<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3139148209091608874</id><updated>2012-01-13T12:07:24.654-08:00</updated><category term='grandstreamdream'/><category term='Italian'/><category term='Unreal Rootkit'/><category term='tools'/><category term='Trojan.PWSteal.BS'/><category term='Fake IE7'/><category term='news'/><category term='Norman'/><category term='Robert Alan Soloway'/><category term='bugs'/><category term='malware'/><category term='Swedish'/><category term='GM'/><category term='Leon Battista Alberti'/><category term='McAfee'/><category term='Windows'/><category term='COMDEX'/><category term='Apple'/><category term='MS Viewer'/><category term='war'/><category term='Wyse'/><category term='Chuck Norris'/><category term='Custom Packer'/><category term='myspace.com'/><category term='Winfixer'/><category term='AV'/><category term='video'/><category term='portal'/><category term='Pctools'/><category term='Gozi'/><category term='spambots'/><category term='Ani Attack'/><category term='Spyware blog'/><category term='Zombies'/><category term='BIOS'/><category term='graphical representation'/><category term='hosting sites'/><category term='Conficker worm'/><category term='Rarlab'/><category term='IBM'/><category term='drama'/><category term='attack'/><category term='Security patch'/><category term='Windows Vista'/><category term='zlob'/><category term='VeriSign'/><category term='airlines'/><category term='Hacker'/><category term='Opera'/><category term='SP1'/><category term='Malicious SWF'/><category term='Fe-Secure BlackLight'/><category term='Clickbot.A'/><category term='Nitin'/><category term='Virtual machine'/><category term='Robotcop'/><category term='jotti virusscan'/><category term='Live Search'/><category term='iPhone'/><category term='report'/><category term='Firefox'/><category term='USB worm'/><category term='VMware'/><category term='Morro'/><category term='Windows Installer'/><category term='marketing'/><category term='Netscape'/><category term='Rockband'/><category term='Aternative Antivirus'/><category term='siteadvisor'/><category term='attachments'/><category term='Norton Computing'/><category term='Automatic threat analyzer'/><category term='Microsoft'/><category term='false positive'/><category term='Virus.Win32.Grum.a'/><category term='Chinese'/><category term='gadget'/><category term='Sysinternals'/><category term='Security Updates'/><category term='AVG'/><category term='Eurikify'/><category term='Spyware'/><category term='popuper'/><category term='Steve Jobs'/><category term='Browsers'/><category term='virus Bulletin'/><category term='Antivirus Industry'/><category term='Project Titan'/><category term='credit card'/><category term='Spam'/><category term='security threat'/><category term='Informationweek'/><category term='Pirates of the Carribean'/><category term='OneCare'/><category term='Webroot'/><category term='email worm'/><category term='Spying'/><category term='virustotal'/><category term='Packers'/><category term='Zango'/><category term='LinkOptimizer'/><category term='music'/><category term='Deluxe Communication'/><category term='over due bill'/><category term='IceSword'/><category term='Internet Security'/><category term='company'/><category term='phishing'/><category term='Antispy'/><category term='Adware.Zango'/><category term='Adware'/><category term='Winrar'/><category term='disgrace'/><category term='Linux'/><category term='Checkpoint'/><category term='virus'/><category term='rebrand'/><category term='AV Industry'/><category term='Sandbox'/><category term='Sophos'/><category term='Warezov'/><category term='Analysis'/><category term='Mark Russinovich'/><category term='discussion'/><category term='animated cursor'/><category term='detecting'/><category term='Antivirus vendors'/><category term='Kaspersky'/><category term='Messagelabs'/><category term='SQL'/><category term='AOL'/><category term='SurfSideKick'/><category term='Secureworks'/><category term='Cyberattack'/><category term='itnews.com'/><category term='Anti-Malware Testing Standards Organisation'/><category term='TCX'/><category term='Gromozon'/><category term='Rootkits'/><category term='Vipin Kumar'/><category term='Australia'/><category term='Windows Updates'/><category term='Attacks'/><category term='F-Secure'/><category term='Rootkit'/><category term='KB927891'/><category term='Jack Bauer'/><category term='BitDefender'/><category term='malware evolution'/><category term='Anti-virus test'/><category term='TrendMicro'/><category term='Clips'/><category term='Safari'/><category term='advertisement'/><category term='Brightmail'/><category term='Antivirus'/><category term='Porn'/><category term='underground economy'/><category term='Rootkit Technology'/><category term='acquisition'/><category term='AV-comparatives.org'/><category term='Anti-Spyware Coalition'/><category term='IE7'/><category term='Sunbelt'/><category term='TV'/><category term='reports'/><category term='court case'/><category term='QA'/><category term='180Solutions'/><category term='Thrid Brigade'/><category term='security scanners'/><category term='Trojan.Gromp'/><category term='New year'/><category term='April Fools'/><category term='Golden Pig'/><category term='RKDetector'/><category term='Spyware Doctor'/><category term='Haxdoor'/><category term='RootkitRevealers'/><category term='VBootkit'/><category term='RootkitBuster'/><category term='Bill Gates'/><category term='Symantec'/><category term='market'/><category term='top malware registry launchpoints'/><category term='Ben Edelman'/><category term='Trojan'/><category term='Hacking'/><category term='RBN'/><category term='Bodysuit'/><category term='Cyberhawk'/><category term='exploit'/><category term='ID theif'/><category term='Rootkit Unhooker'/><category term='24'/><category term='security list'/><category term='Google Maps'/><category term='Banload'/><category term='HIPS'/><category term='Web Ads'/><category term='top malware'/><category term='popups'/><category term='Computer Associates'/><category term='forum'/><category term='TROJ_STARTPA.QC'/><category term='spider drawing'/><category term='Trojan.Kardphisher'/><category term='Future Worrior'/><category term='CEO'/><category term='Robotgenius'/><category term='online scanners'/><category term='lawsuit'/><category term='3D animation'/><category term='Data theft'/><category term='Antispyware'/><category term='New technology'/><category term='Targeted Attacks'/><category term='Future Soldier'/><category term='cnet'/><category term='operating systems'/><category term='Crimeware'/><category term='Zdnet'/><category term='Ani exploit'/><category term='Windows fake activation'/><category term='Claus Valca'/><category term='YouTubes'/><category term='ID Focus'/><category term='Russian'/><category term='Advance research'/><category term='YouTube'/><category term='website'/><category term='Signacert'/><category term='XXX'/><category term='TrendProtect'/><category term='Passport'/><category term='Threat Expert'/><category term='Cybercrooks'/><category term='PC Tools'/><category term='John Howard'/><category term='GhostNet'/><category term='joke'/><category term='RFID'/><category term='Update'/><category term='Orkut'/><category term='RSA Conference'/><category term='cryptographers'/><category term='Orchestria'/><category term='threats'/><title type='text'>Consoleman Blog - Data forensic &amp; QA</title><subtitle type='html'>This blog is for public wanting to know more about computer security and IT Industry.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>94</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3978598087024556885</id><published>2009-04-30T18:53:00.000-07:00</published><updated>2009-04-30T18:58:02.104-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HIPS'/><category scheme='http://www.blogger.com/atom/ns#' term='TrendMicro'/><category scheme='http://www.blogger.com/atom/ns#' term='Thrid Brigade'/><title type='text'>AV Industry: Trend Micro buys Third Brigade</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(102, 0, 0);"&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold; color: rgb(102, 0, 0);"&gt;Trend Micro buys Third Brigade&lt;/span&gt;&lt;br /&gt;http://www.itnews.com.au/News/102128,trend-micro-buys-third-brigade.aspx&lt;br /&gt;By    Shaun Nichols&lt;br /&gt;30 April 2009 01:46PM&lt;br /&gt;&lt;br /&gt;Security giant Trend Micro is aiming to increase its enterprise security presence by acquiring enterprise specialist &lt;a href="http://thirdbrigade.com/"&gt;Third Brigade&lt;/a&gt; for an undisclosed sum.&lt;br /&gt;&lt;br /&gt;The companies said that the deal was made with server security in mind.&lt;br /&gt;&lt;br /&gt;Third Brigade specialises in datacentre security and Trend hopes that the deal will bolster its arsenal in both the physical and virtualised server markets.&lt;br /&gt;&lt;br /&gt;"Trend Micro has been a pioneer and global leader in server protection software for over ten years," said Trend chief executive Eva Chen.&lt;br /&gt;&lt;br /&gt;"This acquisition underscores our commitment to maintaining that leadership position, and accelerates our ongoing efforts to deliver innovative new solutions that are uniquely suited to dynamic datacentres, as they expand from physical to virtual and public/private cloud-computing environments."&lt;br /&gt;&lt;br /&gt;The company said that it also hopes to parlay Third Brigade's intrusion prevention systems (IPS) into its own enterprise offerings.&lt;br /&gt;&lt;br /&gt;The two companies have previously had a deal which includes embedding the Third Brigade IPS in Trend Micro's Intrusion Defense Firewall product.&lt;br /&gt;&lt;br /&gt;The two companies said that they hope to finalise the deal by the end of June.&lt;/blockquote&gt;&lt;br /&gt;Third Brigade specialized in Host Intrusion Prevention Systems (&lt;a href="http://en.wikipedia.org/wiki/Intrusion-prevention_system"&gt;HIPS&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3978598087024556885?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3978598087024556885/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3978598087024556885' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3978598087024556885'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3978598087024556885'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2009/04/av-industry-trend-micro-buys-third.html' title='AV Industry: Trend Micro buys Third Brigade'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-1994296508345837633</id><published>2009-04-07T22:57:00.000-07:00</published><updated>2009-04-07T22:59:49.882-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Norton Computing'/><category scheme='http://www.blogger.com/atom/ns#' term='CEO'/><category scheme='http://www.blogger.com/atom/ns#' term='Symantec'/><category scheme='http://www.blogger.com/atom/ns#' term='Brightmail'/><category scheme='http://www.blogger.com/atom/ns#' term='company'/><title type='text'>Enrique Salem takes over at Symantec</title><content type='html'>&lt;blockquote&gt;By    Shaun Nichols&lt;br /&gt;7 April 2009 02:16PM&lt;br /&gt;&lt;br /&gt;Symantec's new chief executive has officially taken over..&lt;br /&gt;&lt;br /&gt;The security and storage firm said that former chief operating officer Enrique Salem had formally assumed the chief executive and company president roles.&lt;br /&gt;&lt;br /&gt;Outgoing chief John Thompson is remaining with the company as board chairman.&lt;br /&gt;&lt;br /&gt;The move was first announced in November, but the official transition was delayed until the end of the company's fiscal year on April 4.&lt;br /&gt;&lt;br /&gt;"Through that process, Enrique emerged as the right person to lead the company and I am confident in his ability to continue to drive the success of our team," Thompson was quoted as saying in November.&lt;br /&gt;&lt;br /&gt;Salem will be the company's first new chief executive in more than ten years, rising to the position from the chief operating officer role.&lt;br /&gt;&lt;br /&gt;Salem had first joined Symantec as a lead engineer when the company acquired Norton Computing in 1990. He later became the company's first chief technology officer before leaving in 1999 to join Ask Jeeves.&lt;br /&gt;&lt;br /&gt;Salem returned to the company in 2004 when Symantec purchased Brightmail.&lt;br /&gt;&lt;br /&gt;Copyright © 2009 vnunet.com&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-1994296508345837633?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/1994296508345837633/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=1994296508345837633' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1994296508345837633'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1994296508345837633'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2009/04/enrique-salem-takes-over-at-symantec.html' title='Enrique Salem takes over at Symantec'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-5444609934901987786</id><published>2009-04-01T23:13:00.000-07:00</published><updated>2009-04-01T23:14:14.545-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rootkit'/><category scheme='http://www.blogger.com/atom/ns#' term='operating systems'/><category scheme='http://www.blogger.com/atom/ns#' term='BIOS'/><category scheme='http://www.blogger.com/atom/ns#' term='Attacks'/><title type='text'>New BIOS attack renders antivirus useless</title><content type='html'>&lt;blockquote&gt;By    Iain Thomson&lt;br /&gt;27 March 2009 10:45AM&lt;br /&gt;A new form of attack that installs a rootkit directly onto a computer’s BIOS system would render antivirus software useless researchers have warned.&lt;br /&gt;&lt;br /&gt;Alfredo Ortego and Anibal Sacco of Core Security Technologies explained that the attack was possible against almost all types of commonly used BIOS systems in use today.&lt;br /&gt;&lt;br /&gt;The two devised a 100 line Python script that could be flashed onto the BIOS to install a rootkit. Because the BIOS software activated before any other program on a computer when it starts up then normal antivirus software would be unable to detect it.&lt;br /&gt;&lt;br /&gt;“We tested the system on the most common types of BIOS,” said Ortega.&lt;br /&gt;&lt;br /&gt;“There is the possibility that newer types of Extensible Firmware Interface (EFI) BIOS may be resistant to the attack but more testing is needed.”&lt;br /&gt;&lt;br /&gt;The attack is only possible if the attacker already has full administrative control of the target PC, but this is possible through a standard virus infection. Once that is achieved the malware operator would be able to flash a rootkit directly onto the BIOS.&lt;br /&gt;&lt;br /&gt;Even if the initial virus was detected and removed the computer would still be under remote control. Even a full wipe of the hard drive and complete reinstallation of the operating system would not remove it they warned.&lt;br /&gt;&lt;br /&gt;If a sophisticated rootkit was put onto the BIOS it could be even more difficult for an administrator to debug the system, said Ivan Arce, chief technology officer at Core Security Technologies.&lt;br /&gt;&lt;br /&gt;“You’d need to reflash the BIOS with a system that you know has not been tampered with,” he said.&lt;br /&gt;&lt;br /&gt;“But if the rootkit is sophisticated enough it may be necessary to physically remove and replace the BIOS chip.”&lt;br /&gt;&lt;br /&gt;The attack vector is also usable against virtual systems the researchers said. The BIOS in VMware is embedded as a module in main VMware executable and thus could be altered.&lt;br /&gt;&lt;br /&gt;However it is possible to protect against this attack by locking down the BIOS chip from flash updates, either by password protecting the system against unauthorised changes or physically.&lt;br /&gt;&lt;br /&gt;“The best approach is prevention, preventing the virus from flashing onto the BIOS,” said Sacco.&lt;br /&gt;&lt;br /&gt;“You need to prevent flashing of the bios, even if it means pulling out jumper on motherboard.”&lt;br /&gt;&lt;br /&gt;Copyright © 2009 vnunet.com&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-5444609934901987786?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/5444609934901987786/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=5444609934901987786' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5444609934901987786'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5444609934901987786'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2009/04/new-bios-attack-renders-antivirus.html' title='New BIOS attack renders antivirus useless'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-2703974151022459068</id><published>2009-03-30T15:43:00.000-07:00</published><updated>2009-03-30T15:46:12.201-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='attack'/><category scheme='http://www.blogger.com/atom/ns#' term='April Fools'/><category scheme='http://www.blogger.com/atom/ns#' term='Conficker worm'/><title type='text'>Conficker worm threatens April Fools' chaos</title><content type='html'>&lt;blockquote&gt;March 30, 2009&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.smh.com.au/news/technology/security/conficker-worm-threatens-april-fools-chaos/2009/03/29/1238261419679.html?page=fullpage#contentSwap1"&gt;Article link&lt;/a&gt;&lt;br /&gt;The fast-moving &lt;a href="http://en.wikipedia.org/wiki/Conficker"&gt;Conficker computer worm&lt;/a&gt;, a scourge of the internet that has infected at least 3 million PCs, is set to spring to life in a new way on Wednesday - April Fools' Day.&lt;br /&gt;&lt;br /&gt;That's when many of the poisoned machines will get more aggressive about "phoning home" to the worm's creators over the internet. When that happens, the bad guys behind the worm will be able to trigger the program to send spam, spread more infections, clog networks with traffic, or try and bring down websites.&lt;br /&gt;&lt;br /&gt;Technically, this could cause havoc, from massive network outages to the creation of a cyberweapon of mass destruction that attacks government computers. But researchers who have been tracking Conficker say the date will probably come and go quietly.&lt;br /&gt;&lt;br /&gt;More likely, these researchers say, the programming change that goes into effect April 1 is partly symbolic - an April Fools' Day tweaking of Conficker's pursuers, who for now have been able to prevent the worm from doing significant damage.&lt;br /&gt;&lt;br /&gt;"I don't think there will be a cataclysmic network event," said Richard Wang, manager of the US research division of security firm Sophos. "It doesn't make sense for the guys behind Conficker to cause a major network problem, because if they're breaking parts of the internet they can't make any money."&lt;br /&gt;&lt;br /&gt;Previous Internet threats were designed to cause haphazard destruction. In 2003 a worm known as Slammer saturated the internet's data pipelines with so much traffic it crippled corporate and government systems, including ATM networks and 911 centres.&lt;br /&gt;&lt;br /&gt;Far more often now, internet threats are designed to ring up profits. Control of infected PCs is valuable on the black market, since the machines can be rented out, from one group of bad guys to another, and act as a kind of illicit supercomputer, sending spam, scanning Web sites for security holes, or participating in network attacks.&lt;br /&gt;&lt;br /&gt;The army of Conficker-infected machines, known as a "botnet," could be one of the greatest cybercrime tools ever assembled. Conficker's authors just need to figure out a way to reliably communicate with it.&lt;br /&gt;&lt;br /&gt;Infected PCs need commands to come alive. They get those commands by connecting to websites controlled by the bad guys. Even legitimate sites can be co-opted for this purpose, if hackers break in and use the sites' servers to send out malicious commands.&lt;br /&gt;&lt;br /&gt;So far, Conficker-infected machines have been trying to connect each day to 250 Internet domains - the spots on the internet where websites are parked. The bad guys need to get just one of those sites under their control to send their commands to the botnet. (The name Conficker comes from rearranging letters in the name of one of the original sites the worm was connecting to.)&lt;br /&gt;&lt;br /&gt;Conficker has been a victim of its success, however, because its rapid spread across the Internet drew the notice of computer security companies. They have been able to work with domain name registrars, which administer website addresses, to block the botnet from dialing in.&lt;br /&gt;&lt;br /&gt;Now those efforts will get much harder. On April 1, many Conficker-infected machines will generate a list of 50,000 new domains a day that they could try. Of that group, the botnet will randomly select 500 for the machines to actually query.&lt;br /&gt;&lt;br /&gt;The bad guys still need to get only one of those up and running to connect to their botnet. And the bigger list of possibilities increases the odds they'll slip something by the security community.&lt;br /&gt;&lt;br /&gt;Researchers already know which domains the infected machines will check, but pre-emptively registering them all, or persuading the registrars to neutralise all of them, is a bigger hurdle.&lt;br /&gt;&lt;br /&gt;"We expect something will happen, but we don't quite know what it will look like," said Jose Nazario, manager of security research for Arbor Networks, a member of the "Conficker Cabal," an alliance trying to hunt down the worm's authors.&lt;br /&gt;&lt;br /&gt;"With every move that they make, there's the potential to identify who they are, where they're located and what we can do about them," he added. "The real challenge right now is doing all that work around the world. That's not a technical challenge, but it is a logistical challenge."&lt;br /&gt;&lt;br /&gt;Conficker's authors also have updated the worm so infected machines have new ways to talk to each other. They can share malicious commands rather than having to contact a hacked Web site for instructions.&lt;br /&gt;&lt;br /&gt;That variation is important because it shows that even as security researchers have neutralised much of what the botnet might do, the worm's authors "didn't lose control of their botnet," said Michael La Pilla, manager of the malicious code operations team at VeriSign's iDefense division.&lt;br /&gt;&lt;br /&gt;The Conficker outbreak illustrates the importance of keeping current with Internet security updates. Conficker moves from PC to PC by exploiting a vulnerability in Windows that Microsoft Corp. fixed in October. But many people haven't applied the patch or are running pirated copies of Windows that don't get the updates.&lt;br /&gt;&lt;br /&gt;Unlike other internet threats that trick people into downloading a malicious program, Conficker is so good at spreading because it finds vulnerable PCs on its own and doesn't need human involvement to infect a machine.&lt;br /&gt;&lt;br /&gt;Once inside, it does nasty things. The worm tries to crack administrators' passwords, disables security software, blocks access to antivirus vendors' websites to prevent updating, and opens the machines to further infections by Conficker's authors.&lt;br /&gt;&lt;br /&gt;Someone whose machine is infected might have to reinstall the operating system.&lt;br /&gt;&lt;br /&gt;AP&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-2703974151022459068?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/2703974151022459068/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=2703974151022459068' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/2703974151022459068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/2703974151022459068'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2009/03/conficker-worm-threatens-april-fools.html' title='Conficker worm threatens April Fools&apos; chaos'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-2730130504102653561</id><published>2009-03-29T23:06:00.000-07:00</published><updated>2009-03-29T23:08:20.635-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='GhostNet'/><category scheme='http://www.blogger.com/atom/ns#' term='Spying'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking'/><category scheme='http://www.blogger.com/atom/ns#' term='Chinese'/><title type='text'></title><content type='html'>&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold;"&gt;Massive Chinese cyber hack revealed&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Reports reveal over 1000 computers were hacked&lt;br /&gt;&lt;br /&gt;Phil Muncaster&lt;br /&gt;vnunet.com, 29 Mar 2009&lt;br /&gt;&lt;br /&gt;&lt;img src="http://ivory.vnunet.com/images/security/censorship-china/medium.jpg" border="0" /&gt;&lt;br /&gt;&lt;span style="font-size: 9px; line-height: normal;"&gt;Chinese PCs conducted the cyber espionage&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Canadian researchers have revealed an extensive Chinese spying operation, which involved the hacking of over 1000 computers in 103 countries, according to reports in several leading newspapers today.&lt;br /&gt;&lt;br /&gt;The new report from the Information Warfare Monitor, a group comprising researchers from Ottawa-based think tank SecDev Group and the University of Toronto's Munk Centre for International Studies, was originally set up to investigate allegations of Chinese snooping on Tibetan exiles.&lt;br /&gt;&lt;br /&gt;However, the research ended up uncovering a much larger scale operation, eventually taking ten months to complete.&lt;br /&gt;&lt;br /&gt;According to a report in The Independent, the researchers uncovered a network involving 1,295 compromised computers from the ministries of foreign affairs of Iran, Bangladesh, Latvia, Indonesia, and others, and embassies including India, South Korea, Indonesia, Germany and Pakistan.&lt;br /&gt;&lt;br /&gt;Computers in the offices of the Dalai Lama in India, Brussels, London and New York, were also compromised.&lt;br /&gt;&lt;br /&gt;The network, dubbed GhostNet, used malware to penetrate PCs, conduct covert monitoring and steal files, according to the reports. The malware could also switch on the audio and camera equipment sometimes built-in to PCs in order to monitor those in the same room as those computers, the reports said.&lt;br /&gt;&lt;br /&gt;"This report serves as a wake-up call... these are major disruptive capabilities that the professional information security community, as well as policymakers, need to come to terms with rapidly,” the researchers are quoted as saying in The Guardian.&lt;br /&gt;&lt;br /&gt;Althought GhostNet is thought to have been controlled from Chinese PCs, the researchers were not able to make any firm link to Chinese government agencies. The team has now notified law enforcement agencies, including the FBI, according to reports. &lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-2730130504102653561?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/2730130504102653561/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=2730130504102653561' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/2730130504102653561'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/2730130504102653561'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2009/03/massive-chinese-cyber-hack-revealed.html' title=''/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-6954588757045214932</id><published>2009-03-25T16:10:00.000-07:00</published><updated>2009-03-25T16:12:33.873-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Eurikify'/><category scheme='http://www.blogger.com/atom/ns#' term='ID Focus'/><category scheme='http://www.blogger.com/atom/ns#' term='Computer Associates'/><category scheme='http://www.blogger.com/atom/ns#' term='court case'/><category scheme='http://www.blogger.com/atom/ns#' term='Orchestria'/><title type='text'>CA cuts one third of its Melbourne developers</title><content type='html'>&lt;blockquote&gt;By    Brett Winterford&lt;br /&gt;25 March 2009&lt;br /&gt;&lt;br /&gt;International software vendor CA will make just under one third of its Australian R&amp;amp;D staff redundant as a result of recent acquistions.&lt;br /&gt;&lt;br /&gt;Some 31 of the 103 security experts at its Melbourne R&amp;amp;D Lab will be offered alternative positions, outplacement services or severance packages.&lt;br /&gt;&lt;br /&gt;CA's Melbourne research and development lab has been responsible for the development of several IAM (Identity and Access Management) solutions including CA Identity Manager and CA Directory, core components of the vendor's IAM portfolio.&lt;br /&gt;&lt;br /&gt;The Melbourne Lab has developed new technologies for CA that are patented on a global basis.&lt;br /&gt;&lt;br /&gt;CA says the 31 developers are no longer required due to three new acquisitions.&lt;br /&gt;&lt;br /&gt;CA acquired &lt;a href="http://www.ca.com/us/press/release.aspx?cid=186938"&gt;ID Focus&lt;/a&gt; in October 2008, &lt;a href="http://www.ca.com/us/content/campaign.aspx?cid=199987"&gt;Eurikify&lt;/a&gt; in November 2008 and &lt;a href="http://www.itnews.com.au/News/92098,ca-to-acquire-orchestria.aspx"&gt;Orchestria&lt;/a&gt; in January 2009.&lt;br /&gt;&lt;br /&gt;A spokesperson for CA said these acquisitions created some duplicate roles within the vendor's global R&amp;amp;D operations.&lt;br /&gt;&lt;br /&gt;The spokesperson said the Melbourne development labs will continue to develop CA's IAM solutions after the restructure.&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-6954588757045214932?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/6954588757045214932/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=6954588757045214932' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6954588757045214932'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6954588757045214932'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2009/03/ca-cuts-one-third-of-its-melbourne.html' title='CA cuts one third of its Melbourne developers'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3255566705887977907</id><published>2009-02-08T19:37:00.000-08:00</published><updated>2009-02-08T19:38:28.604-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='website'/><category scheme='http://www.blogger.com/atom/ns#' term='Kaspersky'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL'/><title type='text'>Kaspersky failed to protect their own website from hackers</title><content type='html'>Full article: &lt;a href="http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/"&gt;Link&lt;/a&gt;&lt;br /&gt;&lt;blockquote&gt;Kaspersky is one of the leading companies in the security and antivirus&lt;br /&gt;market. It seems as though they are not able to secure their own data&lt;br /&gt;bases.&lt;br /&gt;Seems incredible but unfortunately, its true.&lt;br /&gt;Alter one of&lt;br /&gt;the parameters and you have access to EVERYTHING: users, activation codes, lists&lt;br /&gt;of bugs, admins, shop, etc.&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3255566705887977907?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3255566705887977907/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3255566705887977907' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3255566705887977907'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3255566705887977907'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2009/02/kaspersky-failed-to-protect-their-own.html' title='Kaspersky failed to protect their own website from hackers'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-1414552975914285464</id><published>2009-02-08T19:31:00.000-08:00</published><updated>2009-02-08T19:34:52.973-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RFID'/><category scheme='http://www.blogger.com/atom/ns#' term='ID theif'/><category scheme='http://www.blogger.com/atom/ns#' term='Passport'/><title type='text'>Why RFID is not suitable for ID card/Passport?</title><content type='html'>Here is why.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.itnews.com.au/News/95588,hackers-clone-passports-in-driveby-rfid-heist.aspx"&gt;&lt;strong&gt;Hackers clone passports in drive-by RFID heist&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;By Iain Thomson 4 February 2009&lt;br /&gt;&lt;blockquote&gt;A British hacker has shown how easy it is to clone US passport cards that use&lt;br /&gt;RFID by conducting a drive-by test on the streets of San Francisco.&lt;br /&gt;Chris&lt;br /&gt;Paget, director of research and development at Seattle-based IOActive, used a&lt;br /&gt;US$250 Motorola RFID reader and an antenna mounted in a car’s side window and&lt;br /&gt;drove for 20 minutes around San Francisco, with a colleague videoing the&lt;br /&gt;demonstration.&lt;br /&gt;During the demonstration he picked up the details of two US&lt;br /&gt;passport cards, which are fitted with RFID chips and can be used instead of&lt;br /&gt;traditional passports for travel to Canada, Mexico and the Caribbean.&lt;br /&gt;“I&lt;br /&gt;personally believe that RFID is very unsuitable for tagging people,” he&lt;br /&gt;said.&lt;br /&gt;“I don’t believe we should have any kind of identity document with RFID&lt;br /&gt;tags in them. My ultimate goal here would be, my dream for this research, would&lt;br /&gt;be to see the entire Western Hemisphere Travel Initiative be scrapped.”&lt;br /&gt;Using&lt;br /&gt;the data gleaned it would be relatively simple to make cloned passport cards he&lt;br /&gt;said. Real passport cards also support a ‘kill code’ (which can wipe the card’s&lt;br /&gt;data) and a ‘lock code’ that prevents the tag’s data being changed.&lt;br /&gt;However&lt;br /&gt;he believes these are not currently being used and even if they were the radio&lt;br /&gt;interrogation is done in plain text so is relatively easy for a hacker to&lt;br /&gt;collect and analyse.&lt;br /&gt;The ease with which the passport cards were picked up is&lt;br /&gt;even more worrying considering that less than a million have been issued to&lt;br /&gt;date.&lt;br /&gt;Paget is a renowned ‘white hat’ ethical hacker and has made the study&lt;br /&gt;of the security failings of RFID something of a speciality.&lt;br /&gt;In 2007 he was&lt;br /&gt;due to present a paper on the security failings of RFID at the Black Hat&lt;br /&gt;security conference in Washington but was forced to abandon the plans after an&lt;br /&gt;RFID company threatened him with legal action.&lt;br /&gt;He points out that RFID tags&lt;br /&gt;are increasingly being used in physical security systems such as building access&lt;br /&gt;cards and the technology needs significant security adding before it could be&lt;br /&gt;considered safe for commercial use.&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Copyright © 2009 vnunet.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-1414552975914285464?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/1414552975914285464/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=1414552975914285464' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1414552975914285464'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1414552975914285464'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2009/02/why-rfid-is-not-suitable-for-id.html' title='Why RFID is not suitable for ID card/Passport?'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-2505093901397637834</id><published>2008-12-11T19:41:00.000-08:00</published><updated>2008-12-11T19:52:52.684-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows Updates'/><category scheme='http://www.blogger.com/atom/ns#' term='Security patch'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Updates'/><title type='text'>Another big updates from Microsoft</title><content type='html'>&lt;blockquote&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Microsoft issues mammoth security update, biggest in five years&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 153);"&gt;Fixes 28 flaws in Windows, Office, IE, ActiveX development tools and more&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;By Gregg Keizer&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;December 9, 2008 (&lt;/span&gt;&lt;a style="color: rgb(0, 51, 0);" href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=Security&amp;amp;articleId=9123042&amp;amp;taxonomyId=17&amp;amp;pageNumber=1"&gt;Article&lt;/a&gt;&lt;span style="color: rgb(0, 51, 0);"&gt; from: Computerworld)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;Microsoft Corp. today patched 28 vulnerabilities, nearly all of them marked "critical," in the biggest batch of fixes it has issued since it switched to a regular monthly update schedule more than five years ago.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;Of the 28 bugs quashed today, Microsoft ranked 23 of them critical, the top rating in its four-step scoring system. Of the five others, three were judged to be "important," the next step down, and two were pegged as "moderate." The patches were issued in eight updates for Windows, Internet Explorer, Office, SharePoint, Windows Media, and the company's most popular development tools, Visual Basic and Visual Studio. