<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: windows-like]]></title>
    <link>http://securityratty.com/tag/windows-like</link>
    <description></description>
    <pubDate>Tue, 12 Aug 2008 21:14:31 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Microsoft seeds WSUS with Windows 7 Client]]></title>
      <link>http://securityratty.com/article/ef6975d3a7b01a8d5e63a6b844f263f6</link>
      <guid>http://securityratty.com/article/ef6975d3a7b01a8d5e63a6b844f263f6</guid>
      <description><![CDATA[Microsoft adds a reference to Windows 7 Client, its upcoming replacement to Vista, in the product selection screen of Windows Server Update Services, which lets companies feed security updates to...]]></description>
      <content:encoded><![CDATA[Microsoft adds a reference to Windows 7 Client, its upcoming replacement to Vista, in the product selection screen of Windows Server Update Services, which lets companies feed security updates to their machines.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=iHCitR"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=iHCitR" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/370265761" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/windows server">windows server</category>
      <category domain="http://securityratty.com/tag/companies feed security">companies feed security</category>
      <category domain="http://securityratty.com/tag/product selection">product selection</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/client">client</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/vista">vista</category>
      <category domain="http://securityratty.com/tag/machines">machines</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/370265761/article.do">Microsoft seeds WSUS with Windows 7 Client</source>
    </item>
    <item>
      <title><![CDATA[Mac, Windows clipboards poisoned by URL attacks]]></title>
      <link>http://securityratty.com/article/43d63112d7898b8e1b4494611586bcab</link>
      <guid>http://securityratty.com/article/43d63112d7898b8e1b4494611586bcab</guid>
      <description><![CDATA[In what a security researcher called a cunning attack, infected Web ads are poisoning Mac and Windows users' clipboards with URLs designed to trick people into visiting sites touting bogus security...]]></description>
      <content:encoded><![CDATA[In what a security researcher called a cunning attack, infected Web ads are poisoning Mac and Windows users' clipboards with URLs designed to trick people into visiting sites touting bogus security software.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=Y69kEH"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=Y69kEH" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/369315537" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bogus security software">bogus security software</category>
      <category domain="http://securityratty.com/tag/web ads">web ads</category>
      <category domain="http://securityratty.com/tag/windows users">windows users</category>
      <category domain="http://securityratty.com/tag/security researcher">security researcher</category>
      <category domain="http://securityratty.com/tag/clipboards">clipboards</category>
      <category domain="http://securityratty.com/tag/trick people">trick people</category>
      <category domain="http://securityratty.com/tag/mac">mac</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/369315537/article.do">Mac, Windows clipboards poisoned by URL attacks</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Two]]></title>
      <link>http://securityratty.com/article/9d3454e7551fca2a11e4a5ee55704677</link>
      <guid>http://securityratty.com/article/9d3454e7551fca2a11e4a5ee55704677</guid>
      <description><![CDATA[With scammers continuing to introduce new typosquatted domains promoting well known brands of rogue security software that is most often found at the far end of a malware campaign, exposing yet...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SKphU3YsSbI/AAAAAAAACDk/28wApKSrbYA/s1600-h/fake_security_software.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="76" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SKphU3YsSbI/AAAAAAAACDk/bPxU6HdrxA8/s200-R/fake_security_software.JPG" width="200" /></a>With scammers continuing to introduce new typosquatted domains promoting well known brands of rogue security software that is most often found at the far end of a malware campaign, exposing yet another diverse portfolio of last week's introduced domains is what follows.<br />
