<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Information Security Blog &#124; Perimeter E-Security &#187; cybersecurity</title>
	<atom:link href="http://perimeterusa.com/blog/tag/cybersecurity/feed/" rel="self" type="application/rss+xml" />
	<link>http://perimeterusa.com/blog</link>
	<description>News, Notes, and Opinions from the World of Information, Network, and Data Security</description>
	<lastBuildDate>Thu, 26 Aug 2010 15:33:35 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Lax Legislation May Let &#8216;Mariposa&#8217; Botnet Creators Go Free</title>
		<link>http://perimeterusa.com/blog/lax-legislation-may-let-mariposa-botnet-creators-go-free/</link>
		<comments>http://perimeterusa.com/blog/lax-legislation-may-let-mariposa-botnet-creators-go-free/#comments</comments>
		<pubDate>Fri, 26 Mar 2010 16:05:34 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[cybersecurity]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=715</guid>
		<description><![CDATA[Lax cyber crime legislation in Spain may let the "Mariposa" botnet authors avoid any jail time.]]></description>
			<content:encoded><![CDATA[<div class="mceTemp">
<dl id="attachment_716" class="wp-caption alignleft" style="width: 147px;">
<dt class="wp-caption-dt"><img class="size-medium wp-image-716" title="Weakness" src="http://perimeterusa.com/blog/wp-content/uploads/2010/03/Chain-weak-224x300.jpg" alt="c" width="137" height="148" /></dt>
</dl>
</div>
<p>The three guys that were <a href="http://perimeterusa.com/blog/massive-mariposa-botnet-shut-down-with-arrest-of-administrators/" target="_blank">arrested for the Mariposa botnet</a> may <a href="http://www.krebsonsecurity.com/2010/03/mariposa-botnet-authors-may-avoid-jail-time/" target="_blank">never go to jail</a>.</p>
<p>Apparently if you are going to operate a botnet, Spain is the perfect place to do it because there are currently no laws around the their alleged crimes.  Now prosecutors are trying to link their activity to other crimes that there are laws for.   So I guess botnet owners have perhaps found a &#8220;safe haven&#8221;.</p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/lax-legislation-may-let-mariposa-botnet-creators-go-free/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Massive Mariposa Botnet Shut Down with Arrest of Administrators</title>
		<link>http://perimeterusa.com/blog/massive-mariposa-botnet-shut-down-with-arrest-of-administrators/</link>
		<comments>http://perimeterusa.com/blog/massive-mariposa-botnet-shut-down-with-arrest-of-administrators/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 15:25:51 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[Banking Information Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Firewall Software]]></category>
		<category><![CDATA[Identity Theft]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=687</guid>
		<description><![CDATA[Mariposa, a massive botnet, was shut down as three of the administrators were arrested. Personal info from more than 800,000 people was recovered.]]></description>
			<content:encoded><![CDATA[<p>A very large botnet named &#8220;Mariposa&#8221; <a href="http://www.computerworld.com/s/article/9164838/Spanish_police_take_down_massive_Mariposa_botnet?taxonomyId=17" target="_blank">was recently shut down</a> with the <a href="http://edition.cnn.com/2010/TECH/03/03/spain.computer.virus.arrest/" target="_blank">arrest of 3 of the main administrators</a>.  More arrests are expected in other countries.</p>
<p>Mariposa is said to have as many as 12.7 million compromised computers (Zombies) worldwide.  The software acted as a Trojan horse and captured login credentials for online bank accounts. Following the arrests, police recovered personal information of more than 800,000 people.  Zombies were in many of the Fortune 1000 companies as well as in 40 major banks.  The Mariposa Working Group, which is a coalition of security experts, academics and law enforcement, were the ones who got it shut down.</p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/massive-mariposa-botnet-shut-down-with-arrest-of-administrators/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Aurora Cyber Attackers Infiltrate Source-Code Management Systems of Google and Others</title>
		<link>http://perimeterusa.com/blog/aurora-cyber-attackers-infiltrate-source-code-management-systems-of-google-and-others/</link>
		<comments>http://perimeterusa.com/blog/aurora-cyber-attackers-infiltrate-source-code-management-systems-of-google-and-others/#comments</comments>
		<pubDate>Mon, 15 Mar 2010 19:05:08 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Firewall Software]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=678</guid>
		<description><![CDATA[Aurora cyber attackers targeted Google and others by utilizing spear phishing attacks to gain access to source-code management systems]]></description>
			<content:encoded><![CDATA[<div class="mceTemp">
<dl id="attachment_679" class="wp-caption alignleft" style="width: 190px;">
<dt class="wp-caption-dt"><img class="size-full wp-image-679" title="Google_Logo" src="http://perimeterusa.com/blog/wp-content/uploads/2010/03/Google.jpg" alt="G" width="180" height="62" /></dt>
