<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Visa issues security alert</title>
	<atom:link href="http://www.merchantequip.com/merchant-account-blog/641/visa-issues-security-alert/feed" rel="self" type="application/rss+xml" />
	<link>http://www.merchantequip.com/merchant-account-blog/641/visa-issues-security-alert</link>
	<description>Merchant Accounts, Ecommerce, Processing Equipment</description>
	<lastBuildDate>Fri, 23 Sep 2011 22:04:18 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: jestep</title>
		<link>http://www.merchantequip.com/merchant-account-blog/641/visa-issues-security-alert/comment-page-1#comment-20026</link>
		<dc:creator>jestep</dc:creator>
		<pubDate>Wed, 20 May 2009 15:00:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.merchantaccountblog.com/?p=641#comment-20026</guid>
		<description>Visa posted this on their website finally. 3 months after they issued the alert to their partners.</description>
		<content:encoded><![CDATA[<p>Visa posted this on their website finally. 3 months after they issued the alert to their partners.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wenningstedt auf Sylt</title>
		<link>http://www.merchantequip.com/merchant-account-blog/641/visa-issues-security-alert/comment-page-1#comment-19708</link>
		<dc:creator>Wenningstedt auf Sylt</dc:creator>
		<pubDate>Tue, 24 Feb 2009 02:34:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.merchantaccountblog.com/?p=641#comment-19708</guid>
		<description>How are we going to check if the blockers of this IP addresses were doing the right thing in blacklisting? Its not rare that errors occur. I pity those addresses that were included even if they were not in any way doing illegal stuff.</description>
		<content:encoded><![CDATA[<p>How are we going to check if the blockers of this IP addresses were doing the right thing in blacklisting? Its not rare that errors occur. I pity those addresses that were included even if they were not in any way doing illegal stuff.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.merchantequip.com/merchant-account-blog/641/visa-issues-security-alert/comment-page-1#comment-19695</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Fri, 20 Feb 2009 05:40:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.merchantaccountblog.com/?p=641#comment-19695</guid>
		<description>Big companies has dedicated technical teams who work hard to make the system totally secure. But still these type of instances occure. I don&#039;t know when these type of incidents will stop happenning.</description>
		<content:encoded><![CDATA[<p>Big companies has dedicated technical teams who work hard to make the system totally secure. But still these type of instances occure. I don&#8217;t know when these type of incidents will stop happenning.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jestep</title>
		<link>http://www.merchantequip.com/merchant-account-blog/641/visa-issues-security-alert/comment-page-1#comment-19644</link>
		<dc:creator>jestep</dc:creator>
		<pubDate>Wed, 04 Feb 2009 23:01:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.merchantaccountblog.com/?p=641#comment-19644</guid>
		<description>I think one of the major problems that I&#039;ve read about is that malicious software can be installed in unpartitioned spaces on a hard drive. It&#039;s even possible to make the partition invisible to the current operating system. As far as this goes, make sure you don&#039;t ever leave unpartitioned space on a drive.

The only way to scan for these would be to use a process monitor and then calculate the hash of a running process that matches the listed filename. You can also search for the filename but I have a suspicion that some of these may be generated on the fly, in which case you could only look for a running process. You would need to manually do this on every computer on a network. Ideally, you don&#039;t ever let an intruder in to install these in the first place, because it&#039;s going to be difficult to detect them.

If you need a good process monitor, &lt;a href=&quot;http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx&quot; rel=&quot;nofollow&quot;&gt;here&#039;s one from Microsoft&lt;/a&gt;. This will show you everything that is currently running through the operating system.</description>
		<content:encoded><![CDATA[<p>I think one of the major problems that I&#8217;ve read about is that malicious software can be installed in unpartitioned spaces on a hard drive. It&#8217;s even possible to make the partition invisible to the current operating system. As far as this goes, make sure you don&#8217;t ever leave unpartitioned space on a drive.</p>
<p>The only way to scan for these would be to use a process monitor and then calculate the hash of a running process that matches the listed filename. You can also search for the filename but I have a suspicion that some of these may be generated on the fly, in which case you could only look for a running process. You would need to manually do this on every computer on a network. Ideally, you don&#8217;t ever let an intruder in to install these in the first place, because it&#8217;s going to be difficult to detect them.</p>
<p>If you need a good process monitor, <a href="http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx" rel="nofollow">here&#8217;s one from Microsoft</a>. This will show you everything that is currently running through the operating system.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tod</title>
		<link>http://www.merchantequip.com/merchant-account-blog/641/visa-issues-security-alert/comment-page-1#comment-19643</link>
		<dc:creator>Tod</dc:creator>
		<pubDate>Wed, 04 Feb 2009 22:55:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.merchantaccountblog.com/?p=641#comment-19643</guid>
		<description>That&#039;s my point ... Visa&#039;s proper response was to notify the Malware scanning folks ... which they stated they did.

