<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Dumb Malware Authors Cause More Damage Than Smart Ones</title>
	<atom:link href="http://blogs.mcafee.com/mcafee-labs/2009/06/11/dumb-malware-authors-cause-more-damage-than-smart-ones/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.mcafee.com/mcafee-labs/dumb-malware-authors-cause-more-damage-than-smart-ones</link>
	<description></description>
	<lastBuildDate>Tue, 29 Nov 2011 07:51:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Diego Carvalho</title>
		<link>http://blogs.mcafee.com/mcafee-labs/dumb-malware-authors-cause-more-damage-than-smart-ones/comment-page-1#comment-24257</link>
		<dc:creator>Diego Carvalho</dc:creator>
		<pubDate>Fri, 30 Oct 2009 19:50:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=1795#comment-24257</guid>
		<description>Hey Pedro,

Who is the dumbest, the good (smart) malware coder ou the bad (dumb) one?</description>
		<content:encoded><![CDATA[<p>Hey Pedro,</p>
<p>Who is the dumbest, the good (smart) malware coder ou the bad (dumb) one?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jon</title>
		<link>http://blogs.mcafee.com/mcafee-labs/dumb-malware-authors-cause-more-damage-than-smart-ones/comment-page-1#comment-24247</link>
		<dc:creator>jon</dc:creator>
		<pubDate>Fri, 12 Jun 2009 18:59:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=1795#comment-24247</guid>
		<description>lolo i want to find this pws sample to study it</description>
		<content:encoded><![CDATA[<p>lolo i want to find this pws sample to study it</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: darkmoon</title>
		<link>http://blogs.mcafee.com/mcafee-labs/dumb-malware-authors-cause-more-damage-than-smart-ones/comment-page-1#comment-24246</link>
		<dc:creator>darkmoon</dc:creator>
		<pubDate>Fri, 12 Jun 2009 14:33:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=1795#comment-24246</guid>
		<description>That might be the case, but it also makes tracking a lot easier.   It&#039;s the ones that know how to obfuscate their data that make tracking them challenging, but also frustrating if they&#039;re very good at what they do.

So it kind of plays in both sides.   Yes, that&#039;s bad coding.  While it&#039;s not a feat of genius, I would rather them being dumb than smart and cause some serious damage.</description>
		<content:encoded><![CDATA[<p>That might be the case, but it also makes tracking a lot easier.   It&#8217;s the ones that know how to obfuscate their data that make tracking them challenging, but also frustrating if they&#8217;re very good at what they do.</p>
<p>So it kind of plays in both sides.   Yes, that&#8217;s bad coding.  While it&#8217;s not a feat of genius, I would rather them being dumb than smart and cause some serious damage.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Erik</title>
		<link>http://blogs.mcafee.com/mcafee-labs/dumb-malware-authors-cause-more-damage-than-smart-ones/comment-page-1#comment-24245</link>
		<dc:creator>Erik</dc:creator>
		<pubDate>Fri, 12 Jun 2009 07:48:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=1795#comment-24245</guid>
		<description>Very interesting!

The latest version of NetworkMiner (0.88) can extract SQL credentials directly from a pcap or by sniffing data. Have you tried sniffing the traffic from the PWS-Banker.gen.i with NetworkMiner to extract the SQL credentials used by the worm?

It would probably be a simple thing to do for people at homeâ€¦ Just sniff your network with NetworkMiner while doing your banking, then watch the &#8220;Credentials&#8221; tab in NetworkMiner to see if someone has stolen you credentials and posted them elsewhere.

Network Miner is available here:
http://sourceforge.net/projects/networkminer/</description>
		<content:encoded><![CDATA[<p>Very interesting!</p>
<p>The latest version of NetworkMiner (0.88) can extract SQL credentials directly from a pcap or by sniffing data. Have you tried sniffing the traffic from the PWS-Banker.gen.i with NetworkMiner to extract the SQL credentials used by the worm?</p>
<p>It would probably be a simple thing to do for people at homeâ€¦ Just sniff your network with NetworkMiner while doing your banking, then watch the &ldquo;Credentials&rdquo; tab in NetworkMiner to see if someone has stolen you credentials and posted them elsewhere.</p>
<p>Network Miner is available here:<br />
http://sourceforge.net/projects/networkminer/</p>
]]></content:encoded>
	</item>
</channel>
</rss>

