<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; Malware</title>
	<atom:link href="http://www.darknet.org.uk/category/virustrojanswormsrootkits/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Thu, 19 Nov 2009 10:29:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Jailbroken iPhone Users Get Rickrolled</title>
		<link>http://www.darknet.org.uk/2009/11/jailbroken-iphone-users-get-rickrolled/</link>
		<comments>http://www.darknet.org.uk/2009/11/jailbroken-iphone-users-get-rickrolled/#comments</comments>
		<pubDate>Wed, 11 Nov 2009 05:28:41 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[apple iphone]]></category>
		<category><![CDATA[apple iphone security]]></category>
		<category><![CDATA[apple iphone virus]]></category>
		<category><![CDATA[australia]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[iphone malware]]></category>
		<category><![CDATA[iphone security]]></category>
		<category><![CDATA[iphone virus]]></category>
		<category><![CDATA[iphone worm]]></category>
		<category><![CDATA[jailbreak]]></category>
		<category><![CDATA[jailbroken]]></category>
		<category><![CDATA[rick astley]]></category>
		<category><![CDATA[rickroll]]></category>
		<category><![CDATA[rickrolled]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2283</guid>
		<description><![CDATA[The &#8216;big&#8217; news this week was the first self-replicating worm hit the iPhone, it only seemed to be spreading in Australia though and only worked under a specific set of circumstances.
It only effects iPhone users that have jailbroken their phone and have the SSH software installed with a default password of alpine.
Thankfully it&#8217;s not particularly [...]]]></description>
			<content:encoded><![CDATA[<p>The &#8216;big&#8217; news this week was the first self-replicating worm hit the <a href="http://www.darknet.org.uk/tag/iphone/">iPhone</a>, it only seemed to be spreading in Australia though and only worked under a specific set of circumstances.</p>
<p>It only effects iPhone users that have jailbroken their phone and have the SSH software installed with a default password of <em>alpine</em>.</p>
<p>Thankfully it&#8217;s not particularly malicious unless you are allergic to Rick Astley.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
google_alternate_ad_url = "http://www.darknet.org.uk/google_adsense_script.html";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text";
google_ad_channel ="9647861209";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "df6f0b";
google_color_url = "df6f0b";
google_color_text = "000000";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<blockquote><p>iPhone owners in Australia awoke this weekend to find their devices targeted by self-replicating attacks that display an image of 1980s heart throb Rick Astley that&#8217;s not easily removed. The attacks, which researchers say are the world&#8217;s first iPhone worm in the wild, target jailbroken iPhones that have SSH software installed and keep Apple&#8217;s default root password of &#8220;alpine.&#8221; In addition to showing a well-coiffed picture of Astley, the new wallpaper displays the message &#8220;ikee is never going to give you up,&#8221; a play on Astley&#8217;s saccharine addled 1987 hit &#8220;Never Gonna Give You Up.&#8221;</p>
<p>Tricking victims in to inadvertently playing the song has become a popular prank known as Rickrolling. A review of some of the <a href="http://code.google.com/p/ikee-virus/source/browse/#svn/trunk">source code</a>, shows that the malware, once installed, searches the mobile phone network for other vulnerable iPhones and when it finds one, copies itself to them using the the default password and SSH, a Unix application also known as secure shell. People posting to <a href="http://forums.whirlpool.net.au/forum-replies.cfm?t=1315624">this thread</a> on Australian discussion forum Whirlpool first reported being hit on Friday.</p></blockquote>
<p>A new twist on the rickrolling phenomena at least, and of course the good thing for the rest of the World is that the infection seems to be fairly localized.</p>
<p>To me it&#8217;s more of a PoC (Proof of Concept) than anything else, but it is a neat piece of programming and shows what some malicious minds could put together if they wanted to target iPhones.</p>
<p>From the authors perspective he just wants to let people know that if they are gonna mess with their iPhone they better secure their shit.</p>
<p><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
google_alternate_ad_url = "http://www.darknet.org.uk/google_adsense_script.html";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text";
google_ad_channel ="9647861209";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "df6f0b";
google_color_url = "df6f0b";
google_color_text = "000000";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<blockquote><p>The attack is a wakeup call for anyone who takes the time to jailbreak an iPhone. While the hack greatly expands the capabilities of the Apple smartphone, it can also make it more vulnerable. Programs such as OpenSSH, which can only be installed after iPhones have undergone the procedure, can be extremely useful, but if owners haven&#8217;t bothered to change their root password, the programs also represent a gaping hole waiting to be exploited.</p>
<p>Indeed, a hacker going by the moniker ikee and claiming to be responsible for the worm said here that he wrote the program to bring awareness to the widely followed practice of failing to change the iPhone&#8217;s password.</p>
<p>&#8220;I was quite amazed by the number of people who didn&#8217;t RTFM and change their default passwords,&#8221; the unidentified worm writer said. &#8220;I admit I probably pissed of [sic] a few people, but it was all in good fun (well ok for me anyway).&#8221;</p>
<p>Ikee said the worm disables the SSH daemon so it can&#8217;t be targeted further.</p></blockquote>
<p>And in the true hacker spirit, the worm disables SSH so it can&#8217;t get infected again or hacked by anyone else.</p>
<p>It doesn&#8217;t takes skills to own the box, it takes skills to stay on the box <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Source: <a href="http://www.theregister.co.uk/2009/11/08/iphone_worm_rickrolls_users/">The Register</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Jailbroken+iPhone+Users+Get+Rickrolled+http://bit.ly/2Yo5rg+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/11/jailbroken-iphone-users-get-rickrolled/&amp;title=Jailbroken+iPhone+Users+Get+Rickrolled" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/11/jailbroken-iphone-users-get-rickrolled/&amp;title=Jailbroken+iPhone+Users+Get+Rickrolled" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/11/jailbroken-iphone-users-get-rickrolled/&amp;t=Jailbroken+iPhone+Users+Get+Rickrolled" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/11/jailbroken-iphone-users-get-rickrolled/&amp;title=Jailbroken+iPhone+Users+Get+Rickrolled" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/11/jailbroken-iphone-users-get-rickrolled/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Facebook Used By Whitewell Trojan To Communicate</title>
		<link>http://www.darknet.org.uk/2009/11/facebook-used-by-whitewell-trojan-to-communicate/</link>
		<comments>http://www.darknet.org.uk/2009/11/facebook-used-by-whitewell-trojan-to-communicate/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 07:49:45 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[facebook security]]></category>
		<category><![CDATA[facebook trojan]]></category>
		<category><![CDATA[facebook virus]]></category>
		<category><![CDATA[facebook-privacy]]></category>
		<category><![CDATA[online malware]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[whitewell]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2256</guid>
		<description><![CDATA[Facebook has had it&#8217;s fair share of security woes and the latest is the discovery of a new Trojan that uses Facebook to communicate.
