<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Support You Can TRUST</title>
	<atom:link href="http://doyphoto.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://doyphoto.wordpress.com</link>
	<description>A SMART, WITTY I.T. GUY</description>
	<lastBuildDate>Fri, 05 Feb 2010 18:41:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='doyphoto.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Support You Can TRUST</title>
		<link>http://doyphoto.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://doyphoto.wordpress.com/osd.xml" title="Support You Can TRUST" />
	<atom:link rel='hub' href='http://doyphoto.wordpress.com/?pushpress=hub'/>
		<item>
		<title>What Clients Say&#8230;</title>
		<link>http://doyphoto.wordpress.com/2009/12/06/what-clients-say/</link>
		<comments>http://doyphoto.wordpress.com/2009/12/06/what-clients-say/#comments</comments>
		<pubDate>Sun, 06 Dec 2009 23:14:29 +0000</pubDate>
		<dc:creator>doyphoto</dc:creator>
				<category><![CDATA[Live Support]]></category>
		<category><![CDATA[SME INC]]></category>
		<category><![CDATA[Customer Service]]></category>
		<category><![CDATA[Testimonials]]></category>

		<guid isPermaLink="false">http://thesuperman.net/?p=1133</guid>
		<description><![CDATA[I owned Carter&#8217;s Motel, RV park, and Mobile home park in Edgewater Fl when Randy stayed with us on business travel. Before meeting Randy by chance, had 4 different supposed specialists try to provide a solid and dependable universal WIFI system for my business which covered 6 acres, and had over 70 residents not including [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1133&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I owned Carter&#8217;s Motel, RV park, and Mobile home park in Edgewater Fl when Randy stayed with us on business travel.</p>
<p>Before meeting Randy by chance, had 4 different supposed specialists try to provide a solid and dependable universal WIFI system for my business which covered 6 acres, and had over 70 residents not including motel and RV guests; all to no avail, and thousands of dollars spent.</p>
<p>Within  1 week Randy had ordered the proper equipment and had a viable system that supplied all the service we needed. He maintained and modified the system as needed from where ever he was in the world remotely, and within minutes of my call, he completed all I asked.</p>
<p>My opinion of Randy Vanderveer is; he is a (hyper) intelligent young man, who has laser type focus into all he delves. He is utterly obsessive about perfection in his work. He has shown me absolute promptness in returning all calls, completing work on time, and to specification, and maintaining said work with pride. You could do no better than he for computer technical work. He now maintains all of my families computers (7) remotely. He has become a close friend who will rush to our aid. This man has the highest of work ethics. By having access to my families computers he could easily abscond with exceedingly valuable information and assets at any time.</p>
<p><strong><em>I have never had a second thought of his integrity being less than my closest confidante. Feel free to call me any time.</em></strong></p>
<p>-Peter Gordon</p>
<p>Respectfully,</p>
<p>Peter Gordon, Vice President</p>
<p>Carter&#8217;s Motel &amp; Mobile Village</p>
<p>2450 S. Ridgewood Ave</p>
<p>Edgewater, FL 32141</p>
<p>(386) 314-4189 Cell</p>
<p><a href="http://www.cartersmotel.com/" target="_blank">http://www.cartersmotel.com</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/doyphoto.wordpress.com/1133/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/doyphoto.wordpress.com/1133/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/doyphoto.wordpress.com/1133/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/doyphoto.wordpress.com/1133/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/doyphoto.wordpress.com/1133/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/doyphoto.wordpress.com/1133/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/doyphoto.wordpress.com/1133/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/doyphoto.wordpress.com/1133/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/doyphoto.wordpress.com/1133/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/doyphoto.wordpress.com/1133/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/doyphoto.wordpress.com/1133/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/doyphoto.wordpress.com/1133/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/doyphoto.wordpress.com/1133/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/doyphoto.wordpress.com/1133/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1133&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://doyphoto.wordpress.com/2009/12/06/what-clients-say/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7a8169574c67a32fc0a969387de6a998?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=PG" medium="image">
			<media:title type="html">Superman</media:title>
		</media:content>
	</item>
		<item>
		<title>H1N1 Malware Campaign Circulating</title>
		<link>http://doyphoto.wordpress.com/2009/12/02/h1n1-malware-campaign-circulating/</link>
		<comments>http://doyphoto.wordpress.com/2009/12/02/h1n1-malware-campaign-circulating/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 17:03:34 +0000</pubDate>
		<dc:creator>doyphoto</dc:creator>
				<category><![CDATA[SME INC]]></category>
		<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[H1N1]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://doyphoto.wordpress.com/2009/12/02/h1n1-malware-campaign-circulating/</guid>
		<description><![CDATA[H1N1 Malware Campaign Circulating Original release date: December 2, 2009 at 9:56 am Last revised: December 2, 2009 at 9:56 am US-CERT is aware of public reports of a malware campaign circulating. This campaign is circulating via email messages offering information regarding the H1N1 vaccination. This email messages contain a link to a bogus Centers [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1131&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>H1N1 Malware Campaign Circulating</p>
<p>Original release date: December 2, 2009 at 9:56 am<br />
Last revised: December 2, 2009 at 9:56 am</p>
<p>US-CERT is aware of public reports of a malware campaign circulating.</p>
<p>This campaign is circulating via email messages offering information<br />
regarding the H1N1 vaccination. This email messages contain a link to<br />
a bogus Centers for Disease Control and Prevention website. Users who<br />
click on this link may become infected with malware. Public reports<br />
indicate that these email messages are noted as having subject lines<br />
such as: &#8220;Governmental registration program on the H1N1 vaccination&#8221;<br />
and &#8220;Your personal vaccination profile.&#8221; Please note that subject<br />
