<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: worm]]></title>
    <link>http://securityratty.com/tag/worm</link>
    <description></description>
    <pubDate>Mon, 25 Aug 2008 05:57:04 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Managed Fast Flux Provider - Part Two]]></title>
      <link>http://securityratty.com/article/210da9c1b19bf76a539ca28b24edc989</link>
      <guid>http://securityratty.com/article/210da9c1b19bf76a539ca28b24edc989</guid>
      <description><![CDATA[We're slowly entering into a stage where RBN bullet proof hosting franchises are vertically integrating, and due to the requests from their customers are starting to offer that they refer to as...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQymgVga0I/AAAAAAAACOw/geleqRWDOE0/s1600-h/pharma_spam_fastflux.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQymgVga0I/AAAAAAAACOw/8PTQr8G6mBM/s200-R/pharma_spam_fastflux.png" /></a>We're slowly entering into a stage where <a href="http://ddanchev.blogspot.com/2008/09/estdomains-and-intercage-vs-cybercrime.html">RBN bullet proof hosting franchises</a> are vertically integrating, and due to the requests from their customers are starting to offer that they refer to as "mirrored hosting" which in practice is plain simple fast flux network consisting of RBN-alike purchased netblocks, and naturally, botnet infected hosts.<br />
<br />
Managed fast-fluxing is only starting to go mainstream, for instance, in July I found evidence that <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">money mule recruiters were using ASProx's infected hosts as hosting infrastructure</a>, and in November, 2007, <a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">an infamous spamming software vendor</a> was also found to have been offering fast-flux services in the past.<br />
<br />
In this most recent fast-flux service, we have a known spammer and botnet master that in between self-serving himself on is way to ensure his portfolio of scammy domains remains online for a "little longer", is commercializing fast-fluxing and is offered a DIY service :<br />
<br />
"<i>Finally after hardwork and great appreciation from our normal bullet proof  hosting/server clients we are able to launch Mirrored hosting. What is </i><i>Mirrored hosting</i><i> ?</i><br />
<i><br />
================<br />
</i><i>Mirrored hosting</i><i> is a powerful mirrored  web hosting management, uses multiple Virtual servers to host  website with 100% uptime. </i><i>Mirrored hosting </i><i>is a combination of two things, which  are:<br />
<br />
1. Specially Designed Virtual Servers</i><br />
<i> 2. Powerful  Automated Control Panel</i><br />
<br />
<i>How does it work ?<br />
===============&nbsp;</i><br />
<br />
<i>Mirrored hosting</i><i> uses specially configured Virtual Servers making them link with the </i><i>Mirrored hosting</i><i> Control Panel  which is then controlled by our own control panel allowing us to provide smooth  streamline hosting with no downtime. No one is able to trace original IP of the  server or the place where the files are hosted so the websites/domains hosted  have a 100% Uptime. This is achieved by unique customisation of our Virtual Servers.<br />
<br />
<b>Actually, it takes ips around the world and our  powerful control panel just rotates the ips every 15 minutes. though all these  ips you will see will be fake no one can trace the orignal ip where files are  hosted. Sometimes the ip is from China, Korea, USA, UK, Japan, Lithuania etc.</b></i>"<br />
<br />
The concept has always been there for cybercriminals to take advantage of, but once it matures into a managed service it would undoubtedly lower down the entry barriers allowing yesterday's average phishers to take advantage of what only the "pros" were used to.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AO71M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AO71M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xZIrM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xZIrM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZGgOm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZGgOm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=e7OAm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=e7OAm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BVPbM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BVPbM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iS1HM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iS1HM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iQOUm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iQOUm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/409475392" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 08:39:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/recent fast-flux service">recent fast-flux service</category>
      <category domain="http://securityratty.com/tag/powerful control panel">powerful control panel</category>
      <category domain="http://securityratty.com/tag/control panel">control panel</category>
      <category domain="http://securityratty.com/tag/virtual servers">virtual servers</category>
