<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: native]]></title>
    <link>http://www.securityratty.com/tag/native</link>
    <description></description>
    <pubDate>Wed, 30 Jul 2008 01:32:44 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Army Contractor Charged With Murder]]></title>
      <link>http://www.securityratty.com/article/76c64ef50ea5bc73ec5c4b9fffcdc2a2</link>
      <guid>http://www.securityratty.com/article/76c64ef50ea5bc73ec5c4b9fffcdc2a2</guid>
      <description><![CDATA[A member of the Army's controversial combat anthropology program is accused of second-degree murder for killing Kandahar native Abdul Salam in Afghanistan. Don Ayala supposedly shot the Afghani...]]></description>
      <content:encoded><![CDATA[A member of the Army's controversial combat anthropology program is accused of second-degree murder for killing Kandahar native Abdul Salam in Afghanistan. Don Ayala supposedly shot the Afghani villager in the head, after Salam set one of Ayala's Human Terrain Team co-workers on fire.<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=1a5179f9e0bb2e0e5ae2b8e030916e75&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=1a5179f9e0bb2e0e5ae2b8e030916e75&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=1a5179f9e0bb2e0e5ae2b8e030916e75" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=3pWgN"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=3pWgN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=lz7Hn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=lz7Hn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=A7Jdn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=A7Jdn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=fgXvN"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=fgXvN" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=qZoJN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=qZoJN" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=JPxan"><img src="http://feeds.wired.com/~f/wired/politics/security?i=JPxan" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=dwDXn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=dwDXn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Wm5vN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Wm5vN" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/459979488" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/459979496" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 02:29:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/ayala supposedly shot">ayala supposedly shot</category>
      <category domain="http://www.securityratty.com/tag/ayala">ayala</category>
      <category domain="http://www.securityratty.com/tag/salam set">salam set</category>
      <category domain="http://www.securityratty.com/tag/army">army</category>
      <category domain="http://www.securityratty.com/tag/afghani villager">afghani villager</category>
      <category domain="http://www.securityratty.com/tag/second-degree murder">second-degree murder</category>
      <category domain="http://www.securityratty.com/tag/head">head</category>
      <category domain="http://www.securityratty.com/tag/afghanistan">afghanistan</category>
      <category domain="http://www.securityratty.com/tag/fire">fire</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/459979496/hts-murder.html">Army Contractor Charged With Murder</source>
    </item>
    <item>
      <title><![CDATA[Security Runtime Engine]]></title>
      <link>http://www.securityratty.com/article/fe29603f1c8ad78d47c5f02cc2e3afba</link>
      <guid>http://www.securityratty.com/article/fe29603f1c8ad78d47c5f02cc2e3afba</guid>
      <description><![CDATA[Today we posted some preview details about a .NET security runtime engine we have been working on that overloads encoding methods in the .NET framework. Its pretty cool, running at near native speed!...]]></description>
      <content:encoded><![CDATA[Today we posted some preview details about a .NET security runtime engine we have been working on that overloads encoding methods in the .NET framework. It&#8217;s pretty cool, running at near native speed!
http://blogs.msdn.com/cisg
&#160;&#160;&#160;&#160;&#160;&#160;     ]]></content:encoded>
      <pubDate>Fri, 24 Oct 2008 04:25:57 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/preview details">preview details</category>
      <category domain="http://www.securityratty.com/tag/pretty cool">pretty cool</category>
      <category domain="http://www.securityratty.com/tag/net framework">net framework</category>
      <category domain="http://www.securityratty.com/tag/native speed">native speed</category>
      <category domain="http://www.securityratty.com/tag/blogs">blogs</category>
      <category domain="http://www.securityratty.com/tag/overloads">overloads</category>
      <category domain="http://www.securityratty.com/tag/msdn">msdn</category>
      <category domain="http://www.securityratty.com/tag/methods">methods</category>
      <category domain="http://www.securityratty.com/tag/comcisg">comcisg</category>
      <source url="http://securitybuddha.com/2008/10/24/security-runtime-engine/">Security Runtime Engine</source>
    </item>
    <item>
      <title><![CDATA[The Commercialization of Anti Debugging Tactics in Malware]]></title>
      <link>http://www.securityratty.com/article/91955d7bc08228b99c0f5fa478c039b5</link>
      <guid>http://www.securityratty.com/article/91955d7bc08228b99c0f5fa478c039b5</guid>
      <description><![CDATA[Commoditization or commercialization, Themida or Code Virtualizer, individually crypting or outsourcing to an experienced malware crypting service offering discounts on a volume basis next to...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SN0BFks8GsI/AAAAAAAACMQ/J_vLiffz110/s1600-h/figure_multiple.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="128" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SN0BFks8GsI/AAAAAAAACMQ/bz624nz5JbE/s200-R/figure_multiple.jpg" width="200" /></a><a href="http://ddanchev.blogspot.com/2008/09/commoditization-of-anti-debugging.html">Commoditization</a> or commercialization, Themida or Code Virtualizer, individually crypting or outsourcing to an experienced malware crypting service offering discounts on a volume basis next to detection rates of the crypted binary offered by a trusted online scanner that is NOT distributing the samples to the vendors? These are just some of the questions malware authors often ask themselves, while others distribute pirated copies of Code Virtualizer urging everyone to start taking advantage of commercial anti-reverse engineering tools to make their malware harder to analyze. Once again, just like we've seen before, a legitimate commercial application can come handy in the hands of the wrong people :<br />
<br />
"<i>Code Virtualizer will convert your original code (Intel x86 instructions) into Virtual Opcodes that will only be understood by an internal Virtual Machine. Those Virtual Opcodes and the Virtual Machine itself are unique for every protected application, avoiding a general attack over Code Virtualizer. Code Virtualizer can protect your sensitive code areas in any x32 and x64 native PE files (like executable files/EXEs, system services, DLLs , OCXs , ActiveX controls, screen savers and device drivers).</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SN0CPwG9MzI/AAAAAAAACMY/lB8WtKqycj4/s1600-h/cvprotopt.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="149" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SN0CPwG9MzI/AAAAAAAACMY/kgSYpWIHW2E/s200-R/cvprotopt.png" width="200" /></a><i>Code Virtualizer can generate multiple types of virtual machines with a different instruction set for each one. This means that a specific block of Intel x86 instructions can be converted into different instruction set for each machine, preventing an attacker from recognizing any generated virtual opcode after the transformation from x86 instructions. The following picture represents how a block of Intel x86 instructions is converted into different kinds of virtual opcodes, which could be emulated by different virtual machines.</i><br />
<br />
<i>When an attacker tries to decompile a block of code that was protected by Code Virtualizer, he will not find the original x86 instructions. Instead, he will find a completely new instruction set which is not recognized by him or any other special decompiler. This will force the attacker to go through the extremely hard work of identifying how each opcode is executed and how the specific virtual machine works for each protected application. Code Virtualizer totally obfuscates the execution of the virtual opcodes and the study of each unique virtual machine in order to prevent someone from studying how the virtual opcodes are executed.</i>"<br />
