<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>phishing &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/phishing/</link>
	<description>Feed of posts on WordPress.com tagged "phishing"</description>
	<pubDate>Mon, 23 Nov 2009 20:48:41 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[What The Hell?  Spike in Misdiagnosis, Part 2]]></title>
<link>http://whatthehellsecurity.com/2009/11/23/what-the-hell-spike-in-misdiagnosis-part-2/</link>
<pubDate>Mon, 23 Nov 2009 20:20:01 +0000</pubDate>
<dc:creator>ljh</dc:creator>
<guid>http://whatthehellsecurity.com/2009/11/23/what-the-hell-spike-in-misdiagnosis-part-2/</guid>
<description><![CDATA[Referring to my previous post, here is the skinny on my Anti-Fraudulent Hot Dog Vendor Detector. Wel]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Referring to my previous post, here is the skinny on my Anti-Fraudulent Hot Dog Vendor Detector.</p>
<p>Well, hold on.  I&#8217;m up to Version 2.0.  Before I describe that, I really should explain Version 1.0.  Here&#8217;s a theoretical average day in its life.  Bear with me, there&#8217;s actually something to be learned.</p>
<ul>
<li>100 people walk past the fraudulent vendor&#8217;s hot dog cart</li>
<li>42 buy the bait</li>
<li>4 have their card numbers pilfered</li>
<li>0.2 notice strange charges on their next bill</li>
<li>0.06 bother to report it to their fraudulent hot dog vendor detective (me)</li>
<li>After 33.3 business days I discern a solid pattern of 2 reports from my clientele, so I mention it to the neighborhood beat cop</li>
<li>After 66.6 business days, the beat cop discerns a solid pattern of 2 reports from me, so he starts warning hungry-looking pedestrians</li>
</ul>
<p>Believe it or not, this service was so effective that unimaginative copycats started coming out of the woodwork.   What the hell?  This left me no choice but to release Version 2.0, which has the following benefits over Version 1.0:</p>
<ul>
<li><em>this space intentionally left blank<br />
</em></li>
</ul>
<p>See, a Fraudulent Hot Dog Vendor Detector can only get so good.  No matter how fast it gets at detecting bad guys, they always win <em>by definition</em>.   You can&#8217;t detect something that hasn&#8217;t happened.  At least at it pertains to hot dogs, which I&#8217;m guessing Heisenberg was not a fan of.</p>
<p>What hot dog eating pedestrians would <em>really</em> benefit from is a drop-dead simple way to identify which hot dog vendors are legitimate before they take the bait.  And what online pedestrians would really benefit from is a drop-dead simple way to identify which links and forms are legitimate before they click.</p>
<p>Yeah, I know what you&#8217;re thinking.  SiteAdvisor does that, right?  Let&#8217;s just say that their green checkmarks are more like black lies.  They&#8217;re derived from &#8212; get this &#8212; a blacklist they compile from scouring Web content.  The checkmarks don&#8217;t tell you what&#8217;s good &#8212; they tell you what&#8217;s not bad.</p>
<p>It&#8217;s time to blacklist the blacklists.  Or at least, put them in their proper place, meaning somewhere other than &#8220;state-of-the-art.&#8221;</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Les clients Orange victimes de phishing]]></title>
<link>http://scteam.wordpress.com/2009/11/23/les-clients-orange-victimes-de-phishing/</link>
<pubDate>Mon, 23 Nov 2009 19:06:55 +0000</pubDate>
<dc:creator>ju4n1t0</dc:creator>
<guid>http://scteam.wordpress.com/2009/11/23/les-clients-orange-victimes-de-phishing/</guid>
<description><![CDATA[Attention aux fausses pages d&#8217;Orange ! Un mail sous l&#8217;allure d&#8217;Orange redirige les]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p style="text-align:center;"><img class="alignnone" src="http://www.ariase.com/fr/news/media/scam-orange-novembre-2009-2.png" alt="" width="450" height="327" /></p>
<p style="text-align:left;">Attention aux fausses pages d&#8217;Orange !</p>
<p style="text-align:left;">Un mail sous l&#8217;allure d&#8217;Orange redirige les clients sur <a href="http://www.ariase.com/fr/news/phishing-article-2205.html" target="_blank">une fausse page Web</a> et invite l&#8217;utilisateur à donner ses coordonnés bancaires.</p>
<p style="text-align:center;"><img class="alignnone" src="http://www.ariase.com/fr/news/media/scam-orange-novembre-2009.png" alt="" width="449" height="244" /></p>
<p style="text-align:left;">La page en question est sous l&#8217;adresse whoditty.com/logs/.</p>
<p style="text-align:left;">Prudence !</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Un nouveau virus pour les iPhones Jailbreakés !]]></title>
<link>http://scteam.wordpress.com/2009/11/23/un-nouveau-virus-pour-les-iphones-jailbreakes/</link>
<pubDate>Mon, 23 Nov 2009 18:55:57 +0000</pubDate>
<dc:creator>ju4n1t0</dc:creator>
<guid>http://scteam.wordpress.com/2009/11/23/un-nouveau-virus-pour-les-iphones-jailbreakes/</guid>
<description><![CDATA[Selon F-Secure, le ver en question redirigerait les utilisateurs sur une fausse page Web imitant la ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img class="alignnone" src="http://www.thewwwblog.com/images/apple/iphone-jailbreak.jpg" alt="" width="210" height="196" /></p>
<p>Selon <a href="http://www.f-secure.com/weblog/archives/00001822.html" target="_blank">F-Secure</a>, le ver en question redirigerait les utilisateurs sur une fausse page Web imitant la banque <a href="http://www.ingdirect.fr" target="_blank">ING Direct</a>.</p>
<p>La page Web est hébergée en Lithuanie sous l&#8217;IP 92.61.38.16.</p>
<p style="text-align:center;"><img class="alignnone" src="http://www.f-secure.com/weblog/archives/duh.png" alt="" width="448" height="101" /></p>
<p>Le ver n&#8217;est pas très répandu, mais il est beaucoup plus dangereux que le ver <a href="http://www.f-secure.com/weblog/archives/00001814.html" target="_blank">Ikee</a>.</p>
<p>Cela concerne les iPhones Jailbeakés dont le mot de passe par défaut n&#8217;a pas été changé.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thanks for all the phishing]]></title>
<link>http://secforall.info/2009/11/22/thanks-for-all-the-phishing/</link>
<pubDate>Mon, 23 Nov 2009 05:42:09 +0000</pubDate>
<dc:creator>Joseph Webster</dc:creator>
<guid>http://secforall.info/2009/11/22/thanks-for-all-the-phishing/</guid>
<description><![CDATA[Thank you India Thank you providence Thank you disillusionment Thank you nothingness Thank you clari]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img class="alignleft" title="Being Thankful" src="http://jfcbookstore.org/images/ThankfulWeb.jpg" alt="" width="138" height="104" /></p>
<blockquote><p><em>Thank you India<br />
Thank you providence<br />
Thank you disillusionment<br />
Thank you nothingness<br />
Thank you clarity<br />
Thank you thank you silence<br />
<strong>from Thank U by Alanis Morissette</strong></em></p></blockquote>
<p>This week being Thanksgiving in the US and me being a wickedly sarcastic scamp here are some things that I would be thankful for. If they were even remotely true. I&#8217;m a collector and, dare I say connoisseur, of Nigerian 411 style phishing messages. So without further ado, here is a sampling of my favorites. The things I&#8217;m thankful for.</p>
<p><strong>I&#8217;m thankful for </strong><a title="Unknown inheritance" href="http://webjoseph425.wordpress.com/files/2009/11/your-kind-attention.pdf" target="_blank"><strong>long lost relatives that die and leave me obscene amounts of money</strong></a><strong>.</strong></p>
<blockquote><p><em>Dear  Joseph Webster,</em></p>
<p><em> I am Ding Xiang Liang, barrister at law. A deceased client of mine, by name Mr. Andrew Webster, who here in after shall be referred to as my client, died as the result of a heart-related condition in November 2004. His heart condition was due to the death of all the members of his family in the Gulf Air Flight Crashes in Persian Gulf Near Bahrain Aired August 23, 2000 &#8211; 2:50 p.m. ET as reported on http://transcripts.cnn.com/TRANSCRIPTS/0008/23/bn.08.html.</em></p>
<p><em> I have contacted you to assist in distributing the money left behind by my client before it is confiscated or declared unserviceable by the bank where this deposit valued at <strong>$19.5 million</strong></em><em> dollars is lodged. This bank has issued me a notice to contact the next of kin, or the account will be confiscated. My proposition to you is to seek your consent to present you as the next-of-kin and beneficiary of my late client, since you have the same last name, so that the proceeds of this account can be paid to you. Then we can share the amount on a mutually agreed-upon percentage.</em></p></blockquote>
<p><strong>I am thankful for </strong><a title="Unknown money owed" href="http://webjoseph425.wordpress.com/files/2009/11/from-mr-william-griffen.pdf" target="_blank"><strong>helpful bureaucrats that find millions owed to me that I don&#8217;t even remember</strong></a><strong>.</strong></p>
<blockquote><p><em>Dear Beneficiary,</em></p>
<p><em>I am William Griffen, a senior staff with the World Bank fact finding &#38; special duties office. I and the chief security officer (CSO) of this organization have arranged with an officer in computer section engineer Peter Uba to bring out part of your total pending payment sum amounting to <strong>US$10 million</strong></em><em>. Why we did this is because according to information gathered from the banks/security computer, you have been waiting for a long time to receive your money without success.</em></p>
<p><em>As I found out that you have almost met all the statutory requirements in respect of your pending payment, your problem is that of interest groups.. A lot of people are interested in your payment and those people are merely doing paper works with you and that explains why you receive fax and phone messages from different people everyday. Also we found out that some of the officials of the parastatals have been extorting a lot of money from you with the pretext of helping you receive your money. I can assure you that this may last for years yet nothing happens if you do not do away with those officers that you call your partners.</em></p></blockquote>
<p><strong>I am thankful for </strong><a title="a fortune in money and diamonds" href="http://webjoseph425.wordpress.com/files/2009/11/be-mindfull.pdf" target="_blank"><strong>strangers who are so impressed with my integrity that they want to send me a fortune</strong></a><strong>.</strong></p>
