<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: vulnerable]]></title>
    <link>http://securityratty.com/tag/vulnerable</link>
    <description></description>
    <pubDate>Wed, 17 Sep 2008 19:41:44 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[New Cross-Site Request Forgery Attacks]]></title>
      <link>http://securityratty.com/article/97352e193bff92587f51944a500f9de1</link>
      <guid>http://securityratty.com/article/97352e193bff92587f51944a500f9de1</guid>
      <description><![CDATA[Interesting : CSRF vulnerabilities occur when a website allows an authenticated user to perform a sensitive action but does not verify that the user herself is invoking that action. The key to...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.freedom-to-tinker.com/blog/wzeller/popular-websites-vulnerable-cross-site-request-forgery-attacks">Interesting</a>:</p>

<blockquote>CSRF vulnerabilities occur when a website allows an authenticated user to perform a sensitive action but does not verify that the user herself is invoking that action. The key to understanding CSRF attacks is to recognize that websites typically don't verify that a request came from an authorized user. Instead they verify only that the request came from <i>the browser of</i> an authorized user. Because browsers run code sent by multiple sites, there is a danger that one site will (unbeknownst to the user) send a request to a second site, and the second site will mistakenly think that the user authorized the request.

<p>If a user visits an attacker's website, the attacker can force the user's browser to send a request to a page that performs a sensitive action on behalf of the user. The target website sees a request coming from an authenticated user and happily performs some action, whether it was invoked by the user or not. CSRF attacks have been confused with Cross-Site Scripting (XSS) attacks, but they are very different. A site completely protected from XSS is still vulnerable to CSRF attacks if no protections are taken. </blockquote></p>

<p>Paper <a href="http://www.freedom-to-tinker.com/sites/default/files/csrf.pdf">here</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=u3eOM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=u3eOM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=C8ODM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=C8ODM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 01:42:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <category domain="http://securityratty.com/tag/cross-site">cross-site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/user visits">user visits</category>
      <category domain="http://securityratty.com/tag/csrf attacks">csrf attacks</category>
      <category domain="http://securityratty.com/tag/sensitive action">sensitive action</category>
      <category domain="http://securityratty.com/tag/action">action</category>
      <category domain="http://securityratty.com/tag/site completely">site completely</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/new_cross-site.html">New Cross-Site Request Forgery Attacks</source>
    </item>
    <item>
      <title><![CDATA[Hacking Your VoIP Box From The Net]]></title>
      <link>http://securityratty.com/article/ddef0bbead6572419deccb8cf4914ce6</link>
      <guid>http://securityratty.com/article/ddef0bbead6572419deccb8cf4914ce6</guid>
      <description><![CDATA[Do you do penetration testing of your own network? Is it comprehensive enough? Read this recent blog from McAfee's Avert Labs and you may wonder. An Avert analyst, reading about vulnerabilities in the...]]></description>
      <content:encoded><![CDATA[Do you do penetration testing of your own network? Is it comprehensive enough? Read <a href="http://www.avertlabs.com/research/blog/index.php/2008/09/29/the-lack-of-attention-in-voip-devices/">this recent blog from McAfee's Avert Labs</a> and you may wonder.

An Avert analyst, reading about vulnerabilities in the Cisco IP phone model 7960 then used Google to try to find publicly-accessible 7960 phones. He found "almost 10" (does that mean 9? awkward turn of phrase). 1 of them had the vulnerable firmware version  And the vulnerability was that the phone's web interface reveals a lot of sensitive network information, so the company that holds that phone has a vulnerable network.

What was revealed by the phone? "...the IP addresses of the TFTP server/router/DNS server/DHCP server/Cisco Call Manager, as well as some application links, internal device configuration, and debugging information. If there are any exploitable vulnerabilities in one of these linked servers, attackers could use this information to stage further attacks."

There's always more to test for, and mistakes you in device configuration can have dire consequences.