</dl>
</div>
<p>More things are coming to light about the <a href="http://www.crn.com/security/223101584;jsessionid=EKMG0FEDZZDL3QE1GHPCKHWATMY32JVN" target="_blank">Aurora cyber attackers who targeted Google and other companies</a>.  This is really pretty interesting stuff (if your geek-o-meter pegs solidly in the red).  McAfee released a paper at RSA last week that says that the Aurora cyber attackers had been going after source-code management systems.  These are software systems that house, manage, and control the source code for companies. Keeping track of source code can be a big task.  Imagine all the different developers, different versions, etc.  These systems are the life blood of development organizations.  If a hacker could gain access to these systems, they could modify code, inject trojans and malware potentially, and certainly steal code (intellectual property).</p>
<p>According to the paper released by McAfee, the source code system was virtually &#8220;wide open&#8221; which tells us they had a severe lack in their security.  But here is where it gets interesting.  Remember that other companies were targeted by the same Aurora group at the same time?  Well they were all using the same code management system…with likely all the same security vulnerabilities.  Someone might ask how cyber criminals could determine which companies were using which code management systems.  There was a lot of talk about &#8220;Google Hacking&#8221; a few years ago.  This is different than hacking Google, but rather using Google&#8217;s search engine to hack others…or maybe Google as well.  Google and other search engines are such amazing indexing tools that often they can find bits of code or web pages that indicate what software a particular company uses.  This is most often the case with web applications, web servers, etc.  You can run specific queries in Google and it will tell you exactly who uses what.  I don&#8217;t know for sure that is what was used here, but it seems like a perfect application of such a tactic.</p>
<p>The cyber criminals had to get on the inside of the organization because code management systems are never connected to the Internet (or at least they definitely shouldn&#8217;t be).  <a href="http://ibnlive.in.com/news/google-china-hackers-stole-source-code-researcher/111020-11.html?from=tn?from=rssfeed" target="_blank">So they used targeted (spear) phishing attacks to do it.</a> Basically the bad guys knew if they could get some insider to fall prey to their phishing attack, they would essentially have the keys to the kingdom…which essentially they did.</p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/aurora-cyber-attackers-infiltrate-source-code-management-systems-of-google-and-others/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Attack Simulation Sheds Light on Lack of US Cybersecurity Preparedness</title>
		<link>http://perimeterusa.com/blog/attack-simulation-sheds-light-on-lack-of-us-cybersecurity-preparedness/</link>
		<comments>http://perimeterusa.com/blog/attack-simulation-sheds-light-on-lack-of-us-cybersecurity-preparedness/#comments</comments>
		<pubDate>Wed, 24 Feb 2010 16:15:58 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=644</guid>
		<description><![CDATA[The US staged a cyber attack simulation where a mobile phone worm spread to the internet and shuts down the financial markets, and the results were concerning.]]></description>
			<content:encoded><![CDATA[<div class="mceTemp">
<dl id="attachment_645" class="wp-caption alignleft" style="width: 310px;">
<dt class="wp-caption-dt"><img class="size-medium wp-image-645" title="_G1_8837" src="http://perimeterusa.com/blog/wp-content/uploads/2010/02/G1_8837-300x172.jpg" alt="s" width="300" height="172" /></dt>
<dd class="wp-caption-dd"></dd>
</dl>
</div>
<p>Perhaps some of you watched the <a href="http://bipartisanpolicy.org/events/cyber2010" target="_blank">Cyber Attack Simulation</a> on CNN on Sunday night (Feb 21).  It was a cyber attack simulation in which former US federal officials played roles as cabinet members.  It began with a mobile phone worm that spreads to the Internet subsequently shutting down the financial markets.  Then is what was assumed as a coordinated attack, physical bombs were detonated on key power grid points that shut down much of the eastern united states.  Throughout the course of the 2 hour event, it illustrated just <a href="http://www.washingtonpost.com/wp-dyn/content/article/2010/02/16/AR2010021605762_pf.html" target="_blank">how ill prepared the U.S. is</a> for a variety of scenarios like this.</p>
<p>What I liked about the program was learning about the policy limitations we have in the U.S. that make mitigation and damage control possible.  It was also interesting to see just how focused they are on perception of the public and fear of public back lash later for either doing to much or to little.  I don&#8217;t doubt that meetings like this are very concerned with those very things rather than getting the problem taken care of.</p>
