<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AndrewSaysHello.com &#187; malware</title>
	<atom:link href="http://www.andrewsayshello.com/tag/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.andrewsayshello.com</link>
	<description>Andrew&#039;s Website for Lots-o-Fun and Junk!</description>
	<lastBuildDate>Wed, 24 Aug 2011 19:20:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>More Mac Malware and Some Top Tips For Avoiding Infection!</title>
		<link>http://www.andrewsayshello.com/technology/more-mac-malware-and-some-top-tips-for-avoiding-infection/</link>
		<comments>http://www.andrewsayshello.com/technology/more-mac-malware-and-some-top-tips-for-avoiding-infection/#comments</comments>
		<pubDate>Tue, 07 Jun 2011 13:45:16 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[mac shield]]></category>
		<category><![CDATA[macshield]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[scareware]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1974</guid>
		<description><![CDATA[More Mac scareware is continuing to pop up which seems almost daily, with the cybercrooks following the same sort of strategy which has worked so well on Windows: regularly change the look and feel of the fake anti-virus software; use legitimate-sounding brand names (or steal genuine product names); stick to a price-point between $50 and [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/more-mac-malware-and-some-top-tips-for-avoiding-infection/"></g:plusone></div><p><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/06/apple-logo.jpg" rel="lightbox[1974]"><img class="alignright size-medium wp-image-1980" title="apple-logo" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/06/apple-logo-248x300.jpg" alt="" width="248" height="300" /></a>More Mac scareware is continuing to pop up which seems almost daily, with the cybercrooks following the same sort of strategy which has worked so well on Windows: regularly change the look and feel of the fake anti-virus software; use legitimate-sounding brand names (or steal genuine product names); stick to a price-point between $50 and $100; keep the fear factor high; but keep the core programming very similar so development costs are negligible.</p>
<p>Scareware, or fake anti-virus, is fake security software which pretends to find dangerous security threats &#8211; such as viruses &#8211; on your computer. The initial scan is free, but if you want to clean up the fraudulently-reported &#8220;threats&#8221;, you need to pay.</p>
<p>Once you&#8217;ve paid, the scareware stops lying to you about the non-existent threats, as though it really did clean them up. This means that many victims of this sort of fraud don&#8217;t even realise they&#8217;ve been duped. Until next time.</p>
<p>These latest OS X scareware variants come from the MacDefender group, though they identify themselves during startup as Mac Shield:</p>
<div id="attachment_1975" class="wp-caption aligncenter" style="width: 418px"><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/06/macshield.png" rel="lightbox[1974]"><img class="size-full wp-image-1975" title="mac shield loading screen" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/06/macshield.png" alt="" width="408" height="158" /></a><p class="wp-caption-text">Mac Shield loading screen.</p></div>
<p>Once activated, the software pretends to look through your files, pretends to find malware, and invites you to clean up:</p>
<div id="attachment_1976" class="wp-caption aligncenter" style="width: 475px"><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/06/macshield2.png" rel="lightbox[1974]"><img class="size-full wp-image-1976" title="mac shield viruses" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/06/macshield2.png" alt="" width="465" height="116" /></a><p class="wp-caption-text">Mac Shield Virus Scan</p></div>
<p>But the cleanup isn&#8217;t free &#8211; you&#8217;re required to register:</p>
<div id="attachment_1977" class="wp-caption aligncenter" style="width: 452px"><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/06/macshield3.png" rel="lightbox[1974]"><img class="size-full wp-image-1977" title="mac shield registration" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/06/macshield3.png" alt="mac shield registration" width="442" height="108" /></a><p class="wp-caption-text">Mac Shield registration screen.</p></div>
<p>Registration means payment. The minimum you can get away with is $59.95. But for just $40 more, you can get a lifetime software licence and lifetime support &#8211; which would be a good deal, were it not for the fact that the software is completely fraudulent, that the &#8220;lifetime&#8221; of the software ends tomorrow when the crooks move on to the next bogus brand name, and that there&#8217;s nothing to support, since there was no malware in the first place.</p>
<p>You even get a 30-day money back guarantee. Good luck claiming it.</p>
<p>Here are some top anti-scareware tips for Apple users:</p>
<p>* <strong>If you use Safari, <a href="http://nakedsecurity.sophos.com/2011/05/26/use-safari-on-your-mac-make-sure-you-change-the-default-settings/">turn OFF</a> the <em>open &#8220;safe&#8221; files after downloading</em>option.</strong> This stops files such as the ZIP-based installers favoured by scareware authors from running automatically if you accidentally click their links.</p>
<p>* <strong>Don&#8217;t rely on Apple&#8217;s built-in <a href="http://nakedsecurity.sophos.com/2009/08/28/apples-integrated-antimalware-feature-xprotect/">XProtect</a> malware detector.</strong> It&#8217;s better than nothing, but it only detects viruses using basic techniques, and under a limited set of conditions. For example, malware on a USB key would go unnoticed, as would malware already on your Mac. And it only updates once in 24 hours, which probably isn&#8217;t enough any more.</p>
<p>* <strong>Install genuine anti-virus software.</strong> Ironically, the Apple App Store is a bad place to look &#8211; any anti-virus sold via the App Store is required by Apple&#8217;s rules to exclude the kernel-based filtering component (known as a real-time or on-access scanner) needed for reliable virus prevention.</p>
<p>* <strong>Religiously refuse any anti-malware software which offers a free scan but forces you to pay for cleanup.</strong> Reputable brands don&#8217;t do this &#8211; an anti-virus evaluation should let you try out detection <em>and</em> disinfection before you buy.</p>
<p>If you would like to try a great free version of a REAL anti-virus software package for free, Sophos has a great free product you can try out <a href="http://www.sophos.com/en-us/products/free-tools/sophos-antivirus-for-mac-home-edition.aspx">here</a>.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/more-mac-malware-and-some-top-tips-for-avoiding-infection/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Rogue AV Malware Starts Using Alternate Browser Internals!</title>
		<link>http://www.andrewsayshello.com/technology/rogue-av-malware-starts-using-alternate-browser-internals/</link>
		<comments>http://www.andrewsayshello.com/technology/rogue-av-malware-starts-using-alternate-browser-internals/#comments</comments>
		<pubDate>Thu, 03 Mar 2011 13:58:00 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[apple safari]]></category>
		<category><![CDATA[fake antivirus]]></category>
		<category><![CDATA[fake av]]></category>
		<category><![CDATA[google chrome]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[mozilla firefox]]></category>
		<category><![CDATA[scareware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1889</guid>
		<description><![CDATA[For years, ads pimping malware disguised as legitimate antivirus programs have gone to great lengths to mimic the look and feel of Microsoft&#8217;s Internet Explorer browser and Windows operating system. Now Mozilla Firefox, Google Chrome, and Apple Safari are getting the same treatment. A security researcher from Zscaler has recently uncovered a campaign that&#8217;s tailored [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/rogue-av-malware-starts-using-alternate-browser-internals/"></g:plusone></div><p>For years, ads pimping malware disguised as legitimate antivirus programs have gone to great lengths to mimic the look and feel of Microsoft&#8217;s Internet Explorer browser and Windows operating system. Now Mozilla Firefox, Google Chrome, and Apple Safari are getting the same treatment.</p>
<p>A security researcher from Zscaler has recently uncovered a campaign that&#8217;s tailored to the browser that the intended victim is using. Those with IE will see the same tired graphic depicting a Windows 7 security alert, but look what happens when the visitor is using Firefox.</p>
<div id="attachment_1890" class="wp-caption aligncenter" style="width: 410px"><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/03/firefox_warning.png" rel="lightbox[1889]"><img class="size-full wp-image-1890" title="firefox warning" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/03/firefox_warning.png" alt="" width="400" height="303" /></a><p class="wp-caption-text">Fake Warning in Firefox</p></div>
<p>Not only does the image contain internal Firefox elements in the source code, it also spoofs the security warning the browser shows when users attempt to navigate to an address known to be malicious, said Julien Sobrier, a senior security researcher at Zscaler.</p>
<p>When the intended mark visits the page with Chrome, the ruse looks altogether different. The first screen shows a warning window bearing the browser&#8217;s distinctive logo and the words “Chrome Security has found critical process activity on your system and will perform fast scan of system files.”</p>
<div id="attachment_1891" class="wp-caption aligncenter" style="width: 392px"><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/03/chrome_warning.png" rel="lightbox[1889]"><img class="size-full wp-image-1891" title="chrome warning" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/03/chrome_warning.png" alt="" width="382" height="158" /></a><p class="wp-caption-text">Fake Google Chrome warning</p></div>
<p>The user then sees what purports to be a Chrome window showing a virus scan.</p>
<div id="attachment_1892" class="wp-caption aligncenter" style="width: 410px"><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/03/chrome_scan.png" rel="lightbox[1889]"><img class="size-full wp-image-1892" title="chrome scan" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/03/chrome_scan.png" alt="" width="400" height="333" /></a><p class="wp-caption-text">Fake scan in Google Chrome</p></div>
<p>Not to be left out, Safari is also spoofed, although with significantly less effort. The initial warning looks like this:</p>
<div id="attachment_1894" class="wp-caption aligncenter" style="width: 410px"><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/03/safari_warning.png" rel="lightbox[1889]"><img class="size-full wp-image-1894" title="safari warning" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/03/safari_warning.png" alt="" width="400" height="156" /></a><p class="wp-caption-text">Fake Safari warning</p></div>
<p>But the scan page defaults to the look and feel of IE.</p>
<p>The ads are an attempt to trick visitors into believing they have infections that can be cured by the software being offered in the ad. By customizing the screens to the browser, it stands to reason, malware mongers stand a better chance of succeeding.</p>
<blockquote><p>“I&#8217;ve seen malicious pages tailored in the past, but they were mostly fake Flash updates or fake codec upgrades for Internet Explorer and Firefox,” Sobrier said. “I&#8217;ve never seen targeted fake AV pages for so many different browsers.”</p></blockquote>
<p>Some of the sites that redirect to the scam include columbia.faircitynews.com, www.troop391.org, jmvcorp.com. When successful, the redirected page pushes the file InstallInternetDefender_xxx.exe, where “xxx” is a number that changes frequently. At time of writing, it was detected as malicious by just 9.5 percent of the major (legitimate) AV packages, according to a <a href="http://www.virustotal.com/file-scan/report.html?id=a52344814b68b7d3a3cdd5b7fb4f73f4b4b98e0caeed9c8c85ad52ff2e05e1ce-1299087679" target="_blank">VirusTotal scan</a>.</p>
