<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Spyware Sucks : Security, Technology</title><link>http://msmvps.com/blogs/spywaresucks/archive/tags/Security/Technology/default.aspx</link><description>Tags: Security, Technology</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Press Release: Attorney General McKenna’s new laws go into effect Thursday</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/06/12/1634223.aspx</link><pubDate>Thu, 12 Jun 2008 00:25:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1634223</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1634223</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/06/12/1634223.aspx#comments</comments><description>&lt;p&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;The full press release is&amp;nbsp;below.&amp;nbsp; The&amp;nbsp;section most relevant to this blog is&amp;nbsp;the new laws related to spyware.&amp;nbsp;&amp;nbsp;A&amp;nbsp;change that I anticipate will have a great impact is that the new laws &lt;/span&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&amp;quot;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;strong&gt;&lt;em&gt;Create&lt;img src="http://msmvps.com/emoticons/emotion-56.gif" alt="Sleep" /&gt; liability for web hosting services who ignore violators’ use of their products&lt;/em&gt;&amp;quot;&lt;/strong&gt;.&amp;nbsp; I believe that this new law will encourage web hosting services to act quickly when malvertizement activity is reported to them.&amp;nbsp; Far too often web hosting services have responded to my complaints by saying that they are not responsible for what their clients are doing, or they say that all they can do is contact their client and tell them that there has been a complaint, or they don&amp;#39;t respond at all.&amp;nbsp; Now that web hosting services can be found to be directly liable for the activities of their clients, it is going to be harder to ignore or fob off our complaints.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;Here is the House Bill 2879 (the Bill related to changes to spyware laws):&lt;br /&gt;&lt;a class="" href="http://apps.leg.wa.gov/documents/billdocs/2007-08/Pdf/Bills/House%20Passed%20Legislature/2879-S.PL.pdf" target="_blank"&gt;http://apps.leg.wa.gov/documents/billdocs/2007-08/Pdf/Bills/House%20Passed%20Legislature/2879-S.PL.pdf&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;The important changes as&amp;nbsp;relate to malvertizings follow - the changes are bold and underlined, or struck through:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;The definition of &amp;quot;Transmit&amp;quot; has been changed to ensure that if a web hosting service &amp;quot;&lt;strong&gt;knows or reasonably should have known&lt;/strong&gt;&amp;quot; that the chapter is being violated, then that web hosting service is liable for violations under the chapter.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;em&gt;&amp;quot;Transmit&amp;quot; means to &lt;strong&gt;&lt;u&gt;knowingly, or with conscious avoidance of knowledge,&lt;/u&gt;&lt;/strong&gt; transfer, send, or make available computer software, or any component thereof, via the internet or any other medium, including local area networks of computers, other nonwire transmission, and disc or other data storage device.&amp;nbsp; &amp;quot;Transmit&amp;quot; does not include any action by a person providing:&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;em&gt;(a) The internet connection, telephone connection, or other means of transmission capability (&lt;strike&gt;(such as a compact disk or digital video disk)&lt;/strike&gt;) through which the software was made available;&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;em&gt;(b) The storage or hosting of the software program or a web page through which the software was made available, &lt;strong&gt;&lt;u&gt;unless the person providing the storage or hosting services knows or reasonably should know there is or will be a violation of this chapter, and participates in or ratifies the actions constituting the violation;&lt;/u&gt;&lt;/strong&gt;&amp;quot;&lt;/em&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;--------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;PRESS RELEASE:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;b&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;OLYMPIA&lt;/span&gt;&lt;/b&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt; – New laws requested by Attorney General Rob McKenna dealing with mortgage foreclosure schemes, identity theft, &lt;strong&gt;spyware&lt;/strong&gt; and third-party marketing of cell phone numbers will go into effect on Thursday.&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;em&gt;“These new laws address critical threats to consumers from the purveyors of modern frauds—from mortgage rescue schemes to identity theft and online spying” McKenna said. “Also beginning this week, consumers’ cell phone numbers will be protected from solicitors, since they can no longer be published without express consent. I want to thank legislators from both parties who helped pass these crucial protections.”&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;em&gt;The following laws go into effect on Thursday, June 12:&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;u&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;em&gt;Prohibiting third-party marketing of cell phone numbers&lt;/em&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;b&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;House Bill 2479&lt;/span&gt;&lt;/b&gt;&lt;font size="3" face="Times New Roman"&gt; &lt;/font&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;requires any person in the business of compiling, marketing or selling phone numbers for commercial purposes to obtain a consumer’s express opt-in consent before publishing his or her wireless phone number in a directory. A violation of the law is punishable by a fine of up to $50,000. The Attorney General may bring actions to enforce compliance and may notify first-time violators with a letter of warning.