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;Researchers agreed that one of the Windows updates should be tops on everyone's to-do list. "There are a few that will stick out for a lot of people," said Andrew Storms, director of security operations at nCircle Network Security Inc. "The GDI is one." &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="color: rgb(0, 51, 0);" href="http://www.microsoft.com/technet/security/Bulletin/MS08-071.mspx"&gt;MS08-071&lt;/a&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;, which contains two separate vulnerabilities, both critical, updates the Graphics Device Interface (GDI), the core graphics rendering component of Windows. GDI has been repeatedly patched by Microsoft, most recently in September. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;"This looks very similar to &lt;/span&gt;&lt;a style="color: rgb(0, 51, 0);" href="http://www.microsoft.com/technet/security/Bulletin/MS08-021.mspx"&gt;MS08-021&lt;/a&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;," said Storms, referring to an April update that patched two other GDI bugs. Like that earlier fix, as well as the one in September, hackers could exploit the vulnerabilities by duping users into opening or viewing malicious Windows Metafile (WMF) images. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;"[MS08-071] is something similar to what we saw with WMF files once before this year, and once last year, too," said Amol Sarwate, manager of Qualys Inc.'s vulnerability lab. "It's in the core kernel, it's always there, it's in all versions of Windows and the attack vector is pretty high." Like Storms, Sarwate put the update at the top of his list. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;The long-running patch job on GDI will, said Storms, inevitably prompt some to ask whether Microsoft's vaunted Security Development Lifecycle (SDL) process, under which it scrutinizes code as its written for bugs, really works. "Is SDL functioning? I don't know," Storms admitted. "Without seeing the code analysis, it's difficult to presume it's not." &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;"Yes, I think that's a fair question," said Wolfgang Kandek, chief technology officer at Qualys. "But is it realistic to expect Microsoft to find everything? No, it's not." &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;Storms said the IE update, &lt;/span&gt;&lt;a style="color: rgb(0, 51, 0);" href="http://www.microsoft.com/technet/security/Bulletin/MS08-073.mspx"&gt;MS08-073&lt;/a&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;, would be his next highest update priority, simply because of the number of vulnerabilities it fixes -- four, all critical -- and because of the dominance of Microsoft's browser. After that, it gets murkier. "GDI and IE are certainly top of the list, but beyond that it's a toss-up," he said. "It's going to be difficult for people in the trenches to understand what to go after the first and second." &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;Qualys' Sarwarte and Kandek, meanwhile, staked out &lt;/span&gt;&lt;a style="color: rgb(0, 51, 0);" href="http://www.microsoft.com/technet/security/Bulletin/MS08-070.mspx"&gt;MS08-070&lt;/a&gt;&lt;span style="color: rgb(0, 51, 0);"&gt; as the second-most-interesting update among today's eight. "This is a far-reaching vulnerability," said Kandek, who noted that while end users won't be installing this update for Visual Basic, it can potentially affect anyone who browses the Internet with IE. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;"Microsoft's telling developers that they need to update their development system and the Visual Basic runtimes, then notify users of the ActiveX controls that they've created," said Kandek, talking about the technology that provides IE with add-on functionality. "And again, all [hackers] have to do is just come up with a malicious Web site with vulnerable ActiveX controls." &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;The Visual Basic update patches a total of six bugs, all ranked critical. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;Other bulletins include updates that patch Microsoft Word's file format (&lt;/span&gt;&lt;a style="color: rgb(0, 51, 0);" href="http://www.microsoft.com/technet/security/Bulletin/MS08-072.mspx"&gt;MS08-072&lt;/a&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;, with a total of eight vulnerabilities), Microsoft Excel's file format (&lt;/span&gt;&lt;a style="color: rgb(0, 51, 0);" href="http://www.microsoft.com/technet/security/Bulletin/MS08-074.mspx"&gt;MS08-074&lt;/a&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;, three vulnerabilities), Windows Media (&lt;/span&gt;&lt;a style="color: rgb(0, 51, 0);" href="http://www.microsoft.com/technet/security/Bulletin/MS08-076.mspx"&gt;MS08-076&lt;/a&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;, two vulnerabilities), SharePoint (&lt;/span&gt;&lt;a style="color: rgb(0, 51, 0);" href="http://www.microsoft.com/technet/security/Bulletin/MS08-077.mspx"&gt;MS08-077&lt;/a&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;, one bug) and Windows Search (&lt;/span&gt;&lt;a style="color: rgb(0, 51, 0);" href="http://www.microsoft.com/technet/security/Bulletin/MS08-075.mspx"&gt;MS08-075&lt;/a&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;, which deals with two vulnerabilities). &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;Some caught the eye of researchers. "The reason why I'm expecting questions about whether SDL is working is because of &lt;/span&gt;&lt;a style="color: rgb(0, 51, 0);" href="http://www.microsoft.com/technet/security/Bulletin/MS08-076.mspx"&gt;MS08-076&lt;/a&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;," said Storms, referring to the two-patch update for Windows Media. "Both those bugs are very similar to what we've seen before in other Microsoft products." &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;Eric Schultze, the chief technology officer at Shavlik Technologies LLC, agreed. "This is closely related to a security patch from last month -- &lt;/span&gt;&lt;a style="color: rgb(0, 51, 0);" href="http://www.microsoft.com/technet/security/Bulletin/MS08-068.mspx"&gt;MS08-068&lt;/a&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;," said Schultze in an e-mail today. That bug, which Microsoft fixed in November, was in how the Server Message Block (SMB) protocol handled credentials when a user connected to an attacker's SMB server. At the time, Schultze and others claimed that the bug went back at least seven years. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;"It's similar to the &lt;/span&gt;&lt;a style="color: rgb(0, 51, 0);" href="http://www.microsoft.com/technet/security/Bulletin/MS08-068.mspx"&gt;MS08-068&lt;/a&gt;&lt;span style="color: rgb(0, 51, 0);"&gt; attack, but uses different communication mechanisms to log on to the computers," Schultze added. "Microsoft says that Windows Media Player doesn't play by the same rules as the operating system, and that's why this issue wasn't fixed in November. I'd get this one patched right away. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;Storms, however, pointed to &lt;/span&gt;&lt;a style="color: rgb(0, 51, 0);" href="http://www.microsoft.com/technet/security/Bulletin/MS08-075.mspx"&gt;MS08-075&lt;/a&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;, which patches Windows Search, the integrated desktop search function, in Windows Vista and Windows Server 2008. He found the update interesting, not so much because it only affects Microsoft's newest operating system, but because one of its two patches fixed a flaw in yet another protocol, this time "search-ms." &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;"There have been issues prior with protocol handlers in Windows," said Storms. "Why would Microsoft make it possible for a protocol handler to call my local file system? What's the validity of that?" &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;As Storms said, Microsoft has had to patch several protocol handler vulnerabilities in the last 13 months, starting with one in November 2007 in Windows XP and Server 2003 that the company argued for months was not its responsibility to fix. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 51, 0);"&gt;This month's eight security updates can be downloaded and installed via the Microsoft Update and Windows Update services, as well as through Windows Server Update Services.&lt;/span&gt;&lt;/blockquote&gt;This must be one of busiest month before the X-mas break.&lt;br /&gt;I've notice my Vista computer wanting me to install around 8 updates last night.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-2505093901397637834?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/2505093901397637834/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=2505093901397637834' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/2505093901397637834'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/2505093901397637834'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/12/another-big-updates-from-microsoft.html' title='Another big updates from Microsoft'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-8756133157340506109</id><published>2008-12-10T16:11:00.000-08:00</published><updated>2008-12-10T16:18:25.703-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='threats'/><category scheme='http://www.blogger.com/atom/ns#' term='AV Industry'/><title type='text'>More scary news before the X-mas from Antivirus vendors</title><content type='html'>&lt;blockquote style="color: rgb(102, 51, 102);"&gt;&lt;a href="http://www.itnews.com.au/News/90912,computer-threats-becoming-more-sophisticated.aspx"&gt;&lt;span style="font-weight: bold;"&gt;Computer threats becoming more sophisticated &lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;By Computing staff&lt;br /&gt;11 December 2008&lt;br /&gt;&lt;br /&gt;The scale and sophistication of IT security threats increased at an unprecedented rate during 2008, according to a series of end-of-year research studies published last week.&lt;br /&gt;&lt;br /&gt;Anti-virus vendor Kaspersky Lab said that 15 million new forms of malware will have been detected by the end of this year ­ up from just two million in 2007.&lt;br /&gt;&lt;br /&gt;IBM said data from its 3,700 managed security services customers worldwide showed that the number of security events rose from 1.8 billion to 2.5 billion per day over the past four months alone.&lt;br /&gt;&lt;br /&gt;And security firm F-Secure said the level of malware detections trebled over the year to equal the total amount accumulated over the previous 21 years.&lt;br /&gt;&lt;br /&gt;“It would be no surprise if the cyber-crime business [in 2008] was worth not less than US$100bn, said Kaspersky Lab chief executive Eugene Kaspersky. “Unfortunately, the anti-malware industry is in a panic. It has finally recognised that it needs to invest more in technology.”&lt;br /&gt;&lt;br /&gt;Kaspersky estimated that there are “tens of thousands of people in the cyber-crime business”, and that security vendors are engaging in technical espionage and battling with each other to recruit the best engineers to keep up.&lt;br /&gt;&lt;br /&gt;Mikko Hyppönen, chief research officer at F-Secure, said online crime is now more prevalent and more professional than ever before, and put the blame on the inability of national and international authorities to catch, prosecute and sentence computer criminals.&lt;br /&gt;&lt;br /&gt;“The bottom line is that too few of the perpetrators of internet crime are either caught or punished,” he said. “If no action is taken it sends the message to these criminals that internet crime is an easy way to make a lot of money and they will never be caught or punished.”&lt;br /&gt;&lt;br /&gt;Copyright © 2008 Computing&lt;/blockquote&gt;&lt;br /&gt;As expected from every year's end of the year reports by AV vendors, in another words it's expected numbers as number of computers are increasing as well as market competitions becoming difficult and these AV vendors are scared of financial meltdown may led to slow sale.&lt;br /&gt;So this may help them to stay.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-8756133157340506109?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/8756133157340506109/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=8756133157340506109' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8756133157340506109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8756133157340506109'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/12/more-scary-news-before-x-mas-from.html' title='More scary news before the X-mas from Antivirus vendors'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-8334640419071429816</id><published>2008-12-02T21:00:00.000-08:00</published><updated>2008-12-02T21:07:56.723-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VMware'/><category scheme='http://www.blogger.com/atom/ns#' term='Wyse'/><category scheme='http://www.blogger.com/atom/ns#' term='TCX'/><category scheme='http://www.blogger.com/atom/ns#' term='Virtual machine'/><title type='text'>VMware: New VMware 3.0</title><content type='html'>&lt;blockquote&gt;&lt;span style="color:#663366;"&gt;&lt;strong&gt;VMware View 3 enhances virtual desktops&lt;/strong&gt;&lt;br /&gt;By Daniel Robinson 3 December 2008&lt;br /&gt;&lt;br /&gt;VMware has updated its virtual desktop product with enhancements that&lt;br /&gt;make it easier to provision and manage virtual clients, and new capabilities&lt;br /&gt;that support mobile workers on laptops.Released today, VMware View 3 is a&lt;br /&gt;rebranding of the firm's Virtual Desktop Infrastructure (VDI) but with several&lt;br /&gt;new features.&lt;br /&gt;Key among these is View Composer, which can provision virtual&lt;br /&gt;machines by combining a fixed master image with changeable user data stored&lt;br /&gt;separately, dramatically cutting the storage required for virtual&lt;br /&gt;clients.&lt;br /&gt;The second key feature is Offline Desktop, which lets a worker&lt;br /&gt;download their corporate virtual client onto a laptop and take it out of the&lt;br /&gt;office.&lt;br /&gt;Tommy Armstrong, VMware's senior marketing manager for enterprise&lt;br /&gt;desktops, explained that the development is about broadening out virtual&lt;br /&gt;desktops for customers looking at more strategic deployments.&lt;br /&gt;"The number one&lt;br /&gt;thing customers told us they need for virtual desktops is to bring down the&lt;br /&gt;initial capital investment, for example in storage requirements," he&lt;br /&gt;said.&lt;br /&gt;View Composer addresses this by splitting each virtual client into the&lt;br /&gt;operating system, applications and user data such as files and&lt;br /&gt;settings.&lt;br /&gt;"Firms can manage lots of clones linked back to a single master&lt;br /&gt;image. Any commonality - Windows XP, service packs - is in that 'golden master'.&lt;br /&gt;The deltas [differences], which contain anything unique, can be much smaller,"&lt;br /&gt;Armstrong said.&lt;br /&gt;This can reduce storage requirements by up to 90 per cent&lt;br /&gt;compared with traditional virtual desktop deployments, VMware claimed, as well&lt;br /&gt;as enabling centralised patching and backup of the virtual&lt;br /&gt;clients.&lt;br /&gt;Meanwhile, Offline Desktop enables firms to implement a virtual&lt;br /&gt;desktop strategy even if they have roaming users or some workers connected via a&lt;br /&gt;high latency connection. It combines VDI with another VMware product, ACE, that&lt;br /&gt;lets firms distribute virtual machines with corporate policy mechanisms applied&lt;br /&gt;to them.&lt;br /&gt;"We're bringing these together so users can connect to their virtual&lt;br /&gt;desktop over the network as usual, but if a user wants to run their virtual&lt;br /&gt;machine locally they can 'check out' their desktop and run it on the local&lt;br /&gt;machine," said Armstrong.&lt;br /&gt;Users can check their desktop back in when they&lt;br /&gt;reconnect to the network, or check in a backup, a delta file that just updates&lt;br /&gt;the datacentre image with any changes.&lt;br /&gt;This will also allow users to make use&lt;br /&gt;of local resources for demanding applications, such as those that are&lt;br /&gt;graphics-intensive, according to Armstrong.&lt;br /&gt;"It's about being able to run&lt;br /&gt;apps where it makes most sense, being able to move the virtual machine between&lt;br /&gt;datacentre and the client itself, the access device, if necessary," he&lt;br /&gt;said.&lt;br /&gt;View Manager 3, VMware's connection broker (previously called Virtual&lt;br /&gt;Desktop Manager) can now connect users to a Terminal Services session or to&lt;br /&gt;physical PCs, such as blade workstations, as well as virtual clients.&lt;br /&gt;Other&lt;br /&gt;enhancements address the end-user experience with virtual printing support,&lt;br /&gt;better USB redirection and improved multimedia handling.&lt;br /&gt;Virtual printing&lt;br /&gt;lets the user print to whichever printer is currently attached to their access&lt;br /&gt;device, whatever or wherever that may be, according to VMware. USB redirection&lt;br /&gt;now allows for a broader range of peripherals to be connected to the access&lt;br /&gt;device and used with the virtual desktop.&lt;br /&gt;With View 3, VMware has licensed&lt;br /&gt;Wyse's TCX technology for better media handling. This recognises media files,&lt;br /&gt;such as music and video, and sends them to the endpoint access device to be&lt;br /&gt;played locally.&lt;br /&gt;VMware View 3 currently supports only Windows, but Armstrong&lt;br /&gt;strongly hinted at future Mac support, enabling users to check out their&lt;br /&gt;Windows-based corporate virtual client to an Intel-based Mac laptop, for&lt;br /&gt;example.&lt;br /&gt;Copyright © 2008 vnunet.com&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Great news for these virtual machine users.&lt;br /&gt;Link: &lt;a href="http://www.vmware.com/products/view/whatsincluded.html"&gt;http://www.vmware.com/products/view/whatsincluded.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-8334640419071429816?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/8334640419071429816/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=8334640419071429816' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8334640419071429816'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8334640419071429816'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/12/vmware-new-vmware-30.html' title='VMware: New VMware 3.0'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-8698640481549832396</id><published>2008-12-02T20:09:00.000-08:00</published><updated>2008-12-02T20:57:46.337-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Internet Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Symantec'/><category scheme='http://www.blogger.com/atom/ns#' term='underground economy'/><title type='text'>Report: Symantec Report on the Underground Economy: November, 2008</title><content type='html'>&lt;blockquote&gt;&lt;p&gt;&lt;span style="color:#3333ff;"&gt;&lt;strong&gt;Secrets of the underground economy&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color:#3333ff;"&gt;By Kathryn Small 1 December 2008 01:11PM&lt;br /&gt;&lt;br /&gt;In IRC channels and web-based forums, the underground economy is thriving, according to the latest year-long report by Symantec. Find out how much a botnet or a set of credit card details would cost you.&lt;br /&gt;&lt;/span&gt;&lt;span style="color:#3333ff;"&gt;&lt;br /&gt;The ‘underground economy’ refers to commercial cybercrime activity – specifically, the purchase and sale of fraudulent goods and services. Items for sale might include sold credit card data, bank account credentials, email accounts, and other data.&lt;br /&gt;Services might include cashiers who can transfer funds from stolen accounts into true currency, phishing and scam page hosting, and job advertisements for roles such as scam developers or phishing partners.&lt;br /&gt;&lt;br /&gt;The value of the total advertised goods on underground economy servers during the twelve-month period was more than US$276 million.&lt;br /&gt;Information is bought and sold on IRC channels and web forums. Sometimes sellers set up shop on legitimate servers, which makes it harder for police to shut them down.&lt;br /&gt;&lt;br /&gt;The underground economy is highly diverse. “The top ten servers control the top 11 per cent of the revenue,” said Craig Scroggie, VP and MD of Symantec Asia Pacific.&lt;br /&gt;Sixty-three (63) per cent of sellers were offering online credit as payment, using wire transfers, or funnelling money through online currencies such as Linden dollars or World of Warcraft gold.&lt;br /&gt;&lt;br /&gt;Credit card information was the most highly prized data, accounting for 31 per cent of everything that was sold during the survey period. That included credit card numbers, credit cards with CVV2 numbers, and credit card dumps. It was also the most requested category, making up 24 per cent of all goods requested.&lt;br /&gt;&lt;br /&gt;Credit card details might be as cheap as US$0.10 per card, ranging up to US$25, while credit cards with CVV2 numbers ranged from US$0.50 to US$12.&lt;br /&gt;“The thing about credit cards is that it could cost you as little as 10 cents, but the average advertised stolen credit card limit observed by Symantec is more than US$4,000. So it’s an incredible return on investment,” said Scroggie.&lt;br /&gt;&lt;br /&gt;“We calculated that the potential worth of all credit cards advertised during the reporting period was US$5.3 billion.”&lt;br /&gt;&lt;br /&gt;Credit card information is popular because it’s easy to obtain and easy to use for fraud, explained Scroggie.&lt;br /&gt;&lt;br /&gt;“Credit cards are easy to use for online shopping, and it’s often difficult for merchants or credit card providers to identify and address fraudulent transactions before fraudsters complete these transactions and receive their goods.”&lt;br /&gt;&lt;br /&gt;Australia has a disproportionately high number of credit card transactions every year. Scroggie explained that in Australia there are 14 million credit cards in circulation, performing 1.4 billion transactions in the last year. By contrast, the UK is three times as large, but had less than 1.8 billion transactions.&lt;br /&gt;&lt;br /&gt;“Australia’s always been an early and strong adopter of technology, and we’re an early adopter from a market stand-point. We have high credit card usage relative to other strong economies.”Next, fraudsters traded in financial accounts, at 20 per cent of the total. Stolen bank account information sells for between $10 and $1,000, but the average advertised stolen bank account balance is nearly $40,000. Symantec calculated that the total value of bank accounts advertised as US$1.7 billion.&lt;br /&gt;The average price of a botnet was $25, while the price of phishing scam hosting, keystroke loggers or screen scrapers was $10.&lt;br /&gt;&lt;br /&gt;Desktop computer games made up 49 per cent of pirated software, which Scroggie said directly correlated to retail sales in the legitimate market. Following that was commercial software suites such as Adobe’s Creative Suite. “There was a large number of pirated games but the average retail price of games is low – around $50. So there’s a large amount of piracy, but not a large amount of money.”&lt;br /&gt;The underground economy is spread out across the world, ranging from loose collections of individuals to organised and sophisticated groups. North America hosted the largest number of servers, with 45 per cent of the total; Europe/Middle East/Africa hosted 38 per cent; Asia/Pacific with 12 per cent; and Latin America with 5 per cent.&lt;br /&gt;&lt;br /&gt;The report noted that the geographical locations of underground economy servers are constantly changing to evade detection.&lt;br /&gt;Scroggie said businesses and individuals could take simple steps to protecting themselves from online fraud.&lt;br /&gt;&lt;br /&gt;“They can protect themselves by ensuring they have messaging filtering, a defensive depth strategy, multiple mutual overlapping or complementary software, such as anti-viral, anti-spyware, anti-malware and anti-phishing.&lt;br /&gt;“You can buy a combination of these technologies from reputable security vendors.”&lt;br /&gt; &lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;Symantec report page : &lt;a href="http://www.symantec.com/business/theme.jsp?themeid=threatreport"&gt;Link &lt;/a&gt;&lt;br /&gt;Actual download link for report: &lt;a href="http://eval.symantec.com/mktginfo/enterprise/white_papers/b-whitepaper_underground_economy_report_11-2008-14525717.en-us.pdf"&gt;Here&lt;/a&gt; (PDF file)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-8698640481549832396?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/8698640481549832396/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=8698640481549832396' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8698640481549832396'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8698640481549832396'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/12/report-symantec-report-on-underground.html' title='Report: Symantec Report on the Underground Economy: November, 2008'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-4590502415386093769</id><published>2008-11-23T16:58:00.000-08:00</published><updated>2008-11-23T17:20:21.225-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='AVG'/><category scheme='http://www.blogger.com/atom/ns#' term='marketing'/><category scheme='http://www.blogger.com/atom/ns#' term='Antivirus Industry'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><title type='text'>Does Microsoft's free AV will put cloud over the current AV Industry?</title><content type='html'>&lt;span style="font-weight: bold;"&gt;AVG Sees Uphill Battle for Microsoft in Its Launch of Free Anti-Virus Software&lt;/span&gt;&lt;br /&gt;&lt;blockquote style="color: rgb(51, 51, 153);"&gt;AVG Replies to Announcement of Competitor's Replication of Its Anti-Virus Software Offering&lt;br /&gt;&lt;br /&gt;Last update: 9:22 a.m. EST Nov. 21, 2008&lt;br /&gt;AMSTERDAM, Netherlands, Nov 21, 2008 /PRNewswire via COMTEX/ -- AVG, a global anti-virus and Internet security software provider with over 85 million users in 167 countries, today responded to Microsoft's announcement of a free anti-virus software product slated to appear in mid-2009.&lt;br /&gt;AVG, which for eight years has offered free anti-virus software to users worldwide, noted the multiple challenges Microsoft faces in supporting a free anti-virus software product -- chief among them the enormous overhead costs it will incur for customer service and support issues, as well as for ongoing product management and upgrades.&lt;br /&gt;Microsoft will also likely contend with a severe backlash from dissatisfied channel partners, whose margins and unit sales will be negatively impacted as a result of the free product offering, AVG believes.&lt;br /&gt;"For over eight years, AVG has recognized and responded to the growing global threat of malware by offering a free and comprehensive tool to combat computer viruses, spyware, malware and online threats," said J.R. Smith, the company's CEO. "Microsoft is clearly following our lead, which will certainly help combat basic and less sophisticated threats. But the real threat in this scenario is to Microsoft's own profitability and channel partner relations."&lt;br /&gt;AVG also highlighted the challenges facing Microsoft to keep pace with the growing proliferation of new and increasingly onerous online threats. Microsoft often relies on its monthly "patch Tuesday" updates to refresh its current anti-virus product, leaving computer users vulnerable to botnets and other malicious attacks. Importantly, the free Microsoft anti-virus software will have even less protective features than its current OneCare offering - further heightening computer users' vulnerability to fast-spreading viruses and other threats.&lt;br /&gt;Statistics highlight the escalating problem. Computer infections from malware are increasing exponentially. AVG's in-house research team notes that 50,000 variants are being issued every day - further pointing up the need for real-time protection.&lt;br /&gt;AVG's LinkScanner feature provides up-to-the-minute protection against the very latest threats. What's more, AVG's award-winning anti-virus products have long been recognized for providing maximum computer security and online protection with minimal resource strain.&lt;br /&gt;From a global protection perspective, AVG has a strong presence in established and emerging markets. The company's strategic growth plan includes the introduction of several new native-language versions of its anti-virus programs in the coming weeks. Moreover, the company's worldwide user-support community -- with people and small businesses from 167 countries -- continues to grow as the industry's only truly "self-help" network.&lt;br /&gt;"The exceptional ease of use and simplicity of AVG's products have long been a strong sell for the channel, providing more security strength and functionality at a much lower cost than Microsoft's anti-virus offerings," added Mr. Smith. "Given these tough economic times, our resellers appreciate the robust product margins we offer and the vitality of our end-user community to help drive future sales."&lt;br /&gt;&lt;br /&gt;About AVG Technologies&lt;br /&gt;AVG is a global security solutions leader protecting more than 85 million consumers and small business computer users in 167 countries from the ever-growing incidence of web threats, viruses, spam, cyber-scams and hackers on the Internet. Headquartered in Amsterdam, AVG has nearly two decades of experience in combating cyber crime and one of the most advanced laboratories for detecting, pre-empting and combating Web-borne threats from around the world. Its free online, downloadable software model allows entry-level users to gain basic anti-virus protection and then to easily and inexpensively upgrade to greater levels of safety and defense in both single and multi-user environments. Nearly 6,000 resellers, partners and distributors team with AVG globally including Amazon.com, CNET, Cisco, Ingram Micro, Play.com, Wal-Mart, and Yahoo!. More information is available at http://www.avg.com.&lt;br /&gt;SOURCE AVG Technologies&lt;br /&gt;&lt;br /&gt;http://www.avg.com&lt;/blockquote&gt;Just recently Microsoft announced that they will offer free AV for Windows users, and so does this mean everyone will use Microsoft's free Antivirus instead of paid Antivirus software?&lt;br /&gt;The real question is why Microsoft is offering FREE AV? If Microsoft's AV was great Antivirus software would Microsoft give it away for FREE? Their Microsoft's Office is NOT FREE, because they know they can make profit. The bottom line is Microsoft's AV is simply not the worthy competitor in AV Industry.&lt;br /&gt;&lt;br /&gt;Microsoft was trying to persuade Windows users to use their Antivirus program for years and failed miserably; very few customers out there will use Microsoft's OneCare as its rated one of worse performing AV.&lt;br /&gt;&lt;br /&gt;Even AVG's free AV don't detect much as some of the paid Antivirus like Norton, McAfee, Trend Micro, Kaspersky etc.. These free AV users out there are NOT using AVG free AV or free Microsoft's AV because they want to use it but rather they have to, they wants FREE AV and don't want to pay for it. Average computer users know that AVG or Microsoft's AV is not good as others that they can buy from computer shops or Internet.&lt;br /&gt;&lt;br /&gt;Freebie users often don't pay for other software that they are using, therefore having freebie users as main market is No good for the software company.&lt;br /&gt;&lt;br /&gt;I remember the free Antispyware companies like Adaware and Search &amp;amp; Destroy; both companies are now selling their software; and they are not doing well on their sale because their initial offerings were FREE base software. Once a free, then it will have to be remain as FREE otherwise average computer users will not use them again. Why would you pay for second graded software where you can get the best available software on the market for same price?&lt;br /&gt;&lt;br /&gt;These freebie users will use other free softwares when free versions ceased, simply means freebie users will always wants freebies. Going from freebie to pay versions is not a good marketing strategy.&lt;br /&gt;&lt;br /&gt;If you don't make any profit then you are out of the business is fundamental law of the business&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-4590502415386093769?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/4590502415386093769/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=4590502415386093769' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4590502415386093769'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4590502415386093769'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/11/does-microsofts-free-av-will-put-cloud.html' title='Does Microsoft&apos;s free AV will put cloud over the current AV Industry?'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-4419051806903817246</id><published>2008-11-19T15:14:00.000-08:00</published><updated>2008-11-19T15:19:24.748-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OneCare'/><category scheme='http://www.blogger.com/atom/ns#' term='Morro'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><title type='text'>Microsoft dumps OneCare</title><content type='html'>Article: &lt;a href="http://www.itnews.com.au/News/89385,microsoft-scraps-onecare-security-suite.aspx"&gt;Microsoft scraps OneCare security suite&lt;/a&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;By Daniel Robinson &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;20 November 2008 06:10AM&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;Microsoft is to replace Windows Live OneCare with a free security service from the second half of 2009.&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;The company said that the replacement, codenamed Morro, will provide comprehensive protection from malware including viruses, spyware, rootkits and Trojans.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;It will also be less demanding on system resources, making it suitable for low bandwidth connections or less powerful PCs.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;Morro will be available as a download for users running XP, Vista and Windows 7. OneCare will continue to be available through retail for XP and Vista until 30 June 2009, and will be gradually phased out when Morro becomes available. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;At the time of writing, Microsoft had not responded to inquiries regarding the reasons for dropping OneCare. Some commentators have speculated that the service has not been doing as well as the company had hoped, while others believe that Microsoft is trying to get a foothold in emerging markets.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;"This new, no-cost offering will give us the ability to protect an even greater number of consumers, especially in markets where the growth of new PC purchases is outpaced only by the growth of malware," said Amy Barzdukas, senior director of product management for online services at Microsoft.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;Other security vendors appeared unfazed by Microsoft's announcement, at least publicly.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;AVG sees the move as a positive step in the anti-malware landscape, according to head of global communications Siobhan McDermott, who said that AVG did not feel threatened by Microsoft's entering the market.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;"Our free product competes with most paid-for products from other vendors. We see no need to change our product at this time, based on what Microsoft has announced so far," she said.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;Symantec warned that Morro would probably offer less protection than currently provided by OneCare.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;"The security business is fundamentally different from any other market Microsoft plays in, and consumers are encouraged to consider how they will protect themselves, their identities and their families online," said Tom Powledge, vice president of Symantec's consumer business.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;McAfee was even more scathing, suggesting in a statement that Microsoft was effectively exiting the security market because OneCare had failed.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;"Microsoft has given up. They have now defaulted to a dressed-down freeware product that does not meet consumers' security needs. With more malware attacks than ever before, consumers require a trusted advisor and expert in security like McAfee," it said.