<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>(-) HatSecurity.com</title>
	<atom:link href="http://hatsecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://hatsecurity.com</link>
	<description>../something for all Hats</description>
	<pubDate>Fri, 21 Nov 2008 12:29:48 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
	<language>en</language>
			<item>
		<title>Microsoft to dump OneCare subscription model</title>
		<link>http://hatsecurity.com/2008/11/19/microsoft-to-dump-onecare-subscription-model-offer-free-service-instead/</link>
		<comments>http://hatsecurity.com/2008/11/19/microsoft-to-dump-onecare-subscription-model-offer-free-service-instead/#comments</comments>
		<pubDate>Wed, 19 Nov 2008 20:42:36 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
		
		<category><![CDATA[general]]></category>

		<category><![CDATA[news]]></category>

		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=238</guid>
		<description><![CDATA[Microsoft&#8217;s Windows Live OneCare service never really received good reviews despite being one of the first entrants in to the retail Windows PC security marketplace with a all-in-one solution. Why not? Many reasons but primarily because it relies on products that are already available for free and does not work well with third-party programs.
Things could [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hatsecurity.com/wp-content/uploads/2008/11/windows_live_onecare_logo.png"><img class="alignright size-medium wp-image-239" title="windows_live_onecare_logo" src="http://hatsecurity.com/wp-content/uploads/2008/11/windows_live_onecare_logo.png" alt="" width="143" height="143" /></a>Microsoft&#8217;s Windows Live OneCare service never really received good reviews despite being one of the first entrants in to the retail Windows PC security marketplace with a all-in-one solution. Why not? Many reasons but primarily because it relies on products that are already available for free and does not work well with third-party programs.</p>
<p>Things could change for Microsoft with the introduction of &#8220;Morro&#8221; - a free solution that Microsoft describes as &#8220;comprehensive protection from malware including viruses, spyware, rootkits and trojans&#8230;will be architected for a smaller footprint that will use fewer computing resources, making it ideal for low-bandwidth scenarios or less powerful PCs&#8221;. &#8220;Morro&#8221; would be available in the second half of 2009; Windows Live OneCare subscription service will be discontinued effective June 30, 2009.</p>
<p>According to Microsoft&#8217;s official <a href="http://www.microsoft.com/Presspass/press/2008/nov08/11-18NoCostSecurityPR.mspx" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.microsoft.com');">press release:</a></p>
<blockquote><p>“Customers around the world have told us that they need comprehensive, ongoing protection from new and existing threats, and we take that concern seriously,” said Amy Barzdukas, senior director of product management for the Online Services and Windows Division at Microsoft. “This new, no-cost offering will give us the ability to protect an even greater number of consumers, especially in markets where the growth of new PC purchases is outpaced only by the growth of malware.”</p></blockquote>
<p>It would be interesting to see how Symantec and McAfee respond to this move by Microsoft.</p>
<p class="addtoany_share_save_container">
    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=%28-%29%20HatSecurity.com&amp;siteurl=http%3A%2F%2Fhatsecurity.com%2F&amp;linkname=Microsoft%20to%20dump%20OneCare%20subscription%20model&amp;linkurl=http%3A%2F%2Fhatsecurity.com%2F2008%2F11%2F19%2Fmicrosoft-to-dump-onecare-subscription-model-offer-free-service-instead%2F"><img src="http://hatsecurity.com/wp-content/plugins/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>

	</p>]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/11/19/microsoft-to-dump-onecare-subscription-model-offer-free-service-instead/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Dodgy domain registrar de-accredited by ICANN</title>
		<link>http://hatsecurity.com/2008/10/30/domain-registrar-de-accredited-by-icann-on-charges-of-fraud/</link>
		<comments>http://hatsecurity.com/2008/10/30/domain-registrar-de-accredited-by-icann-on-charges-of-fraud/#comments</comments>
		<pubDate>Thu, 30 Oct 2008 21:51:20 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
		