Interesting that it&#8217;s using the Facebook notes feature to communicate depending on title/subject of the note.
The actual malware itself is spread through doc/pdf exploits and not through any flaws in Facebook itself.

Researchers [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.darknet.org.uk/tag/facebook/">Facebook</a> has had it&#8217;s fair share of security woes and the latest is the discovery of a new Trojan that uses Facebook to communicate.</p>
<p>Interesting that it&#8217;s using the Facebook notes feature to communicate depending on title/subject of the note.</p>
<p>The actual malware itself is spread through doc/pdf exploits and not through any flaws in Facebook itself.</p>
<p><!--adsense#New468--></p>
<blockquote><p>Researchers at Symantec find a Trojan that uses Facebook to communicate with a command and control server.</p>
<p>The Trojan malware, known to Symantec as Whitewell, is being spread via e-mail through &#8220;documents (PDF, or MS Office formats) containing exploits for known vulnerabilities,&#8221; Andrea Lelli, a security analyst with Symantec Security Response, wrote on a Symantec blog Oct. 31. The malware works by contacting the mobile version of Facebook and using its Notes section. By analyzing the Trojan&#8217;s code, Lelli found that the Trojan will perform four different actions, depending on the notes&#8217; titles that are found.</p>
<p>If the title is Wells, the note will contain the timedate stamp for when a machine was infected. If it is WebServer, however, the note will contain a URL to be contacted from which the Trojan will receive commands, Lelli wrote.</p></blockquote>
<p>The malware can actually parse the data in Facebook, and post new notes itself meaning it is self-propagating according to whatever logic is programmed inside.</p>
<p>The ability of the trojan to do anything damaging is somewhat limited but it does show what could be achieved by using a social networking site as a command and control channel.</p>
<p>I&#8217;d imagine this won&#8217;t be the last we see and this could evolve into something much nastier.</p>
<p><!--adsense#New468--></p>
<blockquote><p>If the note has the title &#8216;White&#8217;, it contains a URL that leads to an executable to be downloaded. If the title is anything else, the Trojan is programmed to wait, Lelli wrote.</p>
<p>This is not the first time social networks have been used to help control malware. In August, Arbor Networks researcher Jose Nazario uncovered a <a href="http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/">botnet using Twitter to communicate</a> with its army of compromised machines.</p>
<p>According to Symantec, in this case, the documents containing the malware are made to look legitimate to conceal their intent, mimicking for example the names of well-known courier companies and utilizing popular headlines from the news media.</p>
<p>&#8220;Besides documents they can also spread the executables themselves, sending them with icons that resemble those that accompany legitimate documents, and with legit-looking file names such as &#8216;Competitive assessment.pdf .exe,&#8217;&#8221; Lelli wrote.</p></blockquote>
<p>As with most attacks of this kind, the actual infection comes from lack of user knowledge and social engineering (double file extensions) as Windows STILL insists on hiding known file extensions from the user.</p>
<p>People have been falling for the old double-extension forever, I don&#8217;t see why Windows can&#8217;t just show extensions by default &#8211; do they scare people that much they have to be hidden?</p>
<p>Source: <a href="http://www.eweek.com/c/a/Security/Symantec-Uncovers-Scheme-to-Use-Facebook-to-Relay-Commands-to-Trojan-755029/?kc=rss">eWeek</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Facebook+Used+By+Whitewell+Trojan+To+Communicate+http://bit.ly/4wiqUz+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/11/facebook-used-by-whitewell-trojan-to-communicate/&amp;title=Facebook+Used+By+Whitewell+Trojan+To+Communicate" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/11/facebook-used-by-whitewell-trojan-to-communicate/&amp;title=Facebook+Used+By+Whitewell+Trojan+To+Communicate" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/11/facebook-used-by-whitewell-trojan-to-communicate/&amp;t=Facebook+Used+By+Whitewell+Trojan+To+Communicate" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/11/facebook-used-by-whitewell-trojan-to-communicate/&amp;title=Facebook+Used+By+Whitewell+Trojan+To+Communicate" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/11/facebook-used-by-whitewell-trojan-to-communicate/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Windows 7 UAC (User Access Control) Ineffective Against Malware</title>
		<link>http://www.darknet.org.uk/2009/11/windows-7-uac-user-access-control-ineffective-against-malware/</link>
		<comments>http://www.darknet.org.uk/2009/11/windows-7-uac-user-access-control-ineffective-against-malware/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 08:09:25 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[sophos]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[uac]]></category>
		<category><![CDATA[user access control]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[windows 7]]></category>
		<category><![CDATA[windows 7 malware]]></category>
		<category><![CDATA[windows 7 security]]></category>
		<category><![CDATA[windows 7 uac]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2267</guid>
		<description><![CDATA[There have been a few stories about Windows 7, even one about Windows 7 UAC before and now it&#8217;s officially on sale I&#8217;d expect there to be many more.
