Saturday, September 13, 2008

[Lockergnome] Computer Security ~ September 13, 2008

Lockergnome's Computer Security ~ September 13, 2008
Lockergnome
Lockergnome's Computer Security ~ September 13, 2008   



ZipBackup: Hard disks can and do fail, and if you send them to a data recovery center for retrieval, there's no guarantee they can get the data back safely. Even then, if they have to take your hard drive into a clean room and try to rebuild it, costs could even run into the thousands. If you're looking for an easy and inexpensive solution, consider ZipBackup. ZipBackup's Wizard walks you through a simple step-by-step process for... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Friday, September 12, 2008

[Lockergnome] Computer Security ~ September 12, 2008

Lockergnome's Computer Security ~ September 12, 2008
Lockergnome
Lockergnome's Computer Security ~ September 12, 2008   



Chess Vision Trainer: Chess Vision Trainer is a chess training system (patent rights reserved) to improve your visualization and move calculation skills in chess. Visualization and calculation plays a major role in chess. These are the skills that separate the masters from the amateurs. When Alekhine was asked "How many moves do you see ahead?" his answer was "Just one move deeper than my opponent!" The built-in chess playing engine acts as your spar. The position displayed on... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

US-CERT Current Activity - Apple Releases iPhone v2.1

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

US-CERT Current Activity

Apple Releases iPhone v2.1

Original release date: September 12, 2008 at 1:46 pm
Last revised: September 12, 2008 at 1:46 pm


Apple has released iPhone v2.1 to address multiple vulnerabilities in
Application Sandbox, CoreGraphics, mDNSResponder, Networking, Passcode
Lock, and Webkit. These vulnerabilities may allow an attacker to
execute arbitrary code, conduct DNS cache poisoning attacks, spoof or
hijack TCP sessions, bypass Passcode Lock, obtain sensitive
information, or cause a denial-of-service condition.

US-CERT encourages users to review Apple document HT3129 and upgrade
to iPhone v2.1.

Relevant Url(s):
<http://support.apple.com/kb/HT3129>

====
This entry is available at
http://www.us-cert.gov/current/index.html#apple_releases_iphone_v2_1

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iQEVAwUBSMqsJHIHljM+H4irAQLmQAgAvsVvd44RxpxmLY52J3BNW/s2LVtDIR84
NpTSPXExj1k+w7olIPJmS+8Iw1qYuDn5jVVeVdlhWaABuZCh4RxoV93fkWXoFfAs
oMl/oHSnFQ63hKERKeFiBjyaZgUmbEV1M6Cx6kxp+W5HJBrtdbtEbLASVPvDRUCQ
Of8wvIUny8Y62JUeqNXktMHlRWL8wZOKwyLgmfqu4TtQL6HnHzCuagRYpQKYGt3k
amfNaTkkDG8PpRfsKtBm1LANHYea0q57jq4uYi2He5YEOPZlHSHt2Ts06sbaw1MH
KrrcIsjWN9csJuB0mfovtYqvCXTq7a+vJtemaIxJ3nx9lWp6wcCCsg==
=lNFZ
-----END PGP SIGNATURE-----

US-CERT Current Activity - TWiki Releases Security Alert

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

US-CERT Current Activity

TWiki Releases Security Alert

Original release date: September 12, 2008 at 12:38 pm
Last revised: September 12, 2008 at 12:38 pm


TWiki has released a Security Alert to address a vulnerability. This
vulnerability is due to the way TWiki processes the "image" variable
in URLs. Exploitation of this vulnerability may allow a remote,
unauthenticated attacker to execute arbitrary code.

US-CERT encourages users and administrators to review the TWiki
Security Alert and apply the workaround listed in the Countermeasures
section of the document or upgrade to version 4.2.3 to help mitigate
the risks.

Relevant Url(s):
<http://twiki.org/cgi-bin/view/Codev/TWikiRelease04x02x03>

<http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2008-3195>

====
This entry is available at
http://www.us-cert.gov/current/index.html#twiki_releases_security_alert

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iQEUAwUBSMqcGnIHljM+H4irAQI7UAf3dUBLQHZ9vM+iZxc8RpQIH9LQ7lM67vYl
tKTZ/TRH+Sst3XNzvXxhBT229cRq20H99FvkWk44dtdd0OqGydMr0kevqaC6J8d2
vLDJamqQwvrJvrUcf+qDgWTz2FyF1ha3I6tQ7IREJoVUsIC6sqygVYNun5uU8pFi
4D65N2DS06l2T+t+qRJWsw77ndRNov2sVHjO6qItWKs7VQ3KqV/ttD/bW0s6jsFr
psWGhIQrGZOVhk7gTepxf8cnV9WLjbzf3GGtvw6YE9bsxQJFitCb8BNdGwwZpkw9
oOncIDLUdLJ7wMmISlyBFC2pT6vj/n38qz0p2s69QxbDnmSwjKYp
=LAxV
-----END PGP SIGNATURE-----

National committee sets goals for open-source info

Having trouble viewing this email? View as a web page.
Federal Computer Week  logo Daily News
September 12, 2008
http://www.fcw.com
Daily News for IT professionals in government
What would make feds happier on the job?