<p>What I didn&#8217;t like is how unrealistic the simulation was.  First, it is possible that a worm designed for mobile phones could spread to PCs and the Internet at large, but that isn&#8217;t likely…at least not right now.  That would have to be a pretty flexible worm, and flexibility means large in size, which means it probably wouldn&#8217;t have originated on mobile phones.  But it isn&#8217;t out of the question. Second, they were talking about millions of people without mobile phones the cause of which would be an &#8220;act of war&#8221; etc.  That is silly.  There have been many times in the last several years that mobile phone networks have had issues, and I doubt it is even something discussed at a cabinet meeting.  There have been many times that worms, viruses, malware, or botnets rage on the Internet and no one calls a special cabinet session to figure out our &#8220;response&#8221;.  They made mention that emails were taking hours to be delivered.  Some people call that &#8220;Wednesday&#8221;.  That by itself simply doesn&#8217;t have enough weight to be worried about by the administration.  Then this cascaded into the shutdown of the financial markets, which from my limited understanding is quite separate from the Internet and there is little chance that a worm that is designed to spread from mobile phones to the Internet could then spread and take down the financial markets.  They are very separate things, with very different back end systems that do not have the same vulnerabilities that could be exploited by a single piece of malware.  Individual traders that use the Internet to buy and sell shares would likely have delays or no access.   But they could always call their broker and get them to trade on their behalf…unless they try to do that from their mobile phone.  But then in the simulation they said that it could spread to the regular phone network.  While communications companies are using and sharing more and more equipment for both data and voice communications, I don&#8217;t think a botnet/worm of nearly any imaginable size could take out the entire voice network disabling all communications.  Then there were the power outages.  They never said that the power outages were caused by the cyber attack, but referenced localized explosions at key points in the power grid.  If what the government and utility companies have told us in the past is true, then this may be possible.  When the northeast had their power outages a few years ago, they blamed it on overgrown trees in Ohio…although some speculate that it was the work of a cyber attack.  What I didn&#8217;t like about this portion was when a private power company notified the NSA that they were going to divert power from them to other customers that were without power.  While this may be a hypothetical scenario, I just can&#8217;t believe it would happen like that.</p>
<p>Overall, I didn&#8217;t think the scenario was very credible or realistic and clearly those that designed and played parts in it were not up to speed on how attacks like this are likely conducted, but it did shine light on interesting policy limitations that the government has that will make future real scenarios very interesting.</p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/attack-simulation-sheds-light-on-lack-of-us-cybersecurity-preparedness/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is the Chinese Government Really Trying to Stop Cybercrime?</title>
		<link>http://perimeterusa.com/blog/is-the-chinese-government-really-trying-to-stop-cybercrime/</link>
		<comments>http://perimeterusa.com/blog/is-the-chinese-government-really-trying-to-stop-cybercrime/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 14:53:30 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[Intrusion Detection System]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=612</guid>
		<description><![CDATA[The Chinese government has shut down hacker site Black Hawk, but it is questionable as to whether or not they are sincere about cracking down on cybercrime or just managing perception.]]></description>
			<content:encoded><![CDATA[<div class="mceTemp">
<dl id="attachment_613" class="wp-caption alignleft" style="width: 144px;">
<dt class="wp-caption-dt"><img class="size-full wp-image-613" title="china" src="http://perimeterusa.com/blog/wp-content/uploads/2010/02/china.gif" alt="c" width="134" height="89" /></dt>
<dd class="wp-caption-dd"></dd>
</dl>
</div>
<p>The Chinese police <a href="http://www.computerworld.com/s/article/9153238/China_shuts_hacker_training_site_arrests_three_?taxonomyId=17" target="_blank">have arrested 3</a> in conjunction with a hacker site called Black Hawk.  This site had been (among other things) selling membership fees totaling more than $1 million US.  This group has been known to threaten businesses such as Internet cafés telling them they would be shut down with a DDOS attack if they didn&#8217;t pay them.  Ultimately the Chinese authorities found them by tracking the phone number given to these businesses to pay Black Hawk.</p>