As always malware and mass infections is a numbers game so the bad guys will always target the most popular and prolific operating systems to increase their [...]]]></description>
			<content:encoded><![CDATA[<p>There have been a few stories about <a href="http://www.darknet.org.uk/tag/windows-7/">Windows 7</a>, even one about <a href="http://www.darknet.org.uk/2009/02/windows-7-uac-vulnerable-user-mode-program-can-disable-user-access-control/">Windows 7 UAC</a> before and now it&#8217;s officially on sale I&#8217;d expect there to be many more.</p>
<p>As always malware and mass infections is a numbers game so the bad guys will always target the most popular and prolific operating systems to increase their chances of widespread infections.</p>
<p>For me personally UAC in Windows Vista was simply a pain in the ass, so much so I just turned it off completely as did most people rendering it completely ineffective. They seem to have toned it down in Windows 7 to make it less invasive and perhaps as a byproduct have made it less effective.</p>
<p><!--adsense#New468--></p>
<blockquote><p>A researcher at Sophos reports putting Windows 7&#8217;s User Account Control feature to the test and finding the technology failed to block numerous pieces of malware. Microsoft, however, stresses that UAC is only one part of Windows 7&#8217;s security.</p>
<p>A researcher at Sophos called the UAC feature in Windows 7 ineffective after numerous pieces of malware snuck by the technology in a test.</p>
<p>Microsoft first introduced User Account Control in Windows Vista to improve security. After some users complained the number of alerts it generated were annoying, the company pledged to cut down on the number of prompts in Windows 7. The move however has raised concerns in the security community, and Sophos Senior Security Adviser Chester Wisniewski said his test proves Microsoft took it a step too far.</p>
<p>Wisniewski wrote on his blog Nov. 3 that seven of the 10 pieces of malware he tested ran with the default AUC enabled in Windows 7 without generating any prompts. As part of the test, no antivirus software was installed on the system. Two of the malware samples did not work in Windows 7; of the remaining eight, only one generated a prompt, and that one still would have been installed had the user clicked yes, Wisniewski told eWEEK.</p></blockquote>
<p>I&#8217;d imagine it only throws an alert if the software being installed tries to modify system files or place itself in system directories (c:/windows etc).</p>
<p>That would make sense to me, and yes it would make it ineffective against malware and even more ineffective when the bad guys work out how it functions and adapt to that.</p>
<p>Nothing much new here though is it, run anything on Windows XP and you&#8217;ll get no warnings..so just be vigilant. I&#8217;d rather Microsoft try an educate people on good security practice rather than trying to implement half-arsed technical measures to protect against wetware ignorance.</p>
<p><!--adsense#New468--></p>
<blockquote><p>When asked about the test, Microsoft officials pointed to the other features of Windows 7 that have improved security.</p>
<p>&#8220;Windows 7 is built upon the security platform of Windows Vista, which included a defense-in-depth approach to help protect customers from malware; this includes features like Security Development Lifecycle (SDL), User Account Control (UAC), Kernel Patch Protection, Windows Service Hardening, Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP),&#8221; a spokesperson said.</p>
<p>&#8220;Windows 7 retains all of the development processes, including going through the Security Development Lifecycle, and technologies that made Windows Vista the most secure Windows operating system ever released,&#8221; the spokesperson added. &#8220;Coupled with Internet Explorer 8—which includes added malware protection with its SmartScreen Filter—and Microsoft Security Essentials, Windows 7 provides flexible security protection against malware and intrusions.&#8221;.</p></blockquote>
<p>All the above technologies are great and they do help a LOT when it comes to exploitation of vulnerabilities and trying to execute shell-code. But that&#8217;s not the biggest threat, the biggest threat is idiot users installing malware &#8216;<em>by accident</em>&#8216; on their own computers.</p>
<p>So yes, however obvious it may seem to us &#8211; you still need to install Anti-virus software on Windows 7. </p>
<p>Source: <a href="http://www.eweek.com/c/a/Security/Windows-7-UAC-Ineffective-Security-Solution-for-Malware-Sophos-Says-885011/?kc=rss">eWeek</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Windows+7+UAC+%28User+Access+Control%29+Ineffective+Against+Malware+http://bit.ly/U7YJ9+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/11/windows-7-uac-user-access-control-ineffective-against-malware/&amp;title=Windows+7+UAC+%28User+Access+Control%29+Ineffective+Against+Malware" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/11/windows-7-uac-user-access-control-ineffective-against-malware/&amp;title=Windows+7+UAC+%28User+Access+Control%29+Ineffective+Against+Malware" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/11/windows-7-uac-user-access-control-ineffective-against-malware/&amp;t=Windows+7+UAC+%28User+Access+Control%29+Ineffective+Against+Malware" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/11/windows-7-uac-user-access-control-ineffective-against-malware/&amp;title=Windows+7+UAC+%28User+Access+Control%29+Ineffective+Against+Malware" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/11/windows-7-uac-user-access-control-ineffective-against-malware/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Facebook E-mail Spam Conceals Malware Attack</title>
		<link>http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/</link>
		<comments>http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 09:47:07 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[anti sandbox]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[bredolab]]></category>
		<category><![CDATA[bredolab trojan]]></category>
		<category><![CDATA[cutwail]]></category>
		<category><![CDATA[drone]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[facebook password]]></category>
		<category><![CDATA[facebook security]]></category>
		<category><![CDATA[facebook spam]]></category>
		<category><![CDATA[hacking-facebook]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[password theft]]></category>
		<category><![CDATA[pushdo]]></category>
		<category><![CDATA[sandbox]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spammers]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[zombie]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2236</guid>
		<description><![CDATA[Facebook has had a fair share of problems, being a large community of course it&#8217;s going to be a ripe target for spammers, scammers and malware distributors.