<br />
Naturally, in between taking advantage of the usual hosting services, most of the domains remain parked at the same IPs, this centralization makes it easier to locate them all, then having to go through several misconfigured malicious doorways that will anyway expose the portfolio.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKpjp46fg4I/AAAAAAAACDs/hW-zlDsLSIg/s1600-h/antivirus_pro_2008.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="160" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKpjp46fg4I/AAAAAAAACDs/mjJJ2yUIcsE/s200-R/antivirus_pro_2008.png" width="200" /></a><b>antivirus2008t-pro .com</b> - (91.203.92.64; 78.157.142.7)<br />
<b>antivirus2008pro-download1 .com<br />
antivirus2008pro-download2 .com<br />
scanner.antivir64 .com<br />
antivirus2008t-pro .com<br />
antivirus-2008y-pro .com</b><br />
<br />
<b>&nbsp;systemscanner2009 .com</b> - (89.18.189.44; 208.88.53.114)<br />
<b>xpdownloadserver .com&nbsp;&nbsp;&nbsp; <br />
global-advers .com<br />
xpantivirus .com&nbsp;&nbsp;&nbsp; <br />
updatesantivirus .com<br />
windows-scannernv .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKpkn-kX73I/AAAAAAAACD0/GOsFiicPQXs/s1600-h/xp_anti_virus.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="160" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKpkn-kX73I/AAAAAAAACD0/AekOVq9ibn0/s200-R/xp_anti_virus.png" width="200" /></a><b>ratemyblog1 .com</b> - 208.88.53.114<br />
<b>windows-scanner2009 .com<br />
systemscanner2009 .com<br />
antivirus-database .com<br />
antivirus2009professional .com<br />
antivirus-2009pro .com<br />
antivirus2009-scanner .com<br />
global-advers .com<br />
drivemedirect .com<br />
windows-scannernv .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKpmSONqTJI/AAAAAAAACEE/4Cukn7sK9ek/s1600-h/fake_IE_7.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="160" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKpmSONqTJI/AAAAAAAACEE/iHExDhLb0z4/s200-R/fake_IE_7.png" width="200" /></a><b>webscweb-scannerfree .com</b> - (58.65.238.106; 208.88.53.180)<br />
<b>freebmwx3 .com<br />
mytube4 .com<br />
beginner2009 .com<br />
webscweb-scannerfree .com<br />
antivirus2009-software .com<br />
antivirus-database .com<br />
purchase-anti .com</b><br />
<br />
<b><br />
onlinescannerxp .com<br />
virus-onlinescanner .com<br />
spywareonlinescanner .com<br />
xponlinescanner .com<br />
virus-securityscanner .com<br />
virus-securityscanner .com<br />
webscannerfreever .com<br />
blazervips .com<br />
global-advers .com<br />
xpantivirus .com&nbsp;&nbsp;&nbsp; <br />
drivemedirect .com<br />
windows-scannernv .com</b><br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKplujVb0XI/AAAAAAAACD8/laUP6HFKiPc/s1600-h/xp_anti_virus2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKplujVb0XI/AAAAAAAACD8/vH2l1Xo0k0Y/s200-R/xp_anti_virus2.png" /></a><b>mytube4 .com</b> - 58.65.238.106<br />
<b>beginner2009 .com<br />
webscweb-scannerfree .com<br />
securityscannerfree .com<br />
xpcleaner-online .com<br />
streamhotvideo .com<br />
xpcleanerpro .com<br />
onlinescannerxp .com<br />
online-xpcleaner .com<br />
antispyguard-scanner .com<br />
virus-onlinescanner .com<br />
microsoft.browsersecuritycenter .com<br />
fastupdateserver .com<br />
blazervips .com<br />
xpantivirus .com<br />
drivemedirect .com<br />
fastwebway .com<br />
xpantivirussecurity .com<br />
wordpress.firm .in<br />
megacodec .biz<br />
mcprivate .biz</b><br />
<br />
<b>internet-defense2009 .com </b>- 84.16.252.73<b><br />
myfreespace3 .com<br />
greatvideo3 .com<br />
internet-defense2009 .com<br />
windows-defense .com<br />
3gigabytes .com<br />
teledisons .com<br />
updatesantivirus .com<br />
update-direct .com<br />
xp-protectsoft .com</b><br />
<br />
<b>top-pc-scanner .com - </b>(91.203.92.50; 92.62.101.43)<b><br />
nortonsoft .com - </b>(91.186.11.5)<b><br />
powerantivirus-2009 .com - (</b>91.208.0.233)<b><br />
powerantivirus2009 .com - </b>(91.208.0.233)<b><br />
pwrantivirus .com - </b>(91.208.0.231)<b><br />
xp-guard .com - </b>(92.62.101.35)<b><br />
xpertantivirus .com - </b>(91.208.0.230)<b><br />
internetscanner2009 .com - </b>(89.149.229.168)<br />
<br />
Where's the business model here? Where it's always been, upon installation of the rogue security software, the malware campaigner earns up to 40% revenue from the rogue security software's vendor.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse Portfolio of Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">Got Your XPShield Up and Running?</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/fake-pestpatrol-security-software.html">Fake PestPatrol Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's Fake Security Software</a><br />
