<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Spam Cryer &#187; Barracuda Networks</title>
	<atom:link href="http://www.thespamcryer.com/category/barracuda-networks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespamcryer.com</link>
	<description>Intelligent Discussion on Anti-Spam</description>
	<lastBuildDate>Thu, 02 Feb 2012 18:37:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>FTC Permanently Shuts Down Notorious Rogue I.S.P.</title>
		<link>http://www.thespamcryer.com/ftc-permanently-shuts-down-notorious-rogue-i-s-p/</link>
		<comments>http://www.thespamcryer.com/ftc-permanently-shuts-down-notorious-rogue-i-s-p/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 15:12:05 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[CudaMail]]></category>
		<category><![CDATA[Web Filter]]></category>
		<category><![CDATA[3FN]]></category>
		<category><![CDATA[Barracuda Web Filter]]></category>
		<category><![CDATA[Botnets]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=285</guid>
		<description><![CDATA[At the Federal Trade Commission]]></description>
			<content:encoded><![CDATA[<h3>3FN Service Specialized in Hosting Spam-Spewing Botnets, Phishing Websites, Child Pornography, and Other Illegal, Malicious Web Content</h3>
<p>At the Federal Trade Commission</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/ftc-permanently-shuts-down-notorious-rogue-i-s-p/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Swine Flu Phishing Attacks and Email Scams</title>
		<link>http://www.thespamcryer.com/swine-flu-phishing-attacks-and-email-scams/</link>
		<comments>http://www.thespamcryer.com/swine-flu-phishing-attacks-and-email-scams/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 21:37:22 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Barracuda Networks]]></category>
		<category><![CDATA[Online Scams]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam Firewall]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Barracuda]]></category>
		<category><![CDATA[CudaMail]]></category>
		<category><![CDATA[US-CERT]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=219</guid>
		<description><![CDATA[US-CERT is aware of public reports of email scams circulating related to the Swine Flu. The attacks arrive via an unsolicited email message typically containing a subject line related to the Swine Flu. These email messages may contain a link or an attachment. If users click on this link or open the attachment, they may be directed to a phishing website or exposed to malicious code.]]></description>
			<content:encoded><![CDATA[<p><strong>US-CERT</strong> is aware of public reports of email scams circulating related to the Swine Flu. The attacks arrive via an unsolicited email message typically containing a subject line related to the Swine Flu. These email messages may contain a link or an attachment. If users click on this link or open the attachment, they may be directed to a phishing website or exposed to malicious code.</p>
<p>US-CERT encourages users to take the following measures to protect themselves:</p>
<ul>
<li>Do not follow unsolicited web links or attachments in email messages.</li>
<li>Maintain up-to-date antivirus software.</li>
<li>Refer to the Recognizing and Avoiding Email Scams (pdf) document for more information on avoiding email scams.</li>
<li>Refer to the Avoiding Social Engineering and Phishing Attacks document for more information on social engineering attacks.</li>
</ul>
<p>Maintaining up-to-date anti-virus is vital. Some appliances, like the <a href="http://www.BarracudaNetworks.ca" target="_blank">Barracuda Spam &amp; Virus Firewalls</a> that are used by <a title="CudaMail Managed Spam &amp; Virus Filtering Service" href="http://www.CudaMail.com" target="_blank">CudaMail.com</a> to filter mail are updated on a constant basis.</p>
<p><strong>US-CERT</strong> will provide additional details as they become available.</p>
<h3>Relevant Url(s):</h3>
<p><a href="http://www.us-cert.gov/cas/tips/ST04-014.html" target="_blank">http://www.us-cert.gov/cas/tips/ST04-014.html</a></p>
<p><a href="http://www.avertlabs.com/research/blog/index.php/2009/04/27/swine-flue-spam/" target="_blank">http://www.avertlabs.com/research/blog/index.php/2009/04/27/swine-flue-spam/</a></p>
<p><a href="http://www.us-cert.gov/reading_room/emailscams_0905.pdf" target="_blank">http://www.us-cert.gov/reading_room/emailscams_0905.pdf</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/swine-flu-phishing-attacks-and-email-scams/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are you ready to see your spam volume Jump 10 times?</title>
		<link>http://www.thespamcryer.com/are-you-ready-to-see-your-spam-volume-jump-10-times/</link>
