<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: &#8216;Citadel&#8217; Trojan Touts Trouble-Ticket System</title>
	<atom:link href="http://krebsonsecurity.com/2012/01/citadel-trojan-touts-trouble-ticket-system/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2012/01/citadel-trojan-touts-trouble-ticket-system/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Mon, 21 May 2012 22:21:48 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: roflem</title>
		<link>http://krebsonsecurity.com/2012/01/citadel-trojan-touts-trouble-ticket-system/comment-page-1/#comment-57379</link>
		<dc:creator>roflem</dc:creator>
		<pubDate>Tue, 14 Feb 2012 19:45:48 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13474#comment-57379</guid>
		<description>I wonder what CIS means when they say :
&quot;Our software does not work on Russian-language systems. If a Russian or Ukrainian layout is detected, the bot terminates. 

This is done to prevent installs on CIS systems. You may disagree, but that’s taboo for us.&quot;

??????</description>
		<content:encoded><![CDATA[<p>I wonder what CIS means when they say :<br />
&#8220;Our software does not work on Russian-language systems. If a Russian or Ukrainian layout is detected, the bot terminates. </p>
<p>This is done to prevent installs on CIS systems. You may disagree, but that’s taboo for us.&#8221;</p>
<p>??????</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-57379" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('57379', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-57379-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-57379" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('57379', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-57379-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: helly</title>
		<link>http://krebsonsecurity.com/2012/01/citadel-trojan-touts-trouble-ticket-system/comment-page-1/#comment-49185</link>
		<dc:creator>helly</dc:creator>
		<pubDate>Wed, 01 Feb 2012 23:43:06 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13474#comment-49185</guid>
		<description>Sadly it generally doesn&#039;t work out that these guys can be easily caught by the methods you mention. They tend not to funnel their money directly through US banks for one thing. There are also cash services like Liberty Reserve or Web Money that make these type of transactions even more difficult to trace. 

In addition there are also escrow services out there that these guys can use to ensure their transactions are safe. 

And finally even if you do track one of these guys down, getting local law enforcement to prosecute can be extremely challenging. These guys tend not to operate in countries where law enforcement is on the ball with this stuff. 

There is a whole slew of other challenges I&#039;m glossing over, but hopefully that provides you a bit more insight into how these guys do that stuff.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFFFCC !important"><p>Sadly it generally doesn&#8217;t work out that these guys can be easily caught by the methods you mention. They tend not to funnel their money directly through US banks for one thing. There are also cash services like Liberty Reserve or Web Money that make these type of transactions even more difficult to trace. </p>
<p>In addition there are also escrow services out there that these guys can use to ensure their transactions are safe. </p>
<p>And finally even if you do track one of these guys down, getting local law enforcement to prosecute can be extremely challenging. These guys tend not to operate in countries where law enforcement is on the ball with this stuff. </p>
<p>There is a whole slew of other challenges I&#8217;m glossing over, but hopefully that provides you a bit more insight into how these guys do that stuff.</p>
</div><div class="CommentRating">Well-loved. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-49185" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('49185', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-49185-up" style="font-size:14px; color:#009933;">6</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-49185" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('49185', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-49185-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: ZoomZoom</title>
		<link>http://krebsonsecurity.com/2012/01/citadel-trojan-touts-trouble-ticket-system/comment-page-1/#comment-48279</link>
		<dc:creator>ZoomZoom</dc:creator>
		<pubDate>Wed, 25 Jan 2012 19:56:19 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13474#comment-48279</guid>
		<description>Someone break this down for me, please.  We have developers that actively tout their latest and greatest malware versions, offer support, and charge one time and/or maintenance fees for the software and/or support.  

It looks like this would require registering domains and setting up payment systems, which, with some effort, could be tied to a real, living and breathing human being with a birth certificate and a government-issued ID of some sort...not just a witty handle on a forum somewhere.

With the amount of Customer Identification Program (CIP) required by US banks (and I am assuming similar laws in foreign countries), the banks WILL have identifying information on these individuals, even if they are IDing them only as a signitory or beneficial owner on an account that&#039;s receiving payments for the malware.

