<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: xmas]]></title>
    <link>http://securityratty.com/tag/xmas</link>
    <description></description>
    <pubDate>Mon, 24 Dec 2007 15:33:57 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[I want one Santa!]]></title>
      <link>http://securityratty.com/article/89d3ee7c6d80bf5c5d00de224adad33b</link>
      <guid>http://securityratty.com/article/89d3ee7c6d80bf5c5d00de224adad33b</guid>
      <description><![CDATA[Add this to your Xmas wish list. You know I did


clipped from web.mit.edu
The WARCART


Warcarting : when
wardriving, warwalking, warflying, warrocketing, warballooning, warbiking, and
warboating are...]]></description>
      <content:encoded><![CDATA[<div > Add this to your Xmas wish list. You know I did. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/26EEAD84-A085-4F60-8194-8F9D84548627/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/65438bb1-2cb3-4c8e-a9b9-8df0f1c3502a/26EEAD84-A085-4F60-8194-8F9D84548627/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://web.mit.edu/zacka/www/warcart.html" href="http://web.mit.edu/zacka/www/warcart.html" style="font-size: 11px;">web.mit.edu</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://web.mit.edu/zacka/www/warcart.html --><FONT size="7" face="Georgia">The WARCART</FONT></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://web.mit.edu/zacka/www/warcart.html --><P align="center"><B><FONT size="4" face="Arial">&#8220;<I>Warcarting</I>: when<br />
wardriving, warwalking, warflying, warrocketing, warballooning, warbiking, and<br />
warboating are just not good enough.&#8221;</FONT></B></P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://web.mit.edu/zacka/www/warcart.html --><FONT size="4" face="Arial">&#8220;You&#8217;ve been wardriving, but<br />
have you ever gone <I>warcarting</I>?&#8221;</FONT></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://web.mit.edu/zacka/www/warcart.html --><FONT size="4" face="Arial">&#8220;<I>Warcarting</I>: because<br />
wardriving is so 2000, and warflying is so 2002.&#8221;</FONT></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://web.mit.edu/zacka/www/warcart.html --><FONT size="4" face="Arial">&#8220;<I>Warcarting</I>: the hobo&#8217;s<br />
approach to wireless communications interception.&#8221;</FONT></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://web.mit.edu/zacka/www/warcart.html --><FONT size="4" face="Arial">&#8220;<I>Warcarting</I>: wardriving on a<br />
budget&#8221;</FONT></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/26EEAD84-A085-4F60-8194-8F9D84548627/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 14:10:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wireless communications interception">wireless communications interception</category>
      <category domain="http://securityratty.com/tag/hobos">hobos</category>
      <category domain="http://securityratty.com/tag/xmas">xmas</category>
      <category domain="http://securityratty.com/tag/budget">budget</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/warcart">warcart</category>
      <category domain="http://securityratty.com/tag/approach">approach</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/mit">mit</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=534">I want one Santa!</source>
    </item>
    <item>
      <title><![CDATA[The New Media Malware Gang - Part Two]]></title>
      <link>http://securityratty.com/article/c279dc531962fb0c454b3951d45b3649</link>
      <guid>http://securityratty.com/article/c279dc531962fb0c454b3951d45b3649</guid>
      <description><![CDATA[How you would you go for ruining the Xmas holidays of a malware gang directly related to the RBN, Storm Worm, Possiblity Media's malware attack, and the malware embedded at the Syrian Embassy's web...]]></description>
      <content:encoded><![CDATA[<a href="http://bp3.blogger.com/_wICHhTiQmrA/R3WKqj8-MnI/AAAAAAAABSw/9FrQmDwhpb4/s1600-h/mcgruff_cybercrime.jpg"><img id="BLOGGER_PHOTO_ID_5149174212778144370" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/R3WKqj8-MnI/AAAAAAAABSw/9FrQmDwhpb4/s200/mcgruff_cybercrime.jpg" border="0" /></a>How you would you go for ruining the Xmas holidays of <a href="http://ddanchev.blogspot.com/2007/12/have-your-malware-in-timely-fashion.html">a malware gang</a> directly related to the RBN, Storm Worm, Possiblity Media's malware attack, and the malware embedded at the Syrian Embassy's web site, the way they've ruined the holidays for lots of security folks out there? You disclose all of their publicly known and currently active "online properties", <a href="http://www.google.com/safebrowsing/report_badware/">submit them to Stopbadware</a>, then see how they reply with a <strong>"Die();"</strong> message on one of their IPs (<strong>85.255.116.206</strong>), which is instantly confirming