<p>No doubt, many readers are savvy enough to spot scams like this, but what about poor Aunt Mildred, who has being told by a well-meaning relative to never, ever use the heavily targeted IE? Makes you realize why fake AV can be such a <a title="New Scareware Tactic Lures in More FAKEAV Buyers!" href="http://www.andrewsayshello.com/technology/new-scareware-tactic-lures-in-more-fakeav-buyers/">huge revenue generator</a>.</p>
<p>Sobrier, who blogged about his findings <a href="http://research.zscaler.com/2011/03/new-fake-av-page-uses-firefox-internals.html" target="_blank">here</a>, first spotted the customized ads on Monday.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/rogue-av-malware-starts-using-alternate-browser-internals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Updates AutoPlay to Help Combat USB Malware</title>
		<link>http://www.andrewsayshello.com/technology/microsoft-updates-autoplay-to-help-combat-usb-malware/</link>
		<comments>http://www.andrewsayshello.com/technology/microsoft-updates-autoplay-to-help-combat-usb-malware/#comments</comments>
		<pubDate>Wed, 09 Feb 2011 14:05:05 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[autorun]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[flash drive]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[usb]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[windows xp]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1858</guid>
		<description><![CDATA[Here&#8217;s some good news for anyone who has been struck by auto-running malware from a USB stick in the past. Microsoft has rolled-out an &#8220;important, non-security update&#8221; through Windows Update, changing the behaviour of Autorun when you plug a USB stick into your computer. Not sure what Autorun is? It&#8217;s the technology which causes a program [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/microsoft-updates-autoplay-to-help-combat-usb-malware/"></g:plusone></div><div id="attachment_1860" class="wp-caption alignright" style="width: 250px"><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/02/USB_Flash_Drive.png" rel="lightbox[1858]"><img class="size-medium wp-image-1860 " title="USB Flash Drive" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/02/USB_Flash_Drive-300x300.png" alt="" width="240" height="240" /></a><p class="wp-caption-text">USB Flash Drive</p></div>
<p>Here&#8217;s some good news for anyone who has been struck by auto-running malware from a USB stick in the past. Microsoft has rolled-out an &#8220;important, non-security update&#8221; through Windows Update, changing the behaviour of Autorun when you plug a USB stick into your computer.</p>
<p>Not sure what Autorun is? It&#8217;s the technology which causes a program to start automatically when you insert a CD or USB stick into your Windows PC. You may have spotted the Autorun.inf files in the root directory of your USB sticks and on CDs in the past.</p>
<p>It may sound like a neat idea, but a lot of malware (The <a href="http://www.andrewsayshello.com/technology/new-w32downadup-variant-spotted-by-symantec/">Conficker worm</a> would be perhaps the most infamous example) has exploited the technology to infect computers via USB sticks in the past.</p>
<p>The more recent versions of Windows, like Windows Vista and Windows 7, have made changes to the way that Autorun operates and this has helped fight the spread of Autorun malware. But older versions of Windows, such as Windows XP, were still often at risk.</p>
<p>In fact, in a <a title="Link to Microsoft blog post" rel="nofollow" href="http://blogs.technet.com/b/mmpc/archive/2011/02/08/breaking-up-the-romance-between-malware-and-autorun.aspx">blog post</a> published yesterday, Microsoft&#8217;s Holly Stewart presented statistics which suggested that &#8220;Windows XP users were nearly 10 times as likely to get infected by [Autorun malware] in comparison to Windows 7.&#8221;</p>
<div id="attachment_1859" class="wp-caption aligncenter" style="width: 488px"><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/02/autorun.jpg" rel="lightbox[1858]"><img class="size-full wp-image-1859  " title="autorun" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/02/autorun.jpg" alt="" width="478" height="287" /></a><p class="wp-caption-text">XP vs. 7 using Autorun.</p></div>
<p>Yesterday, Microsoft rolled out an update via its Windows Update infrastructure, to users running versions prior to Windows 7, which effectively prevents Autorun malware from automatically infecting computers without the user&#8217;s permission.</p>
<p>Note, however, that this isn&#8217;t the death of Autorun entirely. As Microsoft&#8217;s Adam Shostack explains on the <a title="Link to MSRC blog" rel="nofollow" href="http://blogs.technet.com/b/msrc/archive/2011/02/04/deeper-insight-into-the-security-advisory-967940-update.aspx">MSRC blog</a>, Autorun is still available for &#8220;shiny media&#8221; such as CDs and DVDs.</p>
<p>Hmm. I guess that will be welcome news for any misguided company which tries to emulate <a href="http://www.sophos.com/pressoffice/news/articles/2005/11/sonydrmpoll.html">Sony&#8217;s disastrous scheme</a> from 2005 where music CDs automatically installed a rootkit as part of their DRM copy protection.</p>
<p>All in all, though, Microsoft has done a good thing here. Autorun was never a necessary technology in my point of view, and its exploitation by malware made it a dangerous liability. Locking it in a windowless room, handing it a service revolver and appealing to its sense of decency is probably the best move that can we make.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/microsoft-updates-autoplay-to-help-combat-usb-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Shortened URLs Are in High Use by Spammers!</title>
		<link>http://www.andrewsayshello.com/technology/shortened-urls-are-in-high-user-by-spammers/</link>
		<comments>http://www.andrewsayshello.com/technology/shortened-urls-are-in-high-user-by-spammers/#comments</comments>
		<pubDate>Sun, 02 Jan 2011 17:21:43 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[messagelabs]]></category>
		<category><![CDATA[short urls]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam message]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[url shortener spam]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1784</guid>
		<description><![CDATA[Shortened URLs included in garden-variety emails and tweets are harder for antivirus and antispam applications to weed out, giving hackers another lucrative avenue to spread spam quickly and with much greater efficiency. That&#8217;s the word from security software vendor Symantec (NASDAQ: SYMC), which dedicated most of its July MessageLabs Intelligence report to the pesky shortened URLs [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/shortened-urls-are-in-high-user-by-spammers/"></g:plusone></div><p><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/01/spam.png" rel="lightbox[1784]"><img class="alignright size-full wp-image-1813" title="spam" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2011/01/spam.png" alt="" width="210" height="210" /></a>Shortened URLs included in garden-variety emails and tweets are harder for antivirus and antispam applications to weed out, giving hackers another lucrative avenue to spread spam quickly and with much greater efficiency.</p>
<p>That&#8217;s the word from security software vendor Symantec (NASDAQ: SYMC), which dedicated most of its July MessageLabs Intelligence report to the pesky shortened URLs that are pretty much a prerequisite for quickly sharing links to stories, tweets and images on Twitter and other microblogging services.</p>
<p>Symantec&#8217;s report found that shortened-hyperlink spam hit a one-day peak of 18 percent of all spam emails on April 30, a total of more than 23.4 billion messages in one 24-hour period.</p>
<p>More troubling, Symantec security experts said, is the recent trend showing that shortened, spam-laden URLs are becoming as much a fabric of the spam culture as come-ons from Nigerian royalty and shady pharmaceutical dispensaries.</p>
<p>In the second quarter of last year, Symantec found that there was one day out of the three-month span during which shortened hyperlinks appeared in more than 1 in 200 spam messages. This year, however, there were 43 days when shortened URLs with spam accounted for 0.5 percent of all spam traffic and 10 days when the total surged to more than 5 percent of all spam messages.</p>
<p>&#8220;As far as spammers are concerned, any tactics that make it harder to block their spam emails are going to be exploited,&#8221; Paul Wood, a senior analyst at Symantec&#8217;s MessageLabs, said in the report.</p>
<p>&#8220;When spammers include a shortened URL in spam messages, these shortened hyperlinks contain reputable and legitimate domains, making it harder for traditional antispam filters to identify the messages as spam based on the reputation of the domains found in the spam emails,&#8221; he added.</p>
<p>This <a href="http://www.internetnews.com/security/article.php/3840996/Twitter-URLs-Again-Under-Siege-by-Hackers.htm">alarming influx of shortened URLs containing spam and malware</a> was to be expected, security experts say, as more and more people embrace Twitter, its messages&#8217; 140-character limit and the short URLs they often necessitate. And now that these shortened URLs with legitimate-looking domains are now being disseminated by botnets, the spammers are increasing their infection rate and generating lots of ill-gotten revenue.</p>
<p>Symantec&#8217;s surveillance revealed that the <a href="http://www.internetnews.com/security/article.php/3802331">infamous Storm botnet</a>, which reemerged in May, is the main source of malicious shortened URLs, accounting for some 11.8 percent of spam in the category.</p>
<p>&#8220;While botnets are often the source of short URL spam, 28 percent of this type of spam originated from sources not linked to a known botnet, such as unidentified spam-sending botnets or non-botnet sources, such as webmail accounts created using CAPTCHA-breaking tools,&#8221; Wood added.</p>
<p>The report discovered that that on average, one website visit is generated for every 74,000 spam emails containing a shortened URL link and the most frequently visited shortened links from spam received more than 63,000 website visits.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/shortened-urls-are-in-high-user-by-spammers/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Number Of Malware-Infected Websites Passes 1 Million!</title>
		<link>http://www.andrewsayshello.com/technology/number-of-malware-infected-websites-passes-1-million/</link>
		<comments>http://www.andrewsayshello.com/technology/number-of-malware-infected-websites-passes-1-million/#comments</comments>
		<pubDate>Mon, 04 Oct 2010 12:51:16 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Dasient]]></category>
		<category><![CDATA[drive-by download]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[infected website]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1609</guid>
		<description><![CDATA[According to a new report published in a blog last month by researchers at security firm Dasient, the number of websites infected by malware in the second quarter of 2010 spiked to more than 1.3 million &#8212; the first time that figure has ever topped 1 million. &#8220;That&#8217;s a jump of almost two times the number [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/number-of-malware-infected-websites-passes-1-million/"></g:plusone></div><div id="attachment_1611" class="wp-caption alignright" style="width: 310px"><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/10/InfectedSite.jpg" rel="lightbox[1609]"><img class="size-medium wp-image-1611" title="InfectedSite" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/10/InfectedSite-300x181.jpg" alt="" width="300" height="181" /></a><p class="wp-caption-text">Example of infected website warning.</p></div>
<p>According to <a href="http://blog.dasient.com/2010/09/continued-growth-in-web-based-malware_9357.html" target="new">a new report</a> published in a blog last month by researchers at security firm Dasient, the number of websites infected by malware in the second quarter of 2010 spiked to more than 1.3 million &#8212; the first time that figure has ever topped 1 million.</p>
<blockquote><p>&#8220;That&#8217;s a jump of almost two times the number that we saw in the previous quarter,&#8221; says Neil Daswani, co-founder of Dasient. &#8220;The numbers are really surprising.&#8221;</p></blockquote>
