Saturday, September 20, 2008

[Lockergnome] Computer Security ~ September 20, 2008

Lockergnome's Computer Security ~ September 20, 2008
Lockergnome
Lockergnome's Computer Security ~ September 20, 2008   



PicoZip: An easy-to-use file compression utility packed with lots of user-friendly features. You can create archives in 7 formats (BH, CAB, JAR, LHA, LZH, TAR, ZIP), extract files from 17 archive formats (ACE, ARC, ARJ, BH, CAB, GZ, JAR, LHA, LZH, RAR, TAR, TGZ, Z, ZIP, ZOO, UUE, XXE) and create self-extracting archives in 8 formats. Other features: quick backup, batch processing, extensive Windows shell integration, email support, file filtering and archive format conversion. [Get More... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

TrendLabs | Malware Blog - by Trend Micro - MySpace Pages Rigged with Bad Script

 

Your email updates, powered by FeedBlitz

 
Here are the latest updates for security-news@awsoda.net

"TrendLabs | Malware Blog - by Trend Micro" - 1 new article

  1. MySpace Pages Rigged with Bad Script
  2. More Recent Articles
  3. Search TrendLabs | Malware Blog - by Trend Micro

MySpace Pages Rigged with Bad Script

Trend Micro was recently alerted to a possible malware detection triggered when visiting MySpace Web pages. According to reports, certain MySpace pages are being detected as Possible_HiFrm.

Possible_HiFrm is a heuristic detection noted for being effective in detecting malicious iframes and redirects pointing to most of the old and some of the recent Web threats. Possible_Hifrm is Trend Micro’s aggressive pattern used to detect characteristics common to iframes pointing to malicious web sites.

Reports of recent Web site compromises accomplished through iframes include the high-profile SEO attacks, Wired.com and History.com search engine attacks, the mass compromise of various sites in China, Taiwan, etc., and other Asian sites injected with nasty code, most of which have been summarized in Total Recall: The Month of Mass Compromises.

Further analysis reveals the reported MySpace pages do contain malicious scripts that Trend Micro detects as JS_DIRESEX.A. This JavaScript is programmed to secretly connect to a porn site (hence the detection name) which pops up unexpectedly while the user is browsing. Its code is obfuscated three times (whereas a single deobfuscation is already a telltale sign of malicious behavior this side of the industry), in an attempt to make analysis of the JavaScript harder for malware analysts.

Trend Micro has reported to Myspace the findings on the said reports from their users and has not received a reply as of writing. This is not the first time a social networking site has been leveraged to target unsuspecting users. Around three weeks ago we reported about Worms Wriggling Their Way Through Facebook.



More Recent Articles



Click here to safely unsubscribe now from "TrendLabs | Malware Blog - by Trend Micro" or change subscription settings

 
Unsubscribe from all current and future newsletters powered by FeedBlitz
Your requested content delivery powered by FeedBlitz, LLC, 9 Thoreau Way, Sudbury, MA 01776, USA. +1.978.776.9498

 

Friday, September 19, 2008

[Lockergnome] Computer Security ~ September 19, 2008

Lockergnome's Computer Security ~ September 19, 2008
Lockergnome
Lockergnome's Computer Security ~ September 19, 2008   



Video Edit Magic: If you think all professional video editing software is expensive, think again. Video Edit Magic is a Windows video editing application that gives you high-end power at an entry-level price. Its drag-and-drop interface makes it easy to capture video footage onto the editing timeline and assemble a movie in mere minutes. Then add professional scene transitions, some background music, a couple of title effects, and get ready to show the world your finished masterpiece. You... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

US-CERT Current Activity - VMware Releases Security Advisory VMSA-0008-0015

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

US-CERT Current Activity

VMware Releases Security Advisory VMSA-0008-0015

Original release date: September 19, 2008 at 9:51 am
Last revised: September 19, 2008 at 9:51 am


VMware has released a Security Advisory indicating it has updated the
ESXi and ESX 3.5 packages to address a vulnerability in "openwsman".
This vulnerability is due to several buffer overflow conditions in the
handling of HTTP basic authentication headers. Exploitation of this
vulnerability may allow a remote, unauthenticated attacker to execute
arbitrary code on the host running ESXi or ESX.

US-CERT encourages users and administrators to review VMware Security
Advisory VMSA-0008-0015 and apply any necessary updates to help
mitigate the risks.