      <category domain="http://securityratty.com/tag/multiple virtual servers">multiple virtual servers</category>
      <category domain="http://securityratty.com/tag/fast flux spam">fast flux spam</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/409475392/managed-fast-flux-provider-part-two.html">Managed Fast Flux Provider - Part Two</source>
    </item>
    <item>
      <title><![CDATA[Malware Uses GDI Local Elevation Of Privilege Vulnerability To Install Untraceable Rootkit]]></title>
      <link>http://securityratty.com/article/d74e545fb09b155ee87d48f1387e9bf5</link>
      <guid>http://securityratty.com/article/d74e545fb09b155ee87d48f1387e9bf5</guid>
      <description><![CDATA[Security researchers from F-Secure have discovered one of the most subtle and sophisticated examples of Windows rootkit software known to date. The AutoRun-NOX worm extends the standard VXer trick of...]]></description>
      <content:encoded><![CDATA[Security researchers from F-Secure have discovered one of the most subtle and sophisticated examples of Windows rootkit software known to date. The AutoRun-NOX worm extends the standard VXer trick of using software vulnerabilities to infect systems, by including functionality that allows the worm to exploit Windows security bugs to hook into parts of the Windows [...]]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 18:46:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows rootkit software">windows rootkit software</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/autorun-nox worm extends">autorun-nox worm extends</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <category domain="http://securityratty.com/tag/standard vxer trick">standard vxer trick</category>
      <category domain="http://securityratty.com/tag/software vulnerabilities">software vulnerabilities</category>
      <category domain="http://securityratty.com/tag/infect systems">infect systems</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/hook">hook</category>
      <source url="http://cyberinsecure.com/malware-uses-gdi-local-elevation-of-privilege-vulnerability-to-install-untraceable-rootkit/">Malware Uses GDI Local Elevation Of Privilege Vulnerability To Install Untraceable Rootkit</source>
    </item>
    <item>
      <title><![CDATA[EstDomains & Intercage: A Perfect Couple in Crime]]></title>
      <link>http://securityratty.com/article/8490240982532919695d5c4c9231e15f</link>
      <guid>http://securityratty.com/article/8490240982532919695d5c4c9231e15f</guid>
      <description><![CDATA[If you track malware issues as readily as I do, you're likely aware of the failings of clownpacks like EstDomains and their hosting buddies Atrivo/Intercage. You need only follow Sunbelt's take on the...]]></description>
      <content:encoded><![CDATA[If you track malware issues as readily as I do, you're likely aware of the failings of clownpacks like EstDomains and their hosting buddies Atrivo/Intercage. You need only follow Sunbelt's <a href="http://www.google.com/search?hl=en&q=site%3Asunbeltblog.blogspot.com+estdomains+atrivo+intercage&btnG=Search" target="_blank">take</a> on the topic, or <a href="http://www.emergingthreats.net/index.php?searchword=intercage&option=com_search&Itemid=5" target="_blank">search</a> Emergingthreats to come up to speed.<br />Yesterday, EstDomains posted the most inept, ridiculous <a href="http://www.domainnews.com/en/general/estdomains-denies-links-to-malware-distribution.html" target="_blank">response</a> ever issued to the endless and worthy criticism, largely <a href="http://technewsreview.com.au/article.php?article=5882" target="_blank">leveled</a> by Brian Krebs at the Washington Post. <br />Not only can't these morons from EstDomains write, they're either so deeply clueless or flagrantly malicious (likely both), it's beyond laughable. This section sums it up best:<br /><span style="font-style:italic;">"The company also has a reliable ally in its battle against malware in a face of Intercage, Inc which provides company with the hosting services of the highest quality. But the outstanding performance of hosting services is not the sole reason why EstDomains, Inc appreciates this partnership so greatly. Intercage, Inc generously provides EstDomains, Inc specialists with reports regarding discovered malware vehicles. As the main database for additional domain name management services is located in Intercage Data Center, EstDomains, Inc has the perfect opportunity to get notifications of the slightest mark of malware presence in the shortest time and take measures in advance."</span><br /><span style="font-weight:bold;">What? Really?</span> <br />Again, aside from the absolute butchery of the language, did they just say <span style="font-style:italic;">"The company also has a reliable ally in its battle against malware in a face of Intercage, Inc which provides company with the hosting services of the highest quality."</span>? SIGH...yes, they did.<br /><br />Allow me to exemplify just how ridiculous a claim that is.