<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;A08BR30yfip7ImA9WhVbEEs.&quot;"><id>tag:blogger.com,1999:blog-18341144</id><updated>2012-05-26T18:04:16.396-04:00</updated><category term="Mobile" /><category term="Robots" /><category term="Duqu" /><category term="Tools of the Trade" /><category term="Music" /><category term="Photos" /><category term="Pwnage" /><category term="Stuxnet" /><category term="Real Life Pirates" /><category term="Art" /><category term="Science" /><category term="Wallpapers" /><category term="Awesomesauce" /><category term="APT" /><category term="North Korea" /><category term="Malcode" /><category term="Texas" /><category term="Targeted Attack" /><category term="Spy vs Spy" /><category term="Big Brother" /><category term="Iran" /><category term="Exploit Kit Intelligence" /><category term="Data Loss" /><category term="Social Splinter" /><category term="Terrorism / CT" /><category term="DRM" /><category term="Operation Aurora" /><category term="RFID" /><category term="Humor" /><category term="D'oh" /><category term="Rumor Mill" /><category term="Mexico" /><category term="Health" /><title>Thoughts of a Technocrat</title><subtitle type="html">Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science &amp;amp; Security together with the occasional bass-heavy break of Humor. &lt;br&gt;&lt;br&gt;
"There is no security on this earth, there is only opportunity" &lt;br&gt;
- General Douglas MacArthur (1880-1964)</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://djtechnocrat.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>7061</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/ThoughtsOfATechnocrat" /><feedburner:info uri="thoughtsofatechnocrat" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly>This is an XML content feed. It is intended to be viewed in a newsreader or syndicated to another site, subject to copyright and fair use.</feedburner:browserFriendly><entry gd:etag="W/&quot;A08BR3o7cCp7ImA9WhVbEEs.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-3695384270106496365</id><published>2012-05-26T18:04:00.001-04:00</published><updated>2012-05-26T18:04:16.408-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-26T18:04:16.408-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Music" /><title>Music: Ruckspin &amp; Quark - Sunshine</title><content type="html">&lt;iframe width="420" height="315" src="https://www.youtube-nocookie.com/embed/XTeR5UTa3_E?rel=0" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;br /&gt;
--------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://soundcloud.com/ranking-records"&gt;http://soundcloud.com/ranking-records&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-3695384270106496365?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=zXMmg2_Kw1s:PBXAEhgviuY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/zXMmg2_Kw1s" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/3695384270106496365/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/05/music-ruckspin-quark-sunshine.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/3695384270106496365?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/3695384270106496365?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/zXMmg2_Kw1s/music-ruckspin-quark-sunshine.html" title="Music: Ruckspin &amp; Quark - Sunshine" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/05/music-ruckspin-quark-sunshine.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0QMQHc4eSp7ImA9WhVUEE8.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-1810683352088522414</id><published>2012-05-14T15:58:00.002-04:00</published><updated>2012-05-14T17:03:01.931-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-14T17:03:01.931-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="APT" /><title>Fundamentals of Chinese Information Warfare</title><content type="html">&lt;i&gt;The Potomac Institute Cyber Center hosted a special program on Fundamentals of Chinese Information Warfare and Impacts on the Western World on Friday, May 11, 2012. The guest speakers included William T. Hagestad II, author of the new book 21st Century Chinese Cyberwarfare (IT Governance, 2012)&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.potomacinstitute.org/index.php?option=com_content&amp;view=article&amp;id=1193:new-date-may-11-fundamentals-of-chinese-information-warfare&amp;catid=65:past-events&amp;Itemid=94"&gt;http://www.potomacinstitute.org/index.php?option=com_content&amp;view=article&amp;id=1193:new-date-may-11-fundamentals-of-chinese-information-warfare&amp;catid=65:past-events&amp;Itemid=94&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
The commentary is pretty insightful and near the end of touches on some possible geopolitical solutions that can be used to change China's behavior. &lt;br /&gt;
&lt;br /&gt;
Hat-tip to Bill and his &lt;a href="http://red-dragonrising.com/blog/73-video-fundamentals-of-chinese-information-warfare"&gt;Red Dragon Rising&lt;/a&gt; blog.&lt;br /&gt;
&lt;br /&gt;
-----------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Here is the Potomac Institute for Policy Studies lecture and panel discussion on "&lt;a href="http://www.potomacinstitute.org/index.php?option=com_content&amp;view=article&amp;id=1096:live-webcast-at-noon-tuesday-november-8-&amp;catid=65:past-events&amp;Itemid=94"&gt;Russian Cyber Capabilities&lt;/a&gt;".&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-1810683352088522414?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=U6Z0-seyJKs:KMd8403VTNs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/U6Z0-seyJKs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/1810683352088522414/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/05/fundamentals-of-chinese-information.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/1810683352088522414?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/1810683352088522414?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/U6Z0-seyJKs/fundamentals-of-chinese-information.html" title="Fundamentals of Chinese Information Warfare" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/05/fundamentals-of-chinese-information.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ck8NQno6eip7ImA9WhVUEE8.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-7033113028665171</id><published>2012-05-14T14:41:00.002-04:00</published><updated>2012-05-14T14:41:33.412-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-14T14:41:33.412-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Awesomesauce" /><title>Project Grey Goose - Operation Poachers</title><content type="html">&lt;a href="http://jeffreycarr.blogspot.com/2012/05/announcing-project-grey-goose-operation.html"&gt;http://jeffreycarr.blogspot.com/2012/05/announcing-project-grey-goose-operation.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;I'm pleased to announce that the fourth Project Grey Goose investigation, commencing today, will target the very serious problem of domestic and international poaching of endangered species. I founded Project Grey Goose in August, 2008 as an experiment in crowd-sourcing an Open Source Intelligence (OSINT) effort whose goal was to investigate possible Russian government connections in the cyber attacks against Georgian government websites during the Russia Georgia war. Rather than focusing on hackers, this project will focus on criminals who are viciously taking the lives of rare and beautiful animals for body parts and profit; i.e. poachers. The problem is vast and growing, and it's my sincere hope that Project Grey Goose's unique international collaborative approach to OSINT will make an impact.&lt;br /&gt;
&lt;br /&gt;
I'm particularly happy to announce that my co-manager for this project is Nada Bakos, a former CIA intelligence analyst and targeting officer. I can't imagine a more qualified person to help lead this effort than Nada and I'm excited to have her aboard to help this mission succeed.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
-----------------------------------&lt;br /&gt;
&lt;br /&gt;
Check out the link above to Jeffrey's blog, if you want to know how you can help.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-7033113028665171?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=Px24UhVCDKw:HQBth5rkvh8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/Px24UhVCDKw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/7033113028665171/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/05/project-grey-goose-operation-poachers.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/7033113028665171?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/7033113028665171?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/Px24UhVCDKw/project-grey-goose-operation-poachers.html" title="Project Grey Goose - Operation Poachers" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/05/project-grey-goose-operation-poachers.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEACQHY6eSp7ImA9WhVUEEw.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-2119029136897214158</id><published>2012-05-14T12:23:00.002-04:00</published><updated>2012-05-14T12:26:01.811-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-14T12:26:01.811-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="APT" /><title>Uighur Leader Accuses China of ‘Systematic Assimilation’</title><content type="html">Via &lt;a href="http://www.voanews.com/content/uighur_leader_kadeer_accuses_china_systematic_assimiliation/666327.html"&gt;VOA News&lt;/a&gt; -&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Exiled representatives of the Uighur, an ethnic group that lives mainly in Western China’s province of Xinjiang, are meeting in Japan for their fourth annual conference. The World Uighur Congress, based in Germany, opposes what it calls the Chinese occupation of their land, and the group's gatherings routinely draw criticism from Beijing. &lt;br /&gt;
&lt;br /&gt;
Rebiya Kadeer, leader of the World Uighur Congress, and also known as "the Mother of the Uighur Nation," has been living in exile in the United States since her release from a Chinese prison in 2005.&lt;br /&gt;
&lt;br /&gt;
She joined more than 100 representatives of the ethnic group from more than 20 countries, including the United States, Germany and Australia, to elect new leadership and discuss strategies to engage China over the issue of self-determination.&lt;br /&gt;
&lt;br /&gt;
Kadeer said the Uighurs are facing a threat to their existence because of the Chinese government’s policy of systematic assimilation. She also accuses Chinese authorities of committing extra-judicial killings, economic exploitation, and destroying Uighur values.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
--------------------------------------&lt;br /&gt;
&lt;br /&gt;
With that in mind, could you guess who might want to &lt;a href="http://contagiodump.blogspot.com/2012/05/may-3-cve-2012-0779-world-uyghur.html"&gt;target companies or organization interested in the Uyghur Congress with targeted zero-day malware&lt;/a&gt;? I wonder. ;)&lt;br /&gt;
&lt;br /&gt;
APT: A Geopolitical Problem&lt;br /&gt;