<br />
With Cyber-as-a-Service business model becoming increasingly common, the entire <a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">quality assurance model in respect to malware</a> is slowly maturing from individual malware crypting propositions, where the seller of the service is basically taking advantage of a diverse set of public/private tools, into DIY web services offering crypting discounts on a volume basis, and perhaps most importantly - improving the customer's experience by letting him take advantage of the inventory of crypting tools and bypassing verification services. Within the tool's inventory are naturally lots of (pirated) commercial anti-reverse engineering tools.<br />
<br />
As we've seen before, whenever someone starts commercializing what used to be a self-selving process, others will either follow, or disintermediate their services by persistently releasing crypting tools for free in the wild. At the end of the day, it's all a matter of how serious they're about commercializing this market segment, and taking into consideration that a spamming vendor is offering malware crypting services "in between" the rest of the services in their portfolio, this underground cash cow is yet to prove itself in the long term.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wJDSL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wJDSL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QoCNL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QoCNL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=e4uxl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=e4uxl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sXqbl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sXqbl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=khiOL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=khiOL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2cQ2L"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2cQ2L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HiSTl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HiSTl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/406651187" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 12:55:54 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/machine">machine</category>
      <category domain="http://www.securityratty.com/tag/specific virtual machine">specific virtual machine</category>
      <category domain="http://www.securityratty.com/tag/internal virtual machine">internal virtual machine</category>
      <category domain="http://www.securityratty.com/tag/code">code</category>
      <category domain="http://www.securityratty.com/tag/sensitive code">sensitive code</category>
      <category domain="http://www.securityratty.com/tag/malware">malware</category>
      <category domain="http://www.securityratty.com/tag/unique virtual machine">unique virtual machine</category>
      <category domain="http://www.securityratty.com/tag/original code">original code</category>
      <category domain="http://www.securityratty.com/tag/code virtualizer">code virtualizer</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/406651187/commercialization-of-anti-debugging.html">The Commercialization of Anti Debugging Tactics in Malware</source>
    </item>
    <item>
      <title><![CDATA[250k of Harvested Hotmail Emails Go For?]]></title>
      <link>http://www.securityratty.com/article/efaf965e7dacf43f06479ec7778d04e6</link>
      <guid>http://www.securityratty.com/article/efaf965e7dacf43f06479ec7778d04e6</guid>
      <description><![CDATA[50 in this particular case, however, keeping in mind that the email harvester is anything but ethical, this very same database will be sold and re-sold more times than the original buyer would like to...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SNuLDFWiz9I/AAAAAAAACLo/fQ_TqPImTk0/s1600-h/harvested_hotmail_sale.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="113" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SNuLDFWiz9I/AAAAAAAACLo/YJqc75ZUQgE/s200-R/harvested_hotmail_sale.png" width="200" /></a>$50 in this particular case, however, keeping in mind that the email harvester is anything but ethical, this very same database will be sold and re-sold more times than the original buyer would like to know about. Moreover, what someone is offering for sale, may in fact be already available as a value-added addition to a managed spamming service.<br />
<br />
With metrics and quality assurance applied in a growing number of spam and phishing campaigns, filling in the niche of email harvesting by distinguishing between different types of obfuscated emails by releasing an easily embeddable module, was an anticipated move. What's to come? <a href="http://ddanchev.blogspot.com/2008/05/harvesting-youtube-usernames-for.html">Spam and malware campaigns across social networks</a> "as usual" will propagate faster thanks to the ongoing harvesting of usernames within social networks, that would later on get imported in Web 2.0 "marketing" tools targeting the high-trafficked sites and automatically spamming them.<br />
<br />
From a spammer's perspective, geolocating these 250k emails could increase their selling prices since the buyers would be able to launch localized attacks with messages in the native languages of the receipts. Is the demand for quality email databases fueling the developments of this market segment, or are the spammers self-serving themselves and cashing-in by reselling what they've already abused a log time ago? That seems to be the case, since there's no way a buyer could verify the freshness of the harvested emails database and whether or not it has already been abused. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SNvGk2eGKcI/AAAAAAAACL4/yhy61idSl6I/s1600-h/segmented_harvested_emails.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="200" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SNvGk2eGKcI/AAAAAAAACL4/xFYzYTCaDes/s200-R/segmented_harvested_emails.JPG" width="152" /></a>For the time being, we've got several developed and many other developing market segments within spamming and phishing as different markets with different players. On one hand are the legitimately looking spamming providers offering "direct marketing services" working with lone spammers who find a reliable business partner in the face of the spamming vendor whose customers drive both side's business models. On the other hand, you've got the <a href="http://blogs.zdnet.com/security/?p=1835">spammers excelling in outsourcing the automatic account registration process</a>, coming up with ways to build a spamming infrastructure -- already available as a module to integrate in <a href="http://blogs.zdnet.com/security/?p=1899">managed spamming services</a> -- using legitimate services as a provider of the infrastructure.<br />
<br />
Despite that the arms race seems to be going on at several different fronts, spammers VS the industry and spammers VS spammers fighting for market share, the entire underground ecosystem is clearly allocating a lot of resources for research and development in order to ensure that they are always a step ahead of the industry.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/05/harvesting-youtube-usernames-for.html">Harvesting  Youtube Usernames for Spamming</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2007/10/thousands-of-im-screen-names-in-wild.html">Thousands  of IM Screen Names in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/automatic-email-harvesting-20.html">Automatic  Email Harvesting 2.0</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - the Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2007/01/inside-email-harvesters-configuration.html">Inside an Email Harvester's Configuration File</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/segmenting-and-localizing-spam.html">Segmenting and Localizing Spam Campaigns</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample.html">Shots from the Malicious Wild West - Sample Four</a><br />
