
<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Inside Dark Networks</title>
	<atom:link href="http://www.darknetworks.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknetworks.org</link>
	<description>Network Security from an Insider</description>
	<pubDate>Fri, 13 Jun 2008 12:54:26 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>DHS/SRI Identity Theft Council</title>
		<link>http://www.darknetworks.org/2008/06/dhssri-identity-theft-council/</link>
		<comments>http://www.darknetworks.org/2008/06/dhssri-identity-theft-council/#comments</comments>
		<pubDate>Fri, 13 Jun 2008 12:54:26 +0000</pubDate>
		<dc:creator>Ken Baylor</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.darknetworks.org/2008/06/dhssri-identity-theft-council/</guid>
		<description><![CDATA[Yesterday I attended the above meeting in the Bay Area. I joined two years ago and the group has gone from strength to strength.
We had an excellent presentation covering a study of 517 U.S. Secret Service cases, and their conclusions on current Identity Theft Perpetrators, Victims and Methodologies. It was followed by a Panel led [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday I attended the above meeting in the Bay Area. I joined two years ago and the group has gone from strength to strength.</p>
<p>We had an excellent presentation covering a study of 517 U.S. Secret Service cases, and their conclusions on current Identity Theft Perpetrators, Victims and Methodologies. It was followed by a Panel led by Jerry Archer, CISO Intuit, on Critical Emerging Threats. Definitely it was an engaging afternoon.</p>
<p>Security people some in all sorts and personalities. Normally we don&#8217;t put anything in writing about the people themselves. However, for two of the attendees, I will break this rule.</p>
<p>Jerry Archer led the panel. In all my time in the valley, and after meeting with half the countries CISO/CSO&#8217;s, I don&#8217;t think I have ever met such a genuine honest and all-round good security person. Jerry deeply cares about his company, his people, the profession, stopping the bad guys and keeping the average person safe. He gives up hundreds of hours per year to protect the man in the street and is a yardstick by which other CISOs should be measured by. Good to see him again.</p>
<p>The second person who deserves credit is the organizer, Robert Rodriguez. Robert since retiring from the USSS has tiringly build bridges between the public and private sectors. His list of contacts inside the US Government agencies is legendary, and he is driven by the goal of protecting the US infrastructure and its citizens. I have had the pleasure of knowing Robert these last 4 years.</p>
<p>Both men are a true credit to their profession, and it&#8217;s worth breaking the rules every now and then by calling this out.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.darknetworks.org/2008/06/dhssri-identity-theft-council/feed/</wfw:commentRss>
		</item>
		<item>
		<title>McAfee, botnets, libel, Open Source and Tax day</title>
		<link>http://www.darknetworks.org/2008/04/mcafee-botnets-libel-open-source-and-tax-day/</link>
		<comments>http://www.darknetworks.org/2008/04/mcafee-botnets-libel-open-source-and-tax-day/#comments</comments>
		<pubDate>Tue, 15 Apr 2008 22:45:00 +0000</pubDate>
		<dc:creator>Ken Baylor</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.darknetworks.org/2008/04/mcafee-botnets-libel-open-source-and-tax-day/</guid>
		<description><![CDATA[What a day!
Leaving aside my pain in enriching the government with my checks yesterday, I received a rather interesting email in my inbox today.
It came from McAfee&#8230;.apparently Matt Asay is saying McAfee has slandered open source by a comment I wrote in my white paper ( http://www.cnet.com/8301-13505_1-9917989-16.html) and (www.mcafee.com/us/local_content/white_papers/wp_botnet.pdf).
First Assumption: I am a McAfee minion [...]]]></description>
			<content:encoded><![CDATA[<p>What a day!</p>
<p>Leaving aside my pain in enriching the government with my checks yesterday, I received a rather interesting email in my inbox today.</p>
<p>It came from McAfee&#8230;.apparently Matt Asay is saying McAfee has slandered open source by a comment I wrote in my white paper ( http://www.cnet.com/8301-13505_1-9917989-16.html) and (<span class="a">www.<strong>mcafee</strong>.com/us/local_content/white_papers/wp_<strong>botnet</strong>.pdf</span>).</p>
<p>First Assumption: I am a McAfee minion employed to destroy open source. Let&#8217;s see&#8230;after I left McAfee I ran security at Symantec, so no&#8230;not a good minion of anyone.</p>
<p>Second Assumption: McAfee wanted that comment in there: No, based on the evidence I had at the time, it was a true statement. It still is.</p>
<p>Well, what did that comment actually mean? Quite simply, two of the nastiest bots out there&#8230;PhatBot and AgoBot had published source code. Many people got there hands on it and built uber-bots. We killed those variants, they built more. etc etc etc. Sophos clocked the variants of those two bots at well over a thousand.</p>
<p>Could these bots be described as Open-Source? I believe so.</p>
<p>Was the source code modified multiple times? Yes. Were open source techniques used? Absolutely</p>
<p>Were these bot modifiers core to the Open Source movement? No, just a few bad apples that taint the majority<br />
Was the comment taken out of context? I think so too.</p>
<p>Has McAfee identified crimeware users who rely on Open Source? Absolutely&#8230;see David Marcus&#8217;s comments here ( http://www.pcadvisor.co.uk/news/index.cfm?newsid=6601)</p>
<p>Sorry Matt, McAfee is NOT your enemy, nor are they ignorant about open source.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.darknetworks.org/2008/04/mcafee-botnets-libel-open-source-and-tax-day/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Website Inquiry: Phishing Scam</title>
		<link>http://www.darknetworks.org/2008/02/website-inquiry-phishing-scam/</link>
		<comments>http://www.darknetworks.org/2008/02/website-inquiry-phishing-scam/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 17:03:25 +0000</pubDate>
		<dc:creator>Ken Baylor</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.darknetworks.org/2008/02/website-inquiry-phishing-scam/</guid>
		<description><![CDATA[&#160;
If you own a domain name, you will likely have received a slew of emails similar to the one below.    They are part of a new phishing scam. Do NOT reply as they will only solicit further information from you, which will be used to rip you off. 
Some points to note: [...]]]></description>
			<content:encoded><![CDATA[<p>&#160;</p>
<p>If you own a domain name, you will likely have received a slew of emails similar to the one below.    <br />They are part of a new phishing scam. Do NOT reply as they will only solicit further information from you, which will be used to rip you off. </p>
<p>Some points to note: The &#8216;from name&#8217; has no relation to the &#8216;from email&#8217;, which is different from the person who signs the email and the &#8216;reply to email address&#8217; is also different</p>
<p><em></em></p>
<blockquote><p><u><strong>Website Enquiry</strong></u>       <br /><em>From: <b>Pearle Joyce</b> (</em><a href="http://by137w.bay137.mail.live.com/mail/ApplicationMain_12.1.0069.1213.aspx?culture=en-US&amp;hash=2051678514#"><em>akanidaniels@virgilio.it</em></a><em>)        <br /><img alt="Medium risk" src="http://gfx2.hotmail.com/mail/w2/ltr/i_yellowshield.gif" /> You may not know this sender. </em><a href="http://by137w.bay137.mail.live.com/mail/ApplicationMain_12.1.0069.1213.aspx?culture=en-US&amp;hash=2051678514#"><em>Mark as safe</em></a><em> | </em><a href="http://by137w.bay137.mail.live.com/mail/ApplicationMain_12.1.0069.1213.aspx?culture=en-US&amp;hash=2051678514#"><em>Mark as unsafe</em></a>       <br /><em>Sent:Tue 2/05/08 1:37 AM        <br />Reply-to:Pearle Joyce (</em><a href="mailto:bond.marketing@gmail.com"><em>bond.marketing@gmail.com</em></a><em>)        <br />To: XXXX.org (</em><a href="mailto:XXXXXX@hotmail.com"><em>XXXXXX@hotmail.com</em></a><em>)        <br />Hello ,         <br />My name is Richard Thompson and I am interested in having a link on your website (XXXXX.org).         <br />I will be very thankful to you if you give me some prices for the following ads:         <br />1) text link on your homepage/all pages         <br />2) text box ad 120&#215;60, 125&#215;125 on homepage/all pages         <br />Thank you in advance!         <br />Richard Thompson         </p>
<p></em></p>
<div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:2f244e55-f285-480d-9d24-5e5d53a0b041" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/Ken%20baylor%20Phishing%20Scam%20Website%20Inquiry%20Security%20Alert" rel="tag">Ken baylor Phishing Scam Website Inquiry Security Alert</a></div>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.darknetworks.org/2008/02/website-inquiry-phishing-scam/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Building a powerful sub-$1000 VMWare ESX server</title>
		<link>http://www.darknetworks.org/2008/02/building-a-powerful-sub-1000-vmware-esx-server/</link>
		<comments>http://www.darknetworks.org/2008/02/building-a-powerful-sub-1000-vmware-esx-server/#comments</comments>
		<pubDate>Sat, 02 Feb 2008 01:18:11 +0000</pubDate>
		<dc:creator>Ken Baylor</dc:creator>
		
		<category><![CDATA[General IT]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.darknetworks.org/2008/02/building-a-powerful-sub-1000-vmware-esx-server/</guid>
		<description><![CDATA[VMWare has recently released its ESX 3.5 server. While the &#8216;free&#8217; server version has some benefits, the overhead to run it is way too high, so ESX is still the best way to virtualize.
