<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: e-Banking Bandits Stole $465,000 From Calif. Escrow Firm</title>
	<atom:link href="http://krebsonsecurity.com/2010/06/e-banking-bandits-stole-465000-from-calif-escrow-firm/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/06/e-banking-bandits-stole-465000-from-calif-escrow-firm/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 23 May 2012 21:31:36 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: self-defeating assumption?</title>
		<link>http://krebsonsecurity.com/2010/06/e-banking-bandits-stole-465000-from-calif-escrow-firm/comment-page-1/#comment-16232</link>
		<dc:creator>self-defeating assumption?</dc:creator>
		<pubDate>Thu, 23 Dec 2010 01:31:46 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3796#comment-16232</guid>
		<description>&lt;i&gt;&quot;No online banking authentication system works unless it &lt;b&gt;starts&lt;/b&gt; with the premise that the &lt;b&gt;customer&lt;/b&gt;’s machine &lt;b&gt;is&lt;/b&gt; already compromised by &lt;b&gt;malware&lt;/b&gt; that gives thieves &lt;b&gt;complete&lt;/b&gt; control over the customer system&quot;&lt;/i&gt;
IOW, bank server must assume the client browser is not controlled by the customer. In which case, the only rational choice for the bank server, is to block the client ip. 
Seriously, if the bank assumes all customer interactions are fake/hijacked/impersonated, the bank and customer should give up while they&#039;re ahead. 

I don&#039;t see how bank can be responsible for customer&#039;s equipment, unless the bank leases dedicated &quot;untamperable&quot; package (like cable tv box, or creditcard swipe and approve gizmo, postage meter, dsl modem, etc.) for customer&#039;s location .. a personal atm? Embedded os? Biometric &#039;dongle&#039; strategy? (But, &quot;if you have to ask &#039;how much&#039;, you can&#039;t afford it&quot;)</description>
		<content:encoded><![CDATA[<p><i>&#8220;No online banking authentication system works unless it <b>starts</b> with the premise that the <b>customer</b>’s machine <b>is</b> already compromised by <b>malware</b> that gives thieves <b>complete</b> control over the customer system&#8221;</i><br />
IOW, bank server must assume the client browser is not controlled by the customer. In which case, the only rational choice for the bank server, is to block the client ip.<br />
Seriously, if the bank assumes all customer interactions are fake/hijacked/impersonated, the bank and customer should give up while they&#8217;re ahead. </p>
<p>I don&#8217;t see how bank can be responsible for customer&#8217;s equipment, unless the bank leases dedicated &#8220;untamperable&#8221; package (like cable tv box, or creditcard swipe and approve gizmo, postage meter, dsl modem, etc.) for customer&#8217;s location .. a personal atm? Embedded os? Biometric &#8216;dongle&#8217; strategy? (But, &#8220;if you have to ask &#8216;how much&#8217;, you can&#8217;t afford it&#8221;)</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-16232" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('16232', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-16232-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-16232" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('16232', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-16232-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: -</title>
		<link>http://krebsonsecurity.com/2010/06/e-banking-bandits-stole-465000-from-calif-escrow-firm/comment-page-1/#comment-16229</link>
		<dc:creator>-</dc:creator>
		<pubDate>Thu, 23 Dec 2010 01:06:44 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3796#comment-16229</guid>
		<description>Crime victims aren&#039;t at fault for crimes they suffer. (Though blaming the victim has become a popular &#039;meme&#039; in this &quot;brashly&quot; offensive/antagonistic era of conservative political correctness.)
However, crime exists, so people are better off defending themselves. 
Community college business curriculum should add security methods, though this solution assumes &quot;struggling&quot; business people take business courses.</description>
		<content:encoded><![CDATA[<p>Crime victims aren&#8217;t at fault for crimes they suffer. (Though blaming the victim has become a popular &#8216;meme&#8217; in this &#8220;brashly&#8221; offensive/antagonistic era of conservative political correctness.)<br />
However, crime exists, so people are better off defending themselves.<br />
Community college business curriculum should add security methods, though this solution assumes &#8220;struggling&#8221; business people take business courses.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-16229" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('16229', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-16229-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-16229" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('16229', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-16229-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: -</title>
		<link>http://krebsonsecurity.com/2010/06/e-banking-bandits-stole-465000-from-calif-escrow-firm/comment-page-1/#comment-16228</link>
		<dc:creator>-</dc:creator>
		<pubDate>Thu, 23 Dec 2010 00:54:44 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3796#comment-16228</guid>
		<description>i&#039;ve experienced atms that rejected simple (not mine) passwords, with no explanation.
just try another day.</description>
		<content:encoded><![CDATA[<p>i&#8217;ve experienced atms that rejected simple (not mine) passwords, with no explanation.<br />
just try another day.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-16228" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('16228', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-16228-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-16228" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('16228', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-16228-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: curiousity exploited the pc?</title>
		<link>http://krebsonsecurity.com/2010/06/e-banking-bandits-stole-465000-from-calif-escrow-firm/comment-page-1/#comment-16227</link>
		<dc:creator>curiousity exploited the pc?</dc:creator>
		<pubDate>Thu, 23 Dec 2010 00:52:18 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3796#comment-16227</guid>
		<description>retail customers should just avoid online financial activity. 