<b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=De2zL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=De2zL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CYcFL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CYcFL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OQPDl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OQPDl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Lhexl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Lhexl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sZRFL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sZRFL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ifNGL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ifNGL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BYibl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BYibl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/402968423" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 08:13:08 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/emails">emails</category>
      <category domain="http://www.securityratty.com/tag/email">email</category>
      <category domain="http://www.securityratty.com/tag/email harvester">email harvester</category>
      <category domain="http://www.securityratty.com/tag/spam campaigns">spam campaigns</category>
      <category domain="http://www.securityratty.com/tag/spam">spam</category>
      <category domain="http://www.securityratty.com/tag/lone spammers">lone spammers</category>
      <category domain="http://www.securityratty.com/tag/spammers">spammers</category>
      <category domain="http://www.securityratty.com/tag/250k emails">250k emails</category>
      <category domain="http://www.securityratty.com/tag/automatic email">automatic email</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/402968423/250k-of-harvested-hotmail-emails-go-for.html">250k of Harvested Hotmail Emails Go For?</source>
    </item>
    <item>
      <title><![CDATA[Skype Spamming Tool in the Wild - Part Two]]></title>
      <link>http://www.securityratty.com/article/2f4b287e34b2a08136f91837e197028e</link>
      <guid>http://www.securityratty.com/article/2f4b287e34b2a08136f91837e197028e</guid>
      <description><![CDATA[The less technologically sophisticated lone cybercriminals have always enjoyed the benefits of stand alone DIY applications. From DIY exploit embedding tools in a Cybercrime 1.0 world , maturing to...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SMqdKYNwv9I/AAAAAAAACKE/hHcsAQOFSi8/s1600-h/skype_spamming_tool_02.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SMqdKYNwv9I/AAAAAAAACKE/sy6IR6q_hyE/s200-R/skype_spamming_tool_02.jpg" /></a>The less technologically sophisticated lone cybercriminals have always enjoyed the benefits of stand alone DIY applications. From <a href="http://ddanchev.blogspot.com/2007/09/diy-exploits-embedding-tools.html">DIY exploit embedding tools</a> in a <a href="http://ddanchev.blogspot.com/2008/04/diy-exploit-embedding-tool-proprietary.html">Cybercrime 1.0 world</a>, maturing to today's <a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">web malware exploitation kits</a> and their <a href="http://ddanchev.blogspot.com/2008/09/copycat-web-malware-exploitation-kits.html">copycat alternatives</a>, to plain simple spamming tools that matured into <a href="http://blogs.zdnet.com/security/?p=1899">today's managed spamming services</a> already starting to offer spamming services beyond email, stand alone spamming applications remain pretty popular.<br />
<br />
With yet another <a href="http://ddanchev.blogspot.com/2008/04/skype-spamming-tool-in-wild.html">Skype spamming tool</a> released in the wild, which just like the previous one I discussed a couple of months relies on Skype's support for wildcast searches, and is spamming with authorization request messages until the user adds the contact, malicious parties seems to be more interested into supplying the desired services, than emphasizing on the quality assurance process.<br />
<br />
Despite the possibilities for localized targeted attacks delivering messages with malicious URLs into the user's native language, benchmarking this tool's features next to the ones offered by certain bots taking advantage of social engineering by spamming the infected host's contacts, is positioning it far behind even the most primitive IM spreading bot modules, whose extra layer of social engineering personalization makes their IM malware campaigns much more effective ones.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/05/harvesting-youtube-usernames-for.html">Harvesting Youtube Usernames for Spamming</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/uncovering-msn-social-engineering-scam.html">Uncovering a MSN Social Engineering Scam</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/msn-spamming-bot.html">MSN Spamming Bot</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/diy-fake-msn-client-stealing-passwords.html">DIY Fake MSN Client Stealing Passwords</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/thousands-of-im-screen-names-in-wild.html">Thousands of IM Screen Names in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/yahoo-messenger-controlled-malware.html">Yahoo Messenger Controlled Malware</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DnpcL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DnpcL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JdbNL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JdbNL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WyKQl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WyKQl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gjRhl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gjRhl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MFoXL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MFoXL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cB2ML"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cB2ML" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XFyul"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XFyul" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/393258731" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 05:28:04 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/social">social</category>
      <category domain="http://www.securityratty.com/tag/msn social">msn social</category>
      <category domain="http://www.securityratty.com/tag/tool">tool</category>
      <category domain="http://www.securityratty.com/tag/skype">skype</category>
      <category domain="http://www.securityratty.com/tag/wild">wild</category>
      <category domain="http://www.securityratty.com/tag/bot">bot</category>
      <category domain="http://www.securityratty.com/tag/msn">msn</category>
      <category domain="http://www.securityratty.com/tag/malware campaigns">malware campaigns</category>
      <category domain="http://www.securityratty.com/tag/malware">malware</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/393258731/skype-spamming-tool-in-wild-part-two.html">Skype Spamming Tool in the Wild - Part Two</source>
    </item>
    <item>
      <title><![CDATA[Links List 8.22.08]]></title>
      <link>http://www.securityratty.com/article/e37289e3f28c0134060472b8a33b4f97</link>
      <guid>http://www.securityratty.com/article/e37289e3f28c0134060472b8a33b4f97</guid>
      <description><![CDATA[Ah, the opening ceremonies of the Olympics. How spectacular. Is that Li Ning running in the sky with the torch? Oooh, aah. And wait, whats that image on the wall behind him? Looks kinda familiaroops,...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="170" alt="bsod_nest_main2" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/bsod-nest-main2.jpg" width="244" align="left" border="0"> Ah, the opening ceremonies of the Olympics. How spectacular. Is that Li Ning “running” in the sky with the torch? Oooh, aah. And wait, what’s that image on the wall behind him? Looks kinda familiar…oops, it’s an <a href="http://weblog.infoworld.com/robertxcringely/archives/2008/08/geek_week_tk_tk_1.html?source=NLC-NOTES&amp;cgd=2008-08-18" target="_blank">XP blue screen of death</a>….I wonder how much Microsoft paid for advertising during the Olympics?
<p><em>(</em><a href="http://cache.gizmodo.com/assets/images/gizmodo/2008/08/bsod_nest_main2.jpg" target="_blank"><em>Photo Credit: Gizmodo</em></a><em>)</em>
<p>You lose some. You win some: Of course as NBC’s online partner, Microsoft gets a least a cut of the <a href="http://www.paidcontent.org/entry/419-online-ad-spend-tied-to-olympics-expected-to-reach-100-million/" target="_blank">$100 million dollars in online advertising</a> spent around the Olympics. And the millions of <a href="http://www.businessweek.com/technology/content/aug2008/tc20080820_627259.htm?campaign_id=rss_daily" target="_blank">downloads of Silverlight</a> aren’t too shabby either.