&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;u&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;em&gt;Mortgage Foreclosure Legislation&lt;/em&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;b&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;House Bill 2791&lt;/span&gt;&lt;/b&gt;&lt;font size="3" face="Times New Roman"&gt; &lt;/font&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;adds protections for homeowners from losing their homes in “mortgage rescue” scams by:&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:Symbol;"&gt;·&lt;/span&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;font size="3" face="Times New Roman"&gt; &lt;/font&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;Requiring a written contract with clearly disclosed terms be completed, signed and dated by the homeowner and the purchaser prior to the property’s transfer; &lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:Symbol;"&gt;·&lt;/span&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;font size="3" face="Times New Roman"&gt; &lt;/font&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;Providing the foreclosed homeowner the right to cancel the contract within five business days; &lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:Symbol;"&gt;·&lt;/span&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;font size="3" face="Times New Roman"&gt; &lt;/font&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;Requiring that the purchaser demonstrate that the foreclosed homeowner is able to meet the terms of the contract including making interest and lease payments and is capable of purchasing the property within the allowable period;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:Symbol;"&gt;·&lt;/span&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;font size="3" face="Times New Roman"&gt; &lt;/font&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;Requiring that the homeowner must receive at least 82 percent of the difference between the property’s fair market value and the underlying mortgage in the event of a sale to a third party.&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;em&gt;A violation of the law is a per se violation of the Consumer Protection Act, making the outcome of litigation against foreclosure rescue schemes substantially certain and resulting in broad deterrence.&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;u&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;em&gt;Identity Theft Legislation&lt;/em&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;b&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;Senate Bill 5878&lt;/span&gt;&lt;/b&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt; creates a statutory requirement for police to take reports from victims of the identity theft. &lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:Symbol;"&gt;·&lt;/span&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;font size="3" face="Times New Roman"&gt; &lt;/font&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;Victims have the option to file a report in their local jurisdiction or with the agency where the crime occurred. &lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:Symbol;"&gt;·&lt;/span&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;font size="3" face="Times New Roman"&gt; &lt;/font&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;Allows prosecutors to bring separate charges against an accused identity thief for each use of a particular piece of someone’s personal information. This bill reverses policy set in State v. Leyda (2006), where the Washington Supreme Court held that a defendant may only be charged once for use of someone else’s information even when that information is used in multiple locations multiple times.&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;b&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;House Bill 2637&lt;/span&gt;&lt;/b&gt;&lt;font size="3" face="Times New Roman"&gt; &lt;/font&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;allows records provided by out-of-state businesses to be authenticated by affidavit, rather than in person, in criminal cases. When properly served with a request for records, the recipient must provide the records within 20 business days and verify the authenticity by providing a signed affidavit, declaration or certification. This allows for the more effective prosecution of identity thieves.&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;u&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;em&gt;Shutting Down Spyware&lt;/em&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;b&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;House Bill 2879&lt;/span&gt;&lt;/b&gt;&lt;font size="3" face="Times New Roman"&gt; &lt;/font&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;remedies loopholes and weaknesses in the state’s Computer Spyware Statute by:&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:Symbol;"&gt;·&lt;/span&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;font size="3" face="Times New Roman"&gt; &lt;/font&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;Removing onerous requirements that hinder the ability to prove cases against violators; &lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:Symbol;"&gt;·&lt;/span&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;font size="3" face="Times New Roman"&gt; &lt;/font&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;&lt;strong&gt;Creates liability for web hosting services who ignore violators’ use of their products; &lt;/strong&gt;&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:Symbol;"&gt;·&lt;/span&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;font size="3" face="Times New Roman"&gt; &lt;/font&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;Adds violations for new forms of spyware; and &lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:Symbol;"&gt;·&lt;/span&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Courier New&amp;#39;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;font size="3" face="Times New Roman"&gt; &lt;/font&gt;&lt;span style="FONT-SIZE:10pt;FONT-FAMILY:&amp;#39;Arial&amp;#39;,&amp;#39;sans-serif&amp;#39;;"&gt;Clarifies the standards for proof of violations and the circumstances under which actions may be brought.