lines may change at any time.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/doyphoto.wordpress.com/1131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/doyphoto.wordpress.com/1131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/doyphoto.wordpress.com/1131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/doyphoto.wordpress.com/1131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/doyphoto.wordpress.com/1131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/doyphoto.wordpress.com/1131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/doyphoto.wordpress.com/1131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/doyphoto.wordpress.com/1131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/doyphoto.wordpress.com/1131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/doyphoto.wordpress.com/1131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/doyphoto.wordpress.com/1131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/doyphoto.wordpress.com/1131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/doyphoto.wordpress.com/1131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/doyphoto.wordpress.com/1131/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1131&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://doyphoto.wordpress.com/2009/12/02/h1n1-malware-campaign-circulating/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7a8169574c67a32fc0a969387de6a998?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=PG" medium="image">
			<media:title type="html">Superman</media:title>
		</media:content>
	</item>
		<item>
		<title>US-CERT: BlackBerry PDF Distiller Vulnerabilities</title>
		<link>http://doyphoto.wordpress.com/2009/12/01/us-cert-blackberry-pdf-distiller-vulnerabilities/</link>
		<comments>http://doyphoto.wordpress.com/2009/12/01/us-cert-blackberry-pdf-distiller-vulnerabilities/#comments</comments>
		<pubDate>Tue, 01 Dec 2009 21:50:08 +0000</pubDate>
		<dc:creator>doyphoto</dc:creator>
				<category><![CDATA[BlackBerry]]></category>
		<category><![CDATA[US-CERT]]></category>
		<category><![CDATA[Blackberry Enerprise Server]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://doyphoto.wordpress.com/2009/12/01/us-cert-blackberry-pdf-distiller-vulnerabilities/</guid>
		<description><![CDATA[Research In Motion Releases Advisory for BlackBerry PDF Distiller Vulnerabilities Original release date: December 1, 2009 at 1:58 pm Last revised: December 1, 2009 at 1:58 pm Research In Motion has released a security advisory to address multiple vulnerabilities in the PDF distiller of some released versions of the BlackBerry Attachment Service. The advisory lists [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1129&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Research In Motion Releases Advisory for BlackBerry PDF Distiller Vulnerabilities</p>
<p>Original release date: December 1, 2009 at 1:58 pm<br />
Last revised: December 1, 2009 at 1:58 pm</p>
<p>Research In Motion has released a security advisory to address<br />
multiple vulnerabilities in the PDF distiller of some released<br />
versions of the BlackBerry Attachment Service. The advisory lists the<br />
affected versions as BlackBerry Enterprise Server 5.0.0 running on<br />
Microsoft Windows version 2003 or 2008, BlackBerry Enterprise Server<br />
5.0.0 running on Microsoft Windows 2000, BlackBerry Enterprise Server<br />
software versions 4.1.3 through 4.1.7, and BlackBerry Professional<br />
Software 4.1.4. By convincing a user to view a specially crafted PDF<br />
file, an attacker may be able to execute arbitrary code or cause a<br />
denial-of-service condition on the system that hosts the BlackBerry<br />
Attachment Service.</p>
<p>US-CERT encourages users and administrators to review BlackBerry<br />
security advisory KB19860 and apply any necessary updates.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/doyphoto.wordpress.com/1129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/doyphoto.wordpress.com/1129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/doyphoto.wordpress.com/1129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/doyphoto.wordpress.com/1129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/doyphoto.wordpress.com/1129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/doyphoto.wordpress.com/1129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/doyphoto.wordpress.com/1129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/doyphoto.wordpress.com/1129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/doyphoto.wordpress.com/1129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/doyphoto.wordpress.com/1129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/doyphoto.wordpress.com/1129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/doyphoto.wordpress.com/1129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/doyphoto.wordpress.com/1129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/doyphoto.wordpress.com/1129/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1129&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://doyphoto.wordpress.com/2009/12/01/us-cert-blackberry-pdf-distiller-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7a8169574c67a32fc0a969387de6a998?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=PG" medium="image">
			<media:title type="html">Superman</media:title>
		</media:content>
	</item>
		<item>
		<title>Malicious Code Circulating via Social Security Administration Phishing Messages</title>
		<link>http://doyphoto.wordpress.com/2009/11/24/malicious-code-circulating-via-social-security-administration-phishing-messages/</link>
		<comments>http://doyphoto.wordpress.com/2009/11/24/malicious-code-circulating-via-social-security-administration-phishing-messages/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 20:18:32 +0000</pubDate>
		<dc:creator>doyphoto</dc:creator>
				<category><![CDATA[PHISHING SCAMS]]></category>
		<category><![CDATA[SME INC]]></category>
		<category><![CDATA[US-CERT]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing Emails]]></category>
		<category><![CDATA[Social Security Administration]]></category>

		<guid isPermaLink="false">http://doyphoto.wordpress.com/2009/11/24/malicious-code-circulating-via-social-security-administration-phishing-messages/</guid>
		<description><![CDATA[Malicious Code Circulating via Social Security Administration Phishing Messages Original release date: November 24, 2009 at 2:42 pm Last revised: November 24, 2009 at 2:42 pm US-CERT is aware of public reports of malicious code circulating via phishing email messages that appear to come from the Social Security Administration. The messages indicate that the users&#8217; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1123&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Malicious Code Circulating via Social Security Administration Phishing Messages</p>
<p>Original release date: November 24, 2009 at 2:42 pm<br />
Last revised: November 24, 2009 at 2:42 pm</p>
<p>US-CERT is aware of public reports of malicious code circulating via<br />
phishing email messages that appear to come from the Social Security<br />
Administration. The messages indicate that the users&#8217; annual Social<br />
Security statements may contain errors and instruct users to follow a<br />
link to review their Social Security statement. If users click this<br />
link, they will be redirected to a seemingly legitimate website that<br />
prompts them for their Social Security number. If users enter their<br />
Social Security number and continue to the next page, they will be<br />
given an option to generate a statement. If users attempt to generate<br />
a statement, malicious code may be installed on their systems. This<br />
malicious code attempts to collect online banking traffic to gain<br />
access to the users&#8217; bank accounts.</p>
<p>US-CERT encourages users and administrators to take the following<br />
preventative measures to help mitigate the security risks:<br />
  * Install antivirus software, and keep the virus signatures up to<br />
    date.<br />
  * Do not follow unsolicited links and do not open unsolicited email<br />
