<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: verification]]></title>
    <link>http://securityratty.com/tag/verification</link>
    <description></description>
    <pubDate>Tue, 03 Jun 2008 03:01:20 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Banker Malware Targeting Brazilian Banks in the Wild]]></title>
      <link>http://securityratty.com/article/4c146364a5e5366271bb42a4f795af8d</link>
      <guid>http://securityratty.com/article/4c146364a5e5366271bb42a4f795af8d</guid>
      <description><![CDATA[Despite the ongoing customerization of malware, and the malware coding for hire customer tailored services, certain malware authors still believe in the product concept, namely, they build it and wait...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKldLvANUBI/AAAAAAAACC8/4JM_2PVEVY4/s1600-h/banker_malware_brazil_banks.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKldLvANUBI/AAAAAAAACC8/zzcjUAMw61E/s200-R/banker_malware_brazil_banks.jpg" /></a>Despite the ongoing customerization of malware, and the malware coding for hire customer tailored services, certain malware authors still believe in the product concept, namely, they build it and wait for someone to come. In this underground proposition for a proprietary banker malware targeting primarily Brazillian bank, the author is relying on the localized value added to his malware forgetting a simply fact - that the most popular banker malware is generalizing E-banking transactions in such a way that it's successfully able to hijack the sessions of banks it hasn't originally be coded to target in general.<br />
<br />
<b>Banks targetted in this banker malware :</b><br />
<i>Bank Equifax<br />
Bank Itau<br />
Bank Check<br />
Bank Vivo<br />
Bank Banrisul<br />
Tim Bank Brazil<br />
Bank Nossa Caixa<br />
Bank Santander Banespa<br />
Bank Infoseg<br />
Bank Paypal <br />
Bank Caixa Economica Federal<br />
Bank Bradesco<br />
Bank Northeast<br />
Royal Bank<br />
Bank Itau Personnalite<br />
Bank PagSeguro<br />
Australia Bank<br />
Credicard Citi Bank<br />
Credicard Bank Itau<br />
Rural Bank</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKlgsZBqOLI/AAAAAAAACDE/kN2MQLJqjls/s1600-h/banker_malware_brazil_banks1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKlgsZBqOLI/AAAAAAAACDE/niBpSaKVaTE/s200-R/banker_malware_brazil_banks1.jpg" /></a>Taking into consideration the fact that not everyone would be willing to pay a couple of thousand dollars for a <a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">banker malware kit targeting banks the customer isn't interested in at the first place</a>, malware authors have long been tailoring their propositions on the basis of modules. Adding an additional module for stealtness increases the prices, as well as an additional module forwarding the process of updating the malware binary to the "customer support desk". Moreover, stripping the banker kit from modules in which the customer doesn't have interest, like for instance exclude all Asian banks the kit has already built-in capabilities to hijack and log transactions from, decreases its price.<br />
<br />
In a truly globalized IT underground, Brazillian cybercriminals tend to prefer using the <a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">market leading tools courtesy of Russian malware authors</a>, so this localized banker malware with its basic session screenshot taking capabilities and accounting data logging has a very long way to go before it starts getting embraced by the local underground.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/08/twitter-malware-campaign-wants-to-bank.html">The Twitter Malware Campaign Wants to Bank With You</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/targeted-spamming-of-bankers-malware.html">Targeted Spamming of Bankers Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/localized-bankers-malware-campaign.html">A Localized Bankers Malware Campaign</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/76service-cybercrime-as-service-going.html">76Service - Cybercrime as a Service Going Mainstream</a><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Multiple Firewalls Bypassing Verification on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - The Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">Malware as a Web Service</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed "Spamming Appliances" - The Future of Spam</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UycytK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UycytK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=aWvyIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=aWvyIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KGP6hk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KGP6hk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1wZEOk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1wZEOk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PycnBK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PycnBK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KVzVsK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KVzVsK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XGelDk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XGelDk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/368038328" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 03:01:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/banker malware">banker malware</category>
      <category domain="http://securityratty.com/tag/banker malware kit">banker malware kit</category>
      <category domain="http://securityratty.com/tag/kit">kit</category>
      <category domain="http://securityratty.com/tag/popular banker malware">popular banker malware</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/bank itau personnalite">bank itau personnalite</category>
      <category domain="http://securityratty.com/tag/bank itau">bank itau</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/russian malware authors">russian malware authors</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/368038328/banker-malware-targetting-brazilian.html">Banker Malware Targeting Brazilian Banks in the Wild</source>
    </item>
    <item>
      <title><![CDATA[76Service - Cybercrime as a Service Going Mainstream]]></title>
      <link>http://securityratty.com/article/35bdaf104e9aecf7703834d959f39050</link>
      <guid>http://securityratty.com/article/35bdaf104e9aecf7703834d959f39050</guid>
      <description><![CDATA[Disintermediating the intermediaries in the cybercrime ecosystem, ultimately results in more profitable operations. Controversial to the concept of outsourcing, some cybercriminals are in fact so...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKKs5L3ihpI/AAAAAAAACBs/vEaSMC2S8nI/s1600-h/76service.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKKs5L3ihpI/AAAAAAAACBs/qhgjQh39ej8/s200-R/76service.JPG" style="border: 0pt none ;" /></a>Disintermediating the intermediaries in the cybercrime ecosystem, ultimately results in more profitable operations. Controversial to the concept of outsourcing, some cybercriminals are in fact so self-sufficient, that the stereotype of a mysterious 76service server offered for rent could in fact easily cease to exist in an ecosystem so vibrant that literally everyone can partion their botnet and start offering access to it on a multi-user basis. Evil? Obviously. Extending the lifecycle of a proprietary malware tool? Definitely.<br />
<br />
<a href="http://www.youtube.com/watch?v=lw9IeuKkNbc">The infamous 76service</a>, a cybercrime as a service web interface where customers basically collect the final output out of the banking malware botnet during the specific period of time for which they've purchases access to the service, is going mainstream, with 76Service's Spring Edition apparently leaking out, and cybercriminals enjoying its interoperability potential by introducing different banking trojans in their campaigns. <br />
<br />
In this post, I'll discuss the 76service's spring.edition that has been combined with a <a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher banking malware</a>, an a popular <a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">web malware exploitation kit</a>, with two campaigns currently hosting 5.51GB of stolen banking data based on over 1 million compromised hosts 59% of which are based in Russia. Screenshots courtesy of an egocentric underground show-off.<br />
<br />
<a href="http://www.cio.com/article/print/135500">Some general info on the 76service</a> :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKyWAXgYGI/AAAAAAAACB0/JXHZFuBb6Rs/s1600-h/76service1.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKyWAXgYGI/AAAAAAAACB0/2qZfVy6YfU8/s200-R/76service1.JPG" style="border: 0pt none ;" /></a>"<i>Subscribers could log in with their assigned user name and     password any time during the 30-day project. They’d be     met with a screen that told them which of their bots was     currently active, and a side bar of management options. For     example, they could pull down the latest drops—data     deposits that the Gozi-infected machines they subscribed to     sent to the servers, like the 3.3 GB one Jackson had     found. A project was like an investment portfolio. Individual     Gozi-infected machines were like stocks and subscribers bought     a group of them, betting they could gain enough personal     information from their portfolio of infected machines to make a     profit, mostly by turning around and selling credentials on the     black market. (In some cases, subscribers would use a few of     the credentials themselves). Some machines, like some stocks, would under perform and     provide little private information. But others would land the     subscriber a windfall of private data. The point was to     subscribe to several infected machines to balance that risk,     the way Wall Street fund managers invest in many stocks to     offset losses in one company with gains in another.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKy5q1ebVI/AAAAAAAACB8/uGe8GuhDvRg/s1600-h/76service2.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKy5q1ebVI/AAAAAAAACB8/88IxypeBf74/s200-R/76service2.JPG" style="border: 0pt none ;" /></a>The 76service empowers everyone who is either not willing to spend time and resources for building and maintaining a botnet, launching campaigns, and SQL injecting hundreds of thousands of sites in order to take advantage of the long tail of malware infected sites that theoretically can outpace the traffic that could come from a SQL injected high-profile site.<br />
<br />
Next to the spring.edition, <a href="http://secureworks.com/research/threats/gozi/">the winter edition's price starts from $1000 and goes to $2000</a>, which is all a matter of who you're buying it from, unless of course you haven't come across leaked copies :<br />
<br />
"<i>Assuming that the dealer offering what he claimed was the 76service kit was correct, the profit is not only in the kit, but in selling value added services like exploitation, compromised servers/accounts, database configuration, and customization of the interface. Prices start between $1000 to $2000 and go up based on added services. The underground payment methods generally involve hard-to-track virtual currencies, whose central authority is in a jurisdiction where regulation is liberal to non-existent, and feature non-reversible transactions. The individual or group called "76service" was easy to track down on the Web, but not in person.</i>" <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKLUyA7g9LI/AAAAAAAACCE/nl-OA3FHPs0/s1600-h/76service3.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKLUyA7g9LI/AAAAAAAACCE/8zS6gcoEdvk/s200-R/76service3.JPG" style="border: 0pt none ;" /></a>It's interesting to monitor how services aiming to provide specific malicious services are vertically integrating by expanding their portfolio of related services -- taka a spamming vendor that will offer the segmented email databases, the advanced metrics, and the localization of the spam messages to different languages -- or letting the buyer have full control of anything that comes out of a particular botnet for a specific period of time in which he has bought access to it. For instance, DDoS for hire matured into botnet for hire, which evolved into today's "What type of stolen data do you want?" for hire mentality I'm starting to see emerging, next to the usual interest in improving the metrics and thereby the probability for a more succesful campaign. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKLa2TO4yAI/AAAAAAAACCM/4s3Mkgb-NOY/s1600-h/metafisher1_ukstories.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKLa2TO4yAI/AAAAAAAACCM/Bt7wKW7IPcE/s200-R/metafisher1_ukstories.jpg" style="border: 0pt none ;" /></a>Ironically, this cybercrime model is so efficient that the people behind it cannot seem to be able to process all of the stolen data, which like a great deal of underground assets loses its value if not sold as fast as possible. The result of this oversupply of stolen data are the increasing number of services selling raw logs segmented based on a particular country for a specific period of time.<br />