<p>Malware authors are becoming more efficient and creative in their methods of attacking websites, Dasient says. For one thing, they are creating new malware at an exceedingly rapid rate: Dasient detected more than 58,000 new infections in Q2 alone, raising its comprehensive malware library to more than 200,000 different infections.</p>
<p>Attackers are also becoming more crafty in the way they distribute their payloads, Daswani observes. For example, many malware authors have begun deploying new infections late on Friday afternoons, when they know most IT departmental resources will be at an ebb over the weekend.</p>
<p>&#8220;They can make the campaign last longer by starting it right before a weekend,&#8221; Daswani says. The average malvertising campaign in Q2, for example, lasted 11.5 days.</p>
<p>Malvertising itself continues to grow, Dasient says: More than 1.6 million malvertisements are served on an average day, up 20 percent in the second half of Q2, according to the report. Some 42 percent of websites rely on third-party advertising resources, yet many site operators do not vet this content for malware before they serve it, Daswani notes.</p>
<p>Attackers favored JavaScript over iFrames as a means of delivering malware in Q2, according to the report. &#8220;In Q2, over 43,000 JavaScripts and over 15,000 IFRAMEs were added to Dasient’s infection library,&#8221; Dasient says. &#8220;As a percentage of the total number of new entries, JavaScript samples have increased by 19 percent, and JavaScript samples now make up 74 percent of the entries for the quarter [as compared to 55 percent three quarters ago].&#8221;</p>
<blockquote><p>&#8220;One of the advantages of JavaScript is that it can be used to modify a whole Web page, whereas an iFrame is more limited,&#8221; Daswani says. &#8220;JavaScript offers a larger attack surface.&#8221;</p></blockquote>
<p>Attackers use .com and .cn domains most frequently to host malicious code, Dasient says. In Q2, there was a rise in .info domains that were infected and used to host malicious code, the report states.</p>
<p>Three out of four drive-by-downloads have one letter filenames and are written to the User&#8217;s Application Data directory, according to Dasient. The most common name for a drive-by-download was f.exe.</p>
<p>The level of attack sophistication is going to only increase over time, Daswani says. &#8220;This is a problem that isn&#8217;t slowing down,&#8221; he says. &#8220;It&#8217;s not going away.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/number-of-malware-infected-websites-passes-1-million/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dell Warns on Spyware Infected Server Motherboards!</title>
		<link>http://www.andrewsayshello.com/technology/dell-warns-on-spyware-infected-server-motherboards/</link>
		<comments>http://www.andrewsayshello.com/technology/dell-warns-on-spyware-infected-server-motherboards/#comments</comments>
		<pubDate>Sun, 25 Jul 2010 13:41:48 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[dell]]></category>
		<category><![CDATA[firmware]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[motherboard]]></category>
		<category><![CDATA[poweredge]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1457</guid>
		<description><![CDATA[The PowerEdge R410 Rack server has spyware within its embedded systems management software. The direct seller is sending customers letters warning of the danger and also telephoning those affected. A post in a support forum says customers should hear from Dell shortly. It does not provide any technical explanation of what type of spyware is included [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/dell-warns-on-spyware-infected-server-motherboards/"></g:plusone></div><p><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/07/dell.jpg" rel="lightbox[1457]"><img class="alignright size-medium wp-image-1458" title="dell" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/07/dell-300x225.jpg" alt="" width="300" height="225" /></a>The PowerEdge R410 Rack server has spyware within its embedded systems management software. The direct seller is sending customers letters warning of the danger and also telephoning those affected.</p>
<p>A post in a support forum says customers should hear from Dell shortly. It does not provide any technical explanation of what type of spyware is included with the hardware or what extra cleaning process customers should go through.</p>
<p>Some forms of malware are likely to have spread if the hardware has been attached to a network. The forum post, from yesterday morning, is <a href="http://en.community.dell.com/support-forums/servers/f/956/t/19339458.aspx" target="_blank">here</a>.</p>
<p>The forum poster was concerned not to have more technical information &#8211; and that the call he received to book technical support said the call might not happen for up to ten days.</p>
<p>In response a Dell support staffer said there was an issue with a small number of service motherboard stock &#8211; new PowerEdge systems are not infected. He said the malware would not infect non-Windows servers.</p>
<p>Dell has also sent out the following statement:</p>
<blockquote><p>“Dell is aware of the issue and is contacting affected customers. The issue affects a limited number of replacement motherboards in four servers &#8211; PowerEdge R310, PowerEdge R410, PowerEdge R510 and PowerEdge T410 – and only potentially manifests itself when a customer has a specific configuration and is not running current anti-virus software.</p>
<p>This issue does not affect systems as shipped from our factory and is limited to replacement parts only. Dell has removed all impacted motherboards from its service supply chain and new shipping replacement stock does not contain the malware.</p>
<p>Customers can find more information on Dell’s community forum.” – Forrest Norrod, vice president and general manager of server platforms at Dell.</p></blockquote>
<p>Fortunately the forum has also been updated with information which answers some of the relevant questions &#8211; the malware was found in the flash on motherboards, not in firmware. It is a W32.Spybot worm which should be detected by any decent anti-virus software.</p>
<p>Dell said that less than one per cent of boards shipped have the infection. Systems using an iDRAC Express or iDRAC Enterprise card will not be damaged. In fact systems will only be hit if you run an update to either Unified Server Configurator (USC) or 32-bit Diagnostics.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/dell-warns-on-spyware-infected-server-motherboards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Pirate Bay Hacked, Attackers Gain Access To Entire User Database!</title>
		<link>http://www.andrewsayshello.com/technology/the-pirate-bay-hacked-attackers-gain-access-to-entire-user-database/</link>
		<comments>http://www.andrewsayshello.com/technology/the-pirate-bay-hacked-attackers-gain-access-to-entire-user-database/#comments</comments>
		<pubDate>Fri, 09 Jul 2010 12:38:08 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[krebsonsecurity]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[mpaa]]></category>
		<category><![CDATA[riaa]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[the pirate bay]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1375</guid>
		<description><![CDATA[A series of attacks on The Pirate Bay, one of the most well known and controversial file-sharing websites has allowed a group of Argentinian hackers, headed by malware researcher Ch Russo, to access both the user database and the website administration panel of The Pirate Bay, comprising over 4 million usernames and email addresses in the [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/the-pirate-bay-hacked-attackers-gain-access-to-entire-user-database/"></g:plusone></div><div id="attachment_1377" class="wp-caption alignright" style="width: 310px"><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/07/TPB.jpg" rel="lightbox[1375]"><img class="size-medium wp-image-1377" title="TPB" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/07/TPB-300x225.jpg" alt="" width="300" height="225" /></a><p class="wp-caption-text">The Pirate Bay</p></div>
<p>A series of attacks on <a href="http://www.thepiratebay.org/">The Pirate Bay</a>, one of the most well known and controversial file-sharing websites has allowed a group of Argentinian hackers, headed by malware researcher Ch Russo, to access both the user database and the website administration panel of The Pirate Bay, comprising over 4 million usernames and email addresses in the process.</p>
<p>It is thought that the group first targeted the website administration panel on The Pirate Bay, the group succeeded and then employed a series of SQL injection vulnerabilities to gain access to the user database, where they were able to add and amend records and obtain information to identify trackers and torrents uploaded by specific users.</p>
<p>Ch Russo posted a cryptic message on <a href="http://insilence.biz/2010/07/multiple-sql-injections-on-the-pirate-bay/">his blog</a> detailing reasons behind the attack:</p>
<blockquote><p>As any other website, as any other system or mechanism, www.thepiratebay.org has robust parts and soft spots. We beleive that the people behind this comunity always acted with the local laws on their side, and so have we. The community caused problems to huge companies and corporations which turned into threats between this companies and them. What we have done, we did not do it with anger, or for commercial value. As always, we saw the change, the moment and decided to take it. The protocol or procedure done to achieve this wasn’t anything out of the ordinary.</p></blockquote>
<p>As you can see, Russo acknowledges that the data would be of huge interest to anti-piracy groups like the Recording Industry Association of America (RIAA) and the Motion Picture Association of America (MPAA). In a telephone interview with <a href="http://www.krebsonsecurity.com/" target="_blank">KrebsOnSecurity</a> he said: “Probably these groups would be very interested in this information, but we are not [trying] to sell it,” adding “Instead we wanted to tell people that their information may not be so well protected.”</p>
<div id="attachment_1376" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/07/TPB-backend.png" rel="lightbox[1375]"><img class="size-medium wp-image-1376" title="TPB-backend" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/07/TPB-backend-300x224.png" alt="" width="300" height="224" /></a><p class="wp-caption-text">Screenshot of the backend of The Pirate Bay</p></div>
<p>According to <a href="http://news.softpedia.com/news/The-Pirate-Bay-Hacked-146668.shtml">Softpedia</a>, the attackers have not been in contact with The Pirate Bay administrators since the attack but the offending weakness has since been identified and patched.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/the-pirate-bay-hacked-attackers-gain-access-to-entire-user-database/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lenovo Support Page Compromise Leads to BREDOLAB Trojan!</title>
		<link>http://www.andrewsayshello.com/technology/lenovo-support-page-compromise-leads-to-bredolab-trojan/</link>
		<comments>http://www.andrewsayshello.com/technology/lenovo-support-page-compromise-leads-to-bredolab-trojan/#comments</comments>
		<pubDate>Wed, 23 Jun 2010 12:04:18 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[bkis]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[bredolab]]></category>
		<category><![CDATA[fakeav]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[lenovo]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[pushdo]]></category>
		<category><![CDATA[trend micro]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[zbot]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1330</guid>
		<description><![CDATA[Chinese PC manufacturer Lenovo is the latest high-profile company to be compromised. Sometime over the past weekend, its support pages, which allowed users to download drivers and manuals, were compromised with the addition of a malicious iframe. The website in this malicious iframe led to the download of a BREDOLAB variant detected as TROJ_BREDOLAB.BY (by Trend Micro). This malware [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/lenovo-support-page-compromise-leads-to-bredolab-trojan/"></g:plusone></div><p>Chinese PC manufacturer Lenovo is the latest high-profile company to be <strong><span style="font-weight: normal;">compromised.</span></strong> Sometime over the past weekend, its support pages, which allowed users to download drivers and manuals, were compromised with the addition of a malicious iframe.</p>
