<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecuriTeam Blogs &#187; David Harley</title>
	<atom:link href="http://blogs.securiteam.com/index.php/archives/author/davidh/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.securiteam.com</link>
	<description>Thoughts about the world of security</description>
	<lastBuildDate>Tue, 15 May 2012 05:11:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Counter eCrime Operations Summit next week</title>
		<link>http://blogs.securiteam.com/index.php/archives/1675</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1675#comments</comments>
		<pubDate>Tue, 17 Apr 2012 11:31:29 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=1675</guid>
		<description><![CDATA[[I've blogged on this elsewhere, but I'm pretty sure that this will be of interest to some of the readers of this blog, so here are the details as supplied by the Anti-Phishing Working Group.] ‘Containing the Global Cybercrime Threat’ is the focus of the Counter eCrime Operations Summit (CeCOS VI) in Prague, April 25-27 [...]]]></description>
			<content:encoded><![CDATA[<p>[I've blogged on this elsewhere, but I'm pretty sure that this will be of interest to some of the readers of this blog, so here are the details as supplied by the Anti-Phishing Working Group.]</p>
<p>‘Containing the Global Cybercrime Threat’ is the focus of the Counter eCrime Operations Summit (CeCOS VI) in Prague, April 25-27</p>
<p>The 6th annual Counter eCrime Operations Summit (CeCOS VI) will convene in Prague, Czech Republic, April 25-27, 2012, as the APWG gathers global leaders from the financial services, technology, government, law enforcement, communications sectors, and research centers to define common goals and harmonize resources to strengthen the global counter-cybercrime effort.</p>
<p>CeCOS VI Prague will review the development of response systems and resources available to counter-cybercrime managers and forensic professionals from around the world.</p>
<p>Specific goals of this high-level, multi-national conference are to identify common forensic needs, in terms of the data, tools, and communications protocols required to harmonize cybercrime response across borders and between private sector financial and industrial sector responders and public sector policy professionals and law enforcement.</p>
<p>Key presentations will include:</p>
<p>» Toward a Universal eCrime Taxonomy for Industry and Law Enforcement; by Iain Swaine, Ensequrity.<br />
» Budapest Convention on Cybercrime: Transborder Law Enforcement Access to Data; by Alexander Seger, Director of the Data Protection and Cybercrime Division of the Council of Europe.<br />
» Adventures in Cybercrime Event Data Sharing; by Pat Cain, AWPG Resident Research Fellow.<br />
Additional presentations about industrial policy at CeCOS VI will investigate policies that complicate the work of exploited brand holders and responders including the domain name system (DNS) registration process that is abused by phishers as part of their phishing campaigns.</p>
<p>ABOUT the Counter eCrime Operations Summit</p>
<p>CeCOS VI, the second APWG conference held in Europe, is an open conference for members of the electronic-crime fighting community, hosted by the APWG and its Conference Partner AVG, Program Partners: The Council of Europe and Organization for Security and Cooperation in Europe, and sponsored by AVG, Google, Microsoft, MarkMonitor, ESET, Telefonica and ICANN. The CeCOS programs are widely considered the most vital events to investigators and managers of electronic crime from across the private and public sectors.</p>
<p>AGENDA</p>
<p>http://apwg.org/events/2012_cecos.html#agenda</p>
<p>CONFERENCE REGISTRATION </p>
<p>http://secure.lenos.com/lenos/antiphishing/cecos2012/</p>
<p>CONTACTS<br />
APWG: Foy Shiver, +1 404-434-7282. fshiver@apwg.org</p>
<p><strong>David Harley CITP FBCS CISSP</strong></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1675&amp;title=Counter%20eCrime%20Operations%20Summit%20next%20week" id="wpa2a_2"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1675/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The malware problem looks better after the first cup of coffee</title>
		<link>http://blogs.securiteam.com/index.php/archives/1595</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1595#comments</comments>
		<pubDate>Mon, 13 Feb 2012 13:59:28 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1595</guid>
		<description><![CDATA[So if evading AV software is really the point, this seems to suggest that all those people who've moved to the East Coast are coping even less effectively with their email than I am. ]]></description>
			<content:encoded><![CDATA[<p>Since most of my income comes from a company on the West Coast, I&#8217;m used to people assuming that I should be working according to their time zone (PST) rather than my own (GMT). But apparently we&#8217;re <em>all </em>wrong.<br />
According to <a href="https://www.trustwave.com/">Trustwave&#8217;s </a>Global Security Report: </p>
<blockquote><p>&#8220;The number of executables and viruses sent in the early morning hours increased, eventually hitting a maximum between 8 a.m. and 9 a.m. Eastern Standard Time before tapering off throughout the rest of the day. The spike is likely an attempt to catch people as they check emails at the beginning of the day.&#8221;</p></blockquote>
<p>Did I miss something? Has everyone but me moved to the East Coast? I&#8217;m not even sure it matters when you receive a malicious executable, unless you don&#8217;t get around to opening it until after your security software has been updated to detect it. However, the report also tells us that:</p>
<blockquote><p>&#8220;The time from compromise to detection in most environments is about six months&#8230;&#8221;</p></blockquote>
