<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Michael Gracie &#187; malware</title>
	<atom:link href="http://michaelgracie.com/tag/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://michaelgracie.com</link>
	<description>Clever Tagline Unavailable At Publication Time</description>
	<pubDate>Tue, 02 Dec 2008 19:53:44 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>Subverted search sites lead to massive malware attack in progress</title>
		<link>http://michaelgracie.com/2007/12/02/subverted-search-sites-lead-to-massive-malware-attack-in-progress/</link>
		<comments>http://michaelgracie.com/2007/12/02/subverted-search-sites-lead-to-massive-malware-attack-in-progress/#comments</comments>
		<pubDate>Mon, 03 Dec 2007 04:04:31 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Notes]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[search results]]></category>

		<guid isPermaLink="false">http://michaelgracie.com/2007/12/02/subverted-search-sites-lead-to-massive-malware-attack-in-progress/</guid>
		<description><![CDATA[One of the many pitfalls of big, popular search indexes.
]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>One of the many <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9049269">pitfalls</a> of big, popular search indexes.</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2007/12/02/subverted-search-sites-lead-to-massive-malware-attack-in-progress/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Turn Gmail Into a Social Network Hub</title>
		<link>http://michaelgracie.com/2007/10/01/turn-gmail-into-a-social-network-hub/</link>
		<comments>http://michaelgracie.com/2007/10/01/turn-gmail-into-a-social-network-hub/#comments</comments>
		<pubDate>Mon, 01 Oct 2007 18:03:18 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Notes]]></category>

		<category><![CDATA[Gmail]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[social networks]]></category>

		<guid isPermaLink="false">http://michaelgracie.com/2007/10/01/turn-gmail-into-a-social-network-hub/</guid>
		<description><![CDATA[Yes, if you really want to parse your social network ever further online, you can engage Gmail for help.
Just keep an eye out for malware while you&#8217;re doing it.
]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>Yes, if you really want to parse your social network ever further online, you can <a href="http://www.micropersuasion.com/2007/09/looking-for-the.html">engage Gmail for help</a>.</p>
<p>Just keep an eye out for <a href="http://mashable.com/2007/09/28/gmail-malware-fixed/">malware</a> while you&#8217;re doing it.</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2007/10/01/turn-gmail-into-a-social-network-hub/feed/</wfw:commentRss>
		</item>
		<item>
		<title>StopBadware takes hold</title>
		<link>http://michaelgracie.com/2006/08/03/stopbadware-takes-hold/</link>
		<comments>http://michaelgracie.com/2006/08/03/stopbadware-takes-hold/#comments</comments>
		<pubDate>Thu, 03 Aug 2006 15:12:12 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Spamroll]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[search results]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/stopbadware-takes-hold/</guid>
		<description><![CDATA[StopBadware, the coalition of big names aiming to protect people from drive-by infections, is on the move.  Google is now integrating warnings into it&#8217;s search results.  Nice.
Google, a &#8220;crossing guard&#8221; for malware avoiders.  No telling what other members of StopBadware are doing, but I&#8217;ll guess Websense doesn&#8217;t care - they are now [...]]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>StopBadware, the <a title="Spamroll: Powerhouse Coalition To Fight Spyware With Publicity" href="http://www.michaelgracie.com/2006/01/25/powerhouse-coalition-to-fight-spyware-with-publicity/" target="">coalition of big names</a> aiming to protect people from drive-by infections, is on the move.  Google is <a title="Google Operating System: Malware Warnings on Google Search Results" href="http://googlesystem.blogspot.com/2006/08/malware-warnings-on-google-search.html" target="">now integrating warnings into it&#8217;s search results</a>.  Nice.</p>
<p>Google, a &#8220;crossing guard&#8221; for malware avoiders.  No telling what other members of StopBadware are doing, but I&#8217;ll guess <a title="Spamroll: Google digs deep, and Websense sifts the dirt" href="http://www.michaelgracie.com/2006/07/10/google-digs-deep-and-websense-sifts-the-dirt/" target="">Websense</a> doesn&#8217;t care - they are now someone&#8217;s likely acquisition target.</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2006/08/03/stopbadware-takes-hold/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Where social networks and web threats really clash</title>
		<link>http://michaelgracie.com/2006/08/02/where-social-networks-and-web-threats-really-clash/</link>
		<comments>http://michaelgracie.com/2006/08/02/where-social-networks-and-web-threats-really-clash/#comments</comments>
		<pubDate>Wed, 02 Aug 2006 15:00:22 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Spamroll]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[social network]]></category>

