Twitter users need to be on the lookout for a new round of
malware-carrying spam messages that are coming from compromised
accounts, possibly even from Twitter profiles they trust.
If you receive a direct message suggesting that someone has posted or
tagged you in a Facebook video, beware. Clicking on the link could
infect your computer with malware. According to the Sophos Naked
Security blog, the direct messages are not originating from spam
accounts, but instead compromised accounts of friends - which makes it
even more likely that a careless user could fall victim.
Although the messages vary, the common thread between all of
them is that they contain a "facebook.com/________" link and mention
that a video of you has been posted on Facebook. "Your in this
facebook.com/________ video, LOL" reads one spam message, while another
says "you even see him taping u, that's awful."
When an unsuspecting user clicks on the link, they are shown a
YouTube video player and prompted with a message that says, "and update
for YouTube player is needed. It says that it will install Flash Player
10.1 onto your computer, but instead installs "Troj/Mdrop-EML, a
backdoor Trojan that can also copy itself to accessible drives and
network shares," according to Sophos.
Of course, clicking on any link in a direct message that links
you offsite is risky, and the fact that these messages are coming from
trusted sources makes it especially tricky. However, the fact that the
messages contain various misspellings and gramatical errors should
suggest to the discerning user that they might not be legit.
::Trend Micro Threat Resource Center::
29 September 2012
18 September 2012
HOWTO Brute Force Android Encryption on Santoku Linux
This HOWTO will guide you through the process of cracking the pin used
to encrypt an Android device (Ice Cream Sandwich and Jelly Bean) using
brute force on Santoku Linux Community edition.
Labels:
Android,
bootable CDs,
brute force,
encryption,
Linux,
mobilephone
14 September 2012
iPhone 5 release brings out email scammers
Apple's long awaited release of iPhone 5 has provided cyber crooks with a perfect opportunity to scam users.
Even before yesterday's official presentation of the new device, a mass mailing campaign offering a protective case for it has been spotted by Kaspersky Lab researchers:

Now - even if this offer was legitimate, it is highly unlikely that the case would fit, as the iPhone 5 is thinner and longer than its predecessor. The fact that the senders sent out the email before the release of the device indicates that this is likely a scam.
It's hard to tell just what type of scam it is, but at best you can get saddled with a case that doesn't fit, and at worst your credit card information can be stolen and used by the scammers.
In any case, beware of offers like these and restrict your online shopping to legitimate e-commerce sites.
Even before yesterday's official presentation of the new device, a mass mailing campaign offering a protective case for it has been spotted by Kaspersky Lab researchers:

Now - even if this offer was legitimate, it is highly unlikely that the case would fit, as the iPhone 5 is thinner and longer than its predecessor. The fact that the senders sent out the email before the release of the device indicates that this is likely a scam.
It's hard to tell just what type of scam it is, but at best you can get saddled with a case that doesn't fit, and at worst your credit card information can be stolen and used by the scammers.
In any case, beware of offers like these and restrict your online shopping to legitimate e-commerce sites.
17 July 2012
USB drives left in car park as corporate espionage attack vector
A number of infected USB flash drives were recently left in the car park of Dutch chemical firm DSM in a failed corporate espionage attempt. According to a report
from Dutch newspaper Dagblad De Limburger, these drives were planted by
an unknown party in hopes that one or more of the company's employees
would insert them into their office systems.
However, instead of plugging it into one of the company's systems, an employee who found one of the USB sticks turned it over to DSM's IT department. Upon examination, they discovered that the drives contained malware that was set to automatically run upon being inserted into a computer. The malware is said to have been a key logger designed to capture usernames and passwords, and access the company network to send them to an external site.
Upon finding this, the company blocked all access to the IP addresses which the malware attempted to contact. Because, they say, it was a clumsy attempt to steal data and as no damage was done, DSM decided not to contact the police.
Would you report to the police?
However, instead of plugging it into one of the company's systems, an employee who found one of the USB sticks turned it over to DSM's IT department. Upon examination, they discovered that the drives contained malware that was set to automatically run upon being inserted into a computer. The malware is said to have been a key logger designed to capture usernames and passwords, and access the company network to send them to an external site.
Upon finding this, the company blocked all access to the IP addresses which the malware attempted to contact. Because, they say, it was a clumsy attempt to steal data and as no damage was done, DSM decided not to contact the police.
Would you report to the police?
15 July 2012
Disable Windows Sidebar and Gadgets NOW on Vista and Windows 7. Microsoft warns of security risk
Users of Windows Vista and Windows 7 have been advised to completely
disable their Windows Sidebar and Gadgets, in response to what appears
to be a serious security risk.
The Windows Sidebar is a vertical bar that can appear at the side of your desktop, containing mini-programs (known as gadgets) that can provide a number of functions such as a clock, the latest news headlines, weather report and so forth.
A security advisory
issued by Microsoft's security team advises that vulnerabilities exist
that could allow malicious code to be executed via the Windows Sidebar
when running insecure Gadgets.
The warning comes ahead of a talk scheduled for Black Hat later this month by Mickey Shkatov and Toby Kohlenberg. Shkatov and Kohlenberg's talk, entitled "We have you by the gadgets", threatens to expose various attack vectors against gadgets, how malicious gadgets can be created, and the flaws they have found in published gadgets.
Clearly Microsoft is worried about the security researchers' findings, and has issued a "Fix It Tool" which will protect Windows 7 and Vista users by entirely disabling the Windows Sidebar and Gadgets functionality.
Yes, that's right. Microsoft hasn't issued a security patch to fix the vulnerability. They're suggesting you completely nuke your Windows Sidebar and Gadgets.
Which is bad news if you found those sidebar gadgets useful. You better find a new way to tell what time it is, or catch the latest from your favourite RSS feeds.
Sorry if it causes you any pain, but I would recommend you follow Microsoft's advice if you run Windows 7 or Vista and apply their "Fix It tool" as soon as possible. It may be a sledgehammer to crack a nut - but it's a nut that needs smashing, and fast.
Interestingly, Microsoft has dropped Gadgets from the upcoming Windows 8. In retrospect, that was probably a very good idea.
The Windows Sidebar is a vertical bar that can appear at the side of your desktop, containing mini-programs (known as gadgets) that can provide a number of functions such as a clock, the latest news headlines, weather report and so forth.

