<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Fake CNN Custom Alert</title>
	<atom:link href="http://blog.didierstevens.com/2008/08/08/fake-cnn-custom-alert/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2008/08/08/fake-cnn-custom-alert/</link>
	<description>(blog 'DidierStevens)</description>
	<pubDate>Wed, 07 Jan 2009 17:59:26 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Charlene</title>
		<link>http://blog.didierstevens.com/2008/08/08/fake-cnn-custom-alert/#comment-33335</link>
		<dc:creator>Charlene</dc:creator>
		<pubDate>Sat, 16 Aug 2008 02:16:55 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=537#comment-33335</guid>
		<description>Fortunately I didn't fall for it, but I did think the email was unusual since I had never gotten one before from CNN.  That fact may have saved me - I only read the headlines and deleted it.</description>
		<content:encoded><![CDATA[<p>Fortunately I didn&#8217;t fall for it, but I did think the email was unusual since I had never gotten one before from CNN.  That fact may have saved me - I only read the headlines and deleted it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gregory D. Kramer</title>
		<link>http://blog.didierstevens.com/2008/08/08/fake-cnn-custom-alert/#comment-33321</link>
		<dc:creator>Gregory D. Kramer</dc:creator>
		<pubDate>Tue, 12 Aug 2008 17:51:25 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=537#comment-33321</guid>
		<description>It sure would be nice if CNN's web security people would go after these people. They are using their logo and faking their emails.</description>
		<content:encoded><![CDATA[<p>It sure would be nice if CNN&#8217;s web security people would go after these people. They are using their logo and faking their emails.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2008/08/08/fake-cnn-custom-alert/#comment-33308</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Sun, 10 Aug 2008 22:10:33 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=537#comment-33308</guid>
		<description>Thanks for the details!</description>
		<content:encoded><![CDATA[<p>Thanks for the details!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PBCliberal</title>
		<link>http://blog.didierstevens.com/2008/08/08/fake-cnn-custom-alert/#comment-33307</link>
		<dc:creator>PBCliberal</dc:creator>
		<pubDate>Sun, 10 Aug 2008 22:08:24 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=537#comment-33307</guid>
		<description>&lt;b&gt;Didier writes:&lt;/b&gt; &lt;i&gt;your users got a mail in their inbox (not in their SPAM folder)&lt;/i&gt;

Yes, because &lt;i&gt;it came in that way&lt;/i&gt; which is the last thing you'd expect SPAM to say first thing out of the box. To be more precise than my earlier post, we &lt;i&gt;used&lt;/i&gt; to do a subject: header rewrite adding [SPAM] to suspected spam, but we stopped that a few days ago. So when the CNN Alerts: style spam (that we'd previously eliminated with its unique own filter rule) started showing up with what appeared to be a header rewrite that was no longer enabled, it drove me crazy for a few minutes because I first blamed our mail server (which is Ability Mail Server*), but then realized that our spam header rewrite was typographically different than what we were seeing on the pre-labeled CNN spam.

