<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Super-targeted spear phishing attacks</title>
	<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks/</link>
	<description>Comments on MetaFilter post Super-targeted spear phishing attacks</description>
	<pubDate>Thu, 27 Mar 2008 22:55:15 -0800</pubDate>
	<lastBuildDate>Thu, 27 Mar 2008 22:55:15 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Super-targeted spear phishing attacks</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks</link>	
		<description>The recent cyber attacks on &lt;a href=&quot;http://www.washingtonpost.com/wp-dyn/content/article/2008/03/21/AR2008032102605.html&quot;&gt;pro-Tibet groups&lt;/a&gt; in the U.S. (&lt;a href=&quot;http://www.f-secure.com/weblog/archives/00001406.html&quot;&gt;attack details&lt;/a&gt;, &lt;a href=&quot;http://isc.sans.org/diary.html?storyid=4177&quot;&gt;technical data&lt;/a&gt;) and on the &lt;a href=&quot;http://www.washingtonpost.com/wp-dyn/content/article/2008/03/20/AR2008032003193.html&quot;&gt;Save Darfur&lt;/a&gt; Coalition, among &lt;a href=&quot;http://www.scmagazineus.com/Olympic-spam-carries-malicious-code-MessageLabs/article/107232/&quot;&gt;others&lt;/a&gt;, have managed to catch the attention of some in the mainstream media. 
Such super-targeted &lt;a href=&quot;http://searchsecurity.techtarget.com/sDefinition/0,,sid14_gci1134829,00.html&quot;&gt;spear phishing&lt;/a&gt; attacks have been on the &lt;a href=&quot;http://64.233.169.104/search?q=cache:xywpL9uO1CsJ:www.ci.hillsboro.or.us/Police/documents/Argus/SpearPhishing-11-03-05.pdf&quot;&gt;rise&lt;/a&gt; for several years, and have become an important &lt;a href=&quot;http://resources.zdnet.co.uk/articles/features/0,1000002000,39365959,00.htm&quot;&gt;tool&lt;/a&gt; for corporate &lt;a href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9045564&quot;&gt;espionage&lt;/a&gt; and military &lt;a href=&quot;http://www.fcw.com/online/news/97186-1.html&quot;&gt;infiltration&lt;/a&gt; attempts. &lt;a href=&quot;http://govexec.com/dailyfed/0807/082207mm.htm&quot;&gt;Teaching users&lt;/a&gt; to recognize such attack emails is probably the most effective deterrence, as &lt;a href=&quot;http://www.infoworld.com/article/07/11/09/Zero-day-specialists-hooked-on-spear-phishing_1.html&quot;&gt;technology&lt;/a&gt; solutions have shown to not be particularly effective. Some companies and government agencies even conduct &lt;a href=&quot;http://online.wsj.com/public/article/SB112424042313615131-z_8jLB2WkfcVtgdAWf6LRh733sg_20060817.html&quot;&gt;sting operations&lt;/a&gt; to ferret out which internal users fail the test, targeting them for additional training. &lt;br /&gt;&lt;br /&gt;Thanks to &lt;a href=&quot;http://www.metafilter.com/user/12845&quot;&gt;homunculus&lt;/a&gt; for &lt;a href=&quot;http://www.metafilter.com/70026/Trouble-on-the-Roof-of-the-World#2056111&quot;&gt;encouraging&lt;/a&gt; me to post on this.</description>
		<guid isPermaLink="false">post:www.metafilter.com,2008:site.70295</guid>
		<pubDate>Thu, 27 Mar 2008 20:34:53 -0800</pubDate>
		<dc:creator>gemmy</dc:creator>		<category>spearphishing</category>		<category>phishing</category>		<category>cyber</category>		<category>attack</category>		<category>trojan</category>		<category>malware</category>		<category>Tibet</category>		<category>espionage</category>		<category>deterrence</category>
	</item>	<item>
		<title>By: madamjujujive</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2060902</link>	
		<description>Thanks, gemmy - what a thorough overview you provided.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2060902</guid>
		<pubDate>Thu, 27 Mar 2008 22:55:15 -0800</pubDate>
		<dc:creator>madamjujujive</dc:creator>
	</item>	<item>
		<title>By: agress</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2060906</link>	
		<description>I think it&apos;s somewhat sad that a malicious form of e-mail spamming has taken on the name of a relatively well-known hippie jam band. I actually kinda like Phish =(

