<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: victims]]></title>
    <link>http://securityratty.com/tag/victims</link>
    <description></description>
    <pubDate>Thu, 31 Jul 2008 07:57:54 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Best Western Hotel Online Booking Breached, 8 Million Victims In Personal Data Theft]]></title>
      <link>http://securityratty.com/article/1e268670aae5d79f21ac2627114fd3b4</link>
      <guid>http://securityratty.com/article/1e268670aae5d79f21ac2627114fd3b4</guid>
      <description><![CDATA[Criminal gang has stolen the identities of an estimated eight million people in a hacking raid that could ultimately net more than 2.8billion in illegal funds. Thursday night, an unknown hacker,...]]></description>
      <content:encoded><![CDATA[Criminal gang has stolen the identities of an estimated eight million people in a hacking raid that could ultimately net more than £2.8billion in illegal funds. Thursday night, an unknown hacker, possibly indian, successfully breached the IT defences of the Best Western Hotel group&#8217;s online booking system and sold details of how to access it [...]]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 09:57:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/western hotel">western hotel</category>
      <category domain="http://securityratty.com/tag/unknown hacker">unknown hacker</category>
      <category domain="http://securityratty.com/tag/possibly indian">possibly indian</category>
      <category domain="http://securityratty.com/tag/thursday night">thursday night</category>
      <category domain="http://securityratty.com/tag/million people">million people</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/ultimately net">ultimately net</category>
      <category domain="http://securityratty.com/tag/criminal gang">criminal gang</category>
      <category domain="http://securityratty.com/tag/illegal funds">illegal funds</category>
      <source url="http://cyberinsecure.com/best-western-hotel-online-booking-breached-8-million-victims-in-personal-data-theft/">Best Western Hotel Online Booking Breached, 8 Million Victims In Personal Data Theft</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Four]]></title>
      <link>http://securityratty.com/article/89e92ac703db317a9f2d0ad0ae004a56</link>
      <guid>http://securityratty.com/article/89e92ac703db317a9f2d0ad0ae004a56</guid>
      <description><![CDATA[Thanks to the affiliate based business model that's driving the increase of fake security software and rogue codecs serving domains, the very same templates, but with different domain names, continue...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLKFy9dsYiI/AAAAAAAACHE/DiRDPArpb4A/s1600-h/fake_security_software_august.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLKFy9dsYiI/AAAAAAAACHE/jlXrnI7ApPo/s200-R/fake_security_software_august.JPG" /></a>Thanks to the affiliate based business model that's driving the increase of fake security software and rogue codecs serving domains, the very same templates, but with different domain names, continue appearing in blackhat SEO, spam, and malicious doorways redirection campaigns.<br />
<br />
Moreover, with the "time-to-market" of a fake security software decreasing due to the efficiency approach introduced in the form of tips for abuse-free hosting services provided by the "known suspects", and the freely available templates, we're slowly starting to see the upcoming peak of this approach. <br />
<br />
In a true proactive spirit, the domains parked at 216.195.56.88 are all upcoming fake security software, to be introduced anytime soon.<br />
<br />
<b>fast-pc-scanner-online .com</b> - (92.62.101.41; 91.203.92.48; 91.203.92.106; 58.65.238.171)<br />
<b>top-pc-scanner .com<br />
buy-secure-protection .com<br />
security-scan-pc .com<br />
pc-scanner-online .com<br />
viruses-scanonline .com<br />
virus-scanonline .com<br />
antivirus-scanonline .com<br />
topvirusscan .com<br />
virusbestscan .com<br />
best-security-protection .com<br />
infectionscanner .com<br />
virusbestscanner .com<br />
full-protection-now .com</b><br />
<br />
<b>Pwrantivirus .com</b> - 91.208.0.246<br />
<b>vav-x-scanner .com<br />
vav-scanner .com<br />
scanner.vavscan .com<br />
malware-scan .com<br />
Scanner-Pwrantivirus .com<br />
Xpertantivirus .com<br />
Scanner-xpertantivirus .com</b><br />
<br />
<b>spyware-quickscan-2008 .com</b> - (216.195.56.88)<br />
<b>virus-quickscan-2008 .com<br />
spyware-quickscan-2009 .com<br />
virus-quickscan-2009 .com<br />
winmalwarecontrol .com<br />
antispyware-quick-scan .com<br />
virus-quick-scan .com<br />
antivirus-quick-scan .com<br />
winprivacytool .com</b><br />
<br />
<b>topantispyware2008 .com</b> - (216.195.56.86)<br />
<b>cleanermaster .com</b> - (216.195.56.85)<br />
<b>antivirus777 .com</b> - (67.228.120.3)<br />
<b>pcsecuritynotice .com </b>- (67.228.120.3)<br />
<br />
Whereas the average Internet users are falling victims into this type of fraud, what I'm more concerned about is the large traffic the malicious domains receive in general due to all the different traffic acquisition tactics the people behind them apply. This anticipated traffic can then be greatly used as valuable metrics for the many other malicious ways in which it can be monetized.<br />
<br />
