<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Top Spam Botnet, &#8220;Grum,&#8221; Unplugged</title>
	<atom:link href="http://krebsonsecurity.com/2012/07/top-spam-botnet-grum-unplugged/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2012/07/top-spam-botnet-grum-unplugged/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Thu, 23 May 2013 06:13:48 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: JohnAdams</title>
		<link>http://krebsonsecurity.com/2012/07/top-spam-botnet-grum-unplugged/comment-page-1/#comment-95571</link>
		<dc:creator>JohnAdams</dc:creator>
		<pubDate>Wed, 08 Aug 2012 13:28:49 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16045#comment-95571</guid>
		<description><![CDATA[First of all , I&#039;d like to thank the author of this website for doing such a great job. When I read it for the first time a few years ago, I couldn&#039;t believe it. So I started doing my own research and I was amazed how incredibly easy  available atm skimmers or their parts are  on the internet. Then I thought:  Obviously its possible to build a skimmer at home . But can someone actually come up with some sort of antiskimming device that would be simple , cheap to produce and would be EFFECTIVE at the same time ? I&#039;ve read there are several good antiskimming technologies that work to some extend , but not always. Plastic antiskimmers that supposed to make it harder for crooks to install a skimming device , actually make it easier. Every time a new antiskimmer comes out ,  you can see skimmers that look identical to those antiskimmers. Moreover, they buy an antiskimmer and rebuild it making it  a skimming device. Then of F2Fasic delta microchips and software that is made specifically to target interrupted swiping , thieves are still able to beat it. Another way is &quot;scale&quot; that is weighing fascia around a card reader on ATM . Supposively , if any foreign device is attached it should alarm the authorities. Well , usually crooks attach a nail or something heavy during the night hours and watch if the location is being checked up by the police. Plus with all those mini and nano skimmers that literally weigh 5-10 grams &quot;scales&quot; isn&#039;t that effective. The best antiskimming technology IMO is a lazer scanner that looks like a camera and it scans the fascia around reader and other parts of ATM.if any foreign body is attached , the lazer that constantly scans the facia , alarms the authorities with a silent alarm .  
To be honest this is a very interesting subject and since I read it for the first time ,  I&#039;ve been on the mission to build an antiskimming device. I have a few good ideas. Maybe if Im successful , I&#039;ll be able to share it with you in the near future . 
Sincerely , John ADAMS]]></description>
		<content:encoded><![CDATA[<p>First of all , I&#8217;d like to thank the author of this website for doing such a great job. When I read it for the first time a few years ago, I couldn&#8217;t believe it. So I started doing my own research and I was amazed how incredibly easy  available atm skimmers or their parts are  on the internet. Then I thought:  Obviously its possible to build a skimmer at home . But can someone actually come up with some sort of antiskimming device that would be simple , cheap to produce and would be EFFECTIVE at the same time ? I&#8217;ve read there are several good antiskimming technologies that work to some extend , but not always. Plastic antiskimmers that supposed to make it harder for crooks to install a skimming device , actually make it easier. Every time a new antiskimmer comes out ,  you can see skimmers that look identical to those antiskimmers. Moreover, they buy an antiskimmer and rebuild it making it  a skimming device. Then of F2Fasic delta microchips and software that is made specifically to target interrupted swiping , thieves are still able to beat it. Another way is &#8220;scale&#8221; that is weighing fascia around a card reader on ATM . Supposively , if any foreign device is attached it should alarm the authorities. Well , usually crooks attach a nail or something heavy during the night hours and watch if the location is being checked up by the police. Plus with all those mini and nano skimmers that literally weigh 5-10 grams &#8220;scales&#8221; isn&#8217;t that effective. The best antiskimming technology IMO is a lazer scanner that looks like a camera and it scans the fascia around reader and other parts of ATM.if any foreign body is attached , the lazer that constantly scans the facia , alarms the authorities with a silent alarm .<br />
To be honest this is a very interesting subject and since I read it for the first time ,  I&#8217;ve been on the mission to build an antiskimming device. I have a few good ideas. Maybe if Im successful , I&#8217;ll be able to share it with you in the near future .<br />
Sincerely , John ADAMS</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hhhobbit</title>
		<link>http://krebsonsecurity.com/2012/07/top-spam-botnet-grum-unplugged/comment-page-1/#comment-92869</link>
		<dc:creator>hhhobbit</dc:creator>
		<pubDate>Mon, 30 Jul 2012 01:45:11 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16045#comment-92869</guid>
		<description><![CDATA[Thanks