		<category><![CDATA[targeted attacks]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/where-social-networks-and-web-threats-really-clash/</guid>
		<description><![CDATA[With all the talk about social networks - the inherent safety issues of &#8220;going public,&#8221; the politics that won&#8217;t help, and the sneaky buggers taking advantage of the situation, we&#8217;ve forgotten to take a step back and see what might be headed this way so we can prepare.
You have some much in your face, but [...]]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>With all the talk about social networks - the <a title="Spamroll: The MySpace Hysteria" href="http://www.michaelgracie.com/2006/07/03/the-myspace-hysteria/" target="">inherent safety issues</a> of &#8220;going public,&#8221; the <a title="Spamroll: What MySpace fixes, politics breaks" href="http://www.michaelgracie.com/2006/07/28/what-myspace-fixes-politics-breaks/" target="">politics that won&#8217;t help</a>, and the <a title="Spamroll: MySpace sees increasing external threats" href="http://www.michaelgracie.com/2006/07/20/myspace-sees-increasing-external-threats/" target="">sneaky buggers taking advantage of the situation</a>, we&#8217;ve forgotten to take a step back and see what might be headed this way so we can prepare.</p>
<p>You have some much in your face, but what&#8217;s next?  Well, think about all those public profiles - a great way to develop dossiers.  Add the fact that there are groups of like-kind thinkers/feelers banding together for social interaction.  Throw in malicious code writers <a title="Hackers ramp up 'insidious' targeted attacks - vnunet.com" href="http://www.vnunet.com/vnunet/news/2161464/hackers-ramp-insidious-targeted" target="">ramping up targeted attacks</a>.</p>
<p>I say it&#8217;s a recipe for a big headache.</p>
<p>***UPDATE***</p>
<p>A new study <a title="Social sites a breeding ground for malware: report | The Register" href="http://www.theregister.co.uk/2006/08/10/social_sites_breed_malware/" target="">suggests the same</a>.</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2006/08/02/where-social-networks-and-web-threats-really-clash/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Virus writers now have a full toolbox</title>
		<link>http://michaelgracie.com/2006/07/18/virus-writers-now-have-a-full-toolbox/</link>
		<comments>http://michaelgracie.com/2006/07/18/virus-writers-now-have-a-full-toolbox/#comments</comments>
		<pubDate>Tue, 18 Jul 2006 15:21:46 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Spamroll]]></category>

		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/virus-writers-now-have-a-full-toolbox/</guid>
		<description><![CDATA[Just a few years back, malicious code writers were meeting in stealthy IRC chat rooms, exchanging ideas on obscure forums, and doing their thing just for fun (and notoriety).  Now, it is a money game, and in business you need efficiencies.
Couldn&#8217;t think of anything better to drive down time to market in the software [...]]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>Just a few years back, malicious code writers were meeting in stealthy IRC chat rooms, exchanging ideas on obscure forums, and doing their thing just for fun (and notoriety).  Now, it is a money game, and in business you need efficiencies.</p>
<p>Couldn&#8217;t think of anything better to drive down time to market in the software game than <a title="RED HERRING | Malware Turns to Open Source" href="http://www.redherring.com/article.aspx?a=17610" target="">going open source</a>, and that is exactly what malware technicians are doing.  They are leveraging tools like CVS to share code, and it wouldn&#8217;t surprise me if CVS and Subversion depositories start popping up all over the place.  But how will we know when that happens?</p>
<p>There are now <a title="Metasploit Creator Releases Malware Search Engine" href="http://www.eweek.com/article2/0,1895,1990158,00.asp" target="">malware search engines</a> as well.</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2006/07/18/virus-writers-now-have-a-full-toolbox/feed/</wfw:commentRss>
		</item>
		<item>
		<title>A blue pill cures all problems</title>
		<link>http://michaelgracie.com/2006/06/29/a-blue-pill-cures-all-problems/</link>
		<comments>http://michaelgracie.com/2006/06/29/a-blue-pill-cures-all-problems/#comments</comments>
		<pubDate>Thu, 29 Jun 2006 15:16:28 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Spamroll]]></category>