&lt;a href="http://www.ericjhuber.com/2011/08/apt-geopolitical-problem.html"&gt;http://www.ericjhuber.com/2011/08/apt-geopolitical-problem.html&lt;/a&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-2119029136897214158?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=87VTuz_2tLg:D6y86HptQHU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/87VTuz_2tLg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/2119029136897214158/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/05/uighur-leader-accuses-china-of.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/2119029136897214158?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/2119029136897214158?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/87VTuz_2tLg/uighur-leader-accuses-china-of.html" title="Uighur Leader Accuses China of ‘Systematic Assimilation’" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/05/uighur-leader-accuses-china-of.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU8CRXc8fCp7ImA9WhVUEUw.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-392103382620766594</id><published>2012-05-13T13:28:00.000-04:00</published><updated>2012-05-15T16:31:04.974-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-15T16:31:04.974-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Pwnage" /><title>South China Sea Spat Goes Cyber</title><content type="html">Via &lt;a href="http://the-diplomat.com/asean-beat/2012/05/11/south-china-sea-spat-goes-cyber/"&gt;The Diplomat&lt;/a&gt; -&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;China continues to raise the heat in its dispute with the Philippines over the sovereignty of Scarborough Shoal/Huangyan Island. On Monday, He Jia, an anchor on China’s state-run CCTV, mistakenly declared that “China has unquestionable sovereignty over the Philippines” rather than just over the disputed island. On Tuesday, Chinese Vice Foreign Minister Fu Ying warned a Philippine diplomat that China was fully prepared to do anything to respond to escalation. Deep-water drilling has begun near islands in the South China Sea and Chinese travel agencies have reportedly suspended tours to the Philippines. Chinese netizens are fully in support of the claims, and have in many instances criticized the Ministry of Foreign Affairs for not taking more assertive action.&lt;br /&gt;
&lt;br /&gt;
As with previous territorial disputes in East Asia these days (see China-Vietnam, China-Japan, and Korea-Japan), the political, diplomatic, and military maneuvering has a cyber component. On April 20, Chinese hackers attacked the website of the University of the Philippines. The next day, Filipino hackers struck back with the defacement of Chinese websites. On the 23rd and 24th, the two sides again traded tit-for-tat attacks (a very useful timeline up until April 30 can be found &lt;a href="http://hackmageddon.com/2012/05/01/philippines-and-china-on-the-edge-of-a-new-cyber-conflict/"&gt;here&lt;/a&gt;). Attacks have continued over the last week; attackers have also pasted the Chinese flag on the website of the Philippines News Agency.&lt;br /&gt;
&lt;br /&gt;
From almost the beginning of the attacks, the Philippines government has called for both sides to stop. On April 22, a Philippines government spokesperson said, “We call on citizens, including ours, to exercise civil temperance.” On April 25, the Philippines’ Department of Science and Technology and Information and Communications Technology Office declared that the attacks were neither sanctioned nor condoned, and on May 10 a spokesman went further in warning that such attacks “will not benefit anyone and could possibly lead to bigger problems in the future for the Philippines and China and escalate the already tense situation at Panatag Shoal (Scarborough Shoal).” This is not a misplaced worry as freelance attacks could make it much more difficult for the two sides to communicate and signal intentions.&lt;br /&gt;
&lt;br /&gt;
Unfortunately, there has been silence from Beijing on the issue. China’s leaders seem to be embracing the conflict, or at least the prospect of conflict, as a welcome distraction from the problems of Chen Guangcheng and Bo Xilai. As Michael Yip and Craig Weber argue, the Chinese government – after years of enrolling students in patriotic education that stresses a history of national humiliation – needs to align itself with and divert away from nationalistic responses to real and perceived slights. Political hacking acts as a diversion – venting resentment away from the regime, focusing web users’ ire on outside actors, and maintaining the government’s nationalistic credentials.&lt;br /&gt;
&lt;br /&gt;
When China’s Minister of Defense General Liang Guanglie was at the Pentagon this week, he talked about how China wanted to work to improve cybersecurity. Beijing could gain a great deal of credibility by doing what the Philippines has done: call on both sides to stop the attacks.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-392103382620766594?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=uzTtyAkzHi4:IULAJKEKNc8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/uzTtyAkzHi4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/392103382620766594/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/05/south-china-sea-spat-goes-cyber.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/392103382620766594?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/392103382620766594?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/uzTtyAkzHi4/south-china-sea-spat-goes-cyber.html" title="South China Sea Spat Goes Cyber" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>3</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/05/south-china-sea-spat-goes-cyber.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0IGQ34-eSp7ImA9WhVVF0s.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-9031392416022425897</id><published>2012-05-11T14:37:00.000-04:00</published><updated>2012-05-11T14:38:42.051-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-11T14:38:42.051-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="APT" /><title>TTPs: Lessons from Today's Amnesty Hack</title><content type="html">Via &lt;a href="http://blog.imperva.com/2012/05/lessons-from-todays-amnesty-hack.html"&gt;Imperva&lt;/a&gt; - &lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Amnesty International UK's website was hacked courtesy a backdoor dropped on visitors systems. Most likely done by a foreign government, many speculate that it's the Chinese. Websense's blog &lt;a href="http://community.websense.com/blogs/securitylabs/archive/2012/05/11/amnesty-international-uk-compromised.aspx?cmpid=sltw"&gt;gives a good technical overview of the attack&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
But what does it mean for security teams?&lt;br /&gt;
&lt;br /&gt;
In some cases, hackers don’t want to steal the data from the website but rather want to infect the users who are visiting. This can lead to more access to business critical data which, for example, is often stored as files on a fileserver. In the Amnesty case, the real prize isn't Amnesty's data per se, but the corporate and individual data and files of those who visit the site.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
This exact technique has been used by advanced adversaries in previous targeted attacks. Intelligence sources have obvsered this technique being used in attacks against the US defense industry as well.&lt;br /&gt;
&lt;br /&gt;
July 2011 - &lt;a href="http://www.darkreading.com/advanced-threats/167901091/security/attacks-breaches/231002231/attack-on-pacific-northwest-national-lab-started-at-public-web-servers.html"&gt;Attack On Pacific Northwest National Lab Started At Public Web Servers&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-9031392416022425897?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=u_Coe7lHB1E:dr2Qce564SI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/u_Coe7lHB1E" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/9031392416022425897/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/05/ttps-lessons-from-todays-amnesty-hack.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/9031392416022425897?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/9031392416022425897?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/u_Coe7lHB1E/ttps-lessons-from-todays-amnesty-hack.html" title="TTPs: Lessons from Today's Amnesty Hack" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/05/ttps-lessons-from-todays-amnesty-hack.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEIAQ3oyfSp7ImA9WhVVFks.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-7377875865889570837</id><published>2012-05-10T11:09:00.000-04:00</published><updated>2012-05-10T11:09:02.495-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-10T11:09:02.495-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Iran" /><title>Iran's Web Censorship Filters Supreme Leader's Own Statement</title><content type="html">Via &lt;a href="http://arstechnica.com/tech-policy/2012/05/irans-web-censorship-filters-supreme-leaders-own-statement/"&gt;Ars Technica&lt;/a&gt; -&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Iranian Supreme Leader Ayatollah Ali Khamenei’s own words have now become a victim of Iran’s massive online censorship infrastructure.&lt;br /&gt;
&lt;br /&gt;
According to &lt;a href="http://www.rferl.org/content/iran_filters_khamenei_fatwa_on_antifiltering_internet/24575143.html"&gt;Radio Free Europe&lt;/a&gt; (RFE), last week Khamenei issued a “fatwa,” or religious edict, confirming that anti-filtering tools and software are illegal in Iran. The decree came in response to a question by Mehr News (Google Translate), a semi-official news agency, which had asked for clarification on the ruling due to the fact that, as journalists, employees sometimes need to access blocked websites and other non-authorized information.&lt;br /&gt;
&lt;br /&gt;
Khamenei, according to a translation by RFE, replied: "In general, the use of antifiltering software is subject to the laws and regulations of the Islamic republic, and it is not permissible to violate the law."&lt;br /&gt;
&lt;br /&gt;
However, his own use of the word “antifiltering” apparently triggered Iran’s own filtering system, making Khamenei’s words inaccessible to most Iranians.&lt;br /&gt;
&lt;br /&gt;
RFE also reported that this filtering episode prompted Tabnak, a conservative news website, to respond: "The filtering of a [religious] order is so ugly for the executive [branch] that it can bring into question the whole philosophy of filtering."&lt;br /&gt;
&lt;br /&gt;