After reviewing the forums, there still exist a number of problems when pursuing the home ESX server option. The main issue being version 3.X has very limited [...]]]></description>
			<content:encoded><![CDATA[<p>VMWare has recently released its ESX 3.5 server. While the &#8216;free&#8217; server version has some benefits, the overhead to run it is way too high, so ESX is still the best way to virtualize.</p>
<p>After reviewing the forums, there still exist a number of problems when pursuing the home ESX server option. The main issue being version 3.X has very limited SATA support. While some support for EIDE exists, these cannot be used for hosting the actual VM images (which is the whole point of virtualization in the first place).</p>
<p>After a great amount of research, it turns out the LSI Logic MegaRAID 150-4, which supports SATA, uses the same VMWare driver  <a href="http://www.darknetworks.org/wp-content/uploads/2008/02/Megaraid%20sata%20150-4.jpg"><img style="border: 0px" height="154" alt="Megaraid sata 150-4" src="http://www.darknetworks.org/wp-content/uploads/2008/02/Megaraid%20sata%20150-4_thumb.jpg" width="204" align="right" border="0" /></a>(MegaRAID2) as it&#8217;s SCSI predecessor. It is also available cheaply on eBay (approx $120). The card supports up to 4 SATA drives. Another version of this card, the 150-6 supports 6 SATA drives.</p>
<p>With the difficult part out of the way, the next part was to find a motherboard that would support more than the typical 4GB of RAM and support a powerful processor, all on a budget.</p>
<p>Surprisingly, rather than build one of my own, the Gateway GT5630 came to the rescue. The machine is available from Frys for a mere <a href="http://www.darknetworks.org/wp-content/uploads/2008/02/GT5630.gif"><img style="border: 0px" height="179" alt="GT5630" src="http://www.darknetworks.org/wp-content/uploads/2008/02/GT5630_thumb.gif" width="244" border="0" /></a> $699. It comes with a quad-core Intel Q6600 processor and motherboard that supports 8GB of RAM. Fry&#8217;s again came to the rescue with 8GB for $150.</p>
<p>So, once I got my PC surgery was minimal. I simply opened the box, and took out the paltry amount of included RAM, replacing it with my 4&#215;2GB sticks for 8GB. I then inserted my full length card in my normal length PCI slot. Make sure you upgrade your BIOS from the LSI web site as otherwise it will be quite unreliable in &#8216;degraded PCI mode&#8217;. Then connect the RAID card to your SATA drive and you are ready to boot.</p>
<p>Then I booted up the machine. Happily, it automatically detected the RAID card and automatically loaded the megaraid2 driver.</p>
<p>However, another problem came up. Despite booting off the ESX CD, the ESX installation decided that it could not read the included IDE CD-drive. My work around was as follows:</p>
<blockquote><p><font color="#303030">Luckily the GT5630 comes with an Intel NIC card for which ESX has drivers. So I ejected the installation CD, and stuck it into another machine. I then downloaded a free FTP server program and configured it to make the installation CD available on the second machine via FTP.<br />
       I went back to my GT5630. I told it to install via FTP. It received a DHCP address and I pointed it to the FTP server with the installation CD. It carried on installing flawlessly.</font></p></blockquote>
<p>So despite a few minor hiccups, I now have ESX server running on a pretty powerful (quad core with 8GB RAM) server for less than $1000. Most likely, I will add a few hard drives to it soon.</p>
<p>Hardware Costs:</p>
<blockquote><p><font color="#303030">Gateway GT5630 = $699<br />
8GB RAM            = $150<br />
<u>RAID Card          = $120<br />
</u>Total Cost           = $969</font></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.darknetworks.org/2008/02/building-a-powerful-sub-1000-vmware-esx-server/feed/</wfw:commentRss>
		</item>
		<item>
		<title>ISACA-SV Winter Conference</title>
		<link>http://www.darknetworks.org/2008/01/isaca-sv-winter-conference/</link>
		<comments>http://www.darknetworks.org/2008/01/isaca-sv-winter-conference/#comments</comments>
		<pubDate>Fri, 25 Jan 2008 20:43:05 +0000</pubDate>
		<dc:creator>Ken Baylor</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.darknetworks.org/2008/01/isaca-sv-winter-conference/</guid>
		<description><![CDATA[The ISACA Silicon Valley Chapter&#8217;s Winter conference is in full swing. This year it has been split into two separate tracks (Information Security and IT Governance) on consecutive days.
IT governance is really starting to get interesting in 2008. This is for a number of reasons. With the downturn in the economy, there are two things [...]]]></description>
			<content:encoded><![CDATA[<p>The ISACA Silicon Valley Chapter&#8217;s Winter conference is in full swing. This year it has been split into two separate tracks (Information Security and IT Governance) on consecutive days.</p>
<blockquote><p><font color="#303030">IT governance is really starting to get interesting in 2008. This is for a number of reasons. With the downturn in the economy, there are two things people are thinking about:</font></p>
<p><font color="#303030">1) How is information security and IT spending my money? The concept of transparency, good management, regulatory compliance and showing value will become critical for most organizations in 2008 and 2009. Most likely this will result in a boom in IT governance.</font></p>
<p><font color="#303030">2) 2008 will likely lead to layoffs and the freezing of InfoSec budgets. The IT targets are most likely the &#8216;old guard&#8217;, i.e. those who do not believe in business alignment and assisting the business grow revenue. This will likely result in many out of work admins, who have a grudge against their old employers, and are armed with network diagrams and root passwords. If they do decide to attack their employers, this may lead to a mandatory SB1386 disclosure, causing huge embarrassment. The good news is this will lead to the unfreezing of InfoSec budgets and an increase in InfoSec hiring and training&#8230;..roll on 2008.</font></p>
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.darknetworks.org/2008/01/isaca-sv-winter-conference/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Can IPS alleviate the botnet problem?</title>
		<link>http://www.darknetworks.org/2006/10/can-ips-alleviate-the-botnet-problem/</link>
		<comments>http://www.darknetworks.org/2006/10/can-ips-alleviate-the-botnet-problem/#comments</comments>
		<pubDate>Wed, 25 Oct 2006 23:10:44 +0000</pubDate>
		<dc:creator>Ken Baylor</dc:creator>
		
		<category><![CDATA[Network Security]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.darknetworks.org/2006/10/can-ips-alleviate-the-botnet-problem/</guid>
		<description><![CDATA[Botnets are back in the news. Leading experts have recently gone on record stating we are losing the war on botnets. Then yesterday, McAfee released a whitepaper showing startling success in Central America against botnets. This has ignited a debate in both the IPS and botnet sub-cultures of the Information Security World.