I&apos;m not sure that they&apos;d be into using spears...</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2060906</guid>
		<pubDate>Thu, 27 Mar 2008 22:57:29 -0800</pubDate>
		<dc:creator>agress</dc:creator>
	</item>	<item>
		<title>By: homunculus</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2060909</link>	
		<description>Wow, great post.  Thanks for putting this together, gemmy.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2060909</guid>
		<pubDate>Thu, 27 Mar 2008 23:05:03 -0800</pubDate>
		<dc:creator>homunculus</dc:creator>
	</item>	<item>
		<title>By: adamvasco</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2060943</link>	
		<description>Thanks gemmy. When I read the the cyber attack comments &lt;a href=&quot;http://www.metafilter.com/70026/Trouble-on-the-Roof-of-the-World#2054351&quot;&gt;here&lt;/a&gt; I didn&apos;t really understand what was happening and MSM didn&apos;t enlighten me very much. Thanks for educating me.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2060943</guid>
		<pubDate>Fri, 28 Mar 2008 00:59:16 -0800</pubDate>
		<dc:creator>adamvasco</dc:creator>
	</item>	<item>
		<title>By: Skorgu</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2061009</link>	
		<description>Great post, thank you!

This kind of specifically-targeted attack (spear-phishing, I love it) is an extension and refinement of the social engineering attacks that *ahem* hackers have been using for literally decades. Attacks like this are substantially harder to mitigate against because they come not in a generic wave of v1agr4 but a coordinated, integrated campaign to seem &apos;real&apos; to the recipient. 

The levels of detail can seem absurd if you&apos;re not knee-deep in it, down to physically watching the movements of individuals in and out of the office so that everyday realities like Bob being on site in Tulsa can be worked into messages. 

Just goes to show that the biggest problem in computer security is between the chair and the keyboard.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2061009</guid>
		<pubDate>Fri, 28 Mar 2008 04:58:36 -0800</pubDate>
		<dc:creator>Skorgu</dc:creator>
	</item>	<item>
		<title>By: Malor</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2061070</link>	
		<description>Holy cow.  I finally got around to reading about this... jesus.  These people are &lt;i&gt;really good&lt;/i&gt;. 

If you&apos;re a pro-resistance movement activist, you need to take some immediate steps to reduce your chance of compromise.  Either don&apos;t ever open attachments, ever...  or else you need to take serious steps to protect yourself.  If you open attachments, ever, you&apos;re eventually gonna get taken by these guys.  This is at a level of sophistication that I haven&apos;t seen before.  

To protect yourself, it would be wisest to read your email and communicate with the outside world with a virtual machine running inside your main OS.  It would be particularly good if you were to use Linux in your virtual machine.   You can do this for free.  The VMWare Server program is entirely free, and will allow you to create and host images.  

By running an oddball OS like this, you make yourself much less vulnerable to common exploits.  You can also improve your resilence even further by running the client in &quot;non-persistent&quot; mode; that is, changes that get made to the disk aren&apos;t saved permanently, and disappear when the virtual machine is shut down.  This will only be convenient if you have an email provider that stores all your mail for you permanently, like GMail.   If you download mail to your local disk, that won&apos;t work right with a non-persistent image.  