<blockquote><p><em>Dear   Joseph Webster ,</em></p>
<p><em>How are you and every member of the family? I hope they are fine? if so may almighty God continue to guide you and protect you in your entire endeavor.I am Mr Yester Koma a Liberian by nationality.</em></p>
<p><em>I got your contact through a Christian sister who told us that you are reliable and trust worthy person who can assist us in area of investment, though I did not disclosed to her then strength of what we have in our possession.</em></p>
<p><em>I am the eldest Son of Chief George Koma who was killed six years ago in the recent war at Liberia, by some political imgrates. Before he died he was the owner of Koma and sons Diamond Company in Liberia.</em></p>
<p><em>After the death of my father, I and my mother quickly rush into my fathers private warehouse and took away (Two trunk boxes One containing<strong>$20,million dollars</strong> , and the Second one containing<strong> 10kgs of Diamond</strong>) .</em></p>
<p><em>Friend, the two trunk boxes are now in a private security company near Lome Togo international airport awaiting shipment. Dear Sir, what we want you to do for us is to send us your Full name and address also your private phone number to enable me and my mother get all necessary documents needed to get the consignments delivered to your door step through diplomatic means.</em></p></blockquote>
<p><strong>I am thankful for </strong><a title="dying millionaire needs your help" href="http://webjoseph425.wordpress.com/files/2009/11/im-seriously-sick.pdf" target="_blank"><strong>dying strangers who seek me out to distribute their fabulous wealth to charities</strong></a><strong>.</strong></p>
<blockquote><p><em>My last wish,</em></p>
<p><em>My Name is Mr. Abdul Raham,i am 57years old. Am a citizen of Saudi Arabia, but i am resident in Cayman Island. I was born an Orphan in 1952. I have no Father or Mother, and i have no Relatives.I struggled and Worked Hard and Almighty God blessed me Abundantly with Riches. I used to be a Dealer in Gold, Diamonds and Tantalite. I have no Wife but i happend to have a child of 5Yrs from my late Wife who happens to die of Cancer of the Breast. For 2 years now i am seriously sick. I have been diagnosed with Cancer which was discovered very late, due to my laxity in caring for my health. It has defiled all forms of Medicine, Right now I have only about a Year to Live, according to my Medical Doctor. I have not particularly lived my life so well since after the Death of my wife Four Years ago, as I never really cared for myself but the Business. Though I am very Rich, I was never Generous, I only focused on my Business as that was the only thing I cared for. But now I Regret all this as I now know that there is more to life than just wanting to have or make all the Money in the world. I believe when God gives me a second chance and heal me I would live my life a different way from how I have lived it.</em></p>
<p><em>Please i have sowed a seed for my healing; I have willed and given most of my properties andassets to my immediate Orphans childrens and as well as a few close Friends.I want God to be merciful to me and accept my soul and so, I have decided to give Arms to charity Organizations and give succor and comfort to the less privileged of the Tsunami Victims, as I want this to be one of the last good deeds I do on earth. So far, I have donated money to Some charity organizations. Now that my health has deteriorated so badly, I Cannot do this my self anymore. I once asked a close friend of mine to close one of my accounts in Saudi Bank and donate the money which I have there to charity organization and to the less Privileged in Bulgaria and Sudan-Africa he cashed the money but kept it only to himselves.</em></p>
<p><em>Hence, I do not trust him anymore, as he seem not to be contended with what I have left for him already. The last of my money, which no one knows of, is the huge cash of Twenty Two million(<strong>22 Million US DOLLARS</strong>) deposited in the Vault of a financial institution in Europe for Safekeeping. I want you to collect this deposit on my behalf and disburse thus 30percent of the total amount among the Mudslide Earthquake Victims in Asia, Hurricane Katrina, Hurricane Rita, Hurricane Wilma and for the less Privileged, 30percent for you for your time and efforts and 40percent for my only child for his upbringing as you will be responsible for his education,health and other activities.</em></p>
<p><em>So i need your urgent reply so that I will not have to go on sourcing for a credible person to handle this project, please if this is what you Know that you can handle kindly respond back to me with the information below.</em></p></blockquote>
<p><strong>I am thankful for </strong><a title="Lawyer saves you from evil partner" href="http://webjoseph425.wordpress.com/files/2009/11/attention_-beneficiary.pdf" target="_blank"><strong>lawyers who want to protect my fortune from my evil partner &#8211; neither of which I knew about</strong></a><strong>.</strong></p>
<blockquote><p><em> ATTENTION: BENEFICIARY,</em></p>
<p><em> This is to bring to your notice about the due process of your outstanding contractual payment which was suspended by the Federal ministry of Finance thereby stopping the telex unit to pause the transfer of your contract fund to your nominated Bank Account. As a result of this development, verification conducted by the newly appointed Finance Minister inconjunction with the Newly Appointed Member of Presidential Board of Trustee on Debt Verification Panel to contact you and let you Know that your contract casefile has been endorsed for payment awaiting your confirmations.</em></p>
<p><em> In view of several efforts already made by us to contact you proved abortive. Based on the new Address submitted to this office on your behalf:</em></p>
<p><em> (1) My Office desks have just received a new contact address from Mr. Bill Carlton, to deliver your Payment into a new address as stated bellow: 100 Wellington Street West ,Suite 1200 ,Toronto , Ontario , Canada ,M5K 1J3 The Sum of <strong>8.5 Million US Dollars</strong> (Eight Million Five Hundred Thousand USDollars) should be paid to Mr. Bill Carlton, as your beneficiary/Partner..</em></p>
<p><em> (2) Please,confirm to our Bank/Office if you have instructed Mr. Bill Carlton,to appoint an attorney/agent on your behalf thereby asking that he receive cashcall Remittance on your behalf as your Partner.</em></p>
<p><em> (3) It have come to our notice that you are being contacted by unauthorized individuals with respect to your contract/Inheritance payment but unfortunately this office is not aware of your unofficial dealings and warned that it is at your own risk.</em></p>
<p><em> (4) Please, also confirm if you have authorized Mr. Bill Carlton, To change your Residential Address to the following address stated below:100 Wellington Street West ,Suite 1200 ,Toronto , Ontario , Canada ,M5K 1J3We have decided to contact you for re-verification because we suspected that Mr. Bill Carlton, is trying to divert your money through the sworn affidavit to a new different address as your Partner Because of the fraudulent activities going around the globe, The World Bank and IMF advices the Central Bank not to contact you again regarding your Contractual Payment, which is why this Department (Foreign Fund Unit/Audit Department of the Dept Verification Panel Of Federal Ministry of Finance is now in charge of the Fund to be released to you through one of the Nominated Bank by World Bank and IMF.</em></p>
<p><em> Therefore, if you had not authorized Mr. Bill Carlton, to claim this Contractual Payment on your behalf as your Partner, Kindly get back to us with the down listed information requested for re-confirmation/verification and for fast and swift release of the Fund to you without any Further Delay.</em></p></blockquote>
<p><strong>I am thankful for </strong><a title="Senator needs help" href="//webjoseph425.wordpress.com/files/2009/11/i-need-your-response-urge.pdf" target="_blank"><strong>politicians who urgently need my help with shady foreign real estate investments</strong></a><strong>.</strong></p>
<blockquote><p><em>Hello, Webster</em></p>
<p><em>I am interested to acquire properties abroad, hence my contact with you. I wish to inform you therefore that I have the intention to invest a total sum <strong>US$65 million</strong> abroad on real estate. Kindly let me know your terms/conditions for my considerations. </em></p>
<p><em>Best regards,<br />
Senator Kathleen.</em></p></blockquote>
<p><strong>I am thankful for </strong><a title="Soldier needs help smuggling funds out of Iraq" href="http://webjoseph425.wordpress.com/files/2009/11/funds-shipment1.pdf" target="_blank"><strong>soldiers who want me to help them smuggle funds out of Iraq</strong></a><strong>.</strong></p>
<blockquote><p><em>Fellow Brother,</em></p>
<p><em>I hope my email meets you well. I am in need of your assistance. I am in the Engineering military unit here in Ba&#8217;qubah in Iraq, we have some amount of funds that we want to move out of the country. My partners and I need a good partner someone we can trust. Basically since we are working for the government we cannot keep these funds, but we want to transfer and move the funds to you, so that you can keep it for us in your safe account or an offshore account. But we are moving it through Diplomatic means, to send it to your house directly or a bank of your choice using Diplomatic Courier Service. The most important thing is that can we trust you? Once the funds get to you, you take your 30% out and keep our own 70%. Your own part of this deal is to find a safe place where the funds can be sent to. Our own part is sending it to you. If you are interested i will furnish you with more details.</em></p>
<p><em>Regards,</em></p>
<p><em>Sgt. Phillip Newman.</em></p></blockquote>
<p><strong>I am thankful for </strong><a title="Dearly Beloved" href="http://webjoseph425.wordpress.com/files/2009/11/confidential-letter.pdf" target="_blank"><strong>bankers who want me to be the lost heir to a fortune or maybe perform a wedding</strong></a><strong>.</strong></p>
<blockquote>
<div id="_mcePaste"><em>Dearly Beloved,</em></div>
