<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Spyware Sucks : Technology</title><link>http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx</link><description>Tags: Technology</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Caught installing a skimming device….</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/12/03/1743433.aspx</link><pubDate>Thu, 03 Dec 2009 06:37:21 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1743433</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1743433</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/12/03/1743433.aspx#comments</comments><description>&lt;p&gt;If you have ever wondered how long it takes to install an ATM skimmer, check this movie out (yes the crook was caught red handed)&lt;/p&gt;  &lt;p&gt;&lt;a title="http://www.liveleak.com/view?i=074_1252777692" href="http://www.liveleak.com/view?i=074_1252777692" target="_blank"&gt;http://www.liveleak.com/view?i=074_1252777692&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1743433" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>The number one rule of technical support, which Symantec seems to have forgotten, is ***PAY ATTENTION***</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/06/16/1695601.aspx</link><pubDate>Tue, 16 Jun 2009 10:31:44 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1695601</guid><dc:creator>sandi</dc:creator><slash:comments>13</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1695601</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/06/16/1695601.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-right-width:0px;margin:10px 15px 15px 0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7848.image_5F00_062D6E81.png" width="482" height="302" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;I sent a request for technical support to Symantec today – I thought, foolishly it seemed, that it was clear, succinct, and to the point.&amp;#160; My message was:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;&lt;em&gt;Unable to download hotfix &lt;/em&gt;&lt;/strong&gt;&lt;a target="_blank"&gt;ftp://ftp.symantec.com/public/english_us_canada/hotfix/defutil/KB20080828105226EN.exe&lt;/a&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;strong&gt;&lt;em&gt; &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;Error when attempting download:&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;220 spftp/1.0.0000 Server [68.177.231.161]          &lt;br /&gt;501 Syntax incorrect           &lt;br /&gt;421 Service not available, closing control connection&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;I have been trying to download the hotfix for 48 hours.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;Norton error requiring hotfix: - &amp;quot;The virus definitions required by Norton Internet Security are not valid. You cannot run a scan until this problem is resolved.&amp;quot;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;The Norton systray icon is RED.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Symantec technical support sent me the following response:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;&lt;em&gt;“I understand from your message that you have installed Norton Internet Security (NIS) 2009 and you are encountering an error message Error: &amp;quot;(3038,100)&amp;quot; when you run a Full System Scan with your Norton 2009 product. &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;This issue may occur if the virus definitions are not up to date, In order to resolve this issue we need to update the virus definitions using Intelligent Updater and run Full System Scan. For step by step instructions, please click on&amp;#160; the link provided below: &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;Title: &amp;#39;Error: &amp;quot;(3038,100)&amp;quot; when you run a Full System Scan with your Norton 2009 product&amp;#39;          &lt;br /&gt;Document ID: 20081007220233EN           &lt;br /&gt;Web URL:           &lt;br /&gt;&lt;/em&gt;&lt;/strong&gt;&lt;a href="http://www.symantec.com/norton/support/kb/web_view.jsp?wv_type=public_web&amp;amp;ssfromlink=true&amp;amp;sprt_cid=8eafb964-d4eb-407c-a3ff-d8b5b42a18c0&amp;amp;seg=hho&amp;amp;ct=us&amp;amp;lg=en&amp;amp;docurl=20081007220233EN&amp;rdquo;" target="_blank"&gt;http://www.symantec.com/norton/support/kb/web_view.jsp?wv_type=public_web&amp;amp;ssfromlink=true&amp;amp;sprt_cid=8eafb964-d4eb-407c-a3ff-d8b5b42a18c0&amp;amp;seg=hho&amp;amp;ct=us&amp;amp;lg=en&amp;amp;docurl=20081007220233EN”&lt;/a&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The KB article I was referred to advises me to, and I quote…&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;&lt;em&gt;“Download the fix tool. &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;Save the file to the Windows desktop. &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;a target="_blank"&gt;ftp://ftp.symantec.com/public/english_us_canada/hotfix/defutil/KB20080828105226EN.exe&lt;/a&gt;&lt;/em&gt;&lt;/strong&gt;&lt;strong&gt;&lt;em&gt;”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;strong&gt;For pity’s sake, which of the very first 4 words in my technical support request, being “Unable to download hotfix”, is so difficult to understand???&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;BTW, you will see that I did not actually tell Symantec that the error on the system in question was 3038,100 – that little gem of information was taken from a slew of system data that was added to the bottom of my request by support by the NIS support interface itself, unbeknownst to me (damned if I can understand why they need to know if I have an optical drive installed, or what the local time is where I am).&amp;#160; The error being reported the affected system was actually 3035,2 (but it seems that that error requires the same fix as 3038,100, so we’ll let them off for that one).&lt;/p&gt;  &lt;p&gt;To save myself the grief that comes from beating my head against the brick wall that is Symantec technical support I sourced the hotfix via alternate means, ran the hotfix, rebooted TWICE and ran a Live Update.&amp;#160; Guess what… it actually WORKED.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;UPDATE&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;I had replied to Symantec, before I was able to source the hotfix by other means, and asked that they send the hotfix direct to me via email.&amp;#160; I was less than polite, I am afraid.&amp;#160; This is what I wrote:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;&lt;em&gt;The VERY FIRST SENTENCE IN MY TECHNICAL SUPPORT REQUEST IS: &amp;quot; Unable to download hotfix &lt;/em&gt;&lt;/strong&gt;&lt;a target="_blank"&gt;ftp://ftp.symantec.com/public/english_us_canada/hotfix/defutil/KB20080828105226EN.exe&lt;/a&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;strong&gt;&lt;em&gt;.&amp;#160; Let me repeat the error message in hopes that somebody will actually READ it this time. &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;Error when attempting download:         &lt;br /&gt;220 spftp/1.0.0000 Server [68.177.231.161]          &lt;br /&gt;501 Syntax incorrect          &lt;br /&gt;421 Service not available, closing control connection &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;&lt;em&gt;With that in mind, WHY ON EARTH WOULD YOU SEND ME TO A TECHNICAL SUPPORT DOCUMENT that tells me to download a hotfix when I have already told you that it won&amp;#39;t download???&amp;#160; Please send the fixes to me by email.         &lt;br /&gt;Also, PLEASE NOTE that the Norton Support Window refers me to the 3038,100 fix tool, BUT the NORTON PROGRAM ITSELF reports that the problem is 3035,2.&amp;#160; &amp;lt;--- PLEASE READ THAT VERY CAREFULLY - NORTON 360 IS ALSO REPORTING THE ERROR 3035,2.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;I have another email here.&amp;#160; This time Symantec Technical support wrote:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;em&gt;“I understand that you are getting an error message with error code &amp;quot;(3038,100)&amp;quot; when you run a Full System Scan with your Norton 2009 product and &lt;strong&gt;&lt;u&gt;you tried to download the fix tool and it failed with error code “220 spftp/1.0.0000 Server [68.177.231.161]”, “501 Syntax incorrect” and “421 Service not available, closing control connection&lt;/u&gt;&lt;/strong&gt;” (My emphasis)&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;I would like to inform you that this issue might occur might due to lack of latest virus definition updates or if the virus definitions are corrupted.&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;In order to resolve it, we need to update the virus definitions of Norton by running the fix tool and then restart the PC. After restarting the computer, a Help &amp;amp; Support window may open and you may still see the error. Please exit the Help &amp;amp; Support window, and then restart the computer again. It must resolve the issue.&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;For further assistance with the steps that need to be followed, please go through the following link.