<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Ignorance Is Bliss</title>
	<atom:link href="http://mitmwatcher.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://mitmwatcher.wordpress.com</link>
	<description>Security is Illusion</description>
	<lastBuildDate>Mon, 07 Jul 2008 15:07:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='mitmwatcher.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Ignorance Is Bliss</title>
		<link>http://mitmwatcher.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://mitmwatcher.wordpress.com/osd.xml" title="Ignorance Is Bliss" />
	<atom:link rel='hub' href='http://mitmwatcher.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Security Karma&#8230;</title>
		<link>http://mitmwatcher.wordpress.com/2007/06/21/security-karma/</link>
		<comments>http://mitmwatcher.wordpress.com/2007/06/21/security-karma/#comments</comments>
		<pubDate>Thu, 21 Jun 2007 15:30:10 +0000</pubDate>
		<dc:creator>mitmwatcher</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[usability]]></category>

		<guid isPermaLink="false">http://mitmwatcher.wordpress.com/2007/06/21/security-karma/</guid>
		<description><![CDATA[Recent reports suggest that security Industry expects lot from Users and Designers compared to other Industries and thats the cause of all evil .. as a rephrased quote goes &#8220;Uncertainty and expectation are the root causes of Security failure&#8220;. What NOT to Expect from Users: 1)Install Browser Toolbars/Pulgins 2)Verify/Check Security Locks,Indicators,Certificates,Extended Validations. 3)Not to click,download [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mitmwatcher.wordpress.com&amp;blog=1222634&amp;post=6&amp;subd=mitmwatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:justify;"><img src="http://mitmwatcher.files.wordpress.com/2007/06/security-karma.jpg?w=389&#038;h=274" align="top" height="274" width="389" /></p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">Recent <a href="http://www.gnn.gov.uk/environment/fullDetail.asp?ReleaseID=292275&amp;NewsAreaID=2&amp;NavigatedFromDepartment=False" target="_blank">reports</a> suggest that security Industry expects lot from Users and Designers compared to other Industries and thats the cause of all evil .. as a rephrased quote goes &#8220;<b><i>Uncertainty and expectation are the root causes of  Security failure</i></b>&#8220;.</p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">                                   <b>What NOT to Expect from Users:</b></p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">1)Install Browser <a href="https://addons.mozilla.org/en-US/firefox/search?q=phishing&amp;status=4" target="_blank">Toolbars/Pulgins</a></p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">2)Verify/Check Security Locks,Indicators,Certificates,<a href="http://en.wikipedia.org/wiki/Extended_Validation_Certificate">Extended Validations.</a></p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">3)Not to click,download links and attachments sent in Email,IMs.</p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">4)Install latest updates,maintain clean hygiene of the system.</p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">5)Use the same PC for watching P0rn(at least sandbox p0rn..) and sensitive transactions.</p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">6)Not to<a href="http://www.microsoft.com/uk/businesscentral/newsletters/bulletins/stay-safe-with-strong-passwords.mspx"> Share/write</a><a href="http://www.microsoft.com/uk/businesscentral/newsletters/bulletins/stay-safe-with-strong-passwords.mspx">  t</a>heir password with <a href="http://news.scotsman.com/glasgow.cfm?id=929632007">friends,coworkers</a> and change their password at least every month.</p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">7)Not to call the VP/CEO for a small(amount) breach in their account after all its hard earned money..</p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">8)Use Strong ,different  passwords  for different accounts.</p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">9)Identify XSS,Html,JS Injections by checking/blocking sources of the pages.</p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">10)To change their browsing  habits</p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">11)Not to use <a href="http://www.first.org/newsroom/globalsecurity/119925.html">laptops</a>,CD,DVD,<a href="http://www.first.org/newsroom/globalsecurity/119764.html">USB</a> to store sensitive data without protection(Encryption).</p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;"><b>                             What NOT  to Expect from Security people:</b></p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">1)Not to use a homegrown implementation of well-known cryptographic algorithms or design/implement a home grown crypto algorithm.</p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">2)Plan for protocol flaws,unexpected errors and multiple protection mechanisms failing or  being bypassed.</p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">3)Externalize client side components from trust model as its not very difficult to prevent algorithm,key,data recovery when the attacker has full access to the client software, device.</p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">4)Use multiple layers of protection whenever possible and adding  detection and logging at every layer.</p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">5)Compartmentalize  data in such a way that a breach will not escalate to other   compartments.</p>
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">
<div style="text-align:justify;"> </div>
<p style="text-align:justify;">6)Design hardware crypto  considering  economics of the attack(time,money,skillset) and the life expectancy of the product</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mitmwatcher.wordpress.com/6/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mitmwatcher.wordpress.com/6/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mitmwatcher.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mitmwatcher.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mitmwatcher.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mitmwatcher.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mitmwatcher.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mitmwatcher.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mitmwatcher.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mitmwatcher.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mitmwatcher.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mitmwatcher.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mitmwatcher.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mitmwatcher.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mitmwatcher.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mitmwatcher.wordpress.com/6/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mitmwatcher.wordpress.com&amp;blog=1222634&amp;post=6&amp;subd=mitmwatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://mitmwatcher.wordpress.com/2007/06/21/security-karma/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9aa34e1a354800a0e8158ef7b9129355?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mitmwatcher</media:title>
		</media:content>