&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1634223" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/safety+and+privacy+on+the+Internet/default.aspx">safety and privacy on the Internet</category></item><item><title>New SWF analysis tools - thanks to TeMerc for pointing this out</title><link>http://msmvps.com/blogs/spywaresucks/archive/2007/12/07/1383523.aspx</link><pubDate>Thu, 06 Dec 2007 23:58:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1383523</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1383523</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2007/12/07/1383523.aspx#comments</comments><description>&lt;p&gt;Yay, &lt;a class="" href="http://isc.sans.org/diary.html?storyid=3727&amp;amp;rss" target="_blank"&gt;a new tool&lt;/a&gt;.&amp;nbsp; Thank you &lt;a class="" href="http://temerc.com/" target="_blank"&gt;TeMerc&lt;/a&gt;, I owe you a drink of your choice when I am next in town...&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;a class="" href="http://isc.sans.org/diary.html?storyid=3727&amp;amp;rss" target="_blank"&gt;In light of a growing problem that has the potential to effectively place every internet user at risk, even when only visiting sites they would otherwise fully trust, there is at least a new tool available to assist the security researcher community with a means to better identify malicious SWF files.&amp;nbsp; The timing for this is excellent, as I have personally only learned of this tool just this morning.&amp;nbsp; This particular tool is the OWASP hosted project named &amp;#39;SWFIntruder&amp;#39;.&lt;/a&gt;&amp;quot;&lt;/p&gt;
&lt;p&gt;There is a *lot* going on right now with regards to malicious advertising - too much to write about now - but watch this space. There may be FUN times ahead (for us, that is,&amp;nbsp;not the purveyors of the malicious banner advertisements)&amp;nbsp;:o)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1383523" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities/default.aspx">Vulnerabilities</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/safety+and+privacy+on+the+Internet/default.aspx">safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/viruses+and+exploits/default.aspx">viruses and exploits</category></item><item><title>Breaking news: skyauction.com, unauthorised malicious advertisements, a fake letter of mandate.. oh my...</title><link>http://msmvps.com/blogs/spywaresucks/archive/2007/12/07/1383504.aspx</link><pubDate>Thu, 06 Dec 2007 23:15:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1383504</guid><dc:creator>sandi</dc:creator><slash:comments>3</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1383504</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2007/12/07/1383504.aspx#comments</comments><description>&lt;p&gt;My regular readers may recall &lt;a class="" href="http://msmvps.com/blogs/spywaresucks/archive/2007/12/05/1379077.aspx" target="_blank"&gt;my recent&amp;nbsp;article about emusic&amp;#39;s claim&lt;/a&gt; that various advertising networks (&lt;strong&gt;uniqueads.com&lt;/strong&gt;, &lt;strong&gt;adtraff.com&lt;/strong&gt; and&amp;nbsp;&lt;strong&gt;forceup.com&lt;/strong&gt;) were fraudulently claiming to represent emusic.&amp;nbsp; Said advertising networks were apparently selling unauthorised, malicious, advertisements touting emusic.com; advertisements that hijacked users in an attempt to spread malware.&lt;/p&gt;
&lt;p&gt;Well, I have received an email from the Chief Technology Officer at skyauction.com and he has quite a story to tell.&amp;nbsp; Here is a quote from his email - information shared with permission:&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;We were contacted by another company today that were duped into hosting one&amp;nbsp;of the fraudulent ads for a couple of days (which have since been taken down). It seems that the source of the ads is a company called &lt;strong&gt;NetMediaGroup&lt;/strong&gt; (&lt;strong&gt;http://www.netmediagroup.net&lt;/strong&gt;). They are claiming to represent us and even provided a fake letter of mandate&amp;quot; (which I can email you) to one of their targets saying that they represent us.&amp;nbsp; As with our logo, they were pretty sloppy creating this fake &amp;quot;mandate&amp;quot; because there are some obvious errors. In this case, someone with the pseudonym (one can only guess) of &amp;quot;Jim Burch&amp;quot; (jim@netmediagroup.net) contacted the site claiming to represent us and asking to put up ads on the contact&amp;#39;s site. The the ads go up and deliver the fake malcious Skyauction ads until someone complains and they are finally taken down. NetMediaGroup appears at first glance to be a real company, but they are probably a completely&lt;br /&gt;&amp;nbsp;fraudelent one. The domain name is registered to some organization in Germany, but the contact us phone number seems to be in the Netherlands. All of the names on the web site are just generic (i.e. they don&amp;#39;t give full names).&lt;/em&gt;&amp;quot;&lt;/p&gt;
&lt;p&gt;Here is a picture of the fake letter of mandate as sent to me by skyauction.com - click on the graphic to view a full size copy:&lt;/p&gt;
&lt;p&gt;&lt;a class="" href="http://msmvps.com/photos/spyware_sucks/images/1383462/original.aspx" target="_blank"&gt;&lt;img src="http://msmvps.com/photos/spyware_sucks/images/1383462/301x425.aspx" alt="" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Ok, so who are netmediagroup.net?&amp;nbsp; Let&amp;#39;s do a Whois search (copied below)&amp;nbsp;- hmm, note the email address burnads_c@yahoo.com.&amp;nbsp; Yep, that rings a bell - thinking back to the &lt;a class="" href="http://msmvps.com/blogs/spywaresucks/archive/2007/12/03/1376492.aspx" target="_blank"&gt;fake skyauction.com advertisement that hit soccernet.com&lt;/a&gt;, I remember that the name burnads appeared.&amp;nbsp; The referrer for performanceoptimizer was: &lt;strong&gt;burnads.com/swf/gnida.swf?campaign=flatfootup&amp;amp;u=23423424.&amp;nbsp;&lt;/strong&gt;That URL, when I just loaded it in my system, redirected me immediately to fraudware site.&lt;/p&gt;