		<comments>http://www.thespamcryer.com/are-you-ready-to-see-your-spam-volume-jump-10-times/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 20:41:08 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[Barracuda Networks]]></category>
		<category><![CDATA[Botnets]]></category>
		<category><![CDATA[Bulletins]]></category>
		<category><![CDATA[CudaMail]]></category>
		<category><![CDATA[Spam Firewall]]></category>
		<category><![CDATA[Barracuda Central]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=185</guid>
		<description><![CDATA[It took less than 3 months for the Spammers to ramp up their production to 90% of where it was pre-McColo takedown in November 2008 according to a number of reports and graphs available online.]]></description>
			<content:encoded><![CDATA[<p>It took less than 3 months for the Spammers to ramp up their production to 90% of where it was pre-McColo takedown in November 2008 according to a number of reports and graphs available online.</p>
<p>The first report is from Message Labs and it reports that with spam volume up another 5% so far in January 2009 the top 10 Botnets, while consisting of between 10 thousand to 1 Million bots (estimated), were capable of sending out between 131 Million to almost 40 BILLION Spam messages PER DAY per Botnet. Total Volume from just the top 10 Botnets totalled almost 65 Billion messages per day! Are you getting your fair share?</p>
<p>It is interesting to see that the largest Botnet Cutwail/Pandex placed second behind Mega-D/Ozdok in spam volume per day category (7 Billion to 38 Billion) even though it had more compromised PC</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/are-you-ready-to-see-your-spam-volume-jump-10-times/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Merry Malware &#8211; Tis the season for postcards</title>
		<link>http://www.thespamcryer.com/merry-malware-tis-the-season-for-postcards/</link>
		<comments>http://www.thespamcryer.com/merry-malware-tis-the-season-for-postcards/#comments</comments>
		<pubDate>Fri, 12 Dec 2008 20:31:55 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[CudaMail]]></category>
		<category><![CDATA[Web Filter]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[postcards]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=165</guid>
		<description><![CDATA[Every year at the holidays we see an upsurge of 'postcard ware' based malware. They look like a e-card from a loved one so you are enticed to open them up and while some do display a pretty picture or a play a nice tune in the background they are infecting your pc.]]></description>
			<content:encoded><![CDATA[<p>Well it&#8217;s that time of year again when your thoughts turn to family and friends and you want to &#8216;reach out&#8217; to them with a nice greeting card &#8211; either Xmas or New Years. If you get or give an electronic version all the better as you save on postage and don&#8217;t have to wait for snail mail.</p>
<p>We aren&#8217;t the only ones thinking of others at this time of year and by that I mean the malware writers. Every year at the holidays we see an upsurge of &#8216;postcard ware&#8217; based malware. They look like a e-card from a loved one so you are enticed to open them up and while some do display a pretty picture or a play a nice tune in the background they are infecting your pc.</p>
<p>Some recent sample are posted on the Microsoft Malware blog so you can see the pictures without having to get infected.</p>
<p><a href="http://blogs.technet.com/mmpc/archive/2008/12/02/merry-malware.aspx">http://blogs.technet.com/mmpc/archive/2008/12/02/merry-malware.aspx</a></p>
<p><a href="http://blogs.technet.com/mmpc/archive/2008/12/04/o-come-all-ye-malware.aspx">http://blogs.technet.com/mmpc/archive/2008/12/04/o-come-all-ye-malware.aspx</a></p>
<p>While many of the e-cards sent at this time of the year are legitimate and sent with the best of intentions it is up to you to double check with the supposed sender if they really did send you one and if you don&#8217;t recognize the from e-mail address then don&#8217;t open it no matter how tempting it looks.</p>
<p>- Shaun</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/merry-malware-tis-the-season-for-postcards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Relay Chat (IRC) re-gaining in the Billion-dollar underground economy</title>
		<link>http://www.thespamcryer.com/internet-relay-chat-irc-re-gaining-in-the-billion-dollar-underground-economy/</link>
		<comments>http://www.thespamcryer.com/internet-relay-chat-irc-re-gaining-in-the-billion-dollar-underground-economy/#comments</comments>
		<pubDate>Mon, 01 Dec 2008 20:38:02 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[Bulletins]]></category>
