Saturday, January 17, 2009

[Lockergnome] Computer Security ~ January 17, 2009

Lockergnome
Lockergnome's Computer Security ~ January 17, 2009   



DupeWatcher: Anyone who regularly uses the computer or downloads files from the Internet will find DupeWatcher a must have utility. This smart companion will help you to housekeep your system with ease. Features include: The ability to delete duplicate files The ability to move duplicate files to the recycle bin or a specified folder The compression of such files into a single file using an industry standard ZIP algorithm Include and exclude filter options that allow... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

Teachphysed.com's Top Fitness Tips: "50 fitness tips for exercising amateurs." If we all spent as much time taking care of our bodies as we do tweaking our computer systems, the world would be a healthier place. Ben Pirillo, younger brother of Chris and phys ed instructor, guides you through 50 things to consider when planning any fitness program. From nutritional considerations, to exercises that require no cash investment, to things you can do around the house to increase... [Click Here to Download]

Administrivia

Tech Help and How To


DTV Transition Shows Confusion Between Competing views

Movers by Moov - Portland?s Worst Moving Company

The Negative Side of Toy Safety legislation

Is Belkin Cheating On Reviews?

Young Girl Sends Over 14,000 Text Messages In One Month!

Circuit City Shut Down Will Hurt Best Buy

Good HP/Linux Printing News

PC Power & Cooling : First Steps to Oblivion

Is God Watching The Collaspe Of Circuit City?

Liquidation Sales at Circuit City

CNBC: $7.36 trillion? [federal handout]

What Others Say ? When the Publication Will Allow It

Conficker Worm Continues to Spread

WeatherBug Total Lightning Network Is Live

24 Season 7: Does It Get Any Better?

Inauguration Done - in Legoland

TweetDeck

It Was To Good To Be True - DTV May Be Delayed

Seagate Hard Drives Failing - Warranty Shrinks

Copy Files Fast In Vista Using TeraCopy - Free

Online Web Conferencing for Meetings

Network Tools for Windows

Trade in Your Cell Phones for Money

Get Your Own Web Site

Free Audio Book


TrendLabs | Malware Blog - by Trend Micro - 2 new articles

 

Your email updates, powered by FeedBlitz

 
Here are the latest updates for security-news@awsoda.net

"TrendLabs | Malware Blog - by Trend Micro" - 2 new articles

  1. Security Policy for Dummies - how to avoid WORM_DOWNAD infection
  2. Don't be Fooled by Obama Inauguration Scams
  3. More Recent Articles
  4. Search TrendLabs | Malware Blog - by Trend Micro

Security Policy for Dummies - how to avoid WORM_DOWNAD infection

Quite a few Security Websites and Media outlets have reported on the current wave of WORM_DOWNAD.AD detections over the last few weeks. And last weekend seemed to be a busy time for the worm infecting a considerable number of machines.

Whats noteworthy about this particular beastie is not only the scale of the infections (some estimates put it at over 8 million infected machines), but also the propagation techniques - a 3 pronged attack designed to exploit weak Company Security Policys.

Firstly WORM_DOWNAD.AD sends exploit packets for the recent Microsoft Server Service Vulnerability to every machine on the network, and to several randomly selected targets over the Internet. This vulnerability allows remote code execution for an attacker, and effects just about every version of Windows since Windows 2000.

For its next trick WORM_DOWNAD.AD drops a copy of itself in the Recycler folder (Recycle Bin) of all available removable and network drives. Next it creates an obfuscated Autorun.inf file on these drives, so that the Worm is executed simply by browsing to the network folder or removable drive (the user does not need to actually click on the file). A sign for the infection can be sometimes seen in Windows Explorer when the removable drives are shown with the folder icon instead of the usual drive icon.

And then comes the icing on the cake - It first enumerates the available servers on the Network and then, using this information, it gathers a list of user accounts on these machines. Finally it runs a dictionary attack against these accounts using a predefined password list (more details here). If successful (and a scary amount of the time peoples passwords are that bad), it drops a copy of itself on their system and uses a scheduled task, also known as an AT job, to execute the worm.

So why is this Worm so successful? Simple - poor security policies.

The first propagation technique is really exploiting Poor Patch Management. A patch for this vulnerability has been available since late last year, but still some administrators (or the safety representatives) have not properly rolled this out to all machines on their network.
Remember even one unpatched machine is enough to have this Worm spread through the entire network. Patch Management is a critical component of any IT departments jobs today, and it is vitally important that it is applied in a timely fashion across ALL of the companies machines, including laptops and other mobile devices. Companies also need to have very clear policies on patch levels of external parties who access their network (e.g. Partner Companies, Contractors, etc). Like so many aspects of Security, it only takes one hole to bring down an entire network.