The warning comes ahead of a talk scheduled for Black Hat later this month by Mickey Shkatov and Toby Kohlenberg. Shkatov and Kohlenberg's talk, entitled "We have you by the gadgets", threatens to expose various attack vectors against gadgets, how malicious gadgets can be created, and the flaws they have found in published gadgets.

"We will be talking about our research into creating malicious gadgets, misappropriating legitimate gadgets and the sorts of flaws we have found in published gadgets."If the researchers have managed to find ways to exploit existing gadgets that's particularly worrying.
Clearly Microsoft is worried about the security researchers' findings, and has issued a "Fix It Tool" which will protect Windows 7 and Vista users by entirely disabling the Windows Sidebar and Gadgets functionality.
Yes, that's right. Microsoft hasn't issued a security patch to fix the vulnerability. They're suggesting you completely nuke your Windows Sidebar and Gadgets.
Which is bad news if you found those sidebar gadgets useful. You better find a new way to tell what time it is, or catch the latest from your favourite RSS feeds.
Sorry if it causes you any pain, but I would recommend you follow Microsoft's advice if you run Windows 7 or Vista and apply their "Fix It tool" as soon as possible. It may be a sledgehammer to crack a nut - but it's a nut that needs smashing, and fast.
Interestingly, Microsoft has dropped Gadgets from the upcoming Windows 8. In retrospect, that was probably a very good idea.
14 May 2012
FixMeStick: USB device for removing malware
FixMeStick has launched the first ever, consumer-ready USB device for removing viruses from infected PCs.

The principles of the FixMeStick are not new to security IT professionals: multiple anti-virus engines increase the number of detectable viruses, and clean external scanning devices prevent viruses from hiding or from interfering with their removal. But, for the first time, FixMeStick has built these principles into a ready-to-go USB device.
"This is about enabling everyone to rid their machines of malware," says co-founder Marty Algire. "And it will help people continue to enjoy their computers and the Internet."
The FixMeStick costs $49.99 for an unlimited number of uses on three PCs per year. Renewals can be purchased for $24.99 annually.
The FixMeStick is powered by three of the biggest names in anti-virus software: Kaspersky Lab, Sophos, and GFI.
"This collaboration will allow organizations and their users to significantly minimize the impact of a malware infection," stresses Michael Rogers, Vice President, Global Alliances & OEM at Sophos.

The principles of the FixMeStick are not new to security IT professionals: multiple anti-virus engines increase the number of detectable viruses, and clean external scanning devices prevent viruses from hiding or from interfering with their removal. But, for the first time, FixMeStick has built these principles into a ready-to-go USB device.
"This is about enabling everyone to rid their machines of malware," says co-founder Marty Algire. "And it will help people continue to enjoy their computers and the Internet."
The FixMeStick costs $49.99 for an unlimited number of uses on three PCs per year. Renewals can be purchased for $24.99 annually.
The FixMeStick is powered by three of the biggest names in anti-virus software: Kaspersky Lab, Sophos, and GFI.
"This collaboration will allow organizations and their users to significantly minimize the impact of a malware infection," stresses Michael Rogers, Vice President, Global Alliances & OEM at Sophos.
Subscribe to:
Posts (Atom)


