<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Security Top Headlines</title>
	<atom:link href="http://www.pinolobu.com/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pinolobu.com/security</link>
	<description>interesting news and opinions about IT security</description>
	<lastBuildDate>Wed, 30 Sep 2009 09:05:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Ukraine-based cybercriminals steal from online German banks</title>
		<link>http://www.pinolobu.com/security/2009/09/30/ukraine-based-cybercriminals-steal-from-online-german-banks/</link>
		<comments>http://www.pinolobu.com/security/2009/09/30/ukraine-based-cybercriminals-steal-from-online-german-banks/#comments</comments>
		<pubDate>Wed, 30 Sep 2009 09:05:30 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[bank]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[germany]]></category>
		<category><![CDATA[online]]></category>
		<category><![CDATA[ukraine]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/?p=109</guid>
		<description><![CDATA[A report from security company Finjan said that cyber-criminals have developed sophisticated ways to remain undetected, describing how a Ukraine-based gang managed to steal 300,000 euros in 3 weeks in August 2009 from several German online banks.
It used a malicious software which:
- fooled banks&#8217; anti-fraud systems
- forging bank statements to hide the thefts.
It also recruited [...]]]></description>
			<content:encoded><![CDATA[<p>A <a href="http://www.finjan.com/GetObject.aspx?ObjId=679">report from security company Finjan</a> said that cyber-criminals have developed sophisticated ways to remain undetected, describing how a Ukraine-based gang managed to steal 300,000 euros in 3 weeks in August 2009 from several German online banks.</p>
<p>It used a malicious software which:<br />
- fooled banks&#8217; anti-fraud systems<br />
- forging bank statements to hide the thefts.</p>
<p>It also recruited innocent job-seekers as money mules.</p>
<p><a href="http://news.bbc.co.uk/2/hi/technology/8271384.stm">Full</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2009/09/30/ukraine-based-cybercriminals-steal-from-online-german-banks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to detect inserted hidden illicit content in web pages</title>
		<link>http://www.pinolobu.com/security/2009/08/25/how-to-detect-inserted-hidden-illicit-content-in-web-pages/</link>
		<comments>http://www.pinolobu.com/security/2009/08/25/how-to-detect-inserted-hidden-illicit-content-in-web-pages/#comments</comments>
		<pubDate>Tue, 25 Aug 2009 07:18:24 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
				<category><![CDATA[how-to]]></category>
		<category><![CDATA[frames]]></category>
		<category><![CDATA[Gumblar]]></category>
		<category><![CDATA[hidden]]></category>
		<category><![CDATA[unmaskparasites]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/?p=106</guid>
		<description><![CDATA[Hackers exploit security vulnerabilities in popular web software such as blogs, forums, CMS, image galleries and wikis to insert hidden illicit content into web pages of innocent third-party web sites.
Thousands of web site owners are unaware that their sites are hacked and infected with parasites.
So what you think is your website might not be really [...]]]></description>
			<content:encoded><![CDATA[<p>Hackers exploit security vulnerabilities in popular web software such as blogs, forums, CMS, image galleries and wikis to insert hidden illicit content into web pages of innocent third-party web sites.</p>
<p>Thousands of web site owners are unaware that their sites are hacked and infected with parasites.</p>
<p>So what you think is your website might not be really yours after all.</p>
<p>One tool to detect the presence of suspicious URLs in hidden frames is by using this tool:</p>
<p>http://www.unmaskparasites.com/</p>
<p>I used this to detect Gumblar, a botnet that infects Web servers and  infected Web site visitors for the purposes of installing malcode  on PCs that redirects end-user Google searches to fraudulent Web sites.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2009/08/25/how-to-detect-inserted-hidden-illicit-content-in-web-pages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware of facebook phishing site: faecibook.com</title>
		<link>http://www.pinolobu.com/security/2009/08/15/beware-of-facebook-phishing-site-faecibookcom/</link>
		<comments>http://www.pinolobu.com/security/2009/08/15/beware-of-facebook-phishing-site-faecibookcom/#comments</comments>
		<pubDate>Sat, 15 Aug 2009 02:56:51 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
				<category><![CDATA[case studies]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[faecibook]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/?p=105</guid>
		<description><![CDATA[First post I&#8217;ve seen is dated 7th August 2009.
