<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>SpywareGuide Greynets Blog</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/" />
    <link rel="self" type="application/atom+xml" href="http://blog.spywareguide.com/atom.xml" />
    <id>tag:blog.spywareguide.com,2008-05-15://4</id>
    <updated>2009-12-31T21:34:56Z</updated>
    <subtitle>SpywareGuide&apos;s Greynets Blog is a destination where you can hear from the people who are part of the SpywareGuide and FaceTime Security Labs research teams, as well as developers, programmers and the occasional guest blogger. You never know what topics will be covered -- spyware, adware, rootkits, botnets, IM worms, the money side of malware, the underbelly of affiliate marketing, the world of greynets. Greynets are network-enabled applications that are installed on an end user&apos;s system without permission from IT and are highly evasive to existing security infrastructure. Greynet applications pose a security risk, but their risk must be managed in concert with the business benefits of the applications.</subtitle>
    <generator uri="http://www.sixapart.com/movabletype/">Movable Type Open Source 4.1</generator>

<entry>
    <title>A Year In Security</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/2009/12/a-year-in-security.html" />
    <id>tag:blog.spywareguide.com,2009://4.1058</id>

    <published>2009-12-31T18:43:30Z</published>
    <updated>2009-12-31T21:34:56Z</updated>

    <summary> Normal 0 false false false EN-GB X-NONE X-NONE /* Style Definitions */ table.MsoNormalTable {mso-style-name:&quot;Table Normal&quot;; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-priority:99; mso-style-qformat:yes; mso-style-parent:&quot;&quot;; mso-padding-alt:0cm 5.4pt 0cm 5.4pt; mso-para-margin-top:0cm; mso-para-margin-right:0cm; mso-para-margin-bottom:10.0pt; mso-para-margin-left:0cm; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:&quot;Times New Roman&quot;; mso-fareast-theme-font:minor-fareast;...</summary>
    <author>
        <name>Christopher Boyd</name>
        <uri>http://blog.spywareguide.com</uri>
    </author>
    
