- Home
- Cyber Security Industry Watch
Behind The Scene Look At How Botnet Services Operate & Are Sold On The Global Market
- By Grey McKenzie
- Published 03/11/2008
- Cyber Security Industry Watch , Cyber Hackers , Cyber Security Identity Theft Watch , Cyber Phishing Alerts
- Unrated
You will learn how anyone, even those without the skills to create a Botnet, can still hire their services.
Fast and Double Flux Attacks 2
Version 1.0 January 2008
Introduction
"Fast flux" is an evasion technique that cyber-criminals and Internet miscreants use to evade identification and to frustrate law enforcement and anticrime efforts aimed at locating and shutting down web sites used for illegal purposes.
Fast flux hosting is an application of technology that supports a wide variety of cyber-crime activities (fraud, identity theft, online scams) and is considered one of the most serious threats to online activities today.
Basic fast flux hosting uses rapid modification of IP addresses associated with a system that hosts a malicious activity to evade detection and take down efforts.
This technique is also used to rapidly modify the IP addresses of the name servers that resolve the domain names of the fluxed malicious hosts (this variant is sometimes called NS fast flux).
A particularly troublesome variant of fast flux hosting, "double flux",
fluxes addresses of both name servers and malicious (web server) hosts.
This Advisory describes the technical aspects of fast flux hosting and fast flux service networks.
It explains how the DNS is exploited to abet criminal activities that employ fast flux hosting, identifying the impacts of fast flux hosting, and calling particular attention to the way such attacks extend the malicious or profitable lifetime of the illegal activities conducted using these fast flux techniques.
It describes current and possible methods of mitigating fast flux hosting at various points in the Internet. The Advisory discusses the pros and cons of these mitigation methods, identifies those methods that SSAC considers practical and sensible, and recommends that appropriate bodies consider policies that would make the practical mitigation methods universally available to registrants, ISPs, registrars and registries (where applicable for each).
End User Must Become New Front Line On Cyber Warfare
- By Grey McKenzie
- Published 12/27/2007
- Cyber Security Industry Watch
- Unrated
United we stand, divided we fall.With the myriad of complex cyber threats looming on the horizon, it is vital that we realize, the new front line of any cyber defense system is without a doubt, the end user.
Cyber security experts are starting to understand that the weak point in any networking system are the users themselves.
The new buzzword according to Yankee Group Analyst Andrew Jaquith is "Herd Mentality".
Trojan Steals Hundreds of Thousands From Biggest Banks in the U.S., the U.K., Spain and Italy,
- By Grey McKenzie
- Published 12/14/2007
- Cyber Security Alert , Cyber Security Industry Watch , Cyber Phishing Alerts
- Unrated
December 13, 2007 (Computerworld) -- A German hacker crew is looting commercial bank accounts in four countries using a custom-built Trojan put in place by expertly crafted and extremely focused phishing attacks, a security researcher said today.
The malware's most distinguishing feature, said Don Jackson, a senior security researcher with SecureWorks Inc., is its ability to mimic the steps the human account owner would take to move money.
Age Verification and Email/Screen Name Registration, a Weak Substitute for Real Education
- By Kevin McDonald
- Published 11/13/2007
- Cyber Child Protection Watch , Cyber Security Industry Watch , Cyber Security Government Watch
- Unrated
There are many in the government and our communities that are finally beginning to understand the serious implications of children using the Internet. There have been several attempts to manage the content that children see and they have failed for reasons of free speech and the inability to control the internationally operated Internet. The reality of Dateline’s “To Catch a Predator,” has caused a renewed effort to control the people that our children are exposed to as they surf the
Hacker Targeting U.S. Executives
- By Grey McKenzie
- Published 11/12/2007
- Cyber Security Industry Watch , Cyber Hackers
- Unrated
MYRTLE BEACH --
For months, a sophisticated hacker has been stealing the personal data of American corporate executives.Hot
on the hacker's trail is Joe Stewart. The former bass-guitarist-turned-cyber-sleuth stumbled onto the case in February.
Since then, the 36-year-old Stewart has spent weeks in his office, in a
nondescript building next to a half-abandoned strip mall here,
virtually chasing the mysterious perpetrator across several continents.
Stewart early on thought he had traced the scammer to China, then realized it was a false lead. Only when the perpetrator stumbled did Stewart get a break in the case.
How Online Crooks Cost Us Billions
- By Grey McKenzie
- Published 11/10/2007
- Cyber Security Industry Watch , Cyber Hackers , Cyber Security Identity Theft Watch
- Unrated
Somewhere in St. Petersburg, Russia's second city, a tiny start-up has struck Internet gold. Its dozen-odd employees are barely old enough to recall the demise of the Soviet Union, but industry analysts believe they're raking in well over $100 million a year from the world's largest banks, including Wells Fargo and Washington Mutual.
Their two-year rise might be the greatest success story of the former Eastern Bloc's high-tech boom - if only it weren't so illegal. But the cash may be coming from your bank account, and they could be using the computer in your den to commit their crimes.
Hacker Arrested On Spy Charges... Invited By Microsoft To Speak
- By Grey McKenzie
- Published 11/10/2007
- Cyber Security Industry Watch , Cyber Hackers
- Unrated
Preatoni is the founder of Wabisabilabi, a Switzerland-based company that bills itself as an auction site for the software bugs that companies like Microsoft never want anybody to see. He spoke at Microsoft in late September as an invited guest at Microsoft's semi-annual Blue Hat security conference.
But what had been an edgy invite by Microsoft's Blue Hat planners took on a new dimension this week, when Preatoni was arrested in Milan on charges relating to a national spying scandal at Telecom Italia, Italy's largest telephone carrier.FBI Director Robert Muellers "Net Threat Cyber Security Speech"
- By Grey McKenzie
- Published 11/8/2007
- Cyber Security Identity Theft Watch , Cyber Hackers , Cyber Security Industry Watch , Cyber Security Government Watch , Cyber Terrorism Watch
- Unrated
"If we lose the Internet, we do not simply lose the ability to
e-mail or to surf the Web. We lose access to our data. We lose our
connectivity. We lose our intellectual property. We lose our security.
Bot Nets... Audio Spam... Storm Worm... What's Next?
- By Grey McKenzie
- Published 11/7/2007
- Cyber Security Identity Theft Watch , Cyber Hackers , Cyber Security Industry Watch
- Unrated
If there were any questions that the current
generation of spammers and hackers have dug in for the long haul,
events in the past few weeks should eliminate them. Botnet operators
and spammers are continuing the evolution of their networks and
techniques to ensure that their messages continue to arrive in our
inboxes.
Bush Administration Preparing To Unveil a Major "Cyber Initiative"
- By Grey McKenzie
- Published 11/6/2007
- Cyber Terrorism Watch , Cyber Security Government Watch , Cyber Security Industry Watch
- Unrated
A recent denial-of-service attack on government and private sector computer systems in The Bush Administration is preparing to unveil a major "Cyber Initiative" designed to thwart malicious acts by states or transnational threats. Congress is pressing for details and consultation on the plan, and the House Homeland Security Committee recently announced the creation of a commission to study the government's proposals.
As these efforts get underway, Congress and the Administration need to ensure that their initiatives meet all of the nation's priorities: enhancing security, promoting economic growth, and preserving the liberty and privacy of American citizens and respecting those of our friends and allies.

Cyber Security Industry Watch