Read More

FCW Insider: Is micromanagement a problem at federal agencies?


Read More

SPONSORED BY
newsletter sponsor advertisement
FEDERAL IT NEWS
SPONSORED BY - SAP
Public Sector solutions from SAP

Help improve the efficiency of your public sector organization with an SAP solution. Click to find out how SAP software helps to reduce costs and streamline processes so your organization can stay as effective as possible.
SPONSORED BY
newsletter sponsor advertisement
SPONSORED MESSAGE

Government Insights: Extensible Content Management with XML
Learn about XML basics, details on how the government is using XML including active standards initiatives, benefits and challenges of using XML, as well as the latest information on the emergence of XML platforms.

FCW MARKETPLACE: PRODUCTS AND SERVICES FROM OUR SPONSORS

Adobe Government Solutions on GSA Schedule
Get all Adobe products & services through Carahsoft; special government pricing through Sept 30.

Federal IT Market Forecast 2008-2013 - Free Executive Summary
Get a detailed view of federal IT spending and a market forecast covering the next 5 years. INPUT provides critical recommendations to help you maximize your government business planning and win more federal business. Download a Free Exec Summary!

Top 10 Small Business Set-Aside Technology Opportunities of 2008
Free Report - This INPUT report examines the Top 10 Small Business Set-Aside Federal Technology Opportunities across the government, accounting for an anticipated $4.4 billion in contractual ceiling value. Download Free Report!

Free White Paper: Accelerate Gov't Apps 2500%
Sign up to learn how solid state disks boost application speed for lots more users and transactions.

Need Help Migrating to IPv6?
Spirent Federal Systems is the industry leader in IPv6 Migration Testing. Military programs have to migrate to IPv6. Government agencies turn to Spirent Federal Systems to certify networks are fully compliant. Click to learn about IPv6 testing.

Federal Computer Week
1105 Government Information Group
3141 Fairview Park Drive, Suite 777
Falls Church, VA 22042
703-876-5100

TrendLabs | Malware Blog - by Trend Micro - News Videos, Anyone?

 

Your email updates, powered by FeedBlitz

 
Here are the latest updates for security-news@awsoda.net

"TrendLabs | Malware Blog - by Trend Micro" - 1 new article

  1. News Videos, Anyone?
  2. More Recent Articles
  3. Search TrendLabs | Malware Blog - by Trend Micro

News Videos, Anyone?

Keeping the texts short and malicious, the spam our filters caught this time use catchy headlines so absurd they could actually pique their readers’ curiosity.

Below are screenshots of spammed email messages:

The address bars and Subject fields carry sensational headlines whose details supposedly are in the attached video. The said attachment is a compressed file, which when opened contains not a video but a malicious executable file named Exclusive.Cut.avi.exe. The file uses the double extension technique commonly used by malware authors to trick users into executing a malware. Trend Micro detects the malicious file as TROJ_FAKEALER.FR.

Some of the spammed messages here use prominent news organizations like CNN and BCC to look more credible, a technique popular with spammers as seen in several previous spam runs. CNN in particular looks to be a favorite. We blogged about at least three runs featuring fake CNN news last August (see our posts here, here, and here).

Also, another angle we see here is this run’s possible connection to the spate of rogue-AV-related spam runs the past few weeks. TROJ_FAKEALER.FR makes HTTP requests to URLs to download files (these files may, of course, change anytime). One of the files displays a fake bluescreen while the other is a TROJ_RENOS variant, a downloader known to download rogue AV components. Other spam runs that have been seen to download rogue AV include the Paris spam run, the “Free Windows Update” spam run, and bogus celebrity videos.

The Trend Micro Smart Protection Network already blocks the spammed message and protects users from the malicious attachment. Users are always advised to be cautious of unsolicited and unexpected email messages, as the attachments they carry may be harmful to systems.



More Recent Articles



Click here to safely unsubscribe now from "TrendLabs | Malware Blog - by Trend Micro" or change subscription settings

 
Unsubscribe from all current and future newsletters powered by FeedBlitz
Your requested content delivery powered by FeedBlitz, LLC, 9 Thoreau Way, Sudbury, MA 01776, USA. +1.978.776.9498

 

Subscribe via email

Enter your email address:

Delivered by FeedBurner

Blog Archive