<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: zombie]]></title>
    <link>http://securityratty.com/tag/zombie</link>
    <description></description>
    <pubDate>Thu, 10 Apr 2008 13:50:04 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[MySpace And Facebook Users Targeted By New Worms]]></title>
      <link>http://securityratty.com/article/4d809174d365be423426ff372787f924</link>
      <guid>http://securityratty.com/article/4d809174d365be423426ff372787f924</guid>
      <description><![CDATA[Kaspersky Lab reports two new variants of a worm which attack MySpace and Facebook users. As part of their malicious payload, the worms transform victim machines into zombie computers to form botnets....]]></description>
      <content:encoded><![CDATA[Kaspersky Lab reports two new variants of a worm which attack MySpace and Facebook users. As part of their malicious payload, the worms transform victim machines into zombie computers to form botnets. New worms are labeled as Net-Worm.Win32.Koobface.a. and Net-Worm.Win32.Koobface.b.
Currently the worms are only infecting MySpace and Facebook users but their design allows to upload [...]]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 06:51:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/facebook users">facebook users</category>
      <category domain="http://securityratty.com/tag/myspace">myspace</category>
      <category domain="http://securityratty.com/tag/worms">worms</category>
      <category domain="http://securityratty.com/tag/kaspersky lab reports">kaspersky lab reports</category>
      <category domain="http://securityratty.com/tag/attack myspace">attack myspace</category>
      <category domain="http://securityratty.com/tag/net-worm">net-worm</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <category domain="http://securityratty.com/tag/zombie computers">zombie computers</category>
      <category domain="http://securityratty.com/tag/form botnets">form botnets</category>
      <source url="http://cyberinsecure.com/myspace-and-facebook-users-targeted-by-new-worms/">MySpace And Facebook Users Targeted By New Worms</source>
    </item>
    <item>
      <title><![CDATA[Baby Bubba Finds A New Mummy: A Zombie Children's Book]]></title>
      <link>http://securityratty.com/article/e537279946128bfced9d242bf8a098a3</link>
      <guid>http://securityratty.com/article/e537279946128bfced9d242bf8a098a3</guid>
      <description><![CDATA[Ok, this one is not security related, but those of you who know me know I have a thing for zombie movies. See my LAN Of The Dead article on computer zombies to see what I mean. Pascalle Ballard and I...]]></description>
      <content:encoded><![CDATA[Ok, this one is not security related, but those of you who know me know I have a thing for zombie movies. See my <a href="http://www.irongeek.com/i.php?page=security/computerzombies">LAN Of The Dead article on computer zombies</a> to see what I mean. Pascalle Ballard and I started to work on our own children's book, with a baby zombie as the lead character. Follow the link, I hope you will enjoy it.
<p><a href="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?a=VrH05f"><img src="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?i=VrH05f" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/343176692" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 19:53:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/baby zombie">baby zombie</category>
      <category domain="http://securityratty.com/tag/dead article">dead article</category>
      <category domain="http://securityratty.com/tag/computer zombies">computer zombies</category>
      <category domain="http://securityratty.com/tag/lead character">lead character</category>
      <category domain="http://securityratty.com/tag/pascalle ballard">pascalle ballard</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/zombie movies">zombie movies</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/follow">follow</category>
      <source url="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~3/343176692/baby-bubba">Baby Bubba Finds A New Mummy: A Zombie Children's Book</source>
    </item>
    <item>
      <title><![CDATA[Fast Track to Botnet Central]]></title>
      <link>http://securityratty.com/article/d62636e855a8a6846b44ec6cafe10519</link>
      <guid>http://securityratty.com/article/d62636e855a8a6846b44ec6cafe10519</guid>
      <description><![CDATA[Its true, you too can finally get into the botnet you always wanted. Finally the ability to be a zombie computer under some losers control is yours

Seriously though, becoming a victim to a hacker's...]]></description>
      <content:encoded><![CDATA[