&lt;p&gt;I think it is time to get in touch with the CTO of emusic and find out what *his* story is.&amp;nbsp; The CTO of skyauction and I both believe that the best way to fight the fraudsters is to expose their activities.&lt;/p&gt;
&lt;p&gt;Domain Name : netmediagroup.net&lt;br /&gt;&lt;br /&gt;::Registrant::&lt;br /&gt;Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Martin Such&lt;br /&gt;Email&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : burnads_c@yahoo.com&lt;br /&gt;Address&amp;nbsp;&amp;nbsp; : Debusweg 6-18,&amp;nbsp; Koenigstein - Falkenstein Frankfurt &lt;br /&gt;Zipcode&amp;nbsp;&amp;nbsp; : 61462&lt;br /&gt;Nation&amp;nbsp;&amp;nbsp;&amp;nbsp; : DE&lt;br /&gt;Tel&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : +49(0)4513456&lt;br /&gt;Fax&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : &lt;br /&gt;&lt;br /&gt;::Administrative Contact::&lt;br /&gt;Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Martin Such&lt;br /&gt;Email&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : burnads_c@yahoo.com&lt;br /&gt;Address&amp;nbsp;&amp;nbsp; : Debusweg 6-18,&amp;nbsp; Koenigstein - Falkenstein Frankfurt &lt;br /&gt;Zipcode&amp;nbsp;&amp;nbsp; : 61462&lt;br /&gt;Nation&amp;nbsp;&amp;nbsp;&amp;nbsp; : DE&lt;br /&gt;Tel&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : +49(0)4513456&lt;br /&gt;Fax&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : &lt;br /&gt;&lt;br /&gt;::Technical Contact::&lt;br /&gt;Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Martin Such&lt;br /&gt;Email&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : burnads_c@yahoo.com&lt;br /&gt;Address&amp;nbsp;&amp;nbsp; : Debusweg 6-18,&amp;nbsp; Koenigstein - Falkenstein Frankfurt &lt;br /&gt;Zipcode&amp;nbsp;&amp;nbsp; : 61462&lt;br /&gt;Nation&amp;nbsp;&amp;nbsp;&amp;nbsp; : DE&lt;br /&gt;Tel&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : +49(0)4513456&lt;br /&gt;Fax&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : &lt;br /&gt;&lt;br /&gt;::Name Servers::&lt;br /&gt;ns1.netmediagroup.net&lt;br /&gt;ns2.netmediagroup.net&lt;br /&gt;&lt;br /&gt;::Dates &amp;amp; Status::&lt;br /&gt;Created Date&amp;nbsp;&amp;nbsp; 2006-06-29 05:38:33 EDT&lt;br /&gt;Updated Date&amp;nbsp;&amp;nbsp; 2007-06-27 17:59:00 EDT&lt;br /&gt;Valid Date&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2008-06-29 05:38:33 EDT&lt;br /&gt;Status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACTIVE&lt;br /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1383504" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities/default.aspx">Vulnerabilities</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/safety+and+privacy+on+the+Internet/default.aspx">safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/viruses+and+exploits/default.aspx">viruses and exploits</category></item><item><title>Is this the beginning of the end for malicious SWF files?</title><link>http://msmvps.com/blogs/spywaresucks/archive/2007/12/07/1383460.aspx</link><pubDate>Thu, 06 Dec 2007 22:56:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1383460</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1383460</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2007/12/07/1383460.aspx#comments</comments><description>&lt;p&gt;Oh, I hope so.&amp;nbsp; Mind you, it&amp;#39;s going to take me quite a while to get my head around this 7 page document, and all of the extra pages referred to ... anybody want to give me a crash course, or explain to my readers what sort of difference this will make in the fight against malicious banner advertisements? ;o)&lt;/p&gt;
&lt;p&gt;Source: &lt;a class="" href="http://www.adobe.com/devnet/flashplayer/articles/fplayer9_security.html" target="_blank"&gt;http://www.adobe.com/devnet/flashplayer/articles/fplayer9_security.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;In 2003, Flash Player 7 software introduced a channel of client-server communication that was new to the web: direct cross-domain data loading, authorized by policy files. Before policy files, web content could only perform two-way communication with its own server, such as runtime configuration or transactions without page reloads. Policy files allowed servers to open up their data selectively to client content from other domains, or generally to content from anywhere. Since the introduction of policy files, domain boundaries have been less of a barrier for authors of rich Internet applications.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Like most new technologies, policy files weren&amp;#39;t perfect when they were first introduced. After four years, the Internet security community has found two undesirable situations (described later in this article) that can arise from the existence of policy files. The basic premise of policy files remains valid, and Flash developers can continue to rely on policy files just as they have since Flash 6. To address the new concerns, however, Adobe is specifying some stricter rules for the use of policy files. Additionally, there are a number of improvements that make policy files more useful and usable. We will try to explain the reasons for our changes clearly and simply.&lt;/em&gt;&amp;quot;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1383460" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities/default.aspx">Vulnerabilities</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/safety+and+privacy+on+the+Internet/default.aspx">safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/viruses+and+exploits/default.aspx">viruses and exploits</category></item><item><title>Not even my immediate family is safe from malware....</title><link>http://msmvps.com/blogs/spywaresucks/archive/2007/11/23/1349529.aspx</link><pubDate>Fri, 23 Nov 2007 12:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1349529</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1349529</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2007/11/23/1349529.aspx#comments</comments><description>&lt;p&gt;There&amp;#39;s my Dad, searching the net for an update to a particular specialist programme on his system; he finds what he wants, he downloads, he starts to install (we don&amp;#39;t know if he closed his Web browser first - I&amp;#39;m bettting not), he&amp;#39;s prompted to update *DirectX* and whammo, he&amp;#39;s hit with spyware.cyberlog-x.&lt;/p&gt;
