<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hacker4Lease - IT Security Services</title>
	<atom:link href="http://www.hacker4lease.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hacker4lease.com</link>
	<description>The IT and Security Source</description>
	<lastBuildDate>Mon, 06 Feb 2012 21:11:43 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>IT Security for Spear Phishing</title>
		<link>http://www.hacker4lease.com/2012/02/370/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.hacker4lease.com/2012/02/370/#comments</comments>
		<pubDate>Mon, 06 Feb 2012 21:07:15 +0000</pubDate>
		<dc:creator>Karen</dc:creator>
				<category><![CDATA[White Papers]]></category>

		<guid isPermaLink="false">http://www.hacker4lease.com/?p=370</guid>
		<description><![CDATA[IT Security Services Focus on Spear Phishing
Phishing.  It’s been a hot topic and the focus of IT security services companies for a long time.  What is it?  Phishing is a way of acquiring information including, usernames, passwords, and credit card details, as well as other personal information through methods that are masquerades for trustworthy entities. [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><strong>IT Security Services Focus on Spear Phishing</strong></p>
<p>Phishing.  It’s been a hot topic and the focus of IT security services companies for a long time.  What is it?  Phishing is a way of acquiring information including, usernames, passwords, and credit card details, as well as other personal information through methods that are masquerades for trustworthy entities.  For example, emails meant to look like official emails from a bank or other official business are intended to make the recipient “log on” to the phisher’s website and provide user names and passwords.</p>
<p>A more advanced type of phishing is what is termed spear phishing.  This type of phishing has led to a lot of concern from the IT security services market.  With spear phishing, the phishing emails target specific organizations in an attempt to gain unauthorized access to confidential data.  With traditional phishing, the emails typically appear to come from large, well-known companies such as eBay or Paypal; conversely, spear phishing emails appear to come from an individual within the recipient’s company and often from persons holding authority.</p>
<p>IT security assessment services and IT security watchdogs have discovered yet another highly targeted email attack using phony conference invitations to garner information from recipients.  These spear phishing attempts are targeting government related organizations around the world, specifically those related to the defense industry.  The focus of the attacks is to try to use existing security flaws in various Adobe programs to place a Trojan on vulnerable computers, thus providing backdoor access for hackers to hijack the system.</p>
<p>The malware, once placed, becomes undetectable by disguising itself as a Windows Update utility.  Security researchers from IT security services companies, Seculert and Zscaler ThreatlabZ, uncovered this particular spear phishing method.  After joining forces to analyze the incidents involving the malware, they issued a joint warning.  Similar spear phishing attacks were tracked back to 2009.   The most recent targets of these attacks are companies (foreign and domestic) that own intellectual property related to geospace, aerospace, and defense industries.  Of particular concern is the level of sophistication of the malware.  Malware that infiltrates into virtual machine environments will simply exit the machine.  In suitable environments, the malware is implanted and the infected machine connects with the command-and-control (C&amp;C) server then transmits system information such as the type of operating system and identifiers that allow the zombie to authenticate with the server.  After the initial connection is successfully completed, the infected system gains the potential to download and upload files, as well as executing commands.</p>
<p>With this latest method of spear phishing, recipients receive emails that contain PDF attachments from phony companies, inviting recipients to various conferences.   Once opened, the PDF files contain malware that implements zero-day vulnerabilities resident in Adobe Reader, allowing for installation of the RAT (Remote Access Trojan) malware.    Because the malware hides itself as a Windows Updater, the Trojan is named the MSUpdater Trojan.</p>
<p>At this time the people responsible for these attacks are unknown.  Given that the targets are all specific government related organizations, there is suspicion that the attackers are high-profile entities, and could possible even be a country.</p>
<p>IT security service integrators have long believed and warned that attachers responsible for spear phishing attacks start by researching their victims through professional networking sites.  This way, the attacks can be customized in ways that gain the interest of the target recipient.  For example, conference invitations include invitations to industry conferences relevant to the recipient and his or her job or interests.</p>
<p>IT security services consulting personnel advise that targeted victims should understand that the attacks are advanced threats and tend to be persistent.  Not only have the attacks continued undetected for quite a length of time, but they will continue on in the future.</p>
<p>Spear phishing takes many forms.  A recent example is the Sony PlayStation Network hack.  While it is unknown how much personal information was hijacked through this attack, it is believed it was much worse than the Epsilon and PSN breaches.    It is possible that the attackers may have gained credit card information.  Whether this is actually the case or not, it is of major concern because any information gained can subsequently be used to personalize future spear phishing attacks.  Spear phishing attempts are much more convincing when they contain personalized information and whether or not the original attacks garner the desired information, with personalization, the odds of gaining further information go up when more personal information is available to include in future spear phishing efforts.</p>
<p>What is known at the present time is that the attackers appear to be very patient and take the time to thoroughly research their targets.  Tending to target organizations whose intellectual property and assets have high value, the malware campaigns constantly evolve with frequent changes in binaries, which serves to allow the malware to continue to fly under the radar.</p>
<p>Law enforcement agencies such as the FBI take spear phishing seriously.  Organizations such as the US Secret Service and the investigative agencies related to the various Departments of Defense actively work to uncover and contain it.  In the meantime, people and organizations must be wary.  The keys for combatting spear phishing attempts are vigilance, IT security risk assessment services and, where necessary, outsourcing IT security services.  Education is vital and includes methods to determine whether URLs are legit, not clicking on email links, and keeping security tools active – and current!  It is money well spent to employ IT security services consulting companies to perform risk assessment and education, and to consider managed IT security services.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacker4lease.com/2012/02/370/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WIFI comes with responsibility now!</title>
		<link>http://www.hacker4lease.com/2010/05/wifi-comes-with-respnsibiloity-now/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.hacker4lease.com/2010/05/wifi-comes-with-respnsibiloity-now/#comments</comments>
		<pubDate>Mon, 17 May 2010 09:25:37 +0000</pubDate>
		<dc:creator>lior</dc:creator>
				<category><![CDATA[News Archive]]></category>