Botnets are problematic for [...]]]></description>
			<content:encoded><![CDATA[<p><font face="Arial" size="2">Botnets are back in the news. Leading experts have recently gone on record stating we are losing the war on botnets. Then yesterday, McAfee released a whitepaper showing startling success in Central America against botnets. This has ignited a debate in both the IPS and botnet sub-cultures of the Information Security World.</font></p>
<p><font face="Arial" size="2">Botnets are problematic for a number of reasons:</font></p>
<p><font face="Arial" size="2">1)</font>       <font face="Arial" size="2">We have no idea how many botnets are out there. Most of our results come from honeynets (</font><a href="http://www.honeynet.org/papers/honeynet/"><font face="Arial" size="2">http://www.honeynet.org/papers/honeynet/</font></a><font face="Arial" size="2">) which are globally distributed. However, honeynets are binary, they are either infected by a particular botnet or they are not. It is quite possible to have a huge botnet army in the wild that misses the honeynet traps.</font></p>
<p><font face="Arial" size="2">2)</font>       <font face="Arial" size="2">We have no idea how big the active botnets are. Botnet armies have been reported which are smaller than 1,000 and others larger than a million. Bot herders will exaggerate their size, until they get caught, in which case they will lower their size attempting to get a lower sentence.</font></p>
<p><font face="Arial" size="2">3)</font>       <font face="Arial" size="2">Size is not correlated directly to lethality. A small botnet which infects a computer in a sensitive network can do untold damage. The botnet may download keyloggers and password sniffers leading to confidential data leakage. The compromised bot may even be used as a launchpad for attacking other machines in the internal network.</font></p>
<p><font face="Arial" size="2">4)</font>       <font face="Arial" size="2">Many botnets are programmable. When a 0-day exploit becomes available, a bot herder can push the code to the bots and get them to attack other machines, attempting to recruit them.</font></p>
<p><font face="Arial" size="2">5)</font>       <font face="Arial" /><font size="2">Bots create a lot of ‘network noise’ as they scan and attack other hosts. This extra traffic can disrupt the internal networks of enterprises, leading to slower application response and causing servers to crash.  </font></p>
<p><font face="Arial" size="2">Botnets have a complex life cycle. The life cycle below, however, is typical:</font></p>
<p><font size="2" /></p>
<p><font size="2"> <img id="image28" title="Anatomy of Botnet attack" style="width: 477px; height: 413px" height="413" alt="Anatomy of Botnet attack" src="http://www.darknetworks.org/wp-content/uploads/2006/10/fig1.JPG" width="477" align="middle" /></font><br />
<font size="2"> </font></p>
<p><strong><u><font size="2">Figure 1: Anatomy of a typical botnet attack<br />
</font></u></strong><font size="2"><em>Step 1:</em> Bot herder loads remote exploit code on an ‘attack machine’, which may be dedicated for this purpose or an already compromised bot. Many bots use file-sharing and RPC ports to spread. Initial infection vectors ensure victim machines have sufficient configuration information to contact bot controller when compromised. <em>Step 2:</em> Attack machines scan for unpatched targets and launch attacks. An unpatched machine becomes a victim to the exploit. <em>Steps 3 &#038; 4:</em> The victim machine is ordered to download binaries from another server (frequently a compromised web or FTP server). <em>Step 5:</em> These binaries are run on the victim machine and convert it to a bot. The victim connects to the bot controller and ‘reports for duty’. <em>Step 6:</em> The bot controller issues commands to the victim. These instructions may include commands to download new modules, steal account details, install spyware, attack other machines and relay spam. <em>Step 7:</em> The Bot herder controls all bots by issuing commands via the bot controller(s).<br />
</font></p>
<p><font face="Arial" size="2">Just as in the Biological Sciences, by interrupting a pest’s life cycle we can stop them.  Almost all quality IPS devices can stop Step 2 (see figure 1). There are many IPS devices deployed globally, but often there is a detection-only mindset held by some who call themselves information security professionals. This indifference allows botnets to spread deep inside networks.</font></p>
<p><font size="2" /><font face="Arial">            Steps 5 &#038; 6 can be stopped by Next-Generation IPS devices (that have up-to-date and comprehensive signatures, and can truly decode the protocols). These are not common and the successful deployment of these forms the basis of the McAfee case study (</font><a href="http://www.mcafee.com/us/local_content/white_papers/wp_botnet.pdf"><font face="Arial" size="2">http://www.mcafee.com/us/local_content/white_papers/wp_botnet.pdf</font></a><font face="Arial" size="2">). Those with legacy IPS devices can only slow the growth of botnets only at step 2, and should be encouraged to do so. To destroy established botnets requires Next-Generation IPS devices.</font></p>
<p><font face="Arial" size="2">Next-Generation IPS devices bring a number of extra benefits, and solve many of the botnet problems. When deployed at the network edge, IPS devices can see all traffic entering and exciting the network. This brings a number of advantages, we can:</font></p>
<p><font face="Arial" size="2">i)</font>                  <font face="Arial" size="2">see how many bots are on our network,<br />
</font><font face="Arial" size="2">ii)</font>                 <font face="Arial" size="2">see where their bot controllers are,<br />
</font><font face="Arial" size="2">iii)</font>                <font face="Arial" size="2">estimate the size of each  botnet army<br />
</font><font face="Arial" size="2">iv)</font>                <font face="Arial" size="2">see which botnet variant the infected machines are using,<br />
</font><font face="Arial" size="2">v)</font>                 <font face="Arial" size="2">see deeply into the command and control structures including the commands being sent to individual bots.<br />
</font><font face="Arial" size="2">vi)</font>                  <font face="Arial" size="2">capture traffic from the small but lethal botnets and give visibility into their mission.<br />
</font><font face="Arial" size="2">vii)</font>                 <font face="Arial" size="2">capture traffic which may be used to secure bot herder convictions.</font></p>
<p><strong><font face="Arial">Is the botnet war over then?<br />
</font></strong><font face="Arial" size="2">Next-Generation IPS devices have proven themselves to be very helpful in the war on botnets. Bot herders and their botnets will however evolve, and seek to evade them. The cat and mouse game played so often in the past with virus writers will now come to the botnet world. </font></p>
<p><font face="Arial" size="2">Nonetheless, IPS devices can pinpoint botnets, indicate their size, show where their controllers are and enable us to see their control &#038; command traffic. We are much closer to putting bot herders behind bars, with the active assistance of law enforcement. Perhaps that is the message bot herders should take away.</font></p>
]]></content:encoded>
			<wfw:commentRss>http://www.darknetworks.org/2006/10/can-ips-alleviate-the-botnet-problem/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Paper: Evolution of the hacker threat posted</title>
		<link>http://www.darknetworks.org/2006/09/evolution-of-the-hacker-threat/</link>
		<comments>http://www.darknetworks.org/2006/09/evolution-of-the-hacker-threat/#comments</comments>
		<pubDate>Mon, 11 Sep 2006 23:10:41 +0000</pubDate>
		<dc:creator>Ken Baylor</dc:creator>
		
		<category><![CDATA[Host Security]]></category>

		<category><![CDATA[Management]]></category>

		<category><![CDATA[Network Security]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.darknetworks.org/2006/09/evolution-of-the-hacker-threat/</guid>
		<description><![CDATA[During recent months I created a presentation which described the recent evolution of hackers, primarily covering their motivations. This we presented in the UK, France and Germany. There were follow up presentations in Poland and the Czech Republic. However, rather than create a world tour, I changed the presentation into the format of an article [...]]]></description>
			<content:encoded><![CDATA[<p><img id="image22" title="layeredsecurity.jpg" style="width: 420px; height: 292px" alt="layeredsecurity.jpg" src="http://www.darknetworks.org/wp-content/uploads/2006/09/layeredsecurity.jpg" align="right" />During recent months I created a presentation which described the recent evolution of hackers, primarily covering their motivations. This we presented in the UK, France and Germany. There were follow up presentations in Poland and the Czech Republic. However, rather than create a world tour, I changed the presentation into the format of an article an published it here:</p>
<p> <a href="http://www.securitypronews.com/news/securitynews/spn-45-20060911EvolutionoftheHackerThreat.html">http://www.securitypronews.com/news/securitynews/spn-45-20060911EvolutionoftheHackerThreat.html</a></p>
<p> Although long (>2000 words) the article covers both opportunistic and targeted hacking and describes &#8217;spring boarding&#8217; which is used more and more in identity theft. The ability to &#8216;fence&#8217; stolen identities online has lead to large profits being generated within hours. It also covers the step by step hacker methodology and the best practices for system security.</p>
<p> </p>
<p>Happy reading <img src='http://www.darknetworks.org/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.darknetworks.org/2006/09/evolution-of-the-hacker-threat/feed/</wfw:commentRss>
		</item>
		<item>
		<title>High School Security Initiative</title>
		<link>http://www.darknetworks.org/2006/09/high-school-security-initiative/</link>
		<comments>http://www.darknetworks.org/2006/09/high-school-security-initiative/#comments</comments>
		<pubDate>Mon, 11 Sep 2006 18:46:04 +0000</pubDate>
		<dc:creator>Ken Baylor</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.darknetworks.org/2006/09/high-school-security-initiative/</guid>
		<description><![CDATA[There are a number of interesting security initiatives right now. Most of them are technical but one which has drawn my attention is educational. 
