<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Praetorian Prefect &#187; china</title>
	<atom:link href="http://praetorianprefect.com/archives/tag/china/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Fri, 16 Mar 2012 05:46:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>A twitter &#8220;worm&#8217;s&#8221; brilliant variation</title>
		<link>http://praetorianprefect.com/archives/2009/10/a-twitter-worms-brilliant-variation/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/a-twitter-worms-brilliant-variation/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 21:55:03 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[money mule]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1285</guid>
		<description><![CDATA[A new twitter worm is being reported making the rounds this morning, which is actually an expertly crafted variant of the worm we reported <a href="http://praetorianprefect.com/archives/2009/09/rofl-this-you-on-here-the-latest-twitter-worm/">back on September 24th</a>. The variant has changed the direct message from "ROFL, this you on here?" to "hi. this you on here?". The bad actor in China has also used a new URL, but with the same Twitter login landing page identifiable by its stray HTML brace ">" following the line under 'Sign in to Twitter'. This important difference in wording should allow for a spate of new captured twitter credentials.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/a-twitter-worms-brilliant-variation/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ROFL this you on here? The latest Twitter Worm</title>
		<link>http://praetorianprefect.com/archives/2009/09/rofl-this-you-on-here-the-latest-twitter-worm/</link>
		<comments>http://praetorianprefect.com/archives/2009/09/rofl-this-you-on-here-the-latest-twitter-worm/#comments</comments>
		<pubDate>Thu, 24 Sep 2009 08:25:29 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[captcha]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[money mule]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=484</guid>
		<description><![CDATA[At 2pm on Wednesday 9/24, wide scale reports started showing up on Twitter that a new Twitter worm sends you a direct message with the content “rofl this you on here? http://videos.twitter.secure-logins01.com”.  The link opens a Twitter style log in page (albeit Twitter’s previous version of this page, they have a new one) which, except for being an old version and a stray angle bracket is convincing.  Upon logging in the user’s credentials are stolen, and presumably direct messages are sent to each follower that user has.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/09/rofl-this-you-on-here-the-latest-twitter-worm/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