<p><em>Let me start by introducing myself to you, I am Dr Stephen Annan, DirectorForeign Remittance Department, CITI BANK GHANA, Accra Head Office. I saw yourcontact during my private search in the internet and I want to believe that youwill be very honest, committed and capable of handling this transaction.</em></p>
<p><em>First, let me explain the source of this fund and what you are expected todo. A foreigner, late MR RONALD M. EBELING worked with the Ghanaian GOLD/MINERALRESOURCES COMMISSION and had a functional account with CITI BANK until his deathsome years ago. The deceased Ronald Ebeling banked with us and had a closingbalance as at 22nd November 2000 worth <strong>$8,000,000.00</strong> (Eight Million U.S Dollars)</em></p>
<p><em>CITI BANK has been expecting any of his close relatives to make claim onthe fund since there was no record of any beneficiary stated in the depositoryagreement. Efforts have been made by the Bank Agents to get in touch with RonaldEbeling’s family or relative but to no avail.</em></p>
<p><em>Based on the perceived possibility of not being able to locate RonaldEbeling’s relatives, the management under the influence of our chairman and theboard of directors are making arrangements for the fund to be declared unclaimedand channeled to an unknown account. It is based on this fact, I have contactedyou to approach the Bank as the next-of-kin to Late Ronald Ebeling so that thefund will be released and paid into your account as the beneficiary/next-of-kinto the deceased.</em></p></blockquote>
<p>But mostly I&#8217;m thankful that <a title="Google Translate" href="http://translate.google.com" target="_blank">Google Translate</a> isn&#8217;t any better than it is. Otherwise this stuff wouldn&#8217;t be nearly as amusing. So Happy Thanksgiving. So long and thanks for all the phish.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[REN-ISAC] Notification - URL redirecting to a phishing web page]]></title>
<link>http://referer.wordpress.com/2009/11/22/ren-isac-notification-url-redirecting-to-a-phishing-web-page/</link>
<pubDate>Sun, 22 Nov 2009 10:09:22 +0000</pubDate>
<dc:creator>referer</dc:creator>
<guid>http://referer.wordpress.com/2009/11/22/ren-isac-notification-url-redirecting-to-a-phishing-web-page/</guid>
<description><![CDATA[Hello Gabriel Iovino, http://referer.us/1/UdBiS3 created by our free redirection service (http://ref]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Hello Gabriel Iovino,</p>
<p><span style="text-decoration:underline;"><span style="color:#3366ff;">http://referer.us/1/UdBiS3 </span></span><br />
created by our <a href="http://referer.us/">free redirection service</a> (<a href="http://referer.us/">http://referer.us/</a>) and it redirects to <span style="color:#3366ff;"><span style="text-decoration:underline;">http://planetchiltern.com/phpformgenerator/use/striker/form1.html</span></span><br />
I checked this page and it looks NOT like a phishing webpage, it&#8217;s a sign UP page, not a sign in. Then I checked &#8220;<span style="text-decoration:underline;"><span style="color:#3366ff;">planetchiltern.com</span></span>&#8221; on McAfee SiteAdvisor, it says fine.<!--more--></p>
<p>&#8220;<span style="text-decoration:underline;"><span style="color:#3366ff;">vn27.9hz.com</span></span>&#8221; seems a phishing site according to &#8220;<a href="http://www.phishtank.com/phish_detail.php?phish_id=869455">phishtank.com</a>&#8220;, however, I cannot open it.</p>
<p>Therefor, I will not remove the url or block the site, thank you for your email and understanding.</p>
<p>Best regards,</p>
<p>======= At 2009-11-22, 05:48:49 you wrote: =======</p>
<blockquote><p>&#62;&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br />
&#62;Hash: SHA1<br />
&#62;<br />
&#62;Greetings,<br />
&#62;<br />
&#62;The following URL on your network has been identified as redirecting to<br />
&#62;a Phishing webpage:<br />
&#62;<br />
&#62;!!Warning these URL(s) may contain live malware!!<br />
&#62;<br />
&#62;[url]hxxp://referer.us/1/UdBiS3<br />
&#62;<br />
&#62;Path to this URL was seen via these links:<br />
&#62;<br />
&#62;1. hxxp://vn27.9hz.com/<br />
&#62;2. hxxp://referer.us/1/UdBiS3<br />
&#62;3. hxxp://planetchiltern.com/phpformgenerator/use/striker/form1.html<br />
&#62;<br />
&#62;Here is the Phishing email with full mail headers:<br />
&#62;</p>
<blockquote><p>&#62;&#62; Return-Path: &#60;bintsann@staff.pccu.edu.tw&#62;<br />
&#62;&#62; Received: from relays.pccu.edu.tw (relays.pccu.edu.tw [140.137.16.12])<br />
&#62;&#62; by smtp.xxx.edu (8.14.3/8.14.3) with ESMTP id nAKNEtMW017993<br />
&#62;&#62; for &#60;xxx@xxx.xxx.edu&#62;; Fri, 20 Nov 2009 15:14:56 -0800<br />
&#62;&#62; Received: from faculty.pccu.edu.tw (faculty.pccu.edu.tw [140.137.16.1])<br />
&#62;&#62; by relays.pccu.edu.tw (Postfix) with ESMTP id 915E81CAD80;<br />
&#62;&#62; Sat, 21 Nov 2009 07:14:50 +0800 (CST)<br />
&#62;&#62; From: &#8220;bintsann&#8221; &#60;bintsann@staff.pccu.edu.tw&#62;<br />
&#62;&#62; Reply-To: webmaster.team0@live.com<br />
&#62;&#62; Subject: System Administrator<br />
&#62;&#62; Date: Sat, 21 Nov 2009 07:14:50 +0800<br />
&#62;&#62; Message-Id: &#60;20091120231450.M94072@staff.pccu.edu.tw&#62;<br />
&#62;&#62; X-Mailer: OpenWebMail 2.53<br />
&#62;&#62; X-OriginatingIP: 213.255.218.244 (bintsann)<br />
&#62;&#62; MIME-Version: 1.0<br />
&#62;&#62; Content-Type: text/plain;<br />
&#62;&#62; charset=big5<br />
&#62;&#62; To: undisclosed-recipients:;<br />
&#62;&#62; Content-Transfer-Encoding: quoted-printable<br />
&#62;&#62; X-MIME-Autoconverted: from 8bit to quoted-printable by smtp.xxx.edu id nAKNEuee018002<br />
&#62;&#62;<br />
&#62;&#62; Your mailbox has exceeded the storage limit which is 20GB as set by your=20<br />
&#62;&#62; administrator; you are currently running on 20.9GB,<br />
&#62;&#62;<br />
&#62;&#62; You may not be able to send or receive new mail until you re-validate you=<br />
&#62;&#62; r=20<br />
&#62;&#62; mailbox.<br />
&#62;&#62;<br />
&#62;&#62; To re-validate your mailbox please click the link below:<br />
&#62;&#62;<br />
&#62;&#62; hxxp://vn27.9hz.com/<br />
&#62;&#62;<br />
&#62;&#62; If the link above doesn=A1=A6t work please copy and paste the link below =<br />
&#62;&#62; to your=20<br />
&#62;&#62; browser window<br />
&#62;&#62;<br />
&#62;&#62; hxxp://vn27.9hz.com/<br />
&#62;&#62;<br />
&#62;&#62; Thanks Bintsann Staff, =20<br />
&#62;&#62; System Administrator</p></blockquote>
<p>&#62;<br />
&#62;Should you feel you&#8217;ve received this report in error, please let us know.<br />
&#62;<br />
&#62;On behalf of the REN-ISAC Team,<br />
&#62;<br />
&#62;Gabriel Iovino<br />
&#62;Principal Security Engineer, REN-ISAC<br />
&#62;http://www.ren-isac.net<br />
&#62;24&#215;7 Watch Desk +1(317)278-6630<br />
&#62;&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br />
&#62;Version: GnuPG v1.4.9 (MingW32)<br />
&#62;Comment: Using GnuPG with Mozilla &#8211; http://enigmail.mozdev.org/<br />
&#62;<br />
&#62;iEYEARECAAYFAksItKEACgkQwqygxIz+pTvlggCgsu4RXH6LfyMbZzGqpDxMX3xl<br />
&#62;CqAAn0WytQ9D5&#215;4477RMHUmyOjhnDXxJ<br />
&#62;=i9YP<br />
&#62;&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;</p></blockquote>
<p>= = = = = = = = = = = = = = = = = = = =</p>
<p>@<a href="http://referer.us/">referer.us</a><br />
2009-11-22</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Princeton Who's Who]]></title>
<link>http://njtravelgal.wordpress.com/2009/11/21/princeton-whos-who/</link>
<pubDate>Sun, 22 Nov 2009 02:11:59 +0000</pubDate>
<dc:creator>NJTravelGal</dc:creator>
<guid>http://njtravelgal.wordpress.com/2009/11/21/princeton-whos-who/</guid>
<description><![CDATA[This past week, I got a fax from Princeton Who&#8217;s Who.  Wow, why would my little start-up busin]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>This past week, I got a fax from Princeton Who&#8217;s Who.  Wow, why would my little start-up business get something like this.  You know the thoughts that go through your mind, &#8220;I must be doing something right, I have attracted attention of  Who&#8217;s Who for Princeton NJ who want to list me&#8221;  Excited about the progress, I printed out the form that I was to fill out and return. </p>
<p>&#8216;We are pleased to inform you that you and your business have been selected to be published for free in the 2009/2010 Edition of Princeton Who&#8217;s Who of Executives, Professionals &#38; Entrepreneurs.&#8217; Who me?  Wow&#8230; &#8216;On November 16th, your candidacy was approved.  Your prompt response is needed to ensure your correct information is published.  For accuracy purposes, please be sure to fill out the information below and FAX it back to 609-6132-5918 at the earliest opportunity.&#8217;  Boy oh Boy, that LinkedIn account must be working!!</p>
<p>Then it hit me.  It was faxed to &#8216;Owner/Manager&#8217;, not directly to me.  No mention of my name or my company name (Two Sisters Travel). Better Google it to make sure that this is legitimate.   Now my excitement is starting to wane.  Sure enough, this is a scam.</p>
<p>Apparently this isn&#8217;t so &#8220;free&#8221;. They get you to send them your information to get you interested and excited.  Then they contact you to upgrade to the &#8220;premier&#8217; level but for a fee.  $876 worth of a fee.  Well, that just deflated this bubble. </p>
<p>The reason why I&#8217;m blogging about this?  Just to get this out there as much as possible.  It just amazes me how there are such unethical people out there on the web who will stoop to any level to get what people work so hard to earn.  And unfortunately, people fall for it!  Some aren&#8217;t as lucky as I was and  have those bells and whistles go off until AFTER they give them their credit card information to pay for the &#8220;premier&#8221; level.  By that time it is too late!  And that all ripples down to the credit card companies, which we have recently found out, put it right back to the credit card holder who is now paying outrageous interest rates and crazy fees! (Oh don&#8217;t get me started on that! Who ever heard of making someone with responsible credit &#8211; pays on time, etc.,  pay a fee because they DO pay on time??)</p>
<p>Anyway, if this blog helps just one person not fall for this scam,  it is well worth the time that I have taken to write it.  Bottom Line, if it seems too good to be true, it probably is.  If you get a fax from Princeton Who&#8217;s Who (click on link below), toss it in the trash or shred it, and you will have saved yourself $800+. </p>