<p>So if evading AV software is really the point, this seems to suggest that all those people who&#8217;ve moved to the East Coast are coping even less effectively with their email than I am. </p>
<p>Hold on, though. Maybe this tells something about the blackhat&#8217;s time zone, rather than the victim&#8217;s? The report doesn&#8217;t seem to tell us anything about the geographical origin of the emails that Trustwave has tracked, but it does tells us that apart from the 32.5% of attacks in general that are of unknown origin, the largest percentage (29.6%) come from the Russian Federation. Russia actually covers no less than nine time zones (until a couple of years ago, it was eleven), but perhaps we can assume for the sake of argument that a high percentage of those attackers are in time zones between CET and Moscow Standard (now UTC+4), which applies to most of European Russia. (That assumption allows us to include Romania and the Ukraine.) Perhaps, after a hard morning administering botnets, Eastern European gangsters are best able to find time to fire off a few malicious emails between the afternoon samovar break and early evening cocktails. Convinced? No, me neither. </p>
<p>Actually, there are some interesting statistics in the <a href="https://www.trustwave.com/global-security-report">report</a>. If they&#8217;re reliable, some assumptions that we make about geographical distribution, for example, might bear re-examination. But I&#8217;d really have to suggest that journalists in search of something new to say about malware examine some of the report&#8217;s <a href="http://news.cnet.com/8301-1023_3-57374422-93/e-mail-viruses-most-likely-to-appear-in-the-morning/?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20">interpretations </a>with a little more salt and scepticism. I suppose I should be grateful that no-one has noticed yet that according to the report, twice as many attacks originate in the Netherlands as do in China. Just think of the sub-editorial puns <em>that </em>could inspire&#8230;</p>
<p><strong>David Harley CITP FBCS CISSP<br />
Small Blue-Green World/AVIEN<br />
ESET Senior Research Fellow</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1595/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PC Support Sites: Scams and Credibility</title>
		<link>http://blogs.securiteam.com/index.php/archives/1565</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1565#comments</comments>
		<pubDate>Wed, 09 Nov 2011 16:40:09 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1565</guid>
		<description><![CDATA[Just as 419-ers seem to have been permanently renamed in some quarters as &#8220;the Lads from Lagos&#8221;, I wonder if we should refer to those irritating individuals who persist in ringing us to offer us help (for a not particularly small fee) with non-existent malware as the &#8220;Krooks from Kolkata&#8221; (or more recently, the Ne&#8217;erdowells [...]]]></description>
			<content:encoded><![CDATA[<p>Just as 419-ers seem to have been permanently renamed in some quarters as &#8220;the Lads from Lagos&#8221;, I wonder if we should refer to those irritating individuals who persist in ringing us to offer us help (for a not particularly small fee) with non-existent malware as the &#8220;Krooks from Kolkata&#8221; (or more recently, the Ne&#8217;erdowells from New Delhi). It would be a pity to slur an entire nation with the misdeeds of a few individuals, but the network of such scammers does seem to be expanding across the Indian continent.</p>
<p>Be that as it may, I&#8217;ve recently been doing a little work (in association with Martijn Grooten of Virus Bulletin) on some of the ways that PC support sites that may be associated with cold-call scams are bolstering their own credibility by questionable means. Of course, legitimate businesses are also fond of Facebook likes, testimonials and so on, but we&#8217;ve found that some of these sites are not playing altogether nicely. </p>
<p>I&#8217;ve posted a fairly lengthy joint blog on the topic here: <a href="http://blog.eset.com/2011/11/09/facebook-likes-and-cold-call-scams">Facebook Likes and cold-call scams</a> </p>
<p><strong>David Harley CITP FBCS CISSP<br />
ESET Senior Research Fellow</strong></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1565&amp;title=PC%20Support%20Sites%3A%20Scams%20and%20Credibility" id="wpa2a_4"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1565/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Help Desk Scams and Microsoft</title>
		<link>http://blogs.securiteam.com/index.php/archives/1553</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1553#comments</comments>
		<pubDate>Wed, 21 Sep 2011 16:22:25 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1553</guid>
		<description><![CDATA[Apparently when the coldcalling species of scamming maggot claims to be Microsoft or partnered with Microsoft, there really is sometimes a relationship of sorts lurking behind the scenes there, though that doesn&#8217;t mean that Microsoft are at all a party to the scam, of course. I&#8217;ve been gnawing at that particular bone for quite a [...]]]></description>
			<content:encoded><![CDATA[<p>Apparently when the coldcalling species of scamming maggot claims to be Microsoft <em>or </em>partnered with Microsoft, there really is sometimes a relationship of sorts lurking behind the scenes there, though that doesn&#8217;t mean that Microsoft are at all a party to the scam, of course.</p>