&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;Web URL:&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;&lt;a href="http://www.symantec.com/norton/support/kb/web_view.jsp?wv_type=public_web&amp;amp;ssfromlink=true&amp;amp;sprt_cid=8eafb964-d4eb-407c-a3ff-d8b5b42a18c0&amp;amp;seg=hho&amp;amp;ct=us&amp;amp;lg=en&amp;amp;docurl=20081007220233EN" target="_blank"&gt;http://www.symantec.com/norton/support/kb/web_view.jsp?wv_type=public_web&amp;amp;ssfromlink=true&amp;amp;sprt_cid=8eafb964-d4eb-407c-a3ff-d8b5b42a18c0&amp;amp;seg=hho&amp;amp;ct=us&amp;amp;lg=en&amp;amp;docurl=20081007220233EN&lt;/a&gt;&lt;/em&gt;&lt;em&gt;”&lt;/em&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The technician then continued on, telling me that if the hotfix did not work I would need to download the Norton Removal Tool.&lt;/p&gt;  &lt;p&gt;Yeah, I didn’t believe it either.&amp;#160; I was referred back to exactly the same URL even after they acknowledged that I was not able to download hotfixes.&amp;#160; My response began with:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;&lt;em&gt;“Forget it.&amp;#160; Please close this Technical Support Incident as &amp;quot;customer gave up&amp;quot;.”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1695601" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>News: lovesick hacker cripples Northern Territory Health Department, hospital, prison and Supreme Court servers?</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/03/13/1677824.aspx</link><pubDate>Fri, 13 Mar 2009 02:07:57 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1677824</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1677824</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/03/13/1677824.aspx#comments</comments><description>&lt;p&gt;For heavens sake … according to the news report at the URL below it took “130 experts” to “find the problem and fix it” – the “problem” was, apparently, the fact that the “hacker” (and I use that term very loosely) “deleted 10,475 user accounts”.&lt;/p&gt;  &lt;p&gt;The incident is explained as:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“&lt;em&gt;In submissions from his lawyer Tom Berkley and prosecutor Paul Usher yesterday, the court heard that McIntosh hacked into the system on his workmate&amp;#39;s computer, using her password. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;He was living with her in May, 2008, when he logged into government servers and deleted 10,475 user accounts from the Health Department, hospital, prison and Supreme Court servers.&lt;/em&gt;”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Who was this “workmate”?&amp;#160; And how the heck did he know her password? Especially a password for a user account that I can only assume had high level administrative credentials?&amp;#160; And how can such an unsubtle slash-and-burn attack need “130 experts” and a bill of $1,253,750 to fix?&lt;/p&gt;  &lt;p&gt;Cite: &lt;a title="http://www.ntnews.com.au/article/2009/03/13/38995_ntnews.html" href="http://www.ntnews.com.au/article/2009/03/13/38995_ntnews.html" target="_blank"&gt;http://www.ntnews.com.au/article/2009/03/13/38995_ntnews.html&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1677824" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>Heated toilet seats!</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/02/27/1674739.aspx</link><pubDate>Fri, 27 Feb 2009 15:32:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1674739</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1674739</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/02/27/1674739.aspx#comments</comments><description>&lt;p&gt;Yep, that is an enduring impression that I will take away from my visit to Google&amp;rsquo;s offices &amp;ndash; heated toilet seats; that and the slide from one floor to another that went down the stairwell&amp;nbsp; :o)&lt;/p&gt;
&lt;p&gt;I was very excited to have been offered the opportunity to visit Google while I was in town.&amp;nbsp; It was immediately obvious that Google&amp;rsquo;s offices have a completely different ambiance to Microsoft &amp;ndash; there was lots of open plan floor space, lots of spots of primary color, and fun names for meeting rooms &amp;ndash; it was much lighter and brighter than many of the buildings that I have visited at Redmond and the view was amazing (there was even one of those coin operated pedestal binoculars, but it didn&amp;rsquo;t require coins).&amp;nbsp; Sadly I didn&amp;rsquo;t dare to ask if I could take any pictures of the offices to share with my readers.&lt;/p&gt;
&lt;p&gt;To my hosts &amp;ndash; thank you!&amp;nbsp; It was time well spent and enjoyed, and I hope we get the opportunity to meet again some time in the not to distant future.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Edit: Yes, yes, I know... this posting is pure fluff but what can I say - I signed an NDA :-D&lt;/em&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1674739" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>Unhelpful error message….</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/01/26/1665966.aspx</link><pubDate>Mon, 26 Jan 2009 08:23:06 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1665966</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1665966</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/01/26/1665966.aspx#comments</comments><description>&lt;p&gt;&amp;#160;&lt;img style="border-bottom:0px;border-left:0px;margin:0px 25px 25px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_192343D1.png" width="237" height="229" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Uh, thanks for that (software name obscured to protect me from the not-so-innocent)&amp;#160; ;o)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1665966" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>Oh dear, oh dear, oh dear…</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/01/26/1665956.aspx</link><pubDate>Mon, 26 Jan 2009 06:08:16 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1665956</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1665956</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/01/26/1665956.aspx#comments</comments><description>&lt;p&gt;Its amazing what we find sometimes…&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;WARNING: I am assuming that my readers are smart enough to *NOT* visit the victim site, or the malicious URLs, without hefty protection in place, yes?&amp;#160; In fact, don’t go there at all unless you are willing to reformat your computer, potentially without being able to back up your data (yes, some nasties out there are killing the ability to copy data to USB and whatnot).&amp;#160; You have been warned!&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;I was taking a look at one of the recent SQL injection incidents the other day when I came across an interesting web site that had been affected (millerscitax.com).&amp;#160; Here is a screenshot of an obvious problem:-&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_048EA0A7.png" width="701" height="620" /&gt; &lt;/p&gt;  &lt;p&gt;If we click on a “Read More” link, we see the following:-&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_0280445D.png" width="817" height="450" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;So, anyway, being a good netizen ‘n’ all that, I decided to use the “Contact Us” page to warn the site owners that they had a problem (&lt;em&gt;it should be noted that the News page is not hyperlinked as far as I can see – you need to know that it is there, and guess the URL, to find it&lt;/em&gt;).&amp;#160; When I clicked on the “Submit” button on the “Contact Us” page, this is what I saw:-&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_189A73D0.png" width="813" height="310" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;lt;sigh&amp;gt;&amp;#160; You would think that that is bad enough, yes?&amp;#160; But, it gets even better (err, worse)… when we view the page source on the “Contact Us” page for the taxi site we find the following:&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_1B75BBAE.png" width="826" height="454" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;So, the next question is – why does the Millers City Taxis “Contact Us” page have code that references the gillibrand.co.uk web site?&amp;#160; A potential explanation may be found in the fact that the Registrant for millerscitax.com is “eBusiness UK Ltd” (&lt;em&gt;Capricorn House, Capricorn Park, Blakewater Road, Blackburn, Lancashire - 44.1254.279.998&lt;/em&gt;), and the fact that the “Web design” for gillibrand.co.uk is listed as having been completed by, you guessed it, &lt;a target="_blank" href="http://www.ebusinessuk.com/"&gt;eBusiness UK Ltd&lt;/a&gt; which lists its Lancashire address as &lt;em&gt;Capricorn House, Capricorn Park, Blackburn, Lancashire - 01254.279.998&lt;/em&gt;.&lt;/p&gt;  &lt;p&gt;Umm, oops.