 
There is a major initiative underway in the Bay Area to create a High School security initiative and have this taught in every California High School, eventualy as a mandatory core unit. [...]]]></description>
			<content:encoded><![CDATA[<p><font size="2"></font><font face="Arial"><img id="image20" title="High School" alt="High School" src="http://www.darknetworks.org/wp-content/uploads/2006/09/highschool.jpg" align="left" />There are a number of interesting security initiatives right now. Most of them are technical but one which has drawn my attention is educational. </p>
<p></font><font face="Arial" size="2"> </font></p>
<p><font size="2"></font><font face="Arial">There is a major initiative underway in the Bay Area to create a High School security initiative and have this taught in every California High School, eventualy as a mandatory core unit. While there are many excellent sites on the net which target this age group the problem is that it is purely voluntary. The end result is they are ignored. </p>
<p></font><font face="Arial" size="2"> </font></p>
<p><font size="2"></font><font face="Arial">I joined this committee three months ago and we hope to present the finalized and proposed curriculum late October 2006 in Sacramento. Quite a number of interested parties have come together to form this committee; the FBI, McAfee, Visa, Dept of Consumer affairs of California and last week, we were joined by ZoneLabs. In addition to this a number of third level institutions have joined, as well as a few all-important teachers and high-school students, who will have to deliver and receive the information respectively. It is great to see these different groups work for a common altruistic purpose. </p>
<p></font><font face="Arial" size="2"> </font></p>
<p><font size="2"></font><font face="Arial">The curriculum will cover such topics as boundaries of acceptable behavior, crimes against the person, crimes against property etc. The curriculum will educate students about threats, identity theft, etc and what to do about them. It will also educate would be perpetrators about the potential repercussions and hopefully make them think twice before committing. </p>
<p></font><font face="Arial" size="2"> </font></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><font face="Arial" size="2">If you have strong feelings about this project, or opinions please either add a comment or send me an email.</font></p>
]]></content:encoded>
			<wfw:commentRss>http://www.darknetworks.org/2006/09/high-school-security-initiative/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Wifi Security Law passes California assembly</title>
		<link>http://www.darknetworks.org/2006/08/wifi-security-law-passes-california-assembly/</link>
		<comments>http://www.darknetworks.org/2006/08/wifi-security-law-passes-california-assembly/#comments</comments>
		<pubDate>Tue, 29 Aug 2006 23:06:02 +0000</pubDate>
		<dc:creator>Ken Baylor</dc:creator>
		
		<category><![CDATA[Network Security]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.darknetworks.org/2006/08/wifi-security-law-passes-california-assembly/</guid>
		<description><![CDATA[California Assembly Bill 2415 ( by Speaker Fabian Núñez ) passed today and now goes to the Governor. What does it actually do?
http://democrats.assembly.ca.gov/members/a46/press/a462006116.htm
http://www.mercurynews.com/mld/mercurynews/15397371.htm
Hopefully it means more secure wireless networks. In the Bay Area almost 50% of consumer wireless access points have no encryption turned on. Many of these devices have their passwords still set to [...]]]></description>
			<content:encoded><![CDATA[<p><img id="image18" title="Linksys open Wifi" alt="Linksys open Wifi" src="http://www.darknetworks.org/wp-content/uploads/2006/08/linksys.jpg" align="left" />California Assembly Bill 2415 ( by Speaker Fabian Núñez ) passed today and now goes to the Governor. What does it actually do?<br />
<a href="http://democrats.assembly.ca.gov/members/a46/press/a462006116.htm" target="_blank">http://democrats.assembly.ca.gov/members/a46/press/a462006116.htm</a></p>
<p><a href="http://www.mercurynews.com/mld/mercurynews/15397371.htm" target="_blank">http://www.mercurynews.com/mld/mercurynews/15397371.htm</a><br />
Hopefully it means more secure wireless networks. In the Bay Area almost 50% of consumer wireless access points have no encryption turned on. Many of these devices have their passwords still set to the defaults. This bill means that manufacturers of WiFi devices will have educate home users how to secure their networks, or at least alert them to the risks if they chose not to.</p>
<p><font size="2">Identity theft is a major threat to Californians. Most WiFi devices lack protection, making home users easy prey for hackers. Once intruders gain access, they can wreak havoc inside your home network and steal personal information and install spyware. Consumers should be educated on the risks of wireless access and the additional steps needed for protection. These include:</font></p>
<p><font size="2">1) Change default passwords on WiFi routers<br />
2) Turn on the highest level of encryption possible (currently WPA2)<br />
3) Turn off SSID Broadcasting (hiding the network)<br />
4) Turn on MAC filtering (only pre-approved machines may join the network)<br />
5) Install Anti-Virus, Anti-Spyware and desktop firewalls on all machines.</p>
<p>The law has been well covered below:<br />
<a href="http://www.publicradio.org/columns/futuretense/2006/09/01.shtmlhttp://www.mercurynews.com/mld/mercurynews/business/15395913.htm">http://www.publicradio.org/columns/futuretense/2006/09/01.shtml<br />
</a></font><a href="http://www.mercurynews.com/mld/mercurynews/business/15395913.htm" target="_blank">http://www.mercurynews.com/mld/mercurynews/business/15395913.htm</a><br />
<a href="http://www.darkreading.com/document.asp?doc_id=102598&#038;WT.svl=news1_3">http://www.darkreading.com/document.asp?doc_id=102598&#038;WT.svl=news1_3</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.darknetworks.org/2006/08/wifi-security-law-passes-california-assembly/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Is Google Wifi/WiMax safe and secure?</title>
		<link>http://www.darknetworks.org/2006/08/is-google-wifiwimax-safe-and-secure/</link>
		<comments>http://www.darknetworks.org/2006/08/is-google-wifiwimax-safe-and-secure/#comments</comments>
		<pubDate>Wed, 16 Aug 2006 18:51:16 +0000</pubDate>
		<dc:creator>Ken Baylor</dc:creator>
		
		<category><![CDATA[Management]]></category>

		<category><![CDATA[Network Security]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.darknetworks.org/2006/08/is-google-wifiwimax-safe-and-secure/</guid>
		<description><![CDATA[Today Google finally opened their free GoogleWifi to all residents of Mountain View California. Tempted though I am to ditch my current provider and migrate to Google, I must question&#8230;.How am I sure it is Google I am connecting to?