The latest to hit is a spam e-mail claiming to be from the Facebook team that actually spreads a nasty piece of malware called Bredolab. It&#8217;s also been observed [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.darknet.org.uk/tag/facebook/">Facebook</a> has had a fair share of problems, being a large community of course it&#8217;s going to be a ripe target for spammers, scammers and malware distributors.</p>
<p>The latest to hit is a spam e-mail claiming to be from the Facebook team that actually spreads a nasty piece of malware called Bredolab. It&#8217;s also been observed the trojan will connect to additional servers to install more malware.</p>
<p>The ultimate goal as usual is to make the victims part of a <a href="http://www.darknet.org.uk/tag/botnet/">botnet</a>. </p>
<p><!--adsense#New468--></p>
<blockquote><p>Researchers at several security firms have uncovered a spam campaign targeting Facebook users. The e-mails, which pose as communications from Facebook about password resets, contain a nasty downloader that ultimately makes users part of a notorious botnet.</p>
<p>Researchers at several security firms have tied the Bredolab Trojan to a spam campaign targeting Facebook users.</p>
<p>The malware is being blasted out by spammers in e-mails claiming to come from “The Facebook Team.&#8221; Inside the e-mails is a message that the recipient&#8217;s Facebook password has been changed. In order to get the new one, recipients are told to open the accompanying attachment containing the malware.</p>
<p> Researchers at Websense told eWEEK Oct. 27 that they have observed more than 350,000 of the messages. On the company’s blog, researchers explained that the malware connects to two servers to download additional malicious files. Among them is Pushdo, also known as Cutwail.</p></blockquote>
<p>This spam campaign seems to be generating some fairly high levels of traffic meaning whoever is behind it is pretty serious and committed to this vector for disseminating malware.</p>
<p>Social engineering isn&#8217;t a new method for propagating malware as always the weakest link is never the technological barriers but is always the stupidity/greed/gullibility of humans.</p>
<p>You can ALWAYS hack the wetware.</p>
<p><!--adsense#New468--></p>
<blockquote><p>&#8220;One of the first things we saw this Trojan horse download was the Pushdo bot which began spamming out more of these Facebook password reset emails,” according to M86 Security. </p>
<p>MX Logic noted that Bredolab bypasses firewalls by injecting its own code into the legitimate process svchost.exe and explorer.exe. It also contains anti-sandbox code to thwart researchers, and creates the following files: %AppData%\wiaservg.log, %Windir%\temp\wpv861256600826.exe and %Programs%\Startup\isqsys32.exe. Bredolab also creates the processes isqsys32.exe and svchost.exe.</p>
<p>Sophos is detecting the malware as Troj/BredoZp-M or Mal/Bredo-A.</p>
<p>&#8220;Don&#8217;t make life easy for the hackers hell-bent on infecting your computer, stealing your identity and emptying your bank account &#8211; exercise caution when you receive unsolicited emails and protect your computer with up-to-date security software,&#8221; Graham Cluley, senior technology consultant at Sophos, advised in a blog post.</p></blockquote>
<p>It looks like a pretty advanced piece of malware code which evades firewall measures and even tries to thwart analysis by AV companies.</p>
<p>Anti sandbox code and process injection, these bad guys are getting smart.</p>
<p>That does not bode well for the average citizen.</p>
<p>Source: <a href="http://www.eweek.com/c/a/Security/Facebook-Password-Spam-Conceals-Malware-Attack-635899/?kc=rss">eWeek</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Facebook+E-mail+Spam+Conceals+Malware+Attack+http://bit.ly/XheUR+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;title=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;title=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;t=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/&amp;title=Facebook+E-mail+Spam+Conceals+Malware+Attack" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/10/facebook-e-mail-spam-conceals-malware-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AVG Stepping Up Consumer Anti-Virus Offerings</title>
		<link>http://www.darknet.org.uk/2009/10/avg-stepping-up-consumer-anti-virus-offerings/</link>
		<comments>http://www.darknet.org.uk/2009/10/avg-stepping-up-consumer-anti-virus-offerings/#comments</comments>
		<pubDate>Wed, 07 Oct 2009 10:27:56 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[avast]]></category>
		<category><![CDATA[avg]]></category>
		<category><![CDATA[avg 9]]></category>
		<category><![CDATA[avg antivirus]]></category>
		<category><![CDATA[avg free]]></category>
		<category><![CDATA[avira]]></category>
		<category><![CDATA[bitdefender]]></category>
		<category><![CDATA[free antivirus software]]></category>
		<category><![CDATA[free antivrus]]></category>
		<category><![CDATA[free av]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2159</guid>
		<description><![CDATA[AVG used to be THE anti-virus software a few years ago, especially with it being the first major vendor offering a free solution for home users.
If you asked any techie back in 2002 which AV should you use, the answer would invariably be AVG free (or perhaps Panda).
After that AVG just got bloated, slow and [...]]]></description>
			<content:encoded><![CDATA[<p>AVG used to be THE anti-virus software a few years ago, especially with it being the first major vendor offering a free solution for home users.</p>
<p>If you asked any techie back in 2002 which AV should you use, the answer would invariably be AVG free (or perhaps Panda).</p>
<p>After that AVG just got bloated, slow and their signature files became very weak missing a lot of nasty infections, I had to fix so many PCs running AVG that were infected up the ass with all kind of malware.</p>
<p>People starting recommending other like Avast!, Avira and BitDefender which also offer free use versions for home use.</p>
<p><!--adsense#New468--></p>
<blockquote><p>AVG is putting an emphasis on increased speed with a revamp of its free and paid for security suites.</p>
<p>The latest revamp &#8211; AVG 9.0 &#8211; boasts 50 per cent faster speed and increased ease of use. Improvements in speed have been achieved by skipping the scan of files already marked as safe in future scans unless the file structure changes. The approach also offers claimed improvements of ten to 15 per cent for boot times and memory usage, respectively.</p>
<p>The firewall module in AVG 9.0 has also been redesigned to be less intrusive (ie fewer &#8216;Do you want to allow this application online&#8217; questions) alongside tighter integration with the anti-malware scanner that forms the core of the product. This anti-malware scanner makes greater use of behaviour-based, cloud-based and white-listing technologies.</p></blockquote>
<p>I haven&#8217;t tested AVG 9.0 yet as the free version isn&#8217;t being released until later this month, but if it stands up to their claims it could be a good product. </p>
<p>Speed and bloat is definitely something they need to work on along with a more accurate scanning engine and complete signature files.</p>
<p>Let&#8217;s hope it&#8217;s not all just hype.</p>
<p><!--adsense#New468--></p>
<blockquote><p>AVG Free 9.0 will be available mid-October. Details of the features are being held back until then, but expect to see a cut-down product based on the same engine but without a firewall and other bells and whistles. Based on past form, AVG free will offer an anti-malware scanner alongside LinkScanner safe search technology.</p>
<p>AVG&#8217;s business model relies on selling into small business and getting a percentage of consumer users of its free product (perhaps around two per cent) to upgrade. The consumer end of this equation is severely threatened by Microsoft Security Essentials launch.</p>
<p>Recommendations from tech savvy friends were one of the main reasons consumers latched onto AVG in the first place. AVG lost a lot of goodwill in this area with the traffic-spewing fiasco that attached to version 8.0 of its security scanner.</p>
<p>Secondly, irrespective of the technical merits of its product, AVG is facing off against Redmond&#8217;s marketing muscle while at the same time hunting for a new chief executive.</p></blockquote>
<p>Microsoft Security Essentials is definitely a huge entry barrier for them and they will need to push hard to gain back a decent market share. There are some extremely good AV products out there now and a lot more choice for consumers.</p>
<p>Plus of course the big fat behemoths are still out there bundling their software with OEMs (Symantec, McAfee etc).</p>
<p>We shall see if it stands up to the tests of real world use.</p>
<p>Source: <a href="http://www.theregister.co.uk/2009/10/06/avg9/">The Register</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=AVG+Stepping+Up+Consumer+Anti-Virus+Offerings+http://bit.ly/jsxns+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/10/avg-stepping-up-consumer-anti-virus-offerings/&amp;title=AVG+Stepping+Up+Consumer+Anti-Virus+Offerings" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/10/avg-stepping-up-consumer-anti-virus-offerings/&amp;title=AVG+Stepping+Up+Consumer+Anti-Virus+Offerings" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/10/avg-stepping-up-consumer-anti-virus-offerings/&amp;t=AVG+Stepping+Up+Consumer+Anti-Virus+Offerings" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/10/avg-stepping-up-consumer-anti-virus-offerings/&amp;title=AVG+Stepping+Up+Consumer+Anti-Virus+Offerings" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/10/avg-stepping-up-consumer-anti-virus-offerings/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Nasty Trojan Zeus Evades Antivirus Software</title>
		<link>http://www.darknet.org.uk/2009/09/nasty-trojan-zeus-evades-antivirus-software/</link>
		<comments>http://www.darknet.org.uk/2009/09/nasty-trojan-zeus-evades-antivirus-software/#comments</comments>
		<pubDate>Fri, 18 Sep 2009 07:20:24 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[bank details]]></category>
		<category><![CDATA[bank security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[prg]]></category>
		<category><![CDATA[prg trojan]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[stealth malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[trusteer]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[zbot]]></category>
		<category><![CDATA[zbot trojan]]></category>
		<category><![CDATA[zeus]]></category>
		<category><![CDATA[zeus malware]]></category>
		<category><![CDATA[zeus trojan]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2131</guid>
		<description><![CDATA[This is one nasty piece of malware, seems like it&#8217;s working on a low level as per rootkits, there aren&#8217;t many technical details but it may well be operating on a Ring 0 level.