        Its true, you too can finally get into the botnet you always wanted.&nbsp; Finally the ability to be a zombie computer under some losers control is yours!<br /><br />Seriously though, becoming a victim to a hacker's botnet is incredibly easy.&nbsp; These attacks are not typical to other forms of destruction found on the internet.&nbsp; There true intent is usually to remain hidden from view until called upon.&nbsp; In the case of <a href="http://www.spywareguide.com/spydet_31297_fasttrackbot.html">FastTrackBot</a> however there is a new objective.&nbsp; <a href="http://www.spywareguide.com/spydet_31297_fasttrackbot.html">FastTrackBot</a> downloads several executable files that keep your computer clicking on the attacker's affiliate links.&nbsp; These executable files keep the webpages in hidden iexplore.exe windows in order to hide the application from suspicious eyes.&nbsp; If you're using X-cleaner, I suggest you take a look at the Expert Tab.&nbsp; The Show All Hidden Windows function is great for showing you exactly what is open at the time.<br /><br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/fasttrack/replace%20ad.html" onclick="window.open('http://blog.spywareguide.com/fasttrack/replace%20ad.html','popup','width=488,height=332,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/fasttrack/replace%20ad-thumb-488x332.png" alt="replace ad.png" class="mt-image-center" style="margin: 0pt auto 20px; text-align: center; display: block;" width="488" height="332" /></a></span>FastTrackBot phones home to several of these sites in order to keep the user clicks through affiliate links.<br /><br />Aside from creating invisible windows to hog your bandwidth up, it also attempts to install a rogue anti-spyware application.&nbsp; This is a popular technique when attempting to fraud the victim into leaking credit card information when actually attempting to purchase the fake product.&nbsp; FastTrackBot inserts a fake security center that appears identical to the one found in Windows XP.<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/fasttrack/securitycenter.html" onclick="window.open('http://blog.spywareguide.com/fasttrack/securitycenter.html','popup','width=786,height=576,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/fasttrack/securitycenter-thumb-500x366.png" alt="securitycenter.png" class="mt-image-center" style="margin: 0pt auto 20px; text-align: center; display: block;" width="500" height="366" /></a></span>As you can see in the address bar, this is not the actual security center.&nbsp; Clicking anywhere on this window means almost certain doom in the worst way possible...a never ending stream of fake "YOU ARE INFECTED!!!!" alerts.<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/fasttrack/infect.html" onclick="window.open('http://blog.spywareguide.com/fasttrack/infect.html','popup','width=764,height=523,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/fasttrack/infect-thumb-500x342.png" alt="infect.png" class="mt-image-center" style="margin: 0pt auto 20px; text-align: center; display: block;" width="500" height="342" /></a></span><br />In order to kill the actual application, you have to remove it from memory first, then remove its autostart which is found in 5 different locations - or simply remove with our free <a href="http://www.spywareguide.com/onlinescan.php">Microscanner</a>.<br />
        
    ]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 05:41:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fasttrackbot">fasttrackbot</category>
      <category domain="http://securityratty.com/tag/fasttrackbot inserts">fasttrackbot inserts</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/invisible windows">invisible windows</category>
      <category domain="http://securityratty.com/tag/fake">fake</category>
      <category domain="http://securityratty.com/tag/actual application">actual application</category>
      <category domain="http://securityratty.com/tag/fake security center">fake security center</category>
      <category domain="http://securityratty.com/tag/fasttrackbot phones home">fasttrackbot phones home</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <source url="http://blog.spywareguide.com/2008/07/fast-track-to-botnet-central.html">Fast Track to Botnet Central</source>
    </item>
    <item>
      <title><![CDATA[11 Signs That Your SIEM Is A Dog or "Raffy, You Killed SIM!"]]></title>
      <link>http://securityratty.com/article/673e8180fd78aec9c906c77e3732eaf4</link>
      <guid>http://securityratty.com/article/673e8180fd78aec9c906c77e3732eaf4</guid>
      <description><![CDATA[Prerequisite: read this (thanks Raffy). Stop reading right before you reach the last line though :-) Then maybe read this too (thanks anonymous
Next, insert appropriate morbid jokes for &quot; IDS is dead...]]></description>
      <content:encoded><![CDATA[<p>Prerequisite: read <a href="http://blogs.splunk.com/raffy/2008/06/23/security-information-management-sim-is-dead">this</a> (thanks Raffy). Stop reading right before you reach the last line though :-)&nbsp; Then maybe <a href="http://www.prismmicrosys.com/Logtalk/?p=20">read this</a> too (thanks anonymous).</p> <p>Next, insert appropriate morbid jokes &lt;here&gt; for "<a href="http://www.gartner.com/5_about/press_releases/pr11june2003c.jsp">IDS is dead</a>", "<a href="http://www.networkworld.com/community/node/27459">NAC is dead</a>", "<a href="http://securosis.com/2008/05/13/grc-is-dead/">GRC is dead</a>", everybody is dead... WTF? Are we at the cemetery or what? Is "dead" dead? Yeah, but it came back as a zombie :-) So, "dead" is a "living dead" "dead" now. Ha*3.</p> <p>Finally, think! Why were you thinking of buying a SIEM? 