<p><a href="http://feedads.googleadservices.com/~a/KqezZ8B5wlQOthXrTY4hSBEoKXo/a"><img src="http://feedads.googleadservices.com/~a/KqezZ8B5wlQOthXrTY4hSBEoKXo/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/sIcbcZ5FSGQ" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 04 Oct 2008 13:06:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sensitive network information">sensitive network information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/device configuration">device configuration</category>
      <category domain="http://securityratty.com/tag/internal device configuration">internal device configuration</category>
      <category domain="http://securityratty.com/tag/phone model">phone model</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/exploitable vulnerabilities">exploitable vulnerabilities</category>
      <category domain="http://securityratty.com/tag/vulnerable network">vulnerable network</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/sIcbcZ5FSGQ/hacking_your_voip_box_from_the_net.html">Hacking Your VoIP Box From The Net</source>
    </item>
    <item>
      <title><![CDATA[Taleb on the Limitations of Risk Management]]></title>
      <link>http://securityratty.com/article/f91dcedda258c55172e0d795aebda8a8</link>
      <guid>http://securityratty.com/article/f91dcedda258c55172e0d795aebda8a8</guid>
      <description><![CDATA[Nice paragraph on the limitations of risk management in this occasionally interesting interview with Nicholas Taleb: Because then you get a Maginot Line problem. [After World War I, the French erected...]]></description>
      <content:encoded><![CDATA[<p>Nice paragraph on the limitations of risk management in this <a href="http://www.portfolio.com/views/columns/the-world-according-to/2008/08/14/Interview-With-Nassim-Nicholas-Taleb">occasionally interesting interview</a> with Nicholas Taleb:</p>

<blockquote>Because then you get a Maginot Line problem. [After World War I, the French erected concrete fortifications to prevent Germany from invading again -- a response to the previous war, which proved ineffective for the next one.] You know, they make sure they solve that particular problem, the Germans will not invade from here. The thing you have to be aware of most obviously is scenario planning, because typically if you talk about scenarios, you'll overestimate the probability of these scenarios. If you examine them at the expense of those you don't examine, sometimes it has left a lot of people worse off, so scenario planning can be bad. I'll just take my track record. Those who did scenario planning have not fared better than those who did not do scenario planning. A lot of people have done some kind of "make-sense" type measures, and that has made them more vulnerable because they give the illusion of having done your job. This is the problem with risk management. I always come back to a classical question. Don't give a fool the illusion of risk management. Don't ask someone to guess the number of dentists in Manhattan after asking him the last four digits of his Social Security number. The numbers will always be correlated. I actually did some work on risk management, to show how stupid we are when it comes to risk.</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=XoSTM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=XoSTM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=iSyHM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=iSyHM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 03:48:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/scenario">scenario</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/people worse">people worse</category>
      <category domain="http://securityratty.com/tag/concrete fortifications">concrete fortifications</category>
      <category domain="http://securityratty.com/tag/maginot line">maginot line</category>
      <category domain="http://securityratty.com/tag/illusion">illusion</category>
      <category domain="http://securityratty.com/tag/social security">social security</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/taleb_in_the_li.html">Taleb on the Limitations of Risk Management</source>
    </item>
    <item>
      <title><![CDATA[Encrypted image backups open to new attack]]></title>
      <link>http://securityratty.com/article/00c0afdd4ac3a13212797ce9ae2614ce</link>
      <guid>http://securityratty.com/article/00c0afdd4ac3a13212797ce9ae2614ce</guid>
      <description><![CDATA[Bitmaps stored inside encrypted backup files could be vulnerable to a sophisticated 'comparison' attack, a German security researcher has...]]></description>
      <content:encoded><![CDATA[Bitmaps stored inside encrypted backup files could be vulnerable to a sophisticated 'comparison' attack, a German security researcher has discovered.]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/german security researcher">german security researcher</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/backup files">backup files</category>