<a href="http://http//ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><br />
<br />
<b></b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=h33YSK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=h33YSK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jVrJfK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jVrJfK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FyAb7k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FyAb7k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1wEuVk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1wEuVk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zeV8HK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zeV8HK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Xb2U2K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Xb2U2K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1JfUGk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1JfUGk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/368786894" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 21:51:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/portfolio">portfolio</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/rogue security software">rogue security software</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/domains remain">domains remain</category>
      <category domain="http://securityratty.com/tag/drivemedirect">drivemedirect</category>
      <category domain="http://securityratty.com/tag/global-advers">global-advers</category>
      <category domain="http://securityratty.com/tag/lazy summer days">lazy summer days</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/368786894/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Two</source>
    </item>
    <item>
      <title><![CDATA[Aussie security company set to be bought by Symantec ]]></title>
      <link>http://securityratty.com/article/53ea99ae1f62dc9f8cbebbf532de0260</link>
      <guid>http://securityratty.com/article/53ea99ae1f62dc9f8cbebbf532de0260</guid>
      <description><![CDATA[Symantec has announced it has signed an agreement to acquire Australian security vendor PC Tools. The privately held PC Tools, which is headquartered in Sydney, has risen to global prominence since...]]></description>
      <content:encoded><![CDATA[Symantec has announced it has signed an agreement to acquire Australian security vendor PC Tools. The privately held PC Tools, which is headquartered in Sydney, has risen to global prominence since hitting the world stage in 2003 with its security and privacy products for Windows-based PCs.]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/global prominence">global prominence</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/privacy products">privacy products</category>
      <category domain="http://securityratty.com/tag/world stage">world stage</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/privately held">privately held</category>
      <category domain="http://securityratty.com/tag/sydney">sydney</category>
      <category domain="http://securityratty.com/tag/pcs">pcs</category>
      <source url="http://www.networkworld.com/news/2008/081908-symantec-buys-pctools.html?fsrc=rss-security">Aussie security company set to be bought by Symantec </source>
    </item>
    <item>
      <title><![CDATA[Mac, Windows clipboards poisoned by URL attacks]]></title>
      <link>http://securityratty.com/article/01e8c93b636ba1aad52bc5733a7c0b33</link>
      <guid>http://securityratty.com/article/01e8c93b636ba1aad52bc5733a7c0b33</guid>
      <description><![CDATA[Infected Web ads are poisoning Mac and Windows users' clipboards with URLs, researchers said Tuesday, in a &quot;very cunning&quot; attack designed to trick people into visiting sites touting bogus security...]]></description>
      <content:encoded><![CDATA[Infected Web ads are poisoning Mac and Windows users' clipboards with URLs, researchers said Tuesday, in a "very cunning" attack designed to trick people into visiting sites touting bogus security software.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=5668?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=5668?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bogus security software">bogus security software</category>
      <category domain="http://securityratty.com/tag/web ads">web ads</category>