'Cause the big "G" in the sky said so? And while you are thinking, check these fun points out:</p> <ol> <li>Does your SIEM require 17 beefy servers to operate? How many gallons of foreign oil have to go up in smoke to power that mammoth up? And you know what happened to mammoths, don't you?  <li>If your "high-performance" SIEM appliance can only run 5 correlation rules at the same time, what "high" do they mean, really? Hold this thought....  <li>Is five field engineers, two developers and CTO enough to install it? Who else needs to help? Ah, sorry, I missed the DBA :-)  <li>Do you know when "If CustomVariable17 = Value5" condition matches? Will you still remember it in a year?  <li>Can you tell "taxonomy" from "ontology"? You can now? Good for you. Are you more secure now? More efficient? Compliant?  <li>How many shifts of security analysts do you have watching the shiny consoles 24/7? If zero, then why - oh - why those consoles are running in the first place? "If a tree falls..." - you know how this one ends. Correct! You get hit by the bough.  <li>When was the last time you built a custom agent for parsing and normalizing, say, SAP logs? Did it work? What did you do after it didn't? Cried? And did it help? Then a burly vendor SE showed up, charged you $37,600 and left? Happy now?  <li>Do you automatically correlate IDS/IPS alerts with vulnerability data ... for client-side attacks? Really? :-)  <li>There are dozens of firewall, IDS/IPS, router, etc brands, each with its own log type. This is actually simple! But there are thousands upon thousands of applications in use today. Some have logs. All are different. Care to build rules for that? Now you <em>finally</em> know why SIEM vendors <em>don't parse their own</em> Java logs (no shit!)  <li>Do you know what "threat x vulnerability x <em>random()</em>" equals to? Yup, it still equals <em>random()</em>. Automated prioritization, you say?  <li>Do you know why some SIEM vendors are migrating to IT GRC now? So they can go and die there ... quietly.</li></ol> <p>All in all, I have to <a href="http://blogs.splunk.com/raffy/2008/06/23/security-information-management-sim-is-dead/#comment-1332">agree with Raffy</a> to a large extent!&nbsp; The world has evolved - and SIEM has not. It might not be dead (as old attacks and defenses never really die and large organization still build and man massive SOCs where SIEM is "a must"), but in this age of web application hacking, CSRF and XSS, phishing, PCI DSS, massive bot armies, client-side 0-days, stealth malware, etc, paying $x,000,000 for a pile of ugly Java code is insane ... As a result, SIEM has greatly diminished in importance and has become just one small thing you might do with logs and some other data. What made it so? Mostly implementation complexity - but a slew of other factors mentioned above as well.</p> <p>So, consider this instead:</p> <ul> <li>Compliance? "Sorry, buddy, you need <a href="http://www.loglogic.com">this</a> for compliance, not <u><a href="http://chuvakin.blogspot.com/search/label/SIEM">that</a></u>. "  <li>Want to simplify your incident response? Get <a href="http://www.loglogic.com">log management</a> and <strong>fly through all your logs</strong>, not <em>crawl through some of them. </em> <li>Have a very real need to dig into your logs for troubleshooting or tracking that pesky user? <a href="http://www.loglogic.com">Log management</a> works.</li></ul> <p>Now, what if you have a latent and vague desire to "correlate something" and a million nice greenbacks to flush down the drain? OK, go get your SIEM toy for $780,000 + 20% maintenance/year ... a true bargain (<em>price valid today only</em>).</p> <p>Finally, I would like to end this on an optimistic note. Do we need more intelligence to analyze the log data we have collected? Of course! Do we have a widest set of log use cases from today's security&nbsp; to tomorrow's regulations? You bet. And, for <a href="http://www.raffy.ch/blog/">you Raffy</a>, I'd add "... we also have other data to analyze together with logs." So, can we "reinvent SIEM?" Yes, I think so! It just hasn't been done yet ... For now, just use <a href="http://www.loglogic.com">log management.</a></p> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:bbd77171-6078-4829-b04e-f71e64e80d0a" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/SIEM" rel="tag">SIEM</a>, <a href="http://technorati.com/tags/SIM" rel="tag">SIM</a>, <a href="http://technorati.com/tags/SEM" rel="tag">SEM</a>, <a href="http://technorati.com/tags/log%20management" rel="tag">log management</a>, <a href="http://technorati.com/tags/humor" rel="tag">humor</a>, <a href="http://technorati.com/tags/security" rel="tag">security</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=1cEN1I"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=1cEN1I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=RRufwI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=RRufwI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=UT0laI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=UT0laI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/320020300" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 10:40:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/siem">siem</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/siem require">siem require</category>