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;Copyright © 2008 vnunet.com&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;OneCare security suit have been scoring one of lowest detections from various independent virus samples testers. And despite the effort from MS marketing team, OneCare wasn't selling well; may be this made the decision to dump the OneCare.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-4419051806903817246?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/4419051806903817246/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=4419051806903817246' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4419051806903817246'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4419051806903817246'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/11/microsoft-dumps-onecare.html' title='Microsoft dumps OneCare'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-2914749097281833106</id><published>2008-11-18T19:53:00.000-08:00</published><updated>2008-11-18T19:59:21.070-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='over due bill'/><category scheme='http://www.blogger.com/atom/ns#' term='joke'/><category scheme='http://www.blogger.com/atom/ns#' term='email worm'/><category scheme='http://www.blogger.com/atom/ns#' term='spider drawing'/><title type='text'>Joke: Man tries to pay bill with spider drawing</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_DAkCiWAwOQ4/SSOPDgQLF3I/AAAAAAAAAEI/TvvxDKuPI-4/s1600-h/spider.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 150px;" src="http://3.bp.blogspot.com/_DAkCiWAwOQ4/SSOPDgQLF3I/AAAAAAAAAEI/TvvxDKuPI-4/s320/spider.jpg" alt="" id="BLOGGER_PHOTO_ID_5270213279313762162" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Australian man, David Thorne tries to pay his over due bill with his spider drawing.&lt;br /&gt;So funny! Read the &lt;a href="http://news.ninemsn.com.au/article.aspx?id=665847"&gt;email&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-2914749097281833106?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/2914749097281833106/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=2914749097281833106' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/2914749097281833106'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/2914749097281833106'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/11/joke-man-tries-to-pay-bill-with-spider.html' title='Joke: Man tries to pay bill with spider drawing'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_DAkCiWAwOQ4/SSOPDgQLF3I/AAAAAAAAAEI/TvvxDKuPI-4/s72-c/spider.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3479925916806301803</id><published>2008-11-18T19:37:00.000-08:00</published><updated>2008-11-18T19:48:01.576-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='QA'/><category scheme='http://www.blogger.com/atom/ns#' term='AV Industry'/><category scheme='http://www.blogger.com/atom/ns#' term='AVG'/><category scheme='http://www.blogger.com/atom/ns#' term='false positive'/><title type='text'>Importance of QA in Antivirus Industry: Case 1 - False positive detection</title><content type='html'>Just recently AVG offered infected customers with free one year license or update.&lt;br /&gt;Read the article:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;a href="http://www.itnews.com.au/News/89085,avg-offers-infected-users-free-year-of-service.aspx"&gt;&lt;span style="font-weight: bold;"&gt;AVG offers infected users free year of service&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;By Emma Hughes&lt;br /&gt;17 November 2008 07:06AM&lt;br /&gt;Security&lt;br /&gt;&lt;br /&gt;AVG announced yesterday that it would be offering a free year of service after its antivirus software got confused and misidentified a key Windows system file as malware.&lt;br /&gt;&lt;br /&gt;The problem affected non-English versions of XP.&lt;br /&gt;&lt;br /&gt;The security vendor identified earlier this week that user32.dll was coming up as a generic Trojan which caused a warning pop-up asking if the user wanted to delete it – unfortunately for those who say ‘yes’ they were stuck in an endless reboot cycle.&lt;br /&gt;&lt;br /&gt;Once the floods of complaints began, AVG identified the mistake and began offering workarounds for affected users – which is fine if you’ve got someone else to look it up for you.&lt;br /&gt;&lt;br /&gt;Yesterday however, AVG announced, "As a follow-up to the rapid distribution of recovery instructions and repair CDs, AVG Technologies is offering all affected users a free license or license extension as follows.”&lt;br /&gt;&lt;br /&gt;This basically means a free year of AVG 8.0 service, or a free upgrade for AVG 7.5 users.&lt;br /&gt;&lt;br /&gt;The upgrade also includes users of the free AVG antivirus service.&lt;br /&gt;&lt;br /&gt;Once the company began apologising, it seemed to be unable to stop, "AVG Technologies apologises again for the inconvenience caused to our customers and wishes to assure our users worldwide that the company is actively putting new processes in place to avoid similar occurrences in the future.”&lt;br /&gt;&lt;br /&gt;AVG has said that it will begin contacting affected customers beginning November 24 in order to give further instructions on this service. &lt;/blockquote&gt;Look how important is QA testing for false positive in AV Industry; not only AVG have lost revenue for little mistake, it also created unwanted media attraction.&lt;br /&gt;&lt;br /&gt;Few years ago and only few months ago, Symantec had exactly same thing when Norton AV was deleting part of Windows. It's all fixed up and updated now, but if these companies have done proper scanning testing before the release of their anti virus definitions or database then this wouldn't happened.&lt;br /&gt;&lt;br /&gt;False positive detection must be cleared before the release of the anti virus definition/database, if only AV companies properly implemented QA testing lab to perform FP detection at least on popular operating systems like Windows XP/Vista then AV Industry won't spend their time &amp;amp; money on patching or fixing their mistakes.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3479925916806301803?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3479925916806301803/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3479925916806301803' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3479925916806301803'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3479925916806301803'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/11/importance-of-qa-in-antivirus-industry.html' title='Importance of QA in Antivirus Industry: Case 1 - False positive detection'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3668987304025145667</id><published>2008-11-11T15:02:00.000-08:00</published><updated>2008-11-11T15:07:11.475-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Antivirus vendors'/><category scheme='http://www.blogger.com/atom/ns#' term='virus Bulletin'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti-Malware Testing Standards Organisation'/><title type='text'>Security giants propose new testing standard</title><content type='html'>By Shaun Nichols 12 November 2008&lt;br /&gt;&lt;br /&gt;A group of leading security firms has proposed a new standardised system for testing security software.Symantec, McAfee, F-Secure and Kaspersky are among the names that have pledged support for the project, which boasts more than 40 security vendors and media groups as part of the &lt;a href="http://www.amtso.org/"&gt;Anti-Malware Testing Standards Organisation&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The new system would provide guidelines as to how a test should be conducted, including the types of malware used, method of analysis and accurate support for a conclusion.&lt;br /&gt;The guidelines will also outline procedures for studying and disclosing new malware samples.&lt;br /&gt;Security vendors and experts have long called for an updated standard for testing.&lt;br /&gt;&lt;br /&gt;Current security tests, such as the &lt;a href="http://www.virusbtn.com/vb100"&gt;Virus Bulletin 100&lt;/a&gt; system, have been criticised for their procedures and what some say is an inability accurately to access certain types of anti-malware programs.&lt;br /&gt;The new group hopes that its outlines will allow security firms and independent testing groups to research the effectiveness of anti-malware solutions with better accuracy and a built-in neutrality.&lt;br /&gt;&lt;br /&gt;"While there have been many great security software reviews in the past, many poor reviews have confused or misled people," said McAfee senior vice president Jeff Green.&lt;br /&gt;"This is a significant milestone that should skew the balance towards fair and scientific testing, providing users with a true viewpoint on the security protection vendors provide."&lt;br /&gt;&lt;br /&gt;Copyright © 2008 vnunet.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3668987304025145667?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3668987304025145667/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3668987304025145667' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3668987304025145667'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3668987304025145667'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/11/security-giants-propose-new-testing.html' title='Security giants propose new testing standard'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3907633725789299279</id><published>2008-10-30T22:29:00.000-07:00</published><updated>2008-10-30T22:36:38.206-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='acquisition'/><category scheme='http://www.blogger.com/atom/ns#' term='Messagelabs'/><category scheme='http://www.blogger.com/atom/ns#' term='Symantec'/><title type='text'>Symantec adds Messagelabs to Christmas shopping basket</title><content type='html'>&lt;strong&gt;Symantec to acquire MessageLabs, bolster SaaS&lt;/strong&gt;&lt;br /&gt;by David M Williams Thursday, 09 October 2008&lt;br /&gt;&lt;br /&gt;Symantec Corporation, producer of the popular Symantec Anti-Virus corporate suite and of the less-than-popular Norton consumer product, has today announced its intention to acquire global e-mail-filtering company MessageLabs. The move signals Symantec's growth as a provider of SaaS. Symantec has been on the acquisition trail for several years with other notable purchases being Veritas - of backup fame - and Altiris - known for their enterprise network management and help-desk suite.&lt;br /&gt;MessageLabs differs from the products Symantec is best known for due to its Software as a Service (SaaS) model. That is, MessageLabs requires no infrastructure or maintenance within your network save to redirect your incoming mail to hit their servers, not your own.&lt;br /&gt;The MessageLabs machinery scrubs and cleans your inbound e-mail stream, delivering a spam- and virus-free feed to your corporate mail server.&lt;br /&gt;MessageLabs report their customers include major financial institutions and legal firms as well as governments.&lt;br /&gt;Additional MessageLabs services include a web proxy element and e-mail archiving.&lt;br /&gt;In one sense MessageLabs was a competitor to Symantec's existing mail security product. Yet, the acquisition appears little to do with shutting down a competitor and more about bolstering Symantec's overall presence in the growing cloud space.&lt;br /&gt;The CEO of MessageLabs, Adrian Chamberlain, said the interest by Symantec proved MessageLab's SaaS model worked and that the company was a leader in its field.&lt;br /&gt;Chamberlain stated at the close of the acquisition Symantec would launch a new SaaS arm which combined MessageLabs and the existing Symantec solutions for online storage, online backup and remote access. This new arm will be lead by the MessageLabs management team thus giving their division a stronger product from day one.&lt;br /&gt;The purchase price will be $USD 695 million but at this time the expected completion date has not been advised, no doubt with due diligence still in progress.&lt;br /&gt;&lt;br /&gt;Messagelabs &lt;a href="http://www.messagelabs.com/"&gt;Link&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Symantec is expanding is's business but downsizing its workforce.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Seeing Tough Times Ahead, Symantec Plans Layoffs&lt;/strong&gt;&lt;br /&gt;Robert McMillan, IDG News ServiceThursday, October 30, 2008 6:10 PM PDT&lt;br /&gt;&lt;br /&gt;Anticipating a slowdown in IT spending, Symantec expects to begin laying off employees next month.&lt;br /&gt;Symantec isn't saying exactly how many jobs it will cut, but on Wednesday Chief Financial Officer James Beer said that the company is looking to trim about 4.5 percent of the cost of its workforce. Separately, Symantec is also outsourcing some of the work done by its IT and finance departments, he said during a conference call with financial analysts.&lt;br /&gt;Symantec has not yet determined how many cuts it will make to its workforce of 17,800 employees, but the layoffs will affect staff in all regions, said Cris Paden, a company spokesman. "We'll be notifying employees next month," he said.&lt;br /&gt;On Nov. 1, Hewlett-Packard's EDS division will start taking over some of the company's IT operations, and IT and finance employees will be moved off the company payroll over the next 12 months, Paden said. Those reductions have been planned for months, and are separate from the cuts announced Wednesday.&lt;br /&gt;Symantec's stock [SYMC] dropped nearly 18 percent Thursday on the company's sober economic outlook and its reduced earnings expectations.&lt;br /&gt;Starting in the last weeks of September, Symantec saw some "hesitation from some of our customers when it came to finalizing commitments," Beer said in an interview.&lt;br /&gt;"We did see some pulling back," he added. "It was an effect that we saw in different parts of our customer base around the world."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3907633725789299279?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3907633725789299279/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3907633725789299279' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3907633725789299279'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3907633725789299279'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/10/symantec-adds-messagelabs-to-christmas.html' title='Symantec adds Messagelabs to Christmas shopping basket'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-7772391093492784644</id><published>2008-10-21T16:32:00.000-07:00</published><updated>2008-10-21T16:37:06.532-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Data theft'/><category scheme='http://www.blogger.com/atom/ns#' term='itnews.com'/><category scheme='http://www.blogger.com/atom/ns#' term='Symantec'/><title type='text'>Human error and hardware theft are the two main causes of data breaches</title><content type='html'>&lt;a href="http://www.itnews.com.au/News/87188,data-breaches-caused-by-human-error-hardware-theft.aspx"&gt;&lt;span style="font-weight: bold;"&gt;Data breaches caused by human error, hardware theft&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;By Kathryn Small&lt;br /&gt;21 October 2008 05:00PM&lt;br /&gt;Human error and hardware theft are the two main causes of data breaches, according to Symantec’s recent survey into Data Loss Prevention.&lt;br /&gt;The global security, storage and systems management company surveyed 156 Australian companies with 100 or more employees. Results were sent in from IT managers and C-level executives. The majority of respondents represented businesses with a financial turnover of $10-$500 million.&lt;br /&gt;&lt;br /&gt;The survey’s headline result is that 79 per cent of respondents have experienced some form of data breach, and 40 per cent have experienced anywhere from six to 20 known data breaches in the past five years.&lt;br /&gt;&lt;br /&gt;Further, 59 per cent of respondents suspect that they have experienced undetected data breaches, with many considering it “impossible” to catch every attempted breach.&lt;br /&gt;&lt;br /&gt;Respondents lost different kinds of data, including customer records (55 per cent); employee records (48 per cent); intellectual property (43 per cent); commercially sensitive information (35 per cent); bank and credit card details (21 per cent) and financial information (20 per cent).&lt;br /&gt;&lt;br /&gt;Lost or stolen laptops were the top cause of data breaches, at 45 per cent. “Respondents estimated that the average cost of a data breach was the same as replacing a lost laptop,” said Steve Martin, Mid Market Manager Pacific. “But I believe that’s too low, since it doesn’t take into account the potential value of the data.”&lt;br /&gt;&lt;br /&gt;Lost mobile phones or portable devices also weighed in at 30 per cent. “A phone is the easiest thing to lose, and the easiest thing to steal,” said Martin. “Whenever I ask groups if they have email access on their phones, and whether their phone is password protected, the second number is always very low.”&lt;br /&gt;&lt;br /&gt;The other key cause of data breaches was accidental human error (42 per cent). Craig Scroggie, VP and MD Pacific, cited the case of a restaurant which accidentally emailed 3,500 customers a copy of their client database, containing names, addresses and dates of birth.&lt;br /&gt;&lt;br /&gt;Malicious attacks included hacked systems (29 per cent), malicious insiders (28 per cent), paper records being smuggled out of an organisation (26 per cent) and malicious code infiltrating systems (24 per cent).&lt;br /&gt;&lt;br /&gt;“Today’s organisations have no walls and information can be anywhere, so securing the perimeter is no longer adequate. Additionally, many organisations believe that confidential information is most at risk from malicious acts when employees are mobile and not connected to the corporate network,” said Scroggie.&lt;br /&gt;&lt;br /&gt;Among intentional security breaches of company secrets or intellectual property, 77 per cent said that data was copied to removable storage devices, and 51 per cent said that printed paper records were removed from the premises.&lt;br /&gt;&lt;br /&gt;Other methods of moving stolen data included email or instant messaging (41 per cent), posting to public websites (26 per cent) and copying or photographing confidential data onto mobile phones or PDAs (21 per cent).&lt;br /&gt;&lt;br /&gt;Scroggie emphasised that Data Loss Prevention required a holistic approach to protect customers, brands and intellectual property.&lt;br /&gt;&lt;br /&gt;“We can stop these problems today,” said Scroggie. “We have the ability to discover, monitor and protect confidential data.”&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-7772391093492784644?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/7772391093492784644/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=7772391093492784644' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7772391093492784644'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7772391093492784644'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/10/human-error-and-hardware-theft-are-two.html' title='Human error and hardware theft are the two main causes of data breaches'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3379980476678620573</id><published>2008-10-07T22:09:00.000-07:00</published><updated>2008-10-07T22:25:40.086-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Sandbox'/><category scheme='http://www.blogger.com/atom/ns#' term='PC Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyberhawk'/><category scheme='http://www.blogger.com/atom/ns#' term='acquisition'/><category scheme='http://www.blogger.com/atom/ns#' term='AV'/><category scheme='http://www.blogger.com/atom/ns#' term='Symantec'/><title type='text'>PC Tools to be poor man's Norton</title><content type='html'>&lt;span style="font-family:times new roman;"&gt;Liam Tung, &lt;/span&gt;&lt;a href="http://www.zdnet.com.au/"&gt;&lt;span style="font-family:times new roman;"&gt;ZDNet.com.au&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;"&gt;28 August 2008 04:16 PM&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;"&gt;Computer security giant &lt;/span&gt;&lt;a href="http://www.symantec.com/"&gt;&lt;span style="font-family:times new roman;"&gt;Symantec&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:times new roman;"&gt; said it would not integrate the software of recent acquisition &lt;/span&gt;&lt;a href="http://www.pctools.com/"&gt;&lt;span style="font-family:times new roman;"&gt;PC Tools&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:times new roman;"&gt; into its mainstream Norton suite, instead using the products as its low-cost option for countries such as India and China.&lt;br /&gt; "The goal right now is to look at emerging markets. We'd like to see PC Tools take emerging markets — countries like Brazil, Russia, India, China," said Symantec's VP of consumer engineering, Rowan Trollope.&lt;br /&gt;"They have been very successful at selling to a very specific segment of the market place that is more interested in lower price solutions."&lt;br /&gt;The Australian security vendor is reported to have cost Symantec AU$300 million, and according to Trollope, gives it an avenue to target these countries without needing to drop its prices for Norton.&lt;br /&gt;Asia Pacific is Symantec's fastest growing region, however, it generates the least revenue of its global operations, netting the company US$231 million, or about 14 per cent, of its total revenues for Symantec's first quarter 2009 earnings.&lt;br /&gt;"I think price is an important component of the offering you bring to an emerging market. Some require lower prices, some accept higher prices, but with India and China in particular, you have to go in with lower prices," the executive told ZDNet.com.au.&lt;br /&gt;While Norton Antivirus 2008 costs AU$59.00, and its Internet Security suite costs AU$99.00, PC Tools' equivalents respectively cost AU$49.95 and AU$79.95.&lt;br /&gt;At the time of the acquisition, technology analysts at Gartner and Intelligent Business Research Services struggled to explain why Symantec would buy PC Tools, which had similar products to its own and added just 200 staff to Symantec's ranks of 17,000.&lt;br /&gt;Trollope said that PC Tools did offer it some new technologies. Registry Mechanic, PC Tools Utility Suite, Threat Fire, and Browser Defender are considered "complementary" to Symantec's products.&lt;br /&gt;While Symantec planned to run PC Tools as a "completely independent company", he said some products would be assessed for overlaps with Symantec's existing products.&lt;br /&gt;"[PC Tools] have Spyware Doctor and they've got some other products that are similar to our products where we will be certainly interested in looking at how do they overlap and who provides which service," he said.&lt;br /&gt;Trollope declined to confirm whether it had paid AU$300 million for PC Tools.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;----------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Symantec have acquired PC Tools because of &lt;/span&gt;&lt;a href="http://www.threatfire.com/"&gt;&lt;span style="font-family:arial;"&gt;Threatfire&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt; engine (formerly &lt;/span&gt;&lt;a href="http://www.novatix.com/"&gt;&lt;span style="font-family:arial;"&gt;Cyberhawk&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;, Zero-day behavior based anti-malware) and &lt;u&gt;&lt;span style="color:#810081;"&gt;&lt;a href="http://www.threatexpert.com/"&gt;ThreatExpert&lt;/a&gt;&lt;/span&gt;&lt;/u&gt; (PC Tools's sandbox automation tool for threat analysis).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Furthermore, because AV market is increasingly becoming competitive and narrower, it’s very important to acquired competitors to stay competitive in the market place.&lt;br /&gt;Both Symantec, McAfee and Trend Micro have been acquiring third party anti-malware and security product vendors in order to acquire newly developed technology or destroy possible competitors, it’s usual Art of War strategy in ever competitive business world.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3379980476678620573?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3379980476678620573/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3379980476678620573' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3379980476678620573'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3379980476678620573'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/10/pc-tools-to-be-poor-mans-norton.html' title='PC Tools to be poor man&apos;s Norton'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3394497245581205944</id><published>2008-10-06T15:48:00.001-07:00</published><updated>2008-10-06T15:48:50.662-07:00</updated><title type='text'>Single Trojan accounts for 60 per cent of September attacks</title><content type='html'>By Lain Thomson 1 October 2008&lt;br /&gt;&lt;br /&gt;A single family of Trojans has accounted for over 60 per cent of malware infections in September, according to Fortinet. The RogueSecurity Trojan and its variants accounted for 61.5 per cent of all malware attacks in September the company claims. The Trojan and its varients took the top four positions of the company’s malware list.“Not since the start of this year when the notorious Storm virus made a continuous run of devastating attacks has any comparison been seen with this level of activity,” said the company.“However where the Rogue security applications excel is the accumulated volume: maintaining these extreme levels of activity for at least six days, not to mention the other variants. “The bulk of malware activity occurred in the second and third week of the month, with the W32/Inject.GZW!tr.bdr Trojan peaking at nearly two million in the middle of the month.&lt;br /&gt;&lt;br /&gt;Virustotal report from two samples:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/es/analisis/d77f8abb7f1ec62fb41aad8b322317bd"&gt;Sample 1&lt;/a&gt; &lt;a href="http://www.virustotal.com/analisis/120fb641310e4704565ef683ca33b2d0"&gt;Sample 2&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is usual Fakealert trojan that have capability to inject it's own dll process to any executable (PE) files that alerts users being danger of "new bogus" infection or actually telling user that their PC is compromised and buy their Anti-virus or Anti-Spy product.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3394497245581205944?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3394497245581205944/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3394497245581205944' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3394497245581205944'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3394497245581205944'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/10/single-trojan-accounts-for-60-per-cent.html' title='Single Trojan accounts for 60 per cent of September attacks'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-8945531791669661664</id><published>2008-08-19T00:58:00.000-07:00</published><updated>2008-08-19T01:03:34.306-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PC Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='acquisition'/><category scheme='http://www.blogger.com/atom/ns#' term='rebrand'/><category scheme='http://www.blogger.com/atom/ns#' term='Symantec'/><category scheme='http://www.blogger.com/atom/ns#' term='company'/><title type='text'>Symantec acquires Sydney's PC Tools</title><content type='html'>&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;Symantec acquires PC Tools&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Mahesh Sharma    | &lt;em class="timestamp"&gt;August 19, 2008&lt;/em&gt;&lt;div class="module-subheader"&gt;&lt;p&gt;   &lt;/p&gt;&lt;/div&gt; &lt;!-- // .module-subheader --&gt;            &lt;p class="intro"&gt;&lt;strong&gt;SYMANTEC has bolstered its consumer product portfolio with the acquisition of Australian security software developer PC Tools.&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;The value of the deal wasn’t disclosed. It is expected to be finalised by the end of the year.&lt;/p&gt; &lt;p&gt;PC Tools is headquartered in Sydney, with offices in US, Britain, Ireland and Ukraine. Symantec said the acquisition expands its reach in emerging regional markets.&lt;br /&gt;&lt;br /&gt;PC Tools has over 200 staff globally and will remain a separate entity in the security giant’s consumer business.&lt;br /&gt;&lt;br /&gt;Chief executive Simon Clausen will report to Symantec’s group president of consumer products, Janice Chaffin.&lt;br /&gt;&lt;br /&gt;Symantec will not rebrand PC Tools’ products and will maintain existing partners and channels. &lt;/p&gt; While there is significant overlap with Symantec’s security offerings, PC Tools also has a range of PC utility products to maintain, repair and optimise Windows operating environments.&lt;br /&gt;&lt;br /&gt;PC Tools also recently released anti-virus software to protect the Mac OS X operating system.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-8945531791669661664?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/8945531791669661664/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=8945531791669661664' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8945531791669661664'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8945531791669661664'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/08/symantec-acquires-sydneys-pc-tools.html' title='Symantec acquires Sydney&apos;s PC Tools'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-220279231077026241</id><published>2008-08-05T05:30:00.000-07:00</published><updated>2008-08-05T05:37:54.316-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='bugs'/><category scheme='http://www.blogger.com/atom/ns#' term='SP1'/><category scheme='http://www.blogger.com/atom/ns#' term='Update'/><category scheme='http://www.blogger.com/atom/ns#' term='KB927891'/><title type='text'>Vista Service Pack 1 isn't actually SP1</title><content type='html'>&lt;div class="entrytitle"&gt;         &lt;a href="http://www.appscout.com/2008/02/microsoft_alerts_users_about_v.php" class="entrytitle"&gt;Microsoft Alerts Users about Vista SP1 Bug &lt;/a&gt;       &lt;/div&gt;&lt;br /&gt;It appears that Microsoft's woes with Vista aren't quite over yet. According to the company's official &lt;a href="http://windowsvistablog.com/blogs/windowsvista/archive/2008/02/19/update-on-windows-vista-sp1-prerequisite-kb937287.aspx"&gt;Windows Vista blog&lt;/a&gt;, a bug in the SP1 update is the latest in a mounting load of blunders. &lt;span name="intelliTxt" id="intelliTXT"&gt;  &lt;p&gt;A number of users reported problems resulting from the service pack prerequisite &lt;a href="http://support.microsoft.com/kb/937287"&gt;KB937287&lt;/a&gt;. After receiving reports of the error, Nick White, Microsoft's Product Manager, quickly responded by notifying customers that a decision has been made to "temporarily suspend automatic distribution of the update to avoid further customer impact while we investigate possible causes." Microsoft says that only a small number of users has been effected and that the company is presently working to crack the problem and put the update back online as soon as possible.&lt;/p&gt;Also, if your Vista PC have installed SP1, makesure you have done all the critical Windows Updates upto late June's update. Apparently there are two major critical updates relating to Windows stability and performance issues.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-220279231077026241?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/220279231077026241/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=220279231077026241' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/220279231077026241'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/220279231077026241'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/08/vista-service-pack-1-isnt-actually-sp1.html' title='Vista Service Pack 1 isn&apos;t actually SP1'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-5367767528067651845</id><published>2008-04-08T04:57:00.000-07:00</published><updated>2008-04-08T05:00:36.313-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti-virus test'/><category scheme='http://www.blogger.com/atom/ns#' term='Sophos'/><category scheme='http://www.blogger.com/atom/ns#' term='SP1'/><category scheme='http://www.blogger.com/atom/ns#' term='TrendMicro'/><category scheme='http://www.blogger.com/atom/ns#' term='McAfee'/><title type='text'>Trend, Sophos and McAfee flunk Vista SP1 anti-virus tests</title><content type='html'>Trend, Sophos and McAfee flunk Vista SP1 anti-virus tests&lt;br /&gt;That would be a FAIL, then&lt;br /&gt;By &lt;a title="Send email to the author" href="http://forms.theregister.co.uk/mail_author/?story_url=/2008/04/03/vista_sp1_av_tests/"&gt;John Leyden&lt;/a&gt; â†’ &lt;a title="More stories from this site by John Leyden" href="http://search.theregister.co.uk/?author=John%20Leyden"&gt;More by this author&lt;/a&gt;&lt;br /&gt;Published Thursday 3rd April 2008 16:52Â GMT&lt;br /&gt;Article from: &lt;a href="http://www.theregister.co.uk/2008/04/03/vista_sp1_av_tests/"&gt;http://www.theregister.co.uk/2008/04/03/vista_sp1_av_tests/&lt;/a&gt;&lt;br /&gt;&lt;u&gt;&lt;span style="color:#0000ff;"&gt;&lt;/span&gt;&lt;/u&gt;&lt;br /&gt;Top tier anti-virus vendors including McAfee, Trend Micro, and Sophos all failed to secure Windows Vista SP1 in recent independent tests.&lt;br /&gt;Virus Bulletin, the independent security certification body, said 17 of 37 anti-virus products tested failed to reach the VB100 certification standard. McAfee VirusScan, Trend Micro Internet Security and Sophos Anti-Virus overlooked threats known to be in circulation. Other vendors whose products failed to make the grade included Alwil, BitDefender, Norman, PC Tools, and VirusBuster.&lt;br /&gt;Some of the ignored threats - largely polymorphic file infectors - have been in circulation for months. "It is disappointing to see so many products tripping up over threats that are not even new - computer users should be getting a better service from their anti-virus vendors than this," Virus Bulletin technical consultant John Hawes said.&lt;br /&gt;Products from Symantec, Microsoft (which has problems in the past in previous VB100 tests), AVG, and Kaspersky Lab all passed.&lt;br /&gt;Although still lagging behind Windows XP, Vista is likely to see more widespread use with the introduction of its first service pack, making it more important for anti-virus vendors to deliver dependable protection for the platform. Vista SP1 came out in mid March.&lt;br /&gt;Virus Bulletin's VB100 tests pit each anti-virus product against a set of viruses from the WildList, a publicly available up-to-date list of viruses known to be circulating. To earn VB100 certification, products must be able to detect all the viruses contained in the WildList test set without generating false alarms when scanning a set of clean files.&lt;br /&gt;Unlike other certification schemes, Virus Bulletin tests all products free of charge and does not allow re-testing. Virus Bulletin's comparative reviews also cover detection rates against a selection of zoo viruses (those not seen outside the laboratory), scanning speeds, and computational overheads.&lt;br /&gt;Test results are &lt;a href="http://www.virusbtn.com/vb100/archive/2008/04" target="_blank"&gt;here&lt;/a&gt; (free registration required). ®&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-5367767528067651845?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/5367767528067651845/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=5367767528067651845' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5367767528067651845'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5367767528067651845'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/04/trend-sophos-and-mcafee-flunk-vista-sp1.html' title='Trend, Sophos and McAfee flunk Vista SP1 anti-virus tests'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-8192232172201248068</id><published>2008-04-08T04:50:00.000-07:00</published><updated>2008-04-08T04:57:10.240-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='spambots'/><title type='text'>Top Spam Botnets Exposed</title><content type='html'>SrizbiEstimated # of bots: 315,000Alternate names: Cbeplay, ExchangerSMTP engine: Template-basedTotal botnet spam-sending capacity: 60 billion spams/dayControl: encrypted, UDP and TCP ports 4099Rootkit-enabled: YesIdentifying strings: \SystemRoot\Minidump\%s, Udp6, Tcp6, MachineNumNotes: With the combination of stealth and an efficient SMTP engine, Srizbi is a highly capable botnetspamming machine. However, Srizbi is not a monolithic botnet - it is split between several customers ofReactor Mailer, with over a dozen control servers. Because of this, a wide variety of spam can be seencoming from Srizbi at any given time. In addition, Srizbi is one of the most active botnets attempting toseed new infections by advertising links to porn-related video files of different celebrities, which areactually new copies of Srizbi.