I removed the blog entry.]]></description>
		<content:encoded><![CDATA[<p>Thanks</p>
<p>I removed the blog entry.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: voksalna</title>
		<link>http://krebsonsecurity.com/2012/07/top-spam-botnet-grum-unplugged/comment-page-1/#comment-92255</link>
		<dc:creator>voksalna</dc:creator>
		<pubDate>Fri, 27 Jul 2012 09:44:10 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16045#comment-92255</guid>
		<description><![CDATA[It could be because you don&#039;t understand how spam works (and to be fair, most people do not). This is/was hardly the only spam botnet, and comments like this will probably just rile people on (for the record, I am a security professional). Good luck to you.]]></description>
		<content:encoded><![CDATA[<p>It could be because you don&#8217;t understand how spam works (and to be fair, most people do not). This is/was hardly the only spam botnet, and comments like this will probably just rile people on (for the record, I am a security professional). Good luck to you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Neo</title>
		<link>http://krebsonsecurity.com/2012/07/top-spam-botnet-grum-unplugged/comment-page-1/#comment-92213</link>
		<dc:creator>Neo</dc:creator>
		<pubDate>Thu, 26 Jul 2012 21:17:37 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16045#comment-92213</guid>
		<description><![CDATA[Try now.]]></description>
		<content:encoded><![CDATA[<p>Try now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: No Name</title>
		<link>http://krebsonsecurity.com/2012/07/top-spam-botnet-grum-unplugged/comment-page-1/#comment-92212</link>
		<dc:creator>No Name</dc:creator>
		<pubDate>Thu, 26 Jul 2012 21:08:33 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16045#comment-92212</guid>
		<description><![CDATA[Krebs,
Do you know that the RSS feed to your website is not working. It hasn&#039;t been for a couple of days. I assumed that maybe the feed link was changed but that doesn&#039;t appear to be the case. clicking on https://krebsonsecurity.com/feed/
just sends the browser in to a constant connect, reconnect loop.]]></description>
		<content:encoded><![CDATA[<p>Krebs,<br />
Do you know that the RSS feed to your website is not working. It hasn&#8217;t been for a couple of days. I assumed that maybe the feed link was changed but that doesn&#8217;t appear to be the case. clicking on <a href="https://krebsonsecurity.com/feed/" rel="nofollow">https://krebsonsecurity.com/feed/</a><br />
just sends the browser in to a constant connect, reconnect loop.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Henry Hertz Hobbit</title>
		<link>http://krebsonsecurity.com/2012/07/top-spam-botnet-grum-unplugged/comment-page-1/#comment-92175</link>
		<dc:creator>Henry Hertz Hobbit</dc:creator>
		<pubDate>Wed, 25 Jul 2012 20:00:32 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16045#comment-92175</guid>
		<description><![CDATA[I forgot to add one thing.  I stabilized on one file that indicates that the PeskySpammer.7z contents have changed.  It is called SpamOfTheDay.txt.  I take it this one lone negative vote against what I have written is from the people that are doing this that also tried to give me an anonymous phone call yesterday (2012-07-24) that I did not take.  But if spammers don&#039;t want me blocking their hosts the solution is simple - just grep out hhhobbit, henryhertzhobbit, and securemecca out of their spam sending lists.]]></description>
		<content:encoded><![CDATA[<p>I forgot to add one thing.  I stabilized on one file that indicates that the PeskySpammer.7z contents have changed.  It is called SpamOfTheDay.txt.  I take it this one lone negative vote against what I have written is from the people that are doing this that also tried to give me an anonymous phone call yesterday (2012-07-24) that I did not take.  But if spammers don&#8217;t want me blocking their hosts the solution is simple &#8211; just grep out hhhobbit, henryhertzhobbit, and securemecca out of their spam sending lists.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Henry Hertz Hobbit</title>
		<link>http://krebsonsecurity.com/2012/07/top-spam-botnet-grum-unplugged/comment-page-1/#comment-92101</link>
		<dc:creator>Henry Hertz Hobbit</dc:creator>
		<pubDate>Tue, 24 Jul 2012 19:27:24 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16045#comment-92101</guid>
		<description><![CDATA[I have proof that the people that are sending out this spam are making it look like some of it is coming from my SecureMecca.com domain.  I know that they are doing it to another domain for certain and suspect they are doing it to many other domains as well.  Here is my blog on it with links to the proof that is coming in with maybe a momentary lull but no end in sight:

http://securemecca.blogspot.com/2012/06/why-i-block-spam.html

They intend to keep it going forever.  This is where the PeskySpammer link in the blog goes to:

http://securemecca.com/public/PeskySpammer/

This is not pointing to static data.  It is ongoing and changes at least weekly.  I just got a list of another 100+ hosts selling drugs that can potentially kill you or disable you for life from bounces in my email during the past 12 hours.  Most of the hosts are in the Russian domain and for now are hosted in China.  Do not rush to a judgement that the people doing it are in those countries.  The criminals may live in the United States or Europe.  I do add blocks of their hosts in my hosts file and rules in my PAC filter which feeds into some of the information stored in the PeskySpammer folder.