		<category><![CDATA[compliance]]></category>

		<category><![CDATA[general]]></category>

		<category><![CDATA[news]]></category>

		<category><![CDATA[fraud]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=234</guid>
		<description><![CDATA[The Internet Corporation for Assigned Names and Numbers (ICANN) has terminated its Registrar Accreditation Agreement (RAA) with EstDomains.com after the President of the company was convicted for credit card fraud, money laundering and document forgery.
This comes as welcome news by the cyber security community as EstDomains.com has been used by cyber criminals for years to hide their identities [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-235" title="estdomains" src="http://hatsecurity.com/wp-content/uploads/2008/10/estdomains.jpg" alt="" width="211" height="64" />The Internet Corporation for Assigned Names and Numbers (ICANN) has terminated its Registrar Accreditation Agreement (RAA) with EstDomains.com after the President of the company was convicted for credit card fraud, money laundering and document forgery.</p>
<p>This comes as welcome news by the cyber security community as EstDomains.com has been used by cyber criminals for years to hide their identities and conduct various malicious activities such as using domains for bot command &amp; control servers, drive-by downloads as well as spamming.</p>
<p>Here are some links of interest that provide more information on this story:</p>
<p>1. F-Secure Weblog - <a href="http://www.f-secure.com/weblog/archives/00001522.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.f-secure.com');">&#8220;Case EstDomains&#8221;</a> <br />
2. The Washington Post Company - <a href="http://voices.washingtonpost.com/securityfix/2008/10/icann_de-accredits_estdomains.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/voices.washingtonpost.com');">&#8220;ICANN De-Accredits EstDomains for CEO&#8217;s Fraud Convictions&#8221;</a><br />
3. Notice sent to EstDomains.com by ICANN <a href="http://www.icann.org/correspondence/burnette-to-tsastsin-28oct08-en.pdf" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.icann.org');">(pdf)</a></p>
<p class="addtoany_share_save_container">
    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=%28-%29%20HatSecurity.com&amp;siteurl=http%3A%2F%2Fhatsecurity.com%2F&amp;linkname=Dodgy%20domain%20registrar%20de-accredited%20by%20ICANN&amp;linkurl=http%3A%2F%2Fhatsecurity.com%2F2008%2F10%2F30%2Fdomain-registrar-de-accredited-by-icann-on-charges-of-fraud%2F"><img src="http://hatsecurity.com/wp-content/plugins/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>

	</p>]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/10/30/domain-registrar-de-accredited-by-icann-on-charges-of-fraud/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Yahoo! fixes cross-site scripting vulnerability</title>
		<link>http://hatsecurity.com/2008/10/28/yahoo-fixes-cross-site-scripting-vulnerability/</link>
		<comments>http://hatsecurity.com/2008/10/28/yahoo-fixes-cross-site-scripting-vulnerability/#comments</comments>
		<pubDate>Tue, 28 Oct 2008 23:13:28 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
		
		<category><![CDATA[general]]></category>

		<category><![CDATA[news]]></category>

		<category><![CDATA[cross-site scripting]]></category>

		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=202</guid>
		<description><![CDATA[Yahoo! has fixed a cross-site scripting vulnerability affecting the HotJobs website. The vulnerability, first reported by Netcraft allowed injection of malicious code that stole session authentication cookie of Yahoo! users and submitting them to a US-based webserver. Yahoo!&#8217;s statement found on Netcraft states:
 The team was made aware of this particular Cross-Site Scripting issue yesterday [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-203" title="yahoo" src="http://hatsecurity.com/wp-content/uploads/2008/10/yahoo.jpg" alt="" width="141" height="33" />Yahoo! has fixed a cross-site scripting vulnerability affecting the <a href="http://hotjobs.yahoo.com/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/hotjobs.yahoo.com');">HotJobs</a> website. The vulnerability, <a href="http://news.netcraft.com/archives/2008/10/26/ongoing_phishing_attack_exposes_yahoo_accounts.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/news.netcraft.com');">first reported by Netcraft</a> allowed injection of malicious code that stole session authentication cookie of Yahoo! users and submitting them to a US-based webserver. Yahoo!&#8217;s <a href="http://news.netcraft.com/archives/2008/10/26/ongoing_phishing_attack_exposes_yahoo_accounts.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/news.netcraft.com');">statement</a> found on Netcraft states:</p>
<blockquote><p><em> The team was made aware of this particular Cross-Site Scripting issue yesterday morning (Sunday, Oct. 26) and a fix was deployed within a matter of hours. Yahoo! appreciates Netcraft&#8217;s assistance in identifying this issue.</em></p>
<p><em> As a safety precaution, we recommend users change their passwords, should they still be concerned. Users should always verify via their Sign-in Seal that they are giving their passwords to Yahoo.com.</em></p></blockquote>
<p>The session authentication cookies could have been used for accessing Yahoo! services such as Yahoo! Mail and Yahoo! HotJobs amongst others.</p>
<p class="addtoany_share_save_container">
    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=%28-%29%20HatSecurity.com&amp;siteurl=http%3A%2F%2Fhatsecurity.com%2F&amp;linkname=Yahoo%21%20fixes%20cross-site%20scripting%20vulnerability&amp;linkurl=http%3A%2F%2Fhatsecurity.com%2F2008%2F10%2F28%2Fyahoo-fixes-cross-site-scripting-vulnerability%2F"><img src="http://hatsecurity.com/wp-content/plugins/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>