<p>The website in this malicious iframe led to the download of a <strong>BREDOLAB</strong> variant detected as <a href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_BREDOLAB.BY">TROJ_BREDOLAB.BY</a> (by Trend Micro). This malware family is well-known for being a downloader of other malware onto affected systems, particularly ZBOT and FAKEAV variants.</p>
<p>BREDOLAB first gained prominence in late 2009 when the number of reported infections significantly grew. <a href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/bredolab_final.pdf">Upon investigation</a> by senior advanced threats researcher David Sancho, it was found that BREDOLAB was a new malware family similar to earlier PUSHDO variants.</p>
<p>Later investigations by senior advanced threats researcher Loucif Kharouni established the key role BREDOLAB plays in the criminal underworld. As mentioned earlier, cybercriminals running pay-per-install (PPI) scams frequently use BREDOLAB to infect user systems.</p>
<div id="attachment_1331" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/06/botnet_model.jpg" rel="lightbox[1330]"><img class="size-medium wp-image-1331" title="botnet_model" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/06/botnet_model-300x230.jpg" alt="" width="300" height="230" /></a><p class="wp-caption-text">Botnet Model</p></div>
<p>Lenovo has acknowledged the incident <a href="http://forums.lenovo.com/t5/General-Discussion/Warning-Lenovo-download-site-is-infected-by-trojan-downloader/td-p/241901">on its official forum</a> and has indicated that the affected pages have now been cleaned. Reports from Vietnamese antivirus vendor <a href="http://cyberinsecure.com/lenovo-support-website-loads-malicious-iframe-infects-visitors-with-trojan/">Bkis</a> indicated that the pages have been infected since at least Sunday afternoon. Some users also reported getting antivirus warnings while visiting Lenovo’s download website since Saturday.</p>
<p>Users who did go to the Lenovo pages to download support materials from late on June 18 (Friday) to June 21 (Monday) may have been affected by this compromise and should check their systems accordingly.</p>
<p>This further proves the point that you should always have an antivirus program running on your computer at all times (and make sure its updated as well!). Even websites that you think are safe can fall victim to these types of attacks leaving everyone at risk. So be safe out there&#8230; cause the internet is one crazy place!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/lenovo-support-page-compromise-leads-to-bredolab-trojan/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Malware has Begun Multiplying on Smartphones!</title>
		<link>http://www.andrewsayshello.com/technology/malware-has-begun-multiplying-on-smartphones/</link>
		<comments>http://www.andrewsayshello.com/technology/malware-has-begun-multiplying-on-smartphones/#comments</comments>
		<pubDate>Tue, 08 Jun 2010 12:33:17 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[blackberry]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[lookout]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[smartphone]]></category>
		<category><![CDATA[sms]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[Windows Mobile]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1268</guid>
		<description><![CDATA[The number of malware and spyware programs found on smartphones has more than doubled in the past six months &#8212; and some types of malware are more prevalent on certain smartphone platforms than others. New data gathered from users of a free smartphone security tool shows the bad guys are increasingly going after smartphone users. [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/malware-has-begun-multiplying-on-smartphones/"></g:plusone></div><p>The number of malware and spyware programs found on smartphones has more than doubled in the past six months &#8212; and some types of malware are more prevalent on certain smartphone platforms than others.</p>
<p>New data gathered from users of a free smartphone security tool shows the bad guys are increasingly going after smartphone users. According to Lookout, which offers a free lightweight mobile client with cloud-based security, backup, and anti-theft features, there were about nine pieces of malware and spyware per 100 smartphones as of last month &#8212; more than twice as many as in November 2009.</p>
<p>Even more worrisome is how rapidly these threats are hitting smartphones in comparison to the desktop: What took 15 years to evolve with the desktop machine is happening practically overnight in mobile handsets, security experts say. &#8220;We call this the 1999 factor: It feels like about 10 years ago in terms of prevalence of threats. There was a tipping point between 2000 and 2002 [for PC threats] that was driven by broadband&#8221; and more consumers going online, according to John Hering, CEO and founder of Lookout, formerly Flexilis. &#8220;The same trends are going to hold true here [with smartphones].&#8221;</p>
<p>Tyler Shields, senior security researcher with Veracode, says he has seen a definite uptick in malware arriving for smartphones during the past few months. &#8220;It&#8217;s coming at a much faster rate now. It&#8217;s difficult to quantify the amount of growth,&#8221; however, he says. Shields earlier this year developed and released proof-of-concept source code for a spyware app he created that forces a BlackBerry to hand over its contacts and messages. The spyware can also can grab text messages, listen in on the victim, as well as track his physical location via the phone&#8217;s GPS.</p>
<p>Spyware is the main type of malware Lookout sees being created for BlackBerrys, while Windows Mobile phones suffer more from traditional malware, and Androids from a little of both, according to Lookout&#8217;s data. &#8220;We&#8217;re seeing a pretty equal spread [of the threats] across these platforms,&#8221; Lookout&#8217;s Hering says. The firm doesn&#8217;t yet support the Apple iPhone in its app, so data on the iPhone isn&#8217;t included.</p>
<p>Why mostly spyware on the BlackBerry? Veracode&#8217;s Shields says it might be due to the heavy corporate use of BlackBerrys, which would make any data lifted from them more easily monetized. &#8220;The type of data on a BlackBerry generally is going to be corporate-centric and could be of interest to attackers,&#8221; he says.</p>
<p>A recent malware attack against Windows Mobile phones basically took an existing, legitimate smartphone app and booby-trapped it with malware: The 3D Anti-Terrorist app game for Windows Mobile was rewritten with auto-dialer malware, according to Lookout&#8217;s Hering. The app basically fires up the auto-dialer malware when the user runs the game. &#8220;It sits dormant for hours or days, and then wakes up and calls numbers at a premium rate &#8212; from Somalia to the South Pole,&#8221; for instance, he says. &#8220;The victim is then incurring charges but doesn&#8217;t notice until [he] receives the phone bill.&#8221;</p>
<p>A Windows codec and poker app also were hijacked, copied, and repackaged with malware. The apps are being distributed via typical mobile download and app store sites, such as sharewareplaza.com, geardownload.com, myzips.com, and top4download.com. &#8220;We&#8217;re seeing the same evolution on mobile as on the desktop: It&#8217;s going from notoriety [purposes] to trying to profit,&#8221; Hering says.</p>
<p>The malware attack vector being used against smartphones isn&#8217;t the SMS or email spam that was all the rage in the early days of mobile attacks. Instead, it&#8217;s following smartphone user behavior trends and exploiting downloadable applications, experts say. &#8220;Users are downloading apps at a huge pace,&#8221; Hering says.</p>
<p>And smartphones are actually more &#8220;personal&#8221; than PCs. They include GPS location, payment information, email, text messages, and records of who a user communicates with. Hering says today&#8217;s smartphone malware is all about grabbing personal information and, now, attempting to monetize it. &#8220;On the spyware side, you can imagine an app grabbing personal data that you&#8217;re unaware of [occurring] and transmitting that to a third-party location&#8221; where it can be resold, for example, he says.</p>
<p>Meanwhile, enterprises should be aware of the risks of breaches via their smartphone users. &#8220;They should be worried about this,&#8221; Hering says.</p>
<p>But the likelihood of another Operation Aurora-scale targeted attack isn&#8217;t as likely to hit via the smartphone just yet: &#8220;At this point in time, the PC [attack] model is so much easier and faster. I don&#8217;t foresee that level of coordination to target mobile devices at this point,&#8221; Veracode&#8217;s Shields says.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/malware-has-begun-multiplying-on-smartphones/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Malware Writers Are Now Renting Out Botnets!</title>
		<link>http://www.andrewsayshello.com/technology/malware-writers-are-now-renting-out-botnets/</link>
		<comments>http://www.andrewsayshello.com/technology/malware-writers-are-now-renting-out-botnets/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 14:36:47 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[fake antivirus]]></category>
		<category><![CDATA[for sale]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[rent]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[zombie]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1255</guid>
		<description><![CDATA[Have you got $67 burning a hole in your pocket? Then you can rent a botnet for 24 hours to launch distributed denial of service (DDoS) attacks, sell fake antivirus software and relay spam to unsuspecting email users via millions of compromised &#8212; aka zombie &#8212; PCs. Or if you only need an hour, that’s [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/malware-writers-are-now-renting-out-botnets/"></g:plusone></div><div id="attachment_1256" class="wp-caption alignright" style="width: 310px"><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/06/malware.gif" rel="lightbox[1255]"><img class="size-full wp-image-1256 " title="malware" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/06/malware.gif" alt="" width="300" height="380" /></a><p class="wp-caption-text">Is your computer secure?</p></div>
<p>Have you got $67 burning a hole in your pocket? Then you can rent a botnet for 24 hours to launch distributed denial of service (DDoS) attacks, sell fake antivirus software and relay spam to unsuspecting email users via millions of compromised &#8212; aka zombie &#8212; PCs. Or if you only need an hour, that’s just $9.</p>
<p>Those findings come from iDefense VeriSign’s security intelligence service, which studied 25 black market botnet offerings. Based on the company’s research, botnets are becoming increasingly commoditized, with sellers freely hawking their wares via online forums and banner advertising.</p>
<p>“Organizations need to be wary of the fact that their critical online applications or services could be taken down in under a day by a criminal renting services from bot herders,” said Rick Howard, director of intelligence at iDefense, in a statement.</p>
<p>Unfortunately, the easy access to botnets, as well as the emergence of more automated botnet software, has lowered the botnet barrier to entry for less technologically inclined or well-connected criminals.</p>
<p>In March, for example, Spanish police arrested the three alleged masterminds behind the Marisposa botnet, which ran undetected for six months, compromising more than 12 million PCs, many at blue-chip firms and banks.</p>
<blockquote><p>“Our preliminary analysis indicates that the botmasters did not have advanced hacking skills,” Pedro Bustamante, senior research adviser with Panda Security, told the Guardian. “This is very alarming because it proves how sophisticated and effective malware distribution software has become, empowering relatively unskilled cyber criminals to inflict major damage and financial loss.”</p></blockquote>
<p>Mariposa may now be defect, but one of the most well-known botnet tools, Zeus, is still alive and well. According to a recent report from managed security services provider SecureWorks, “Zeus is sold in the criminal underground as a kit for around $3,000-4,000, and is likely the one malware most utilized by criminals specializing in financial fraud.”</p>