<p>What is really happening here is that the Chinese government feels the pressure as a result of the Google hacks and wants to appear like they are really cracking down on cybercrime.  The truth is, these bozos at Black Hawk aren&#8217;t anywhere near the level of sophistication as the Google hacks (which many believe were in face Chinese state sponsored).  So this really is nothing more than perception management by the Chinese, which likely means they are feeling a bit of pressure but ultimately have no intention of changing their behavior at the government level.</p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/is-the-chinese-government-really-trying-to-stop-cybercrime/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dispelling Long-Standing Myths About Cybersecurity</title>
		<link>http://perimeterusa.com/blog/dispelling-long-standing-myths-about-cybersecurity/</link>
		<comments>http://perimeterusa.com/blog/dispelling-long-standing-myths-about-cybersecurity/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 15:27:04 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[cybersecurity]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=160</guid>
		<description><![CDATA[There are a number of cybersecurity myths that need to be dispelled in order to properly mitigate the risk of a security breach.]]></description>
			<content:encoded><![CDATA[<div class="mceTemp">
<dl id="attachment_165" class="wp-caption alignleft" style="width: 157px;">
<dt class="wp-caption-dt"><img class="size-medium wp-image-165 " title="Dispelling Long-Standing Cybersecurity Myths" src="http://www.perimeterusa.com/blog/wp-content/uploads/2010/02/Myth-300x199.jpg" alt="Dispelling Long-Standing Cybersecurity Myths" width="147" height="97" /></dt>
</dl>
</div>
<p>I came across the following in the <a title="SANS NewsBites Newsletter - December" href="http://www.sans.org/newsletters/newsbites/newsbites.php?vol=11&amp;issue=100#sID301" target="_blank">December issue of the SANS Newsletter</a>.  I wanted to share because it&#8217;s so true!</p>
<blockquote><p>Melissa Hathaway, who earlier this year prepared the Cyberspace Policy Review for the Obama administration, says that we as individuals, organizations, governments and a nation need to shatter long-held myths about cyber space security and take steps to mitigate threats.  Some of the myths behind which these threats lurk include the notion that firewalls and antivirus software offer adequate protection from breaches; the idea that the government has solutions for cyber security problems; and the idea that &#8220;laws are keeping pace with technological innovation.&#8221;</p></blockquote>
<p>Melissa&#8217;s Blog Post &#8211; <a title="5 Myths About Cybersecurity" href="http://blog.executivebiz.com/five-myths-about-cybersecurity/6102" target="_blank">5 Myths About Cybersecurity</a></p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/dispelling-long-standing-myths-about-cybersecurity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Engineering Task Force Releases Botnet Remediation Recommendations</title>
		<link>http://perimeterusa.com/blog/internet-engineering-task-force-releases-botnet-remediation-recommendations/</link>
		<comments>http://perimeterusa.com/blog/internet-engineering-task-force-releases-botnet-remediation-recommendations/#comments</comments>
		<pubDate>Tue, 13 Oct 2009 15:38:12 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[cybersecurity]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=110</guid>
		<description><![CDATA[Worried about botnets? Well the IETF published a new document on their recommendation for botnet remediation. It sounds like they have written several methods to help internet service providers identify compromised systems and perhaps even redirect users to notification sites directing them to get their systems fixed. The truth is, it isn&#8217;t terribly difficult to [...]]]></description>
			<content:encoded><![CDATA[<p>Worried about botnets? Well the <a href="http://tools.ietf.org/html/draft-oreirdan-mody-bot-remediation-03" target="_new">IETF published a new document</a> on their recommendation for botnet remediation. It sounds like they have written several methods to help internet service providers identify compromised systems and perhaps even redirect users to notification sites directing them to get their systems fixed. The truth is, it isn&#8217;t terribly difficult to identify infected systems, but until the ISP&#8217;s have motivation and money to do this, it will likely not get installed very many places. It also doesn&#8217;t address what would happen to users that refuse to clean up their systems (for whatever reason). So this really sounds like one of those really good ideas that isn&#8217;t going to go anywhere.</p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/internet-engineering-task-force-releases-botnet-remediation-recommendations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter Used to Control Botnet</title>
		<link>http://perimeterusa.com/blog/twitter-used-to-control-botnet/</link>
