<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Digital crime</title>
	<atom:link href="http://digitalcrime.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://digitalcrime.wordpress.com</link>
	<description>Digital crime, forensics and law</description>
	<lastBuildDate>Tue, 05 May 2009 19:09:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='digitalcrime.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Digital crime</title>
		<link>http://digitalcrime.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://digitalcrime.wordpress.com/osd.xml" title="Digital crime" />
	<atom:link rel='hub' href='http://digitalcrime.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Torpig : visit of a botnet</title>
		<link>http://digitalcrime.wordpress.com/2009/05/05/torpig-visit-of-a-botnet/</link>
		<comments>http://digitalcrime.wordpress.com/2009/05/05/torpig-visit-of-a-botnet/#comments</comments>
		<pubDate>Tue, 05 May 2009 19:06:05 +0000</pubDate>
		<dc:creator>Eric Freyssinet</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[Looking forward]]></category>
		<category><![CDATA[Anserin]]></category>
		<category><![CDATA[Botnets]]></category>
		<category><![CDATA[Sinowal]]></category>
		<category><![CDATA[Torpig]]></category>

		<guid isPermaLink="false">http://digitalcrime.wordpress.com/?p=25</guid>
		<description><![CDATA[En français No, I am not going to tell you yet another story about the swine flu. Researchers from the University of Santa Barbara in California published a report on their discoveries after temporarily taking control of the command system of the Torpig botnet. This botnet is made up of victims of a certain piece [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digitalcrime.wordpress.com&amp;blog=7246476&amp;post=25&amp;subd=digitalcrime&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:right;"><a href="http://blog.crimenumerique.fr/2009/05/04/torpig-visite-du-centre-de-commande-dun-botnet/" target="_blank">En français <img class="alignnone size-full wp-image-6" title="francais" src="http://digitalcrime.files.wordpress.com/2009/04/francais.png?w=23&#038;h=15" alt="francais" width="23" height="15" /></a></p>
<div id="attachment_302" class="wp-caption alignleft" style="width: 130px"><a href="http://commons.wikimedia.org/wiki/File:Pig_DSC03978.jpg"><img class="size-full wp-image-302" title="120px-pig_dsc039781" src="http://crimenumerique.files.wordpress.com/2009/05/120px-pig_dsc039781.jpg?w=120&#038;h=90" alt="120px-pig_dsc039781" width="120" height="90" /></a><p class="wp-caption-text">Tor-pig ?</p></div>
<p>No, I am not going to tell you yet another story about the swine flu. Researchers from the University of Santa Barbara in California published a <a href="http://www.cs.ucsb.edu/%7Eseclab/projects/torpig/torpig.pdf" target="_blank">report</a> on their discoveries after temporarily taking control of the command system of the <a href="http://en.wikipedia.org/wiki/Torpig" target="_blank">Torpig botnet</a>.</p>
<p>This botnet is made up of victims of a certain piece of malware (Torpig/Sinowal/Anserin) which targets Microsoft Windows systems. <a href="http://news.bbc.co.uk/1/hi/technology/7701227.stm" target="_blank">According to some previous accounts</a> it was first spotted (says here RSA) in February 2006 or in July 2005 <a href="http://www.secuser.com/alertes/2005/anserin-torpig.htm" target="_blank">according to other sources</a>. Thus, it has now been almost four years since the birth of this trojan and it is still very active!</p>
<p>In concluding their report, the researchers from Santa Barbara <a href="http://blogs.zdnet.com/security/?p=3310" target="_blank">quoted by ZDNet this week</a>, have found that this malicious software can collect millions of passwords, thousands of credit card numbers or bank account credentials in a ten day period. They are maintaining a <a href="http://www.cs.ucsb.edu/~seclab/projects/torpig/index.html" target="_blank">project webpage</a>.</p>
<p>This is a new example of the techniques that are necessary today to efficiently collect information about these botnets : penetrating their command centres. Today, such methods for collecting evidence remain illegal in Europe (and even research conducted in this manner could be questioned).</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/digitalcrime.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/digitalcrime.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/digitalcrime.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/digitalcrime.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/digitalcrime.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/digitalcrime.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/digitalcrime.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/digitalcrime.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/digitalcrime.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/digitalcrime.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/digitalcrime.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/digitalcrime.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/digitalcrime.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/digitalcrime.wordpress.com/25/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digitalcrime.wordpress.com&amp;blog=7246476&amp;post=25&amp;subd=digitalcrime&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://digitalcrime.wordpress.com/2009/05/05/torpig-visit-of-a-botnet/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c49828206dfd6be9fc185eb955cb8460?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Eric Freyssinet</media:title>
		</media:content>