    
    <content type="html" xml:lang="en" xml:base="http://blog.spywareguide.com/">
        <![CDATA[<meta http-equiv="Content-Type" content="text/html; charset=utf-8"><meta name="ProgId" content="Word.Document"><meta name="Generator" content="Microsoft Word 12"><meta name="Originator" content="Microsoft Word 12"><link rel="File-List" href="file:///C:%5CUsers%5CPAPERG%7E1%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"><link rel="themeData" href="file:///C:%5CUsers%5CPAPERG%7E1%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"><link rel="colorSchemeMapping" href="file:///C:%5CUsers%5CPAPERG%7E1%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"><!--[if gte mso 9]><xml>
 <w:WordDocument>
  <w:View>Normal</w:View>
  <w:Zoom>0</w:Zoom>
  <w:TrackMoves/>
  <w:TrackFormatting/>
  <w:PunctuationKerning/>
  <w:ValidateAgainstSchemas/>
  <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>
  <w:IgnoreMixedContent>false</w:IgnoreMixedContent>
  <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>
  <w:DoNotPromoteQF/>
  <w:LidThemeOther>EN-GB</w:LidThemeOther>
  <w:LidThemeAsian>X-NONE</w:LidThemeAsian>
  <w:LidThemeComplexScript>X-NONE</w:LidThemeComplexScript>
  <w:Compatibility>
   <w:BreakWrappedTables/>
   <w:SnapToGridInCell/>
   <w:WrapTextWithPunct/>
   <w:UseAsianBreakRules/>
   <w:DontGrowAutofit/>
   <w:SplitPgBreakAndParaMark/>
   <w:DontVertAlignCellWithSp/>
   <w:DontBreakConstrainedForcedTables/>
   <w:DontVertAlignInTxbx/>
   <w:Word11KerningPairs/>
   <w:CachedColBalance/>
  </w:Compatibility>
  <m:mathPr>
   <m:mathFont m:val="Cambria Math"/>
   <m:brkBin m:val="before"/>
   <m:brkBinSub m:val="&#45;-"/>
   <m:smallFrac m:val="off"/>
   <m:dispDef/>
   <m:lMargin m:val="0"/>
   <m:rMargin m:val="0"/>
   <m:defJc m:val="centerGroup"/>
   <m:wrapIndent m:val="1440"/>
   <m:intLim m:val="subSup"/>
   <m:naryLim m:val="undOvr"/>
  </m:mathPr></w:WordDocument>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267">
  <w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/>
  <w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/>
  <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 1"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 2"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 3"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 4"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 5"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 6"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 7"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 8"/>
  <w:LsdException Locked="false" Priority="39" Name="toc 9"/>
  <w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/>
  <w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/>
  <w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/>
  <w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/>
  <w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/>
  <w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/>
  <w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/>
  <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/>
  <w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/>
  <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/>
  <w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/>
  <w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/>
  <w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/>
  <w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/>
  <w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/>
  <w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/>
  <w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/>
  <w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/>
  <w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/>
  <w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/>
  <w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/>
  <w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/>
  <w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/>
  <w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/>
  <w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/>
  <w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/>
  <w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/>
  <w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/>
  <w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/>
  <w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/>
  <w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/>
  <w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/>
  <w:LsdException Locked="false" Priority="37" Name="Bibliography"/>
  <w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/>
 </w:LatentStyles>
</xml><![endif]--><style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:"Cambria Math";
	panose-1:0 0 0 0 0 0 0 0 0 0;
	mso-font-charset:1;
	mso-generic-font-family:roman;
	mso-font-format:other;
	mso-font-pitch:variable;
	mso-font-signature:0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:-1610611985 1073750139 0 0 159 0;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-parent:"";
	margin-top:0cm;
	margin-right:0cm;
	margin-bottom:10.0pt;
	margin-left:0cm;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:Calibri;
	mso-fareast-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;
	mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	mso-themecolor:hyperlink;
	text-decoration:underline;
	text-underline:single;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-noshow:yes;
	mso-style-priority:99;
	color:purple;
	mso-themecolor:followedhyperlink;
	text-decoration:underline;
	text-underline:single;}
.MsoChpDefault
	{mso-style-type:export-only;
	mso-default-props:yes;
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:Calibri;
	mso-fareast-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;
	mso-fareast-language:EN-US;}
.MsoPapDefault
	{mso-style-type:export-only;
	margin-bottom:10.0pt;
	line-height:115%;}
@page Section1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;
	mso-header-margin:36.0pt;
	mso-footer-margin:36.0pt;
	mso-paper-source:0;}
div.Section1
	{page:Section1;}
-->
</style><!--[if gte mso 10]>
<style>
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin-top:0cm;
	mso-para-margin-right:0cm;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0cm;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;}
</style>
<![endif]--><span style="font-size: 11pt; line-height: 115%; font-family: &quot;Calibri&quot;,&quot;sans-serif&quot;;">2009
has seen some incredibly diverse and creative attacks - shall we take one last
look the scams, hijacks and infections that particularly caught our eye?<br />
<br />
<b>January</b>: If someone told you people will pay good money to have a third party
create a Botnet designed to DDoS gamers out of Xbox console sessions, you might
have wondered what exactly they were talking about. However, this technique
(which has remained off radar for quite some time) finally went <a href="http://news.bbc.co.uk/1/hi/technology/7888369.stm">mainstream</a> with
every second script kiddy trying to work out how to do it via endless Youtube
tutorials and "What am I doing wrong" posts on hacking forums.<br />
<br />
Attacks on games and gamers have been a constant thread in research this year,
as scammers realise there's a fair amount of money invested in gaming profiles
- and those profiles can be bought and sold, just like any other stolen
account. Attacks on consoles provide a bit of a headache for office network
admins, who may well be jumping on the "put a net connected console in the
office rec room and leave it to its own devices" bandwagon. Not a good idea...<br />
<br />
<b>February</b>: Taking the idea of valued gaming accounts one step further, Erik
Larkin of PC World explored the attacks on <a href="http://www.pcworld.com/article/160490/avoid_steam_games_scam_sites.html">Steam
account holders via phishing techniques</a>. Steam accounts can have hundreds
(or in some cases thousands) of dollars invested in them, and regular seasonal
sales tend to send profits through the roof. Indeed, there's a heavy collection
of "ten free games in exchange for your login" phish pages in circulation at
the moment. Don't be fooled! <br />
<br />
<b>April</b>: You can never be too careful with downloads, as <a href="http://blog.spywareguide.com/2009/04/instant-messaging-password-ste.html">this
story readily illustrated</a>. An instant messaging password stealer (that
could disguise itself as Yahoo Messenger, Live Messenger or Skype) turned up on
Download.com, a trusted source of legit downloads. Rogue elements will sadly
always slip through somewhere, but full credit to CNET for removing the offending
program quickly.<br />
<br />
<b>June</b>: A program surfaced claiming to be a mail <a href="http://www.webuser.co.uk/news/top-stories/369849/email-bomb-program-warning">bombing
extravaganza</a> that would smite all of your enemies. The catch? You had to
give them your own email address to use it.<br />
<br />
We've seen many, many programs that attempt to punk out people in the hacking /
cracking communities and while the majority of those files tend to stay on hacking
forums some do occasionally creep outside into the daylight.<br />
<br />
<b>July</b>: Oh dear. Targeting twelve year old kids? There's lame - then there's <a href="http://www.foxnews.com/story/0,2933,530684,00.html">this</a>. Popular
social networking / gaming site Neopets came under attack from individuals who
decided to offer kids "magical paintbrushes" for their Neopet in return for
running an executable file. Of course, those files would be Trojans, password
stealers and various other nasties in disguise. Taking advantage of a young
child's desire to obtain rare ingame items - then break their computer - is one
of the lowest attempts at being "a hacker" we can think of.<br />
<br />
There was also a <a href="http://games.slashdot.org/story/09/07/28/0716246/Gamerscore-Hacking-and-Its-Underground-Economy?art_pos=1">look
at Xbox Gamerscore hacking</a> - a technique used by people who want to
artificially inflate statistics related to a gaming account then sell it on.<br />
<br />
Did we mention the Megan Fox fake sex tape yet? No? Well, <a href="http://www.webuser.co.uk/news/top-stories/384758/megan-fox-sex-tape-warning">here
it is</a> (an article about it, anyway). Celebrities will always be used as low
hanging fruit as a means for people to infect themselves or fill in surveys and
Megan is no exception where that is concerned.<br />
<br />
<b>August</b>: Here we arrived at what seems to have been a phishing page linked to
from a <a href="http://www.theregister.co.uk/2009/08/17/facebook_phishing/">legit
Facebook application URL</a>. There was also this infection, designed to <a href="http://www.webuser.co.uk/news/top-stories/391522/image-eating-worm-warning">overwrite
all the images on your PC</a> with the word "Hacked".<span style="">&nbsp; </span>The Facebook attack was fairly inventive,
though we haven't seen a repeat performance so that's good news.<br />
<br />
<b>September</b>:<span style="">&nbsp; </span>Twilight fever. This was
always going to be sucked into various scams and sure enough, just before New
Moon came out in cinemas sites such as Youtube had videos on them promoting "<a href="http://www.webuser.co.uk/news/top-stories/396230/twilight-new-moon-video-scam-warning">online
versions" of the film</a>. Sure enough, all you got for your trouble was Zango
installers and empty pages.<br />
<br />
Can't have an end of year summary without a mention of Zango!<br />
<br />
<b>October</b>: This particular file hit the streets a little while after Google Wave
invites were no longer the hot topic of debate which probably helped to lessen
the impact. A <a href="http://www.webuser.co.uk/news/top-stories/427834/google-wave-invite-scam-warning">fake
Google Wave invite generator</a> most certainly did not generate passwords of
any kind, but did seem to be a likely candidate for harvesting email passwords.
Clever.<br />
<br />
We also talked about <a href="http://www.internetnews.com/security/article.php/3842751/Hackers+Target+Xbox+Live.htm">Gamers
Under Fire</a> at SecTor 2009, a security conference held in Canada. You can
take in all the conference presentations <a href="http://www.sector.ca/presentations.htm">here</a> - they're well worth
checking out.<br />
<br />
<b>November</b>: Ah, Facebook applications. Sometimes you get rogue ones - other
times, you get scams like this where no applications exist. Someone had the
idea of putting together a fake program that claimed to exploit a genuine
application by revealing <a href="http://www.scmagazineuk.com/new-facebook-malware-promises-to-reveal-identities-in-a-users-honesty-box/article/157102/">who-said-what
about you</a>. Of course, this was all nonsense and the program infected your
PC with a horrible file of the attacker's choosing. A simple but effective
attack technique.<br />
<br />
<b>December</b>:<span style="">&nbsp; </span>We'd been writing about
various fake "work from home with Google" scams all year long, and it was nice
to see some of them finally being <a href="http://www.pcworld.com/article/184003/company_sued_by_google_had_a_profitable_year.html">tickled
with the legal stick</a>. Long may it continue.<br />
<br />
We wound up the year with <a href="http://www.webuser.co.uk/news/top-stories/434767/visa-online-statement-scam-warning">ZBot</a>,
in the form of a fake "Your VISA account has been compromised, download this
file to see what's been going on" alert.<br />
<br />
A wide-ranging set of attacks then, and a good indication (as if any were
needed) that social networks, popular culture, videogames and the lives of
celebrities will be targets for Botnets, exploits, scams, get rich quick
schemes and every fake program you can think of well into 2010. It will be
interesting to see how many 2.0 sites maintain a robust privacy policy (if such
a thing is even possible) in the face of potential earnings from ad revenue,
and how easy (or difficult) those policies will make it for those who want to
use that data for nefarious purposes.</span> ]]>
        
    </content>
</entry>

<entry>
    <title>Youtube Comment Bot Spams In Waves</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/2009/12/youtube-comment-bot-spams-in-w.html" />
    <id>tag:blog.spywareguide.com,2009://4.1055</id>

    <published>2009-12-15T10:42:04Z</published>
    <updated>2009-12-15T10:43:55Z</updated>

    <summary>This is a rather interesting little tool. People have been making Youtube video rating tools (and spam commenters) for a while now, but with varying degrees of success.This one combines the two, and also attempts to randomise the Bot comments...</summary>
    <author>
        <name>Christopher Boyd</name>
        <uri>http://blog.spywareguide.com</uri>
    </author>
    
        <category term="Spam" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="youtube" label="Youtube" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://blog.spywareguide.com/">
        <![CDATA[This is a rather interesting little tool. People have been making Youtube video rating tools (and spam commenters) for a while now, but with varying degrees of success.<br /><br />This one combines the two, and also attempts to randomise the Bot comments to some degree, meaning Youtube may well miss a chunk of the fake ratings / messages attached to each video.<br /><br />Shall we take a look?<br /><br />This is the rating / comment bot in question, taking the form of an application wrapped around IE:<br /><br /> <style type="text/css">
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
</style>
<div class="flickr-frame">
<a href="http://www.flickr.com/photos/paperghost/4187469780/" title="photo sharing"><img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2707/4187469780_52ba609c2f.jpg" /></a>
<a href="http://www.flickr.com/photos/paperghost/4187469780/">Youtube Comment Bot</a>, originally uploaded by <a href="http://www.flickr.com/people/paperghost/">Paperghost</a>.<br /><br />In an attempt to win a game of "miss the Bot", the program preloads 50 accounts and numerous comments, and divides the accounts across five "wave" buttons, each containing 10 Youtube accounts. When a user runs the program, the following file is dropped into the Win32 Folder:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="ytcmntr4.jpg" src="http://blog.spywareguide.com/images/ytcmntr4.jpg" class="mt-image-none" style="" height="22" width="271" /></span><br /><br />It doesn't appear to do anything harmful to the target PC - it simply acts as the source for the account logins and comments.<br /><br />Anyway, depending on which wave you select, a randomly selected account from each group of ten tries to login to Youtube and rate / comment on a video of your choosing. Some of the accounts have already been flagged by Youtube, so they're not doing quite as well as they'd hoped:<br /><br />
</div>
<div class="flickr-yourcomment">