		<comments>http://perimeterusa.com/blog/twitter-used-to-control-botnet/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 21:54:19 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=219</guid>
		<description><![CDATA[Twitter was used to control a botnet of a couple hundred infected personal computers, mostly in Brazil.]]></description>
			<content:encoded><![CDATA[<p>I am often asked to describe legitimate business uses for social networking services.  There are many legitimate uses.  I have heard some neat processes that use Twitter for disaster recovery alerts and Facebook to promote a companies products and services.  But I always find it interesting when criminals use technology for their purposes.  <a href="http://www.msnbc.msn.com/id/32421408/ns/technology_and_science-security/" target="_new">In this article </a><a href="http://www.msnbc.msn.com/id/32421408/ns/technology_and_science-security/" target="_new">the criminal  was using Twitter to send botnet command and control signals.</a> In other words, the criminal would post something to Twitter and the zombies (compromised computers) would listen on Twitter for messages to come through that could perform various desired commands.  A botnet may update software, launch attacks such as DDOS, spread to other systems, relay SPAM, and other nefarious acts.</p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/twitter-used-to-control-botnet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Golden Cash Bot</title>
		<link>http://perimeterusa.com/blog/golden-cash-bot/</link>
		<comments>http://perimeterusa.com/blog/golden-cash-bot/#comments</comments>
		<pubDate>Wed, 15 Jul 2009 21:45:19 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Firewall Software]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=361</guid>
		<description><![CDATA[A post regarding the Golden Cash bot and how it operates]]></description>
			<content:encoded><![CDATA[<p>A few more details that were uncovered on the Golden Cash Bot that can be leased by individuals for $5 to $100 for 1000 compromised PCs.  Once under your control, you can use it to steal data, send SPAM or any number of other nefarious purposes.</p>
<p>They call it Golden Cash because it is &#8220;Your money-making machine&#8221;. Customers pay for the ability to install different types of malware on the Golden Cash bots, which are recycled for new jobs and new customers afterward. Prices are higher for compromised PCs in western countries. In their examples 1,000 bots in Australia go for $100, but 1,000 bots in Vietnam go for a mere $5.</p>
<p>There was a good breakdown of the most common ways you can be infected &#8220;a cyber criminal creates a botnet by hiding malicious code in a legitimate Web site that is used to turn Web surfing PCs into zombies. The code, typically an iFrame, points the PCs to a separate Web site where they are then infected with a Trojan backdoor that reports back to the Golden Cash command and control server. Then the Golden Cash server installs an FTP (file transfer protocol) grabber on new zombies to steal credentials used by the computers to run Web sites, giving the server control over additional legitimate Web sites. Approximately 100,000 domains, including corporate domains from around the world, were identified among the stolen FTP credentials under Golden Cash&#8217;s control.&#8221;  100,000 domains is a whole lot of compromised websites.  Think how many hundreds, thousands, and millions of users hit these various websites daily.  For those interested, the Trojan name is &#8220;Trojan-Spy.Win32.Agent.amdz&#8221;.</p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/golden-cash-bot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Botnets for Rent Online</title>
		<link>http://perimeterusa.com/blog/botnets-for-rent-online/</link>
		<comments>http://perimeterusa.com/blog/botnets-for-rent-online/#comments</comments>
		<pubDate>Tue, 14 Jul 2009 21:46:39 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[cybersecurity]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=364</guid>
		<description><![CDATA[A post on the recent discovery of an online provider that rents botnets]]></description>
			<content:encoded><![CDATA[<p>Some people wonder how the use of botnets is facilitated. Certainly those that exploit systems effectively turning them into &#8220;Zombies&#8221; and placing them in a botnet can&#8217;t be the ones that always utilize these compromised systems, can they? Well researches recently uncovered what they believe to be a &#8220;clearninghosue&#8221; for botnets and malware. It is called &#8220;Golden Cash&#8221; and allows those with less then pure motives to rent time on botnet network. This clearninghouse allows controllers to buy, sell, collect data, share malware, and development tools. It is believed that Golden Cash is run by the Russian Business Network.</p>
<p>(<a href="http://news.cnet.com/8301-1009_3-10266977-83.html" target="_new">Read the CNET.com article here</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/botnets-for-rent-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8221; Macking &#8221; &#8211; Media Hacking</title>