		<media:content url="http://digitalcrime.files.wordpress.com/2009/04/francais.png" medium="image">
			<media:title type="html">francais</media:title>
		</media:content>

		<media:content url="http://crimenumerique.files.wordpress.com/2009/05/120px-pig_dsc039781.jpg" medium="image">
			<media:title type="html">120px-pig_dsc039781</media:title>
		</media:content>
	</item>
		<item>
		<title>A 1.9 million zombie botnet revealed &#8211; need for new methods</title>
		<link>http://digitalcrime.wordpress.com/2009/04/23/a-19-million-zombie-botnet-revealed-need-for-new-methods/</link>
		<comments>http://digitalcrime.wordpress.com/2009/04/23/a-19-million-zombie-botnet-revealed-need-for-new-methods/#comments</comments>
		<pubDate>Thu, 23 Apr 2009 09:03:34 +0000</pubDate>
		<dc:creator>Eric Freyssinet</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Looking forward]]></category>
		<category><![CDATA[Botnets]]></category>
		<category><![CDATA[RSA Conference]]></category>
		<category><![CDATA[Ukraine]]></category>

		<guid isPermaLink="false">http://digitalcrime.wordpress.com/?p=22</guid>
		<description><![CDATA[En français Finjan revealed yesterday the existence of a botnet with over 1.9 million infected machines. The command &#38; control (C&#38;C) server of this network has been located in Ukraine and according to the data collected by the people at Finjan, after infiltrating into this C&#38;C server, their could be a group of six people [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digitalcrime.wordpress.com&amp;blog=7246476&amp;post=22&amp;subd=digitalcrime&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:right;"><a href="http://blog.crimenumerique.fr/2009/04/22/botnet-de-19-million-de-machines/" target="_blank">En français <img class="alignnone size-full wp-image-6" title="francais" src="http://digitalcrime.files.wordpress.com/2009/04/francais.png?w=23&#038;h=15" alt="francais" width="23" height="15" /></a></p>
<p>Finjan <a href="http://www.finjan.com/MCRCblog.aspx?EntryId=2237" target="_blank">revealed yesterday</a> the existence of a botnet with over 1.9 million infected machines.</p>
<p>The command &amp; control (C&amp;C) server of this network has been located in Ukraine and according to the data collected by the people at Finjan, after infiltrating into this C&amp;C server, their could be a group of six people managing it.</p>
<p><a href="http://www.finjan.com/MCRCblog.aspx?EntryId=2237" target="_blank">On Finjan&#8217;s blog</a>, screenshots of the web interface to this C&amp;C are shown. The Trojan horses installed through this botnet have a variety of functionalities: &#8220;read email address and other details from the infected computer; communicate with other computers using HTTP protocol; execute a process; <a href="http://en.wikipedia.org/wiki/Code_injection" target="_blank">inject code</a> into other processes; visit websites without end-users’ consent; register as a background service on the infected computer and a few dozen other commands.&#8221;</p>
<p>Finjan also counted the share of infected machines worldwide: US / 45%, UK / 6%, Canada / 4%, Germany / 4%, <strong>France / 3%</strong>, autres / 38%. That would make a total of 60.000 victim machines in France alone&#8230; It would seem that <a href="http://www.securitypark.co.uk/security_article262978.html" target="_blank">computers infected are running Windows XP</a>.</p>
<p><em><strong>Once again, it is shown here that to fight this type of cybercrime, it is essential to collect evidence by infiltrating into suspects computer systems. And investigative services do not have such legal powers in France. It is even not sure that we would be allowed to present evidence collected in this manner by private entities in order to bring the suspects to court. As was pointed out <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9131909" target="_blank">by Joe Stewart at the RSA conference this week</a> &#8211; San Francisco &#8211; it is high time that methods used to fight against this new type of criminal activities online are adapted to the challenge, and not only on the side of the industry but also in partnership with law enforcement and the justice to put an end to the activities of such criminal groups.</strong></em></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/digitalcrime.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/digitalcrime.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/digitalcrime.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/digitalcrime.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/digitalcrime.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/digitalcrime.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/digitalcrime.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/digitalcrime.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/digitalcrime.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/digitalcrime.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/digitalcrime.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/digitalcrime.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/digitalcrime.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/digitalcrime.wordpress.com/22/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digitalcrime.wordpress.com&amp;blog=7246476&amp;post=22&amp;subd=digitalcrime&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://digitalcrime.wordpress.com/2009/04/23/a-19-million-zombie-botnet-revealed-need-for-new-methods/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c49828206dfd6be9fc185eb955cb8460?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Eric Freyssinet</media:title>
		</media:content>