<br />
Time for a remotely exploitable vulnerability in yet another malware kit about to go mainstream? Definitely, unless of course backdooring it and releasing it doesn't achieve the obvious results of controlling someone else's cybercrime ecosystem.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Multiple Firewalls Bypassing Verification on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - The Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">Malware as a Web Service</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed "Spamming Appliances" - The Future of Spam</a><br />
<br />
<b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NWhwdK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NWhwdK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7zGnyK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7zGnyK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Rqgfok"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Rqgfok" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zA7GDk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zA7GDk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4r7WMK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4r7WMK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=880FjK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=880FjK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3wtOmk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3wtOmk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/363878623" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 04:08:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/76service">76service</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/malware botnet">malware botnet</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/mysterious 76service server">mysterious 76service server</category>
      <category domain="http://securityratty.com/tag/web service">web service</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/363878623/76service-cybercrime-as-service-going.html">76Service - Cybercrime as a Service Going Mainstream</source>
    </item>
    <item>
      <title><![CDATA[Dissecting a Managed Spamming Service]]></title>
      <link>http://securityratty.com/article/a86a7c12b2395b3c5ee8667c3a4d13e0</link>
      <guid>http://securityratty.com/article/a86a7c12b2395b3c5ee8667c3a4d13e0</guid>
      <description><![CDATA[With cybercrime getting easier to outsource these days, and with the overall underground economy's natural maturity from products to services, &quot; managed spamming appliances &quot; and managed spamming...]]></description>
      <content:encoded><![CDATA[<div class="separator" style="text-align: left; clear: both;"><a href="http://bp2.blogger.com/_wICHhTiQmrA/SJAiYgYGvGI/AAAAAAAAB-c/0z_b5zxZV0c/s1600-h/customer_support.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SJAiYgYGvGI/AAAAAAAAB-c/bUYt5gvY6SU/s320-R/customer_support.jpg" style="border: 0pt none ;" /></a></div>With cybercrime getting easier to outsource these days, and with the overall underground economy's natural maturity from products to services, "<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">managed spamming appliances</a>" and managed spamming services are becoming rather common. Increasingly, these "vendors" are starting to "vertically integrate", namely, start diversifying the portfolio of services they offer in order to steal market share from other "vendors" offering related services like, email database cleaning, segmentation of email databases, email servers or botnets whose hosts have a pre-checked and relatively clean IP reputation, namely they're not blacklisted yet.<br />
<br />
How much does it cost to send 1 million spam emails these days? According to a random spamming service, $100 excluding the discounts based on the speed of sending desired, namely 10-20 per second or 20-30 per second. Let's dissect the service, and emphasize on its key differentiation factors, as well as the customerization offered in the form of a dedicated server if the customer would like to send billions of emails :<br />
<br />
"<i>-- High quality and percentage of spam delivery&nbsp;</i><br />
<i> -- Fast speed of delivery<br />
-- Spam database on behalf of the vendor, or using your own database of harvested emails<br />
-- Easily obtainable and segmented spam databases on per country basis<br />
-- Randomization of the spam email's body and headers in order to achieve a higher delivery rate<br />
-- Support for attachments, executables, and image files<br />
<br />
The cost - $100 for a million for letters delivered spam, with the large volume of spam discounts 20% -30% -40% based on the value-added Do-it-yourself customer interfare based on a multi-user botnet command and control interface :<br />
&nbsp;</i><br />
<i>-- Automatic RBL verification  <br />
-- Support for many subjects, headers,  <br />
-- Total customization of the email sending process  <br />
-- Autogenerating junk content next to the spammers email/link in order to bypass filtering<br />
-- Faking Outlook Message ID / Boundary / Content-ID  <br />
-- Interface added. Now do not necessarily understand all the features into the system to start the list.  <br />
-- Convenient management tasks.  <br />
-- A high percentage of punching, on the basis of good europe - 40-60% (For the United States - less because there aol and others). <br />
-- Improved metrics, whether or not the emails have been sent, lost, unknown receipt, or have been RBL-ed<br />
<br />
With the weight of a billion - even discounts and the possibility of making a personal server. " <br />
<br />
</i>Rather surprising, they state that European email users have a higher probability of receiving the spam message compared the U.S due to AOL. What they're actually trying to say is due to AOL's use of Domain Keys Identified Mail (DKIM). As far as <a href="http://ddanchev.blogspot.com/2008/05/segmenting-and-localizing-spam.html">localization of the spam to the email owner's native languag</a>e is concerned, this segmentation concept has been take place for over an year now.<br />
<br />
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SJA7MWbx4jI/AAAAAAAAB-k/BvKdLNRflW4/s1600-h/phishme_demo_ethical.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJA7MWbx4jI/AAAAAAAAB-k/Y5691Se7e2k/s200-R/phishme_demo_ethical.JPG" style="border: 0pt none ;" /></a>This service, like the majority of others rely entirely on malware infected hosts, which due to the multi-user nature of most of the malware command and control interfaces, allows them to easily add customers and set their privileges based on the type of service that they purchase. This leaves a countless number of opportunities for targeted spamming, and yes, spear phishing attacks made possible due to the segmentation of the emails based on a country, city, even company.<br />
<br />
In the long term, the people behind spamming providers, web malware exploitation kits and <a href="http://ddanchev.blogspot.com/2008/05/diy-phishing-kits-introducing-new.html">DIY phishing kits</a>, will inevitably start introducing built-in features which were once available through third-party services. For instance, hosting infrastructure for the spam/phishing/live exploit URLs, or even managed fast-flux infrastructure, have the potential to become widely available if such optional features get built-in phishing kits, or start getting offered by the spamming provider itself. And since the affiliate based model seems to be working just fine, the <a href="http://ddanchev.blogspot.com/2007/12/phishers-spammers-and-malware-authors.html">ongoing underground consolidation</a> will converge providers of different underground goods and services, where everyone would be driving customers to one another's services and earning revenue in the process.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bsJ3iJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bsJ3iJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IEP1EJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IEP1EJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZzurFj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZzurFj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uIY3Pj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uIY3Pj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=60gQsJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=60gQsJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Nb7yGJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Nb7yGJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=y37sBj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=y37sBj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/350363899" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 01:32:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/spam message">spam message</category>
      <category domain="http://securityratty.com/tag/spam discounts">spam discounts</category>
      <category domain="http://securityratty.com/tag/spam database">spam database</category>
      <category domain="http://securityratty.com/tag/spam databases">spam databases</category>
      <category domain="http://securityratty.com/tag/spam email">spam email</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/emails based">emails based</category>
      <category domain="http://securityratty.com/tag/email servers">email servers</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/350363899/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</source>
    </item>
    <item>
      <title><![CDATA[Coding Spyware and Malware for Hire]]></title>
      <link>http://securityratty.com/article/1dbd4bddd9e4248009d0273ad7cae5dd</link>
      <guid>http://securityratty.com/article/1dbd4bddd9e4248009d0273ad7cae5dd</guid>
      <description><![CDATA[What type of antivirus evasion do you want today? For the past several years, we have been witnessing the emerging customerization applied in malware and spyware for hire services. What used to be a...]]></description>
      <content:encoded><![CDATA[<div class="separator" style="text-align: left; clear: both;"><a href="http://bp2.blogger.com/_wICHhTiQmrA/SIWJkocpGwI/AAAAAAAAB8U/_v3hJOM2k_s/s1600-h/preview_random.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SIWJkocpGwI/AAAAAAAAB8U/15Yc8N_lG74/s200-R/preview_random.jpg" style="border: 0pt none ;" /></a></div>What type of antivirus evasion do you want today? For the past several years, we have been witnessing the emerging customerization applied in malware and spyware for hire services. What used to be a situation where the malware authors would code and then start promoting a piece of malware including features that he thinks his potential customers would want by generalizing a cybercriminal's needs, is today's "listening to the customer" win-win situation that they've reached already. <br />
<br />