&lt;br /&gt;Srizbi has emerged over the past year as the distributed part of the long-established Reactor Mailerweb-based spam tool. Reactor may have used proxy servers in the past, but at some point a re-write of thesoftware was commissioned by the head of the company, known only as “spm”. The author who did there-write of the backend is a contract programmer living in Smila, Ukraine. It is unclear as to whether ornot he wrote the Srizbi trojan also, but it is a likely possibility.&lt;br /&gt;BobaxEstimated # of bots: 185,000Alternate names: Bobic, Oderoor, Cotmonger, Hacktool.Spammer, KrakenSMTP engine: Template-basedTotal botnet spam-sending capacity: 9 billion spams/dayControl: encrypted, TCP port 447Rootkit-enabled: NoIdentifying strings: cCdipsuxX%, w:\projects\b3\release\core.pdbNotes: Despite reports of its demise, Bobax continues to be a strong player in the spam arena. At onetime, Bobax was solidly in the business of sending mortgage spam, but lately has been seen mailing lowinterestloan spam.&lt;br /&gt;RustockEstimated # of bots: 150,000Alternate names: RKRustok, CostratSMTP engine: Template-basedTotal botnet spam-sending capacity: 30 billion spams/dayControl: HTTP with encryption, TCP port 80Rootkit-enabled: YesIdentifying strings: tmpcode.bin, unluckystrings, filesnamesNotes: Although Rustock started out in the stock spam business, it has branched out, and can currently beseen sending out pharmaceutical spam.&lt;br /&gt;CutwailEstimated # of bots: 125,000Alternate names: Pandex, Mutant (related to: Wigon, Pushdo)SMTP engine: Template-basedTotal botnet spam-sending capacity: 16 billion spams/dayControl: HTTP with encryption, TCP port 4080Rootkit-enabled: YesIdentifying strings: Poshel-ka ti na hui drug averNotes: Cutwail is the most common spambot installed by the Pushdo malware installer system, but it'snot the only one. We've also seen Srizbi, Storm, Xorpix and Rustock installed on the same host togetherwith Pushdo and Cutwail.Canadian Pharmacy spam is one of the things we most commonly see withCutwail, but other types of spam are sent. Sometimes the botnet is used to send social-engineering emailsin order to seed more infected hosts with Cutwail.&lt;br /&gt;StormEstimated # of bots: 85,000 (only 35,000 send email)Alternate names: Nuwar, Peacomm, ZhelatinSMTP engine: Template-basedTotal botnet spam-sending capacity: 3 billion spams/dayControl: HTTP on random ports with base64/zlib encoding, P2P-based server directoryRootkit-enabled: YesIdentifying strings: [blacklist], [peers]Notes: Although Storm has been rumored to be quite large in the past, it has dropped to a morereasonable size. In addition only Storm bots behind NAT firewalls actually send spam. This makes thecapacity of the spam-sending part of the Storm botnet smaller than most of the other lesser-knownbotnets. However, those other hosts don't go to waste, they are used as fast-flux HTTP and DNS hosts forthe spam system. Storm spent a lot of time sending pump-and-dump stock spam in the past, butoccasionally will send pharmaceutical spam and job-offer (phishing mule) emails. When it's notspamming, Storm is sending links to fake greeting card sites which use browser exploits and socialengineeringto infect more users with Storm.&lt;br /&gt;GrumEstimated # of bots: 50,000Alternate names: None known, except for generic/misassignedSMTP engine: Template-basedTotal botnet spam-sending capacity: 2 billion spams/dayControl: HTTP on TCP port 80Rootkit-enabled: YesIdentifying strings: Hi all, Already start, $TO_HEXMAIL, /spm/s_alive, /spm/s_tasksNotes: Although little-known, Grum has accumulated a seizable botnet over the past year by sendingspam with supposed porn URLs which actually point to browser exploiting pages. This botnet usuallysends URLs hidden in non-related HTML, so it may be the botnet referred to by anti-spam vendorMarshal as “HTML”. Ultimately the links lead to Canadian Pharmacy sites.&lt;br /&gt;OneWordSubEstimated # of bots: 40,000Alternate names: UnknownSMTP engine: Template-basedTotal botnet spam-sending capacity: UnknownControl: UnknownRootkit-enabled: UnknownIdentifying strings: UnknownNotes: Although we see a significant amount of spam emanating from this botnet, as of yet the malwarebehind it has yet to be identified. Due to the format of the spam it is sending, we believe this is the samebotnet which anti-spam vendor Marshal refers to as "One Word Sub". This botnet has been seen sendingCanadian Pharmacy spam.&lt;br /&gt;OzdokEstimated # of bots: 35,000Alternate names: Mega-DSMTP engine: Template-basedTotal botnet spam-sending capacity: 10 billion spams/dayControl: encrypted, TCP port 443Rootkit-enabled: NoIdentifying strings: KILL_LAZZY_ON_CONNECT, KILL_LAZZY_MXNotes: Although Ozdok has a relatively small set of bots compared to some of the other botnets listedhere, it is quite capable of pumping out a generous amount of spam, most of it related to enlargementproducts, but designer knock-offs and other spam are frequently seen.&lt;br /&gt;NucryptEstimated # of bots: 20,000Alternate names: Loosky, LockskySMTP engine: Template-basedTotal botnet spam-sending capacity: 5 billion spams/dayControl: HTTP with encryption, TCP port 3133Rootkit-enabled: YesIdentifying strings: 1f34ff45, taskmon.sys, /synctl/updNotes: Relatively small yet capable botnet - may have been evolving for a few years. Last seen sendingCanadian Pharmacy spam.&lt;br /&gt;WoplaEstimated # of bots: 20,000Alternate names: Pokier, SloggerSMTP engine: Template-basedControl: encrypted, TCP port 8080Total botnet spam-sending capacity: 600 million spams/dayRootkit-enabled: YesIdentifying strings: %sxtempx.xxx, %.250s.lzo, ctxlsp.dll, psrip.dat, mailgrab_emails.dat, OEMSO2000Notes: Wopla is frequently installed by drive-by exploits in the same way as Srizbi, Rustock and Cutwail,although it doesn't appear to have been spread as widely. An interesting feature – Wopla can send spamdirect-to-MX or by logging into at least one public webmail service. Bots which send spam throughwebmail providers will probably continue to increase in number, since the spam can evade IP-basedblocklisting, and must rely solely on content-detection (or fingerprinting/anomaly detection at thewebmail provider). Wopla seems to be primarily dedicated to porn spam.&lt;br /&gt;SpamthruEstimated # of bots: 12,000Alternate names: Spam-DComServ, Covesmer, XmilerSMTP engine: Template-basedTotal botnet spam-sending capacity: 350 million spams/dayControl: encrypted, multiple TCP portsRootkit-enabled: NoIdentifying strings: hs5p, XSMTPXNotes: Another botnet which cut its teeth mailing stock spam in 2006 and 2007, nowadays can be seensending pharmaceutical spam.&lt;br /&gt;Other SpambotsIn addition to these bots, there are several other template-based spam botnets, and still many more proxybasedbotnets. Creating network-based fingerprints for proxy botnets is much more difficult, becauseultimately you are fingerprinting the mailer engine, not the bot itself. In the case where the same spamtool might utilize multiple proxy botnets, it would greatly skew the results.One template-based botnet (Warezov/Stration/Opnis) that was a major player six months ago hascompletely dropped off of the radar. Warezov was known for sending Chinese pump-and-dump stockspam. Perhaps it is no coincidence that in the same time frame that we stopped seeing Warezovspam/malware, the notorious spam kingpin Alan Ralsky was arrested and charged (among other things)with sending pump-and-dump stock spam for Chinese companies.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-8192232172201248068?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/8192232172201248068/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=8192232172201248068' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8192232172201248068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8192232172201248068'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2008/04/top-spam-botnets-exposed.html' title='Top Spam Botnets Exposed'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-6908928064334972455</id><published>2007-08-30T23:01:00.000-07:00</published><updated>2007-08-30T23:05:33.634-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RBN'/><title type='text'>Article: A walk on the dark side</title><content type='html'>Found interesting article on one of the world's worse company that caters crackers and spammers.&lt;br /&gt;Article link from: &lt;a href="http://www.economist.com/displaystory.cfm?story_id=9723768"&gt;economist.com&lt;/a&gt;&lt;br /&gt;=============================================&lt;br /&gt;&lt;h1&gt;A walk on the dark side&lt;/h1&gt; &lt;p class="info"&gt;Aug 30th 2007&lt;br /&gt;From Economist.com&lt;/p&gt;&lt;h2&gt;These badhats may have bought your bank account &lt;/h2&gt;ACCORDING to VeriSign, one of the world’s largest internet security companies, RBN, an internet company based in Russia’s second city, St Petersburg, is “the baddest of the bad”. In a report seen by &lt;em&gt;The Economist&lt;/em&gt;, VeriSign’s investigators unpick an extraordinary story of blatant cybercrime that implies high-level political backing.  &lt;p&gt;In one sense, RBN (Russian Business Network) does not exist. It has no legal identity; it is not registered as a company; its senior figures are anonymous, known only by their nicknames. Its web sites are registered at anonymous addresses with dummy e-mails. It does not advertise for customers. Those who want to use its services contact it via internet messaging services and pay with anonymous electronic cash.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;But the menace it poses certainly exists. “RBN is a for-hire service catering to large-scale criminal operations,” says the report. It hosts cybercriminals, ranging from spammers to phishers, bot-herders and all manner of other fraudsters and wrongdoers from the venal to the vicious. Just one big scam, called Rock Phish (where gullible internet users were tricked into entering personal financial information such as bank account details) made $150m last year, VeriSign estimates.&lt;/p&gt;  &lt;p&gt;Plenty of other internet companies sail close to the wind—hosting unregulated online gambling for example. But according to a VeriSign investigator, “the difference is that RBN is solely criminal”. The pricing depends on the level of complaints. A discreet organisation pays little; one that attracts a lot of unwelcome attention, forcing RBN to take expensive countermeasures, has to pay more.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Despite the attention it is receiving from Western law enforcement agencies, RBN is not on the run. Its users are becoming more sophisticated, moving for example from simple phishing (using fake e-mails) to malware known as “trojans” that sit inside a victim’s computer collecting passwords and other sensitive information and sending them to their criminal masters.&lt;/p&gt;  &lt;p&gt;A favourite trick is to by-pass the security settings of a victim's browser by means of an extra piece of content injected into a legitimate website. An unwary user enters his password or account number into what looks like the usual box on his log-in page, and within minutes a programme such as Corpse’s Nuclear Grabber, OrderGun and Haxdoor has passed it to a criminal who can empty his bank account. When VeriSign managed to hack into the RBN computer running the scam, it found accumulated data representing 30,000 such infections. “Every major trojan in the last year links to RBN” says a VeriSign sleuth.&lt;/p&gt;  &lt;p&gt;RBN even fights back. In October 2006, the National Bank of Australia took active measures against Rock Phish, both directly and via a national anti-phishing group to which the bank’s security director belonged. RBN-based cybercriminals replied by crashing the bank’s home-page for three days.&lt;/p&gt;  &lt;p&gt;What can be done? VeriSign has tracked down the physical location of RBN’s servers. But Western law enforcement officers have so far tried in vain to get their Russian counterparts to pursue the investigation vigorously. “RBN feel they are strongly politically protected. They pay a huge amount of people. They know they are being watched. They cover their tracks,” says VeriSign. The head of RBN goes under the internet alias “Flyman”; his uncle is thought to be a senior St Petersburg politician. Repeated e-mails to RBN’s purported contact addresses asking for comment have gone unanswered.&lt;/p&gt;  &lt;p&gt;Companies can simply block access to any site registered at an RBN IP address. But that will not help most victims, such as those who receive infected e-mails. VeriSign says only strong political pressure on Russia will make the criminal justice system there deal with this glaring example of cyber-illegality.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-6908928064334972455?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/6908928064334972455/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=6908928064334972455' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6908928064334972455'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6908928064334972455'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/08/article-walk-on-dark-side.html' title='Article: A walk on the dark side'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3030074038430807772</id><published>2007-08-26T17:39:00.000-07:00</published><updated>2007-08-26T17:42:40.753-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='top malware'/><title type='text'>Top 5 malwares</title><content type='html'>&lt;div&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;span class="932421223-21082007"&gt;Current HOT  malwares:-&lt;/span&gt;&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;span class="932421223-21082007"&gt;&lt;/span&gt;&lt;/span&gt; &lt;/div&gt; &lt;div&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;span class="932421223-21082007"&gt;1. &lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Virtumonde&lt;/span&gt; - This  is well known mystery little sucker that gives users with Fake Alert and popups  with rogue antispyware product advertisements like Winantispyware 2007,  DriveCleaner etc.. informing users that their computer is not protected from  bogus virus.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;span class="932421223-21082007"&gt;    The big issue  with this Virtumonde (aka; Vundo, FakeAlert, Conhooks) is very users have  differnt sets of Virtumonde which means threats can change file names and it's  content to avoid detection. I've heard Virtumonde can re-generates every hour  into newer variants.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;span class="932421223-21082007"&gt;&lt;/span&gt;&lt;/span&gt; &lt;/div&gt; &lt;div&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;span class="932421223-21082007"&gt;2. &lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;Adware.Agent  variants&lt;/span&gt; - This is very similar to Virtumonde in behavior, this threat also  causes popups informing users to buy some bogus programs to clean out computer  problems.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;span class="932421223-21082007"&gt;&lt;/span&gt;&lt;/span&gt; &lt;/div&gt; &lt;div&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;span class="932421223-21082007"&gt;3. &lt;span style="font-weight: bold; color: rgb(102, 51, 102);"&gt;Maxifies &amp;  PurityScan&lt;/span&gt; - Also causes popups, usually hijacks wedsite to some bogus sites  like "Test your Internet Speed" or some "dating sites" - then when user clicks  to continue to test speed of their Internet or to find cyber lovers - then  user's computer will be hijacked and start downloading hips of malware on to  their computers. I usually find them through many freebie sites such as  downloading ringtone, screensavers, wallpapers, games and mp3s  etc..&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;span class="932421223-21082007"&gt;&lt;/span&gt;&lt;/span&gt; &lt;/div&gt; &lt;div&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;span class="932421223-21082007"&gt;4. &lt;span style="font-weight: bold; color: rgb(102, 51, 0);"&gt;&lt;span style="color: rgb(204, 153, 51);"&gt;Trojan.Popuper&lt;/span&gt; &lt;/span&gt;-  This threat disguise itself as video or audio codec, usually invites users to  some porn or dating or free music/movie trailers sites then informing users that  their Windows is missing some essential video codecs to display their videos,  after user clicks to install codecs, their PC gets hijacked and displays hips of  popups - some what similar to Virtumonde stuffs (and they usually are bundled  with Adware.Agents as well).&lt;/span&gt;&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;span class="932421223-21082007"&gt;   [Myspace.com] had  this ealier, which many hackers can setup bogus profile on myspace.com and  invites users to be friend.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;span class="932421223-21082007"&gt;&lt;/span&gt;&lt;/span&gt; &lt;/div&gt; &lt;div&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;span class="932421223-21082007"&gt;5. &lt;span style="font-weight: bold; color: rgb(0, 153, 0);"&gt;Free game  trojan&lt;/span&gt; - This can be very risky as I have seen so many trojans that bundled with  free games &amp; screensaver, I had few MDT logs showing no sign of malware but  had free Porn games or poker games. many users with repeat detection also  suffers from their istalled programs that keeps re-inserting trojans on to  user's computer after scan &amp;amp; fix. This sort of problem can't be fix  completely without uninstalling risky games.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3030074038430807772?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3030074038430807772/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3030074038430807772' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3030074038430807772'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3030074038430807772'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/08/top-5-malwares.html' title='Top 5 malwares'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-7026521566516249839</id><published>2007-07-19T00:26:00.000-07:00</published><updated>2007-07-19T00:30:49.713-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Ads'/><category scheme='http://www.blogger.com/atom/ns#' term='hosting sites'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojan'/><title type='text'>Hackers Can Now Deliver Viruses via Web Ads</title><content type='html'>Want to know why you gets trojans by just visiting legitimate web sites? Well, this is how myspace.com, ebay.com, youtube.com, and many popular domain sites such as torrent sites are being hijacked to host tones of malwares.&lt;br /&gt;&lt;br /&gt;Here is Wallstreet article on Tom's hardware case: &lt;a href="http://online.wsj.com/public/article/SB118480608500871051-WwvY6WDU_pi_D9m1KrYuwQQX1Y0_20070817.html?mod=tff_main_tff_top"&gt;Link&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-7026521566516249839?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/7026521566516249839/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=7026521566516249839' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7026521566516249839'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7026521566516249839'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/07/hackers-can-now-deliver-viruses-via-web.html' title='Hackers Can Now Deliver Viruses via Web Ads'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-7459795248525920833</id><published>2007-07-09T00:33:00.001-07:00</published><updated>2007-07-09T00:39:46.498-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='3D animation'/><category scheme='http://www.blogger.com/atom/ns#' term='F-Secure'/><category scheme='http://www.blogger.com/atom/ns#' term='Zdnet'/><category scheme='http://www.blogger.com/atom/ns#' term='graphical representation'/><title type='text'>Antivirus firm gets graphical to fight malware</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.zdnet.com.au/video/soa/Antivirus-firm-gets-graphical-to-fight-malware/0,2000065477,22172991p,00.htm"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_DAkCiWAwOQ4/RpHk0amcPXI/AAAAAAAAAC4/iD1f55uimAI/s320/graphical_rep_virus.JPG" alt="" id="BLOGGER_PHOTO_ID_5085097043422887282" border="0" /&gt;&lt;/a&gt;Have you guys wonder how malware looks like from inside your computer. Well, F-Secure have developed 3D animation work that shows how malware infection works.&lt;br /&gt;&lt;br /&gt;It's great, this may be the next data forensic tool.&lt;br /&gt;&lt;br /&gt;See the vid from F-Secure site or from &lt;a href="http://www.zdnet.com.au/video/soa/Antivirus-firm-gets-graphical-to-fight-malware/0,2000065477,22172991p,00.htm"&gt;ZDnet Vid&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-7459795248525920833?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/7459795248525920833/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=7459795248525920833' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7459795248525920833'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7459795248525920833'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/07/antivirus-firm-gets-graphical-to-fight.html' title='Antivirus firm gets graphical to fight malware'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_DAkCiWAwOQ4/RpHk0amcPXI/AAAAAAAAAC4/iD1f55uimAI/s72-c/graphical_rep_virus.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3828345584057131900</id><published>2007-07-03T21:54:00.000-07:00</published><updated>2007-07-03T22:00:18.888-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Kaspersky'/><category scheme='http://www.blogger.com/atom/ns#' term='malware evolution'/><category scheme='http://www.blogger.com/atom/ns#' term='report'/><title type='text'>The evolution of self-defense technologies in malware - Report! from Kaspersky</title><content type='html'>&lt;a href="http://bp1.blogger.com/_DAkCiWAwOQ4/RosoQKmcPWI/AAAAAAAAACw/hHmQihmkX28/s1600-h/0706_evolution_graph1_en.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5083200862606343522" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_DAkCiWAwOQ4/RosoQKmcPWI/AAAAAAAAACw/hHmQihmkX28/s320/0706_evolution_graph1_en.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;Have you ever experience malware or trojans that won't get rid off or just simply don't even get detected by your Antivirus or Antispyware programs? &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;Here is good report on current &amp; new emerging self-defence mechanisms in malware from Kaspersky explained in details.&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.viruslist.com/en/analysis?pubid=204791949"&gt;Direct link&lt;/a&gt;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3828345584057131900?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3828345584057131900/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3828345584057131900' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3828345584057131900'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3828345584057131900'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/07/evolution-of-self-defense-technologies.html' title='The evolution of self-defense technologies in malware - Report! from Kaspersky'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_DAkCiWAwOQ4/RosoQKmcPWI/AAAAAAAAACw/hHmQihmkX28/s72-c/0706_evolution_graph1_en.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-9107675251563177363</id><published>2007-06-20T17:52:00.000-07:00</published><updated>2007-06-20T18:02:13.588-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malicious SWF'/><title type='text'>Analyzing (malicious) SWF file actions</title><content type='html'>Here is interesting article about malicious SWF file (Flashplayer media file).&lt;br /&gt;It's possible to create malicious SWF file and embedded into html code.&lt;br /&gt;&lt;br /&gt;For info visit: Sans.org &lt;a href="http://isc.sans.org/diary.html?storyid=2931&amp;dshield=7ce16504eb27c3ceb44805678286c1b8"&gt;page&lt;/a&gt;&lt;br /&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=2931&amp;amp;dshield=7ce16504eb27c3ceb44805678286c1b8"&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-9107675251563177363?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/9107675251563177363/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=9107675251563177363' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/9107675251563177363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/9107675251563177363'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/06/analyzing-malicious-swf-file-actions.html' title='Analyzing (malicious) SWF file actions'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-623745244316365150</id><published>2007-06-20T17:39:00.000-07:00</published><updated>2007-06-24T04:59:03.841-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='F-Secure'/><category scheme='http://www.blogger.com/atom/ns#' term='top malware registry launchpoints'/><title type='text'>Top10 malware registry launchpoints</title><content type='html'>You guys want to know most common places where Trojans &amp;amp; other nasties loves to live on your Windows OS?&lt;br /&gt;&lt;br /&gt;More info please visit below link from F-Secure.&lt;br /&gt;Link: &lt;a href="http://www.f-secure.com/weblog/archives/archive-062007.html#00001207"&gt;Here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-623745244316365150?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/623745244316365150/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=623745244316365150' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/623745244316365150'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/623745244316365150'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/06/top10-malware-registry-launchpoints.html' title='Top10 malware registry launchpoints'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-1492136503427898767</id><published>2007-06-20T17:30:00.000-07:00</published><updated>2007-06-24T05:02:58.558-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IE7'/><category scheme='http://www.blogger.com/atom/ns#' term='Safari'/><category scheme='http://www.blogger.com/atom/ns#' term='AOL'/><category scheme='http://www.blogger.com/atom/ns#' term='Netscape'/><category scheme='http://www.blogger.com/atom/ns#' term='Browsers'/><category scheme='http://www.blogger.com/atom/ns#' term='Apple'/><category scheme='http://www.blogger.com/atom/ns#' term='Opera'/><category scheme='http://www.blogger.com/atom/ns#' term='Firefox'/><title type='text'>Browser war is on the way - New Safari 3 Browser for Windows</title><content type='html'>Howdy, check out the new Safari Browser for Windows. This Apple's own browser were only available for mac users, now they have released beta version for Windows.&lt;br /&gt;&lt;br /&gt;Link: &lt;a href="http://www.apple.com/safari/"&gt;http://www.apple.com/safari/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;According to Apple, Safari 3 is faster than any browsers on Internet. Hmmm, I though K-Meleon browser was fastest &amp;amp; smallest browser.&lt;br /&gt;&lt;br /&gt;K-Meleon browser can be download from: &lt;a href="http://kmeleon.sourceforge.net/"&gt;http://kmeleon.sourceforge.net/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Most popular browsers are: &lt;a href="http://downloads.channel.aol.com/browser"&gt;AOL&lt;/a&gt;, , &lt;a href="http://www.firefox.com/"&gt;Firefox&lt;/a&gt;, &lt;a href="http://www.microsoft.com/windows/downloads/ie/getitnow.mspx"&gt;Internet Explorer&lt;/a&gt;, &lt;a href="http://www.opera.com/download/"&gt;Opera&lt;/a&gt;, &lt;a href="http://browser.netscape.com/"&gt;Netscape&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-1492136503427898767?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/1492136503427898767/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=1492136503427898767' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1492136503427898767'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1492136503427898767'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/06/browser-war-is-on-way-new-safari-3.html' title='Browser war is on the way - New Safari 3 Browser for Windows'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-4702526506236803052</id><published>2007-06-20T17:24:00.000-07:00</published><updated>2007-06-24T04:59:36.162-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Winrar'/><category scheme='http://www.blogger.com/atom/ns#' term='TROJ_STARTPA.QC'/><category scheme='http://www.blogger.com/atom/ns#' term='Rarlab'/><category scheme='http://www.blogger.com/atom/ns#' term='TrendMicro'/><title type='text'>Watch out for fake Winrar - they are Trojans</title><content type='html'>If you guys want to download popular zip utility like Winrar then you should visit eaither download.com or actual vendor site &lt;a href="http://www.rarlab.com/"&gt;http://www.rarlab.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Do not visit fake Winrar site called &lt;a href="http://www.winrar(dot)com/"&gt;http://www.winrar(dot)com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For more info visit Trend Micro's article: &lt;a href="http://blog.trendmicro.com/a-winrar-lose-situation/"&gt;http://blog.trendmicro.com/a-winrar-lose-situation/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-4702526506236803052?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/4702526506236803052/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=4702526506236803052' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4702526506236803052'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4702526506236803052'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/06/watch-out-for-fake-winrar-they-are.html' title='Watch out for fake Winrar - they are Trojans'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-6265488891461910817</id><published>2007-06-20T17:11:00.000-07:00</published><updated>2007-06-20T17:22:27.478-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PC Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='lawsuit'/><category scheme='http://www.blogger.com/atom/ns#' term='Zango'/><category scheme='http://www.blogger.com/atom/ns#' term='court case'/><title type='text'>Zango was denied by US court</title><content type='html'>&lt;span style="color:#000000;"&gt;Good news guys ! Zango was denied by US court early this month. I hope Zango learnt their lesson from this stupid lawsuite.&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#000099;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#000099;"&gt;PC Tools wins fight against Zango&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="color:#cc33cc;"&gt;&lt;span style="color:#330033;"&gt;From:&lt;/span&gt; &lt;a href="http://www.pctools.com/news/view/id/176/"&gt;http://www.pctools.com/news/view/id/176/&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#cc33cc;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#cc0000;"&gt;Kaspersky wins fight against Zango&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="color:#cc33cc;"&gt;&lt;a href="http://spamnotes.com/2007/06/06/zango-update--no-tro-against-kaspersky.aspx"&gt;http://spamnotes.com/2007/06/06/zango-update--no-tro-against-kaspersky.aspx&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color:#cc33cc;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-6265488891461910817?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/6265488891461910817/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=6265488891461910817' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6265488891461910817'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6265488891461910817'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/06/zango-was-denied-by-us-court.html' title='Zango was denied by US court'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-6282501002747313686</id><published>2007-05-31T16:41:00.000-07:00</published><updated>2007-05-31T16:44:33.122-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Zombies'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Crimeware'/><category scheme='http://www.blogger.com/atom/ns#' term='Robert Alan Soloway'/><title type='text'>Good news ! - Hurray! Robert Alan Soloway is arrested</title><content type='html'>Good news for global Internet users, one of the worst email spammer is arrested.&lt;br /&gt;Check out below articles:&lt;br /&gt;&lt;a href="http://www.solowaysucks.net/"&gt;http://www.solowaysucks.net/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;More Info about him: &lt;a href="http://en.wikipedia.org/wiki/Robert_Soloway"&gt;Link&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-6282501002747313686?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/6282501002747313686/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=6282501002747313686' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6282501002747313686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6282501002747313686'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/05/good-news-hurray-robert-alan-soloway-is.html' title='Good news ! - Hurray! Robert Alan Soloway is arrested'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-1189184884762742133</id><published>2007-05-30T18:05:00.000-07:00</published><updated>2007-05-30T18:07:43.116-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Linux'/><category scheme='http://www.blogger.com/atom/ns#' term='joke'/><category scheme='http://www.blogger.com/atom/ns#' term='Clips'/><title type='text'>Watch this funny clips from Novel - PC, Mac... meet Linux</title><content type='html'>Both PC and Mac is meeting Linux.&lt;br /&gt;Direct lnk: &lt;a href="http://www.novell.com/linux/meetlinux/?linuxgamingworld.com"&gt;Here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-1189184884762742133?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/1189184884762742133/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=1189184884762742133' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1189184884762742133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1189184884762742133'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/05/watch-this-funny-clips-from-novel-pc.html' title='Watch this funny clips from Novel - PC, Mac... meet Linux'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-1975271393213823066</id><published>2007-05-30T18:02:00.000-07:00</published><updated>2007-05-30T18:04:48.389-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Pirates of the Carribean'/><title type='text'>Pirates of the Carribean Trojan - has anyone seen this??</title><content type='html'>&lt;span style="font-family:arial;"&gt;&lt;strong&gt;&lt;span style="color:#006600;"&gt;Pirates Trojan keel-hauls surfers&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;Spam messages exploiting the publicity surrounding the release of the latest instalment of the Pirates of the Caribbean film franchise are being used to trick users into installing Trojan horse malware.&lt;br /&gt;The junk mails feature a message that resembles promotional material for the film alongside links that supposedly point users towards trailers for Pirates of the Caribbean: At World’s End. Prospective marks are also offered the chance to win “free tickets”.&lt;br /&gt;Users attempting to download this trailer are, in reality, only offered the Pirabbean-A ( &lt;/span&gt;&lt;a title="http://www.sophos.com/security/analyses/trojyara.html" href="http://www.sophos.com/security/analyses/trojyara.html" target="_blank"&gt;&lt;span style="font-family:arial;"&gt;Yar-A&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;) Trojan.&lt;br /&gt;The malware attempts to switch victims' dial-up connections onto a premium-rate number.&lt;br /&gt;The Pirabbean-A Trojan uses a number of social engineering tricks in a bid to avoid detection.&lt;br /&gt;When the Trojan is run, it shows an error message, claiming that the clip failed to load because a user's PC lacks the necessary codecs. Fans are pointed towards the film's official site. The tactic is an attempt to stop users from suspecting that something amiss may have happened to their machines, making it less likely that users will run an anti-virus check. To make doubly sure, the Trojan also attempts to disable anti-virus software.&lt;br /&gt;The Trojan edits some Internet Explorer settings as well, adding two URLs to a user's Favorites. These maliciously constructed sites are designed to seed other forms of dialler software onto the PCs of prospective marks.&lt;br /&gt;The attack is far from the first time that hackers have used interest in Hollywood's produce to punt their wares. Previous malware strains have posed as clips from Harry Potter movies or targeted fans of such favourites as Kill Bill and Star Wars.