businesses with multiple daily transactions need to learn to do their job. the pc&#039;s security shouldn&#039;t have loaded the trojan.</description>
		<content:encoded><![CDATA[<p>retail customers should just avoid online financial activity. </p>
<p>businesses with multiple daily transactions need to learn to do their job. the pc&#8217;s security shouldn&#8217;t have loaded the trojan.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-16227" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('16227', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-16227-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-16227" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('16227', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-16227-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: -</title>
		<link>http://krebsonsecurity.com/2010/06/e-banking-bandits-stole-465000-from-calif-escrow-firm/comment-page-1/#comment-16226</link>
		<dc:creator>-</dc:creator>
		<pubDate>Thu, 23 Dec 2010 00:47:15 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3796#comment-16226</guid>
		<description>1. backup documents and bookmarks (and whatever similar). 2. fresh install</description>
		<content:encoded><![CDATA[<p>1. backup documents and bookmarks (and whatever similar). 2. fresh install</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-16226" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('16226', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-16226-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-16226" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('16226', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-16226-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: David McCullough</title>
		<link>http://krebsonsecurity.com/2010/06/e-banking-bandits-stole-465000-from-calif-escrow-firm/comment-page-1/#comment-7468</link>
		<dc:creator>David McCullough</dc:creator>
		<pubDate>Sun, 11 Jul 2010 22:59:00 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3796#comment-7468</guid>
		<description>Compromise is a matter of degree. I think the point is that there is no perfect solution. However, a Live CD  banking session is far safer than an un-patched Windows XP installation since the latter is the attack vector of least resistance right now.

To eliminate the risk, businesses would have to start physically visiting their banks again and sever all online capability. That is something that most businesses probably won&#039;t consider unless they become a victim and possibly show up on Brian&#039;s blog. 

But, based on the tricks Brian reported on here, the thieves are getting cleverer all the time. It could be a matter of time until they can bypass the business and steal directly from the bank.