</div>
<style type="text/css">
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
</style>
<div class="flickr-frame">
<a href="http://www.flickr.com/photos/paperghost/4187469840/" title="photo sharing"><img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2761/4187469840_b4d7dc4425.jpg" /></a>
<br /><a href="http://www.flickr.com/photos/paperghost/4187469840/">Account Disabled</a>, originally uploaded by <a href="http://www.flickr.com/people/paperghost/">Paperghost</a>.<br /><br />It's easy enough to find some of their success stories, however.<br /><br />Here's one:<br /><br />
</div>
<div class="flickr-yourcomment">

</div>
<style type="text/css">
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
</style>
<div class="flickr-frame">
<a href="http://www.flickr.com/photos/paperghost/4187493778/" title="photo sharing"><img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2712/4187493778_6285e7eda7.jpg" /></a>
<a href="http://www.flickr.com/photos/paperghost/4187493778/">Youtube Comment Bot Spam</a>, originally uploaded by <a href="http://www.flickr.com/people/paperghost/">Paperghost</a>.<br /><br />Here's another, it's Banhammer time:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="ytcmntr6.gif" src="http://blog.spywareguide.com/images/ytcmntr6.gif" class="mt-image-none" style="" height="119" width="325" /></span><br /><br />As you might have guessed, this program has been in circulation on numerous hacking forums for a couple of weeks now and in general, the comments are being posted to videos promoting fake programs that are actually infection files.<br /><br />Not that you should ever take notice of Youtube comments anyway, of course...<br />
</div>
<div class="flickr-yourcomment">

</div>
]]>
        
    </content>
</entry>

<entry>
    <title>VGA Awards Trailers Used As Bait For Spam Offers</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/2009/12/vga-awards-trailers-used-as-ba.html" />
    <id>tag:blog.spywareguide.com,2009://4.1054</id>

    <published>2009-12-14T08:59:53Z</published>
    <updated>2009-12-14T09:46:19Z</updated>

    <summary>The VGA awards took place yesterday, and in the mad dash to see the trailers from the show online spam bait such as this is appearing on sites such as Youtube:From there, you&apos;re taken through a long chain of sites...</summary>
    <author>
        <name>Christopher Boyd</name>
        <uri>http://blog.spywareguide.com</uri>
    </author>
    
    
    <content type="html" xml:lang="en" xml:base="http://blog.spywareguide.com/">
        <![CDATA[The <a href="http://news.google.com/news/search?aq=f&amp;pz=1&amp;cf=all&amp;ned=uk&amp;hl=en&amp;q=vga+awards">VGA awards</a> took place yesterday, and in the mad dash to see the trailers from the show online spam bait such as this is appearing on sites such as Youtube:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="battrlr1.jpg" src="http://blog.spywareguide.com/images/battrlr1.jpg" class="mt-image-none" style="" height="280" width="499" /></span><br /><br />From there, you're taken through a long chain of sites asking for a "Minute of your time" to select and fill in one of a wide range of offers involving sites such as<br /><br />hotshootnews.com/celeb<br />seemyreview.com/votehh.htm<br /><br />An "end game" set of selections are all lumped together on this splash page:<br /><br />empire404.com/bonus/bonus.php<br /><br />with all of the landing pages hosted at<br /><br />tracking101.com.<br /><br />Quite a lot of hard work for some advert spam, and at every landing page you're told the "free videos" are one step away (even though they all turn out to be adverts and offers). There's $1000 gas cards, Mc Donalds VS Burger King and "Soda survey" (exciting!) to choose from, along with lots of other offers I couldn't possibly recommend filling in. Of particular note is the "favourite twitter celeb":<br /><br /><br /> <style type="text/css">
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
</style>
<div class="flickr-frame">
<a href="http://www.flickr.com/photos/paperghost/4183729779/" title="photo sharing"><img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2490/4183729779_82aef31a5f.jpg" /></a>
<a href="http://www.flickr.com/photos/paperghost/4183729779/">twitter celeb</a>, originally uploaded by <a href="http://www.flickr.com/people/paperghost/">Paperghost</a>.<br /><br />What's slightly more worrying is the above offers are geographically targeted - if you're outside the States, you're dropped onto this URL:<br /><br />032.com<br /><br />If you're in Europe, the page is blank. But if you go back with a US IP address, you may be served up with an embedded Facebook login page to access an application called "Loot" or an application called "Fish Isle":<br /><br />
</div>
<div class="flickr-yourcomment">

</div>
<style type="text/css">
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
</style>
<div class="flickr-frame">
<a href="http://www.flickr.com/photos/paperghost/4184517280/" title="photo sharing"><img alt="" class="flickr-photo" src="http://farm5.static.flickr.com/4003/4184517280_144aaa4d5a.jpg" /></a>
<a href="http://www.flickr.com/photos/paperghost/4184517280/">Facebook Ad</a>, originally uploaded by <a href="http://www.flickr.com/people/paperghost/">Paperghost</a>.<br /><br />While this appears to be a legit ad and not a phish , served up from<br /><br />apps.facebook.com/fishisle/t/fishad/ad.jsp?ads=facebook<br /><br />...the practice of popping login prompts from random redirection scripts is not a good one, and not something end-users should be trained in. That could just as easily have been something more malicious, and (funnily enough) only makes me somewhat suspicious of the applications being advertised.<br /><br />Marketing fail?<br />
</div>
<div class="flickr-yourcomment">

</div>
<div><br /></div>]]>
        
    </content>
</entry>

<entry>
    <title>Fake Visa Electronic Report Serves Up Zbot Data Stealer</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/2009/12/fake-visa-electronic-report-se.html" />
    <id>tag:blog.spywareguide.com,2009://4.1053</id>

    <published>2009-12-10T22:24:58Z</published>
    <updated>2009-12-11T15:24:31Z</updated>

    <summary>If you receive an EMail claiming to show an &quot;online statement&quot; from VISA, beware - you&apos;ll be walking into a trap of the &quot;horrible infection file&quot; variety.A website (with a .co.uk domain but hosted in India) is playing host to...</summary>
    <author>
        <name>Christopher Boyd</name>
        <uri>http://blog.spywareguide.com</uri>
    </author>
    