      <category domain="http://securityratty.com/tag/windows users">windows users</category>
      <category domain="http://securityratty.com/tag/trick people">trick people</category>
      <category domain="http://securityratty.com/tag/clipboards">clipboards</category>
      <category domain="http://securityratty.com/tag/mac">mac</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <source url="http://www.networkworld.com/news/2008/081908-mac-windows-clipboards-poisoned-by.html?fsrc=rss-security">Mac, Windows clipboards poisoned by URL attacks</source>
    </item>
    <item>
      <title><![CDATA[Microsoft Puts Out 11 Fixes, Pulls Another]]></title>
      <link>http://securityratty.com/article/44120fe698f9ecd13fed0f070d170698</link>
      <guid>http://securityratty.com/article/44120fe698f9ecd13fed0f070d170698</guid>
      <description><![CDATA[Microsoft released its largest batch of security fixes since February 2007: 11 software updates designed to plug 26 holes in Windows, Office and other...]]></description>
      <content:encoded><![CDATA[Microsoft released its largest batch of security fixes since February 2007: 11 software updates designed to plug 26 holes in Windows, Office and other products.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=3mkNQz"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=3mkNQz" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/367767251" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 03:30:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/security fixes">security fixes</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/holes">holes</category>
      <category domain="http://securityratty.com/tag/office">office</category>
      <category domain="http://securityratty.com/tag/plug">plug</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/batch">batch</category>
      <category domain="http://securityratty.com/tag/february">february</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/367767251/article.do">Microsoft Puts Out 11 Fixes, Pulls Another</source>
    </item>
    <item>
      <title><![CDATA[Zero-day Microsoft Windows NSlookup.exe Vulnerability Exploited In The Wild]]></title>
      <link>http://securityratty.com/article/611a4500bae5305083aff35d9565bcf9</link>
      <guid>http://securityratty.com/article/611a4500bae5305083aff35d9565bcf9</guid>
      <description><![CDATA[According to SecurityFocus, a new public zero-day Windows vulnerability is being exploited in the wild. Microsoft Windows is prone to a remote code-execution vulnerability due to an unspecified error...]]></description>
      <content:encoded><![CDATA[According to SecurityFocus, a new public zero-day Windows vulnerability is being exploited in the wild. Microsoft Windows is prone to a remote code-execution vulnerability due to an unspecified error in &#8216;NSlookup.exe&#8217;. Successfully exploiting this issue would allow the attacker to execute arbitrary code on an affected computer. Failed attacks will cause denial-of-service conditions. Microsoft Windows [...]]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 19:07:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/microsoft windows">microsoft windows</category>
      <category domain="http://securityratty.com/tag/execute arbitrary code">execute arbitrary code</category>
      <category domain="http://securityratty.com/tag/wild">wild</category>
      <category domain="http://securityratty.com/tag/nslookup">nslookup</category>
      <category domain="http://securityratty.com/tag/exe">exe</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/prone">prone</category>
      <category domain="http://securityratty.com/tag/issue">issue</category>
      <category domain="http://securityratty.com/tag/error">error</category>
      <source url="http://cyberinsecure.com/zero-day-microsoft-windows-nslookupexe-vulnerability-exploited-in-the-wild/">Zero-day Microsoft Windows NSlookup.exe Vulnerability Exploited In The Wild</source>
    </item>
    <item>
      <title><![CDATA[Follow Windows 7 Engineering]]></title>
      <link>http://securityratty.com/article/00030fea89f556b799e34f490dcb2463</link>
      <guid>http://securityratty.com/article/00030fea89f556b799e34f490dcb2463</guid>
      <description><![CDATA[Seeking to promote &quot;an open and honest, and two-way, discussion about how we balance all of these interests and deliver software on the scale of Windows,&quot; Microsoft has launched the Engineering...]]></description>