      <category domain="http://securityratty.com/tag/log">log</category>
      <category domain="http://securityratty.com/tag/siem toy">siem toy</category>
      <category domain="http://securityratty.com/tag/reinvent siem">reinvent siem</category>
      <category domain="http://securityratty.com/tag/siem vendors">siem vendors</category>
      <category domain="http://securityratty.com/tag/dead">dead</category>
      <category domain="http://securityratty.com/tag/log type">log type</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/320020300/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or "Raffy, You Killed SIM!"</source>
    </item>
    <item>
      <title><![CDATA[Marshall Islands Email Service Paralysed By Spam Attack]]></title>
      <link>http://securityratty.com/article/3a35dfe75aa92edd2bf1f3ca85aa5afd</link>
      <guid>http://securityratty.com/article/3a35dfe75aa92edd2bf1f3ca85aa5afd</guid>
      <description><![CDATA[Email communication in the Marshall Islands was paralysed Tuesday after hackers launched a zombie computer attack on the western Pacific nations only Internet service provider. The Marshall Islands is...]]></description>
      <content:encoded><![CDATA[Email communication in the Marshall Islands was paralysed Tuesday after hackers launched a &#8220;zombie&#8221; computer attack on the western Pacific nation&#8217;s only Internet service provider. The Marshall Islands is a Micronesian island nation in the western Pacific Ocean, located east of the Federated States of Micronesia and south of the U.S. territory of Wake Island.
The [...]]]></content:encoded>
      <pubDate>Tue, 24 Jun 2008 19:55:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/marshall islands">marshall islands</category>
      <category domain="http://securityratty.com/tag/micronesian island nation">micronesian island nation</category>
      <category domain="http://securityratty.com/tag/island">island</category>
      <category domain="http://securityratty.com/tag/zombie computer attack">zombie computer attack</category>
      <category domain="http://securityratty.com/tag/western pacific ocean">western pacific ocean</category>
      <category domain="http://securityratty.com/tag/western pacific nations">western pacific nations</category>
      <category domain="http://securityratty.com/tag/internet service provider">internet service provider</category>
      <category domain="http://securityratty.com/tag/email communication">email communication</category>
      <category domain="http://securityratty.com/tag/territory">territory</category>
      <source url="http://cyberinsecure.com/marshall-islands-email-service-paralysed-by-spam-attack/">Marshall Islands Email Service Paralysed By Spam Attack</source>
    </item>
    <item>
      <title><![CDATA[Wednesday Zombie PostZombie Reagan]]></title>
      <link>http://securityratty.com/article/307326c14c955721ace7fd5324960cbe</link>
      <guid>http://securityratty.com/article/307326c14c955721ace7fd5324960cbe</guid>
      <description><![CDATA[Longing for the good ol days, Zombie Reagan proposes reincarnating the big guy himself in order to steer conservatism back on track

Bookmark...]]></description>
      <content:encoded><![CDATA[<p style="text-align: left;"> Longing for the good ol&#8217; days, <a href="http://sweasel.com/wp-content/themes/weasel/graphics/zombiereagan.php" target="_blank">Zombie Reagan </a>proposes reincarnating the big guy himself in order to steer conservatism back on track.</p>
<p style="text-align: center;"><img src="http://sweasel.com/wp-content/themes/weasel/graphics/zombiereaganbrains.jpg" alt="Zombie Ronald Reagan" width="160" height="235" /></p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/402&amp;title=Wednesday+Zombie+Post%26%238211%3BZombie+Reagan" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Del.icio.us" alt="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/402&amp;title=Wednesday+Zombie+Post%26%238211%3BZombie+Reagan" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to digg" alt="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/402&amp;title=Wednesday+Zombie+Post%26%238211%3BZombie+Reagan" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to reddit" alt="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Wednesday+Zombie+Post%26%238211%3BZombie+Reagan&amp;url=http://www.guerilla-ciso.com/archives/402&amp;version=0.7" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Feed Me Links" alt="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/402" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Technorati" alt="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/402&amp;t=Wednesday+Zombie+Post%26%238211%3BZombie+Reagan" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Yahoo My Web" alt="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/402&amp;title=Wednesday+Zombie+Post%26%238211%3BZombie+Reagan" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Stumble Upon" alt="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/402&amp;title=Wednesday+Zombie+Post%26%238211%3BZombie+Reagan" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Google Bookmarks" alt="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/402" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Squidoo" alt="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/402" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Bloglines" alt="Add 'Wednesday Zombie Post&#8211;Zombie Reagan' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=GfzuGI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=GfzuGI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=Z5LLTi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=Z5LLTi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/299852381" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 28 May 2008 09:41:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/zombie reagan proposes">zombie reagan proposes</category>
