<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Three Charged in Connection with ‘Gozi’ Trojan</title>
	<atom:link href="http://krebsonsecurity.com/2013/01/three-men-charged-in-connection-with-gozi-trojan/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2013/01/three-men-charged-in-connection-with-gozi-trojan/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Sat, 25 May 2013 19:09:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: polo</title>
		<link>http://krebsonsecurity.com/2013/01/three-men-charged-in-connection-with-gozi-trojan/comment-page-1/#comment-146368</link>
		<dc:creator>polo</dc:creator>
		<pubDate>Sat, 26 Jan 2013 22:59:13 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=6878#comment-146368</guid>
		<description><![CDATA[Bob,

sorry but I don&#039;t understand your reply.

It&#039;s not about generating a card number (what you refer to as &quot;id&quot;?), since that number is asked ( and alas gotten ) already in the inject field &quot;card number&quot;.

And anyway if you get that number you won&#039;t (from what i read) be able to make a usable card without adding CVV to the stripe. The CVV is calculated factoring various front info like card number and expiary date AND a secret key know only to the card maker.]]></description>
		<content:encoded><![CDATA[<p>Bob,</p>
<p>sorry but I don&#8217;t understand your reply.</p>
<p>It&#8217;s not about generating a card number (what you refer to as &#8220;id&#8221;?), since that number is asked ( and alas gotten ) already in the inject field &#8220;card number&#8221;.</p>
<p>And anyway if you get that number you won&#8217;t (from what i read) be able to make a usable card without adding CVV to the stripe. The CVV is calculated factoring various front info like card number and expiary date AND a secret key know only to the card maker.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nov</title>
		<link>http://krebsonsecurity.com/2013/01/three-men-charged-in-connection-with-gozi-trojan/comment-page-1/#comment-145787</link>
		<dc:creator>nov</dc:creator>
		<pubDate>Fri, 25 Jan 2013 18:23:00 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=6878#comment-145787</guid>
		<description><![CDATA[According to the Paunescu complaint (http://krebsonsecurity.com/wp-content/uploads/2013/01/Paunescu-Mihai-Ionut-Complaint.pdf) it seems the Paunescu hosting service was a callback for the ‘Virut’ Botnet (http://krebsonsecurity.com/2013/01/polish-takedown-targets-virut-botnet/) .  See the complaint page 15, paragraph 25.a. and page 13, paragraph 23.b.]]></description>
		<content:encoded><![CDATA[<p>According to the Paunescu complaint (<a href="http://krebsonsecurity.com/wp-content/uploads/2013/01/Paunescu-Mihai-Ionut-Complaint.pdf" rel="nofollow">http://krebsonsecurity.com/wp-content/uploads/2013/01/Paunescu-Mihai-Ionut-Complaint.pdf</a>) it seems the Paunescu hosting service was a callback for the ‘Virut’ Botnet (<a href="http://krebsonsecurity.com/2013/01/polish-takedown-targets-virut-botnet/" rel="nofollow">http://krebsonsecurity.com/2013/01/polish-takedown-targets-virut-botnet/</a>) .  See the complaint page 15, paragraph 25.a. and page 13, paragraph 23.b.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aleksey</title>
		<link>http://krebsonsecurity.com/2013/01/three-men-charged-in-connection-with-gozi-trojan/comment-page-1/#comment-145701</link>
		<dc:creator>Aleksey</dc:creator>
		<pubDate>Fri, 25 Jan 2013 15:40:33 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=6878#comment-145701</guid>
		<description><![CDATA[What is &quot; slow and cumbersome, useless and of no impact.&quot; ? FBI efforts in addressing the issue of financial trojans? I would disagree, they definitely deserve credit for uncovering the real identity of a person behind online nickname and they definitely used well the amazing opportunity they got when Kuzmin was stupid enough to travel to the states.
Looking at the trend, it seems like FBI knows the real identity of many people who are prominent in &quot;the biz&quot;. Once the criminals take the mind-boggling-stupid step of entering US or US-friendly  jurisdiction they are caught and detained. I say this is really good work by the agency.]]></description>
		<content:encoded><![CDATA[<p>What is &#8221; slow and cumbersome, useless and of no impact.&#8221; ? FBI efforts in addressing the issue of financial trojans? I would disagree, they definitely deserve credit for uncovering the real identity of a person behind online nickname and they definitely used well the amazing opportunity they got when Kuzmin was stupid enough to travel to the states.<br />
Looking at the trend, it seems like FBI knows the real identity of many people who are prominent in &#8220;the biz&#8221;. Once the criminals take the mind-boggling-stupid step of entering US or US-friendly  jurisdiction they are caught and detained. I say this is really good work by the agency.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bob</title>
		<link>http://krebsonsecurity.com/2013/01/three-men-charged-in-connection-with-gozi-trojan/comment-page-1/#comment-145645</link>
		<dc:creator>bob</dc:creator>
		<pubDate>Fri, 25 Jan 2013 13:36:46 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=6878#comment-145645</guid>
		<description><![CDATA[Some card manufacturers still create the card using non-random ids. Depending on the card, if I know your bank and account number I can generate a valid card id.