      <category domain="http://securityratty.com/tag/comparison">comparison</category>
      <category domain="http://securityratty.com/tag/inside">inside</category>
      <category domain="http://securityratty.com/tag/vulnerable">vulnerable</category>
      <category domain="http://securityratty.com/tag/bitmaps">bitmaps</category>
      <source url="http://www.networkworld.com/news/2008/100308-encrypted-image-backups-open-to.html?fsrc=rss-security">Encrypted image backups open to new attack</source>
    </item>
    <item>
      <title><![CDATA[Hype Alert: Internet Shopping Carts Are Secure]]></title>
      <link>http://securityratty.com/article/6f0706e64d78d354492017803497a079</link>
      <guid>http://securityratty.com/article/6f0706e64d78d354492017803497a079</guid>
      <description><![CDATA[My blog reader fed me a nugget today that set off my hype monitor, specifically a post entitled Internet Shopping Carts are Secure
OMG...really
To be fair, I realize the author is speaking from the...]]></description>
      <content:encoded><![CDATA[My blog reader fed me a nugget today that set off my hype monitor, specifically a post entitled <a href="http://hubpages.com/hub/Internet-Shopping-Carts-Are-Secure" taget="_blank">Internet Shopping Carts are Secure</a>. <br />OMG...really?<br />To be fair, I realize the author is speaking from the eCommerce perspective, rather than that of an information security practitioner, but here's where the trouble begins:<br /><span style="font-style:italic;">"Shopping cart service providers have developed secure ecommerce shopping cart solutions for any business owner looking to enhance their current online store, or create a new one. Some ecommerce shopping cart solution providers are even receiving PABP (Payment Application Best Practice) certification which supports PCI compliance requirements for all businesses accepting credit card payments online."</span><br />This may be true in part, but it is by no means an all-inclusive claim. Shopping carts continue to be sieve-like, even when apparently reviewed per <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI</a> standards.<br />Allow me to elaborate.<br />We'll kick off our hype eliminating effort with a simple Google dork: <a href="http://www.google.com/search?hl=en&q=inurl%3A%22cart.cfm%22&btnG=Search" target="_blank"{>inurl:"cart.cfm"</a> (picking on ColdFusion again, but man, they make it easy)<br /><a href="http://www.gmpartsdirect.com/cart.cfm" target="_blank">GM Parts Direct: Your Shopping Cart</a> jumped right out at me for a number of reasons.<br />First, I sensed XSS vulns lurking like a Geiger counter senses radiation. Sound <a href="http://www.ringelkater.de/Sounds/2geraeusche_gegenst/geigerzaehler.wav" target="_blank">effect</a> for edification. :-)<br />Second, the page contained one of the growing number of aforementioned conversion-driving website <a href="http://sealserver.trustwave.com/cert.php?customerId=w6ordzctHpqOVGcB1cmBsViTpDGC2k&size=105x54&style=normal&language=en" target="_blank">security</a> seals. <br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_kVOWaY1TAF0/SN1tYvapkkI/AAAAAAAAADg/6k1ncKqufL4/s1600-h/GMparts.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_kVOWaY1TAF0/SN1tYvapkkI/AAAAAAAAADg/6k1ncKqufL4/s320/GMparts.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5250473012396397122" /></a><br /><br />Tick, tick, click...the Gieger counter is getting louder. <br />Trustwave claims that the site operator "is enrolled in Trustwave's Trusted Commerce™ program to validate compliance with the Payment Card Industry Data Security Standard (PCI DSS) mandated by all the major credit card associations including: American Express, Diners Club, Discover, JCB, MasterCard Worldwide, Visa, Inc. and Visa Europe."<br />Methinks that <a href="https://www.trustwave.com/" target="_blank">Trustwave's</a> Trusted Commerce program is missing a few fundamental security checks. Remember, XSS in PCI regulated sites, according to the <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI DSS</a>, indicates that a site is not compliant (see section 6.5.4) if vulnerable to XSS.<br />Uh-oh.<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SN1wVI4q8FI/AAAAAAAAADo/ZzFA7u8xNCA/s1600-h/GMparts_xss_trustwave.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SN1wVI4q8FI/AAAAAAAAADo/ZzFA7u8xNCA/s320/GMparts_xss_trustwave.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5250476249048608850" /></a><br />All it takes is a fake login page, as opposed to our friends at <a href="http://xssed.com/" target="_blank">XSSED.com</a>, and...well, you get the point.<br />Simply, this is one of an endless number of shopping cart not secure, and not PCI compliant. For shame. You need only browse the <a href="http://holisticinfosec.org/content/category/6/23/45/" target="_blank">Holisticinfosec.org Advisories</a> page to find multiple ecommerce platforms and shopping carts that are missing the mark. Trust me, these are a fraction of the <a href="http://secunia.com/advisories/search/?search=shopping+cart" target="_blank">problem</a>.<br />ecommerce<>security<br />ecommerce<><a href="http://msdn.microsoft.com/en-us/library/ms995349.aspx" target="_blank">SDL</a><br />ecommerce<>PCI<br />website security seal<>security<br />Sigh.]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 11:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ecommerce">ecommerce</category>
