<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>certifiedbug.com</title>
	
	<link>http://certifiedbug.com/blog</link>
	<description>Consumer Security on the web, information to assist you in practicing safe computing</description>
	<pubDate>Wed, 19 Nov 2008 22:18:59 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
	<language>en</language>
			<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by-nc-sa/3.0/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/Certifiedbugcom" type="application/rss+xml" /><feedburner:emailServiceId>1175433</feedburner:emailServiceId><feedburner:feedburnerHostname>http://www.feedburner.com</feedburner:feedburnerHostname><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2FCertifiedbugcom" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FCertifiedbugcom" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2FCertifiedbugcom" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.rojo.com/add-subscription?resource=http%3A%2F%2Ffeeds.feedburner.com%2FCertifiedbugcom" src="http://blog.rojo.com/RojoWideRed.gif">Subscribe with Rojo</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/Certifiedbugcom" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FCertifiedbugcom" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FCertifiedbugcom" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FCertifiedbugcom" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:browserFriendly>Thank you for visiting my blog.</feedburner:browserFriendly><item>
		<title>Keylogger vendor CyberSpy under temporary restraining order</title>
		<link>http://certifiedbug.com/blog/2008/11/19/keylogger-vendor-cyberspy-under-temporary-restraining-order/</link>
		<comments>http://certifiedbug.com/blog/2008/11/19/keylogger-vendor-cyberspy-under-temporary-restraining-order/#comments</comments>
		<pubDate>Wed, 19 Nov 2008 22:18:59 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[FTC]]></category>

		<category><![CDATA[Program]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=1536</guid>
		<description><![CDATA[Federal Trade Commission
Court Orders Halt to Sale of Spyware
At the request of the Federal Trade Commission, a U.S. District Court has issued a temporary restraining order halting the sale of keylogger spyware. According to the FTC’s complaint, the Florida-based CyberSpy Software, LLC marketed and sold RemoteSpy keylogger spyware to clients who would then secretly monitor [...]]]></description>
			<content:encoded><![CDATA[<p>Federal Trade Commission</p>
<blockquote><p>Court Orders Halt to Sale of Spyware</p>
<p>At the request of the Federal Trade Commission, a U.S. District Court has issued a temporary restraining order halting the sale of keylogger spyware. According to the FTC’s complaint, the Florida-based CyberSpy Software, LLC marketed and sold RemoteSpy keylogger spyware to clients who would then secretly monitor unsuspecting consumers’ computers. The FTC seeks to permanently bar the unfair and deceptive practices and require the defendants to give up their ill-gotten gains.</p>
<p>According to papers filed with the court, the defendants provided RemoteSpy clients with detailed instructions explaining how to disguise the spyware as an innocuous file, such as a photo, attached to an email. When consumer victims clicked on the disguised file, the keylogger spyware silently installed in the background without the victims’ knowledge. This spyware recorded every keystroke typed on the victim’s computer (including passwords); captured images of the computer screen; and recorded Web sites visited. </p></blockquote>
<p>News Release: <a href="http://ftc.gov/opa/2008/11/cyberspy.shtm">http://ftc.gov/opa/2008/11/cyberspy.shtm</a></p>
<p>Original FTC <a href="http://ftc.gov/os/caselist/0823160/081105cyberspycmplt.pdf">complaint</a>. (PDF) November 5, 2008.</p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>
</p>
<p><a href="http://certifiedbug.com/blog/2008/11/19/keylogger-vendor-cyberspy-under-temporary-restraining-order/">Keylogger vendor CyberSpy under temporary restraining order</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=0F0XN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=0F0XN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=orCSN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=orCSN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=AI8gN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=AI8gN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=WQpiN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=WQpiN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=swbUn"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=swbUn" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2008/11/19/keylogger-vendor-cyberspy-under-temporary-restraining-order/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Peer-to-peer (P2P) botnets</title>
		<link>http://certifiedbug.com/blog/2008/11/19/peer-to-peer-p2p-botnets/</link>
		<comments>http://certifiedbug.com/blog/2008/11/19/peer-to-peer-p2p-botnets/#comments</comments>
		<pubDate>Wed, 19 Nov 2008 21:30:04 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Botnet]]></category>