&lt;br /&gt;Pirates of the Caribbean: At World’s End opened worldwide this weekend and is likely to do very well at the box office, despite the best efforts of critics such as the BBC Five Live's Mark Kermode. ®&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-1975271393213823066?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/1975271393213823066/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=1975271393213823066' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1975271393213823066'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1975271393213823066'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/05/pirates-of-carribean-trojan-has-anyone.html' title='Pirates of the Carribean Trojan - has anyone seen this??'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3208722988594116094</id><published>2007-05-23T00:46:00.000-07:00</published><updated>2007-05-23T00:48:52.519-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows Installer'/><category scheme='http://www.blogger.com/atom/ns#' term='KB927891'/><title type='text'>New Windows problem with Windows Installer</title><content type='html'>Did you guys had any problem with Windows lately?&lt;br /&gt;Check out this info on &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2007/05/23/920070.aspx"&gt;Microsoft Security Advisory KB927891 - fix for Windows Installer (MSI) problems&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3208722988594116094?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3208722988594116094/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3208722988594116094' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3208722988594116094'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3208722988594116094'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/05/new-windows-problem-with-windows.html' title='New Windows problem with Windows Installer'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-1549597517159034133</id><published>2007-05-23T00:45:00.000-07:00</published><updated>2007-05-23T00:46:15.432-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='Ani exploit'/><title type='text'>Analyzing an obfuscated ANI exploit</title><content type='html'>Check out this detailed work on ANI exploit from this &lt;a href="http://isc.sans.org/diary.html?storyid=2826&amp;amp;dshield=5e2f46f506d62f193abfd263446c4338"&gt;link&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-1549597517159034133?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/1549597517159034133/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=1549597517159034133' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1549597517159034133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1549597517159034133'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/05/analyzing-obfuscated-ani-exploit.html' title='Analyzing an obfuscated ANI exploit'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-4748893787356596869</id><published>2007-05-23T00:40:00.000-07:00</published><updated>2007-05-23T00:49:43.895-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Pctools'/><category scheme='http://www.blogger.com/atom/ns#' term='Zango'/><category scheme='http://www.blogger.com/atom/ns#' term='court case'/><category scheme='http://www.blogger.com/atom/ns#' term='Adware.Zango'/><category scheme='http://www.blogger.com/atom/ns#' term='Spyware Doctor'/><category scheme='http://www.blogger.com/atom/ns#' term='180Solutions'/><title type='text'>Adware.Zango sues PcTools's Spyware Doctor</title><content type='html'>This is very interesting developing lawsuit against major Antispyware company.&lt;br /&gt;Check out the story:&lt;a href="http://www.infoworld.com/article/07/05/18/zango-sues-antispyware-vendor_1.html"&gt;Link&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;How can this Zango be legitimate media company? After all they actually installs bunch of Trojans automatically.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-4748893787356596869?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/4748893787356596869/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=4748893787356596869' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4748893787356596869'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4748893787356596869'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/05/adwarezango-sues-pctoolss-spyware.html' title='Adware.Zango sues PcTools&apos;s Spyware Doctor'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-4253250889002168878</id><published>2007-05-14T05:39:00.000-07:00</published><updated>2007-05-14T05:42:39.338-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><title type='text'>Check out new graphical spam</title><content type='html'>&lt;a href="http://bp0.blogger.com/_DAkCiWAwOQ4/RkhYvkqEDNI/AAAAAAAAACo/362TY4B4z8I/s1600-h/spam_1.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5064395355295321298" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_DAkCiWAwOQ4/RkhYvkqEDNI/AAAAAAAAACo/362TY4B4z8I/s320/spam_1.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;I've received few spams today with graphical &amp;amp; refined spam.&lt;/div&gt;Spams today are getting new looks.&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-4253250889002168878?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/4253250889002168878/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=4253250889002168878' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4253250889002168878'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4253250889002168878'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/05/check-out-new-graphical-spam.html' title='Check out new graphical spam'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_DAkCiWAwOQ4/RkhYvkqEDNI/AAAAAAAAACo/362TY4B4z8I/s72-c/spam_1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3982764978989671888</id><published>2007-05-14T05:32:00.000-07:00</published><updated>2007-05-14T05:36:05.476-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='YouTube'/><category scheme='http://www.blogger.com/atom/ns#' term='Orkut'/><category scheme='http://www.blogger.com/atom/ns#' term='USB worm'/><category scheme='http://www.blogger.com/atom/ns#' term='Spyware blog'/><category scheme='http://www.blogger.com/atom/ns#' term='Firefox'/><title type='text'>Watch out for New threat! - USB Worm</title><content type='html'>This new threat targets Firefox/Orkut/Youtube.&lt;br /&gt;Check out the full description from:&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3982764978989671888?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3982764978989671888/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3982764978989671888' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3982764978989671888'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3982764978989671888'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/05/watch-out-for-new-threat-usb-worm.html' title='Watch out for New threat! - USB Worm'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-7477576621292099624</id><published>2007-05-06T23:39:00.000-07:00</published><updated>2007-05-06T23:48:36.578-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Trojan.Kardphisher'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojan.PWSteal.BS'/><category scheme='http://www.blogger.com/atom/ns#' term='credit card'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows fake activation'/><title type='text'>Watch out for new variant of Trojan.PWSteal.BS or aka Trojan.Kardphisher</title><content type='html'>&lt;a href="http://bp1.blogger.com/_DAkCiWAwOQ4/Rj7LWPBZmkI/AAAAAAAAACg/9jBPgOF90qA/s1600-h/Kardphisher2sm.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5061706614060980802" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 228px; CURSOR: hand; HEIGHT: 205px" height="225" alt="" src="http://bp1.blogger.com/_DAkCiWAwOQ4/Rj7LWPBZmkI/AAAAAAAAACg/9jBPgOF90qA/s320/Kardphisher2sm.jpg" width="265" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp0.blogger.com/_DAkCiWAwOQ4/Rj7KU_BZmjI/AAAAAAAAACY/rA-xkKdmqSs/s1600-h/Kardphisher1sm.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5061705493074516530" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 217px; CURSOR: hand; HEIGHT: 191px" height="204" alt="" src="http://bp0.blogger.com/_DAkCiWAwOQ4/Rj7KU_BZmjI/AAAAAAAAACY/rA-xkKdmqSs/s320/Kardphisher1sm.jpg" width="241" border="0" /&gt;&lt;/a&gt;There is new trojan that appears Windows Activation asking for credit card details, it's fake.More detailed info can be found from Symantec blog &lt;a href="http://www.symantec.com/enterprise/security_response/weblog/2007/05/ms_needs_your_credit_card_deta.html"&gt;page&lt;/a&gt;.&lt;/div&gt;&lt;br /&gt;&lt;p&gt;Or look at &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-042705-0108-99"&gt;Trojan.Kardphisher&lt;/a&gt; [Symantec]&lt;br /&gt;or &lt;a href="http://www.pctools.com/mrc/infections/id/Trojan.PWSteal.BS/"&gt;Trojan.PWSteal.BS&lt;/a&gt; [PCTools]&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-7477576621292099624?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/7477576621292099624/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=7477576621292099624' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7477576621292099624'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7477576621292099624'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/05/watch-out-for-new-variant-of.html' title='Watch out for new variant of Trojan.PWSteal.BS or aka Trojan.Kardphisher'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_DAkCiWAwOQ4/Rj7LWPBZmkI/AAAAAAAAACg/9jBPgOF90qA/s72-c/Kardphisher2sm.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-6121005631737647770</id><published>2007-04-29T17:32:00.000-07:00</published><updated>2007-04-29T17:34:24.495-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Pctools'/><category scheme='http://www.blogger.com/atom/ns#' term='news'/><category scheme='http://www.blogger.com/atom/ns#' term='Sunbelt'/><category scheme='http://www.blogger.com/atom/ns#' term='Antispyware'/><category scheme='http://www.blogger.com/atom/ns#' term='Antispy'/><category scheme='http://www.blogger.com/atom/ns#' term='cnet'/><category scheme='http://www.blogger.com/atom/ns#' term='market'/><category scheme='http://www.blogger.com/atom/ns#' term='war'/><category scheme='http://www.blogger.com/atom/ns#' term='Webroot'/><title type='text'>AntiSpy VS AntiSpy - AntiSpyware market news</title><content type='html'>Article link: &lt;a title="http://reviews.cnet.com/4520-3513_7-6729554-1.html" href="http://reviews.cnet.com/4520-3513_7-6729554-1.html"&gt;http://reviews.cnet.com/4520-3513_7-6729554-1.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-6121005631737647770?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/6121005631737647770/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=6121005631737647770' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6121005631737647770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6121005631737647770'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/antispy-vs-antispy-antispyware-market.html' title='AntiSpy VS AntiSpy - AntiSpyware market news'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-1020784493265672763</id><published>2007-04-26T21:32:00.000-07:00</published><updated>2007-05-06T23:49:10.170-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Signacert'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyberhawk'/><category scheme='http://www.blogger.com/atom/ns#' term='Robotgenius'/><category scheme='http://www.blogger.com/atom/ns#' term='Aternative Antivirus'/><title type='text'>Found aternative tools for Antivirus protection.</title><content type='html'>There are many alternative protection tools are available to purchase or try for free.&lt;br /&gt;Go ahead try test driving some of them.&lt;br /&gt;They all claimed to be non signature type of Antivirus tools, but what happens when malware can bypass them?&lt;br /&gt;&lt;br /&gt;o &lt;a href="http://www.signacert.com/index.php?id=579"&gt;Signacert&lt;/a&gt;&lt;br /&gt;o &lt;a href="http://www.robotgenius.net/applications/desktop.jsp"&gt;Robotgenius&lt;/a&gt;&lt;br /&gt;o &lt;a href="http://www.novatix.com/Cyberhawk/"&gt;Cyberhawk&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For home user visit &lt;a href="http://www.novatix.com/Cyberhawk/"&gt;Cyberhawk&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-1020784493265672763?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/1020784493265672763/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=1020784493265672763' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1020784493265672763'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1020784493265672763'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/found-aternative-protction-tools-for.html' title='Found aternative tools for Antivirus protection.'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3696249151647718746</id><published>2007-04-26T21:28:00.000-07:00</published><updated>2007-04-26T21:31:38.772-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Custom Packer'/><category scheme='http://www.blogger.com/atom/ns#' term='Packers'/><title type='text'>Custom Packer ! Article "Packers, Packers, Packers for sale !"</title><content type='html'>&lt;a href="http://bp0.blogger.com/_DAkCiWAwOQ4/RjF8jPBZmiI/AAAAAAAAACQ/ZOv0KKIRWX4/s1600-h/packer1.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5057960801283447330" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_DAkCiWAwOQ4/RjF8jPBZmiI/AAAAAAAAACQ/ZOv0KKIRWX4/s320/packer1.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;Has anyone noticed that some of the malware are packed with some weird packers?&lt;/div&gt;&lt;br /&gt;&lt;div&gt;For detailed information visit Websense &lt;a href="http://www.websense.com/securitylabs/blog/blog.php?BlogID=123"&gt;link&lt;/a&gt;.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;I wish I can obtain this packer.. ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3696249151647718746?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3696249151647718746/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3696249151647718746' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3696249151647718746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3696249151647718746'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/custom-packer-article-packers-packers.html' title='Custom Packer ! Article &quot;Packers, Packers, Packers for sale !&quot;'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_DAkCiWAwOQ4/RjF8jPBZmiI/AAAAAAAAACQ/ZOv0KKIRWX4/s72-c/packer1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-4989604196577194010</id><published>2007-04-26T21:22:00.000-07:00</published><updated>2007-04-26T21:27:24.201-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ani Attack'/><category scheme='http://www.blogger.com/atom/ns#' term='Ani exploit'/><title type='text'>Tale of 2 ANI attacks</title><content type='html'>&lt;a href="http://bp0.blogger.com/_DAkCiWAwOQ4/RjF7gPBZmhI/AAAAAAAAACI/51TTCxSfI_Y/s1600-h/Ani_attack.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5057959650232211986" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_DAkCiWAwOQ4/RjF7gPBZmhI/AAAAAAAAACI/51TTCxSfI_Y/s320/Ani_attack.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;Check out the two very different continental ANI exploit from Websense.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Detailed explaination can be locate &lt;a href="http://www.websense.com/securitylabs/blog/blog.php?BlogID=122"&gt;here&lt;/a&gt;.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;Also see the map provided by Google on the report.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-4989604196577194010?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/4989604196577194010/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=4989604196577194010' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4989604196577194010'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4989604196577194010'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/tale-of-2-ani-attacks.html' title='Tale of 2 ANI attacks'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_DAkCiWAwOQ4/RjF7gPBZmhI/AAAAAAAAACI/51TTCxSfI_Y/s72-c/Ani_attack.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-5159844564316090540</id><published>2007-04-26T17:39:00.000-07:00</published><updated>2007-04-26T17:44:13.144-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='New technology'/><category scheme='http://www.blogger.com/atom/ns#' term='detecting'/><title type='text'>New approaches to malware detection coming into view</title><content type='html'>The major AV vendors like Symantec, McAfee &amp; TrendMicro is seeking new ways to detect Malware or viruses.&lt;br /&gt;Detailed article can be found &lt;a href="http://www.networkworld.com/news/2007/042507-malware-detection.html?page=1"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-5159844564316090540?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/5159844564316090540/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=5159844564316090540' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5159844564316090540'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5159844564316090540'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/new-approaches-to-malware-detection.html' title='New approaches to malware detection coming into view'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-2399302693779167164</id><published>2007-04-26T17:29:00.000-07:00</published><updated>2007-04-26T17:39:05.154-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='operating systems'/><category scheme='http://www.blogger.com/atom/ns#' term='airlines'/><category scheme='http://www.blogger.com/atom/ns#' term='joke'/><title type='text'>JOKE! If Operating Systems Ran The Airlines...</title><content type='html'>Different operating systems. Different styles. But what if the quirks and styles of the different operating systems were applied to AIRLINES? What if airlines ran things the way operating systems do? This humorous analogy, applying operating system philosophies as if they were airlines, is a long-standing much-circulated amusing story, and we'd credit the author if we knew who wrote it!&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#663366;"&gt;&lt;strong&gt;If Operating Systems Ran The Airlines...&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;UNIX Airways&lt;/span&gt;&lt;br /&gt;Everyone brings one piece of the plane along when they come to the airport. They all go out on the runway and put the plane together piece by piece, arguing non-stop about what kind of plane they are supposed to be building.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#3333ff;"&gt;Air DOS&lt;/span&gt;&lt;br /&gt;Everybody pushes the airplane until it glides, then they jump on and let the plane coast until it hits the ground again. Then they push again, jump on again, and so on...&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;Mac Airlines&lt;/span&gt;&lt;br /&gt;All the stewards, captains, baggage handlers, and ticket agents look and act exactly the same. Every time you ask questions about details, you are gently but firmly told that you don't need to know, don't want to know, and everything will be done for you without your ever having to know, so just shut up.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#3333ff;"&gt;Windows Air&lt;/span&gt;&lt;br /&gt;The terminal is pretty and colourful, with friendly stewards, easy baggage check and boarding, and a smooth take-off. After about 10 minutes in the air, the plane explodes with no warning whatsoever.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#3333ff;"&gt;Windows NT Air&lt;/span&gt;&lt;br /&gt;Just like Windows Air, but costs more, uses much bigger planes, and takes out all the other aircraft within a 40-mile radius when it explodes.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#3333ff;"&gt;Windows XP Air&lt;/span&gt;&lt;br /&gt;You turn up at the airport,which is under contract to only allow XP Air planes. All the aircraft are identical, brightly coloured and three times as big as they need to be. The signs are huge and all point the same way. Whichever way you go, someone pops up dressed in a cloak and pointed hat insisting you follow him. Your luggage and clothes are taken off you and replaced with an XP Air suit and suitcase identical to everyone around you as this is included in the exorbitant ticket cost. The aircraft will not take off until you have signed a contract. The inflight entertainment promised turns out to be the same Mickey Mouse cartoon repeated over and over again. You have to phone your travel agent before you can have a meal or drink. You are searched regularly throughout the flight. If you go to the toilet twice or more you get charged for a new ticket. No matter what destination you booked you will always end up crash landing at Whistler in Canada.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#cc0000;"&gt;OSX Air&lt;/span&gt;&lt;br /&gt;You enter a white terminal, and all you can see is a woman sitting in the corner behind a white desk, you walk up to get your ticket. She smiles and says "Welcome to OS X Air, please allow us to take your picture", at which point a camera in the wall you didn't notice before takes your picture. "Thank you, here is your ticket" You are handed a minimalistic ticket with your picture at the top, it already has all of your information. A door opens to your right and you walk through. You enter a wide open space with one seat in the middle, you sit, listen to music and watch movies until the end of the flight. You never see any of the other passengers. You land, get off, and you say to yourself "wow, that was really nice, but I feel like something was missing"&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#3333ff;"&gt;Windows Vista Airlines&lt;/span&gt;&lt;br /&gt;You enter a good looking terminal with the largest planes you have ever seen. Every 10 feet a security officer appears and asks you if you are "sure" you want to continue walking to your plane and if you would like to cancel. Not sure what cancel would do, you continue walking and ask the agent at the desk why the planes are so big. After the security officer making sure you want to ask the question and you want to hear the answer, the agent replies that they are bigger because it makes customers feel better, but the planes are designed to fly twice as slow. Adding the size helped achieve the slow fly goal.Once on the plane, every passenger has to be asked individually by the flight attendants if they are sure they want to take this flight. Then it is company policy that the captain asks the passengers collectively the same thing. After answering yes to so many questions, you are punched in the face by some stranger who when he asked "Are you sure you want me to punch you in the face? Cancel or Allow?" you instinctively say "Allow".After takeoff, the pilots realize that the landing gear driver wasn't updated to work with the new plane. Therefore it is always stuck in the down position. This forces the plane to fly even slower, but the pilots are used to it and continue to fly the planes, hoping that soon the landing gear manufacturer will give out a landing gear driver update.You arrive at your destination wishing you had used your reward miles with XP airlines rather than trying out this new carrier. A close friend, after hearing your story, mentions that Linux Air is a much better alternative and helps.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#ff0000;"&gt;Linux Air&lt;/span&gt;&lt;br /&gt;Disgruntled employees of all the other OS airlines decide to start their own airline. They build the planes, ticket counters, and pave the runways themselves. They charge a small fee to cover the cost of printing the ticket, but you can also download and print the ticket yourself.&lt;br /&gt;When you board the plane, you are given a seat, four bolts, a wrench and a copy of the seat-HOWTO.html. Once settled, the fully adjustable seat is very comfortable, the plane leaves and arrives on time without a single problem, the in-flight meal is wonderful. You try to tell customers of the other airlines about the great trip, but all they can say is, "You had to do what with the seat?"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-2399302693779167164?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/2399302693779167164/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=2399302693779167164' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/2399302693779167164'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/2399302693779167164'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/joke-if-operating-systems-ran-airlines.html' title='JOKE! If Operating Systems Ran The Airlines...'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-6103838293081944811</id><published>2007-04-26T17:28:00.000-07:00</published><updated>2007-04-26T17:29:37.264-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='joke'/><title type='text'>JOKE! Micro$oft &amp; Unix joke qoutes</title><content type='html'>To err is human, but to really foul things up requires a computer.&lt;br /&gt;&lt;br /&gt;Any sufficiently advanced bug is indistinguishable from a feature.&lt;br /&gt;The UNIX philosophy basically involves giving you enough rope to hang yourself. And then a couple of feet more, just to be sure.&lt;br /&gt;&lt;br /&gt;Those parts of the system that you can hit with a hammer (not advised) are called hardware; those program instructions that you can only curse at are called software.&lt;br /&gt;The difference between Microsoft and Jurassic Park?In one, a mad businessman makes a lot of money with beasts that should be extinct.The other is a film.&lt;br /&gt;&lt;br /&gt;The gates in my computer are AND, OR and NOT; they are not Bill.&lt;br /&gt;&lt;br /&gt;Nobody will ever need more than 640k RAM!?Bill Gates, 1981Windows 95 needs at least 8 MB RAM.?Bill Gates, 1996Nobody will ever need Windows 95.?Logical conclusion&lt;br /&gt;&lt;br /&gt;Those who can't write, write manuals.&lt;br /&gt;&lt;br /&gt;You have moved the mouse. NT must be restarted for the changes to take effect.&lt;br /&gt;&lt;br /&gt;A computer without any MS Windows is like a fish without a bicycle.&lt;br /&gt;UNIX is user friendly. It's just selective about who its friends are.&lt;br /&gt;&lt;br /&gt;If all else fails, read the documentation.&lt;br /&gt;&lt;br /&gt;Unix, MS-DOS, and Windows NT (also known as the Good, the Bad, and the Ugly).&lt;br /&gt;Those who don't understand Unix are doomed to reinvent it, poorly.&lt;br /&gt;&lt;br /&gt;You may not understand what I'm installing, but that's not my job. I just need to click Next, Next, Finish here so I can walk to the next system and repeat the process?&lt;br /&gt;Gates' Law: Every 18 months, the speed of software halves.&lt;br /&gt;&lt;br /&gt;MCSE == Minesweeper Consultant / Solitaire Expert&lt;br /&gt;&lt;br /&gt;Press any key to continue, or any other key to cancel.&lt;br /&gt;&lt;br /&gt;The only place for 63,000 bugs is a rain forest?&lt;br /&gt;&lt;br /&gt;Of course I use Microsoft. Setting up a stable unix network is no challenge ;p&lt;br /&gt;&lt;br /&gt;If the ancients were right and to think is to exist, does Microsoft exist?&lt;br /&gt;&lt;br /&gt;The BeOS takes the best features from the major operating systems. It's got the power and flexibility of Unix, the interface and ease of use of the MacOS, and Minesweeper from Windows.&lt;br /&gt;Everyone has a photographic memory. Some don't have film.&lt;br /&gt;&lt;br /&gt;A Law of Computer Programming:Make it possible for programmers to write in English and you will find that programmers cannot write in English.&lt;br /&gt;&lt;br /&gt;Mosher's Law of Software Engineering:Don't worry if it doesn't work right.If everything did, you'll be out of a job&lt;br /&gt;&lt;br /&gt;Real programmers don't write in BASIC. Actually, no programmers write in BASIC after reaching puberty.&lt;br /&gt;&lt;br /&gt;Premature optimization is the root of all evil.&lt;br /&gt;Voodoo Programming: Things programmers do that they know shouldn't work but they try anyway, and which sometimes actually work, such as recompiling everything.&lt;br /&gt;Eagleson's Law:Any code of your own that you haven't looked at for six or moremonths, might as well have been written by someone else.&lt;br /&gt;&lt;br /&gt;A programming language that is sort of like Pascal except more likeassembly except that it isn't very much like either one, or anything else. It is either the best language available to the art today, or it isn't.&lt;br /&gt;If the code and the comments disagree, then both are probably wrong.?&lt;br /&gt;&lt;br /&gt;/* Halley */(Halley's comment.)&lt;br /&gt;&lt;br /&gt;Never attribute to malloc that which can be adequately explained by stupidity.&lt;br /&gt;C is a language that combines all the elegance and power of assembly language with all the readability and maintainability of assembly language.&lt;br /&gt;&lt;br /&gt;If it wasn't for C, we'll be using BASI, PASAL and OBOL&lt;br /&gt;&lt;br /&gt;99 little bugs in the code, 99 bugs in the code,fix one bug, compile it again?101 little bugs in the code?&lt;br /&gt;&lt;br /&gt;#define QUESTION ((bb)  !(bb)) /* Shakespeare */&lt;br /&gt;&lt;br /&gt;Give a man a computer program and you give him a headache, but teach him to program computers and you give him the power to create headaches for others for the rest of his life?&lt;br /&gt;Bus error - driver executed.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-6103838293081944811?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/6103838293081944811/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=6103838293081944811' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6103838293081944811'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6103838293081944811'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/joke-microoft-unix-joke-qoutes.html' title='JOKE! Micro$oft &amp; Unix joke qoutes'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-7488628627464413638</id><published>2007-04-25T22:56:00.000-07:00</published><updated>2007-04-25T22:58:45.835-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='Nitin'/><category scheme='http://www.blogger.com/atom/ns#' term='Vipin Kumar'/><category scheme='http://www.blogger.com/atom/ns#' term='VBootkit'/><title type='text'>0wning Vista from the boot</title><content type='html'>Read full article from &lt;a href="http://www.securityfocus.com/columnists/442/1"&gt;here&lt;/a&gt;.&lt;br /&gt;Federico Biancuzzi interviews Nitin and Vipin Kumar, authors of VBootkit, a rootkit that is able to load from Windows Vista boot-sectors. They discuss the "features" of their code, the support of the various versions of Vista, the possibility to place it inside the BIOS (it needs around 1500 bytes), and the chance to use it to bypass Vista's product activation or avoid DRM.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-7488628627464413638?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/7488628627464413638/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=7488628627464413638' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7488628627464413638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7488628627464413638'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/0wning-vista-from-boot.html' title='0wning Vista from the boot'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-389256140537220484</id><published>2007-04-25T22:54:00.002-07:00</published><updated>2007-04-25T22:59:32.809-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security list'/><category scheme='http://www.blogger.com/atom/ns#' term='portal'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><title type='text'>MicroSoft's own detailed threats listing site!</title><content type='html'>Checkout MS's threat listing, wow are they going to be full Antivirus company?&lt;br /&gt;&lt;a title="http://www.microsoft.com/security/portal/" href="http://www.microsoft.com/security/portal/"&gt;http://www.microsoft.com/security/portal/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-389256140537220484?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/389256140537220484/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=389256140537220484' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/389256140537220484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/389256140537220484'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/microsofts-own-detailed-threats-listing.html' title='MicroSoft&apos;s own detailed threats listing site!'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-236580723615954582</id><published>2007-04-25T22:54:00.001-07:00</published><updated>2007-04-25T22:54:40.762-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Clickbot.A'/><title type='text'>Anatomy of Clickbot.A</title><content type='html'>Get PDF report from: &lt;a title="http://www.usenix.org/events/hotbots07/tech/full_papers/daswani/daswani.pdf" href="http://www.usenix.org/events/hotbots07/tech/full_papers/daswani/daswani.pdf"&gt;http://www.usenix.org/events/hotbots07/tech/full_papers/daswani/daswani.pdf&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-236580723615954582?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/236580723615954582/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=236580723615954582' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/236580723615954582'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/236580723615954582'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/anatomy-of-clickbota.html' title='Anatomy of Clickbot.A'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-180308961085385588</id><published>2007-04-25T22:46:00.000-07:00</published><updated>2007-04-25T22:53:42.072-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='joke'/><title type='text'>JOKE! Some social mathematics for you</title><content type='html'>&lt;strong&gt;&lt;span style="color:#ff6666;"&gt;ROMANCE MATHEMATICS&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;Smart man + smart woman = romance&lt;br /&gt;Smart man + dumb woman = affair&lt;br /&gt;Dumb man + smart woman = marriage&lt;br /&gt;Dumb man + dumb woman = pregnancy&lt;br /&gt;`````````````````````````````````````&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#3366ff;"&gt;OFFICE ARITHMETIC&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;Smart boss + smart employee = profit&lt;br /&gt;Smart boss + dumb employee = production&lt;br /&gt;Dumb boss + smart employee = promotion&lt;br /&gt;Dumb boss + dumb employee = overtime&lt;br /&gt;```````````````````````````````````````&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#cc33cc;"&gt;SHOPPING MATH&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;A man will pay $2 for a $1 item he needs.&lt;br /&gt;A woman will pay $1 for a $2 item that she doesn't need.&lt;br /&gt;``````````````````````````````````````````````````&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#cc9933;"&gt;GENERAL EQUATIONS &amp; STATISTICS&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;A woman worries about the future until she gets a husband.&lt;br /&gt;A man never worries about the future until he gets a wife.&lt;br /&gt;A successful man is one who makes more money than his wife can spend.&lt;br /&gt;A successful woman is one who can find such a man.&lt;br /&gt;````````````````````````````````````````````````&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#cc0000;"&gt;HAPPINESS &lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;To be happy with a man, you must understand him a lot and love him a little.&lt;br /&gt;To be happy with a woman, you must love her a lot and not try to understand her at all.&lt;br /&gt;`````````````````````````````````````````````````````````````````````````````&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#33ff33;"&gt;LONGEVITY&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;Married men live longer than single men do, but married men are a lot more willing to die.&lt;br /&gt;``````````````````````````````````````````````````````````````````````````````&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#cc33cc;"&gt;PROPENSITY TO CHANGE&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;woman marries a man expecting he will change, but he doesn't.A man marries a woman expecting that she won't change, and she does.&lt;br /&gt;```````````````````````````````````````````````````````````````````````````````&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#663333;"&gt;DISCUSSION TECHNIQUE&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;A woman has the last word in any argument.Anything a man says after that is the beginning of a new argument.&lt;br /&gt;````````````````````````````````````````````````````````````````````````````````&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#006600;"&gt;HOW TO STOP PEOPLE FROM BUGGING YOU ABOUT GETTING MARRIED&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;Old aunts used to come up to me at weddings, poking me in the ribs and cackling, telling me, "You're next." They stopped after I started doing the same thing to them at funerals.