      <category domain="http://securityratty.com/tag/multiple ecommerce platforms">multiple ecommerce platforms</category>
      <category domain="http://securityratty.com/tag/ecommerce sdl">ecommerce sdl</category>
      <category domain="http://securityratty.com/tag/ecommerce perspective">ecommerce perspective</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/cart solutions">cart solutions</category>
      <category domain="http://securityratty.com/tag/cart">cart</category>
      <category domain="http://securityratty.com/tag/ecommerce security">ecommerce security</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/hype-alert-internet-shopping-carts-are.html">Hype Alert: Internet Shopping Carts Are Secure</source>
    </item>
    <item>
      <title><![CDATA[Two Copycat Web Malware Exploitation Kits in the Wild]]></title>
      <link>http://securityratty.com/article/59660edd6ee56561c03dbddbfcbaac92</link>
      <guid>http://securityratty.com/article/59660edd6ee56561c03dbddbfcbaac92</guid>
      <description><![CDATA[We're slowly entering into &quot;can you find the ten similarities&quot; stage in respect to web malware exploitation kits, and their coders continuous supply of copycat malware kits under different names,...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SNqBEcPBZZI/AAAAAAAACLA/AJVrNj6P8JE/s1600-h/zopa01.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SNqBEcPBZZI/AAAAAAAACLA/of0mCvvFn4o/s200-R/zopa01.JPG" /></a>We're slowly entering into "can you find the ten similarities" stage in respect to web malware exploitation kits, and their coders continuous supply of copycat malware kits under different names, taking advantage of different exploits combination. <a href="http://ddanchev.blogspot.com/2008/09/copycat-web-malware-exploitation-kits.html">Copycat web malware exploitation kits are faddish</a>, however, from a strategic perspective, releasing exploits kits like this one <a href="http://www.trustedsource.org/blog/153/Rise-Of-The-PDF-Exploits">covered by Trustedsource</a>, consisting entirely of PDF exploits, can greatly increase the exploitability level of Adobe vulnerabilities in general.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SNqC_oeGqgI/AAAAAAAACLI/tCvdE7XRFt4/s1600-h/zopa02.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SNqC_oeGqgI/AAAAAAAACLI/iSGUOgS9ZUg/s200-R/zopa02.JPG" /></a>A similar web malware exploitation kit, once again using only Adobe related exploits is Zopa. Have you seen this layout before? That's the very same layout <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">MPack</a> and <a href="http://ddanchev.blogspot.com/2007/07/icepack-malware-kit-in-action.html">IcePack</a> were using, were in the sense of cybercriminals preferring to use much mode modular alternatives these days. Ironically, Zopa is more expensive than MPack and IcePack, with the coder trying to cash-in on its biased exclusiveness and introduction stage buzz generated around it.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SNqFtIcwL7I/AAAAAAAACLQ/ZTdoCdSNYbA/s1600-h/stats_copycat_kit.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="200" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SNqFtIcwL7I/AAAAAAAACLQ/aGd-dPNq3TY/s200-R/stats_copycat_kit.jpg" width="151" /></a>The second web malware exploitation kit is relying on a mix of exploits targeting patched vulnerabilities affecting IE, Firefox and Opera, with its authors asking for $50 for monthly updates, updates of what yet remains unknown. Both of these kits once again demonstrate the current&nbsp; mentality of the kit's coders having to do with -- thankfully -- zero innovation, fast cash and no long-term value.<br />
<br />
However, modularity, convergence with traffic management kits, vertical integration with cybercrime services and bullet proof hosting providers, advanced metrics, <a href="http://securitylabs.websense.com/content/Blogs/3183.aspx">evasive practices</a>, improved OPSEC (operational security), and dedicated cybercrime campaign optimizing staff, are all in the works.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Web  Based Botnet Command and Control Kit 2.0</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diy-botnet-kit-promising-eternal.html">DIY  Botnet Kit Promising Eternal Updates</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch  Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The  Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The  Small Pack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">Crimeware  in the Middle - Zeus</a><br />