The level of detection by AV software is quite scary, especially since the malware is specifically targeting bank login details and it [...]]]></description>
			<content:encoded><![CDATA[<p>This is one nasty piece of malware, seems like it&#8217;s working on a low level as per <a href="http://www.darknet.org.uk/tag/rootkit/">rootkits</a>, there aren&#8217;t many technical details but it may well be operating on a <a href="http://en.wikipedia.org/wiki/Ring_%28computer_security%29">Ring 0 level</a>.</p>
<p>The level of detection by AV software is quite scary, especially since the malware is specifically targeting bank login details and it has the ability to intercept the browser process.</p>
<p>Definitely one to watch out for in your organization.</p>
<p><!--adsense#New468--></p>
<blockquote><p>One of the world&#8217;s nastiest password-stealing trojans evades detection by the majority PCs running anti-virus programs, according to a study that examined 10,000 machines.</p>
<p>Zeus, a stealthy piece of malware that sits on a PC and waits for users to log in to bank websites, is detected just 23 per cent of time by AV programs, according to the <a href="http://www.trusteer.com/files/Zeus_and_Antivirus.pdf">study [PDF]</a> released by security firm Trusteer. Even AV programs with up-to-date malware signatures were unable to identify the infection a majority of the time, the authors said.</p>
<p>Zeus, which also goes by the name Zbot and PRG, escapes detection using sophisticated techniques such as root-kit technology, the Trusteer report said. The company is able to detect it by examining the fingerprint Zeus leaves when it penetrates an infected PC&#8217;s browser process.</p></blockquote>
<p>It seems to be operating on a level that the AV engines can&#8217;t even detect as when installed with the latest signatures they still can&#8217;t alert a user they are infected.</p>
<p>It&#8217;s time AV engines get a little more advanced and hook into important processes like the browser and ensure they aren&#8217;t being tampered with or monitored.</p>
<p>Some kind of active memory protection must be possible.</p>
<p><!--adsense#New468--></p>
<blockquote><p>A recent report estimated that Zeus is the No. 1 trojan, with 3.6 million infections in the US alone, or about 1 per cent of the installed base of PCs. Trusteer&#8217;s study, which found Zeus accounted for 44 per cent of the banking malware infections, was consistent with that finding. After sneaking onto a PC, it sits quietly in the background until a user logs on to a financial website. It then sends the login credentials to a remote server in real time, sometimes by use of instant messaging programs.</p>
<p>Of Zeus-infected machines, about 31 per cent don&#8217;t run AV at all and 14 percent run AV that&#8217;s out of date. The remaining 55 per cent had AV programs that were up to date. </p></blockquote>
<p>Sitting at number 1 trojan this is a serious issue, especially with the stealthy mode in which it operates it looks like it&#8217;s going to be hard to stop the infections.</p>
<p>I someone comes up with a tool or method to prevent and detect these infections.</p>
<p>Source: <a href="http://www.theregister.co.uk/2009/09/18/zeus_evades_detection/">The Register</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Nasty+Trojan+Zeus+Evades+Antivirus+Software+http://bit.ly/66Bja+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/09/nasty-trojan-zeus-evades-antivirus-software/&amp;title=Nasty+Trojan+Zeus+Evades+Antivirus+Software" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/09/nasty-trojan-zeus-evades-antivirus-software/&amp;title=Nasty+Trojan+Zeus+Evades+Antivirus+Software" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/09/nasty-trojan-zeus-evades-antivirus-software/&amp;t=Nasty+Trojan+Zeus+Evades+Antivirus+Software" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/09/nasty-trojan-zeus-evades-antivirus-software/&amp;title=Nasty+Trojan+Zeus+Evades+Antivirus+Software" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/09/nasty-trojan-zeus-evades-antivirus-software/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Mac OS X Snow Leopard Bundled With Malware Detector</title>
		<link>http://www.darknet.org.uk/2009/08/mac-os-x-snow-leopard-bundled-with-malware-detector/</link>
		<comments>http://www.darknet.org.uk/2009/08/mac-os-x-snow-leopard-bundled-with-malware-detector/#comments</comments>
		<pubDate>Fri, 28 Aug 2009 08:43:46 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[apple malware detector]]></category>
		<category><![CDATA[apple-security]]></category>
		<category><![CDATA[mac osx security]]></category>
		<category><![CDATA[os x malware detector]]></category>
		<category><![CDATA[osx]]></category>
		<category><![CDATA[osx malware]]></category>
		<category><![CDATA[osx spyware]]></category>
		<category><![CDATA[osx viruses]]></category>
		<category><![CDATA[snow leopard]]></category>
		<category><![CDATA[snow leopard malware detector]]></category>
		<category><![CDATA[snow leopard security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2059</guid>
		<description><![CDATA[Ah we saw this coming didn&#8217;t we, back in June we reported on Apple Struggling With Security &#038; Malware and now they have shown they were paying attention.
