<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:admin="http://webns.net/mvcb/"
	xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Dancho Danchev &#45; CircleID</title>
		<link>http://www.circleid.com/</link>
		<description>Postings from Dancho Danchev on CircleID</description>
		<dc:language>en</dc:language>
		<dc:rights>Copyright 2008, unless where otherwise noted.</dc:rights>
		<dc:date>2008-11-28T11:02:00-08:00</dc:date>
		

		
		<item>
			<title> Localizing Cybercrime (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/20081128_localizing_cybercrime</guid>
			<link>http://www.circleid.com/posts/20081128_localizing_cybercrime</link>
			<description><![CDATA[It's where you advertise your services, and how you position yourself that speak for your intentions, of course, "between the lines". There's a common misunderstanding that in order for a malware campaigner or scammer to launch a localized attack, they need to speak the local language. This misconception is largely based on the fact that a huge number of people remain unaware on how core strategic business practices have been in operation across the cybercrime underground for the last couple of years. <a href="http://www.circleid.com/posts/20081128_localizing_cybercrime">More...</a>]]></description>
			<dc:date>2008-11-28T11:02:00-08:00</dc:date>
		</item>
		
		<item>
			<title> Compromised Portfolios of Legitimate Domain Names for Sale (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/20081024_compromised_domain_names_for_sale</guid>
			<link>http://www.circleid.com/posts/20081024_compromised_domain_names_for_sale</link>
			<description><![CDATA[Is the demand for access to compromised legitimate portfolios of domain names -- where the price is based on the pagerank and is shaped by the number of domains in question -- the main growth factor for the increasing supply of such stolen accounting data? Or is it the result of cybercriminals data mining their botnets for accounting data that would provide them with access to such portfolios of high trafficked domains with clean reputation? <a href="http://www.circleid.com/posts/20081024_compromised_domain_names_for_sale">More...</a>]]></description>
			<dc:date>2008-10-24T09:33:00-08:00</dc:date>
		</item>
		
		<item>
			<title> Massive SQL Injection Attacks: The Chinese Way (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/20081022_sql_injection_attacks_chinese_way</guid>
			<link>http://www.circleid.com/posts/20081022_sql_injection_attacks_chinese_way</link>
			<description><![CDATA[From copycats and "localizers" of Russian web malware exploitation kits, to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the obvious insecurities on a large scale. They are either filling the niches left open by other international communities, or coming up with tools and setting new benchmarks for massive SQL injection attacks. <a href="http://www.circleid.com/posts/20081022_sql_injection_attacks_chinese_way">More...</a>]]></description>
			<dc:date>2008-10-22T12:43:00-08:00</dc:date>
		</item>
		
		<item>
			<title> DDoS Attack Graphs from Russia vs. Georgia's Cyberattacks (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/20081016_graphs_russia_georgias_cyberattacks</guid>
			<link>http://www.circleid.com/posts/20081016_graphs_russia_georgias_cyberattacks</link>
			<description><![CDATA[Part of Georgia's information warfare campaign was aiming to minimize the bandwidth impact on its de-facto media platforms such as the website of their Ministry of Foreign Affairs. I've just received a report on "Russian Invasion of Georgia," titled "Russian Cyberwar on Georgia" which is quoting me on page 4 regarding "too good to be courtesy of Russia's cyber militia" creative that appeared on the defaced Georgian President's website. <a href="http://www.circleid.com/posts/20081016_graphs_russia_georgias_cyberattacks">More...</a>]]></description>
			<dc:date>2008-10-16T07:50:00-08:00</dc:date>
		</item>
		
		<item>
			<title> Inside a Managed Spam Service (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/20081006_inside_managed_spam_service</guid>
			<link>http://www.circleid.com/posts/20081006_inside_managed_spam_service</link>
			<description><![CDATA[A managed spam vendor always has to raise the stakes during its introduction period on the market. But what happens when a market follower starts using the market leader's proprietary managed spamming system, and is able to provide better spamming rates at cheaper prices? Market forces and unethical competition at its best. <a href="http://www.circleid.com/posts/20081006_inside_managed_spam_service">More...</a>]]></description>
			<dc:date>2008-10-06T10:00:00-08:00</dc:date>
		</item>
		
