Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts
| 0 comments ]

The latest attack to hit Twitter is a "security nightmare" and marks the first time hackers have taken to using the micro-blogging site for profit, a researcher said today. Unlike earlier cross-site scripting attacks on Twitter, the latest wasn't a worm, said Roel Schouwenberg, a senior antivirus researcher with Moscow-based Kaspersky Labs.

Instead, it's something even scarier: The first instance of hackers serving up "scareware," fake security software that, once installed, nags users with so many alerts that some fork over $50 or more just to "register" the program and get rid of the warnings.

"This is just another scareware installer," Schouwenberg said, referring to the malware that's downloaded onto victimized PCs. "There's no worm component. But it's quite significant as it's the first time that Twitter's been used for a traditional type of attack."

Over the weekend, Twitter users began receiving tweets with the phrase "Best Video" and a link to a Russian domain. Although those who clicked on the link were directed to a site with a video, they were also served a malicious PDF document via an IFRAME on that site. The PDF, said Schouwenberg, contains a number of exploits, and tries each in turn. If it's able to compromise the computer using one of those exploits, the malware then installs phony security software.

The PDF appears to contain attack code from "LuckySploit," a relatively-new multi-strike hacker toolkit that uses malicious JavaScript, said Schouwenberg.

On Saturday, Twitter warned users of the tweets with the "Best Video" link, then later noted that it had suspended compromised accounts, but would restore then shortly after they'd been scrubbed.

Twitter's not able to remove any malware installed by the attacks, of course, leaving that chore up to users.

Schouwenberg's sure that Twitter's talk of cleaning accounts was a smokescreen, as unlike attacks in April, this one wasn't a worm. "There was no self-replicating code in the binary," he said. Instead, Schouwenberg believes that the malicious tweets were sent from Twitter accounts whose log-on credentials had been hijacked previously by basic phishing-style scams.

"When I first saw this Saturday night, I thought of the Twitter phishing attack, which was quite high profile," said Schouwenberg. "Phishing always has a greater purpose ... so when all of a sudden you see a new 'worm' but there's no worm component [in the attack code], it's clear that this was based on compromised accounts, rather than self-replicating."

Schouwenberg also found the links in the malicious tweets on multiple Web forums, giving credence to his theory that hijacked accounts were used to launch the scareware attack.

Twitter users should expect to see more such attacks, Schouwenberg said. "The whole idea of Twitter is to click on links," he said. "It's a security nightmare."

From : computerworld.com

Technorati Tags: ,,,
| Continue Reading..

| 0 comments ]

Conficker Virus Internet Long time not hear about Conficker, the conficker virus is considered stop swing the action. In fact do not. Virus that has not been found the vaccine still roam.

In fact, according to one observer security Guy Bunker, conficker are still evolving to attack computers. According to Guy, to this day conficker still infecting at least 50 thousand computers each day.

"Many people who have left news about conficker. Think again. Conficker still continue to attack a computer, every day," said Guy, as quoted PC World, Friday (5/22/2009).

Conficker is a frightening specter for the computer users in the world. The virus that attacked since February ago is a difficult virus to destroy. Even-up software giant Microsoft issued a classmate contest to eradicate the virus.

Up to now these countries are often victims conficker is the United States, Brazil, India and the average of 350 thousand virus attacked every day. Following then Mexico, Italy, and China is at least 89 thousand infected computers.

Technorati Tags: ,,
| Continue Reading..

| 0 comments ]

A hacker has been claiming successfully break all the credit card information belonging to Apple’s boss, Steve Jobs. Via email that is sent to the Cult of Mac, a hacker called orin0co claim to have obtained the credit card information of Jobs via a fake Amazon.com page that he created.

"Only me that hold all the information belonging to Jobs," said orin0co through an email with Hushmail account in it.

The story was, two years ago he make a fake amazon.com page and send an email to several people, including Steve Jobs in order to immediately update all account information at Amazon.com, including name, address, credit card number and password at Amazon.com.