		<category><![CDATA[P2P]]></category>

		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=1533</guid>
		<description><![CDATA[Internet providers can pull the plug on botnets, even if it comes belatedly under pressure from the security community and newpaper articles. We have seen this with the recent take downs of Atrivo-Intercage, Est, McColo, where the bad stuff flowed from central servers.
Brian Krebs at The Washington Post, So Much Spam From One Place?
Vincent Weafer, [...]]]></description>
			<content:encoded><![CDATA[<p>Internet providers can pull the plug on botnets, even if it comes belatedly under pressure from the security community and newpaper articles. We have seen this with the recent take downs of Atrivo-Intercage, Est, McColo, where the bad stuff flowed from central servers.</p>
<p>Brian Krebs at The Washington Post, <a href="http://voices.washingtonpost.com/securityfix/2008/11/so_much_spam_from_one_place.html">So Much Spam From One Place?</a></p>
<blockquote><p>Vincent Weafer, director of development for Symantec Security Response, said the success of Storm, combined with so many criminal operations having been burned by the McColo takedown, strongly suggests botnets are going to continue adopting P2P technology.</p></blockquote>
<p>That means decentralization.</p>
<p>The Recording Industry Association of America (RIAA) may get an earful. </p>
<p>Also at the Washington Post:<br />
<a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/11/18/AR2008111801120.html?hpid=topnews&#038;sid=ST2008111801165&#038;s_pos=">Answers Trickle Out as Spammer Networks Remain Compromised</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>
</p>
<p><a href="http://certifiedbug.com/blog/2008/11/19/peer-to-peer-p2p-botnets/">Peer-to-peer (P2P) botnets</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=RcAiN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=RcAiN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=BXWiN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=BXWiN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=JLqDN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=JLqDN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=grbzN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=grbzN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=qyGUn"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=qyGUn" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2008/11/19/peer-to-peer-p2p-botnets/feed/</wfw:commentRss>
		</item>
		<item>
		<title>McColo. Exploiting un-vetted bandwidth reselling</title>
		<link>http://certifiedbug.com/blog/2008/11/18/mccolo-exploiting-un-vetted-bandwidth-reselling/</link>
		<comments>http://certifiedbug.com/blog/2008/11/18/mccolo-exploiting-un-vetted-bandwidth-reselling/#comments</comments>
		<pubDate>Wed, 19 Nov 2008 00:52:23 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Botnet]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[McColo]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=1527</guid>
		<description><![CDATA[McColo, estimated to host the command-and-control servers for at least five large botnets, briefly regained connectivity Saturday for approximately 12-24 hours.
This happened after a Los Angeles-based reseller named Giglinx sold bandwidth from the Swedish internet service provider TeliaSonera to the bad guys.
The reconnection opened the door, enabling a partial update of the botnet and pushing [...]]]></description>
			<content:encoded><![CDATA[<p>McColo, estimated to host the command-and-control servers for at least five large botnets, briefly regained connectivity Saturday for approximately 12-24 hours.</p>
<p>This happened after a Los Angeles-based reseller named Giglinx sold bandwidth from the Swedish internet service provider TeliaSonera to the bad guys.</p>
<p>The reconnection opened the door, enabling a partial update of the botnet and pushing as much as 15MB of data per second to servers located in Russia, before Telia quickly pulled the plug.</p>
<p>Jart Armin &amp; Paul Ferguson.<br />
Report Supplement; <a href="http://hostexploit.com/downloads/Hostexploit_McColo_supplement_111808.pdf">McColo – Exploiting the security flaw in un-vetted bandwidth reselling Version 2.1 Nov 18th 08</a> (PDF)</p>
<p>Host Expoit also has a video presentation mapping McColo&#8217;s attempt to reconnect to the internet November 15/16 2008.<br />
<a href="http://hostexploit.com/index.php?option=com_content&amp;view=article&amp;id=25&amp;Itemid=34">http://hostexploit.com/index.php?option=com_content&amp;view=article&amp;id=25&amp;Itemid=34</a></p>
<p>FireEye Malware Intelligence Lab&#8217;s blog has a map showing the masses of Srizbi Bots.<br />
<a href="http://blog.fireeye.com/research/2008/11/not-to-sound-the-panic-alarm.html#more">http://blog.fireeye.com/research/2008/11/not-to-sound-the-panic-alarm.html#more</a></p>
<p>http://certifiedbug.com/blog/tag/mccolo/</p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>
</p>
<p><a href="http://certifiedbug.com/blog/2008/11/18/mccolo-exploiting-un-vetted-bandwidth-reselling/">McColo. Exploiting un-vetted bandwidth reselling</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=GZQKN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=GZQKN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=eb7hN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=eb7hN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=oUGHN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=oUGHN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=X4jSN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=X4jSN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=kgRrn"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=kgRrn" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2008/11/18/mccolo-exploiting-un-vetted-bandwidth-reselling/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Windows Live OneCare to be replaced by “Morro”</title>
		<link>http://certifiedbug.com/blog/2008/11/18/windows-live-onecare-to-be-replaced-by-morro/</link>
		<comments>http://certifiedbug.com/blog/2008/11/18/windows-live-onecare-to-be-replaced-by-morro/#comments</comments>
		<pubDate>Tue, 18 Nov 2008 22:55:24 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
		