    
    <content type="html" xml:lang="en" xml:base="http://blog.spywareguide.com/">
        <![CDATA[If you receive an EMail claiming to show an "online statement" from VISA, beware - you'll be walking into a trap of the "horrible infection file" variety.<br /><br />A website (with a .co.uk domain but hosted in India) is playing host to the following fake setup, asking you to download an "electronic report" of your card transactions in relation to fraudulent transactions:<br /><br /> <style type="text/css">
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
</style>
<div class="flickr-frame">
<a href="http://www.flickr.com/photos/paperghost/4175381704/" title="photo sharing"><img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2759/4175381704_c8b946467a.jpg" /></a>
<br /><a href="http://www.flickr.com/photos/paperghost/4175381704/">ZBot Visa EXE</a>, originally uploaded by <a href="http://www.flickr.com/people/paperghost/">Paperghost</a><br /><br />Of course, the "statement" is in the form of an executable related to our old friend <a href="http://www.scmagazineus.com/zbot-evades-most-anti-virus-programs/article/149057/">Zbot</a>, which has been spammed out in every form of scam possible, from fake Windows and Outlook updates to phish attacks and server updates.<br /><br />Should you download and run it, your PC will immediately start making calls to the following domain:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="zbvisa2.jpg" src="http://blog.spywareguide.com/images/zbvisa2.jpg" class="mt-image-none" style="" width="298" height="30" /></span><br /><br />That particular URL has been linked to Zeus Botnet C&amp;C and other dubious practices - currently, it appears to be offline. The infected PC will have a file called SDRA64.exe running in the System32 Folder, which is a rather <a href="http://www.threatexpert.com/files/sdra64.exe.html">nasty little thing</a> associated with everything from <a href="http://www.pcanswers.co.uk/blog/sdra64exe-remove-trojan-menace-21-05-09">banking datatheft</a> to keylogging and IRC. The good news is, that particular file has been around for a while so detection levels across the board should be pretty good at this point (I'd double check with Virustotal, but I'm not alone in having some issues with that site at present).<br /><br />Never, ever download an executable file mentioned in an EMail claiming to be from your bank - you'll end up in a world of hurt.<br /><br />We detect the file as <a href="http://www.spywareguide.com/product_show.php?id=80236">Cardstatement.exe</a>. A huge thank you to Senior Threat Researcher Peter Jayaraj for his late night assistance with this one!<br />
</div>
<div class="flickr-yourcomment">

</div>
]]>
        
    </content>
</entry>

<entry>
    <title>Banned Console Owners Beat The System - With Stickers</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/2009/12/banned-console-owners-beat-the.html" />
    <id>tag:blog.spywareguide.com,2009://4.1052</id>

    <published>2009-12-10T09:28:26Z</published>
    <updated>2009-12-10T09:41:01Z</updated>

    <summary>Since the highly publicised wave of console bans for anybody found pirating XBox games (and, to a lesser extent cheating on the XBox Live network) there seems to be a rather popular item appearing all the time on sites such...</summary>
    <author>
        <name>Christopher Boyd</name>
        <uri>http://blog.spywareguide.com</uri>
    </author>
    
        <category term="Videogames" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="videogames" label="Videogames" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="xbox" label="XBox" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://blog.spywareguide.com/">
        <![CDATA[Since the highly publicised wave of console bans for anybody found pirating XBox games (and, to a lesser extent cheating on the XBox Live network) there seems to be a rather popular item appearing all the time on sites such as EBay.<br /><br />Shall we see what it is?<br /><br />Let's fire up EBay, and see how early a suggestion appears for the item we're looking for:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="xboxwar1.jpg" src="http://blog.spywareguide.com/images/xboxwar1.jpg" class="mt-image-none" style="" width="251" height="140" /></span><br /> <div><br />...oh dear. Why would people buy a warranty sticker for a games console? Simple:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="4xboxwar0.jpg" src="http://blog.spywareguide.com/images/4xboxwar0.jpg" class="mt-image-none" style="" width="309" height="37" /></span><br /><br />Nobody is going to take your console as a "broken" return from the place you bought it when the warranty is screaming "leet hax", right? Warranty sticker sale waves seem to come and go on trading / selling sites, but they seem to be coming back into fashion at the moment. Here's a few samples:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="4xboxwar3.jpg" src="http://blog.spywareguide.com/4xboxwar3.jpg" class="mt-image-none" style="" width="531" height="272" /></span><br /><br /></div>As you can see, a reasonable moneymaker for the seller. I particularly like the text on this one:<br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/xboxwar2.html" onclick="window.open('http://blog.spywareguide.com/images/xboxwar2.html','popup','width=608,height=355,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/xboxwar2-thumb-300x175.jpg" alt="xboxwar2.jpg" class="mt-image-none" style="" width="300" height="175" /></a></span>
<br />
Click to Enlarge<br />
<br />That's right, a sticker for your COLLECTION! I guess these are the new Pokemon cards.<br /><div><br />Here's one final batch - appearently these are the newer type of warranty sticker, which greatly increase your chances of getting a new console out of the store you bought it from (instead of them hitting you with the "cheater" stick and chasing you out of the building).<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="xboxwar4.jpg" src="http://blog.spywareguide.com/images/xboxwar4.jpg" class="mt-image-none" style="" width="308" height="242" /></span><br /></div><div><br />I'll stick with Pokemon, I think...<br /></div><div><br /></div>]]>
        
    </content>
</entry>

<entry>
    <title>Spot The Hack</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/2009/12/spot-the-hack.html" />
    <id>tag:blog.spywareguide.com,2009://4.1051</id>

    <published>2009-12-09T17:49:37Z</published>
    <updated>2009-12-09T17:58:58Z</updated>

    <summary>Sometimes, I see strange things.This is one of those moments. Can you see where the defacer has worked their &quot;magic&quot; on the below website called foremostbeverage.com?Could it be here, right at the top of the page? .flickr-photo { border: solid...</summary>
    <author>
        <name>Christopher Boyd</name>
        <uri>http://blog.spywareguide.com</uri>
    </author>
    
    
    <content type="html" xml:lang="en" xml:base="http://blog.spywareguide.com/">
        <![CDATA[Sometimes, I see strange things.<br /><br />This is one of those moments. Can you see where the defacer has worked their "magic" on the below website called foremostbeverage.com?<br /><br />Could it be here, right at the top of the page?<br /><style type="text/css">
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
</style>
<div class="flickr-frame">
<a href="http://www.flickr.com/photos/paperghost/4172325012/" title="photo sharing"><img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2711/4172325012_2b352cf17a.jpg" /></a>
<br /><a href="http://www.flickr.com/photos/paperghost/4172325012/">spot the hack 1</a>, originally uploaded by <a href="http://www.flickr.com/people/paperghost/">Paperghost</a>.
</div>
<div class="flickr-yourcomment">

</div>
<br />Nope.<br /><br />Perhaps they did their damage on the sidebar, or posted malicious URLs where the Social Networking sites should be?<br /><br /><style type="text/css">
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
</style>
<div class="flickr-frame">
<a href="http://www.flickr.com/photos/paperghost/4171569753/" title="photo sharing"><img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2619/4171569753_894360902c.jpg" /></a>
<br /><a href="http://www.flickr.com/photos/paperghost/4171569753/">spot the hack 2</a>, originally uploaded by <a href="http://www.flickr.com/people/paperghost/">Paperghost</a>.
</div>
<div class="flickr-yourcomment">

</div>
<br />Nope.<br /><br />Ah, they probably tampered with the fancy ad rollover and redirect you to some horrible .ru domain stuffed with Adware and Spyware and...<br /><br /><style type="text/css">
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
</style>
<div class="flickr-frame">
<a href="http://www.flickr.com/photos/paperghost/4171569811/" title="photo sharing"><img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2720/4171569811_ac3f170ccb.jpg" /></a>
<br /><a href="http://www.flickr.com/photos/paperghost/4171569811/">spot the hack 3</a>, originally uploaded by <a href="http://www.flickr.com/people/paperghost/">Paperghost</a>.
</div>
<div class="flickr-yourcomment">

</div>
<br />Nope. Hang on, what is that?<br /><br /><style type="text/css">
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
</style>
<div class="flickr-frame">
<a href="http://www.flickr.com/photos/paperghost/4171615911/" title="photo sharing"><img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2560/4171615911_4ed8fe8f9f.jpg" /></a>
<br /><a href="http://www.flickr.com/photos/paperghost/4171615911/">spot the hack 4</a>, originally uploaded by <a href="http://www.flickr.com/people/paperghost/">Paperghost</a>.
</div>
<div class="flickr-yourcomment">