		<category><![CDATA[blue pill]]></category>

		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/a-blue-pill-cures-all-problems/</guid>
		<description><![CDATA[When you think of blue pills, you imagine tv ads by politicians, people who are bored with their partners, and people who can&#8217;t get enough of their partners.  You might also think of a lot of spam, due primarily to the previous points.  However, you&#8217;d likely never think a &#8220;blue pill&#8221; could hide [...]]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>When you think of blue pills, you imagine tv ads by politicians, people who are bored with their partners, and people who can&#8217;t get enough of their partners.  You might also think of a lot of spam, due primarily to the previous points.  However, you&#8217;d likely never think a &#8220;blue pill&#8221; could hide malware, completely undetectable, on your Windows computer, but that is exactly what a researcher in Singapore <a title="'Blue Pill' Prototype Creates 100% Undetectable Malware" href="http://www.eweek.com/article2/0,1759,1983037,00.asp?kc=EWRSS03119TX1K0000594" target="">has devised</a>.  I suspect the name was an afterthought.</p>
<p>I&#8217;d say its good to know that such things are possible ahead of time, so someone can devise a way of detecting the undetectable (always happens).  I&#8217;d also say I&#8217;m feeling pretty comfy sitting in at my desk right now - with one computer running OS X and the other running Fedora Core.</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2006/06/29/a-blue-pill-cures-all-problems/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Malware site just won&#8217;t die</title>
		<link>http://michaelgracie.com/2006/06/26/malware-site-just-wont-die/</link>
		<comments>http://michaelgracie.com/2006/06/26/malware-site-just-wont-die/#comments</comments>
		<pubDate>Mon, 26 Jun 2006 13:55:34 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Spamroll]]></category>

		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/malware-site-just-wont-die/</guid>
		<description><![CDATA[Despite all the &#8220;altruistic&#8221; services warning people of dangerous websites (via paid clients, of course), Jose Nazario has found one that just won&#8217;t die.  Note: various contributors are &#8220;ready to take action.&#8221;  I&#8217;d personally love to hear why action has been so absent for so long.
]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>Despite all the &#8220;altruistic&#8221; services warning people of dangerous websites (via paid clients, of course), Jose Nazario has <a title="The perpetual malware distribution site lives on | Spyware Confidential | ZDNet.com" href="http://blogs.zdnet.com/Spyware/?p=835" target="">found one that just won&#8217;t die</a>.  Note: various contributors are &#8220;ready to take action.&#8221;  I&#8217;d personally love to hear why action has been so absent for so long.</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2006/06/26/malware-site-just-wont-die/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The History of Malware (and more)</title>
		<link>http://michaelgracie.com/2006/06/14/the-history-of-malware-and-more/</link>
		<comments>http://michaelgracie.com/2006/06/14/the-history-of-malware-and-more/#comments</comments>
		<pubDate>Wed, 14 Jun 2006 14:09:54 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Spamroll]]></category>

		<category><![CDATA[history]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/the-history-of-malware-and-more/</guid>
		<description><![CDATA[Compliments of Sophos (pdf).
I love the introduction, where they say the whole thing about rumored slowing of threats (which never seems to happen).  Of course, take all reports of growing threats from security companies with a grain of salt - the same dose of incredulity you would apply to an operating system company saying [...]]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>Compliments of <a href="http://www.sophos.com/sophos/docs/eng/papers/Growing-threat-wpus.pdf">Sophos</a> (pdf).</p>
<p>I love the introduction, where they say the whole thing about rumored slowing of threats (which never seems to happen).  Of course, take all reports of growing threats from security companies with a grain of salt - the same dose of incredulity you would apply to an operating system company saying their software is safe and sound will do just fine.</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2006/06/14/the-history-of-malware-and-more/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Is your PC part of the walking dead?</title>
		<link>http://michaelgracie.com/2006/04/05/is-your-pc-part-of-the-walking-dead/</link>
		<comments>http://michaelgracie.com/2006/04/05/is-your-pc-part-of-the-walking-dead/#comments</comments>
		<pubDate>Wed, 05 Apr 2006 21:10:12 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Spamroll]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[zombie]]></category>