If you see a comment that goes something like this, DO NOT CLICK ON IT:
seen this really bad blog about you? http://www.jdsense.com/search/redirect.php?f=http://blogs.faecibook.com/sessionid?nglnbskuf

Apparently China based, it will bring you to an authentic-looking FAKE Facebook page that tells you Your Session Has Expired and will require you to login [...]]]></description>
			<content:encoded><![CDATA[<p>First post I&#8217;ve seen is dated 7th August 2009.</p>
<p>If you see a comment that goes something like this, DO NOT CLICK ON IT:</p>
<blockquote><p>seen this really bad blog about you? http://www.jdsense.com/search/redirect.php?f=http://blogs.faecibook.com/sessionid?nglnbskuf
</p></blockquote>
<p>Apparently China based, it will bring you to an authentic-looking FAKE Facebook page that tells you Your Session Has Expired and will require you to login with your email and password. </p>
<p>Its only purpose is to harvest your email address and facebook password, and the creators are writing comments on strangers&#8217; statuses. </p>
<p>So far, the comments have been either &#8220;seen this really bad blog about you?&#8221; or &#8220;I have a 13 year old daughter who is in LOVE with you.&#8221; </p>
<p>Apparently, in a few minutes, the message will be deleted.</p>
<p>If you happen to experience this, CHANGE YOUR PASSWORD NOW!!!</p>
<p>Technical info:</p>
<p>It seems the domain was set up on 6th August 2009 under the name Li Wang, registered in Shanghai with email lixing688@gmail.com, and phone/fax no: 86-021-51697771</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2009/08/15/beware-of-facebook-phishing-site-faecibookcom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>High profile websites attacked</title>
		<link>http://www.pinolobu.com/security/2009/08/07/high-profile-websites-attacked/</link>
		<comments>http://www.pinolobu.com/security/2009/08/07/high-profile-websites-attacked/#comments</comments>
		<pubDate>Fri, 07 Aug 2009 13:04:22 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[DDOS]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[livejournal]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/?p=104</guid>
		<description><![CDATA[High-profile websites including Google, Facebook and Twitter have been targeted by hackers in what is described as a &#8220;massively co-ordinated attack&#8221;. Other sites such as the blogging platform Live Journal were also reportedly targeted. 
Full
]]></description>
			<content:encoded><![CDATA[<p>High-profile websites including Google, Facebook and Twitter have been targeted by hackers in what is described as a &#8220;massively co-ordinated attack&#8221;. Other sites such as the blogging platform Live Journal were also reportedly targeted. </p>
<p><a href="http://news.bbc.co.uk/2/hi/technology/8189162.stm">Full</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2009/08/07/high-profile-websites-attacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter suffers DDOS attack, reopens 2 hours later</title>
		<link>http://www.pinolobu.com/security/2009/08/07/twitter-suffers-ddos-attack-reopens-2-hours-later/</link>
		<comments>http://www.pinolobu.com/security/2009/08/07/twitter-suffers-ddos-attack-reopens-2-hours-later/#comments</comments>
		<pubDate>Thu, 06 Aug 2009 17:45:57 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/?p=103</guid>
		<description><![CDATA[Micro-blogging service Twitter was taken offline for more than two hours on 6th August in what the company believes was a co-ordinated denial-of-service (DDOS) attack.
Full
]]></description>
			<content:encoded><![CDATA[<p>Micro-blogging service Twitter was taken offline for more than two hours on 6th August in what the company believes was a co-ordinated denial-of-service (DDOS) attack.</p>
<p><a href="http://news.bbc.co.uk/2/hi/technology/8188201.stm">Full</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2009/08/07/twitter-suffers-ddos-attack-reopens-2-hours-later/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple fixing iPhone security issue</title>
		<link>http://www.pinolobu.com/security/2009/08/01/apple-fixing-iphone-security-issue/</link>
		<comments>http://www.pinolobu.com/security/2009/08/01/apple-fixing-iphone-security-issue/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 18:05:35 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/?p=102</guid>
		<description><![CDATA[Apple is going to release a software patch to fix a recently reported iPhone security vulnerability, which is that specially crafted SMS messages could disconnect the phones from the network, or worse, hijacked.