The whole maturity from a product concept to customerization is in fact so prevalent these days, that malware authors wanting to preserve their intellectual property are forbidding their customers from reverse engineering their malware modules, presumably fearing that <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">remotely exploitable flaws like this one in one of the most popular Ebanker malwares for the last two yers Zeus</a>, could be discovered due to the malware author's insecure coding practices. Moreover, limiting the distribution of a single license they are given to more than three people will result in the malware author ignoring any future business relationships with the party that ruined the exclusiveness of the malware, thereby leaking it to the public, something that's been happening and will continue happening with web malware exploitation kits.<br />
<br />
What would be the price of a custom malware module coded on demand? How much does it cost to have a built in email harvester that would sniff all the incoming and outgoing email addresses from the infected host to later on include them in upcoming spam and malware campaigns? Would the malware author also provide a managed hosting service for the command and control and the actual binaries on a revenue sharing <br />
<br />
Here's an automatically translated, and fairly easy to understand random proposition for coding spyware and malware for hire, aiming to answer many of these questions, clearly demonstrating that today's malware is coded in exactly the same way the customer wants it to : <br />
<br />
"<i>As you can see in the history of its development turned directly into the combine, while almost no raspuh in weight, full-size pack аж 18 kb and minialno 5 kb, for all nampomnyu again, all descriptions below can be done as otdelnym bot, and any combination of cross except for a few restrictions. This product is targeted at mass-user and will not be all prodavatsya row. So, you can choose from:</i><br />
<br />
<i>Actually loader - is able to load a file from adminki, by country and other characteristics, such as the number of animals on board with a specific bot, a country group of countries, the availability of certain authors or Fire, sredenemu time online, etc. etc.. You can adjust the speed of shipping limits for each file, can load 1 as well as how files simultaneously<br />
300 €</i><br />
<br />
<i><b>FTP and not only Graber</b><br />
Analyzes user traffic and collects from the ftp acclamation, that is ftp acclamation would you regardless of how the customer uses ftp user, thus can be obtained most valuable ftp aka (even those to which the password is not saved), you can also grab other in a way not only acclamation acclamation and other tasty things more)<br />
150 €<b>&nbsp;</b></i><br />
<br />
<i><b>Assembler spam bases</b><br />
Analyzes user traffic and collects from all email, snifit http pop3 smtp protocols, keeps records unikallnosti locally on each boat to reduce the burden on the server as well as globally on a server has 2 mode of operation - ie passive with only collects user to please and active - the very beginning to download the entire inet) in search of soap<br />
220 €<br />
<br />
<b>Socks 4 / 5</b><br />
Normal soks with competently implemented multithreading, is activated only if the user real Ip, otherwise not. And also optional, depending on the connection type and speed ineta.<br />
70 €<br />
<br />
<b>Indicates</b><br />
The primitive method, contamination fleshek avtoranom gives 2-3% increase in the first week and up to 7% in the next, a pleasant trifle)<br />
35 €<br />
<br />
<b>Scripts</b><br />
Loader supports internal scripting language - jscript, to carry out arbitrary actions on the victim machine, whether recording data in the register, setting authentic hon-Pago, opening URL in your browser (it was done so to please with 90% punching)), apload arbitrary files on a server, even theoretically possible to form and grabing inzhekty in IE) has only to write the script zaebetes, vobschem lyuboye actions soul who wish)<br />
70 € basic functionality<br />
<br />
<b>Assembler passwords</b><br />
Collects data such as passwords pstorage IE, MSN, etc., will be added at the request of other sources of passwords<br />
70 €<br />
<br />
<b>Mini-AV</b><br />
When installing loadera wheelbarrows to remove BHO shaped three, zevso-shaped, the majority of shit from all avtoranov, render most keylogerov until all) forward proposals to improve<br />
70 €<br />
<br />
<b>File-default</b><br />
In exe loadera program URL (in adminke) to the file which once progruzit 1 and run at first start loadera on wheelbarrows, while simultaneously helping progruzke Trojan for example, in its entire botnet that does not paired with challenges in adminke, the module operates in 20 seconds after the mini - av which excludes the removal of your Trojan bot, after progruza this exe bot continues to normal activities.<br />
35 €<br />
<br />
<b>Form Graber</b><br />
While in beta version, robbed IE. Sends logs in adminku, folding country. Logs are like logs agent. It consists of:<br />
<br />
<b>Graber certificats</b><br />
On the idea is part formgrabera but could work and of itself, actually there is nothing to describe)<br />
<br />
<b>Injections</b><br />
Literacy sold inzhekty, did not begin work after full progruza pages (as in bolshistve three) and immediately supported injection yavaskript code, which allows avtozalivy and DC inzhekty for data collection. For example not to yuzat acclamation at all is not yet introduce the necessary number of Britain, after which inzhekt ceases to operate. Вобщем mdelat can be anything and in any form) rather than the meager request field pin) And also inzhektov subspecies - a substitute for the issuance of search enginee.<br />
<br />
<b>Graber balances</b><br />
Makes loot aka balances at the entrance to the user acclamation, detail added to the logs.<br />
<br />
<b>Screen</b><br />
Universal method to grab information from absolutely any species and varieties klaiviatur screens, in particular html, flash, in one picture, with a drop-down fields after choosing your encrypted, as well as information such as "enter 3 yu secret letter word" etc. as well as any information which is visible a user but not seen in the logs. Screen settings of adminki, set URL where do screen as well as the type of screen: for virtual keyboard (done several small images of areas around the clique) or to "enter 3 yu secret letter words" (makes 1 full shot). With the withdrawal screen recorded in the log entry with the name of the file to the screen this position.<br />
<br />
<b>Antiabuznost for botneta</b><br />
Feachem adminki, keep botnet enables fast, normal, bezglyuchnyh NEabuzoustoychivyh hosting, with features that you forget what abuzy, nohistory week saporta "abuzoustoychivogo" hosting inaccessibility host to half ineta etc., etc., also with the help of the supplement will be able to keep huge botnety (over SL) at 1 dedike with 512 Lake) and well on the price of hosting a savings, not $ 500 a month and 150. It may use this feature to stroronnim development, Trojans, bots, etc., actually is a separate product. And incidentally, if you do not understand the theory that nenado ask "and how does it work?" imagine that it works and point and neubivaemo in pritsnipe.<br />
600 € +<br />
&nbsp;</i><br />
<i>All prices are in euros, the calculation is made at the rate of CB on the day of purchase. ps I will not disappear as most authors after months of sales, I DONT how to please you get to the assembly ftp, I DONT how many soap collects soap-graber, I DONT what otstuk from loadera, I DONT soksov how many will be from 1 to downloads, and how best To work load a file is not dead quickly, if you are confused my ignorance - that my loader so you do not need more tries)<br />
<br />
Rules / Licence<br />
-- Customer has no right to transfer any of his three 3 persons except options for harmonizing with me<br />
-- Customer does not have the right to make any decompile, research, malicious modification of any three parts<br />
-- Customer has no right where either rasprostanyat information about three and a public discussion with the exception of three entries.<br />
-- For violating the rules - without any license denial manibekov and further conversations</i>" <br />
<br />
This malware coder seems to be participating in an affiliate program with a malicious ISP that is offering hosting services for the entire campaign, not just the malware binaries, so you have a rather good example that incentives and revenue-sharing models result in value-added services, a all-in-one shop for a customer to take advantage of without bothering to approach a third-party.<br />
<br />
Cybercrime is getting even more easier to outsource these days, and with the malicious parties improving their communication and incentives model, the resulting transparency in the underground market<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Multiple Firewalls Bypassing Verification on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - The Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/russias-fsb-vs-cybercrime.html">Russia's FSB vs Cybercrime</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">Malware as a Web Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/localizing-open-source-malware.html">Localizing Open Source Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/quality-and-assurance-in-malware.html">Quality and Assurance in Malware Attacks</a><br />
<a href="http://ddanchev.blogspot.com/2006/09/benchmarking-and-optimising-malware.html">Benchmarking and Optimising Malware</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CfEGOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CfEGOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZmZP2J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZmZP2J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3RDQbj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3RDQbj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uN1LUj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uN1LUj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=oSzTOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=oSzTOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KOIqZJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KOIqZJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8gh7xj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8gh7xj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/342366718" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 23:52:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware author">malware author</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/malware binaries">malware binaries</category>
      <category domain="http://securityratty.com/tag/malware attacks">malware attacks</category>
      <category domain="http://securityratty.com/tag/ftp">ftp</category>
      <category domain="http://securityratty.com/tag/ftp user">ftp user</category>
      <category domain="http://securityratty.com/tag/collects">collects</category>
      <category domain="http://securityratty.com/tag/malware industry">malware industry</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/342366718/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</source>
    </item>
    <item>
      <title><![CDATA[Assessing the Security Benefits of Cloud Computing]]></title>
      <link>http://securityratty.com/article/1e09e5c89f15d3a4df4ea921f9230c2d</link>
      <guid>http://securityratty.com/article/1e09e5c89f15d3a4df4ea921f9230c2d</guid>
      <description><![CDATA[With all this talk and reporting about security concerns, lets change the channel for a moment and assess the potential security benefits of Cloud Computing
In my view, there are some strong technical...]]></description>
      <content:encoded><![CDATA[<p><a title="Is the glass half empty or half full?" href="http://www.flickr.com/photos/94094843@N00/2292559560/" target="_blank"><img class="alignright" style="border: 0; float: right; margin: 3px;" src="http://farm4.static.flickr.com/3004/2292559560_378f226531_m.jpg" border="0" alt="Is the glass half empty or half full?" /></a></p>
<p>With all this <a href="http://cloudsecurity.org">talk</a> and <a href="http://www.gartner.com/DisplayDocument?id=685308">reporting</a> about security concerns, lets change the channel for a moment and assess the <strong>potential security benefits</strong> of Cloud Computing.</p>
<p>In my view, there are some strong technical security arguments in favour of Cloud Computing - assuming we can find ways to manage the risks.</p>