So, I doubt that banking will ever be completely safe in the modern cyber-world. That&#039;s not comforting to me as one of those small business owners.</description>
		<content:encoded><![CDATA[<p>Compromise is a matter of degree. I think the point is that there is no perfect solution. However, a Live CD  banking session is far safer than an un-patched Windows XP installation since the latter is the attack vector of least resistance right now.</p>
<p>To eliminate the risk, businesses would have to start physically visiting their banks again and sever all online capability. That is something that most businesses probably won&#8217;t consider unless they become a victim and possibly show up on Brian&#8217;s blog. </p>
<p>But, based on the tricks Brian reported on here, the thieves are getting cleverer all the time. It could be a matter of time until they can bypass the business and steal directly from the bank.</p>
<p>So, I doubt that banking will ever be completely safe in the modern cyber-world. That&#8217;s not comforting to me as one of those small business owners.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7468" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7468', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7468-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7468" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7468', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7468-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Phil Cooper</title>
		<link>http://krebsonsecurity.com/2010/06/e-banking-bandits-stole-465000-from-calif-escrow-firm/comment-page-1/#comment-7418</link>
		<dc:creator>Phil Cooper</dc:creator>
		<pubDate>Thu, 08 Jul 2010 21:48:04 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3796#comment-7418</guid>
		<description>I LIKE operating in that 1% crowd.  The fact that my **** OS is only 1% of the market makes it an unattractive target for hackers and crackers.  I&#039;ve encountered malware sites that tried to take control of the browser and install .exe files on my system, but failed.  It&#039;s a little unnerving to actually watch an attack in progress, but with my **** system all it takes is a couple of mouse clicks and the offender is gone.</description>
		<content:encoded><![CDATA[<p>I LIKE operating in that 1% crowd.  The fact that my **** OS is only 1% of the market makes it an unattractive target for hackers and crackers.  I&#8217;ve encountered malware sites that tried to take control of the browser and install .exe files on my system, but failed.  It&#8217;s a little unnerving to actually watch an attack in progress, but with my **** system all it takes is a couple of mouse clicks and the offender is gone.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7418" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7418', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7418-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7418" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7418', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7418-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Tomato</title>
		<link>http://krebsonsecurity.com/2010/06/e-banking-bandits-stole-465000-from-calif-escrow-firm/comment-page-1/#comment-7378</link>
		<dc:creator>Tomato</dc:creator>
		<pubDate>Wed, 07 Jul 2010 21:02:52 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3796#comment-7378</guid>
		<description>&quot;The things that make you go hmmm...&quot;  Peter&#039;s ridiculous statement reminds me of what a silly customer of mine said to me recently.  Something to the tune of, &quot;I recently got hacked while surfing the net via my ISP that I pay good money to each month, and felt that they should cover the costs of rebuilding my computer since they allowed me to get hacked by letting that garbage through in the first place.  Even after a good 30 minutes and two managers, they wouldn&#039;t as much as allow me to skip a single bill!  In the future, how can I force them to pay me for your work so that I don&#039;t lose any money when it happens again?&quot;  He thought I had to pickup my lower jaw because they didn&#039;t pay him...is it ethical not to tell him the real reason why?</description>
		<content:encoded><![CDATA[<p>&#8220;The things that make you go hmmm&#8230;&#8221;  Peter&#8217;s ridiculous statement reminds me of what a silly customer of mine said to me recently.  Something to the tune of, &#8220;I recently got hacked while surfing the net via my ISP that I pay good money to each month, and felt that they should cover the costs of rebuilding my computer since they allowed me to get hacked by letting that garbage through in the first place.  Even after a good 30 minutes and two managers, they wouldn&#8217;t as much as allow me to skip a single bill!  In the future, how can I force them to pay me for your work so that I don&#8217;t lose any money when it happens again?&#8221;  He thought I had to pickup my lower jaw because they didn&#8217;t pay him&#8230;is it ethical not to tell him the real reason why?</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7378" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7378', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7378-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7378" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7378', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7378-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: McLovin</title>
		<link>http://krebsonsecurity.com/2010/06/e-banking-bandits-stole-465000-from-calif-escrow-firm/comment-page-1/#comment-7376</link>
		<dc:creator>McLovin</dc:creator>
		<pubDate>Wed, 07 Jul 2010 20:02:24 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3796#comment-7376</guid>
		<description>Last sentence was meant to say, &quot;wouldn&#039;t they have worked to stop the tunnel that was described?&quot;  Very interested in comments about such software, and if they wouldn&#039;t work for some reason.</description>
		<content:encoded><![CDATA[<p>Last sentence was meant to say, &#8220;wouldn&#8217;t they have worked to stop the tunnel that was described?&#8221;  Very interested in comments about such software, and if they wouldn&#8217;t work for some reason.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7376" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7376', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7376-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7376" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7376', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7376-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: McLovin</title>
		<link>http://krebsonsecurity.com/2010/06/e-banking-bandits-stole-465000-from-calif-escrow-firm/comment-page-1/#comment-7375</link>
		<dc:creator>McLovin</dc:creator>
		<pubDate>Wed, 07 Jul 2010 19:58:52 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3796#comment-7375</guid>
		<description>xAdmin made some very interesting statements about the PEBCAK error at the root of the problem.  The article eludes to two people needing to perform the transaction, and it seems both were duped by a simple email attack that all of us are hit with on any given day were they not?  This may be a stupid question given someone will spout off with (ZERO-DAY!), but where were the anti-virus program and anti-spyware programs in all of this?  Did they even have any of this protection, as it sounds like they were foolish enough to have none.  Or, did they win the lotto and land the zero-day vunlerability (which is doubtful)??  Even if it was a zero-day, some anti-spyware and software lockdown and block anything from infecting and changing the computers settings, so why wouldn&#039;t they be using something like that on so critical a system(s)?  Black-Ice and programs of such nature block anything outbound, so even if a Trojan got in, wouldn&#039;t they work to tunnel that was described?

Anyone?</description>
		<content:encoded><![CDATA[<p>xAdmin made some very interesting statements about the PEBCAK error at the root of the problem.  The article eludes to two people needing to perform the transaction, and it seems both were duped by a simple email attack that all of us are hit with on any given day were they not?  This may be a stupid question given someone will spout off with (ZERO-DAY!), but where were the anti-virus program and anti-spyware programs in all of this?  Did they even have any of this protection, as it sounds like they were foolish enough to have none.  Or, did they win the lotto and land the zero-day vunlerability (which is doubtful)??  Even if it was a zero-day, some anti-spyware and software lockdown and block anything from infecting and changing the computers settings, so why wouldn&#8217;t they be using something like that on so critical a system(s)?  Black-Ice and programs of such nature block anything outbound, so even if a Trojan got in, wouldn&#8217;t they work to tunnel that was described?</p>
<p>Anyone?</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7375" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7375', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7375-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7375" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7375', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7375-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 6/31 queries in 0.010 seconds using memcached
Object Caching 957/989 objects using memcached

Served from: krebsonsecurity.com @ 2012-05-23 18:53:39 -->