</div><br />There. Right there. Allow me to use a large red arrow, drawn in MS Paint:<br /><br /><style type="text/css">
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
</style>
<div class="flickr-frame">
<a href="http://www.flickr.com/photos/paperghost/4171615985/" title="photo sharing"><img alt="" class="flickr-photo" src="http://farm5.static.flickr.com/4038/4171615985_c1f436389b.jpg" /></a>
<br /><a href="http://www.flickr.com/photos/paperghost/4171615985/">spot the hack 5</a>, originally uploaded by <a href="http://www.flickr.com/people/paperghost/">Paperghost</a><br /><br />It appears to be moving. What on Earth could it possib -<br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />
</div>
<div class="flickr-yourcomment">

<a href="http://img130.imageshack.us/i/dancingbananak.gif/"><img src="http://img130.imageshack.us/img130/1922/dancingbananak.gif" alt="Image Hosted by ImageShack.us" border="0" /></a><br />By <a href="http://profile.imageshack.us/user/Paperghost">Paperghost</a><br /><br />...oh. Well, that's different.<br /><br />We have of course notified the site owners (and don't think we didn't spot the hidden text message on the website, either). Now if you'll excuse me, I have a serious case of banana related eye strain...<br />
</div>
<br /> ]]>
        
    </content>
</entry>

<entry>
    <title>The Futility Of EULAs</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/2009/12/the-futility-of-eulas.html" />
    <id>tag:blog.spywareguide.com,2009://4.1050</id>

    <published>2009-12-09T12:33:55Z</published>
    <updated>2009-12-09T12:38:35Z</updated>

    <summary>Here we have a typical IM toolbar (SweetIM), which has a rather curious EULA. .flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; } Sweet? Nope..., originally uploaded by...</summary>
    <author>
        <name>Christopher Boyd</name>
        <uri>http://blog.spywareguide.com</uri>
    </author>
    
        <category term="Instant Messaging" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="instantmessaging" label="Instant Messaging" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://blog.spywareguide.com/">
        <![CDATA[Here we have a typical IM toolbar (SweetIM), which has a rather curious EULA.<br /><br /><style type="text/css">
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
</style>
<div class="flickr-frame">
<a href="http://www.flickr.com/photos/paperghost/4171749786/" title="photo sharing"><img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2533/4171749786_d1183d19d1.jpg" /></a>
<a href="http://www.flickr.com/photos/paperghost/4171749786/">Sweet? Nope...</a>, originally uploaded by <a href="http://www.flickr.com/people/paperghost/">Paperghost</a><br /><br />Yes, they <i>really</i> want you to download this program. What particularly caught my eye was the age requirements on the EULA:<br /><br /><span style="font-size: 90%;"><i>Please note: (1) you MUST be 13 years or older to install or to use the SweetIM Software. If you are not yet 13, do 
not download SweetIM Software</i><br /><br />Thirteen? I must admit, I don't see many applications with an age requirement as low as that.<br /><br />Okay, fine. You want to allow 13 year old kids to download this thing, fair enough; they're not stupid. However, if you're going to aim your app at kids that young, you probably shouldn't include a EULA that takes about six weeks to read.<br /><br />Seriously, <a href="http://www.sweetim.com/eula.html#terms">check it out</a>.<br /><br />Ten points to anybody who can explain how a reasonably intelligent adult could plough through that lot, let alone a kid. The default narrow web browser it opens in (see the above screenshot) makes it appear to be even longer than it actually is. I dusted off our <a href="http://www.spywareguide.com/analyze/index.php">EULA Analyzer</a> to see what it thought of it all; the results are pretty much as you expected. That is to say, completely ludicrous:<br /><br /></span><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="swetim2.jpg" src="http://blog.spywareguide.com/images/swetim2.jpg" class="mt-image-none" style="" width="454" height="234" /></span><br /><br />According to the above, an application that they want thirteen year olds to use has a EULA that's BEYOND twelfth grade reading level. For those of you not in the States, a twelfth grader is usually <i>seventeen or eighteen</i>.<br /><br />Doh.<br /><br />170 sentences, 5,000+ words, 34 odd words per sentence......enjoy, kids!<br />
</div>
<div class="flickr-yourcomment">

</div>]]>
        
    </content>
</entry>

<entry>
    <title>Auto Whaler Spears Phishers</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/2009/12/auto-whaler-spears-phishers.html" />
    <id>tag:blog.spywareguide.com,2009://4.1048</id>

    <published>2009-12-07T11:59:33Z</published>
    <updated>2009-12-07T12:06:22Z</updated>

    <summary>Proving conclusively that there is no honour among thieves (as if you needed proof), here&apos;s a website that goes hunting for so-called &quot;big fish&quot; - namely, phishers with a plentiful collection of logins stored on their phishing pages.The website itself...</summary>
    <author>
        <name>Christopher Boyd</name>
        <uri>http://blog.spywareguide.com</uri>
    </author>
    
        <category term="Phish" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Phishing Scams" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="phish" label="Phish" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="phishing" label="Phishing" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://blog.spywareguide.com/">
        <![CDATA[Proving conclusively that there is no honour among thieves (as if you needed proof), here's a website that goes hunting for so-called "big fish" - namely, phishers with a plentiful collection of logins stored on their phishing pages.<br /><br />The website itself is free of content, save for one small search bar at the top of the screen.<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="autowhle1.jpg" src="http://blog.spywareguide.com/images/autowhle1.jpg" class="mt-image-none" style="" width="407" height="158" /></span><br /> <div><br />As you've probably guessed, the wannabe <a href="http://blogs.pcmag.com/securitywatch/2008/04/whale_phishing.php">Whaler</a> (traditionally a hunter of high level executives and CEOs, now turning their target on, um, random phishers) enters the URL of a confirmed phishing site into the box and hits "Submit".<br /><br />At this point, the site checks a large list of common (and not so common) filenames that are likely to contain lots of logins gathered up by the original phisher.<br /><br />If the Whaler is successful, they'll see something like this:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="autowhle3.jpg" src="http://blog.spywareguide.com/images/autowhle3.jpg" class="mt-image-none" style="" width="337" height="265" /></span><br /></div><div><br />From there, it's simply a case of the Whaler collecting the logins, changing all the passwords and bumping up their tally of stolen details with a minimum of effort. If you're one of the phishing victims whose login details are now changing hands from phisher to whaler, you have my apologies - it can't be nice to see your already stolen account become that little bit dirtier.<br /><br />While the above site will no doubt be crashing and burning sometime in the near future (especially as the free hosting it sits on can't seem to cope with the strain of becoming the most popular site on the web for script kiddies and account stealers in general), you can bet there will be endless copycats to take its place.<br /><br />Can't wait to see what "Version 2" brings...<br /></div>]]>
        
    </content>
</entry>

<entry>
    <title>Fake Porn Grabbers Snag Nothing But Malware</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/2009/12/fake-porn-grabbers-snag-nothin.html" />
    <id>tag:blog.spywareguide.com,2009://4.1046</id>

    <published>2009-12-02T09:11:06Z</published>
    <updated>2009-12-02T09:17:36Z</updated>

    <summary>Hm - not so much a &quot;porn success&quot; as a &quot;porn fail&quot;.I find it rather interesting that in the wake of the recent hunt for individuals caught sharing pornography via P2P applications that many programs such as these are suddenly...</summary>
    <author>
        <name>Christopher Boyd</name>
        <uri>http://blog.spywareguide.com</uri>
    </author>
    