You should be able to find a Ubuntu image that you can use, so you don&apos;t have to install the OS onto the virtual machine yourself.   Overall difficulty level would be medium, but, geeze... with the sophistication of these assholes, you &lt;i&gt;really want&lt;/i&gt; the extra layer of protection.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2061070</guid>
		<pubDate>Fri, 28 Mar 2008 06:59:39 -0800</pubDate>
		<dc:creator>Malor</dc:creator>
	</item>	<item>
		<title>By: jadepearl</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2061082</link>	
		<description>Knew someone in the field who could put together a pr0n site completely geared to the target.  Man, nice to know what some of those high end servers were being used to do.  Friend could also target anyone who used Ebay as well including search histories.   Yes, you are indeed being watched; very closely.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2061082</guid>
		<pubDate>Fri, 28 Mar 2008 07:23:52 -0800</pubDate>
		<dc:creator>jadepearl</dc:creator>
	</item>	<item>
		<title>By: eye of newt</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2061150</link>	
		<description>Companies like Norton should send out occasional sting e-mails to its registered users as part of their anti-virus package. It would probably be even more useful than scanning the computer.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2061150</guid>
		<pubDate>Fri, 28 Mar 2008 08:32:20 -0800</pubDate>
		<dc:creator>eye of newt</dc:creator>
	</item>	<item>
		<title>By: Skorgu</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2061234</link>	
		<description>&lt;a href=&quot;http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2061150&quot;&gt;eye of newt&lt;/a&gt;: &quot;&lt;i&gt;Companies like Norton should &lt;strike&gt;send out occasional sting e-mails to its registered users as part of their anti-virus package&lt;/strike&gt; &lt;b&gt;finally get pwned by a black hat and compromise every &apos;protected&apos; system out there&lt;/b&gt;. It would probably be even more useful than scanning the computer.&lt;/i&gt;&quot; 