*Full Disclosure: I have no interest in Code-Crafters Ability Mail Server other than as a satisfied long-term user.</description>
		<content:encoded><![CDATA[<p><b>Didier writes:</b> <i>your users got a mail in their inbox (not in their SPAM folder)</i></p>
<p>Yes, because <i>it came in that way</i> which is the last thing you&#8217;d expect SPAM to say first thing out of the box. To be more precise than my earlier post, we <i>used</i> to do a subject: header rewrite adding [SPAM] to suspected spam, but we stopped that a few days ago. So when the CNN Alerts: style spam (that we&#8217;d previously eliminated with its unique own filter rule) started showing up with what appeared to be a header rewrite that was no longer enabled, it drove me crazy for a few minutes because I first blamed our mail server (which is Ability Mail Server*), but then realized that our spam header rewrite was typographically different than what we were seeing on the pre-labeled CNN spam.</p>
<p>*Full Disclosure: I have no interest in Code-Crafters Ability Mail Server other than as a satisfied long-term user.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sampling a Malicious Site &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2008/08/08/fake-cnn-custom-alert/#comment-33304</link>
		<dc:creator>Sampling a Malicious Site &#171; Didier Stevens</dc:creator>
		<pubDate>Sun, 10 Aug 2008 21:59:39 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=537#comment-33304</guid>
		<description>[...] Sampling a Malicious&#160;Site Filed under: Malware, My Software &#8212; Didier Stevens @ 21:59   Fake CNN alerts galore! [...]</description>
		<content:encoded><![CDATA[<p>[...] Sampling a Malicious&nbsp;Site Filed under: Malware, My Software &#8212; Didier Stevens @ 21:59   Fake CNN alerts galore! [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2008/08/08/fake-cnn-custom-alert/#comment-33303</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Sun, 10 Aug 2008 20:36:38 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=537#comment-33303</guid>
		<description>Are you running on Windows XP, and are you using an administrative account? If so, it's better to do some additional checks. Do you know which version of the McAfee DAT files you used to scan? According to Virustotal the 5357 DAT files didn't detect the Fake CNN Alert malware.

The best thing you can do is scan your machine off-line: boot from a live CD and do a a malware scan of your disks. F-secure just released a new ISO file to do this. And to be really safe, don't download and burn this ISO on your suspect machine, but use another one.

Look for the F_secure ISO here, and also update the virus database:
http://www.f-secure.com/linux-weblog/2008/06/19/f-secure-rescue-cd-300-released/</description>
		<content:encoded><![CDATA[<p>Are you running on Windows XP, and are you using an administrative account? If so, it&#8217;s better to do some additional checks. Do you know which version of the McAfee DAT files you used to scan? According to Virustotal the 5357 DAT files didn&#8217;t detect the Fake CNN Alert malware.</p>
<p>The best thing you can do is scan your machine off-line: boot from a live CD and do a a malware scan of your disks. F-secure just released a new ISO file to do this. And to be really safe, don&#8217;t download and burn this ISO on your suspect machine, but use another one.</p>
<p>Look for the F_secure ISO here, and also update the virus database:<br />
<a href="http://www.f-secure.com/linux-weblog/2008/06/19/f-secure-rescue-cd-300-released/" rel="nofollow">http://www.f-secure.com/linux-weblog/2008/06/19/f-secure-rescue-cd-300-released/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Racetimer</title>
		<link>http://blog.didierstevens.com/2008/08/08/fake-cnn-custom-alert/#comment-33302</link>
		<dc:creator>Racetimer</dc:creator>
		<pubDate>Sun, 10 Aug 2008 20:22:13 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=537#comment-33302</guid>
		<description>I received this e-mail yesterday evening and thought it was iffy - BUT - it said Bank of America just announced bankruptcy and as I bank there I stupidly clicked on the link for the story.

It came back with "you must upload the newest version of ?? player" to see video"

I KNEW there was a problem at that point but it would not allow me to exit - kept coming back with the same window.

Bottom line, in trying to get out of the loop I hit the "allow" button by mistake.

I immediately did a cntrl/alt/delete and closed browser. 

I was/am running McAfee - it never said it stopped anything.

I ran a complete McAfee scan, found nothing.
I then ran Ad-Aware - only found normal cookies.
Then ran SuperAntiSpyware - only found normal cookies.
Just finishing running Trend Micro - seems to have found nothing.

Did I get a virus/trojan/etc. in the short time before I closed the browser and none of the virus programs I have run found it??

Any suggestions of other virus program(s) I should run as well?

How do I know if I got infected?