Iran, of course, has a notorious surveillance and filtration system in place—just last month, the &lt;a href="http://arstechnica.com/tech-policy/news/2012/04/iran-publishes-request-for-information-for-halal-internet-project.ars"&gt;Islamic Republic published a "Request for Information"&lt;/a&gt; for furthering its so-called "halal Internet."&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-7377875865889570837?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=LwTUQJxzUK0:zRmmG8v1ZxQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/LwTUQJxzUK0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/7377875865889570837/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/05/irans-web-censorship-filters-supreme.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/7377875865889570837?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/7377875865889570837?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/LwTUQJxzUK0/irans-web-censorship-filters-supreme.html" title="Iran's Web Censorship Filters Supreme Leader's Own Statement" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/05/irans-web-censorship-filters-supreme.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEYHQXo4cSp7ImA9WhVVFkw.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-2858639991835684115</id><published>2012-05-09T22:15:00.000-04:00</published><updated>2012-05-09T22:15:30.439-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-09T22:15:30.439-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Music" /><title>Matisyahu - One Day (Coma Remix)</title><content type="html">&lt;iframe width="420" height="315" src="https://www.youtube-nocookie.com/embed/0upDphQdFwY?rel=0" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-2858639991835684115?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=FGAcq6W-CN0:5J0pV3HtHO8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/FGAcq6W-CN0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/2858639991835684115/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/05/matisyahu-one-day-coma-remix.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/2858639991835684115?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/2858639991835684115?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/FGAcq6W-CN0/matisyahu-one-day-coma-remix.html" title="Matisyahu - One Day (Coma Remix)" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/05/matisyahu-one-day-coma-remix.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0MDQX4_cSp7ImA9WhVVFEU.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-6019000502811501558</id><published>2012-05-08T11:04:00.003-04:00</published><updated>2012-05-08T11:04:30.049-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-08T11:04:30.049-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="North Korea" /><title>GPS Jamming Affects Ship Navigation off Korean Coast</title><content type="html">Via &lt;a href="http://www.marinelink.com/news/navigation-jamming344438.aspx"&gt;Marine Link&lt;/a&gt; -&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;122 ships, including Coast Guard vessels and a passenger vessel, have reported malfunctions in their navigation systems since the apparent jamming of satellite signals by North Korea last week, reported 'Safety4Sea'.&lt;br /&gt;
&lt;br /&gt;
According to the Coast Guard in Incheon, west of Seoul, a total of 122 ships were affected by the disruption to Global Positioning System (GPS) signals. Among the vessels were eight patrol boats belonging to the Coast Guard, a passenger liner carrying 387 people and a petrol products carrier.&lt;br /&gt;
&lt;br /&gt;
Fishing boats operating near the tense western maritime border with North Korea also reported errors in their navigation systems, although none of them led to accidents, Coast Guard officials said.&lt;br /&gt;
&lt;br /&gt;
The transport ministry said about 250 commercial flights in and out of international airports at Incheon and Gimpo, also west of Seoul, were also affected by the jamming, although they were not put in danger.&lt;br /&gt;
&lt;br /&gt;
South Korea came under similar electronic attacks in March of last year, and in August and December of 2010, all of which were blamed on the North. South Korean Defense Minister Kim Kwan-jin has said anti-jamming programs are being developed to counter the attacks.&lt;br /&gt;
&lt;br /&gt;
The defense ministry has also said the North operates a regiment-sized electronic warfare unit near its capital Pyongyang, and some battalion-sized units closer to the inter-Korean border.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-6019000502811501558?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=IIsQdoAICHA:7WRgauFN__g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/IIsQdoAICHA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/6019000502811501558/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/05/gps-jamming-affects-ship-navigation-off.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/6019000502811501558?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/6019000502811501558?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/IIsQdoAICHA/gps-jamming-affects-ship-navigation-off.html" title="GPS Jamming Affects Ship Navigation off Korean Coast" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/05/gps-jamming-affects-ship-navigation-off.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0INSH87eSp7ImA9WhVVE0s.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-6838532831151580774</id><published>2012-05-06T23:32:00.000-04:00</published><updated>2012-05-06T23:33:19.101-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-06T23:33:19.101-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Terrorism / CT" /><title>On The Rebound: Shining Path Factions Vie for Control of Upper Huallaga Valley</title><content type="html">Via &lt;a href="http://www.jamestown.org/single/?no_cache=1&amp;tx_ttnews[tt_news]=39249&amp;tx_ttnews[backPid]=7&amp;cHash=1619237a4707dc8fdd291d5d5d570574"&gt;The Jamestown Foundation&lt;/a&gt; -&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;After the Peruvian army captured Comrade Artemio on February 12 and two potential successors on March 4 and April 3, President Ollanta Humala declared that the Shining Path was “totally defeated”—a prediction that is already proving to be premature. The Shining Path faction in the Upper Huallaga Valley retains a core group of loyal fighters capable of conducting military operations to pressure the government for Artemio’s release, but they are more dangerous for their apparent alliance with Movadef, a rising political movement that the government sees as a “front” for the Shining Path. Meanwhile, the 500-fighter faction of the Shining Path led by Comrade Jose in the VRAE has made clear its desire to expand its international narco-trafficking enterprise into the Upper Huallaga Valley and exploit the power vacuum with Artemio out of the picture. A takeover of the Upper Huallaga Valley would elevate Comrade Jose to the level of one of South America’s premier narco-trafficking bosses. Neither Shining Path faction is near surrender, and questions linger about whether President Humala’s new four-year anti-drug strategy underwritten by millions of dollars of U.S. aid will tame or enflame the country’s narco-trafficking insurgencies.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Background&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The Shining Path consists of a 500-fighter faction in the River Apurimac and River Ene Valley (VRAE) led by Comrade Jose and a smaller 150-fighter faction in the Upper Huallaga Valley led until February 12 by Comrade Artemio. The VRAE and Upper Huallaga Valley factions split in 1999 after the capture of then leader Comrade Feliciano (Oscar Ramirez Durand). Comrade Artemio succeeded Feliciano in 1999 and remained loyal to Shining Path founder, Abimael Guzman (Chairman Gonzalo), who was captured in 1992. After Feliciano’s capture, Comrade Jose’s faction disavowed the Shining Path of Guzman, Feliciano and Artemio, who they criticized for alienating the campesinos during the war against the State in 1980s and for offering truces to the government once Guzman was captured.&lt;br /&gt;
&lt;br /&gt;
Both factions officially espouse turning Peru into a Marxist state, but they depend on their capitalist narco-trafficking enterprises for financial survival. It is no coincidence that the two surviving factions of the once 15,000-fighter Shining Path operate in the country’s two main coca producing regions—the VRAE and the Upper Huallaga Valley, which produce 75% of Peru’s coca. With Peru expected to surpass Colombia as the world’s largest coca producer (61,200 hectares) in 2012, both factions stand to benefit.&lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Conclusion&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The capture of Comrade Artemio has weakened his faction, but a core group of his fighters continue to engage in shows of military force to support Movadef’s political goals. There appears to be a low likelihood of a Shining Path merger considering that the two groups operate in distinct areas and harbor contrasting motivations. If Artemio’s faction continues to splinter, however, Jose’s faction may gain control of the major drug trafficking routes in the Upper Huallaga Valley and revive the Shining Path under a model like the FARC—a drug cartel with a nominal Marxist ideology. Both Shining Path factions benefit from the country’s increasing coca production, while they are also capable attracting recruits from the cocaleros if the drug eradication plan moves forward. The drug war can only be won if the cocaleros are provided with a substitute to growing coca, but historically the state has struggled to meet this need.&lt;br /&gt;
&lt;br /&gt;
After the capture of Abimael Guzman in 1992, then President Fujimori said, “Sendero has been defeated. I defeated it.” Twenty years later, President Humala shows similar optimism, but the events on the ground suggest that both Shining Path factions will adapt to the realities on the ground after Artemio’s picture and implement new strategies in order to survive.&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://en.wikipedia.org/wiki/Shining_Path"&gt;http://en.wikipedia.org/wiki/Shining_Path&lt;/a&gt;&lt;br /&gt;
&lt;blockquote&gt;&lt;i&gt;Shining Path (Sendero Luminoso in Spanish) is a Maoist guerrilla insurgent organization in Peru. It prefers to be called the "Communist Party of Peru" or "PCP" for short.  The Shining Path's ideology and tactics have been influential on other Maoist insurgent groups, notably the Communist Party of Nepal (Maoist) and other Revolutionary Internationalist Movement-affiliated organizations. Widely condemned for its brutality, including violence deployed against peasants, trade union organizers, popularly elected officials and the general civilian population, the Shining Path is described by the Peruvian government as a terrorist organization. The group is on the U.S. Department of State's list of Foreign Terrorist Organizations, and the European Union and Canada likewise describe it as a terrorist organization and prohibit providing funding or other financial support.&lt;/i&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-6838532831151580774?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=Byoc_F5HG_8:yhZjt8IgtHA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/Byoc_F5HG_8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/6838532831151580774/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/05/on-rebound-shining-path-factions-vie.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/6838532831151580774?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/6838532831151580774?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/Byoc_F5HG_8/on-rebound-shining-path-factions-vie.html" title="On The Rebound: Shining Path Factions Vie for Control of Upper Huallaga Valley" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/05/on-rebound-shining-path-factions-vie.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEEMSHkzeSp7ImA9WhVVEUk.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-3954094924897790359</id><published>2012-05-04T11:50:00.000-04:00</published><updated>2012-05-04T11:51:29.781-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-04T11:51:29.781-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Targeted Attack" /><title>Xtreme RAT Used in Targeted Attack Against Syria Activist</title><content type="html">Via &lt;a href="http://www.f-secure.com/weblog/archives/00002356.html"&gt;F-Secure Labs&lt;/a&gt; -&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Syria has been the center of much international attention lately. There's unrest in the country and the authoritarian government is using brutal tactics against dissidents. These tactics include using technology surveillance, trojans and backdoors.&lt;br /&gt;