<p>Customize Zeus with numerous add-ons: virtual networking to take over an infected PC ($10,000), an upgrade for attacking Windows 7 or Vista ($2,000), Jabber IM broadcasting to receive stolen data in real time ($500), a Firefox form grabber ($2,000) and a back-connect module for making financial transactions from an infected PC ($1,500). Interestingly, the Zeus application also includes sophisticated anti-piracy features.</p>
<p>If the going rate for renting a botnet or buying the right software seems steep, antivirus vendor Sunbelt recently said that it’s been tracking a Twitter-controlled botnet that can be used to launch DDoS attacks. Dubbed TwitterNET Builder, the tool &#8212; available at no charge &#8212; lets an attacker simply enter a Twitter username and hit “build” to generate the required malware.</p>
<p>Thankfully, the tool’s reliance on public Twitter commands for control means that attackers get what they pay for. “We’ve notified Twitter about this bot creation system, and they’re looking into it,” said Boyd. In other words, don’t try this at home.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/malware-writers-are-now-renting-out-botnets/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>FTC Shuts Doors On Notorious Rogue Internet Service Provider!</title>
		<link>http://www.andrewsayshello.com/technology/ftc-shuts-doors-on-notorious-rogue-internet-service-provider/</link>
		<comments>http://www.andrewsayshello.com/technology/ftc-shuts-doors-on-notorious-rogue-internet-service-provider/#comments</comments>
		<pubDate>Thu, 27 May 2010 13:30:45 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[3fn]]></category>
		<category><![CDATA[3fn.net]]></category>
		<category><![CDATA[aps communication]]></category>
		<category><![CDATA[aps communications]]></category>
		<category><![CDATA[aps telecom]]></category>
		<category><![CDATA[apx telecom]]></category>
		<category><![CDATA[bot herder]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[c&c server]]></category>
		<category><![CDATA[ftc]]></category>
		<category><![CDATA[isp]]></category>
		<category><![CDATA[malicious software]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[porn]]></category>
		<category><![CDATA[rogue Internet service provider]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[triple fiber network]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1205</guid>
		<description><![CDATA[At the Federal Trade Commission&#8217;s request, a district court judge has permanently shut down 3FN, a rogue Internet service provider that recruited, hosted, and actively participated in the distribution of spam, spyware, child pornography, and other illegal content. The ISP&#8217;s computer servers and other assets have been seized and will be sold by a court-appointed [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/ftc-shuts-doors-on-notorious-rogue-internet-service-provider/"></g:plusone></div><div id="attachment_1207" class="wp-caption alignright" style="width: 310px"><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/05/server-room.png" rel="lightbox[1205]"><img class="size-medium wp-image-1207" title="Server Room" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/05/server-room-300x225.png" alt="Example of a Server Room" width="300" height="225" /></a><p class="wp-caption-text">Example of a Server Room.</p></div>
<p>At the Federal Trade Commission&#8217;s request, a district court judge has permanently shut down 3FN, a rogue Internet service provider that recruited, hosted, and actively participated in the distribution of spam, spyware, child pornography, and other illegal content.</p>
<p>The ISP&#8217;s computer servers and other assets have been seized and will be sold by a court-appointed receiver. The operation has been ordered to turn over $1.08 million in ill-gotten gains to the FTC.</p>
<p>In June 2009, the FTC charged that 3FN, which does business under a variety of names, actively recruited and colluded with criminals to distribute harmful electronic content, including spyware, viruses, Trojan horses, phishing schemes, botnet command-and-control (C&amp;C) servers, and pornography. The FTC alleged that the defendant advertised its services in the darkest corners of the Internet, including a chat room for spammers.</p>
<p>The FTC complaint alleged that 3FN actively shielded its criminal clientele by either ignoring takedown requests issued by the online security community, or by shifting its criminal elements to other Internet protocol addresses it controlled to evade detection.</p>
<p>The FTC also alleged that 3FN deployed and operated botnets. According to the FTC, the defendant recruited bot herders and hosted the C&amp;C servers.</p>
<p>Transcripts of instant-message logs filed with the district court show the defendants&#8217; senior employees discussing the configuration of botnets with bot herders. And, in filings with the district court, the FTC alleged that more than 4,500 malicious software programs were controlled by C&amp;C servers hosted by 3FN.</p>
<p>This malware included programs capable of keystroke logging, password stealing, and data theft; programs with hidden backdoor remote control activity; and programs involved in spam distribution, the FTC said.</p>
<p>On June 15, 2009, the court issued a preliminary injunction to prohibit 3FN&#8217;s illegal activities and require its upstream Internet providers and data centers to stop providing services to 3FN.</p>
<p>The court has now ordered a permanent bar on the illegal activities of 3FN and its agents. It has appointed a receiver and instructed him to liquidate the operation&#8217;s assets.</p>
<p>The defendants named in the FTC&#8217;s complaint are Pricewert LLC, also doing business as 3FN.net, Triple Fiber Network, APS Telecom, APX Telecom, APS Communications, and APS Communication.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/ftc-shuts-doors-on-notorious-rogue-internet-service-provider/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Facebook &#8220;sexiest video&#8221; Malware Spreading Virally!</title>
		<link>http://www.andrewsayshello.com/technology/facebook-sexiest-video-malware-spreading-virally/</link>
		<comments>http://www.andrewsayshello.com/technology/facebook-sexiest-video-malware-spreading-virally/#comments</comments>
		<pubDate>Wed, 19 May 2010 16:00:51 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[adware]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hotbar]]></category>
		<category><![CDATA[ie6]]></category>
		<category><![CDATA[internet explorer]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[toolbar]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1180</guid>
		<description><![CDATA[If you get a posting on your Facebook wall telling you &#8220;this is without doubt the sexiest video ever! &#8221; which seems to be accompanied by a video titled &#8220;Candid Camera Prank [HQ]&#8221; then don&#8217;t click on the video: it&#8217;s a lead-in to malware. Clicking the link will take you to what seems like a [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/facebook-sexiest-video-malware-spreading-virally/"></g:plusone></div><p>If you get a posting on your Facebook wall telling you &#8220;this is without doubt the sexiest video ever! <img src='http://www.andrewsayshello.com/wordpress/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />  <img src='http://www.andrewsayshello.com/wordpress/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />  <img src='http://www.andrewsayshello.com/wordpress/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> &#8221; which seems to be accompanied by a video titled &#8220;Candid Camera Prank [HQ]&#8221; then don&#8217;t click on the video: it&#8217;s a lead-in to malware.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="500" height="340" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://www.youtube.com/v/YHbjed_BaGk&amp;rel=0&amp;color1=0xb1b1b1&amp;color2=0xd0d0d0&amp;hl=en_US&amp;feature=player_embedded&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="500" height="340" src="http://www.youtube.com/v/YHbjed_BaGk&amp;rel=0&amp;color1=0xb1b1b1&amp;color2=0xd0d0d0&amp;hl=en_US&amp;feature=player_embedded&amp;fs=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>Clicking the link will take you to what seems like a Facebook application which then tells you that your video player is out of date – and encourages you to download a file.</p>
<p>If you do, then the same &#8220;video&#8221; plus link gets posted using <em>your</em> avatar to al your friends on Facebook -– meaning it is spreading virally.</p>
<p>It&#8217;s not clear at present whether Facebook has acted to halt it. You should, however, expect that it will mutate in the coming hours/days (depending on how determined the virus writer is), so it might not be exactly that message or video frame. The key element in the attack is that it tells you to download a file.</p>
<p>At <a href="http://www.sophos.com/blogs/gc/g/2010/05/15/sexiest-video-facebook">Sophos, Graham Cluley notes</a> that:</p>
<blockquote><p>&#8220;Judging by the number of messages posted on Facebook, thousands of people received this attack. If you were one of them, you should scan your computer with an up-to-date anti-virus, change your passwords, review your Facebook application settings, and learn not to be so quick as to fall for a simple social engineering trick like this in future.&#8221;</p></blockquote>
<p>The file seems to install a piece of adware called <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Adware%3AWin32%2FHotbar">Hotbar</a>, which thus generates revenue for the malware writer. (About Hotbar: &#8220;displays a dynamic toolbar and targeted pop-up ads based on its monitoring of Web-browsing activity. The toolbar appears in Internet Explorer and Windows Explorer. The toolbar contains buttons that can change depending on the current Web page and keywords on the page. Clicking a button on the toolbar may open an advertiser Web site or paid search site. Hotbar also installs graphical skins for Internet Explorer, Outlook, and Outlook Express. Hotbar may collect user-related information and may silently download and run updates or other code from its servers.&#8221;)</p>
<p>Microsoft is, separately, <a href="http://www.microsoft.com/australia/technet/ie8milk/">strongly encouraging people and companies to stop using Internet Explorer 6</a>, using the argument that &#8220;you wouldn&#8217;t drink 9-year-old milk, so why use a 9-year-old browser?&#8221;</p>
<p>Though aimed at the Australian market (possibly IE6 has a higher prevalence there due to some geographical quirk), the arguments for abandoning IE6 are stronger than ever, and have been repeated many times – not least on this site (the browser that won&#8217;t die, why the NHS can&#8217;t get its browser act together). And of course it is widely believed – though so far not confirmed – that IE6 was the vector for an <a href="http://arstechnica.com/microsoft/news/2010/01/ie-flaw-used-in-chinese-attacks-on-google-patched-tomorrow.ars">attack against Google by Chinese hackers</a> at the end of last year.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/facebook-sexiest-video-malware-spreading-virally/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Symantec Warns of Cyber Attacks Worse Than Love Bug!</title>
		<link>http://www.andrewsayshello.com/technology/symantec-warns-of-cyber-attacks-worse-than-love-bug/</link>
		<comments>http://www.andrewsayshello.com/technology/symantec-warns-of-cyber-attacks-worse-than-love-bug/#comments</comments>
		<pubDate>Mon, 10 May 2010 02:12:59 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[love bug]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[messagelabs]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1141</guid>
		<description><![CDATA[A decade after the Love Bug virus attacked millions of computers worldwide and put the Philippines in the IT world map in a negative way, computer security experts have noticed that today&#8217;s computer attacks are more malicious than the original computer security threat. In its April 2010 security report, Symantec said it has detected 36,208 unique strains [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/symantec-warns-of-cyber-attacks-worse-than-love-bug/"></g:plusone></div><p>A decade after the Love Bug virus attacked millions of computers worldwide and put the Philippines in the IT world map in a negative way, computer security experts have noticed that today&#8217;s computer attacks are more malicious than the original computer security threat.</p>