    messages.<br />
  * Use caution when visiting untrusted websites.<br />
  * Use caution when entering personal information online.<br />
  * Refer to the Recognizing and Avoiding Email Scams (pdf) document<br />
    for more information on avoiding email scams.<br />
  * Refer to the Avoiding Social Engineering and Phishing Attacks<br />
    document for more information on social engineering attacks.</p>
<p>Users are encouraged to contact the Social Security Administration to<br />
verify the authenticity of any messages. Additional information will<br />
be provided as it becomes available.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/doyphoto.wordpress.com/1123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/doyphoto.wordpress.com/1123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/doyphoto.wordpress.com/1123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/doyphoto.wordpress.com/1123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/doyphoto.wordpress.com/1123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/doyphoto.wordpress.com/1123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/doyphoto.wordpress.com/1123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/doyphoto.wordpress.com/1123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/doyphoto.wordpress.com/1123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/doyphoto.wordpress.com/1123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/doyphoto.wordpress.com/1123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/doyphoto.wordpress.com/1123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/doyphoto.wordpress.com/1123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/doyphoto.wordpress.com/1123/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1123&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://doyphoto.wordpress.com/2009/11/24/malicious-code-circulating-via-social-security-administration-phishing-messages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7a8169574c67a32fc0a969387de6a998?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=PG" medium="image">
			<media:title type="html">Superman</media:title>
		</media:content>
	</item>
		<item>
		<title>Framed for child porn _ by a PC virus</title>
		<link>http://doyphoto.wordpress.com/2009/11/10/pornvirus/</link>
		<comments>http://doyphoto.wordpress.com/2009/11/10/pornvirus/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 18:00:35 +0000</pubDate>
		<dc:creator>doyphoto</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[SME INC]]></category>
		<category><![CDATA[Child Porn]]></category>
		<category><![CDATA[PC Viruses]]></category>

		<guid isPermaLink="false">http://doyphoto.wordpress.com/?p=1119</guid>
		<description><![CDATA[*Disclaimer: The details in this story are somewhat reprehensible, but true. I in no way, shape, or form condone the actions specified in this AP Story, but these are true accounts; people have had child porn appear on their pc&#8217;s after getting infected with a virus.* Link to Ap story: HERE Framed for child porn [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1119&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>*Disclaimer: The details in this story are somewhat reprehensible, but true. I in no way, shape, or form condone the actions specified in this AP Story, but these are true accounts; people have had child porn appear on their pc&#8217;s after getting infected with a virus.*</p>
<p>Link to Ap story: <a href="http://www.google.com/hostednews/ap/article/ALeqM5iFP7nhggkjFFeVx5PS60H2O4qeIwD9BRFQ680" target="_blank">HERE</a></p>
<p>Framed for child porn _ by a PC virus</p>
<p>By JORDAN ROBERTSON (AP) – 2 days ago</p>
<p>Of all the sinister things that Internet viruses do, this might be the worst: They can make you an unsuspecting collector of child pornography.</p>
<p>Heinous pictures and videos can be deposited on computers by viruses — the malicious programs better known for swiping your credit card numbers. In this twist, it&#8217;s your reputation that&#8217;s stolen.</p>
<p>Pedophiles can exploit virus-infected PCs to remotely store and view their stash without fear they&#8217;ll get caught. Pranksters or someone trying to frame you can tap viruses to make it appear that you surf illegal Web sites.</p>
<p>Whatever the motivation, you get child porn on your computer — and might not realize it until police knock at your door.</p>
<p>An Associated Press investigation found cases in which innocent people have been branded as pedophiles after their co-workers or loved ones stumbled upon child porn placed on a PC through a virus. It can cost victims hundreds of thousands of dollars to prove their innocence.</p>
<p>Their situations are complicated by the fact that actual pedophiles often blame viruses — a defense rightfully viewed with skepticism by law enforcement.</p>
<p>&#8220;It&#8217;s an example of the old `dog ate my homework&#8217; excuse,&#8221; says Phil Malone, director of the Cyberlaw Clinic at Harvard&#8217;s Berkman Center for Internet &amp; Society. &#8220;The problem is, sometimes the dog does eat your homework.&#8221;</p>
<p>The AP&#8217;s investigation included interviewing people who had been found with child porn on their computers. The AP reviewed court records and spoke to prosecutors, police and computer examiners.</p>
<p>One case involved Michael Fiola, a former investigator with the Massachusetts agency that oversees workers&#8217; compensation.</p>
<p>In 2007, Fiola&#8217;s bosses became suspicious after the Internet bill for his state-issued laptop showed that he used 4 1/2 times more data than his colleagues. A technician found child porn in the PC folder that stores images viewed online.</p>
<p>Fiola was fired and charged with possession of child pornography, which carries up to five years in prison. He endured death threats, his car tires were slashed and he was shunned by friends.</p>
<p>Fiola and his wife fought the case, spending $250,000 on legal fees. They liquidated their savings, took a second mortgage and sold their car.</p>
<p>An inspection for his defense revealed the laptop was severely infected. It was programmed to visit as many as 40 child porn sites per minute — an inhuman feat. While Fiola and his wife were out to dinner one night, someone logged on to the computer and porn flowed in for an hour and a half.</p>
<p>Prosecutors performed another test and confirmed the defense findings. The charge was dropped — 11 months after it was filed.</p>
<p>The Fiolas say they have health problems from the stress of the case. They say they&#8217;ve talked to dozens of lawyers but can&#8217;t get one to sue the state, because of a cap on the amount they can recover.</p>
<p>&#8220;It ruined my life, my wife&#8217;s life and my family&#8217;s life,&#8221; he says.</p>
<p>The Massachusetts attorney general&#8217;s office, which charged Fiola, declined interview requests.</p>
<p>At any moment, about 20 million of the estimated 1 billion Internet-connected PCs worldwide are infected with viruses that could give hackers full control, according to security software maker F-Secure Corp. Computers often get infected when people open e-mail attachments from unknown sources or visit a malicious Web page.</p>
<p>Pedophiles can tap viruses in several ways. The simplest is to force someone else&#8217;s computer to surf child porn sites, collecting images along the way. Or a computer can be made into a warehouse for pictures and videos that can be viewed remotely when the PC is online.</p>