<br />Following is content from a packet capture I took during a recent Storm worm analysis.<br /><br />Using the ip2asn module included in <a href="http://writequit.org/projects/nsm-console/" target="_blank">NSM-console</a> availabe in <a href="http://www.rawpacket.org/projects/hex" target="_blank">HeX</a>, we find:<br />27595   | 216.255.189.211  | INTERCAGE - InterCage, Inc.<br /><br />Using Etherape, also included in <a href="http://www.rawpacket.org/projects/hex" target="_blank">HeX</a>, we see:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SM880rNW5JI/AAAAAAAAACs/dWY8MUgSMUU/s1600-h/etherape_intercage.png"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SM880rNW5JI/AAAAAAAAACs/dWY8MUgSMUU/s320/etherape_intercage.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5246478966559532178" /></a><br /><br />Using <a href="http://networkminer.wiki.sourceforge.net/NetworkMiner" target="_blank">Eric Hjelmvik's</a> <a href="http://holisticinfosec.org/toolsmith/docs/august2008.pdf" target="_blank">NetworkMiner</a>, we see:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_kVOWaY1TAF0/SM8-JQvlEKI/AAAAAAAAAC0/vjYvpHAoFDw/s1600-h/NetworMiner_intercage.png"><img style="cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_kVOWaY1TAF0/SM8-JQvlEKI/AAAAAAAAAC0/vjYvpHAoFDw/s320/NetworMiner_intercage.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5246480419744190626" /></a><br /><br />See the recurring theme? Intercage, EstDomain's <span style="font-style:italic;">"reliable ally in its battle against malware"</span>.<br />Nice work, guys...keep it up.<br /><br />I'm submitting this to <a href="http://thedailywtf.com/" target="blank">The Daily WTF</a> as we speak.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html&title=EstDomains%20&%20Intercage:%20A%20Perfect%20Couple%20in%20Crime " title="EstDomains & Intercage: A Perfect Couple in Crime ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html" title="EstDomains & Intercage: A Perfect Couple in Crime ">digg</a>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 17:32:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/intercage">intercage</category>
      <category domain="http://securityratty.com/tag/estdomains">estdomains</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware presence">malware presence</category>
      <category domain="http://securityratty.com/tag/intercage data center">intercage data center</category>
      <category domain="http://securityratty.com/tag/track malware issues">track malware issues</category>
      <category domain="http://securityratty.com/tag/reliable ally">reliable ally</category>
      <category domain="http://securityratty.com/tag/management services">management services</category>
      <category domain="http://securityratty.com/tag/malware vehicles">malware vehicles</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html">EstDomains &amp; Intercage: A Perfect Couple in Crime</source>
    </item>
    <item>
      <title><![CDATA[Malware Infects Space Station Laptop]]></title>
      <link>http://securityratty.com/article/70eeae7eeabcdc69d20b928bbb4f4b56</link>
      <guid>http://securityratty.com/article/70eeae7eeabcdc69d20b928bbb4f4b56</guid>
      <description><![CDATA[NASA has confirmed that malware has managed to get aboard the International Space Station and that it's not the first time a worm has been discovered on space station...]]></description>
      <content:encoded><![CDATA[NASA has confirmed that malware has managed to get aboard the International Space Station and that it's not the first time a worm has been discovered on space station computers.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=M60rkU"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=M60rkU" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/380148447" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 01 Sep 2008 03:33:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/space station computers">space station computers</category>
      <category domain="http://securityratty.com/tag/international space station">international space station</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/nasa">nasa</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/aboard">aboard</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/380148447/article.do">Malware Infects Space Station Laptop</source>
    </item>
    <item>
      <title><![CDATA[Computer Worm Infects International Space Station Laptops]]></title>
      <link>http://securityratty.com/article/3aa31f809eee6f5bc755729eabd5ba31</link>
      <guid>http://securityratty.com/article/3aa31f809eee6f5bc755729eabd5ba31</guid>
      <description><![CDATA[NASA has confirmed that a computer worm that steals passwords managed to finds its way into laptops aboard the International Space Station. It is not the first time a NASA computer has become...]]></description>
      <content:encoded><![CDATA[NASA has confirmed that a computer worm that steals passwords managed to finds its way into laptops aboard the International Space Station. It is not the first time a NASA computer has become infected.