&lt;br /&gt;
Some time ago we received a hard drive via a contact. The drive had an image of the system of a Syrian activist who had been targeted by the local authorities.&lt;br /&gt;
&lt;br /&gt;
The activist's system had become infected as a result of a Skype chat. The chat request came from a fellow activist. The problem was that the fellow activist had already been arrested and could not have started the chat.&lt;br /&gt;
&lt;br /&gt;
Initial infection occurred when the activist accepted a file called MACAddressChanger.exe over the chat. This utility was supposed to change the hardware MAC address of the system in order to bypass some monitoring tools. Instead, it dropped a file called silvia.exe which was a backdoor — a backdoor called "Xtreme RAT". &lt;br /&gt;
&lt;br /&gt;
Xtreme Rat is a full-blown malicious Remote Access Tool.&lt;br /&gt;
&lt;br /&gt;
Sold for 100 euro (Paypal) via a page hosted at Google Sites: hxxps://sites.google.com/site/nxtremerat&lt;br /&gt;
&lt;br /&gt;
We have reasons to believe this infection wasn't just bad luck. We believe the activist's computer was specifically targeted. In any case, the backdoor calls home to the IP address 216.6.0.28. This IP block belongs to Syrian Arab Republic — STE (Syrian Telecommunications Establishment).&lt;br /&gt;
&lt;br /&gt;
This would not have been the first case of using trojans for such purposes in Syria, either.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-3954094924897790359?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=SIWpyT_g7k8:ZXyhNt1IPxg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/SIWpyT_g7k8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/3954094924897790359/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/05/xtreme-rat-used-in-targeted-attacks.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/3954094924897790359?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/3954094924897790359?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/SIWpyT_g7k8/xtreme-rat-used-in-targeted-attacks.html" title="Xtreme RAT Used in Targeted Attack Against Syria Activist" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/05/xtreme-rat-used-in-targeted-attacks.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEEFQHg7eip7ImA9WhVVEUw.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-8959334882595853731</id><published>2012-05-04T02:23:00.002-04:00</published><updated>2012-05-04T02:23:31.602-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-04T02:23:31.602-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Music" /><title>"Right On" by The Roots (feat. Joanna Newsom &amp; STS)</title><content type="html">&lt;iframe src="http://player.vimeo.com/video/12744936" width="500" height="283" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-8959334882595853731?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=_BJTUs1PMzY:Dd4aOsK0DMU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/_BJTUs1PMzY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/8959334882595853731/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/05/right-on-by-roots-feat-joanna-newsom.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/8959334882595853731?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/8959334882595853731?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/_BJTUs1PMzY/right-on-by-roots-feat-joanna-newsom.html" title="&quot;Right On&quot; by The Roots (feat. Joanna Newsom &amp; STS)" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/05/right-on-by-roots-feat-joanna-newsom.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUEAR3k7fSp7ImA9WhVVEUk.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-4773489026644720419</id><published>2012-05-03T16:20:00.002-04:00</published><updated>2012-05-04T11:00:46.705-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-04T11:00:46.705-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="APT" /><title>Microsoft Fingers Chinese Firewall/IPS Vendor In Windows Exploit Leak</title><content type="html">Via &lt;a href="http://www.darkreading.com/insider-threat/167801100/security/vulnerabilities/232901426/microsoft-fingers-chinese-firm-in-windows-exploit-leak.html"&gt;Dark Reading&lt;/a&gt; -&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Microsoft today announced that it had rooted out the source of a leak from within its third-party security software firm partnership program that resulted in the weaponization of a bug in Windows -- raising questions about whether the Microsoft Active Protections Program (MAPP) could be vulnerable to other such breaches. &lt;br /&gt;
&lt;br /&gt;
Chinese firewall and IPS vendor Hangzhou DPTech Technologies Co., Ltd., according to Microsoft, was the culprit behind a rapid-fire turnaround of a working exploit for the Windows Remote Desktop (RDP) flaw in mid-March, &lt;a href="http://www.darkreading.com/vulnerability-management/167901026/security/news/232602627/microsoft-flaw-demonstrates-dangers-of-remote-desktop-access.html"&gt;just after the bug was patched by Microsoft&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
Microsoft today was mum on how it ultimately rooted out DPTech as the source of the leak, or on just what Hangzhou DPTech Technologies did. "During our investigation into the disclosure of confidential data shared with our Microsoft Active Protections Program (MAPP) partners, we determined that a member of the MAPP program, Hangzhou DPTech Technologies Co., Ltd., had breached our non-disclosure agreement (NDA). Microsoft takes breaches of our NDAs very seriously and has removed this partner from the MAPP Program," said Yunsun Wee, director or Microsoft Trustworthy Computing, in a statement. &lt;br /&gt;
&lt;br /&gt;
HD Moore, chief security officer at Rapid7 and creator of Metasploit, says it couldn't have been simple to trace the leak to a specific company. "[It's] interesting and somewhat surprising that they found it at all," Moore says. &lt;br /&gt;
&lt;br /&gt;
Meanwhile, the announcement by Microsoft appears to raise more questions than it answers. Concerns about a Chinese security vendor leaking Windows vulnerability details before the patch window had closed, and whether this was truly the first breach of the MAPP program, sent a chill through the industry. &lt;br /&gt;
&lt;br /&gt;
"Yes, it is a little concerning that it was a Chinese firm that leaked the Microsoft information. That being said, what did Microsoft really expect was going to happen? The Chinese do not have a very good track record of adhering to NDA and other agreements," says Paul Henry, security and forensic analyst at Lumension. "It is important to recognize that the MAPP program is relatively new, so there will be bumps in the road as Microsoft works out the delicate balance between strategic sharing and safeguarding the distribution of sensitive information regarding its products." &lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
-----------------------------------------&lt;br /&gt;
&lt;br /&gt;
MAPP Update: Taking Action to Decrease Risk of Information Disclosure&lt;br /&gt;
&lt;a href="http://blogs.technet.com/b/msrc/archive/2012/05/03/mapp-update-taking-action-to-decrease-risk-of-information-disclosure.aspx"&gt;http://blogs.technet.com/b/msrc/archive/2012/05/03/mapp-update-taking-action-to-decrease-risk-of-information-disclosure.aspx&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
-----------------------------------------&lt;br /&gt;
&lt;br /&gt;
Shocker. Kudos to MS for tracking this down to the company. Impressive.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-4773489026644720419?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=8GOer0bv_Ag:7ItiJjMYUwU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/8GOer0bv_Ag" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/4773489026644720419/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/05/microsoft-fingers-chinese-firewallips.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/4773489026644720419?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/4773489026644720419?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/8GOer0bv_Ag/microsoft-fingers-chinese-firewallips.html" title="Microsoft Fingers Chinese Firewall/IPS Vendor In Windows Exploit Leak" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/05/microsoft-fingers-chinese-firewallips.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DE4FRng9cCp7ImA9WhVWGEw.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-6921016824977419780</id><published>2012-04-30T16:10:00.001-04:00</published><updated>2012-04-30T16:15:17.668-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-30T16:15:17.668-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Targeted Attack" /><category scheme="http://www.blogger.com/atom/ns#" term="APT" /><title>Determined Adversaries and Targeted Attacks</title><content type="html">Via &lt;a href="http://www.microsoft.com/security/sir/story/default.aspx#!determined_adversaries"&gt;Microsoft Security Intelligence Report&lt;/a&gt; -&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Over the past two decades the internet has become fundamental to the pursuit of day-to-day commercial, personal, and governmental business. However, the ubiquitous nature of the internet as a communications platform has also increased the risk to individuals and organizations from cyberthreats. These threats include website defacement, virus and worm (or malware) outbreaks, and network intrusion attempts. In addition, the global presence of the internet has allowed it to be used as a significant staging ground for espionage activity directed at industrial, political, military, and civil targets.&lt;br /&gt;
&lt;br /&gt;
During the past 5 years, one specific category of threat has become much more widely discussed. Originally referred to as Advanced Persistent Threats (APT) by the U.S. military — referring to alleged nation-state sponsored attempts to infiltrate military networks and exfiltrate sensitive data — the term APT is today widely used in media and IT security circles to describe any attack that seems to specifically target individual organization, or is thought to be notably technical in nature, regardless of whether the attack was actually either advanced or persistent.&lt;br /&gt;
&lt;br /&gt;
In fact, this type of attack typically involves two separate components — the action(s) and the actor(s) — that may be targeted against governments, military organizations or, increasingly, commercial entities and civil society.&lt;br /&gt;
&lt;br /&gt;
The actions are the attacks themselves, which may be IT-related or not, and are referred to as Targeted Attacks in this paper. These attacks are initiated and conducted by human actors, who are collectively referred to in this paper as Determined Adversaries. These definitions are important because they emphasize the point that the attacks are carried out by human actors who may use any tools or techniques necessary to achieve their goals; these attacks are not merely malicious software or exploits. Using an encompassing term such as APT can mask this reality and create the impression that all such attacks are technically sophisticated and malware-driven, making it harder to plan an effective defensive posture.&lt;br /&gt;
&lt;br /&gt;
For these reasons, this paper uses Targeted Attacks and Determined Adversaries as more specific and meaningful terms to describe this category of attack.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