		<category><![CDATA[CudaMail]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spim]]></category>
		<category><![CDATA[Vishing]]></category>
		<category><![CDATA[Web Filter]]></category>
		<category><![CDATA[bank fraud]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[IRC]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=146</guid>
		<description><![CDATA[Over at IT Business they are reporting that Internet Relay Chat or IRC is again a popular place for Cyber Criminals to hang out and market their ill-gotten gains. With a market estimated at 7 Billion dollars you can be sure that they aren't going away anytime soon.]]></description>
			<content:encoded><![CDATA[<p>Over at <strong>IT Business</strong> they are reporting that <strong>Internet Relay Chat</strong> or <acronym title="Internet Relay Chat">IRC</acronym> is again a popular place for Cyber Criminals to hang out and market their ill-gotten gains. With a market estimated at 7 Billion dollars you can be sure that they aren&#8217;t going away anytime soon.</p>
<p><a title="IT Business" href="http://www.itbusiness.ca/it/client/en/home/News.asp?id=50885" target="_blank">http://www.itbusiness.ca/it/client/en/home/News.asp?id=50885</a></p>
<p>It is interesting to note that there are so many compromised bank accounts that they sell at a discount ($1,000 for an account with $40K in it. $10 for an account with $2500 in it) This tells us that the tricks the Cyber Criminals are using (phishing, vishing, spim) are working so you have to be careful out there or it will be your bank account that they are selling online.</p>
<p>Thankfully at IT Business they have provided the following list to remind us of what to and not do online.</p>
<p>Tips to protect yourself</p>
<ul>
<li>Use an <a title="Barracuda Web Filter" href="http://www.barracudanetworks.ca/web-filter.aspx" target="_blank">e-mail filter</a> to block fraudulent messages that are often used in phishing attacks . Use many layers of security such as anti-virus software, firewalls, and anti-phishing toolbars for your browser . Limit the amount of sensitive personal information on your computer.</li>
<li>Use strong passwords and change them on a regular basis.</li>
<li>Do not store online account passwords with your Web browser&#8217;s automatic feature.</li>
</ul>
<p>Shaun</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/internet-relay-chat-irc-re-gaining-in-the-billion-dollar-underground-economy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How To Stop a Spammer &#8211; Go After His Bank Account!</title>
		<link>http://www.thespamcryer.com/how-to-stop-a-spammer-go-after-his-bank-account/</link>
		<comments>http://www.thespamcryer.com/how-to-stop-a-spammer-go-after-his-bank-account/#comments</comments>
		<pubDate>Thu, 16 Oct 2008 15:21:15 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Barracuda Networks]]></category>
		<category><![CDATA[Bulletins]]></category>
		<category><![CDATA[CudaMail]]></category>
		<category><![CDATA[Online Scams]]></category>
		<category><![CDATA[anti-spam solution]]></category>
		<category><![CDATA[IT Brief]]></category>
		<category><![CDATA[Lance Atkinson]]></category>
		<category><![CDATA[Shane Atkinson]]></category>
		<category><![CDATA[Spammers]]></category>
		<category><![CDATA[The Register]]></category>
		<category><![CDATA[US Federal Trade Commission]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=93</guid>
		<description><![CDATA[The US Federal Trade Commission along with their counterparts in New Zealand and Australia have finally made a dent in the spam volume. As reported by the The Register and IT Brief, a two month investigation involving international cooperation has resulted in the laying of charges against Shane Atkinson ...]]></description>
			<content:encoded><![CDATA[<p>The US Federal Trade Commission along with their counterparts in New Zealand and Australia have finally made a dent in the spam volume.</p>
<div class="wp-caption alignnone" style="width: 220px"><a title="Wikipedia | Shane Atkinson" href="http://en.wikipedia.org/wiki/Shane_Atkinson" target="_blank"><img title="Spam King Shane Atkinson" src="http://www.clueby4.com/Shane_Atkinson.jpg" alt="Spam King Shane Atkinson" width="210" height="330" /></a><p class="wp-caption-text">- Spam King Shane Atkinson</p></div>
<p>As reported by the The Register and IT Brief, a two month investigation involving international cooperation has resulted in the laying of charges against [tag]Shane Atkinson[/tag], his brother [tag]Lance Atkinson[/tag] and Roland Smits alleging that they were responsible for the spam messages marketing &#8216;Herbal King&#8217;, &#8216;Elite Herbal&#8217; and &#8216;Express Herbal&#8217; along with &#8216;genuine replica watches&#8217; and &#8216;adult toy&#8217;s&#8217;. This has resulted in a noticeable drop in spam volume as this &#8216;team&#8217; was responsible for up to 1/3 of the spam.</p>