SpaceReg.com identified the infection as W32.TGammima.AG, a worm that spreads by copying itself to removable media devices. Once in place, it steals [...]]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 12:10:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/international space station">international space station</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <category domain="http://securityratty.com/tag/computer worm">computer worm</category>
      <category domain="http://securityratty.com/tag/removable media devices">removable media devices</category>
      <category domain="http://securityratty.com/tag/nasa">nasa</category>
      <category domain="http://securityratty.com/tag/nasa computer">nasa computer</category>
      <category domain="http://securityratty.com/tag/steals">steals</category>
      <category domain="http://securityratty.com/tag/steals passwords">steals passwords</category>
      <category domain="http://securityratty.com/tag/laptops aboard">laptops aboard</category>
      <source url="http://cyberinsecure.com/computer-worm-infects-international-space-station-laptops/">Computer Worm Infects International Space Station Laptops</source>
    </item>
    <item>
      <title><![CDATA[Virus Infects the Space Station]]></title>
      <link>http://securityratty.com/article/be6e0f1492d31de6c800d92e920c6489</link>
      <guid>http://securityratty.com/article/be6e0f1492d31de6c800d92e920c6489</guid>
      <description><![CDATA[Laptops aboard the International Space Station have been infected with the W32.Gammima.AG worm. And it's not the first time this sort of thing has...]]></description>
      <content:encoded><![CDATA[<p>Laptops aboard the International Space Station <a href="http://www.spaceref.com/news/viewnews.html?id=1305">have</a> <a href="http://blog.wired.com/27bstroke6/2008/08/virus-infects-s.html">been</a> <a href="http://news.bbc.co.uk/2/hi/technology/7583805.stm">infected</a> with the W32.Gammima.AG worm.  And it's not the first time this sort of thing has happened.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=mdla2K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=mdla2K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=a00rvK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=a00rvK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 09:27:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/international space station">international space station</category>
      <category domain="http://securityratty.com/tag/laptops aboard">laptops aboard</category>
      <category domain="http://securityratty.com/tag/sort">sort</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/gammima">gammima</category>
      <category domain="http://securityratty.com/tag/w32">w32</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/virus_infects_t.html">Virus Infects the Space Station</source>
    </item>
    <item>
      <title><![CDATA[Malware infects space station laptops]]></title>
      <link>http://securityratty.com/article/aeff2468dc20c1ddc70d74b79b272123</link>
      <guid>http://securityratty.com/article/aeff2468dc20c1ddc70d74b79b272123</guid>
      <description><![CDATA[Malware has managed to get onto the International Space Station, NASA confirmed today. And it's not the first time that a worm or virus has made it into...]]></description>
      <content:encoded><![CDATA[Malware has managed to get onto the International Space Station, NASA confirmed today. And it's not the first time that a worm or virus has made it into space.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=b2SKbR"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=b2SKbR" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/376461962" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/space">space</category>
      <category domain="http://securityratty.com/tag/international space station">international space station</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/nasa">nasa</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/virus">virus</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/376461962/article.do">Malware infects space station laptops</source>
    </item>
    <item>
      <title><![CDATA[NASA infected with W32.TGammima.AG ]]></title>
      <link>http://securityratty.com/article/65c9e1c56e2e178d8e0cb128b63a0a9e</link>
      <guid>http://securityratty.com/article/65c9e1c56e2e178d8e0cb128b63a0a9e</guid>
      <description><![CDATA[A computer worm that ferrets out passwords managed to stow away on laptops aboard the International Space Station, NASA has confirmed. It is not the first time a NASA computer has become...]]></description>
      <content:encoded><![CDATA[A computer worm that ferrets out passwords managed to stow away on laptops aboard the International Space Station, NASA has confirmed. It is not the first time a NASA computer has become infected.]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 08:26:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nasa">nasa</category>