<p>I&#8217;ve been gnawing at that particular bone for quite a while now &#8211; see, for instance, <a href="http://blog.eset.com/?s=Harley+%2B+support+scam">http://blog.eset.com/?s=Harley+%2B+support+scam</a> and <a href="http://go.eset.com/us/resources/white-papers/Hanging-On-The-Telephone.pdf">http://go.eset.com/us/resources/white-papers/Hanging-On-The-Telephone.pdf</a> and <a href="http://www.scmagazineus.com/supporters-club/article/199459/">http://www.scmagazineus.com/supporters-club/article/199459/</a> &#8211; and the name Comantra has turned up time and time again in the context of site registrations, though I haven&#8217;t had the resources to confirm links with the company in terms of individual scam calls. </p>
<p>But somehow I&#8217;d never realized the company really <em><a href="http://www.channelregister.co.uk/2011/09/21/microsoft_bins_gold_partner/">was</a> </em>a Microsoft Gold Partner.  Apparently Microsoft took some time to make the connection too. But they have, and Comantra is no longer a Gold Partner. According to <a href="http://www.pcpro.co.uk/news/370054/microsoft-dumps-partner-over-support-call-scam">PC Pro</a>, a Microsoft spokesman said: </p>
<p>&#8220;We were made aware of a matter involving one of the members of the Microsoft Partner Network acting in a manner that caused us to raise concerns about this member&#8217;s business practices.Following an investigation, the allegations were confirmed and we took action to terminate our relationship with the partner in question and revoke their Gold status.&#8221;</p>
<p>Somehow, though, I doubt if this means the end of coldcall scams. There were lots of sites and lots of names registered for sites that were associated with individual scammers, and there seems to be no real pressure from law-enforcement in the regions where the calls are actually originating. And Comantra is claiming that it&#8217;s all to do with negative marketing from their competitors. Gosh, never heard that one before&#8230;</p>
<p>On the other hand, since I moved house a few weeks ago, I haven&#8217;t had a single support scam call, though there&#8217;ve been a few &#8220;we can help you sue your mortgage lender&#8221; calls with a reassuringly Indian accent. Still, I miss being told I&#8217;m leaking viruses all over Surrey.  How long do you suppose it will take them to catch up with me?</p>
<p><strong>David Harley CITP FBCS CISSP. And stuff.<br />
Small Blue-Green World </strong></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1553&amp;title=Help%20Desk%20Scams%20and%20Microsoft" id="wpa2a_6"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1553/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Comment(ary) Spam&#8230;</title>
		<link>http://blogs.securiteam.com/index.php/archives/1541</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1541#comments</comments>
		<pubDate>Mon, 15 Aug 2011 19:53:36 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1541</guid>
		<description><![CDATA[I&#8217;m not sure why I feel the urge to keep writing about comment spam: primarily, I suppose it&#8217;s because I get so much amusement from it (just as well considering how much of it I read when I moderate comments on the ESET blog), rather than because the world is full of bloggers waiting for [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m not sure why I feel the urge to keep writing about comment spam: primarily, I suppose it&#8217;s because I get so much amusement from it (just as well considering how much of it I read when I moderate comments on the ESET blog), rather than because the world is full of bloggers waiting for me to tell them how to recognize it, even if it isn&#8217;t apparently posted by someone called <em>nike soccer shoes</em> or <em>where to buy a laptop</em> or even my personal favourite of the moment, <em>rolling in the deep adele</em>. (Well, there went my favourite heuristic.)</p>
<p>Still, I liked the cheek of this one:</p>
<p>&#8220;Throughout the great scheme of things you&#8217;ll get  a B- for effort. Where you actually confused me personally was first on your particulars. As people say, the devil is in the details&#8230; And it couldn&#8217;t be more correct here. Having said that, let me inform you what did deliver the results. Your authoring is pretty powerful which is most likely the reason why I am taking the effort in order to comment. I do not make it a regular habit of doing that. 2nd, even though I can easily see a leaps in reason you make, I am not sure of just how you appear to connect the points which inturn produce the final result. For the moment I shall yield to your point but trust in the foreseeable future you actually link the facts better.&#8221; </p>
<p>So much so that I did a quick Google to see how common this particular approach is, and sure enough I found a whole bunch of very similar posts &#8211; by similar, I mean the same core text with minor changes such as &#8220;the great pattern of things&#8221;. Apparently, I&#8217;m not the only blogger who tends to assume that if a comment is enthusiastic, it&#8217;s probably spam.</p>
<p>Thank you for your constructive criticism, Mr <em>feather extensions online</em>: I like your style. But my absolute favourite at the moment is Fritz, who commented dispiritedly that he is &#8220;always a big fan of linking to bloggers that I love but don’t get a lot of link love from&#8221;: too bad URLs in comments are stripped automatically, or I might have allowed that one through just to put a smile on your face. </p>
<p>David Harley </p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1541&amp;title=Comment%28ary%29%20Spam%E2%80%A6" id="wpa2a_8"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1541/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Commoditizing Pay-Per-Install</title>
		<link>http://blogs.securiteam.com/index.php/archives/1521</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1521#comments</comments>
		<pubDate>Fri, 10 Jun 2011 13:26:16 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1521</guid>