<a href="http://ddanchev.blogspot.com/2006/11/nuclear-grabber-toolkit.html">The  Nuclear Grabber Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">The  Apophis Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">The  FirePack Exploitation Kit Localized to Chinese</a><span style="font-weight: bold;"><br />
</span><a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">MPack  and IcePack Localized to Chinese</a><br />
<span style="font-weight: bold;"><span style="font-weight: bold;"></span></span><a href="http://ddanchev.blogspot.com/2008/05/icepack-exploitation-kit-localized-to.html">The  Icepack Exploitation Kit Localized to French</a> <br />
<a href="http://ddanchev.blogspot.com/2008/04/firepack-exploitation-kit-part-two.html">The  FirePack Exploitation Kit - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/firepack-web-malware-exploitation-kit.html">The  FirePack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/webattacker-in-action.html">The  WebAttacker in Action</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/nuclear-malware-kit.html">Nuclear  Malware Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/random-js-malware-exploitation-kit.html">The  Random JS Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher  Malware Kit Spotted in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_7672.html">The  Black Sun Bot</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_20.html">The  Cyber Bot</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/google-hacking-for-mpacks-zunkers-and.html">Google  Hacking for MPacks, Zunkers and WebAttackers</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/icepack-malware-kit-in-action.html">The  IcePack Malware Kit in Action</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=H3UxL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=H3UxL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=p3TZL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=p3TZL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=h2h0l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=h2h0l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LBCnl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LBCnl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ntatL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ntatL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AnrYL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AnrYL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0AlHl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0AlHl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/402081047" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 10:28:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/diy botnet kit">diy botnet kit</category>
      <category domain="http://securityratty.com/tag/kit">kit</category>
      <category domain="http://securityratty.com/tag/nuclear malware kit">nuclear malware kit</category>
      <category domain="http://securityratty.com/tag/icepack exploitation kit">icepack exploitation kit</category>
      <category domain="http://securityratty.com/tag/nuclear grabber kit">nuclear grabber kit</category>
      <category domain="http://securityratty.com/tag/apophis kit">apophis kit</category>
      <category domain="http://securityratty.com/tag/malware exploitation kit">malware exploitation kit</category>
      <category domain="http://securityratty.com/tag/kits">kits</category>
      <category domain="http://securityratty.com/tag/control kit">control kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/402081047/two-copycat-web-malware-exploitation.html">Two Copycat Web Malware Exploitation Kits in the Wild</source>
    </item>
    <item>
      <title><![CDATA[CCTV Firm Threatens The Researcher Who Found Vulnerable Products That Reveal Cam Images Without Authentication]]></title>
      <link>http://securityratty.com/article/004b60ada89c39b7a3f4bb4d0ecf0735</link>
      <guid>http://securityratty.com/article/004b60ada89c39b7a3f4bb4d0ecf0735</guid>
      <description><![CDATA[A flaw discovered by security researcher Mike Stephens, affects The LookC 44 server and Pro IX server, which allows anyone to view static images from any camera connected to its servers. This product...]]></description>