	</p>]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/10/28/yahoo-fixes-cross-site-scripting-vulnerability/feed/</wfw:commentRss>
		</item>
		<item>
		<title>US forms task force to combat defense data leaks</title>
		<link>http://hatsecurity.com/2008/10/28/usa-forms-task-force-to-combat-defense-data-leaks/</link>
		<comments>http://hatsecurity.com/2008/10/28/usa-forms-task-force-to-combat-defense-data-leaks/#comments</comments>
		<pubDate>Tue, 28 Oct 2008 14:03:09 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
		
		<category><![CDATA[general]]></category>

		<category><![CDATA[news]]></category>

		<category><![CDATA[Add new tag]]></category>

		<category><![CDATA[data leak]]></category>

		<category><![CDATA[military]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=190</guid>
		<description><![CDATA[A special task force has been setup by the US Army to combat theft of sensitive military information stored on computer systems of private-sector contractors. The task force, Defense Industrial Base Cyber-Security Task Force, came in to being earlier this year without much noise.
According to an army document produced in August this year for the [...]]]></description>
			<content:encoded><![CDATA[<p><img class="size-full wp-image-198 alignright" style="margin-left: 3px; margin-right: 3px;" title="usarmy-logo" src="http://hatsecurity.com/wp-content/uploads/2008/10/usarmy-logo2.jpg" alt="" width="118" height="150" />A special task force has been setup by the US Army to combat theft of sensitive military information stored on computer systems of private-sector contractors. The task force, Defense Industrial Base Cyber-Security Task Force, came in to being earlier this year without much noise.</p>
<p>According to an army document produced in August this year for the Pentagon&#8217;s Department for Acquisition, Technology and Logistics and first reported last week by <a href="http://www.insidedefense.com/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.insidedefense.com');">Inside Defense</a>:</p>
<blockquote><p>&#8220;Exfiltrations of unclassified data from [military contractor computer] systems have occurred and continue to occur, potentially undermining and even neutralizing the technological advantage and combat effectiveness of the future force,&#8221;</p>
<p><span id="intelliTXT">&#8220;Current … efforts largely focus on mitigating risks of compromise to war-fighting technologies as a result of traditional espionage or industrial theft,&#8221; </span></p>
<p><span id="intelliTXT">&#8220;hostile actors can exfiltrate large volumes of unclassified program information in a single attack that can potentially net enough information to enable adversaries to narrow a capability gap.&#8221; </span></p></blockquote>
<p>Sure this initiative will bear fruit but I think more needs to be done within the Government security departments to combat potential cyber security threats. Only this week I saw Airport Security personnel hooked up on MSN.com at the Chicago O&#8217;Hare International Airport on a light day. Open Internet is a risky area for airport security personnel don&#8217;t you think?</p>
<p>More on the story <a href="http://www.washingtontimes.com/news/2008/oct/27/army-defense-task-force-targeting-hackers/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.washingtontimes.com');">here</a></p>
<p class="addtoany_share_save_container">
    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=%28-%29%20HatSecurity.com&amp;siteurl=http%3A%2F%2Fhatsecurity.com%2F&amp;linkname=US%20forms%20task%20force%20to%20combat%20defense%20data%20leaks&amp;linkurl=http%3A%2F%2Fhatsecurity.com%2F2008%2F10%2F28%2Fusa-forms-task-force-to-combat-defense-data-leaks%2F"><img src="http://hatsecurity.com/wp-content/plugins/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>

	</p>]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/10/28/usa-forms-task-force-to-combat-defense-data-leaks/feed/</wfw:commentRss>
		</item>
		<item>
		<title>UK defense ministry in possible identify theft scare</title>
		<link>http://hatsecurity.com/2008/10/10/uk-defense-ministry-in-possible-identify-theft/</link>
		<comments>http://hatsecurity.com/2008/10/10/uk-defense-ministry-in-possible-identify-theft/#comments</comments>
		<pubDate>Fri, 10 Oct 2008 19:11:59 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
		
		<category><![CDATA[general]]></category>

		<category><![CDATA[news]]></category>

		<category><![CDATA[identify theft]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=184</guid>
		<description><![CDATA[CNN is reporting that the Ministry of Defense of the UK has lost track of a portable hard drive which according to a tabloid carries information on some 100,000 British military personnel and 600,000 potential recruits.
One can only wonder whether the information on the hard drive was encrypted or not&#8230;

    