Thanks for the help.</description>
		<content:encoded><![CDATA[<p>I received this e-mail yesterday evening and thought it was iffy - BUT - it said Bank of America just announced bankruptcy and as I bank there I stupidly clicked on the link for the story.</p>
<p>It came back with &#8220;you must upload the newest version of ?? player&#8221; to see video&#8221;</p>
<p>I KNEW there was a problem at that point but it would not allow me to exit - kept coming back with the same window.</p>
<p>Bottom line, in trying to get out of the loop I hit the &#8220;allow&#8221; button by mistake.</p>
<p>I immediately did a cntrl/alt/delete and closed browser. </p>
<p>I was/am running McAfee - it never said it stopped anything.</p>
<p>I ran a complete McAfee scan, found nothing.<br />
I then ran Ad-Aware - only found normal cookies.<br />
Then ran SuperAntiSpyware - only found normal cookies.<br />
Just finishing running Trend Micro - seems to have found nothing.</p>
<p>Did I get a virus/trojan/etc. in the short time before I closed the browser and none of the virus programs I have run found it??</p>
<p>Any suggestions of other virus program(s) I should run as well?</p>
<p>How do I know if I got infected?</p>
<p>Thanks for the help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2008/08/08/fake-cnn-custom-alert/#comment-33301</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Sun, 10 Aug 2008 20:20:48 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=537#comment-33301</guid>
		<description>If I understand you correctly, your users got a mail in their inbox (not in their SPAM folder), with subject "[Spam] - CNN Alerts: My Custom Alert"?

That's interesting, I've speculated (privately) about the blending of SPAM and malware e-mails.

Thanks for sharing this.</description>
		<content:encoded><![CDATA[<p>If I understand you correctly, your users got a mail in their inbox (not in their SPAM folder), with subject &#8220;[Spam] - CNN Alerts: My Custom Alert&#8221;?</p>
<p>That&#8217;s interesting, I&#8217;ve speculated (privately) about the blending of SPAM and malware e-mails.</p>
<p>Thanks for sharing this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PBCliberal</title>
		<link>http://blog.didierstevens.com/2008/08/08/fake-cnn-custom-alert/#comment-33300</link>
		<dc:creator>PBCliberal</dc:creator>
		<pubDate>Sun, 10 Aug 2008 20:02:41 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=537#comment-33300</guid>
		<description>The latest twist? An alternate header that reads:

[Spam] - CNN Alerts: My Custom Alert

Since we do a similar header modification around here to flag spam, but were handling this malware differently, it caused some serious confusion and head scratching, which was just what the bastards intended. 

These guys are Machiavellian. Its as clever as balancing a bucket of water above a door jamb in a way the intended victim can see it, but then when he carefully removes it and proudly takes it to the sink to pour it out, he discovers the real gotcha was that the undersink trap has been removed so the water pours all over his feet and the floor.</description>
		<content:encoded><![CDATA[<p>The latest twist? An alternate header that reads:</p>
<p>[Spam] - CNN Alerts: My Custom Alert</p>
<p>Since we do a similar header modification around here to flag spam, but were handling this malware differently, it caused some serious confusion and head scratching, which was just what the bastards intended. </p>
<p>These guys are Machiavellian. Its as clever as balancing a bucket of water above a door jamb in a way the intended victim can see it, but then when he carefully removes it and proudly takes it to the sink to pour it out, he discovers the real gotcha was that the undersink trap has been removed so the water pours all over his feet and the floor.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: evelien</title>
		<link>http://blog.didierstevens.com/2008/08/08/fake-cnn-custom-alert/#comment-33299</link>
		<dc:creator>evelien</dc:creator>
		<pubDate>Sun, 10 Aug 2008 08:05:17 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=537#comment-33299</guid>
		<description>hey.... 
i ran across this twice on one morning...... I'm from the netherlands, and i don't even watch cnn !!!!!! lucily I didn't fell for it and i've developed a habit that everytime i see something like this in my mailbox, i look it up on the internet before i open it..... that's how this website saved me a whole lot of trouble, thanx very much !!!!!!!!</description>
		<content:encoded><![CDATA[<p>hey&#8230;.<br />
i ran across this twice on one morning&#8230;&#8230; I&#8217;m from the netherlands, and i don&#8217;t even watch cnn !!!!!! lucily I didn&#8217;t fell for it and i&#8217;ve developed a habit that everytime i see something like this in my mailbox, i look it up on the internet before i open it&#8230;.. that&#8217;s how this website saved me a whole lot of trouble, thanx very much !!!!!!!!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