Even though they tried to do so quietly, they are slipping a &#8216;malware detector&#8217; into the latest OS X update known as Snow Leopard.
The problem is though, it [...]]]></description>
			<content:encoded><![CDATA[<p>Ah we saw this coming didn&#8217;t we, back in June we reported on <a href="http://www.darknet.org.uk/2009/06/apple-struggling-with-security-malware/">Apple Struggling With Security &#038; Malware</a> and now they have shown they were paying attention.</p>
<p>Even though they tried to do so quietly, they are slipping a &#8216;malware detector&#8217; into the latest OS X update known as Snow Leopard.</p>
<p>The problem is though, it only scans for two trojans? Seems a bit pointless to me.</p>
<p><!--adsense#New468--></p>
<blockquote><p>Although Mac OS X is considered by many to be the most secure operating system available to end users, it does suffer from security issues. Perhaps the new malware detector in Apple&#8217;s new Mac OS X Snow Leopard release will help prove that.</p>
<p>Mac OS X is viewed by many as the most secure operating system on the market. It&#8217;s certainly considered far more secure than Microsoft&#8217;s Windows operating system.  </p>
<p>But with a report hitting the wire Wednesday claiming Apple&#8217;s new Mac OS X release, Snow Leopard, will feature a malware-detection tool, some of those beliefs might be put into question.</p>
<p>According to reports, Mac OS X will feature an application that will scan the user&#8217;s Mac for known trojans. It will also flag malicious files if they are downloaded from Safari, iChat, Entourage and a few other applications. There&#8217;s just one catch: that feature will only look for two trojans. Every other possibly damaging trojan will not be scanned for. </p></blockquote>
<p>Only two trojans? Why not make it a full on malware scanner, or at least something a little more useful than a finite scanner.</p>
<p>I mean even Windows pushes their Malicious Software Removal Tool and I&#8217;m sure it scans for more than just two threats.</p>
<p>Either way it&#8217;s a step in the right direction and Apple are acknowledging their OS isn&#8217;t bullet proof and they need to do something to address that.</p>
<p><!--adsense#New468--></p>
<blockquote><p>Over the past few months, we have seen several Mac OS X security issues hit the wire. From security outbreaks to an update that included several security fixes, it was becoming clear that Mac OS X&#8217;s reputation for strong security wasn&#8217;t as reliable as some believed. And if Mac OS X Snow Leopard does, in fact, feature that new malware detector, it could change everything. Just don&#8217;t expect Apple to change.</p>
<p>&#8220;The Mac is designed with built-in technologies that provide protection against malicious software and security threats right out of the box,&#8221; Apple wrote on the company&#8217;s Mac OS X Snow Leopard page. &#8220;However, since no system can be 100 percent immune from every threat, anti-virus software may offer additional protection.&#8221;</p>
<p>I&#8217;m a little shocked by that statement. Although Apple does admit that no system is totally immune from issues, it says anti-virus software “may” offer additional protection. I think that perpetuates the myth that end users don&#8217;t need to worry about Mac OS X security. </p></blockquote>
<p>I think the landscape for Apple is changing, as they get more users in the marketplace they WILL be exposed to more threats.</p>
<p>And more people will have their fingers in the operating system trying to break it for fun and profit. With Mac machines being sold as lifestyle products you can bet the majority of Apple users aren&#8217;t very tech savvy.</p>
<p>You can&#8217;t really compare it to the Linux desktop market, but even then Linux does have anti-virus software available for free and commercially.</p>
<p>Source: <a href="http://www.eweek.com/c/a/Security/Snow-Leopard-Reveals-Cracks-in-Apples-Mac-OS-X-Security-Reputation-392998/1/">eWeek</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Mac+OS+X+Snow+Leopard+Bundled+With+Malware+Detector+http://bit.ly/109Gmj+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/08/mac-os-x-snow-leopard-bundled-with-malware-detector/&amp;title=Mac+OS+X+Snow+Leopard+Bundled+With+Malware+Detector" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/08/mac-os-x-snow-leopard-bundled-with-malware-detector/&amp;title=Mac+OS+X+Snow+Leopard+Bundled+With+Malware+Detector" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/08/mac-os-x-snow-leopard-bundled-with-malware-detector/&amp;t=Mac+OS+X+Snow+Leopard+Bundled+With+Malware+Detector" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/08/mac-os-x-snow-leopard-bundled-with-malware-detector/&amp;title=Mac+OS+X+Snow+Leopard+Bundled+With+Malware+Detector" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/08/mac-os-x-snow-leopard-bundled-with-malware-detector/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Twitter Being Used As Botnet Command Channel</title>
		<link>http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/</link>
		<comments>http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/#comments</comments>
		<pubDate>Mon, 17 Aug 2009 04:00:59 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnet command]]></category>
		<category><![CDATA[botnet command channel]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[twitter botnet]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2024</guid>
		<description><![CDATA[Ah Twitter in the news again, the bad guys sure do keep up with new trends. After being taken offline for a while by a Joejob DDoS attack Twitter is in the news again &#8211; this time it&#8217;s being used as the command channel for a Botnet.