Or maybe I am ignorant and overly optimistic...?</description>
		<content:encoded><![CDATA[<p>Someone break this down for me, please.  We have developers that actively tout their latest and greatest malware versions, offer support, and charge one time and/or maintenance fees for the software and/or support.  </p>
<p>It looks like this would require registering domains and setting up payment systems, which, with some effort, could be tied to a real, living and breathing human being with a birth certificate and a government-issued ID of some sort&#8230;not just a witty handle on a forum somewhere.</p>
<p>With the amount of Customer Identification Program (CIP) required by US banks (and I am assuming similar laws in foreign countries), the banks WILL have identifying information on these individuals, even if they are IDing them only as a signitory or beneficial owner on an account that&#8217;s receiving payments for the malware.</p>
<p>Or maybe I am ignorant and overly optimistic&#8230;?</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-48279" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('48279', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-48279-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-48279" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('48279', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-48279-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://krebsonsecurity.com/2012/01/citadel-trojan-touts-trouble-ticket-system/comment-page-1/#comment-48210</link>
		<dc:creator>John</dc:creator>
		<pubDate>Tue, 24 Jan 2012 21:57:19 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13474#comment-48210</guid>
		<description>CP means child porn</description>
		<content:encoded><![CDATA[<p>CP means child porn</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-48210" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('48210', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-48210-up" style="font-size:14px; color:#009933;">3</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-48210" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('48210', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-48210-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: prairie_sailor</title>
		<link>http://krebsonsecurity.com/2012/01/citadel-trojan-touts-trouble-ticket-system/comment-page-1/#comment-48209</link>
		<dc:creator>prairie_sailor</dc:creator>
		<pubDate>Tue, 24 Jan 2012 21:40:06 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13474#comment-48209</guid>
		<description>Unfortunately most end users don&#039;t know what to do when the update boxes for Flash/Java etc pop up so they tend to ignore them.  The end result - horribly out of date software with easily exploitable vulnerabilities.  The only other solution I see in the end is to start requiring a licence to use a computer (kind of like a driver&#039;s licence) - like that&#039;s going to happen any time soon.</description>
		<content:encoded><![CDATA[<p>Hidden due to low comment rating. <a href="javascript:crSwitchDisplay('ckhide-48209');" title="Click to see comment">Click here to see</a>.</p><div id='ckhide-48209' style="display:none; opacity:0.6;filter:alpha(opacity=60) !important;"><p>Unfortunately most end users don&#8217;t know what to do when the update boxes for Flash/Java etc pop up so they tend to ignore them.  The end result &#8211; horribly out of date software with easily exploitable vulnerabilities.  The only other solution I see in the end is to start requiring a licence to use a computer (kind of like a driver&#8217;s licence) &#8211; like that&#8217;s going to happen any time soon.</p>
</div><div class="CommentRating">Poorly-rated. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-48209" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('48209', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-48209-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-48209" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('48209', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-48209-down" style="font-size:14px; color:#990033;">6</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://krebsonsecurity.com/2012/01/citadel-trojan-touts-trouble-ticket-system/comment-page-1/#comment-48185</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Tue, 24 Jan 2012 03:55:16 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13474#comment-48185</guid>
		<description>My problem with approach is that it makes the already ignorant user (which is most users) even more dependent on the major software vendors. I&#039;m reminded of the old saying that the only thing it takes for evil to flourish is for good people to run to those in authority. In some ways I fear the omnipotent reach Google/Java more than I do these guys.  

There has to be a better solution than an ever escalating arms race between various groups of brainiacs. At a certain point all the members of the intellectual oligarchy look alike.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFF0F5 !important"><p>My problem with approach is that it makes the already ignorant user (which is most users) even more dependent on the major software vendors. I&#8217;m reminded of the old saying that the only thing it takes for evil to flourish is for good people to run to those in authority. In some ways I fear the omnipotent reach Google/Java more than I do these guys.  </p>
<p>There has to be a better solution than an ever escalating arms race between various groups of brainiacs. At a certain point all the members of the intellectual oligarchy look alike.</p>
</div><div class="CommentRating">Hot debate. What do you think? <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-48185" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('48185', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-48185-up" style="font-size:14px; color:#009933;">6</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-48185" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('48185', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-48185-down" style="font-size:14px; color:#990033;">3</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: prairie_sailor</title>
		<link>http://krebsonsecurity.com/2012/01/citadel-trojan-touts-trouble-ticket-system/comment-page-1/#comment-48176</link>
		<dc:creator>prairie_sailor</dc:creator>
		<pubDate>Mon, 23 Jan 2012 23:05:54 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=13474#comment-48176</guid>
		<description>It seems to me that the best way to combat this is for software writers (i.e. Adobe Reader/Flash/Shockwave/AIR and Oracle Java) need to make their updates more automatic with less user interaction (ala Google Chrome) They also need to up their time for the default check for updates - once a day at least instead of once per week or month. 

On kind of a sidways note - has any one seen a recentl explination why the 64-bit version of Java for windows does not have an auto updater yet?  I am seeing this installed more and more by OEMs and with no auto-updater since its release in late 2008 no auto-updater means that ther are alot of unsafe machines out there.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFF0F5 !important"><p>It seems to me that the best way to combat this is for software writers (i.e. Adobe Reader/Flash/Shockwave/AIR and Oracle Java) need to make their updates more automatic with less user interaction (ala Google Chrome) They also need to up their time for the default check for updates &#8211; once a day at least instead of once per week or month. </p>
<p>On kind of a sidways note &#8211; has any one seen a recentl explination why the 64-bit version of Java for windows does not have an auto updater yet?  I am seeing this installed more and more by OEMs and with no auto-updater since its release in late 2008 no auto-updater means that ther are alot of unsafe machines out there.</p>
</div><div class="CommentRating">Hot debate. What do you think? <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-48176" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('48176', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-48176-up" style="font-size:14px; color:#009933;">6</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-48176" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('48176', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-48176-down" style="font-size:14px; color:#990033;">7</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 12/14 queries in 0.002 seconds using memcached
Object Caching 729/733 objects using memcached

Served from: krebsonsecurity.com @ 2012-05-21 19:06:07 -->
