close
The Wayback Machine - https://web.archive.org/web/20110510051226/http://community.websense.com:80/blogs/securitylabs/
  • Search Blog Archives

Follow us: 
Like us on Facebook Follow us on Twitter Visit us on YouTube Get Websense Security Labs alerts delivered to your inbox Follow us on LinkedIn
The "real" Osama Bin Laden dead pics
Posted: 04 May 2011 03:26 PM

Messages inviting users to see the "real photos" of Osama Bin Laden's remains made the rounds in the email realm today, in addition to the Facebook scams and malware recently spread via Twitter abusing the same topic.  Our customers are protected from these types of blended attacks by ACE, our Advanced Classification Engine.

 

Subjects being used in this attack are "As Fotos do Terrorista Osama Morto" and "As Fotos de Osama Binladem Morto" which of course are designed to tap into the user's curiosity. 

 

The email sample we got hold of today is in Portuguese, like the one below.

 

Image

 

The text translates as:

 

After the pronouncement of the death of Osama Bin Laden several pictures of the body were released on the internet. According to American newspapers not all are real.
The real photos are available on the link below.

 

Clicking on the provided link prompts the user to download a file called FOTOS.Terroris.zip, which is fairly detected by AV engines.

Mary Grace Timcang

A weekend of Click-jacking on Facebook
Posted: 02 May 2011 07:17 PM

 

In this blog post, I will analyze a Facebook scam technique that we've seen grow in popularity over the past few weeks, but let's focus on one example that was circulating this past weekend. As a Websense customer, if you are running our Web Security Software or real-time analytics, your users would have been protected from the first link right off the bat, thanks to our Advanced Classification Engine (ACE):

 

To show how this particular attack works, I set up a scenario using a test account. In this scenario, a friend named Chris has already fallen for the scam and posted a comment to his own Facebook profile page, which appears on all of his friends' walls.

 

Here's what Chris, a victim of this scam, commented on:

 

The Enticement

 

.Image

 

Remember scammers aren't going to post something boring, this is meant to be enticing ... OK, I'll play along. Let's see what happens as I follow the trail. By clicking on the link, I'm redirected to mcdshock DOT info (robtex):

Image

 

A Real CAPTCHA?

 

Interesting. So this site says that I can only continue if I solve a CAPTCHA. The site explains that it's using the CAPTCHA because it is attempting to protect itself from  BOTS. That seems to make sense. CAPTCHAs are in fact meant to tell humans and programs apart (in theory) - but this particular page has more going on than meets the eye. 

 

Let's look at the source code behind this page (full source code can be found here):

Image

 

 

 

The first thing that is noticeably odd is that the source code indicates the use of the Facebook comments social plugin (see fb:comments code) that allows websites to include a comment box linking to a user's Facebook page if they are logged into Facebook in another window or tab. A typical comment box looks like this:

Image

 

But looking at the source code, no such comment box was displayed. Let's take an even closer look at the source code to figure out why ...

 

Classic Click-jacking

The style sheet section of the source code shows that the Facebook comment box is being wrapped in a div that has been given a style making it completely invisible (see opacity):

 

Image

 

Next the source code is overlaying a background image on the entire section where the Facebook comment box is:

Image

 

Can you guess what that image looks like? Here it is ...

Image

 

Analysis of the source code indicates that the CAPTCHA is not a real CAPTCHA but an image sitting on top of a Facebook comment box meant to trick me, the unprotected user, into clicking on something - all the while, hiding its true nature. The submit button is carefully placed on top of the comment button. By clicking on it, I would be submitting text to my Facebook wall with text that is supplied by the scammer's website.

 

... and sure enough, once I hit submit, here is the comment that is posted to my Facebook page:

Image

 

Classic case of click-jacking!

 

That's not the end of it though! What happens next after clicking submit, apart from a comment being posted to my profile page is that I'm redirected, first to a tracking website:

Image

 

 

... and next to isozbanks DOT com, where I'm asked for further verification to either play a Pacman game or answer what my favorite Facebook game is:

Image

 

 

Another click? Can you say clicking-jacking part deux? Indeed, if I click on one of the above links, another comment is posted to my Facebook profile page:

Image

 

 

Click-jack complete, commence project information gathering

 

Next, I'll be redirected to playsushi DOT com (Alexa Ranking: 7903)  where if I click on "Click Here To Play," I'll be prompted to download an executable called SetupPlaySushi.exe (VirusTotal report):

Image

 

 

Had I chosen instead to take the survey of my favorite Facebook game, I would've been brought to the following pages where the attacker would have a very good opportunity to capture my email address and post another comment to my Facebook page. Upon clicking continue, I'd be asked to give out more information (a great method for attackers to build up a profile for tracking purposes and to store their victims' personal information).

