<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Zeus Attack Spoofs NSA, Targets .gov and .mil</title>
	<atom:link href="http://krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 19 Jun 2013 20:40:46 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: SpliFF</title>
		<link>http://krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/comment-page-2/#comment-19112</link>
		<dc:creator>SpliFF</dc:creator>
		<pubDate>Fri, 04 Mar 2011 05:28:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=954#comment-19112</guid>
		<description><![CDATA[I&#039;ve run my primary PC on linux for 10+ years and in all that time not one break-in or malware infection despite having no firewall or antivirus software. I&#039;ve even inserted infected USB sticks with autorun malware plainly visible on the drive. I&#039;ve opened numerous suspicious PDFs in xpdf, visited known attack sites with Firefox and NoScript, I open Word docs with impunity via LibreOffice and connect regularly to infected networks.

All my software and dependencies install and update automatically from trustworthy repositories. I&#039;ve never paid a cent for any of my software because it&#039;s all free. I&#039;ve never been given a document I couldn&#039;t open, a disk format I couldn&#039;t read or a file server I couldn&#039;t connect to.

Why anybody would pay for commercial software like Windows, MacOSX or Office when those tools are so easily and commonly exploited is completely beyond me. I wouldn&#039;t even accept those programs as gifts! Frankly users of Microsoft/Apple/Adobe software get exactly what they deserve when they bring me their toasted systems every six months and pay me $120/hr to recover what&#039;s left of their system. 

Using the above mentioned software in a home environment is bad enough, but using them in a commercial environment is the height of stupidity. In a military, healthcare, financial or government institution it is entirely unforgivable! I would go so far as to call it an act of treason equivalent to arming a modern defence force with bolt action rifles. God help us all once this sort of software finds general use in automotives, military hardware and hazardous industries!

You want to argue that hackers would exploit linux more often if we all used it? Sure they would - but since ignorance is such a universal property amongst computer users that isn&#039;t likely to happen any time soon.]]></description>
		<content:encoded><![CDATA[<p>I&#8217;ve run my primary PC on linux for 10+ years and in all that time not one break-in or malware infection despite having no firewall or antivirus software. I&#8217;ve even inserted infected USB sticks with autorun malware plainly visible on the drive. I&#8217;ve opened numerous suspicious PDFs in xpdf, visited known attack sites with Firefox and NoScript, I open Word docs with impunity via LibreOffice and connect regularly to infected networks.</p>
<p>All my software and dependencies install and update automatically from trustworthy repositories. I&#8217;ve never paid a cent for any of my software because it&#8217;s all free. I&#8217;ve never been given a document I couldn&#8217;t open, a disk format I couldn&#8217;t read or a file server I couldn&#8217;t connect to.</p>
<p>Why anybody would pay for commercial software like Windows, MacOSX or Office when those tools are so easily and commonly exploited is completely beyond me. I wouldn&#8217;t even accept those programs as gifts! Frankly users of Microsoft/Apple/Adobe software get exactly what they deserve when they bring me their toasted systems every six months and pay me $120/hr to recover what&#8217;s left of their system. </p>
<p>Using the above mentioned software in a home environment is bad enough, but using them in a commercial environment is the height of stupidity. In a military, healthcare, financial or government institution it is entirely unforgivable! I would go so far as to call it an act of treason equivalent to arming a modern defence force with bolt action rifles. God help us all once this sort of software finds general use in automotives, military hardware and hazardous industries!</p>
<p>You want to argue that hackers would exploit linux more often if we all used it? Sure they would &#8211; but since ignorance is such a universal property amongst computer users that isn&#8217;t likely to happen any time soon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JAson</title>
		<link>http://krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/comment-page-2/#comment-12002</link>
		<dc:creator>JAson</dc:creator>
		<pubDate>Mon, 01 Nov 2010 00:25:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=954#comment-12002</guid>
		<description><![CDATA[Outlawing windows from making operating systems would really really help the situation out greatly.  Sure everyone would have to learn new stuff, but in the case of new and complex parental controls for tv, parent were willing to learn something new to make them feel safer or their kids safer, so why not extend that same logic to protecting ones self.  Learn to use something new, the free model seems to be the one that is out to protect you, after all Microsoft collects tons of personal information for law enforcement use.  Linux is a good start, a linux kernal seems to be the right model, seems other try to copy the wy it works anyways, but they just dont quite get it right.

Windows may look pretty , but it sure dont run so pretty, and ubuntu for one outdoes windows when it comes to eye candy and usefullness.  Im not even commenting on mac, becsue its liek back in the day when everyone realize AOL was a fake ISP, the mac isnt a real pc, more like nazzi central with every mac lookign the same.