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-180308961085385588?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/180308961085385588/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=180308961085385588' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/180308961085385588'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/180308961085385588'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/joke-some-social-mathematics-for-you.html' title='JOKE! Some social mathematics for you'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-5997136680665369684</id><published>2007-04-25T22:45:00.000-07:00</published><updated>2007-04-25T22:46:34.463-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Adware'/><title type='text'>Adware poses as ActiveX control</title><content type='html'>Article can be found &lt;a href="http://www.theregister.co.uk/2007/04/17/adware_activex_control/"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Security researchers have discovered samples of adware posing as ActiveX controls that allow voyeurs to watch online smut.&lt;br /&gt;The ploy used by ImageAccesActiveXObject represents a new tactic in the battle to infect users' PCs, according to anti-virus firm Panda Software. The malware infects Windows PCs when users visit hacker-controlled websites posing as repositories of porn. When users visit these sites a window opens offering "erotic pictures". If the user agrees, another window informs that an ActiveX has to be installed. This control, however, is really the adware ImageAccesActiveXObject as demonstrated in a &lt;a title="http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/04/16/FakeImages_210021002100_.aspx" href="http://blogs.pandasoftware.com/blogs/pandalabs/archive/2007/04/16/FakeImages_210021002100_.aspx" target="_blank"&gt;video&lt;/a&gt; produced by Panda on the threat.&lt;br /&gt;document.write('\x3Cscript src="http://ad.uk.doubleclick.net/adj/reg.security.4159/antivirus;'+RegExCats+GetVCs()+'ptype='+RegPage+';maid='+maid+';pf='+RegPF+';dcove=d;test='+test+';sz=336x280;tile=3;ord=' + rand + '?" type="text/javascript"&gt;\x3C\/script&gt;');&lt;br /&gt;&lt;a title="http://ad.uk.doubleclick.net/click;h=" sscs="%3fhttp://forms.theregister.co.uk/studies/200704/?pid=" href="http://ad.uk.doubleclick.net/click;h=v8/3538/0/0/%2a/w;98289618;0-0;0;13500661;4252-336/280;20774815/20792708/1;;~sscs=%3fhttp://forms.theregister.co.uk/studies/200704/?pid=m" target="_blank"&gt;&lt;/a&gt;“Before now we had seen adware disguised as codecs to see videos, but never as ActiveX controls for viewing pictures. This is another strategy for tricking users. They think they are giving their consent to the installation of a legitimate tool when really they are allowing adware to be installed”, explained Luis Corrons, technical director of PandaLabs.&lt;br /&gt;Once installed, the adware takes users to a page - which is currently unavailable - hosting smutty pictures. Meanwhile, malicious code is surreptitiously loaded onto compromised PCs. Among the sample of malware loaded onto PCs is SpyLocked, adware warning users that their computer is infected, and detectingImageAccesActiveXObject. The "scareware" posing as security software will not allow computers to be disinfected unless users register the product. ImageAccesActiveXObject also downloads the Securitytoolbar adware, which installs a toolbar and displays intrusive pop-up pages when users visit certain websites. ®&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-5997136680665369684?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/5997136680665369684/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=5997136680665369684' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5997136680665369684'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5997136680665369684'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/adware-poses-as-activex-control.html' title='Adware poses as ActiveX control'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-5688087237739029899</id><published>2007-04-25T22:43:00.000-07:00</published><updated>2007-04-25T22:44:54.497-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='disgrace'/><category scheme='http://www.blogger.com/atom/ns#' term='discussion'/><category scheme='http://www.blogger.com/atom/ns#' term='Sunbelt'/><category scheme='http://www.blogger.com/atom/ns#' term='Webroot'/><title type='text'>Webroot's disgrace action</title><content type='html'>Checkout the post messages as well!&lt;br /&gt;&lt;a title="http://sunbeltblog.blogspot.com/2007/04/this-is-just-weird.html" href="http://sunbeltblog.blogspot.com/2007/04/this-is-just-weird.html"&gt;http://sunbeltblog.blogspot.com/2007/04/this-is-just-weird.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-5688087237739029899?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/5688087237739029899/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=5688087237739029899' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5688087237739029899'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5688087237739029899'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/webroots-disgrace-action.html' title='Webroot&apos;s disgrace action'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-8959678052175237240</id><published>2007-04-25T22:40:00.000-07:00</published><updated>2007-04-25T22:42:51.571-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cybercrooks'/><title type='text'>Cybercrooks who rig Web sites to break into PCs are getting better at hiding their malicious code, a security expert say</title><content type='html'>Article can be found &lt;a href="http://www.zdnetasia.com/news/security/0,39044215,62006444,00.htm"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;VANCOUVER, B.C.--Cybercrooks who rig Web sites to break into PCs are getting better at hiding their malicious code, a security expert said Wednesday.&lt;br /&gt;Increasingly the actual code, often JavaScript, used to attack PCs is hidden in Flash animations or scrambled so that anyone who examines the source of a page can't easily identify it, said Jose Nazario, a senior software engineer at Arbor Networks, in a presentation at the &lt;a title="http://www.cansecwest.com/" href="http://www.cansecwest.com/" target="_blank"&gt;CanSecWest security confab&lt;/a&gt; here.&lt;br /&gt;"Their obfuscation tools are primitive but effective," Nazario said. "They use obfuscation to avoid simple signatures," he said, referring to security techniques based on signatures to detect malicious Web sites. Signatures are fingerprints of known attacks.&lt;br /&gt;Web attacks have become commonplace. Tens of thousands of Web sites attempt to install malicious code, according to &lt;a title="http://www.stopbadware.org/" href="http://www.stopbadware.org/" target="_blank"&gt;StopBadware.org&lt;/a&gt;. The sites, the bulk of which are compromised sites, often drop a Trojan horse or other pest onto a PC through a security hole in the Web browser.&lt;br /&gt;Many attacks use JavaScript. Initially miscreants &lt;a title="http://www.zdnetasia.com/news/internet/0,39044246,39378888,00.htm&amp;#10;The security risk in Web 2.0 -- Monday, Jul. 31, 2006" href="http://www.zdnetasia.com/news/internet/0,39044246,39378888,00.htm"&gt;used plain JavaScript in their attacks&lt;/a&gt;, but that has changed, Nazario said. He has spotted an encoded script function called "makemelaugh" that downloads a Trojan horse that captures bank information and a Paris Hilton Flash animation that installs a tool that makes a PC part of a botnet.&lt;br /&gt;Attackers also are trying to outsmart security pros by programming malicious sites to load their malicious code only once on the same PC, Nazario said. Furthermore, a new toolkit called NeoSploit identifies the browser and is packed with security exploits to launch the proper attack, he said.&lt;br /&gt;There are things security professionals can do to investigate attacks, Nazario said. "Bad guys are limited by the fact that &lt;a title="http://www.zdnetasia.com/news/security/0,39044215,39378884,00.htm&amp;#10;JavaScript opens doors to browser-based attacks -- Monday, Jul. 31, 2006" href="http://www.zdnetasia.com/news/security/0,39044215,39378884,00.htm"&gt;JavaScript has to be decoded&lt;/a&gt; to be used by the browser. As long as you can analyze it outside the browser, you can figure out what it is going to do," he said.&lt;br /&gt;The scrambled code can be made legible since it typically uses simple Base64 encoding for obfuscation and not actual encryption, Nazario said. He suggested NJS, SpiderMonkey and Rhino as tools to investigate script code. Flash files can be analyzed using a program called Flasm, he said.&lt;br /&gt;Malicious JavaScript can be embedded in a Web page and will typically run without warning when the page is viewed in any ordinary browser. Attackers could try to lure you to their own, rigged Web site. But an attack could also lurk on a trusted Web site by exploiting a common flaw known as cross-site scripting.&lt;br /&gt;To shield against malicious JavaScript, Web surfers can disable JavaScript, but that can impact the functionality of many Web sites. An alternative is to use security tools that have blacklists of known bad sites such as McAfee's SiteAdvisor or Google's Toolbar or Desktop software.&lt;br /&gt;Another alternative is Exploit Prevention Labs' LinkScanner, which monitors traffic going into a PC and blocks known exploits.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-8959678052175237240?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/8959678052175237240/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=8959678052175237240' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8959678052175237240'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8959678052175237240'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/cybercrooks-who-rig-web-sites-to-break.html' title='Cybercrooks who rig Web sites to break into PCs are getting better at hiding their malicious code, a security expert say'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-719885898807138280</id><published>2007-04-25T22:30:00.000-07:00</published><updated>2007-04-25T22:39:49.288-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='siteadvisor'/><category scheme='http://www.blogger.com/atom/ns#' term='TrendMicro'/><category scheme='http://www.blogger.com/atom/ns#' term='McAfee'/><category scheme='http://www.blogger.com/atom/ns#' term='TrendProtect'/><title type='text'>Check out the TrendMicro answer to McAfee's SiteAdvisor</title><content type='html'>&lt;a href="http://www.trendmicro.com"&gt;TrendMicro&lt;/a&gt; is following footstep of &lt;a href="http://www.mcafee.com"&gt;McAfee&lt;/a&gt;'s popular &lt;a href="http://us.mcafee.com/root/product.asp?productid=sa&amp;cid=26044"&gt;SiteAdvisor&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Want to see their newest tool "TrendProtect"?&lt;br /&gt;Here: &lt;a href="http://www.trendsecure.com/portal/en-US/free_security_tools/trendprotect.php"&gt;Link&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-719885898807138280?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/719885898807138280/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=719885898807138280' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/719885898807138280'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/719885898807138280'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/check-out-trendmicro-answer-to-mcafees.html' title='Check out the TrendMicro answer to McAfee&apos;s SiteAdvisor'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-6814646636364735905</id><published>2007-04-11T23:03:00.000-07:00</published><updated>2007-04-11T23:13:54.728-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Robotcop'/><category scheme='http://www.blogger.com/atom/ns#' term='Future Worrior'/><category scheme='http://www.blogger.com/atom/ns#' term='Future Soldier'/><category scheme='http://www.blogger.com/atom/ns#' term='Bodysuit'/><title type='text'>Future Soldier - Robotcop look alike bodysuit</title><content type='html'>&lt;a href="http://bp1.blogger.com/_DAkCiWAwOQ4/Rh3Mt8T7y1I/AAAAAAAAACA/1Jpd6Xet53s/s1600-h/future_soldier_suit.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5052419446635481938" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_DAkCiWAwOQ4/Rh3Mt8T7y1I/AAAAAAAAACA/1Jpd6Xet53s/s320/future_soldier_suit.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Check out cool Future Worrior's bodysuit, look just like from Robotcop movie.&lt;br /&gt;&lt;br /&gt;Battlefiled 2025 style&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Direct link: &lt;a href="http://soldiermagazine.co.uk/mag/feature1.htm"&gt;http://soldiermagazine.co.uk/mag/feature1.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;* Super-strength soldiers&lt;br /&gt;* Water-tight design&lt;br /&gt;* Head start on the enemy&lt;br /&gt;* Bullet-proof bootnecks&lt;br /&gt;* Robo-Rangers &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-6814646636364735905?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/6814646636364735905/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=6814646636364735905' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6814646636364735905'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6814646636364735905'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/future-soldier-robotcop-look-alike.html' title='Future Soldier - Robotcop look alike bodysuit'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_DAkCiWAwOQ4/Rh3Mt8T7y1I/AAAAAAAAACA/1Jpd6Xet53s/s72-c/future_soldier_suit.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-6478054404749929180</id><published>2007-04-02T17:49:00.000-07:00</published><updated>2007-04-04T17:03:43.455-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='animated cursor'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows'/><category scheme='http://www.blogger.com/atom/ns#' term='Ani exploit'/><title type='text'>New threat - Windows's ANI exploit</title><content type='html'>Cnet security site is reporting Window's animated cursor exploit.&lt;br /&gt;Direct link: &lt;a href="http://reviews.cnet.com/4520-6600_7-6722377-1.html"&gt;http://reviews.cnet.com/4520-6600_7-6722377-1.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you happend to be received some spam emails with free Windows animated cursors attached, then do Not installs them! and run Windows update to obtain security patch from Microsoft.&lt;br /&gt;Microsoft security pacth for animated cursor vulnerabilities Download link: &lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS07-017.mspx"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From Cnet Security Center:-&lt;br /&gt;&lt;br /&gt;Windows animated cursor attackThe way Microsoft Windows handles animated cursors on Web sites puts PCs at risk.By &lt;a href="mailto:robert.vamosi@cnet.com"&gt;Robert Vamosi&lt;/a&gt; (March 30, 2007)(revised 4/2/07)&lt;br /&gt;QUICK FACTS&lt;br /&gt;Name: Windows animated cursor attack Date first reported: 03/29/07 CVE Number: CVE 2007-0038 Vulnerable software: Microsoft Windows 2000, SP1 through Windows Vista. What it does: Causes a denial of service attack (persistent reboot) or could allow remote access. Recommendations: Use an Internet browser other than Microsoft Internet Explorer, such as Firefox or Opera. Exploit code available: Yes Vendor patch available: Expected April 3, 2007.&lt;br /&gt;&lt;br /&gt;8out of 10INTERNET THREAT RATING&lt;a class="vsc_bkarrow v1" href="http://reviews.cnet.com/4520-6600_7-6274572-1.html?tag=sc.hwr"&gt;How we rate&lt;/a&gt; There's a new Microsoft Windows vulnerability being exploited across the Internet on &lt;a href="http://www.websense.com/securitylabs/alerts/alert.php?AlertID=763"&gt;over 100 Web sites&lt;/a&gt;, according to security vendor Websense. The vulnerability is caused by an unspecified error in the way Windows 2000, XP, and Vista handles animated cursors. Animated cursors allow a mouse pointer to appear animated on a Web site. The feature is often designated by the .ani suffix, but attacks for this vulnerability are not constrained by this file type so simply blocking .ani files won't necessarily protect a PC. Users need not do anything but visit a compromised site to become infected. Antivirus vendor F-Secure reports there's also a &lt;a href="http://www.f-secure.com/weblog/archives/archive-042007.html#00001158"&gt;worm associated with this vulnerability.&lt;/a&gt;&lt;br /&gt;Successful exploitation can result in memory corruption when processing cursors, animated cursors, and icons. According to Arbor Networks, the malicious code on compromised Web sites exploiting this flaw appears to be originating from the following sites, which you may want to block:&lt;br /&gt;wsfgfdgrtyhgfd.net&lt;br /&gt;85.255.113.4&lt;br /&gt;uniq-soft.com&lt;br /&gt;fdghewrtewrtyrew.biz&lt;br /&gt;newasp.com.cn&lt;br /&gt;To become infected, users must be using Internet Explorer 6 or 7; there is no need to click, just visiting an infected site is enough for an infection. The flaw does not affect Firefox or Opera Internet Browsers. Microsoft will release a patch on April 3, 2007. Until a patch is released, users should browse the Internet using a non-Internet Explorer browser. There is also a third-party (non-Microsoft) patch available &lt;a href="http://zert.isotf.org/advisories/zert-2007-01.htm"&gt;here&lt;/a&gt; from the Zeroday Emergency Response Team (ZERT), however, this patch is offered "as is" and will need to be manually removed when Microsoft issues the official patch tomorrow.&lt;br /&gt;Additional Resources&lt;br /&gt;Microsoft: &lt;a href="http://www.microsoft.com/technet/security/advisory/935423.mspx"&gt;Advisory 935423&lt;/a&gt;&lt;br /&gt;Zeroday Emergency Response Team (ZERT): &lt;a href="http://zert.isotf.org/advisories/zert-2007-01.htm"&gt;Unofficial patch&lt;/a&gt;&lt;br /&gt;NIST: &lt;a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0038"&gt;CVE-2007-0038&lt;/a&gt;&lt;br /&gt;Arbor Networks: &lt;a href="http://reviews.cnet.com/%20http://asert.arbornetworks.com/2007/03/any-ani-file-could-infect-you/"&gt;Any Ani file could infect you&lt;/a&gt;&lt;br /&gt;Websense: &lt;a href="http://www.websense.com/securitylabs/alerts/alert.php?AlertID=763"&gt;Alert&lt;/a&gt;&lt;br /&gt;F-Secure: &lt;a href="http://www.f-secure.com/weblog/archives/archive-042007.html#00001158"&gt;Blog post&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-6478054404749929180?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/6478054404749929180/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=6478054404749929180' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6478054404749929180'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6478054404749929180'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/04/new-threat-windowss-ani-exploit.html' title='New threat - Windows&apos;s ANI exploit'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3093410655139539479</id><published>2007-03-29T18:39:00.000-07:00</published><updated>2007-03-29T18:48:52.804-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fake IE7'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus.Win32.Grum.a'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><title type='text'>Fake Internet Explorer 7 beta discovered !!!</title><content type='html'>&lt;a href="http://bp0.blogger.com/_DAkCiWAwOQ4/RgxrNZONtUI/AAAAAAAAAB4/ClmlDN2InEE/s1600-h/fakeie_small.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5047527160228459842" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_DAkCiWAwOQ4/RgxrNZONtUI/AAAAAAAAAB4/ClmlDN2InEE/s320/fakeie_small.jpg" border="0" /&gt;&lt;/a&gt; There are report of fake IE7 beta download via spammer.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Please do NOT install or download IE7 beta as Microsoft never sends emails out about their new release softwares.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The spam email looks like the one shown on this blog, it comes with legitimate looking IE7 logo.&lt;br /&gt;&lt;br /&gt;This spam email contains illegal link to download trojan Virus.Win32.Grum.a&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3093410655139539479?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3093410655139539479/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3093410655139539479' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3093410655139539479'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3093410655139539479'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/03/fake-internet-explorer-7-beta.html' title='Fake Internet Explorer 7 beta discovered !!!'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_DAkCiWAwOQ4/RgxrNZONtUI/AAAAAAAAAB4/ClmlDN2InEE/s72-c/fakeie_small.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-6119003519596054871</id><published>2007-03-26T00:18:00.000-07:00</published><updated>2007-03-26T00:25:31.396-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Gozi'/><category scheme='http://www.blogger.com/atom/ns#' term='Russian'/><category scheme='http://www.blogger.com/atom/ns#' term='Secureworks'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojan'/><category scheme='http://www.blogger.com/atom/ns#' term='Advance research'/><title type='text'>Detailed workout of Gozi the Russian Trojan</title><content type='html'>If you guys wants to read through very detailed work on Gozi, please click the below link.&lt;br /&gt;It shows advanced research work done in detailed documental format.&lt;br /&gt;This is sort of work I do as well.&lt;br /&gt;&lt;br /&gt;Link: &lt;a href="http://www.secureworks.com/research/threats/gozi/"&gt;http://www.secureworks.com/research/threats/gozi/&lt;/a&gt;&lt;br /&gt;Info on Gozi: &lt;a href="http://blogs.zdnet.com/security/?p=133"&gt;http://blogs.zdnet.com/security/?p=133&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-6119003519596054871?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/6119003519596054871/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=6119003519596054871' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6119003519596054871'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6119003519596054871'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/03/detailed-workout-of-gozi-russian-trojan.html' title='Detailed workout of Gozi the Russian Trojan'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-166699293574171858</id><published>2007-03-21T23:05:00.000-07:00</published><updated>2007-03-21T23:09:56.309-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='YouTube'/><category scheme='http://www.blogger.com/atom/ns#' term='Targeted Attacks'/><category scheme='http://www.blogger.com/atom/ns#' term='F-Secure'/><title type='text'>F-Secure posted Youtube vid on Targeted Attacks.</title><content type='html'>Watch and learn about Targeted Attacks from F-Secure Youtube video.&lt;br /&gt;Direct link: &lt;a href="http://www.youtube.com/watch?v=nFw9ZHy0V3c"&gt;http://www.youtube.com/watch?v=nFw9ZHy0V3c&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-166699293574171858?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/166699293574171858/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=166699293574171858' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/166699293574171858'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/166699293574171858'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/03/f-secure-posted-youtube-viid-on.html' title='F-Secure posted Youtube vid on Targeted Attacks.'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3920816537294472881</id><published>2007-03-21T23:00:00.000-07:00</published><updated>2007-03-21T23:02:49.340-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Anti-Spyware Coalition'/><category scheme='http://www.blogger.com/atom/ns#' term='reports'/><title type='text'>Anti-Spyware Coalition released reports</title><content type='html'>On March 15th, the &lt;a href="http://www.antispywarecoalition.org/"&gt;Anti-Spyware Coalition&lt;/a&gt; released the finalized versions of two documents. One is titled Best Practices Suggestions and the other is on the topic of Conflicts Resolution.&lt;br /&gt;&lt;br /&gt;Download reports from: &lt;a href="http://www.antispywarecoalition.org/documents/"&gt;http://www.antispywarecoalition.org/documents/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3920816537294472881?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3920816537294472881/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3920816537294472881' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3920816537294472881'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3920816537294472881'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/03/anti-spyware-coalition-released-reports.html' title='Anti-Spyware Coalition released reports'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-1434378652055365579</id><published>2007-03-21T22:57:00.000-07:00</published><updated>2007-03-21T23:10:35.111-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Live Search'/><category scheme='http://www.blogger.com/atom/ns#' term='Italian'/><category scheme='http://www.blogger.com/atom/ns#' term='Gromozon'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><title type='text'>Microsoft's search excels in spreading malware</title><content type='html'>It seems Italian Gromozon is over taking MS live search site.&lt;br /&gt;&lt;span style="font-family:arial;"&gt;More reading from: &lt;/span&gt;&lt;a href="http://www.theregister.co.uk/2007/03/20/windows_live_malware/"&gt;&lt;span style="font-family:arial;"&gt;http://www.theregister.co.uk/2007/03/20/windows_live_malware/&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-1434378652055365579?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/1434378652055365579/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=1434378652055365579' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1434378652055365579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1434378652055365579'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/03/microsofts-search-excels-in-spreading.html' title='Microsoft&apos;s search excels in spreading malware'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-1779711506818603891</id><published>2007-03-15T16:26:00.000-07:00</published><updated>2007-03-15T16:28:02.908-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='GM'/><category scheme='http://www.blogger.com/atom/ns#' term='Bill Gates'/><category scheme='http://www.blogger.com/atom/ns#' term='joke'/><category scheme='http://www.blogger.com/atom/ns#' term='COMDEX'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><title type='text'>Some Microsoft &amp; GM joke</title><content type='html'>&lt;span style="font-family:arial;"&gt;At a recent computer expo (COMDEX), Bill Gates reportedly compared the computer industry with the auto industry and stated, "'If GM had kept up with technology like the computer industry has, we would all be driving $25.00 cars that got 1,000 miles to the gallon.'&lt;br /&gt;&lt;br /&gt;In response to Bill's comments, General Motors issued a press release stating:&lt;br /&gt;&lt;br /&gt;If GM had developed technology like Microsoft, we would all be driving cars with the following&lt;br /&gt;characteristics (and I just love this part):&lt;br /&gt;&lt;br /&gt;1. For no reason whatsoever, your car would crash........ Twice a day.&lt;br /&gt;&lt;br /&gt;2. Every time they repainted the lines in the road, you would have to buy a new car.&lt;br /&gt;&lt;br /&gt;3. Occasionally your car would die on the freeway for no reason. You would have to&lt;br /&gt;pull to the side of the road, close all of the windows, shut off the car, restart it, and&lt;br /&gt;reopen the windows before you could continue. For some reason you would simply&lt;br /&gt;accept this.&lt;br /&gt;&lt;br /&gt;4. Occasionally, executing a maneuver such as a left turn would cause your car to shut&lt;br /&gt;down and refuse to restart, in which case you would have to reinstall the engine.&lt;br /&gt;&lt;br /&gt;5. Macintosh would make a car that was powered by the sun, was reliable, five times&lt;br /&gt;as fast and twice as easy to drive - but would run on only five percent of the roads.&lt;br /&gt;&lt;br /&gt;6. The oil, water temperature, and alternator warning lights would all be replaced by&lt;br /&gt;a single 'This Car Has Performed An Illegal Operation' warning light.&lt;br /&gt;&lt;br /&gt;7. The airbag system would ask 'Are you sure?' before deploying.&lt;br /&gt;&lt;br /&gt;8. Occasionally, for no reason whatsoever, your car would lock you out and refuse to&lt;br /&gt;let you in until you simultaneously lifted the door handle, turned the key and grabbed&lt;br /&gt;hold of the radio antenna.&lt;br /&gt;&lt;br /&gt;9. Every time a new car was introduced car buyers would have to learn how to drive all&lt;br /&gt;over again because none of the controls would operate in the same manner as the old car.&lt;br /&gt;&lt;br /&gt;10. You'd have to press the 'Start' button to turn the engine OFF. &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-1779711506818603891?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/1779711506818603891/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=1779711506818603891' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1779711506818603891'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1779711506818603891'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/03/some-microsoft-gm-joke.html' title='Some Microsoft &amp; GM joke'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-150549983080297660</id><published>2007-03-13T17:57:00.000-07:00</published><updated>2007-03-13T18:01:46.778-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='siteadvisor'/><category scheme='http://www.blogger.com/atom/ns#' term='report'/><category scheme='http://www.blogger.com/atom/ns#' term='McAfee'/><title type='text'>Interesting reading from McAfee's SiteAdvisor</title><content type='html'>Some interesting report cameup from Siteadvisor, check it out&lt;br /&gt;&lt;br /&gt;Direct link: &lt;a title="http://www.siteadvisor.com/studies/map_malweb_mar2007.html" href="http://www.siteadvisor.com/studies/map_malweb_mar2007.html"&gt;http://www.siteadvisor.com/studies/map_malweb_mar2007.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-150549983080297660?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/150549983080297660/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=150549983080297660' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/150549983080297660'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/150549983080297660'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/03/interesting-reading-from-mcafees.html' title='Interesting reading from McAfee&apos;s SiteAdvisor'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-6763781742892427040</id><published>2007-03-11T04:54:00.000-07:00</published><updated>2007-03-11T04:58:13.327-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Winfixer'/><category scheme='http://www.blogger.com/atom/ns#' term='video'/><category scheme='http://www.blogger.com/atom/ns#' term='YouTube'/><title type='text'>Watch Winfixer lawsuit video</title><content type='html'>Feb. 26, 2007 Special Report on a lawsuit involving Beatrice Ochoa, whose computer was infected by the notorious Winfixer&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=zBUZHiKhsog"&gt;http://www.youtube.com/watch?v=zBUZHiKhsog&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-6763781742892427040?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/6763781742892427040/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=6763781742892427040' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6763781742892427040'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6763781742892427040'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/03/watch-winfixer-lawsuit-video.html' title='Watch Winfixer lawsuit video'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3779563010316388298</id><published>2007-03-05T19:13:00.000-08:00</published><updated>2007-03-05T19:18:25.900-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='attachments'/><category scheme='http://www.blogger.com/atom/ns#' term='email worm'/><category scheme='http://www.blogger.com/atom/ns#' term='F-Secure'/><category scheme='http://www.blogger.com/atom/ns#' term='Warezov'/><title type='text'>New threat arlert: Warezov email worm</title><content type='html'>&lt;a href="http://bp0.blogger.com/_DAkCiWAwOQ4/RezdH4xj0BI/AAAAAAAAABs/kI23UY6t_e0/s1600-h/worm_warezov_kb.gif"&gt;&lt;img id="BLOGGER_PHOTO_ID_5038645210689818642" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_DAkCiWAwOQ4/RezdH4xj0BI/AAAAAAAAABs/kI23UY6t_e0/s320/worm_warezov_kb.gif" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;F-Secure blog reported new Warezov email worm with attachment is going around, please be careful, the spam email looks like below:-&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;span style="font-size:85%;"&gt;Do not reply to this message&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;Dear Customer, Our robot has fixed an abnormal activity from your IP address on sending e-mails. Probably it is connected with the last epidemic of a worm which does not have patches at the moment. We recommend you to install a firewall module and it will stop e-mail sending. Otherwise your account will be blocked until you do not eliminate malfunction. Customer support center robot&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;font-size:100%;"&gt;The attachment is a ZIP file which contains a static EXE file. The name varies, but it's always something like Update-KB[random numbers]-x86.exe.&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3779563010316388298?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3779563010316388298/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3779563010316388298' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3779563010316388298'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3779563010316388298'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/03/new-threat-arlert-warezov-email-worm.html' title='New threat arlert: Warezov email worm'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_DAkCiWAwOQ4/RezdH4xj0BI/AAAAAAAAABs/kI23UY6t_e0/s72-c/worm_warezov_kb.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-6802735667059368458</id><published>2007-03-01T01:55:00.000-08:00</published><updated>2007-03-01T02:02:52.095-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Antivirus vendors'/><category scheme='http://www.blogger.com/atom/ns#' term='AV-comparatives.org'/><category scheme='http://www.blogger.com/atom/ns#' term='report'/><title type='text'>AV Comparative February 2007 is out now !</title><content type='html'>&lt;span style="font-family:arial;"&gt;AV-comparatives.org is European based AV software certifier that test many popular &amp; well known Antivirus software against to their extensive malware collection.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Obviously they are using European virus honey pod as result shows favourable to European based AV vendors.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;You can view online result on ths &lt;/span&gt;&lt;a href="http://www.av-comparatives.org/seiten/ergebnisse_2007_02.php"&gt;&lt;span style="font-family:arial;"&gt;link&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt; or download actualy report on PDF file from &lt;/span&gt;&lt;a href="http://www.av-comparatives.org/seiten/ergebnisse/report13.pdf"&gt;&lt;span style="font-family:arial;"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-6802735667059368458?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/6802735667059368458/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=6802735667059368458' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6802735667059368458'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6802735667059368458'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/03/av-comparative-february-2007-is-out-now.html' title='AV Comparative February 2007 is out now !'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-8972020928389461207</id><published>2007-02-27T17:01:00.000-08:00</published><updated>2007-02-27T22:03:04.810-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MS Viewer'/><category scheme='http://www.blogger.com/atom/ns#' term='zlob'/><category scheme='http://www.blogger.com/atom/ns#' term='popups'/><category scheme='http://www.blogger.com/atom/ns#' term='F-Secure'/><category scheme='http://www.blogger.com/atom/ns#' term='popuper'/><category scheme='http://www.blogger.com/atom/ns#' term='myspace.com'/><title type='text'>New threat - Zlob variant or Trojan.popuper spreading via Myspace.com</title><content type='html'>Popups&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp2.blogger.com/_DAkCiWAwOQ4/ReTVYmcuegI/AAAAAAAAABI/6h3IjAbbxAc/s1600-h/fake_msviewer.gif"&gt;&lt;img id="BLOGGER_PHOTO_ID_5036384901921667586" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp2.blogger.com/_DAkCiWAwOQ4/ReTVYmcuegI/AAAAAAAAABI/6h3IjAbbxAc/s320/fake_msviewer.gif" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;a href="http://bp3.blogger.com/_DAkCiWAwOQ4/ReTV22cueiI/AAAAAAAAABY/SGUZvb7I4nc/s1600-h/truth_fakemsviewer.gif"&gt;&lt;img id="BLOGGER_PHOTO_ID_5036385421612710434" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_DAkCiWAwOQ4/ReTV22cueiI/AAAAAAAAABY/SGUZvb7I4nc/s320/truth_fakemsviewer.gif" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;F-secure reported that there is new variant of zlob spreading through Myspace.com forcing visitors to install MS viewer to read adult consent, instead they are actually installing zlob.