Ironically, the participant in the affiliate program whose original objective was to drive traffic to the fake security software's site, may in fact start receiving so much traffic due to the combination of traffic acquisition tactics, that <a href="http://ddanchev.blogspot.com/2008/02/serving-malware-through-advertising.html">introducing client-side exploits courtesy of a third-party affiliate network</a>, may in fact prove more profitable then the revenue sharing partnership with the rogue security software's vendor at the first place.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse Portfolio of Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">Got Your XPShield Up and Running?</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/fake-pestpatrol-security-software.html">Fake PestPatrol Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">Geolocating Malicious ISPs</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">The Malicious ISPs You Rarely See in Any Report</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=T4pWXK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=T4pWXK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fUdxLK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fUdxLK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wfXZZk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wfXZZk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DNdBTk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DNdBTk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=A69ooK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=A69ooK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kvp7rK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kvp7rK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PdsGMk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PdsGMk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/374177616" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 01:58:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/traffic">traffic</category>
      <category domain="http://securityratty.com/tag/drive traffic">drive traffic</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/traffic acquisition tactics">traffic acquisition tactics</category>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <category domain="http://securityratty.com/tag/malicious isps">malicious isps</category>
      <category domain="http://securityratty.com/tag/due">due</category>
      <category domain="http://securityratty.com/tag/traffic due">traffic due</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/374177616/diverse-portfolio-of-fake-security_25.html">A Diverse Portfolio of Fake Security Software - Part Four</source>
    </item>
    <item>
      <title><![CDATA[Spam Victims Wont Go to Rehab, No No No]]></title>
      <link>http://securityratty.com/article/b25a06e307c1aad4281d5182bdc4ef3f</link>
      <guid>http://securityratty.com/article/b25a06e307c1aad4281d5182bdc4ef3f</guid>
      <description><![CDATA[I was reading the Symantec State of Spam report for August and I thought this was funny and tragic email spam targeting alcoholics and other users, and advertising rehab services. Users click the link...]]></description>
      <content:encoded><![CDATA[<p>I was reading the Symantec State of Spam report for August and I thought this was funny and tragic&#8211; email spam targeting alcoholics and other users, and advertising rehab services. Users click the link allegedly for a rehab program, enter their personal information &#8212; and instead of getting help, they get scammed.</p>
<p>The report says:</p>
<blockquote><p>July 2008 saw the emergence of rehab spam. Subject lines have included</p>
<p>- Get help today with Drug Rehab Info<br />
- Overcome Alcoholism today<br />
Spammers are constantly trying new tactics to try and coerce recipients into opening a<br />
spam message so that they can obtain personal information from end users. In this particu-<br />
lar example, they are trying to target individuals who are not in good health, in the hopes<br />
that they will act on this spam message and give away their personal details.</p></blockquote>
<p>Read the full <a rel="nofollow" target="_blank" href="http://eval.symantec.com/mktginfo/enterprise/other_resources/b-state_of_spam_report_08-2008.en-us.pdf">August State of Spam</a> report here.</p>]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 06:10:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam report">spam report</category>
      <category domain="http://securityratty.com/tag/obtain personal information">obtain personal information</category>
      <category domain="http://securityratty.com/tag/report">report</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/spam message">spam message</category>
      <category domain="http://securityratty.com/tag/users click">users click</category>
      <category domain="http://securityratty.com/tag/tragic email spam">tragic email spam</category>
      <category domain="http://securityratty.com/tag/drug rehab info">drug rehab info</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/370169331/">Spam Victims Wont Go to Rehab, No No No</source>
    </item>
    <item>
      <title><![CDATA[Reputation Attacks: A Little Known Internet Threat]]></title>
      <link>http://securityratty.com/article/14e7534f22832db87db5d8489dea5b4a</link>
      <guid>http://securityratty.com/article/14e7534f22832db87db5d8489dea5b4a</guid>
      <description><![CDATA[Reputation attacks target both individuals and companies, and their goal is to ruin the victims reputation. While attack techniques are varied, the consequences are often the same: a damaged...]]></description>
      <content:encoded><![CDATA[Reputation attacks target both individuals and companies, and their goal is to ruin the victims reputation. While attack techniques are varied, the consequences are often the same: a damaged reputati...]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 08:02:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/reputation attacks target">reputation attacks target</category>
      <category domain="http://securityratty.com/tag/victims reputation">victims reputation</category>
      <category domain="http://securityratty.com/tag/attack techniques">attack techniques</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/individuals">individuals</category>
      <category domain="http://securityratty.com/tag/consequences">consequences</category>
      <category domain="http://securityratty.com/tag/goal">goal</category>
      <category domain="http://securityratty.com/tag/reputati">reputati</category>
