Showing newest 2 of 33 posts from 2008-07-27. Show older posts
Showing newest 2 of 33 posts from 2008-07-27. Show older posts

Saturday, August 2, 2008

[Lockergnome] Computer Security ~ August 2, 2008

Lockergnome
Lockergnome's Computer Security ~ August 2, 2008   



FTP Voyager: FTP Voyager is a powerful FTP client program. With an intuitive drag-and-drop interface, FTP Voyager lets you update a Web site with a single click, transfer files directly between FTP servers, resume interrupted downloads, and perform advanced file searches while doing other FTP tasks. The FTP Site Profile Manager makes it easy for you to add your own FTP sites. You can also import your FTP sites from many other FTP applications for use in... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security

virtualPhotographer: virtualPhotographer is an Adobe Photoshop plug-in that enables you to apply a variety of color filter effects to your images. It includes dozens of black and white styles, as well as color effects that can add drama and impact to your images. Each effect can be further customized, including options for film grain simulation, contrast adjustment, and REG filters. Your settings can be saved, and you can also download additional sets from the Web site.... [Click Here to Download]

Administrivia

Tech Help and How To

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security






» OS 4.5 is now available for Blackberry 8700
» iPhone 3G Review
» Repair Sitemeter Error in Internet Explorer
» Opera Tweaks for Speed
» File Sharing on College Campus has Some Mixed Reviews
» Disk Redactor
» Dr.Web CureIt!
» 3CX Phone System for Windows Free
» SC-DiskInfo
» ProxyChecker.Net (1.0.0.23)


TrendLabs | Malware Blog - by Trend Micro - 3 new articles

 

Your email updates, powered by FeedBlitz

 
Here are the latest updates for security-news@awsoda.net

"TrendLabs | Malware Blog - by Trend Micro" - 3 new articles

  1. Phishing Site Claims Bank Monitors IPs
  2. Phishers Hit Multiple Banks with One Stone
  3. Another al Qaeda News Spam, Now on Video
  4. More Recent Articles
  5. Search TrendLabs | Malware Blog - by Trend Micro

Phishing Site Claims Bank Monitors IPs

A phishing email uses a novel-sounding concept that can sound alarming enough to get unsuspecting users to click on the available links and land themselves in danger.

Trend Micro Content Security team recently came across a Bank of America phishing site which shows users that their online accounts are recently “logged on from an unregistered computer using a foreign IP without an International Access Code (IAC).” Here's a screenshot:


Figure 1. Newly discovered page warning the user of a possible intruder attempt at accessing his/her accounts.

When the verification link is clicked, the page opens a new window containing the phishing page. Users who have fallen for the breach alert will be more than willing to enter their credentials into the login page which, of course, turns out to be absolutely fake. Here is a screenshot of the phishing page:


Figure 2. The verification link in Figure 1 leads to this Bank of America phishing page.

A familiar but still effective phishing technique lends a false sense of credibility to this attack: the use of address bar spoofing to hide the real phishing URL. As seen in the screenshot below, checking the Properties of the phishing page (by right-clicking anywhere on the phishing page and then clicking Properties) shows that the real URL is different from that displayed in the URL address bar.


Figure 3. The URL of the phishing page in Figure 2 is fake. Here we see the real phishing URL in the page’s Properties section.

Users are reminded that banks have never been known to register their clients’ computers to their online banking systems. Although we have yet to see specific spam messages pointing to the site in Figure 1, an attack leveraging these made-up sites will not be too long in coming. Trend Micro Smart Protection Network already blocks this phishing Web site.



Phishers Hit Multiple Banks with One Stone

A spoofed Web site that bears a close resemblance to the legitimate Internal Revenue Service Web page was recently encountered by the Trend Micro Content Security Team. Distributed through spam, the phishing URL http:// {BLOCKED}xxx.javabien.fr/, can be seen in the status bar when the cursor is hovered over the visible link as well as when the email is viewed via a text editor such as Notepad.


Figure 1 Sample of spam containing link to phishing site

The phishing site displays a message telling the user that they are eligible to receive a tax refund of a specific amount. But here comes the interesting part: the user is then asked to select the bank to where the supposed “tax refund” will be credited through a drop-down menu that is displayed in the page.


Figure 2 Screenshot of phishing site

Upon selecting a certain bank, the user will then be redirected to a spoofed login page of whichever bank they had chosen. Below are screenshots of spoofed login pages from the said list:


Figure 3 Spoofed Bank of America login page


Figure 4 Spoofed Capital One login page


Figure 5 Spoofed Wachovia login page

All spoofed login pages of course prompts the user to enter their account credentials. This is a really clever attack; phishers are now making the users unknowingly choose for themselves which phishing attack will apply to them.

The URL of the phishing site is now blocked by the Trend Micro Smart Protection Network.



Another al Qaeda News Spam, Now on Video

It seems like al Qaeda are the terrorists of choice for spammers. Just recently, spammed messages claiming to contain news on Osama bin Laden and the al Qaeda terrorist network were found by Trend Micro researchers. Now here's another one, and it comes with a video.

The spam claims to be from El Comercio - a popular news site in Lima, Peru. It tries to lure users by placing a malicious link that supposedly leads to a video download of Al-Qaeda about their attempt to attack Peru last July 28, 2008.

Figure 1.1 Spam that claims to be from El Comercio

Aside from El Comercio, spammers also used CNN to lure users into clicking the malicious link. Below is a screenshot of the said spam email.

Figure 2.1 Spam that claims to be from CNN

Clicking the link to download the video opens an instance of the user's Internet browser and prompts the user to save the file.

Figure 2.2 Displayed message upon clicking the link on spammed messages

The video file Video_amenaza+Al-Qaeda.exe is detected by Trend Micro as TROJ_DROPPER.ODZ

Users are already protected from this attack by the Trend Micro Smart Protection Network. Spam runs banking on current affairs are really, old news. But as long as people keep falling for them, spammers will keep on using them.



More Recent Articles



Click here to safely unsubscribe now from "TrendLabs | Malware Blog - by Trend Micro" or change subscription settings

 
Unsubscribe from all current and future newsletters powered by FeedBlitz
Your requested content delivery powered by FeedBlitz, LLC, 9 Thoreau Way, Sudbury, MA 01776, USA. +1.978.776.9498

 

Subscribe via email

Enter your email address:

Delivered by FeedBurner

Blog Archive