<p>&#8220;They&#8217;re kind of like locusts that descend on a cornfield: They eat up everything in sight and they move on to the next cornfield,&#8221; says Eric Goldman, academic director of the High Tech Law Institute at Santa Clara University. Goldman has represented Web companies that discovered child pornographers were abusing their legitimate services.</p>
<p>But pedophiles need not be involved: Child porn can land on a computer in a sick prank or an attempt to frame the PC&#8217;s owner.</p>
<p>In the first publicly known cases of individuals being victimized, two men in the United Kingdom were cleared in 2003 after viruses were shown to have been responsible for the child porn on their PCs.</p>
<p>In one case, an infected e-mail or pop-up ad poisoned a defense contractor&#8217;s PC and downloaded the offensive pictures.</p>
<p>In the other, a virus changed the home page on a man&#8217;s Web browser to display child porn, a discovery made by his 7-year-old daughter. The man spent more than a week in jail and three months in a halfway house, and lost custody of his daughter.</p>
<p>Chris Watts, a computer examiner in Britain, says he helped clear a hotel manager whose co-workers found child porn on the PC they shared with him.</p>
<p>Watts found that while surfing the Internet for ways to play computer games without paying for them, the manager had visited a site for pirated software. It redirected visitors to child porn sites if they were inactive for a certain period.</p>
<p>In all these cases, the central evidence wasn&#8217;t in dispute: Pornography was on a computer. But proving how it got there was difficult.</p>
<p>Tami Loehrs, who inspected Fiola&#8217;s computer, recalls a case in Arizona in which a computer was so &#8220;extensively infected&#8221; that it would be &#8220;virtually impossible&#8221; to prove what an indictment alleged: that a 16-year-old who used the PC had uploaded child pornography to a Yahoo group.</p>
<p>Prosecutors dropped the charge and let the boy plead guilty to a separate crime that kept him out of jail, though they say they did it only because of his age and lack of a criminal record.</p>
<p>Many prosecutors say blaming a computer virus for child porn is a new version of an old ploy.</p>
<p>&#8220;We call it the SODDI defense: Some Other Dude Did It,&#8221; says James Anderson, a federal prosecutor in Wyoming.</p>
<p>However, forensic examiners say it would be hard for a pedophile to get away with his crime by using a bogus virus defense.</p>
<p>&#8220;I personally would feel more comfortable investing my retirement in the lottery before trying to defend myself with that,&#8221; says forensics specialist Jeff Fischbach.</p>
<p>Even careful child porn collectors tend to leave incriminating e-mails, DVDs or other clues. Virus defenses are no match for such evidence, says Damon King, trial attorney for the U.S. Justice Department&#8217;s Child Exploitation and Obscenity Section.</p>
<p>But while the virus defense does not appear to be letting real pedophiles out of trouble, there have been cases in which forensic examiners insist that legitimate claims did not get completely aired.</p>
<p>Loehrs points to Ned Solon of Casper, Wyo., who is serving six years for child porn found in a folder used by a file-sharing program on his computer.</p>
<p>Solon admits he used the program to download video games and adult porn — but not child porn. So what could explain that material?</p>
<p>Loehrs testified that Solon&#8217;s antivirus software wasn&#8217;t working properly and appeared to have shut off for long stretches, a sign of an infection. She found no evidence the five child porn videos on Solon&#8217;s computer had been viewed or downloaded fully. The porn was in a folder the file-sharing program labeled as &#8220;incomplete&#8221; because the downloads were canceled or generated an error.</p>
<p>This defense was curtailed, however, when Loehrs ended her investigation in a dispute with the judge over her fees. Computer exams can cost tens of thousands of dollars. Defendants can ask the courts to pay, but sometimes judges balk at the price. Although Loehrs stopped working for Solon, she argues he is innocent.</p>
<p>&#8220;I don&#8217;t think it was him, I really don&#8217;t,&#8221; Loehrs says. &#8220;There was too much evidence that it wasn&#8217;t him.&#8221;</p>
<p>The prosecution&#8217;s forensics expert, Randy Huff, maintains that Solon&#8217;s antivirus software was working properly. And he says he ran other antivirus programs on the computer and didn&#8217;t find an infection — although security experts say antivirus scans frequently miss things.</p>
<p>&#8220;He actually had a very clean computer compared to some of the other cases I do,&#8221; Huff says.</p>
<p>The jury took two hours to convict Solon.</p>
<p>&#8220;Everybody feels they&#8217;re innocent in prison. Nobody believes me because that&#8217;s what everybody says,&#8221; says Solon, whose case is being appealed. &#8220;All I know is I did not do it. I never put the stuff on there. I never saw the stuff on there. I can only hope that someday the truth will come out.&#8221;</p>
<p>But can it? It can be impossible to tell with certainty how a file got onto a PC.</p>
<p>&#8220;Computers are not to be trusted,&#8221; says Jeremiah Grossman, founder of WhiteHat Security Inc. He describes it as &#8220;painfully simple&#8221; to get a computer to download something the owner doesn&#8217;t want — whether it&#8217;s a program that displays ads or one that stores illegal pictures.</p>
<p>It&#8217;s possible, Grossman says, that more illicit material is waiting to be discovered.</p>
<p>&#8220;Just because it&#8217;s there doesn&#8217;t mean the person intended for it to be there — whatever it is, child porn included.&#8221;</p>
<p><!-- google_ad_section_end(name=article) --></p>
<p id="hn-distributor-copyright">Copyright ©  2009   The Associated Press. All rights reserved.</p>
<h4 id="rn-header">Related articles</h4>
<ul>
<li><a href="http://gizmodo.com/5401312/oh-sht-new-viruses-download-child-porn-onto-your-computer">Oh Sh*t: New Viruses Download Child Porn Onto Your Computer</a><br />
Gizmodo.com &#8211; 25 minutes ago</li>
<li><a href="http://www.whptv.com/news/local/story/AP-Virus-Downloads-Child-Porn-to-Your-Computer/ChE2D5oSokKoe21G8hcdZg.cspx">AP: Virus Downloads Child Porn to Your Computer</a><br />
CBS 21 &#8211; 17 hours ago</li>
<li><a href="http://www.bloggernews.net/122905">Why is Child Pornography on Your PC?</a><br />
Blogger News Network (blog) &#8211; 1 day ago</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/doyphoto.wordpress.com/1119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/doyphoto.wordpress.com/1119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/doyphoto.wordpress.com/1119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/doyphoto.wordpress.com/1119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/doyphoto.wordpress.com/1119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/doyphoto.wordpress.com/1119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/doyphoto.wordpress.com/1119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/doyphoto.wordpress.com/1119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/doyphoto.wordpress.com/1119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/doyphoto.wordpress.com/1119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/doyphoto.wordpress.com/1119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/doyphoto.wordpress.com/1119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/doyphoto.wordpress.com/1119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/doyphoto.wordpress.com/1119/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1119&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://doyphoto.wordpress.com/2009/11/10/pornvirus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7a8169574c67a32fc0a969387de6a998?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=PG" medium="image">