      <category domain="http://securityratty.com/tag/steer conservatism">steer conservatism</category>
      <category domain="http://securityratty.com/tag/bookmark">bookmark</category>
      <category domain="http://securityratty.com/tag/track">track</category>
      <category domain="http://securityratty.com/tag/guy">guy</category>
      <category domain="http://securityratty.com/tag/days">days</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/299852381/402">Wednesday Zombie PostZombie Reagan</source>
    </item>
    <item>
      <title><![CDATA[Wednesday Zombie PostNerd Zombies]]></title>
      <link>http://securityratty.com/article/93c72850d4eba1486c4e951e460dfb43</link>
      <guid>http://securityratty.com/article/93c72850d4eba1486c4e951e460dfb43</guid>
      <description><![CDATA[Fantastic cartoon strip and maybe a future movie at zombiesdontrun.com
If vulcans are driven solely by logic, how come TPol has a boob job
Bookmark...]]></description>
      <content:encoded><![CDATA[<p>Fantastic cartoon strip and maybe a future movie at <a href="http://www.zombiesdontrun.com/" target="_blank">zombiesdontrun.com</a>.</p>
<p style="padding-left: 30px;"><em>&#8220;If vulcans are driven solely by logic, how come T&#8217;Pol has a boob job?&#8221;</em></p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/401&amp;title=Wednesday+Zombie+Post%26%238211%3BNerd+Zombies" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Del.icio.us" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/401&amp;title=Wednesday+Zombie+Post%26%238211%3BNerd+Zombies" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to digg" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/401&amp;title=Wednesday+Zombie+Post%26%238211%3BNerd+Zombies" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to reddit" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Wednesday+Zombie+Post%26%238211%3BNerd+Zombies&amp;url=http://www.guerilla-ciso.com/archives/401&amp;version=0.7" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Feed Me Links" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/401" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Technorati" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/401&amp;t=Wednesday+Zombie+Post%26%238211%3BNerd+Zombies" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Yahoo My Web" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/401&amp;title=Wednesday+Zombie+Post%26%238211%3BNerd+Zombies" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Stumble Upon" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/401&amp;title=Wednesday+Zombie+Post%26%238211%3BNerd+Zombies" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Google Bookmarks" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/401" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Squidoo" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/401" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Bloglines" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=iiab5I"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=iiab5I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=31p1yi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=31p1yi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/295210547" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 21 May 2008 13:49:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fantastic cartoon strip">fantastic cartoon strip</category>
      <category domain="http://securityratty.com/tag/future movie">future movie</category>
      <category domain="http://securityratty.com/tag/boob job">boob job</category>
      <category domain="http://securityratty.com/tag/tpol">tpol</category>
      <category domain="http://securityratty.com/tag/solely">solely</category>
      <category domain="http://securityratty.com/tag/zombiesdontrun">zombiesdontrun</category>
      <category domain="http://securityratty.com/tag/bookmark">bookmark</category>
      <category domain="http://securityratty.com/tag/vulcans">vulcans</category>
      <category domain="http://securityratty.com/tag/logic">logic</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/295210547/401">Wednesday Zombie PostNerd Zombies</source>
    </item>
    <item>
      <title><![CDATA[Air Force Colonel Wants to Build a Military Botnet]]></title>
      <link>http://securityratty.com/article/234d6f8e57720f7a8ddcc2dcba28906e</link>
      <guid>http://securityratty.com/article/234d6f8e57720f7a8ddcc2dcba28906e</guid>