<p>The Internet is Falling! Arbor Networks, a security and network management company, partnered with ninety network services and content providers from around the world to publish an extensive <a href="http://www.circleid.com/posts/88181_largest_study_of_ipv6_traffic/" target="_blank">study of IPv6 traffic</a> on the Internet. Craig Labovitiz, Arbor Networks chief scientist, stated that <a href="http://asert.arbornetworks.com/2008/8/the-end-is-near-but-is-ipv6/" target="_blank">only 900 days were left until the end of the Internet</a>, or at least the exhaustion of IPv4 registry allocations. For the past year, the study shows very little IPv6 traffic – something like 1/100<sup>th</sup> of 1% of Internet traffic. Craig credits this to money issues. “The department of commerce estimates it will cost $25 billion for ISPs to upgrade to native IPv6.”
<p>Blogger <a href="http://blog.jamesurquhart.com/2008/08/cloud-computing-bill-of-rights.html" target="_blank">James Urquhart created a bill of rights for cloud computing</a>. The purpose of the bill is to “help guide would-be cloud customers to those clouds best able to guarantee their freedom.” The blogosphere is a great place to get some open debate going, and I applaud James for trying to make something yet so “cloudy” a bit more clear and concrete. But what’s up with the creating a PAC for this?? (Check out the comments.)
<p>Trying to get by on limited resources? Need more money, staff and the freedom to focus on long-term projects? Sound familiar? Then you just might be in <a href="http://blogs.wsj.com/biztech/2008/08/21/life-is-tough-for-midsize-tech-departments/?mod=djemTECH" target="_blank">IT at a midsize company</a>. (or in marketing at a young but rapidly growing IT company <img src='http://blog.sciencelogic.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> ) Arrow Enterprise Computing Solutions conducted a survey of 200 tech leaders at midsize companies (500 to 3000 employees). The upside: 61% of those surveyed think they’ll be spending more on IT next year – is this bullish thinking about the economy or how much their own business (rev) will be growing?
<p>Bill Snyder calls Dell “<a href="http://weblog.infoworld.com/tech-bottom-line/archives/2008/08/michael_dell_is.html?source=NLC-DAILY&amp;cgd=2008-08-21" target="_blank">Bozo of the Month</a>” for trying to trademark “cloud computing”. Yikes. Maybe not a “bozo” move but certainly inadvisable given how ubiquitous the term is. Here’s <a href="http://blog.sciencelogic.com/no-trademark-for-cloud-computing/08/2008" target="_blank">our take</a> on it.</p>
]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 16:15:48 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/network management company">network management company</category>
      <category domain="http://www.securityratty.com/tag/internet">internet</category>
      <category domain="http://www.securityratty.com/tag/internet traffic">internet traffic</category>
      <category domain="http://www.securityratty.com/tag/company">company</category>
      <category domain="http://www.securityratty.com/tag/nbcs online partner">nbcs online partner</category>
      <category domain="http://www.securityratty.com/tag/ipv6 traffic">ipv6 traffic</category>
      <category domain="http://www.securityratty.com/tag/online">online</category>
      <category domain="http://www.securityratty.com/tag/blogger james urquhart">blogger james urquhart</category>
      <category domain="http://www.securityratty.com/tag/ninety network services">ninety network services</category>
      <source url="http://blog.sciencelogic.com/links-list-82208/08/2008">Links List 8.22.08</source>
    </item>
    <item>
      <title><![CDATA[This Generations ApathyThe Age of Specialization and ADD]]></title>
      <link>http://www.securityratty.com/article/de3980adf7c1fb760b23b64836636412</link>
      <guid>http://www.securityratty.com/article/de3980adf7c1fb760b23b64836636412</guid>
      <description><![CDATA[Robert Scoble has some interesting commentary this morning about the number of photojournalists with expensive gear covering the Olympics
Hes a bit indignant that so much energy goes to sporting...]]></description>
      <content:encoded><![CDATA[<p>Robert Scoble has some interesting <a rel="nofollow" target="_blank" href="http://scobleizer.com/">commentary</a> this morning about the number of photojournalists with expensive gear covering the Olympics.</p>
<p>He&#8217;s a bit indignant that so much energy goes to sporting events like the Olympics rather than more important news that isn&#8217;t getting reported around the world.</p>
<blockquote><p>This is in a year when tons of journalists are getting laid off.</p>
<p>This is in a year when there are tons of stories around the world that aren’t getting reported on.</p>
<p>Could we take half of those photographers and send them to Russia, for instance</p></blockquote>
<p>Reminds me of a feeling I had back in college as an undergrad student studying social sciences and humanities, about the way my friends who were physicists interacted with the world. They were so awed by the stars, Mars, astrophysics, and it seemed to me interesting but altogether unimportant. They argued they may find something outside our planet that could help solve Earth-bound problems like disease, or find the origins of earth and humanity &#8212; but really they were doing it because they loved it. One of my friends had a good argument, though &#8212; there are enough people right now that we can specialize in what we care about, and there will still be others covering other topics. He could be a physicist and look into the universe&#8217;s origin, while I studied social interaction and writing, and our other friends looked into solving cancer or eradicating invasive plants in the native wetlands. We have to specialize, and there are enough of us to do it too.</p>
<p>I think it&#8217;s the same way in journalism &#8212; whether it&#8217;s sports, celebrity journalism, or coverage of politics and war, there are a lot of opportunities right now for journalists. Of course the business model is changing, and some old-schoolers won&#8217;t know how to roll with that, but generations change slowly; we&#8217;re learning.</p>
<p>Also, the Olympics is seen as more than a sporting event, it&#8217;s also a symbol of world competition and cooperation too &#8212; a way for countries to come together and share entertainment globally. I think that&#8217;s worth covering.</p>
<p>In the second post, Robert Scoble says there are plenty of great journalists but the public doesn&#8217;t care. In some ways I have to agree with that, but I don&#8217;t think it&#8217;s negative, necessarily. I had a conversation with someone the other day about world news reportage. He says, &#8220;I was just reading this story, but what does it matter to me if there&#8217;s a flood in some city in another country I&#8217;ll never visit and some farmer lost his sheep?&#8221; World news is only important when it&#8217;s relevant, so it&#8217;s no wonder that many people don&#8217;t care &#8212; if they don&#8217;t know much about the area, and it doesn&#8217;t affect them, they have no incentive to give it full attention. You can call that apathy, but I think it&#8217;s an important selectivity skill that humans have. We have to choose what to give priority to, so if nothing stands out as being particularly important, we just ignore it or gloss over it. Human nature&#8230;</p>