		<link>http://perimeterusa.com/blog/macking-media-hacking/</link>
		<comments>http://perimeterusa.com/blog/macking-media-hacking/#comments</comments>
		<pubDate>Thu, 02 Jul 2009 21:53:09 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Macking]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=378</guid>
		<description><![CDATA[A post on the new classification of hacking the media, or Media Hacking called &#34;Macking&#34;.  Macking is a very popular tool used by cyber criminals to manipulate the media.]]></description>
			<content:encoded><![CDATA[<p>This is been quite a week with several celebrities that have passed away including Ed Mcmahon, Farrah Fawcett, and of course Michael Jackson.  As a result there are of course a flury of scams that are attempting to get people to click on links, open attachments and an assortment of other things.  In addition to this, we are seeing people taking advantage of the media, and how quickly bad information can be spread in our &#8220;instant information&#8221; society.  Stars that in fact are alive and well had passed away supposidly according to Internet blogs, web posts, Twitter, Facebook, and even some television stations.  A hacker even broke into Britney Spears Twitter account and and posted this message to all those that follow her &#8220;Britney has passed today. It is a sad day for everyone. More news to come&#8221;.</p>
<p>Manipulating media&#8230;in other words Media Hacking or &#8220;Macking&#8221; (as we have decided to call it)  is becoming quite popular.  There are of course many ways this can be facilitated.  I love the example on September 8, 2008 when old news report from December of 2002 was rehashed by someone about the bankrupcy of American Airlines and posted to Google who then applied a current date to the article (because it didn&#8217;t have one of its own).  The article was picked up by a 3rd party analyst and posted to the Bloomberg news network and within minutes the stock had plumeted more than 80% and the SEC had to halt trading on it.</p>
<p>Macking can be very profitable for cyber criminals, and in this day in age when search engines can be manipulated, botnets can send billions of email messages, social networking sites have works and viruses that can spread messages, it is easy to see why they do this.</p>
<p>In my opinion, Macking is the lowest of the low hanging fruit.  It is practically the fruit that falls off the tree and rolls to your feet.</p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/macking-media-hacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Botnet Threat</title>
		<link>http://perimeterusa.com/blog/the-botnet-threat/</link>
		<comments>http://perimeterusa.com/blog/the-botnet-threat/#comments</comments>
		<pubDate>Wed, 01 Jul 2009 21:54:59 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[cybersecurity]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=382</guid>
		<description><![CDATA[Botnets are becoming a bigger and bigger threat with relatively few people understanding why it is a big deal  The following  article  posted in Netw]]></description>
			<content:encoded><![CDATA[<p>Botnets are becoming a bigger and bigger threat, with relatively few people understanding why it is a big deal.  The following quote is from an article posted on NetworkWorld.com.</p>
<p><em>&#8220;Research from security vendor Finjan Inc. suggests enterprise IT shops are losing the war against those who would hijack company computers for botnets. Almost half the victims appear to be in the U.S. &#8212; most using Microsoft&#8217;s Internet Explorer (IE) browser.&#8221;</em></p>
<p><a href="http://www.networkworld.com/news/2009/050409-usa-and-ie-number-1.html?page=1" target="_new">You can read the full article at the NetworkWorld.com site here.</a> The article has some good information regarding the botnet threat.</p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/the-botnet-threat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>30,000 sites infected with malware</title>
		<link>http://perimeterusa.com/blog/30000-sites-infected/</link>
		<comments>http://perimeterusa.com/blog/30000-sites-infected/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 22:01:51 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Pharming]]></category>
		<category><![CDATA[Web Content Filtering]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=416</guid>
		<description><![CDATA[A post regarding the success of a particular pharming / redirection attack that has already lead to the compromise of more than 30,000 websites worldwide.]]></description>
			<content:encoded><![CDATA[<p>Several days ago I posted an article based on an announcement by Websense regarding a series of attacks that were compromising websites.  Since that time, the attack has infected and compromised more than 30,000 websites.  This is a pharming attack using website compromise that redirects to a malicious site.</p>