<p><a href="http://njtravelgal.wordpress.com/files/2009/11/img015.pdf">Princeton Who&#8217;s Who</a><a href="http://njtravelgal.wordpress.com/files/2009/11/img015.pdf"></a></p>
<p>On another subject, I will be cruising again from December 6-13th on NCL&#8217;s Jewel.  Hopefully this time, all will go well and I can blog from the ship and post my pictures from the cruise right away.  Keep your fingers crossed.  And please join me for my blogs from NCL&#8217;s Jewel, right here in 2 weeks time.</p>
<p>Talk to you then!</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[WhoIs software777.net]]></title>
<link>http://scamfraudalert.wordpress.com/2009/11/21/whois-software777-net/</link>
<pubDate>Sat, 21 Nov 2009 08:57:28 +0000</pubDate>
<dc:creator>Scrub</dc:creator>
<guid>http://scamfraudalert.wordpress.com/2009/11/21/whois-software777-net/</guid>
<description><![CDATA[Consumer &amp; Business Alert This Is A Fraudulent Website ScamFraudAlert.com Recommend That You Do ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3 style="text-align:center;"><span style="color:#ff0000;"><br />
Consumer &#38; Business Alert                                    <img class="alignright size-full wp-image-6724" title="Sign" src="http://scamfraudalert.wordpress.com/files/2009/07/sign.png" alt="Sign" width="127" height="92" /><br />
This Is A Fraudulent Website<br />
<a href="http://scamfraudalert.com" target="_blank">ScamFraudAlert.com</a> Recommend That You<br />
Do Not Conduct<br />
or Transact Business With This Site</span></h3>
<h3>Address lookup</h3>
<table border="0" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td align="right" valign="baseline">canonical name</td>
<td valign="baseline"><a href="http://www.software777.net/">software777.net</a>.</td>
</tr>
<tr>
<td align="right" valign="baseline">aliases</td>
<td valign="baseline"></td>
</tr>
<tr>
<td align="right" valign="baseline">addresses</td>
<td valign="baseline">59.63.41.17<br />
117.41.183.3</td>
</tr>
</tbody>
</table>
<h3>Domain Whois record</h3>
<p>Queried whois.internic.net with &#8220;dom software777.net&#8221;&#8230;<br />
Domain Name: SOFTWARE777.NET<br />
Registrar: CHINA SPRINGBOARD INC.<br />
Whois Server: whois.namerich.cn<br />
Referral URL: http://www.namerich.cn<br />
Name Server: NS1.CUERMORADS.COM<br />
Name Server: NS2.CUERMORADS.COM<br />
Name Server: NS3.CUERMORADS.COM<br />
Name Server: NS4.CUERMORADS.COM<br />
Status: clientDeleteProhibited<br />
Status: clientTransferProhibited<br />
Updated Date: 20-nov-2009<br />
Creation Date: 12-nov-2009<br />
Expiration Date: 12-nov-2010</p>
<p>Last update of whois database: Sat, 21 Nov 2009 08:52:31 UTC</p>
<p>Queried whois.namerich.cn with &#8220;software777.net&#8221;&#8230;<br />
DomainName : software777.net </p>
<p>RSP: China Springboard Inc.<br />
URL: http://www.namerich.cn  </p>
<p>Name Server :NS1.CUERMORADS.COM<br />
Name Server :NS4.CUERMORADS.COM<br />
Name Server :NS2.CUERMORADS.COM<br />
Name Server :NS3.CUERMORADS.COM</p>
<p>Status :clientTransferProhibited<br />
Status :clientDeleteProhibited</p>
<p>Creation  Date :2009-11-12<br />
Expiration Date :2010-11-12<br />
Last Update  Date :2009-11-21</p>
<p>Registrant ID :V-X-64668-23345<br />
Registrant Name :wang xia<br />
Registrant Organization :wang xia<br />
Registrant Address :beijingshichanghailu111hao<br />
Registrant City :beijing<br />
Registrant Province/State :beijing<br />
Registrant Country Code :CN<br />
Registrant Postal Code :234232<br />
Registrant Phone Number :+86.010546236554<br />
Registrant Fax :+86.010546236554<br />
Registrant Email :dfdfddf2@sina.com</p>
<p>Administrative ID :V-X-64668-23345<br />
Administrative Name :wang xia<br />
Administrative Organization :wang xia<br />
Administrative Address :beijingshichanghailu111hao<br />
Administrative City :beijing<br />
Administrative Province/State :beijing<br />
Administrative Country Code :CN<br />
Administrative Postal Code :234232<br />
Administrative Phone Number :+86.010546236554<br />
Administrative Fax :+86.010546236554<br />
Administrative Email :dfdfddf2@sina.com</p>
<p>Billing ID :V-X-64668-23345<br />
Billing Name :wang xia<br />
Billing Organization :wang xia<br />
Billing Address :beijingshichanghailu111hao<br />
Billing City :beijing<br />
Billing Province/State :beijing<br />
Billing Country Code :CN<br />
Billing Postal Code :234232<br />
Billing Phone Number :+86.010546236554<br />
Billing Fax :+86.010546236554<br />
Billing Email :dfdfddf2@sina.com</p>
<p>Technical ID :V-X-64668-23345<br />
Technical Name :wang xia<br />
Technical Organization :wang xia<br />
Technical Address :beijingshichanghailu111hao<br />
Technical City :beijing<br />
Technical Province/State :beijing<br />
Technical Country Code :CN<br />
Technical Postal Code :234232<br />
Technical Phone Number :+86.010546236554<br />
Technical Fax :+86.010546236554<br />
Technical Email :dfdfddf2@sina.com<br />
; Please register your domains at</p>
<p>; http://www.namerich.cn</p>
<h3>Network Whois record</h3>
<p>Queried whois.apnic.net with &#8220;59.63.41.17&#8243;&#8230;<br />
inetnum:      59.62.0.0 &#8211; 59.63.255.255<br />
netname:      CHINANET-JX<br />
descr:        CHINANET Jiangxi province network<br />
descr:        China Telecom<br />
descr:        No.31,jingrong street<br />
descr:        Beijing 100032<br />
country:      CN<br />
admin-c:      CH93-AP<br />
tech-c:       JN113-AP<br />
remarks:      service provider</p>
<p>status:       ALLOCATED PORTABLE<br />
mnt-by:       APNIC-HM<br />
mnt-lower:    MAINT-IP-WWF<br />
changed:      hm-changed@apnic.net 20050208<br />
source:       APNIC</p>
<p>role:         JXDCB NET</p>
<p>address:      DATA COMMUNICATION BUREAY<br />
address:      NO.39,YANJIANG NORTH ROAD,NANCHANG,JIANGXI<br />
country:      CN<br />
phone:        +86 791 6730586<br />
fax-no:       +86 791 6707755<br />
e-mail:       hostmaster@public1.nc.jx.cn</p>
<p>trouble:      send spam reports to hostmaster@public1.nc.jx.cn<br />
trouble:      and abuse reports to hostmaster@public1.nc.jx.cn</p>
<p>admin-c:      XY1-AP<br />
tech-c:       WZ1-CN<br />
tech-c:       WW49-AP<br />
nic-hdl:      JN113-AP</p>
<p>remarks:      http://www.online.jx.cn<br />
notify:       hostmaster@public1.nc.jx.cn</p>
<p>mnt-by:       MAINT-IP-WWF<br />
changed:      hm-changed@apnic.net 20020812<br />
source:       APNIC<br />
person:       Chinanet Hostmaster</p>
<p>nic-hdl:      CH93-AP</p>
<p>e-mail:       anti-spam@ns.chinanet.cn.net</p>
<p>address:      No.31 ,jingrong street,beijing</p>
<p>address:      100032</p>
<p>phone:        +86-10-58501724</p>
<p>fax-no:       +86-10-58501724</p>
<p>country:      CN</p>
<p>changed:      dingsy@cndata.com 20070416</p>
<p>mnt-by:       MAINT-CHINANET</p>
<p>source:       APNIC</p>
<h3>DNS records</h3>
<p>DNS query for 17.41.63.59.in-addr.arpa  returned an error from the server: <strong>NameError</strong></p>
<table border="0" cellspacing="1" cellpadding="5">
<tbody>
<tr>
<td>name</td>
<td>class</td>
<td>type</td>
<td>data</td>
<td colspan="2">time to live</td>
</tr>
<tr>
<td valign="top">software777.net</td>
<td valign="top">IN</td>
<td valign="top">SOA</td>
<td valign="top">
<table border="0" cellspacing="0" cellpadding="2" width="100%">
<tbody>
<tr>
<td>server:</td>
<td align="right">ns1.domain.com</td>
</tr>
<tr>
<td>email:</td>
<td align="right">admin.domain.com</td>
</tr>
<tr>
<td>serial:</td>
<td align="right">1</td>
</tr>
<tr>
<td>refresh:</td>
<td align="right">300</td>
</tr>
<tr>
<td>retry:</td>
<td align="right">300</td>
</tr>
<tr>
<td>expire:</td>
<td align="right">300</td>
</tr>
<tr>
<td>minimum  ttl:</td>
<td align="right">1440</td>
</tr>
</tbody>
</table>
</td>
<td align="right" valign="top">1440s</td>
<td valign="top">(00:24:00)</td>
</tr>
<tr>
<td valign="top">software777.net</td>
<td valign="top">IN</td>
<td valign="top">A</td>
<td valign="top">117.41.183.3</td>
<td align="right" valign="top">1440s</td>
<td valign="top">(00:24:00)</td>
</tr>
<tr>
<td valign="top">software777.net</td>
<td valign="top">IN</td>
<td valign="top">NS</td>
<td valign="top">ns1.software777.net</td>
<td align="right" valign="top">1440s</td>
<td valign="top">(00:24:00)</td>
</tr>
<tr>
<td valign="top">software777.net</td>
<td valign="top">IN</td>
<td valign="top">NS</td>
<td valign="top">ns2.software777.net</td>
<td align="right" valign="top">1440s</td>
<td valign="top">(00:24:00)</td>
</tr>
<tr>
<td valign="top">software777.net</td>
<td valign="top">IN</td>
<td valign="top">NS</td>
<td valign="top">ns3.software777.net</td>
<td align="right" valign="top">1440s</td>
<td valign="top">(00:24:00)</td>
</tr>
<tr>
<td valign="top">software777.net</td>
<td valign="top">IN</td>
<td valign="top">NS</td>
<td valign="top">ns4.software777.net</td>
<td align="right" valign="top">1440s</td>
<td valign="top">(00:24:00)</td>
</tr>
<tr>
<td valign="top">software777.net</td>
<td valign="top">IN</td>
<td valign="top">A</td>
<td valign="top">59.63.41.17</td>
<td align="right" valign="top">1440s</td>
<td valign="top">(00:24:00)</td>
</tr>
</tbody>
</table>
<p>&#8211; end &#8211;</p>
<h2><span style="color:#ff0000;"><a href="http://rss.uribl.com/nic/CHINA_SPRINGBOARD_INC_.html" target="_blank"> Listed Domains registered at CHINA SPRINGBOARD INC.</a></span></h2>
<p>	Domain  	Date/Time Added</p>
<p>#1	orgarnuveros.net	Sat, 21 Nov 2009 08:36:39 +0000</p>
<p>#2	elitevips24.net	Sat, 21 Nov 2009 08:10:07 +0000</p>
<p>#3	hotcan.net	Sat, 21 Nov 2009 08:07:02 +0000</p>
<p>#4	willcan.net	Sat, 21 Nov 2009 07:59:22 +0000</p>
<p>#5	amazedshopp.com	Sat, 21 Nov 2009 07:57:58 +0000</p>
<p>#6	kingspingame.net	Sat, 21 Nov 2009 07:54:08 +0000</p>
<p>#7	himgold.net	Sat, 21 Nov 2009 07:27:41 +0000</p>
<p>#8	ardiromabos.net	Sat, 21 Nov 2009 07:18:50 +0000</p>
<p>#9	createlamp.com	Sat, 21 Nov 2009 07:07:02 +0000</p>
<p>#10	feverhandle.com	Sat, 21 Nov 2009 07:05:59 +0000</p>
<p>#11	orpeak.com	Sat, 21 Nov 2009 07:04:40 +0000</p>
<p>#12	raisenoon.com	Sat, 21 Nov 2009 07:00:31 +0000</p>
<p>#13	drawroad.com	Sat, 21 Nov 2009 06:45:14 +0000</p>
<p>#14	urketoniafos.net	Sat, 21 Nov 2009 06:21:11 +0000</p>
<p>#15	lifttotal.com	Sat, 21 Nov 2009 06:12:14 +0000</p>
<p>#16	grassaroma.com	Sat, 21 Nov 2009 06:11:17 +0000</p>
<p>#17	yellowwere.com	Sat, 21 Nov 2009 05:53:22 +0000</p>
<p>#18	appearfill.com	Sat, 21 Nov 2009 05:40:04 +0000</p>
<p>#19	shegot.net	Sat, 21 Nov 2009 05:38:01 +0000</p>