<p>Also I think the common person today just gets desensitized and doesn&#8217;t know where to turn their energy, when surrounded by so many crises. Either you focus on one specialty and do your best to work toward one cause in your life &#8212; and maybe that&#8217;s just in the course of your daily work &#8212; or you become a complete Attention-Deficit-Disorder case and bounce from one problem to the next, without knowing how to solve anything. That just causes a sense of bewilderment, despair, and either that bogs you down or eventually you get desensitized.</p>
<p>There&#8217;s a commenter on Scoble&#8217;s blog, Spencer, who talks about this generation&#8217;s apathy. There are so many people who want to blame today&#8217;s generation or the young generation for this &#8220;apathy&#8221; that they sense. But I see it as a survival mechanism that arises from the way information flows these days. We&#8217;re surrounded by crises, everyone wants us to know about them &#8212; the water shortage, global warming, death in Iraq, the national deficit. Okay, crisis, I get it. But no one gives a real clear idea on what any individual is really supposed to do to solve the problem. You can&#8217;t get involved with one global cause, without ignoring all the others, and if you do get involved it&#8217;s likely to become your life&#8217;s purpose. Most people are concerned with other things &#8212; their families, their work, personal development, their homes and futures, and really that&#8217;s enough to take up all their time.</p>
<p>I&#8217;m always amazed when I read about the early unionists. Emma Goldman for example, the activist who pushed for the 8-hr workday, and campaigned for free love in the early 1900s when women were still wearing corsets, used to work 16 hour factory days as a seamstress, then lead meetings late into the night. Today we lead cushy lives comparatively&#8211;8 hour days, plus commute and lunch, family time, dinner time, gym maybe, sleep&#8230; but it still doesn&#8217;t seem like we ever have enough energy and time.</p>
<p>What Emma had that most people today don&#8217;t, is a community living in the same conditions as herself, with clear goals about what they were campaigning for, and a cause that affected their own daily lives. Today, unionism and local activism is in much shorter supply, in part due to the many people who work fairly comfy desk jobs, and the problem that everyone has his own specialization, works in a cubicle, does his or her own thing. The problems we&#8217;re facing today in terms of global warming, global water shortage, aren&#8217;t the same kinds of problems that activists have fought for in the past, and there&#8217;s no clear road map for how to solve them. Our leaders sure aren&#8217;t leading the way.</p>
<p>What we do have, at least, is the Olympics, which is an age old symbol of international cooperation, play and competition&#8230;so, uh, go sports! As for full disclosure, I don&#8217;t actually have a TV and haven&#8217;t watched the Olympics in many years, but I do try taking short showers&#8211;does that help?</p>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 09:46:26 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/world news reportage">world news reportage</category>
      <category domain="http://www.securityratty.com/tag/world">world</category>
      <category domain="http://www.securityratty.com/tag/world competition">world competition</category>
      <category domain="http://www.securityratty.com/tag/world news">world news</category>
      <category domain="http://www.securityratty.com/tag/global water shortage">global water shortage</category>
      <category domain="http://www.securityratty.com/tag/global">global</category>
      <category domain="http://www.securityratty.com/tag/time">time</category>
      <category domain="http://www.securityratty.com/tag/news">news</category>
      <category domain="http://www.securityratty.com/tag/solve earth-bound">solve earth-bound</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/369359733/">This Generations ApathyThe Age of Specialization and ADD</source>
    </item>
    <item>
      <title><![CDATA[Even More Logging Questions - Answered]]></title>
      <link>http://www.securityratty.com/article/42419cabc2c6779620c8b8bb44fe54c9</link>
      <guid>http://www.securityratty.com/article/42419cabc2c6779620c8b8bb44fe54c9</guid>
      <description><![CDATA[I did this fun webcast on logging for accountability ( here ) and people asked a lot of good questions. Here are some of the answers for them and all my blog readers

Q1: How do you handle variety of...]]></description>
      <content:encoded><![CDATA[<p>I did <a href="http://isc2.brighttalk.com/node/403">this fun webcast</a> on logging for accountability (<a href="http://isc2.brighttalk.com/node/403">here</a>) and people asked a lot of good questions. Here are some of the answers for them and all my blog readers.</p>  <p>&#160;</p>  <p>Q1: How do you handle variety of log sources? There are so many, almost beyond my capability. </p>  <p>A1: Sorry to ponder the meaning of &quot;is&quot; here, but what is meant by &quot;handle&quot;? It is really not that hard to collect logs from a large number of diverse sources (as long as the logs can be delivered via syslog or exist as files and can be collected). Now, there will certainly be challenges&#160; when the volume of logs gets large, but if by &quot;handle&quot; you mean &quot;collect + store&quot;, it is really not that hard, given <a href="http://www.loglogic.com">the right tools.</a> Now, if &quot;handle&quot; means &quot;make sense of what all those logs are trying to tell you,&quot; it is a different story altogether.</p>  <p>&#160;</p>  <p>Q2: You talked about the importance of logging; however for an intermediate or novice admin what are the starting steps .. what are the minimal logs they should start at once?</p>  <p>A2: Answered in <a href="http://chuvakin.blogspot.com/2008/07/log-management-day-1.html">&quot;Log Management - Day 1&quot;</a> If you want a simple list of things to &quot;enable today,&quot;&#160; I cannot really answer it since I know neither your needs, nor your environment. In other words, this is the &quot;what is the meaning of life question?&quot; :-)</p>  <p>&#160;</p>  <p>Q3: What regulations, rules or guidance exist regarding sharing or visibility of logs to users?</p>  <p>A3: PCI DSS says in Requirement 10.5:&#160; &quot;Secure audit trails so they cannot be altered.    <br /><em>10.5.1 Limit viewing of audit trails to those with a job-related need      <br /></em>10.5.2 Protect audit trail files from unauthorized modifications     <br />10.5.3 Promptly back-up audit trail files to a centralized log server or media that is difficult to     <br />alter&quot; </p>  <p>NIST guidance for FISMA also says something similar (for example, look in <a href="http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf">NIST 800-92 doc</a>). Overall, <a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">log protection and security</a> are mentioned in many other regulations as well. </p>  <p>&#160;</p>  <p>Q4: Privileged groups membership monitoring in AD one of the most important from my point of view. However I did not find effective way to monitor/report on changes in those groups. Any recommendations?</p>  <p>A4: This is indeed a tricky one which might take more space to answer than I have here; it might also take you 'beyond logs.' One good source of information is <a href="http://www.ultimatewindowssecurity.com/encyclopedia.aspx">Randy Smith's site</a> and, specifically, his webinar on 'Active Directory &quot;Logging Gap&quot;' (<a href="http://www.ultimatewindowssecurity.com/aaad/">here somewhere</a>) - which covers how to audit things of that sort when then native logging is not sufficient.