I would not be surprised to hear that the drugs these people are selling kill or disable people for life.  When the people selling them hear that what they sold killed or disabled a person for life they would probably laugh.  They are not just being nerds.  They are evil criminals that don&#039;t care who they harm.]]></description>
		<content:encoded><![CDATA[<p>I have proof that the people that are sending out this spam are making it look like some of it is coming from my SecureMecca.com domain.  I know that they are doing it to another domain for certain and suspect they are doing it to many other domains as well.  Here is my blog on it with links to the proof that is coming in with maybe a momentary lull but no end in sight:</p>
<p><a href="http://securemecca.blogspot.com/2012/06/why-i-block-spam.html" rel="nofollow">http://securemecca.blogspot.com/2012/06/why-i-block-spam.html</a></p>
<p>They intend to keep it going forever.  This is where the PeskySpammer link in the blog goes to:</p>
<p><a href="http://securemecca.com/public/PeskySpammer/" rel="nofollow">http://securemecca.com/public/PeskySpammer/</a></p>
<p>This is not pointing to static data.  It is ongoing and changes at least weekly.  I just got a list of another 100+ hosts selling drugs that can potentially kill you or disable you for life from bounces in my email during the past 12 hours.  Most of the hosts are in the Russian domain and for now are hosted in China.  Do not rush to a judgement that the people doing it are in those countries.  The criminals may live in the United States or Europe.  I do add blocks of their hosts in my hosts file and rules in my PAC filter which feeds into some of the information stored in the PeskySpammer folder.</p>
<p>I would not be surprised to hear that the drugs these people are selling kill or disable people for life.  When the people selling them hear that what they sold killed or disabled a person for life they would probably laugh.  They are not just being nerds.  They are evil criminals that don&#8217;t care who they harm.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nonegiven</title>
		<link>http://krebsonsecurity.com/2012/07/top-spam-botnet-grum-unplugged/comment-page-1/#comment-91977</link>
		<dc:creator>nonegiven</dc:creator>
		<pubDate>Tue, 24 Jul 2012 13:44:02 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16045#comment-91977</guid>
		<description><![CDATA[I&#039;m getting plenty of viagra spam, still.]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m getting plenty of viagra spam, still.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Neej</title>
		<link>http://krebsonsecurity.com/2012/07/top-spam-botnet-grum-unplugged/comment-page-1/#comment-91914</link>
		<dc:creator>Neej</dc:creator>
		<pubDate>Tue, 24 Jul 2012 08:24:57 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16045#comment-91914</guid>
		<description><![CDATA[&gt;&gt; But if not a clever marketing scheme, what’s the motive here?

I&#039;m not speaking for the company in question but seeing as they&#039;re a computer security firm they probably see it as their business to disrupt criminal operations which neatly dovetails with getting their name out there (ie. marketing).  

I don&#039;t really see the point of your question.  Another way they could have made people aware of their brand is purchasing ad space so you have to look at it but it&#039;s so much more legitimate when it&#039;s done this way.

&gt;&gt; Do the spam bots have instructions that eventually expire

Once again an assumption on my part but I imagine all spam  campaigns have expiry dates not least because the bot net may have been rented out to other spammers.]]></description>
		<content:encoded><![CDATA[<p>&gt;&gt; But if not a clever marketing scheme, what’s the motive here?</p>
<p>I&#8217;m not speaking for the company in question but seeing as they&#8217;re a computer security firm they probably see it as their business to disrupt criminal operations which neatly dovetails with getting their name out there (ie. marketing).  </p>
<p>I don&#8217;t really see the point of your question.  Another way they could have made people aware of their brand is purchasing ad space so you have to look at it but it&#8217;s so much more legitimate when it&#8217;s done this way.</p>
<p>&gt;&gt; Do the spam bots have instructions that eventually expire</p>
<p>Once again an assumption on my part but I imagine all spam  campaigns have expiry dates not least because the bot net may have been rented out to other spammers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kurt wismer</title>
		<link>http://krebsonsecurity.com/2012/07/top-spam-botnet-grum-unplugged/comment-page-1/#comment-91794</link>
		<dc:creator>kurt wismer</dc:creator>
		<pubDate>Mon, 23 Jul 2012 20:47:44 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16045#comment-91794</guid>
		<description><![CDATA[so, if i&#039;m reading this right, russia&#039;s CERT disavowed any knowledge of their own IP addresses? that kind of anomalous behaviour seems like something worth looking into.]]></description>
		<content:encoded><![CDATA[<p>so, if i&#8217;m reading this right, russia&#8217;s CERT disavowed any knowledge of their own IP addresses? that kind of anomalous behaviour seems like something worth looking into.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 4/20 queries in 0.010 seconds using memcached
Object Caching 382/394 objects using memcached

 Served from: krebsonsecurity.com @ 2013-05-23 02:14:04 by W3 Total Cache -->