<p><a title="The Register: Feds hamstring world's largest spam gang" href="http://www.theregister.co.uk/2008/10/14/prolific_spammers_targeted/" target="_blank">http://www.theregister.co.uk/2008/10/14/prolific_spammers_targeted/</a></p>
<p><a title="Christchurch spam kings face $200K fines " href="http://www.itbrief.co.nz/index.php?option=com_content&amp;task=view&amp;id=2995&amp;Itemid=799" target="_blank">http://www.itbrief.co.nz/index.php?option=com_content&amp;task=view&amp;id=2995&amp;Itemid=799 </a></p>
<p>These same people appear to have been involved in spamming for a while according to a <a title="Wikipedia | Shane Atkinson" href="http://en.wikipedia.org/wiki/Shane_Atkinson" target="_blank">Wikipedia </a>article with reports going back as far as 2003 with a previous monetary judgment against Lance.</p>
<p><strong>Why did the last judgment not stop then and this time it did? </strong></p>
<p>The authorities froze their bank accounts.</p>
<p>I applaud the authorities taking this step but only time will tell if this is going to force them out of the spam game for good.</p>
<p>I believe that this is a temporary slowdown in the volume of spam. They were able to get away with it for a long time and made lots and lots of money.</p>
<p>Where there is lots of easy money it attracts those drawn to easy money so I would expect the vacuum to be filled shortly or for the same team to be back at it shortly.</p>
<p>Sorry but this does not mean that you don&#8217;t need an <a title="Barracuda Spam Firewall" href="http://www.barracudanetworks.ca/spam-firewall.aspx" target="_blank">anti-spam solution</a> <img src='http://www.thespamcryer.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>- The Spam Cryer</p>
<p>Here are some more articles on the subject for you:</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/how-to-stop-a-spammer-go-after-his-bank-account/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Register &#8211; &#8220;Beloved Websites Riddled With Crimeware&#8221;</title>
		<link>http://www.thespamcryer.com/the-register-beloved-websites-riddled-with-crimeware/</link>
		<comments>http://www.thespamcryer.com/the-register-beloved-websites-riddled-with-crimeware/#comments</comments>
		<pubDate>Wed, 30 Jul 2008 16:13:14 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Barracuda Networks]]></category>
		<category><![CDATA[Barracuda Website Firewall]]></category>
		<category><![CDATA[Crimeware]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Websense]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=26</guid>
		<description><![CDATA[Great but quick article on how any website can be taken over and a great reason to use something like the Barracuda Website Firewall in front of your web servers.]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal">Great but quick article on how any website can be taken over  and a great reason to use something like the <a title="Barracuda Website Firewall" href="http://www.barracudanetworks.ca/website-firewall.aspx" target="_blank">Barracuda Website Firewall</a> in front  of your web servers.</p>
<p class="MsoNormal"><a title="http://www.theregister.co.uk/2008/07/30/websense_high_profile_website_malware_survey/" href="http://www.theregister.co.uk/2008/07/30/websense_high_profile_website_malware_survey/" target="_blank">www.theregister.co.uk/2008/07/30/websense_high_profile_website_malware_survey/</a></p>
<h2>Beloved websites riddled with crimeware</h2>
<h3 class="Standfirst">Web 2.0 malware mash-up madness</h3>
<div class="Byline">By <a title="Send email to the author" href="http://forms.theregister.co.uk/mail_author/?story_url=/2008/07/30/websense_high_profile_website_malware_survey/">John Leyden</a> <small class="MoreByAuthor">? <a title="More stories from this site by John Leyden" href="http://search.theregister.co.uk/?author=John%20Leyden">More by this author</a></small></div>
<div class="Date"><small>Published Wednesday 30th July 2008 20:23 GMT</small></div>
<hr id="UnderDate" />Sixty of the 100 most popular websites either hosted malicious content or linked to malicious websites at some point during the first six months of 2008, according to a new study by web security firm Websense.</p>
<p>Many of these sites include search engine and social networking sites that are becoming a popular target for attackers thanks to their huge user bases allied to inadequate security controls. Open redirects that allow hackers to bounce surfers off well-known sites onto dodgy domains are a big part of this problem, according to Carl Leonard, security research manager EMEA at Websense. SQL injection attacks are also a major cause of grief, he added.</p>