			<media:title type="html">Superman</media:title>
		</media:content>
	</item>
		<item>
		<title>New Strain of Conficker worsens infections.</title>
		<link>http://doyphoto.wordpress.com/2009/04/09/badwormgotworse/</link>
		<comments>http://doyphoto.wordpress.com/2009/04/09/badwormgotworse/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 00:45:20 +0000</pubDate>
		<dc:creator>doyphoto</dc:creator>
				<category><![CDATA[SME INC]]></category>
		<category><![CDATA[US-CERT]]></category>
		<category><![CDATA[Conficker]]></category>

		<guid isPermaLink="false">http://doyphoto.com/?p=1113</guid>
		<description><![CDATA[Conficker Worm Targets Microsoft Windows Systems added March 29, 2009 at 08:18 pm &#124; updated April 9, 2009 at 06:44 pm UPDATE: Researchers have discovered a new variant of the Conficker Worm on April 9, 2009. This variant updates earlier infections via its peer to peer (P2P) network as well as resuming scan-and-infect activity against [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1113&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Conficker Worm Targets Microsoft Windows Systems added March 29, 2009 at 08:18 pm | updated April 9, 2009 at 06:44 pm</p>
<p><strong>UPDATE: Researchers have discovered a new variant of the Conficker Worm on April 9, 2009. This variant updates earlier infections via its peer to peer (P2P) network as well as resuming scan-and-infect activity against unpatched systems. Public reporting indicates that this variant attempts to download additional malicious code onto victim systems, possibly including copies of the Waledac Trojan, a spam-oriented malicious application which has previously propagated only via bogus email messages containing malicious links. </strong></p>
<p>US-CERT is aware of public reports indicating a widespread infection of the Conficker/Downadup worm, which can infect a Microsoft Windows system from a thumb drive, a network share, or directly across a corporate network, if the network servers are not patched with the MS08-067 patch from Microsoft.</p>
<p>Home users can apply a simple test for the presence of a Conficker/Downadup infection on their home computers. The presence of a Conficker/Downadup infection may be detected if a user is unable to surf to their security solution website or if they are unable to connect to the websites:  http://www.symantec.com/norton/theme.jsp?themeid=conficker_worm&amp;inid=us_ghp_link_conficker_worm http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx http://www.mcafee.com</p>
<p>If a user is unable to reach any of these websites, it may indicate a Conficker/Downadup infection. The most recent variant of Conficker/Downadup interferes with queries for these sites, preventing a user from visiting them. If a Conficker/Downadup infection is suspected, the system or computer should be removed from the network or unplugged from the Internet &#8211; in the case for home users.</p>
<p><span style="font-family:Arial,Geneva,Helvetica;"><span style="font-weight:bold;">UPDATED: </span>US-CERT encourages users to take the following preventative measures to help prevent a Conficker/Downadup infection:</span></p>
<p><span style="font-family:Arial,Geneva,Helvetica;"><br />
</span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/doyphoto.wordpress.com/1113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/doyphoto.wordpress.com/1113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/doyphoto.wordpress.com/1113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/doyphoto.wordpress.com/1113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/doyphoto.wordpress.com/1113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/doyphoto.wordpress.com/1113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/doyphoto.wordpress.com/1113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/doyphoto.wordpress.com/1113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/doyphoto.wordpress.com/1113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/doyphoto.wordpress.com/1113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/doyphoto.wordpress.com/1113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/doyphoto.wordpress.com/1113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/doyphoto.wordpress.com/1113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/doyphoto.wordpress.com/1113/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1113&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://doyphoto.wordpress.com/2009/04/09/badwormgotworse/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7a8169574c67a32fc0a969387de6a998?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=PG" medium="image">
			<media:title type="html">Superman</media:title>
		</media:content>
	</item>
		<item>
		<title>US-CERT: Economic Stimulus Email and Website Scams</title>
		<link>http://doyphoto.wordpress.com/2009/03/05/badstimulus/</link>
		<comments>http://doyphoto.wordpress.com/2009/03/05/badstimulus/#comments</comments>
		<pubDate>Thu, 05 Mar 2009 22:07:48 +0000</pubDate>
		<dc:creator>doyphoto</dc:creator>
				<category><![CDATA[US-CERT]]></category>
		<category><![CDATA[malicious websites]]></category>
		<category><![CDATA[Stimulus Scams]]></category>

		<guid isPermaLink="false">http://doyphoto.com/?p=1111</guid>
		<description><![CDATA[Economic Stimulus Email and Website Scams added March 5, 2009 at 04:08 pm US-CERT is aware of reports of economic stimulus scams circulating. These scams are being conducted through both email and malicious websites.  Some of the email scam messages request personal information, which can then be used for identity theft. Other email scam messages [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1111&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h2>Economic Stimulus Email and Website Scams</h2>
<p><em>added March 5, 2009 at 04:08 pm</em><br />
US-CERT is aware of reports of economic stimulus scams circulating. These scams are being conducted through both email and malicious websites. </p>
<p>Some of the email scam messages request personal information, which can then be used for identity theft. Other email scam messages offer to deposit the stimulus funds directly into users&#8217; bank accounts. If users provide their banking information, the attackers may be able to withdraw funds from the users&#8217; accounts.</p>
<p>The website scams entice users by claiming that they can help them get money from the stimulus fund. These websites typically request payment for their services. If users provide their credit card information, the attackers running the malicious sites may make unauthorized charges to the card, or charge users more than the agreed upon terms.</p>
<p>US-CERT encourages users to do the following to help mitigate the risks:</p>
<ul>
<li>Review the <a href="http://www.ftc.gov/opa/2009/03/stimulusscam.shtm" target="_self">Federal Trade Commission alert</a> about economic stimulus scams.</li>
