<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Harvesting Data on the Xarvester Botmaster</title>
	<atom:link href="http://krebsonsecurity.com/2012/08/harvesting-data-on-the-xarvester-botmaster/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2012/08/harvesting-data-on-the-xarvester-botmaster/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 22 May 2013 20:24:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: bob</title>
		<link>http://krebsonsecurity.com/2012/08/harvesting-data-on-the-xarvester-botmaster/comment-page-1/#comment-95829</link>
		<dc:creator>bob</dc:creator>
		<pubDate>Thu, 09 Aug 2012 09:26:58 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15206#comment-95829</guid>
		<description><![CDATA[&#039; registered to the English equivalent of “John Smith” &#039;

&#039; Russian equivalent &#039;, surely?]]></description>
		<content:encoded><![CDATA[<p>&#8216; registered to the English equivalent of “John Smith” &#8216;</p>
<p>&#8216; Russian equivalent &#8216;, surely?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kathy</title>
		<link>http://krebsonsecurity.com/2012/08/harvesting-data-on-the-xarvester-botmaster/comment-page-1/#comment-95587</link>
		<dc:creator>Kathy</dc:creator>
		<pubDate>Wed, 08 Aug 2012 14:14:52 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15206#comment-95587</guid>
		<description><![CDATA[Can anyone tell me about this spam attack?,adapter=A]]></description>
		<content:encoded><![CDATA[<p>Can anyone tell me about this spam attack?,adapter=A</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BrianKrebs</title>
		<link>http://krebsonsecurity.com/2012/08/harvesting-data-on-the-xarvester-botmaster/comment-page-1/#comment-95585</link>
		<dc:creator>BrianKrebs</dc:creator>
		<pubDate>Wed, 08 Aug 2012 14:07:49 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15206#comment-95585</guid>
		<description><![CDATA[Do me a favor, Na and drop me a line at an email address I can reply to. Contact form is here:

http://krebsonsecurity.com/about/

Thanks.]]></description>
		<content:encoded><![CDATA[<p>Do me a favor, Na and drop me a line at an email address I can reply to. Contact form is here:</p>
<p><a href="http://krebsonsecurity.com/about/" rel="nofollow">http://krebsonsecurity.com/about/</a></p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BrianKrebs</title>
		<link>http://krebsonsecurity.com/2012/08/harvesting-data-on-the-xarvester-botmaster/comment-page-1/#comment-95584</link>
		<dc:creator>BrianKrebs</dc:creator>
		<pubDate>Wed, 08 Aug 2012 14:07:00 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15206#comment-95584</guid>
		<description><![CDATA[I&#039;ve been focusing on individuals who either ran and developed large spam botnets or had a hand in operating parts of them. So far, I&#039;ve done that with most of the present and past major spam bots, including Cutwail, Grum, Rustock, Srizbi, Festi, Bredolab, Mega-D ZeuS, and Waledac.

http://krebsonsecurity.com/category/pharma-wars/]]></description>
		<content:encoded><![CDATA[<p>I&#8217;ve been focusing on individuals who either ran and developed large spam botnets or had a hand in operating parts of them. So far, I&#8217;ve done that with most of the present and past major spam bots, including Cutwail, Grum, Rustock, Srizbi, Festi, Bredolab, Mega-D ZeuS, and Waledac.</p>
<p><a href="http://krebsonsecurity.com/category/pharma-wars/" rel="nofollow">http://krebsonsecurity.com/category/pharma-wars/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: na</title>
		<link>http://krebsonsecurity.com/2012/08/harvesting-data-on-the-xarvester-botmaster/comment-page-1/#comment-95572</link>
		<dc:creator>na</dc:creator>
		<pubDate>Wed, 08 Aug 2012 13:29:14 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15206#comment-95572</guid>
		<description><![CDATA[neej, I would remind you that these are open comments and you have no idea who you could be speaking to. A grain of salt might be wise before you go off on someone especially if you are mistaken. &#039;Lockers&#039; as I mentioned has NOTHING to do with mobile phones or anything you mentioned in the reply. This leads me to believe you are not only belligerent but also do not know what you are talking about.

Many examples of &#039;Lockers&#039; can be found on botcrawl (dot) com on the /Malware/ Blog

&#039;Lockers&#039; are a term that refers generically to some sort of ransomeware that &#039;locks&#039; a users pc requiring a payment through a money processing system before the computer can be used again.

In the past mostly EU countries have been targeted with these attacks via Ukask or Paysafe. However, in the last month or so there has been a significant uptake in the attacks on US citizens -- in this case MoneyPak is the favored payment system. 