		<media:content url="http://mitmwatcher.files.wordpress.com/2007/06/security-karma.jpg" medium="image" />
	</item>
		<item>
		<title>Business Plan for a  Phishing 2.0 Startup:</title>
		<link>http://mitmwatcher.wordpress.com/2007/06/14/business-plan-for-a-phishing-20-startup/</link>
		<comments>http://mitmwatcher.wordpress.com/2007/06/14/business-plan-for-a-phishing-20-startup/#comments</comments>
		<pubDate>Thu, 14 Jun 2007 21:01:51 +0000</pubDate>
		<dc:creator>mitmwatcher</dc:creator>
				<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://mitmwatcher.wordpress.com/2007/06/14/business-plan-for-a-phishing-20-startup/</guid>
		<description><![CDATA[Problem : Around 55 million people or 44% of internet users do online banking and recent Emperor (Read Gartner) report say 96% of users does not understand security or confused by the goofy methods security vendors provide. The Solution: Phishing 2.0 provides all in one toolkit to cover all types of client side and channel [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mitmwatcher.wordpress.com&amp;blog=1222634&amp;post=4&amp;subd=mitmwatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://mitmwatcher.files.wordpress.com/2007/06/phising.jpg" title="phising.jpg"></a><img src="http://mitmwatcher.files.wordpress.com/2007/06/phising.jpg?w=450" align="texttop" /></p>
<p><strong>Problem  :</strong></p>
<p style="text-align:justify;"> Around  <a href="http://www.pewinternet.org/PPF/r/149/report_display.asp">55 million people  </a>or  44% of  internet users  do online banking and recent  <a href="http://www.usablesecurity.org/emperor/emperor.pdf">Emperor</a> (Read Gartner) report say 96% of users does not understand security or confused by the goofy methods security vendors provide.</p>
<p><span style="font-weight:bold;">The Solution:</span></p>
<p style="text-align:justify;">Phishing 2.0 provides all in one toolkit to cover all types of client side and channel attacks It s patent pending methods like <a href="http://www.internetnews.com/security/article.php/3619086">vishing </a>(VOIP   ,<a href="http://www.crime-research.org/news/04.09.2006/2221/">SMS phishing</a> and active <a href="http://www.finextra.com/fullstory.asp?id=16750">MITM</a>(Man In the Middle) attacks for channel and platform independent root kit installable Trojans, Hardware keyloggers,screen scrappers etc for client attacks.</p>
<p><span style="font-weight:bold;"><br />
Benefits </span>:</p>
<p style="text-align:justify;">&nbsp;</p>
<ol>
<li>Automated Phishing Attacks can be launched at single click.</li>
<li>Other features include  launch of automated  DoDs attacks.</li>
<li>The whole ecosystem of phishing under one process.</li>
<li>Its so easy that your mama  can  also launch a attack..</li>
<li>Leaves no forensics evidences, FBI will never catch you.</li>
</ol>
<p><span style="font-weight:bold;"><br />
Revenue Model</span>:</p>
<p style="text-align:justify;">Average server Uptime of Home user License is   <a href="http://www.cl.cam.ac.uk/%7Ernc1/weis07-phishing.pdf">58 hrs and Average uptime of Enterprise serve r license is 19 days and around </a>200 people give away their identify and gain of per user is around $532 , 10k per attack.</p>
<ol>
<li>Renting the toolkit for per attack/hour basis.</li>
<li>Licensing Fee from  countries to launch DoDs attacks.</li>
<li>User centric packaging   like spear phishing or launching attacks against a group, site etc.</li>
<li>Industry specific attacks  like IRS Share Brokering, Fund raising.</li>
</ol>
<p><span style="font-weight:bold;">Channel partners</span> :</p>
<ol>
<li>Money laundering agents who act as mules and non banking money exchange like (eGold,Hawala etc )</li>
<li>Outsourcing partners  for server maintenance    and support   mainly Rockphish group whose average server uptime is 19 days.</li>
<li>Domain registration agents for the different names.</li>
<li>Email harvesters provide 2 million address per hour.</li>
</ol>
<p><span style="font-weight:bold;">Funding Requirement:</span></p>
<p style="text-align:justify;">100k for lots of bandwidth and 100k for lots of domain space  100K for beer and smoke .</p>
<p style="text-align:justify;"><span style="font-weight:bold;">Team</span>:</p>
<p><span style="font-weight:bold;">X00r Founder</span> :Ex-black,white,blue hat. Has been in the industry from phish 1.0 days ,famed for launching many DoDs attacks.</p>
<p><span style="font-weight:bold;">Mr.X Co Founder</span> :Controller of 3 biggest botnets on the planet and Trojan  writer</p>
<p><span style="font-weight:bold;">Agent W0lF</span>:Client side attack vector specialist  and web site cloner</p>
<p style="text-align:justify;"> <span style="font-weight:bold;">Board of advisors</span> :</p>
<p>Has some great Board from Old school and bring lots of experience on board.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mitmwatcher.wordpress.com/4/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mitmwatcher.wordpress.com/4/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mitmwatcher.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mitmwatcher.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mitmwatcher.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mitmwatcher.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mitmwatcher.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mitmwatcher.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mitmwatcher.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mitmwatcher.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mitmwatcher.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mitmwatcher.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mitmwatcher.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mitmwatcher.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mitmwatcher.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mitmwatcher.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=mitmwatcher.wordpress.com&amp;blog=1222634&amp;post=4&amp;subd=mitmwatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://mitmwatcher.wordpress.com/2007/06/14/business-plan-for-a-phishing-20-startup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9aa34e1a354800a0e8158ef7b9129355?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mitmwatcher</media:title>
		</media:content>

		<media:content url="http://mitmwatcher.files.wordpress.com/2007/06/phising.jpg" medium="image" />
	</item>
	</channel>
</rss>