<p>With this new paradigm come challenges <strong>and </strong>opportunities.  The challenges are getting plenty of attention - I&#8217;m regularly afforded the opportunity to <a href="http://www.gridtoday.com/grid/2422309.html">comment</a> on them, plus obviously I cover them on this blog.  However, lets not lose sight of the potential upside.</p>
<p>In this post, I walk through seven technical security benefits.  Some are immediate, others may arise over time and have conditions attached (some unstated for the sake of brevity).  However, I&#8217;m including the longer-range benefits now to raise awareness.  Some of the outcomes listed are available today without the Cloud, but they are either complex and slow to implement (and thus less likely to happen) or prohibitive for capital cost reasons.  I don&#8217;t claim this is a definitive list - it reflects where my thinking is today.</p>
<p>Some benefits depend on the Cloud service used and therefore do not apply across the board.  For example; I see no solid forensic benefits with SaaS.  Also, for space reasons, I&#8217;m purposely not including the &#8216;flip side&#8217; to these benefits, however if you read this blog regularly you should <a href="http://cloudsecurity.org/2008/04/24/cloud-stacks-please-mind-the-gap/">recognise some</a>.</p>
<p>On a sidenote, I believe the Cloud offers Small and Medium Businesses major potential security benefits.  Frequently SMBs struggle with limited or non-existent in-house INFOSEC resources and budgets.  The caveat is that the Cloud market is still very new - security offerings are somewhat foggy - making selection tricky.  Clearly, not all Cloud providers will offer the same security.</p>
<h4>Seven Technical Security Benefits of the Cloud</h4>
<h4>1. Centralised Data</h4>
<ul>
<li><strong>Reduced Data Leakage</strong>: this is the benefit I hear most from Cloud providers - and in my view they are right.  How many laptops do we need to lose before we get this?  How many backup tapes?  The data &#8220;landmines&#8221; of today could be greatly reduced by the Cloud as thin client technology becomes prevalent.  Small, temporary caches on handheld devices or Netbook computers pose less risk than transporting data buckets in the form of laptops.  Ask the CISO of any large company if all laptops have company &#8216;mandated&#8217; controls consistently applied; e.g. full disk encryption.  You&#8217;ll see the answer by looking at the whites of their eyes.  Despite best efforts around asset management and endpoint security we continue to see embarrassing and disturbing misses.  And what about SMBs?  How many use encryption for sensitive data, or even have a data classification policy in place?</li>
<li><strong>Monitoring benefits</strong>: central storage is easier to control and monitor.  The flipside is the nightmare scenario of <a href="http://www.gnucitizen.org/blog/most-attractive-targets-saas/">comprehensive data theft</a>.  However, I would rather spend my time as a security professional figuring out smart ways to protect and monitor access to data stored in one place (with the benefit of situational advantage) than trying to figure out all the places where the company data resides across a myriad of thick clients!  You can get the benefits of Thin Clients today but Cloud Storage provides a way to centralise the data faster and potentially cheaper.  The logistical challenge today is getting Terabytes of data to the Cloud in the first place.</li>
</ul>
<h4>2. Incident Response / Forensics</h4>
<ul>
<li><strong>Forensic readiness</strong>: with Infrastructure as a Service (IaaS) providers, I can build a dedicated forensic server in the same Cloud as my company and place it offline, ready for use when needed.  I would only need pay for storage until an incident happens and I need to bring it online.  I don&#8217;t need to call someone to bring it online or install some kind of remote boot software - I just click a button in the Cloud Providers web interface.  If I have multiple incident responders, I can give them a copy of the VM so we can distribute the forensic workload based on the job at hand or as new sources of evidence arise and need analysis.  To fully realise this benefit, commercial forensic software vendors would need to move away from archaic, physical dongle based licensing schemes to a network licensing model.</li>
<li><strong>Decrease evidence acquisition time</strong>: if a server in the Cloud gets compromised (i.e. broken into), I can now clone that server at the click of a mouse and make the cloned disks instantly available to my Cloud Forensics server.  I didn&#8217;t need to &#8220;find&#8221; storage or have it &#8220;ready, waiting and unused&#8221; - its just there.</li>
<li><strong>Eliminate or reduce service downtime</strong>: Note that in the above scenario I didn&#8217;t have to go tell the COO that the system needs to be taken offline for hours whilst I dig around in the RAID Array hoping that my physical acqusition toolkit is compatible (and that the version of RAID firmware isn&#8217;t supported by my forensic software).  Abstracting the hardware removes a barrier to even doing forensics in some situations.</li>
<li><strong>Decrease evidence transfer time</strong>: In the same Cloud, bit fot bit copies are super fast - made faster by that replicated, distributed filesystem my Cloud provider engineered for me.  From a network traffic perspective, it may even be free to make the copy in the same Cloud.  Without the Cloud, <strong>I </strong>would have to a lot of time consuming and expensive provisioning of physical devices.  I only pay for the storage as long as I need the evidence.</li>
<li><strong>Eliminate forensic image verification time</strong>: Some Cloud Storage implementations expose a cryptographic checksum or hash.  For example, Amazon S3 generates an MD5 hash <a href="http://docs.amazonwebservices.com/AmazonS3/2006-03-01/index.html?RESTObjectPUT.html">automagically</a> when you store an object.  In theory you no longer need to generate time-consuming MD5 checksums using external tools - its already there.</li>
<li><strong>Decrease time to access protected documents</strong>: Immense CPU power opens some doors.  Did the suspect password protect a document that is relevant to the investigation?  You can now test a wider range of candidate passwords in less time to speed investigations.</li>
</ul>
<h4>3. Password assurance testing (aka cracking)</h4>
<ul>
<li><strong>Decrease password cracking time</strong>: if your organisation regularly tests password strength by running password crackers you can use Cloud Compute to decrease crack time and you only pay for what you use.  Ironically, your cracking costs go up as people choose better passwords ;-).</li>
<li><strong>Keep cracking activities to dedicated machines</strong>: if today you use a distributed password cracker to spread the load across non-production machines, you can now put those agents in dedicated Compute instances - and thus stop mixing sensitive credentials with other workloads.</li>
</ul>
<h4>4. Logging</h4>
<ul>
<li><strong>&#8220;Unlimited&#8221;, pay per drink storage</strong>: logging is often an afterthought, consequently insufficient disk space is allocated and logging is either non-existant or minimal.  Cloud Storage changes all this - no more &#8216;guessing&#8217; how much storage you need for standard logs.</li>
<li><strong>Improve log indexing and search</strong>: with your logs in the Cloud you can leverage Cloud Compute to index those logs in real-time and get the benefit of <a href="http://blogs.splunk.com/thewilde/2008/06/24/splunk-ninja-inside-the-cloud/">instant search results.</a> What is different here?  The Compute instances can be plumbed in and scale as needed based on the logging load - meaning a true real-time view.</li>
<li><strong>Getting compliant with Extended logging</strong>: most modern operating systems offer extended logging in the form of a C2 audit trail.  This is rarely enabled for fear of performance degradation and log size.  Now you can &#8216;opt-in&#8217; easily - if you are willing to pay for the enhanced logging, you can do so.  Granular logging makes compliance and investigations easier.</li>
</ul>
<h4>5. Improve the state of security software (performance)</h4>
<ul>
<li><strong>Drive vendors to create more efficient security software</strong>: Billable CPU cycles get noticed.  More attention will be paid to inefficient processes; e.g. poorly tuned security agents.  Process accounting will make a comeback as customers target &#8216;expensive&#8217; processes.  Security vendors that understand how to squeeze the most performance from their software will win.</li>
</ul>
<h4>6. Secure builds</h4>
<ul>
<li><strong>Pre-hardened, change control builds</strong>: this is primarily a benefit of virtualization based Cloud Computing.  Now you get a chance to start &#8217;secure&#8217; (by your own definition) - you create your Gold Image VM and clone away.  There are ways to do this today with bare-metal OS installs but frequently these require additional 3rd party tools, are time consuming to clone or add yet another agent to each endpoint.</li>
<li><strong>Reduce exposure through patching offline</strong>: Gold images can be kept up securely kept up to date.  Offline VMs can be conveniently patched &#8220;off&#8221; the network.</li>
<li><strong>Easier to test impact of security changes</strong>: this is a big one.  Spin up a copy of your production environment, implement a security change and test the impact at low cost, with minimal startup time.  This is a big deal and removes a major barrier to &#8216;doing&#8217; security in production environments.</li>
</ul>
<h4>7. Security Testing</h4>
<ul>
<li><strong>Reduce cost of testing security: </strong>a SaaS provider only passes on a portion of their security testing costs.  By sharing the same application as a service, you don&#8217;t foot the expensive security code review and/or penetration test.  Even with Platform as a Service (PaaS) where your developers get to write code, there are potential cost economies of scale (particularly around use of code scanning tools that sweep source code for security weaknesses).</li>
</ul>
<h4>Your Thoughts?</h4>
<p>What benefits do you see that I haven&#8217;t included in the above list?  Where do you agree/disagree and importantly, why?</p>
<img src="http://feeds.feedburner.com/~r/CloudSecurity/~4/341289594" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 03:00:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/benefits">benefits</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/technical security benefits">technical security benefits</category>
      <category domain="http://securityratty.com/tag/based">based</category>
      <category domain="http://securityratty.com/tag/virtualization based cloud">virtualization based cloud</category>
      <category domain="http://securityratty.com/tag/efficient security software">efficient security software</category>
      <category domain="http://securityratty.com/tag/security software">security software</category>
      <category domain="http://securityratty.com/tag/cloud market">cloud market</category>
      <source url="http://feeds.feedburner.com/~r/CloudSecurity/~3/341289594/">Assessing the Security Benefits of Cloud Computing</source>
    </item>
    <item>
      <title><![CDATA[CBAC & Medical Identity Theft]]></title>
      <link>http://securityratty.com/article/02105d066a63c57c66a00f92ef63e99d</link>
      <guid>http://securityratty.com/article/02105d066a63c57c66a00f92ef63e99d</guid>
      <description><![CDATA[Good story to keep in mind for those of you working on CBAC. Claims neeed protection and verification. Why steal an identity when you can capture a claim? (hattip: askelizabeth
The Sopranokovs
The...]]></description>
      <content:encoded><![CDATA[<p>Good story to keep in mind for those of you working on CBAC. Claims neeed protection and verification. Why steal an identity when you can capture a claim? (hattip: <a href="http://askelizabeth.typepad.com/weblog/2008/07/medical-identity-theft-the-new-frontier-for-organized-crime.html">askelizabeth</a>)