<p>#20	agreesoil.com	Sat, 21 Nov 2009 05:31:01 +0000</p>
<p>#21	daringday.com	Sat, 21 Nov 2009 04:47:44 +0000</p>
<p>#22	himnot.net	Sat, 21 Nov 2009 04:18:05 +0000</p>
<p>#23	kiropadonts.net	Sat, 21 Nov 2009 04:16:32 +0000</p>
<p>#24	gameroyalruby.net	Sat, 21 Nov 2009 02:09:38 +0000</p>
<p>#25	gamerubyroyal.net	Sat, 21 Nov 2009 02:08:26 +0000</p>
<p>#26	cheap-rx4u.com	Sat, 21 Nov 2009 02:06:19 +0000</p>
<p>#27	drawrain.com	Sat, 21 Nov 2009 01:40:00 +0000</p>
<p>#28	findthemmedsherenow.com	Sat, 21 Nov 2009 01:34:36 +0000</p>
<p>#29	superbmove.com	Sat, 21 Nov 2009 00:51:39 +0000</p>
<p>#30	meds-for-you-today.com	Fri, 20 Nov 2009 22:07:15 +0000</p>
<p>#31	meds-for-you-now.com	Fri, 20 Nov 2009 21:54:25 +0000</p>
<p>#32	refill-your-meds-today.com	Fri, 20 Nov 2009 21:43:57 +0000</p>
<p>#33	rx-refill-now.com	Fri, 20 Nov 2009 21:43:42 +0000</p>
<p>#34	your-rx-for-cheap.com	Fri, 20 Nov 2009 21:43:31 +0000</p>
<p>#35	fastest-rx-today.com	Fri, 20 Nov 2009 21:42:44 +0000</p>
<p>#36	bestquality-rx-today.com	Fri, 20 Nov 2009 21:40:43 +0000</p>
<p>#37	refill-all-meds.com	Fri, 20 Nov 2009 21:39:44 +0000</p>
<p>#38	no-doctor-wait.com	Fri, 20 Nov 2009 21:39:23 +0000</p>
<p>#39	meds-for-cheap.com	Fri, 20 Nov 2009 21:39:10 +0000</p>
<p>#40	medicine-daily.com	Fri, 20 Nov 2009 21:21:19 +0000</p>
<p>#41	kinggamespin.net	Fri, 20 Nov 2009 20:29:24 +0000</p>
<p>#42	ospakyrekass.net	Fri, 20 Nov 2009 19:21:47 +0000</p>
<p>#43	booststrong.com	Fri, 20 Nov 2009 18:02:30 +0000</p>
<p>#44	tellbold.com	Fri, 20 Nov 2009 16:36:11 +0000</p>
<p>#45	hopedisc.com	Fri, 20 Nov 2009 16:14:30 +0000</p>
<p>#46	hopestable.com	Fri, 20 Nov 2009 16:01:36 +0000</p>
<p>#47	posterlobndon1.com	Fri, 20 Nov 2009 15:34:33 +0000</p>
<p>#48	hopecreate.com	Fri, 20 Nov 2009 14:55:45 +0000</p>
<p>#49	unedomergods.net	Fri, 20 Nov 2009 14:30:02 +0000</p>
<p>#50	suffixbits.com	Fri, 20 Nov 2009 12:49:16 +0000</p>
<p>#51	fuperasconts.net	Fri, 20 Nov 2009 10:24:06 +0000</p>
<p>#52	meatyear.com	Fri, 20 Nov 2009 09:52:00 +0000</p>
<p>#53	drugqualitybread.com	Fri, 20 Nov 2009 08:59:30 +0000</p>
<p>#54	desirejump.com	Fri, 20 Nov 2009 07:54:15 +0000</p>
<p>#55	vurtersonats.net	Fri, 20 Nov 2009 05:02:42 +0000</p>
<p>#56	titodarombs.net	Fri, 20 Nov 2009 03:23:57 +0000</p>
<p>#57	flushlamp.com	Fri, 20 Nov 2009 03:08:54 +0000</p>
<p>#58	saltroot.com	Fri, 20 Nov 2009 02:15:00 +0000</p>
<p>#59	themjoy.com	Fri, 20 Nov 2009 01:51:29 +0000</p>
<p>#60	nutrition-lab.com	Fri, 20 Nov 2009 01:32:55 +0000</p>
<p>#61	vagrstore.com	Fri, 20 Nov 2009 00:59:05 +0000</p>
<p>#62	winterfour.com	Thu, 19 Nov 2009 22:09:34 +0000</p>
<p>#63	resultdeep.com	Thu, 19 Nov 2009 22:05:23 +0000</p>
<p>#64	basican.com	Thu, 19 Nov 2009 21:19:07 +0000</p>
<p>#65	gladend.com	Thu, 19 Nov 2009 19:59:08 +0000</p>
<p>#66	zondubaris.net	Thu, 19 Nov 2009 19:13:17 +0000</p>
<p>#67	eatspeech.com	Thu, 19 Nov 2009 17:15:42 +0000</p>
<p>#68	checkhumane.com	Thu, 19 Nov 2009 17:10:39 +0000</p>
<p>#69	logbright.com	Thu, 19 Nov 2009 17:07:16 +0000</p>
<p>#70	whoserope.com	Thu, 19 Nov 2009 17:03:29 +0000</p>
<p>#71	verbstreet.com	Thu, 19 Nov 2009 16:59:20 +0000</p>
<p>#72	indastorgus.net	Thu, 19 Nov 2009 16:54:06 +0000</p>
<p>#73	juicymore.com	Thu, 19 Nov 2009 16:52:41 +0000</p>
<p>#74	seetail.com	Thu, 19 Nov 2009 16:34:08 +0000</p>
<p>#75	boostjoin.com	Thu, 19 Nov 2009 16:20:27 +0000</p>
<p>#76	placelowly.com	Thu, 19 Nov 2009 13:06:21 +0000</p>
<p>#77	freshwife.com	Thu, 19 Nov 2009 12:52:56 +0000</p>
<p>#78	greatroyalplay.net	Thu, 19 Nov 2009 10:24:48 +0000</p>
<p>#79	gameeuroland.net	Thu, 19 Nov 2009 10:22:18 +0000</p>
<p>#80	gamelandeuro.net	Thu, 19 Nov 2009 10:11:04 +0000</p>
<p>#81	landgameeuro.net	Thu, 19 Nov 2009 10:06:43 +0000</p>
<p>#82	fabledblue.com	Thu, 19 Nov 2009 09:45:13 +0000</p>
<p>#83	flushhot.com	Thu, 19 Nov 2009 07:33:31 +0000</p>
<p>#84	melukorasors.net	Thu, 19 Nov 2009 07:20:40 +0000</p>
<p>#85	cheapermedicine2009.com	Thu, 19 Nov 2009 06:56:52 +0000</p>
<p>#86	milkcome.com	Thu, 19 Nov 2009 06:27:16 +0000</p>
<p>#87	77-33.com	Thu, 19 Nov 2009 05:23:30 +0000</p>
<p>#88	pressdouble.com	Thu, 19 Nov 2009 05:09:37 +0000</p>
<p>#89	cutermorads.net	Thu, 19 Nov 2009 04:59:21 +0000</p>
<p>#90	royalplaygreat.net	Thu, 19 Nov 2009 03:21:02 +0000</p>
<p>#91	casinokingspin.net	Thu, 19 Nov 2009 02:21:07 +0000</p>
<p>#92	luxuryplayeuro.net	Thu, 19 Nov 2009 02:12:44 +0000</p>
<p>#93	movewant.com	Thu, 19 Nov 2009 01:56:19 +0000</p>
<p>#94	hadwheel.com	Thu, 19 Nov 2009 01:52:27 +0000</p>
<p>#95	flushsheet.com	Thu, 19 Nov 2009 01:46:28 +0000</p>
<p>#96	multidry.com	Thu, 19 Nov 2009 00:08:59 +0000</p>
<p>#97	scorelength.com	Wed, 18 Nov 2009 22:37:33 +0000</p>
<p>#98	trucktrue.com	Wed, 18 Nov 2009 21:38:20 +0000</p>
<p>#99	politemodest.com	Wed, 18 Nov 2009 21:27:48 +0000</p>
<p>#100	belowcostrx.com	Wed, 18 Nov 2009 21:19:36 +0000</p>
<p>#101	pressroot.com	Wed, 18 Nov 2009 21:08:54 +0000</p>
<p>#102	nalbox.net	Wed, 18 Nov 2009 21:00:07 +0000</p>
<p>#103	zirdobalkons.net	Wed, 18 Nov 2009 20:58:30 +0000</p>
<p>#104	playcasinostars.net	Wed, 18 Nov 2009 20:55:47 +0000</p>
<p>#105	playstarscasino.net	Wed, 18 Nov 2009 20:55:32 +0000</p>
<p>#106	casinoplaystars.net	Wed, 18 Nov 2009 20:53:46 +0000</p>
<p>#107	ormeant.com	Wed, 18 Nov 2009 18:53:08 +0000</p>
<p>#108	miomerandos.net	Wed, 18 Nov 2009 18:03:19 +0000</p>
<p>#109	pickthan.com	Wed, 18 Nov 2009 17:48:22 +0000</p>
<p>#110	staybegan.com	Wed, 18 Nov 2009 17:47:53 +0000</p>
<p>#111	gamevegasopen.net	Wed, 18 Nov 2009 17:46:23 +0000</p>
<p>#112	leddoes.com	Wed, 18 Nov 2009 16:20:18 +0000</p>
<p>#113	nightyour.com	Wed, 18 Nov 2009 14:46:54 +0000</p>
<p>#114	eurodicegreat.net	Wed, 18 Nov 2009 14:44:15 +0000</p>
<p>#115	camelocate.com	Wed, 18 Nov 2009 13:26:33 +0000</p>
<p>#116	ogieromass.net	Wed, 18 Nov 2009 12:45:13 +0000</p>
<p>#117	appearpast.com	Wed, 18 Nov 2009 12:10:18 +0000</p>
<p>#118	yourcodeine.com	Wed, 18 Nov 2009 11:00:38 +0000</p>
<p>#119	longtangy.com	Wed, 18 Nov 2009 10:40:06 +0000</p>
<p>#120	greatrxcatch.com	Wed, 18 Nov 2009 07:42:00 +0000</p>
<p>#121	makeylate.com	Wed, 18 Nov 2009 07:12:37 +0000</p>
<p>#122	feromanos.net	Wed, 18 Nov 2009 06:20:46 +0000</p>
<p>#123	solvetable.com	Wed, 18 Nov 2009 06:08:56 +0000</p>
<p>#124	extrafar.com	Wed, 18 Nov 2009 06:04:13 +0000</p>
<p>#125	doesmother.com	Wed, 18 Nov 2009 05:15:49 +0000</p>
<p>#126	tipbull.net	Wed, 18 Nov 2009 04:57:42 +0000</p>
<p>#127	software777.net	Wed, 18 Nov 2009 04:49:31 +0000</p>
<p>#128	33-66.com	Wed, 18 Nov 2009 04:43:30 +0000</p>
<p>#129	remtuplasoms.net	Wed, 18 Nov 2009 04:01:04 +0000</p>
<p>#130	redthey.com	Wed, 18 Nov 2009 03:37:56 +0000</p>
<p>#131	soundmy.com	Wed, 18 Nov 2009 02:34:57 +0000</p>
<p>#132	eagerpotent.com	Wed, 18 Nov 2009 01:47:56 +0000</p>
<p>#133	whenhas.com	Wed, 18 Nov 2009 01:41:40 +0000</p>
<p>#134	getrxeasilyonline.com	Wed, 18 Nov 2009 01:41:31 +0000</p>
<p>#135	tiodarombs.net	Wed, 18 Nov 2009 01:39:18 +0000</p>
<p>#136	portekohios.net	Wed, 18 Nov 2009 00:12:13 +0000</p>
<p>#137	drinkspicy.com	Tue, 17 Nov 2009 23:10:19 +0000</p>
<p>#138	glassgot.com	Tue, 17 Nov 2009 22:17:11 +0000</p>
<p>#139	cardpose.com	Tue, 17 Nov 2009 21:18:57 +0000</p>
<p>#140	numboklavers.net	Tue, 17 Nov 2009 20:54:22 +0000</p>
<p>#141	silentdaring.com	Tue, 17 Nov 2009 20:14:37 +0000</p>
<p>#142	readyadore.com	Tue, 17 Nov 2009 19:23:25 +0000</p>
<p>#143	edsherebuy.com	Tue, 17 Nov 2009 19:05:28 +0000</p>
<p>#144	mostyard.com	Tue, 17 Nov 2009 18:48:49 +0000</p>
<p>#145	greatgameeuro.net	Tue, 17 Nov 2009 18:44:43 +0000</p>
<p>#146	gamegreateuro.net	Tue, 17 Nov 2009 18:34:51 +0000</p>
<p>#147	fabrecord.com	Tue, 17 Nov 2009 17:11:42 +0000</p>
<p>#148	casinobeststars.net	Tue, 17 Nov 2009 17:02:24 +0000</p>
<p>#149	boldsecond.com	Tue, 17 Nov 2009 15:36:59 +0000</p>
<p>#150	ageshore.com	Tue, 17 Nov 2009 15:20:50 +0000</p>
<p>#151	drugsearl93.net	Tue, 17 Nov 2009 14:28:50 +0000</p>
<p>#152	commoncatch.com	Tue, 17 Nov 2009 14:23:29 +0000</p>
<p>#153	grepondass.net	Tue, 17 Nov 2009 13:34:10 +0000</p>
<p>#154	luxurygreatroyal.net	Tue, 17 Nov 2009 11:45:04 +0000</p>
<p>#155	samcorefos.net	Tue, 17 Nov 2009 11:22:26 +0000</p>
<p>#156	eagerfour.com	Tue, 17 Nov 2009 10:37:33 +0000</p>
<p>#157	cookfeel.com	Tue, 17 Nov 2009 08:54:29 +0000</p>
<p>#158	onlineseth2.net	Tue, 17 Nov 2009 08:39:30 +0000</p>
<p>#159	quartbeat.com	Tue, 17 Nov 2009 07:21:54 +0000</p>
<p>#160	drugsedwin62.net	Tue, 17 Nov 2009 07:05:02 +0000</p>
<p>#161	coreinovels.net	Tue, 17 Nov 2009 06:39:57 +0000</p>
<p>#162	royalrubycasino.net	Tue, 17 Nov 2009 06:27:00 +0000</p>
<p>#163	rubycasinoroyal.net	Tue, 17 Nov 2009 06:23:48 +0000</p>
<p>#164	rubdoes.com	Tue, 17 Nov 2009 05:56:36 +0000</p>
<p>#165	valuenight.com	Tue, 17 Nov 2009 05:42:32 +0000</p>
<p>#166	cropafter.com	Tue, 17 Nov 2009 04:54:29 +0000</p>
<p>#167	zoportovukas.net	Tue, 17 Nov 2009 04:50:50 +0000</p>
<p>#168	novirgomers.net	Tue, 17 Nov 2009 03:17:06 +0000</p>
<p>#169	tiechange.com	Tue, 17 Nov 2009 02:52:49 +0000</p>
<p>#170	topcheap-ed.com	Tue, 17 Nov 2009 02:20:59 +0000</p>
<p>#171	foundcase.com	Tue, 17 Nov 2009 02:15:41 +0000</p>
<p>#172	refillstorerxnow.com	Tue, 17 Nov 2009 01:57:41 +0000</p>
<p>#173	mainmakey.com	Tue, 17 Nov 2009 01:48:47 +0000</p>
<p>#174	fishhope.com	Tue, 17 Nov 2009 01:45:00 +0000</p>
<p>#175	quality-codeines.com	Tue, 17 Nov 2009 01:38:37 +0000</p>
<p>#176	elaboratesz.com	Tue, 17 Nov 2009 01:35:10 +0000</p>
<p>#177	readywe.com	Tue, 17 Nov 2009 01:29:30 +0000</p>
<p>#178	wirtokrages.net	Tue, 17 Nov 2009 01:06:23 +0000</p>
<p>#179	printhumane.com	Tue, 17 Nov 2009 00:02:23 +0000</p>
<p>#180	vrigolosams.net	Mon, 16 Nov 2009 23:56:45 +0000</p>
<p>#181	pharmtowney21.net	Mon, 16 Nov 2009 23:18:57 +0000</p>
<p>#182	kingspincasino.net	Mon, 16 Nov 2009 22:23:44 +0000</p>
<p>#183	kingcasinospin.net	Mon, 16 Nov 2009 22:20:04 +0000</p>
<p>#184	mouthmighty.com	Mon, 16 Nov 2009 21:03:28 +0000</p>
<p>#185	safeextra.com	Mon, 16 Nov 2009 20:57:17 +0000</p>
<p>#186	alsoof.com	Mon, 16 Nov 2009 18:03:00 +0000</p>
<p>#187	sidethey.com	Mon, 16 Nov 2009 17:40:27 +0000</p>
<p>#188	elite2009-jackpots.com	Mon, 16 Nov 2009 17:02:41 +0000</p>
<p>#189	rollmonth.com	Mon, 16 Nov 2009 16:36:17 +0000</p>
<p>#190	termdoes.com	Mon, 16 Nov 2009 15:03:46 +0000</p>
<p>#191	vanishhold.com	Mon, 16 Nov 2009 14:09:12 +0000</p>
<p>#192	starscasino888.net	Mon, 16 Nov 2009 14:08:57 +0000</p>
<p>#193	exactcome.com	Mon, 16 Nov 2009 14:04:52 +0000</p>
<p>#194	germinatbig.com	Mon, 16 Nov 2009 13:49:38 +0000</p>
<p>#195	awareplay.com	Mon, 16 Nov 2009 13:44:09 +0000</p>