		<description><![CDATA[We all know, I guess, about the professionalization of Internet crime and the diversification of the underground economy, but measuring it isn&#8217;t so easy. ESET&#8217;s Aleksandr Matrosov and Eugene Rodionov have alluded to it in several papers and presentations with particular reference to TDSS, and we consolidated some of that material into an article (actually [...]]]></description>
			<content:encoded><![CDATA[<p>We all know, I guess, about the professionalization of Internet crime and the diversification of the underground economy, but measuring it isn&#8217;t so easy. </p>
<p>ESET&#8217;s Aleksandr Matrosov and Eugene Rodionov have alluded to it in several papers and presentations with particular reference to TDSS, and we consolidated some of that material into an <a href="http://resources.infosecinstitute.com/tdss4-part-1/">article</a> (actually the first of a series of three articles on TDSS) that talks about the Dogma Millions and GangstaBucks affiliate models used in that context. </p>
<p>However, a paper on <a href="http://www.icir.org/vern/papers/ppi-usesec11.pdf">Measuring <em>Pay-per-Install</em>: The Commoditization of Malware Distribution</a> by Juan Caballero, Chris Grier, Christian Kreibich, and Vern Paxson, is based on a measurement study implemented by infiltrating four PPI service providers: LoaderAdv (of which GangstaBucks is one of the brands), GoldInstall, Virut, and Zlob. The authors assert that 12 out of the top 20 malware families tracked by Fire Eye between April and June 2010, twelve were using PPI services to buy infections. </p>
<p>Lots of other interesting data there, too. Hat tip to Aleks for bringing it to my attention.</p>
<p>David Harley CITP FBCS CISSP<br />
ESET Senior Research Fellow</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1521&amp;title=Commoditizing%20Pay-Per-Install" id="wpa2a_10"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1521/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Japan Disaster Commentary and Resources</title>
		<link>http://blogs.securiteam.com/index.php/archives/1493</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1493#comments</comments>
		<pubDate>Mon, 14 Mar 2011 18:52:28 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1493</guid>
		<description><![CDATA[It probably hasn&#8217;t escaped your notice that there&#8217;s a lot of malware/SEO/scamming whenever a major disaster occurs. A few days ago I started to put together a list of commentary (some of it my own) and resources relating to the Japanese earthquake and tsunami, in anticipation of that sort of activity. Originally, I was using [...]]]></description>
			<content:encoded><![CDATA[<p>It probably hasn&#8217;t escaped your notice that there&#8217;s a lot of malware/SEO/scamming whenever a major disaster occurs. A few days ago I started to put together a list of commentary (some of it my own) and resources relating to the Japanese earthquake and tsunami, in anticipation of that sort of activity. </p>
<p>Originally, I was using several of my usual blog venues, but decided eventually to focus on one site. As ESET had no monopoly on useful information, I wanted to use a vendor-agnostic site. Actually, I could have used this one, but for better or worse, I decided to use the AVIEN blog, since I&#8217;ve pretty much taken over the care and feeding of that organization. The blog in question is <a href="http://avien.net/blog/?p=643">Japan Disaster: Commentary &amp; Resources</a>. </p>
<p>It&#8217;s certainly not all-inclusive, but it&#8217;s the largest resource of its type that I&#8217;m aware of. Eventually, it will be organized more so as to focus again on the stuff that&#8217;s directly related to security, but right now, given the impact of the crisis, I&#8217;m posting pretty much anything that strikes me as useful, even if its relevance to security is a bit tenuous.</p>
<p>I&#8217;m afraid I&#8217;m going to post this pointer one or two other places: apologies if you trip over it more often than you really want to!</p>
<p><strong>David Harley CITP FBCS CISSP<br />
AVIEN COO<br />
ESET Senior Research Fellow</strong></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1493&amp;title=Japan%20Disaster%20Commentary%20and%20Resources" id="wpa2a_12"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1493/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Back on the AMTSO wheel</title>
		<link>http://blogs.securiteam.com/index.php/archives/1469</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1469#comments</comments>
		<pubDate>Mon, 24 Jan 2011 12:57:02 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1469</guid>
		<description><![CDATA[The next AMTSO members&#8217; meeting is at San Mateo, California, on the 10th-11th February, just before RSA. I&#8217;m not sure how many supporters of the Anti-Malware Testing Standards Organization there are reading this blog, as opposed to those who regard AMTSO as a club with which to beat the anti-virus industry. However, I&#8217;m pretty sure [...]]]></description>
			<content:encoded><![CDATA[<p>The next <a href="http://www.amtso.org/">AMTSO</a> members&#8217; meeting is at San Mateo, California, on the 10th-11th February, just before RSA. </p>
<p>I&#8217;m not sure how many supporters of the Anti-Malware Testing Standards Organization there are reading this blog, as opposed to those who regard AMTSO as a club with which to beat the anti-virus industry. However, I&#8217;m pretty sure that even those who find the generation of testing guidelines documents (which constitutes most of the work at AMTSO meetings) excruciatingly boring will find some interesting material coming out of the organization in the next few weeks.</p>