	]]></description>
			<content:encoded><![CDATA[<p>CNN is <a href="http://edition.cnn.com/2008/WORLD/europe/10/10/MOD.data.loss.ap/index.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/edition.cnn.com');">reporting</a> that the Ministry of Defense of the UK has lost track of a portable hard drive which according to a tabloid carries information on some 100,000 British military personnel and 600,000 potential recruits.</p>
<p>One can only wonder whether the information on the hard drive was encrypted or not&#8230;</p>
<p class="addtoany_share_save_container">
    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=%28-%29%20HatSecurity.com&amp;siteurl=http%3A%2F%2Fhatsecurity.com%2F&amp;linkname=UK%20defense%20ministry%20in%20possible%20identify%20theft%20scare&amp;linkurl=http%3A%2F%2Fhatsecurity.com%2F2008%2F10%2F10%2Fuk-defense-ministry-in-possible-identify-theft%2F"><img src="http://hatsecurity.com/wp-content/plugins/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>

	</p>]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/10/10/uk-defense-ministry-in-possible-identify-theft/feed/</wfw:commentRss>
		</item>
		<item>
		<title>South Korean missile blueprints stolen?</title>
		<link>http://hatsecurity.com/2008/10/02/south-korean-missile-blueprints-stolen/</link>
		<comments>http://hatsecurity.com/2008/10/02/south-korean-missile-blueprints-stolen/#comments</comments>
		<pubDate>Thu, 02 Oct 2008 12:59:54 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
		
		<category><![CDATA[general]]></category>

		<category><![CDATA[news]]></category>

		<category><![CDATA[data leak]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=182</guid>
		<description><![CDATA[South Korea’s major newspaper, The Chosun Ilbo (Korean Daily News), is reporting that two of the country’s top defense equipment manufacturers, LIGNex1 and Hyundai Heavy Industries found malicious code on its computer systems designed to steal information.
According to the report:
LIGNex1 develops and manufactures Hyunmoo surface-to-surface missile, Haeseong ship-to-ship missile and Shingung portable ground-to-air weapons. Hyundai [...]]]></description>
			<content:encoded><![CDATA[<p>South Korea’s major newspaper,<em> <a href="http://english.chosun.com" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/english.chosun.com');">The Chosun Ilbo</a></em><a href="http://english.chosun.com" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/english.chosun.com');"> </a>(Korean Daily News), is reporting that two of the country’s top defense equipment manufacturers, <a href="http://lignex1.com/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/lignex1.com');">LIGNex1</a> and <a href="http://english.hhi.co.kr/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/english.hhi.co.kr');">Hyundai Heavy Industries</a> found malicious code on its computer systems designed to steal information.</p>
<p>According to the <a href="http://english.chosun.com/w21data/html/news/200809/200809290015.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/english.chosun.com');">report:</a></p>
<blockquote><p>LIGNex1 develops and manufactures Hyunmoo surface-to-surface missile, Haeseong ship-to-ship missile and Shingung portable ground-to-air weapons. Hyundai Heavy Industries manufactures Haeseong, the nation&#8217;s first Aegis ship, plus destroyers and submarines for the Navy. Although the development costs of such high-tech weapons are kept secret, the construction of the King Sejong the Great-class destroyer is said to cost over W1 trillion (US$1=W1,165) and development of Haeseong ship-to-ship missile W100 billion with each missile at approximately W2 billion.</p>
<p>The National Security Research Institute, which is affiliated with the Electronics and Telecommunications Research Institute, believes hackers have planted vicious codes through which they stolen information. &#8220;The research institute suspects the culprits are Chinese or North Korean hackers but doesn&#8217;t know specifically what information they stole,&#8221; Kim said. &#8220;In the worst case, the blueprints of missiles and Aegis ship could have been stolen.&#8221;</p></blockquote>
<p class="addtoany_share_save_container">
    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=%28-%29%20HatSecurity.com&amp;siteurl=http%3A%2F%2Fhatsecurity.com%2F&amp;linkname=South%20Korean%20missile%20blueprints%20stolen%3F&amp;linkurl=http%3A%2F%2Fhatsecurity.com%2F2008%2F10%2F02%2Fsouth-korean-missile-blueprints-stolen%2F"><img src="http://hatsecurity.com/wp-content/plugins/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>

	</p>]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/10/02/south-korean-missile-blueprints-stolen/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Biggest hacker underground market going bust; what next?</title>
		<link>http://hatsecurity.com/2008/09/21/darkmarket-biggest-hacker-underground-market-bust/</link>
		<comments>http://hatsecurity.com/2008/09/21/darkmarket-biggest-hacker-underground-market-bust/#comments</comments>
		<pubDate>Sun, 21 Sep 2008 12:35:05 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
		