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_36D2C004.png" width="559" height="205" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_1FA9D637.png" width="639" height="256" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1665956" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>DIRECTI finally agree to act</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/01/22/1664762.aspx</link><pubDate>Thu, 22 Jan 2009 14:05:39 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1664762</guid><dc:creator>sandi</dc:creator><slash:comments>9</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1664762</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/01/22/1664762.aspx#comments</comments><description>&lt;p&gt;&amp;#160;&lt;img style="border-bottom:0px;border-left:0px;margin:0px 25px 25px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_3126DD9B.png" width="649" height="544" /&gt; &lt;/p&gt;  &lt;p&gt;I sent an email to DIRECTI on the same day that I wrote this blog post:   &lt;br /&gt;&lt;a title="http://msmvps.com/blogs/spywaresucks/archive/2009/01/21/1663955.aspx" target="_blank" href="http://msmvps.com/blogs/spywaresucks/archive/2009/01/21/1663955.aspx"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/01/21/1663955.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The email said, essentially, the same thing that I said in that blog post.&lt;/p&gt;  &lt;p&gt;As you can see, they have initiated a “whois inaccuracy complaint” against the domains quigley-simpson.net, hyundai-inc.com, mediavest-corp.com, posnerpromotion.com &amp;amp; singlesnet-inc.com.&lt;/p&gt;  &lt;p&gt;Frankly, they should have taken such steps immediately upon receiving the impersonation complaint but at least they say they have taken action now.&lt;/p&gt;  &lt;p&gt;It will be interesting to see what happens next, and how long it takes for something to happen.&lt;/p&gt;  &lt;p&gt;By the way, there is something screwy about the date and time of the email. See the screenshot which shows that the displayed sent date and time of the email above is in the future!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1664762" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>Spotting the bad guys…</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/01/19/1663247.aspx</link><pubDate>Mon, 19 Jan 2009 13:59:48 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1663247</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1663247</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/01/19/1663247.aspx#comments</comments><description>&lt;p&gt;It is very important to be familiar with the traits and suspicious behaviour/signs common to domains associated with malware, fraudware and malvertizing, affiliate misbehaviour and whatnot. By studying what the bad guys are doing, and how they do it, and the domains that they are using, we can build a dossier of features common to dangerous domains which can be built into our reputational assessments and other due diligence checks. &lt;/p&gt;  &lt;p&gt;By way of example, let&amp;#39;s take the example of a series of fraudware domains as highlighted by the PandaLabs blog:   &lt;br /&gt;&lt;a target="_blank" href="http://pandalabs.pandasecurity.com/archive/Rash-of-Rogue-Security-Malware.aspx"&gt;http://pandalabs.pandasecurity.com/archive/Rash-of-Rogue-Security-Malware.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;As we take a closer look at the domains it becomes clear that there a high likelihood of danger, not just because of the domains themselves (&lt;em&gt;my personal opinion is that any new domain names that can be used to infer antivirus, or antispyware, or scanning, or security or similar themes should immediately be flagged for closer examination by Registrars as a matter of course&lt;/em&gt;) but because the Registrant details are suspicious. What we see below is 24 domains that can be gathered into 7 distinct &amp;quot;groups&amp;quot;.&amp;#160; Nearly all of the domains are registered via the same Registrar, and are shared between six different Registrants.&amp;#160; There is also a lot of what I can best describe as &amp;quot;cross pollination&amp;quot; between the various &amp;quot;groups&amp;quot; and Registrants. &lt;/p&gt;  &lt;p&gt;I have sorted the 24 domains, using various criteria, to make it easier to see the “ties that bind” between the various Registrants and groups.&amp;#160; I see no reason why Registrars cannot implement similar checks and balances – checks that could be triggered by particular symptoms, such as a series of similar domains being registered, or when certain key words make up part of a domain name, or when “cross pollination” is detected via automated cross-checks.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Sorted by domain: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;best6scan.com&amp;#160; - REGTIME, for Robert Flork (flork.robert@gmail.com) - Rue de Limalsart 20, Brussel   &lt;br /&gt;bestscan6.com&amp;#160; - REGTIME, for Robert Flork (flork.robert@gmail.com) - Rue de Limalsart 20, Brussel &lt;/p&gt;  &lt;p&gt;The two “Robert Flork” registrations above seems innocuous from the perspective of WHOIS information and domain “group”, until we realise that the name and email address is used in association with other suspicious domains (below), which then leads us to wonder if the various names we see are nothing more than pseudonyms.&amp;#160; &lt;/p&gt;  &lt;p&gt;easy4scan.com&amp;#160; - REGTIME, for Michael Apenbrinck (subossink@gmail.com) - Slovenska Cesta 34, Ljubljana, SI   &lt;br /&gt;easy6scan.com&amp;#160; - REGTIME, for Alex Kitzmiller (alkitzmiller@gmail.com) - Zoutelaan 175, Knokke-Heist, BE    &lt;br /&gt;easyscan6.com&amp;#160; - REGTIME, for Alex Kitzmiller (alkitzmiller@gmail.com) - Zoutelaan 175, Knokke-Heist, BE &lt;/p&gt;  &lt;p&gt;fastscan4.com&amp;#160; - REGTIME, for Michael Apenbrinck (subossink@gmail.com) - Slovenska Cesta 34, Ljubljana, SI   &lt;br /&gt;fastscan6.com&amp;#160; - REGTIME, for Alex Kitzmiller (alkitzmiller@gmail.com) - Zoutelaan 175, Knokke-Heist, BE    &lt;br /&gt;fast4scan.com&amp;#160; - REGTIME, for Edmund Vandiver (qassadari@gmail.com) - Ljubljansua 6, Bled, SI &lt;/p&gt;  &lt;p&gt;livescan4.com&amp;#160; - REGTIME, for Edmund Vandiver (qassadari@gmail.com) - Ljubljansua 6, Bled, SI    &lt;br /&gt;livescan5.com&amp;#160; - REGTIME, for Ernest Lucas (wohuldah@gmail.com) - Vsehrdova 16, Praha    &lt;br /&gt;livescan6.com&amp;#160; - REGTIME, for Robert Flork (flork.robert@gmail.com) - Rue de Limalsart 20, Brussel &lt;/p&gt;  &lt;p&gt;newscan4.com&amp;#160;&amp;#160; - REGTIME, for Edmund Vandiver (qassadari@gmail.com) - Ljubljansua 6, Bled, SI   &lt;br /&gt;newscan5.com&amp;#160;&amp;#160; - UK2 GROUP LTD, for Jahn Bemis (jhbemis@gmail.com) - 1541 W Ninth Street, West Palm Beach, Florida    &lt;br /&gt;newscan6.com&amp;#160;&amp;#160; - REGTIME, for Robert Flork (flork.robert@gmail.com) - Rue de Limalsart 20, Brussel    &lt;br /&gt;new7scan.com&amp;#160;&amp;#160; - UK2 GROUP LTD, for Jahn Bemis (jhbemis@gmail.com) - 1541 W Ninth Street, West Palm Beach, Florida &lt;/p&gt;  &lt;p&gt;plus4scan.com&amp;#160; - REGTIME, for Michael Apenbrinck (subossink@gmail.com) - Slovenska Cesta 34, Ljubljana, SI   &lt;br /&gt;plus6scan.com&amp;#160; - REGTIME, for Alex Kitzmiller, (alkitzmiller@gmail.com) - Zoutelaan 175, Knokke-Heist, BE     &lt;br /&gt;plusscan4.com&amp;#160; - REGTIME, for Michael Apenbrinck (subossink@gmail.com) - Slovenska Cesta 34, Ljubljana, SI &lt;/p&gt;  &lt;p&gt;scan4easy.com&amp;#160; - REGTIME, for Edmund Vandiver (qassadari@gmail.com) - Ljubljansua 6, Bled, SI   &lt;br /&gt;scan4fast.com&amp;#160; - REGTIME, for Michael Apenbrinck (subossink@gmail.com) - Slovenska Cesta 34, Ljubljana, SI    &lt;br /&gt;scan5best.com&amp;#160; - REGTIME, for Ernest Lucas (wohuldah@gmail.com) - Vsehrdova 16, Praha    &lt;br /&gt;scan5plus.com&amp;#160; - REGTIME, for Ernest Lucas (wohuldah@gmail.com) - Vsehrdova 16, Praha    &lt;br /&gt;scan6live.com&amp;#160; - REGTIME, for Robert Flork (flork.robert@gmail.com) - Rue de Limalsart 20, Brussel    &lt;br /&gt;scan7live.com&amp;#160; - UK2 GROUP LTD, for Jahn Bemis (jhbemis@gmail.com) - 1541 W Ninth Street, West Palm Beach, Florida &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Sorted by Registrant: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;best6scan.com&amp;#160; - REGTIME, for Robert Flork (flork.robert@gmail.com) - Rue de Limalsart 20, Brussel   &lt;br /&gt;bestscan6.com&amp;#160; - REGTIME, for Robert Flork (flork.robert@gmail.com) - Rue de Limalsart 20, Brussel    &lt;br /&gt;livescan6.com&amp;#160; - REGTIME, for Robert Flork (flork.robert@gmail.com) - Rue de Limalsart 20, Brussel    &lt;br /&gt;scan6live.com&amp;#160; - REGTIME, for Robert Flork (flork.robert@gmail.com) - Rue de Limalsart 20, Brussel    &lt;br /&gt;newscan6.com&amp;#160;&amp;#160; - REGTIME, for Robert Flork (flork.robert@gmail.com) - Rue de Limalsart 20, Brussel &lt;/p&gt;  &lt;p&gt;easy4scan.com&amp;#160; - REGTIME, for Michael Apenbrinck (subossink@gmail.com) - Slovenska Cesta 34, Ljubljana, SI   &lt;br /&gt;fastscan4.com&amp;#160; - REGTIME, for Michael Apenbrinck (subossink@gmail.com) - Slovenska Cesta 34, Ljubljana, SI    &lt;br /&gt;plus4scan.com&amp;#160; - REGTIME, for Michael Apenbrinck (subossink@gmail.com) - Slovenska Cesta 34, Ljubljana, SI     &lt;br /&gt;plusscan4.com&amp;#160; - REGTIME, for Michael Apenbrinck (subossink@gmail.com) - Slovenska Cesta 34, Ljubljana, SI    &lt;br /&gt;scan4fast.com&amp;#160; - REGTIME, for Michael Apenbrinck (subossink@gmail.com) - Slovenska Cesta 34, Ljubljana, SI &lt;/p&gt;  &lt;p&gt;easy6scan.com&amp;#160; - REGTIME, for Alex Kitzmiller (alkitzmiller@gmail.com) - Zoutelaan 175, Knokke-Heist, BE   &lt;br /&gt;easyscan6.com&amp;#160; - REGTIME, for Alex Kitzmiller (alkitzmiller@gmail.com) - Zoutelaan 175, Knokke-Heist, BE    &lt;br /&gt;fastscan6.com&amp;#160; - REGTIME, for Alex Kitzmiller (alkitzmiller@gmail.com) - Zoutelaan 175, Knokke-Heist, BE    &lt;br /&gt;plus6scan.com&amp;#160; - REGTIME, for Alex Kitzmiller (alkitzmiller@gmail.com) - Zoutelaan 175, Knokke-Heist, BE &lt;/p&gt;  &lt;p&gt;fast4scan.com&amp;#160; - REGTIME, for Edmund Vandiver (qassadari@gmail.com) - Ljubljansua 6, Bled, SI   &lt;br /&gt;livescan4.com&amp;#160; - REGTIME, for Edmund Vandiver (qassadari@gmail.com) - Ljubljansua 6, Bled, SI     &lt;br /&gt;newscan4.com&amp;#160;&amp;#160; - REGTIME, for Edmund Vandiver (qassadari@gmail.com) - Ljubljansua 6, Bled, SI    &lt;br /&gt;scan4easy.com&amp;#160; - REGTIME, for Edmund Vandiver (qassadari@gmail.com) - Ljubljansua 6, Bled, SI &lt;/p&gt;  &lt;p&gt;livescan5.com&amp;#160; - REGTIME, for Ernest Lucas (wohuldah@gmail.com) - Vsehrdova 16, Praha   &lt;br /&gt;scan5best.com&amp;#160; - REGTIME, for Ernest Lucas (wohuldah@gmail.com) - Vsehrdova 16, Praha     &lt;br /&gt;scan5plus.com&amp;#160; - REGTIME, for Ernest Lucas (wohuldah@gmail.com) - Vsehrdova 16, Praha &lt;/p&gt;  &lt;p&gt;newscan5.com&amp;#160;&amp;#160; - UK2 GROUP LTD, for Jahn Bemis (jhbemis@gmail.com) - 1541 W Ninth Street, West Palm Beach, Florida   &lt;br /&gt;new7scan.com&amp;#160;&amp;#160; - UK2 GROUP LTD, for Jahn Bemis (jhbemis@gmail.com) - 1541 W Ninth Street, West Palm Beach, Florida    &lt;br /&gt;scan7live.com&amp;#160; - UK2 GROUP LTD, for Jahn Bemis (jhbemis@gmail.com) - 1541 W Ninth Street, West Palm Beach, Florida &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Sorted by IP: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;best6scan.com&amp;#160; - REGTIME, for Robert Flork (flork.robert@gmail.com) - Rue de Limalsart 20, Brussel&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; (66.101.58.54)   &lt;br /&gt;newscan6.com&amp;#160;&amp;#160; - REGTIME, for Robert Flork (flork.robert@gmail.com) - Rue de Limalsart 20, Brussel&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; (66.101.58.54)    &lt;br /&gt;scan6live.com&amp;#160; - REGTIME, for Robert Flork (flork.robert@gmail.com) - Rue de Limalsart 20, Brussel&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; (66.101.58.54) &lt;/p&gt;  &lt;p&gt;easy4scan.com&amp;#160; - REGTIME, for Michael Apenbrinck (subossink@gmail.com) - Slovenska Cesta 34, Ljubljana, SI&amp;#160; (194.165.4.41)   &lt;br /&gt;fastscan4.com&amp;#160; - REGTIME, for Michael Apenbrinck (subossink@gmail.com) - Slovenska Cesta 34, Ljubljana, SI&amp;#160; (194.165.4.41)    &lt;br /&gt;fast4scan.com&amp;#160; - REGTIME, for Edmund Vandiver (qassadari@gmail.com) - Ljubljansua 6, Bled, SI&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; (194.165.4.41)    &lt;br /&gt;livescan4.com&amp;#160; - REGTIME, for Edmund Vandiver (qassadari@gmail.com) - Ljubljansua 6, Bled, SI&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; (194.165.4.41)    &lt;br /&gt;plus4scan.com&amp;#160; - REGTIME, for Michael Apenbrinck (subossink@gmail.com) - Slovenska Cesta 34, Ljubljana, SI (194.165.4.41)    &lt;br /&gt;plusscan4.com&amp;#160; - REGTIME, for Michael Apenbrinck (subossink@gmail.com) - Slovenska Cesta 34, Ljubljana, SI (194.165.4.41)    &lt;br /&gt;scan4easy.com&amp;#160; - REGTIME, for Edmund Vandiver (qassadari@gmail.com) - Ljubljansua 6, Bled, SI&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; (194.165.4.41)    &lt;br /&gt;scan4fast.com&amp;#160; - REGTIME, for Michael Apenbrinck (subossink@gmail.com) - Slovenska Cesta 34, Ljubljana, SI (194.165.4.41) &lt;/p&gt;  &lt;p&gt;livescan5.com&amp;#160; - REGTIME, for Ernest Lucas (wohuldah@gmail.com) - Vsehrdova 16, Praha&amp;#160;&amp;#160; (69.10.52.12)   &lt;br /&gt;scan5best.com&amp;#160; - REGTIME, for Ernest Lucas (wohuldah@gmail.com) - Vsehrdova 16, Praha (69.10.52.12)    &lt;br /&gt;scan5plus.com&amp;#160; - REGTIME, for Ernest Lucas (wohuldah@gmail.com) - Vsehrdova 16, Praha&amp;#160; (69.10.52.12) &lt;/p&gt;  &lt;p&gt;newscan4.com&amp;#160;&amp;#160; - REGTIME, for Edmund Vandiver (qassadari@gmail.com) - Ljubljansua 6, Bled, SI&amp;#160;&amp;#160; (78.159.99.66) &lt;/p&gt;  &lt;p&gt;bestscan6.com&amp;#160; - REGTIME, for Robert Flork (flork.robert@gmail.com) - Rue de Limalsart 20, Brussel   &lt;br /&gt;easy6scan.com&amp;#160; - REGTIME, for Alex Kitzmiller (alkitzmiller@gmail.com) - Zoutelaan 175, Knokke-Heist, BE    &lt;br /&gt;easyscan6.com&amp;#160; - REGTIME, for Alex Kitzmiller (alkitzmiller@gmail.com) - Zoutelaan 175, Knokke-Heist, BE    &lt;br /&gt;fastscan6.com&amp;#160; - REGTIME, for Alex Kitzmiller (alkitzmiller@gmail.com) - Zoutelaan 175, Knokke-Heist, BE    &lt;br /&gt;livescan6.com&amp;#160; - REGTIME, for Robert Flork (flork.robert@gmail.com) - Rue de Limalsart 20, Brussel    &lt;br /&gt;newscan5.com&amp;#160;&amp;#160; - UK2 GROUP LTD, for Jahn Bemis (jhbemis@gmail.com) - 1541 W Ninth Street, West Palm Beach, Florida    &lt;br /&gt;new7scan.com&amp;#160;&amp;#160; - UK2 GROUP LTD, for Jahn Bemis (jhbemis@gmail.com) - 1541 W Ninth Street, West Palm Beach, Florida    &lt;br /&gt;plus6scan.com&amp;#160; - REGTIME, for Alex Kitzmiller, (alkitzmiller@gmail.com) - Zoutelaan 175, Knokke-Heist, BE     &lt;br /&gt;scan7live.com&amp;#160; - UK2 GROUP LTD, for Jahn Bemis (jhbemis@gmail.com) - 1541 W Ninth Street, West Palm Beach, Florida &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;These last few domains highlighted by PandaLabs exhibit identical Registrants and (for the most part) different IP addresses (by the way, I would look askance at WHOIS which records a USA street address but a Russian email address): &lt;/p&gt;  &lt;p&gt;best2008-scan-av.com&amp;#160; - REGTIME, for Rui Harvey (harvdavis@yandex.ru) - 1248 Pinchelone Street, Herndon, VA&amp;#160; (64.27.1.203)   &lt;br /&gt;av-pcscan-comp.com&amp;#160;&amp;#160; - REGTIME, for Rui Harvey (harvdavis@yandex.ru) - 1248 Pinchelone Street, Herndon, VA&amp;#160;&amp;#160; (216.240.149.159)    &lt;br /&gt;forpc-av-scanner.net&amp;#160; - REGTIME, for Rui Harvey (harvdavis@yandex.ru) - 1248 Pinchelone Street, Herndon, VA&amp;#160; (216.240.149.159)    &lt;br /&gt;best-scanner-pc.net&amp;#160; - REGTIME, for Rui Harvey (harvdavis@yandex.ru) - 1248 Pinchelone Street, Herndon, VA&amp;#160;&amp;#160; (64.27.18.54)    &lt;br /&gt;quickly-scan-no-av.com - REGTIME, for Rui Harvey (harvdavis@yandex.ru) - 1248 Pinchelone Street, Herndon, VA (64.27.18.54) &lt;/p&gt;  &lt;p&gt;sg10scanner.com - REGTIME, for Kire Serona (kiresl1540@yahoo.com) - Ilichova 16, Ljubljana, Ljubljana, SI (78.26.179.253)   &lt;br /&gt;sg11scanner.com - REGTIME, for Kire Serona (kiresl1540@yahoo.com) - Ilichova 16, Ljubljana, Ljubljana, SI (94.247.2.39)    &lt;br /&gt;sg12scanner.com - REGTIME, for Kire Serona (kiresl1540@yahoo.com) - Ilichova 16, Ljubljana, Ljubljana, SI &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;Who are REGTIME, and UK2 GROUP? &lt;/p&gt;  &lt;p&gt;UK2 Group Ltd, Suite 2C, Eurolife Building 1, Corral Road, Gibraltar &lt;/p&gt;  &lt;p&gt;Regtime Ltd, 1 Krasnoarmeyskaya Street, Samara, Russian Rederation &lt;/p&gt;  &lt;p&gt;&amp;quot;&lt;em&gt;Regtime Ltd was the first Russian ICANN-accredited registrar to offer a full service of cyrillic domains to Russian companies and individuals. Russian is the native or second language for more than 230 million people, so the decision to launch cyrillic language domains in 2001 was an important stage in the ability of Russian-speakers to access the Internet and the World Wide Web. Regtime continues to play a key role in the development of the Internet in Russia, including its work with the Cyrillic Languages Internet Names Consortium (CLINC).&lt;/em&gt;&amp;quot; &lt;/p&gt;  &lt;p&gt;CITE: &lt;a target="_blank" href="http://www.nic.aero/news/2008-06-30-03"&gt;http://www.nic.aero/news/2008-06-30-03&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1663247" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>Advertising in RSS feeds</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/01/14/1661550.aspx</link><pubDate>Wed, 14 Jan 2009 08:11:11 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1661550</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1661550</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/01/14/1661550.aspx#comments</comments><description>&lt;p&gt;I really don’t like advertising in my RSS feeds – especially silly advertisements like this one:&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_2C26D13F.png" width="430" height="552" /&gt;&lt;/p&gt;  &lt;p&gt;The screenshot above is of &lt;a target="_blank" href="http://scobleizer.wordpress.com/feed/"&gt;Robert Scoble’s RSS feed&lt;/a&gt;.&amp;#160; I have to say, in all honesty, that such advertising simply lowers the perceived tone and quality of a blog.