      <content:encoded><![CDATA[A flaw discovered by security researcher Mike Stephens, affects The LookC 4&#215;4 server and Pro IX server, which allows anyone to view static images from any camera connected to its servers. This product is installed in some primary and secondary schools. The flaw requires no authentication to exploit and vulnerable servers might be found via [...]]]></content:encoded>
      <pubDate>Sat, 20 Sep 2008 04:22:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flaw requires">flaw requires</category>
      <category domain="http://securityratty.com/tag/vulnerable servers">vulnerable servers</category>
      <category domain="http://securityratty.com/tag/flaw">flaw</category>
      <category domain="http://securityratty.com/tag/view static images">view static images</category>
      <category domain="http://securityratty.com/tag/servers">servers</category>
      <category domain="http://securityratty.com/tag/secondary schools">secondary schools</category>
      <category domain="http://securityratty.com/tag/authentication">authentication</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/pro">pro</category>
      <source url="http://cyberinsecure.com/cctv-firm-threatens-the-researcher-who-found-vulnerable-products/">CCTV Firm Threatens The Researcher Who Found Vulnerable Products That Reveal Cam Images Without Authentication</source>
    </item>
    <item>
      <title><![CDATA[Yahoo, Hotmail, Gmail all vulnerable to password reset hack]]></title>
      <link>http://securityratty.com/article/3f5a4742421e165861808e01664b0846</link>
      <guid>http://securityratty.com/article/3f5a4742421e165861808e01664b0846</guid>
      <description><![CDATA[Yahoo Mail isn't the only Web-based mail service that could be duped into giving up someone else's account password, the tactic that some have argued was used to break into Gov. Sarah Palin's e-mail...]]></description>
      <content:encoded><![CDATA[Yahoo Mail isn't the only Web-based mail service that could be duped into giving up someone else's account password, the tactic that some have argued was used to break into Gov. Sarah Palin's e-mail earlier this week.]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/account password">account password</category>
      <category domain="http://securityratty.com/tag/yahoo mail">yahoo mail</category>
      <category domain="http://securityratty.com/tag/sarah palin">sarah palin</category>
      <category domain="http://securityratty.com/tag/mail service">mail service</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/duped">duped</category>
      <category domain="http://securityratty.com/tag/gov">gov</category>
      <category domain="http://securityratty.com/tag/e-mail">e-mail</category>
      <category domain="http://securityratty.com/tag/tactic">tactic</category>
      <source url="http://www.networkworld.com/news/2008/091908-yahoo-hotmail-gmail-all-vulnerable.html?fsrc=rss-security">Yahoo, Hotmail, Gmail all vulnerable to password reset hack</source>
    </item>
    <item>
      <title><![CDATA[Fear not, no wait, you should fear.]]></title>
      <link>http://securityratty.com/article/62970ace259302e46fc33f22f86e9c5e</link>
      <guid>http://securityratty.com/article/62970ace259302e46fc33f22f86e9c5e</guid>
      <description><![CDATA[Ever get the feeling that the bow of the ship is slipping under the waves


clipped from www.msnbc.msn.com

U.S. Cybersecurity Is Weak, GAO Says



Five years after the Homeland Security Dept. took...]]></description>
      <content:encoded><![CDATA[<div > Ever get the feeling that the bow of the ship is slipping under the waves? </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/3EFCAA8A-BF2C-497A-8513-A48D6844A0AD/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/ad915f0a-26dc-4cc3-8945-0ed58ccf8ec1/3EFCAA8A-BF2C-497A-8513-A48D6844A0AD/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.msnbc.msn.com/id/26738121/" href="http://www.msnbc.msn.com/id/26738121/" style="font-size: 11px;">www.msnbc.msn.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">
U.S. Cybersecurity Is Weak, GAO Says
</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ --><P class="textBodyBlack"><SPAN id="byLine"></SPAN><br />
Five years after the Homeland Security Dept. took charge of the team as a critical safeguard against threats to national security, US-CERT &#8220;still does not exhibit aspects of the attributes essential to having a truly national capability,&#8221; according to the draft report.<br />
</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ --><P class="textBodyBlack"><SPAN id="byLine"></SPAN><br />
Vulnerable to Foreign Adversaries</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ --><P class="textBodyBlack"><SPAN id="byLine"></SPAN><br />
Goals Not Being Met</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ --><P class="textBodyBlack"><SPAN id="byLine"></SPAN><br />
Actions Are Inadequate</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.msnbc.msn.com/id/26738121/ --><P class="textBodyBlack"><SPAN id="byLine"></SPAN><br />