Unconsciously, Jobs took to update the data in the fake Amazon website. "But I never presume own the data that I've got," he said as quoted from Softpedia, Sunday (5/17/2009).

Many people who deny the truth of the case, but the statement in the email that reinforce the information is correct. The data indicate that Jobs has purchased approximately 20 thousand items from the Amazon during the last ten years. Jobs are often known to buy films in the HBO mini-series in the DVD form.

Nevertheless, rumor has not yet confirmed as true story, even some thought that it is the effort to topple Apple. "Imagine how safe the Mac if you can playing with a Steve Jobs," write orin0co.

Technorati Tags: ,,
| Continue Reading..

| 0 comments ]

Basically, cloud computing is an environment / platform that is designed for users to be able to access the application from various devices connected to the Internet from any parts of the world which drastically reduces the energy to process (processor) and increase productivity.

The Panda security technology using their own called 'Collective Intelligence' in the Cloud Antivirus so that this can provide a high level of protection in real time, and reduce the use of system resources on your computer. This technology is a database can detect the virus, malware, rootkit, and heuristics. Because this application is located on the Internet, the Cloud Antivirus does not require the system to update the virus definitions as well as in the traditional anti-virus. New virus sample obtained from the millions of users their security applications to detect new malware faster, where the Collective Intelligence can make a new classification of malware in less than six minutes per day so that they can handle the 50,000 new samples.

When the scan process, Cloud Antivirus will work to do with the classification of the threats that exist, which can be executable file (. Exe) will be a priority for review does not compare to that. Speed also amazing, according to a statement from the Panda, because the scan is done through the server PandaLab, the detection level can be higher. Then make sure the process continues to scan your computer to always connected to the internet.

Technorati Tags: ,,,
| Continue Reading..

| 0 comments ]

Who does not know faceebook? This social networking site to absorb a lot of user from the bottom to the top. But have you knew that facebook also can not guarantee the security of your data? here's some tricks to secure your facebook account.

  1. Avoid facebook login from http://www.facebook.com/
    Page is not encrypted. Your login information (email and password) should be encrypted. Because the login form is in the login frame, users can not see if their data is encrypted or not.
    Another way to know whether the web page is secure enough is to see a padlock sign on the right bottom of the screen. Sample image that there is no sign.
  2. Make facebook login from https: / / login.facebook.com / login.php? Login_attempt = 1
    When you log in from http://www.facebook.com, click the login button without entering your email and password.
    You will be automatically redirected to the login page that has been encrypted.
    You can check the login page that has been encrypted, look for the padlock sign at the right bottom of the browser, such as in the picture below.
  3. Do NOT continue with the login process if there is a warning / safety signs.
    If you click Yes, there may be bad people who want to attack the encrypted page (this can be happen even in the https session ). If you click Yes, press ESC key on your keyboard to stop the login process.
  4. DO NOT forget to logout (Valid for all things related to the login session)
    If you are not using your own computer (as in the cafe), closing the browser without logout will leave the login session that can be used by other people. I find a lot of this in front of the Computer in the cafe.
  5. DO NOT Using Operating system to open and work with administrator privileges. Surfing on the Internet, open email, photos, documents and other activities should not use the user account with administrator privileges. The action was very dangerous! Unfortunately, the majority of computer users work with administrator privileges.
    So it's the computer user (except administrators), should use the Guest account if you want to work in the operating system environment.
  6. Beware of the danger of Facebook Widgets.
    Some Widget on facebook, is an application made by third parties, and allows the programmer to access the sensitive widget information or install spyware on the target computer. One of them who have ever appeared in the Facebook application is: Secret Crush attack the Facebook user data.
  7. Beware of the computer that is not secure.
    Computers that are not safe here in the understanding that the computer is not have patch, have not anti-virus update, or infected by malware. Computers infected by the worm Koobface (koob = books), or Keylogger malware that steals user passwords.
  8. Be careful with the internet Wi-Fi connection that you use.
    Facebook login process is encrypted using SSL / TLS (https). Your Facebook cookies can easily be taken from the air. Wi-Fi that protected with WEP encryption can easily be infiltrated in a maximum of 10 minutes. The bad people can set up an access point Wi-Fi for free, he will provide free access, so that people can see all of your internet activity, including the Facebook cookie. Do not store personal or sensitive information on Facebook.
  9. Think safety first before you click anything.
    Clicking the website link in the Facebook Wall is a risk. The wicked and malware (malicious) that spread like Koobface, they use Facebook Wall for post a bad website link.