		<media:content url="http://digitalcrime.files.wordpress.com/2009/04/francais.png" medium="image">
			<media:title type="html">francais</media:title>
		</media:content>
	</item>
		<item>
		<title>11 month sentence for a juvenile cracker</title>
		<link>http://digitalcrime.wordpress.com/2009/04/22/11-month-sentence-for-a-juvenile-cracker/</link>
		<comments>http://digitalcrime.wordpress.com/2009/04/22/11-month-sentence-for-a-juvenile-cracker/#comments</comments>
		<pubDate>Wed, 22 Apr 2009 08:46:40 +0000</pubDate>
		<dc:creator>Eric Freyssinet</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Cracker]]></category>
		<category><![CDATA[DDos]]></category>
		<category><![CDATA[DShocker]]></category>
		<category><![CDATA[Hacker]]></category>
		<category><![CDATA[Juvenile cracker]]></category>
		<category><![CDATA[Sentence]]></category>

		<guid isPermaLink="false">http://digitalcrime.wordpress.com/?p=18</guid>
		<description><![CDATA[En français Aged 17 today, a young boy from Worcester, in the Boston area (Massachusetts, USA), was sentenced last week to 11 months of emprisonment in a juvenile detention center. He was found guilty of hacking into corporate computer systems, making hoax 911 calls which led to SWAT team responses and using stolen credit card [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digitalcrime.wordpress.com&amp;blog=7246476&amp;post=18&amp;subd=digitalcrime&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:right;"><a href="http://blog.crimenumerique.fr/2009/04/22/condamnation-dun-cracker-de-17-ans-a-11-mois-de-prison-aux-usa/" target="_blank">En français <img class="alignnone size-full wp-image-6" title="francais" src="http://digitalcrime.files.wordpress.com/2009/04/francais.png?w=23&#038;h=15" alt="francais" width="23" height="15" /></a></p>
<div id="attachment_281" class="wp-caption alignleft" style="width: 138px"><img class="size-thumbnail wp-image-281" title="worcester" src="http://crimenumerique.files.wordpress.com/2009/04/worcester.png?w=128&#038;h=80" alt="Worcester" width="128" height="80" /><p class="wp-caption-text">Worcester</p></div>
<p>Aged 17 today, a young boy from Worcester, in the Boston area (Massachusetts, USA), <a href="http://news.bostonherald.com/news/regional/view/2009_04_20_Teen_hacker_sentenced_to_11_months/srvc=home&amp;amp;position=recent" target="_blank">was sentenced</a> last week to 11 months of emprisonment in a juvenile detention center.</p>
<p>He was found guilty of hacking into corporate computer systems, making hoax 911 calls which led to SWAT team responses and using stolen credit card numbers to buy goods. All these offences were committed between November 2005 and May 2008.</p>
<p>The suspect, known under the screenname of  <a href="http://www.theregister.co.uk/2008/11/19/dshocker_pleads_guilty/" target="_blank">DShocker</a>, decided to plead guilty and was originally facing a maximum sentence of 10 years in prison. In France, although being a minor he might not have faced imprisonment, for similar actions the maximum penalty would be of 5 years in prison and a 75 000 € fine (<a href="http://www.legifrance.gouv.fr/affichCode.do?idSectionTA=LEGISCTA000006149839&amp;cidTexte=LEGITEXT000006070719&amp;dateTexte=20090422" target="_blank">articles 323-1 à 323-7 of the penal code</a>).</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/digitalcrime.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/digitalcrime.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/digitalcrime.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/digitalcrime.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/digitalcrime.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/digitalcrime.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/digitalcrime.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/digitalcrime.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/digitalcrime.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/digitalcrime.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/digitalcrime.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/digitalcrime.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/digitalcrime.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/digitalcrime.wordpress.com/18/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digitalcrime.wordpress.com&amp;blog=7246476&amp;post=18&amp;subd=digitalcrime&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://digitalcrime.wordpress.com/2009/04/22/11-month-sentence-for-a-juvenile-cracker/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c49828206dfd6be9fc185eb955cb8460?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Eric Freyssinet</media:title>
		</media:content>