-------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Be sure to check out Microsoft's Security Intelligence Report (SIR) Volume 12.&lt;br /&gt;
&lt;a href="http://www.microsoft.com/security/sir/default.aspx"&gt;http://www.microsoft.com/security/sir/default.aspx&lt;/a&gt;&lt;br /&gt;
&lt;blockquote&gt;&lt;i&gt;The Microsoft Security Intelligence Report (SIR) analyzes the threat landscape of exploits, vulnerabilities, and malware using data from Internet services and over 600 million computers worldwide. Threat awareness can help you protect your organization, software, and people.&lt;/i&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-6921016824977419780?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=53NE9M8HsEk:TPnA7Rya3NI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/53NE9M8HsEk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/6921016824977419780/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/04/determined-adversaries-and-targeted.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/6921016824977419780?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/6921016824977419780?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/53NE9M8HsEk/determined-adversaries-and-targeted.html" title="Determined Adversaries and Targeted Attacks" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/04/determined-adversaries-and-targeted.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkYFQHs_fyp7ImA9WhVWF00.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-4708656472639865926</id><published>2012-04-29T10:01:00.002-04:00</published><updated>2012-04-29T10:01:51.547-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-29T10:01:51.547-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Malcode" /><title>Snow Leopard Users Most Prone to Flashback Infection</title><content type="html">Via &lt;a href="http://www.computerworld.com/s/article/9226696/Snow_Leopard_users_most_prone_to_Flashback_infection"&gt;Computerworld.com&lt;/a&gt; -&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Of the Macs that have been infected by the Flashback malware, nearly two-thirds are running OS X 10.6, better known as Snow Leopard, a Russian antivirus company said Friday.&lt;br /&gt;
&lt;br /&gt;
Doctor Web, which earlier this month was the first to report the largest-ever malware attack against Apple Macs, mined data it's intercepted from compromised computers to come up with its findings.&lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
In a &lt;a href="http://news.drweb.com/?i=2410&amp;c=5&amp;lng=en&amp;p=0"&gt;Friday blog post&lt;/a&gt;, Doctor Web published an analysis of the communications between 95,000 Flashback-infected Macs and the sinkholed domains. Those communication attempts took place on April 13, more than a week after Doctor Web broke the news of the botnet's massive size.&lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
Not surprisingly, 63.4% of the Flashback-infected machines identified themselves as running OS X 10.6, or Snow Leopard, the newest version of Apple's operating system that comes with Java.&lt;br /&gt;
&lt;br /&gt;
Snow Leopard accounted for the largest share of OS X last month, according to metrics company Net Applications, making it the prime target of Flashback.&lt;br /&gt;
&lt;br /&gt;
Leopard, or OS X 10.5, is the second-most-common Flashback-infected operating system, said Doctor Web: 25.5% of the 95,000 Macs harboring the malware ran that 2007 edition.&lt;br /&gt;
&lt;br /&gt;
Apple bundled Java with Leopard as well, but unlike Snow Leopard and Lion, it no longer ships security updates for the OS, and so has not updated Java on those Macs.&lt;br /&gt;
&lt;br /&gt;
Last month, Leopard powered 13.6% of all Macs.&lt;br /&gt;
&lt;br /&gt;
But while Snow Leopard's and Leopard's infection rates are higher than their usage shares, the opposite's true of OS X 10.7, or Lion. The 2011 OS accounted for 39.6% of all copies of OS X used last month, yet represented only 11.2% of the Flashback-compromised Macs.&lt;br /&gt;
&lt;br /&gt;
Doctor Web did not connect those dots in its analysis, but the numbers make clear that versions of Mac OS X that included Java -- Snow Leopard and Leopard -- are much more likely to be infected by Flashback. Conversely, Lion -- by default, sans Java -- is significantly more resistant to the malware.&lt;br /&gt;
&lt;br /&gt;
The Russian company's data also showed that many Mac users don't keep their machines up-to-date, something ZDNet blogger Ed Bott noted on Friday.&lt;br /&gt;
&lt;br /&gt;
Twenty-four percent of the Snow Leopard-infected Macs were at least one update behind, 10.4% were three or more behind, and 8.5% were four or more behind.&lt;br /&gt;
&lt;br /&gt;
Lion users were no better patch practitioners: 28% were one or more updates behind.&lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
To protect Snow Leopard and Lion systems from the Java-exploiting Flashback, users should launch Software Update from the Apple menu and download this month's Java updates. Software Update will also serve the newest version of those operating systems to Macs running outdated editions.&lt;br /&gt;
&lt;br /&gt;
People running Leopard can disable Java in their browser(s) to stymie attacks.&lt;br /&gt;
&lt;br /&gt;
Later this year, Oracle will release Java 7 for OS X. Mac users who upgrade to Java 7 will then receive security updates directly from Oracle, not from Apple.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-4708656472639865926?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=xtk2-cNVw14:0mjyqXUXihg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/xtk2-cNVw14" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/4708656472639865926/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/04/snow-leopard-users-most-prone-to.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/4708656472639865926?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/4708656472639865926?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/xtk2-cNVw14/snow-leopard-users-most-prone-to.html" title="Snow Leopard Users Most Prone to Flashback Infection" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/04/snow-leopard-users-most-prone-to.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEEMSH4zeip7ImA9WhVWFk4.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-8558101804854226479</id><published>2012-04-28T13:03:00.001-04:00</published><updated>2012-04-28T13:04:49.082-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-28T13:04:49.082-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Music" /><title>Music: Swindle (ft. Footsie &amp; Nadia Suliman) – Ignition</title><content type="html">&lt;iframe width="560" height="315" src="https://www.youtube-nocookie.com/embed/fokZmNqoXKs?rel=0" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;
&lt;br /&gt;
---------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.beatport.com/artist/swindle/136004"&gt;Swindle&lt;/a&gt; and &lt;a href="http://www.beatport.com/release/ignition/844783"&gt;Ignition&lt;/a&gt; on Beatport.com.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-8558101804854226479?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=hhMLdv5RaxE:0UatYGkQNeM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/hhMLdv5RaxE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/8558101804854226479/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/04/music-swindle-ft-footsie-nadia-suliman.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/8558101804854226479?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/8558101804854226479?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/hhMLdv5RaxE/music-swindle-ft-footsie-nadia-suliman.html" title="Music: Swindle (ft. Footsie &amp; Nadia Suliman) – Ignition" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/04/music-swindle-ft-footsie-nadia-suliman.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkAHR384eSp7ImA9WhVWFkg.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-843670047482443244</id><published>2012-04-27T20:07:00.000-04:00</published><updated>2012-04-28T20:18:56.131-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-28T20:18:56.131-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Photos" /><title>Photos: Space Shuttle Discovery</title><content type="html">Grabbed these shots today, at about 4:45pm EST. Free entrance and parking at Steven F. Udvar-Hazy Center.&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://en.wikipedia.org/wiki/Space_Shuttle_Discovery"&gt;Space Shuttle Discovery&lt;/a&gt; (Orbiter Vehicle Designation: OV-103) @ &lt;a href="http://en.wikipedia.org/wiki/Steven_F._Udvar-Hazy_Center"&gt;Steven F. Udvar-Hazy Center&lt;/a&gt;, an annex of the Smithsonian Institution's National Air and Space Museum.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-nGvD96zg5c8/T5yItHR0WqI/AAAAAAAAA_U/YGJ9SSS5byU/s1600/Discovery-5.jpg" imageanchor="1" style=""&gt;&lt;img border="0" height="400" width="300" src="http://3.bp.blogspot.com/-nGvD96zg5c8/T5yItHR0WqI/AAAAAAAAA_U/YGJ9SSS5byU/s400/Discovery-5.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-g2bTf9trmQk/T5yI3nAyabI/AAAAAAAAA_g/2hqIoTiFifI/s1600/Discovery-4.jpg" imageanchor="1" style=""&gt;&lt;img border="0" height="300" width="400" src="http://3.bp.blogspot.com/-g2bTf9trmQk/T5yI3nAyabI/AAAAAAAAA_g/2hqIoTiFifI/s400/Discovery-4.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-gcAEf-9AZt8/T5sz6rYMwWI/AAAAAAAAA-Y/333r7R8_bQk/s1600/IMG_2906.jpg" imageanchor="1" style=""&gt;&lt;img border="0" height="400" width="300" src="http://4.bp.blogspot.com/-gcAEf-9AZt8/T5sz6rYMwWI/AAAAAAAAA-Y/333r7R8_bQk/s400/IMG_2906.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-0EYCLUbVo74/T5s0A2UAjFI/AAAAAAAAA-k/LBwNBS9NaJA/s1600/IMG_2989.jpg" imageanchor="1" style=""&gt;&lt;img border="0" height="274" width="400" src="http://1.bp.blogspot.com/-0EYCLUbVo74/T5s0A2UAjFI/AAAAAAAAA-k/LBwNBS9NaJA/s400/IMG_2989.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-K8urI1DyWOY/T5s0WWKN5MI/AAAAAAAAA-w/FC_XqsNnouI/s1600/Discovery-2.jpg" imageanchor="1" style=""&gt;&lt;img border="0" height="364" width="400" src="http://4.bp.blogspot.com/-K8urI1DyWOY/T5s0WWKN5MI/AAAAAAAAA-w/FC_XqsNnouI/s400/Discovery-2.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-pD7egMhV7Xk/T5s0ke-bwTI/AAAAAAAAA-8/KANXq0IKasg/s1600/Discovery-3.jpg" imageanchor="1" style=""&gt;&lt;img border="0" height="142" width="400" src="http://2.bp.blogspot.com/-pD7egMhV7Xk/T5s0ke-bwTI/AAAAAAAAA-8/KANXq0IKasg/s400/Discovery-3.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-843670047482443244?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=nLh5zJekrug:-SBRkOSzrqA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/nLh5zJekrug" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/843670047482443244/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/04/photos-space-shuttle-discovery.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/843670047482443244?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/843670047482443244?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/nLh5zJekrug/photos-space-shuttle-discovery.html" title="Photos: Space Shuttle Discovery" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-nGvD96zg5c8/T5yItHR0WqI/AAAAAAAAA_U/YGJ9SSS5byU/s72-c/Discovery-5.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/04/photos-space-shuttle-discovery.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0cGRnYzcCp7ImA9WhVWE0Q.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-1835001373682421795</id><published>2012-04-25T17:55:00.002-04:00</published><updated>2012-04-25T17:57:07.888-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-25T17:57:07.888-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Terrorism / CT" /><title>US Experts To Help Decrypt 'FARC' Computers</title><content type="html">Via &lt;a href="http://colombiareports.com/colombia-news/news/23635-us-experts-help-decrypt-farc-computers.html"&gt;ColombiaReports.com&lt;/a&gt; (23 April 2012) -&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;A team of U.S. computer experts has arrived in Colombia to help national authorities recover information from the computer of deceased &lt;a href="https://en.wikipedia.org/wiki/Revolutionary_Armed_Forces_of_Colombia"&gt;FARC&lt;/a&gt; leader "Alfonso Cano," reported Colombian newspaper El Espectador Monday.&lt;br /&gt;