<p>In its April 2010 security report, Symantec said it has detected 36,208 unique strains of malware that were designed to carry out targeted attacks.</p>
<p>MessageLabs, which was acquired by Symantec later, was the first one to raise the alert on the Love Bug virus, which was designed to overwrite and destroy data. The virus came in the form of a message attachment when, once opened, sent itself to the addresses of the email recipient and spread on from there.</p>
<p>Ten years since Symantec Hosted Services, then MessageLabs, intercepted 13,000 copies of the virus in a single day on 4 May 2000, MessageLabs Intelligence said it now stops 1.5 million copies of malicious e-mails each day.</p>
<p>&#8220;Although mass mailing viruses like the Love Bug are rare today, cyber criminals&#8217; techniques have evolved to more malicious, highly targeted attacks and they are motivated less by achievement and credibility than by financial gain and identity theft,&#8221; Symantec said in a statement. &#8220;On 4 May, 2000, 1 in 28 e-mails contained the Love Bug virus. By comparison, 1 in 287.2 e-mails contained a virus on 9 April 2010, the peak for April. In April 2010 overall, MessageLabs Intelligence intercepted 36,208 unique strains of malware.&#8221;</p>
<p>&#8220;The Love Bug was operating in the wake of the Melissa virus, a similarly destructive worm from the previous year,&#8221; said MessageLabs Intelligence senior analyst Paul Wood. &#8220;Back then, users were less savvy, regarding the dangers posed by suspicious e-mail attachments and e-mails from unknown senders. The general public was also less aware of issues such as spam and denial of service attacks.&#8221;</p>
<h2><strong>Bot Attacks<span style="font-weight: normal; font-size: 13px;"> </span></strong></h2>
<p>The April 2010 MessageLabs Intelligence Report also revealed that Rustock has surpassed Cutwail as the biggest botnet both in terms of the amount of spam it sends and the amount of active bots under its control.</p>
<p>The report noted that Rustock has reduced the output of individual bots by 65 per cent but increased the number of active bots by 300 per cent, thus, making up for the decreased output. Meanwhile, Cutwail has reduced in size to 600,000 bots from two million bots in May 2009 and is now responsible for only four per cent of all spam. &#8220;Rustock remains the largest spam-sending botnet responsible for 32.8 per cent of all spam,&#8221; the report read.</p>
<p>&#8220;Affected by the closure of ISP Real Host in August 2009, Cutwail likely lost the ability to update some of its bots causing its numbers to diminish greatly without the ability to recover,&#8221; said Wood. &#8220;As a result, Rustock has taken over significant volumes from spammers by undercutting the market with greater capacity and lower operational costs.&#8221;</p>
<h2><strong>Spam<span style="font-weight: normal; font-size: 13px;"> </span></strong></h2>
<p>Worldwide, the spam rate this month was pegged at 89.9 per cent, a drop of 0.8 per cent from the previous month. In the region, Malaysia and Singapore also saw a drop in the spam rate to 87.7 per cent, and 87.6 per cent respectively, the report added.</p>
<p>&#8220;Spam is more commonly sent from computers running Windows than from those running other operating systems,&#8221; Wood said. &#8220;However, spam not identified as coming from botnets was seen in lower proportions coming from Windows machines than from known botnets.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/symantec-warns-of-cyber-attacks-worse-than-love-bug/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Instant Messaging Worm Spreading Fast!</title>
		<link>http://www.andrewsayshello.com/technology/new-instant-messaging-worm-spreading-fast/</link>
		<comments>http://www.andrewsayshello.com/technology/new-instant-messaging-worm-spreading-fast/#comments</comments>
		<pubDate>Tue, 04 May 2010 23:19:20 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[bitdefender]]></category>
		<category><![CDATA[bkis]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[im]]></category>
		<category><![CDATA[instant message]]></category>
		<category><![CDATA[kazaa]]></category>
		<category><![CDATA[limewire]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[palevo]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[yahoo]]></category>
		<category><![CDATA[yahoo messenger]]></category>
		<category><![CDATA[yimfoca]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1138</guid>
		<description><![CDATA[A smiley-faced instant message with a photo link posing as if it&#8217;s from someone on your buddy list is actually spreading misery worldwide in the form of a worm on Yahoo Instant Messenger: The IM ultimately delivers a worm that allows an attacker to take over the victim&#8217;s machine, not to mention spread itself among [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/new-instant-messaging-worm-spreading-fast/"></g:plusone></div><p>A smiley-faced instant message with a photo link posing as if it&#8217;s from someone on your buddy list is actually spreading misery worldwide in the form of a worm on Yahoo Instant Messenger: The IM ultimately delivers a worm that allows an attacker to take over the victim&#8217;s machine, not to mention spread itself among the victim&#8217;s contact list.</p>
<p>Researchers at BitDefender, BKIS, and Symantec today each separately warned Yahoo Messenger users about the worm attack, which is rapidly growing. Catalin Coisoi, senior malware and virus researcher for BitDefender, based in Romania, says his team has seen infection rates as high as 500 percent per hour in his home country since they first spotted it last week. &#8220;Today it started spreading like wildfire,&#8221; Coisoi says.</p>
<p>He says the socially engineered message appears to be capitalizing on the May 1 national holiday in Romania. &#8220;People expect to see pictures [from their friends and colleagues] after a national holiday,&#8221; he says. But he also expects the worm to make inroads in the U.S. today and tomorrow, with potential victims coming off of a weekend.</p>
<p>The worm &#8212; known as <a href="http://www.malwarecity.com/blog/extremely-aggressive-worm-chokes-instant-messaging-806.html" target="new">Palevo by BitDefender</a>, <a href="http://blog.bkis.com/en/new-worm-spreading-via-yahoo-messenger/" target="new">W32.Ymfocard.fam.Botnet by BKIS</a>, and <a href="http://www.symantec.com/connect/blogs/new-yahoo-messenger-worm" target="new">W32.Yimfoca by Symantec</a> &#8212; is a new variant of an existing worm. In the Yahoo IM attack, it tricks the user into saving what appears to be a JPG or GIF file, but instead is a malicious executable.</p>
<p>BitDefender says the worm contains a backdoor, which lets an attacker take over the victim&#8217;s compromised machine, to install more malware, steal files, intercept passwords, and launch spam or other malware attacks on other systems. It&#8217;s also spreading the way the infamous Conficker worm has done, via network shares and removable USB drives using the Autorun feature. When an infected memory stick gets loaded into a machine with Autorun enabled or unprotected, the machine can automatically be infected with the worm.</p>
<blockquote><p>&#8220;You can do anything you want with a backdoor &#8212; keylogging to search for passwords, or it could be a botnet,&#8221; Coisoi says. &#8220;It offers the attacker full system access.&#8221;</p></blockquote>
<p>It also spreads via peer-to-peer sharing sites, such as Kazaa and LimeWire which are all too easy to pack these types of files in with movies files and software cracks.</p>
<p>The good news: Because it drops an .exe file, it requires the user to run it for it to go live. According to Symantec, once the worm is run, it adds itself to the Windows Firewall list, stops the Windows Update service, and configures itself such that it runs each time the system boots. The worm automatically sends itself to everyone on the victim&#8217;s contact list.</p>
<blockquote><p>&#8220;The nature of this attack is nothing new, because some worms already used this way of attack,&#8221; BKIS researchers blogged. &#8220;However, it is always potentially dangerous to [unaware] users. Bad guys have integrated some phishing elements to trick [the] user into clicking the link and then opening the downloaded file.&#8221;</p></blockquote>
<p>So basically, if someone sends you a link via an instant message out of the blue, it might be best to double check with them what exactly they are sending you, so you don&#8217;t fall victim to this new worm.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/new-instant-messaging-worm-spreading-fast/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Top 10 Signs Your Computer May be Part of a Botnet!</title>
		<link>http://www.andrewsayshello.com/technology/top-10-signs-your-computer-may-be-part-of-a-botnet/</link>
		<comments>http://www.andrewsayshello.com/technology/top-10-signs-your-computer-may-be-part-of-a-botnet/#comments</comments>
		<pubDate>Thu, 29 Apr 2010 19:08:33 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[adware]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[koobface]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[registry]]></category>
		<category><![CDATA[task manager]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[zombie]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1131</guid>
		<description><![CDATA[There are few signs that indicate your computer is part of a botnet that might not be indicating something else. Any malware can cause almost all of the same symptoms that a bot can. Sometimes conflicts between programs or corrupted files can cause the same symptoms as well, but still, there are some signs that [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/top-10-signs-your-computer-may-be-part-of-a-botnet/"></g:plusone></div><p>There are few signs that indicate your computer is part of a botnet that might not be indicating something else. Any malware can cause almost all of the same symptoms that a bot can. Sometimes conflicts between programs or corrupted files can cause the same symptoms as well, but still, there are some signs that should not be ignored. So, in no particular order…</p>
<p><strong>1)    Your fan kicks into overdrive when your computer is idle</strong><br />
This can indicate that a program is running without your knowledge and using a fair amount of resources. Of course this could also be a bunch of Microsoft updates being installed. Another problem that can cause the fan to kick in like that is excessive dirt in the computer or a failing CPU fan.</p>
<p><strong>2)    Your computer takes a long time to shut down, or won’t shut down properly</strong><br />
Oftentimes malicious software has bugs in it that can cause a variety of symptoms, including long shut down times of a failure to shut down. Unfortunately, operating system bugs and conflicts with legitimate programs may cause the same symptom.</p>
<p><strong>3)    You see a list of outbound Wall posts you didn’t send on your Facebook page (see below)</strong></p>
<p><strong><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/04/facebookspam.jpg" rel="lightbox[1131]"><img class="aligncenter size-medium wp-image-1132" title="facebookspam" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/04/facebookspam-242x300.jpg" alt="" width="242" height="300" /></a></strong></p>
<p><strong><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/04/facebookspam.jpg" rel="lightbox[1131]"></a><span style="font-weight: normal;">There are few reasons other than malicious software or having your account hacked that would cause this problem. If you see this happening, you definitely want to change your password and make sure you computer is not infected. Best to make sure your computer is not infected before changing your password!!! Don’t use your Facebook password on multiple sites!!!</span></strong></p>
<p><strong>4)    Programs are running very slowly</strong><br />
This can be a sign that hidden programs are using a lot of your computer’s resources. This also can be a sign of other problems. On Windows systems if there are 10,000 files or more in a single directory it can really bring a system to a crawl.</p>