Note:
Always to update your operating system, and also with Antivirus update.

Technorati Tags: ,,,
| Continue Reading..

| 0 comments ]

A network security company F-Secure in order to remind computer users to temporarily do not use the Adobe Acrobat Reader application  to read PDF files. Section during the last few years, many virtual world criminals who exploit holes in the program to spread Malware.

"Approximately 47 percent of attacks exploit weaknesses Acrobat Reader," said researchers at security firm F-Secure, Mikko Hypponen, as quoted from CNET, Saturday (4/24/2009).

One month ago, Adobe has fix the hole in Acrobat Reader, but F-Secure still find the chink in the application of the PDF files. Therefore, F-Secure said that the users should use other program to read PDF files.

"Adobe should make the security as a main priority," he said.

In the year 2008, the virtual world criminals more sponge Microsoft Word application. According to Hypponen 34.5 percent in 2008 was the attack of the files Microsoft Word.

Technorati Tags: ,,
| Continue Reading..

| 0 comments ]

W32/Conficker is a family-propagating network worms. There are several variants. Worm is the most interesting features that spread to other computers via security vulnerabilities in the Windows Server Service Vulnerability is possible to download from himself to a remote computer without the user’s knowledge.

When executed, the worm will copy itself as a randomly named DLL to the Windows System folder. He also copied to the network share itself and tries to run itself on the remote machine.

Conficker aliases: W32.Downadup, W32/Conficker.worm, Net-Worm.Win32.Kido

Computers that have been infected will try to connect to some site that is:

http://checkip.dyndns.org
http://www.whatismyip.org
http://www.whatsmyipaddress.com
http://www.getmyip.org
Please check the internet gateway in your location. If there is a connection to the site above the block only.

To turn off this virus:

1. Update on the windows computer (better all the infected computer is updated before all). see ref: http://www.microsoft.com/technet/security/Bulletin/ms08-067.mspx

2. Use the special removal tool virus, one of which is  the Anti-Downadup.exe From http://www.bitdefender.com

Do not forget to restart the computer after that.

Technorati Tags: ,,
| Continue Reading..

| 0 comments ]

Researchers at Symantec accept apparent what could be a cogent development in the advancing Conficker bastard saga: a new bore that is getting pushed out to some adulterated systems. In a brace of ways, the new basic is advised to amalgamate adulterated machines adjoin an industry bunch that is actively aggravating to accommodate the abounding worm.

For one, the amend targets antivirus software and aegis assay accoutrement to anticipate them from removing the malware. Not alone does it try to attenuate anti-malware titles, it aswell goes afterwards programs such as Wireshark and regmon.

And for another, it aswell abundantly expands the amount of area names adulterated machines acquaintance on a circadian basis.

Up to now, a bogus accidental area name architect produced 250 addresses that adulterated machines appear to anniversary day. The industry consortium, dubbed the Conficker cabal, responded by arise the algorithm and snapping up those domains advanced of the malware authors to anticipate the adulterated machines from comestible added damage.

The new basic ups the ante by accretion the amount of domains to 50,000 per day.

"It's acutely aggravating to plan about the plan of the cabal," Vincent Weafer, carnality admiral of Symantec Aegis Response, told The Register.