&amp;#160; And, its all downhill from there – clicking on the advert takes us to this (oh well, at least it wasn’t one of those irritating “fun” sites that won’t let you close the page without jumping through dialogue hoops):&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_6A479E03.png" width="359" height="245" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Don’t feel too bad Rob – &lt;a target="_blank" href="http://www.stillsecureafteralltheseyears.com/ashimmy/atom.xml"&gt;StillSecure&lt;/a&gt; were showing the same advert:&lt;/p&gt;  &lt;p&gt;&lt;img style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_44740851.png" width="537" height="272" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;For those of you who really want/need to pollute your feeds with advertising (personally, I hope that you don’t succumb to the temptation), please remember that there are more discreet advertising styles around the place – take &lt;a target="_blank" href="http://db.tidbits.com/feeds/tidbits.rss"&gt;TidBITS&lt;/a&gt; for example – their advertisements are discreet, relevant to the theme of the blog, and they maintain an aura of professionalism:&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_6759EB63.png" width="432" height="245" /&gt; &lt;/p&gt;  &lt;p&gt;This one is teetering on the edge of irritating, from the &lt;a target="_blank" href="http://syndication.thedailywtf.com/TheDailyWtf"&gt;The Daily WTF blog&lt;/a&gt;.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_365CCB67.png" width="498" height="242" /&gt; &lt;/p&gt;  &lt;p&gt;A big benefit of RSS, for me, has been the fact that it was advertising free for a long time.&amp;#160; It is sad that that benefit is being eroded away.&amp;#160; Oh well, at least the darned things aren’t Flash adverts.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1661550" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>Lawyers given permission to serve debtors with default judgement through Facebook</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/12/16/1656821.aspx</link><pubDate>Tue, 16 Dec 2008 03:13:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1656821</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1656821</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/12/16/1656821.aspx#comments</comments><description>&lt;p&gt;&amp;quot;&lt;em&gt;TWO friends who defaulted on a six-figure loan are about to find out through their Facebook page a mortgage lender&amp;#39;s lawyers are on their trail. In an Australian and possibly world first, two lawyers have won a court order to allow them to serve a default judgment through Facebook. After failing to serve the court documents personally, lawyers Mark McCormack and Jason Oliver tracked down the debtors&amp;#39; Facebook page.&amp;nbsp; They were granted permission in the ACT Supreme Court to serve the default judgment through a Facebook email to the debtors.&lt;/em&gt;&amp;quot; &lt;p&gt;Cite: &lt;a title="http://www.news.com.au/technology/story/0,28348,24806438-5014239,00.html" target="_blank" href="http://www.news.com.au/technology/story/0,28348,24806438-5014239,00.html"&gt;http://www.news.com.au/technology/story/0,28348,24806438-5014239,00.html&lt;/a&gt;&lt;/p&gt; &lt;p&gt;There is more detail about the events that led up to the decision at this URL: &lt;br /&gt;&lt;a target="_blank" href="http://www.canberratimes.com.au/news/local/news/general/youve-been-served-court-approves-facebook-notice/1387146.aspx"&gt;http://www.canberratimes.com.au/news/local/news/general/youve-been-served-court-approves-facebook-notice/1387146.aspx&lt;/a&gt; &lt;ul&gt; &lt;li&gt;The Defendants are Carmel Rita Corbo and Gordon Kingsley Maxwell Poyser. &lt;/li&gt; &lt;li&gt;The couple failed to appear in court to defend the action by lending company MKM Capital. &lt;/li&gt; &lt;li&gt;Private investigators were hired, and an advertisement was placed in The Canberra Times. &lt;/li&gt; &lt;li&gt;11 attempts were made to serve the couple at their Wyselaskie Circuit home between November 8 and December 6. &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Its not the first time unusual steps have been used to achieve service in a legal case. Take the case of Sonny Bill Williams. &lt;blockquote&gt; &lt;p&gt;&amp;quot;&lt;em&gt;Earlier this year, lawyers acting for the Bulldogs NRL club served player Sonny Bill Williams with a subpoena via SMS text message.&amp;nbsp; &lt;/em&gt;&lt;em&gt;Williams was in Europe after defecting to French rugby club Toulon.&lt;/em&gt;&amp;quot; &lt;br /&gt;Cite:&amp;nbsp; &lt;a target="_blank" href="http://news.smh.com.au/national/facebook-used-to-track-down-debtors-20081216-6zgt.html"&gt;http://news.smh.com.au/national/facebook-used-to-track-down-debtors-20081216-6zgt.html&lt;/a&gt; &lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;Back in the late 1980&amp;#39;s/early 1990&amp;#39;s I worked in the field of debt recovery and bankruptcy, including during the &amp;quot;recession we had to have&amp;quot; (according to Australia&amp;#39;s then treasurer) and the time of amazingly high interest rates that sent so many people to the wall (I can remember standing in my bank, and looking at an poster offering an interest rate of 11% to those people lucky enough to be able to save money during those difficult times).&amp;nbsp; I have seen how clever debtors (and especially what we call &amp;quot;professional debtors&amp;quot;) can be when they are determined to evade service of documents.&amp;nbsp; I for one am pleased at this new development. &lt;p&gt;I would be interested to hear if anybody knows of an occasion when Facebook or any other social networking site was used to achieve service of legal documentation. &lt;p&gt;More coverage about the Facebook decision:&lt;br /&gt;&lt;a title="http://news.google.com/news?hl=en&amp;amp;ie=UTF-8&amp;amp;tab=wn&amp;amp;as_drrb=q&amp;amp;as_qdr=d&amp;amp;as_mind=14&amp;amp;as_minm=12&amp;amp;as_maxd=15&amp;amp;as_maxm=12&amp;amp;ncl=1280569682" target="_blank" href="http://news.google.com/news?hl=en&amp;amp;ie=UTF-8&amp;amp;tab=wn&amp;amp;as_drrb=q&amp;amp;as_qdr=d&amp;amp;as_mind=14&amp;amp;as_minm=12&amp;amp;as_maxd=15&amp;amp;as_maxm=12&amp;amp;ncl=1280569682"&gt;http://news.google.com/news?hl=en&amp;amp;ie=UTF-8&amp;amp;tab=wn&amp;amp;as_drrb=q&amp;amp;as_qdr=d&amp;amp;as_mind=14&amp;amp;as_minm=12&amp;amp;as_maxd=15&amp;amp;as_maxm=12&amp;amp;ncl=1280569682&lt;/a&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1656821" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>Me.dium is no more...</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/12/02/1655525.aspx</link><pubDate>Tue, 02 Dec 2008 03:55:46 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1655525</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1655525</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/12/02/1655525.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:0px 25px 25px 0px;border-top:0px;border-right:0px;" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.Me.diumisnomore_5F00_A6AA/image_5F00_153671ea_2D00_fa2e_2D00_4597_2D00_80ab_2D00_5dbb844bb406.png" width="224" height="366" /&gt; &lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;Me.dium was replaced by something called OneRiot on the 11th of November and the Me.dium social map that I liked so much is no more.&amp;nbsp; So now I have to go through my web sites and remove all of the defunct Me.dium code and track down what will happen to Me.dium accounts.&lt;/p&gt; &lt;p&gt;According to &lt;a target="_blank" href="http://getsatisfaction.com/oneriot/topics/what_happened_to_my_me_dium_account?utm_medium=widget&amp;amp;utm_source=widget_oneriot"&gt;Jennifer Lauren&lt;/a&gt;, Me.dium data &amp;quot;&lt;em&gt;is no longer active and is contained in offline backup files that are not connected to OneRiot in anyway [sic].&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;p&gt;If you want your data and your Me.dium account to be deleted, you are going to have to send Jennifer an email. &lt;p&gt;Note the reviews at the FF add-on site since Me.dium disappeared - there have only been a few reviews posted since the change, and they are all negative:&lt;br /&gt;&lt;a target="_blank" href="https://addons.mozilla.org/en-US/firefox/addon/4365#reviews"&gt;https://addons.mozilla.org/en-US/firefox/addon/4365#reviews&lt;/a&gt; &lt;p&gt;I tend to agree with commentator who says that all of the positive reviews that are reviews of the Me.dium application should be deleted (or OneRiot should have its own download page).&amp;nbsp; Weekly and total download counts should also be reset to zero as at 11 November 2008. &lt;p&gt;Will I be installing OneRiot?&amp;nbsp;&amp;nbsp; Well, I won&amp;#39;t be installing the toolbars or the Pulse Checker.&amp;nbsp; I&amp;#39;ll only install the Search Provider (which adds OneRiot to Internet Explorer&amp;#39;s built in search box) because I can see a potential research benefit if OneRiot&amp;#39;s promised ability to feature the most popular results makes it easier to find the most current content and conversations out on the net (the biggest problem with Google and other search engines is sorting the recent from the old, and the noise and spam from the useful conversations).