Make it your homepage

Add to favorites

Site map

The Information Security Center portal - all about IT security



Navigation

Microsoft Certified Partner



Subscription to newsletters

Partners


Безопасность для всех

News for 30 July 2008 Year

  • 23:53 Security Bulletin Webcast Questions & Answers
  • Hey everyone,

    This is Jerry Bryant. I am the Business, Operations & Communications Manager on the Security Response Communications team. I am writing to let you know about a new process we are implementing regarding the questions and answers from our monthly security bulletin webcast.

    Attendees to the webcast ask a lot of great questions concerning the security updates we just released and we have many subject matter experts (SMEs) on hand to answer them. In order for the broader community to also benefit from the exchange, we will now be posting the questions and answers here on the MSRC blog. Our goal is to get them here within two days of the webcast.

    To kick things off, we have posted the questions and answers from the June 2008 and July 2008 webcasts:

    http://blogs.technet.com/msrc/pages/microsoft-security-bulletin-webcast-q-a-june-2008.aspx
    http://blogs.technet.com/msrc/pages/microsoft-security-bulletin-webcast-q-a-july-2008.aspx

    We will also maintain an index of the monthly postings here:

    http://blogs.technet.com/msrc/pages/microsoft-security-bulletin-webcast-q-a-index-page.aspx

    So look for a post with the August 2008 Q&A on or around August 15th!

    If you would like to attend the August webcast in person, you can register here:
    http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032374631&Culture=en-US

    You can also view all of our previous webcasts on demand. Just go here to find them:
    http://www.microsoft.com/events/security/ondemand.mspx

    Thanks and I hope you can join us in August!

    Jerry Bryant

    *This posting is provided "AS IS" with no warranties, and confers no rights.*

    >>>

  • 23:23 Beloved websites riddled with crimeware
  • Web 2.0 malware mash-up madness

    Sixty of the 100 most popular websites either hosted malicious content or linked to malicious websites at some point during the first six months of 2008, according to a new study by web security firm Websense.

    >>>

  • 23:20 McAfee SiteAdvisor blocks SANS
  • Showing you just how much they understand about security, McAfee blocked the SANS website, sans.org, as well as giac.org and sans.edu, with their SiteAdvisor application, listing it as a “bad” site. Interestingly enough, SANS sites are some of the best sites to go to for security related news. Several people count on SANS for training on [...]
    >>>

  • 22:36 Off the wire: Despite mandate, only 30% of government devices are encrypted
  • A Government Accountability (GAO) report on the status of government agency efforts to encrypt and protect sensitive information identified commercially available technology, reviewed laws and policie... >>>

  • 22:21 Security World: PhishLock pro-active anti-phishing solution
  • SentryBay has launched PhishLock, a real-time solution which protects users of a companys web site from phishing attacks. PhishLock offers protection in real-time and can operate in the cloud, p... >>>

  • 22:14 Security World: DeepNines wins patent lawsuit against McAfee
  • Deep Nines Inc. announced today that it won its patent infringement lawsuit against competitor McAfee, Inc. On July 15, 2008, a unanimous jury in the Beaumont Division of the United States District Co... >>>

  • 22:10 Security World: Denial of service vulnerability in Firefox 3
  • Radware announced it has found a vulnerability that may cause application Denial of Service (DoS) in Firefox 3, Mozilla's latest Web browser application. Discovered by the vulnerability researc... >>>

  • 21:42 Security World: As credit crunch continues, biometrics bucks the trend
  • Market analysis from ABI research predicts that increased interest and investment in a variety of biometric technologies is set to push total spending to £3.7 billion by 2013, more than double th... >>>

  • 21:39 Security World: "NASA hacker" loses extradition appeal in House of Lords
  • The so-called 'NASA hacker' from North London, is now expected to continue his fight against extradition in the European courts. Today's verdict comes six and a half years after McKinnon was original... >>>

  • 21:28 Security World: First automated DNSSEC signing application
  • Secure64 Software Corporation has developed a product that simplifies the implementation and management of DNSSEC. Secure64 DNS Signer is the first and only product that addresses each of the obstacle... >>>

  • 21:24 Security World: Security for road warriors using Windows
  • CoSoSys released Carry it Easy +Plus 3.0 for portable storage devices. The new software version includes features that focus on increased security, productivity and comfort for users of portable stora... >>>

  • 18:22 Gmail certificate expiry snafu follows security upgrade
  • Webmail service POP losses its fizzle

    Google allowed one of its Gmail SSL certificates to expire days after promising users improved webmail security.