<p>There&#8217;s more information on this year&#8217;s AMTSO meetings on the AMTSO meetings page at <a href="http://www.amtso.org/meetings.html">http://www.amtso.org/meetings.html</a>, including a preliminary agenda.</p>
<p><strong>David Harley CITP FBCS CISSP<br />
Small Blue-Green World</strong></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1469&amp;title=Back%20on%20the%20AMTSO%20wheel" id="wpa2a_14"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1469/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stuxnet Guesswork</title>
		<link>http://blogs.securiteam.com/index.php/archives/1447</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1447#comments</comments>
		<pubDate>Sat, 25 Sep 2010 20:33:19 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1447</guid>
		<description><![CDATA[Aviram said in a recent blog about Stuxnet and SCADA here: After that, we get to theorize on who’s behind it and who is the target. What’s your guess? And sure enough, half the security world has done just that, and the rest will be talking about it at Virus Bulletin next week. Good fun, [...]]]></description>
			<content:encoded><![CDATA[<p>Aviram said in a recent blog about Stuxnet and SCADA <a href="http://blogs.securiteam.com/index.php/archives/1445">here</a>:</p>
<blockquote><p>After that, we get to theorize on who’s behind it and who is the target. What’s your guess?  </p></blockquote>
<p>And sure enough, half the security world has done just that, and the rest will be talking about it at <a href="http://www.virusbtn.com/conference/vb2010/programme">Virus Bulletin next week</a>. Good fun, maybe, if you don&#8217;t think too hard about some of the political implications, but I&#8217;m not sure it&#8217;s been productive or useful. Which is why I blogged today <a href="http://blog.eset.com/2010/09/25/cyberwar-cyberhisteria">here</a>. </p>
<p>I&#8217;d love to cover the same ground again here, but frankly I&#8217;m just too dispirited&#8230;</p>
<p>David Harley CITP FBCS CISSP<br />
<a href="http://blog.eset.com/">ESET</a> Senior Research Fellow</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1447&amp;title=Stuxnet%20Guesswork" id="wpa2a_16"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1447/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conspiracy Theory</title>
		<link>http://blogs.securiteam.com/index.php/archives/1402</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1402#comments</comments>
		<pubDate>Wed, 07 Jul 2010 16:26:08 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1402</guid>
		<description><![CDATA[After a while (about 20 years in my case) around the anti-malware industry (the last couple of years actually in it&#8230;), you get used to the idea that everyone expects the worst of them&#8230; errrr, us: hype and extreme marketing FUD incompetence putting our bottom line above the public well-being bad hygiene Maybe the last [...]]]></description>
			<content:encoded><![CDATA[<p>After a while (about 20 years in my case) around the anti-malware industry (the last couple of years actually in it&#8230;), you get used to the idea that everyone expects the worst of them&#8230; errrr, us:</p>
<ul>
<li>hype and extreme marketing</li>
<li>FUD</li>
<li>incompetence</li>
<li>putting our bottom line above the public well-being
	</li>
<li>bad hygiene</li>
</ul>
<p>Maybe the last one is a bit paranoid.</p>
<p>Still, we have a bad rep. And the popular myth that AV companies run <a href="http://www.amtso.org/">AMTSO</a> (the Anti-Malware Testing Standards Organization) purely for their own aggrandizement and marketing advantage has some of its origins in that universal mistrust of AV. </p>
<p>If you buy into all that, then you&#8217;ll also assume that when five AV researchers, all from different companies, collaborate on a blog that responds to the recent attacks on AMTSO, that&#8217;s proof of a conspiracy.</p>
<p>Actually, the AV industry is founded in co-operation: otherwise, your AV product would only ever catch the malware that company had seen in its own honeynets, been sent in by its customers, and so on. But apparently that&#8217;s a sign of bad intentions, too.</p>
<p>Whatever. If you&#8217;re interested in the blog, here are five places you should be able to find it.</p>
<p><a href="http://bit.ly/at6WT4">http://bit.ly/at6WT4</a><br />
<a href="http://tinyurl.com/35dv44x">http://tinyurl.com/35dv44x</a><br />
<a href="http://tinyurl.com/2w4g6fh">http://tinyurl.com/2w4g6fh</a><br />
<a href="http://tinyurl.com/3aka782">http://tinyurl.com/3aka782</a><br />
<a href="http://community.norton.com/t5/Norton-Protection-Blog/Testing-and-Accountability/ba-p/247711">http://community.norton.com/t5/Norton-Protection-Blog/Testing-and-Accountability/ba-p/247711</a></p>
<p>(And for a somewhat related commentary, <a href="http://avien.net/blog/?p=539">http://avien.net/blog/?p=539</a>).</p>
<p>David Harley CITP FBCS CISSP<br />
Not speaking for AMTSO or the AV industry, and definitely not speaking for the testing industry or the media.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1402&amp;title=Conspiracy%20Theory" id="wpa2a_18"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1402/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AMTSO Inside and Outside</title>
		<link>http://blogs.securiteam.com/index.php/archives/1399</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1399#comments</comments>
		<pubDate>Sat, 03 Jul 2010 07:42:53 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Sec Tools]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1399</guid>
		<description><![CDATA[God bless Twitter. A day or two ago, I was edified by the sight of two journalists asking each other whether AMTSO (the Anti-Malware Testing Standards Organization) had actually achieved anything yet. Though one of them did suggest that the other might ask me. (Didn&#8217;t happen.) Well, it&#8217;s always a privilege to see cutting edge [...]]]></description>