		<category><![CDATA[Microsoft]]></category>

		<category><![CDATA[Program]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=1524</guid>
		<description><![CDATA[According to the press release “Morro” will have a smaller footprint and be lighter on computing resources than OneCare.
A big difference for users is that it will be a free stand-alone download, no charge to consumers.
Windows Live OneCare will continue to be sold for Windows XP and Windows Vista at retail through June 30, 2009. [...]]]></description>
			<content:encoded><![CDATA[<p>According to the press release “Morro” will have a smaller footprint and be lighter on computing resources than OneCare.</p>
<p>A big difference for users is that it will be a free stand-alone download, no charge to consumers.</p>
<blockquote><p>Windows Live OneCare will continue to be sold for Windows XP and Windows Vista at retail through June 30, 2009. Direct sales of OneCare will be gradually phased out when “Morro” becomes available. Regardless of their method of purchase, Microsoft will ensure that all current customers remain protected through the life of their subscriptions.</p></blockquote>
<p>PressPass:<br />
<a href="http://www.microsoft.com/presspass/press/2008/nov08/11-18NoCostSecurityPR.mspx">Microsoft Announces Plans for No-Cost Consumer Security Offering</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>
</p>
<p><a href="http://certifiedbug.com/blog/2008/11/18/windows-live-onecare-to-be-replaced-by-morro/">Windows Live OneCare to be replaced by &#8220;Morro&#8221;</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=tGPIN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=tGPIN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=Um0EN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=Um0EN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=gyoJN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=gyoJN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=dU1IN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=dU1IN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=cWnDn"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=cWnDn" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2008/11/18/windows-live-onecare-to-be-replaced-by-morro/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Spamhaus remarks on McColo</title>
		<link>http://certifiedbug.com/blog/2008/11/17/spamhaus-remarks-on-mccolo/</link>
		<comments>http://certifiedbug.com/blog/2008/11/17/spamhaus-remarks-on-mccolo/#comments</comments>
		<pubDate>Mon, 17 Nov 2008 17:23:26 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Botnet]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[McColo]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=1519</guid>
		<description><![CDATA[Spamhaus.