It could be an &#8216;Evil Twin&#8217; access point masquerading as a legitimate Google Wifi Access point. [...]]]></description>
			<content:encoded><![CDATA[<p><img align="right" alt="WiMax" title="WiMax" id="image16" src="http://www.darknetworks.org/wp-content/uploads/2006/08/wimax.jpg" />Today Google finally opened their free GoogleWifi to all residents of Mountain View California. Tempted though I am to ditch my current provider and migrate to Google, I must question&#8230;.<em>How am I sure it is Google I am connecting to?</em></p>
<p>It could be an &#8216;Evil Twin&#8217; access point masquerading as a legitimate Google Wifi Access point. To see how difficult it is to create an evil twin network, capable of stealing passwords, login information, instant messages and emails, I put one together.</p>
<p>The whole process took less than 15 minutes. The step by step approach I took has been fully documented here (<a href="http://www.darknetworks.org/uploads/WiMax.pdf">http://www.darknetworks.org/uploads/WiMax.pdf</a>). If you are going to use the Google Wifi network, perhaps you should think about installing their encryption client.</p>
<p>Otherwise you may fall prey to:</p>
<p><font size="2" face="Times New Roman"> Victims, when they connect to the evil twin access point, become very vulnerable:</font></p>
<p><font size="2" face="Times New Roman"> </font></p>
<p><font face="Times New Roman"></font><font size="3">a)</font>      <font size="2">All the traffic between them and the real access point is unencrypted. This means that a recording device (such as a PC running a sniffer, such as the freeware tool ethereal) may capture their traffic and spy on them. Unencrypted passwords, instant messages, emails and credit card information are easily intercepted.</font></p>
<p><font face="Times New Roman"></font><font size="2" face="Times New Roman"> </font></p>
<p><font face="Times New Roman"></font><font face="Times New Roman"></font><font size="2">b)</font>      <font size="2">Machines that join the network via the evil twin may be directly scanned and accessed by the attack machine. Sensitive information may be stolen from shared folders.</font></p>
<p><font face="Times New Roman"></font><font face="Times New Roman"></font><font size="2" face="Times New Roman"> </font></p>
<p><font face="Times New Roman"></font><font face="Times New Roman"></font><font size="2" face="Times New Roman"> </font></p>
<p><font face="Times New Roman"></font><font face="Times New Roman"></font><font face="Times New Roman"></font><font size="2">c)</font>      <font size="2">The attack machine can easily be configured for phishing. Even when Google WiFi is fully operational, users will have to authenticate to the network. Users may be redirected to a fake login page on the attack server, which will steal the users credentials. This Google login gives access to user email and so may be used for identity theft later.</font></p>
<p><font face="Times New Roman"></font><font face="Times New Roman"></font><font face="Times New Roman"></font><font size="2" face="Times New Roman"> </font></p>
<p><font face="Times New Roman"></font><font face="Times New Roman"></font><font face="Times New Roman"></font><font face="Times New Roman"></font><font size="2">d)</font>      <font size="2">The attack machine may trick the end user into downloading spyware/malware, by modifying the logon page. This may allow the attacker to install keylogging software and access private files.</font></p>
<p><font face="Times New Roman"></font><font face="Times New Roman"></font><font face="Times New Roman"></font><font face="Times New Roman"></font><font size="2" face="Times New Roman"> </font></p>
<p><font face="Times New Roman"></font><font face="Times New Roman"></font><font face="Times New Roman"></font><font face="Times New Roman"></font><font face="Times New Roman"></font><font size="2">e)</font>      <font size="2">The hacking server may also act as a poisoned DNS server. This would redirect users to phishing sites rather than legitimate financial sites where their logons and account information could be stolen. Banks and eBay are logical targets. These servers would completely control where the victim is allowed to visit on the Internet.</font></p>
]]></content:encoded>
			<wfw:commentRss>http://www.darknetworks.org/2006/08/is-google-wifiwimax-safe-and-secure/feed/</wfw:commentRss>
		</item>
		<item>
		<title>SPAM..Blame the Irish!</title>
		<link>http://www.darknetworks.org/2006/08/spamblame-the-irish/</link>
		<comments>http://www.darknetworks.org/2006/08/spamblame-the-irish/#comments</comments>
		<pubDate>Thu, 10 Aug 2006 18:50:17 +0000</pubDate>
		<dc:creator>Ken Baylor</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.darknetworks.org/2006/08/spamblame-the-irish/</guid>
		<description><![CDATA[So within the last two days, I have received three new spam/phishing atttempts. What is so bizarre about these? They all pretend to have links either with Ireland or at least use an Irish persons name, here&#8217;s two of the most interesting:
 
 
 
Return-Path: 
Received: from galadriel.portugalmail.pt (galadriel.portugalmail.pt [195.245.179.73])
     by XXXXXXXXXXXXXXXXX with ESMTP id k7AETcrP030275
     for XXXX@.xxx.com Thu, 10 Aug [...]]]></description>
			<content:encoded><![CDATA[<p><img id="image15" title="Phishing" style="width: 137px; height: 127px" alt="Phishing" src="http://www.darknetworks.org/wp-content/uploads/2006/08/phishing.jpg" align="left" />So within the last two days, I have received three new spam/phishing atttempts. What is so bizarre about these? They all pretend to have links either with Ireland or at least use an Irish persons name, here&#8217;s two of the most interesting:</p>
<p> </p>
<p> </p>
<p> </p>
<p><em><font face="Courier New"><strong>Return-Path:</strong> <</font></em><a href="http://www.darknetworks.org/kenmail/src/compose.php?send_to=elsa_dalton1%40portugalmail.pt"><em><font face="Courier New">elsa_dalton1@portugalmail.pt</font></em></a><em><font face="Courier New">><br />
</font></em><tt><em><strong>Received:</strong> from galadriel.portugalmail.pt (galadriel.portugalmail.pt [195.245.179.73])<br />
     by XXXXXXXXXXXXXXXXX with ESMTP id k7AETcrP030275<br />
     for </em><a href="mailto:XXXX@.xxx.com"><em>XXXX@.xxx.com</em></a><em> Thu, 10 Aug 2006 15:29:38 +0100<br />
</em></tt><tt><em><strong>Received:</strong> by galadriel.portugalmail.pt (Postfix, from userid 30)<br />
     id 48DE0D4F6B; Thu, 10 Aug 2006 14:24:42 +0100 (WEST)<br />
</em></tt><tt><em><strong>Received:</strong> from 83.229.62.123 ([83.229.62.123])<br />
     by gold.portugalmail.pt (IMP) with HTTP<br />
     for <</em><a href="http://www.darknetworks.org/kenmail/src/compose.php?send_to=elsa_dalton1%40portugalmail.pt"><em>elsa_dalton1@portugalmail.pt</em></a><em>@localhost>; Thu, 10 Aug 2006 14:24:42 +0100<br />
</em></tt><tt><em><strong>Message-ID:</strong> <1155216282.44db339a48357@gold3.portugalmail.pt><br />
</em></tt><tt><em><strong>Date:</strong> Thu, 10 Aug 2006 14:24:42 +0100<br />
</em></tt><tt><em><strong>From:</strong> </em><a href="http://www.darknetworks.org/kenmail/src/compose.php?send_to=elsa_dalton1%40portugalmail.pt"><em>elsa_dalton1@portugalmail.pt</em></a><br />
</tt><tt><em><strong>To:</strong> </em><a href="http://www.darknetworks.org/kenmail/src/compose.php?send_to=elsa_dalton1%40portugalmail.pt"><em>elsa_dalton1@portugalmail.pt</em></a><br />
</tt><tt><em><strong>Subject:</strong> CONGRATULATIONS!!!<br />