</p><blockquote><p>
	The Sopranokovs 
	</p></blockquote><blockquote><p>The Russian mob comes to town with a new scam—medical identity theft. 	
	</p></blockquote><blockquote><p>When FBI special agent Ted Price peered through the window of a dingy brick storefront on Southwest Morrison Street in March, it was what he didn’t see that caught his attention. 	</p></blockquote><blockquote><p>The business, called UnimedCorner, claimed to provide ailing seniors with orthotics—braces and other devices to correct foot, joint and back problems. 	
	</p></blockquote><blockquote><p>Price and other federal investigators were skeptical. 	
	</p></blockquote><blockquote><p>On Unimed’s showroom floor, Price saw wheelchairs, motorized scooters, a variety of canes and, on the walls, a selection of amateurish paintings and framed photographs. There was no evidence, however, of the kinds of equipment for which Unimed had billed Medicare nearly $2 million in the previous couple of months. 	
	</p></blockquote><blockquote><p>“I observed wheelchairs and canes through the window but did not see any orthotics in the store,” Price later wrote in a search-warrant affidavit. “It is a sign of fraud that the store is not stocking the items [for which] it is billing.” 	
	</p></blockquote><blockquote><p>By the time Price arrived on the scene, the company’s owner, a shadowy Russian immigrant named Alexandr Shcherbakov, was long gone. 	
	</p></blockquote><blockquote><p>Today, Shcherbakov’s store sits undisturbed. The message light on the phone blinks, dead potted plants droop and a stuffed toy monkey slumps in a glass display case. 	
	</p></blockquote><blockquote><p>And behind the cash register hangs a framed poster of television’s best-known mobsters, the Sopranos. 	
	</p></blockquote><blockquote><p>From interviews and information presented in federal affidavits, it is clear Shcherbakov moved to Oregon to commit a crime elegant and lucrative enough to make Tony Soprano envious: medical identity theft. 	
	</p></blockquote><blockquote><p>... 	
	</p></blockquote><blockquote><p>“Medical identity theft is the new frontier for organized crime,” says Alex Johnson, a former FBI agent who investigates fraud for Regence BlueShield. “Pretty much anybody can set up a mom-and-pop operation and start cranking out claims.”
	