		<category><![CDATA[general]]></category>

		<category><![CDATA[opinions]]></category>

		<category><![CDATA[identify theft]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=166</guid>
		<description><![CDATA[DarkMarket.ws, the online forum better known as the biggest hacker market for trading stolen online identities, credit card information, ATM skimmers, and a host of other related items - is shutting down Oct 4 according to a notice posted on the forum by one of the forum administrators, Splyntr.
The shut down plan follows arrest of [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hatsecurity.com/wp-content/uploads/2008/09/darkmarket-ws.jpg"><img class="alignright size-full wp-image-168" style="margin: 3px;" title="darkmarket-ws" src="http://hatsecurity.com/wp-content/uploads/2008/09/darkmarket-ws.jpg" alt="" width="280" height="90" /></a>DarkMarket.ws, the online forum better known as the biggest hacker market for trading stolen online identities, credit card information, <a href="http://en.wikipedia.org/wiki/Credit_card_fraud#Skimming" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">ATM skimmers</a>, and a host of other related items - is shutting down Oct 4 according to a notice posted on the forum by one of the forum administrators, <em>Splyntr</em>.</p>
<p>The shut down plan follows <a href="http://www.haber7.com/haber/20080912/Enselenen-Chao-sanal-semayi-anlatti.php" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.haber7.com');">arrest</a> of one of its administrators, <em>Cha0</em> (Cagatay Evyapan), by Turkish police earlier this month.</p>
<p>The whole story is covered in great detail this story on Wired&#8217;s Blog, <a href="http://blog.wired.com/27bstroke6/2008/09/notorious-crime.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/blog.wired.com');">Threat Level</a>.  So, what&#8217; next after DarkMarket.ws?</p>
<p><span id="more-166"></span></p>
<p>DarkMarket emerged after ShadowCrew.com was taken offline and I reckon it is not going to take long before another online community fills the void left by DarkMarket&#8217;s departure from the scene.</p>
<p>There are already a handful of other established online forums that cater to the needs of cyber criminals and new ones crop up all the time offering some high-value loot for those in need:</p>
<div id="attachment_170" class="wp-caption aligncenter" style="width: 272px"><a href="http://hatsecurity.com/wp-content/uploads/2008/09/card_fraud_1.jpg"><img class="size-medium wp-image-170" title="card_fraud_1" src="http://hatsecurity.com/wp-content/uploads/2008/09/card_fraud_1-262x300.jpg" alt="Trade details by a &quot;respected&quot; underground individual on a new forum" width="262" height="300" /></a><p class="wp-caption-text">Fig. 1- A post on a DarkMarket wanna-be forum</p></div>
<div id="attachment_171" class="wp-caption aligncenter" style="width: 310px"><a href="http://hatsecurity.com/wp-content/uploads/2008/09/card_fraud_2.jpg"><img class="size-medium wp-image-171" title="card_fraud_2" src="http://hatsecurity.com/wp-content/uploads/2008/09/card_fraud_2-300x289.jpg" alt="dfs" width="300" height="289" /></a><p class="wp-caption-text">Fig. 2: Same post, more details</p></div>
<p>Some of the more established forums would welcome the extra traffic that they generate from the less experienced DarkMarket users, looking for other market places to trade in:</p>
<div id="attachment_173" class="wp-caption aligncenter" style="width: 310px"><a href="http://hatsecurity.com/wp-content/uploads/2008/09/fake_credit_card1.jpg"><img class="size-medium wp-image-173" title="fake_credit_card1" src="http://hatsecurity.com/wp-content/uploads/2008/09/fake_credit_card1-300x163.jpg" alt="asdsadsa" width="300" height="163" /></a><p class="wp-caption-text">Fig. 3: &quot;Real-looking&quot; credit cards packed with actual victim data are now being sold online. </p></div>
<div id="attachment_176" class="wp-caption aligncenter" style="width: 310px"><a href="http://hatsecurity.com/wp-content/uploads/2008/09/fake_credit_card2.jpg"><img class="size-medium wp-image-176" title="fake_credit_card2" src="http://hatsecurity.com/wp-content/uploads/2008/09/fake_credit_card2-300x165.jpg" alt="dsf" width="300" height="165" /></a><p class="wp-caption-text">Fig. 4: They sure do look &quot;real&quot;</p></div>
<p>Indepent trading sites are likely to see a surge in their business too as some of the cyber criminals are likely to deal direct without exposing any of their information on any online forums:</p>
<div id="attachment_175" class="wp-caption aligncenter" style="width: 233px"><a href="http://hatsecurity.com/wp-content/uploads/2008/09/dumps.jpg"><img class="size-medium wp-image-175" title="dumps" src="http://hatsecurity.com/wp-content/uploads/2008/09/dumps-223x300.jpg" alt="sdf" width="223" height="300" /></a><p class="wp-caption-text">Fig. 5: One of the more &quot;reputable&quot; stolen credit card sales website. </p></div>
<p>Although none of the existing online hacker market places can truly replace the stature of DarkMarket, there is likely to be a surge in competition amongst the various online underground sites to try and reach the level of popularity that DarkMarket currently enjoys.</p>
<p>Any new community formed by the existing DarkMarket admins is likely to see stricter membership controls which probably served as the weak link for the forum; DarkMarket user-level access accounts were being retailed at competing forums privately for US$800 and above, just a couple of weeks ago.</p>
<p>It would be interesting to see what comes next after DarkMarket - and how the law enforcement agencies play catch-up with the notorious underground hacker market places.</p>
<p class="addtoany_share_save_container">
    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=%28-%29%20HatSecurity.com&amp;siteurl=http%3A%2F%2Fhatsecurity.com%2F&amp;linkname=Biggest%20hacker%20underground%20market%20going%20bust%3B%20what%20next%3F&amp;linkurl=http%3A%2F%2Fhatsecurity.com%2F2008%2F09%2F21%2Fdarkmarket-biggest-hacker-underground-market-bust%2F"><img src="http://hatsecurity.com/wp-content/plugins/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>