<p>Keep in mind that it isn&#8217;t just 30,000 sites that get infected, but rather how many individual users access these sites while they are compromised.  These users are redirected and potentially compromised themselves.  If just 1000 users are compromised from each site, we are talking about 30,000,000 new systems under remote command and control.  You can see why and how botnets grow so quickly.</p>
<p>For more details from Webense, click <a href="http://securitylabs.websense.com/content/Alerts/3412.aspx" target="_new">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/30000-sites-infected/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DDOS Attack Against Domain Register DNS</title>
		<link>http://perimeterusa.com/blog/ddos-attack-against-domain-register-dns/</link>
		<comments>http://perimeterusa.com/blog/ddos-attack-against-domain-register-dns/#comments</comments>
		<pubDate>Tue, 09 Jun 2009 22:06:51 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Intrusion Detection System]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=423</guid>
		<description><![CDATA[A post regarding an attack against a domain name registers DNS that resulted in a distributed denial of service (DDOS) condition for several Internet websites.]]></description>
			<content:encoded><![CDATA[<p>In a previous post, I mentioned how botnets have grown in size and sophistication that  we should gear up for some real attacks coming from them.  I think we will begin to see more attacks like the one that happened a couple of weeks ago in China.  A DDOS attack against a popular domain registrer in China.  The DDOS attack was specifically against the domain name servers (DNS).  The DNS servers resolve the friendly name like www.mydomain.com to the numbered IP address that is assigned to the web server.  When a system like this comes under attack, it makes it so other cannot get to the system, and therefore cannot resolve the name.  Effectively this blocks their access to the site&#8230;even though the site itself wasn&#8217;t attacked.  As time goes on and with the continual growth of botnets, we will see more attacks like this.</p>
<p><a href="http://www.pcworld.com/businesscenter/article/165319/dns_attack_downs_internet_in_parts_of_china.html" target="_new">Article</a></p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/ddos-attack-against-domain-register-dns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Infected Systems Worldwide</title>
		<link>http://perimeterusa.com/blog/infected-systems-worldwide/</link>
		<comments>http://perimeterusa.com/blog/infected-systems-worldwide/#comments</comments>
		<pubDate>Tue, 19 May 2009 20:44:28 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=455</guid>
		<description><![CDATA[A post regarding the growth of malware and botnets according to McAfee and Microsoft.]]></description>
			<content:encoded><![CDATA[<p>According to <a href="http://resources.mcafee.com/content/AvertReportQ109" target="_new">McAfee</a>, &#8220;Cybercriminals have taken control of almost 12 million new IP addresses in Q1 2009, a 50 percent increase over the previous quarter. The United States is now home to the largest percentage of botnet-infected computers, hosting 18 percent of all &#8220;zombie&#8221; machines.&#8221;  In their Global Threats Report, it shows Austrailia being #3 in the world for most infected computers.</p>
<p>Microsoft <a href="http://www.microsoft.com/security/portal/sir.aspx" target="_new">reports</a> are quite a bit different.  See <a href="http://www.atthebreach.com/blog/botnet-growth-worldwidebotnet-growth-worldwide/ " target="_new">chart</a>.  I don&#8217;t think it much matters who is in the lead or falling behind.  Several years ago when we attempted to implement blacklists based on world geography, it could have helped.  However those days are long gone in that we are truly a global society.  What I think is important to note here is that everyone agrees that the number of infected systems is going up at an alarming rate.</p>
<p>We at Perimeter E-Security of course monitor this traffic and behavior as well.  For those that are interested, our finding more closely match those of Microsoft and not McAfee in that Australia is close to the bottom on our list.</p>
<p>There might be several reasons for the discrepancy between McAfee and Microsoft.  Microsoft&#8217;s seems to me a better indicator because their tool is free and globally distributed and used.  McAfee, while having a very large user base, is not as equally distributed.  So their findings are likely skewed.</p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/infected-systems-worldwide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Botnets Can Now Officially Be Feared</title>
		<link>http://perimeterusa.com/blog/botnets-can-now-officially-be-feared/</link>
		<comments>http://perimeterusa.com/blog/botnets-can-now-officially-be-feared/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 21:24:44 +0000</pubDate>
		<dc:creator>Kevin Prince</dc:creator>
				<category><![CDATA[Blog Post]]></category>
		<category><![CDATA[cybersecurity]]></category>

		<guid isPermaLink="false">http://perimeterusa.com/blog/?p=484</guid>