    
    <content type="html" xml:lang="en" xml:base="http://blog.spywareguide.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="prndlder0.jpg" src="http://blog.spywareguide.com/images/prndlder0.jpg" class="mt-image-none" style="" width="103" height="104" /></span><br /><br />Hm - not so much a "porn success" as a "porn fail".<br /><br />I find it rather interesting that in the wake of the recent hunt for individuals caught <a href="http://torrentfreak.com/30000-internet-users-to-receive-file-sharing-cash-demands-091125/">sharing pornography via P2P applications</a> that many programs such as these are suddenly appearing on forum links, downloads and chat rooms:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/prndlder1.html" onclick="window.open('http://blog.spywareguide.com/images/prndlder1.html','popup','width=702,height=483,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/prndlder1-thumb-300x206.png" alt="prndlder1.png" class="mt-image-none" style="" width="300" height="206" /></a></span> <div>Click to Enlarge<br /><br />"Porn Downloader", which for all the World looks like it's made to look like some kind of primitive P2P application, even though the program is designed to let you select a file for download from a website then manually grab it - so not quite the same thing.<br /><br />The similarity is still striking, especially as the above fake application would be 100% pointless if it were real - why would you use a program like that to download something when you would (logically enough) simply right click and save as? It goes without saying that the program is a fake, designed to be wrapped up with whatever virus, worm or trojan the attacker feels like.<br /><br />Here's another one, this time claiming to grab you lots and lots of free passwords from paid-for porn sites:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/prndlder2.html" onclick="window.open('http://blog.spywareguide.com/images/prndlder2.html','popup','width=393,height=580,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/prndlder2-thumb-300x442.jpg" alt="prndlder2.jpg" class="mt-image-none" style="" width="300" height="442" /></a></span><br /></div><div>Click to Enlarge<br /><br />Despite the password / login box, you can enter anything you like - or nothing at all - and be taken straight to the application proper.<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="prndlder25.jpg" src="http://blog.spywareguide.com/images/prndlder25.jpg" class="mt-image-none" style="" width="532" height="306" /></span><br /></div><div><br />"If no accounts show up please try again later" - well, you'll probably be too busy trying to remove whatever infection file has been bound to the fake application to care (not that the program gives you any logins - it doesn't).<br /><br />As usual, steer clear and think twice before grabbing programs such as the above. If the legal letter slingers don't get you, the infection files will...<br /></div>]]>
        
    </content>
</entry>

<entry>
    <title>Console DDoS Botnets - A Thriving Industry</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/2009/12/console-ddos-botnets-a-thrivin.html" />
    <id>tag:blog.spywareguide.com,2009://4.1045</id>

    <published>2009-12-01T10:04:50Z</published>
    <updated>2009-12-01T19:31:55Z</updated>

    <summary>I&apos;ve talked about Botnets used to kick gamers out of sessions before, but I thought it might be interesting to check out some of the current pricing, along with a few other things.Botnets and Gaming - wha?People have been using...</summary>
    <author>
        <name>Christopher Boyd</name>
        <uri>http://blog.spywareguide.com</uri>
    </author>
    
        <category term="Videogames" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="ddos" label="DDoS" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="videogames" label="Videogames" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="xbox" label="XBox" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://blog.spywareguide.com/">
        <![CDATA[I've talked about Botnets used to kick gamers out of sessions before, but I thought it might be interesting to check out some of the current pricing, along with a few other things.<br /><br /><b>Botnets and Gaming - wha?</b><br /><br />People have been using various means to lag people out of games for many years, but it had always been a PC thing. The moment online console gaming took off, somebody realised most console gaming sessions were peer to peer (which meant IP addresses were easy to grab), combined Botnets with moneymaking and rolled out an unstoppable army of teabagging and headshottery.<br /><br /><b>How?</b><br /><br />It all depends on the game. Most online console games offer up rewards for progressing through the ranks, be it additional items, weapons, outfits and / or levels.<br /><br />Stolen high level accounts in games such as Halo themselves fetch a tidy sum on the black market (would anybody have seriously thought a stolen gaming account could pull in as much as $25 a few years ago?) but the art of "host booting" has turned into a bit of a money spinner.<br /><br />There are three main types of lagging a game out, and depending on how the game works various types will be deployed or blended to ensure the attacker wins the game and levels up.<br /><br /><b>1) Lag switching</b>. A <a href="http://blog.spywareguide.com/2009/03/lag-switching-big-business.html">lag switch</a> can be picked up for around $20, and if you've ever been in a game that appears to be frozen while the other team happily runs around shooting you this is likely the culprit. Quite common, unfortunately.<br /><br /><b>2) Host forcing</b>. More often than not, many games come down to who happens to be hosting it. To ensure the hosting advantage (which may or may not be debated endlessly by those who refute being pwned by something as basic as "my connection wasn't as good") the art of "host forcing" was born. Typically, a combination of various programs are used such as Zone Alarm, Commview and custom built programs such as this one:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="ekksbawks2.jpg" src="http://blog.spywareguide.com/images/ekksbawks2.jpg" class="mt-image-none" style="" width="390" height="340" /></span><br /><br /> <div>....to discover the IP addresses of the players, and start throwing them into various "Trusted zones" (which then leads to the not-entirely-sophisticated process of, er, waggling sliders up and down rapidly in Zone Alarm. Nobody ever said this was an elegant solution). That "ION" program has been around since the days of Halo 2, by the way.<br /><br />Once you have the host, the theory is that you have a slight advantage over the other players because you have no lag. However, this isn't enough for the cheaters so what they'd do is hit the "standby" button on their router and when the game would come back (after lagging all over the place) everybody bar the host would still be lagging. This would result in lots and lots of headshots with a fair amount of swearing from the others in the session.<br /><br />Worse, in addition to single players doing this, whole teams can bridge their connections and attempt a "team standby", where one team is fine but the other is doomed.<br /><br />Not very nice, but there you go.<br /><br /><b>3) DDoS Host Booters</b>. These are probably the worst of the three tactics on offer, and involve custom made programs that target specific players, then knock them offline via a dedicated Botnet. This is no different to someone aiming a regular Botnet at your home connection.<br /><br /><style type="text/css">
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
</style>
<div class="flickr-frame">
<a href="http://www.flickr.com/photos/paperghost/4149968150/" title="photo sharing"><img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2514/4149968150_5f0f47d3b2.jpg" /></a>
<br /><a href="http://www.flickr.com/photos/paperghost/4149968150/">host booter</a>, originally uploaded by <a href="http://www.flickr.com/people/paperghost/">Paperghost</a>.
</div>
<div class="flickr-yourcomment">