&amp;nbsp; But, that being said, a lot of the stuff that I work on is really obscure.&amp;nbsp; I wouldn&amp;#39;t be doing my job well if I end up simply following a crowd - that&amp;#39;s not the way to stay on the cutting edge. &lt;p&gt;I&amp;#39;ve gotta say, too, that I&amp;#39;m going to really miss the social map. &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1655525" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>PRESS RELEASE: "Mirror image" web site leads to a $10,000.00 fine - penalty suspended</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/12/02/1655513.aspx</link><pubDate>Mon, 01 Dec 2008 23:59:01 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1655513</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1655513</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/12/02/1655513.aspx#comments</comments><description>&lt;p&gt;&lt;em&gt;The Washington Attorney General’s Office says a Pinole, Calif., man’s mirror-image version of Russell Investments’ site violated the state’s anti-phishing law.&lt;/em&gt; &lt;p&gt;&lt;em&gt;Rommel Balingit was ordered to pay $10,000 civil penalty under an &lt;/em&gt;&lt;a target="_blank" href="http://atg.wa.gov/uploadedFiles/Home/News/Press_Releases/2008/Balingit%20AOD%2011-08.pdf"&gt;&lt;em&gt;agreement&lt;/em&gt;&lt;/a&gt;&lt;em&gt; filed in November in Thurston County Superior Court. The penalty is suspended provided he complies with the agreement terms.&lt;/em&gt; &lt;p&gt;&lt;em&gt;Assistant Attorney General Katherine Tassi said that Russell, a global financial services company headquartered in Tacoma, alerted the Attorney General’s Office to a lookalike site that resembled the company’s own site.&lt;/em&gt; &lt;p&gt;&lt;em&gt; “The real Russell did stand up,” Tassi said. “And helped make sure the phony site was shut down.”&lt;/em&gt; &lt;p&gt;&lt;em&gt;An investigation by the Consumer Protection High-Tech Unit led to Balingit. &lt;/em&gt; &lt;p&gt;&lt;em&gt;Balingit claimed he built the Web site as a model to solicit clients to his now-defunct Web site design company, Tassi said. &lt;/em&gt; &lt;p&gt;&lt;a target="_blank" href="http://atg.wa.gov/uploadedFiles/Home/News/Press_Releases/2008/Balingit%20AOD%2011-08.pdf"&gt;&lt;em&gt;Balingit Assurance of Discontinuance&lt;/em&gt;&lt;/a&gt; &lt;p&gt;&amp;nbsp; &lt;p&gt;The WHOIS details for the domain that triggered the Attorney General&amp;#39;s action, russellassets.com, were originally hidden behind the privacy protection service supplied by domainsbyproxy.com.&amp;nbsp; That protection was removed in or around April 2008, and ownership of the domain seems to have been transferred to the Frank Russell Company in or around June of this year after the National Arbitration Forum handed ownership of the domain to Frank Russell Company on 30 May 2008.&amp;nbsp; According to the Forum&amp;#39;s &lt;a target="_blank" href="http://domains.adrforum.com/domains/decisions/1178430.htm"&gt;Decision&lt;/a&gt;,&amp;nbsp; Balingit failed to respond to the Forum&amp;#39;s &amp;quot;Notification of Complaint and Commencement of Administrative Proceeding&amp;quot;&amp;nbsp; or submit a response. &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1655513" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>Directi has taken over Estdomains' Registrar operations</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/11/26/1655082.aspx</link><pubDate>Wed, 26 Nov 2008 02:18:12 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1655082</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1655082</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/11/26/1655082.aspx#comments</comments><description>&lt;p&gt;&lt;a target="_blank" href="http://blog.resellerclub.com"&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:0px 20px 20px 0px;border-top:0px;border-right:0px;" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.DirectihastakenoverEstdomainsRegistrarop_5F00_88DE/image_5F00_55436863_2D00_9347_2D00_4d82_2D00_a245_2D00_2555f40a6d0f.png" width="499" height="862" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;Announcement:&lt;br /&gt;&lt;a title="http://www.icann.org/en/announcements/announcement-25nov08-en.htm" target="_blank" href="http://www.icann.org/en/announcements/announcement-25nov08-en.htm"&gt;http://www.icann.org/en/announcements/announcement-25nov08-en.htm&lt;/a&gt;&lt;/p&gt; &lt;p&gt;It is important to note that Estdomains &lt;strong&gt;designated&lt;/strong&gt; Directi as its successor.&amp;nbsp; This is despite the fact that Directi apparently dumped Estdomains as a client a while back (see &amp;quot;Historical Stuff&amp;quot; below).&lt;/p&gt; &lt;p&gt;It will be very interesting to watch developments going forward.&amp;nbsp; What Registrar will the fraudsters use from now on?&amp;nbsp; Will Directi audit the domains that have been passed on to them?&amp;nbsp; How fast (or slow) will takedowns be?&amp;nbsp; Will they red flag and audit domains associated with email addresses which use multiple pseudonyms, or pseudonyms that use multiple email addresses (like these?) (btw, don&amp;#39;t assume that these are used for Estdomain/Directi registered domains - they&amp;#39;re examples of what the bad guys do):&lt;/p&gt; &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;border-top:0px;border-right:0px;" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.DirectihastakenoverEstdomainsRegistrarop_5F00_88DE/image_5F00_8bfa29cb_2D00_96cf_2D00_45d6_2D00_ac97_2D00_f9c11b4200b8.png" width="408" height="189" /&gt; &lt;/p&gt; &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;border-top:0px;border-right:0px;" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.DirectihastakenoverEstdomainsRegistrarop_5F00_88DE/image_5F00_067ff30c_2D00_6d90_2D00_46ea_2D00_b69f_2D00_a053a2dfe053.png" width="369" height="64" /&gt; &lt;/p&gt; &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;border-top:0px;border-right:0px;" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.DirectihastakenoverEstdomainsRegistrarop_5F00_88DE/image_5F00_f3ff403b_2D00_39a2_2D00_4ed3_2D00_9a6f_2D00_9dd96d7a03ae.png" width="380" height="108" /&gt; &lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Historical stuff:&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;28 August 2008&lt;br /&gt;&lt;/strong&gt;Washington Post - Hostexploit - Report slams US host as major source of badware (Atrivo) - mentions Directi&lt;br /&gt;&lt;a target="_blank" href="http://hostexploit.blogspot.com/2008/08/report-slams-us-host-as-major-source-of.html"&gt;http://hostexploit.blogspot.com/2008/08/report-slams-us-host-as-major-source-of.html&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;3 September 2008&lt;/strong&gt;&lt;br /&gt;The Register - Anonymous domain registration nixed amid fraud complaints&lt;br /&gt;&lt;a target="_blank" href="http://www.theregister.co.uk/2008/09/03/directi_strikes_back/"&gt;http://www.theregister.co.uk/2008/09/03/directi_strikes_back/&lt;/a&gt; &lt;p&gt;&lt;strong&gt;6 September 2008&lt;/strong&gt;&lt;br /&gt;Hostexploit - Atrivo - Cyber Crime US Report - update 090608 - Directi take action&lt;br /&gt;&lt;a target="_blank" href="http://hostexploit.blogspot.com/2008/09/atrivo-cyber-crime-usa-report-update.html"&gt;http://hostexploit.blogspot.com/2008/09/atrivo-cyber-crime-usa-report-update.html&lt;/a&gt; &lt;p&gt;&lt;strong&gt;7 September 2008&lt;/strong&gt;&lt;br /&gt;Hostexploit - Joint statement from Directi, HostExploit and Kunujon&lt;br /&gt;&lt;a target="_blank" href="http://hostexploit.blogspot.com/2008/09/joint-statement-from-directi.html"&gt;http://hostexploit.blogspot.com/2008/09/joint-statement-from-directi.html&lt;/a&gt; &lt;p&gt;&lt;strong&gt;8 September 2008&lt;/strong&gt;&lt;br /&gt;A Superlative Scam and Spam Site Registrar - includes a section entitled &amp;quot;The Role of Directi&amp;quot;&lt;br /&gt;&lt;a target="_blank" href="http://voices.washingtonpost.com/securityfix/2008/09/estdomains.html"&gt;http://voices.washingtonpost.com/securityfix/2008/09/estdomains.html&lt;/a&gt; &lt;p&gt;Domains registered at Directi that have been listed in URIBL - URIBL lists domains that appear in spam (Note: 830 domains have been listed in my URIBL RSS Feed of Directi domains that have appeared in spam since the afternoon of &lt;strong&gt;18 September 2008)&lt;/strong&gt;&lt;br /&gt;&lt;a target="_blank" href="http://rss.uribl.com/nic/DIRECT_INFORMATION_PVT_LTD_D_B_A_PUBLICDOMAINREGISTRY_COM.html"&gt;http://rss.uribl.com/nic/DIRECT_INFORMATION_PVT_LTD_D_B_A_PUBLICDOMAINREGISTRY_COM.html&lt;/a&gt; &lt;p&gt;&lt;strong&gt;18 October 2008&lt;/strong&gt;&lt;br /&gt;Directi blog - Action against registry services abuses&lt;br /&gt;&lt;a target="_blank" href="http://blog.directi.com/0-directi/actions-against-registry-services-abuse-%E2%80%93-report-oct-2008-hostexploit-and-directi/"&gt;http://blog.directi.com/0-directi/actions-against-registry-services-abuse-%E2%80%93-report-oct-2008-hostexploit-and-directi/&lt;/a&gt; &lt;p&gt;&lt;strong&gt;Various dates&lt;/strong&gt;&lt;br /&gt;Mention of Directi at rbn.blogspot.com&lt;br /&gt;&lt;a target="_blank" href="http://rbnexploit.blogspot.com/search?q=directi"&gt;http://rbnexploit.blogspot.com/search?q=directi&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Various dates&lt;/strong&gt;&lt;br /&gt;Mention of Directi at knujon.com&lt;br /&gt;&lt;a target="_blank" href="http://www.knujon.com/news.html#directi"&gt;http://www.knujon.com/news.html#directi&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1655082" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>The Julie Amero saga is finally over</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/11/22/1654793.aspx</link><pubDate>Sat, 22 Nov 2008 01:30:51 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1654793</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1654793</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/11/22/1654793.aspx#comments</comments><description>&lt;p&gt;But, she had to agree to plead guilty to a misdemeanor charge of &amp;quot;disorderly conduct&amp;quot;, to finally see an end to her nightmare.