	</p>]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/09/21/darkmarket-biggest-hacker-underground-market-bust/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Google&#8217;s Chrome under fire</title>
		<link>http://hatsecurity.com/2008/09/08/google-chrome-security-vulnerabilities/</link>
		<comments>http://hatsecurity.com/2008/09/08/google-chrome-security-vulnerabilities/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 07:30:46 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
		
		<category><![CDATA[general]]></category>

		<category><![CDATA[news]]></category>

		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=156</guid>
		<description><![CDATA[The new JavaScript speed king, Google Chrome web browser is getting hammered by security researchers over security vulnerabilities ranging from crashing the browser to potentially running malicious code on the user&#8217;s computer.  Here&#8217;s a quick round-up of what I have come across so far:
1. &#8220;Carpet bomb&#8221; - September 3, 2008. Security researcher Aviv Raff managed [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hatsecurity.com/wp-content/uploads/2008/09/google-chrome.jpg"><img class="alignright size-full wp-image-157" title="google-chrome" src="http://hatsecurity.com/wp-content/uploads/2008/09/google-chrome.jpg" alt="" width="150" height="55" /></a>The new JavaScript <a href="http://news.cnet.com/8301-1001_3-10030888-92.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/news.cnet.com');">speed king</a>, Google Chrome web browser is getting hammered by security researchers over security vulnerabilities ranging from crashing the browser to potentially running malicious code on the user&#8217;s computer.  Here&#8217;s a quick round-up of what I have come across so far:</p>
<p>1. <strong>&#8220;Carpet bomb&#8221; - September 3, 2008</strong>. Security researcher <a href="http://aviv.raffon.net/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/aviv.raffon.net');">Aviv Raff</a> managed to discover this vulnerability hours after the browser was released. The vulnerability, when exploited could litter the user&#8217;s download directory with numerous irrelevant files or could potentially be used to exploit other vulnerabilities that may exist on the user&#8217;s machine.</p>
<p><span id="articleBody">Raff describes on his <a href="http://aviv.raffon.net/2008/09/03/GoogleMule.aspx" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/aviv.raffon.net');">site</a> how a specially-crafted java archive file (JAR), combined with a social engineering ploy could trick a user in to downloading and executing the file without any warning from the browser.</span></p>
<p>The vulnerability comes from Google&#8217;s use of an outdated version of <a href="http://webkit.org/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/webkit.org');">WebKit</a>, the open source browser engine toolkit used also by Apple&#8217;s Safari browser. The WebKit version used in Chrome is the same used in Safari 3.1, which had its own set of vulnerabilities.</p>
<p><strong>2. URL Handler Crash - September 3, 2008. </strong><a href="http://evilfingers.com/advisory/google_chrome_poc.php" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/evilfingers.com');">Rishi Narang</a> discovered an issue in Chrome that can crash Chrome altogether when the user visits a specially-crafted URL, throwing the following (<strong>G</strong>)message:</p>
<blockquote><p>Whoa! Google Chrome has crashed. Restart now?</p></blockquote>
<p><span id="more-156"></span></p>
<p><strong>3. &#8216;SaveAs&#8217; Buffer Overflow - September 5, 2008. </strong><a href="http://security.bkis.vn/?p=119" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/security.bkis.vn');">SVRT-Bkis</a>, a security team from Vietnam discovered this vulnerability that can allow an attacker to take control of the user&#8217;s computer.</p>
<p>The vulnerability lies in the &#8220;Save page as&#8230;&#8221; function which causes a buffer overflow when saving pages with very long page titles.  This aids the attackers to execute arbitrary code on users’ systems.</p>
<p>As of this writing, Google has patched this vulnerability.</p>
<p><strong>4. &#8220;Tool tip&#8221; DoS - September 8, 2008. </strong><em>Exodus</em><strong> </strong>of BlackHat Security (Israel) has <a href="http://www.blackhat.org.il/index.php/ready-set-chrome/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.blackhat.org.il');">discovered</a> that a large object title can crash Chrome. This works on the current version of Chrome (0.2.149.29 Built 1798). The PoC is <a href="http://www.blackhat.org.il/exploits/chrome-freeze-exploit.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.blackhat.org.il');">here.</a></p>
<p><em>Update: Click <a href="http://code.google.com/p/chromium/issues/list" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/code.google.com');">here</a> for an updated list of all publicly tracked Chrome issues.<br />
</em></p>
<pre><em>Article updated - October 01 - 3PM +4GMT</em></pre>
<p class="addtoany_share_save_container">
    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=%28-%29%20HatSecurity.com&amp;siteurl=http%3A%2F%2Fhatsecurity.com%2F&amp;linkname=Google%26%238217%3Bs%20Chrome%20under%20fire&amp;linkurl=http%3A%2F%2Fhatsecurity.com%2F2008%2F09%2F08%2Fgoogle-chrome-security-vulnerabilities%2F"><img src="http://hatsecurity.com/wp-content/plugins/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>