Weak Warning Capabilities</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/3EFCAA8A-BF2C-497A-8513-A48D6844A0AD/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_180908012351"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=180908012351&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=180908012351&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=180908012351&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_180908012351" /></a></P>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 09:23:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/homeland security dept">homeland security dept</category>
      <category domain="http://securityratty.com/tag/exhibit aspects">exhibit aspects</category>
      <category domain="http://securityratty.com/tag/critical safeguard">critical safeguard</category>
      <category domain="http://securityratty.com/tag/attributes essential">attributes essential</category>
      <category domain="http://securityratty.com/tag/national capability">national capability</category>
      <category domain="http://securityratty.com/tag/draft report">draft report</category>
      <category domain="http://securityratty.com/tag/weak">weak</category>
      <category domain="http://securityratty.com/tag/national security">national security</category>
      <category domain="http://securityratty.com/tag/foreign adversaries">foreign adversaries</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=623">Fear not, no wait, you should fear.</source>
    </item>
    <item>
      <title><![CDATA[A suit of armor is needed now to protect you online]]></title>
      <link>http://securityratty.com/article/28df93f6285f4ab9101e0e388076ab79</link>
      <guid>http://securityratty.com/article/28df93f6285f4ab9101e0e388076ab79</guid>
      <description><![CDATA[How many of you are fully patched? 100%? Raise your hands


clipped from www.sci-tech-today.com
Searching for Brad Pitt Can Lure Surfers To Malware



Malware with criminal intent tends to last for a...]]></description>
      <content:encoded><![CDATA[<div > How many of you are fully patched? 100%?<br/>Raise your hands. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/7A2E5925-3318-4F13-9A00-B495FDD7C788/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/fed9a8b8-5e21-4bd0-981d-e765078d6f07/7A2E5925-3318-4F13-9A00-B495FDD7C788/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.sci-tech-today.com/news/Malware-Sites-Use-Brad-Pitt-as-Lure/story.xhtml?story_id=10100B9ZZQVP" href="http://www.sci-tech-today.com/news/Malware-Sites-Use-Brad-Pitt-as-Lure/story.xhtml?story_id=10100B9ZZQVP" style="font-size: 11px;">www.sci-tech-today.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.sci-tech-today.com/news/Malware-Sites-Use-Brad-Pitt-as-Lure/story.xhtml?story_id=10100B9ZZQVP --><B>Searching for Brad Pitt Can Lure Surfers To Malware</B></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.sci-tech-today.com/news/Malware-Sites-Use-Brad-Pitt-as-Lure/story.xhtml?story_id=10100B9ZZQVP --><P><br />
Malware with criminal intent tends to last for a short time, according to Green, only five to seven hours. And most of it is static and obfuscated or intentionally made difficult to read, he said.<br />
</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.sci-tech-today.com/news/Malware-Sites-Use-Brad-Pitt-as-Lure/story.xhtml?story_id=10100B9ZZQVP --><P><br />
Criminals are now shifting from SMTP to HTTP as a way to steal information from Internet users, according to F-Secure, and unless you have a fully patched browser, plug-ins and operating system, you are vulnerable.<br />
</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/7A2E5925-3318-4F13-9A00-B495FDD7C788/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_170908114144"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=170908114144&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=170908114144&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=170908114144&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_170908114144" /></a></P>]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 19:41:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lure surfers">lure surfers</category>
      <category domain="http://securityratty.com/tag/brad pitt">brad pitt</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/internet users">internet users</category>
      <category domain="http://securityratty.com/tag/short time">short time</category>
      <category domain="http://securityratty.com/tag/criminal intent">criminal intent</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/smtp">smtp</category>
      <category domain="http://securityratty.com/tag/browser">browser</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=618">A suit of armor is needed now to protect you online</source>
    </item>
  </channel>
</rss>