      <content:encoded><![CDATA[Seeking to promote "an open and honest, and two-way, discussion about how we balance all of these interests and deliver software on the scale of Windows," Microsoft has launched the <a href="http://blogs.msdn.com/e7/default.aspx" target="_blank">Engineering Windows 7 blog,</a> hosted by two senior Microsoft stars, <A href="http://www.microsoft.com/presspass/exec/devaan/" target="_blank">Jon DeVaan</A> and <A href="http://www.microsoft.com/presspass/exec/ssinofsky/" target="_blank">Steven Sinofsky.</A>

A two-way discussion probably doesn't mean they are taking orders for features, but they will listen to concerns of the technical community and respond to them publicly. They specifically ask for topic suggestions (I've already sent one in). Not too many years ago this sort of thing was unthinkable at Microsoft, but it's been moving steadily in this direction.<img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/vAz-9017J-0" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 16:54:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/senior microsoft stars">senior microsoft stars</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/two-way discussion">two-way discussion</category>
      <category domain="http://securityratty.com/tag/discussion">discussion</category>
      <category domain="http://securityratty.com/tag/two-way">two-way</category>
      <category domain="http://securityratty.com/tag/topic suggestions">topic suggestions</category>
      <category domain="http://securityratty.com/tag/jon devaan">jon devaan</category>
      <category domain="http://securityratty.com/tag/deliver software">deliver software</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/vAz-9017J-0/follow_windows_7_engineering.html">Follow Windows 7 Engineering</source>
    </item>
    <item>
      <title><![CDATA[Security is bigger than finding and fixing bugs]]></title>
      <link>http://securityratty.com/article/9c8ebf47be004fc532a7e7de3eceed48</link>
      <guid>http://securityratty.com/article/9c8ebf47be004fc532a7e7de3eceed48</guid>
      <description><![CDATA[Ive been catching up on various security-related articles that Ive been meaning to read, and the following article was on the list...]]></description>
      <content:encoded><![CDATA[<P>I’ve been catching up on various security-related articles that I’ve been meaning to read, and the following article was on the list <A href="http://www.itnews.com.au/News/73635,google-shares-its-security-secrets.aspx">http://www.itnews.com.au/News/73635,google-shares-its-security-secrets.aspx</A> about Google’s “security secrets.” <BR>&nbsp;<BR>Quoting from the article: </P>
<BLOCKQUOTE>
<P>“In order to keep its products safe, Google has adopted a philosophy of 'security as a cultural value'. The programme includes mandatory security training for developers, a set of in-house security libraries, and code reviews both by Google developers and outside security researchers."</P></BLOCKQUOTE>
<P>I think it is great that Google has a security program they are willing to talk about and I could not agree more with the ‘security as a cultural value’ philosophy. But isn’t there something really fundamental missing here? Design? There is a lot more to software engineering other than coding and testing. <BR>&nbsp;<BR>The SDL has a very large set of implementation-related requirements, but there are many design-related requirements also.</P>
<P>Computer security experts have known since the early 1970s that you have to get the design right; and our experiences with the SDL over the last 5 years have taught us that you need to consider security and privacy (but remember, you have to ship too!) very early in the design phase and have a consistent end-to-end process if you truly hope to reduce vulnerabilities and create more secure software. This is how the SDL is helping to create ‘security as a cultural value’ at Microsoft. </P>