</em><strong>X-Originating-IP:</strong> 80.89.176.36</tt></p>
<p> </p>
<p> <em>IRISH WEB LOTTERY HEADQUARTERS.<br />
THE OAKROOM LOUNGE.          <br />
21 PICCADILLY IRISH. W1B 0BH.<br />
                                            <br />
                                               </em><em>IRISH WEB LOTTERY  <br />
IRISH GOVERNMENT ACCREDITED LICENSED<br />
IRISH WEB LOTTERY<br />
IS REGISTERED UNDER THE DATA PROTECTION ACT OF<br />
(Registration Z720633X).<br />
The Irish Lottery<br />
47 Meadow Vale,<br />
Sligo , Ireland .<br />
Ref: LSUK/2031/8162/05<br />
Batch: R4/A312-53<br />
                                                        <br />
                                                         WINNING NOTIFICATION<br />
CONGRATULATIONS!<br />
We the Board and Management of the Irish Lottery London, UK<br />
</em><em>wishes to inform you theresults of the E-mail address ballot<br />
lottery international program held on 1st day of August, 2006.<br />
Your email accounts have been picked as a winner of  £500,000 (<br />
FIVE HUNDRED THOUSAND BRITISH POUNDS STERLING).</em><em> </em><em>This<br />
result is today released to you and your email address attached<br />
in the A Category. All email addresses were selected through a<br />
computer ballot system in which your email address was selected<br />
as one of the lucky winners.</em><em>This results is today released to you<br />
and your email address attached  in the A Category. All email<br />
addresses were selected through a computer ballot system in<br />
which your email address was selected as one of the lucky winners.<br />
Your lucky numbers are:   and bonus ball number:<br />
</em><em>CONGRATULATIONS!!!<br />
Due to mix up of some numbers and names, we ask that you<br />
keep your winning information confidential until your claims<br />
have been processed and your money remitted to you.<br />
This is part of our security protocol to avoid double claiming and<br />
unwarranted abuse of this program by some participants.<br />
                           <br />
 <br />
All participants were selected randomly from World Wide<br />
Web site through computer draw system and extracted<br />
</em><em>from over 100,000 companies. This promotion takes place<br />
biannually.<br />
To file for your claim/winning, please contact our Legal<br />
Department through finance director (DR LEONARD WALTER)<br />
via email as </em><a href="http://www.darknetworks.org/kenmail/src/compose.php?send_to=leonard_walter_00%40yahoo.co.uk"><em>leonard_walter_00@yahoo.co.uk</em></a><em> for<br />
processing and payment of your claims/winning. Quote your<br />
reference/batch numbers in your correspondence with us and<br />
you are advised not to expose your numbers to avoid<br />
double claiming or voiding of your winning.</em><em>                 <br />
 </em><em>Please note in order to avoid unnecessary delays and<br />
complications quote your reference number and batch numbers<br />
in all correspondence. Should there be any change of addresses<br />
do inform our agent as soon as possible.<br />
Furthermore your winning numbers fall within our IRISH<br />
(London) region and you are required to contact our representative<br />
office in LONDON via Leonard Walter through this email address<br />
cc: </em><a href="http://www.darknetworks.org/kenmail/src/compose.php?send_to=leonard.walter00%40yahoo.co.uk"><em>leonard.walter00@yahoo.co.uk</em></a><em> as soon as you receive this mail<br />
to enable them file your papers for claim/payment of your prize.<br />
ANYONE BELOW EIGHTEEN YEARS OF AGE CAN MAKE HIS/ HER<br />
CLAIM IN PROXY THROUGH EITHER OF THE PARENTS. </em><em>Once again<br />
congratulations from our members and staff of the IRISH LOTTERY.<br />
Thank you for being one of the winners of our promotional<br />
program.</em><em>Sincerely Yours<br />
Elsa Dalton<br />
International Relation Officer.<br />
email: <a href="http://www.darknetworks.org/kenmail/src/compose.php?send_to=leonard.walter00%40yahoo.co.uk"><em>leonard.walter00@yahoo.co.uk</em></a><br />
<em>cc: </em><a href="http://www.darknetworks.org/kenmail/src/compose.php?send_to=leonard_walter_00%40yahoo.co.uk"><em>leonard_walter_00@yahoo.co.uk</em></a><br />
<em>Phone:+44-703-192-8619(office hours monday-fridays 8am-6pm)<br />
Phone::+44-702-407-6741<br />
Fax: +44-8704783062<br />
</em><a href="http://www.irishlotto.net/" target="_blank"><em>http://www.irishlotto.net/</em></a><br />
<em>BELOW ARE THE SPONSORS OF THIS PROGRAM<br />
                                                                                        <br />
 <br />
Executives:<br />
Dr. P. Swier (CEO), Mr. Gerald Goodman (Manager Foreign<br />
Operations), Mr. Franklyn Van Der Weijden (Manager Domestic<br />
Banking Operations), Dr. James Williams (Director International<br />
Credit Department), Mrs. Lonni K Anderson (Legal Representative), Mrs.<br />
Lyudmyla Marchukova(Regional Manager), Mr. Stephen Boer<br />
</em></em><em><em>(Chairman), Mr. Chris Moritz(International Relation Officer). </em></em><em> </em></p>
<p> </p>
<p> Now, that&#8217;s a lot of names and information&#8230;.IT MUST BE TRUE. But, of course, it is not. The IP address emanates from LEBANON, not Ireland.  Why would they use free yahoo email addresses? The Irish Lotto does not give away free money to random email addresses, and if they did, they would give it away in  EUROS. Ireland stopped being ruled by the British in 1922,And here&#8217;s another;</p>
<p><em> <font face="Courier New"><strong>Return-Path:</strong> <</font></em><a href="http://www.darknetworks.org/kenmail/src/compose.php?send_to=shirleypatrick3%40virgilio.it"><font face="Courier New"><em>shirleypatrick3@virgilio.it</em></font></a><font face="Courier New"><em>><br />
</em></font><tt><em><strong>Received:</strong> from vsmtp4.tin.it (vsmtp4.tin.it [212.216.176.224])<br />
     by xxx.xxx.xx) with ESMTP id k78Kv7EV004308<br />
     for </em><a href="mailto:XXX@XXX.com"><em>XXX@XXX.com</em></a><em>; Tue, 8 Aug 2006 21:57:08 +0100<br />
</em></tt><tt><em><strong>Received:</strong> from pswm2.cp.tin.it (192.168.70.14) by vsmtp4.tin.it (7.2.072.1)<br />
     id 44D349AF0041BECD; Tue, 8 Aug 2006 22:06:28 +0200<br />
</em></tt><tt><em><strong>Message-ID:</strong> <10cef6351c6.shirleypatrick3@virgilio.it><br />
</em></tt><tt><em><strong>Date:</strong> Tue, 8 Aug 2006 21:04:58 +0100 (GMT+01:00)<br />
</em></tt><tt><em><strong>From:</strong> Elias Maclawrence <</em><a href="http://www.darknetworks.org/kenmail/src/compose.php?send_to=shirleypatrick3%40virgilio.it"><em>shirleypatrick3@virgilio.it</em></a><em>><br />
</em></tt><tt><em><strong>Reply-To:</strong> </em><a href="http://www.darknetworks.org/kenmail/src/compose.php?send_to=elias_lawrence1999%40yahoo.co.uk"><em>elias_lawrence1999@yahoo.co.uk</em></a><br />
</tt><tt><em><strong>Subject:</strong> Greetings,<br />
</em></tt><tt><em><strong>Mime-Version:</strong> 1.0<br />
</em></tt><tt><em><strong>Content-Type:</strong> text/plain;charset=&#8221;UTF-8&#8243;<br />
</em></tt><tt><em><strong>Content-Transfer-Encoding:</strong> 7bit<br />
</em></tt><em><tt><strong>X-Originating-IP:</strong> 80.89.176.36<br />
</tt><tt><tt><tt><tt><tt><tt><tt /></tt></tt><tt><tt><tt><tt><tt /></tt></tt></tt></tt></tt><tt><tt><tt><tt><tt><tt><tt /></tt></tt></tt></tt></tt></tt></tt></tt></tt></em><tt><tt><tt><tt><tt><tt><tt><tt><tt><tt></p>
<pre><font face="Courier New">Greetings,</font></pre>