<div id="MidArticleSlot" class="Ad"><script type="text/javascript"><!--
 tile++;
 document.write('\x3Cscript src="http://ad.uk.doubleclick.net/adj/reg.security.4159/front;cta='+cta+';ctb='+ctb+';ctc='+ctc+';sc='+sc+';cid='+cid+';'+RegExCats+GetVCs()+'pid='+RegId+RegDT+';'+RegKW+';test='+test+';pf='+RegPF+';dcove=d;tile='+tile+';sz=336x280;ord=' + rand + '?" type="text/javascript"&gt;\x3C\/script&gt;');
// --></script><script style="display: none;" src="http://ad.uk.doubleclick.net/adj/reg.security.4159/front;cta=0;ctb=0;ctc=0;sc=3;cid=;vc=sec.front;vc=sec.crime;pid=80270;kw=websense;kw=malicious%20scripts;kw=sql%20injection;kw=web%20attacks;kw=warez;kw=security%20survey;kw=legitimate%20websites;kw=drive-by%20download;;test=;pf=0;dcove=d;tile=2;sz=336x280;ord=47332697577531?" type="text/javascript"></script> <noscript></noscript>Websense recorded a market increase in drive-by download attacks that involve hackers loading malicious scripts, using tactics such as SQL injection attacks, onto otherwise reputable websites. More than 75 per cent of the Web sites Websense classified as malicious during the 1H 2008 were legitimate websites that had become the victim of cybercrooks. In the past, the majority of malware would crop up on warez and smut sites.</div>
<p>Overall 29 percent of malicious Web attacks included data-stealing code, demonstrating that information pilfering rather than simple mischief is becoming a more and more significant driver of malware creation.</p>
<p>Brazilian and Chinese hackers get all the blame but the majority of spyware sends its information back to systems based in the US.</p>
<p>Around half (46 per cent) of the malware attacks monitored by Websense in the first half of 2008 send data back over the web with connections made to systems in the US in 57.3 per cent of these cases. By comparison, just 6 per cent of spyware phones home to China, only 4.3 per cent pings Russia and a similar 4 per cent hooks up with cybercrooks in Brazil.</p>
<p>Websense&#8217;s Leonard cautioned that its findings don&#8217;t necessarily mean malware-spreading cybercrooks are mostly based in the US. &#8220;It could be the attacker is located in a different country. cybercrime is international,&#8221; he said.</p>
<p>In other findings, Websense recorded a marked drop in malicious code created using exploitation kits over recent months. It reckons VXers are using customized attacks more often in an attempt to bypass signature detection tools that are likely to block the product of rudimentary malware creation toolkits.</p>
<p>A summary of Websense&#8217;s latest research can be found <a title="Websense" href="http://investor.websense.com/releasedetail.cfm?ReleaseID=324871" target="_blank">here</a>. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/the-register-beloved-websites-riddled-with-crimeware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>From &#8220;Fastflux&#8221; to &#8220;Hydraflux&#8221;: A Brief History Of The Botnet</title>
		<link>http://www.thespamcryer.com/from-fastflux-to-hydraflux-a-brief-history-of-the-botnet/</link>
		<comments>http://www.thespamcryer.com/from-fastflux-to-hydraflux-a-brief-history-of-the-botnet/#comments</comments>
		<pubDate>Mon, 21 Jul 2008 19:28:52 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Barracuda Networks]]></category>
		<category><![CDATA[Botnets]]></category>
		<category><![CDATA[Barracuda Web Filter]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Fastflux]]></category>
		<category><![CDATA[Hydraflux]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=10</guid>
		<description><![CDATA[I'm not sure if you've been reading the news over at the Internet Storm Center recently but ... they have a an interesting write up on what William Salusky dubs the "Hydraflux" that is worth reading.]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m not sure if you&#8217;ve been reading the news over at the [tag]Internet Storm Center[/tag] recently but &#8230; they have a an interesting write up on what William Salusky dubs the &#8220;<a title="A Twist In Fluxnet Operations - Enter Hydraflux" href="https://isc.sans.org/diary.html?storyid=4753" target="_blank">Hydraflux</a>&#8221; that is worth reading.</p>
<p>The popular technique for writing botnets over the last while is called &#8216;[tag]Fast Flux[/tag]&#8216; where an group of infected PC&#8217;s act as a proxy layer between the web server hosting the malware and the PC&#8217;s that are going to be infected.</p>
<p>This proxy layer is called the &#8216;[tag]Fluxnodes[/tag]&#8216;.</p>