&lt;br /&gt;
Investigators with the Prosecutor General's office are working to break encryption codes on seven computers, 38 USB sticks and 24 hard drives recovered after a military bombing killed Cano in November, 2011.&lt;br /&gt;
&lt;br /&gt;
The technology was retrieved from a FARC camp after the attack in Suarez, a town in the southwestern Cauca department.&lt;br /&gt;
&lt;br /&gt;
The heavily-encrypted data uses four languages and multiple passwords, and requires the "meticulous" skills of the U.S. team to salvage and analyze it.&lt;br /&gt;
&lt;br /&gt;
Investigators have already recovered some information from Cano's computer, including a plan to attack five army air bases with remote controlled helicopters.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Some of the 'plans' may be more aspirational, than operational ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-1835001373682421795?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=HSELtEzDOzI:zSzTjZfqRIg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/HSELtEzDOzI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/1835001373682421795/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/04/us-experts-to-help-decrypt-farc.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/1835001373682421795?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/1835001373682421795?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/HSELtEzDOzI/us-experts-to-help-decrypt-farc.html" title="US Experts To Help Decrypt 'FARC' Computers" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/04/us-experts-to-help-decrypt-farc.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0EDRHo7cSp7ImA9WhVWEkQ.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-4525508408192300968</id><published>2012-04-24T16:30:00.003-04:00</published><updated>2012-04-24T16:34:35.409-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-24T16:34:35.409-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Malcode" /><category scheme="http://www.blogger.com/atom/ns#" term="Pwnage" /><category scheme="http://www.blogger.com/atom/ns#" term="Mobile" /><title>The Mobile Exploit Intelligence Project</title><content type="html">Dan Guido, working with Mike Arpaia, brings his well received intelligence-driven security ideas from "The Exploit Intelligence Project" of 2011, into the mobile space.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.trailofbits.com/research/"&gt;http://www.trailofbits.com/research/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-4525508408192300968?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=tkoksv46_ow:1e63hU9IMts:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/tkoksv46_ow" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/4525508408192300968/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/04/mobile-exploit-intelligence-project.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/4525508408192300968?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/4525508408192300968?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/tkoksv46_ow/mobile-exploit-intelligence-project.html" title="The Mobile Exploit Intelligence Project" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/04/mobile-exploit-intelligence-project.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C04ESHs-fyp7ImA9WhVWEkU.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-41127451006811203</id><published>2012-04-24T11:36:00.000-04:00</published><updated>2012-04-24T11:38:29.557-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-24T11:38:29.557-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Targeted Attack" /><title>Nissan Gets Hacked, Intellectual Property Possible Target</title><content type="html">Via &lt;a href="http://www.dailytech.com/Nissan+Gets+Hacked+Target+Couldve+Been+Intellectual+Property/article24527.htm"&gt;DailyTech.com&lt;/a&gt; (April 24, 2012) -&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
Nissan Motor Company has announced that its information systems have been hacked. So far, the company doesn't know who the hackers were, or where they struck from and it's unclear what data may have been compromised. Nissan believes that the hackers were looking for intellectual property related to its EV drivetrains.&lt;br /&gt;
&lt;br /&gt;
Nissan maintains that it quickly secured its system and issued a statement alerting customers and employees that its data systems were breached. Nissan says that the infiltration was noticed on April 13 so it has been roughly 10 days since the database was compromised.&lt;br /&gt;
&lt;br /&gt;
The statement read:&lt;br /&gt;
&lt;blockquote&gt;We have detected an intrusion into our company's global information systems network.&lt;br /&gt;
&lt;br /&gt;
On April 13, 2012, our information security team confirmed the presence of a computer virus on our network and immediately took aggressive actions to protect the company's systems and data. This included actions to protect information related to customers, employees and other partners worldwide. This incident initially involved the malicious placement of malware within our IS network, which then allowed transfer from a data store, housing employee user account credentials.&lt;br /&gt;
&lt;br /&gt;
As a result of our swift and deliberate actions we believe that our systems are secure and that no customer, employee or program data has been compromised. However, we believe that user IDs and hashed passwords were transmitted. We have no indication that any personal information and emails have been compromised. Regardless, we are continuing to take appropriate precautionary measures.&lt;br /&gt;
&lt;br /&gt;
Due to the ever-evolving sophistication and tenacity of hackers targeting corporations and governments on a daily basis, we continue to vigilantly maintain our protection and detection systems and related countermeasures to keep ahead of emerging threats. Our focus remains on safeguarding the integrity of employee, consumer and corporate information.&lt;/blockquote&gt;Nissan says that it opted to keep the hack secret for the last 10 days until it had a better idea what was going on according to a spokesman cited by The Detroit Bureau.&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
------------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Looks like Active Directory might have got popped.&lt;br /&gt;
&lt;br /&gt;
Primary Sources....&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://nissannews.com/en-US/nissan/usa/releases/statement-nissan-is-taking-actions-to-protect-and-inform-employees-and-customers-following-an-intrusion-into-the-company-s-global-network-systems"&gt;Nissan Statement: Nissan is Taking Actions to Protect and Inform Employees and Customers Following an Intrusion into the Company's Global Network Systems&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.thedetroitbureau.com/2012/04/nissan-scrambles-after-major-cyber-attack/"&gt;&lt;br /&gt;
The Detroit Bureau: Nissan Scrambles After Major Cyber-Attack&lt;/a&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-41127451006811203?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=vA5yrL3jz14:S235AbNcPuk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/vA5yrL3jz14" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/41127451006811203/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/04/nissan-gets-hacked-intellectual.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/41127451006811203?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/41127451006811203?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/vA5yrL3jz14/nissan-gets-hacked-intellectual.html" title="Nissan Gets Hacked, Intellectual Property Possible Target" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/04/nissan-gets-hacked-intellectual.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEAARHwycCp7ImA9WhVWEk4.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-3096152915170544285</id><published>2012-04-23T23:05:00.001-04:00</published><updated>2012-04-23T23:05:45.298-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-23T23:05:45.298-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Malcode" /><title>Both Mac and Windows are Targeted at Once</title><content type="html">Via &lt;a href="http://www.symantec.com/connect/blogs/both-mac-and-windows-are-targeted-once"&gt;Symantec Security Response Blog&lt;/a&gt; -&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Symantec Security Response, along with some other security vendors, reported the discovery of the OSX.Flashback malware recently patched by Apple. Many people may be surprised to learn the infection volume is reported at over 600,000 computers.&lt;br /&gt;
&lt;br /&gt;
On a new front, we have recently identified new Java Applet malware, which uses the &lt;a href="http://www.securityfocus.com/bid/52161"&gt;Oracle Java SE Remote Java Runtime Environment Code Execution Vulnerability&lt;/a&gt; (CVE-2012-0507) to download its payload. This attack vector is the same as the older one, but in this case the Java Applet checks which OS it is running on and downloads a suitable malware for the OS.&lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
When a victim loads the Java Applet malware, it breaks the Java Applet sandbox by using the CVE-2012-0507 vulnerability. This vulnerability is effective for both Mac and Windows operating systems. Then, if the threat is running on a Mac operating system, it downloads a dropper type malware written in Python. However, if the threat is running on a Windows operating system, it downloads a standard Windows executable file dropper. Both droppers drop a Trojan horse program that opens a back door on the compromised computer.&lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
The Trojan only checks whether it is a Windows operating system or not in this code, but the downloaded Python dropper checks again whether it is a Mac operating system or not. If it is running on Linux or some other operating system, the threat does nothing. Python is not a popular script to write malware in, but it works fine on a Mac operating system because Python has already been installed by default.&lt;br /&gt;
&lt;br /&gt;
Finally, one of two back door Trojans is dropped on to the computer. These two Trojans are downloaded from the same server, but are a little bit different from each other.&lt;br /&gt;
&lt;br /&gt;
The back door Trojan for the Mac operating system written in Python can control the “polling times”, which is related to how many times it gets commands from the server at certain time intervals. The author has done this in order to avoid IDS or IPS detection by reducing network communication. The network connection is also encrypted by RC4 or compressed by Zlib.&lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