		<description><![CDATA[A post on the growing danger from botnets]]></description>
			<content:encoded><![CDATA[<p>Botnets have been around for a long time.  For those not familiar, a botnet is a number of compromised computers put under the command and control of a single individual or group.  Individually compromised computers are known as zombies.  These systems are anywhere and everywhere in the world.  They can be the machine you are reading this from.  They can be a home or work computer.</p>
<p>It was only a couple of years ago that Vint Cerf, one of the original developers of the Internet estimated that one out of every four computers had malware and potentially part of a botnet.  At the same time the number of Internet enabled computers worldwide was about 600 million.  Today, F-Secure estimates the number of Internet accessible systems to be about double that at 1.2 billion systems.  <a href="http://www.fsecure.com/en_EMEA/security/security-lab/latest-threats/security-threat-summaries/2008-4.html" target="_new">F-Secure</a> claims that Finland has the lowest malware/botnet infection rate at about 1 percent of all systems.  So likely, the number is somewhere between 1 percent and 25 percent.  While that is a big spread, what is bigger is the number of systems that represents where 1 percent is over 12 million systems alone.</p>
<p>The Conficker botnet has lots of estimates on its size being anywhere from about 3 million to 12 million systems strong&#8230;and is likely one of the very biggest.  But Conficker is just one single botnet and there are many.</p>
<p>Systems in the U.S. account for only about 6 percent of Conficker computers.  This is likely a similar percentage of infection across other botnets as well.  This is primarily due to the high rate in which we have legal versions of operating systems and applications and can patch them.  In other areas of the world where software pirating is a huge problem, there is a much higher infection rate because those systems are not allowed to recieve patches and updates.</p>
<p>These botnets have very sophisticated communications with different methods including web access, peer-to-peer, etc.  This gives the botnet a secure (encrypted) method as well as differing methods to give and accept command and control instructions.</p>
<p>The scary thing about botnets is that with that many systems under the control of one individual, they could do a tremendous amount of damage to segments of the Internet or any business they targeted.  This would likely include distributed denial of service attacks (DDOS).  To date, botnets have been used to distribute SPAM which is why SPAM now accounts for more than 90% of all email sent.  When the controllers decide to do something really malicious&#8230;watch out!</p>
<p>On April 1st, 2009 Conficker went into a new mode that enhanced its capabilities.  Some thought this would lead to some instructions (or payload) that would launch some attack.  In reality, nothing happened for about a week.  Then the first update came instructing Conficker systems to begin harvesting new systems.  So they began scanning other systems looking for unpatched systems to compromise and spread to.  I think what scared some professionals was that previous to it getting its April 1 update, it had stopped all activity.  So some thought that might be a sign of the quiet before the storm.  Others thought that the botnet controllers were negotiating for the use of the botnet once April 1st hit.  While this may be true, with the new instructions for the systems to begin harvesting other computers, it may be that those negotiations ended.  It may mean nothing at all.</p>
<p>While the new instructions are timed to end in May, we must remember that the controllers can send a payload anytime they want to these systems to use new instructions.</p>
<p>With (likely) tens of millions of systems in botnets, I believe we are at a tipping point where the threat they impose is formitable and we need to be more aware of the threat.  While there isn&#8217;t a lot we can do to stop they once they take action against us, we can do a lot to keep our systems from joining the ranks of a botnet.</p>
<p>First, you should check if your systems are already infected.  There are many ways to do this.  For Conficker, there is a really easy method described <a href="http://www.atthebreach.com/blog/the-easiest-way-to-detect-conficker-compromised-systems/" target="_new">here</a>.  Most system virus and spyware protection packages can detect most botnet worms and infections.  Other applcations like Spybot Search and Destroy and Adaware as well as the free tool from Microsoft are also helpful.  But don&#8217;t make the mistake of assuming you only need one tool.</p>
<p>Second, keep the worms out and off your systems.  This takes a layered security approach and no one single solution.  Talk with a security professional about the best ways to protect yourself from botnet infections.</p>
]]></content:encoded>
			<wfw:commentRss>http://perimeterusa.com/blog/botnets-can-now-officially-be-feared/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
