Saturday, July 19, 2008

[Lockergnome] Computer Security ~ July 19, 2008

Lockergnome
Lockergnome's Computer Security ~ July 19, 2008   



Say the Time v6.0: Say the Time is the fun and easy way to get organized. Hear the date and time spoken aloud in a pleasant voice. Keep track of time commitments with customizable reminders. Transform your boring taskbar clock into a colorful timepiece. Easily sync your PC with an Internet time server - and much more! [Get more info | Download a trial]... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security

Exploring VB6 Volume 2: Files and Directories: The Exploring VB6 series is a "best of" collction of Dan Appleman's previously published work for Visual Basic 6 developers. This second volume is intended for intermediate and advanced developers, and focuses on file and directory operations. Also covers advanced API programming techniques and how to migrate them to VB .NET. [ Available in PDF Format for $8 / Download ]... [Click Here to Download]

Administrivia

Tech Help and How To

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security






» A Little Magic
» The MacBook Is Going Aluminum
» Next Grand Theft Auto
» Updates.
» AirMe - WeatherBug API Entry
» Disk Redactor
» Dr.Web CureIt!
» 3CX Phone System for Windows Free
» SC-DiskInfo
» ProxyChecker.Net (1.0.0.23)


TrendLabs | Malware Blog - by Trend Micro - YAMSIA (Yet Another Massive SQL Injection Attack)

 

Your email updates, powered by FeedBlitz

 
Here are the latest updates for security-news@awsoda.net

"TrendLabs | Malware Blog - by Trend Micro" - 1 new article

  1. YAMSIA (Yet Another Massive SQL Injection Attack)
  2. More Recent Articles
  3. Search TrendLabs | Malware Blog - by Trend Micro

YAMSIA (Yet Another Massive SQL Injection Attack)

Clever mnemonics aside, last week we have seen another large scale SQL injection attack (or YAMSIA, if you prefer), this time being orchestrated by a botnet that has become known as Asprox—but first, a history lesson.

The code behind the Asprox botnet seems to have been around for quite some time now, but it was only in the last year that it has upgraded to a botnet where its main focus is to send phishing emails. This has changed in late May / early June of this year when the bots where issued a new set of commands–namely to start searching the Web for certain .ASP pages - and then launching an SQL injection attack against these pages (hmm … I wonder where they got that idea from).


Figure 1. The modus operandi that has become more and more common.

Compromised sites have a piece of JavaScript (JS) embedded in them, which in turn points to another JS file on a seperate domain (the first technique has been taught in Bouncing Malware 101). These domains are part of a fast-flux network hosted on the botnet itself (a technique widely used by another well-known botnet, Storm). The JS file name was originally b.js, but this has since changed and, in the latest wave, it is the highly imaginative ngg.js.


Figure 2. Sample of malicious script (with some parts removed)

As you can see, this script creates a cookie that expires after 9 days. This serves as an infection marker on the page, as it then “bounces” the threat once more to the page pointed to by the iFrame.

Depending on what country you are browsing from, the Asprox botnet may decide not to let you access this page, in which case, you will be redirected to the legitimate www.msn.com. If you are “lucky” enough to be allowed access to the page, however, your browser will be promptly slapped in the face with a barrage of vulnerabilities–all with the goal of having your computer join in all of the fun by hooking your PC up to the botnet.

SQL injection attacks can be very effective as they are normally completely hidden to the Internet user—everything is quietly downloaded in the background without their knowledge. We were sure this was a criminal act, and as such have added a detection for the threat, as well as the bouncing JavaScript (JS_IFRAME.ADN) itself.

Unfortunately, security is still a major issue with the majority of Web sites, and until it becomes one of the core design goals from the start of a Web site project, expect to see more YAMSIA (Can you tell I’m trying to get this mnemonic to stick?) blogs in the future.

ShareThis



More Recent Articles



Click here to safely unsubscribe now from "TrendLabs | Malware Blog - by Trend Micro" or change subscription settings

 
Unsubscribe from all current and future newsletters powered by FeedBlitz
Your requested content delivery powered by FeedBlitz, LLC, 9 Thoreau Way, Sudbury, MA 01776, USA. +1.978.776.9498

 

Friday, July 18, 2008

[Lockergnome] Computer Security ~ July 18, 2008

Lockergnome
Lockergnome's Computer Security ~ July 18, 2008   



AstroAvenger: Looking for a space shooter that will surprise you? AstroAvenger features cool graphics, excellent sound effects and a groovy sound track. The game employs an advanced upgrade and power-up system that allows you to buy new types of weapons, ammo, armor and batteries as you advance from one level to another. Fighting takes place in five distinct and expansive galaxies, with over 25 different enemy ships types to combat. [Download Free Trial]... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security

Pirates of Treasure Island: Avast, ye hearties! Give aid to thee swarthy Captain Gingerbeard and his merry auld crew find th' legendary fortunes o' Treasure Island! Enjoy bedevilishly lovely graphics and swashbuckling concertina music in this game with a unique combination o' brick-matchin' puzzles and thrillin' pirate adventures. Show 'em how we do it on the high seas, hearties! Lay on your backs and haul! Earn your salt, scurvy bilge rats! Hargh! [Screenshot] [Download Shareware]... [Click Here to Download]

Administrivia

Tech Help and How To

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security






» Disk Redactor
» Dr.Web CureIt!
» 3CX Phone System for Windows Free
» SC-DiskInfo
» ProxyChecker.Net (1.0.0.23)


Subscribe via email

Enter your email address:

Delivered by FeedBurner

Blog Archive