		<category><![CDATA[ZoneAlarm]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/is-your-pc-part-of-the-walking-dead/</guid>
		<description><![CDATA[You&#8217;ll never know if your PC has been zombified unless you check.  IT Observer gives you a few clues, but I will make it even simpler.
Install a free copy of the ZoneAlarm firewall (and turn off the Windows firewall for a bit as well).  Keep ZoneAlarm access messages on, and wait.  If [...]]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>You&#8217;ll never know if your PC has been zombified unless you check.  IT Observer <a href="http://www.ebcvg.com/articles/1100/how_do_know_if_my_pc_zombie/" target="">gives you a few clues</a>, but I will make it even simpler.</p>
<p>Install a <a title="Zone Labs: Download &#038; Buy" href="http://www.zonelabs.com/store/content/catalog/products/sku_list_za.jsp?dc=12bms&#038;ctry=&#038;lang=en&#038;lid=nav_za" target="">free copy of the ZoneAlarm firewall</a> (and turn off the Windows firewall for a bit as well).  Keep ZoneAlarm access messages on, and wait.  If you start seeing all kinds of popups coming from your taskbar, with no applications active, that is likely the zombie talking.  Those popups signify your computer trying to access the internet every which way from Sunday, with spamming and further infection attempts high on the priority list.</p>
<p>If you are an everyday joe, you can pick up some anti-virus tools to clean things up.  If you are a Microsoft executive, you just <a title="Spamroll: Microsoft throwing in the malware towel" href="http://www.michaelgracie.com/2006/04/04/microsoft-throwing-in-the-malware-towel/" target="">reformat your hard drive and start over</a>.</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2006/04/05/is-your-pc-part-of-the-walking-dead/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Spyware coalition on verge of breakthrough report</title>
		<link>http://michaelgracie.com/2006/03/22/spyware-coalition-on-verge-of-breakthrough-report/</link>
		<comments>http://michaelgracie.com/2006/03/22/spyware-coalition-on-verge-of-breakthrough-report/#comments</comments>
		<pubDate>Wed, 22 Mar 2006 14:35:00 +0000</pubDate>
		<dc:creator>Michael Gracie</dc:creator>
		
		<category><![CDATA[Spamroll]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[spyware]]></category>

		<category><![CDATA[stopbadware]]></category>

		<guid isPermaLink="false">http://www.michaelgracie.com/spyware-coalition-on-verge-of-breakthrough-report/</guid>
		<description><![CDATA[StopBadware.org, that coalition of smarties aiming to, uh, stop badware in its tracks, is about to release its first report.  This report is rumored to contain a doosie - that P2P file sharing software like Kazaa may contain spyware!
The group will recommend..
&#8220;that users stay away from Kazaa and three other programs that can be [...]]]></description>
			<content:encoded><![CDATA[<!-- sphereit start --><p>StopBadware.org, that <a title="Spamroll: Powerhouse Coalition To Fight Spyware With Publicity" href="http://www.michaelgracie.com/2006/01/25/powerhouse-coalition-to-fight-spyware-with-publicity/">coalition of smarties</a> aiming to, uh, stop badware in its tracks, is about to release its first report.  This report is rumored to contain a doosie - that <a title="Spyware Trail Leads to Kazaa, Big Advertisers" href="http://www.eweek.com/article2/0,1759,1940747,00.asp?kc=EWRSS03119TX1K0000594" target="">P2P file sharing software like Kazaa may contain spyware</a>!</p>
<p>The group will recommend..</p>
<blockquote><p><cite>&#8220;that users stay away from Kazaa and three other programs that can be combined with Trojans and bots for use in data theft attacks.&#8221;</cite></p></blockquote>
<p>Damn, am I glad those guys are around.  Who <a title="Kazaa spyware - Yahoo! Search Results" href="http://search.yahoo.com/search?_adv_prop=web&#038;x=op&#038;ei=UTF-8&#038;fr=FP-tab-web-t&#038;va=Kazaa+spyware&#038;va_vt=any&#038;vp_vt=any&#038;vo_vt=any&#038;ve_vt=any&#038;vd=all&#038;vst=0&#038;vf=all&#038;vm=i&#038;fl=0&#038;n=10" target="">would of thought</a>?<br />
<span id="more-1097"></span><br />
***UPDATE***</p>
<p>For those interested, the cadre of intellectuals has <a title="The Chronicle: Wired Campus Blog: A Few Bad Actors" href="http://chronicle.com/wiredcampus/article/1117/a-few-bad-apples" target="">three other programs on their list</a> as well.  That is four whole programs that distribute spyware!</p>
<p>Would some safety prone Windows user please tell me how many programs are in a Webroot DAT file?</p>
<!-- sphereit end -->]]></content:encoded>
			<wfw:commentRss>http://michaelgracie.com/2006/03/22/spyware-coalition-on-verge-of-breakthrough-report/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