McColo is a bit different from Intercage/Atrivo in that although the IP addresses were from the N. American registry ARIN, were routed in the US, and the company used US postal addresses, the person or persons controlling the operation are based in Moscow, Russia. 
We recommend anyone who saw more than a 30% reduction look [...]]]></description>
			<content:encoded><![CDATA[<p>Spamhaus.</p>
<blockquote><p>
McColo is a bit different from Intercage/Atrivo in that although the IP addresses were from the N. American registry ARIN, were routed in the US, and the company used US postal addresses, the person or persons controlling the operation are based in Moscow, Russia. </p></blockquote>
<blockquote><p>We recommend anyone who saw more than a 30% reduction look into employing some sort of SMTP connection filtering as this drop in botnet spam, nice as it is, will not last. Investigators report that many of the C&#038;C servers at McColo were originally hosted at Intercage/Atrivo. Even now, several of the C&#038;C functions are migrating to hosting closer to the homes of the botmasters: Russia. </p></blockquote>
<p>Complete article: <a href="http://www.spamhaus.org/news.lasso?article=640">Another one bytes the dust</a></p>
<p>Certifiedbug, November 13, 2008. <a href="http://certifiedbug.com/blog/2008/11/13/mccolo-on-the-move/">McColo on the move?</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>
</p>
<p><a href="http://certifiedbug.com/blog/2008/11/17/spamhaus-remarks-on-mccolo/">Spamhaus remarks on McColo</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=rSsIN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=rSsIN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=b27CN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=b27CN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=y00lN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=y00lN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=pdA9N"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=pdA9N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=rxbdn"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=rxbdn" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2008/11/17/spamhaus-remarks-on-mccolo/feed/</wfw:commentRss>
		</item>
		<item>
		<title>AVG Flags Adobe Flash</title>
		<link>http://certifiedbug.com/blog/2008/11/14/avg-flags-adobe-flash/</link>
		<comments>http://certifiedbug.com/blog/2008/11/14/avg-flags-adobe-flash/#comments</comments>
		<pubDate>Sat, 15 Nov 2008 00:42:47 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
		
		<category><![CDATA[Programs]]></category>

		<category><![CDATA[Program]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=1516</guid>
		<description><![CDATA[Less than a week after crippling non-english versions of Windows XP with a flawed update, AVG&#8217;s latest update of their suite is flagging Adobe Flash as potentially malicious.
Some might say that&#8217;s not too far from the truth  but the detection is a false positive. The Register
Certifiedbug, November 11, 2008. AVG update removed critical Windows [...]]]></description>
			<content:encoded><![CDATA[<p>Less than a week after crippling non-english versions of Windows XP with a flawed update, AVG&#8217;s latest update of their suite is flagging Adobe Flash as potentially malicious.</p>
<p>Some might say that&#8217;s not too far from the truth <img src='http://certifiedbug.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> but the detection is a false positive. <a href="http://www.theregister.co.uk/2008/11/14/avg_false_positive_flash/">The Register</a></p>
<p>Certifiedbug, November 11, 2008. <a href="http://certifiedbug.com/blog/2008/11/11/avg-update-removed-critical-windows-file/">AVG update removed critical Windows file</a></p>
<p>Certifiedbug, November 5, 2008. <a href="http://certifiedbug.com/blog/2008/11/05/adobe-flash-player-update-for-clickjacking-vulnerability/">Adobe Flash Player update for Clickjacking vulnerability</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>
</p>
<p><a href="http://certifiedbug.com/blog/2008/11/14/avg-flags-adobe-flash/">AVG Flags Adobe Flash</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=TBv0N"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=TBv0N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=TktyN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=TktyN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=8861N"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=8861N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=UKcRN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=UKcRN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=CnLDn"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=CnLDn" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2008/11/14/avg-flags-adobe-flash/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Thunderbird 2.0.0.17 released</title>
		<link>http://certifiedbug.com/blog/2008/11/14/thunderbird-20018-released/</link>
		<comments>http://certifiedbug.com/blog/2008/11/14/thunderbird-20018-released/#comments</comments>
		<pubDate>Fri, 14 Nov 2008 21:13:23 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
		
		<category><![CDATA[Programs]]></category>

		<category><![CDATA[Program]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Thunderbird]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=1509</guid>
		<description><![CDATA[Security Advisory
Two Critical Five Moderate.
MFSA 2008-46 Heap overflow when canceling newsgroup message
MFSA 2008-44 resource: traversal vulnerabilities
MFSA 2008-43 BOM characters stripped from JavaScript before execution
MFSA 2008-42 Crashes with evidence of memory corruption (rv:1.9.0.2/1.8.1.17)
MFSA 2008-41 Privilege escalation via XPCnativeWrapper pollution
MFSA 2008-38 nsXMLDocument::OnChannelRedirect() same-origin violation
MFSA 2008-37 UTF-8 URL stack buffer overflow
Thunderbird 2.0.0.17 Download
Certifiedbug.com