Autorun malware has been a big problem over the last 6 months, and to be honest, it really should be a non-issue. Quick grab a piece of paper and a pencil. Got them? Great, ok - now in 30 seconds try to write down a single reason why your company needs to have the ability for all Removable Drives and Network Shares to automatically execute code just by viewing them. Its ok I’ll wait till you are done…didn’t come up with one did you. Let me save you the pain of figuring out the next step - How to disable Autorun (more details here)

Lastly we have the old classic - using weak passwords. You could write a book on how to ensure users use strong passwords (in fact people already have), but to help save your hard earned money during this economic downturn, we’ve kindly made one available as part of our Safe Computing Guide . Go have a read. After all it would be nice to not have to explain to your boss that every machine in the company is infected because you had picked “123456″ as the default password on all of your machines and shared drives.

To quote my favourite sportsperson Roy Keane - “Failure to Prepare, Prepare to Fail”.

Post from: TrendLabs | Malware Blog - by Trend Micro

Security Policy for Dummies - how to avoid WORM_DOWNAD infection



Don't be Fooled by Obama Inauguration Scams

Barack Obama’s campaign and eventual election to the United States presidency proved an excellent opportunity for cybercriminals in their malicious operations. News about the president-elect was a popular, and most of the time effective, social engineering technique used to trick unknowing Web users into downloading and installing malicious files in their PCs.

Web threats that feature Obama-related baits may have died down after what has been a historic election, however users could expect more of them before and after his inauguration on January, 20th. At the begin of the week TrendLabs researchers predicted that soon cybercriminals will take advantage of this event. Ticket scams were considered to be a most probable cybercriminal attack.

Tickets for the said Washington occasion are for free but they are to be distributed by both Senators and Representatives of the 111th Congress, as reported on the SignOnSanDiego website. Detailed information on tickets may be found at the official web site of  The Joint Congressional Committee on Inaugural Ceremonies .

Spammers might send scamming emails promising their recipients tickets to the inauguration. Non-existent tickets may be offered in exchange for money. Or they may be given away for free; users would just need to click on links or download and print tickets, where the supposed ticket turns out be malicious binaries.

Scams may not be limited to just inauguration tickets alone. The huge demand for hotel rooms, accommodations, and even parking spaces could also be potentially used in Web attacks.

Post-inauguration threats would likely include fake news and fabricated events that again may be used to lead users to malware. Threats could use the same strategies as those we saw in the elections:

We advise Web users to not trust spammed messages and to be careful in clicking unknown links. Several scam warnings are already posted on the Web, and may also provide useful to users.

Trend Micro continues to monitor threats related to Obama’s inauguration.

Post from: TrendLabs | Malware Blog - by Trend Micro

Don’t be Fooled by Obama Inauguration Scams



More Recent Articles



Click here to safely unsubscribe now from "TrendLabs | Malware Blog - by Trend Micro" or change subscription settings

 
Unsubscribe from all current and future newsletters powered by FeedBlitz
Your requested content delivery powered by FeedBlitz, LLC, 9 Thoreau Way, Sudbury, MA 01776, USA. +1.978.776.9498

 

Friday, January 16, 2009

[Lockergnome] Computer Security ~ January 16, 2009

Lockergnome
Lockergnome's Computer Security ~ January 16, 2009   



150+ Microsoft Office Tips: More than 80% of home and business users are running Microsoft Office on their computer. However, the majority of users do not know how to utilize their favorite Office applications to their full potential. Whether you are a home or business user, the 150+ Microsoft Office Tips ebook will help you get the most out of your Office applications so you can use them more efficiently and more effectively. With the 150+ Microsoft Office... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

CompreXX: Archives behave like folders in Explorer! Browse, copy files from, and add files to archives just like any regular folder. Drag, drop, copy, and paste files to and from the archive folders. Perform all archive tasks without ever leaving Explorer, including converting archive types from one to another. Right-Click Explorer Extensions! Create any archive type from the 28 available with a single right click. Create (and e-mail) multiple archives of different types. Extract multiple... [Click Here to Download]

Administrivia

Tech Help and How To


Write The Perfect Wedding Speeches And Toasts

ATi Drivers for Win 7 Beta Pulled

Radio Goes Straight to the Web

Energy-Efficient Water Purification Made Possible By Yale Engineers

Carcinogen Present at Five Schools

The $64,000 Turntable

Vista And WSUS Part II

Can You See Me Now? Flexible Photodetectors Could Help Sharpen Photos

AMD Upgrade Paths

Privacy and A Parent?s Open Letter to Malia and Sasha

LifeLock Follow-Up Report

Wallpaper Picks for January 16th

Honda Adds to Production Halt

Low-Cost Strategy Developed For Curbing Computer Worms

PCMag Lists 173 Free Programs

The Minneapolis Star Tribune Files for Bankruptcy

I Think I?ll Change My Mind

Just A Keyboard?

10 Times Faster Than USB 3.0

It?s been a week. What have we learned from Windows 7?

Online Web Conferencing for Meetings

Network Tools for Windows

Trade in Your Cell Phones for Money

Get Your Own Web Site

Free Audio Book


Subscribe via email

Enter your email address:

Delivered by FeedBurner

Blog Archive