<li>Refer to the <a href="http://www.us-cert.gov/reading_room/emailscams_0905.pdf" target="_self">Recognizing and Avoiding Email Scams</a> (pdf) document for more information on avoiding email scams.</li>
<li>Refer to the <a href="http://www.us-cert.gov/cas/tips/ST04-014.html" target="_self">Avoiding Social Engineering and Phishing Attacks</a> document for more information on social engineering attacks.</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/doyphoto.wordpress.com/1111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/doyphoto.wordpress.com/1111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/doyphoto.wordpress.com/1111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/doyphoto.wordpress.com/1111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/doyphoto.wordpress.com/1111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/doyphoto.wordpress.com/1111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/doyphoto.wordpress.com/1111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/doyphoto.wordpress.com/1111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/doyphoto.wordpress.com/1111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/doyphoto.wordpress.com/1111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/doyphoto.wordpress.com/1111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/doyphoto.wordpress.com/1111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/doyphoto.wordpress.com/1111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/doyphoto.wordpress.com/1111/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1111&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://doyphoto.wordpress.com/2009/03/05/badstimulus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7a8169574c67a32fc0a969387de6a998?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=PG" medium="image">
			<media:title type="html">Superman</media:title>
		</media:content>
	</item>
		<item>
		<title>US-CERT: Malicious Code Targeting Social Networking Sites</title>
		<link>http://doyphoto.wordpress.com/2009/03/04/socialattack/</link>
		<comments>http://doyphoto.wordpress.com/2009/03/04/socialattack/#comments</comments>
		<pubDate>Wed, 04 Mar 2009 17:53:00 +0000</pubDate>
		<dc:creator>doyphoto</dc:creator>
				<category><![CDATA[US-CERT]]></category>
		<category><![CDATA[Facebook.com]]></category>
		<category><![CDATA[hi5.com]]></category>
		<category><![CDATA[Koobface]]></category>
		<category><![CDATA[livejournal.com]]></category>
		<category><![CDATA[Myspace.com]]></category>

		<guid isPermaLink="false">http://doyphoto.com/2009/03/04/us-cert-malicious-code-targeting-social-networking-sites/</guid>
		<description><![CDATA[Malicious Code Targeting Social Networking Site Users added March 4, 2009 at 11:53 am US-CERT is aware of public reports of malicious code spreading via popular social networking sites including myspace.com, facebook.com, hi5.com, friendster.com, myyearbook.com, bebo.com, and livejournal.com. The reports indicate that the malware, named Koobface, is spreading through invitations from a user&#8217;s contact that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1106&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h2>Malicious Code Targeting Social Networking Site Users</h2>
<p><em>added March 4, 2009 at 11:53 am</em><br />
US-CERT is aware of public reports of malicious code spreading via popular social networking sites including myspace.com, facebook.com, hi5.com, friendster.com, myyearbook.com, bebo.com, and livejournal.com.</p>
<p><strong><em>The reports indicate that the malware, named Koobface, is spreading through invitations from a user&#8217;s contact that include a link to view a video. If the users click on the link in this invitation, they are prompted to update Adobe Flash Player. This update is not a legitimate Adobe Flash Player update, it is malicious code.</em></strong></p>
<p>Additionally, some of the reports indicate that there are multiple bogus Facebook applications being used to obtain users&#8217; private information.</p>
<p>US-CERT encourages users and administrators to do the following to help mitigate the risks:</p>
<ul>
<li>Install antivirus software and keep the virus signature files up to date.</li>
<li>Do not follow unsolicited links.</li>
<li>Use caution when downloading and installing applications.</li>
<li>Obtain software applications and updates directly from the vendor&#8217;s website.</li>
<li>Refer to the <a href="http://www.us-cert.gov/cas/tips/ST06-003.html" target="_self">Staying Safe on Social Networking Sites</a> document for more information on safe use of social networking sites.</li>
<li>Refer to the <a href="http://www.us-cert.gov/cas/tips/ST04-014.html" target="_self">Avoiding Social Engineering and Phishing Attacks</a> document for more information on social engineering attacks.</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/doyphoto.wordpress.com/1106/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/doyphoto.wordpress.com/1106/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/doyphoto.wordpress.com/1106/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/doyphoto.wordpress.com/1106/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/doyphoto.wordpress.com/1106/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/doyphoto.wordpress.com/1106/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/doyphoto.wordpress.com/1106/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/doyphoto.wordpress.com/1106/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/doyphoto.wordpress.com/1106/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/doyphoto.wordpress.com/1106/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/doyphoto.wordpress.com/1106/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/doyphoto.wordpress.com/1106/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/doyphoto.wordpress.com/1106/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/doyphoto.wordpress.com/1106/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1106&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://doyphoto.wordpress.com/2009/03/04/socialattack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7a8169574c67a32fc0a969387de6a998?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=PG" medium="image">
			<media:title type="html">Superman</media:title>
		</media:content>
	</item>
		<item>
		<title>US-CERT: New Variant of Conficker/Downadup Worm Circulating</title>
		<link>http://doyphoto.wordpress.com/2009/02/23/superbadworm/</link>
		<comments>http://doyphoto.wordpress.com/2009/02/23/superbadworm/#comments</comments>
		<pubDate>Tue, 24 Feb 2009 00:01:31 +0000</pubDate>
		<dc:creator>doyphoto</dc:creator>
				<category><![CDATA[SME INC]]></category>
		<category><![CDATA[US-CERT]]></category>

		<guid isPermaLink="false">http://doyphoto.com/?p=1100</guid>
		<description><![CDATA[New Variant of Conficker/Downadup Worm Circulating added February 23, 2009 at 05:02 pm *For Immediate remote support in removing Conficker B++, call (509) 438-0990. For more info, please visit LIVE SUPPORT.   US-CERT is aware of public reports concerning a new variant of the Conficker/Downadup worm, named Conficker B++. This variant propagates itself via multiple methods, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1100&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h2>New Variant of Conficker/Downadup Worm Circulating</h2>
<p><span style="font-size:x-small;"><em>added February 23, 2009 at 05:02 pm</em><br />
</span></p>