      <category domain="http://securityratty.com/tag/ruin">ruin</category>
      <source url="http://www.net-security.org/article.php?id=1168">Reputation Attacks: A Little Known Internet Threat</source>
    </item>
    <item>
      <title><![CDATA[Digital Cash in Iraq]]></title>
      <link>http://securityratty.com/article/84493590b736c33ff0c22bfa1fc5590a</link>
      <guid>http://securityratty.com/article/84493590b736c33ff0c22bfa1fc5590a</guid>
      <description><![CDATA[Smart cards have still never quite taken off across the US, and at this point its fair to wonder if they will or if they will be eclipsed by phones or some such, but smart cards sure are big outside...]]></description>
      <content:encoded><![CDATA[<p>Smart cards have still never quite taken off across the US, and at this point its fair to wonder if they will or if they will be eclipsed by phones or some such, but smart cards sure are big outside the US. One of the most interesting applications is of course digital cash and transaction processing. <a href="http://www.aplitec.co.za/">Net1 UEPS</a>&#160;(ticker: <a href="http://finance.google.com/finance?q=ueps">UEPS</a>) out of South Africa appears to be the leader here having built a $1.2B business out of this model. there are lots of regions in the world where people are underbanked or unbanked altogether and where its dangerous to have too much cash. I blogged about this earlier on <a href="http://1raindrop.typepad.com/1_raindrop/2007/08/beer-shotguns-a.html">Beer, Shotguns and Digital Cash</a>.&#160;</p><br /><div>Now <a href="http://biz.yahoo.com/iw/080804/0421781.html">Net1 UEPS is in Iraq as well</a>:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">The first UEPS transaction was performed on Sunday, August 3, 2008, in Baghdad, Iraq, during the official launch of the UEPS smart card technology with the two state banks namely, Rafidain Bank and Rasheed Bank.</span></p></blockquote><div><span style="font-family: arial; line-height: normal;"><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">The official launch, attended by invitees from Rafidain Bank, Rasheed Bank, the Iraqi Government, War Victim Ministry and Martyrdom Ministry, demonstrated smart card registration, biometric enrolment and issuing of UEPS cards, offline loading of wage payments and government grants to the UEPS cards and dispensing of cash.</span><br /><span style="font-family: arial; line-height: normal; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">The pilot project involving 100,000 beneficiaries is now ready for implementation across selected bank branches and will enable the distribution and payment of government grants to war victims and martyrdom beneficiaries, as well as salary and wage distribution and payment to employees of the two state banks.</span><br /><span style="font-family: arial; line-height: normal; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">Brenda Stewart, Net1 Senior Vice President Sales and Marketing, said, &quot;From the entire team at Net1, we congratulate the Iraqi consortium on this historic achievement and look forward to the successful implementation of the various projects already identified for implementation, as well as the projects currently in business development. Net1 is proud that the development of its core technology, from which it creates end-user products that satisfy the requirements of its customers, can change the way business is conducted leading to the improvement of people&#39;s lives. We share the belief of our Iraqi partners that our technology can play a fundamental role in the upliftment of the economy. The success of any technology should be measured, not only by the profits it generates for its inventors, suppliers and users, but also by the difference that it makes to the lives of people,&quot; Stewart concluded.</span></p></blockquote><div><span style="font-family: arial; line-height: normal;"><p>I think there are lessons to be learned here wrt data and message level security. Net1 UEPS is a good example a of system carrying valuable assets across hostile terrain, web security architecture can learn a lot from this model.</p><p>P.S. If you are a <a href="http://en.wikipedia.org/wiki/Joel_Greenblatt">Joel Greenblatt</a> geek - UEPS is a <a href="http://www.magicformulainvesting.com/">magic formula stock</a>&#160;(meaning they make cash and are priced cheaply) last time I checked.</p><p></p></span></div>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 08:53:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ueps cards">ueps cards</category>
      <category domain="http://securityratty.com/tag/ueps">ueps</category>
      <category domain="http://securityratty.com/tag/digital cash">digital cash</category>
      <category domain="http://securityratty.com/tag/cash">cash</category>
      <category domain="http://securityratty.com/tag/net1 ueps">net1 ueps</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/net1">net1</category>
      <category domain="http://securityratty.com/tag/rafidain bank">rafidain bank</category>
      <category domain="http://securityratty.com/tag/ueps transaction">ueps transaction</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/digital-cash-in-iraq.html">Digital Cash in Iraq</source>
    </item>
    <item>
      <title><![CDATA[Beijing Olympics Lottery Phishers Verify Their Victims]]></title>
      <link>http://securityratty.com/article/28fe52f3c075902c10a853e9765300e5</link>
      <guid>http://securityratty.com/article/28fe52f3c075902c10a853e9765300e5</guid>
      <description><![CDATA[Websense has recently discovered another rogue Beijing Olympics website, this time for fake ticket lottery. The Web site uses the hostname that is a clear typo-squat to the official Olympic Games Web...]]></description>
      <content:encoded><![CDATA[Websense has recently discovered another rogue Beijing Olympics website, this time for fake ticket lottery.