Recently, malware that targets Mac computers, such as &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2011-093016-1216-99"&gt;OSX.Flashback&lt;/a&gt; and &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2012-041310-1536-99"&gt;OSX.Sabpab&lt;/a&gt;, are increasing. This recent increase provides evidence that malware authors now consider Mac computers a viable battleground along with the Windows platform. Certainly it is now time for you to arm your Mac computer with a good security product.&lt;br /&gt;
&lt;br /&gt;
Symantec detects the Java Applet malware as &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2010-102003-2856-99"&gt;Trojan.Maljava&lt;/a&gt;, the droppers as &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-082718-3007-99"&gt;Trojan.Dropper&lt;/a&gt;, and the back door Trojans as &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2001-062614-1754-99"&gt;Backdoor.Trojan&lt;/a&gt;. We continue to watch out for both Mac and Windows malware in order to protect our customers.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-3096152915170544285?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=AHWjqydB01I:pdYcqPf-jrE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/AHWjqydB01I" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/3096152915170544285/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/04/both-mac-and-windows-are-targeted-at.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/3096152915170544285?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/3096152915170544285?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/AHWjqydB01I/both-mac-and-windows-are-targeted-at.html" title="Both Mac and Windows are Targeted at Once" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/04/both-mac-and-windows-are-targeted-at.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D08HR3k4eyp7ImA9WhVWEk4.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-8262453083312352895</id><published>2012-04-23T22:50:00.002-04:00</published><updated>2012-04-23T22:50:36.733-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-23T22:50:36.733-04:00</app:edited><title>Defense Clandestine Service: Pentagon Reorganizes Intel into New Spy Shop</title><content type="html">Via &lt;a href="http://www.cbsnews.com/8301-250_162-57419103/pentagon-reorganizes-intel-into-new-spy-shop/"&gt;CBS News&lt;/a&gt; -&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;The Pentagon is rebranding and reorganizing its clandestine spy shop, sending more of its case officers to work alongside CIA officers to gather intelligence in places like China, after a decade of focusing intensely on war zones.&lt;br /&gt;
&lt;br /&gt;
Several hundred case officers will make up the new Defense Clandestine Service. Drawn from the Defense Intelligence Agency, the officers will be sent to beef up U.S. intelligence teams in areas that are now receiving more attention. Those include Africa, where al Qaeda is increasingly active, to parts of Asia where the North Korean missile threat and Chinese military expansion are causing increasing U.S. concern.&lt;br /&gt;
&lt;br /&gt;
The new effort was described by a senior defense official who spoke on condition of anonymity because he was not authorized to speak publicly about the classified program.&lt;br /&gt;
&lt;br /&gt;
Defense Department case officers already secretly gather intelligence across the globe on terrorism, weapons of mass destruction and other issues, mostly working out of CIA stations in embassies and operating undercover like their CIA counterparts.&lt;br /&gt;
&lt;br /&gt;
But an internal study by the Director of National Intelligence last year found the agency still focused more on its traditional mission of providing the military with intelligence in war zones, and less on what's called "national" intelligence — gathering and disseminating information on global issues and sharing that intelligence with other national security agencies, the official said.&lt;br /&gt;
&lt;br /&gt;
The study also found that the Pentagon did not always reward clandestine service overseas with promotions, so its most experienced case officers often left for the CIA, or switched to other career paths within the Pentagon.&lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
The case officers in the field — some military and some civilian — will answer directly to the top intelligence representative in their post, usually the CIA's chief of station, in addition to serving their agency back home. The arrangement is likely to curb complaints seen in earlier expansions of the Defense Department's spy mission, which the CIA and other agencies saw as the military stepping on their territory.&lt;br /&gt;
&lt;br /&gt;
The changes were worked out by the top Pentagon intelligence official, Under Secretary of Defense for Intelligence Michael Vickers, and his CIA counterpart who heads the National Clandestine Service, and briefed to Congress before Defense Secretary Leon Panetta signed off on the new program last Friday.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Looks like they are playing better together, post-&lt;a href="http://en.wikipedia.org/wiki/Counterintelligence_Field_Activity"&gt;CIFA&lt;/a&gt; days.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-8262453083312352895?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=0qFAYBctvoE:d4WJ6a9k06U:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/0qFAYBctvoE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/8262453083312352895/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/04/defense-clandestine-service-pentagon.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/8262453083312352895?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/8262453083312352895?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/0qFAYBctvoE/defense-clandestine-service-pentagon.html" title="Defense Clandestine Service: Pentagon Reorganizes Intel into New Spy Shop" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/04/defense-clandestine-service-pentagon.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUIMQH4yfSp7ImA9WhVXFkw.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-5592908647972906700</id><published>2012-04-16T17:41:00.000-04:00</published><updated>2012-04-16T17:59:41.095-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-16T17:59:41.095-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="APT" /><title>Recent Purported CEIEC Document Dump Booby-Trapped</title><content type="html">Via &lt;a href="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20120416"&gt;ShadowServer&lt;/a&gt; -&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;In recent weeks thousands documents have been released online by a hacktivist going by the online moniker of "&lt;a href="https://twitter.com/#%21/HardcoreCharle"&gt;Hardcore Charlie&lt;/a&gt;." These documents appear to have potentially been sourced and possibly stolen from various businesses and governments in different countries including the United States, the Philippines, Myanmar, Vietnam, and others. In particular Hardcore Charlie has been attempting to draw attention to some of the documents that apparently relate to U.S. military operations in Afghanistan. The twist in all of this is that the documents are purported to have been stolen by Hardcore Charlie from the Beijing based military contractor China National Import &amp;amp; Export Corp (CEIEC). If true, that would mean that the documents were stolen at least twice. These are allegations that CEIEC has strongly denied and condemned in a post on &lt;a href="http://www.ceiec.com/news/554"&gt;their website&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
This entire turn of events has raised more questions than they have answered. Are the documents legitimate? Where were they original stolen from? If these were really stolen twice, who stole them first? We unfortunately do not have the answer to any of these questions. However, one thing we do have are words of caution and some interesting information about a handful of the documents found in this dump. Within the document dump in a folder related to Vietnam are 11 malicious documents (8 unique) that exploit vulnerabilities (CVE-2010-3333 and CVE-2009-3129) in Microsoft Office to install malware. These documents installed four different types of backdoors that reported back to six distinct command and control servers. Two of the backdoors were unfamiliar to us and the other two were the well known Poison Ivy RAT and the Enfal/Lurid. At least one hostname could be tied back to a known set of persistent actors engaged in cyber espionage. &lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Vietnamese Targeting and Timeline&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
These nine unique samples from the document dump from Hardcore Charlie appear to lead to multiple different attack campaigns targeting Vietnamese interests. The malicious documents have Vietnamese names and will open legitimate clean versions of the documents in Vietnamese upon successful exploitation. At least one of the trojan samples even saves itself as a file that might blend in on a Vietnamese computer. Another has strings related to the Vietnamese version of Google, while another uses a DNS name that is in Vietnamese as well. We would suspect this may just be the tip of the ice berg.&lt;br /&gt;
&lt;br /&gt;
As for timing -- several indicators seem to point to these documents being approximately a year old. The most obvious and more tamper proof piece of evidence being a &lt;a href="https://www.virustotal.com/file/15f9f9f3e617d84083e6ac3652dfa9090f236ca8879a66654464a5b781318df5/analysis/"&gt;VirusTotal submission&lt;/a&gt; from April 2011. You may note the document from this submission was named BC cua chi binh voi BCS.doc. However, this file has the same MD5 hash of of32f5ad4f09135fcdde86ecd4c466a993, which matches the file was saw named Danh sach.doc. This indicates that his activity is not new and these files may have been unknowingly included in this document dump&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Conclusion&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
These malicious documents within the data dump raise several questions and can lead to plenty of speculation. Were these malicious documents resident on victim systems from previous targeted APT campaigns and exfiltrated alongside the legitimate documents as part of another cyber espionage operation? Could it be that they were intentionally placed into this data dump? Anything is possible and we do not have all the answers. However, we can tell you that a few of the malware samples had previously been submitted to VirusTotal in early 2011. Additionally meta data of the clean documents dropped by a few of the malware payloads showed that the documents were also created in 2011, indicating that the malicious documents have likely been circulating in the wild for more than year.&lt;br /&gt;
&lt;br /&gt;
Although many questions remain, the following facts are clear:&lt;/i&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;i&gt;A small subset of the documents contained in the purported CEIEC dump are malicious.&lt;br /&gt;