If I&#039;ve got the pin as well, generating a (non-chip&amp;pin) card is trivial.]]></description>
		<content:encoded><![CDATA[<p>Some card manufacturers still create the card using non-random ids. Depending on the card, if I know your bank and account number I can generate a valid card id.</p>
<p>If I&#8217;ve got the pin as well, generating a (non-chip&amp;pin) card is trivial.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aleksey</title>
		<link>http://krebsonsecurity.com/2013/01/three-men-charged-in-connection-with-gozi-trojan/comment-page-1/#comment-145201</link>
		<dc:creator>Aleksey</dc:creator>
		<pubDate>Thu, 24 Jan 2013 15:36:22 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=6878#comment-145201</guid>
		<description><![CDATA[Bingo! I&#039;m surprised this is not covered in Russian news yet. I&#039;m sure it will be soon.]]></description>
		<content:encoded><![CDATA[<p>Bingo! I&#8217;m surprised this is not covered in Russian news yet. I&#8217;m sure it will be soon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tarzan</title>
		<link>http://krebsonsecurity.com/2013/01/three-men-charged-in-connection-with-gozi-trojan/comment-page-1/#comment-145152</link>
		<dc:creator>tarzan</dc:creator>
		<pubDate>Thu, 24 Jan 2013 14:08:51 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=6878#comment-145152</guid>
		<description><![CDATA[Regrettably, the mechanisms in place to differentiate between secure and unsecure content on a web page are often ignored (although I am unsure of how useful these tools would be in this case). All too frequently consumers are &quot;trained&quot; by web developers to ignore certificate warnings, and browser developers make it easy by including the &quot;do not warne me againe&quot; option on the pop-up boxes, giving the uneducated users a dangerous option. Educating users is the best course of action, and Brian&#039;s blog is doing this quite well - well done Brian. Please continue your efforts.]]></description>
		<content:encoded><![CDATA[<p>Regrettably, the mechanisms in place to differentiate between secure and unsecure content on a web page are often ignored (although I am unsure of how useful these tools would be in this case). All too frequently consumers are &#8220;trained&#8221; by web developers to ignore certificate warnings, and browser developers make it easy by including the &#8220;do not warne me againe&#8221; option on the pop-up boxes, giving the uneducated users a dangerous option. Educating users is the best course of action, and Brian&#8217;s blog is doing this quite well &#8211; well done Brian. Please continue your efforts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LoL</title>
		<link>http://krebsonsecurity.com/2013/01/three-men-charged-in-connection-with-gozi-trojan/comment-page-1/#comment-145108</link>
		<dc:creator>LoL</dc:creator>
		<pubDate>Thu, 24 Jan 2013 12:44:15 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=6878#comment-145108</guid>
		<description><![CDATA[Aleksey, read please this document:
http://www.justice.gov/usao/nys/pressreleases/January13/GoziVirusDocuments/Kuzmin,%20Nikita%20Complaint.pdf, page 22, paragraph 30.]]></description>
		<content:encoded><![CDATA[<p>Aleksey, read please this document:<br />
<a href="http://www.justice.gov/usao/nys/pressreleases/January13/GoziVirusDocuments/Kuzmin,%20Nikita%20Complaint.pdf" rel="nofollow">http://www.justice.gov/usao/nys/pressreleases/January13/GoziVirusDocuments/Kuzmin,%20Nikita%20Complaint.pdf</a>, page 22, paragraph 30.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aleksey</title>
		<link>http://krebsonsecurity.com/2013/01/three-men-charged-in-connection-with-gozi-trojan/comment-page-1/#comment-145085</link>
		<dc:creator>Aleksey</dc:creator>
		<pubDate>Thu, 24 Jan 2013 12:14:14 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=6878#comment-145085</guid>
		<description><![CDATA[There&#039;s certain visual similarity between RdM-[YanDeX] and the foster son of Vladimir Kuz&#039;min. But what links the person with this online nickname to Gozi trojan and the related FBI cybercrime investigation ?]]></description>
		<content:encoded><![CDATA[<p>There&#8217;s certain visual similarity between RdM-[YanDeX] and the foster son of Vladimir Kuz&#8217;min. But what links the person with this online nickname to Gozi trojan and the related FBI cybercrime investigation ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marty K</title>
		<link>http://krebsonsecurity.com/2013/01/three-men-charged-in-connection-with-gozi-trojan/comment-page-1/#comment-145074</link>
		<dc:creator>Marty K</dc:creator>
		<pubDate>Thu, 24 Jan 2013 11:52:42 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=6878#comment-145074</guid>
		<description><![CDATA[As this is the customers browser, we (Banks) can&#039;t do much. Some Banks offer the customer to download security software to prevent the inject (e.g.: software on the browser checks if any unusual activity is going on, and warns the user - and the Bank in the background could e.g. put the transaction on hold)
Main issue: deal with customers and support their browser problems (that have nothing to do with your software)