So ya elimiate windows and watch how fast the talk of virii and major sec issues drops.  Maybe not all but after all, i do think windows system is the gateway for the new attackware platform of stuxnet, so to what end will microsilly decode to so simething serious abtou their issues?  Will windows be resonsible for an accidental nuke launch?]]></description>
		<content:encoded><![CDATA[<p>Outlawing windows from making operating systems would really really help the situation out greatly.  Sure everyone would have to learn new stuff, but in the case of new and complex parental controls for tv, parent were willing to learn something new to make them feel safer or their kids safer, so why not extend that same logic to protecting ones self.  Learn to use something new, the free model seems to be the one that is out to protect you, after all Microsoft collects tons of personal information for law enforcement use.  Linux is a good start, a linux kernal seems to be the right model, seems other try to copy the wy it works anyways, but they just dont quite get it right.</p>
<p>Windows may look pretty , but it sure dont run so pretty, and ubuntu for one outdoes windows when it comes to eye candy and usefullness.  Im not even commenting on mac, becsue its liek back in the day when everyone realize AOL was a fake ISP, the mac isnt a real pc, more like nazzi central with every mac lookign the same.</p>
<p>So ya elimiate windows and watch how fast the talk of virii and major sec issues drops.  Maybe not all but after all, i do think windows system is the gateway for the new attackware platform of stuxnet, so to what end will microsilly decode to so simething serious abtou their issues?  Will windows be resonsible for an accidental nuke launch?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CB</title>
		<link>http://krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/comment-page-1/#comment-11763</link>
		<dc:creator>CB</dc:creator>
		<pubDate>Tue, 26 Oct 2010 16:40:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=954#comment-11763</guid>
		<description><![CDATA[&quot;start all over again&quot;.....hopefully Google will help us to start over.

Most of us have heard the rumors that Google is working on an operating system.  We can only hope.