Thunderbird 2.0.0.17 released
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.mozilla.org/security/known-vulnerabilities/thunderbird20.html">Security Advisory</a></p>
<p>Two <span style="color: #ff0000;">Critical</span> Five <span style="color: #9dce0a;"><span style="color: #339966;">Moderate</span>.</span></p>
<p><span style="color: #ff0000;">MFSA 2008-46 </span>Heap overflow when canceling newsgroup message<br />
<span style="color: #339966;">MFSA 2008-44</span><span style="color: #339966;"> </span>resource: traversal vulnerabilities<br />
<span style="color: #339966;">MFSA 2008-43 </span>BOM characters stripped from JavaScript before execution<br />
<span style="color: #339966;">MFSA 2008-42</span> Crashes with evidence of memory corruption (rv:1.9.0.2/1.8.1.17)<br />
<span style="color: #339966;">MFSA 2008-41</span> Privilege escalation via XPCnativeWrapper pollution<br />
<span style="color: #68d20e;"><span style="color: #339966;">MFSA 2008-38</span> </span>nsXMLDocument::OnChannelRedirect() same-origin violation<br />
<span style="color: #ff0000;">MFSA 2008-37</span> UTF-8 URL stack buffer overflow</p>
<p>Thunderbird 2.0.0.17 <a href="http://www.mozilla.com/en-US/thunderbird/all.html">Download</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>
</p>
<p><a href="http://certifiedbug.com/blog/2008/11/14/thunderbird-20018-released/">Thunderbird 2.0.0.17 released</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=oe4bN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=oe4bN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=M0uHN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=M0uHN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=d4V8N"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=d4V8N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=4nvRN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=4nvRN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=FDJGn"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=FDJGn" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2008/11/14/thunderbird-20018-released/feed/</wfw:commentRss>
		</item>
		<item>
		<title>McColo on the move?</title>
		<link>http://certifiedbug.com/blog/2008/11/13/mccolo-on-the-move/</link>
		<comments>http://certifiedbug.com/blog/2008/11/13/mccolo-on-the-move/#comments</comments>
		<pubDate>Thu, 13 Nov 2008 21:58:16 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Botnet]]></category>