	Someday, most Americans will need a cane, wheelchair, home hospital bed or another of the items healthcare professionals call “durable medical equipment,” or DME. 	
	</p></blockquote><blockquote><p>For those over 64 and without private insurance, there’s a good chance federally funded Medicare will pick up the tab for that equipment. Last year, according to federal statistics, Medicare spent $8.6 billion on DME. 	
	</p></blockquote><blockquote><p>Here’s the way the system is supposed to work: A doctor prescribes a device such as a wheelchair for a patient, who presents his prescription to a DME supplier. The supplier provides the equipment and bills Medicare, which typically pays 80 percent of the cost.
	
	Unlike pharmacists, who fill prescriptions under strict scrutiny of state and federal watchdogs, DME suppliers are lightly regulated.
	
	“DME is very vulnerable to fraud,” says Consuelo Woodhead, the chief healthcare fraud prosecutor for the U.S. Attorney’s Office in Los Angeles. “It doesn’t require any background in medicine, any kind of professional licensure or appreciable capital. </p></blockquote><blockquote><p>There are barriers of entry in other medical fields, but not in DME.”
	
	To operate, DME suppliers simply need a place of business, a business license and liability insurance. Unlike pharmacists, DME suppliers operate under an honor system: The feds count on them to supply the equipment they claim to provide to the beneficiaries who need it. 	
	</p></blockquote><blockquote><p>That honor system is not working. 	
	</p></blockquote><blockquote><p>The epicenter of DME fraud, according to the federal Department of Health and Human Services, is South Florida, where Medicare billing for DME quadrupled from 2002 to 2006 to $1.7 billion.
	
	Investigators found much of that increase was due to fraud. In 2006, federal inspectors revoked the licenses of 634 DME suppliers in South Florida, nearly half the DME dealers in the region. </p></blockquote><blockquote><p>Later the same year, raids in Southern California yielded similar results: The feds shut down 95 DME suppliers.
	
	Many of the DME suppliers shut down around Los Angeles were run by immigrants from the former Soviet Union. It’s probably no coincidence that when the feds raided Los Angeles DME suppliers, some Angelenos fled to cities where there was less scrutiny—such as Portland.</p></blockquote>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 06:09:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dme suppliers simply">dme suppliers simply</category>
      <category domain="http://securityratty.com/tag/dme suppliers">dme suppliers</category>
      <category domain="http://securityratty.com/tag/dme fraud">dme fraud</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/dme">dme</category>
      <category domain="http://securityratty.com/tag/identity">identity</category>
      <category domain="http://securityratty.com/tag/medical identity theft">medical identity theft</category>
      <category domain="http://securityratty.com/tag/dme dealers">dme dealers</category>
      <category domain="http://securityratty.com/tag/dme supplier">dme supplier</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/cbac-medical-identity-theft.html">CBAC &amp; Medical Identity Theft</source>
    </item>
    <item>
      <title><![CDATA[Mission Statement for Federation]]></title>
      <link>http://securityratty.com/article/9794bcabb05d5a9a4ad01ef54236e5df</link>
      <guid>http://securityratty.com/article/9794bcabb05d5a9a4ad01ef54236e5df</guid>
      <description><![CDATA[Bruce Sterling (11/20/2001
You know what I want? I don't want a National ID Card. I want a Global Coalition Visa



Like it or not, we've got a huge global diaspora now. It is a fact of life. Nations...]]></description>
      <content:encoded><![CDATA[<p><span style="font-family: &#39;times new roman&#39;; font-size: 16px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "></span></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "><a href="http://www.viridiandesign.org/notes/251-300/00283_geeks_and_spooks.html">Bruce Sterling</a> (11/20/2001):</p><blockquote><p>You know what I want? I don&#39;t want a National ID Card. I want a Global Coalition Visa.</p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>Like it or not, we&#39;ve got a huge global diaspora now. It is a fact of life. Nations with stupid and corrupt politics have seen their clever people brain- drained away, to places where the cops don&#39;t shake you down twice a day. And jet-setters go everywhere. And properly so. If you&#39;re in a true global society, then you spend a lot of your time among aliens. Quite often you are the alien. You might notice that even Al Qaeda is a genuinely multinational group. They gravitated to wicked, lawless places like Sudan, Chechnya and Afghanistan, where the locals shoot you if you ask for a badge.</p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>But what about all us bright, shiny, world-trading jet setters, huh? There are thirty percent fewer Yankees in Europe this Christmas, and that is bad. Let me pose the problem this way. If I am going into a Japanese restaurant in Japan, I would rather like to be able to haul out some gizmo and flash it at my fellow civilians, and have these kindly people understand with a high degree of likelihood that I am not a mass murderer. On the contrary, I am quite civilized, and I should be brought a beer immediately.</p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>A platinum VISA card and a five-hundred-dollar suit will almost do that, but those are too easy to forge and steal, plus they are not very democratic. The UN should get together on this. We should have a high level summit about digital hardware support for the crippled tourist economy. Fear and ill treatment shut down tourism faster than anything short of open warfare. That is bad for all of us. Killing off tourism harms our civilization and impoverishes our cultures. People in civilized states shouldn&#39;t routinely treat one another as criminal suspects. I don&#39;t want to get done-over for three hours every time I get off a plane in London. When I go to London, I go with empty suitcases. I don&#39;t plan to stay, but I am better news for the London economy than a lot of the people who live there.</p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>They should know all that that&#0160;<span style="font-weight: bold; ">before<span style="font-weight: normal; ">&#0160;I get off the plane. My arrival is excellent news for Britain, so I should be treated that way. If this is a new kind of war, I don&#39;t want to be the evil guy hunkered down in the bunker; I want to fly with the boys from Air Assault. I want one of those handy crypto-style Friend-or-Foe IDs.</span></span></p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>These people who normally meet me whenever I am an alien, they don&#39;t need to know my nationality, my home address or my shoe size. They just need to know that, despite being alien, I&#39;m sort-of okay.</p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>I want a democratic, citizen-to-citizen device that will bridge those social barriers and language barriers. I think we could invent devices and means of verification that would strengthen the global social fabric that terrorism wants to rip. It wouldn&#39;t be easy or simple, but it&#39;s not beyond our ingenuity. Our social capital sustains all civilized societies, and it is all about trust. <span style="font-weight: bold;">So let&#39;s invent new methods of trust.</span></p></blockquote><p>I added bold to the last sentence because I think this is the mission statement for building out federation systems.</p><p></p><p></p>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 06:35:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/clever people brain-">clever people brain-</category>
      <category domain="http://securityratty.com/tag/kindly people">kindly people</category>
      <category domain="http://securityratty.com/tag/platinum visa card">platinum visa card</category>
      <category domain="http://securityratty.com/tag/london">london</category>
      <category domain="http://securityratty.com/tag/mission statement">mission statement</category>
      <category domain="http://securityratty.com/tag/london economy">london economy</category>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/true global society">true global society</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/06/mission-statement-for-federation.html">Mission Statement for Federation</source>
    </item>
    <item>
      <title><![CDATA[Conmen Abuse Web Address Checks]]></title>
      <link>http://securityratty.com/article/b160523f9dd3bf229a3d1348a36e06d3</link>
      <guid>http://securityratty.com/article/b160523f9dd3bf229a3d1348a36e06d3</guid>
      <description><![CDATA[From the BBC
Loopholes in the way addresses are checked by online stores are helping fraudsters cash in, say experts
The flaw means goods bought with stolen credit cards do not trigger security...]]></description>
      <content:encoded><![CDATA[<p>From the BBC:</p>
<blockquote><p>Loopholes in the way addresses are checked by online stores are helping fraudsters cash in, say experts.</p>
<p>The flaw means goods bought with stolen credit cards do not trigger security systems that check addresses.</p>
<p>Security firm The Third Man said it stumbled over fraudsters committing the crime while overseeing transactions on a retail website.</p>
<p>But the UK&#8217;s payments association said it had seen no evidence that the novel crime was being carried out. </p>
<p>&#8220;It&#8217;s pure chance that we picked this up,&#8221; said Andrew Goodwill, director of anti-fraud firm The Third Man.</p>
<p>The scam exploits the mechanics of the Address Verification System (AVS) that many retail sites use to check the address of those using a credit card at an online store. </p></blockquote>
<p>It is really funny how often organizations refuse to accept that an attack has happened/is happening. I was onsite in the US conducting an assessment for a company quite a few years ago and I pointed out that their system had been breached. The executive looked me square in the eye and said, &#8220;no it hasn&#8217;t&#8221;. If he was trying to intimidate me he missed the mark. If he was refusing to accept the reality that is another problem entirely.</p>
<p><a href="http://news.bbc.co.uk/2/hi/technology/7448187.stm">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=TgRya5"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=TgRya5" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=NJMYJI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=NJMYJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=N1oUFi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=N1oUFi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=FA4gYi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=FA4gYi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=xjB4Vi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=xjB4Vi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=BKNU5i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=BKNU5i" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/310407929" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 09:42:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/address">address</category>
      <category domain="http://securityratty.com/tag/address verification system">address verification system</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/check addresses">check addresses</category>
      <category domain="http://securityratty.com/tag/addresses">addresses</category>
      <category domain="http://securityratty.com/tag/fraudsters">fraudsters</category>
      <category domain="http://securityratty.com/tag/fraudsters cash">fraudsters cash</category>
      <category domain="http://securityratty.com/tag/trigger security systems">trigger security systems</category>
      <category domain="http://securityratty.com/tag/check">check</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/310407929/">Conmen Abuse Web Address Checks</source>
    </item>
    <item>
      <title><![CDATA[Fax Signatures]]></title>
      <link>http://securityratty.com/article/02253ed921c243d2881b5f9b92f99712</link>
      <guid>http://securityratty.com/article/02253ed921c243d2881b5f9b92f99712</guid>
      <description><![CDATA[Aren't fax signatures the weirdest thing? It's trivial to cut and paste -- with real scissors and glue -- anyone's signature onto a document so that it'll look real when faxed. There is so little...]]></description>
      <content:encoded><![CDATA[<p>Aren't fax signatures the weirdest thing? It's trivial to cut and paste -- with real scissors and glue -- anyone's signature onto a document so that it'll look real when faxed.  There is so little security in fax signatures that it's mind-boggling that anyone accepts them.</p>