</div><br />As already mentioned, most console games are peer to peer and because you can use Internet Connection Sharing with an XBox console, it's the easiest thing in the world to grab some IP addresses and have some "fun". Because the attacks target the player rather than XBox Live itself (which would likely be a futile effort) it's quite difficult to do anything about it.<br /><br />Many saw an opening for money making with this technique, because there are no end of technologically clueless (but very angry) gamers out there who want to get even.<br /><br />Want to DDoS someone, win that online session and move up a rank or three? No problem, pay us and we'll create a custom built DDoS Low Orbital Cannon to clear out the noobs. Some games punish players / teams that leave a session early, removing experience points and / or awarding the win to the other team which makes this technique rather appealing.<br /><br />Although getting on a bit, the below pricing structure is pretty much what it is now:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="ekksbawks1.jpg" src="http://blog.spywareguide.com/images/ekksbawks1.jpg" class="mt-image-none" style="" width="311" height="439" /></span><br /></div><div><br /><b>$5 for a Bot</b>, with nothing else. This is the option for those who already know what they're doing and have a Booting program ready to roll.<br /><br /><b>$10 for a Bot AND a Booter</b>, for those who have no idea which Booter to pick. You're not going to kick many people out of Halo 3 with one Bot, however, so from there it's <b>$2 per additional infected computer</b> added to your Botnet of Doom.<br /><br /><b>$5</b> extra is needed if you want them to go dabble with your network / Firewall, and it's <b>$20</b> if you want them to remote into your PC and set EVERYTHING up for you. Also note that they'll put a fake icon onto the infection file they're trying to nail people with on your behalf - I suppose paying up is in your best interest if you want them to infect as many people as possible.<br /><br />Some charge per game and / or rank in a particular game, rather than per Bot because hey - they're just that nice, and (more importantly) they figure once you've set up your Botnet for someone you probably can't get anymore money out of them. Keep <i>control</i> of the Botnet, however, and you'll have money rolling in for as long as the buyer wants to DDoS gamers.<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="ekksbawks3.jpg" src="http://blog.spywareguide.com/images/ekksbawks3.jpg" class="mt-image-none" style="" width="248" height="83" /></span><br /></div><div><br />Dedicated Host Booting sites that contain both Booting programs and tutorials are a relatively new addition to the ranks, but they're definitely growing in number. Here's a membership sample from one of the more recent portals:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="host booter community.png" src="http://blog.spywareguide.com/images/host%20booter%20community.png" class="mt-image-none" style="" width="422" height="60" /></span><br /><br />Worryingly, there are rewards for promoting those communities:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="ekksbawks4.jpg" src="http://blog.spywareguide.com/images/ekksbawks4.jpg" class="mt-image-none" style="" width="410" height="205" /></span><br /></div><div><br />Free Bots? Yep. I've seen one or two sites offering up to as many as 30 or 40 free Bots in return for spreading the word. It's interesting how console gaming is becoming a bit of a driving force for individuals racing out to infect computers, and I don't think the situation will improve anytime soon...<br /></div>]]>
        
    </content>
</entry>

<entry>
    <title>Fake Program Is Fake...</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/2009/11/fake-program-is-fake.html" />
    <id>tag:blog.spywareguide.com,2009://4.1044</id>

    <published>2009-11-27T09:56:50Z</published>
    <updated>2009-11-27T09:59:30Z</updated>

    <summary>Throw another fake program that claims to &quot;hack&quot; XBox Live accounts on the pile: If you ever run anything like the above on your PC, the only thing you&apos;ll hack is yourself.Don&apos;t do it, kids!...</summary>
    <author>
        <name>Christopher Boyd</name>
        <uri>http://blog.spywareguide.com</uri>
    </author>
    
        <category term="Videogames" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="videogames" label="Videogames" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://blog.spywareguide.com/">
        <![CDATA[Throw another fake program that claims to "hack" XBox Live accounts on the pile:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fakebawkz1.gif" src="http://blog.spywareguide.com/images/fakebawkz1.gif" class="mt-image-none" style="" width="565" height="394" /></span><br /> <div><br />If you ever run anything like the above on your PC, the only thing you'll hack is yourself.<br /><br />Don't do it, kids!<br /></div>]]>
        
    </content>
</entry>

<entry>
    <title>L4D2 / Modern Warfare 2: Night Of The Living Keygens</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/2009/11/l4d2-modern-warfare-2-night-of.html" />
    <id>tag:blog.spywareguide.com,2009://4.1042</id>

    <published>2009-11-25T11:35:53Z</published>
    <updated>2009-11-25T12:13:48Z</updated>

    <summary>You know how the nice man on the internet offers you free stuff and you download the free stuff and run the free stuff?Yeah, don&apos;t want to be doing that. With the launch of Modern Warfare 2 and Left 4...</summary>
    <author>
        <name>Christopher Boyd</name>
        <uri>http://blog.spywareguide.com</uri>
    </author>
    
    
    <content type="html" xml:lang="en" xml:base="http://blog.spywareguide.com/">
        <![CDATA[You know how the nice man on the internet offers you free stuff and you download the free stuff and run the free stuff?<br /><br />Yeah, don't want to be doing that. With the launch of Modern Warfare 2 and Left 4 Dead 2 on PC in recent weeks, it's only natural that people would quickly jump on the shenanigan bandwagon.<br /><br />Case in point:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mwl4d21.jpg" src="http://blog.spywareguide.com/images/mwl4d21.jpg" class="mt-image-none" style="" height="80" width="222" /></span><br /> <div><br />Numerous forums, chatrooms and Youtube videos abound with plentiful Left 4 Dead and Modern Warfare Keygens that really, really work (honest) and most definitely aren't infection files in the slightest.<br /><br />No sir. Would we put something like this in a video comment if it was an infection file?<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mwl4d22.jpg" src="http://blog.spywareguide.com/images/mwl4d22.jpg" class="mt-image-none" style="" height="87" width="151" /></span><br /></div><div><br />...uh...don't answer that.<br /><br />Anyway, they look nice:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mwl4d23.jpg" src="http://blog.spywareguide.com/images/mwl4d23.jpg" class="mt-image-none" style="" height="284" width="302" /></span><br /></div><div><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mwl4d24.jpg" src="http://blog.spywareguide.com/images/mwl4d24.jpg" class="mt-image-none" style="" height="258" width="350" /></span><br /></div><div><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mwl4d25.jpg" src="http://blog.spywareguide.com/images/mwl4d25.jpg" class="mt-image-none" style="" height="200" width="445" /></span><br /></div><div><br />...but they all come with horrible stings in the tail. Some are designed to be bound with whatever infection the attacker wants to bop you over the head with; others come pre-rolled with a malicious file onboard like the one below that's currently being promoted on various Youtube videos:<br /><br /></div><style type="text/css">
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
</style>
<div class="flickr-frame">
<a href="http://www.flickr.com/photos/paperghost/4132679647/" title="photo sharing"><img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2531/4132679647_ae404cd989.jpg" /></a>
<br /><a href="http://www.flickr.com/photos/paperghost/4132679647/">Modern Warfare / L4D2 Keygen Worm</a>, originally uploaded by <a href="http://www.flickr.com/people/paperghost/">Paperghost</a>.
<br /><br />Allow the randomly named file to open fire on your PC, and you'll see many entries like this filling up a HJT log:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mwl4d27.png" src="http://blog.spywareguide.com/images/mwl4d27.png" class="mt-image-none" style="" height="63" width="363" /></span><br /><br />That particular file is a worm, and not a <a href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SPYBOT.JI&amp;VSect=P">particularly nice one</a> at that. Make no mistake, any and all "keygen creators" you'll see over the coming weeks in relation to the above PC games should be avoided like the plague...or a zombie....or a heavily armed soldier that keeps respawning from the same hut even though you shot him dead ten times already.<br /><br />Stupid respawns...<br /></div>
<div class="flickr-yourcomment">

</div>
]]>
        
    </content>
</entry>

<entry>
    <title>Testimonial Fail</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/2009/11/testimonial-fail.html" />
    <id>tag:blog.spywareguide.com,2009://4.1041</id>

    <published>2009-11-23T08:53:21Z</published>
    <updated>2009-11-23T08:55:39Z</updated>

    <summary>Whoops....</summary>
    <author>
        <name>Christopher Boyd</name>
        <uri>http://blog.spywareguide.com</uri>
    </author>
    
    <category term="fakeadvertising" label="Fake advertising" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://blog.spywareguide.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="testmonfail.gif" src="http://blog.spywareguide.com/images/testmonfail.gif" class="mt-image-none" style="" height="144" width="500" /></span><br /><br />Whoops. <div><br /></div>]]>
        
    </content>
</entry>

<entry>
    <title>The Infection File Popularity Contest</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/2009/11/the-infection-file-popularity.html" />
    <id>tag:blog.spywareguide.com,2009://4.1040</id>

    <published>2009-11-19T16:06:10Z</published>
    <updated>2009-11-19T16:29:42Z</updated>