&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;i&gt;These malicious documents drop a mix of malware families including Poison Ivy, Enfal/Lurid and two unnamed families.&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;i&gt;Some of the malware samples extracted from the CEIEC dump connect to infrastructure used in previous APT campaigns.&lt;/i&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
&lt;i&gt;These documents just go to show that malicious files can end up pretty much anywhere. We are stating the obvious but remember to exercise caution when viewing files you downloaded from the Internet. Microsoft patched the two vulnerabilities used in these attacks quite some time ago. They patched CVE-2009-3129 with &lt;a href="https://technet.microsoft.com/en-us/security/bulletin/MS09-067"&gt;MS09-067&lt;/a&gt; and CVE-2010-3333 with &lt;a href="https://technet.microsoft.com/en-us/security/bulletin/MS10-087"&gt;MS10-087&lt;/a&gt;. Malicious documents that exploit vulnerabilities in Microsoft Office, Adobe Acrobat [Reader], or components loaded by these pieces of software are still some of the most common ways in which cyber espionage attacks are conducted. Staying current with the latest versions and security patches for any software you run is highly recommended.  &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-5592908647972906700?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=tIhiITP7OaE:5-ravPQF7IA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/tIhiITP7OaE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/5592908647972906700/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/04/recent-purported-ceiec-document-dump.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/5592908647972906700?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/5592908647972906700?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/tIhiITP7OaE/recent-purported-ceiec-document-dump.html" title="Recent Purported CEIEC Document Dump Booby-Trapped" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/04/recent-purported-ceiec-document-dump.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0QNR3o-eyp7ImA9WhVXFE8.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-5890283771090326212</id><published>2012-04-14T14:49:00.004-04:00</published><updated>2012-04-14T14:49:56.453-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-14T14:49:56.453-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Malcode" /><category scheme="http://www.blogger.com/atom/ns#" term="APT" /><title>SabPub Mac OS X Backdoor: Java Exploits, Targeted Attacks and Possible APT link</title><content type="html">Via &lt;a href="http://www.securelist.com/en/blog/208193467/SabPub_Mac_OS_X_Backdoor_Java_Exploits_Targeted_Attacks_and_Possible_APT_link"&gt;Securelist.com&lt;/a&gt; (Kaspersky) -&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;We can confirm yet another Mac malware in the wild - Backdoor.OSX.SabPub.a being spread through Java exploits.&lt;br /&gt;
&lt;br /&gt;
This new threat is a custom OS X backdoor, which appears to have been designed for use in targeted attacks. After it is activated on an infected system, it connects to a remote website in typical C&amp;amp;C fashion to fetch instructions. The backdoor contains functionality to make screenshots of the user’s current session and execute commands on the infected machine.&lt;br /&gt;
&lt;br /&gt;
The remote C&amp;amp;C website - rt***.onedumb.com is hosted on a VPS located in the U.S, Fremont, CA.&lt;br /&gt;
&lt;br /&gt;
“Onedumb.com” is a free dynamic DNS service. Interesting, the C&amp;amp;C at IP 199.192.152.* was used in other targeted attacks (known as “&lt;a href="http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp_luckycat_redux.pdf"&gt;Luckycat&lt;/a&gt;”) in the past.&lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Java exploits appear to be pretty standard, however, they have been obfuscated using ZelixKlassMaster, a flexible and quite powerful Java obfuscator. This was obviously done in order to avoid detection from anti-malware products.&lt;br /&gt;
&lt;br /&gt;
At the moment, it is not clear how users get infected with this, but the low number and it’s backdoor functionality indicates that it is most likely used in targeted attacks. Several reports exist which suggest the attack was launched through e-mails containing an URL pointing to two websites hosting the exploit, located in US and Germany.&lt;br /&gt;
&lt;br /&gt;
The timing of the discovery of this backdoor is interesting because in March, several reports pointed to Pro-Tibetan targeted attacks against Mac OS X users. The malware does not appear to be similar to the one used in these attacks, though it is possible that it was part of the same or other similar campaigns.&lt;br /&gt;
&lt;br /&gt;
One other important detail is that the backdoor has been compiled with debug information - which makes its analysis quite easy. This can be an indicator that it is still under development and it is not the final version.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
--------------------------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Kaspersky redacted part of the C2 info, but Symantec did not...&lt;br /&gt;
&lt;br /&gt;
Symantec - OSX.Sabpab&lt;br /&gt;
&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2012-041310-1536-99&amp;amp;tabid=2"&gt;http://www.symantec.com/security_response/writeup.jsp?docid=2012-041310-1536-99&amp;amp;tabid=2&lt;/a&gt;&lt;br /&gt;
&lt;blockquote&gt;&lt;i&gt;Next, the Trojan connects to the following location and opens a back door on the compromised computer: &lt;span style="color: red;"&gt;hxxp://rtx556.onedumb.com &lt;/span&gt;&lt;/i&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-5890283771090326212?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=GqnxTU0Uasg:6jRO8l6uRi8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/GqnxTU0Uasg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/5890283771090326212/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/04/sabpub-mac-os-x-backdoor-java-exploits.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/5890283771090326212?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/5890283771090326212?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/GqnxTU0Uasg/sabpub-mac-os-x-backdoor-java-exploits.html" title="SabPub Mac OS X Backdoor: Java Exploits, Targeted Attacks and Possible APT link" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/04/sabpub-mac-os-x-backdoor-java-exploits.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUcGRHc4fyp7ImA9WhVXFE8.&quot;"><id>tag:blogger.com,1999:blog-18341144.post-3114851012972868927</id><published>2012-04-14T14:10:00.002-04:00</published><updated>2012-04-14T14:10:25.937-04:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-04-14T14:10:25.937-04:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Malcode" /><title>Fighting the OSX/Flashback Hydra</title><content type="html">Via &lt;a href="http://blog.eset.com/2012/04/13/fighting-the-osxflashback-hydra"&gt;ESET Threat Blog&lt;/a&gt; -&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;The biggest Mac botnet ever encountered, the OSX/Flashback botnet, is being hit hard. On April 12th, Apple released a &lt;a href="http://support.apple.com/kb/HT5247"&gt;third Java update&lt;/a&gt; since the Flashback malicious code outbreak. This update includes a new tool called MRT (Malware Removal Tool) which allows Apple to quickly push malware removal code to their user base. The first mission of MRT: remove Flashback.&lt;br /&gt;
&lt;br /&gt;
[...]&lt;br /&gt;
&lt;br /&gt;
When it comes to disclosing a realistic number of unique infected hosts, we strive to be as accurate and objective as possible. Defining a unique host is not trivial, even if OSX/Flashback uses hardware UUIDs. Our data indicates many UUIDs that connected to our sinkhole (a server we set up to capture incoming traffic from bot-infected machines trying to communicate with their command-and-control servers), came from a big range of IP addresses, indicating that there may be UUID duplicates. Virtual Machines or so-called Hack-intosh installations may explain this.&lt;br /&gt;
&lt;br /&gt;
When browsing Hack-intosh forums, we found out that everyone who is using the fourth release candidate of a special distribution has the same hardware UUID (XXXXXXXX-C304-556B-A442-960AB835CB5D) and even discuss ways to arbitrarily modify it.&lt;br /&gt;
&lt;br /&gt;
Oddly enough, we found this UUID connected to our sinkhole from 20 different IP addresses. This indicates that those who considered UUID to count the number of distinct infected hosts probably have underestimated the botnet size.&lt;br /&gt;
&lt;br /&gt;
Flashback evolved a lot in the last few months. The authors moved fast and added obfuscation and fallback methods in case the main C&amp;C server is taken down. The dropper now generates 5 domain names per day and tries to get an executable file from those websites. The latest variants of the dropper and the library encrypt its important strings with the Mac hardware UUID. This makes it difficult for researchers to analyze a variant reported by a customer if they don’t also have access to the UUID.&lt;br /&gt;
&lt;br /&gt;
The fallback mechanism that Flashback uses when it is unable to contact its C&amp;C servers is quite interesting. Each day, it will generate a new Twitter hashtag and search for any tweet containing that hashtag. A new C&amp;C address can be provided to an infected system this way. &lt;a href="http://www.intego.com/mac-security-blog/flashback-mac-malware-uses-twitter-as-command-and-control-center/"&gt;Intego reported this last month&lt;/a&gt;, but the latest version uses new strings. Twitter has been notified of the new hashtags and are working on remediations to make sure the operator of the botnet cannot take back control of his botnet through Twitter.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
Flashback Malware Removal Tool&lt;br /&gt;
&lt;a href="http://support.apple.com/kb/DL1517"&gt;http://support.apple.com/kb/DL1517&lt;/a&gt;&lt;br /&gt;
&lt;blockquote&gt;&lt;i&gt;This Flashback malware removal tool that will remove the most common variants of the Flashback malware. If the Flashback malware is found, a dialog will be presented notifying the user that malware was removed. In some cases, the Flashback malware removal tool may need to restart your computer in order to completely remove the Flashback malware.&lt;br /&gt;
&lt;br /&gt;
This update is recommended for all OS X Lion users without Java installed.&lt;/i&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18341144-3114851012972868927?l=djtechnocrat.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?a=YXool6zFk7s:QrX2Fi_lM2M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThoughtsOfATechnocrat?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThoughtsOfATechnocrat/~4/YXool6zFk7s" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://djtechnocrat.blogspot.com/feeds/3114851012972868927/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://djtechnocrat.blogspot.com/2012/04/fighting-osxflashback-hydra.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/3114851012972868927?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/18341144/posts/default/3114851012972868927?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ThoughtsOfATechnocrat/~3/YXool6zFk7s/fighting-osxflashback-hydra.html" title="Fighting the OSX/Flashback Hydra" /><author><name>Technocrat</name><uri>http://www.blogger.com/profile/05399633416913275459</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://djtechnocrat.blogspot.com/2012/04/fighting-osxflashback-hydra.html</feedburner:origLink></entry></feed>