<p>#196	vurtesonats.net	Mon, 16 Nov 2009 11:25:13 +0000</p>
<p>#197	rootmunchy.com	Mon, 16 Nov 2009 10:54:48 +0000</p>
<p>#198	luxuryroyalgreat.net	Mon, 16 Nov 2009 10:38:50 +0000</p>
<p>#199	royalgreatluxury.net	Mon, 16 Nov 2009 10:21:27 +0000</p>
<p>#200	kiropladonts.net	Mon, 16 Nov 2009 10:19:31 +0000</p>
<p>#201	playeuroluxury.net	Mon, 16 Nov 2009 09:51:31 +0000</p>
<p>#202	storychaste.com	Mon, 16 Nov 2009 08:58:53 +0000</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Internet Security Trends – A Look Back at 2009, A Look Ahead to 2010]]></title>
<link>http://blog.webroot.com/2009/11/20/internet-security-trends-%e2%80%93-a-look-back-at-2009-a-look-ahead-to-2010/</link>
<pubDate>Fri, 20 Nov 2009 21:29:03 +0000</pubDate>
<dc:creator>gerhardeschelbeck</dc:creator>
<guid>http://blog.webroot.com/2009/11/20/internet-security-trends-%e2%80%93-a-look-back-at-2009-a-look-ahead-to-2010/</guid>
<description><![CDATA[By Gerhard Eschelbeck It&#8217;s been a busy year in Internet security &#8212; cybercriminals were c]]></description>
<content:encoded><![CDATA[By Gerhard Eschelbeck It&#8217;s been a busy year in Internet security &#8212; cybercriminals were c]]></content:encoded>
</item>
<item>
<title><![CDATA[Safest Web Browser - IE8]]></title>
<link>http://techpaul.wordpress.com/2009/11/20/safest-web-browser-ie8/</link>
<pubDate>Fri, 20 Nov 2009 19:40:46 +0000</pubDate>
<dc:creator>techpaul</dc:creator>
<guid>http://techpaul.wordpress.com/2009/11/20/safest-web-browser-ie8/</guid>
<description><![CDATA[Internet Explorer 8 Tops Safety Testing Test The primary way cyber-criminals do their dirty deeds ]]></description>
<content:encoded><![CDATA[Internet Explorer 8 Tops Safety Testing Test The primary way cyber-criminals do their dirty deeds ]]></content:encoded>
</item>
<item>
<title><![CDATA[ING-klanten doelwit phishingaanval]]></title>
<link>http://ovis1964.wordpress.com/2009/11/20/ing-klanten-doelwit-phishingaanval/</link>
<pubDate>Fri, 20 Nov 2009 07:31:00 +0000</pubDate>
<dc:creator>ovis</dc:creator>
<guid>http://ovis1964.wordpress.com/2009/11/20/ing-klanten-doelwit-phishingaanval/</guid>
<description><![CDATA[Klanten van de ING zijn opnieuw het doelwit van een phishingaanval die inspeelt op de &#8220;migrati]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Klanten van de ING zijn opnieuw het doelwit van een phishingaanval die inspeelt op de &#8220;migratie&#8221; tussen de Postbank. &#8220;Vanwege de migratie tussen Postbank en ING verzoeken wij u eenmalig uw primair IP-adres te bevestigen&#8221;, zo is in de e-mail te lezen, waarvan inmiddels al vijf varianten zijn rondgegaan. </p>
<p><a href="http://www.security.nl/artikel/31517/1/ING-klanten_doelwit_phishingaanval.html">   Lees meer</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Phishing scams]]></title>
<link>http://parkviewresidents.wordpress.com/2009/11/20/phishing-scams/</link>
<pubDate>Fri, 20 Nov 2009 07:01:07 +0000</pubDate>
<dc:creator>Johanna Kaschke</dc:creator>
<guid>http://parkviewresidents.wordpress.com/2009/11/20/phishing-scams/</guid>
<description><![CDATA[Currently I am getting an enormous amount of phishing e-mails and they usually go to huge mailing li]]></description>
<content:encoded><![CDATA[Currently I am getting an enormous amount of phishing e-mails and they usually go to huge mailing li]]></content:encoded>
</item>
<item>
<title><![CDATA[Phishing]]></title>
<link>http://johnsuddath.wordpress.com/2009/11/19/phishing/</link>
<pubDate>Thu, 19 Nov 2009 15:10:23 +0000</pubDate>
<dc:creator>johnsuddath</dc:creator>
<guid>http://johnsuddath.wordpress.com/2009/11/19/phishing/</guid>
<description><![CDATA[Several weeks ago I got an email query about my bank account that raised my suspicion.  It had the B]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Several weeks ago I got an email query about my bank account that raised my suspicion.  It had the Bank of America logo and some information, but it requested more information about my account.  That raised a red flag, and I did not respond and forwarded it to the fraud department at Earthlink.</p>
<p>Unfortunately, when I came home late Tuesday night from a meeting and was checking my email, I found an email from Earthlink with a notice about an upgrade to the software.  It requested my password to complete the upgrade.  As tired as I was, I responded without thinking—and you guessed it.  Some spam operator compromised my account and stole my password.  When I tried to access my account the next day, I was locked out because the operator was sending out spam using my account. I had to call Earthlink.  They already were aware of the problem, and that&#8217;s why they had cut me off.  When I provided adequate information that I was the owner of the account, the support person gave me a new password and reset the account.   As far as I know, the spam didn&#8217;t go to the accounts in my address book.  If it did, please let me know.</p>
<p>All this raises the question of Internet security.  Since I use a Macintosh, I don&#8217;t have the problems with viruses that plague Windows users, but I guess that has made me lax about other security issues.  We all get bogus offers in the mail and on the phone (even though I&#8217;m on the &#8220;do-not-call&#8221; list).  I&#8217;ve been fortunate that my credit card information has never been compromised even though I buy a lot of stuff online.</p>
<p>My three web sites and blog are all inter-linked and tied to my email account.  I also have a Yahoo email account that I use only for a few groups, and a Google email account that I never use, and a Mobile Me account.  My Earthlink service does a good job of scanning junk mail so ordinarily it isn&#8217;t a problem, but they missed this one.</p>
<p>The point is that while we don&#8217;t want to become paranoid, it&#8217;s not a benign world out there on the web.  Since I&#8217;m spread all over the web, my personal information is readily available.  I want potential clients to be able to contact me easily, but I don&#8217;t want my identity to be compromised.  It&#8217;s a delicate balance.</p>
<p>What&#8217;s your experience?</p>
<p>&#160;</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SecuriTeam Blogs » Is it phish, or is it Amex?]]></title>
<link>http://cyberthreat.wordpress.com/2009/11/19/securiteam-blogs-%c2%bb-is-it-phish-or-is-it-amex/</link>
<pubDate>Thu, 19 Nov 2009 13:29:26 +0000</pubDate>
<dc:creator>pmakohon</dc:creator>
<guid>http://cyberthreat.wordpress.com/2009/11/19/securiteam-blogs-%c2%bb-is-it-phish-or-is-it-amex/</guid>
<description><![CDATA[SecuriTeam Blogs » Is it phish, or is it Amex?: &#8221; SecuriTeam Home Is it phish, or is it Amex? ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><a href="http://blogs.securiteam.com/index.php/archives/1328">SecuriTeam Blogs » Is it phish, or is it Amex?</a>: &#8221; SecuriTeam Home</p>
<p>Is it phish, or is it Amex?<br />
November 4th, 2009 by p1, Filed under: Commentary, Privacy, Spam, Culture, Phishing, Corporate Security<br />
I am a bit freaked.<br />
Last month I received an email message from American Express.  I very nearly deleted it unread: it was obviously phish, right?  (I was teaching in Toronto that week, so I had even more reason to turf it unread rather than look at it.)<br />
However, since I do have an Amex card, I decided to at least have a look at it, and possibly try and find some way to send it to them.  So I looked at it.<br />
And promptly freaked out.<br />
The phishers had my card number.  (Or, at least, the last five digits of it.)  They knew the due date of my statement.  The knew the balance amount of my last statement.<br />
(The fact that this was all happening while I am aware from home wasn’t making me feel any more comfortable with it …)<br />
So I had a look at the headers.  And couldn’t find a single thing indicating that this wasn’t from American Express.<br />
(I &#8220;</p>
<p>(Via <a href=""></a>.)</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Phishing is a major security problem! Good info from CNET - FAQ: Recognizing phishing e-mails]]></title>
<link>http://davehatter.wordpress.com/2009/11/18/phishing-is-a-major-security-problem-good-info-from-cnet-faq-recognizing-phishing-e-mails/</link>
<pubDate>Wed, 18 Nov 2009 20:13:55 +0000</pubDate>
<dc:creator>davehatter</dc:creator>
<guid>http://davehatter.wordpress.com/2009/11/18/phishing-is-a-major-security-problem-good-info-from-cnet-faq-recognizing-phishing-e-mails/</guid>
<description><![CDATA[http://news.cnet.com/8301-27080_3-10396786-245.html?tag=nl.e404]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><a href="http://news.cnet.com/8301-27080_3-10396786-245.html?tag=nl.e404" target="_blank">http://news.cnet.com/8301-27080_3-10396786-245.html?tag=nl.e404</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Overlay banking or phishing/man-in-the-middle attack?]]></title>
<link>http://maarten.wegdam.name/2009/11/18/overlay-banking-or-phishingman-in-the-middle-attack/</link>
<pubDate>Wed, 18 Nov 2009 20:08:33 +0000</pubDate>
<dc:creator>Maarten Wegdam</dc:creator>
<guid>http://maarten.wegdam.name/2009/11/18/overlay-banking-or-phishingman-in-the-middle-attack/</guid>
<description><![CDATA[Today I learned that there is such a thing as overlay banking, which provides a way to pay in websho]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Today I learned that there is such a thing as overlay banking, which provides a way to pay in webshops through your online banking system. Contrary to how in the Netherlands popular iDeal system works, with overlay banking you provide your credentials (including a one-time-password/TAN code)  to a hopefully trusted third party. Technically, you could say this third party is very similar to someone doing a man-in-the-middle attack. The Dutch National Bank and others expressed their <a href="http://www.dnb.nl/en/news-and-publications/news-and-archive/nieuws-2009/dnb224684.jsp">concerns</a> about this, and I completely agree. Although I can imagine that the specific party providing this overlay banking service (the <a href="http://www.payment-network.com/">German Payment Networking</a>) may very well be trustworthy, one should of course never give ones credentials to a third party. There are many technical solutions to avoid this (e.g., OAuth), and let someone act on your behalf without having to give them your credentials. What worries me most is that this may educate people to be more susceptible to phishing and man-in-the-middle attacks!  Apparently Payment Networking <a href="http://webwereld.nl/nieuws/64303/ideal-kloon--ons-systeem-is-niet-onveilig.html">disagrees</a> (article in Dutch), and considers their system secure because they adhere to high security standards. This does not however take my &#8216;educating people to do the wrong thing&#8217; concern away.<br />