<P>We’ve seen a general trend downward in security vulnerabilities in Microsoft products, and the IBM X-Force 2008 mid-year <A href="http://www-935.ibm.com/services/us/iss/xforce/midyearreport/xforce-midyear-report-2008.pdf" mce_href="http://www-935.ibm.com/services/us/iss/xforce/midyearreport/xforce-midyear-report-2008.pdf">report</A> backs the assertion that we’re making progress; according to the report Microsoft’s share of total vulnerabilities decreased from 3.7% in 2007 (1st place) to 2.5% (that’s 2.5% for <STRONG><U>all</U></STRONG> Microsoft products; a more appropriate comparison might be Windows vs Linux vs Mac OSX, or SQL Server vs Oracle vs DB2) in the first 6 months of 2008 (3rd place.) This is an encouraging signal that the SDL is working on a large scale… of course, it might also show that vulnerability researchers are moving to easier targets, which, to me shows the SDL is working too.<BR>&nbsp;<BR>What do you think?<BR></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8867829" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 16:09:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/security vulnerabilities">security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/computer security experts">computer security experts</category>
      <category domain="http://securityratty.com/tag/googles security secrets">googles security secrets</category>
      <category domain="http://securityratty.com/tag/in-house security libraries">in-house security libraries</category>
      <category domain="http://securityratty.com/tag/security program">security program</category>
      <category domain="http://securityratty.com/tag/microsoft products">microsoft products</category>
      <category domain="http://securityratty.com/tag/sdl">sdl</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/08/14/security-is-bigger-than-finding-and-fixing-bugs.aspx">Security is bigger than finding and fixing bugs</source>
    </item>
    <item>
      <title><![CDATA[Hotmail users need to read this ASAP]]></title>
      <link>http://securityratty.com/article/c77e7e8a6d72ff922a69171ab8eb908b</link>
      <guid>http://securityratty.com/article/c77e7e8a6d72ff922a69171ab8eb908b</guid>
      <description><![CDATA[Read this post and dont fall for it folks


clipped from www.nirmaltv.com
Windows Live Hotmail Accounts Phishing Scam- Users Beware


A new phishing scam on Windows Live Hotmail Account is in progress...]]></description>
      <content:encoded><![CDATA[<div > Read this post and dont fall for it folks. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/9EB0ED21-4992-4896-A5F3-D9AC326A20F5/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/4e22c8a3-11b7-4b64-a652-6cb5a85c2c9a/9EB0ED21-4992-4896-A5F3-D9AC326A20F5/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.nirmaltv.com/2008/08/12/windows-live-hotmail-accounts-phishing-scam-users-beware/" href="http://www.nirmaltv.com/2008/08/12/windows-live-hotmail-accounts-phishing-scam-users-beware/" style="font-size: 11px;">www.nirmaltv.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.nirmaltv.com/2008/08/12/windows-live-hotmail-accounts-phishing-scam-users-beware/ --><H2 class="post-title"><A title="Windows Live Hotmail Accounts Phishing Scam- Users Beware" href="http://www.nirmaltv.com/2008/08/12/windows-live-hotmail-accounts-phishing-scam-users-beware/">Windows Live Hotmail Accounts Phishing Scam- Users Beware</A></H2></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.nirmaltv.com/2008/08/12/windows-live-hotmail-accounts-phishing-scam-users-beware/ --><P>A new <STRONG>phishing scam on Windows Live Hotmail Account</STRONG> is in progress and all users are warned by Microsoft not to respond to this mail. The phishing mail sent from @hotmail says that its from Hotmail team and asks users to verify the Hotmail account. Microsoft says that this phishing scam is intended to hijack accounts. <A href="#" class="kLink"  id="KonaLink0"><FONT color="#1359ae"><SPAN class="kLink">Emails</SPAN></FONT></A> with the subject “Hotmail Warning (Verify Your Hotmail Account Now to Avoid it Closed)” are not generated by Microsoft, and are just designed to fool unsuspecting users into handing over their sensitive data to attackers.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/9EB0ED21-4992-4896-A5F3-D9AC326A20F5/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 21:14:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hotmail">hotmail</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/subject hotmail">subject hotmail</category>
      <category domain="http://securityratty.com/tag/scam">scam</category>
      <category domain="http://securityratty.com/tag/scam- users beware">scam- users beware</category>
      <category domain="http://securityratty.com/tag/hotmail team">hotmail team</category>
      <category domain="http://securityratty.com/tag/hotmail account">hotmail account</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/hijack accounts">hijack accounts</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=554">Hotmail users need to read this ASAP</source>
    </item>
  </channel>
</rss>