The Web site uses the hostname that is a clear typo-squat to the official Olympic Games Web site at beijing2008.cn. Benefiting from the hype around the purchasing of tickets for the Games, the social engineering tactic behind this scam is to [...]]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 18:49:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake ticket lottery">fake ticket lottery</category>
      <category domain="http://securityratty.com/tag/olympics website">olympics website</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/websense">websense</category>
      <category domain="http://securityratty.com/tag/games">games</category>
      <category domain="http://securityratty.com/tag/hype">hype</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/hostname">hostname</category>
      <category domain="http://securityratty.com/tag/rogue">rogue</category>
      <source url="http://cyberinsecure.com/beijing-olympics-lottery-phishers-verify-their-victims/">Beijing Olympics Lottery Phishers Verify Their Victims</source>
    </item>
    <item>
      <title><![CDATA[Card Wars: The Phantom Menace]]></title>
      <link>http://securityratty.com/article/9d5b71fcb64161e1a88ba8844117af51</link>
      <guid>http://securityratty.com/article/9d5b71fcb64161e1a88ba8844117af51</guid>
      <description><![CDATA[Just like George Lucas cant help but return to his old projects , I have been returning to mine. After three years of stagnation, I am pleased to announce the re-launch of phantomwithdrawals.com ,...]]></description>
      <content:encoded><![CDATA[<p>Just like George Lucas can&#8217;t help but <a href="http://www.cinematical.com/2005/05/25/lucas-idea-for-new-star-wars-prequel/">return to his old projects</a>, I have been returning to mine. After three years of stagnation, I am pleased to announce the re-launch of <a href="http://www.phantomwithdrawals.com">phantomwithdrawals.com</a>, freshly re-vamped, updated and turned into a Wiki editable by the general public.</p>
<p>In fact, it&#8217;s not just great artists like Mr. Lucas and I starting up old projects, our honourable colleagues wearing the black hats have got the same idea. We have new victims reporting in, <a href="http://www.newsvine.com/_news/2008/07/01/1629600-citibank-atm-breach-reveals-pin-security-problems">rumours</a>&nbsp;<a href="http://blog.wired.com/27bstroke6/2008/06/citibank-issues.html">abound</a> of an auth system compromise at Citi, the Ombudsman is backlogged with months of disputed withdrawal cases, and some like <a href="http://www.guardian.co.uk/technology/2008/jan/03/hitechcrime.news">Alain Job</a> are even going to court.</p>
<p>One original contributor to the phantom case histories has just been hit by a second phantom withdrawal five years on and is chalking up another case in the files. While her new phantom is a bread-and-butter skim incident (a magstripe clone used in the far east), amongst this mass, true phantoms &#8212; the real mystery cases &#8212; are on the rise too. Two new victims with whom I have been corresponding very kindly offered to fund the hosting for the revamped site.</p>
<p>Let&#8217;s consider one of these mysteries. The McGaughey case has been reported in the media in Northern Ireland: dozens of withdrawals taking place over four weeks, totaling almost five thousand pounds, all within a ten mile radius of the McGaughey&#8217;s home. Summarised that way it looks like a classic first party fraud (couple short on cash withdraw money, then deny it later). But no-one in the family is short on cash, the McGaugheys look after their card details carefully, and have solid <a href="http://www.bridgewebs.com/derryvolgie/">alibis</a> at the time of many of the withdrawals, and the interlocking pattern of real and disputed withdrawals is such that any third party would have a hard time taking and returning the card (whether covertly or in collusion with the McGaugheys). No-one appears to have either the means or the motive.</p>
<p>Unusually the bank has been very cooperative, providing logs from their authorisation system (<A href="http://www.aciworldwide.com/products/detail.aspx?product_id=236">BASE24</a>), including all of the cryptograms, input data and transaction parameters covering the affected transactions. Everything turns on the Application Transaction Counter (ATC), an on-card counter which increments with every transaction initiated. If an EMV chip can be fully cloned (secret keys and all), then it will have to submit an ATC value when transacting, and if used in parallel with the real card, it won&#8217;t be long before the same number pops up twice in the auth system, or large gaps in the sequence appear. The McGaughey&#8217;s ATC sequence appears to interlock perfectly: clearly the original card was used?</p>