Normally lockers tend to purposely AVOID infecting PCs in the USA, however this is no longer the case...]]></description>
		<content:encoded><![CDATA[<p>neej, I would remind you that these are open comments and you have no idea who you could be speaking to. A grain of salt might be wise before you go off on someone especially if you are mistaken. &#8216;Lockers&#8217; as I mentioned has NOTHING to do with mobile phones or anything you mentioned in the reply. This leads me to believe you are not only belligerent but also do not know what you are talking about.</p>
<p>Many examples of &#8216;Lockers&#8217; can be found on botcrawl (dot) com on the /Malware/ Blog</p>
<p>&#8216;Lockers&#8217; are a term that refers generically to some sort of ransomeware that &#8216;locks&#8217; a users pc requiring a payment through a money processing system before the computer can be used again.</p>
<p>In the past mostly EU countries have been targeted with these attacks via Ukask or Paysafe. However, in the last month or so there has been a significant uptake in the attacks on US citizens &#8212; in this case MoneyPak is the favored payment system. </p>
<p>Normally lockers tend to purposely AVOID infecting PCs in the USA, however this is no longer the case&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: na</title>
		<link>http://krebsonsecurity.com/2012/08/harvesting-data-on-the-xarvester-botmaster/comment-page-1/#comment-95570</link>
		<dc:creator>na</dc:creator>
		<pubDate>Wed, 08 Aug 2012 13:17:54 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15206#comment-95570</guid>
		<description><![CDATA[Hence my question since you have the whole DB, what has driven you to choose these specific targets verse the rest!]]></description>
		<content:encoded><![CDATA[<p>Hence my question since you have the whole DB, what has driven you to choose these specific targets verse the rest!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: na</title>
		<link>http://krebsonsecurity.com/2012/08/harvesting-data-on-the-xarvester-botmaster/comment-page-1/#comment-95569</link>
		<dc:creator>na</dc:creator>
		<pubDate>Wed, 08 Aug 2012 13:16:52 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15206#comment-95569</guid>
		<description><![CDATA[Oh come now Brain, that was a sarcastic &quot;its not like the whole forum db was leaked&quot;. I&#039;m well aware it is, btw you got a new account on dk yet?]]></description>
		<content:encoded><![CDATA[<p>Oh come now Brain, that was a sarcastic &#8220;its not like the whole forum db was leaked&#8221;. I&#8217;m well aware it is, btw you got a new account on dk yet?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BrianKrebs</title>
		<link>http://krebsonsecurity.com/2012/08/harvesting-data-on-the-xarvester-botmaster/comment-page-1/#comment-95566</link>
		<dc:creator>BrianKrebs</dc:creator>
		<pubDate>Wed, 08 Aug 2012 13:08:55 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15206#comment-95566</guid>
		<description><![CDATA[&quot;I might add I am curious as to why you are choosing certain targets for example this bot-master verse others since it isn’t like the whole DB of the old forum was leaked.&quot;

Sure it was. I have the entire SpamIt customer and affiliate database, and the entire SpamDot forum. As for what I have on more recent forums and programs, I&#039;ll leave that to your imagination.]]></description>
		<content:encoded><![CDATA[<p>&#8220;I might add I am curious as to why you are choosing certain targets for example this bot-master verse others since it isn’t like the whole DB of the old forum was leaked.&#8221;</p>
<p>Sure it was. I have the entire SpamIt customer and affiliate database, and the entire SpamDot forum. As for what I have on more recent forums and programs, I&#8217;ll leave that to your imagination.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: na</title>
		<link>http://krebsonsecurity.com/2012/08/harvesting-data-on-the-xarvester-botmaster/comment-page-1/#comment-95565</link>
		<dc:creator>na</dc:creator>
		<pubDate>Wed, 08 Aug 2012 13:05:28 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15206#comment-95565</guid>
		<description><![CDATA[Brain, thanks for the reply. I swear I did say &#039;Replaced&#039;, I assumed you would get the double meaning (replaced literally with a new domain, replaced Criminal wise with new Venues.) Yes I would consider myself mildly experienced in the area. I might add I am curious as to why you are choosing certain targets for example this bot-master verse others since it isn&#039;t like the whole DB of the old forum was leaked. Any comments on that subject?]]></description>
		<content:encoded><![CDATA[<p>Brain, thanks for the reply. I swear I did say &#8216;Replaced&#8217;, I assumed you would get the double meaning (replaced literally with a new domain, replaced Criminal wise with new Venues.) Yes I would consider myself mildly experienced in the area. I might add I am curious as to why you are choosing certain targets for example this bot-master verse others since it isn&#8217;t like the whole DB of the old forum was leaked. Any comments on that subject?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Neej</title>
		<link>http://krebsonsecurity.com/2012/08/harvesting-data-on-the-xarvester-botmaster/comment-page-1/#comment-95557</link>
		<dc:creator>Neej</dc:creator>
		<pubDate>Wed, 08 Aug 2012 12:39:29 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=15206#comment-95557</guid>
		<description><![CDATA[&gt;&gt;For example ‘Lockers’ are all the rage, even more than Zeusish threats used for Banking theft.

If you&#039;re referring to content lockers you are an idiot.  

The user is clearly informed that they must complete an action to access content.  The action may or may not involve giving personal information that could be used for criminal activity (for example mobile phone numbers, name, email and address).  As it happens many large and established brands (Unilever, GSK for example) gather information using this method but of course I cannot speak for all content locker ... vendors(? - can&#039;t think of the right word)

Compare that to Zeus: software is installed without users knowledge which is then used to steal money from them.]]></description>
		<content:encoded><![CDATA[<p>&gt;&gt;For example ‘Lockers’ are all the rage, even more than Zeusish threats used for Banking theft.</p>
<p>If you&#8217;re referring to content lockers you are an idiot.  </p>
<p>The user is clearly informed that they must complete an action to access content.  The action may or may not involve giving personal information that could be used for criminal activity (for example mobile phone numbers, name, email and address).  As it happens many large and established brands (Unilever, GSK for example) gather information using this method but of course I cannot speak for all content locker &#8230; vendors(? &#8211; can&#8217;t think of the right word)</p>
<p>Compare that to Zeus: software is installed without users knowledge which is then used to steal money from them.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 21/22 queries in 0.002 seconds using memcached
Object Caching 409/425 objects using memcached

 Served from: krebsonsecurity.com @ 2013-05-22 16:36:16 by W3 Total Cache -->