Of course, one may also argue that in addition to raising concerns about overlay banking, the European banks should speed up the process of standardizing interfaces that allow competing international online payment systems. I can imagine that overlay banking is simple a way to provide cheap online payment, and with proper standards and fair competition, this should be possible without the above described security risks.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Faux "Verified By Visa" Phishing Scam Targets Holiday Shoppers]]></title>
<link>http://blog.webroot.com/2009/11/18/faux-verified-by-visa-phishing-scam-targets-holiday-shoppers/</link>
<pubDate>Wed, 18 Nov 2009 17:49:45 +0000</pubDate>
<dc:creator>Andrew Brandt</dc:creator>
<guid>http://blog.webroot.com/2009/11/18/faux-verified-by-visa-phishing-scam-targets-holiday-shoppers/</guid>
<description><![CDATA[By Andrew Brandt When you sign up for a credit card &#8212; even with one of those pre-approved appl]]></description>
<content:encoded><![CDATA[By Andrew Brandt When you sign up for a credit card &#8212; even with one of those pre-approved appl]]></content:encoded>
</item>
<item>
<title><![CDATA[L'aube de la guerre numérique par McAfee]]></title>
<link>http://scteam.wordpress.com/2009/11/18/laube-de-la-guerre-numerique-par-mcafee/</link>
<pubDate>Wed, 18 Nov 2009 16:40:15 +0000</pubDate>
<dc:creator>ju4n1t0</dc:creator>
<guid>http://scteam.wordpress.com/2009/11/18/laube-de-la-guerre-numerique-par-mcafee/</guid>
<description><![CDATA[&#8220;Jusqu&#8217;ici, les rapports de criminologie virtuelle McAfee publiés chaque année s&#8217;i]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p style="text-align:center;"><img class="aligncenter" src="http://www.ecrans.fr/local/cache-vignettes/L450xH302/arton2548-8ab3f.jpg" alt="" width="448" height="301" /></p>
<p>&#8220;<em>Jusqu&#8217;ici, les rapports de criminologie virtuelle McAfee publiés chaque année s&#8217;intéressaient plutôt aux méthodes, aux cibles et aux comportements des cybercriminels.</em></p>
<p><em>Pourtant, à l&#8217;époque où nous rédigions le rapport 2007 déjà, de nombreux experts faisaient observer que, non contents de s&#8217;espionner mutuellement dans le cyberespace, certains Etats développaient des techniques d&#8217;attaque informatique toujours plus sophistiquées. </em></p>
<p><em>Depuis la publication de ce rapport, le concept de cyberguerre revient régulièrement au centre des débats face à la multiplication des attaques et des intrusions réseau apparemment motivées par des objectifs politiques et non plus par le profit, ce qui les distingue incontestablement du cybercrime à proprement parler.</em></p>
<p><em> Dans le rapport de cette année, nous avons donc décidé de nous pencher sur l&#8217;éventualité d&#8217;une guerre menée au coeur du cyberespace.</em>&#8220;</p>
<p>McAfee</p>
<p><a href="http://www.01net.com/Pdf_01net/6735rpt_virtual_criminology_1009_fr_fnl_lores.pdf" target="_blank">http://www.01net.com/Pdf_01net/6735rpt_virtual_criminology_1009_fr_fnl_lores.pdf</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[10 extensions Firefox pour bien se protéger par ZDNet.fr]]></title>
<link>http://scteam.wordpress.com/2009/11/18/10-extensions-firefox-pour-bien-se-proteger-par-zdnet-fr/</link>
<pubDate>Wed, 18 Nov 2009 14:49:41 +0000</pubDate>
<dc:creator>ju4n1t0</dc:creator>
<guid>http://scteam.wordpress.com/2009/11/18/10-extensions-firefox-pour-bien-se-proteger-par-zdnet-fr/</guid>
<description><![CDATA[Vérification des certificats de sécurité, identification des sites à risque, authentification anonym]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img class="alignnone" src="https://addons.mozilla.org/img/amo2009/app-icons/firefox.png" alt="" width="73" height="77" /></p>
<p>Vérification des certificats de sécurité, identification des sites à risque, authentification anonyme, détection des sites de phishing et des fichiers malveillants… ZDNet.fr sélectionne 10 extensions pour protéger sa navigation sur Firefox.</p>
<p>Suivez le guide &#62;&#62; <a href="http://www.zdnet.fr/galerie-image/0,50018840,39710824,00.htm" target="_blank">ZDNet.fr</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spam demenziale]]></title>
<link>http://aghost.wordpress.com/2009/11/18/spam-demenziale/</link>
<pubDate>Wed, 18 Nov 2009 08:21:08 +0000</pubDate>
<dc:creator>aghost</dc:creator>
<guid>http://aghost.wordpress.com/2009/11/18/spam-demenziale/</guid>
<description><![CDATA[Certo in e-mail, quanto a spam e phishing, ne arrivano davvero di cotte e di crude. A volte i messag]]></description>
<content:encoded><![CDATA[Certo in e-mail, quanto a spam e phishing, ne arrivano davvero di cotte e di crude. A volte i messag]]></content:encoded>
</item>
<item>
<title><![CDATA[Les Spams en famille]]></title>
<link>http://fqdn.fr/2009/11/17/les-spams-en-famille/</link>
<pubDate>Tue, 17 Nov 2009 10:43:54 +0000</pubDate>
<dc:creator>fqdn</dc:creator>
<guid>http://fqdn.fr/2009/11/17/les-spams-en-famille/</guid>
<description><![CDATA[Les Spams sont des courriers électroniques illicites, déjà par leur nombre d’envoi qui ne respecte p]]></description>
<content:encoded><![CDATA[Les Spams sont des courriers électroniques illicites, déjà par leur nombre d’envoi qui ne respecte p]]></content:encoded>
</item>
<item>
<title><![CDATA[InBank: un phishing con accesso incorporato]]></title>
<link>http://truffeinrete.wordpress.com/2009/11/17/inbank-un-phishing-con-accesso-incorporato/</link>
<pubDate>Tue, 17 Nov 2009 09:18:43 +0000</pubDate>
<dc:creator>truffeinrete09</dc:creator>
<guid>http://truffeinrete.wordpress.com/2009/11/17/inbank-un-phishing-con-accesso-incorporato/</guid>
<description><![CDATA[Per aggirare i sistemi di protezione antiphishing alcune e-mail contengono un regalino sottoforma di]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p style="text-align:justify;">Per aggirare i sistemi di protezione antiphishing alcune e-mail contengono un regalino sottoforma di allegato; in questo allegato si trova una pagina web salvata in formato MHT (pagina web completa)  che contiene la copia esatta della videata di accesso al sistema online della banca.</p>
<p style="text-align:justify;">La differenza rispetto al phishing &#8220;tradizionale&#8221;, dove bisogna cliccare per andare su un sito fasullo, consiste nel fatto che l&#8217;allegato dell&#8217;email contiene una pagina web perfettamente funzionante nella quale vi viene richiesto di inserire direttamente utente e password, senza necessità di cliccare su un link, che potrebbe essere intercettato e bloccato dai sistemi di protezione antiphishing.</p>
<p style="text-align:justify;">Inutile dire dove finiranno i dati una volta inseriti&#8230;.</p>
<p style="text-align:justify;">Nei casi peggiori l&#8217;apertura dell&#8217;allegato può provocare anche l&#8217;esecuzione di un codice malevolo che può installare del malware nel vostro computer.</p>
<p>Ecco il testo di una email di questo tipo:</p>
<p><em>Da: Phoenix Informatica Bancaria  S.p.A<br />
[mailto:assistenza_ib@in-bank-online.net]<br />
Inviato: lunedì 16  novembre 2009 16.01<br />
Oggetto: Comunicazioni dalla Banca dal 16 Novembre  2009<br />
Priorità: Alta</em></p>
<p><em>Gentile Cliente,<br />
Un nuovo documento di  rendicontazione e a sua disposizione.<br />
Potre consultarlo e salvarlo sul suo PC  entro un anno da oggi, visitando<br />
l&#8217;area Estratto conto e documentazione dei  suoi Servizi via internet.<br />
Per l&#8217;assistenza ai Servizi via internet puo  contattare il numero verde<br />
800.827.455, gratuito anche da  cellulare.<br />
Cordiali saluti.<br />
Servizio Banca di Credito Cooperativo  Online<br />
&#8212;<br />
Questo e un messaggio automatico.<br />
Per disabilitare il  servizio puo utilizzare la funzione Modifica<br />
abilitazioni (Comunicazioni &#62;  Estratto conto e documentazione).</em></p>
<p><em>Copyright © Banca di Credito  Cooperativo S.p.A</em></p>
<p>L&#8217;allegato, una volta aperto, si presenta così:</p>
<p><a rel="attachment wp-att-362" href="http://truffeinrete.wordpress.com/2009/11/17/inbank-un-phishing-con-accesso-incorporato/phoenix-informatica-bancaria/"><img class="aligncenter size-full wp-image-362" title="Phoenix Informatica Bancaria" src="http://truffeinrete.wordpress.com/files/2009/11/phoenix-informatica-bancaria.jpg" alt="" width="450" height="270" /></a></p>
<p>La pagina web dentro l&#8217;allegato è &#8216;attiva&#8217; nel senso che consente di inserire utente e password (in alto a destra).</p>
<p>L&#8217;indirizzo web che si nasconde dietro i campi della pagina è:</p>
<p><strong><span style="color:#ff0000;">http://**pcvirtual.comoj.com**/jsp/Login.jsp.htm#</span></strong></p>
<p><em><span style="color:#ff0000;"><span style="color:#000000;">(gli asterischi per neutralizzare il link)</span></span></em></p>
<p><strong><span style="color:#ff0000;"><span style="color:#000000;">Quindi, se inserite in queste videate le vostre credenziali di accesso finiranno direttamente in pasto ai phisher!!</span></span></strong></p>
<p><strong><span style="color:#ff0000;"><span style="color:#000000;"><br />
</span></span></strong></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[InBoxRevenge Under Attack Again]]></title>
<link>http://inboxrevenge.wordpress.com/2009/11/16/inboxrevenge-under-attack-again/</link>
<pubDate>Mon, 16 Nov 2009 20:06:32 +0000</pubDate>
<dc:creator>reportscams</dc:creator>
<guid>http://inboxrevenge.wordpress.com/2009/11/16/inboxrevenge-under-attack-again/</guid>
<description><![CDATA[This is the third attack on the InBoxRevenge antispam forums within one month. The first DDoS attack]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>This is the third attack on the <a href="http://ksforum.inboxrevenge.com">InBoxRevenge</a> antispam forums within one month. The first DDoS attack which was posted below was on <a href="http://inboxrevenge.wordpress.com/2009/10/28/301/">October 28, 2009</a>.</p>