		<media:content url="http://digitalcrime.files.wordpress.com/2009/04/francais.png" medium="image">
			<media:title type="html">francais</media:title>
		</media:content>

		<media:content url="http://crimenumerique.files.wordpress.com/2009/04/worcester.png?w=128" medium="image">
			<media:title type="html">worcester</media:title>
		</media:content>
	</item>
		<item>
		<title>Covert Internet investigations : first cases</title>
		<link>http://digitalcrime.wordpress.com/2009/04/17/covert-internet-investigations-first-cases/</link>
		<comments>http://digitalcrime.wordpress.com/2009/04/17/covert-internet-investigations-first-cases/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 21:37:25 +0000</pubDate>
		<dc:creator>Eric Freyssinet</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Covert Internet investigations]]></category>

		<guid isPermaLink="false">http://digitalcrime.wordpress.com/?p=15</guid>
		<description><![CDATA[En français There has been many reports in the news today about the first successful attempts to use the new cyberpatrolling powers which were authorized last week by the French legislation. The Bobigny prosecutor chose to communicate around a specific case that was brought forward by the specially trained gendarmes of the cybercrime division of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digitalcrime.wordpress.com&amp;blog=7246476&amp;post=15&amp;subd=digitalcrime&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:right;"><a href="http://blog.crimenumerique.fr/2009/04/17/cyberpatrouilles-premiers-dossiers/" target="_blank">En français <img class="alignnone size-full wp-image-6" title="francais" src="http://digitalcrime.files.wordpress.com/2009/04/francais.png?w=23&#038;h=15" alt="francais" width="23" height="15" /></a></p>
<div id="attachment_275" class="wp-caption alignright" style="width: 210px"><img class="size-full wp-image-275" title="im" src="http://crimenumerique.files.wordpress.com/2009/04/im.png?w=200&#038;h=132" alt="Instant messengers: where many predators lure their victims" width="200" height="132" /><p class="wp-caption-text">Instant messengers: where many predators lure their victims</p></div>
<p>There has been many reports in the news today about the first successful attempts to use the new <em>cyberpatrolling</em> powers which were authorized last week by the French legislation. The Bobigny prosecutor chose to communicate around a specific case that was brought forward by the specially trained gendarmes of the cybercrime division of the STRJD in Rosny sous Bois.</p>
<p>French readers can visit this article on 01Net: <a href="http://www.01net.com/editorial/501218/la-gendarmerie-arrete-un-pedophile-en-sinfiltrant-sur-un-forum/" target="_blank">La gendarmerie arrête un pédophile en s&#8217;infiltrant sur un forum</a>.</p>
<p><a href="http://digitalcrime.wordpress.com/2009/04/05/covert-internet-investigations/" target="_self">As I was explaining</a> a few days ago, this is not about undercover operations but more properly covert Internet investigations.</p>
<p>Some might wonder about the necessity to communicate this much around this specific case. Actually, it is not about exposing police methods, but about sending a clear message to online predators of children in chatrooms, forums, etc. that they can no longer wander around unpunished, to reinstate what we call in French: the <em>peur du gendarme</em> (fear of the <em>gendarme</em>).</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/digitalcrime.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/digitalcrime.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/digitalcrime.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/digitalcrime.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/digitalcrime.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/digitalcrime.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/digitalcrime.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/digitalcrime.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/digitalcrime.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/digitalcrime.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/digitalcrime.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/digitalcrime.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/digitalcrime.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/digitalcrime.wordpress.com/15/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digitalcrime.wordpress.com&amp;blog=7246476&amp;post=15&amp;subd=digitalcrime&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://digitalcrime.wordpress.com/2009/04/17/covert-internet-investigations-first-cases/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c49828206dfd6be9fc185eb955cb8460?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Eric Freyssinet</media:title>
		</media:content>