<p>*<strong>For <span style="text-decoration:underline;">Immediate</span> remote support in removing Conficker B++, call (509) 438-0990. For more info, please visit <a href="http://www.thesuperman.net/livesupport" target="_blank">LIVE SUPPORT</a>.</strong></p>
<p> </p>
<p>US-CERT is aware of public <a href="http://mtc.sri.com/Conficker/" target="_self">reports</a> concerning a new variant of the Conficker/Downadup worm, named Conficker B++. This variant propagates itself via multiple methods, including exploitation of the previously patched vulnerability, password guessing, and the infection of removable media. Most significantly, Conficker B++ implements a new backdoor with &#8220;auto-update&#8221; functionality, allowing machines compromised by the new variant to have additional malicious code installed on them. According to Microsoft, there is no indication that systems infected with previous variants of Conficker can automatically be re-infected with the B++ variant.</p>
<p>US-CERT strongly encourages users to update unpatched systems as soon as possible.</p>
<p>Additionally, US-CERT recommends that users take the following preventative measures to help mitigate the security risks:</p>
<p>Install antivirus software, and keep the virus signatures up to date.</p>
<ul>
<li>Review the Microsoft Malware Protection Center blog entry for details regarding the worm.</li>
<li>Review the <a href="http://www.us-cert.gov/cas/tips/ST08-001.html" target="_self">Using Caution with USB Drives</a> Cyber Security Tip for more information on protecting removable media.</li>
</ul>
<h3>Conficker A/B Top-Level Control Flow</h3>
<p><a href="https://doyphoto.wordpress.com/wp-admin/#Figure_1">Figure 1</a>  illustrates a flow diagram of the main thread for both variants of the Conficker agent, A and B.  In both cases, the Conficker agent is distributed and run as a dynamically linked library. Its base code has been compiled as a DLL and its DLLMain function initiates the main thread represented by the diagram.  The agent code proceeds by first checking the Windows version, and based on this result creates a remote thread in processes such as <span style="font-family:Courier New,Courier,monospace;">svchost.exe</span>.  This is done by invoking LoadLibrary, where the copy of the DLL is passed as an argument.  The malicious library then copies itself in the system root directory under a random file name. After initiating the use of Winsock DLL, the bulk of the malicious code logic is executed.</p>
<hr noshade="noshade" /><span style="font-weight:bold;"><a name="Figure_1"></a></span><br />
<a href="http://doyphoto.files.wordpress.com/2009/02/confickerfig1.jpg"><img class="aligncenter size-full wp-image-1104" title="confickerfig1" src="http://doyphoto.files.wordpress.com/2009/02/confickerfig1.jpg?w=604" alt="confickerfig1"   /></a></p>
<p> </p>
<p style="text-align:center;"><span style="font-weight:bold;">Figure 1: Conficker A (left) /B (right): Top-level control flow</span></p>
<hr noshade="noshade" />Conficker A&#8217;s agent proceeds as follows. First, it checks for the presence of a firewall.  If a firewall exists, the agent sends a UPNP message to open a local random high-order port (i.e., it asks the firewall to open its backdoor port to the Internet).  Next, it opens the same high-order port on its local host: its binary upload backdoor.  This backdoor is used during propagation, to allow newly infected victims to retrieve the Conficker binary.  It proceeds to one of the following sites to obtain its external-facing IP address <span style="font-style:italic;">www.getmyip.org, getmyip.co.uk</span>, and <span style="font-style:italic;">checkip.dyndns.org</span>, and attempts to download the GeoIP database from <span style="font-style:italic;">maxmind.com</span>.  It randomly generates IP addresses to search for additional victims, filtering Ukraine IPs based on the GeoIP database.  The GeoIP information is also used as part of MS08-67 exploit process [<a href="https://doyphoto.wordpress.com/wp-admin/ref-10">10</a>].  Conficker A then sleeps for 30 minutes before starting a thread that attempts to contact <span style="font-family:Courier New,Courier,monospace;">http://trafficconverter.biz/4vir/antispyware/ to </span>download a file called <span style="font-family:Courier New,Courier,monospace;">loadadv.exe</span>.  This thread cycles every 5 minutes.</p>
<p> </p>
<p>Next, Conficker A enters an infinite loop, within which it generates a list of 250 domain names (rendezvous points).  The name-generation function is based on a randomizing function that it seeds with the current UTC system date.  The same list of 250 names is generated every 3 hours, i.e., 8 times per day.  All Conficker clients, with system clocks that are at minimum synchronized to the current UTC date, will compute and attempt to contact the same set of domains. When contacting a domain for which a valid IP address has been registered, Conficker clients send a URL request to TCP port 80 of the target IP, and if a Windows binary is returned, it will be validated via a locally stored public key, stored on the victim host, and executed.  If the computer is not connected to the Internet, then the malicious code will check for connectivity every 60 seconds.  When the computer is connected, Conficker A will execute the domain name generation subroutine, contacting <span style="font-style:italic;">every </span>registered domain in the current 250-name set to inquire if an executable is available for download. </p>
<p>Conficker B is a rewrite of Conficker A with the following noticeable differences.  First, Conficker A incorporates a Ukraine-avoidance routine that causes the process to suicide if the keyboard language layout has been set to Ukrainian. Conficker B does not include this keyboard check.  B also uses different mutex strings and patches a number of Windows APIs, and attempts to disable its victim&#8217;s local security defenses by terminating the execution of a predefined set of antivirus products it finds on the machine.  It has significantly more suicide logic embedded in its code, and employs anti-debugging features to avoid reverse engineering attempts.</p>
<p>Conficker B uses a different set of sites to query its external-facing IP address <span style="font-style:italic;">www.getmyip.org, www.whatsmyipaddress.com, www.whatismyip.org, checkip.dyndns.org</span>.  It does not download the fraudware Antivirus XP software that version A attempts to download.   Conficker&#8217;s propagation methods vary among A and B and are described in Section <a href="https://doyphoto.wordpress.com/wp-admin/#Propagation">Conficker Propagation</a>.  Furthermore, a recent analysis by Symantec has uncovered that the GeoIP file is directly embedded in the Conficker B binary as a compressed RAR (Roshal archive) file encrypted using RC4 [<a href="https://doyphoto.wordpress.com/wp-admin/ref-11">11</a>]. </p>
<p>Like Conficker A, after a relatively short initialization phase  followed by a scan and infect stage,  Conficker B proceeds to generate a daily list of domains to probe for the download of an additional payload.  Conficker B builds its candidate set of rendezvous points every 2 hours, using a similar algorithm.  But it uses different seeds and also appends three additional top-level domains.  The result is that the daily domain lists generated by A and B do not overlap.</p>
<h3><a name="sec-validation"></a>Binary Download and Validation</h3>