		<guid isPermaLink="false">http://www.hacker4lease.com/2010/05/wifi-comes-with-respnsibiloity-now/</guid>
		<description><![CDATA[WIFI owners in Germany better secure their networks &#8211; the courts will hold them responsible for illegal downloads even if done by an intruder.  Read More.
]]></description>
			<content:encoded><![CDATA[<p>WIFI owners in Germany better secure their networks &#8211; the courts will hold them responsible for illegal downloads even if done by an intruder.  <a target="_blank" href="http://www.msnbc.msn.com/id/37107291/ns/technology_and_science-security/" target="_blank">Read More.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacker4lease.com/2010/05/wifi-comes-with-respnsibiloity-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Central Database will help track Cyber Crime</title>
		<link>http://www.hacker4lease.com/2010/05/central-database-will-help-track-cyber-crime/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.hacker4lease.com/2010/05/central-database-will-help-track-cyber-crime/#comments</comments>
		<pubDate>Sun, 16 May 2010 15:15:36 +0000</pubDate>
		<dc:creator>lior</dc:creator>
				<category><![CDATA[News Archive]]></category>

		<guid isPermaLink="false">http://www.hacker4lease.com/?p=344</guid>
		<description><![CDATA[A holistic view can be formed and acted upon &#8211; any across the board attack should be instantly visible. Read More.
]]></description>
			<content:encoded><![CDATA[<p>A holistic view can be formed and acted upon &#8211; any across the board attack should be instantly visible. <a target="_blank" href="http://www.federalnewsradio.com/index.php?nid=35&amp;sid=1957093" target="_blank">Read More.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacker4lease.com/2010/05/central-database-will-help-track-cyber-crime/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CEH comes of age</title>
		<link>http://www.hacker4lease.com/2010/05/us-army-website/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.hacker4lease.com/2010/05/us-army-website/#comments</comments>
		<pubDate>Sun, 16 May 2010 08:34:43 +0000</pubDate>
		<dc:creator>lior</dc:creator>
				<category><![CDATA[News Archive]]></category>