</p>  <p>&#160;</p>  <p>Q5: How I can learn what exactly I need to log?</p>  <p>A5: OMG, this is a $1,000,000 question :-) Let me answer &quot;how can I learn&quot; part and not the &quot;what exactly I need to log part,&quot;&#160; (also see discussion on &quot;<a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a>&quot;) as it is actually answerable. To learn what you need to log, first ask &quot;Why?&quot; (and then see <a href="http://chuvakin.blogspot.com/2008/07/log-management-day-1.html">this</a>) - basically establish what you want to accomplish with logs, catalogue your systems, figure how to tweak the logging knobs - and then do it!</p>  <p>&#160;</p>  <p>Q6: How granular should logging be? What is your recommendation for enterprise servers like domain servers and Windows servers?</p>  <p>A6: Again, too long to answer here in details (it will become a subject of a longer blog post later), but some pointers follow: <a href="http://www.ultimatewindowssecurity.com/blog/blog_commento.asp?blog_id=23&amp;month=05&amp;year=2007&amp;giorno=&amp;archivio=OK">here for Windows</a> (MS site also have a few recommendations on audit policies)</p>  <p>&#160; </p>  <p>Q7: What is &quot;more control&quot; and what is &quot;less control&quot; that you <a href="http://isc2.brighttalk.com/node/403">mention in the webcast</a>? Can you give an example?</p>  <p>A7: OK, I did say that &quot;sometimes when you implement more controls, you actually have less control.&quot; What do I mean? If you buy a firewall (a network security control) and then - over time, of course - configure it with 7800 rules (!) that are supposed to give you control over who can and cannot access your network, you will not gain control over your environment. You will actually be less in control of who is touching your network, compared to, say, having only 20 rules.</p>  <p>&#160;</p>  <p>Q8: What about mandated NIST controls for government systems? Auditing is a specific control for Moderate and High risk systems. What list of events do you recommend for auditing?</p>  <p>A8: This is too long to answer here, but <a href="http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf ">NIST 800-92 Guide</a> is a really good source of such info (&quot;<a href="http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf">Guide to Computer Security Log Management [PDF]</a>&quot;) Also, see my presentation on <a href="http://www.slideshare.net/anton_chuvakin/nist-80092-log-management-guide-in-the-real-world/">NIST 800-92 Guide in the Real World</a>.</p>  <p>&#160;</p>  <p>Q9: The issue that many organizations get stuck on, is the monitoring process, and defining what exceptions to monitor for? Is there guidance / framework for this? How much of it is system specific and how much is applicable generally to all systems?</p>  <p>A9: I outlined some general ideas <a href="http://www.slideshare.net/anton_chuvakin/what-every-organization-should-log-and-monitor">back in 2004 via this presentation</a>&#160;<em>(note to self - update that to be more 2008-relevant);</em> it is mostly general, but also has pointers to specific system. Keep in mind that it is focused on security, not operational monitoring (which is often no less important - in fact, often <a href="http://rationalsecurity.typepad.com/blog/2008/02/omg-availabilit.html">MORE important</a>)</p>  <p>&#160;</p>  <p>Enjoy! Sorry for being brief with some of the answers - I am woefully late with this even as they are...</p>  <p><strong>Other questions that I answered in the past:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/05/more-log-management-questions-answered.html">More Log Management Questions - Answered!</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/some-burning-logging-questions-answered.html">Some Burning Logging Questions - Answered!</a> </li> </ul>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=juyDeK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=juyDeK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=o5WeXK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=o5WeXK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=mnNGqK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=mnNGqK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/357664119" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 07:43:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/log server">log server</category>
      <category domain="http://www.securityratty.com/tag/log">log</category>
      <category domain="http://www.securityratty.com/tag/log sources">log sources</category>
      <category domain="http://www.securityratty.com/tag/log management">log management</category>
      <category domain="http://www.securityratty.com/tag/control">control</category>
      <category domain="http://www.securityratty.com/tag/questions">questions</category>
      <category domain="http://www.securityratty.com/tag/specific control">specific control</category>
      <category domain="http://www.securityratty.com/tag/network security control">network security control</category>
      <category domain="http://www.securityratty.com/tag/log protection">log protection</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/357664119/even-more-logging-questions-answered.html">Even More Logging Questions - Answered</source>
    </item>
    <item>
      <title><![CDATA[Ideal Tool to Solve Real Problems ... of the Near Future? - II]]></title>
      <link>http://www.securityratty.com/article/4d45e2880b790245f00c577a7d0b0226</link>
      <guid>http://www.securityratty.com/article/4d45e2880b790245f00c577a7d0b0226</guid>
      <description><![CDATA[I would like to continue the discussion I started in my previous post called &quot; Ideal Tool to Solve Real Problems ... of the Near Future? &quot; Specifically, upon outlining some problems with logging, I...]]></description>
      <content:encoded><![CDATA[<p>I would like to continue the discussion I started in my previous post called &quot;<a href="http://chuvakin.blogspot.com/2008/06/ideal-tool-to-solve-real-problems-of.html">Ideal Tool to Solve Real Problems ... of the Near Future?</a>&quot; Specifically, upon outlining some problems with logging, I will now forecast what will happen with them in 18-24 months. </p>  <ul>   <li>Which problems will be solved and forgotten? </li>    <li>Which ones will simply go away? </li>    <li>Which ones will persist and in fact increase? </li>    <li>Finally, which new ones might emerge? </li> </ul>  <p>First, let me bet my ass that &quot;<strong>Not knowing what to log</strong>&quot;<strong> </strong>problem <strong>will be licked in 18-24 months</strong>; at least as far as major regulations go, people will have a pretty good idea a) what&#160; the auditors want them to log (and review!) b) what they need to log for solving their problems. Now, for esoteric log sources (and custom applications) might still present a challenge from that point of view, but for basic &quot;staples&quot; (firewall, network gear, major OS) the mystery will be over (again, see &quot;<a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">Tell me EXACTLY what to log for PCI?</a>&quot;&#160; for reference)</p>  <p>Next, the problem of &quot;<strong>Log volume&quot; will&#160; definitely get worse, much worse</strong>.