<blockquote><p>You will have seen this in the recent &#8216;Storm Worm&#8217; spam runs where the e-mail to you consists of a brief subject line and a link to an IP address. When you click on the link in the e-mail your computer connects to the proxy software running on an already infected PC and it then goes out and get&#8217;s the content, including the malware that will end up infecting your PC, from the real source.</p></blockquote>
<p>This makes it harder to track down the real source of the infection as you now have to try and contact the IT people of the computer in the middle (the proxy) and get them to check their log files to find out where the malware content is really coming from.</p>
<p>They may be too busy to respond or they may not even have the logs required to track the source down and meanwhile the &#8216;Storm Worm&#8217; or some variation continues to send out millions of e-mail messages getting more PC&#8217;s infected and adding more pawns to that proxy layer insulating the &#8220;bot herder&#8221; (gotta love the names we give certain people) from the security professionals that are trying to stop the infection.</p>
<p>As hard as it is to coordinate with the IT departments of the infected proxy layer it does happen often enough that the real source of the malware files is found and is shut down. This does not make the &#8220;bot herders&#8221; happy as now they have to start building up their bot nets all over again or redirect their proxy pawns to a second source of infected files. This takes time and while this transition is going on the bot network is down and not doing the bidding of the herder thus the evolution of &#8216;Fast Flux&#8217; to &#8216;Hydra Flux&#8217;.</p>
<p><img class="alignleft" style="margin-left: 3px; margin-right: 3px; float: left;" src="http://hydra-minerva.com/graphics/site/Hydra1.jpg" alt="" width="103" height="129" />[tag]Hydra Flux[/tag] is the same basic idea as Fast Flux but with the addition of many heads &#8211; like the Lernaean Hydra or many headed serpent in Greek mythology &#8211; and just like the ancient snake with many heads you can cut off one of the heads of the modern &#8216;Hydra Flux&#8217; without killing the beast. The Proxy layer talks to many sources of infection, the mother ships of the Internet Storm Article, so that if one gets found out and stopped the proxy layer has a backup. This is a very resilient hosting structure and could be called a great example of &#8216;[tag]cloud computing[/tag]&#8216;.</p>
<p><strong>So what can we do to stop the infections? </strong></p>
<ol>
<li>Ensure that we don&#8217;t settle for setting up our corporate firewall&#8217;s to the point that they work for both us and the malware writers. Too many firewall&#8217;s are setup to stop the traffic coming from the Internet to the LAN but allow anything and everything from the LAN to flow to the Internet.</li>
<li>If you have a corporate mail server then the mail server should be the only system that has SMTP access to the Internet and you can block all other connections from the LAN to any Internet host on port 25.</li>
<li>If the firewall has [tag]Universal Plug and Play[/tag] (UPnP) disable it if at all possible because of the security holes it introduces into your network. Enable the Intrusion Detection (IDS) of your firewall if it has that capability and use it on the inside of your network.</li>
<li>If you don&#8217;t have a firewall that can do IDS get one that can or add a transparent gateway device like the<em> [tag]Barracuda Web Filter[/tag]</em> that looks for infected traffic originating on the inside of your network and can both block it and report to you that you have an infection problem so you can take care of it. The <a href="http://www.barracudanetworks.ca/web-filter.aspx" target="_blank">Barracuda Web Filter</a> also has the log files that would allow you to track down the real source of the malware helping cut off one of the many heads of the Hydra Flux botnet.</li>
</ol>
<p><strong>Interested in learning more?</strong></p>
<p>Here are some links for you:</p>
<p>Hydra Flux</p>
<ul>
<li><a href="http://isc.sans.org/diary.html?storyid=4753">http://isc.sans.org/diary.html?storyid=4753</a></li>
</ul>
<p>Fast Flux</p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Fast_flux">http://en.wikipedia.org/wiki/Fast_flux</a></li>
</ul>
<p>UPnP</p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Universal_Plug_and_Play">http://en.wikipedia.org/wiki/Universal_Plug_and_Play </a></li>
</ul>
<p><a href="http://honeyblog.org/archives/195-Fast-Flux-Data.html">Fast-Flux Data</a></p>
<ul>
<li>Back in February, we published a paper on fast-flux service networks at NDSS&#8217;08. The basic idea behind fast-flux networks is a fast change in the mapping between a domain name and the corresponding IP addresses. &#8230;</li>
