Aug 24, 2008

Interview with Dakeyras

Dakeyras, a future malware fighter from Malware Removal University, asked me for interview regarding malware/security issues for his blog and I was happy to agree.

Read entire interview here

Labels: , ,

May 17, 2008

Security problems in Vista are PEBKAC?

PC Tools published earlier this month a research which claims that Vista is somewhat as secure as Windows 2000.

Microsoft blogger Michael Kleef doesn't agree with that. He wrote in his blog
that way PC Tools used for calculations is wrong because amount of malware isn't only due to operating system fault. He believes in education; users need to understand risks.

Labels: ,

Apr 24, 2008

Crackers target to Beijing Olympics

Security company MessageLabs has recognized many trojan attacks which were related to Olympics theme.

- These attacks have been targeted to organizations which have very valuable and confidential information like army or goverment, says Alex Shipp from MessageLabs.

Different organizations have been approached by name of International Olympic Committee and email header has been related to eg. torch relay. Attackers have been identified to Asia and Pacific region.

Attacks have been usually targeted to only certain persons in organization, amount is limited and credibility is main thing there. Recently in USA was spread widely an email hoax targeted to big company leaders.

In these Olympic attacks have been used eg. Microsoft Office Database (mdb) files hidden in zip archive. After running of mdb file, it drops an infostealing exe file to computer.

Source: MessageLabs

Labels: , , ,

Feb 26, 2008

Spammers have entered GMail

Websense Security Labs has announced that spammers have managed to circumvent GMails CAPTCHA recognition

This means that you can get spam from GMail address in the future.

Websense says that spammers might get many benefits from using GMail. It's very unlikely that GMail mails would be blacklisted and GMail has so many users that picking spammers among them would be very difficult.

Labels: , ,

Feb 2, 2008

Panda received last year over new 3000 malware files daily

PandaLabs (virus laboratory of Panda Security) has announced that it received 3000 new malware samples daily on average.

That mean there were 800 per cent more samples than in 2006 and around 1400 per cent more than in 2005.
That's why Panda said that current situation can be called as silent malware epidemic (hasn't received publicity in media and no major alarms).

Just virus definition updates don't help anymore to ensure users security. PandaLabs reveals that 23 per cent of home users were infected despite of using security programs.

Source: Panda

Labels: ,

Jan 19, 2008

About half a million computers get bot infection daily

About half a million computers get bot infection daily, tells PandaLabs in its 2007 annual report.

Around 11 percent of all computers belong to botnets which is extremely scary. Those computers send over 85 percent of all spam mail.

- Creator of botnet can lease it to others. Internet criminals use those in many criminals acts like infecting those computers and for DoS (Denial of Service) attacks. One of the most commonly used ways is sending of spam mailsm, tells PandaLabs leader Luis Corrons.

In year 2007 over a half of home user mails were spam. And situation is even more difficulties in companies, same amount was there between 80 and 95 percent.

The origin of spam mail was in almost 60 percent of all cases Russia and in 60 percent of all cases USA. Other major spammer countries were Turkey (6 %), Germany (5 %) and Great Britain (3 %).

Source: Panda

Labels: , ,

Dec 19, 2007

Problems with latest IE security update

Microsoft has get reports of users that have had problems using Internet Explorer after last week IE security update.

Some told that they have problems accessing web sites and others said that IE won't open at all.

Reports started to come almost immediately after MS07-069 update release a week ago.

Problems seem to affect both IE 6 and IE7 as well as both Windows XP and Windows Vista.
Microsoft has released a temporary solution.

Source: PC World, Microsoft

Labels: , , ,

Dec 11, 2007

Spam emails reached new record

According to Symantec 72 percent of emails were spam in November.

That was because spammers tried to find new working emails using a method that if mail didn't come back, mail address works.

Bill Gates said on 2004 that spam will be defeated within 2 years. Well that's not exactly what has happen.

Amount of spam emails has raised from 56 percent in 2006 to 72 percent in Nov 2007.

Spam tacticts include eg. seasonal spams (Christmas, Thanksgiving etc.), image spams, attachment spams and pump-and-dump spams.

Read more here

Labels: ,

Nov 22, 2007

"Man in the Browser" - new technique to steal online bank logon credentials

F-Secure warns about a new way to steal online bank logon credentials; "Man in the Browser" - technique, which steals them from browser session and sends to criminal servers.

This technique is based on malware in computer which activates only when user uses online bank. Malware can save username and password from html-code in browsers. These information are being sent to ftp site from which criminals sold them to other criminals.

Network criminals have always used means to steal personal data and bank logon credentials; those techniques have only developed because security programs have, too.

First way was keyloggers and after those phishing and pharming.

In phishing, emails, which are masked to look like ones from bank, are being used. When user opens link in message, he enters a fraud site which looks like real online bank site. When he enters logon credentials they get stolen.

In pharming user is being re-directed from real online bank site to fraud one, forging of URL takes place on internet level.

- Phishing is loosing its force because banks have strengthen logon security. For same reason "Man in the Browser" attacks are growing, says Mikko Hyppönen from F-Secure.

Source: F-secure

Labels: ,

Oct 30, 2007

Cracker site infects for money

PC World has interviewed researchers who have found a East European site which asks 0,2 $ / infected computer. Prepayment is also possible; you can buy eg. for 10000 infections for 2000 $.

After infection site sends purchaser IP addresses of infected machines that cracker knows where to attack. That site doesn't offer exploits or viruses but cracker can choose means freely.

Researchers believe that botnet can have millions of computers inside.

PC World warns that you shouldn't visit loads.cc as it might log IP addresses. There was found no malicious code on front page but that doesn't guarantee that also other pages there are clean.

Source: PC World

Labels: , ,