The normal method for controlling Botnets is via an [...]]]></description>
			<content:encoded><![CDATA[<p>Ah <a href="http://www.darknet.org.uk/tag/twitter/">Twitter</a> in the news again, the bad guys sure do keep up with new trends. After being taken offline for a while by a <a href="http://www.darknet.org.uk/2009/08/twitter-facebook-taken-offline-by-ddos-attacks/">Joejob DDoS attack Twitter</a> is in the news again &#8211; this time it&#8217;s being used as the command channel for a Botnet.</p>
<p>The normal method for controlling Botnets is via an IRC channel, usually a private keyed channel on some obscure network. A lot of people used to use EFnet due to it&#8217;s lack of network services, but nowdays there are so many networks to choose from people can keep out of the limelight.</p>
<p>Sometimes even using a private IRCd setup on a hacked server or via Dynamic DNS on a home server.</p>
<blockquote><p>For the past couple weeks, Twitter has come under attacks that besieged it with more traffic than it could handle. Now comes evidence that the microblogging website is being used to feed the very types of infected machines that took it out of commission.</p>
<p>That&#8217;s the conclusion of Jose Nazario, the manager of security research at Arbor Networks. On Thursday, he stumbled upon a Twitter account that was being used as part of an improvised update server for computers that are part of a botnet.</p>
<p>The account, which Twitter promptly suspended, issued tweets containing a single line of text that looked indecipherable to the naked eye. Using what&#8217;s known as a base64 decoder, however, the dispatches pointed to links where infected computers could receive malware updates.</p></blockquote>
<p>Ok so one such channel was discovered, how many more accounts are there on Twitter being used for nefarious purposes?</p>
<p>Very hard for anyone to track them down, especially if they don&#8217;t use standard syntax across all the accounts.</p>
<p>I&#8217;m sure Twitter will be thinking up some way to auto-discover these accounts.</p>
<p><!--adsense#New468--></p>
<blockquote><p>Master command channels used to herd large numbers of infected machines have long been one of the weak links in the botnet trade. Not only do they cost money to maintain, but they can provide tell-tale clues that help law enforcement agents to track down the miscreants running the rogue networks. Bot herders have used ICQ, internet relay chat, and other chat mediums to get around this limitation, but this appears to be the first time Twitter is known to have been employed.</p>
<p>Nazario said he&#8217;s found at least two other Twitter accounts he suspects were being used in the same fashion, but needs to do additional analysis before he can be sure. The bots using the Twitter account connected using RSS feeds, a technique that allowed them to receive each tweet in real time without the need of an account. It was unclear how many bots connected to the account.</p>
<p>Up to now, the bot designers have done a good job keeping their enterprise under wraps. The original bot software is detected by just 46 percent of the major anti-virus tools, according to this VirusTotal analysis. The updates, which appear to be affiliated with the Buzus trojan, are even stealthier, with only 22 percent of AV engines detecting it.</p></blockquote>
<p>The example discovered uses base64 encoding, so perhaps they can track down accounts with base64 strings in their feed.</p>
<p>You can read more on the Arbor Networks blog here:</p>
<p><a href="http://asert.arbornetworks.com/2009/08/twitter-based-botnet-command-channel/">Twitter-based Botnet Command Channel</a></p>
<p>Source: <a href="http://www.theregister.co.uk/2009/08/13/twitter_master_control_channel/">The Register</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Twitter+Being+Used+As+Botnet+Command+Channel+http://bit.ly/8ybso+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/&amp;title=Twitter+Being+Used+As+Botnet+Command+Channel" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/&amp;title=Twitter+Being+Used+As+Botnet+Command+Channel" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/&amp;t=Twitter+Being+Used+As+Botnet+Command+Channel" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/&amp;title=Twitter+Being+Used+As+Botnet+Command+Channel" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Chinese Firm Writes First SMS Worm</title>
		<link>http://www.darknet.org.uk/2009/07/chinese-firm-writes-first-sms-worm/</link>
		<comments>http://www.darknet.org.uk/2009/07/chinese-firm-writes-first-sms-worm/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 10:54:53 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[mobile phone virus]]></category>
		<category><![CDATA[mobile phone worm]]></category>
		<category><![CDATA[sexy space]]></category>
		<category><![CDATA[sms worm]]></category>
		<category><![CDATA[symbian sms virus]]></category>
		<category><![CDATA[symbian sms worm]]></category>
		<category><![CDATA[symbian virus]]></category>
		<category><![CDATA[symbian worm]]></category>
		<category><![CDATA[symbos yxe]]></category>
		<category><![CDATA[worms]]></category>
		<category><![CDATA[yxe worm]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1966</guid>
		<description><![CDATA[Ah another first, and once again China is at the forefront! We recently reported about a Chinese company sharing their huge malware database and now a group of Chinese companies has managed to develop the first SMS worm!
It&#8217;s a pretty cool concept, abusing the Symbian Express Signing procedure. It reminds me of the heydays of [...]]]></description>
			<content:encoded><![CDATA[<p>Ah another first, and once again China is at the forefront! We recently reported about a <a href="http://www.darknet.org.uk/2009/07/chinese-company-shares-huge-malware-database/">Chinese company sharing their huge malware database</a> and now a group of Chinese companies has managed to develop the first SMS worm!</p>
<p>It&#8217;s a pretty cool concept, abusing the <a href="https://www.symbiansigned.com/">Symbian Express Signing</a> procedure. It reminds me of the heydays of self-propagating e-mail worms when corporate e-mail servers were getting flooded because everyone in the company was sending the same attachment to everyone else in their address book.</p>
<p>Now with the application integration on mobile phones it&#8217;s now possible on mobile phones.</p>
<p><!--adsense#New468--></p>
<blockquote><p>Three Chinese companies &#8212; XiaMen Jinlonghuatian Technology, ShenZhen ChenGuangWuXian Technology, and XinZhongLi TianJin &#8212; created the &#8216;Sexy Space&#8217; worms or Yxe Worm (Worm:SymbOS/Yxe.D) and submitted to Symbian OS-based phones through the express signing procedure, said F-Secure Security Labs recently.</p>
<p>&#8220;The worm is the first text message worm in history,&#8221; said Chia Wing Fei, security response senior manager at F-Secure. &#8220;Our labs have received few confirmed reports from China and Middle East at the moment.&#8221;</p>
<p>The first stage of Symbian&#8217;s signing process is done automatically using an antivirus engine, said Chia, adding that once an application has been submitted and scanned, random samples are then submitted for human audit. </p></blockquote>
<p>So what next? Anti-virus for your mobile phone? Well that already exists (e.g. <a href="http://www.kaspersky.com/kaspersky_mobile_security">Kaspersky Mobile Security</a>).</p>
<p>I&#8217;m sure the Symbian developers will tighten up the OS and the signing procedure too. It&#8217;s an area that is definitely going to get some attention with people starting to do more on their phones (<a href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewSoftware?id=283646709&#038;mt=8">PayPal just came out with an iPhone app</a> for example) and mobile banking has been gaining popularity.</p>