&lt;/div&gt;&lt;div&gt;Article &lt;a href="http://www.f-secure.com/weblog/archives/archive-022007.html#00001125"&gt;Link&lt;/a&gt; here.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-8972020928389461207?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/8972020928389461207/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=8972020928389461207' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8972020928389461207'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8972020928389461207'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/02/new-threat-zlob-variant-or.html' title='New threat - Zlob variant or Trojan.popuper spreading via Myspace.com'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_DAkCiWAwOQ4/ReTVYmcuegI/AAAAAAAAABI/6h3IjAbbxAc/s72-c/fake_msviewer.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-6151642601130557467</id><published>2007-02-22T03:02:00.000-08:00</published><updated>2007-02-22T03:06:32.513-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Crimeware'/><category scheme='http://www.blogger.com/atom/ns#' term='John Howard'/><category scheme='http://www.blogger.com/atom/ns#' term='Google Maps'/><category scheme='http://www.blogger.com/atom/ns#' term='Australia'/><title type='text'>New threat ! -  Malicious Website / Malicious Code: Trojan Crimeware using Google Maps</title><content type='html'>A fake breaking news report claiming that Australia's Prime Minister Mr. John Howard had a heart attack is being circulated by spammers in an attempt to hijack Australians' computers.&lt;br /&gt;&lt;br /&gt;Article:- &lt;a href="http://www.websense.com/securitylabs/alerts/alert.php?AlertID=741"&gt;Link here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-6151642601130557467?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/6151642601130557467/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=6151642601130557467' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6151642601130557467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6151642601130557467'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/02/new-threat-malicious-website-malicious.html' title='New threat ! -  Malicious Website / Malicious Code: Trojan Crimeware using Google Maps'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-8101151470503051944</id><published>2007-02-22T02:56:00.000-08:00</published><updated>2007-02-22T03:01:31.312-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VeriSign'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyberattack'/><category scheme='http://www.blogger.com/atom/ns#' term='Project Titan'/><title type='text'>Cyberattacks Up 50% By 2010, VeriSign Says</title><content type='html'>&lt;span style="font-size:85%;"&gt;VeriSign's unveiling Thursday of &lt;/span&gt;&lt;a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=197004598" target="_blank"&gt;&lt;span style="font-size:85%;"&gt;Project Titan&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;, which seeks to expand the capacity of its global Internet &lt;/span&gt;&lt;a href="http://www.techweb.com/encyclopedia/defineterm.jhtml?term=infrastructure%26x=%26y=" target="_blank"&gt;&lt;span style="font-size:85%;"&gt;infrastructure&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; by 10 times by 2010, will be both a blessing and a bane to Internet users, creating a wider freeway for access to revolutionary new &lt;/span&gt;&lt;a href="http://www.techweb.com/encyclopedia/defineterm.jhtml?term=multimedia%26x=%26y=" target="_blank"&gt;&lt;span style="font-size:85%;"&gt;multimedia&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; content while at the same time creating a greater number of targets for malicious attackers.&lt;br /&gt;Cyberattacks will increase by 50% between now and Project Titan's completion, VeriSign CEO and chairman Stratton Sclavos said Thursday during his RSA Conference keynote. As long as cybercrime continues to grow as an industry, don't count on malicious attacks to abate on their own. "Where the money goes, so do the threats," he added.&lt;br /&gt;While it's easy, not to mention good business, for security vendors to predict gloom and doom for the IT industry, Sclavos' point was punctuated by &lt;/span&gt;&lt;a href="http://www.informationweek.com/showArticle.jhtml?articleID=197004237" target="_blank"&gt;&lt;span style="font-size:85%;"&gt;Tuesday's massive denial-of-service attack&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; against the 13 servers that help manage worldwide Internet traffic. This was a sophisticated attack consisting of "very, very large packets," Sclavos said. "Every request [made by those packets] was bogus, and every [packet] source was false."&lt;br /&gt;Even worse, it was a sophisticated attack that "was very simple to deploy and scales phenomenally well," Sclavos said. "In fact, we're convinced that the perpetrators didn't even know how well it scales."&lt;br /&gt;But the VeriSign CEO pointed the finger at himself and his colleagues in the security space, rather than dwelling on the attackers.&lt;br /&gt;"Shame on all of us in this room who are security vendors," he said. "If we force our customers to choose between ease of use and better security, they will always choose simplicity. We have the security technology and have had it for years. Yet our consumers feel more vulnerable today than they've ever felt."&lt;br /&gt;Still, it's not impossible for organizations to beat back the bad guys. Sclavos pointed to &lt;/span&gt;&lt;a href="http://www.informationweek.com/showArticle.jhtml?articleID=196902261" target="_blank"&gt;&lt;span style="font-size:85%;"&gt;PayPal, one of the companies most targeted by attackers&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;, as a company that has had some security success because it's taken the threats seriously.&lt;br /&gt;"They are using (&lt;/span&gt;&lt;a href="http://www.informationweek.com/showArticle.jhtml?articleID=197003807" target="_blank"&gt;&lt;span style="font-size:85%;"&gt;Extended Validation SSL Certificates&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;) to be sure users don't make a &lt;/span&gt;&lt;a href="http://www.techweb.com/encyclopedia/defineterm.jhtml?term=phishing%26x=%26y=" target="_blank"&gt;&lt;span style="font-size:85%;"&gt;phishing&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; site for PayPal's site," he added.&lt;br /&gt;Microsoft announced that it has enabled support for these certificates in Internet Explorer 7. When a user visits a site with a valid EV SSL Certificate, IE 7 alerts the user to the available identity information by turning the background of the address bar green and displaying identity information. Twelve certificate authorities, including VeriSign, &lt;/span&gt;&lt;a href="http://www.informationweek.com/showArticle.jhtml?articleID=172901005" target="_blank"&gt;&lt;span style="font-size:85%;"&gt;Cybertrust&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;, and &lt;/span&gt;&lt;a href="http://www.informationweek.com/showArticle.jhtml?articleID=173600519" target="_blank"&gt;&lt;span style="font-size:85%;"&gt;Entrust&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;, issue EV &lt;/span&gt;&lt;a href="http://www.techweb.com/encyclopedia/defineterm.jhtml?term=SSL%26x=%26y=" target="_blank"&gt;&lt;span style="font-size:85%;"&gt;SSL&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; Certificates.&lt;br /&gt;Certificate authorities won't issue EV SSL Certificates without first making the organization go through a stringent sign-up process, says Michael Barrett, PayPal's chief &lt;/span&gt;&lt;a href="http://www.techweb.com/encyclopedia/defineterm.jhtml?term=information%20security%26x=%26y=" target="_blank"&gt;&lt;span style="font-size:85%;"&gt;information security&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; officer. In addition, PayPal next week will begin offering certain clients, businesses, and possibly those who've been the victim of past fraud pass code-generating tokens for securely logging on to their PayPal accounts.&lt;br /&gt;Barrett admits there's no easy way to keep bogus e-mailers (known as phishers) and other bad elements at bay, but that's no excuse for not trying, even if it means forcing cybercriminals to change their tactics. "There's no silver bullet," he says. "It's how much lead can you get in the air from a shotgun." &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-8101151470503051944?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/8101151470503051944/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=8101151470503051944' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8101151470503051944'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8101151470503051944'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/02/cyberattacks-up-50-by-2010-verisign.html' title='Cyberattacks Up 50% By 2010, VeriSign Says'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-7854929882270134956</id><published>2007-02-07T22:09:00.000-08:00</published><updated>2007-03-07T21:39:57.041-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Sandbox'/><category scheme='http://www.blogger.com/atom/ns#' term='PC Tools'/><category scheme='http://www.blogger.com/atom/ns#' term='jotti virusscan'/><category scheme='http://www.blogger.com/atom/ns#' term='virustotal'/><category scheme='http://www.blogger.com/atom/ns#' term='Norman'/><category scheme='http://www.blogger.com/atom/ns#' term='Automatic threat analyzer'/><category scheme='http://www.blogger.com/atom/ns#' term='Sunbelt'/><category scheme='http://www.blogger.com/atom/ns#' term='Threat Expert'/><category scheme='http://www.blogger.com/atom/ns#' term='online scanners'/><title type='text'>PC Tools Cracks Hacker Code in Seconds With New Secret Weapon -- Threat Expert(TM)</title><content type='html'>&lt;span style="font-size:85%;"&gt;PC Tools claimed that they have new &amp; better automatic malware analyzer.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;This Threat Expert is similar to Norman's Sandbox &amp;amp; Sunbelt's CWSandbox.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;By looking at their sample report I guess PC Tool's TM is better than Norman's Sandbox. I haven't tried Sunbelt's CWSandbox yet, but I guess they are also similar.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;The PC Tool's TM report is a lot easy to follow but their tool is not free for everyone. You will need to talk to their marketing department in order to gain access to their utility that allows users to submit their sample file(s) [malware] to be analyze, which in return receives full detailed report about submitted file.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Which is great if you need to check the file to see if file is malicious or not.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Article Link: &lt;/span&gt;&lt;a title="http://www.tmcnet.com/usubmit/2007/02/01/2303824.htm" href="http://www.tmcnet.com/usubmit/2007/02/01/2303824.htm"&gt;&lt;span style="font-size:85%;"&gt;http://www.tmcnet.com/usubmit/2007/02/01/2303824.htm&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;PC Tool's TM Link: &lt;/span&gt;&lt;a title="http://www.pctools.com/threat-expert/" href="http://www.pctools.com/threat-expert/"&gt;&lt;span style="font-size:85%;"&gt;http://www.pctools.com/threat-expert/&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Submit sample file: &lt;a href="http://www.pctools.com/threat-expert/submit/"&gt;http://www.pctools.com/threat-expert/submit/&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Other competitors sanbox links:-&lt;/span&gt;&lt;br /&gt;&lt;a href="http://sandbox.norman.no/"&gt;&lt;span style="font-size:78%;"&gt;http://sandbox.norman.no/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://research.sunbelt-software.com/Submit.aspx"&gt;&lt;span style="font-size:78%;"&gt;http://research.sunbelt-software.com/Submit.aspx&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; (more info: &lt;/span&gt;&lt;a href="http://www.cwsandbox.org/"&gt;&lt;span style="font-size:78%;"&gt;http://www.cwsandbox.org/&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Free public Online scanners:- (No analyzer but just command line scanners)&lt;/span&gt;&lt;br /&gt;&lt;a href="http://virusscan.jotti.org/"&gt;&lt;span style="font-size:78%;"&gt;http://virusscan.jotti.org/&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/"&gt;&lt;span style="font-size:78%;"&gt;http://www.virustotal.com/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-7854929882270134956?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/7854929882270134956/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=7854929882270134956' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7854929882270134956'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7854929882270134956'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/02/pc-tools-cracks-hacker-code-in-seconds.html' title='PC Tools Cracks Hacker Code in Seconds With New Secret Weapon -- Threat Expert(TM)'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-6103199278427939515</id><published>2007-02-06T22:00:00.000-08:00</published><updated>2007-02-06T22:13:44.152-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RSA Conference'/><category scheme='http://www.blogger.com/atom/ns#' term='cryptographers'/><category scheme='http://www.blogger.com/atom/ns#' term='Leon Battista Alberti'/><title type='text'>The 16th annual RSA Conference is being held this week at the Moscone Center in San Francisco</title><content type='html'>&lt;a href="http://bp0.blogger.com/_DAkCiWAwOQ4/RclsFqNH1AI/AAAAAAAAAA8/xTXj6WOJ2pE/s1600-h/bg-banner.gif"&gt;&lt;img id="BLOGGER_PHOTO_ID_5028669303420343298" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_DAkCiWAwOQ4/RclsFqNH1AI/AAAAAAAAAA8/xTXj6WOJ2pE/s320/bg-banner.gif" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I won't able to make it to this event, some day I will.&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Here is direct link to RSA Conference:&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.rsaconference.com/2007/US/"&gt;&lt;span style="font-size:85%;"&gt;http://www.rsaconference.com/2007/US/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Conference theme:&lt;/span&gt; &lt;span style="font-family:courier new;font-size:85%;color:#660000;"&gt;&lt;strong&gt;"It is said that man can what he will. If you apply yourself with all your strengths and arts you will reach the foremost and supreme degree of perfection and fame in any effort."– Leon Battista Alberti&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;span style="color:#000000;"&gt;About him:&lt;/span&gt; &lt;a href="http://en.wikipedia.org/wiki/Leon_Battista_Alberti"&gt;&lt;span style="font-family:times new roman;"&gt;http://en.wikipedia.org/wiki/Leon_Battista_Alberti&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;The first keynote of the day was delivered by Microsoft's Bill Gates and Craig Mundie, who naturally drew a big crowd. Throughout the day you could see lots of familiar names on stage, including crypto-legends Whitfield Diffie, Ron Rivest, Adi Shamir and Martin Hellman in the Cryptographers Panel.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-6103199278427939515?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/6103199278427939515/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=6103199278427939515' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6103199278427939515'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6103199278427939515'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/02/16th-annual-rsa-conference-is-being.html' title='The 16th annual RSA Conference is being held this week at the Moscone Center in San Francisco'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_DAkCiWAwOQ4/RclsFqNH1AI/AAAAAAAAAA8/xTXj6WOJ2pE/s72-c/bg-banner.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-1864016875580261070</id><published>2007-02-05T22:22:00.000-08:00</published><updated>2007-02-05T22:26:13.153-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Swedish'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='Haxdoor'/><title type='text'>Meeting the Swedish bank hacker - The author of Haxdoor</title><content type='html'>Another great article on interview with Haxdoor author.&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Direct link: &lt;/span&gt;&lt;a href="http://computersweden.idg.se/2.139/1.93344"&gt;&lt;span style="font-size:85%;"&gt;http://computersweden.idg.se/2.139/1.93344&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For malware analyst like me, it's like having interview with vampire (me as vampire slayer).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-1864016875580261070?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/1864016875580261070/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=1864016875580261070' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1864016875580261070'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/1864016875580261070'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/02/meeting-swedish-bank-hacker-author-of.html' title='Meeting the Swedish bank hacker - The author of Haxdoor'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-2051820207735689393</id><published>2007-02-05T22:19:00.000-08:00</published><updated>2007-02-05T22:21:49.071-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='attack'/><category scheme='http://www.blogger.com/atom/ns#' term='Symantec'/><category scheme='http://www.blogger.com/atom/ns#' term='Virtual machine'/><title type='text'>Attack on Virtual machine</title><content type='html'>Here is good reading material for people interest in Virtual machine and malware.&lt;br /&gt;It's pdf file, so you will need Adobe reader or free PDF reader.&lt;br /&gt;&lt;br /&gt;Link: &lt;a title="http://www.symantec.com/avcenter/reference/Virtual_Machine_Threats.pdf" href="http://www.symantec.com/avcenter/reference/Virtual_Machine_Threats.pdf"&gt;http://www.symantec.com/avcenter/reference/Virtual_Machine_Threats.pdf&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-2051820207735689393?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/2051820207735689393/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=2051820207735689393' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/2051820207735689393'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/2051820207735689393'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/02/attack-on-virtual-machine.html' title='Attack on Virtual machine'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-8952531071068957090</id><published>2007-02-04T22:17:00.000-08:00</published><updated>2007-02-04T22:22:41.672-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Bill Gates'/><category scheme='http://www.blogger.com/atom/ns#' term='Steve Jobs'/><category scheme='http://www.blogger.com/atom/ns#' term='marketing'/><category scheme='http://www.blogger.com/atom/ns#' term='Apple'/><category scheme='http://www.blogger.com/atom/ns#' term='advertisement'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><title type='text'>Funny Mr. Bill Gate's saying about Steve Job's new marketing campaign</title><content type='html'>&lt;span style="font-size:85%;"&gt;Ha ha, I personally never met Bill &amp; Steve, but I think they are bunch of hypocrites, just want to make $$$ by selling second/third grade products. &lt;/span&gt;&lt;span style="font-size:85%;"&gt;They never improve their previous product, just keep on selling NEW PRODUCT !&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;They don't really care about people or this planet earth. They use cheap advertising campaign to fool us.&lt;br /&gt;&lt;br /&gt;The fact is over 90% of desktop computers &amp;amp; notebooks come with pre-loaded MS Windows and god know's how many mobile phones will come with standard Windows OS. :(&lt;br /&gt;&lt;br /&gt;In other hand, Mac OS probadly only covers less than 2% of world computers, and rest are covered by other non MS or Mac OS such as Linux.&lt;br /&gt;&lt;br /&gt;Apple's Mac targets consumer &amp; specialists, MS's Windows targets commercial &amp;amp; dumb pc users and both targets entertainment market, but truth is their products are not so good or nor specialize compare it to other companies anyway. :)&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;Product Quality &amp; features &amp;amp; prices &amp; marketshare:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;----------------------------&lt;br /&gt;Apple's ipod vs iRiver's player (&amp;amp; other 3rd party players)-&gt;(3rd party players beats Apple)&lt;br /&gt;MS's Xbox vs Sony's PS2/3 -&gt;(PS3 beats xbox)&lt;br /&gt;Ms's Windows vs Apple's iMac -&gt; (Windows beats iMac)&lt;br /&gt;MS's Zune player VS ipod -&gt; (ipod beats Zune)&lt;br /&gt;Sony's PSP vs Nintendo portable -&gt; (nintendo beats Sony)&lt;br /&gt;Nokia vs Blackberry -&gt; (Nokia beats Blackberry)&lt;br /&gt;Toyota VS Ford -&gt; (Toyota beats Ford)&lt;br /&gt;so on on on .. blah blah blah...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Link: &lt;/span&gt;&lt;a href="http://blogs.siliconvalley.com/gmsv/2007/02/quoted_1.html"&gt;&lt;span style="font-size:85%;"&gt;http://blogs.siliconvalley.com/gmsv/2007/02/quoted_1.html&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-8952531071068957090?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/8952531071068957090/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=8952531071068957090' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8952531071068957090'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/8952531071068957090'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/02/funny-mr-bill-gates-saying-about-steve.html' title='Funny Mr. Bill Gate&apos;s saying about Steve Job&apos;s new marketing campaign'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-2000858464390780963</id><published>2007-02-04T22:12:00.000-08:00</published><updated>2007-02-04T22:16:57.463-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tools'/><category scheme='http://www.blogger.com/atom/ns#' term='grandstreamdream'/><category scheme='http://www.blogger.com/atom/ns#' term='Claus Valca'/><category scheme='http://www.blogger.com/atom/ns#' term='security scanners'/><title type='text'>Found one coolest blog - very useful info &amp; links for useful tools you can keep</title><content type='html'>&lt;a href="http://grandstreamdreams.blogspot.com/" target="_blank"&gt;Claus Valca&lt;/a&gt; posted a comprehensive list of online security scanners.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Link: &lt;/span&gt;&lt;a href="http://grandstreamdreams.blogspot.com/2007/02/online-system-security-scanners.html"&gt;&lt;span style="font-size:85%;"&gt;http://grandstreamdreams.blogspot.com/2007/02/online-system-security-scanners.html&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;From his blog:-&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;Primarily virus/trojan related online scanners&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.commandondemand.com/"&gt;&lt;span style="font-size:78%;"&gt;Authentium - ThreatMatrix - &lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;(ActiveX required) - Free system virus scan&lt;br /&gt;&lt;/span&gt;&lt;a href="http://arcaonline.arcabit.com/scanner.html"&gt;&lt;span style="font-size:78%;"&gt;Arcabit Online Scanner&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - Free system virus scan&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.bitdefender.com/scan8/ie.html"&gt;&lt;span style="font-size:78%;"&gt;BitDefender Free Online Virus Scan &lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;- (ActiveX required) - Free system virus scan of memory, files, folders, and drives' boot sectors with cleansing option.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www3.ca.com/securityadvisor/virusinfo/scan.aspx"&gt;&lt;span style="font-size:78%;"&gt;Computer Associates eTrust Antivirus Web Scanner&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - provides virus scanning, curing and deletion support.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.freedrweb.com/cureit/"&gt;&lt;span style="font-size:78%;"&gt;Dr.WEB Anti-Virus&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - upload a file to scan for malicious software (look on page's sidebar)&lt;br /&gt;&lt;/span&gt;&lt;a href="http://support.f-secure.com/enu/home/ols.shtml"&gt;&lt;span style="font-size:78%;"&gt;F-secure Online Virus Scanner&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - Free system virus scan&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.freedom.net/viruscenter/onlineviruscheck.html"&gt;&lt;span style="font-size:78%;"&gt;Freedom Online Scanner&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - Free system anti-virus scanner. I cannot tell if it will also remove identified files.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www3.ca.com/securityadvisor/virusinfo/scan.aspx"&gt;&lt;span style="font-size:78%;"&gt;eTrust Antivirus Scanner (requires MS Internet Explorer)&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://housecall65.trendmicro.com/"&gt;&lt;span style="font-size:78%;"&gt;HouseCall (Trend Micro) Online Scanner&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (Java or ActiveX) - Checks for viruses, spyware or other malware/grayware. Also performs additional security checks and assists with detected item removal. (Windows, Linux, Solaris systems supported.)&lt;br /&gt;&lt;/span&gt;&lt;a href="http://usa.kaspersky.com/services/free-virus-scanner.php"&gt;&lt;span style="font-size:78%;"&gt;Kaspersky On-line Scanner&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - Does not remove threats, only alerts user to the presence of a malicious file.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://us.mcafee.com/root/mfs/default.asp?cid=9059"&gt;&lt;span style="font-size:78%;"&gt;McAfee Free Scan&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - Free system virus scan&lt;br /&gt;&lt;/span&gt;&lt;a href="http://safety.live.com/site/en-US/center/howsafe.htm?s_cid=mscom_msrt"&gt;&lt;span style="font-size:78%;"&gt;Microsoft: Windows Live OneCare Free Online Scanner&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - scans for and removes viruses, spyware and other potentially unwanted software and vulnerabilities.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.pandasoftware.com/products/activescan?"&gt;&lt;span style="font-size:78%;"&gt;Panda Active Scan Online Scanner&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - Scans for viruses, trojans, spyware, malware and provides support for removal of virus, worms and Trojans.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.pandasoftware.com/products/spyxposer/com/spyxposer_principal.htm"&gt;&lt;span style="font-size:78%;"&gt;Panda SpyXposer&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - Scans for malware presence. Does not offer removal support.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://security.symantec.com/sscv6/home.asp?langid=ie&amp;venid=sym&amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;plfid=23&amp;pkj=ZSZIZOGIJPUVGCWETOM"&gt;&lt;span style="font-size:78%;"&gt;Symantec Security Check: Virus Detection&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - "Virus Detection checks for known threats, including top threats identified by Symantec Security Response. Virus Detection provides an analysis of your results and offers suggestions for further action. It does not examine compressed files." -- from Symantec's service description.&lt;br /&gt;Single-File Upload Scanners&lt;br /&gt;&lt;/span&gt;&lt;a href="http://onlinescan.avast.com/"&gt;&lt;span style="font-size:78%;"&gt;avast! OnLine scanner&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - upload a single file to check.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://luigi.informatik.uni-mannheim.de/new/home.php?id=submission"&gt;&lt;span style="font-size:78%;"&gt;CWSandbox&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - Laboratory for Dependable Distributed Systems University of Mannheim, upload a single file to check file behavior in a "sandboxed" system. Very cool behavior reporting. &lt;/span&gt;&lt;a href="http://luigi.informatik.uni-mannheim.de/new/home.php?id=home"&gt;&lt;span style="font-size:78%;"&gt;More information at the CWSandbox.org site.&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; (added to list 02/07/2006)&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.fortinet.com/FortiGuardCenter/antivirus/virus_scanner.html"&gt;&lt;span style="font-size:78%;"&gt;FORTINET - Online virus center&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - submit a single file for review.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.f-prot.com/virusinfo/submission_form.html"&gt;&lt;span style="font-size:78%;"&gt;FRISK (f-prot) Software virus lab&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - submit a single file for review.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.ikarus-software.at/portal/modules.php?name=Content&amp;amp;pa=showpage&amp;pid=28"&gt;&lt;span style="font-size:78%;"&gt;IKARUS Software Vienna&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - Upload sample file for analysis and response is via email.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://usa.kaspersky.com/services/free-virus-scanner.php"&gt;&lt;span style="font-size:78%;"&gt;Kaspersky File Scanner&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - upload a single file to check.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://sandbox.norman.no/live_4.html"&gt;&lt;span style="font-size:78%;"&gt;Norman SandBox Information Center - SandBox Live&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - Upload sample file for analysis and response is via email.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.sophos.com/support/samples/"&gt;&lt;span style="font-size:78%;"&gt;Sophos - Sample submission form &lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;- Upload sample file for analysis and response is via email.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.sunbelt-software.com/Sunbelt-CWSandbox.cfm"&gt;&lt;span style="font-size:78%;"&gt;Sunbelt CWSandbox&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - Sunbelt Software's free automated malware analysis. Upload a single file to check file behavior in a "sandboxed" system. From website description, "CWSandbox not only analyzes the given malware, but also all other processes that are started or infected by the malware." Note: at time of posting, reporting "service not available." (added to list 02/07/2006)&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.virusbuster.hu/en/support/contact/redirect_virus"&gt;&lt;span style="font-size:78%;"&gt;Virusbuster&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - submit file to VirusBuster labs for review and feedback.&lt;br /&gt;Malware (spyware/adware/etc.) Online Scanners&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.emsisoft.com/en/software/ax/"&gt;&lt;span style="font-size:78%;"&gt;a-squared Web Malware Scanner&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - Free system scans for trojans, backdoors, worms, dialers, keyloggers, rootkits, hack-tools, riskware, tracking cookies.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.pestpatrol.com/pestscan/index.htm"&gt;&lt;span style="font-size:78%;"&gt;eTrust (Computer Associates) PestScan&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - Free system malware scan and removal tool.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.ewido.net/en/onlinescan/"&gt;&lt;span style="font-size:78%;"&gt;ewdio (Grisoft) Anti-Spyware Scanner&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - Free system malware scan and removal tool.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.tenebril.com/scanner/main_start.php"&gt;&lt;span style="font-size:78%;"&gt;Tenebril - Free Spyware Scan&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - Free system spyware scan&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.xblock.com/onlinescan.php"&gt;&lt;span style="font-size:78%;"&gt;X-Cleaner Micro Edition&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - FaceTime Security Labs malware scanner.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.zonelabs.com/store/content/promotions/spywarescanner/scanner.jsp"&gt;&lt;span style="font-size:78%;"&gt;ZoneAlarm Security Scanner (Check Point)&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - ZoneAlarm Labs malware scanner--will not remove any malicious files by itself.&lt;br /&gt;Online "single-file" Multi-Scan Test Websites&lt;br /&gt;&lt;/span&gt;&lt;a href="http://virusscan.jotti.org/"&gt;&lt;span style="font-size:78%;"&gt;Jotti's Malware Scan -&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; Utilizing 15 different scan engines: AntiVir, ArcaVir, Avast, AVG Antivirus, BitDefender, ClamAV, Dr.Web, F-Prot Antivirus, F-Secure Anti-Virus, Fortinet, Kaspersky Anti-Virus, NOD32, Norman Virus Control, VirusBuster, VBA32.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.virustotal.com/en/indexf.html"&gt;&lt;span style="font-size:78%;"&gt;Virus Total Scan - &lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;Utilizing 28 different scan engines: Aladdin (eSafe), ALWIL (Avast! Antivirus), Authentium (Command Antivirus), Avira (AntiVir), Cat Computer Services (Quick Heal), ClamAV (ClamWin), Computer Associates (Iris, Vet), Doctor Web, Ltd. (DrWeb), Eset Software (NOD32), ewido networks (ewido anti-malware), Fortinet (Fortinet), FRISK Software (F-Prot), Grisoft (AVG), Hacksoft (The Hacker), Ikarus Software (Ikarus), Kaspersky Lab (AVP), McAfee (VirusScan), Microsoft (Malware Protection), Norman (Norman Antivirus), Panda Software (Panda Platinum), Prevx (Prevx1), Softwin (BitDefender), Sophos (SAV), Sunbelt Software (Antivirus), Symantec (Norton Antivirus), UNA Corp (UNA), VirusBlokAda (VBA32), VirusBuster (VirusBuster)&lt;br /&gt;Software or System Security Vulnerability Scanners&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.freedrweb.com/browser/"&gt;&lt;span style="font-size:78%;"&gt;Dr. Web Link checkers service&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - plugin for Opera/Firefox/Internet Explorer. Scans file or web-page prior to opening to verify it is not malicious.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://us.mcafee.com/root/wsc/default.asp"&gt;&lt;span style="font-size:78%;"&gt;McAfee WiFiScan&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - "McAfee Wi-FiScan surveys your current Wi-Fi® connection, your wireless equipment, and local environment to assess security risks introduced by your wireless network." - from McAfee's service description.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://secunia.com/software_inspector/"&gt;&lt;span style="font-size:78%;"&gt;Secunia's Software Inspector&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - "Detects insecure versions of applications installed, verifies that all Microsoft patches are applied, assists you in updating your system and applications, runs through your browser. No installation or download is required." - from Secunia's service description.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://security.symantec.com/sscv6/home.asp?langid=ie&amp;amp;venid=sym&amp;amp;amp;amp;amp;amp;amp;amp;amp;plfid=23&amp;pkj=ZSZIZOGIJPUVGCWETOM"&gt;&lt;span style="font-size:78%;"&gt;Symantec Security Check: Security Scan&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - (ActiveX required) - "Hacker Exposure Check - Checks whether your computer allows unknown or unauthorized Internet communications; Windows Vulnerability Check - Checks whether basic information about your computer, including your PC's network identity, is exposed to hackers; Trojan Horse Check - Checks whether your computer is safe from Trojan horses; Antivirus Product Check - Checks whether you're protected by a commonly-used virus protection product; Virus Protection Update Check - Checks whether you're safe from the latest viruses. Applicable if you have a virus protection product." -- from Symantec's service description.