<p>Since about 10:45 Eastern Time on Monday, November 16th, 2009, IBR&#8217;s forums are once again offline.</p>
<p>We will give you more details as they become available. It seems that spammers are definitely still very angry with the content posted on <a href="http://ksforum.inboxrevenge.com">IBR</a>.</p>
<p>We will continue to spread information online via <a href="http://twitter.com/InBoxRevenge">various</a> <a href="http://twitter.com/spamislame">twitter</a> <a href="http://twitter.com/thegilesmark">accounts</a>, <a href="http://inboxrevenge.blogspot.com/">blogs</a>, and other websites about collecting information which leads to shutting down illegal spammer operations. Attacks such as this one and others do not stop our efforts as we continue to report spamming operations.</p>
<p>As a reminder, check out our other websites online for updates:</p>
<p>Twitter: <a href="http://twitter.com/inboxrevenge">http://twitter.com/inboxrevenge</a><br />
Other blogs:</p>
<p><a href="http://inboxrevenge.blogspot.com/">http://garwarner.blogspot.com/</a></p>
<p><a href="http://inboxrevenge.blogspot.com/">http://inboxrevenge.blogspot.com</a><br />
<a href="http://spamtrackers.org/"></a><a href="http://inboxrevenge.spaces.live.com/"></a></p>
<p><a href="http://inboxrevenge.spaces.live.com/">http://inboxrevenge.spaces.live.com</a></p>
<p>Wiki:</p>
<p><a href="http://spamtrackers.org/">http://spamtrackers.org</a></p>
<p>Please note: that SiL also has his two blogs, which also accept moderated comments:<br />
<a href="http://ikillspammers.blogspot.com/">http://ikillspammers.blogspot.com</a><br />
<a href="http://spamitmustfall.blogspot.com/"></a></p>
<p><a href="http://spamitmustfall.blogspot.com/">http://spamitmustfall.blogspot.com</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Latest online scam hits taxpayers]]></title>
<link>http://startupdonutblog.co.uk/2009/11/16/latest-online-scam-hits-taxpayers/</link>
<pubDate>Mon, 16 Nov 2009 15:38:51 +0000</pubDate>
<dc:creator>Julian Shaw</dc:creator>
<guid>http://startupdonutblog.co.uk/2009/11/16/latest-online-scam-hits-taxpayers/</guid>
<description><![CDATA[It looks like fraudsters used the run up to the October tax deadline to ramp up a scheme to gather p]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>It looks like fraudsters used the run up to the October tax deadline to ramp up a scheme to gather private information from people. At the same time a more dangerous scam was coming across from America. What was happening and what can be done?</p>
<p><strong>Tax refunds?</strong></p>
<p>HMRC reported a record 83,000 scam e-mails in September. In one day alone a massive 10,000 reports were made. Given that these are only the e-mails reported, the actual numbers are probably even higher. It&#8217;s more than a bit worrying.</p>
<p>One scam says something like &#8220;You have a tax refund, click here&#8221;. It directs the person to a website asking for credit or debit card details. These sites only live for a couple of hours before they are closed down and replaced by a new site. Although several have been shut down, they are fiendishly hard to track.</p>
<p>The second fraud was perhaps more worrying.</p>
<p>A US scam appears to be moving to the UK. In the States an e-mail claiming to be from the American federal tax authority, IRS, threatening fines and penalties actually had a Trojan attached.</p>
<p>Andrew Brandt of US internet security company Webroot wrote a great <a title="Andrew Brandt blog" href="http://blog.webroot.com/2009/10/14/irs-tax-warning-fraud-crosses-the-pond/">blog</a> about it.</p>
<p><strong>Phishing and Trojans </strong></p>
<p>Sending fake e-mails to gather personal information is commonly called &#8220;phishing&#8221;. Crooks send millions of emails pretending to be from a well-known respected organisation such as a bank. The e-mail scares the recipient into visiting a genuine-looking but fraudulent website where data is captured. </p>
<p>A trojan is a computer program that installs itself on your computer and without you knowing can send your personal details, passwords and usernames etc to the criminals who sent the e-mail.</p>
<p>Both are tools used by criminals for identity theft.</p>
<p><strong>What to do? </strong></p>
<p>Fortunately, it&#8217;s easy to spot &#8211; HMRC will never send an e-mail regarding a tax refund. They will only ever send you a letter in those circumstances. As John Harrison, head of customer contact at HMRC says: &#8220;We never use e-mails, telephone calls or external companies in these circumstances.&#8221;</p>
<p>So, if you have an email purporting to be from HMRC saying you are owed a tax refund, it&#8217;s a scam. Simple as that.</p>
<p>If you are concerned about an e-mail you have received, the important thing is never to open it or click on any link it contains. Just delete it.  </p>
<p>HMRC have a really informative and up to date web site with details of the latest scams and frauds. <a title="HMRC website" href="http://www.hmrc.gov.uk/security/examples.htm">Click here for more information</a><a href="http://www.hmrc.gov.uk/security/examples.htm.">.</a></p>
<p>Alternatively, simply send the e-mail immediately to phishing@hmrc.gsi.gov.uk without opening it and then delete it. They&#8217;ll deal with it.  </p>
<p>A more in-depth version of this article appears on msn money.</p>
<p><a href="http://www.startupdonut.co.uk/"><img class="alignnone size-full wp-image-453" title="startupdonutbannerbutton728x90" src="http://localbusinessadviser.wordpress.com/files/2009/07/startupdonutbannerbutton728x90.gif" alt="startupdonutbannerbutton728x90" width="500" height="61" /></a></p>
<div><a title="Bookmark and Share" href="http://www.addthis.com/bookmark.php?pub=4a12cd40013be73f" target="_blank"><img src="http://s7.addthis.com/static/btn/lg-share-en.gif" alt="Bookmark and Share" width="125" height="16" /></a></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palestinian suspected of phishing Israeli bank accounts ]]></title>
<link>http://cyberthreat.wordpress.com/2009/11/16/palestinian-suspected-of-phishing-israeli-bank-accounts/</link>
<pubDate>Mon, 16 Nov 2009 14:22:04 +0000</pubDate>
<dc:creator>pmakohon</dc:creator>
<guid>http://cyberthreat.wordpress.com/2009/11/16/palestinian-suspected-of-phishing-israeli-bank-accounts/</guid>
<description><![CDATA[Palestinian suspected of phishing Israeli bank accounts The Israeli media is reporting that authorit]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><a href="http://www.sophos.com/blogs/gc/g/2009/11/16/palestinian-suspected-phishing-israeli-bank-accounts/">Palestinian suspected of phishing Israeli bank accounts </p>
<p>The Israeli media is reporting that authorities have arrested a 22-year-old Palestinian man in relation to a phishing attack against customers of two banks.</p>
<p>The man, who has not been named, was arrested by the IDF (Israeli Defence Force) and police after allegedly sending emails asking customers of Bank Leumi adn the Bank of Israeli to confirm their account details for &#8217;security reasons&#8217;.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Crece el número de sitios vulnerados]]></title>
<link>http://vulnerabilityteam.wordpress.com/2009/11/16/crece-el-numero-de-sitios-vulnerados/</link>
<pubDate>Mon, 16 Nov 2009 08:52:27 +0000</pubDate>
<dc:creator>komz</dc:creator>
<guid>http://vulnerabilityteam.wordpress.com/2009/11/16/crece-el-numero-de-sitios-vulnerados/</guid>
<description><![CDATA[Según ha publicado Kaspersky Lab más del 60% de los sitios que ellos mismos han monitorizado (entre ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p style="text-align:justify;">Según ha publicado Kaspersky Lab más del 60% de los sitios que ellos mismos han monitorizado (entre 100.000 y 300.000 webs de 2006 a 2009) han sido vulnerados más de una vez por atacantes para alojar malware durante el año 2009.  Según este estudio los sitios infectados han aumentado en 100 veces con respecto a hace solo tres años. De uno de cada 20.000 en 2006 a uno de cada 150 en 2009.</p>
<p style="text-align:justify;"><strong><a href="http://www.phishtank.com/" target="_blank">Phishtank</a></strong>, un repositorio de páginas que alojan phishing y lugar habitual donde encontrar webs vulnerables, también ha visto cómo han aumentado el número de incidentes. Recibió en octubre de 2009 más de 23.000 avisos. En el mismo mes de 2006 se reportaron alrededor de 7.000.</p>
<p style="text-align:justify;">Para conseguir acceso a las páginas, los atacantes usan técnicas que también aprovechan de forma automatizada malware como Gumblar. Aunque la industria busca métodos para evitar que el usuario visite páginas infectadas o peligrosas desarrollando herramientas como Google Safe Browsing o la barra de herramientas de Netcraft, el número no para de crecer.</p>
<p style="text-align:justify;">En ocasiones hemos encontrado sitios vulnerados por varios grupos de atacantes y con diferentes shells alojadas (una shell es un método habitual que utiliza un atacante para controlar una página web), accesibles desde semanas o meses atrás. El descuido o la falta de conocimiento sobre cómo actuar ante estas situaciones son los errores que se cometen con mayor frecuencia.</p>
<p style="text-align:justify;">Es muy importante que cuando se nos comunica que un sitio web del que se es responsable ha sido vulnerado, se intente investigar sobre cómo se ha producido el incidente y arreglar el fallo lo antes posible. De lo contrario es muy probable que la página vuelva a ser atacada. Es necesario revisar la existencia de shells, etiquetas iframe usadas para atacar a los visitantes, malware, etc. Es necesario detectarlos y eliminarlos. Si se da el caso, es recomendable pedir la ayuda a la compañía de hosting para la investigación, puesto que dispondrán de más datos.  Es imprescindible además, que tras haber sufrido un ataque, se cambien las contraseñas que se usan en el servidor.</p>
<p><a href="http://www.viruslist.com/en/analysis?pubid=204792089" target="_blank">KASPERSKY REPORT</a></p>
<p><em>fuente: hispasec.com</em></p>
<p><em><a href="http://vulnerabilityteam.wordpress.com/files/2009/11/xss-attacks.jpg"><img class="alignleft size-full wp-image-5440" title="xss-attacks" src="http://vulnerabilityteam.wordpress.com/files/2009/11/xss-attacks.jpg" alt="xss-attacks" width="325" height="239" /></a><br />
</em></p>
<p><em><br />
</em></p>
</div>]]></content:encoded>
</item>

</channel>
</rss>