<p><strong>5)    You cannot download operating system updates</strong><br />
This is a symptom you cannot ignore. Even if it isn’t a bot or other malware, if you don’t keep your system patched your computer probably will get infected.</p>
<p><strong>6)    You cannot download antivirus software updates / visit vendors’ websites</strong><br />
Malware often tries to prevent antivirus software from running or being installed. An inability to update your antivirus software or visit the vendor’s web site is a pretty strong indicator of malware.</p>
<p><strong>7)    Internet access slows to a crawl</strong><br />
If a bot is using your computer to send massive amounts of spam or participate in an attack against other computers, or to upload or download a lot of data it can make your internet access very slow.</p>
<p><strong>8)    Your friends and family have received e-mail message from you that you did not send</strong><br />
This can be a sign of a bot, other malicious software, or that your webmail account has been hacked.</p>
<p><strong>9)    You receive pop-up windows and advertisements even when you are not using a web browser</strong><br />
While this is a classic sign of adware, bots can install adware on your computer. You definitely want to get this problem taken care of.</p>
<p><strong>10)    Windows Task manager shows programs with very cryptic names or descriptions</strong> (the highlighted line is the example)</p>
<p><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/04/taskmanager.jpg" rel="lightbox[1131]"><img class="aligncenter size-medium wp-image-1133" title="taskmanager" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/04/taskmanager-300x118.jpg" alt="" width="300" height="118" /></a></p>
<p><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/04/taskmanager.jpg" rel="lightbox[1131]"></a>Using task manager requires some skill and research. Sometimes legitimate software uses cryptic names as well. An entry in task manager is generally not enough to identify a program as being bad. This can help you find bad programs, but many additional steps must be performed to validate you findings. Killing processes and deleting files or registry entries because you “think” it is a bot or other malware can result in the inability to even boot your computer. Be very careful of making assumptions and acting on them.</p>
<p>Although this doesn&#8217;t cover everything that could mean you are part of a botnet, this is a good list of the major signs you will see, and means you need to get your computer cleaned ASAP!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/top-10-signs-your-computer-may-be-part-of-a-botnet/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New Scareware Tactic Lures in More FAKEAV Buyers!</title>
		<link>http://www.andrewsayshello.com/technology/new-scareware-tactic-lures-in-more-fakeav-buyers/</link>
		<comments>http://www.andrewsayshello.com/technology/new-scareware-tactic-lures-in-more-fakeav-buyers/#comments</comments>
		<pubDate>Wed, 24 Mar 2010 12:48:06 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[explorer]]></category>
		<category><![CDATA[fakeav]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[scareware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1030</guid>
		<description><![CDATA[TrendLabs recently received a new FAKEAV sample, which they now detect as TROJ_FAKEAV.BLW. Like previous variants, it poses as a legitimate antivirus application that displays false detections, disables firewall and security center functions, and produces pop-up warnings to force affected users to purchase rogue antivirus software. Unlike its predecessors, however, this sample uses the file name AV.exe. If [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/new-scareware-tactic-lures-in-more-fakeav-buyers/"></g:plusone></div><p>TrendLabs recently received a new <strong>FAKEAV</strong> sample, which they now detect as <strong><a onclick="javascript:pageTracker._trackPageview('/outgoing/threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_FAKEAV.BLW');" href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_FAKEAV.BLW">TROJ_FAKEAV.BLW</a>.</strong> Like previous variants, it poses as a legitimate antivirus application that displays false detections, disables firewall and security center functions, and produces pop-up warnings to force affected users to purchase rogue antivirus software.</p>
<p>Unlike its predecessors, however, this sample uses the file name <em>AV.exe. </em>If users are not into computers, they may think this is a valid antivirus application. It uses registry shell spawning as autostart technique, which means the malware is executed every time a user runs files that have the <em>.EXE</em> file name extension. It also uses any of the following application names:</p>
<ul>
<li>%1 Antispyware 2010</li>
<li>Antivirus %1 2010</li>
<li>%1 Guardian 2010</li>
<li>%1 Guardian</li>
<li>%1 Defender 2010</li>
<li>%1 Antivirus</li>
<li>%1 Antivirus 2010</li>
<li>%1 Antivirus Pro</li>
<li>%1 Antivirus Pro 2010</li>
<li>%1 Internet Security</li>
<li>%1 Internet Security 2010</li>
</ul>
<p>Note that <em>%1</em> refers to the OS installed on the affected machine. This makes the malware flexible in that it is able to take advantage of the features of an infected user’s OS.</p>
<p>Whenever an infected user attempts to access the Internet via <strong><em>Internet Explorer (IE)</em></strong> or <em><strong>Firefox</strong>,</em> this malware displays warning messages saying these browsers are malicious. (Internet Explorer on the left and Firefox on the right)</p>
<p><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/03/fakeav-ie.gif" rel="lightbox[1030]"><img class="alignleft size-medium wp-image-1029" title="fakeav-ie" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/03/fakeav-ie-300x255.gif" alt="" width="240" height="204" /></a><a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/03/fakeav-firefox.gif" rel="lightbox[1030]"><img class="alignright size-medium wp-image-1028" title="fakeav-firefox" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/03/fakeav-firefox-300x255.gif" alt="" width="240" height="204" /></a></p>
<p>This may cause the user to panic since these are two of the most commonly used browsers. Users who are tricked into purchasing the bogus product are redirected to multiple rogue antivirus domains.</p>
<p>This list ensures that the malware can access other domains even if some have already been taken down. Lastly, this malware does not allow users to execute files from security companies, which prevents the affected user from scanning the affected computer.</p>
<p>When faced with these kinds of false alarms, I would urge users to calm down and avoid purchasing rogue antivirus products. This does not help solve the problem. Instead, it makes things even worse, as this is just a waste of hard-earned money.</p>
<p>This is only the latest tactic seen from the perpetrators of rogue antivirus malware. Recently, advanced threats researchers spotted another FAKEAV run using Sandra Bullock’s recent marital difficulties to spread malware. If you have any questions about this type of malware, please feel free to contact me and I will be glad to answer any of your questions.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/new-scareware-tactic-lures-in-more-fakeav-buyers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New Wave of Ransom Malware Hits Internet!</title>
		<link>http://www.andrewsayshello.com/technology/new-wave-of-ransom-malware-hits-internet/</link>
		<comments>http://www.andrewsayshello.com/technology/new-wave-of-ransom-malware-hits-internet/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 02:17:05 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[fortinet]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[ransom]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[seo]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[vundo]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=1001</guid>
		<description><![CDATA[Criminals reused an attack from 2008 to hit the Internet with a huge wave of ransomware in recent weeks, a security company has reported. In the space of only two days, February 8 and 9, the HTML/Goldun.AXT campaign detected by Fortinet accounted for more than half the total malware detected for February, which gives some indication of its unusual scale. [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/new-wave-of-ransom-malware-hits-internet/"></g:plusone></div><p>Criminals reused an attack from 2008 to hit the Internet with a huge wave of ransomware in recent weeks, a security company has reported.</p>
<p>In the space of only two days, February 8 <a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/03/virus-spyware-malware-pc.jpg" rel="lightbox[1001]"><img class="alignright size-medium wp-image-1008" title="virus" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/03/virus-spyware-malware-pc-200x300.jpg" alt="" width="200" height="300" /></a>and 9, the HTML/Goldun.AXT campaign <a href="http://www.fortiguard.com/reports/roundup_february_2010.html" target="_blank">detected by Fortinet</a> accounted for more than half the total malware detected for February, which gives some indication of its unusual scale.</p>
<p>The attack itself takes the form of a spam e-mail with an attachment, report.zip, which if clicked automatically downloads a rogue antivirus product called Security Tool. It is also being distributed using manipulated search engine optimisation (SEO) on Google and other providers.</p>
<p>Such scams have been common on the Internet for more than a year, but this particular one features a more recently-evolved sting in the tail. The product doesn&#8217;t just ask the infected user to buy a useless license in the mode of scareware, it locks applications and data on the PC, offering access only when a payment has been made through the single functioning application left, Internet Explorer.</p>
<p>What&#8217;s new, then, is that old-style scareware has turned into a default ransom-oriented approach. The former assumes that users won&#8217;t know they are being scammed, while the latter assumes they will but won&#8217;t know what to do about it.</p>
<p>The technique is slowly becoming more common &#8212; see the Vundo attack of a year ago &#8212; but what is also different is the size of this attack, one of the largest ever seen by Fortinet for a single malware campaign.</p>
<p>Fortinet notes that Security Tool is really a reheat of an old campaign from November 2008, which pushed the notorious rogue antivirus product Total Security as a way of infecting users with a keylogging Trojan.</p>
<p>&#8220;This is a great example of how tried and true attack techniques/social engineering can be recycled into future attacks,&#8221; says Fortinet&#8217;s analysis.</p>
<p>According to Fortinet, the &#8220;engine&#8221; pushing the spike in ransom-based malware is believed to be the highly-resilient Cutwail/Pushdo botnet, the same spam and DDoS system behind a number of campaigns in the last three years including the <a href="http://news.techworld.com/security/3211670/cia-fbi-twitter-paypal-hit-by-botnet/" target="_blank">recent pestering of PayPal and Twitter</a> sites.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/new-wave-of-ransom-malware-hits-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Don&#8217;t press F1 key in Windows XP says Microsoft!</title>
		<link>http://www.andrewsayshello.com/technology/dont-press-f1-key-in-windows-xp-says-microsoft/</link>
		<comments>http://www.andrewsayshello.com/technology/dont-press-f1-key-in-windows-xp-says-microsoft/#comments</comments>
		<pubDate>Sun, 07 Mar 2010 05:15:06 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[7]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[explorer]]></category>
		<category><![CDATA[f1]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[vbscript]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[vista]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[xp]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=997</guid>