      <description><![CDATA[The U.S. military ponders creating its own zombie army to flood enemies with junk packets. Can Air Force phishing attacks and 4-19 scams be far...]]></description>
      <content:encoded><![CDATA[The U.S. military ponders creating its own zombie army to flood enemies with junk packets. Can Air Force phishing attacks and 4-19 scams be far behind?<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=365313fcb0065722d9a557a5e75a5e47" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=365313fcb0065722d9a557a5e75a5e47" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=otNHyH"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=otNHyH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=RJoysh"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=RJoysh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=8Ht8Ph"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=8Ht8Ph" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=C3GrWH"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=C3GrWH" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=2UCCeH"><img src="http://feeds.wired.com/~f/wired/politics/security?i=2UCCeH" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=xGtTih"><img src="http://feeds.wired.com/~f/wired/politics/security?i=xGtTih" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=PHw5Nh"><img src="http://feeds.wired.com/~f/wired/politics/security?i=PHw5Nh" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=5JFLgH"><img src="http://feeds.wired.com/~f/wired/politics/security?i=5JFLgH" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/288863651" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/288863739" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 12 May 2008 13:30:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/air force">air force</category>
      <category domain="http://securityratty.com/tag/flood enemies">flood enemies</category>
      <category domain="http://securityratty.com/tag/zombie army">zombie army</category>
      <category domain="http://securityratty.com/tag/military ponders">military ponders</category>
      <category domain="http://securityratty.com/tag/junk packets">junk packets</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/scams">scams</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/288863739/air-force-col-w.html">Air Force Colonel Wants to Build a Military Botnet</source>
    </item>
    <item>
      <title><![CDATA[China's CERT Annual Security Report - 2007]]></title>
      <link>http://securityratty.com/article/8eec1b2624eb89fa1310133e71a9abdb</link>
      <guid>http://securityratty.com/article/8eec1b2624eb89fa1310133e71a9abdb</guid>
      <description><![CDATA[Every coin has two sides, and while China has long embraced unrestricted warfare and people's information warfare for conducting cyber espionage, China's networked infrastructure is also under attack,...]]></description>
      <content:encoded><![CDATA[<a href="http://bp3.blogger.com/_wICHhTiQmrA/SAvJARnVfPI/AAAAAAAABlQ/7XmltP8sxhc/s1600-h/CN_CERT_2007.jpg"><img id="BLOGGER_PHOTO_ID_5191464002040200434" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SAvJARnVfPI/AAAAAAAABlQ/7XmltP8sxhc/s200/CN_CERT_2007.jpg" border="0" /></a>Every coin has two sides, and while China has long embraced <a href="http://ddanchev.blogspot.com/2007/12/combating-unrestricted-warfare.html">unrestricted warfare</a> and <a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">people's information warfare</a> for conducting cyber espionage, China's networked infrastructure is also under attack, and is logically used as stepping stone to hit others country's infrastructures, thereby contributing to the possibility to engineer cyber warfare tensions.<br /><br /><div></div>A week ago, <a href="http://www.cert.org.cn/UserFiles/File/CNCERTCC2007AnnualReport_Chinese.pdf">China's CERT released their annual security report</a> (in Chinese for the time being), outlining the local threatscape with data indicating the increasing efficiency applied by Turkish web site defacement groups, in between the logical increases in spam/phishing and malware related incidents. Here's an excerpt from the report :<br /><br /><div>"<em>According CNCERT / CC monitoring found that in 2007 China's mainland are implanted into the host Trojans alarming increase in the number of IP is 22 times last year, the Trojans have become the largest Internet hazards. Underground black mature industrial chain for the production and the large number of Trojans wide dissemination provides a very convenient conditions, Trojan horses on the Internet led to the proliferation of a lot of personal information and the privacy of data theft, to the personal reputation and cause serious economic losses; In addition, the Trojans also increasingly being used to steal state secrets and secrets of the state and enterprises incalculable losses, the Chinese mainland are implanted into the Trojan Horse computer controlled source, the majority in China's Taiwan region, the phenomenon has been brought to the agency's attention. <strong>Zombie network is still the basic network attacks platform means and resources. 