Image

 

 

Now assuming I either visited the Pacman site or the survey site, the following page is shown:

Image

 

 

I then must proceed through a few more Web pages, which in the end ask me to play more games or fill out more surveys for verification purposes (it's worth noting that each user will be prompted with different games and different links) - again really just to trick me into clicking and sending comment spam to my own Facebook profile page:

Image

 

 

Clicking one of these links will bring me to the following pages:

Image

 

Finally after viewing any of the above sites, I'll get a final Web page screen indicating that  the content has been unlocked and that I can view the video.

Image

 

 

 

Is there even a real video to view?

 

At the end of this entire process, I'll be rewarded for my persistence by being able to finally see the video I was promised.

 

Let's review all that I had to give up to get to view the final video:

 

  • Full name
  • Full address
  • Gender
  • Phone number
  • Downloading and possibly execution of an executable (spyware)

 

The Click-jacking to post comments to my profile was the main motivation from the attacker's point of view. Everything that came after was just a bonus.

Image

 

To give you an estimate of how many people fell for this scam, we can look at the hits on YouTube yesterday and this morning, Overnight more than 100,000 users visited the YouTube video, showing how successful this scam really was.

Image

 

Don't become a victim! Here are some tips and tools to protect yourself against Click-jacking (link).  Websense has a free Facebook plugin called Websense TRITON Defensio that would have protected users from this attack. Install it, and it will protect you from these types of scams.

 

 

 

Web Filtering and real-time analytics within ACE would have protected a user from the start!

 

Image

 

Principal Security Researcher: Stephan Chenette
Thanks to our newest researcher Armin Büscher for the assistance!

Osama bin Laden scams on Facebook
Posted: 02 May 2011 10:34 AM

We've seen scams using Osama bin Laden's death in other places and of course they made it onto Facebook as well. Here is the first example talking about a video:


Image

 

When clicking on the link the user is taken to a page on Facebook asking them to copy/paste the code into the browser's address bar so that they can watch the video:

 


Image

 

All you do is to help spread the message so don't do this.

Filed under:

Patrik Runald

Osama bin Laden's death, Twitter fame and malware
Posted: 02 May 2011 09:33 AM

Cyber criminals will jump at any chance and use any news to spread malware, and news doesn't get much bigger right now (sorry William and Kate) than the death of Osama bin Laden. It was obvious that we would see SEO poisoning leading to malware, image search poisoning, spam campaigns, and so on. But at the same time, cyber criminals also like to get lucky, which happened here.

 

Twitter is a great source of information, and in the aftermath of the news of bin Laden's death, people started noticing that a Twitter account called @ReallyVirtual based in Abbottabad, Pakistan had tweeted about hearing helicopters and explosions in the area six hours before the news became public. Essentially he live tweeted during the attack.

 


Image

 

As can be seen from the screenshot, Mr. Athar links to his blog, and I'm sure a lot of users who saw his tweets went there. Unfortunately for them, the site was compromised and was serving a poorly detected malware through the Blackhole Exploit Kit. Websense customers were proactively protected against this thanks to our real-time analytics in ACE. Below is a screenshot of what the site looks like:

 


Image

 

And here's the exploit code on the page.


Image

 

Anyone going to this page would also load content from the malicious URL above, and the Blackhole Exploit Kit would then try to use several exploits to automatically install malware on the PC.

 

The malware that the drive-by-download attempts to install is a fake system tool named 'WindowsRecovery' that claims to have found problems on the victim's computer:

Image

To convince the user that something really is wrong with the system, the malware hides all files and folders in the hard drives and on the desktop:

Image

But of course the scammers offer the user a quick solution to this problems with a purchase of the premium version of 'WindowsRecovery':

Image

Filed under:

Patrik Runald

SOURCE Boston 2011 Conference RECAP
Posted: 27 Apr 2011 05:46 PM

 

 

I returned this past weekend from SOURCE Boston, where I presented the new features and architecture of Fireshark v2.