      <category domain="http://securityratty.com/tag/nasa computer">nasa computer</category>
      <category domain="http://securityratty.com/tag/international space station">international space station</category>
      <category domain="http://securityratty.com/tag/laptops aboard">laptops aboard</category>
      <category domain="http://securityratty.com/tag/computer worm">computer worm</category>
      <category domain="http://securityratty.com/tag/stow">stow</category>
      <category domain="http://securityratty.com/tag/passwords">passwords</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/ferrets">ferrets</category>
      <source url="http://digg.com/security/NASA_infected_with_W32_TGammima_AG">NASA infected with W32.TGammima.AG </source>
    </item>
    <item>
      <title><![CDATA[Malware infects space station laptops]]></title>
      <link>http://securityratty.com/article/c816674897f23b2e910b47176601f05b</link>
      <guid>http://securityratty.com/article/c816674897f23b2e910b47176601f05b</guid>
      <description><![CDATA[Malware has managed to get off the planet and onto the International Space Station, NASA confirmed today. And it's not the first time that a worm or virus has stowed away on a trip into...]]></description>
      <content:encoded><![CDATA[Malware has managed to get off the planet and onto the International Space Station, NASA confirmed today. And it's not the first time that a worm or virus has stowed away on a trip into orbit.]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/international space station">international space station</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/nasa">nasa</category>
      <category domain="http://securityratty.com/tag/trip">trip</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/virus">virus</category>
      <category domain="http://securityratty.com/tag/orbit">orbit</category>
      <category domain="http://securityratty.com/tag/planet">planet</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <source url="http://www.networkworld.com/news/2008/082708-malware-infects-space-station.html?fsrc=rss-security">Malware infects space station laptops</source>
    </item>
    <item>
      <title><![CDATA[Facebook Worm Still Going Strong]]></title>
      <link>http://securityratty.com/article/3d63cb5f4654a97b393266f752d1c56a</link>
      <guid>http://securityratty.com/article/3d63cb5f4654a97b393266f752d1c56a</guid>
      <description><![CDATA[A colleague of mine had a private message sent to them on Facebook yesterday from the account of a friend. The message is related (of course) to the recent Facebook worm





Click the link, and...]]></description>
      <content:encoded><![CDATA[
        A colleague of mine had a private message sent to them on Facebook yesterday from the account of a friend. The message is related (of course) to the recent <a href="http://blogs.pcmag.com/securitywatch/2008/08/facebook_worm_spreads_rapidly.php">Facebook worm</a>:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fbspam1.jpg" src="http://blog.spywareguide.com/images/fbspam1.jpg" class="mt-image-none" style="" height="304" width="413" /></span></div><br /> <div><br />Click the link, and you'll see something like this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fbspam2.html" onclick="window.open('http://blog.spywareguide.com/images/fbspam2.html','popup','width=700,height=510,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fbspam2-thumb-300x218.jpg" alt="fbspam2.jpg" class="mt-image-none" style="" height="218" width="300" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />Yes, it's Ye Olde Fake Codec installer, hosted on what appears to be a hacked website. As always, pay close attention to what you're being sent from your friends. If it doesn't <i>seem</i> like something they'd send you, that's probably because they didn't...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 05:57:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/recent facebook worm">recent facebook worm</category>
      <category domain="http://securityratty.com/tag/close attention">close attention</category>
      <category domain="http://securityratty.com/tag/message">message</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/facebook yesterday">facebook yesterday</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/friend">friend</category>
      <category domain="http://securityratty.com/tag/website">website</category>
      <category domain="http://securityratty.com/tag/friends">friends</category>
      <source url="http://blog.spywareguide.com/2008/08/facebook-worm-still-going-stro.html">Facebook Worm Still Going Strong</source>
    </item>
  </channel>
</rss>