</ul>
<p><strong>Botnet Videos:</strong></p>
<p><strong>Botnets PART 1 :Building A Botnet (1/2)</strong></p>
<div>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://www.youtube.com/v/pAiWnKRiotI" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/pAiWnKRiotI"></embed></object></p>
</div>
<p>See actual malicious code and understand how it works. Corey Nachreiner explains botnet architecture for beginners, then builds a bot client.</p>
<p><a href="http://www.secumania.org/" target="_blank">http://www.secumania.org</a></p>
<p><a href="http://forums.secumania.org/" target="_blank">http://forums.secumania.org</a></p>
<p><strong> </strong></p>
<p><strong><br />
Botnets PART 1 : Building A Botnet (2/2)</strong></p>
<div>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://www.youtube.com/v/C56ulcvYRE8" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/C56ulcvYRE8"></embed></object></p>
</div>
<p>See actual malicious code and understand how it works. Corey Nachreiner explains botnet architecture for beginners, then builds a bot client.</p>
<p><strong> </strong></p>
<p><strong><br />
Botnets PART 2 : Botnet Attacks (1/2)</strong></p>
<div>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://www.youtube.com/v/gUko4Ncwf5M" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/gUko4Ncwf5M"></embed></object></p>
</div>
<p>Learn how a bot herder uses his bot army for attacks such as Distributed Denial of Service, getting command line control of victims, installing spyware, and more. Hosted by Corey Nachreiner, CISSP.</p>
<p><strong> </strong></p>
<p><strong><br />
Botnets PART 2 : Botnet Attacks (2/2)</strong></p>
<div>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://www.youtube.com/v/cDjsm-dTFyA" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/cDjsm-dTFyA"></embed></object></p>
</div>
<p>Learn how a bot herder uses his bot army for attacks such as Distributed Denial of Service, getting command line control of victims, installing spyware, and more. Hosted by Corey Nachreiner, CISSP.</p>
<p><strong>Some Other Interesting Articles on Botnets:</strong></p>
<p><a rel="nofollow" href="http://honeyblog.org/archives/196-Interesting-Pattern-in-Storm-Worm-Traffic.html" target="_blank">Interesting Pattern in Storm Worm Traffic</a> &#8211; Bj</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/from-fastflux-to-hydraflux-a-brief-history-of-the-botnet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is The Barracuda/CudaMail Outlook Plug-in &amp; How Do I Use It To Reduce The Level of SPAM I Get?</title>
		<link>http://www.thespamcryer.com/outlook-plug-in/</link>
		<comments>http://www.thespamcryer.com/outlook-plug-in/#comments</comments>
		<pubDate>Fri, 22 Feb 2008 21:17:33 +0000</pubDate>
		<dc:creator>Shaun</dc:creator>
				<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[Barracuda Networks]]></category>
		<category><![CDATA[Spam Firewall]]></category>
		<category><![CDATA[CudaMail]]></category>
		<category><![CDATA[Outlook]]></category>
		<category><![CDATA[Plug-In]]></category>

		<guid isPermaLink="false">http://www.thespamcryer.com/?p=170</guid>
		<description><![CDATA[Do you want to educate the CudaMail system so it understands better what kind of e-mail you want to get and what you consider as spam?  Do you want to have a very easy way to submit SPAM and false positive reports  Do you want an easy way to keep your white list up to date?  If you answered YES to any of the above questions then you may want to try the Outlook Plug-in. ]]></description>
			<content:encoded><![CDATA[<p>Do you want to <i>educate the CudaMail system </i>so it understands better what kind of e-mail you want to get and what you consider as spam? </p>
<p>Do you want to have a very easy way<b> </b>to <i>submit SPAM and false positive reports</i>?</p>
<p>Do you want an easy way to <i>keep your white list up to date</i>?</p>
<p>If you answered YES to any of the above questions then you may want to <i>try the Outlook Plug-in</i><b>. </p>
<p>Getting to Know The Outlook Plug-In:</b></p>
<p>This very simple toolbar can be installed in the Outlook 2000 to 2007 e-mail client (not Outlook Express or the new MS Mail) to give you some additional options and two new buttons. These <font color=#008000><b>Green</b></font> and <font color=#ff0000><b>Red </b></font>buttons with an envelope and either a Check Mark (good) or <font color=#ff0000><b>Red</b><b> X</b></font> (bad) make the process of sending a report back to the system that you consider a message SPAM or Wanted as easy as clicking on the corresponding button. It can&#8217;t get any simpler than that!</p>