&#160; One might think that <em>100,000 each second</em> is a lot of log - but there WILL BE more at many companies! <em>Big application log explosion is coming</em>, fueled by the need to address logging in areas where such motivation was lacking before (basically, custom and vertical applications) as well as harness the power of &quot;uncommon&quot; logs for such tasks as fraud analysis or SOA monitoring. Keep in mind that even though in some areas logging is NOT a preferred way of monitoring and auditing activities (see <a href="http://chuvakin.blogspot.com/2007/12/how-to-do-database-loggingmonitoring.html">this discussion</a> on database logs <u><a href="http://chuvakin.blogspot.com/2007/12/how-to-do-database-loggingmonitoring.html">here</a></u>), application logging will still explode on us...</p>  <p>The problem of &quot;<strong>Log diversity&quot; </strong>(the fact that most logs all look different in format and meaning) <strong>will get worse before it will get better</strong> - and better it WILL (!!!) get since <a href="http://cee.mitre.org">standards are being developed</a>. We will see people struggling with all sorts bizarro log data in the coming years. Virtualization, web services and SOA, various ERP applications and even cloud services will increase the diversity of logging in the coming years.</p>  <p>Similar to the above, a problem of &quot;<strong>Bad logs&quot; </strong>(ones that are subjective, miss key information, require groping for a crystal ball to understand, turn log <em>analysis</em> into dark voodooistic experience or are <a href="http://www.loganalysis.org/pipermail/loganalysis/2008-January/000534.html">useless in some other way</a>) will also follow the pattern of the above log diversity problems - it <strong>will get worse before it gets better</strong> (via the <a href="http://cee.mitre.org">CEE standard effort</a> that now covers the <u><a href="http://openxdas.sourceforge.net/">OpenXDAS effort as well</a>!</u>) I noticed that people started asked me questions about &quot;how to do application logging right?&quot; and &quot;what to tell application developers about logging?&quot; which almost never happened in the past. BTW, watch <a href="http://www.securitywarrior.org">my blog</a> for some uber-fun info on that!</p>  <p><strong>&quot;Getting the logs&quot;</strong>&#160; has gotten much easier in recent years; agentless collectors like <u><a href="http://sourceforge.net/projects/lassolog">Project Lasso</a></u> (which, BTW, just <u><a href="http://www.loglogic.com/news/news-releases/2008/07/loglogic-launches-centralized-windows-event-log-collection-appliance-for-enterprise/">got updated</a></u>) and grabbing&#160; files remotely via secure protocols made application log collection easier (syslog-NG with TCP transfer and buffering also helped). Next, Windows 2008 will make it MUCH easier for the whole Windows kingdom due to their <a href="http://www.realtime-windowsserver.com/tips_tricks/2007/08/event_log_subscriptions_in_win.htm">use of web serv</a>ices (<u><a href="http://blogs.msdn.com/ericfitz/">thanks Eric!</a></u>). However, in the future it <strong>might resurface</strong> as we try to collect logs from &quot;weird&quot; places, again, <u><a href="http://chuvakin.blogspot.com/2008/05/cloud-this-cloud-that.html">clouds come to mind</a></u> as well as <u><a href="https://www.sans.org/webcasts/show.php?webcastid=91979">virtual environments</a></u> (e.g. how do you get logs off a dormant VM?). What's the next frontier in this area? Log discovery - automatic finding and identifying log files on systems in order to analyze and retain them (Yo, <u><a href="http://chuvakin.blogspot.com/2008/06/thanks-for-wonderful-t-shirt.html">my t-shirt-making colleagues...</a> </u>:-))</p>  <p>All this, however, pales in comparison with my favorite &quot;uber-challenge&quot;, &quot;<strong>Making sense of logs in&#160; an automated fashion&quot;</strong> - this baby is definitely not going away in 2-3 years. Much more research is needed to make that &quot;<strong>log-&gt;conclusion&quot;</strong> jump automatically without head-scratching, invoking ancient deities and cursing under ones's breath. Only then we can attempt to reliable handle &quot;proactive logging&quot; (i.e. analyzing various failure or compromise precursors in logs and then predicting the future based on them), another Holy Grail of logging domain.</p>  <p>Anything new will emerge? Yes, I think awareness of the <strong>&quot;Logging Gap&quot; problem will grow</strong>. &quot;Logging gap&quot; happens when you combine &quot;a need to log&quot; with utter &quot;inability to do so.&quot;&#160; For example, this will happen when people will know that they HAVE TO log, say, for compliance, but will have no way of doing it due to application or platform limitations. This will become one of the challenges and special &quot;logging add-ons&quot; will appear to close the logging gap and create additional logs where activity audit is desperately needed, but native logging is not helping to achieve it.</p>  <p>Also, I think people will <strong>finally</strong> <strong>wake up to</strong> &quot;<strong>Log security</strong>&quot; challenges - i.e. producing for use as evidence, compliance attestations, etc. <u><a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Log security</a></u> is not getting the attention <u><a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">it deserves</a></u>, but I think this challenge will finally emerge in full force in the next 2-3 years. My next poll will address that :-)</p>  <p>Anything else I missed? Share away!</p>  <p><strong>Related posts:</strong></p>  <ul>   <li>     <h5><a href="http://chuvakin.blogspot.com/2008/06/ideal-tool-to-solve-real-problems-of.html">Ideal Tool to Solve Real Problems ... of the Near Future?</a></h5>   </li>    <li>     <h5><a href="http://chuvakin.blogspot.com/2007/11/ideal-log-management-tool.html">Ideal Log Management Tool?</a></h5>   </li> </ul>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=OiE77K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=OiE77K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=mHZh5K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=mHZh5K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=MlgSPK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=MlgSPK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/356001661" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 17:30:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/log discovery">log discovery</category>
      <category domain="http://www.securityratty.com/tag/log">log</category>
      <category domain="http://www.securityratty.com/tag/log diversity">log diversity</category>
      <category domain="http://www.securityratty.com/tag/esoteric log sources">esoteric log sources</category>
      <category domain="http://www.securityratty.com/tag/log security">log security</category>
      <category domain="http://www.securityratty.com/tag/application log explosion">application log explosion</category>
      <category domain="http://www.securityratty.com/tag/application">application</category>
      <category domain="http://www.securityratty.com/tag/log analysis">log analysis</category>
      <category domain="http://www.securityratty.com/tag/log volume">log volume</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/356001661/ideal-tool-to-solve-real-problems-of.html">Ideal Tool to Solve Real Problems ... of the Near Future? - II</source>
    </item>
    <item>
      <title><![CDATA[Dissecting a Managed Spamming Service]]></title>