		<description><![CDATA[Microsoft told Windows XP users today not to press the F1 key when prompted by a Web site, as part of its reaction to an unpatched vulnerability that hackers could exploit to hijack PCs running Internet Explorer (IE). In a security advisory issued late Monday, Microsoft confirmed the unpatched bug in VBScript that Polish researcher Maurycy Prodeus [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/dont-press-f1-key-in-windows-xp-says-microsoft/"></g:plusone></div><p>Microsoft told Windows XP users today not to press the F1 key when prompted by a Web site, as part of its reaction to an unpatched vulnerability that hackers could exploit to hijack PCs running Internet Explorer (IE).</p>
<p>In a <a href="http://www.microsoft.com/technet/security/advisory/981169.mspx" target="new">security advisory</a> issued late Monday, Microsoft confirmed the unpatched bug in VBScript that Polish researcher Maurycy Prodeus had revealed Friday, offered more information on the flaw and provided some advice on how to protect PCs until a patch shipped.</p>
<p>&#8220;The vulnerability exists in the way that VBScript interacts with Windows Help files when using Internet Explorer,&#8221; read the advisory. &#8220;If a malicious Web site displayed a specially crafted dialog box and a user pressed the F1 key, arbitrary code could be executed in the security context of the currently logged-on user.&#8221;</p>
<p>Last week, Prodeus called the bug a &#8220;logic flaw,&#8221; and said attackers could exploit it by feeding users malicious code disguised as a Windows help file &#8212; such files have a &#8220;.hlp&#8221; extension &#8212; then convincing them to press the F1 key when a pop-up appeared. He rated the vulnerability as &#8220;medium&#8221; because of the required user interaction.</p>
<p>Windows 2000, Windows XP and Windows Server 2003 are impacted by the bug, said Microsoft, and any supported versions of Internet Explorer (IE) on those operating systems &#8212; including IE6 on Windows XP &#8212; could be leveraged by attackers. Previously, Prodeus had said that users running IE7 and IE8 were at risk, but had not called out IE6.</p>
<p>Until a patch is ready, users can protect themselves by not pressing the F1 key if a Web site tells them to, said Microsoft. &#8221;As an interim workaround, users are advised to avoid pressing F1 on dialogs presented from Web pages or other Internet content,&#8221; said David Ross with the Microsoft Security Response Center (MSRC) engineering staff in a <a href="http://blogs.technet.com/srd/archive/2010/03/01/help-keypress-vulnerability-in-vbscript-enabling-remote-code-execution.aspx" target="new">blog entry</a> on Monday.</p>
<p>&#8220;The prompt can appear repeatedly when dismissed, nagging the user to press the F1 key,&#8221; Ross added.</p>
<p>The security advisory made the same recommendation: &#8220;Our analysis shows that if users do not press the F1 key on their keyboard, the vulnerability cannot be exploited.&#8221; Users can also stymie attacks by disabling Windows Help. The advisory explained how to entering a one-line command at a Windows command-line prompt to lock down the Help system.</p>
<p>The company took Prodeus to task for taking the bug public, something it regularly does when researchers disclose a vulnerability or post sample attack code before a patch is available.</p>
<p>&#8220;Microsoft is concerned that this vulnerability was not responsibly disclosed, potentially putting customers at risk,&#8221; said Jerry Bryant, a senior manager with the MSRC, in an e-mail. By <a href="http://isec.pl/vulnerabilities/isec-0027-msgbox-helpfile-ie.txt" target="new">Prodeus&#8217; account</a>, he notified Microsoft of the flaw Feb. 1, about four weeks before publishing his findings.</p>
<p>Microsoft has not set a timeline for a fix, saying only that, &#8220;Microsoft will take the appropriate action to help protect our customers.&#8221; The next scheduled security patch date for the company is March 9.</p>
<p>Although it does not rate the severity of vulnerabilities in its advisories, Microsoft noted that hackers exploiting the VBScript flaw using Windows Help and Internet Explorer could grab complete control of a Windows system. Customers running Windows Vista, Windows Server 2008, Windows 7 or Windows Server 2008 R2 are safe from such attacks, Microsoft said.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/dont-press-f1-key-in-windows-xp-says-microsoft/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Mariposa Botnet has Been Knocked Offline for Good!</title>
		<link>http://www.andrewsayshello.com/technology/the-mariposa-botnet-has-been-knocked-offline-for-good/</link>
		<comments>http://www.andrewsayshello.com/technology/the-mariposa-botnet-has-been-knocked-offline-for-good/#comments</comments>
		<pubDate>Thu, 04 Mar 2010 14:06:35 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[defense intelligence]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[mariposa]]></category>
		<category><![CDATA[panda]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=990</guid>
		<description><![CDATA[The Mariposa botnet had the power to dwarf Georgia and Estonia cyberattacks if it had been used to launch denial of service attacks, say Spanish police. Months of investigations by the Guardia Civil in Spain, the FBI and security firm Panda Security and Defence Intelligence led to the takedown of the 12.7 million strong zombie [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/the-mariposa-botnet-has-been-knocked-offline-for-good/"></g:plusone></div><p>The Mariposa botnet had the power to dwarf Georgia and Estonia cyberattacks if it had been used to launch denial of service attacks, say Spanish police.</p>
<p>Months of investigations by the Guardia Civil in Spain, the FBI and security firm Panda Security and Defence Intelligence led to the takedown of the 12.7 million strong zombie network in December and the arrest of three suspects in Spain two months later.</p>
<p>At a press conference announcing the operation in Madrid on Wednesday, Spanish police said they recovered the personal details of 800,000 people from systems recovered from three alleged cybercriminals. This cache of stolen information includes bank login credentials from businesses and consumers as well as email passwords.</p>
<p>Three Spanish residents suspected of running the botnet have been charged with online offences: the most senior alleged botmaster, nicknamed “Netkairo”, 31, from Balmaseda in the spanish province of Vizcaya, as well as his two alleged lieutenants JPR, 30, from Molina de Segura Murcia and JBR, 25, from Santiago de Compostela in La Coruña. None of the suspects have been named at this stage of proceedings.</p>
<p>In a statement (in Spanish <a href="http://www.guardiacivil.org/prensa/notas/win_noticia.jsp?idnoticia=2776" target="_blank">here</a>), Guardia Civil officers said they were also on the trail of a fourth suspect nicknamed Phoenix, who&#8217;s possibly based in Venezuela.</p>
<p>Defence Intelligence discovered the botnet last May and formed a team that brought in security experts from Bilbao-based Panda and computer scientists at Georgia Tech Information Security Center. Security researchers infiltrated the botnet&#8217;s command and control systems, learning enough to mount a successful takedown operation in cooperation with ISPs on 23 December.</p>
<p>Netkairo responded to this by launching a retaliatory denial of service attack against Defence Intelligence that took out customers at a Canadian ISP for several hours. In wrestling to obtain control of the botnet he made the mistake of connecting to compromised systems using his home PC, a mistake that led to his identification.</p>
<p>Luis Corrons, technical director of PandaLabs, explains the Mariposa botnet&#8217;s business model and the takedown operation in a video below.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://www.youtube.com/v/20Z8izzl994&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;hl=en_US&amp;feature=player_embedded&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/20Z8izzl994&amp;color1=0xb1b1b1&amp;color2=0xcfcfcf&amp;hl=en_US&amp;feature=player_embedded&amp;fs=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/the-mariposa-botnet-has-been-knocked-offline-for-good/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rootkit Causing &#8216;Blue Screen Of Death&#8217; On Newly Patched XP Machines!</title>
		<link>http://www.andrewsayshello.com/technology/rootkit-causing-blue-screen-of-death-on-newly-patched-xp-machines/</link>
		<comments>http://www.andrewsayshello.com/technology/rootkit-causing-blue-screen-of-death-on-newly-patched-xp-machines/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 13:17:03 +0000</pubDate>
		<dc:creator>Andrew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[bsod]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[ms10-015]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[tdss]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[xp]]></category>

		<guid isPermaLink="false">http://www.andrewsayshello.com/?p=964</guid>
		<description><![CDATA[It turns out a rootkit is responsible for some Microsoft users experiencing the dreaded &#8220;blue screen of death&#8221; after applying one of the latest Windows patches, Microsoft said today. Post-Patch Tuesday reports of XP SP2 and SP3 users being unable to restart their systems after applying the new MS10-015 patch led Microsoft to suspend its [...]]]></description>
			<content:encoded><![CDATA[<div name="googleone_share_1" style="position:relative;z-index:5;float: left; margin-right: 5px; margin-top: 15px"><g:plusone size="tall" count="1" href="http://www.andrewsayshello.com/technology/rootkit-causing-blue-screen-of-death-on-newly-patched-xp-machines/"></g:plusone></div><p>It turns out a rootkit is responsible for some Microsoft users experiencing the dreaded &#8220;blue screen of death&#8221; after applying one of the latest Windows patches, Microsoft said today.</p>
<p>Post-Patch Tuesday reports of XP SP2 and SP3 users being unable to restart<a href="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/02/blue-screen-of-death.jpg" rel="lightbox[964]"><img class="size-medium wp-image-968 alignright" title="blue-screen-of-death" src="http://www.andrewsayshello.com/wordpress/wp-content/uploads/2010/02/blue-screen-of-death-300x225.jpg" alt="" width="300" height="225" /></a> their systems after applying the new MS10-015 patch led Microsoft to suspend its automatic distribution of that patch while it investigated whether the patch itself was causing the problem. The director of Microsoft&#8217;s Security Response Center, Mike Reavey, said in <a href="http://blogs.technet.com/msrc/default.aspx" target="new">a blog post today</a> that the issue occurs when a system is infected with the so-called Alureon rootkit.</p>
<blockquote><p>&#8220;The restarts are the result of modifications the Alureon rootkit makes to Windows Kernel binaries, which places these systems in an unstable state. In every investigated incident, we have not found quality issues with security update MS10-015,&#8221; Reavey said. &#8220;Our guidance remains the same: customers should continue to deploy this month&#8217;s security updates and make sure their systems are up-to-date with the latest anti-virus software.&#8221;</p></blockquote>
<p>The finding syncs with what some security researchers concluded earlier in the week, after initial concerns that the patch itself was flawed.</p>
<p>Meanwhile, distribution of the MS10-015 patch is still on hold for some systems via Automatic Update until Microsoft comes up with a fix for the issue, which it says only affects 32-bit machines. Automatic Updates for 64-bit systems are now again pushing the MS10-015 patch, which fixes a bug in the Windows kernel.</p>
<p>&#8220;A malware compromise of this type is serious, and if customers cannot confirm removal of the Alureon rootkit using their chosen anti-virus/anti-malware software, the most secure recommendation is for the owner of the system to back up important files and completely restore the system from a cleanly formatted disk,&#8221; Reavey said.</p>
<p>Microsoft is working on a &#8220;simpler solution&#8221; to detect and eradicate the rootkit from infected systems, which it plans to release in a few weeks, according to Reavey.</p>
<p>Setting a machine to &#8220;standard&#8221; rather than &#8220;administrator&#8221; account mode typically prevents kernel malware from infecting systems, he said, and keeps antivirus signatures up-to-date is also helpful.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.andrewsayshello.com/technology/rootkit-causing-blue-screen-of-death-on-newly-patched-xp-machines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