		<media:content url="http://digitalcrime.files.wordpress.com/2009/04/francais.png" medium="image">
			<media:title type="html">francais</media:title>
		</media:content>

		<media:content url="http://crimenumerique.files.wordpress.com/2009/04/im.png" medium="image">
			<media:title type="html">im</media:title>
		</media:content>
	</item>
		<item>
		<title>Symantec&#8217;s global Internet security threat report on trends for 2008</title>
		<link>http://digitalcrime.wordpress.com/2009/04/16/symantec-report/</link>
		<comments>http://digitalcrime.wordpress.com/2009/04/16/symantec-report/#comments</comments>
		<pubDate>Thu, 16 Apr 2009 09:24:30 +0000</pubDate>
		<dc:creator>Eric Freyssinet</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Information security]]></category>
		<category><![CDATA[Symantec internet threat report]]></category>

		<guid isPermaLink="false">http://digitalcrime.wordpress.com/?p=10</guid>
		<description><![CDATA[En français Symantec published this week its &#8220;Global Internet security threat report&#8221; on trends for 2008. The full document can be downloaded from the website of the company. This report is driven from data collected by Symantec, through its customers and its security teams. Although such reports are always not to be fully taken for [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digitalcrime.wordpress.com&amp;blog=7246476&amp;post=10&amp;subd=digitalcrime&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:right;"><a href="http://blog.crimenumerique.fr/2009/04/15/rapport-symantec-sur-les-menaces-internet-davril-2009/" target="_blank">En français <img class="alignnone size-full wp-image-6" title="francais" src="http://digitalcrime.files.wordpress.com/2009/04/francais.png?w=23&#038;h=15" alt="francais" width="23" height="15" /></a></p>
<div id="attachment_11" class="wp-caption alignright" style="width: 310px"><img class="size-full wp-image-11" title="symantec-xss" src="http://digitalcrime.files.wordpress.com/2009/04/symantec-xss.png?w=300&#038;h=197" alt="An XSS flaw in Symantec's website" width="300" height="197" /><p class="wp-caption-text">A temporary XSS vulnerability in Symantec&#39;s website</p></div>
<p>Symantec published this week its &#8220;Global Internet security threat report&#8221; on trends for 2008. The full document can be downloaded <a href="http://eval.symantec.com/mktginfo/enterprise/white_papers/b-whitepaper_internet_security_threat_report_xiv_04-2009.en-us.pdf" target="_blank">from the website of the company</a>.</p>
<p>This report is driven from data collected by Symantec, through its customers and its security teams. Although such reports are always not to be fully taken for granted, because of the obvious bias, they contain valuable information for the reader. Here are a few of the ideas that are worth noting:</p>
<ul>
<li>Websites are at the top of the list of media used for the distribution of malware ; the implementation of those malware is automated on websites using similar platforms, code or vulnerabilities, such as XSS ; very often those vulnerabilities are classified with a medium risk and are not subject to rapid updates ;</li>
<li>On the contrary, the report underlines that a major vulnerability was exploited to distribute the most active worm today &#8211; Conficker. On this topic, you can read an <a href="http://sid.rstack.org/blog/index.php/337-aveu-de-faiblesse" target="_blank">interesting blog message by Sid</a>.</li>
<li>Motivations of cybercrooks are still mostly financial. Payloads distributed through malware and <a href="http://en.wikipedia.org/wiki/Phishing" target="_blank">phishing</a> scams are predominantly targeted at personal data and payment systems.</li>
<li>The report confirms the existence of a grey market for those data, in particular credit card numbers, which represent 32% of the market observed by Symantec with prices ranging from a couple cents to $30, before banking credentials or email account credentials. Credit card data are obviously easier to intercept and reuse.</li>
<li>Malware and phishing kits have rapidly developed in 2008, leading to a huge increase in the number of online threats discovered by Symantec (+165%).</li>
<li>The report concludes on the success of joint work such as the <a href="http://www.confickerworkinggroup.org/" target="_blank">Conficker cabal</a>. As I have previously written, it can be regretted that government authorities are not officially associated to these initiatives.</li>
</ul>
<p>As other sources of information, this report presents evidence of the growing number of organised crime groups behind online threats.</p>
<p>As a conclusion, it was funny <a href="//www.theregister.co.uk/2009/04/15/symantec_xss_bugs/" target="_blank">to note yesterday</a> that an XSS vulnerability was discovered on Symantec&#8217;s website, but now seems to have been patched.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/digitalcrime.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/digitalcrime.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/digitalcrime.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/digitalcrime.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/digitalcrime.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/digitalcrime.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/digitalcrime.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/digitalcrime.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/digitalcrime.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/digitalcrime.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/digitalcrime.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/digitalcrime.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/digitalcrime.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/digitalcrime.wordpress.com/10/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digitalcrime.wordpress.com&amp;blog=7246476&amp;post=10&amp;subd=digitalcrime&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://digitalcrime.wordpress.com/2009/04/16/symantec-report/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c49828206dfd6be9fc185eb955cb8460?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Eric Freyssinet</media:title>
		</media:content>