<p>Of course logs can be misinterpreted (<a href="http://news.bbc.co.uk/1/hi/programmes/newsnight/7265437.stm">Badger</a>) or even faked, auth systems may not work as expected, and customers may lie and cheat following all sorts of agendas; just around the corner the missing piece of the jigsaw may lie, which reveals the truth behind the case. And there is the totally separate matter of who should suffer the loss in the interim, whilst the truth remains unclear. <a href="http://www.lightbluetouchpaper.org/2008/04/09/new-banking-code-shifts-more-liability-to-customers/">Liability for disputed withdrawals</a> is the most hotly contested issue of all.</p>
<p><a href="http://www.phantomwithdrawals.com">phantomwithdrawals.com</a> can&#8217;t do much more for the McGaugheys, but it can bear witness. Documenting the incidence of phantoms and the experiences of customers disputing them adds much needed transparency to the process, and helps researchers and experts seek out the really interesting cases.</p>
<p>Maybe we can lift the lid and discover the truth behind the &#8220;phantom menace&#8221; &#8212; everyone is united in that goal at least &#8212; but let&#8217;s also hope that Episode 2: <a href="http://www.epaynews.com/index.cgi?survey=&#038;ref=browse&#038;f=view&#038;id=11497625028614136145&#038;block=">Attack of the Clones</a> has not yet started shooting!</p>
<p>Mike.</p>
]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 11:06:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/phantom">phantom</category>
      <category domain="http://securityratty.com/tag/real">real</category>
      <category domain="http://securityratty.com/tag/real card">real card</category>
      <category domain="http://securityratty.com/tag/card details">card details</category>
      <category domain="http://securityratty.com/tag/phantom menace">phantom menace</category>
      <category domain="http://securityratty.com/tag/phantom withdrawal">phantom withdrawal</category>
      <category domain="http://securityratty.com/tag/transaction">transaction</category>
      <category domain="http://securityratty.com/tag/application transaction counter">application transaction counter</category>
      <source url="http://www.lightbluetouchpaper.org/2008/08/05/card-wars-the-phantom-menace/">Card Wars: The Phantom Menace</source>
    </item>
    <item>
      <title><![CDATA[CyberAngels has a great piece on CyberBullying]]></title>
      <link>http://securityratty.com/article/4f0b9874a55b3e6d156c1bc978ec49ec</link>
      <guid>http://securityratty.com/article/4f0b9874a55b3e6d156c1bc978ec49ec</guid>
      <description><![CDATA[If youre a parent, take the time to read this great article, for your kids sake. Then talk to them about it. You remember how tough it was to be a kid when there was no Internet right? Imagine being...]]></description>
      <content:encoded><![CDATA[<div > If you&#8217;re a parent, take the time to read this great article, for your kids sake.<br/>Then talk to them about it.<br/>You remember how tough it was to be a kid when there was no Internet right?<br/>Imagine being bulled with zeros and ones. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/16C6CB3E-AA76-470C-999A-04955CD39F9D/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/c8340db8-7f6d-43f6-92ec-36806a75183d/16C6CB3E-AA76-470C-999A-04955CD39F9D/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.cyberangels.org/" href="http://www.cyberangels.org/" style="font-size: 11px;">www.cyberangels.org</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.cyberangels.org/ --> Cyberbullying</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.cyberangels.org/ --><DIV><STRONG></STRONG><br />
The feeling of anonymity on the web makes it a perfect playground for students to engage in cruel behavior. A study from the National Crime Prevention Council (NCPC) says that 43 percent of teens reported being victims of cyberbullying in the past year. </DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/16C6CB3E-AA76-470C-999A-04955CD39F9D/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 11:39:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kids sake">kids sake</category>
      <category domain="http://securityratty.com/tag/cyberangels">cyberangels</category>
      <category domain="http://securityratty.com/tag/cruel behavior">cruel behavior</category>