Google is an internet company, with lots of talented employees.  I&#039;m hoping that anything they come up with would be miles ahead of MS on the security front.]]></description>
		<content:encoded><![CDATA[<p>&#8220;start all over again&#8221;&#8230;..hopefully Google will help us to start over.</p>
<p>Most of us have heard the rumors that Google is working on an operating system.  We can only hope.</p>
<p>Google is an internet company, with lots of talented employees.  I&#8217;m hoping that anything they come up with would be miles ahead of MS on the security front.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Reflections on RSA &#8211; Security is Really a Control and Data Management Problem &#171; Currents from WaveLength Market Analytics</title>
		<link>http://krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/comment-page-2/#comment-3262</link>
		<dc:creator>Reflections on RSA &#8211; Security is Really a Control and Data Management Problem &#171; Currents from WaveLength Market Analytics</dc:creator>
		<pubDate>Fri, 05 Mar 2010 16:17:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=954#comment-3262</guid>
		<description><![CDATA[[...] there are individuals motivated by greed, power and personal gain (the riseand co-opting of the Zeus attacks, which originally targeted financial institutions, is just one example &#8211; to date it has [...]]]></description>
		<content:encoded><![CDATA[<p>[...] there are individuals motivated by greed, power and personal gain (the riseand co-opting of the Zeus attacks, which originally targeted financial institutions, is just one example &#8211; to date it has [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ZBOT Variant Spoofs the NIC to Spam Other Government Agencies &#171; Spyware Explained</title>
		<link>http://krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/comment-page-2/#comment-3006</link>
		<dc:creator>ZBOT Variant Spoofs the NIC to Spam Other Government Agencies &#171; Spyware Explained</dc:creator>
		<pubDate>Mon, 01 Mar 2010 03:56:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=954#comment-3006</guid>
		<description><![CDATA[[...] security journalist, Brian Krebs, in his blog confirmed that these messages were spoofed due to several obvious reasons, [...]]]></description>
		<content:encoded><![CDATA[<p>[...] security journalist, Brian Krebs, in his blog confirmed that these messages were spoofed due to several obvious reasons, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Craig Spiezle</title>
		<link>http://krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/comment-page-2/#comment-2505</link>
		<dc:creator>Craig Spiezle</dc:creator>
		<pubDate>Mon, 22 Feb 2010 16:05:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=954#comment-2505</guid>
		<description><![CDATA[The Online Trust Alliance (OTA) has been raising the concerns about this exposure for nearly a year.  Last April we posted a failing report card for failing to protect their domains from such spoofing. https://otalliance.org/news/releases/OTA_414reportcard.html.   We are encouraged by the recent willingness to proceed with best practices now adopted by many leading businesses.   In April we will be updating this report to include the top 50 .gov and .mil sites as well as offering the targeted sites training to help implement industry standards.]]></description>
		<content:encoded><![CDATA[<p>The Online Trust Alliance (OTA) has been raising the concerns about this exposure for nearly a year.  Last April we posted a failing report card for failing to protect their domains from such spoofing. <a href="https://otalliance.org/news/releases/OTA_414reportcard.html" rel="nofollow">https://otalliance.org/news/releases/OTA_414reportcard.html</a>.   We are encouraged by the recent willingness to proceed with best practices now adopted by many leading businesses.   In April we will be updating this report to include the top 50 .gov and .mil sites as well as offering the targeted sites training to help implement industry standards.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CyberBits 16 Feb 2010 &#124; Cyber Loop</title>
		<link>http://krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/comment-page-2/#comment-2479</link>
		<dc:creator>CyberBits 16 Feb 2010 &#124; Cyber Loop</dc:creator>
		<pubDate>Sun, 21 Feb 2010 07:02:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=954#comment-2479</guid>
		<description><![CDATA[[...] Krebs on Security By Brian Krebs http://www.krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/ [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Krebs on Security By Brian Krebs <a href="http://www.krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/" rel="nofollow">http://www.krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phishing News of the Week &#8211; 19 February 2010 &#171; Truedomain Blog</title>
		<link>http://krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/comment-page-2/#comment-2438</link>
		<dc:creator>Phishing News of the Week &#8211; 19 February 2010 &#171; Truedomain Blog</dc:creator>
		<pubDate>Sat, 20 Feb 2010 00:21:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=954#comment-2438</guid>
		<description><![CDATA[[...] eSecurity Planet &#124; Identity Theft Cost Victims $54B in 2009 Better Business Bureau &#124; Phishing Concerns Already on Google Buzz Krebs on Security &#124; Zeus Attack Spoofs NSA, Targets .gov and .mil Domains [...]]]></description>
		<content:encoded><![CDATA[<p>[...] eSecurity Planet | Identity Theft Cost Victims $54B in 2009 Better Business Bureau | Phishing Concerns Already on Google Buzz Krebs on Security | Zeus Attack Spoofs NSA, Targets .gov and .mil Domains [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kneber BotNet / Zeus Trojan Strikes! &#124; Complete Source</title>
		<link>http://krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/comment-page-2/#comment-2391</link>
		<dc:creator>Kneber BotNet / Zeus Trojan Strikes! &#124; Complete Source</dc:creator>
		<pubDate>Fri, 19 Feb 2010 05:33:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=954#comment-2391</guid>
		<description><![CDATA[[...] Multi-Vector. There seem to be several ways this attack was propagated, including via social networks, through spam email and even very convincing phishing emails, and by using social engineering hooks. [For more on the very elaborate spoofing effort aimed at the NSA and .gov / .mil sites, see Brian Krebs&#039; post here.] [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Multi-Vector. There seem to be several ways this attack was propagated, including via social networks, through spam email and even very convincing phishing emails, and by using social engineering hooks. [For more on the very elaborate spoofing effort aimed at the NSA and .gov / .mil sites, see Brian Krebs&#39; post here.] [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Usan como señuelo una advertencia sobre ataque de ZeuS &#124; ooo la la la la : ) HACKED ! by ! mOmiX ! Sory Security Team :(((</title>
		<link>http://krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/comment-page-2/#comment-2143</link>
		<dc:creator>Usan como señuelo una advertencia sobre ataque de ZeuS &#124; ooo la la la la : ) HACKED ! by ! mOmiX ! Sory Security Team :(((</dc:creator>
		<pubDate>Wed, 17 Feb 2010 12:10:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=954#comment-2143</guid>
		<description><![CDATA[[...] criminales han hecho participar la columna que escribí la semana pasada sobre los ataques dirigidos del Troyano ZeuS hacia sistemas militares y gubernamentales: los artistas de la estafa ahora estan enviando spam que incluye los primeros párrafos de esta [...]]]></description>
		<content:encoded><![CDATA[<p>[...] criminales han hecho participar la columna que escribí la semana pasada sobre los ataques dirigidos del Troyano ZeuS hacia sistemas militares y gubernamentales: los artistas de la estafa ahora estan enviando spam que incluye los primeros párrafos de esta [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching using memcached
Object Caching 374/380 objects using memcached

 Served from: krebsonsecurity.com @ 2013-06-19 17:31:54 by W3 Total Cache -->