&amp;nbsp; She had to pay a fine of $100 and give up her license to teach in Connecticut.&lt;/p&gt; &lt;p&gt;Cite: &lt;a title="http://sunbeltblog.blogspot.com/2008/11/breaking-julie-amero-horror-is-over.html" target="_blank" href="http://sunbeltblog.blogspot.com/2008/11/breaking-julie-amero-horror-is-over.html"&gt;http://sunbeltblog.blogspot.com/2008/11/breaking-julie-amero-horror-is-over.html&lt;/a&gt;&lt;/p&gt; &lt;p&gt;The Prosecutor, David Smith, added insult to injury by saying to the Court that he felt that they still had a case and that they were only allowing an end to proceedings because of Julie&amp;#39;s declining health.&amp;nbsp; It seems to me that Mr Smith is doing one of two things - he is trying to save face (good luck with that) or he still really doesn&amp;#39;t get it.&amp;nbsp; The way that this sage ended makes me fear that what happened to Julie may happen again.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1654793" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>Request For Information: ICANN Seeks Expressions of Interest from Registrars to Receive Bulk Transfer of Names from De-Accredited Registrar EstDomains</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/10/29/1652349.aspx</link><pubDate>Wed, 29 Oct 2008 07:24:32 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1652349</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1652349</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/10/29/1652349.aspx#comments</comments><description>&lt;p&gt;Announcement here:&lt;br /&gt;&lt;a target="_blank" href="http://www.icann.org/en/announcements/announcement-2-28oct08-en.htm"&gt;http://www.icann.org/en/announcements/announcement-2-28oct08-en.htm&lt;/a&gt; &lt;blockquote&gt; &lt;p&gt;&amp;quot;&lt;em&gt;As the result of the de-accreditation of EstDomains, Inc. (IANA ID 832), ICANN is seeking Statements of Interest from ICANN-accredited registrars that are interested in assuming sponsorship of the gTLD names that had been managed by EstDomains. &lt;/em&gt; &lt;p&gt;&lt;em&gt;EstDomains managed approximately 280,000 gTLD registrations, including registrations in the biz, com, info, mobi, net, and org registries, including approximately 7 second-level internationalized domain names. EstDomains, Inc. is organized in Delaware, United States &lt;/em&gt; &lt;p&gt;&lt;em&gt;Registration data held in escrow is believed to be complete and in a proper format as described in the Registrar Data Escrow Specifications posted at &lt;/em&gt;&lt;a target="_blank" href="http://www.icann.org/en/rde/rde-specs-09nov07.pdf"&gt;&lt;em&gt;http://www.icann.org/en/rde/rde-specs-09nov07.pdf&lt;/em&gt;&lt;/a&gt;&lt;em&gt; [PDF, 33K].&lt;/em&gt;&amp;quot; &lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;It will be interesting to see who takes on this particular can of worms... &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1652349" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>Windows 7 Preview Video</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/10/28/1652202.aspx</link><pubDate>Tue, 28 Oct 2008 04:38:40 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1652202</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1652202</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/10/28/1652202.aspx#comments</comments><description>&lt;p&gt;&lt;img style="margin:0px 25px 25px 0px;" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.Windows7PreviewVideo_5F00_BF21/image_5F00_5d85a2ef_2D00_b7e7_2D00_42ca_2D00_bc97_2D00_d9f49c1be543.png" width="580" height="436" /&gt; For those of you who may be interested:&lt;/p&gt; &lt;p&gt;&lt;a title="http://www.microsoft.com/downloads/details.aspx?familyid=26996ced-888d-4892-b1be-5141da8272bd&amp;amp;displaylang=en&amp;amp;tm" target="_blank" href="http://www.microsoft.com/downloads/details.aspx?familyid=26996ced-888d-4892-b1be-5141da8272bd&amp;amp;displaylang=en&amp;amp;tm"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=26996ced-888d-4892-b1be-5141da8272bd&amp;amp;displaylang=en&amp;amp;tm&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Note: only available for download via systems that pass Windows Genuine Validation&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1652202" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>Adobe has posted a security advisory regarding the "clickjacking" problem</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/10/08/1650061.aspx</link><pubDate>Wed, 08 Oct 2008 02:13:44 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1650061</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1650061</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/10/08/1650061.aspx#comments</comments><description>&lt;p&gt;&lt;img style="margin:0px 25px 25px 0px;" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.Adobehaspostedasecurityadvisoryregarding_5F00_8F1D/image_5F00_241b7da2_2D00_ef66_2D00_4c6b_2D00_859a_2D00_c76d4cf40090.png" width="404" height="283" /&gt;The Advisory is here:&lt;br /&gt;&lt;a title="http://www.adobe.com/support/security/advisories/apsa08-08.html" target="_blank" href="http://www.adobe.com/support/security/advisories/apsa08-08.html"&gt;http://www.adobe.com/support/security/advisories/apsa08-08.html&lt;/a&gt;&lt;/p&gt; &lt;p&gt;I quote:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&lt;em&gt;&amp;quot;Customers: &lt;/em&gt; &lt;p&gt;&lt;em&gt;To prevent this potential issue, customers can change their Flash Player settings as follows: &lt;/em&gt; &lt;p&gt;&lt;em&gt;&amp;nbsp;&amp;nbsp; 1. Access the Global Privacy Settings panel of the Adobe Flash Player Settings Manager at the following URL: &lt;/em&gt;&lt;a href="http://www.adobe.com/suppo"&gt;&lt;em&gt;&lt;a href="http://www.adobe.com/support/documentation/en/flashplayer/help/settings_manager02.html"&gt;http://www.adobe.com/suppo&lt;/em&gt;&lt;/a&gt;&lt;em&gt;rt/documentation/en/flashplayer/help/settings_manager02.html&lt;/a&gt;&lt;/em&gt;&lt;br /&gt;&lt;em&gt;&amp;nbsp;&amp;nbsp; 2. Select the &amp;quot;Always deny&amp;quot; button.&lt;br /&gt;&amp;nbsp;&amp;nbsp; 3. Select ‘Confirm’ in the resulting dialog.&lt;br /&gt;&amp;nbsp;&amp;nbsp; 4. Note that you will no longer be asked to allow or deny camera and / or microphone access after changing this setting. Customers who wish to allow certain sites access to their camera and / or microphone can selectively allow access to certain sites via the Website Privacy Settings panel of the Settings Manager at the following URL: &lt;/em&gt;&lt;a href="http://www.adobe.com/support/documentation/en/flashplayer/help/settings_manager06.html"&gt;&lt;em&gt;http://www.adobe.com/support/documentation/en/flashplayer/help/settings_manager06.html&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&amp;quot;&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1650061" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>Update QuickTime please...</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/09/10/1647314.aspx</link><pubDate>Wed, 10 Sep 2008 08:41:10 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1647314</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1647314</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/09/10/1647314.aspx#comments</comments><description>&lt;p&gt;A new version has been released that addresses several security issues.&lt;/p&gt; &lt;p&gt;Quoting from the Apple security announcement:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;&lt;em&gt;&amp;quot;QuickTime&lt;br /&gt;CVE-ID:&amp;nbsp; CVE-2008-3615&lt;br /&gt;Available for:&amp;nbsp; Windows Vista, XP SP2 and SP3&lt;br /&gt;Impact:&amp;nbsp; Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution&lt;br /&gt;Description:&amp;nbsp; An uninitialized memory access issue exists in the third-party Indeo v5 codec for QuickTime, which does not ship with QuickTime. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by not rendering content encoded with any version of the Indeo codec. This issue does not affect systems running Mac OS X. Credit to Paul Byrne of NGSSoftware for reporting this issue. &lt;/em&gt; &lt;p&gt;&lt;em&gt;QuickTime&lt;br /&gt;CVE-ID:&amp;nbsp; CVE-2008-3635&lt;br /&gt;Available for:&amp;nbsp; Windows Vista, XP SP2 and SP3&lt;br /&gt;Impact:&amp;nbsp; Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution&lt;br /&gt;Description:&amp;nbsp; A stack buffer overflow exists in the third-party Indeo&lt;br /&gt;v3.2 codec for QuickTime. