<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: whitehouse]]></title>
    <link>http://securityratty.com/tag/whitehouse</link>
    <description></description>
    <pubDate>Tue, 20 May 2008 22:38:02 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Links for 2008-06-20 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/80b3696bcd994752426b86df5a76d874</link>
      <guid>http://securityratty.com/article/80b3696bcd994752426b86df5a76d874</guid>
      <description><![CDATA[PCI DSS News and Information Why Logs and Logging Matters - Part 1
PCI DSS News and Information Why Logs Matter - Part 2, A Letter
About Common Event Expression: CEE Documents
Failing Disk Readers
Why...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://treasuryinstitute.org/blog/index.php?itemid=144">PCI DSS News and Information &raquo; Why Logs and Logging Matters - Part 1</a></li>
<li><a href="http://treasuryinstitute.org/blog/index.php?itemid=147">PCI DSS News and Information &raquo; Why Logs Matter - Part 2, A Letter</a></li>
<li><a href="http://cee.mitre.org/documents.html">About Common Event Expression: CEE Documents</a></li>
<li><a href="http://www.s2services.com/diskreaderfreeware.htm">Failing Disk Readers</a></li>
<li><a href="http://lcsmith.com/blog/?p=4">Why standards? | Sanford Whitehouse - Floating By</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/316687871" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 20 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci dss news">pci dss news</category>
      <category domain="http://securityratty.com/tag/common event expression">common event expression</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/logs matter">logs matter</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/sanford whitehouse">sanford whitehouse</category>
      <category domain="http://securityratty.com/tag/disk readers">disk readers</category>
      <category domain="http://securityratty.com/tag/cee documents">cee documents</category>
      <category domain="http://securityratty.com/tag/matters">matters</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/316687871/anton18">Links for 2008-06-20 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[The Whitehouse.org Serving Malware]]></title>
      <link>http://securityratty.com/article/4f895840b6d5da9c0d894880f418e55c</link>
      <guid>http://securityratty.com/article/4f895840b6d5da9c0d894880f418e55c</guid>
      <description><![CDATA[The Whitehouse.org a parody site of the original Whitehouse.gov is serving malware. From TrendMicro's blog

According to Trend Micro Advanced Threats Researcher David Sancho, whitehouse.org has been...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SDNPAHtDXCI/AAAAAAAABuY/5zYB1mdAFPo/s1600-h/whitehouse_org2.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SDNPAHtDXCI/AAAAAAAABuY/5zYB1mdAFPo/s200/whitehouse_org2.JPG" alt="" id="BLOGGER_PHOTO_ID_5202588858029661218" border="0" /></a>The <a href="http://www.google.com/interstitial?url=http://www.whitehouse.org/">Whitehouse.org</a> a parody site of the original Whitehouse.gov is serving malware. From <a href="http://blog.trendmicro.com/whitehouseorg-pwnd-serving-malware/">TrendMicro's blog</a> :<br /><br />"<span style="font-style: italic;">According to Trend Micro Advanced Threats Researcher David Sancho, whitehouse.org has been compromised to harbor some malicious, obfuscated JavaScript code which “background downloads” code to unsuspecting visitors of the site, where a malicious file is downloaded (which is detected by Trend Micro as TROJ_DELF.GKP ). Of course, the official White House Web site is whitehouse.gov, and although it has been reported that some people believe whitehouse.org is the real deal, even those looking for this site specifically should be forewarned.</span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SDNPj3tDXDI/AAAAAAAABug/bTMq90rWqeo/s1600-h/whitehouse_org3.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SDNPj3tDXDI/AAAAAAAABug/bTMq90rWqeo/s200/whitehouse_org3.JPG" alt="" id="BLOGGER_PHOTO_ID_5202589472209984562" border="0" /></a>The malicious domain embedded within the site <span style="font-weight: bold;">ad.ox88.info/13.htm</span> (67.15.212.150) is using Mal/ObfJS-AP/Exploit:HTML/AdoStream to serve the malware, whereas the domain itself is using DNS servers known to provide service to malicious domains from previous malware embedded attacks that I've been assessing.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Co6eDH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Co6eDH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iLthfH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iLthfH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vqxzZh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vqxzZh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3nLcdh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3nLcdh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vRfuJH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vRfuJH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9ZfcMH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9ZfcMH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=t3YCuh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=t3YCuh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/294860129" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 20 May 2008 22:38:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/whitehouse">whitehouse</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <category domain="http://securityratty.com/tag/malicious domains">malicious domains</category>
      <category domain="http://securityratty.com/tag/original whitehouse">original whitehouse</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/malicious file">malicious file</category>
      <category domain="http://securityratty.com/tag/parody site">parody site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/294860129/whitehouseorg-serving-malware.html">The Whitehouse.org Serving Malware</source>
    </item>
  </channel>
</rss>