		<category><![CDATA[Malware]]></category>

		<category><![CDATA[McColo]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=1501</guid>
		<description><![CDATA[This still shows.
CIDR Report for AS26780
26780 MCCOLO - McColo Corporation
Adjacency: 1 Upstream: 1 Downstream: 0
Upstream Adjacent AS list
AS3549 GBLX Global Crossing Ltd.
Steve Linford from Spamhaus responding to a topic at Google Groups,
McColo Corp 
Andreas Kohlbach wrote:
&#62; Mccolo will (under a different name) find a new peer at some
&#62; point, or already has, and in a [...]]]></description>
			<content:encoded><![CDATA[<p>This still shows.</p>
<p>CIDR Report for AS26780<br />
26780 MCCOLO - McColo Corporation<br />
Adjacency: 1 Upstream: 1 Downstream: 0<br />
Upstream Adjacent AS list<br />
AS3549 GBLX Global Crossing Ltd.</p>
<p><a href="http://en.wikipedia.org/wiki/Steve_Linford">Steve Linford</a> from Spamhaus <a href="http://groups.google.com/group/news.admin.net-abuse.email/msg/0e261cced211a267">responding </a>to a topic at Google Groups,<br />
<a href="http://groups.google.com/group/news.admin.net-abuse.email/browse_thread/thread/54d7df6cb854268a/0e261cced211a267?#0e261cced211a267">McColo Corp </a></p>
<blockquote><p>Andreas Kohlbach wrote:</p>
<p>&gt; Mccolo will (under a different name) find a new peer at some<br />
&gt; point, or already has, and in a couple of hours or days all is back where<br />
&gt; it was.</p>
<p>They already have, McColo are now coming back up on retn.net (AKA<br />
Eltel, the old timers will remember that name, a very dirty Russian<br />
network well known for hosting spammers and malware).</p>
<p>Which is a pity, as spam volumes dropped by 30% after McColo went off<br />
the net late Tuesday as vast amounts of bots could no longer contact<br />
their control boxes on McColo IPs and whole botnets went dark. Eltel<br />
(retn.net) will be reactivating the McColo IPs anytime now allowing<br />
the botnets to contact their masters and the spam will flow again.</p>
<p>Spamhaus is preparing to SBL Eltel (retn.net) as soon as we have<br />
confirmation that they have brought McColo&#8217;s botnet control machines<br />
back on line.</p>
<p>Steve Linford<br />
The Spamhaus Project<br />
http://www.spamhaus.org</p></blockquote>
<p><em>Update</em>s<br />
Washington Post, <a href="http://voices.washingtonpost.com/securityfix/2008/11/the_badness_that_was_mccolo.html?nav=rss_blog">A Closer Look at McColo</a></p>
<p>TRACE Blog<br />
<a href="http://www.marshal.com/trace/traceitem.asp?article=816&amp;thesection=trace">Srizbi Stopped, for now</a></p>
<p>FireEye Malware Intelligence Lab<br />
<a href="http://blog.fireeye.com/research/2008/11/index.html">http://blog.fireeye.com/research/2008/11/index.html</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>
</p>
<p><a href="http://certifiedbug.com/blog/2008/11/13/mccolo-on-the-move/">McColo on the move?</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=WKOUN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=WKOUN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=9s8mN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=9s8mN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=edFiN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=edFiN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=zrSrN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=zrSrN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=FLBwn"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=FLBwn" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2008/11/13/mccolo-on-the-move/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firefox 3.0.4 Released</title>
		<link>http://certifiedbug.com/blog/2008/11/13/firefox-v304-released/</link>
		<comments>http://certifiedbug.com/blog/2008/11/13/firefox-v304-released/#comments</comments>
		<pubDate>Thu, 13 Nov 2008 19:23:53 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
		
		<category><![CDATA[Browser]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=1496</guid>
		<description><![CDATA[Mozilla has updated Firefox to version 3.0.4, fixing nine security holes.
Four Critical Two High Two Moderate One Low
MFSA 2008-58  Parsing error in E4X default namespace
MFSA 2008-57 -moz-binding property bypasses security checks on codebase principals
MFSA 2008-56 nsXMLHttpRequest::NotifyEventListeners() same-origin violation
MFSA 2008-55 Crash and remote code execution in nsFrameManager
MFSA 2008-54 Buffer overflow in http-index-format parser
MFSA 2008-53 XSS [...]]]></description>
			<content:encoded><![CDATA[<p>Mozilla has updated Firefox to version 3.0.4, fixing nine security holes.</p>
<p>Four <span style="color: #ff0000;">Critical</span> Two <span style="color: #f3710b;">High</span> Two <span style="color: #339966;">Moderate</span> One Low</p>
<p>MFSA 2008-58  Parsing error in E4X default namespace<br />
<span style="color: #ff6600;">MFSA 2008-57 </span>-moz-binding property bypasses security checks on codebase principals<br />
<span style="color: #ff6600;">MFSA 2008-56</span> nsXMLHttpRequest::NotifyEventListeners() same-origin violation<br />
<span style="color: #ff0000;">MFSA 2008-55</span> Crash and remote code execution in nsFrameManager<br />
<span style="color: #ff0000;">MFSA 2008-54 </span>Buffer overflow in http-index-format parser<br />
<span style="color: #ff0000;">MFSA 2008-53</span> XSS and JavaScript privilege escalation via session restore<br />
<span style="color: #ff0000;">MFSA 2008-52</span> Crashes with evidence of memory corruption (rv:1.9.0.4/1.8.1.18)<br />
<span style="color: #008000;"><span style="color: #339966;">MFSA 2008-51</span> </span>file: URIs inherit chrome privileges when opened from chrome<br />
<span style="color: #008000;"><span style="color: #339966;">MFSA 2008-47</span> </span>Information stealing via local shortcut files</p>
<p><a href="http://www.mozilla.org/security/known-vulnerabilities/firefox30.html#firefox3.0.4">Security Advisories</a></p>
<p>Firefox v3.0.4 <a href=" http://www.mozilla.com/firefox/all.html"> Download</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>
</p>
<p><a href="http://certifiedbug.com/blog/2008/11/13/firefox-v304-released/">Firefox 3.0.4 Released</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=qn1KN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=qn1KN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=3n3RN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=3n3RN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=gJw9N"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=gJw9N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=MLQAN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=MLQAN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=HeGOn"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=HeGOn" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2008/11/13/firefox-v304-released/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Registrar EstDomains Stay of Termination lifted</title>
		<link>http://certifiedbug.com/blog/2008/11/13/registrar-estdomains-stay-of-termination-lifted/</link>
		<comments>http://certifiedbug.com/blog/2008/11/13/registrar-estdomains-stay-of-termination-lifted/#comments</comments>
		<pubDate>Thu, 13 Nov 2008 07:05:16 +0000</pubDate>
		<dc:creator>certifiedbug</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Botnet]]></category>