&lt;p&gt;Unfortunately:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;div&gt;he doesn&amp;#39;t remember what the URL was that he downloaded the software from;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;he&amp;#39;s not sure&amp;nbsp;in what order various events occurred;&amp;nbsp;and &lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;IE&amp;#39;s history, just for today, has been deleted (an interesting symptom in and of itself)&amp;nbsp;- IE&amp;#39;s history record for previous days is intact.&amp;nbsp; &lt;/div&gt;&lt;/li&gt;&lt;/ol&gt;
&lt;p&gt;The affected system is an XPSP2 system and my Dad fell victim to a standard combination of circumstance; a nice dose of social engineering, being confronted by a dialogue box that mentioned a name that was familiar enough to not be too scary, and not paying close enough attention to what he was downloading, and just as importantly, where from.&lt;/p&gt;
&lt;p&gt;My father&amp;#39;s experience today, and our difficulties when trying to clarify exactly what happened and how&amp;nbsp;it happened, combined with other interactions I have seen between IT and computer users, reminds me that the average user really doesn&amp;#39;t &amp;quot;get it&amp;quot; when it comes to working with IT staff.&amp;nbsp; They are sometimes their own worst enemies; not paying attention, and not recording what is, for us, essential information and not interacting well with their IT support.&amp;nbsp; The&amp;nbsp;user mis-steps&amp;nbsp;that I see happening most often are:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;div&gt;The average user will not read the error message on the screen.&lt;br /&gt;&lt;br /&gt;There was the time a very grumpy person complained that somebody had changed his password, because he was sure he was putting it in correctly, but it kept failing.&amp;nbsp; It turned out that the true situation was that he was trying to unlock a locked screen and didn&amp;#39;t read the dialogue box that appeared after he entered his username and password which said (paraphrased) that &amp;quot;this&amp;nbsp;computer is locked, if you proceed the other logged on user&amp;#39;s programs will be shut down and they may lose data&amp;quot;.&amp;nbsp; Instead, he assumed it was an incorrect password dialog, hit enter (which triggered &amp;#39;cancel&amp;#39;), pressed ctrl/alt/del, tried again, didn&amp;#39;t read the message again, hit enter again, rinse/wash/repeat.&amp;nbsp; After 4 or so tries he came to me to complain, and a lot of frustration could have been saved if he had read the dialogue box and acknowledged the warning by clicking ok instead of cancel....&lt;br /&gt;&lt;br /&gt;And this guy had an admin account - don&amp;#39;t let him near a server... please...&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Practice patience.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;If the hourglass is spinning, it won&amp;#39;t do you any good at all to keep clicking; in fact, with some of the line of business applications that I support it will guarantee a crash.&amp;nbsp; Go and get yourself a tea, coffee, fruit juice or whatever and if the problem is still there when you get back, call IT and ask for advice.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;If the cursor turns into a hand, *single* click, don&amp;#39;t double click... again, I support some line of business applications that *will* crash if you double click instead of single click.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;If it doesn&amp;#39;t work the first time that you click, it won&amp;#39;t work if you click 2, 3, 5, 10 or 20 times.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Swearing at the computer won&amp;#39;t help - it can&amp;#39;t hear you.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Swearing and being angry when talking to IT&amp;nbsp;support won&amp;#39;t help either. Stress is bad for both of you.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Sometimes a simple reboot is all that is needed to stabilise your system, especially if you leave it running 24 hours a day.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;It is not a good idea to delay rebooting after installing security updates if prompted to do so&amp;nbsp;- to avoid weird problems and errors, please restart your computer when prompted, even if you&amp;#39;re really really really busy - it doesn&amp;#39;t take that long.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;&amp;quot;It&amp;#39;s been crashing for about a week, but I really need this report right now&amp;quot;.&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Please call IT support before it becomes an emergency.&amp;nbsp; We don&amp;#39;t have crystal balls... we don&amp;#39;t discover that you are having problems via some sort of mysterious osmosis, and if you&amp;#39;ve left things for a week before calling us we have somewhere between &amp;quot;nil and buckleys&amp;quot; chance of working out what went wrong and why.&amp;nbsp; Also, it is difficult for us to minimise the frustration you&amp;#39;re feeling if you only call us after you&amp;#39;ve been &amp;quot;putting up with it&amp;quot; for a week, and you&amp;#39;re now seriously pissed off and ready to throw your computer (and your IT support professional) out the nearest window.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;&amp;quot;There was&amp;nbsp;a weird message then it crashed&amp;quot;... &lt;br /&gt;&lt;br /&gt;&amp;quot;Ok, what was the message?&amp;quot; ... &amp;lt;&amp;lt;silence except for the sound of&amp;nbsp;crickets chirping in the darkness&amp;gt;&amp;gt; ... &amp;quot;I dunno.&amp;nbsp; I clicked on ok, and now nothing works&amp;quot;.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;If you experience a crash, stop what you are doing, read it and write it down, then call me.