I have had the opportunity to speak at many conferences before, but this was my first time doing so in my university town of Boston (Northeastern), and my first time speaking at SOURCE. SOURCE has conference locations in Seattle, Barcelona, and Boston, and attempts to bring security experts together to create a very positive mix of business needs and technology expertise. Boston is a bustling city with a number of technology companies and top universities. The location alone is worth the visit.

That aside, I was impressed with some of the presentations I saw. Here are a few worth mentioning, which are available online at http://www.sourceconference.com/boston/speakers_2011.asp:
 

  • On The Use of Prediction Markets in Information Security - Dan Geer, Alex Hutton, Greg Shannon
  • The Exploit Intelligence Project - Dan Guido, iSEC Partners (great talk!) 
  • Incursion - From Internet To SCADA, Critical Systems Compromise Case Studies in Pictures - Val Smith, Attack Research, and Chris, SecureDNA 
  • Fuel for pwnage: Exploit kits - Vicente Diaz and Jorge Mieres, Kaspersky Lab
  • Reverse Engineering Flash Files with SWFREtools - Sebastian Porst (Flash analysis tool released!)
  • Reversing Obfuscation - Adam Meyers, SRA International
  • Streamline Incident Types for Efficient Incident Response - Predrag Zivic and Mike Lecky, Canadian Tire (really interesting talk on identify tracking)
  • Network Stream Hacking with Mallory - Raj Umadas, Jeremy Allen, The Intrepidus Group (Mallory is a tool worth checking out!)
  • Adding another level of hell to reverse engineering - Ben Agre, Raytheon (Something as reverse engineers that we'll have to become acustomed to more and more: used junk code!)


and finally...

My presentation: Fireshark v2 - An Analysis Toolkit for Malicious Web Sites - Stephan Chenette, Principal Security Researcher, Websense Labs (to be publicly available on or before May 5)

Image

(Figure 1: Stephan Chenette introducing Fireshark v2, an analysis tool kit for malicious websites)

 

I want to thank Stacy Thayer,  SOURCE founder, the SOURCE advisory board and all attendees.

Image

(Figure 2: SOURCE founder, Stacy Thayer)

 

 

Malicious E-Cards on the prowl
Posted: 26 Apr 2011 09:14 PM

 

Emails disguised as electronic cards have been used as bait over and over again for malicious intent. The fact that they are overused is a clear indicator that this lure indeed works.  Websense Security Labs™ and the Websense ThreatSeeker® Network recently came across an e-card themed email.  Our customers are protected from this threat by ACE, our Advanced Classification Engine.

 

Let us first look at the sample email.  The URLs used in the emails are either compromised sites or were only created barely two weeks ago.

 

Screen shot 1 : Sample email that the Websense Email Threat Team got hold of recently
Image


Clicking the URL withing the email directs you to a site containing obfuscated code similar to the one shown on Screen shot 2. This code then creates an iframe containing another URL  which you can see on Screen shot 3.

 

Screen shot 2 : Obfuscated code of the URL that came with the email
Image


Screen shot 3 : Deobfuscated code of the URL from the email.
Image

 

The contents of the URL specified in the iframe contains another obfuscated script.  This script, which uses a strikingly similar redirection code in our recent blog, in turn drops the exploit code and runs a rogue AV on the victim's machine.

 

Screen shot 4 : Code snippet of the URL specified in the iframe used in redirection

Image

 

Having the victim click on the link and then download an executable is usually the norm on these type of attacks. However, in this case, victims are exploited, and malware is downloaded and executed simply by clicking the URL link that came with the email.

 

Screen shot 5 : Snapshot of the malicious website used in the email

Image

 

Websense Email Security and Websense Web Security protect against these kinds of blended attacks.

Filed under: , ,

Mary Grace Timcang

Google Image Poisoning Leads to Exploit
Posted: 21 Apr 2011 01:12 AM

 

Google search results have traditionally been the target of black hat SEO campaigns. Websense® Security Labs™ has identified a new trend in which cyber criminals take advantage of Google Image search rankings to spread malware.

 

 

Websense Security Labs Threatseeker® network has detected that Google Image search returns poisoned pictures when searching on celebrity child "Presley Walker". We first found on Monday that all the image search results took users to a notorious exploit kit – Neosploit. Later, it changed to redirecting users to rogue AV sites. As we publish this blog, the search results are still poisoned and are leading to Neosploit again. Websense customers are protected from both types of attack by ACE, our Advanced Classification Engine.