And not just the iPhone, phones running Windows Mobile and Google Android Oses are also vulnerable.
Full
The BBC, 31 Jul 2009
]]></description>
			<content:encoded><![CDATA[<p>Apple is going to release a software patch to fix a recently reported iPhone security vulnerability, which is that specially crafted SMS messages could disconnect the phones from the network, or worse, hijacked.</p>
<p>And not just the iPhone, phones running Windows Mobile and Google Android Oses are also vulnerable.</p>
<p>Full<br />
<a href="http://news.bbc.co.uk/2/hi/technology/8177755.stm">The BBC, 31 Jul 2009</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2009/08/01/apple-fixing-iphone-security-issue/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Los Angeles proposes to drop own network for Google</title>
		<link>http://www.pinolobu.com/security/2009/07/20/los-angeles-proposes-to-drop-own-network-for-google/</link>
		<comments>http://www.pinolobu.com/security/2009/07/20/los-angeles-proposes-to-drop-own-network-for-google/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 03:03:45 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[angeles]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[LA]]></category>
		<category><![CDATA[los]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/?p=101</guid>
		<description><![CDATA[Security and privacy concerns have been raised over a multimillion-dollar proposal by Los Angeles, the second largest city in the US, to tap Google Inc.&#8217;s Internet-based services for government e-mail, police records and other confidential data.
At issue is the security of computerized records on everything from police investigations to potholes as America&#8217;s second-largest city considers [...]]]></description>
			<content:encoded><![CDATA[<p>Security and privacy concerns have been raised over a multimillion-dollar proposal by Los Angeles, the second largest city in the US, to tap Google Inc.&#8217;s Internet-based services for government e-mail, police records and other confidential data.</p>
<p>At issue is the security of computerized records on everything from police investigations to potholes as America&#8217;s second-largest city considers dumping its in-house computer network for Google e-mail and office programs that are accessed over the Internet.</p>
<p><a href="http://biz.thestar.com.my/news/story.asp?file=/2009/7/20/business/20090720084934&#038;sec=business">Full</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2009/07/20/los-angeles-proposes-to-drop-own-network-for-google/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers attack Facebook users by phishing</title>
		<link>http://www.pinolobu.com/security/2009/05/16/hackers-attack-on-facebook-users-by-phishing/</link>
		<comments>http://www.pinolobu.com/security/2009/05/16/hackers-attack-on-facebook-users-by-phishing/#comments</comments>
		<pubDate>Sat, 16 May 2009 05:30:08 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/?p=100</guid>
		<description><![CDATA[It was reported by Reuters on 16th May 2009 that in phishing attacks on Facebook&#8217;s million of users, they have successfully collected passwords from *some* of them. Exact number not revealed.
This is the latest in a series of attacks on the site.
Facebook said:
(i) it&#8217;s now &#8220;cleaning up damage&#8221;
(ii) it&#8217;s blocking compromised accounts.
Modus operandi of attackers:
(i) [...]]]></description>
			<content:encoded><![CDATA[<p>It was reported by Reuters on 16th May 2009 that in phishing attacks on Facebook&#8217;s million of users, they have successfully collected passwords from *some* of them. Exact number not revealed.</p>
<p>This is the latest in a series of attacks on the site.</p>
<p>Facebook said:<br />
(i) it&#8217;s now &#8220;cleaning up damage&#8221;<br />
(ii) it&#8217;s blocking compromised accounts.</p>
<p>Modus operandi of attackers:<br />
(i) breaking into accounts of some Facebook members; presumably via common methods like weak password guessing?<br />
(ii) send e-mails to friends of the member asking them to click on links to fake websites, designed to look like the Facebook home page. There, the victims were directed to log back in to the site, where in actual fact they logged into the one controlled by the hackers, hence revealing their passwords.</p>
<p>The fake domains include www.151.im, www.121.im and www.123.im. </p>
<p>As to the objective of the hackers, it&#8217;s believed that they wanted to take over a big number of accounts, then use them to send spam selling goods to Facebook members at large.</p>
<p><a href="http://www.reuters.com/article/newsOne/idUSTRE54D6BN20090514">Source</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2009/05/16/hackers-attack-on-facebook-users-by-phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More than 12 million computers are being controlled by cybercriminals</title>
		<link>http://www.pinolobu.com/security/2009/05/06/more-than-12-million-computers-are-being-controlled-by-cybercriminals/</link>
		<comments>http://www.pinolobu.com/security/2009/05/06/more-than-12-million-computers-are-being-controlled-by-cybercriminals/#comments</comments>
		<pubDate>Wed, 06 May 2009 14:52:42 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
				<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/?p=99</guid>
		<description><![CDATA[6 May 2009
Security firm McAfee monitored cyberspace since January 2009 and found that 12 million computers have been taken over by criminals.