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;&amp;quot;I didn&amp;#39;t do anything!&amp;quot; .... sometimes, my friend, yes you jolly well did.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;If your thoughts immediately before clicking are anything like &amp;quot;maybe if I try this...&amp;quot;&amp;nbsp;or if you feel a desire to close your eyes and cross your fingers as you click, then don&amp;#39;t click.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;&amp;quot;It has never worked!!&amp;quot; .... Ok, we&amp;#39;re dealing with the crystal ball thing again, aren&amp;#39;t we...&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Please, don&amp;#39;t try to fix it yourself.&amp;nbsp; You may &amp;quot;know a bit about computers&amp;quot; but if your efforts change a simple fix into a complicated procedure or an &amp;quot;easier to reformat&amp;quot; situation, you won&amp;#39;t win any friends, especially if you call IT and say &amp;quot;It&amp;#39;s been crashing for about a week, but I really need this report right now&amp;quot;.&lt;/div&gt;&lt;/li&gt;&lt;/ol&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1349529" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities/default.aspx">Vulnerabilities</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/safety+and+privacy+on+the+Internet/default.aspx">safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/viruses+and+exploits/default.aspx">viruses and exploits</category></item><item><title>US-CERT alert - MAC OSX Leopard</title><link>http://msmvps.com/blogs/spywaresucks/archive/2007/11/06/1284229.aspx</link><pubDate>Mon, 05 Nov 2007 23:20:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1284229</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1284229</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2007/11/06/1284229.aspx#comments</comments><description>&lt;p&gt;&amp;quot;&lt;a class="" href="http://www.us-cert.gov/current/index.html#possible_faults_in_mac_os" target="_blank"&gt;US-CERT is aware of reports of possible flaws in the Application-Based Firewall in Mac OS X Leopard. According to these reports, users may be misinformed of the status of their firewall rule set, thus placing users with listening network services at an increased risk.&lt;/a&gt;&amp;quot;&lt;/p&gt;
&lt;p&gt;What *were* Apple thinking?&amp;nbsp; &amp;quot;Block all incoming connections&amp;quot; should do exactly that.&lt;/p&gt;
&lt;p&gt;&lt;a class="" href="http://www.heise-security.co.uk/articles/98120" target="_blank"&gt;Heise Security&lt;/a&gt; have a detailed analysis of the Leopard firewall&amp;#39;s protections, or more precisely lack thereof, and their verdict is:&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;The Mac OS X Leopard firewall failed every test. It is not activated by default and, even when activated, it does not behave as expected. Network connections to non-authorised services can still be established and even under the most restrictive setting, &amp;quot;Block all incoming connections,&amp;quot; it allows access to system services from the internet. Although the problems and peculiarities described here are not security vulnerabilities in the sense that they can be exploited to break into a Mac, Apple would be well advised to sort them out pronto.&lt;/em&gt;&amp;quot;&lt;/p&gt;
&lt;p&gt;Ok, so&amp;nbsp;the Leopard firewall is off by default, even if you had your firewall turned on before upgrading to Leopard; it doesn&amp;#39;t distinguish between network types (unlike Vista which allows you to set different security levels for different networks); it is application based (identifying programs via code signatures) and no longer&amp;nbsp;not port based, and&amp;nbsp;there are the reports of applications being unable to access the internet (Skype and World of Warcraft being two that come to mind).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1284229" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities/default.aspx">Vulnerabilities</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/safety+and+privacy+on+the+Internet/default.aspx">safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/viruses+and+exploits/default.aspx">viruses and exploits</category></item><item><title>More on the MAC malware</title><link>http://msmvps.com/blogs/spywaresucks/archive/2007/11/02/1277297.aspx</link><pubDate>Thu, 01 Nov 2007 23:03:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1277297</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1277297</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2007/11/02/1277297.aspx#comments</comments><description>&lt;p&gt;Word is starting to spread about the &lt;a class="" href="http://msmvps.com/blogs/spywaresucks/archive/2007/11/01/1276092.aspx" target="_blank"&gt;MAC targetting malware &amp;quot;MacCodec&amp;quot; aka OSX.RSPlug.A&lt;/a&gt;, but I admit to being concerned at some of the reactions that I am seeing.&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;&lt;a class="" href="http://www.itnews.com.au/News/NewsStory.aspx?story=64163" target="_blank"&gt;A spokesperson for Symantec suggested that Intego &amp;quot;has a tendency to over-hype things&lt;/a&gt;&lt;/em&gt;&amp;quot; - excuse me??&amp;nbsp; What an unhelpful statement by Symantec.&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;It&amp;#39;s not going to spread far because it prompts for the Administrator password&lt;/em&gt;&amp;quot; - ah, if only life were that simple, but reality is those &lt;a class="" href="http://en.wikipedia.org/wiki/Dancing_pigs" target="_blank"&gt;dancing pigs&lt;/a&gt; are just too darned tempting....&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;Practice safe browsing: lock-down your browser (instructions below), and only download from sites you trust and install programs that you download intentionally. If you are unsure whether a program is legitimate, you can check to see if that program is also available from a trusted download site like &lt;/em&gt;&lt;a href="http://www.macupdate.com/" target="_blank"&gt;&lt;em&gt;MacUpdate.com&lt;/em&gt;&lt;/a&gt;&lt;em&gt; or &lt;/em&gt;&lt;a href="http://www.versiontracker.com/" target="_blank"&gt;&lt;em&gt;VersionTracker.com&lt;/em&gt;&lt;/a&gt;&lt;em&gt; (not all legit programs are available on these sites, but they can serve as a good reality check).&lt;/em&gt;&amp;quot; (source: &lt;a href="http://www.smith.edu/its/technotes/?p=41"&gt;http://www.smith.edu/its/technotes/?p=41&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;My apologies in advance to the people at Smith College TechNotes -&amp;nbsp;this&amp;nbsp;isn&amp;#39;t personal, ok? Your article just happened to be high up in a Google search and contained the type of advice that I wanted to highlight.&lt;/p&gt;