    <summary>Ever wondered exactly how people who enjoy putting malicious files into the wide blue yonder ensure their bundles of joy are as attractive as possible to those who would happily download them?Well, I came across this program today and thought...</summary>
    <author>
        <name>Christopher Boyd</name>
        <uri>http://blog.spywareguide.com</uri>
    </author>
    
    
    <content type="html" xml:lang="en" xml:base="http://blog.spywareguide.com/">
        <![CDATA[Ever wondered exactly how people who enjoy putting malicious files into the wide blue yonder ensure their bundles of joy are as attractive as possible to those who would happily download them?<br /><br />Well, I came across this program today and thought it was worth looking into. It dips into what's hot and current in the world of free downloads then uses that to ensnare as many potential victims as possible.<br /><br />How do they do it?<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="iwrz01.png" src="http://blog.spywareguide.com/images/iwrz01.png" class="mt-image-none" style="" width="92" height="55" /></span><br /> <div><br />The above program helps, for starters. Fire it up and you see this:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="iwrz02.png" src="http://blog.spywareguide.com/images/iwrz02.png" class="mt-image-none" style="" width="323" height="318" /></span><br /></div><div><br />As you can see, there's a number of "Top 100" options for music, videos, software and a download button. What are we downloading, and from where? The answer to the first question is quickly revealed when you see a number of text files deposited in one of the application folders:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="iwrz03.png" src="http://blog.spywareguide.com/images/iwrz03.png" class="mt-image-none" style="" width="340" height="169" /></span><br /></div><div>Open up the "Musik" file, and you're presented with a long list of rather current albums:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/iwrz04.html" onclick="window.open('http://blog.spywareguide.com/images/iwrz04.html','popup','width=516,height=440,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/iwrz04-thumb-300x255.png" alt="iwrz04.png" class="mt-image-none" style="" width="300" height="255" /></a></span><br />Click to Enlarge<br /><br />A quick check of network traffic and the source of the lists is clear:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="iwrz07.png" src="http://blog.spywareguide.com/images/iwrz07.png" class="mt-image-none" style="" width="345" height="19" /></span><br /></div><div><br />Compare the list of albums above with the below screenshot of the Top Album Torrents on The Pirate Bay, organised by number of <a href="http://en.wikipedia.org/wiki/Terminology_of_BitTorrent#Seeder">Seeders</a>:<br /><br /></div><style type="text/css">
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
</style>
<div class="flickr-frame">
<a href="http://www.flickr.com/photos/paperghost/4117737470/" title="photo sharing"><img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2599/4117737470_ffccab2c98.jpg" /></a>
<a href="http://www.flickr.com/photos/paperghost/4117737470/">Popular Pirate Bay Downloads</a>, originally uploaded by <a href="http://www.flickr.com/people/paperghost/">Paperghost</a>.<br /><br />In a simple (yet rather clever move) the program organises the various types of file according to the files with the biggest amount of seeders on The Pirate Bay, then rips the names of each file (be it music, video or something else altogether) and arranges them in lists on your PC. From there, it is child's play to apply the names of the files to your infections (it also allows you to change file sizes, icons and remove version data to make your infection look more like the real thing) then offer them as downloads on forums, free file hosting and anywhere else the attacker can think of.<br /><br />By using this tool, someone with a penchant for rogue file distribution is always going to have an easy to use list of the freebies most in demand by the downloaders, and (unfortunately for us) it all makes pimping their infections that little bit easier.<br /><br />Talk about harnessing people power...<br /></div>
<div class="flickr-yourcomment">

</div>]]>
        
    </content>
</entry>

<entry>
    <title>Block Checker Download - Avoid!</title>
    <link rel="alternate" type="text/html" href="http://blog.spywareguide.com/2009/11/block-checker-download-avoid.html" />
    <id>tag:blog.spywareguide.com,2009://4.1039</id>

    <published>2009-11-18T08:54:53Z</published>
    <updated>2009-11-18T09:00:56Z</updated>

    <summary>&quot;Block Checkers&quot; are those wonderful scam sites that claim to be able to show you who has you down as &quot;blocked&quot; on your favourite IM application. They&apos;ve been around for a while, but always take the form of a website...</summary>
    <author>
        <name>Christopher Boyd</name>
        <uri>http://blog.spywareguide.com</uri>
    </author>
    
        <category term="Instant Messaging" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="blockchecker" label="Block Checker" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="instantmessaging" label="Instant Messaging" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://blog.spywareguide.com/">
        <![CDATA["Block Checkers" are those wonderful <a href="http://blog.spywareguide.com/2008/06/another-site-asking-for-msn-lo.html">scam sites</a> that <a href="http://blog.spywareguide.com/2008/11/more-msn-login-harvesting.html">claim</a> to be able to show you <a href="http://blog.spywareguide.com/2009/04/meetyourimscom-spamtacular.html">who has you down as "blocked"</a> on your favourite IM application. They've been around for a while, but <i>always</i> take the form of a website that you enter your details on. Once you've entered your login, you can expect to see your IM account sending lots of spam for viagra (along with adverts for the block checker site you used) to all of your contacts.<br /><br />It's a rather spectacular way to lose all your friends on Instant Messaging (and quickly answers the question of "Who is blocking you". Answer: everybody).<br /><br />Well, some wily individual has taken inspiration from the static webpages and come up with a Block Checker in the form of an executable file. However, this one has somewhat more sinister intentions than spamming links to a useless block check website with the occasional advert for a genuine rolex watch.<br /><br />Shall we take a look?<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mobbkck1.jpg" src="http://blog.spywareguide.com/images/mobbkck1.jpg" class="mt-image-none" style="" width="177" height="50" /></span><br /> <div><br />"MSN Block Checker", from Microsoft Corp. A quick check - aha - will reveal a different story:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mobbkck2.jpg" src="http://blog.spywareguide.com/images/mobbkck2.jpg" class="mt-image-none" style="" width="187" height="116" /></span><br /></div><div><br />"MsnFake"? Oh dear. Here's what the program looks like when fired up:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mobbkck3.png" src="http://blog.spywareguide.com/images/mobbkck3.png" class="mt-image-none" style="" width="380" height="343" /></span><br /><br />Do you want to see the obligatory fake error message that appears when you enter your Windows LIVE ID and hit "Sign in"? Of course you do.<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mobbkck4.png" src="http://blog.spywareguide.com/images/mobbkck4.png" class="mt-image-none" style="" width="288" height="132" /></span><br /></div><div><br />Faintly humorous that they left "MsnFake" in the popup box. Examining the code of the program rather gives the game away:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mobbkck5.png" src="http://blog.spywareguide.com/images/mobbkck5.png" class="mt-image-none" style="" width="247" height="73" /></span><br /></div><div><br />Yes, your LIVE ID login will be mailed back to base. Given that your Windows LIVE ID could be associated with your IM account, your EMail, XBox Live and a bunch of other stuff this could be a Very Bad Thing(TM).<br /><br />One bright spot here is that the program is being distributed in pieces - that is, as a collection of files and images that need to be compiled once you've entered the EMail address you want the stolen logins sent to. Here's what the typical wannabe user will see immediately after downloading it:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/mobbkck6.html" onclick="window.open('http://blog.spywareguide.com/images/mobbkck6.html','popup','width=357,height=333,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/mobbkck6-thumb-300x279.png" alt="mobbkck6.png" class="mt-image-none" style="" width="300" height="279" /></a></span><br /></div><div>Click to Enlarge<br /><br />Hopefully this will result in lots of people creating absolutely unusable infection files, but it pays to be on your guard. NEVER, EVER run a "Block Checker" program because generally speaking a scam based on a scam is not a good thing to get tangled up in.<br /><br />We detect this file as <a href="http://www.spywareguide.com/spydet_77295_mob_blockcheck.html">Mob.Blockcheck</a>.<br /></div>]]>
        
    </content>
</entry>

</feed>