		<media:content url="http://digitalcrime.files.wordpress.com/2009/04/francais.png" medium="image">
			<media:title type="html">francais</media:title>
		</media:content>

		<media:content url="http://digitalcrime.files.wordpress.com/2009/04/symantec-xss.png" medium="image">
			<media:title type="html">symantec-xss</media:title>
		</media:content>
	</item>
		<item>
		<title>Covert Internet investigations start in France</title>
		<link>http://digitalcrime.wordpress.com/2009/04/05/covert-internet-investigations/</link>
		<comments>http://digitalcrime.wordpress.com/2009/04/05/covert-internet-investigations/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 20:39:18 +0000</pubDate>
		<dc:creator>Eric Freyssinet</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Covert Internet investigations]]></category>

		<guid isPermaLink="false">http://digitalcrime.wordpress.com/?p=5</guid>
		<description><![CDATA[En français Legal background The law on the prevention of crime of March 2007 introduced in the French legislation the possibility for specially trained law enforcement officials to get in contact online with people suspected of committing offences such as the traficking of human beings, proxenitism or crimes against children on the Internet, and thus [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digitalcrime.wordpress.com&amp;blog=7246476&amp;post=5&amp;subd=digitalcrime&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:right;"><a href="http://blog.crimenumerique.fr/2009/04/05/cyber-patrouilles/" target="_blank">En français <img class="alignnone size-full wp-image-6" title="francais" src="http://digitalcrime.files.wordpress.com/2009/04/francais.png?w=23&#038;h=15" alt="francais" width="23" height="15" /></a></p>
<h2 style="text-align:left;">Legal background</h2>
<p>The <a href="http://www.legifrance.gouv.fr/affichTexte.do?cidTexte=JORFTEXT000000615568&amp;dateTexte=" target="_blank">law on the prevention of crime of March 2007</a> introduced in the French legislation the possibility for specially trained law enforcement officials to get in contact online with people suspected of committing offences such as the traficking of human beings, proxenitism or crimes against children on the Internet, and thus collect evidence of those infractions. Provocation of the offences is not allowed.</p>
<p>This is covered by articles <a href="http://legifrance.gouv.fr/affichCodeArticle.do?cidTexte=LEGITEXT000006071154&amp;idArticle=LEGIARTI000006577667&amp;dateTexte=20090326&amp;categorieLien=cid" target="_blank">706-35-1</a> and <a href="http://legifrance.gouv.fr/affichCodeArticle.do?idArticle=LEGIARTI000006577702&amp;cidTexte=LEGITEXT000006071154&amp;dateTexte=20090405" target="_blank">706-47-3</a> of the penal procedural code.</p>
<p>A decree, published in May 2007, describes in new articles <a href="http://legifrance.gouv.fr/affichCode.do?idArticle=LEGIARTI000006514949&amp;idSectionTA=LEGISCTA000006137361&amp;cidTexte=LEGITEXT000006071154&amp;dateTexte=20090405" target="_blank">D47-8, D47-9</a> and <a href="http://legifrance.gouv.fr/affichCodeArticle.do?idArticle=LEGIARTI000006514954&amp;cidTexte=LEGITEXT000006071154&amp;dateTexte=20090405" target="_blank">D47-11</a> of the penal procedural code the strict rules that &#8220;cyber-patrols&#8221; must follow when exchanging illegal contenton the Internet.</p>