&lt;p&gt;Ok, so let&amp;#39;s look at the above in segments... &lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;Practice safe browsing: lock down your computer (instructions below)&lt;/em&gt;&amp;quot; - locking down your computer does not protect you from social engineering attacks where you are tricked into running what you think is a safe file, a file that is seemingly required to complete whatever task it is that you are doing on the computer.&amp;nbsp; Locking down your computer only protects you from exploits&amp;nbsp;and&amp;nbsp;&amp;quot;drive by downloads&amp;quot;, neither of which apply to the MAC trojan under discussion.&lt;/p&gt;
&lt;p&gt;And, just what is &amp;quot;safe browsing&amp;quot; anyway?&amp;nbsp; The hacking of *legitimate* &amp;quot;safe&amp;quot; web sites is becoming commonplace.&amp;nbsp; I could tell you about some very big names that have&amp;nbsp;had their Web sites&amp;nbsp;hacked, or who have&amp;nbsp;involuntarily offered infected files&amp;nbsp;for download, or who have hosted malicious&amp;nbsp;Flash based banner advertisements&amp;nbsp;- names that you would never expect to be a danger.&amp;nbsp; The MAC world is going to have to become far more distrusting, and far more cynical, now that the bad guys are&amp;nbsp;targeting them.&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;Only download from sites you trust&lt;/em&gt;&amp;quot; - see the previous paragraph - and anyway, does anybody actually trust a porn site?&amp;nbsp; I don&amp;#39;t.&amp;nbsp; And what will happen when the bad guys start using less nefarious topics&amp;nbsp;such as, for example, a &amp;quot;how to stay safe on the internet&amp;quot; as the theme for their websites and malicious movies?&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;..and install programs that you download intentionally&lt;/em&gt;&amp;quot; - ok, but the user is expecting to view a video - he or she *wants* to view that video&amp;nbsp;and being prompted to install a codec is not unusual.&amp;nbsp; The trick (a fake codec) is a commonly used, and far too often successful, trick used in the Windows world.&amp;nbsp; In light of that reality, I&amp;#39;m not sure how this little snippet of advice helps in a situation like the MAC trojan.&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;if you are unsure whether a program is legitimate, you can check to see if that program is also available from a trusted download site...&lt;/em&gt;&amp;quot; - sorry, this ain&amp;#39;t gonna work unless you decide that if a product or codec&amp;nbsp;isn&amp;#39;t listed, you&amp;#39;re not going to run it AND that you will only download and run from said trusted site, AND it assumes that the site itself has not been compromised.&amp;nbsp; AND, what happens when the bad guys mimic the name of a well-known, trusted product?&amp;nbsp; In the Windows world, the bad guys often mimic the names of Windows system files, and well known software.&lt;/p&gt;
&lt;p&gt;And, in the end, users are lazy.&amp;nbsp; They&amp;#39;re not going to stop what they&amp;#39;re doing, write down the name of whatever it is they have found that wants to install, load another page so that they can view whatever download site and search for the file in question before deciding whether or not to enter their Administrator password.&lt;/p&gt;
&lt;p&gt;MacWorld&amp;#39;s article about the trojan is here:&lt;br /&gt;&lt;a href="http://www.macworld.com/2007/10/firstlooks/trojanhorse/index.php"&gt;http://www.macworld.com/2007/10/firstlooks/trojanhorse/index.php&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;So what does this all boil down to?&amp;nbsp; All of the above advice is good, traditional, advice and it would have been enough in the past&amp;nbsp;- but nowadays it is not a panacea and much of the advice is negated by social engineering attacks anyway.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1277297" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities/default.aspx">Vulnerabilities</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/safety+and+privacy+on+the+Internet/default.aspx">safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/viruses+and+exploits/default.aspx">viruses and exploits</category></item><item><title>MAC users are being targeted in a porn trojan social engineering attack</title><link>http://msmvps.com/blogs/spywaresucks/archive/2007/11/01/1276092.aspx</link><pubDate>Wed, 31 Oct 2007 23:27:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1276092</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1276092</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2007/11/01/1276092.aspx#comments</comments><description>&lt;p&gt;Source: &lt;a class="" href="http://www.theregister.co.uk/2007/10/31/in_the_wild_osx_trojan/" target="_blank"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.theregister.co.uk/2007/10/31/in_the_wild_osx_trojan/&lt;/u&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;font size="2"&gt;
&lt;p&gt;&amp;quot;&lt;em&gt;Miscreants have released a sophisticated Trojan into the wild that targets Mac users, according to Intego, a company that markets security software that runs on OS X.&lt;/em&gt;&lt;/p&gt;&lt;em&gt;The malicious Trojan, dubbed OSX.RSPlug.A, is making the rounds on several porn websites. When Mac users try to view some videos, the site feeds them a page that says QuickTime is unable to play the file unless a special codec is installed first. If the user proceeds, a form of DNSChanger is installed that hijacks some web requests sent to eBay, PayPal and some banking websites, according to this write-up &amp;lt;&lt;/em&gt;&lt;/font&gt;&lt;a class="" href="http://www.intego.com/news/ism0705.asp" target="_blank"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;&lt;em&gt;http://www.intego.com/news/ism0705.asp&lt;/em&gt;&lt;/u&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;&lt;em&gt;&amp;gt; from Intego.&lt;/em&gt;&lt;/font&gt;&lt;/font&gt;&lt;font size="2"&gt; 