		<item>
			<title> EstDomains and Intercage vs. Cybercrime (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/estdomains_and_intercage_vs_cybercrime</guid>
			<link>http://www.circleid.com/posts/estdomains_and_intercage_vs_cybercrime</link>
			<description><![CDATA[Surreal, especially when you get to read that EstDomains has "ruthlessly suspended over five thousand domains only for last week", and also, that it "has a reliable ally in its battle against malware in a face of Intercage, Inc." ... The press release reminds me of Russian Business Network's (RBN) defacement of my blog posted on the 1st of April, and despite that EstDomains started "performing for the community" as of recently, thanks to the collective intelligence and persistence of everyone turning their research into actionable intelligence against them, this performance aiming to minimize the effect of the negative PR is more or less futile... <a href="http://www.circleid.com/posts/estdomains_and_intercage_vs_cybercrime">More...</a>]]></description>
			<dc:date>2008-09-16T08:30:00-08:00</dc:date>
		</item>
		
		<item>
			<title> Copycat Web Malware Exploitation Kits are Faddish (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/copycat_web_malware_exploitation_kits</guid>
			<link>http://www.circleid.com/posts/copycat_web_malware_exploitation_kits</link>
			<description><![CDATA[or the cheap cybercriminals not wanting to invest a couple of thousand dollars into purchasing a cutting edge web malware exploitation kit with all the related and royalty free updates coming with it (a pirated copy of which they could ironically obtain several moths later), there are always the copycat malware kits... Taking into consideration the proprietary nature of some of the kits, the business model of malware kits was mostly relying on their exclusive nature next to the number, and diversity of the exploits included in order to improve the infection rate. This simplistic assumption on behalf of the coders totally ignored the possibility of their kits leaking to the general public... <a href="http://www.circleid.com/posts/copycat_web_malware_exploitation_kits">More...</a>]]></description>
			<dc:date>2008-09-03T08:23:00-08:00</dc:date>
		</item>
		
		<item>
			<title> 76Service: Cybercrime as Service Going Mainstream (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/88142_cybercrime_as_service_going_mainstream</guid>
			<link>http://www.circleid.com/posts/88142_cybercrime_as_service_going_mainstream</link>
			<description><![CDATA[Disintermediating the intermediaries in the cybercrime ecosystem, ultimately results in more profitable operations. Controversial to the concept of outsourcing, some cybercriminals are in fact so self-sufficient, that the stereotype of a mysterious 76service server offered for rent could in fact easily cease to exist in an ecosystem so vibrant that literally everyone can portion their botnet and start offering access to it on a multi-user basis. Evil? Obviously. Extending the lifecycle of a proprietary malware tool? Definitely. <a href="http://www.circleid.com/posts/88142_cybercrime_as_service_going_mainstream">More...</a>]]></description>
			<dc:date>2008-08-14T13:37:00-08:00</dc:date>
		</item>
		
		<item>
			<title> Phishers Backdooring Phishing Pages to Scam One Another (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/88831_phishers_scamming_one_another</guid>
			<link>http://www.circleid.com/posts/88831_phishers_scamming_one_another</link>
			<description><![CDATA[There seems to be no such thing as a free phishing page these days, with phishers scamming one another at an alarming rate according to a recently published research entitled "<a href="http://www.usenix.org/event/woot08/tech/full_papers/cova/cova_html/">There is No Free Phish: An Analysis of "Free" and Live Phishing Kits</a>". Cybercriminals attempting to scam other cybercriminals has been happening for years, with old school cases where backdoored malware tools such as crypters and binders are offered for free, or a newly released RAT whose client is in fact infected with a third-party malware... <a href="http://www.circleid.com/posts/88831_phishers_scamming_one_another">More...</a>]]></description>
			<dc:date>2008-08-08T14:16:00-08:00</dc:date>
		</item>
		