			<content:encoded><![CDATA[<p>God bless Twitter.</p>
<p>A day or two ago, I was edified by the sight of two journalists asking each other whether AMTSO (the Anti-Malware Testing Standards Organization) had actually achieved anything yet. Though one of them did suggest that the other might ask me. (Didn&#8217;t happen.)</p>
<p>Well, it&#8217;s always a privilege to see cutting edge investigative journalism in action. I know the word researcher is in my job title, but I normally charge for doing other people&#8217;s research. But since you&#8217;re obviously both very busy, and as a member of the AMTSO Board of Directors (NB, that&#8217;s a volunteer role) I guess I do have some insight here, so let me help you out, guys.  </p>
<p>Since the first formal meeting of AMTSO in May 2008, where a whole bunch of testers, vendors, publishers and individuals sat down to discuss how the general standard of testing could be raised, the organization has approved and published a number of <a href="http://www.amtso.org/documents.html">guidelines/best practices documents</a>. </p>
<p>To be more specific:</p>
<p>The &#8220;Fundamental Principles of Testing&#8221; document is a decent attempt at doing what it says on the tin, and provide a baseline definition for what good testing is at an abstract level.</p>
<p>The Guidelines document provide&#8230; errrr, guidelines&#8230; in a number of areas:</p>
<ul>
<li>Dynamic Testing</li>
<li>Sample Validation</li>
<li>In the Cloud Testing
</li>
<li>Network Based Product Testing</li>
<li>Whole Product Testing</li>
<li>Performance Testing</li>
</ul>
<p>Another document looks at the pros and cons of creating malware for testing purposes.</p>
<p>The analysis of reviews document provides a basis for the review analysis process which has so far resulted in two <a href="http://www.amtso.org/amtso---review-analysis-board-page.html">review analyses</a> &#8211; well, that was a fairly painful gestation process, and in fact, there was a volatile but necessary period in the first year in particular while various procedures, legal requirements and so on were addressed. There are several other papers in process being worked on</p>
<p>A fairly comprehensive links/files repository for testing-related resources was established <a href="http://www.amtso.org/related-resources.html">here</a> and new resources added, from AMTSO members and others.</p>
<p>Unspectacular, and no doubt journalistically uninteresting. But representing a lot of volunteer work by people who already have full time jobs. </p>
<p>You don&#8217;t have to agree with every sentence of every document: the point is that these documents didn&#8217;t exist before, and they go some way towards meeting the needs of those people who want to know more about testing, whether as a tester, tester&#8217;s audience, producer of products under test, or any other interested party. Perhaps most importantly, the idea has started to spread that perhaps testers should be accountable to their customers (those who read their reviews) for the accuracy and fitness for purpose of their tests, just as security vendors are accountable to their own customers. </p>
<p>[Perhaps I&#8217;d better clarify that: I&#8217;m not saying that tests have to be or can be perfect, any more than products . (You might want 100% security or 100% accuracy, but that isn&#8217;t possible.)</p>
<p>You don&#8217;t have to like what AMTSO does. But it would be nice if you&#8217;d actually make an effort to find out <em>what </em>we do and maybe even consider joining (AMTSO does not only admit vendors and testers) before you moan into extinction an organization that is trying to do something about a serious problem that no-one else is addressing.</p>
<p>David Harley CITP FBCS CISSP<br />
Not speaking for AMTSO</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1399&amp;title=AMTSO%20Inside%20and%20Outside" id="wpa2a_20"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1399/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IEEE eCrime Researchers Summit 2010</title>
		<link>http://blogs.securiteam.com/index.php/archives/1377</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1377#comments</comments>
		<pubDate>Sat, 12 Jun 2010 10:07:16 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1377</guid>
		<description><![CDATA[The fifth IEEE eCrime Researchers Summit 2010 (http://ecrimeresearch.org) will be held in conjunction with the 2010 APWG General Meeting between October 18-20, 2010 at Southern Methodist University in Dallas, TX. Topics of interest include: * Phishing, rogue-AV, pharming, click-fraud, crimeware, extortion and emerging attacks. * Technical, legal, political, social and psychological aspects of fraud and [...]]]></description>
			<content:encoded><![CDATA[<p>The fifth IEEE eCrime Researchers Summit 2010 (<a href="http://ecrimeresearch.org">http://ecrimeresearch.org</a>) will be held in conjunction with the 2010 APWG General Meeting between October 18-20, 2010 at Southern Methodist University in Dallas, TX.</p>
<p>Topics of interest include:</p>
<p>* Phishing, rogue-AV, pharming, click-fraud, crimeware, extortion and emerging attacks.<br />
* Technical, legal, political, social and psychological aspects of fraud and fraud prevention.<br />
* Malware, botnets, ecriminal/phishing gangs and collaboration, or money laundering.<br />
* Techniques to assess the risks and yields of attacks and the success rates of countermeasures.<br />
* Delivery techniques, including spam, voice mail and rank manipulation; and countermeasures.<br />
* Spoofing of different types, and applications to fraud.<br />
