Xiaxue (http://xiaxue.blogspot.com) gets OWNED without even having blog getting touched.
Here is more info on the Zotob.
http://elamb.blogharbor.com/hacked/zotob.htm
I've traveled to every part of this country during the last six years. During my service in the United States Congress, I took the initiative in creating the Internet.–Al Gore (http://www.sethf.com/gore/).
The Zotob Worm has spread across three continents and has brought down systems at CNN, ABC and other networks. It is a decendant of Mytob. Zotob exploits the “plug and play” features of unpatched Win 2000 systems and earlier versions of Windows XP.
The Zotob Worm, like most worms, slows down network connectivity, can shut down/reboot a system, attempts to spread to other systems on the network and ultimately will connect with a remote server to allow downloads of more destructive malware such as virus’ and Trojans.
Zotob Worm Variants:
http://securityresponse.symantec.com/avcenter/vinfodb.html
Summary:
http://singe.rucus.net/blog/archives/510-MS05-039-and-the-Zotob-summary.html
http://singe.rucus.net/blog/archives/510-MS05-039-and-the-Zotob-summary.html
Today I went to the ISSA luncheon. The local ISSA chapter joined forces with an organization called A.S.I.S International (formerly American Society for Industrial Security).
ASIS seems to be composed of a lot of physical security professionals (ie protecting critical infrastructure). Where ISSA assists its members in attaining CISSP, forensics certs and the Security+, ASIS concentrates on Certified Protection Professional (CPP), Physical Security Professional (PSP), and Professional Certified Investigator (PCI).
With my background in physical security, I fit right into their world. I plan on attending one of their meetings in the future.
Between ASIS and ISSA members we filled an auditorium. With that kind of networking something big is begining to happen in Colorado.
Todays presentation of a smart card readers system had a lot of cross over appeal for both information security professionals and physical security professionals alike.
CNN apparently didn't patch their Windows 2000 computers. Link is to story about the Zotob worm but here is a screen shot of CNN's computer getting hit. http://ejeet.home.comcast.net/worm.jpg
Torrent for Pirates of Silicon Valley, coming soon to DVD. Since most of us don't have VCRs, this is useful. Don't forget to buy the DVD!
I've recently experienced an increase in spam traffic on my blog.
It started when I got about 20 comments in one day on one of my least
popular articles. I could see that the porn spammer had dug deep
into my site and found a seemingly insignifigant article to place about
100 links. I deleted them imediately and blocked the IP from
whince they came.
The very next day I had fifteen more. I delete those and blocked
that IP. I've been forced to turn off my anonymous
comments. One of my favorite things about blogs is that anyone
can say anything – they so refreshingly interactive that they create
these close relationships with readers.
Unfortunately, casino, porn and pill spammers also see the power of
blogs. They target blogs with anonymous comments and
trackbacks. And they use thousands of hacked computers to act as
proxies so that even if you block their IP they've got plenty more ways
to get to you.
I've blocked them and I'm still seeing traffic coming from their sites
which tells me that they have linked to my site and my visitors are
clicking into their site then coming back to me.
Here is a list of Casino Spammers retreived from Netaloid.com
“Finding our Poker Spammer’s identifying links is easy. Just
visit one of his web pages by using one of the thousands of spam links
he left on your site. Like poker.terashells.com, for instance. Then
click on the links to the casino sites. You’ll see something like (or
identical to) this:”
http://www.pacificpoker.com/default.htm?sr=904970&flag=0002
http://www.partypoker.com/index20100.htm?wm=2445773
http://www.empirepoker.com/index.htm?wm=2170658
http://banner.casinolasvegas.com/cgi-bin/redir.cgi?id=N&member=onlinecas&profile=lv2m
http://www.888.com/default.htm?sr=611794&flag=0002
http://www.starluckcasino.com/slcasino/links/56296.html
http://www.aceclub.com/aceclub/links/1790.html
http://www.reefclubcasino.com/default.htm?sr=806320&flag=0002
For more on legally stopping Casino, Porn and other spammers visit:
http://www.thepetitionsite.com/takeaction/353566831?ltl=1124161500
http://www.theregister.co.uk/2005/01/31/link_spamer_interview/
Tired of online Casinos Spamming your Blog's comments and trackbacks?
Write congress to nuke spammers! Because it is time for spammers to pay
for their crimes against humanity!
The National Security Agency (NSA) has written security configuration guides for many operating systems and applications. Very helpful when setting up a new network. Wow! Your tax dollars being spent on something useful.