 

 

 

The search results for "Presley Walker" through Google Image:

 

 

 

Image

 

Let's take a look at the first attack case. When a user clicks the pictures on the top line, the user will be redirected to a Neosploit exploit page.

 

Below is one of the redirection chains used by this exploit kit:

 

Image

From the chain, we see the third URL is the malicious site holding the exploit code. We found that all the exploited sites are hosted on the same IP 66.235.180.91, and interestingly, they constructed it with the same path named TF19, which looks like a pattern of this campaign. At last it will trigger appropriate vulnerabilities targeted by this exploit kit according to the user's operating system and browser. From the chain above we see it downloaded a PDF file that targeted three Adobe Reader vulnerabilities. This PDF file is heavily obfuscated and has a relatively low VirusTotal detection.

 

The list of URLs hosted on the IP, as shown from our Threatseeker network:

 

Image

 

Neosploit is a well-known exploit kit in the black market. The authors reportedly stopped supporting and updating the exploit kit due to financial problems, but variants of Neosploit have been updated frequently. The variants may contain MDAC (CVE-2006-0003), ActiveX (CVE-2008-2463, CVE-2008-1898), and three Adobe Reader (Collab.getIcon, Util.Printf, Collab.collectEmailInfo) vulnerabilities, among others.

 

The second case is one of the common tricks black hat SEO campaigns always use: luring users to download fake antivirus software called InstallInternetProtectionXXX.exe. From the VirusTotal scan result, only 20% of antivirus engines detected this malware.

 

 The rogue AV page when using Firefox to surf the Web:

 

Image

 

 

 

 

 

 

 

Xue Yang

Facebook scam "My Top 10 stalkers" targets users in specific countries
Posted: 19 Apr 2011 07:08 PM

A new spam campaign, similar to campaigns we have seen in the past, is spreading on Facebook. This one, however, has some interesting twists to it.

 

The core of the campaign involves a Facebook app that claims to know who your "Top 10 stalkers" are. Our customers are protected from this campaign by ACE, our Advanced Classification Engine.

 

Image

 

It works by creating an album - “My Top 10 stalkers” - with the description "Check who views your profile @," followed by a bit.ly URL-shortened link. It then automatically uploads a photo to the app and tries to mark all the user's friends in the photo.

 

Image

 

The bit.ly link redirects the user to a page that uses JavaScript to determine the geographical location of the computer based on its IP address. Depending on the location, the page then redirects users located in specific targeted countries to the Facebook App in an attempt to further spread the infected link. The campaign is targeted at Facebook users in the United States, Canada, United Kingdom (including a specific target for Great Britain), Saudi Arabia, Norway, Germany, Spain, Slovenia, Ireland, and United Arab Emirates.

 

Image

 

At the time of writing, hackers have switched to using a new app. The first illegitimate app was deleted by the Facebook security team. Both apps use exactly the same mechanism to post spam profile messages in Facebook. Regardless of whether the JavaScript redirects the browser to the Facebook app because of its origin, all users are ultimately redirected to a scam page that tries to lure them into completing several fake surveys. Hackers use this method to try to collect personal information such as the user's home address, e-mail address, or phone number.

 

Image

 

If the user tries to navigate away from the page or close the browser, a message appears asking them to stay and complete a "SPAM-free market research survey to gain access to this special content." Special it may sound, but it is definitely not spam-free!

 

As always, if a page forces you to Like, Share, or install an application in order to view it, DON'T DO IT! Chances are, it's spam.

 

Install Defensio, our free security app for Facebook, to prevent scams like this from ever appearing in your news feed.

 

Filed under: ,

Armin Buescher

Mass Injections Leading to g01pack Exploit Kit
Posted: 19 Apr 2011 01:07 AM

Our ThreatSeeker® Network is constantly on the lookout to protect our customers from malicious attacks.  Recently it has detected a new injection attack which leads to an obscure Web attack kit.  The injection has three phases which will be covered in this blog post. Websense customers are protected from this attack by ACE, our Advanced Classification Engine.