If not the Malware scanner ... how do you recommend scanning for these across your systems?</description>
		<content:encoded><![CDATA[<p>That&#8217;s my point &#8230; Visa&#8217;s proper response was to notify the Malware scanning folks &#8230; which they stated they did.</p>
<p>If not the Malware scanner &#8230; how do you recommend scanning for these across your systems?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Bergert</title>
		<link>http://www.merchantequip.com/merchant-account-blog/641/visa-issues-security-alert/comment-page-1#comment-19642</link>
		<dc:creator>David Bergert</dc:creator>
		<pubDate>Wed, 04 Feb 2009 21:29:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.merchantaccountblog.com/?p=641#comment-19642</guid>
		<description>&quot;Eh.. no. I am sure all of this is custom stuff, which is not picked by AV.&quot;

Yeap, not one of these hashes are in the ThreatExpert.com database...</description>
		<content:encoded><![CDATA[<p>&#8220;Eh.. no. I am sure all of this is custom stuff, which is not picked by AV.&#8221;</p>
<p>Yeap, not one of these hashes are in the ThreatExpert.com database&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Visa issues security alert - Malicious Software and Internet Protocol (IP) Addresses &#124; Payment Systems Blog</title>
		<link>http://www.merchantequip.com/merchant-account-blog/641/visa-issues-security-alert/comment-page-1#comment-19640</link>
		<dc:creator>Visa issues security alert - Malicious Software and Internet Protocol (IP) Addresses &#124; Payment Systems Blog</dc:creator>
		<pubDate>Tue, 03 Feb 2009 23:04:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.merchantaccountblog.com/?p=641#comment-19640</guid>
		<description>[...] it out here. No TweetBacks yet. (Be the first to Tweet this post) Possibly Related Posts (automatically [...]</description>
		<content:encoded><![CDATA[<p>[...] it out here. No TweetBacks yet. (Be the first to Tweet this post) Possibly Related Posts (automatically [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anton Chuvakin</title>
		<link>http://www.merchantequip.com/merchant-account-blog/641/visa-issues-security-alert/comment-page-1#comment-19639</link>
		<dc:creator>Anton Chuvakin</dc:creator>
		<pubDate>Tue, 03 Feb 2009 22:33:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.merchantaccountblog.com/?p=641#comment-19639</guid>
		<description>&quot;This is what we have malware scanners for&quot;

Eh.. no. I am sure all of this is custom stuff, which is not picked by AV.</description>
		<content:encoded><![CDATA[<p>&#8220;This is what we have malware scanners for&#8221;</p>
<p>Eh.. no. I am sure all of this is custom stuff, which is not picked by AV.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tod</title>
		<link>http://www.merchantequip.com/merchant-account-blog/641/visa-issues-security-alert/comment-page-1#comment-19635</link>
		<dc:creator>Tod</dc:creator>
		<pubDate>Tue, 03 Feb 2009 15:36:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.merchantaccountblog.com/?p=641#comment-19635</guid>
		<description>Yes, this seems fairly important ... but this really isn&#039;t the way to handle it.

Table 1 ... This is what we have malware scanners for, how does Visa suggest that we scan for this stuff, if not with our existing tools? 
 
Table 2 ... Is Visa serious regarding the fact that they think that we should create a Black List of IP addresses in our Firewalls?  The bad guys change IPs and domains more often than we change our underwear.
  
This Visa Data Security Alert seems to me to be very ill advised and poorly presented/executed.
 
What is their thought process behind this?</description>
		<content:encoded><![CDATA[<p>Yes, this seems fairly important &#8230; but this really isn&#8217;t the way to handle it.</p>
<p>Table 1 &#8230; This is what we have malware scanners for, how does Visa suggest that we scan for this stuff, if not with our existing tools? </p>
<p>Table 2 &#8230; Is Visa serious regarding the fact that they think that we should create a Black List of IP addresses in our Firewalls?  The bad guys change IPs and domains more often than we change our underwear.</p>
<p>This Visa Data Security Alert seems to me to be very ill advised and poorly presented/executed.</p>
<p>What is their thought process behind this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jestep</title>
		<link>http://www.merchantequip.com/merchant-account-blog/641/visa-issues-security-alert/comment-page-1#comment-19633</link>
		<dc:creator>jestep</dc:creator>
		<pubDate>Tue, 03 Feb 2009 13:32:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.merchantaccountblog.com/?p=641#comment-19633</guid>
		<description>They haven&#039;t posted it up there yet. We usually receive their alerts in an email before they post them publicly. This one seems fairly important, so I&#039;m not sure what&#039;s taking them so long to get it up there.</description>
		<content:encoded><![CDATA[<p>They haven&#8217;t posted it up there yet. We usually receive their alerts in an email before they post them publicly. This one seems fairly important, so I&#8217;m not sure what&#8217;s taking them so long to get it up there.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