Best option is to use two factor authentication (e.g.: send authorization code to SMS), that code will not match the altered transaction. (BUT there is malware out there to circumvent this too - see Zitmo- Zeus in the mobile)
In regards to fully automated mule selection (which mule is &quot;live&quot;, their account number, limits, etc) I have to disappoint you too, this has been seen in malware for a while - again ZEUS being the most prominent one.]]></description>
		<content:encoded><![CDATA[<p>As this is the customers browser, we (Banks) can&#8217;t do much. Some Banks offer the customer to download security software to prevent the inject (e.g.: software on the browser checks if any unusual activity is going on, and warns the user &#8211; and the Bank in the background could e.g. put the transaction on hold)<br />
Main issue: deal with customers and support their browser problems (that have nothing to do with your software)</p>
<p>Best option is to use two factor authentication (e.g.: send authorization code to SMS), that code will not match the altered transaction. (BUT there is malware out there to circumvent this too &#8211; see Zitmo- Zeus in the mobile)<br />
In regards to fully automated mule selection (which mule is &#8220;live&#8221;, their account number, limits, etc) I have to disappoint you too, this has been seen in malware for a while &#8211; again ZEUS being the most prominent one.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wrdlbrmpft</title>
		<link>http://krebsonsecurity.com/2013/01/three-men-charged-in-connection-with-gozi-trojan/comment-page-1/#comment-145061</link>
		<dc:creator>wrdlbrmpft</dc:creator>
		<pubDate>Thu, 24 Jan 2013 11:32:52 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=6878#comment-145061</guid>
		<description><![CDATA[smart crooks? Kuzmin smart to travel to the US where he was caught 2010 and cooperated fully, hoping for a deal? 2 years to catch the romanian? I call that slow and cumbersome, useless and of no impact.]]></description>
		<content:encoded><![CDATA[<p>smart crooks? Kuzmin smart to travel to the US where he was caught 2010 and cooperated fully, hoping for a deal? 2 years to catch the romanian? I call that slow and cumbersome, useless and of no impact.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 5/24 queries in 0.004 seconds using memcached
Object Caching 383/403 objects using memcached

 Served from: krebsonsecurity.com @ 2013-05-25 15:14:12 by W3 Total Cache -->