the positive ROI of your actions. The <a href="http://ddanchev.blogspot.com/2007/11/new-media-malware-gang.html">New Media Malware</a> gang currently operates the following domains/IPs :<br /><br /><strong>flashupdate.net/images/index.php</strong><br /><strong>taktomi.ru/NewYear/ad</strong><br /><strong>l0calh0st.jino-net.ru/tds3</strong><br /><strong>jkh-novgorod.ru/wstat/adpack/</strong><br /><strong>natural-amber.com/spl2/index.php</strong><br /><strong>s0s1.net/mp3/index.php</strong><br /><strong>trffc.org/in.cgi?default</strong><br /><strong>home-xxx.com/shaven/index.shtml</strong><br /><strong>85.255.116.206/ax2/load.php</strong><br /><strong>testers.x5x.ru/subpage/index.php</strong><br /><strong>traffurl.ru/sliv/?91956802f6fabf</strong><br /><strong>88.255.94.250/ddd/index.php</strong><br /><strong>91.192.105.6/images</strong><br /><strong>r52.juhost.ru/ip/index.php</strong><br /><strong>orentraff.cn/tdsslam/index.php?out=1193100109</strong><br /><strong>xll-g.com/beaty/13389babe/cumoninn.com.html</strong><br /><strong>xmaturelife.com/0419/kim5.html</strong><br /><strong>e-learningcenter.ru/eng/index_files/input000.htm</strong><br /><strong>apnea.health-hack.com/old/index.php</strong><br /><strong>milk0soft.com/ipck/index.php</strong><br /><strong>85.255.116.206/ax3/loadj947.php</strong><br /><strong>85.255.116.206/ax2/tet.php</strong><br /><strong>85.255.116.206/ax3/tet.php</strong><br /><strong>spl.vip-ddos.org</strong><br /><strong>spl.vip-ddos.org/index.php</strong><br /><br /><a href="http://bp3.blogger.com/_wICHhTiQmrA/R3WMDj8-MoI/AAAAAAAABS4/BFbpUSgASbQ/s1600-h/newmedia_malware_gang.jpg"><img id="BLOGGER_PHOTO_ID_5149175741786501762" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/R3WMDj8-MoI/AAAAAAAABS4/BFbpUSgASbQ/s200/newmedia_malware_gang.jpg" border="0" /></a>Now go migrate your "infrastructure" on the 31st of December. Happy holidays to you too!<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZgOHpcC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZgOHpcC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=g39aaAC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=g39aaAC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=63sNmFc"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=63sNmFc" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=J3ZL6ac"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=J3ZL6ac" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zGmLwYC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zGmLwYC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PDQUZlC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PDQUZlC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kQossqc"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kQossqc" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/207793505" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 28 Dec 2007 15:17:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/malware gang directly">malware gang directly</category>
      <category domain="http://securityratty.com/tag/media malware gang">media malware gang</category>
      <category domain="http://securityratty.com/tag/malware attack">malware attack</category>
      <category domain="http://securityratty.com/tag/holidays">holidays</category>
      <category domain="http://securityratty.com/tag/happy holidays">happy holidays</category>
      <category domain="http://securityratty.com/tag/xmas holidays">xmas holidays</category>
      <category domain="http://securityratty.com/tag/spl">spl</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/207793505/new-media-malware-gang-part-two.html">The New Media Malware Gang - Part Two</source>
    </item>
    <item>
      <title><![CDATA[Spreading Malware Around the Christmas Tree]]></title>
      <link>http://securityratty.com/article/4907dd75af563bd69ecce94a73eb7766</link>
      <guid>http://securityratty.com/article/4907dd75af563bd69ecce94a73eb7766</guid>
      <description><![CDATA[Stormy Wormy is back in the game on the top of Xmas eve, enticing the end users with a special Xmas strip show for those who dare to download the binary. The domain merrychristmasdude.com is logically...