 

The first phase of the attack is a typical vector for exploit kits to drive traffic to their sites: script injections.  Script HTML code is put on legitimate Web sites meant to drive traffic to the attack kits without the victim's knowledge.  In this case, legitimate sites are injected with malicious JavaScript.

 

Screen shot of malicious script injection (Phase 1):

Image

 

In the second phase, this script injection then pulls obfuscated content from another site.  The obfuscated content creates an iframe that is used to pull content from the exploit kit site. 

 

Screen shot of the obfuscated redirect site used in the above injection (Phase 2):

Image

 

Screen shot of the deobfuscated redirection site:

Image

 

 

The exploit kit can basically be described as a drive-by download site used in the third and final phase of this attack.  Its intent is to scan, attack, and run malicious code on the visitor's computer.  If one of the exploit kit's Web attacks is successful, it could put malware on a victim's computer that is meant to remotely control the computer.  The binary that this kit tries to run on target computers has low detection as a Rogue AV installation.  As is typical, the exploit kit's Web attack code is obfuscated.

 

Screen shot of obfuscated exploit kit code (Phase 3):

Image

 

 

It's in cases like this that we can really harness the power of our ThreatSeeker® Network, not only to better protect our customers but also to perform further research into attacks!  With all of the scanning that ThreatSeeker® does, we get a large amount of data which we can correlate.  In this example, I can see all of the URLs associated with the IP address that this exploit kit was hosted on. 

 

Screen shot of URL report from hosting IP:

Image

 

 

In the screen shot above, I've highlighted that there are a number of URLs with an "/admin/" directory.  Assuming that these are the same attack kits hosted on this IP, I can try to see if our attack host has the same page.  Sure enough, the attack site discussed in this blog follows the convention of other sites hosted on this IP.

 

Screen shot of the attack kit admin page:

Image

 

Notice the title on the admin page: it has an email address for a group known as the Iranian Cyber Army.  This is a known attribute of a kit called g01pack malware tool.  We were able to access the admin panel and confirm that this site is hosting an installation of g01pack malware tool. 

 

Screen shot for g01pack admin statistics for this attack:

Image

 

 

 

Update:

We are aware that the g01pack admin panel is in fact a faked honeypot tool used by attackers.  This admin "tool" is used to track researchers who try to access admin panels for attack kits, an interesting tactic.  However, the threat described in this blog is a very real threat and we are seeing other attack hosts on the same IP attacking visitors.  Seeing that there are other hosts on this IP which also host the fake admin panel, these hosts are seen as exploit kit attack code which could be used in the same script injection attacks as well as other injection attacks.  Thanks @briankrebs for getting in touch with us to clarify this post.

Chris Astacio

Boxes of Money !
Posted: 15 Apr 2011 02:27 AM

 

Phishing and 419 scams have been around for a while now. However, sometimes they never cease to amaze when it comes to their tactics. We caught this most recent one in one of our Honeypots and thought we would share due to the “over-the-top” images sent.

 

Also note the horrific markup of the passport. 

 

-----------------------------------------------------------------------------

 

Email sent from: usermail.uni-ak.ac.at ([193.170.136.34]

Email Subject: urgent response

Email body:

Apologies for having to reach out to you like this, my name is Gideon Kerkula am from Liberia, I and my mother just arrived with 2 inherited trunk boxes which our late father kept in our under ground flat which we discover and we collected money from it and I took picture with the two trunk boxes, we need your help to clear the money from the custom and help us invest it in any profitable investment that will last for a life time, the US$35,000 we collected from the boxes we use it for clearance on Ivory Coast- Abidjan border and the settlement of the military and police force on the highway. Please I want you to keep it confidential between us.

 

I have also attached my passport and the picture I took with the 2 trunks boxes, please if there's anything you don't understand or you want to know, ask and we will enlighten you.

 

I appreciate and wait your response.Please reply to this email;GideonKerkula@removed.cn

 

Thanks,

 

Gideon kerkula

 

-----------------------------------------------------------------------------

 

Images that were attached:

 

Image

 

Image

 

Image

 

You would have thought Gideon would have given up at this point - however, there is a follow-up.  Brace yourself for the sequel:

 

-------------------------------------------------------------------------

From: Kelvin Kerkular [mailto:kkelvin1979@removed.cz]
Sent: 07 April 2011 06:44
Subject: PRIVATE AND CONFIDENTIAL

From:
Kelvin and Vivian
Tel:233 26 750 6123

Dear Beloved,

My name is Kelvin Kerkular I am 32 years old, and my junior sister name is Vivian Kerkular, 29 years old, we are Citizens of Liberia, currently residing in the refugee camp in Ghana. I am contacting you solely on a business related issues.