		<category><![CDATA[EstDomains]]></category>

		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://certifiedbug.com/blog/?p=1490</guid>
		<description><![CDATA[ICANN: http://www.icann.org/en/announcements/announcement-12nov08-en.htm
The termination of ICANN-accredited registrar EstDomains is to go ahead, effective 24 November 2008. 
Letter to EstDomains concerning decision to proceed with termination:
http://www.icann.org/correspondence/burnette-to-poltev-07nov08-en.pdf [PDF]
The notice of primary contact change recently sent to ICANN’s Brussels office is not compliant with the requirements of the RAA and is not an effective notice of primary contact change. [...]]]></description>
			<content:encoded><![CDATA[<p>ICANN: <a href="http://www.icann.org/en/announcements/announcement-12nov08-en.htm">http://www.icann.org/en/announcements/announcement-12nov08-en.htm</a></p>
<blockquote><p>The termination of ICANN-accredited registrar EstDomains is to go ahead, effective 24 November 2008. </p></blockquote>
<p>Letter to EstDomains concerning decision to proceed with termination:<br />
<a href="http://www.icann.org/correspondence/burnette-to-poltev-07nov08-en.pdf ">http://www.icann.org/correspondence/burnette-to-poltev-07nov08-en.pdf </a>[PDF]</p>
<blockquote><p>The notice of primary contact change recently sent to ICANN’s Brussels office is not compliant with the requirements of the RAA and is not an effective notice of primary contact change. Until notice of primary contact change is received at ICANN’s address above, ICANN’s records will continue to reflect that Mr. Vladimir Tsastsin is the primary contact for EstDomains, Inc.</p></blockquote>
<p>Certifiedbug, October 30, 2008. <a href="http://certifiedbug.com/blog/2008/10/30/icann-stays-estdomains-notice-of-termination/">ICANN Stays EstDomains Notice of Termination</a></p>
<p>Certifiedbug, October 29, 2008. <a href="http://certifiedbug.com/blog/2008/10/29/icann-cans-estdomains-inc/">ICANN cans EstDomains, Inc.</a></p>
<p><a href="http://certifiedbug.com/blog/">Certifiedbug.com</a>
</p>
<p><a href="http://certifiedbug.com/blog/2008/11/13/registrar-estdomains-stay-of-termination-lifted/">Registrar EstDomains Stay of Termination lifted</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=eOHKN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=eOHKN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=NvMjN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=NvMjN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=OIJLN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=OIJLN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=Q56WN"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=Q56WN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Certifiedbugcom?a=oxxsn"><img src="http://feeds.feedburner.com/~f/Certifiedbugcom?i=oxxsn" border="0"></img></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://certifiedbug.com/blog/2008/11/13/registrar-estdomains-stay-of-termination-lifted/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