* Techniques to avoid detection, tracking and takedown; and ways to block such techniques.<br />
* Honeypot design, data mining, and forensic aspects of fraud prevention.<br />
* Design and evaluation of user interfaces in the context of fraud and network security.<br />
* Best practices related to digital forensics tools and techniques, investigative procedures, and evidence acquisition, handling and preservation.</p>
<p>Important dates: (11:59pm US EDT)<br />
Full paper and RIP (Research in Progress) paper submissions due: June 30, 2010<br />
Paper notification: Aug 1, 2010<br />
Poster submissions due: August 29, 2010<br />
Poster notifications: September 5, 2010<br />
Conference: October 18-20, 2010<br />
Camera ready due: October 27, 2010</p>
<p>For more information on the submission process, visit<br />
<a href="http://www.ecrimeresearch.org/2010/cfp.html">http://www.ecrimeresearch.org/2010/cfp.html </a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1377&amp;title=IEEE%20eCrime%20Researchers%20Summit%202010" id="wpa2a_22"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1377/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Anti-Phishing Working Group: CeCOS IV</title>
		<link>http://blogs.securiteam.com/index.php/archives/1351</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1351#comments</comments>
		<pubDate>Sat, 20 Mar 2010 16:06:10 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1351</guid>
		<description><![CDATA[The Anti-Phishing Working Group has asked its members to publicize the forthcoming Counter eCrime Operations Summit in Brazil, which I&#8217;m pleased to do. Apologies to those who will have come across this elsewhere, including some of my other blogs. This year the APWG is hosting it&#8217;s fourth annual Counter eCrime Operations Summit (CeCOS IV) on [...]]]></description>
			<content:encoded><![CDATA[<p><em>The <a href="http://www.apwg.org/">Anti-Phishing Working Group </a>has asked its members to publicize the forthcoming Counter eCrime Operations Summit in Brazil, which I&#8217;m pleased to do. Apologies to those who will have come across this elsewhere, including some of my other blogs.</em></p>
<p>This year the APWG is hosting it&#8217;s fourth annual Counter eCrime Operations Summit (CeCOS IV) on May 11, 12 &amp; 13 in São Paulo, Brazil.  The Discounted Early Bird Registration rate will end on April 9th.  Do not miss this opportunity to join our host CERT.br with APWG Members from around the globe at this one of a kind event. Counter-eCrime professionals will meet for sessions and discussion panels that look into case studies of organizations under attack and deliver narratives of successful trans-national forensic cooperation.</p>
<p>This is APWG&#8217;s first visit to South America and will help build our network of trusted friends worldwide.  The discounted registration rate of $250 USD covers all three days of content, lunch, breaks and the Wednesday night reception.  (NOTE: APWG Members will receive an additional discount during registration) This &#8220;Early Bird&#8221; rate will end on April 9th, after that through the beginning of the event on 11 May registration is $325 USD.</p>
<p>A partial agenda is posted at the link below.  Translation services for English, Spanish and Portuguese will be available for all session.</p>
<p><a href="http://www.apwg.org/events/2010_opSummit.html#agenda">http://www.apwg.org/events/2010_opSummit.html#agenda</a></p>
<p>Register Here:</p>
<p><a href="http://www.apwg.org/events/2010_opSummit.html#agenda">http://secure.lenos.com/lenos/antiphishing/cecos2010/</a> </p>
<p><strong>David Harley FBCS CITP CISSP</strong><br />
Security Author/Consultant at Small Blue-Green World<br />
Chief Operations Officer, AVIEN<br />
ESET Research Fellow &amp; Director of Malware Intelligence</p>
<p>Also blogging at:</p>
<p>http://avien.net/blog</p>
<p>http://www.eset.com/blog</p>
<p>http://blogs.securiteam.com</p>
<p>http://blog.isc2.org/</p>
<p>http://dharley.wordpress.com</p>
<p>http://macvirus.com</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1351&amp;title=Anti-Phishing%20Working%20Group%3A%20CeCOS%20IV" id="wpa2a_24"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1351/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mac Virus update</title>
		<link>http://blogs.securiteam.com/index.php/archives/1345</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1345#comments</comments>
		<pubDate>Sat, 30 Jan 2010 13:24:13 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1345</guid>
		<description><![CDATA[I know, there ain&#8217;t no such thing! Well, we could have a lively debate on that topic, but not right now. On this occasion, I&#8217;m just letting anyone who wonders what happened to the Mac Virus web site (http://www.macvirus.com), which I inherited from Susan Lesch some years ago, what&#8217;s happening with it. We have nothing [...]]]></description>
			<content:encoded><![CDATA[<p>I know, there ain&#8217;t no such thing! </p>
<p>Well, we could have a lively debate on that topic, but not right now. </p>
<p>On this occasion, I&#8217;m just letting anyone who wonders what happened to the Mac Virus web site (http://www.macvirus.com), which I inherited from Susan Lesch some years ago, what&#8217;s happening with it. We have nothing to do with the cobwebby sites at http://www.macvirus.net and http://www.macvirus.org, or with http://macvirus.wordpress.com, whatever that is. </p>
<p>The http://www.macvirus.com URL actually redirects to my own Mac page at Small Blue-Green World site, which now re-redirects to a WordPress page. If you want to go straight to the Mac Virus blog, you can go direct <a href="http://macviruscom.wordpress.com/">here</a>. It&#8217;s still malware-oriented, of course, and, is likely to become more rather than less active in that area.</p>