		<guid isPermaLink="false">http://www.hacker4lease.com/2010/01/us-army-website/</guid>
		<description><![CDATA[The EC-Council Certified Ethical Hacker (CEH) certification program is a new baseline skills requirement for U.S.cyber defenders.
read more
]]></description>
			<content:encoded><![CDATA[<p>The EC-Council Certified Ethical Hacker (CEH) certification program is a new baseline skills requirement for U.S.cyber defenders.</p>
<p><a target="_blank" href="http://www.dtic.mil/whs/directives/corres/pdf/857001m.pdf [http://r20.rs6.net/tn.jsp?et=1103115128163&amp;s=13413&amp;e=001Ky7kqPD2SEOuZtKAEYBknwyG23GeCCBlRg_CBCfMmYap7tpo9rujITPGw9fkJnRee481GeKNu6bZY8gfBsW3vYd_cizsbBTFgW5wPcOOlbpwqBWvPCFnAuLqIb0i1rIyGITzGXbx2HJbNI4aP33ncGTVYGOSoNWUYTZrrsPbS68=]" target="_blank">read more</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacker4lease.com/2010/05/us-army-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WIFI comes with responsibility now! &#8230;in Germany</title>
		<link>http://www.hacker4lease.com/2010/05/beware-infected-web-pages/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.hacker4lease.com/2010/05/beware-infected-web-pages/#comments</comments>
		<pubDate>Sun, 16 May 2010 02:11:49 +0000</pubDate>
		<dc:creator>lior</dc:creator>
				<category><![CDATA[News Archive]]></category>

		<guid isPermaLink="false">http://www.hacker4lease.com/?p=312</guid>
		<description><![CDATA[WIFI owners in Germany better secure their networks &#8211; the courts will hold them responsible for illegal downloads even if done by an intruder.  Read More.
]]></description>
			<content:encoded><![CDATA[<p>WIFI owners in Germany better secure their networks &#8211; the courts will hold them responsible for illegal downloads even if done by an intruder.  <a target="_blank" href="http://www.msnbc.msn.com/id/37107291/ns/technology_and_science-security/" target="_blank">Read More.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacker4lease.com/2010/05/beware-infected-web-pages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Central Database will help track Cyber Crime</title>
		<link>http://www.hacker4lease.com/2010/05/china-on-the-attack/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.hacker4lease.com/2010/05/china-on-the-attack/#comments</comments>
		<pubDate>Sat, 15 May 2010 20:10:05 +0000</pubDate>
		<dc:creator>lior</dc:creator>
				<category><![CDATA[News Archive]]></category>

		<guid isPermaLink="false">http://www.hacker4lease.com/?p=309</guid>
		<description><![CDATA[A holistic view can be formed and acted upon &#8211; any across the board attack should be instantly visible. Read More.
]]></description>
			<content:encoded><![CDATA[<p>A holistic view can be formed and acted upon &#8211; any across the board attack should be instantly visible. <a target="_blank" href="http://www.federalnewsradio.com/index.php?nid=35&amp;sid=1957093" target="_blank">Read More.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacker4lease.com/2010/05/china-on-the-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Custom or Packaged Services</title>
		<link>http://www.hacker4lease.com/2010/03/custom-or-packaged-services/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.hacker4lease.com/2010/03/custom-or-packaged-services/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 13:31:53 +0000</pubDate>
		<dc:creator>lior</dc:creator>
				<category><![CDATA[Services]]></category>