<pre><font face="Courier New">I am Mrs shirley patrick,Public relations officer for THE
EXPORT COMPANY (UK) LIMITED a company based in United Kingdom
corperated on 05/02/2001 and a Private Limited Company. We are
searching for individuals/companies that can actually handle the
affairs of our company in the Canada/America and Europe as we intend to
extend our frontiers to the rest of the world at large.</font></pre>
<pre><font face="Courier New">We want to
employ your services as our agent in your country you could assist us
to seek for companies that are ready to go into exportations of goods
from United Kingdom as we would be willing to compensate your effort in
this regards moreso you would be tagged as our agent in your region for
any payments/supplies to come directly to our company you would have to
handle the affairs of the supplies and the payment modalities.</font></pre>
<pre><font face="Courier New">Furthermore note that you would have to be fully registered with our
firm to ascertain the new position beckoned on you and also our terms
and conditions would be availed to you based on our modalities of
operation so that you would know the importance and significance of
your duty to THE EXPORT COMPANY (UK) LIMITED.</font></pre>
<pre><font face="Courier New">Please if you are
interested in transacting business with us, we will be very glad but
modalities of acceptance would be availed to you in subsequent
correspondences to you . Please contact us for more information. if you
are interested you are advised to contact my superior officer with the
details below: </font></pre>
<pre><font face="Courier New">THE EXPORT COMPANY (UK) LIMITED
DELTA HOUSE
175-177
BOROUGH HIGH STREET
LONDON
SE1 1XP
contact person:
Mr Elias Maclawrence
Managing Director,
Fax: +448704796066
direct: +447040113994
email:
<a href="mailto:elias_lawrence1999@yahoo.co.uk">elias_lawrence1999@yahoo.co.uk</a></font></pre>
<pre><font face="Courier New">Contact should be made via fax or email
and this should be done within 14 working days otherwise your
application would be delected from our data base.
We hope you enjoy
doing business with us and from all staff of THE EXPORT COMPANY UK)
LIMITED we wish you a happy day.</font></pre>
<p><font face="Courier New"></p>
<pre>
Kind regards,
Mrs shirley patrick
Public relations officer
for: THE EXPORT COMPANY (UK) LIMITED
Tel:
+447024021608</pre>
<pre>
NOTE
Do not reply to this email if interested reply to
my Mr Elias Maclawrence for immediate attention</pre>
<pre> </pre>
<p></font> <em><font face="Courier New"></p>
<p /></font></em><tt><br />
Now, other than dreadful grammer, a non-existant company (checked it on <a href="http://www.companieshouse.gov.uk/WebCHeck/findinfopage/">http://www.companieshouse.gov.uk/WebCHeck/findinfopage/</a>), use of free e-mail addresses,<br />
</tt><tt>and an IP address ORIGINATING IN NIGERIA, why would I be suspicious&#8230;Hmm? </tt></p>
<p /></tt></tt></tt> </p>
<p></tt></tt></tt></tt> </p>
<p></tt></tt></tt></p>
]]></content:encoded>
			<wfw:commentRss>http://www.darknetworks.org/2006/08/spamblame-the-irish/feed/</wfw:commentRss>
		</item>
		<item>
		<title>WPA PSK weaknesses are easily exploitable</title>
		<link>http://www.darknetworks.org/2006/08/wpa-psk-weaknesses-are-easily-exploitable/</link>
		<comments>http://www.darknetworks.org/2006/08/wpa-psk-weaknesses-are-easily-exploitable/#comments</comments>
		<pubDate>Wed, 09 Aug 2006 23:42:31 +0000</pubDate>
		<dc:creator>Ken Baylor</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.darknetworks.org/2006/08/wpa-psk-weaknesses-are-easily-exploitable/</guid>
		<description><![CDATA[WPA is slowly replacing WEP in the home. A quick wardrive around my suburban area of Silicon Valley produced some interesting results. On average, using a simple Netgear WG511T card (without external antenna), there were 8 wireless networks within reach. Of these approximately 60% were using WEP for encryption, 30% were unencrypted and 10% were [...]]]></description>
			<content:encoded><![CDATA[<p><img id="image12" title="Wireless Hacking" style="width: 169px; height: 228px" height="228" alt="Wireless Hacking" src="http://www.darknetworks.org/wp-content/uploads/2006/08/wirelesshacking.jpg" width="169" align="left" />WPA is slowly replacing WEP in the home. A quick wardrive around my suburban area of Silicon Valley produced some interesting results. On average, using a simple Netgear WG511T card (without external antenna), there were 8 wireless networks within reach. Of these approximately 60% were using WEP for encryption, 30% were unencrypted and 10% were using WPA. 10% may not sound like a lot, but last years results were 60% unencrypted and 40% using WEP.</p>
<p>WPA definitely offers stronger security. We have demonstrated this publicly, by breaking 128 bit WEP encryption in less than 2 minutes, even when when very strong passwords were used.</p>
<p><u><font color="#800080"><a href="http://www.pcw.co.uk/personal-computer-world/news/2161974/mcafee-reiterates-wifi-security">http://www.pcw.co.uk/personal-computer-world/news/2161974/mcafee-reiterates-wifi-security</a></font></u></p>
<p><a href="http://www.typepad.com/t/trackback/5519827" /></p>
<p><u><font color="#800080"><a href="http://labs.pcw.co.uk/2006/07/do_you_use_wpa_.html">http://labs.pcw.co.uk/2006/07/do_you_use_wpa_.html</a></font></u></p>
<p><a href="http://www.pcw.co.uk/actions/trackback/2161974" /></p>
<p>However, WPA is still vulnerable when using a weak Pre-Shared Key (PSK), because <font size="2">WPA eavesdropping is possible and is easy. The hard part is &#8216;cracking&#8217; what you have captured. Most consumers and many SMBs do not use an external authentication server, they instead use WPA-PSK (pre-shared key). If the pre-shared key used is &#8216;easy&#8217; (as in likely to succumb to a dictionary attack), then it can be broken easily. However, if this is not the case, then it may be very very difficult to crack the password.</font><font size="2">WPA can be a powerful defensive tool, however it must be configured correctly. We also publically demonstrated how to crack a weak WPA within seconds. With a more powerful dictionary, it may be minutes. With a truly dificult passwords, it may be many many years.<br />
</font></p>
]]></content:encoded>
			<wfw:commentRss>http://www.darknetworks.org/2006/08/wpa-psk-weaknesses-are-easily-exploitable/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Is Google evil?</title>
		<link>http://www.darknetworks.org/2006/08/is-google-evil/</link>
		<comments>http://www.darknetworks.org/2006/08/is-google-evil/#comments</comments>
		<pubDate>Wed, 09 Aug 2006 17:30:36 +0000</pubDate>
		<dc:creator>Ken Baylor</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.darknetworks.org/2006/08/is-google-evil/</guid>
		<description><![CDATA[For many years Foundstone has been teaching the dark side of Google in its Ultimate Hacking courses, and its “Hacking Exposed” series. Google is the number one search tool for hackers. It allows you to carry out full reconnaissance on your target. It is a goldmine of information for those interested in data theft, exploits, [...]]]></description>
			<content:encoded><![CDATA[<p>For many years Foundstone has been teaching the dark side of Google in its Ultimate Hacking courses, and its “Hacking Exposed” series. Google is the number one search tool for hackers. It allows you to carry out full reconnaissance on your target. It is a goldmine of information for those interested in data theft, exploits, hidden company backdoors, identity theft etc. Without the intrusiveness of Google the world would be a safer place (if only by obfuscation). There are many articles on Digital Dirt and the fact that Google has ruined people’s careers, and yet, it is rare to hear anyone complain about them.<br />
