 2,000 records from Wagner Resource Group that were found online, 700 included Social Security numbers, names and birth dates, while other records included only one or two of those details. <br><br>The breach was not discovered for nearly six months.<br><span style="font-style: italic;">[Evan] This is another danger posed by information leaked through P2P.&nbsp; Once information has leaked, how does an organization detect that it has been leaked?&nbsp; There is no longer any control.</span><br style="font-style: italic;"><br>A reader of washingtonpost.com's Security Fix blog found the information while searching LimeWire in June.<br><span style="font-style: italic;">[Evan] I wonder why the reader did not notify the authorities and/or Wagner at the time of its discovery.&nbsp; Maybe he/she did.&nbsp; I don't know.</span><br style="font-style: italic;"><br>Robert Boback, chief executive of Tiversa, the company hired by Wagner to help contain the data breach, said such breaches are hardly rare.<br><br>About 40 to 60 percent of all data leaks take place outside of a company's secured network, usually as a result of employees or contractors installing file-sharing software on company computers.<br><span style="font-style: italic;">[Evan] Really?!&nbsp; I would have not guessed that the percentage would be so high.&nbsp; Interesting.</span><br><br>"We've seen a lot of instances where a company will be working on a product that's not even released yet, and the diagrams for that product are already out on the Net," Boback said.<br><span style="font-style: italic;">[Evan] Very good point.&nbsp; It isn't just personally identifiable information that is leaked, there are plenty of instances where intellectual property (IP) is exposed.&nbsp; I have read estimates that as much as 80% or organizational assets globally are intangible (information, knowledge, etc.).</span><br style="font-style: italic;"><br>"This case is unique because of the high profile of the targets. The individuals on this list are at a very high risk, almost imminent, of identity theft." <br><br>Tiversa officials found that more than a dozen LimeWire users in places as far away as Sri Lanka and Colombia downloaded the list of personal data from the Wagner network.<br><br>"To me, this was devastating," said Phylyp Wagner, founder of the investment firm. "I didn't even know what peer-to-peer was. I do now."<br><span style="font-style: italic;">[Evan] This is a big problem!&nbsp; Corporate leaders must be made aware of the risks surrounding the information for which they are ultimately responsible for.</span><br style="font-style: italic;"><br>Wagner said his company has contracted with FirstAdvantage of Poway, Calif., which last week sent out letters notifying affected clients of the breach and offering each six months of free credit-report monitoring.<br><br>He emphasized that the peer-to-peer disclosure never endangered his clients' financial records, which are stored by a separate company.<br><span style="font-style: italic;">[Evan] Maybe not their financial records, but it did affect some people's financial status (at least temporarily).</span><br><br>But that may be small consolation to several lawyers on the list who said they recently experienced unexplained financial activity.<br><br>"This may explain why two weeks ago I got a $9,000 cellphone bill from AT&amp;T," said Steven Agresta, a partner with the law firm Alston &amp; Bird.<br><br>Someone had opened a phone account using his date of birth and Social Security number, but with a different address.<br><br>this morning I heard from reader Christopher Lynt, a patent attorney from Virginia whose personal data was included in the file exposed via P2P.<br><br>He told me that last July, an identity thief used his SSN and birth date to have $1,000 wired to Mexico from Lynt's bank and credit accounts.<br><br><span style="font-weight: bold;">Commentary:</span><br>This certainly isn't the first time we have read about P2P file sharing network exposures.&nbsp; If your organization can find a way to use the technology without posing an unacceptable risk, then fine.&nbsp; If not, then don't allow the technology to be used.&nbsp; Seems pretty plain and simple.<br><br>There is much work to be done.&nbsp; At Wagner and elsewhere. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/14/wagner.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 14 Jul 2008 13:08:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wagner">wagner</category>
      <category domain="http://securityratty.com/tag/p2p">p2p</category>
      <category domain="http://securityratty.com/tag/investment firm">investment firm</category>
      <category domain="http://securityratty.com/tag/evan p2p file">evan p2p file</category>
      <category domain="http://securityratty.com/tag/mclean investment firm">mclean investment firm</category>
      <category domain="http://securityratty.com/tag/p2p file">p2p file</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/wagner network">wagner network</category>
      <category domain="http://securityratty.com/tag/wagner resource">wagner resource</category>
      <source url="http://breachblog.com/2008/07/14/wagner.aspx">P2P-related breach affects high-profile clients from Wagner Resource Group</source>
    </item>
  </channel>
</rss>