Paranoia [in computer security] is simply knowing the truth.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2061234</guid>
		<pubDate>Fri, 28 Mar 2008 09:36:53 -0800</pubDate>
		<dc:creator>Skorgu</dc:creator>
	</item>	<item>
		<title>By: homunculus</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2061399</link>	
		<description>&lt;a href=&quot;http://www.nonprofittechblog.org/pro-tibet-non-profit-under-cyber-attack&quot;&gt;Here&apos;s a bit more&lt;/a&gt; about the attacks on &lt;a href=&quot;http://www.studentsforafreetibet.org/index.php&quot;&gt;Students for a Free Tibet&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2061399</guid>
		<pubDate>Fri, 28 Mar 2008 11:30:47 -0800</pubDate>
		<dc:creator>homunculus</dc:creator>
	</item>	<item>
		<title>By: adamvasco</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2071817</link>	
		<description>&lt;a href=&quot;http://www.guardian.co.uk/technology/2008/apr/07/hitechcrime.internet&quot;&gt;Estonia prepares for repeat of cyberattacks on anniversary&lt;/a&gt; similar to those organised by &lt;a href=&quot;http://www.networkworld.com/newsletters/sec/2005/1107sec2.html&quot;&gt;Titan Rain&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2071817</guid>
		<pubDate>Mon, 07 Apr 2008 01:20:15 -0800</pubDate>
		<dc:creator>adamvasco</dc:creator>
	</item>	<item>
		<title>By: homunculus</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2074103</link>	
		<description>&lt;a href=&quot;http://blog.wired.com/27bstroke6/2008/04/feds-cyber-cent.html&quot;&gt;U.S. Has Launched a Cyber Security &apos;Manhattan Project,&apos; Homeland Security Chief Claims&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2074103</guid>
		<pubDate>Tue, 08 Apr 2008 16:31:43 -0800</pubDate>
		<dc:creator>homunculus</dc:creator>
	</item>	<item>
		<title>By: homunculus</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2076888</link>	
		<description>&lt;a href=&quot;http://www.wired.com/politics/security/news/2008/04/chinese_hackers&quot;&gt;Espionage Against Pro-Tibet Groups, Others, Spurred Microsoft Patches&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2076888</guid>
		<pubDate>Thu, 10 Apr 2008 18:42:23 -0800</pubDate>
		<dc:creator>homunculus</dc:creator>
	</item>	<item>
		<title>By: homunculus</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2076891</link>	
		<description>&lt;a href=&quot;http://rconversation.blogs.com/rconversation/2008/04/yahoo-in-china.html&quot;&gt;Yahoo! in China: Lessons for all of us, everywhere.&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2076891</guid>
		<pubDate>Thu, 10 Apr 2008 18:49:29 -0800</pubDate>
		<dc:creator>homunculus</dc:creator>
	</item>	<item>
		<title>By: homunculus</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2077783</link>	
		<description>&lt;a href=&quot;http://www.businessweek.com/print/magazine/content/08_16/b4080032218430.htm&quot;&gt;The New E-spionage Threat: A &lt;i&gt;BusinessWeek&lt;/i&gt; probe of rising attacks on America&apos;s most sensitive computer networks uncovers startling security gaps&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2077783</guid>
		<pubDate>Fri, 11 Apr 2008 16:38:44 -0800</pubDate>
		<dc:creator>homunculus</dc:creator>
	</item>	<item>
		<title>By: homunculus</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2077785</link>	
		<description>&lt;a href=&quot;http://blog.wired.com/27bstroke6/2008/04/researcher-demo.html&quot;&gt;Security Guru Gives Hackers a Taste of Their Own Medicine&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2077785</guid>
		<pubDate>Fri, 11 Apr 2008 16:41:33 -0800</pubDate>
		<dc:creator>homunculus</dc:creator>
	</item>	<item>
		<title>By: homunculus</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2082752</link>	
		<description>&lt;a href=&quot;http://www.boingboing.net/2008/04/16/net-bullies-target-c.html&quot;&gt;&apos;Net bullies target Chinese student participants in pro-Tibet protests&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2082752</guid>
		<pubDate>Wed, 16 Apr 2008 11:39:10 -0800</pubDate>
		<dc:creator>homunculus</dc:creator>
	</item>	<item>
		<title>By: homunculus</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2087625</link>	
		<description>&lt;a href=&quot;http://www.itweb.co.za/sections/internet/2008/0804161030.asp?A=MSG&amp;S=Messaging&amp;O=FPPN&quot;&gt;China movies cause chaos&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2087625</guid>
		<pubDate>Sun, 20 Apr 2008 15:20:52 -0800</pubDate>
		<dc:creator>homunculus</dc:creator>
	</item>	<item>
		<title>By: homunculus</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2090034</link>	
		<description>&lt;a href=&quot;http://www.abovetopsecret.com/forum/thread350381/pg1&quot;&gt;FBI Fears Chinese Hackers Have Back Door Into US Government &amp;amp; Military&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2090034</guid>
		<pubDate>Tue, 22 Apr 2008 20:07:12 -0800</pubDate>
		<dc:creator>homunculus</dc:creator>
	</item>	<item>
		<title>By: blacklite</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2090177</link>	
		<description>&lt;u&gt;wow.&lt;/u&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2090177</guid>
		<pubDate>Tue, 22 Apr 2008 23:08:08 -0800</pubDate>
		<dc:creator>blacklite</dc:creator>
	</item>	<item>
		<title>By: homunculus</title>
		<link>http://www.metafilter.com/70295/Supertargeted-spear-phishing-attacks#2090625</link>	
		<description>More at Slashdot: &lt;a href=&quot;http://hardware.slashdot.org/article.pl?sid=08/04/22/1317212&quot;&gt;FBI Concerned About Implications of Counterfeit Cisco Gear&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2008:site.70295-2090625</guid>
		<pubDate>Wed, 23 Apr 2008 09:33:28 -0800</pubDate>
		<dc:creator>homunculus</dc:creator>
	</item>
	</channel>
</rss>