<p>In fact, most of my <a href="http://www.smallblue-greenworld.co.uk/">Small Blue-Green World </a>content now resides on blog pages. ESET content is still blogged at http://www.eset.com/threat-center/blog/, of course, and AVIEN content is blogged at http://avien.net/blog/. </p>
<p>Confused? Me too&#8230;</p>
<p>We now return you to your normal programming. Scheduling, that is, not coding. Unless that&#8217;s what you&#8217;re doing at the moment. Oh, never mind.</p>
<p>The next time I blog here, it will be about a proper security issue again. I hope.</p>
<p>David Harley FBCS CITP CISSP<br />
Security Author/Consultant at Small Blue-Green World<br />
Chief Operations Officer, AVIEN<br />
ESET Research Fellow &amp; Director of Malware Intelligence</p>
<p>Also blogging at:</p>
<p>http://avien.net/blog</p>
<p>http://www.eset.com/threat-center/blog</p>
<p>http://smallbluegreenblog.wordpress.com/</p>
<p>http://macviruscom.wordpress.com</p>
<p>http://blog.isc2.org/</p>
<p>http://dharley.wordpress.com</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1345&amp;title=Mac%20Virus%20update" id="wpa2a_26"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1345/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Is this the laziest 419 of all time?</title>
		<link>http://blogs.securiteam.com/index.php/archives/1331</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1331#comments</comments>
		<pubDate>Sat, 14 Nov 2009 20:31:16 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1331</guid>
		<description><![CDATA[Subject: the sum of 1,000,000.00 Pounds From: British Tobacco Promo [Most of the address fields spoofed a US educational institution, though the reply-to was an address in China.] Message Body: You have won 1,000,000.00 Reply us with  your  details Name:Occupation:Country:Sex [This message is actually several weeks old, but I just spotted it while cleaning up [...]]]></description>
			<content:encoded><![CDATA[<p>Subject: the sum of 1,000,000.00 Pounds<br />
From: British Tobacco Promo</p>
<p>[<em>Most of the address fields spoofed a US educational institution, though the reply-to was an address in China.</em>]</p>
<p>Message Body:</p>
<p>You have won 1,000,000.00 Reply us with  your  details<br />
Name:Occupation:Country:Sex</p>
<p>[<em>This message is actually several weeks old, but I just spotted it while cleaning up one of my mailboxes. Could any potential victim honestly be that naive?</em>]</p>
<p>David Harley FBCS CITP CISSP<br />
Director of Malware Intelligence, ESET</p>
<p>Also blogging at:<br />
<a href="http://dharley.wordpress.com/"> http://dharley.wordpress.com/</a><br />
<a href="http://www.eset.com/threat-center/blog"> http://www.eset.com/threat-center/blog</a><br />
<a href="http://avien.net/blog"> http://avien.net/blog</a><br />
<a href="http://blog.isc2.org/"> http://blog.isc2.org/</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1331&amp;title=Is%20this%20the%20laziest%20419%20of%20all%20time%3F" id="wpa2a_28"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1331/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>A Fairy Tale</title>
		<link>http://blogs.securiteam.com/index.php/archives/1326</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1326#comments</comments>
		<pubDate>Mon, 05 Oct 2009 19:07:25 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1326</guid>
		<description><![CDATA[Withdrawn on legal advice. Sigh&#8230; So I&#8217;m going to ask some hypothetical questions instead. Principle 3 of the AMTSO (Anti-Malware Testing Standards Organization) guidelines document (http://www.amtso.org/amtso&#8212;download&#8212;amtso-fundamental-principles-of-testing.html) states that &#8220;Testing should be reasonably open and transparent.&#8221; The document goes on to explain what information on the test and the test methodology it&#8217;s reasonable to ask for. [...]]]></description>
			<content:encoded><![CDATA[<p>Withdrawn on legal advice. Sigh&#8230;</p>
<p>So I&#8217;m going to ask some hypothetical questions instead.</p>
<p>Principle 3 of the AMTSO (<a href="http://www.amtso.org">Anti-Malware Testing Standards Organization</a>) guidelines document (<a href="http://www.amtso.org/amtso---download---amtso-fundamental-principles-of-testing.html">http://www.amtso.org/amtso&#8212;download&#8212;amtso-fundamental-principles-of-testing.html</a>) states that &#8220;Testing should be reasonably open and transparent.&#8221; </p>
<p>The document goes on to explain what information on the test and the test methodology it&#8217;s reasonable to ask for.</p>
<p>So is it open and transparent for an anti-malware tester who claims that his tests are compliant with AMTSO guidelines to decline to answer a vendor&#8217;s questions or give any information about the reported performance of their product unless they buy a copy of the report or pay a consultancy fee to the tester?</p>
<p>There is, of course, nothing to stop an anti-malware tester soliciting payment from the vendors whose products have been tested both in advance of the test and in response to requests for further information. But is he then entitled to claim to be independent and working without vendor funding? In what respect is this substantially different to the way in which certification testing organizations work, for example?</p>
<p>It seems to me that AMTSO is going to have to consider those questions at its next meeting (in Prague, next week). Purely hypothetically, of course. What do you think?</p>
<p>David Harley CISSP FBCS CITP<br />
Small Blue-Green World</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1326&amp;title=A%20Fairy%20Tale" id="wpa2a_30"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1326/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