And compared to last year, the number of zombies has increased by 50%.
The real number is likely to be higher.
The United States has 18% of the world&#8217;s infected computers. Second is China with 13%.
SOurce
The [...]]]></description>
			<content:encoded><![CDATA[<p>6 May 2009</p>
<p>Security firm McAfee monitored cyberspace since January 2009 and found that 12 million computers have been taken over by criminals.</p>
<p>And compared to last year, the number of zombies has increased by 50%.</p>
<p>The real number is likely to be higher.</p>
<p>The United States has 18% of the world&#8217;s infected computers. Second is China with 13%.</p>
<p>SOurce<br />
<a href="http://news.bbc.co.uk/2/hi/technology/8032886.stm">The BBC</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2009/05/06/more-than-12-million-computers-are-being-controlled-by-cybercriminals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A web page is infected every 4.5 seconds, and other current statistics</title>
		<link>http://www.pinolobu.com/security/2009/04/22/a-web-page-is-infected-every-45-seconds-and-other-current-statistics/</link>
		<comments>http://www.pinolobu.com/security/2009/04/22/a-web-page-is-infected-every-45-seconds-and-other-current-statistics/#comments</comments>
		<pubDate>Wed, 22 Apr 2009 03:47:11 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
				<category><![CDATA[personality]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/?p=98</guid>
		<description><![CDATA[Amongst other things mentioned at the ongoing 2009 RSA conference in San Francisco, the largest ICT security event in the world:
(i) ICT security pros need to work together to fight the now highly organised cyber criminals the world over. Online fraudsters &#8220;are not bound by any rules of law&#8221; and have control over &#8220;massive armies [...]]]></description>
			<content:encoded><![CDATA[<p>Amongst other things mentioned at the ongoing <a href="http://www.rsaconference.com/2009/US/Home.aspx">2009 RSA conference</a> in San Francisco, the largest ICT security event in the world:</p>
<p>(i) ICT security pros need to work together to fight the now highly organised cyber criminals the world over. Online fraudsters &#8220;are not bound by any rules of law&#8221; and have control over &#8220;massive armies of zombie computers&#8221;. No more acting independently: now there&#8217;s a need to collaborate, to create a common development process: standards, sharing technologies and integrating technologies and controls into the infrastructure.</p>
<p>(ii) Cyber criminals have infiltrated everything imaginable: from the US power grid to the Pentagon.</p>
<p>(iii) Sophos said a web page is infected every 4.5 seconds &#038; every day more than 20,000 new samples of malware are discovered.</p>
<p>(iv) Symantec said it had blocked 245 million attacks per month in 2008 : that&#8217;s 200,000 attacks every 30 minutes, and that 90% of attacks target confidential information</p>
<p>(v) Attackers are changing their approaches, from mass distribution (random attacks) to a few threats being distributed to micro-distribution where there are millions of distinct threats. Meaning, they now target individuals, to try to steal confidential information (medical, financial etc). Hence, anyone can be a victim.</p>
<p>Source<br />
<a href="http://news.bbc.co.uk/2/hi/technology/8011160.stm">The BBC, 21 April 2009</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2009/04/22/a-web-page-is-infected-every-45-seconds-and-other-current-statistics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