2007 CNCERT / CC sampling found to be infected with a zombie monitoring procedures inside and outside the mainframe amounted to 6.23 million, of which China's mainland has 3.62 million IP addresses were implanted zombie mainframe procedures, and more than 10,000 outside the control server to China Host mainland control.</strong> Zombie networks primarily be used launch denial of service (DdoS) attacks, send spam, spread malicious code, as well as theft of the infected host of sensitive information, issued by the zombie network flow, distributed DDOS attack is recognized in the world problems not only seriously affect the operation of the Internet business, but also a serious threat to China's Internet infrastructure in the safe operation. 2007 China's Internet domain name registration and the use of quantitative rapid growth, reaching 11.93 million, an annual growth rate of 190.4 percent, while hackers use of domain names has become a major tool. Use of domain names, the attackers could be flexible, hidden website linked to the implementation of large-scale horse zombie network control, network malicious activities such as counterfeiting. Fast-Flux domain names, such as dynamic analysis technologies, resulting in accordance with the IP to the attacks more difficult to trace and block; 2007 domain names which has been in use analytical services for the existence of security flaws, the public domain analysis of the server domain hijacking security incidents, a large number of users without knowing the circumstances of their fishing lure to the site or sites containing malicious code, such incidents very great danger. Therefore, the strengthening of the management of domain names and domain names analytic system's security protection is very important.</em>"</div><br />6.23 million botnet participating hosts according to their stats, where 3.62 million are Chinese IPs is a great example of how the Chinese Internet infrastructure's getting heavily abused by experienced malware and botnet masters, primarily taking advantage of what's old school social engineering, and outdated malware infection techniques, which undoubtedly will work given China's immature and inexperienced from a security perspective emerging Internet generation.<br /><div><br /></div><div><a href="http://bp1.blogger.com/_wICHhTiQmrA/SAvYUxnVfQI/AAAAAAAABlY/ZVoI70yVk68/s1600-h/chinese_defacer_nationalism.jpg"><img id="BLOGGER_PHOTO_ID_5191480846901935362" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/SAvYUxnVfQI/AAAAAAAABlY/ZVoI70yVk68/s200/chinese_defacer_nationalism.jpg" border="0" /></a>Getting back to the globalization and efficiency of Turkish web site defacement groups' worldwide web application security audit, indicated in the report, according to China's CERT these are the top 10 defacers, where 7 are well known Turkish ones, and 3 are interestingly Chinese :</div><br />sinaritx - 1731 defacements<br /><div>1923turk - 1417 defacements</div>the freedom - 1156 defacements<br /><div>aLpTurkTegin - 1052 defacements</div>Mor0Ccan Islam Defenders Team - 864 defacements<br /><div>iskorpitx - 761 defacements</div>lucifercihan - 525 defacements<br /><br /><div></div>It's also interesting to see pro-democratic Chinese hackers attacking homeland networks.<br /><p><a href="http://bp2.blogger.com/_wICHhTiQmrA/SAvigBnVfRI/AAAAAAAABlg/Gt4kn7d3LN8/s1600-h/anti_cnn_dot_com.jpg"><img id="BLOGGER_PHOTO_ID_5191492035291741458" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/SAvigBnVfRI/AAAAAAAABlg/Gt4kn7d3LN8/s200/anti_cnn_dot_com.jpg" border="0" /></a>Cyber warfare tensions engineering is only starting to take place, and state sponsored or perhaps even tolerated cyber espionage building capabilities in order for the state to later on acquire the already developed resources and capabilities in a cost-effective manner. However, <a href="http://bbs.gliet.edu.cn/bbs/index.php?s=40e077245937853cd6075b3d1cf365f2&amp;showtopic=157692&amp;st=0%EF%BF%BDentry2321659">considering</a> the <a href="http://www.upi.com/International_Security/Emerging_Threats/Analysis/2008/03/24/analysis_cyberattacks_on_tibet_groups/9260/print_view/">recent cyber attacks against "Free Tibet" movements</a>, as well as the <a href="http://asert.arbornetworks.com/2008/04/impending-cnncom-ddos/">DDoS attack attempts at CNN</a> due to <a href="http://www.thedarkvisitor.com/2008/04/breaking-upcoming-chinese-hacker-attack-on-cnn-building-steam/">CNN's coverage of Tibet</a>, Chinese cyber warriors continue demonstrating people's information warfare, and <a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html">Internet PSYOPs</a> by developing an <strong>anti-cnn.com</strong> (121.52.208.243) community, with some catchy altered images from the originals broadcasted worldwide, and with a special section to improve China's image across the world.