		<item>
			<title> Click Fraud, Botnets and Parked Domains - All Inclusive (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/87281_click_fraud_botnets_parked_domains</guid>
			<link>http://www.circleid.com/posts/87281_click_fraud_botnets_parked_domains</link>
			<description><![CDATA[It gets very ugly when someone owns both, the botnet, and the portfolio of parked domains actively participating in pay per click (PPC) advertising programs, where the junk content, or the typosquatted domain names are aiming to attract high value and expensive keywords in order for the scammer to earn higher on per click percentage. This is among the very latest tactics applied by those engaged in click fraud activites. <a href="http://www.circleid.com/posts/87281_click_fraud_botnets_parked_domains">More...</a>]]></description>
			<dc:date>2008-07-28T09:30:00-08:00</dc:date>
		</item>
		
		<item>
			<title> Counting the Bullets on the (Malware) Front (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/87259_counting_bullets_on_malware_front</guid>
			<link>http://www.circleid.com/posts/87259_counting_bullets_on_malware_front</link>
			<description><![CDATA[How much malware is your antivirus solution detecting? A million, ten million, even "worse", less than a million? Does it really matter? No, it doesn't. What's marketable can also be irrelevant if you are to consider that today's malware is no longer coded, but generated efficiently and obfuscated on the fly. Sophos's recent statistics: "It is estimated that the total number of unique malware samples in existence now exceeds 11 million, with Sophos currently receiving approximately 20,000 new samples of suspicious software every single day -- one every four seconds." <a href="http://www.circleid.com/posts/87259_counting_bullets_on_malware_front">More...</a>]]></description>
			<dc:date>2008-07-25T08:11:00-08:00</dc:date>
		</item>
		
		<item>
			<title> Email Hacking Going Commercial (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/87248_email_hacking_going_commercial</guid>
			<link>http://www.circleid.com/posts/87248_email_hacking_going_commercial</link>
			<description><![CDATA[This email hacking as a service offering is the direct result of the public release of a do it yourself hacking kit consisting of each and every publicly known vulnerability for a variety of web based email service providers, with the idea to make it easier for someone to execute their attacks more efficiently. Outsource the hacking of someone's email, and receive a proof in the form of a screenshot of the inbox, next to a guarantee that you'll be able to get back in even after they've changed their passwords? Too good to be true, but since they only charge after they provide you with a proof that they did the job, they could be in fact attempting to hack these emails, compared to the majority of cases where scammers scam the scammers. <a href="http://www.circleid.com/posts/87248_email_hacking_going_commercial">More...</a>]]></description>
			<dc:date>2008-07-24T07:50:00-08:00</dc:date>
		</item>
		
		<item>
			<title> Lithuania Attacked by Russian Hacktivists, 300 Sites Defaced (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/87870_lithuania_internet_attack_russian_hacktivists</guid>
			<link>http://www.circleid.com/posts/87870_lithuania_internet_attack_russian_hacktivists</link>
			<description><![CDATA[Last week's mass defacement of over 300 Lithuanian sites hosted on the same ISP, an upcoming attack that was largely anticipated due to the on purposely escalated online tensions out of Lithuan's accepted legislation banning communist symbols across the country, once again demonstrates information warfare building capabilities in action. Moreover, the attack is again relying on common prerequisites for a successful information warfare campaign, used in the Russia vs. Estonia cyberattack last year. These very same Internet PSYOPS tactics ensure the success of the information warfare as a whole... <a href="http://www.circleid.com/posts/87870_lithuania_internet_attack_russian_hacktivists">More...</a>]]></description>
			<dc:date>2008-07-08T06:18:00-08:00</dc:date>
		</item>
		
		<item>
			<title> Gmail, Yahoo and Hotmail CAPTCHA In Need of Urgent Fix (Featured Blog)</title>
			<guid isPermaLink="true">http://www.circleid.com/posts/8738_spam_captcha_urgent_fix</guid>
			<link>http://www.circleid.com/posts/8738_spam_captcha_urgent_fix</link>
			<description><![CDATA[It's one thing to start efficiently registering thousands of email accounts at reputable email providers by automatically breaking their CAPTCHA authentication, and entirely another to build a business model on the top of it next to the opportunity to abuse if for your own malicious purposes. Which is exactly what we have here, an underground service that's selling registered accounts at Gmail, Yahoo, Hotmail and the most popular Russian email providers in the thousands. <a href="http://www.circleid.com/posts/8738_spam_captcha_urgent_fix">More...</a>]]></description>
			<dc:date>2008-07-03T08:46:01-08:00</dc:date>
		</item>
		
	</channel>
</rss>