Relevant Url(s):
<http://www.vmware.com/security/advisories/VMSA-2008-0015.html>

====
This entry is available at
http://www.us-cert.gov/current/index.html#vmware_releases_security_advisory_vmsa

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iQEVAwUBSNOv3nIHljM+H4irAQLwRggAq0b2umRTEy0lpbXft1+NEvJHTPQB9GP9
JJQSAPv2a6/cnnzHg/L7AhTxdlruUXzPARBok+vb0W3tFVHAt9NusSG1xkTjsYpM
toH7Gg6OfgL9CT6n3D8UvjYDlY4b0OosIoHc7GDvhrpF0WnG9pDp1rcLatJovFGL
THw++buICObc3UK/LxT4GJJW7sKrS9RB0iz1fc/wvCmPLBSTRI7OjONZMt5/6DHX
fJ2KWmS/SnX743PGztdsxDcaE9h8Ah8LOwTIYW5p88bDpWXuBngFA7qva7Nc9OZt
qu/hhd30VvgStLAie2QJYbgjdeQr+VJ7dOOJlKetHKUpNttAyhbI4g==
=9v20
-----END PGP SIGNATURE-----

GAO official: Delay won't derail SBInet

Having trouble viewing this email? View as a web page.
Federal Computer Week  logo Daily News
September 19, 2008
http://www.fcw.com
Daily News for IT professionals in government
FCW Insider:
Wanted: Inaugural speech writer



Read More

Klossner: 10 signs you have too many
contractors on staff



Read More

SPONSORED BY
newsletter sponsor advertisement
FEDERAL IT NEWS
SPONSORED BY - DLT Solutions
Storage will cost less than you think.

New freedom of information laws require government agencies to quickly search for and produce electronic information. DLT Solutions and Symantec offer unparalleled archiving and search functionality to help meet these demands, without increasing storage costs. It’s not only convenient. It’s crucial. For information on special pricing and a quick one-hour quote turnaround call DLT today at 888-262-4DLT or visit dlt.com/quickquote.
SPONSORED BY
newsletter sponsor advertisement
SPONSORED BY - IBM
Government 2020

Government 2020: Read how six evolving global drivers will impact the future of state, local and federal governments, and learn how to create a plan to be better prepared to address the resulting mix of opportunities and unexpected threats. Click here for your complimentary copy of the IBM Government 2020 and the Perpetual Collaboration Mandate paper.
SPONSORED MESSAGE

Don’t miss the 9th Annual Security Conference and Exhibition: Information Assurance and Enabling Identity Management.
Held November 20-21, 2008 at the Ronald Reagan Building in Washington, DC, the event is focused on topics that transcend the government transition, with particular emphasis on programs and priorities that must be sustained to protect public sector assets—people, information, and facilities. You’ll learn directly from security professionals in government and industry about pending and current security policies that impact daily operations, as well as priority programs underway and planned for 2009 – 2010. The Exhibition and Professional Education Sessions on Thursday, November 20th are FREE to Government Professionals. Register online at www.SecurityITConference.com or call 800-746-0099.

FCW MARKETPLACE: PRODUCTS AND SERVICES FROM OUR SPONSORS

IT Asset Management software now on Federal BPA contract
Belarc has been awarded DoD Enterprise Software Initiative Blanket Purchase Agreement for IT Asset Management software, maintenance and services. Click here for details and contact info.

Boost Your Federal Sales
Win more business using INPUT's government market intelligence. Find qualified contract opportunities, teaming partners, key government contacts & more... See why over 30,000 of your peers rely on INPUT to win government business - Get a Free Trial!

Federal IT Market Forecast 2008-2013 - Free Executive Summary
Get a detailed view of federal IT spending and a market forecast covering the next 5 years. INPUT provides critical recommendations to help you maximize your government business planning and win more federal business. Download a Free Exec Summary!

Federal Organization Charts & Contacts Directory
Get access to 280,000 key government contacts within 450 civilian and DoD agencies, departments and offices. Build powerful agency relationships using INPUT's Dynamic Organization Charts & Contacts Directory. Download a Free Organization Chart!

Better Solutions; Proven Results; Program Success
SSCI provides members with the tools, resources and collaborative training they need to engineer even the most complex systems and software development programs. Learn more about our capabilities.

Federal Computer Week
1105 Government Information Group
3141 Fairview Park Drive, Suite 777
Falls Church, VA 22042
703-876-5100

Subscribe via email

Enter your email address:

Delivered by FeedBurner

Blog Archive