<p><!--adsense#New468--></p>
<blockquote><p>However, most applications are not inspected by humans through the express signing procedure, he noted.</p>
<p>An attacker can therefore put a web link pointing to the worm&#8217;s web site into a text message and invite the user to download the worm by clicking the link, Chia said. Once activated, the worm will install itself on the device, and send a similar text messages to all phonebook contacts listed, he added.</p>
<p>&#8220;These messages are sent in your name and from your phone. It means you will pay for each SMS sent by the worm. A typical cost for a single text message might be 5 cents. If you have 500 contacts in your phone, an infection would cost you 500 times 5 cents,&#8221; Chia noted. </p></blockquote>
<p>It could cost you some money getting infected, and definitely cause a headache for you and your friends.</p>
<p>No one likes spam right? Especially when it&#8217;s serving up some self-replicating malware.</p>
<p>Source: <a href="http://www.networkworld.com/news/2009/072709-f-secure-chinese-firms-write-worlds.html">Network World</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Chinese+Firm+Writes+First+SMS+Worm+http://bit.ly/lsDbs+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/07/chinese-firm-writes-first-sms-worm/&amp;title=Chinese+Firm+Writes+First+SMS+Worm" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/07/chinese-firm-writes-first-sms-worm/&amp;title=Chinese+Firm+Writes+First+SMS+Worm" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/07/chinese-firm-writes-first-sms-worm/&amp;t=Chinese+Firm+Writes+First+SMS+Worm" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/07/chinese-firm-writes-first-sms-worm/&amp;title=Chinese+Firm+Writes+First+SMS+Worm" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/07/chinese-firm-writes-first-sms-worm/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>UAE Telco Etisalat Installs Spyware On Users Blackberries</title>
		<link>http://www.darknet.org.uk/2009/07/uae-telco-etisalat-installs-spyware-on-users-blackberries/</link>
		<comments>http://www.darknet.org.uk/2009/07/uae-telco-etisalat-installs-spyware-on-users-blackberries/#comments</comments>
		<pubDate>Fri, 24 Jul 2009 10:51:56 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[blackberry]]></category>
		<category><![CDATA[blackberry hacking]]></category>
		<category><![CDATA[blackberry privacy]]></category>
		<category><![CDATA[blackberry security]]></category>
		<category><![CDATA[blackberry spyware]]></category>
		<category><![CDATA[dubai]]></category>
		<category><![CDATA[etisalat]]></category>
		<category><![CDATA[etisalat spyware]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[uae]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1955</guid>
		<description><![CDATA[Now this is pretty disgusting behaviour from a national telco provider, but well is it really surprising in Dubai? For me..no it&#8217;s not.
I&#8217;ve spent a reasonable amount of time in Dubai on various projects, and my first surprise was Flickr being blocked. Especially as Dubai is probably the most liberal place in the Middle East. [...]]]></description>
			<content:encoded><![CDATA[<p>Now this is pretty disgusting behaviour from a national telco provider, but well is it really surprising in Dubai? For me..no it&#8217;s not.</p>
<p>I&#8217;ve spent a reasonable amount of time in Dubai on various projects, and my first surprise was Flickr being blocked. Especially as Dubai is probably the most liberal place in the Middle East. But now this massive invasion of privacy is taking it one BIG step too far, the sneaky way in which it was done is unforgivable too.</p>
<p>I hope Etisalat sees a mass exodus of users leaving their service and joining one that doesn&#8217;t try and send a copy of their e-mails and messages to some central location.</p>
<p><!--adsense#New468--></p>
<blockquote><p>An update for Blackberry users in the United Arab Emirates could allow unauthorised access to private information and e-mails. The update was prompted by a text from UAE telecoms firm Etisalat, suggesting it would improve performance. Instead, the update resulted in crashes or drastically reduced battery life.</p>
<p>Blackberry maker Research in Motion (RIM) said in a statement the update was not authorised, developed, or tested by RIM. Etisalat is a major telecommunications firm based in the UAE, with 145,000 Blackberry users on its books.</p>
<p>In the statement, RIM told customers that &#8220;Etisalat appears to have distributed a telecommunications surveillance application&#8230; independent sources have concluded that it is possible that the installed software could then enable unauthorised access to private or confidential information stored on the user&#8217;s smartphone&#8221;.</p></blockquote>
<p>With 145,000 BB users, that&#8217;s a fair amount of data they could have been harvesting with their covertly installed monitoring software.</p>
<p>Thankfully the users realised something was wrong with the crashes and terrible battery life not usually seen on Blackberry devices. And RIM have come forward in a responsible manner stating it had nothing to do with them and offering a fix for affected users.</p>
<p><!--adsense#New468--></p>
<blockquote><p>The concern over this unauthorised access only came to light when users started reporting problems with their handsets. After downloading the update, users across the country noticed significantly reduced battery life, poor reception and in some cases, handsets stopped working altogether. Users have complained that the firm&#8217;s customer service is unable to provide information on the problem. Initial advice led many users to simply buy new batteries.</p>
<p>The update has now been identified as an application developed by American firm SS8. The California-based company describes itself as a provider of &#8220;lawful electronic intercept and surveillance solutions&#8221;. It is not clear why Etisalat wanted to include the software in the download.</p>
<p>The firm issued a brief statement last week, calling the problem a &#8220;slight technical fault&#8221;, saying that the &#8220;upgrades were required for service enhancements&#8221;. </p></blockquote>
<p>Yah&#8230;sure! A slight technical fault led to installing spyware on your users phones? Ok, I believe you. How does snooping on your users classify as a service enchantment?</p>
<p>Well the competitors certainly don&#8217;t offer the same spyware service, so you can claim to be unique at least.</p>
<p>Shame on you Etisalat, really, shame on you.</p>
<p>Source: <a href="http://news.bbc.co.uk/2/hi/technology/8161190.stm">BBC</a> (<em>Thanks Navin</em>)</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=UAE+Telco+Etisalat+Installs+Spyware+On+Users+Blackberries+http://bit.ly/10dekm+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/07/uae-telco-etisalat-installs-spyware-on-users-blackberries/&amp;title=UAE+Telco+Etisalat+Installs+Spyware+On+Users+Blackberries" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/07/uae-telco-etisalat-installs-spyware-on-users-blackberries/&amp;title=UAE+Telco+Etisalat+Installs+Spyware+On+Users+Blackberries" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/07/uae-telco-etisalat-installs-spyware-on-users-blackberries/&amp;t=UAE+Telco+Etisalat+Installs+Spyware+On+Users+Blackberries" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/07/uae-telco-etisalat-installs-spyware-on-users-blackberries/&amp;title=UAE+Telco+Etisalat+Installs+Spyware+On+Users+Blackberries" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/07/uae-telco-etisalat-installs-spyware-on-users-blackberries/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