<p>A recent legal instrument the <a href="http://crimenumerique.files.wordpress.com/2009/04/arrete-cyberpatrouilleurs.pdf"><em>arrêté</em> March 30rd 2009</a>, published last week, decides which specific units can host cyber-patrols and how the &#8220;cyber-patrollers&#8221; are trained and appointed. This same text defines the mission of the CNAIP, the French national centre in charge of the national child sexual abuse database, which is hosted by the Gendarmerie nationale in Rosny-sous-Bois. This unit is in charge of receiving all illegal content collected during criminal investigations of child abuse and fulfills the tedious task of examining all those images and videos, in relation with international counterparts, in order to try and identify perpetrators and victims.</p>
<h2>What will cyber-patrollers do?</h2>
<p>These new types of online investigators will connect to forums, exchange groups, discussion groups where suspected pedophiles go and chat with them, using a pseudonym or avatar. They will be in a better position to collect evidence of those offences, in particular the new child-grooming offence which was voted in 2007: making proposals of sexual nature to a minor under 15 years of age. This will hopefully allow to detect predators before they can meet with children and help and identify more of those people who exchange in more discreet forums pictures and movies of children being abused.</p>
<p>A French NGO is currently showing on television a series of prevention messages, which give advice on how to protect children from the risks of the Internet. This can be <a href="http://www.actioninnocence.org/france/webcast.asp" target="_blank">seen here</a>, and you can see one of those video-clips below:</p>
<p><span style="display:block;width:425px;margin:0 auto;"> <embed src='http://widgets.vodpod.com/w/video_embed/Groupvideo.2322791' type='application/x-shockwave-flash' AllowScriptAccess='sameDomain' pluginspage='http://www.macromedia.com/go/getflashplayer' wmode='transparent' flashvars='file={279f0fa4-0b07-472f-b2a8-a1b1138ee451}/{6921b485-a19c-4db2-9b40-75bb070b33a0}/messageries_VP6_1Mbps_Strea.flv&amp;type=video&amp;volume=100&amp;streamer=rtmp://fl.interoute.com/streamrt&amp;image=http://www.actioninnocence.org/img/webcast/messageries.jpg' width='425' height='350' /></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/digitalcrime.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/digitalcrime.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/digitalcrime.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/digitalcrime.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/digitalcrime.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/digitalcrime.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/digitalcrime.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/digitalcrime.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/digitalcrime.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/digitalcrime.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/digitalcrime.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/digitalcrime.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/digitalcrime.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/digitalcrime.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=digitalcrime.wordpress.com&amp;blog=7246476&amp;post=5&amp;subd=digitalcrime&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://digitalcrime.wordpress.com/2009/04/05/covert-internet-investigations/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c49828206dfd6be9fc185eb955cb8460?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Eric Freyssinet</media:title>
		</media:content>

		<media:content url="http://digitalcrime.files.wordpress.com/2009/04/francais.png" medium="image">
			<media:title type="html">francais</media:title>
		</media:content>
	</item>
	</channel>
</rss>