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by not rendering content encoded with any version of the Indeo codec. This issue does not affect systems running Mac OS X. Credit to an anonymous researcher working with TippingPoint&amp;#39;s Zero Day Initiative for reporting this issue. &lt;/em&gt; &lt;p&gt;&lt;em&gt;QuickTime&lt;br /&gt;CVE-ID:&amp;nbsp; CVE-2008-3624&lt;br /&gt;Available for:&amp;nbsp; Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3&lt;br /&gt;Impact:&amp;nbsp; Viewing a maliciously crafted QTVR movie file may lead to an unexpected application termination or arbitrary code execution&lt;br /&gt;Description:&amp;nbsp; A heap buffer overflow exists in QuickTime&amp;#39;s handling of panorama atoms in QTVR (QuickTime Virtual Reality) movie files.&lt;br /&gt;Viewing a maliciously crafted QTVR file may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking of panorama atoms. Credit to Roee Hay of IBM Rational Application Security Research Group for reporting this issue. &lt;/em&gt; &lt;p&gt;&lt;em&gt;QuickTime&lt;br /&gt;CVE-ID:&amp;nbsp; CVE-2008-3625&lt;br /&gt;Available for:&amp;nbsp; Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3&lt;br /&gt;Impact:&amp;nbsp; Viewing a maliciously crafted QTVR movie file may lead to an unexpected application termination or arbitrary code execution&lt;br /&gt;Description:&amp;nbsp; A stack buffer overflow exists in QuickTime&amp;#39;s handling of panorama atoms in QTVR (QuickTime Virtual Reality) movie files.&lt;br /&gt;Viewing a maliciously crafted QTVR file may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking of panorama atoms. Credit to an anonymous researcher working with TippingPoint&amp;#39;s Zero Day Initiative for reporting this issue. &lt;/em&gt; &lt;p&gt;&lt;em&gt;QuickTime&lt;br /&gt;CVE-ID:&amp;nbsp; CVE-2008-3614&lt;br /&gt;Available for:&amp;nbsp; Windows Vista, XP SP2 and SP3&lt;br /&gt;Impact:&amp;nbsp; Opening a maliciously crafted PICT image may lead to an unexpected application termination or arbitrary code execution&lt;br /&gt;Description:&amp;nbsp; An integer overflow exists in QuickTime&amp;#39;s handling of PICT images. Opening a maliciously crafted PICT image may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of PICT images. Credit to an anonymous researcher working with the iDefense VCP for reporting this issue. &lt;/em&gt; &lt;p&gt;&lt;em&gt;QuickTime&lt;br /&gt;CVE-ID:&amp;nbsp; CVE-2008-3626&lt;br /&gt;Available for:&amp;nbsp; Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3&lt;br /&gt;Impact:&amp;nbsp; Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution&lt;br /&gt;Description:&amp;nbsp; A memory corruption issue exists in QuickTime&amp;#39;s handling of STSZ atoms in movie files. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue through improved bounds checking of STSZ atoms. Credit to an anonymous researcher working with TippingPoint&amp;#39;s Zero Day Initiative for reporting this issue. &lt;/em&gt; &lt;p&gt;&lt;em&gt;QuickTime&lt;br /&gt;CVE-ID:&amp;nbsp; CVE-2008-3627&lt;br /&gt;Available for:&amp;nbsp; Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3&lt;br /&gt;Impact:&amp;nbsp; Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution&lt;br /&gt;Description:&amp;nbsp; Multiple memory corruption exist in QuickTime&amp;#39;s handling of H.264 encoded movie files. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. This update addresses the issue by performing additional validation of H.264 encoded movie files. Credit to an anonymous researcher and Subreption LLC working with TippingPoint&amp;#39;s Zero Day Initiative for reporting this issue. &lt;/em&gt; &lt;p&gt;&lt;em&gt;QuickTime&lt;br /&gt;CVE-ID:&amp;nbsp; CVE-2008-3628&lt;br /&gt;Available for:&amp;nbsp; Windows Vista, XP SP2 and SP3&lt;br /&gt;Impact:&amp;nbsp; Opening a maliciously crafted PICT image may lead to an unexpected application termination or arbitrary code execution&lt;br /&gt;Description:&amp;nbsp; An invalid pointer issue exists in QuickTime&amp;#39;s handling of PICT images. Opening a maliciously crafted PICT image may lead to an unexpected application termination or arbitrary code execution.&lt;br /&gt;This update addresses the issue by correctly saving and restoring a global variable. This issue does not affect systems running Mac OS X.&lt;br /&gt;Credit to David Wharton for reporting this issue. &lt;/em&gt; &lt;p&gt;&lt;em&gt;QuickTime&lt;br /&gt;CVE-ID:&amp;nbsp; CVE-2008-3629&lt;br /&gt;Available for:&amp;nbsp; Mac OS X v10.4.9 - v10.4.11, Mac OS X v10.5 or later, Windows Vista, XP SP2 and SP3&lt;br /&gt;Impact:&amp;nbsp; Opening a maliciously crafted PICT image may lead to an unexpected application termination&lt;br /&gt;Description:&amp;nbsp; An out-of-bounds read issue exists in QuickTime&amp;#39;s handling of PICT images. Opening a maliciously crafted PICT image may lead to an unexpected application termination. This update addresses the issue by performing additional validation of PICT images. Credit to Sergio &amp;#39;shadown&amp;#39; Alvarez of n.runs AG for reporting this issue. &lt;/em&gt; &lt;p&gt;&lt;em&gt;QuickTime 7.5.5 may be obtained from the Software Update application, or from the QuickTime Downloads site:&lt;br /&gt;&lt;/em&gt;&lt;a href="http://www.apple.com/quicktime/download/"&gt;&lt;em&gt;http://www.apple.com/quicktime/download/&lt;/em&gt;&lt;/a&gt; &lt;p&gt;&lt;em&gt;For Mac OS X v10.5 or later&lt;br /&gt;The download file is named:&amp;nbsp; &amp;quot;QuickTime755_Leopard.dmg&amp;quot;&lt;br /&gt;Its SHA-1 digest is:&amp;nbsp; 934f784a553c2d4484d298071ad6d95ea34b8b2f &lt;/em&gt; &lt;p&gt;&lt;em&gt;For Mac OS X v10.4.9 through Mac OS X v10.4.11 The download file is named:&amp;nbsp; &amp;quot;QuickTime755_Tiger.dmg&amp;quot;&lt;br /&gt;Its SHA-1 digest is:&amp;nbsp; dcdf58e27aad2a1e958788c0f58584605c4b8e78 &lt;/em&gt; &lt;p&gt;&lt;em&gt;For Windows Vista / XP SP2 and SP3&lt;br /&gt;The download file is named:&amp;nbsp; &amp;quot;QuickTimeInstaller.exe&amp;quot;&lt;br /&gt;Its SHA-1 digest is:&amp;nbsp; 5900ff0b8044972cb06b52dfc913c6364bf27ccc &lt;/em&gt; &lt;p&gt;&lt;em&gt;QuickTime with iTunes for Windows XP or Vista The download file is named:&amp;nbsp; iTunes8Setup.exe Its SHA-1 digest is:&amp;nbsp; 5d4ff8ffbe9feeaed67deb317797c1d71a03c359 &lt;/em&gt; &lt;p&gt;&lt;em&gt;Information will also be posted to the Apple Security Updates web site:&amp;nbsp; http://support.apple.com/kb/HT1222&amp;quot;&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1647314" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>Updated VPC images have been released...</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/09/02/1646430.aspx</link><pubDate>Tue, 02 Sep 2008 01:39:46 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1646430</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1646430</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/09/02/1646430.aspx#comments</comments><description>&lt;p&gt;Download here - the images will expire in January 2009&lt;/p&gt; &lt;p&gt;&lt;a title="http://www.microsoft.com/downloads/details.aspx?FamilyId=21EABB90-958F-4B64-B5F1-73D0A413C8EF&amp;amp;displaylang=en" target="_blank" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=21EABB90-958F-4B64-B5F1-73D0A413C8EF&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyId=21EABB90-958F-4B64-B5F1-73D0A413C8EF&amp;amp;displaylang=en&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Images available:&lt;/p&gt; &lt;p&gt;Windows XP SP3 with IE6&lt;br /&gt;Windows XP SP2 with IE7&lt;br /&gt;Windows XP SP3 with IE8 Beta 2&lt;br /&gt;Vista with IE7 &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1646430" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item><item><title>Google is acting a bit weird today...</title><link>http://msmvps.com/blogs/spywaresucks/archive/2008/08/13/1644468.aspx</link><pubDate>Wed, 13 Aug 2008 03:59:55 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1644468</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1644468</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2008/08/13/1644468.aspx#comments</comments><description>&lt;p&gt;Is anybody else seeing this?&lt;/p&gt; &lt;p&gt;Google in Firefox seems ok.&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.Googleisactingabitweirdtoday_5F00_A8AC/image_5F00_d18ccb92_2D00_81ee_2D00_4ee4_2D00_ba6f_2D00_9ad280ab1f18.png" width="607" height="406" /&gt; &lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;Google in Internet Explorer is showing a strange overlay...&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;img alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.Googleisactingabitweirdtoday_5F00_A8AC/image_5F00_a13c12a7_2D00_1f38_2D00_4dca_2D00_a8bb_2D00_7fa27db45d54.png" width="615" height="444" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1644468" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Off+topic/default.aspx">Off topic</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Technology/default.aspx">Technology</category></item></channel></rss>