Friday, January 30, 2009

[Lockergnome] Computer Security ~ January 30, 2009

Lockergnome
Lockergnome's Computer Security ~ January 30, 2009   



OutBack Plus 5: If you use Microsoft Outlook, you've come to depend on it as one of the most important applications on your system. Is your data safe? Viruses, worms, trojans, power surges, hard drive failure, and human error are just some of the many ways that you can lose data from your PC. While most users understand the importance of backing up their precious information, many find that doing so is time consuming, complicated, and too technical.... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

Aloha TriPeaks: Take a balloon ride over the Hawaiian Islands with the next in the smash-hit Aloha series of classic solitaire games! Relax and discover the islands, without leaving the comfort of your home. Aloha TriPeaks can be played in two different modes with power-up cards to help you get to the next level. Embrace the spirit of Aloha! [Download Free Trial]... [Click Here to Download]

Administrivia

Tech Help and How To



US-CERT Current Activity - Novell Releases Updates for GroupWise

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

US-CERT Current Activity

Novell Releases Updates for GroupWise

Original release date: January 30, 2009 at 11:53 am
Last revised: January 30, 2009 at 11:53 am


Novell has released updates for GroupWise 7 and 8 to address multiple
vulnerabilities. These vulnerabilities may allow an attacker to
execute arbitrary code, compromise a GroupWise account, conduct
cross-site scripting attacks, or obtain sensitive information.

US-CERT encourages users to review the Novell download page and apply
the appropriate patch to help mitigate the risks.

Relevant Url(s):
<http://download.novell.com/index.jsp?tab=patches&page_num=1&build_type=PatchBuildBean&patch_security_alert=on&search_type=&search=Search>

<http://download.novell.com/Download?buildid=nmtA5V6zRo4%7E>

====
This entry is available at
http://www.us-cert.gov/current/index.html#novell_releases_updates_for_groupwise

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iQEVAwUBSYM2K3IHljM+H4irAQJCvAgAi5zWisk/H7sig+dpYdIIHQwjQvJEWOV/
VpoBWYicEnATE3H1OW/QMvinBIrx4w/X3k+2vzw04sMncr6Q+gqeVDxkUbvUE/17
LIhZKhW7jygJWwwe6cuEzInBTRzz5FcyvG7t8N4oLlLBOANSGnljpj+9dc5KzurC
6ycB2n9puVlWNkgl2LGEB6M+cLnI3+qpqu9aKw/TFpB9RvSwPfk/LWTKLyX3a2ge
5b+4WtxMuY2mpB3jCBLCnoBkfdnXygTUNlWVbLXN2g3uEqrSfcH1BBVsRf1+wS06
AsS2hSIe3eqZZxERQHv1ERlSDgH5lzObwhMHvp3ZZD1QI7+N5xRuQA==
=/T/j
-----END PGP SIGNATURE-----

Auditors: DOD, VA need measures to track electronic health record progress

Federal Computer Week: January 30, 2009 Federal Computer Week Daily News
  • Having trouble viewing this email? Click here to view as a web page.
FCW
Daily News
1/30/2009
Daily news for IT professionals in government
SPONSORED BY
newsletter sponsor advertisement
SPONSORED BY
Green Computing - Web 2.0 - Government Health IT - Security
New challenges, same place to tackle them. For over 35 years, FOSE has been the one IT event known government-wide as the annual meeting place for the industry. Register today to learn, network, share experiences, and evaluate products, services, and solutions from over 400 industry partners. FOSE, March 10-12, 2009, Washington, DC.
MORE POLICY AND MANAGMENT NEWS
SPONSORED BY
newsletter sponsor advertisement
SPONSORED MESSAGE
  • Federal Computer Week
    1105 Government Information Group
    3141 Fairview Park Drive, Suite 777
    Falls Church, VA 22042
    703-876-5100

TrendLabs | Malware Blog - by Trend Micro - Embassy Site Attack Reveals Other Compromised Sites

 

Your email updates, powered by FeedBlitz

 
Here are the latest updates for security-news@awsoda.net

"TrendLabs | Malware Blog - by Trend Micro" - 1 new article

  1. Embassy Site Attack Reveals Other Compromised Sites
  2. More Recent Articles
  3. Search TrendLabs | Malware Blog - by Trend Micro

Embassy Site Attack Reveals Other Compromised Sites

The purpose of embassies as a diplomatic channel is continuously being tainted by cybercriminals. Initially reported by researcher Dancho Danchev in his blog, the Indian Embassy in Spain was found serving malware through an injected malicious iFrame.

The said malicious injected iFrame leads to a file detected by Trend Micro as BKDR_TDSS.CG. Trend Micro researchers are currently analyzing file to identify its routines.

Investigations by Trend Micro researchers also reveal that aside from the malicious iFrame, a different and large amount of code was also inserted into the website of the said embassy. Numerous

tags were found in the site, with headers containing links to various websites. The said headers are hidden from unknowing visitors, though, since the code is set where the size of the header is too small to be visible.


Figure 1. Screenshot of code found inserted into the Indian Embassy website

Further analysis also suggests that the Indian Embassy website isn't the only one injected with the codes, pointing to the possibility of a massive and global code injection attack. The set of injected codes was also reported to change from time to time.

Trend Micro Advanced Threats Analyst Ryan Flores also revealed that there is inserted code in the compromised websites that injects pages that look like blog entries into the compromised sites’ domain. The inserted pages contain various pharma information. Flores then states that this is possibly an SEO poisoning scheme, or a plot to use the legitimate domains of the compromised websites to evade spam filters.


Figure 2. Inserted pharma blog entries in one of the compromised websites

Though no trace of malware was found in the other links, Trend Micro Antivirus Engineer Edgardo Diaz, Jr. suggests that this is possibly an advertisement scam or a massive malware attack in its early stage. This would also explain why parts of this threat do not appear to be fully functional. He warns, though, that since the website is already compromised, it's just a matter of modifying the tags to turn the seemingly "non-malicious" injection of code into a full-blown malware attack.

Updated 5:49 PM: BKDR_TDSS.CG drops a rootkit that is then injected into SVCHOST.EXE. While injected, the rootkit attempts to connect to several websites to send and receive information.

Post from: TrendLabs | Malware Blog - by Trend Micro

Embassy Site Attack Reveals Other Compromised Sites



More Recent Articles



Click here to safely unsubscribe now from "TrendLabs | Malware Blog - by Trend Micro" or change subscription settings

 
Unsubscribe from all current and future newsletters powered by FeedBlitz
Your requested content delivery powered by FeedBlitz, LLC, 9 Thoreau Way, Sudbury, MA 01776, USA. +1.978.776.9498

 

Thursday, January 29, 2009

[Lockergnome] Computer Security ~ January 29, 2009

Lockergnome
Lockergnome's Computer Security ~ January 29, 2009   



Email Newsletter Usability: Users have highly emotional reactions to newsletters. This is in strong contrast to studies of website usability, where users are usually much more oriented towards functionality. Even a website that you visit daily will feel like a tool where you simply want to get in and get out. The positive emotional aspect of newsletters is that they can create much more of a bond between user and company than a website can. The negative... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

Hijacking .NET - Volume 1: Role Based Security: Hijacking .NET is today's equivalent of using undocumented Windows API functions. Except that not only are the functions under discussion undocumented, they are actually private - functions internal to the .NET framework that were never intended to be used from outside. [ Available in PDF Format for $10 / Download ]... [Click Here to Download]

Administrivia

Tech Help and How To



Subscribe via email

Enter your email address:

Delivered by FeedBurner

Blog Archive