	</p>]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/09/08/google-chrome-security-vulnerabilities/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Best Western Hotel group&#8217;s systems hacked</title>
		<link>http://hatsecurity.com/2008/08/24/best-western-hotel-group-hacked/</link>
		<comments>http://hatsecurity.com/2008/08/24/best-western-hotel-group-hacked/#comments</comments>
		<pubDate>Sun, 24 Aug 2008 13:51:49 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
		
		<category><![CDATA[general]]></category>

		<category><![CDATA[news]]></category>

		<category><![CDATA[identify theft]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=150</guid>
		<description><![CDATA[The Sunday Herald is reporting that an international gang of computer hackers has penetrated the booking system of the Best Western Hotel group and stolen the identities of an estimated 8 million hotel guests.
The report states:
A Sunday Herald investigation has discovered that late on Thursday night, a previously unknown Indian hacker successfully breached the IT [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hatsecurity.com/wp-content/uploads/2008/08/logo-bestwestern.gif"><img class="alignright size-full wp-image-151" title="logo-bestwestern" src="http://hatsecurity.com/wp-content/uploads/2008/08/logo-bestwestern.gif" alt="" width="97" height="89" /></a><a href="http://www.sundayherald.co.uk/news/heraldnews/display.var.2432225.0.0.php" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.sundayherald.co.uk');">The Sunday Herald</a> is reporting that an international gang of computer hackers has penetrated the booking system of the Best Western Hotel group and stolen the identities of an estimated 8 million hotel guests.</p>
<p>The <a href="http://www.sundayherald.co.uk/news/heraldnews/display.var.2432225.0.0.php" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.sundayherald.co.uk');">report</a> states:</p>
<blockquote><p>A Sunday Herald investigation has discovered that late on Thursday night, a previously unknown Indian hacker successfully breached the IT defences of the Best Western Hotel group&#8217;s online booking system and sold details of how to access it through an underground network operated by the Russian mafia.</p>
<p>It is a move that has been dubbed the greatest cyber-heist in world history. The attack scooped up the personal details of every single customer that has booked into one of Best Western&#8217;s 1312 continental hotels since 2007.</p></blockquote>
<p>Update (August 27 - 11PM +4GMT) - <a href="http://www.foxnews.com/story/0,2933,411403,00.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.foxnews.com');">FOX News is reporting</a> that Best Western has denied the extend of the hacking incident claiming <span id="intelliTXT">the report by the Sunday Herald as </span><span id="intelliTXT">&#8220;grossly unsubstantiated&#8221; and &#8220;largely erroneous.&#8221; </span></p>
<p>Best Western did, however, confirm that a hacker was able to penentrate its computer network in one of the hotels in Berlin and install a trojan on one of the computers designed to steal data.</p>
<p class="addtoany_share_save_container">
    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=%28-%29%20HatSecurity.com&amp;siteurl=http%3A%2F%2Fhatsecurity.com%2F&amp;linkname=Best%20Western%20Hotel%20group%26%238217%3Bs%20systems%20hacked&amp;linkurl=http%3A%2F%2Fhatsecurity.com%2F2008%2F08%2F24%2Fbest-western-hotel-group-hacked%2F"><img src="http://hatsecurity.com/wp-content/plugins/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>