<p>Yet people do, all the time. I've signed book contracts, credit card authorizations, nondisclosure agreements and all sorts of financial documents -- all by fax. I even have a scanned file of my signature on my computer, so I can virtually cut and paste it into documents and fax them directly from my computer without ever having to print them out.  What in the world is going on here?</p>

<p>And, more importantly, why are fax signatures still being used after years of experience?  Why aren't there many stories of signatures forged through the use of fax machines?</p>

<p>The answer comes from looking at fax signatures not as an isolated security measure, but in the context of the larger system. Fax signatures work because signed faxes exist within a broader communications context.</p>

<p>In a 2003 paper, <a href="http://www.dtc.umn.edu/~odlyzko/doc/econ.psych.security.pdf">"Economics, Psychology, and Sociology of Security,"</a> Professor Andrew Odlyzko looks at fax signatures and concludes:</p>

<blockquote>Although fax signatures have become widespread, their usage is restricted. They are not used for final contracts of substantial value, such as home purchases. That means that the insecurity of fax communications is not easy to exploit for large gain. Additional protection against abuse of fax insecurity is provided by the context in which faxes are used. There are records of phone calls that carry the faxes, paper trails inside enterprises and so on.  Furthermore, unexpected large financial transfers trigger scrutiny. As a result, successful frauds are not easy to carry out by purely technical means.</blockquote>

<p>He's right. Thinking back, there really aren't ways in which a criminal could use a forged document sent by fax to defraud me. I suppose an unscrupulous consulting client could forge my signature on an non-disclosure agreement and then sue me, but that hardly seems worth the effort. And if my broker received a fax document from me authorizing a money transfer to a Nigerian bank account, he would certainly call me before completing it.</p>

<p>Credit card signatures aren't verified in person, either -- and I can already buy things over the phone with a credit card -- so there are no new risks there, and Visa knows how to monitor transactions for fraud. Lots of companies accept purchase orders via fax, even for large amounts of stuff, but there's a physical audit trail, and the goods are shipped to a physical address -- probably one the seller has shipped to before. Signatures are kind of a business lubricant: mostly, they help move things along smoothly.</p>

<p>Except when they don't.</p>

<p>On October 30, 2004, Tristian Wilson was <a href="http://www.theeveningtimes.com/articles/2004/11/04/news/news5.txt">released</a> from a Memphis jail on the authority of a forged fax message. It wasn't even a particularly good forgery. It wasn't on the standard letterhead of the West Memphis Police Department. The name of the policeman who signed the fax was misspelled. And the time stamp on the top of the fax clearly showed that it was sent from a local McDonald's.</p>

<p>The success of this hack has nothing to do with the fact that it was sent over by fax. It worked because the jail had lousy verification procedures. They didn't notice any discrepancies in the fax. They didn't notice the phone number from which the fax was sent. They didn't call and verify that it was official. The jail was accustomed to getting release orders via fax, and just acted on this one without thinking. Would it have been any different had the forged release form been sent by mail or courier?</p>

<p>Yes, fax signatures always exist in context, but sometimes they are the linchpin within that context. If you can mimic enough of the context, or if those on the receiving end become complacent, you can get away with mischief.</p>

<p>Arguably, this is part of the security process. Signatures themselves are poorly defined.  Sometimes a document is valid even if not signed: A person with both hands in a cast can still buy a house. Sometimes a document is invalid even if signed: The signer might be drunk, or have a gun pointed at his head. Or he might be a minor. Sometimes a valid signature isn't enough; in the United States there is an entire infrastructure of "notary publics" who officially witness signed documents. When I started filing my tax returns electronically, I had to sign a document stating that I wouldn't be signing my income tax documents. And banks don't even bother verifying signatures on checks less than $30,000; it's cheaper to deal with fraud after the fact than prevent it.</p>

<p>Over the course of centuries, business and legal systems have slowly sorted out what types of additional controls are required around signatures, and in which circumstances.</p>

<p>Those same systems will be able to sort out fax signatures, too, but it'll be slow. And that's where there will be potential problems. Already fax is a declining technology. In a few years it'll be largely obsolete, replaced by PDFs sent over e-mail and other forms of electronic documentation. In the past, we've had time to figure out how to deal with new technologies. Now, by the time we institutionalize these measures, the technologies are likely to be obsolete.</p>

<p>What that means is people are likely to treat fax signatures -- or whatever replaces them -- exactly the same way as paper signatures. And sometimes that assumption will get them into trouble.</p>