      <category domain="http://securityratty.com/tag/perfect playground">perfect playground</category>
      <category domain="http://securityratty.com/tag/victims">victims</category>
      <category domain="http://securityratty.com/tag/percent">percent</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/past">past</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=527">CyberAngels has a great piece on CyberBullying</source>
    </item>
    <item>
      <title><![CDATA[Strong Attractors]]></title>
      <link>http://securityratty.com/article/75d900ac3479f86563ba02a525d2e720</link>
      <guid>http://securityratty.com/article/75d900ac3479f86563ba02a525d2e720</guid>
      <description><![CDATA[Dan Geer and Dan Conway examine the metrics of where attackers are, and where they seek out...]]></description>
      <content:encoded><![CDATA[Dan Geer and Dan Conway examine the metrics of where attackers are, and where they seek out victims.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=4fa2cd22ab1954acf0cb16fc3e3da7a4" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=4fa2cd22ab1954acf0cb16fc3e3da7a4" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 09:30:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dan conway examine">dan conway examine</category>
      <category domain="http://securityratty.com/tag/dan geer">dan geer</category>
      <category domain="http://securityratty.com/tag/victims">victims</category>
      <category domain="http://securityratty.com/tag/attackers">attackers</category>
      <category domain="http://securityratty.com/tag/metrics">metrics</category>
      <category domain="http://securityratty.com/tag/seek">seek</category>
      <source url="http://www.pheedo.com/click.phdo?i=4fa2cd22ab1954acf0cb16fc3e3da7a4">Strong Attractors</source>
    </item>
    <item>
      <title><![CDATA[Safari At Risk of a Cookie Monster attack]]></title>
      <link>http://securityratty.com/article/961de214fdf000dd27ed46ebe9fc758d</link>
      <guid>http://securityratty.com/article/961de214fdf000dd27ed46ebe9fc758d</guid>
      <description><![CDATA[There are reports of a new Apple Safari flaw, exploiting cookies in the browser. However, the vulnerability exploit hasnt been seen in the wild and theres as yet no response from Apple about the flaw....]]></description>
      <content:encoded><![CDATA[<p>There are reports of a new Apple Safari flaw, exploiting cookies in the browser. However, the vulnerability exploit hasn&#8217;t been seen in the wild and there&#8217;s as yet no response from Apple about the flaw. Here&#8217;s the potential damages -</p>
<blockquote><p><span id="articleBody"> An attacker who successfully exploits the vulnerability could perform a <a rel="nofollow" target="_blank" href="http://www.acros.si/papers/session_fixation.pdf">session fixation attack</a>. This allows the attacker to pre-set the victim&#8217;s session ID and to use the fixed session ID for malicious activities. </span></p>
<p>An attack of this sort, known as <a rel="nofollow" target="_blank" href="http://en.wikipedia.org/wiki/Cross-site_cooking">&#8220;cross-site cooking,&#8221;</a> might include tricking a user to log in through a malicious form, exploiting a cross-site scripting vulnerability or meta <a rel="nofollow" target="_blank" href="http://www.techweb.com/encyclopedia/defineterm.jhtml?term=tag&amp;x=&amp;y=">tag</a> injection flaw, breaking into host in the target server&#8217;s domain, and network traffic alteration.</p></blockquote>
<p>To learn more, read the <a rel="nofollow" target="_blank" href="http://www.informationweek.com/news/internet/browsers/showArticle.jhtml?articleID=209800452">full article.</a></p>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 07:57:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/apple safari flaw">apple safari flaw</category>
      <category domain="http://securityratty.com/tag/apple">apple</category>
      <category domain="http://securityratty.com/tag/flaw">flaw</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/vulnerability exploit">vulnerability exploit</category>
      <category domain="http://securityratty.com/tag/session fixation attack">session fixation attack</category>
      <category domain="http://securityratty.com/tag/network traffic alteration">network traffic alteration</category>
      <category domain="http://securityratty.com/tag/target servers domain">target servers domain</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/351874827/">Safari At Risk of a Cookie Monster attack</source>
    </item>
  </channel>
</rss>