    >>>

  • 18:08 HD Moore pwned with his own DNS exploit, vulnerable AT&T DNS servers to blame
  • A week after |)ruid and HD Moore release part 2 of DNS exploit, HD Moore’s company BreakingPoint has suffered a traffic redirection to a rogue Google site, thanks to the already poisoned cache at AT&T servers to which his company was forwarding DNS traffic : “It happened on Tuesday morning, when Moore’s company, BreakingPoint had some [...]
    >>>

  • 17:33 Security World: Despite mandate, only 30% of government devices are encrypted
  • Committee on Homeland Security Chairman Bennie G. Thompson (D-MS) and Committee Member Zoe Lofgren (D-CA) announced the release of a Government Accountability (GAO) report on the status of government ... >>>

  • 17:30 Off the wire: Skype won't say if it decrypts VoIP calls
  • Company may keep keys so authorities can decrypt encrypted VoIP phone calls. >>>

  • 17:26 OS fingerprinting Apples iPhone 2.0 software - a trivial joke
  • Just like every decent web service out there wanting to identify the iPhone’s mobile Safari browser in order to serve custom applications, in this very same way malicious attackers would like to remotely identify iPhone devices through a basic pen-testing practice known as OS detection or OS fingerprinting. It seems that the difficulty level of [...]
    >>>

  • 17:20 Gary McKinnon worlds most dangerous hacker to be extradited
  • The Guardian, out of the United Kingdom, is reporting that Gary McKinnon, the “world’s most dangerous hacker”, will be extradited to the United States to face criminal hacking charges. McKinnon, a 42 year old unemployed systems administrator from north London, allegedly hacked into systems belonging to the US army, navy, air force, and Nasa [...]
    >>>

  • 13:27 Dissecting a Managed Spamming Service
  • With cybercrime getting easier to outsource these days, and with the overall underground economy's natural maturity from products to services, "managed spamming appliances" and managed spamming services are becoming rather common. Increasingly, these "vendors" are starting to "vertically integrate", namely, start diversifying the portfolio of services they offer in order to steal market share from other "vendors" offering related services like, email database cleaning, segmentation of email databases, email servers or botnets whose hosts have a pre-checked and relatively clean IP reputation, namely they're not blacklisted yet.

    How much does it cost to send 1 million spam emails these days? According to a random spamming service, $100 excluding the discounts based on the speed of sending desired, namely 10-20 per second or 20-30 per second. Let's dissect the service, and emphasize on its key differentiation factors, as well as the customerization offered in the form of a dedicated server if the customer would like to send billions of emails :

    "-- High quality and percentage of spam delivery 
    -- Fast speed of delivery
    -- Spam database on behalf of the vendor, or using your own database of harvested emails
    -- Easily obtainable and segmented spam databases on per country basis
    -- Randomization of the spam email's body and headers in order to achieve a higher delivery rate
    -- Support for attachments, executables, and image files

    The cost - $ 100 million for letters delivered spam, with the large volume of spam discounts 20% -30% -40% based on the value-added Do-it-yourself customer interfare based on a multi-user botnet command and control interface :
     
    -- Automatic RBL verification
    -- Support for many subjects, headers,
    -- Total customization of the email sending process
    -- Autogenerating junk content next to the spammers email/link in order to bypass filtering
    -- Faking Outlook Message ID / Boundary / Content-ID
    -- Interface added. Now do not necessarily understand all the features into the system to start the list.
    -- Convenient management tasks.
    -- A high percentage of punching, on the basis of good europe - 40-60% (For the United States - less because there aol and others).
    -- Improved metrics, whether or not the emails have been sent, lost, unknown receipt, or have been RBL-ed

    With the weight of a billion - even discounts and the possibility of making a personal server. "

    Rather surprising, they state that European email users have a higher probability of receiving the spam message compared the U.S due to AOL. What they're actually trying to say is due to AOL's use of Domain Keys Identified Mail (DKIM). As far as localization of the spam to the email owner's natiave language is concerned, this segmentation concept has been take place for over an year now.

    This service, like the majority of others rely entirely on malware infected hosts, which due to the multi-user nature of most of the malware command and control interfaces, allows them to easily add customers and set their privileges based on the type of service that they purchase. This leaves a countless number of opportunities for targeted spamming, and yes, spear phishing attacks made possible due to the segmentation of the emails based on a country, city, even company.