<p>But it won't cause social havoc. Wilson's story is remarkable mostly because it's so exceptional. And even he was rearrested at his home less than a week later. Fax signatures may be new, but fake signatures have always been a possibility.  Our legal and business systems need to deal with the underlying problem -- false authentication -- rather than focus on the technology of the moment. Systems need to defend themselves against the possibility of fake signatures, regardless of how they arrive.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/05/securitymatters_0529">previously appeared</a> on Wired.com.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=AcrMPI"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=AcrMPI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=cTPMJI"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=cTPMJI" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 03 Jun 2008 03:01:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fax">fax</category>
      <category domain="http://securityratty.com/tag/fax signatures">fax signatures</category>
      <category domain="http://securityratty.com/tag/fax communications">fax communications</category>
      <category domain="http://securityratty.com/tag/fax insecurity">fax insecurity</category>
      <category domain="http://securityratty.com/tag/insecurity">insecurity</category>
      <category domain="http://securityratty.com/tag/fax machines">fax machines</category>
      <category domain="http://securityratty.com/tag/fax message">fax message</category>
      <category domain="http://securityratty.com/tag/treat fax signatures">treat fax signatures</category>
      <category domain="http://securityratty.com/tag/fax document">fax document</category>
      <source url="http://www.schneier.com/blog/archives/2008/06/fax_signatures.html">Fax Signatures</source>
    </item>
    <item>
      <title><![CDATA[Fax Signatures]]></title>
      <link>http://securityratty.com/article/7f8f07462740c577743663da07c14ae3</link>
      <guid>http://securityratty.com/article/7f8f07462740c577743663da07c14ae3</guid>
      <description><![CDATA[Aren't fax signatures the weirdest thing? It's trivial to cut and paste -- with real scissors and glue -- anyone's signature onto a document so that it'll look real when faxed. There is so little...]]></description>
      <content:encoded><![CDATA[<p>Aren't fax signatures the weirdest thing? It's trivial to cut and paste -- with real scissors and glue -- anyone's signature onto a document so that it'll look real when faxed.  There is so little security in fax signatures that it's mind-boggling that anyone accepts them.</p>

<p>Yet people do, all the time. I've signed book contracts, credit card authorizations, nondisclosure agreements and all sorts of financial documents -- all by fax. I even have a scanned file of my signature on my computer, so I can virtually cut and paste it into documents and fax them directly from my computer without ever having to print them out.  What in the world is going on here?</p>

<p>And, more importantly, why are fax signatures still being used after years of experience?  Why aren't there many stories of signatures forged through the use of fax machines?</p>

<p>The answer comes from looking at fax signatures not as an isolated security measure, but in the context of the larger system. Fax signatures work because signed faxes exist within a broader communications context.</p>

<p>In a 2003 paper, <a href="http://www.dtc.umn.edu/~odlyzko/doc/econ.psych.security.pdf">"Economics, Psychology, and Sociology of Security,"</a> Professor Andrew Odlyzko looks at fax signatures and concludes:</p>

<blockquote>Although fax signatures have become widespread, their usage is restricted. They are not used for final contracts of substantial value, such as home purchases. That means that the insecurity of fax communications is not easy to exploit for large gain. Additional protection against abuse of fax insecurity is provided by the context in which faxes are used. There are records of phone calls that carry the faxes, paper trails inside enterprises and so on.  Furthermore, unexpected large financial transfers trigger scrutiny. As a result, successful frauds are not easy to carry out by purely technical means.</blockquote>

<p>He's right. Thinking back, there really aren't ways in which a criminal could use a forged document sent by fax to defraud me. I suppose an unscrupulous consulting client could forge my signature on an non-disclosure agreement and then sue me, but that hardly seems worth the effort. And if my broker received a fax document from me authorizing a money transfer to a Nigerian bank account, he would certainly call me before completing it.</p>

<p>Credit card signatures aren't verified in person, either -- and I can already buy things over the phone with a credit card -- so there are no new risks there, and Visa knows how to monitor transactions for fraud. Lots of companies accept purchase orders via fax, even for large amounts of stuff, but there's a physical audit trail, and the goods are shipped to a physical address -- probably one the seller has shipped to before. Signatures are kind of a business lubricant: mostly, they help move things along smoothly.</p>

<p>Except when they don't.</p>

<p>On October 30, 2004, Tristian Wilson was <a href="http://www.theeveningtimes.com/articles/2004/11/04/news/news5.txt">released</a> from a Memphis jail on the authority of a forged fax message. It wasn't even a particularly good forgery. It wasn't on the standard letterhead of the West Memphis Police Department. The name of the policeman who signed the fax was misspelled. And the time stamp on the top of the fax clearly showed that it was sent from a local McDonald's.</p>

<p>The success of this hack has nothing to do with the fact that it was sent over by fax. It worked because the jail had lousy verification procedures. They didn't notice any discrepancies in the fax. They didn't notice the phone number from which the fax was sent. They didn't call and verify that it was official. The jail was accustomed to getting release orders via fax, and just acted on this one without thinking. Would it have been any different had the forged release form been sent by mail or courier?</p>

<p>Yes, fax signatures always exist in context, but sometimes they are the linchpin within that context. If you can mimic enough of the context, or if those on the receiving end become complacent, you can get away with mischief.</p>

<p>Arguably, this is part of the security process. Signatures themselves are poorly defined.  Sometimes a document is valid even if not signed: A person with both hands in a cast can still buy a house. Sometimes a document is invalid even if signed: The signer might be drunk, or have a gun pointed at his head. Or he might be a minor. Sometimes a valid signature isn't enough; in the United States there is an entire infrastructure of "notary publics" who officially witness signed documents. When I started filing my tax returns electronically, I had to sign a document stating that I wouldn't be signing my income tax documents. And banks don't even bother verifying signatures on checks less than $30,000; it's cheaper to deal with fraud after the fact than prevent it.</p>

<p>Over the course of centuries, business and legal systems have slowly sorted out what types of additional controls are required around signatures, and in which circumstances.</p>

<p>Those same systems will be able to sort out fax signatures, too, but it'll be slow. And that's where there will be potential problems. Already fax is a declining technology. In a few years it'll be largely obsolete, replaced by PDFs sent over e-mail and other forms of electronic documentation. In the past, we've had time to figure out how to deal with new technologies. Now, by the time we institutionalize these measures, the technologies are likely to be obsolete.</p>

<p>What that means is people are likely to treat fax signatures -- or whatever replaces them -- exactly the same way as paper signatures. And sometimes that assumption will get them into trouble.</p>

<p>But it won't cause social havoc. Wilson's story is remarkable mostly because it's so exceptional. And even he was rearrested at his home less than a week later. Fax signatures may be new, but fake signatures have always been a possibility.  Our legal and business systems need to deal with the underlying problem -- false authentication -- rather than focus on the technology of the moment. Systems need to defend themselves against the possibility of fake signatures, regardless of how they arrive.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/05/securitymatters_0529">previously appeared</a> on Wired.com.</p>

<p>EDITED TO ADD (6/3): 2005 story, "<a href="http://www.law.com/jsp/article.jsp?id=1124960718229">Federal Jury Convicts N.Y. Attorney of Faking Judge's Order</a>."</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Cp1KKI"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Cp1KKI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=vxhJ2I"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=vxhJ2I" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 03 Jun 2008 03:01:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fax">fax</category>
      <category domain="http://securityratty.com/tag/fax signatures">fax signatures</category>
      <category domain="http://securityratty.com/tag/fax communications">fax communications</category>
      <category domain="http://securityratty.com/tag/fax insecurity">fax insecurity</category>
      <category domain="http://securityratty.com/tag/insecurity">insecurity</category>
      <category domain="http://securityratty.com/tag/fax machines">fax machines</category>
      <category domain="http://securityratty.com/tag/fax message">fax message</category>
      <category domain="http://securityratty.com/tag/treat fax signatures">treat fax signatures</category>
      <category domain="http://securityratty.com/tag/fax document">fax document</category>
      <source url="http://www.schneier.com/blog/archives/2008/06/fax_signatures_1.html">Fax Signatures</source>
    </item>
  </channel>
</rss>