<p>Among the key functions of Conficker is that of probing the daily set of Internet rendezvous points for a new Windows executable file to download and execute.  This mechanism provides an effective binary updating service similar to that of other traditional botnets, with the exception that the Conficker update service is highly mobile and its location (<span style="font-style:italic;">i.e.</span>, to date we have not confirmed this feature in use by the malware authors) is recomputed each day by all infected clients.    Although many groups have been able to break the domain generation algorithm and  registered rendezvous points, Conficker&#8217;s authors have taken care to ensure that other groups cannot upload arbitrary binaries to its infected drones.</p>
<p>Both Conficker A and B clients incorporate a binary validation mechanism to ensure that a downloaded binary has been signed by the Conficker authors.  <a href="https://doyphoto.wordpress.com/wp-admin/#fig-validator">Figure 2</a><span style="font-weight:bold;"> </span>illustrates the download validation procedure used to verify the authenticity of binaries pulled from Internet rendezvous points.   The procedure begins with Conficker&#8217;s authors computing a 512-bit hash <span style="font-weight:bold;">M</span> of the Windows binary that will be downloaded to the client.  The binary is then encrypted using the symmetric stream cipher RC4 algorithm with password <span style="font-weight:bold;">M</span>.   Next, the authors compute a digital signature using an RSA encryption scheme, as follows:  <span style="font-weight:bold;">M^<span style="color:#cc0000;">epriv</span> mod N = Sig</span>,  where <span style="font-weight:bold;">N</span> is a public modulus that is embedded in all Conficker client binaries.   <span style="font-weight:bold;">Sig</span> is then appended to the encrypted binary, and together they can be pushed to all infected Conficker clients that connect to the appropriate rendezvous point.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/doyphoto.wordpress.com/1100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/doyphoto.wordpress.com/1100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/doyphoto.wordpress.com/1100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/doyphoto.wordpress.com/1100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/doyphoto.wordpress.com/1100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/doyphoto.wordpress.com/1100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/doyphoto.wordpress.com/1100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/doyphoto.wordpress.com/1100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/doyphoto.wordpress.com/1100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/doyphoto.wordpress.com/1100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/doyphoto.wordpress.com/1100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/doyphoto.wordpress.com/1100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/doyphoto.wordpress.com/1100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/doyphoto.wordpress.com/1100/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1100&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://doyphoto.wordpress.com/2009/02/23/superbadworm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7a8169574c67a32fc0a969387de6a998?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=PG" medium="image">
			<media:title type="html">Superman</media:title>
		</media:content>

		<media:content url="http://doyphoto.files.wordpress.com/2009/02/confickerfig1.jpg" medium="image">
			<media:title type="html">confickerfig1</media:title>
		</media:content>
	</item>
		<item>
		<title>US-CERT CRITICAL ALERT: IRS Stimulus Package Phishing Scam</title>
		<link>http://doyphoto.wordpress.com/2009/02/06/us-cert-critical-alert-irs-stimulus-package-phishing-scam/</link>
		<comments>http://doyphoto.wordpress.com/2009/02/06/us-cert-critical-alert-irs-stimulus-package-phishing-scam/#comments</comments>
		<pubDate>Fri, 06 Feb 2009 16:11:32 +0000</pubDate>
		<dc:creator>doyphoto</dc:creator>
				<category><![CDATA[US-CERT]]></category>
		<category><![CDATA[PHISHING SCAMS]]></category>
		<category><![CDATA[PHISHING SCAM]]></category>
		<category><![CDATA[STIMULUS]]></category>
		<category><![CDATA[IRS]]></category>

		<guid isPermaLink="false">http://doyphoto.com/2009/02/06/us-cert-critical-alert-irs-stimulus-package-phishing-scam/</guid>
		<description><![CDATA[IRS Stimulus Package Phishing Scam Original release date: February 6, 2009 at 10:03 am Last revised: February 6, 2009 at 10:03 am US-CERT is aware of public reports indicating that phishing scams are circulating via fraudulent U.S. Internal Revenue Service emails offering users stimulus package payments. These emails include text that attempts to convince users [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1096&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>IRS Stimulus Package Phishing Scam</p>
<p>Original release date: February 6, 2009 at 10:03 am<br />
Last revised: February 6, 2009 at 10:03 am</p>
<p>US-CERT is aware of public reports indicating that phishing scams are<br />
circulating via fraudulent U.S. Internal Revenue Service emails<br />
offering users stimulus package payments. These emails include text<br />
that attempts to convince users to follow a link to a website or to<br />
complete an attached document. The website and document request that<br />
the user provide personal information.</p>
<p>US-CERT encourages users to do the following to help mitigate the<br />
risks:<br />
  * Do not follow unsolicited web links received in email messages.<br />
  * Refer to the Recognizing and Avoiding Email Scams (pdf) document<br />
    for more information on avoiding email scams.<br />
  * Refer to the Avoiding Social Engineering and Phishing Attacks<br />
    (pdf) document for more information on social engineering attacks.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/doyphoto.wordpress.com/1096/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/doyphoto.wordpress.com/1096/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/doyphoto.wordpress.com/1096/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/doyphoto.wordpress.com/1096/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/doyphoto.wordpress.com/1096/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/doyphoto.wordpress.com/1096/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/doyphoto.wordpress.com/1096/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/doyphoto.wordpress.com/1096/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/doyphoto.wordpress.com/1096/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/doyphoto.wordpress.com/1096/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/doyphoto.wordpress.com/1096/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/doyphoto.wordpress.com/1096/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/doyphoto.wordpress.com/1096/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/doyphoto.wordpress.com/1096/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=doyphoto.wordpress.com&amp;blog=4276385&amp;post=1096&amp;subd=doyphoto&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://doyphoto.wordpress.com/2009/02/06/us-cert-critical-alert-irs-stimulus-package-phishing-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7a8169574c67a32fc0a969387de6a998?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=PG" medium="image">
			<media:title type="html">Superman</media:title>
		</media:content>
	</item>
	</channel>
</rss>