		<guid isPermaLink="false">http://www.hacker4lease.com/?p=330</guid>
		<description><![CDATA[We offer a variety of services designed to fit your unique requirements. While we have packed up some predefined offerings, we also would be happy to customize a package for you. Let&#8217;s get connected and discuss your security concerns and we can share our experience with you as well. Then we can work together to [...]]]></description>
			<content:encoded><![CDATA[<p>We offer a variety of services designed to fit your unique requirements. While we have packed up some predefined offerings, we also would be happy to customize a package for you. Let&#8217;s get connected and discuss your security concerns and we can share our experience with you as well. Then we can work together to make sure that you have the right mix to protect your business and your assets. There&#8217;s nothing worse than downtime combined with destroyed or exploited assets for a business. Let us help you take the steps to prevent that possibility. <a target="_blank" href="../contact/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed">Contact us</a> today.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hacker4lease.com/2010/03/custom-or-packaged-services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>US Government and Private Sector Can&#8217;t Agree on Cyber Security</title>
		<link>http://www.hacker4lease.com/2010/01/us-government-and-private-sector-cant-agree-on-cyber-security-2/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.hacker4lease.com/2010/01/us-government-and-private-sector-cant-agree-on-cyber-security-2/#comments</comments>
		<pubDate>Sat, 16 Jan 2010 01:13:19 +0000</pubDate>
		<dc:creator>lior</dc:creator>
				<category><![CDATA[News Archive]]></category>

		<guid isPermaLink="false">http://www.hacker4lease.com/?p=156</guid>
		<description><![CDATA[<a href="http://www.latimes.com/business/la-fi-security26-2008aug26,0,2021258.story" target="_blank" rel="nofollow">read more</a>]]></description>
			<content:encoded><![CDATA[<a href="http://www.latimes.com/business/la-fi-security26-2008aug26,0,2021258.story" target="_blank" rel="nofollow">read more</a>]]></content:encoded>
			<wfw:commentRss>http://www.hacker4lease.com/2010/01/us-government-and-private-sector-cant-agree-on-cyber-security-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Computer crime is even broader than we think!</title>
		<link>http://www.hacker4lease.com/2010/01/computer-crime-is-even-broader-than-we-think/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.hacker4lease.com/2010/01/computer-crime-is-even-broader-than-we-think/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 23:26:45 +0000</pubDate>
		<dc:creator>lior</dc:creator>
				<category><![CDATA[News Archive]]></category>

		<guid isPermaLink="false">http://www.hacker4lease.com/?p=126</guid>
		<description><![CDATA[<a href="http://www.securityfocus.com/brief/825" target="_blank" rel="nofollow">read more</a>]]></description>
			<content:encoded><![CDATA[<a href="http://www.securityfocus.com/brief/825" target="_blank" rel="nofollow">read more</a>]]></content:encoded>
			<wfw:commentRss>http://www.hacker4lease.com/2010/01/computer-crime-is-even-broader-than-we-think/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Reports Tool Cleared Phony Security Software</title>
		<link>http://www.hacker4lease.com/2010/01/microsoft-reports-tool-cleared-phony-security-software/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.hacker4lease.com/2010/01/microsoft-reports-tool-cleared-phony-security-software/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 23:27:33 +0000</pubDate>
		<dc:creator>lior</dc:creator>
				<category><![CDATA[News Archive]]></category>

		<guid isPermaLink="false">http://www.hacker4lease.com/?p=130</guid>
		<description><![CDATA[<a href="http://www.sans.org/newsletters/newsbites/newsbites.php?vol=10&#038;issue=93&#038;rss=Y" target="_blank" rel="nofollow">read more</a>]]></description>
			<content:encoded><![CDATA[<a href="http://www.sans.org/newsletters/newsbites/newsbites.php?vol=10&#038;issue=93&#038;rss=Y" target="_blank" rel="nofollow">read more</a>]]></content:encoded>
			<wfw:commentRss>http://www.hacker4lease.com/2010/01/microsoft-reports-tool-cleared-phony-security-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced) (user agent is rejected)
Database Caching 2/13 queries in 0.019 seconds using disk
Object Caching 1003/1014 objects using disk
Content Delivery Network via N/A

Served from: www.hacker4lease.com @ 2012-05-19 02:33:11 -->