So far, Symantec has been able to affirm supply of the new basic to alone a scattering of machines. Symantec advisers are in the action of free if the updates are just the alpha of what will eventually be pushed out to adulterated machines everywhere, but either way, this appears to be the aboriginal time the malware authors accept in fact pushed out an update. Up to now the machines accept phoned home but never accustomed a reply.

"That's what makes this interesting, because this is what we accept is the aboriginal archetype of accepting an acknowledgment to that call," Weafer said. "Today is the actual aboriginal case of that getting successful."

Estimates of the amount of machines adulterated by Conficker vary, from hundreds of bags to added than 10 million. Weafer and added aegis advisers accept said Conficker's advance has slowed over the accomplished few weeks. That suggests its authors may be added focused on attention the machines they've already baffled than claiming new ones. (theregister)

Technorati Tags: ,,
| Continue Reading..

| 0 comments ]

Paris HiltonCalifornia - Paris Hilton Hollywood sosialite private Site appeared dangerous virus.

The visitors who come to the site will become a target of virus threats. Paris Hilton is an interesting name for the world of entertainment gossip about himself and always sought. No wonder if many people find the name of Paris Hilton in the Google search engine.

Because of it, this site is the target for hackers spreading  dangerous virus. Terrible, hackers are changing the view site and then put evil program  in it.

Action is known by the security vendor ScanSafe. Cited  through PC World, on Tuesday (13/1/2008), this site will immediately display a pop-up window.

In a notification, the user is required to download a software, if you want to view images in the site. Whatever you press the button, either Yes or No, the pop-up window is still download the program that contains a virus to your computer. The virus is known as Trojan-Spy.Zbot.YETH.

Technorati Tags: ,,
| Continue Reading..

| 0 comments ]

DNSstuff has released a new tool to help organizations detect if their DNS servers are vulnerable to the DNS protocol flaw revealed last week.

DNSstuff.com is offering a free tool for organizations looking to test the susceptibility of their domain name servers to a fundamental flaw in the Domain Name System (DNS) protocol revealed publicly last week.

A provider of on-demand DNS and network analysis tools, DNSstuff made the freeware, which company officials have dubbed DNS Vulnerability Check, available on its site Wednesday. The tool is meant to test for the vulnerability reported by Dan Kaminsky, director of penetration testing for IOActive.

The researcher reportedly uncovered  a flaw in the DNS protocol that can be exploited to poison DNS server caches and re-direct Internet traffic. While he has publicly kept details of the vulnerability close to his vest, several vendors coordinated the release of a patch in response. In the case of DNSstuff, company officials decided to offer a free tool that checks to see if DNS queries from a user’s server are coming from the same source port.

“When you click the test button on the website, you are redirected to a specially crafted URL that has encoded your web clients IP address, which causes a DNS query to resolve this name to an IP address,” said Paul Parisi, CTO of DNSstuff. “This query is handled by whatever DNS server you have your system configured to use—typically provided by your ISP—and setup to perform recursion for you and other customers.”

“The URL itself resolves to a specially crafted CNAME, which itself resolves to yet another specially crafted CNAME,” he explained. “The end result of this is that the resolver operating on your behalf must make several DNS lookups in series to our tool, during which time we record the IP address of the DNS server making the query, the source port the query came from, and the query ID in the DNS packet header.”

Ultimately, the name will resolve to an IP address of the DNSstuff site. At this point their Web server decodes the information and compares the lookups to one another, Parisi added.

“If you are vulnerable, the data we recorded will show that all the DNS queries made by your resolver originated from the same source IP address,” he said.

The tool also checks for reused query IDs.

“There are far too many attacks against DNS to list; it is the most insecure part of the infrastructure as it relies on easily forged data from a third party you must implicitly trust and cannot verify,” Parisi said. “DNSSEC addresses most of these issues, leaving only run of the mill vulnerabilities such as buffer overflows to contend with.”

source : eweek.com

Technorati Tags: ,

| Continue Reading..