&lt;p&gt;&lt;em&gt;&amp;quot;The noteworthy part is that someone is targeting the [Mac] OS,&amp;quot; said Randy Abrams, a security researcher at antivirus software provider Eset. &amp;quot;This may mean that the OS is beginning to gain enough users to be attractive to attackers.&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The Trojan installs a root crontrab that makes minute-by-minute queries to check that the doctored DNS server is still active. The websites offer different versions of the malware, most likely to tailor web spoofing to the victim&amp;#39;s particular country. There is no way for victims running 10.4 to see the changed DNS server in the OS X GUI. In 10.5, the DNS server is visible in the Advanced Network preferences, but the added servers are dimmed and can&amp;#39;t be removed manually.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Apple PR representatives didn&amp;#39;t respond to an email seeking comment for this story.&lt;/em&gt;&lt;/p&gt;&lt;em&gt;A barrage of spam posted to Mac forums invites readers to visit the malicious websites. The Trojan requires victims to enter the administrative password for their machine, a factor that is likely to mitigate the risk somewhat. Then again, Windows users have for years been tricked into installing malware &amp;lt;&lt;/em&gt;&lt;/font&gt;&lt;a class="" href="http://www.theregister.com/2007/10/19/return_of_trojan_bayrob/" target="_blank"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;&lt;em&gt;http://www.theregister.com/2007/10/19/return_of_trojan_bayrob/&lt;/em&gt;&lt;/u&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;&lt;em&gt;&amp;gt; that can wreak havoc on their PCs. We see no evidence that Mac users are any less resilient to social-engineering attacks.&lt;/em&gt;&amp;quot;&lt;/font&gt;&lt;/font&gt;&lt;font size="2"&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;/font&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1276092" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities/default.aspx">Vulnerabilities</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/safety+and+privacy+on+the+Internet/default.aspx">safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/viruses+and+exploits/default.aspx">viruses and exploits</category></item><item><title>An interesting article by my friend Mauricio, and a timely warning</title><link>http://msmvps.com/blogs/spywaresucks/archive/2007/08/17/1117802.aspx</link><pubDate>Fri, 17 Aug 2007 00:41:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1117802</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1117802</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2007/08/17/1117802.aspx#comments</comments><description>Operating System security is [only] as good as the admins http://www.geekzone.co.nz/freitasm/3578 &amp;quot;This last week, 5 of the 8 servers that are loco hosted but Canonical sponsored, had to be shut down due to reports that they were actively attacking...(&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2007/08/17/1117802.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1117802" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities/default.aspx">Vulnerabilities</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/safety+and+privacy+on+the+Internet/default.aspx">safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/viruses+and+exploits/default.aspx">viruses and exploits</category></item><item><title>Extremely disappointing - Trend Micro fails anti-malware test</title><link>http://msmvps.com/blogs/spywaresucks/archive/2007/08/06/1089373.aspx</link><pubDate>Mon, 06 Aug 2007 05:21:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1089373</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1089373</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2007/08/06/1089373.aspx#comments</comments><description>&lt;p&gt;&lt;em&gt;&amp;quot;All three of its software products report false positives in VB100 testing.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;All three of the anti-malware products submitted by Trend Micro for Virus Bulletin&amp;#39;s independent tests failed because they produced false positives.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Of the 20 products submitted for testing, six generated false positives when scanning a set of known clean files and failed to meet the requirements for VB100 certification.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&amp;quot;Trend Micro, one of the &amp;#39;big four&amp;#39; anti-malware companies, submitted no fewer than three of its anti-virus products, all of which falsely identified a Microsoft development tool as spyware,&amp;quot; said a statement from Virus Bulletin.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&amp;quot;Other products to generate false positives were FortiClient, Ikarus Utilities and VirusBuster.&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Source:&amp;nbsp; &lt;a class="" href="http://www.crn.com.au/story.aspx?CIID=88516&amp;amp;r=rss" target="_blank"&gt;http://www.crn.com.au/story.aspx?CIID=88516&amp;amp;r=rss&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Unfortunately there is no mention in the CRN article (or any of the other verbatim articles appearing on the various news sites) of what the &amp;quot;Microsoft development tool&amp;quot; was/is that triggered the false positive.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1089373" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities/default.aspx">Vulnerabilities</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/safety+and+privacy+on+the+Internet/default.aspx">safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/viruses+and+exploits/default.aspx">viruses and exploits</category></item></channel></rss>