          That Is why I read Gary McGraw’s article <strong>Google Is Evil</strong> (<a href="http://www.darkreading.com/document.asp?doc_id=100643&#038;WT.svl=column1_1">http://www.darkreading.com/document.asp?doc_id=100643&#038;WT.svl=column1_1</a>) with great interest. Here Gary explains the day to day use of Google to find exploits that enable criminal activities every day. Further, it allows criminals find victims.<br />
However, the article concludes in the usual ending; “Google is not bad, it just exposes holes to the public, and it’s your problem to find them and fix them”. Pragmatic? Yes, but that is as far as it goes.<br />
 </p>
]]></content:encoded>
			<wfw:commentRss>http://www.darknetworks.org/2006/08/is-google-evil/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Big Brother is coming, thanks to AOL</title>
		<link>http://www.darknetworks.org/2006/08/big-brother-is-coming-thanks-to-aol/</link>
		<comments>http://www.darknetworks.org/2006/08/big-brother-is-coming-thanks-to-aol/#comments</comments>
		<pubDate>Wed, 09 Aug 2006 16:33:32 +0000</pubDate>
		<dc:creator>Ken Baylor</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.darknetworks.org/2006/08/big-brother-is-coming-thanks-to-aol/</guid>
		<description><![CDATA[Privacy on the internet is eroding&#8230;and eroding quickly.
A few months ago we had the Google search warrant debacle. Now we have the AOL release of very sensitive information on its subscribers.
 
Some of it is quite illuminating.
We have AOL User 2281868: Looking For Gay Black Superman With An Overbite
http://consumerist.com/consumer/aol/aol-user-2281868-looking-for-gay-black-superman-with-an-overbite-193001.php
More scary stuff at http://aohellsearches.ytmnd.com/
User 927 searches range [...]]]></description>
			<content:encoded><![CDATA[<p><img id="image9" title="Big Brother" style="width: 153px; height: 140px" alt="Big Brother" src="http://www.darknetworks.org/wp-content/uploads/2006/08/bigbrother.jpg" align="left" />Privacy on the internet is eroding&#8230;and eroding quickly.<br />
A few months ago we had the Google search warrant debacle. Now we have the AOL release of very sensitive information on its subscribers.<br />
 <br />
Some of it is quite illuminating.</p>
<p>We have AOL User 2281868: Looking For Gay Black Superman With An Overbite</p>
<p><a href="http://consumerist.com/consumer/aol/aol-user-2281868-looking-for-gay-black-superman-with-an-overbite-193001.php">http://consumerist.com/consumer/aol/aol-user-2281868-looking-for-gay-black-superman-with-an-overbite-193001.php</a></p>
<p>More scary stuff at <a href="http://aohellsearches.ytmnd.com/">http://aohellsearches.ytmnd.com/</a></p>
<p>User 927 searches range from how long it takes broken legs to heal, to images that could send you to prison for a long time. One of this user&#8217;s searches look for questionable pictures of &#8216;virtual children&#8217;. In some countries, such as the UK these are classified as being the same as &#8216;real children&#8217;, and this carries severe penalties<br />
<a href="http://www.consumerist.com/consumer/privacy/aol-user-927-illuminated-192502.php">http://www.consumerist.com/consumer/privacy/aol-user-927-illuminated-192502.php</a></p>
<p>You can search throught all their gory details right here: <a href="http://www.aolstalker.com/">http://www.aolstalker.com/</a></p>
<p>While the AOL gaffe looks really embarrassing for them, it has a more darker side.</p>
<p>It is well known that in the USA we have no expectation of privacy at work: <a href="http://news.com.com/Court+rules+against+man+in+porn-at-work+case/2100-1030_3-6103544.html?tag=nefd.top">http://news.com.com/Court+rules+against+man+in+porn-at-work+case/2100-1030_3-6103544.html?tag=nefd.top</a><br />
Many of the headline-grabbing cases involve the most egregious of subjects. None-the-less the rulings impact all people at work. So when you find out the local IT guy has been reading your files, he can hide behind company policy and bizarre precedent cases such as this one.</p>
<p>With the release of this information, the Justice Department may again pluck up the courage to demand more information on users. This would again be used to drive through an online anti-pornography law. And how can such a thing be enforced? Only by monitoring all search engines.</p>
<p>George Orwell&#8217;s Thought Police in the book 1984 were terrifying. We are in an age where we pass our thoughts into search engines, evaluate our results, then search again and again. A profile of how we think and what we think about can be extracted from these search engines. Do we really want to surrender that information and be judged upon it? Are these really our private thoughts or are they in the public record?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.darknetworks.org/2006/08/big-brother-is-coming-thanks-to-aol/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Patch Day!</title>
		<link>http://www.darknetworks.org/2006/08/patch-day/</link>
		<comments>http://www.darknetworks.org/2006/08/patch-day/#comments</comments>
		<pubDate>Wed, 02 Aug 2006 02:33:44 +0000</pubDate>
		<dc:creator>Ken Baylor</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.darknetworks.org/2006/08/patch-day/</guid>
		<description><![CDATA[Today is not a good day for security patches, and it&#8217;s not even Microsoft&#8217;s patch Tuesday.
One of the top two consumer security vendors has been in the news for not-so-positive reasons, but a patch for the affected products should be out after intensive testing. But those of us using wordpress, it is time to upgrade to version 2.04 as [...]]]></description>
			<content:encoded><![CDATA[<p>Today is not a good day for security patches, and it&#8217;s not even Microsoft&#8217;s patch Tuesday.</p>
<p>One of the top two consumer security vendors has been in the news for not-so-positive reasons, but a patch for the affected products should be out after intensive testing. But those of us using wordpress, it is time to upgrade to version 2.04 as the previous versions have a very nasty security flaw:</p>
<p><em>WordPress 2.0.4, the latest stable release in our Duke series, is </em><a href="http://wordpress.org/download/"><em>available for immediate download</em></a><em>. This release contains several important security fixes, so it’s highly recommended for all users. We’ve also rolled in a number of bug fixes (over 50!), so it’s a pretty solid release across the board.</em></p>
<p><em>Upgrading is fairly simple, just overwrite your old files with the latest from the download. If you’d like more thorough instructions, </em><a href="http://codex.wordpress.org/Upgrading_WordPress"><em>the Codex</em></a><em> is always the best spot.</em></p>
<p><em>Since this is a security release, if you have any friends with blogs make sure to remind them to upgrade and lend a hand if they’re not too savvy. We’re all in this together.</em></p>
<p><a href="http://wordpress.org/development/2006/07/wordpress-204/">http://wordpress.org/development/2006/07/wordpress-204/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.darknetworks.org/2006/08/patch-day/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