</p>And logically, there's a <a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html">PSYOPs centered malware</a> released in the wild, a sample of which is basically embedding links to a non-existent domain, descriptive enough to point to <strong>TibetIsAPartOFChina.com</strong> :<br /><br /><p>%\CommonDocuments%\My Music\My Playlists\WWW.cgjSFGrz_TibetIsAPartOFChina.COM<br /></p><p>%CommonDocuments%\My Music\WWW.bimStzno_TibetIsAPartOFChina.COM<br /></p><p>%CommonDocuments%\My Videos\WWW.kUJs_TibetIsAPartOFChina.COM<br /></p><p>%CommonPrograms%\Accessories\Accessibility\WWW.RSulr_TibetIsAPartOFChina.COM<br /></p><p>%CommonPrograms%\Accessories\System Tools\WWW.aEGXBl_TibetIsAPartOFChina.COM</p>Now that's effective digital PSYOPs, isn't it? If you're visionary enough to tolerate the development of underground communities, whereas ensuring their nationalism level remain a priority for anything they do, you end up with a powerful cyber army whose every action perfectly fits with your political and military doctrine, without you even bothering to coordinate their efforts, thereby eliminating the need for a command and control structure.<br /><p>Related posts:</p><a href="http://ddanchev.blogspot.com/2007/09/chinas-cyber-espionage-ambitions.html">China's Cyber Espionage Ambitions</a><br /><a href="http://ddanchev.blogspot.com/2006/09/chinese-hackers-attacking-us.html">Chinese Hackers Attacking U.S Department of Defense Networks</a><br /><a href="http://ddanchev.blogspot.com/2007/12/inside-chinese-underground-economy.html">Inside the Chinese Underground Economy</a><br /><a href="http://ddanchev.blogspot.com/2007/10/chinas-cyber-warriors-video.html">China's Cyber Warriors - Video</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GC5DiiG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GC5DiiG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Vz3Pf1G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Vz3Pf1G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GDo5aKg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GDo5aKg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dETNhLg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dETNhLg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7rxi57G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7rxi57G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZpzUMXG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZpzUMXG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ScAQiNg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ScAQiNg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/274516906" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 20 Apr 2008 22:34:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/china">china</category>
      <category domain="http://securityratty.com/tag/internet infrastructure">internet infrastructure</category>
      <category domain="http://securityratty.com/tag/chinese internet infrastructure">chinese internet infrastructure</category>
      <category domain="http://securityratty.com/tag/chinese">chinese</category>
      <category domain="http://securityratty.com/tag/zombie network flow">zombie network flow</category>
      <category domain="http://securityratty.com/tag/zombie network">zombie network</category>
      <category domain="http://securityratty.com/tag/interestingly chinese">interestingly chinese</category>
      <category domain="http://securityratty.com/tag/infrastructure">infrastructure</category>
      <category domain="http://securityratty.com/tag/chinese underground economy">chinese underground economy</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/274516906/chinas-cert-annual-security-report-2007.html">China's CERT Annual Security Report - 2007</source>
    </item>
    <item>
      <title><![CDATA[Zombie Computers Decried As Imminent National Threat]]></title>
      <link>http://securityratty.com/article/6beecc23e02159a3f965a87e2f2f2b6e</link>
      <guid>http://securityratty.com/article/6beecc23e02159a3f965a87e2f2f2b6e</guid>
      <description><![CDATA[Across the world, thousands of home computers have been conscripted into zombie computer gangs that cyber criminals use to spam, attack and defraud others on the net, causing considerable...]]></description>
      <content:encoded><![CDATA[Across the world, thousands of home computers have been conscripted into zombie computer gangs that cyber criminals use to spam, attack and defraud others on the net, causing considerable consternation to law enforcement and security professionals alike, who count the so-called botnets as the most vexing net threat today.]]></content:encoded>
      <pubDate>Thu, 10 Apr 2008 13:50:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security professionals alike">security professionals alike</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/net threat">net threat</category>
      <category domain="http://securityratty.com/tag/zombie computer gangs">zombie computer gangs</category>
      <category domain="http://securityratty.com/tag/law enforcement">law enforcement</category>
      <category domain="http://securityratty.com/tag/considerable consternation">considerable consternation</category>
      <category domain="http://securityratty.com/tag/home computers">home computers</category>
      <category domain="http://securityratty.com/tag/cyber criminals">cyber criminals</category>
      <category domain="http://securityratty.com/tag/count">count</category>
      <source url="http://digg.com/security/Zombie_Computers_Decried_As_Imminent_National_Threat">Zombie Computers Decried As Imminent National Threat</source>
    </item>
  </channel>
</rss>