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/R3BKyD8-MgI/AAAAAAAABR4/EUZ4T35i3U8/s1600-h/stormworm_xmas_2007.jpg"><img id="BLOGGER_PHOTO_ID_5147696597999432194" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/R3BKyD8-MgI/AAAAAAAABR4/EUZ4T35i3U8/s200/stormworm_xmas_2007.jpg" border="0" /></a>Stormy Wormy is back in the game on the top of Xmas eve, enticing the end users with a special Xmas strip show for those who dare to download the binary. The domain <strong>merrychristmasdude.com</strong> is logically in a fast-flux, here are some more details :<br /><br />Administrative, Technical Contact<br />Contact Name: John A Cortas<br />Contact Organization: John A Cortas<br />Contact Street1: Green st 322, fl.10<br />Contact City: Toronto<br />Contact Postal Code: 12345<br />Contact Country: CA<br />Contact Phone: +1 435 2312633<br />Contact E-mail: cortas2008 @ yahoo.com<br /><br /><a href="http://bp2.blogger.com/_wICHhTiQmrA/R3BLYj8-MhI/AAAAAAAABSA/As1NaO7ksgU/s1600-h/storm_xmas_dude.png"><img id="BLOGGER_PHOTO_ID_5147697259424395794" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/R3BLYj8-MhI/AAAAAAAABSA/As1NaO7ksgU/s200/storm_xmas_dude.png" border="0" /></a>Name Server: <strong>NS.MERRYCHRISTMASDUDE.COM</strong><br />Name Server: <strong>NS10.MERRYCHRISTMASDUDE.COM</strong><br />Name Server: <strong>NS13.MERRYCHRISTMASDUDE.COM</strong><br />Name Server: <strong>NS9.MERRYCHRISTMASDUDE.COM</strong><br />Name Server: <strong>NS11.MERRYCHRISTMASDUDE.COM</strong><br />Name Server: <strong>NS3.MERRYCHRISTMASDUDE.COM</strong><br />Name Server: <strong>NS4.MERRYCHRISTMASDUDE.COM</strong><br />Name Server: <strong>NS6.MERRYCHRISTMASDUDE.COM</strong><br />Name Server: <strong>NS2.MERRYCHRISTMASDUDE.COM</strong><br />Name Server: <strong>NS5.MERRYCHRISTMASDUDE.COM</strong><br />Name Server: <strong>NS7.MERRYCHRISTMASDUDE.COM</strong><br />Name Server: <strong>NS8.MERRYCHRISTMASDUDE.COM</strong><br />Name Server: <strong>NS12.MERRYCHRISTMASDUDE.COM</strong><br /><br />The domain also has an embedded IFRAME pointing to <strong>merrychristmasdude.com/cgi-bin/in.cgi?p=100</strong> where two javascipt obfuscations, courtesy of the Neosploit attack kit attempt to load. Current binary (stripshow.exe) has an over 50% detection rate 17/32 (53.13%). Stay tuned, AV vendors will reach another milestone on the number of malware variants detected, <a href="http://ddanchev.blogspot.com/2007/02/storm-worm-switching-propagation.html">despite</a> that <a href="http://ddanchev.blogspot.com/2007/01/social-engineering-and-malware.html">compared</a> to <a href="http://ddanchev.blogspot.com/2007/08/storm-worm-malware-back-in-game.html">the real</a>, massive <a href="http://ddanchev.blogspot.com/2007/08/storm-worms-use-of-dropped-domains.html">Storm</a> Worm <a href="http://ddanchev.blogspot.com/2007/08/offensive-storm-worm-obfuscation.html">campaign</a> this <a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">one is</a> fairly <a href="http://ddanchev.blogspot.com/2007/09/storm-worms-ddos-attitude.html">easy to</a> prevent <a href="http://ddanchev.blogspot.com/2007/09/storm-worms-ddos-attitude-part-two.html">on a</a> large <a href="http://ddanchev.blogspot.com/2007/11/detecting-and-blocking-russian-business.html">scale</a>.<br /><br />Related info - <a href="http://isc.sans.org/diary.php?storyid=3778">SANS</a>, <a href="http://asert.arbornetworks.com/2007/12/storm-is-back-dude/">ASERT</a>, <a href="http://temerc.blogspot.com/2007/12/merry-x-mas-storm-worm.html">TEMERC</a>, <a href="http://www.disog.org/2007/12/stormworm-is-back-have-merry-christmas.html">DISOG</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=eDGaoaC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=eDGaoaC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qfNXBsC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qfNXBsC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ErAkWvc"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ErAkWvc" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=06nV8Lc"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=06nV8Lc" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ehzZkSC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ehzZkSC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=yw0t7cC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=yw0t7cC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pIkLa1c"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pIkLa1c" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/205853896" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 24 Dec 2007 15:33:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/contact">contact</category>
      <category domain="http://securityratty.com/tag/contact postal code">contact postal code</category>
      <category domain="http://securityratty.com/tag/technical contact">technical contact</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/contact organization">contact organization</category>
      <category domain="http://securityratty.com/tag/contact city">contact city</category>
      <category domain="http://securityratty.com/tag/contact country">contact country</category>
      <category domain="http://securityratty.com/tag/contact street1">contact street1</category>
      <category domain="http://securityratty.com/tag/contact phone">contact phone</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/205853896/spreading-malware-around-christmas-tree.html">Spreading Malware Around the Christmas Tree</source>
    </item>
  </channel>
</rss>