<p>To <i>download the toolbar </i>simply go to the <a href="https://web.CudaMail.com">CudaMail Web Portal</a> and click on the &#8216;<i>Get Mail Client Plugins Here</i>&#8216; link at the bottom of the page. (this download link is only for current CudaMail customers &#8211; if you have a <a href="http://www.barracudanetworks.ca/spam-firewall.aspx">Barracuda Spam Firewall</a> and want the plug-in go talk to your network administrator)</p>
<p>Per-user Web portal is at <a href="https://web.CudaMail.com">https://web.CudaMail.com</a> </p>
<p>Once you download the Outlook Plug-in you have to run it to install it so you need to do this with an account that has administrative access to your PC. After it is installed you should be able to get to the &#8216;<i>Spam Firewall</i>&#8216; tab under the &#8216;<i>Tools&#8217; &#8211; &#8216;Options</i>&#8216; menu item and it should look something like this:</p>
<div align=center><img src="http://www.cudamail.com/blog/content/binary/Tools-Options.jpg" border=0/></div>
<p><b>What Does This All Mean?</b></p>
<p><i>Automatically Update White list: </i>When this option is checked off every time you add someone as a new personal contact or e-mail someone then they will be added to your personal white list. While this sounds like a great idea you need to login to your personal options area on the CudaMail system on a semi-regular basis to clear out old or stale white list entries and specifically to make sure your own e-mail address is not on the white list.</p>
<p>A typical spammer trick is to send you spam pretending to be you so you do not want to white list your own e-mail address or you will get more spam.</p>
<p>This can happen by accident if you &#8216;<i>reply all</i>&#8216; to an e-mail and don&#8217;t take your e-mail address off or if you are in the habit of always cc&#8217;ing yourself.</p>
<p><b>Additional Button Actions:</b></p>
<p><i>Spam:</i> Permanently Delete Message or Move to Deleted Items folder.</p>
<p>While I like to completely get rid of any spam messages by leaving it on the &#8216;<i>Permanently Delete Items</i>&#8216; option you have no way of easily getting back any message you accidently marked as Spam. By setting this option to &#8220;<i>Move to &#8211; Deleted Items Folder</i>&#8216; you can always rescue it from there if you have an accident.</p>
<p><i>Not Spam</i>: Add E-Mail addresses to Whitelist. When a message come through with the subject tagged as spam &#8216;[CudaMailTagged] -original subject&#8217; and you click on the <font color=#008000><b>Green </b></font>button to submit a &#8216;<i>falsely marked as spam</i>&#8216; report this option will also update your personal whitelist so that this senders e-mail will not be tagged in the future.</p>
<p>There is a second benefit to the plug-in as it is building your own personal database of &#8216;<font color=#008000><b>Good</b></font>&#8216; and &#8216;<font color=#ff0000><b>Bad</b></font>&#8216; messages that are unique to you. Once you have marked at least 200 messages of each type then the statistical analysis or &#8216;<i>Barracuda Bayesian Learning</i>&#8216; will kick in and provide additional protection against Spam. You will only be able to mark messages that have been processed by the <a href="http://www.CudaMail.com">CudaMail</a> system so don&#8217;t just select everything in your inbox and try to mark them all as &#8216;<font color=#008000><b>good</b></font>&#8216;. What you should do is look at the message and ask yourself &#8216;Did this e-mail come from outside our organization and is it a representative sample of e-mail that I want to get in the future?&#8217;</p>
<p><b>This plug-in is also the answer to questions like the following:</b></p>
<p>1. How do I automatically whitelist all of my contacts?<br />2. I get so few messages in the per-user quarantine how am I ever going to get 200 &#8216;good&#8217; messages?<br />3. How do I send you samples of spam that I don&#8217;t want?</p>
<p><b>Does the Outlook plug-in work with Microsoft Vista?</b></p>
<p>Yes the Outlook Plug-in versions 2.1.0.5 and above work with Microsoft Vista and Outlook 2007. The plug-in version can be found on the licensing screen when installing the plug-in, or in Microsoft Outlook by viewing the Spam Firewall tab in the Options window. The version number will be located in the bottom-right corner of the window. </p>
<p>If you can give the Outlook Plug-in a try. I have been using it myself for the last 2 years and I get a sense of joy every time I can click on the &#8216;Spam&#8217; button because I know that this is making the Spammer&#8217;s job that much harder next time.</p>
<p>- Shaun</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thespamcryer.com/outlook-plug-in/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