      <link>http://www.securityratty.com/article/a86a7c12b2395b3c5ee8667c3a4d13e0</link>
      <guid>http://www.securityratty.com/article/a86a7c12b2395b3c5ee8667c3a4d13e0</guid>
      <description><![CDATA[With cybercrime getting easier to outsource these days, and with the overall underground economy's natural maturity from products to services, &quot; managed spamming appliances &quot; and managed spamming...]]></description>
      <content:encoded><![CDATA[<div class="separator" style="text-align: left; clear: both;"><a href="http://bp2.blogger.com/_wICHhTiQmrA/SJAiYgYGvGI/AAAAAAAAB-c/0z_b5zxZV0c/s1600-h/customer_support.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SJAiYgYGvGI/AAAAAAAAB-c/bUYt5gvY6SU/s320-R/customer_support.jpg" style="border: 0pt none ;" /></a></div>With cybercrime getting easier to outsource these days, and with the overall underground economy's natural maturity from products to services, "<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">managed spamming appliances</a>" and managed spamming services are becoming rather common. Increasingly, these "vendors" are starting to "vertically integrate", namely, start diversifying the portfolio of services they offer in order to steal market share from other "vendors" offering related services like, email database cleaning, segmentation of email databases, email servers or botnets whose hosts have a pre-checked and relatively clean IP reputation, namely they're not blacklisted yet.<br />
<br />
How much does it cost to send 1 million spam emails these days? According to a random spamming service, $100 excluding the discounts based on the speed of sending desired, namely 10-20 per second or 20-30 per second. Let's dissect the service, and emphasize on its key differentiation factors, as well as the customerization offered in the form of a dedicated server if the customer would like to send billions of emails :<br />
<br />
"<i>-- High quality and percentage of spam delivery&nbsp;</i><br />
<i> -- Fast speed of delivery<br />
-- Spam database on behalf of the vendor, or using your own database of harvested emails<br />
-- Easily obtainable and segmented spam databases on per country basis<br />
-- Randomization of the spam email's body and headers in order to achieve a higher delivery rate<br />
-- Support for attachments, executables, and image files<br />
<br />
The cost - $100 for a million for letters delivered spam, with the large volume of spam discounts 20% -30% -40% based on the value-added Do-it-yourself customer interfare based on a multi-user botnet command and control interface :<br />
&nbsp;</i><br />
<i>-- Automatic RBL verification  <br />
-- Support for many subjects, headers,  <br />
-- Total customization of the email sending process  <br />
-- Autogenerating junk content next to the spammers email/link in order to bypass filtering<br />
-- Faking Outlook Message ID / Boundary / Content-ID  <br />
-- Interface added. Now do not necessarily understand all the features into the system to start the list.  <br />
-- Convenient management tasks.  <br />
-- A high percentage of punching, on the basis of good europe - 40-60% (For the United States - less because there aol and others). <br />
-- Improved metrics, whether or not the emails have been sent, lost, unknown receipt, or have been RBL-ed<br />
<br />
With the weight of a billion - even discounts and the possibility of making a personal server. " <br />
<br />
</i>Rather surprising, they state that European email users have a higher probability of receiving the spam message compared the U.S due to AOL. What they're actually trying to say is due to AOL's use of Domain Keys Identified Mail (DKIM). As far as <a href="http://ddanchev.blogspot.com/2008/05/segmenting-and-localizing-spam.html">localization of the spam to the email owner's native languag</a>e is concerned, this segmentation concept has been take place for over an year now.<br />
<br />
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SJA7MWbx4jI/AAAAAAAAB-k/BvKdLNRflW4/s1600-h/phishme_demo_ethical.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJA7MWbx4jI/AAAAAAAAB-k/Y5691Se7e2k/s200-R/phishme_demo_ethical.JPG" style="border: 0pt none ;" /></a>This service, like the majority of others rely entirely on malware infected hosts, which due to the multi-user nature of most of the malware command and control interfaces, allows them to easily add customers and set their privileges based on the type of service that they purchase. This leaves a countless number of opportunities for targeted spamming, and yes, spear phishing attacks made possible due to the segmentation of the emails based on a country, city, even company.<br />
<br />
In the long term, the people behind spamming providers, web malware exploitation kits and <a href="http://ddanchev.blogspot.com/2008/05/diy-phishing-kits-introducing-new.html">DIY phishing kits</a>, will inevitably start introducing built-in features which were once available through third-party services. For instance, hosting infrastructure for the spam/phishing/live exploit URLs, or even managed fast-flux infrastructure, have the potential to become widely available if such optional features get built-in phishing kits, or start getting offered by the spamming provider itself. And since the affiliate based model seems to be working just fine, the <a href="http://ddanchev.blogspot.com/2007/12/phishers-spammers-and-malware-authors.html">ongoing underground consolidation</a> will converge providers of different underground goods and services, where everyone would be driving customers to one another's services and earning revenue in the process.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bsJ3iJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bsJ3iJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IEP1EJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IEP1EJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZzurFj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZzurFj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uIY3Pj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uIY3Pj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=60gQsJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=60gQsJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Nb7yGJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Nb7yGJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=y37sBj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=y37sBj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/350363899" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 01:32:44 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/spam">spam</category>
      <category domain="http://www.securityratty.com/tag/spam message">spam message</category>
      <category domain="http://www.securityratty.com/tag/spam discounts">spam discounts</category>
      <category domain="http://www.securityratty.com/tag/spam database">spam database</category>
      <category domain="http://www.securityratty.com/tag/spam databases">spam databases</category>
      <category domain="http://www.securityratty.com/tag/spam email">spam email</category>
      <category domain="http://www.securityratty.com/tag/email">email</category>
      <category domain="http://www.securityratty.com/tag/emails based">emails based</category>
      <category domain="http://www.securityratty.com/tag/email servers">email servers</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/350363899/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</source>
    </item>
  </channel>
</rss>