	</p>]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/08/24/best-western-hotel-group-hacked/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Redhat&#8217;s Fedora Project servers compromised</title>
		<link>http://hatsecurity.com/2008/08/23/redhats-fedora-project-servers-compromised/</link>
		<comments>http://hatsecurity.com/2008/08/23/redhats-fedora-project-servers-compromised/#comments</comments>
		<pubDate>Sat, 23 Aug 2008 08:21:06 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
		
		<category><![CDATA[general]]></category>

		<category><![CDATA[news]]></category>

		<category><![CDATA[compromised]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=145</guid>
		<description><![CDATA[Fedora Project Leader, Paul W. Frields, in announcement released yesterday, said that some Fedora servers were &#8220;illegally accessed&#8221; last week.
Here&#8217;s more from the announcement:
One of the compromised Fedora servers was a system used for signing Fedora packages. However, based on our efforts, we have high confidence that the intruder was not able to capture the [...]]]></description>
			<content:encoded><![CDATA[<p>Fedora Project Leader, Paul W. Frields, in <a href="https://www.redhat.com/archives/fedora-announce-list/2008-August/msg00012.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.redhat.com');">announcement</a> released yesterday, said that some Fedora servers were &#8220;illegally accessed&#8221; last week.</p>
<p>Here&#8217;s more from the <a href="https://www.redhat.com/archives/fedora-announce-list/2008-August/msg00012.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.redhat.com');">announcement:</a></p>
<blockquote><p>One of the compromised Fedora servers was a system used for signing Fedora packages. However, based on our efforts, we have high confidence that the intruder was not able to capture the passphrase used to secure the Fedora package signing key. Based on our review to date, the passphrase was not used during the time of the intrusion on the system and the passphrase is not stored on any of the Fedora servers.</p>
<p>While there is no definitive evidence that the Fedora key has been compromised, because Fedora packages are distributed via multiple third-party mirrors and repositories, we have decided to convert to new Fedora signing keys. This may require affirmative steps from every Fedora system owner or administrator. We will widely and clearly communicate any such steps to help users when available.</p></blockquote>
<p><span id="more-145"></span></p>
<p>Interestingly, RedHat has <a href="http://rhn.redhat.com/errata/RHSA-2008-0855.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/rhn.redhat.com');">posted</a> a critical openssh security update at the same time encouraging all customers with systems based on the x86 architecture to apply the update. Here&#8217;s more from the <a href="http://rhn.redhat.com/errata/RHSA-2008-0855.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/rhn.redhat.com');">errata:</a></p>
<blockquote><p>Last week Red Hat detected an intrusion on certain of its computer systems and took immediate action. While the investigation into the intrusion is on-going, our initial focus  was to review and test the distribution channel we use with our customers, Red Hat Network (RHN) and its associated security measures. Based on these efforts, we remain highly confident that our systems and processes prevented the intrusion from compromising RHN or the conten distributed via RHN and accordingly believe that customers who keep their systems updated using Red Hat Network are not at risk.  We are issuing this alert primarily for those who may obtain Red Hat binary packages via channels other than those of official Red Hat subscribers.</p>
<p>In connection with the incident, the intruder was able to sign a small number of OpenSSH packages relating only to Red Hat Enterprise Linux 4 (i386 and x86_64 architectures only) and Red Hat Enterprise Linux 5 (x86_64 architecture only).  As a precautionary measure, we are releasing an updated version of these packages, and have published a list of the tampered packages and how to detect them at</p></blockquote>
<p class="addtoany_share_save_container">
    <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?sitename=%28-%29%20HatSecurity.com&amp;siteurl=http%3A%2F%2Fhatsecurity.com%2F&amp;linkname=Redhat%26%238217%3Bs%20Fedora%20Project%20servers%20compromised&amp;linkurl=http%3A%2F%2Fhatsecurity.com%2F2008%2F08%2F23%2Fredhats-fedora-project-servers-compromised%2F"><img src="http://hatsecurity.com/wp-content/plugins/add-to-any/share_save_120_16.gif" width="120" height="16" alt="Share/Save/Bookmark"/></a>

	</p>]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/08/23/redhats-fedora-project-servers-compromised/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