I became an orphan some couple of years ago. I am contacting you about a need I have and I believe you are well able to help me after my severe and fervent prayer for God to link me up with some one who will be capable of helping me out from Ghana as my foreign beneficiary. It all depends on our trusting each other but I've chosen to contact you prayerfully and believing that you are the person that can help me.

The source of my parent's death was believed to be from our detractors who are never happy that he was making so much progress. The issue is that my parents are diamond merchants in my country Liberia and they made too much money from the business, that prompted the government of Liberia to probe them.

For this reasons, during the crisis in Liberia, our home was among the first target by the Liberian rebels. They allegedly said that, my late parents have a close relationship with former president of Liberia President Charles Taylor) that was their reason of storming our home. My mother died immediately they storm our resident and my father sustained serious bruises that he could not survive while in the hospital. I and my younger sister Vivian managed to escape during the incident. As i am talking to you now, i and my younger sister are staying in Ghana for some obvious reasons that i will like to relay to you on your response to this message.

This is a confidential matter i will like to discuss with someone whom my spirits accepted to deal with. Because after my parents exit, the government of Liberia have taken over all of our belongings. They have also emptied my parents bank accounts left alone with a deposit which my late father made in a nearby country called Ghana during his trade to Ghana. No one knows of this deposit, it is only me as the next of kin. And my father had earlier warned me not to disclose this issue to anyone before he died in the hospital after the incident that cause his death. Today I and my younger sister fend for ourselves here in Ghana.

And life has been very difficult since the government of Ghana started their deportation exercise which says that we refugees should evacuate their Bujumbura refugee camp to our various countries. Please my dear beloved, our plans now are to relocate from Ghana since we can not afford to go back to Liberia following our past experience as they killed our parents, but we will need to move out the fund left by my late father here in Ghana.
please according to my late father's lawyer all we need now before these boxes can leave Ghana to  is your full contact information so as to enable the lawyer work out the papers that will back up the shipment to your location. Please i believe my lawyer will explain more better to you as soon as you come in contact with him.

Once you agree to help us move this fund, we will link you up with our late father's lawyer who will help us in securing all the necessary documents for the shipment. As soon as we agree, we will come to your country where I and my sister will invest the money under your guide. So please let us know what will be your compensation or percentage for helping me and my sister out.

In the attached files, you will see a photograph picture which my late father took me before he made the deposit as a proof, and a picture of my sister, Vivian. Please the lawyer have not seen this picture as my father warned me not to disclose the content of the boxes to anyone except to some one whom i have chosen to be my foreign beneficiary, and also attached are the copies of the documents that is covering the fund in the keeping company, so i want you to go through them carefully. sometime ago there was a problem in the camp and my sister lost her Liberia passport but the lawyer agreed to get her a Ghana passport if we are ready to travel out of Ghana to meet with our foreign beneficiary.

Please NOTE that the earlier you help us the better as you will be doing Almighty God a great favor because our lives are no more safe with these people over here. I will need your reply stating your readiness to help in seeing this through.

We will be needing your details as follows:
(1) Your Full Names.
(2) Your Home or Office Address.
(3) Your cell phone Number.
(4) Occupation.
(5) Age.

Please feel free if you have any question to ask.

Thanks and be bless
Kelvin and sister.

-------------------------------------------------------------------------

And yup, you guessed it: more convincing attachments:

 

 

Image

 

 

Image

 

 

Image

 

 

Image

 

 

And finally, the cream of the crop: a convincing photo of Vivian, Gideon's or (as he prefers in the second email message) Kelvin's sister.

 

 

Image

 

 

Well, Kelvin Gideon Kerkula if that is your real name... consider this. You have been named and shamed.  Unfortunately your overzealous tactics in an attempt to 'social engineer' or to convince me and everyone else do not work. 

 

I wonder what the next in the trilogy will be...

 

Of course Websense customers are being continually protected against phishing emails such as these with our Advanced Classification Engine, ACE.

 

 

Filed under:

John Smith

More Posts Next page »

©2011 Websense, Inc. All Rights Reserved.