&lt;br /&gt;Not Quite "Fully-Online" Based Software or System Security Vulnerability Scanners&lt;br /&gt;A few of the products/services noted on other lists are included in their online scanner lists, but actually require download and execution of a exe (executable) based file on the local pc or download and running of exe (executable) based file from memory. While technically these might be considered "on-line" scanners, they are not so in the manner of the ones listed above.&lt;br /&gt;I have chosen to include some of these products in this post, as they may be otherwise beneficial for interested parties to explore further;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.aluriasoftware.com/index.php?menu=homeproducts&amp;amp;submenu=tools"&gt;&lt;span style="font-size:78%;"&gt;Aluria Software (EarthLink) Spyware Scanner&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - scans and identifies malware on the local pc.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://pestpatrol.com/prescan.htm"&gt;&lt;span style="font-size:78%;"&gt;Computer Associates's Resource Center: (eTrust Pest Patrol, Optimization Scan, Privacy Scan)&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - download the appropriate tool and execute.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.microsoft.com/security/malwareremove/default.mspx"&gt;&lt;span style="font-size:78%;"&gt;Microsoft: Malicious Software Removal Tool (for Windows XP and 2K)&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - targets only specific threats, included in Microsoft Critical Updates, so you may already have the file (MRT.exe) on your system: It is usually located in the C:\Windows\System32\ folder on XP systems or in the C:\WINNT\System32\ folder on Windows 2000 systems.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.webroot.com/services/entaudit/index.php"&gt;&lt;span style="font-size:78%;"&gt;Webroot Enterprise Spy Audit&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - Generate a unique code, download the audit tool executable, find results.&lt;br /&gt;Primary Sources:&lt;br /&gt;I did quite a bit of work hunting these tools down, and then checking the links to get more information about the conditions they ran under and what category they would best be placed under. However, these links were the most helpful in providing me the services noted.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.cleancomputerhelp.com/online-scanners#winp"&gt;&lt;span style="font-size:78%;"&gt;Computer Cleanup : Free Online Scanners&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://mikealao.blogspot.com/2006/11/free-online-virus-and-spyware-scanners.html"&gt;&lt;span style="font-size:78%;"&gt;MikeAlao's Blog: Free Online Virus and Spyware Scanners (including updated links)&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.nist.org/news.php?extend.93"&gt;&lt;span style="font-size:78%;"&gt;NIST IT Security: Free Online Antivirus, Spyware, and Firewall Scanners Review&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.virustotal.com/en/virustotalf.html"&gt;&lt;span style="font-size:78%;"&gt;VIRUSTOTAL &lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;- Hispasec Sistemas's list of participating companies&lt;br /&gt;&lt;/span&gt;&lt;a href="http://virusscan.jotti.org/"&gt;&lt;span style="font-size:78%;"&gt;jotti&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; - list of participating companies&lt;br /&gt;Just another class of security tools to keep you safe!&lt;br /&gt;--Claus&lt;br /&gt;Post updated on 02/07/2007 where noted. Big Thanks to &lt;/span&gt;&lt;a href="http://www.computerdefense.org/"&gt;&lt;span style="font-size:78%;"&gt;Computer Defense blog&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; for pointing out the additional scanner links!&lt;br /&gt;Posted by Claus at &lt;/span&gt;&lt;a class="timestamp-link" title="permanent link" href="http://grandstreamdreams.blogspot.com/2007/02/online-system-security-scanners.html"&gt;&lt;span style="font-size:78%;"&gt;Sunday, February 04, 2007&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-2000858464390780963?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/2000858464390780963/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=2000858464390780963' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/2000858464390780963'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/2000858464390780963'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/02/found-one-coolest-blog-very-useful-info.html' title='Found one coolest blog - very useful info &amp; links for useful tools you can keep'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-994685402379786200</id><published>2007-01-29T16:22:00.000-08:00</published><updated>2007-01-29T16:25:28.044-08:00</updated><title type='text'>Fox news on Julie Amero scandal story</title><content type='html'>Fox news link &lt;a href="http://www.foxnews.com/video2/launchPage.html?012807/012807_wl_kendall&amp;Kelly%27s%20Court&amp;amp;Weekend_Live&amp;Teacher%20faces%20prison%20for%20porn%2C%20but%20was%20it%20just%20pop-ups%3F&amp;amp;Law%20Center&amp;-1&amp;amp;Kelly%27s%20Court&amp;Video%20Launch%20Page&amp;amp;News"&gt;here &lt;img id="BLOGGER_PHOTO_ID_5025612559146372578" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_DAkCiWAwOQ4/Rb6P_uapTeI/AAAAAAAAAAw/yq2P3OFpToQ/s320/foxnews991283182388_small1.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://www.foxnews.com/video2/launchPage.html?012807/012807_wl_kendall&amp;Kelly%27s%20Court&amp;amp;Weekend_Live&amp;Teacher%20faces%20prison%20for%20porn%2C%20but%20was%20it%20just%20pop-ups%3F&amp;amp;Law%20Center&amp;-1&amp;amp;Kelly%27s%20Court&amp;Video%20Launch%20Page&amp;amp;News"&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-994685402379786200?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/994685402379786200/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=994685402379786200' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/994685402379786200'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/994685402379786200'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/01/fox-news-on-julie-amero-scandal-story.html' title='Fox news on Julie Amero scandal story'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_DAkCiWAwOQ4/Rb6P_uapTeI/AAAAAAAAAAw/yq2P3OFpToQ/s72-c/foxnews991283182388_small1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-284437117135557186</id><published>2007-01-21T18:18:00.000-08:00</published><updated>2007-01-21T18:24:16.140-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rootkit'/><category scheme='http://www.blogger.com/atom/ns#' term='Sysinternals'/><category scheme='http://www.blogger.com/atom/ns#' term='Unreal Rootkit'/><category scheme='http://www.blogger.com/atom/ns#' term='forum'/><category scheme='http://www.blogger.com/atom/ns#' term='Rootkit Technology'/><title type='text'>New technology of rootkits: Unreal</title><content type='html'>&lt;span style="font-size:85%;"&gt;There is report of new Rootkit technology that can bypass all known Anti-Rootkit. This rootkit can be downloaded for testing.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Check out the forum site from Sysinternal:&lt;br /&gt;&lt;/span&gt;&lt;a href="http://forum.sysinternals.com/forum_posts.asp?TID=9630&amp;PN=1&amp;amp;TPN=1"&gt;&lt;span style="font-size:85%;"&gt;http://forum.sysinternals.com/forum_posts.asp?TID=9630&amp;PN=1&amp;amp;TPN=1&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-284437117135557186?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/284437117135557186/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=284437117135557186' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/284437117135557186'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/284437117135557186'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/01/new-technology-of-rootkits-unreal.html' title='New technology of rootkits: Unreal'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-4952191180592931866</id><published>2007-01-18T16:59:00.000-08:00</published><updated>2007-01-18T17:08:51.683-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rootkit'/><category scheme='http://www.blogger.com/atom/ns#' term='Fe-Secure BlackLight'/><category scheme='http://www.blogger.com/atom/ns#' term='Rootkits'/><category scheme='http://www.blogger.com/atom/ns#' term='Rootkit Unhooker'/><category scheme='http://www.blogger.com/atom/ns#' term='Sophos'/><category scheme='http://www.blogger.com/atom/ns#' term='RootkitRevealers'/><category scheme='http://www.blogger.com/atom/ns#' term='RKDetector'/><category scheme='http://www.blogger.com/atom/ns#' term='Informationweek'/><category scheme='http://www.blogger.com/atom/ns#' term='IceSword'/><category scheme='http://www.blogger.com/atom/ns#' term='RootkitBuster'/><title type='text'>Review on 6 Rootkit revealers from Informationweek</title><content type='html'>&lt;span style="font-size:85%;"&gt;Check out full review from Informationweek.&lt;br /&gt;&lt;br /&gt;They gives you some good background information that normal people can understand and reveals 6 well known Rootkit revealers. But they missed one more good program Sophos Anti-Rootkit (Which is best out of 6 rootkit revealers reviewed on below link).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Six reviewed anti-rootkit products:-&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;• &lt;/span&gt;&lt;a href="http://www.informationweek.com/story/showArticle.jhtml?articleID=196901062&amp;pgno=2"&gt;&lt;span style="font-size:78%;"&gt;F-Secure BlackLight&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;• &lt;/span&gt;&lt;a href="http://www.informationweek.com/story/showArticle.jhtml?articleID=196901062&amp;amp;pgno=3"&gt;&lt;span style="font-size:78%;"&gt;IceSword&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;• &lt;/span&gt;&lt;a href="http://www.informationweek.com/story/showArticle.jhtml?articleID=196901062&amp;pgno=4"&gt;&lt;span style="font-size:78%;"&gt;RKDetector&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;• &lt;/span&gt;&lt;a href="http://www.informationweek.com/story/showArticle.jhtml?articleID=196901062&amp;amp;pgno=5"&gt;&lt;span style="font-size:78%;"&gt;RootkitBuster&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;• &lt;/span&gt;&lt;a href="http://www.informationweek.com/story/showArticle.jhtml?articleID=196901062&amp;pgno=6"&gt;&lt;span style="font-size:78%;"&gt;RootkitRevealer&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;• &lt;/span&gt;&lt;a href="http://www.informationweek.com/story/showArticle.jhtml?articleID=196901062&amp;amp;pgno=7"&gt;&lt;span style="font-size:78%;"&gt;Rootkit Unhooker&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Sophos Anti-Rootkit can be download from &lt;/span&gt;&lt;a href="http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html"&gt;&lt;span style="font-size:85%;"&gt;http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html&lt;/span&gt;&lt;/a&gt;&lt;a href="http://www.informationweek.com/shared/printableArticle.jhtml?articleID=196901062"&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Full review from Informationweek:-&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Link: &lt;/span&gt;&lt;a href="http://www.informationweek.com/shared/printableArticle.jhtml?articleID=196901062"&gt;&lt;span style="font-size:85%;"&gt;http://www.informationweek.com/shared/printableArticle.jhtml?articleID=196901062&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-4952191180592931866?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/4952191180592931866/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=4952191180592931866' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4952191180592931866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4952191180592931866'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/01/review-on-6-knonw-rootkit-revealer-from.html' title='Review on 6 Rootkit revealers from Informationweek'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-7154656042448118225</id><published>2007-01-18T16:10:00.000-08:00</published><updated>2007-01-18T16:16:44.778-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='Porn'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='YouTubes'/><category scheme='http://www.blogger.com/atom/ns#' term='popups'/><category scheme='http://www.blogger.com/atom/ns#' term='Antivirus'/><title type='text'>Spyware causing your PC to host porn materials</title><content type='html'>&lt;span style="font-size:85%;"&gt;Here is the video for untrained people on how spyware can turn your PC into porn host.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Link: &lt;/span&gt;&lt;a href="http://www.youtube.com/watch?v=gSMz2aEXj8M"&gt;&lt;span style="font-size:85%;"&gt;http://www.youtube.com/watch?v=gSMz2aEXj8M&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Remember, once your PC is turned into Porn junk or zombie, you can't stop them until your totally disable all infected spyware or malware. Try using PC Tools's Spyware Doctor, Webroot's SpywareSweeper and combination of some rootkit revealer from Sophos and good Antivirus software like Kaspersky/McAfee/Symantec/TrendMicro.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-7154656042448118225?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/7154656042448118225/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=7154656042448118225' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7154656042448118225'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7154656042448118225'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/01/spyware-causing-your-pc-to-host-porn.html' title='Spyware causing your PC to host porn materials'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-7926357781600071666</id><published>2007-01-15T18:50:00.000-08:00</published><updated>2007-01-16T16:04:29.822-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='Adware'/><category scheme='http://www.blogger.com/atom/ns#' term='Porn'/><category scheme='http://www.blogger.com/atom/ns#' term='popups'/><category scheme='http://www.blogger.com/atom/ns#' term='XXX'/><category scheme='http://www.blogger.com/atom/ns#' term='Ben Edelman'/><title type='text'>Porno popups - Big deal?</title><content type='html'>&lt;span style="font-size:85%;"&gt;You guys recall report of school teacher was busted for 40 years in prison because of some spyware caused porno popups during class session.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Big deal, we all know all popups are caused by adware &amp; spyware or even cookies &amp;amp; scripts that cause automatic popups by just visiting legitimate web sites. And porno popups are no exception, they are  just another popups with porno pictures.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Even I gets porn popups just visiting some blogs and webcasting sites.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Links: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Teacher get busted - &lt;/span&gt;&lt;a href="http://www.computerworld.com/blogs/node/4346"&gt;&lt;span style="font-size:85%;"&gt;http://www.computerworld.com/blogs/node/4346&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Some examples of popups - &lt;/span&gt;&lt;a href="http://www.benedelman.org/news/062206-1.html"&gt;&lt;span style="font-size:85%;"&gt;http://www.benedelman.org/news/062206-1.html&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-7926357781600071666?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/7926357781600071666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=7926357781600071666' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7926357781600071666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7926357781600071666'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/01/porno-popups-big-deal.html' title='Porno popups - Big deal?'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-5526531039101621144</id><published>2007-01-10T20:54:00.000-08:00</published><updated>2007-01-10T21:14:44.912-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Banload'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='Antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='F-Secure'/><title type='text'>Saddam malware</title><content type='html'>Have seen this Saddam's malware?, if you have copy of this virus file please send me a copy zip &amp;amp; encrypt it before you pasting to me directly or to &lt;a href="http://www.pctools.com/mrc/submit/"&gt;http://www.pctools.com/mrc/submit/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;More info on this w32/bandload virus:-&lt;br /&gt;&lt;a href="http://antivirus.about.com/b/a/257788.htm?nl=1"&gt;&lt;span style="font-size:85%;"&gt;http://antivirus.about.com/b/a/257788.htm?nl=1&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.f-secure.com/weblog/archives/archive-012007.html#00001071"&gt;&lt;span style="font-size:85%;"&gt;http://www.f-secure.com/weblog/archives/archive-012007.html#00001071&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-5526531039101621144?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/5526531039101621144/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=5526531039101621144' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5526531039101621144'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5526531039101621144'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/01/saddam-malware.html' title='Saddam malware'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-7998914943542489473</id><published>2007-01-10T20:42:00.000-08:00</published><updated>2007-01-10T20:52:54.722-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iPhone'/><category scheme='http://www.blogger.com/atom/ns#' term='gadget'/><category scheme='http://www.blogger.com/atom/ns#' term='Apple'/><title type='text'>Macworld 2007: Steve Jobs keynote</title><content type='html'>&lt;div&gt;&lt;a href="http://bp1.blogger.com/_DAkCiWAwOQ4/RaXBCeapTcI/AAAAAAAAAAY/OqpeppBMAOo/s1600-h/iphone.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5018629608043007426" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 123px; CURSOR: hand; HEIGHT: 123px" height="209" alt="" src="http://bp1.blogger.com/_DAkCiWAwOQ4/RaXBCeapTcI/AAAAAAAAAAY/OqpeppBMAOo/s320/iphone.jpg" width="202" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Apple computer have launch new iPhone, check out Steve Jobs keynote&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-size:85%;"&gt;Links: &lt;/span&gt;&lt;a title="http://www.engadget.com/2007/01/09/live-from-macworld-2007-steve-jobs-keynote/" href="http://www.engadget.com/2007/01/09/live-from-macworld-2007-steve-jobs-keynote/"&gt;&lt;span style="font-size:85%;"&gt;http://www.engadget.com/2007/01/09/live-from-macworld-2007-steve-jobs-keynote/&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/a&gt;&lt;div&gt;&lt;a href="http://bp1.blogger.com/_DAkCiWAwOQ4/RaXB7eapTdI/AAAAAAAAAAg/aVK3Gf_cDyo/s1600-h/iphone-2.jpg"&gt;&lt;/a&gt; &lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;a href="http://bp1.blogger.com/_DAkCiWAwOQ4/RaXB7eapTdI/AAAAAAAAAAg/aVK3Gf_cDyo/s1600-h/iphone-2.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5018630587295550930" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 123px; CURSOR: hand; HEIGHT: 121px" height="231" alt="" src="http://bp1.blogger.com/_DAkCiWAwOQ4/RaXB7eapTdI/AAAAAAAAAAg/aVK3Gf_cDyo/s320/iphone-2.jpg" width="235" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-size:85%;"&gt;More links about iPhone &amp; pics:-&lt;br /&gt;&lt;div&gt;&lt;a href="http://bp1.blogger.com/_DAkCiWAwOQ4/RaXB7eapTdI/AAAAAAAAAAg/aVK3Gf_cDyo/s1600-h/iphone-2.jpg"&gt;&lt;/a&gt; &lt;/div&gt;From Apple: &lt;/span&gt;&lt;a href="http://www.apple.com/iphone/"&gt;&lt;span style="font-size:85%;"&gt;http://www.apple.com/iphone/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;From Blogger: &lt;/span&gt;&lt;a href="http://appleiphone.blogspot.com/"&gt;&lt;span style="font-size:85%;"&gt;http://appleiphone.blogspot.com/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;From Gadget news: &lt;/span&gt;&lt;a href="http://www.engadget.com/2007/01/09/the-apple-iphone/"&gt;&lt;span style="font-size:85%;"&gt;http://www.engadget.com/2007/01/09/the-apple-iphone/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://bp1.blogger.com/_DAkCiWAwOQ4/RaXB7eapTdI/AAAAAAAAAAg/aVK3Gf_cDyo/s1600-h/iphone-2.jpg"&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-7998914943542489473?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/7998914943542489473/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=7998914943542489473' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7998914943542489473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/7998914943542489473'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/01/macworld-2007-steve-jobs-keynote.html' title='Macworld 2007: Steve Jobs keynote'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_DAkCiWAwOQ4/RaXBCeapTcI/AAAAAAAAAAY/OqpeppBMAOo/s72-c/iphone.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-6649438513553818750</id><published>2007-01-10T20:37:00.000-08:00</published><updated>2007-01-10T20:40:45.223-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security threat'/><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Zdnet'/><title type='text'>New sophisticated phishing tool</title><content type='html'>Zdnet reported that there is new sophisticated phishing tool use by cybercrooks. Check out the link below.&lt;br /&gt;&lt;br /&gt;From Zdnet January 10, 2007, 11:47 AM PT&lt;br /&gt;&lt;br /&gt;Security experts at RSA have come across a new tool that automatically creates sophisticated phishing sites, a sign that cybercrooks are getting increasingly professional.&lt;br /&gt;The tool, which RSA calls the "Universal Man-in-the-Middle Phishing Kit," is available on underground online marketplaces for about $1,000, Jens Hinrichsen, RSA's product marketing manager for fraud auction, said in an interview Wednesday.&lt;br /&gt;"Unlike other phishing kits which have been in existence for quite some time, this kit is unique because with a very simple user interface you can choose whatever site you'd like to spoof," Hinrichsen said. "The arms race continues; we on the security side have to continue to escalate resources and invest in technology."&lt;br /&gt;Phishing scams are &lt;a title="Phishers catch on to the Net's 'long tail' -- Tuesday, Sep 12, 2006" href="http://news.zdnet.com/2100-1009_22-6114815.html?tag=nl"&gt;a prevalent online threat&lt;/a&gt; that typically use fraudulent Web pages and spammed e-mail messages to trick people into giving up personal information such as user credentials or credit card data.&lt;br /&gt;Using the new kit, a fraudster only has to enter variables such as which site should be spoofed and where the fraudulent page will be hosted. The tool then produces a dynamic Web page in the PHP (hypertext preprocessor) scripting language. The fraudster hosts this page somewhere on the Web, typically on a compromised Web server or a free Web host, and lures people to it with spammed e-mail messages or other links.&lt;br /&gt;Unlike traditional phishing Web sites that have static Web pages designed to look like a real online bank or other trusted site, the dynamic page created by the phishing kit actually pulls in the current Web site of the target organization and displays it. However, any data entered is captured by the miscreants, Hinrichsen said.&lt;br /&gt;"Once you enter your credentials, it would be intercepted by that server where the PHP file is hosted," he said. At the same time, the victim is actually logged in to the legitimate site and may never know he's been phished.&lt;br /&gt;Shrewd phishers monitor the log-in process to validate that the data they capture is legitimate, Hinrichsen said. An incorrect username and password combination would be discarded. Also, the man-in-the-middle-style attack lets the miscreants continue to eavesdrop on the victim's interactions with the legitimate Web site, according to RSA.&lt;br /&gt;The most popular phishing targets are banks and online payment services such as PayPal. Auctioneer eBay is also a common target. Fraudsters run phishing scams to collect personal information that can be used for identity fraud.&lt;br /&gt;&lt;br /&gt;Link: &lt;a href="http://news.zdnet.com/2100-1009_22-6149090.html"&gt;http://news.zdnet.com/2100-1009_22-6149090.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-6649438513553818750?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/6649438513553818750/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=6649438513553818750' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6649438513553818750'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/6649438513553818750'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/01/new-sophisticated-phishing-tool.html' title='New sophisticated phishing tool'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-5475959439277056016</id><published>2007-01-04T14:44:00.000-08:00</published><updated>2007-01-04T14:49:43.313-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='YouTube'/><category scheme='http://www.blogger.com/atom/ns#' term='Rockband'/><category scheme='http://www.blogger.com/atom/ns#' term='AV'/><category scheme='http://www.blogger.com/atom/ns#' term='music'/><category scheme='http://www.blogger.com/atom/ns#' term='BitDefender'/><title type='text'>Another Antivirus music band !</title><content type='html'>SecuriTeam blog reported another AV music band, it's from BitDefender, it's funny how Antivirus companies are trying to brain wash people with their music ;)&lt;br /&gt;&lt;br /&gt;Check out their music from Youtube links;&lt;br /&gt;&lt;a href="http://www.youtube.com/results?search_query=bitdefender" target="_blank"&gt;http://www.youtube.com/results?search_query=bitdefender&lt;/a&gt;&lt;br /&gt;And specifically:&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=XLfNeYkgjpI" target="_blank"&gt;http://www.youtube.com/watch?v=XLfNeYkgjpI&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=NLHQknOP90c" target="_blank"&gt;http://www.youtube.com/watch?v=NLHQknOP90c&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=g-0IqmHiLRw" target="_blank"&gt;http://www.youtube.com/watch?v=g-0IqmHiLRw&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=-dhGZwinLrY" target="_blank"&gt;http://www.youtube.com/watch?v=-dhGZwinLrY&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Now, go and watch the Symantec version: &lt;a href="http://www.youtube.com/watch?v=x-UnYm6qfy8" target="_blank"&gt;http://www.youtube.com/watch?v=x-UnYm6qfy8&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-5475959439277056016?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/5475959439277056016/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=5475959439277056016' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5475959439277056016'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5475959439277056016'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/01/another-antivirus-music-band.html' title='Another Antivirus music band !'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-849510822281159307</id><published>2007-01-03T18:33:00.000-08:00</published><updated>2007-01-04T14:51:55.311-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Jack Bauer'/><category scheme='http://www.blogger.com/atom/ns#' term='Chuck Norris'/><category scheme='http://www.blogger.com/atom/ns#' term='TV'/><category scheme='http://www.blogger.com/atom/ns#' term='drama'/><category scheme='http://www.blogger.com/atom/ns#' term='24'/><title type='text'>The TV 24 series: Jack Bauer - the next Chuck Norris?</title><content type='html'>&lt;a href="http://bp1.blogger.com/_DAkCiWAwOQ4/RZxpaC4XgLI/AAAAAAAAAAM/xT0DC5ZJ19Y/s1600-h/24.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5015999981154697394" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_DAkCiWAwOQ4/RZxpaC4XgLI/AAAAAAAAAAM/xT0DC5ZJ19Y/s320/24.jpg" border="0" /&gt;&lt;/a&gt; Check out the top 100 facts about Jack Bauer (Fictional character from TV Series called 24 - season 6 ~will air on 14.15 January 2007). It's pretty funny :)&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;Link: &lt;a title="http://www.notrly.com/jackbauer/index.php?tophundred" href="http://www.notrly.com/jackbauer/index.php?tophundred"&gt;http://www.notrly.com/jackbauer/index.php?tophundred&lt;/a&gt;&lt;/div&gt;&lt;div&gt;TV link: &lt;a href="http://www.fox.com/24/Info"&gt;http://www.fox.com/24/Info&lt;/a&gt;&lt;br /&gt;link: &lt;a href="http://en.wikipedia.org/wiki/24_(TV_series"&gt;http://en.wikipedia.org/wiki/24_(TV_series&lt;/a&gt;)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-849510822281159307?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/849510822281159307/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=849510822281159307' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/849510822281159307'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/849510822281159307'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/01/tv-24-series-jack-bauer-next-chuck.html' title='The TV 24 series: Jack Bauer - the next Chuck Norris?'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_DAkCiWAwOQ4/RZxpaC4XgLI/AAAAAAAAAAM/xT0DC5ZJ19Y/s72-c/24.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-4638589135090295575</id><published>2007-01-03T15:34:00.000-08:00</published><updated>2007-01-03T15:48:04.824-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SurfSideKick'/><category scheme='http://www.blogger.com/atom/ns#' term='LinkOptimizer'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojan.Gromp'/><category scheme='http://www.blogger.com/atom/ns#' term='Gromozon'/><category scheme='http://www.blogger.com/atom/ns#' term='Deluxe Communication'/><title type='text'>Sunbelt blog's report on Gromozon.com</title><content type='html'>Sunbelt blog reported Gromozon attack, here is more info from Symantec.&lt;br /&gt;&lt;br /&gt;Link:&lt;br /&gt;&lt;a href="http://www.symantec.com/enterprise/security_response/weblog/2006/08/gromozoncom_and_italian_spaghe.html"&gt;http://www.symantec.com/enterprise/security_response/weblog/2006/08/gromozoncom_and_italian_spaghe.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Looks like &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-082416-2803-99"&gt;LinkOptimizer&lt;/a&gt; and Trojan.Gromp is back again. Did you know both LinkOptimizer &amp; Trojan.Gromp is actually same threat?&lt;br /&gt;&lt;br /&gt;The latest LinkOptimizer files are detected as Trojan.Gromp by most European AV vendors where as US vendors such as Symantec &amp; Spysweeper detected as LinkOptimizer.&lt;br /&gt;&lt;br /&gt;Just like Deluxe Communication &amp; SurfSideKick (another same threat, just different names).&lt;br /&gt;Links:&lt;br /&gt;&lt;a href="http://www.pchell.com/support/surfsidekick.shtml"&gt;http://www.pchell.com/support/surfsidekick.shtml&lt;/a&gt;&lt;br /&gt;&lt;a href="http://affiliatefairplay.com/newsblog/2006/08/28/surfsidekick-now-dxcdirect/"&gt;http://affiliatefairplay.com/newsblog/2006/08/28/surfsidekick-now-dxcdirect/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.anti-spyware-101.com/remove-deluxecommunications/"&gt;http://www.anti-spyware-101.com/remove-deluxecommunications/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Removal info for Deluxe Comminication &amp; SurfSideKick:&lt;br /&gt;&lt;a href="http://www.spywareremove.com/removeDeluxeCommunications.html"&gt;http://www.spywareremove.com/removeDeluxeCommunications.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-4638589135090295575?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/4638589135090295575/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=4638589135090295575' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4638589135090295575'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4638589135090295575'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/01/sunbelt-blogs-report-on-gromozoncom.html' title='Sunbelt blog&apos;s report on Gromozon.com'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-3494108954693545541</id><published>2007-01-03T15:30:00.000-08:00</published><updated>2007-01-03T15:32:31.171-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IBM'/><category scheme='http://www.blogger.com/atom/ns#' term='Rockband'/><category scheme='http://www.blogger.com/atom/ns#' term='Symantec'/><category scheme='http://www.blogger.com/atom/ns#' term='Checkpoint'/><title type='text'>Rockband for Checkpoint, Symantec &amp; IBM</title><content type='html'>Check out another Rockband for company.&lt;br /&gt;Link: &lt;a href="http://www.ranum.com/editorials/corporate-songs/index.html"&gt;http://www.ranum.com/editorials/corporate-songs/index.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Including&lt;br /&gt;The Checkpoint song&lt;br /&gt;Symantec Revolution&lt;br /&gt;Ever Onward I.B.M&lt;br /&gt;&lt;br /&gt;Followup from Symantec Rockband &lt;a href="http://www.rockdotrock.com/"&gt;http://www.rockdotrock.com/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-3494108954693545541?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/3494108954693545541/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=3494108954693545541' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3494108954693545541'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/3494108954693545541'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/01/rockband-for-checkpoint-symantec-ibm.html' title='Rockband for Checkpoint, Symantec &amp; IBM'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-5843556308682742889</id><published>2007-01-02T22:43:00.000-08:00</published><updated>2007-01-02T22:46:22.836-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='New year'/><category scheme='http://www.blogger.com/atom/ns#' term='Golden Pig'/><title type='text'>Happy New Year ! The year of the Golden Pig ! Wow</title><content type='html'>According to Chinese mythology, which is also believed by Koreans, the year of the golden pig arrives every 600 years, and it is considered extremely propitious, especially in terms of monetary wealth. Thus, couples all across Asia are giving it their best to bring in babies within the next lunar year which starts on Feb. 18, 2007.&lt;br /&gt;Granted, folklore scholars dispute the existence at all of a golden pig year. They say that further research will likely debunk the myth just as it did the myth of 2006 as the "year of the two springs," an extremely favorable year for marriages, according to The Korea Times, an English-language newspaper published out of Seoul.&lt;br /&gt;But the legend has gained widespread popularity, regardless, especially among young couples looking to have their first or second child. South Korea, for example, is expected to see a 10 percent increase in the birth rate, primarily because of the rumor, according to The Korea Times.&lt;br /&gt;Retailers are also capitalizing on the trend by printing golden-pig-year calendars, baby clothing and a whole array of toys to meet the sudden demand. Marriage halls during 2006 saw just as significant an increase in business last year, because of the myth about that propitious year.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-5843556308682742889?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/5843556308682742889/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=5843556308682742889' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5843556308682742889'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/5843556308682742889'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/01/happy-new-year-year-of-golden-pig-wow.html' title='Happy New Year ! The year of the Golden Pig ! Wow'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3139148209091608874.post-4967969160672924712</id><published>2007-01-02T22:27:00.000-08:00</published><updated>2007-01-02T22:30:48.605-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rootkit'/><category scheme='http://www.blogger.com/atom/ns#' term='Mark Russinovich'/><title type='text'>Mark Russinovich's video on malware detection and cleaning!</title><content type='html'>Check out some interesting video on Rootkit hunting&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/emea/itsshowtime/sessionh.aspx?videoid=359"&gt;http://www.microsoft.com/emea/itsshowtime/sessionh.aspx?videoid=359&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3139148209091608874-4967969160672924712?l=consoleman.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://consoleman.blogspot.com/feeds/4967969160672924712/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3139148209091608874&amp;postID=4967969160672924712' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4967969160672924712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3139148209091608874/posts/default/4967969160672924712'/><link rel='alternate' type='text/html' href='http://consoleman.blogspot.com/2007/01/mark-russinovichs-video-on-malware.html' title='Mark Russinovich&apos;s video on malware detection and cleaning!'/><author><name>Benon</name><uri>http://www.blogger.com/profile/00424458236915031426</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://bp1.blogger.com/_DAkCiWAwOQ4/SJhF7e2eLkI/AAAAAAAAADI/-6HFJGm2WpU/S220/space_craft_man.JPG'/></author><thr:total>0</thr:total></entry></feed>