    In the long term, the people behind spamming providers, web malware exploitation kits and DIY phishing kits, will inevitably start introducing built-in features which were once available through third-party services. For instance, hosting infrastructure for the spam/phishing/live exploit URLs, or even managed fast-flux infrastructure, have the potential to become widely available if such optional features get built-in phishing kits, or start getting offered by the spamming provider itself. And since the affiliate based model seems to be working just fine, the ongoing underground consolidation will converge providers of different underground goods and services, where everyone would be driving customers to one another's services and earning revenue in the process.
    >>>

  • 13:21 Evolution is punctuated equilibria
  • Guest editorial by Dino Dai Zovi In evolutionary biology, the theory of punctuated equilibiria states that evolution is not a gradual process but instead consists of long periods of stasis interrupted by rapid, catastrophic change. This is supported by fossil evidence that shows little variation within a species and new species that appear to come out [...]
    >>>

  • 07:54 Neosploit hack-by-numbers kit euthanized
  • Victim of its own success

    The distributors of Neosploit, one of the most noxious infection kits available on the internet, are retiring the product, citing support costs that didn't justify the expense.

    >>>

  • 04:04 No podcast this week
  • Rich and I are both incredibly busy, trying to get some work done before Black Hat and Defcon start. We’re planning on producing a podcast next week from the showroom floor at BH as well as a few microcasts from the both Black Hat and Defcon. So tune in next week, I promise [...] >>>

  • 03:51 Security World: StealthWatch System 5.8 for increased network visibility
  • Lancope announced the general availability of StealthWatch System 5.8. The system-wide upgrade includes new features that further utilize flow data, including Cisco IOS NetFlow or sFlow, to significan... >>>

  • 03:00 News: Poisoned DNS servers pop up as ISPs patch
  • Poisoned DNS servers pop up as ISPs patch >>>

  • 03:00 Social Engineering
  • Video demonstrating how easy it is to social engineer you way into clubs by pretending you're the DJ.

    >>>

  • 03:00 TSA Proud of Confiscating Non-Dangerous Item
  • This is just sad. The TSA confiscated a battery pack not because it's dangerous, but because other passengers might think its dangerous. And they're proud of the fact.

    "We must treat every suspicious item the same and utilize the tools we have available to make a final determination," said Federal Security Director David Wynn. "Procedures are in place for a reason and this is a clear indication our workforce is doing a great job."

    My guess is that if Kip Hawley were allowed to comment on my blog, he would say something like this: "It's not just bombs that are prohibited; it's things that look like bombs. This looks enough like a bomb to fool the other passengers, and that in itself is a threat."

    Okay, that's fair. But the average person doesn't know what a bomb looks like; all he knows is what he sees on television and the movies. And this rule means that all homemade electronics are confiscated, because anything homemade with wires can look like a bomb to someone who doesn't know better. The rule just doesn't work.

    And in today's passengers-fight-back world, do you think anyone is going to successfully do anything with a fake bomb?

    >>>

  • 01:51 Security World: Cyber threats accelerate and browser vulnerabilities proliferate
  • IBM today released results from its X-Force 2008 Midyear Trend Statistics report that indicates cyber-criminals are adopting new automation techniques and strategies that allow them to exploit vulnera... >>>

  • 01:42 Security World: First database security solution for virtual environments
  • Secerno announced the availability of its award-winning Secerno.SQL database activity monitoring and blocking solution as a virtualised appliance on the Vmware platform. This marks the first availabi... >>>

  • 00:09 Neosploit Team Leaving the IT Underground
  • The Neosploit Team are abandoning support for their Neosploit web exploitation malware kit, citing a negative return on investment as the main reason behind their decision. However, given Neosploit's open source nature just like the majority of web malware kits, and the fact that it's slowly, but surely turning into a commodity malware kit just like MPack and Icepack did, greatly contribute to its extended "product lifecycle" :

    "Lets discuss their business model, how other cybercriminals disintermediated it thereby ruining it, and most importantly, how is it possible that such a popular web malware exploitation kit cannot seem to achieve a positive return on investment (ROI). The short answer is - piracy in the IT underground, and their over-optimistic assumption that high-profit margins can compensate the lack of long-term growth strategy, which in respect to web malware exploitation kits has do with the benefits coming from converging with traffic management tools. Lets discuss some key points."

    The end of Neosploit malware kit, doesn't mean the end of Neosploit Team, or the sudden migration to other malware kits since they're no longer providing support in the form of new obfuscations and set of exploits to their customers. Their customers have been in fact self-servicing their needs enjoying the modular nature of the kit, the result of which is an unknown number of modified Neosploit kits.

    Related posts:
    The Underground Economy's Supply of Goods and Services
    The Dynamics of the Malware Industry - Proprietary Malware Tools 
    Localizing Cybercrime - Cultural Diversity on Demand 
    E-crime and Socioeconomic Factors 
    Localizing Open Source Malware 
    Coding Spyware and Malware for Hire
    The FirePack Exploitation Kit Localized to Chinese
    MPack and IcePack Localized to Chinese
    The Icepack Exploitation Kit Localized to French 
    >>>

MIPS 2010




The latest news

   RSS feed