Saturday, August 29, 2009

[Lockergnome] Computer Security ~ August 29, 2009

Lockergnome
Lockergnome's Computer Security ~ August 29, 2009   



ClipCache Plus: ClipCache Plus is an easy to use and powerful clipboard extender and a whole lot more! It monitors clipboard activity and aids not only in the management of saved clips, but in cleaning up and modifying those clips in many, many useful ways. Now you can copy and store clips from emails or webpages and remove the annoying ">>>>" marks or huge gaps and spaces left when copying from webpages constructed with webtables. The time... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

Mega Monty: Mix a roulette wheel with a slot machine and a little bit of draw poker and what do you get? BoxerJam's Mega Monty, a high-energy game of skill, strategy, and of course, luck. Climb through more and more challenging levels as you search for the winning score in a quest for "cash" and points. Mega Monty: the casinos never had it so good! But where's the Rat Pack when you need 'em? [Screenshot] [Download Shareware]... [Click Here to Download]

Administrivia

Tech Help and How To


Optimizing Transaction Logs?

The Chic-ness of Complaining About Apple

Snow Leopard is Here!

Windows 7 - XP Mode - No Rhyme Or Reason To CPU Support

Opera Releases Second Release Candidate for Version 10

Snow Leopard Does Offer Malware Protection Of Sorts

10.6 First Impressions

Font War Searches Computer Licensing for Dummies

Asus, A Company Too Small, But Still Too Big

Have Another Round of Sadness, On Me

Apple Says iPhone Explosions, Cracking Caused By Outside Pressure

Governor Schwarzenegger Weekly Address

Chrome ? Perhaps It?s Not The Best Answer? BTW, The Question Was?

Snow Leopard - Are We Sure That Microsoft Didn?t Produce This? LOL

Mega Millions Jackpot Now $325 Million

Hello Hillary Clinton - Let Your People Use Firefox!

Robocalls About to End - September 1!

Thermaltake + BMW - Could Case Design Get Any Better?

WPA Hack Subprime Surveillance Cameras

OpenOffice 3.1.1 Available - Praise, and a Small Gripe


TrendLabs | Malware Blog - by Trend Micro - 4 new articles

 

Your email updates, powered by FeedBlitz

 
Here are the latest updates for security-news@awsoda.net

"TrendLabs | Malware Blog - by Trend Micro" - 4 new articles

  1. Mobile Users Unfazed by Web Threats
  2. Firefox Add-on Spies on Google Search Results
  3. XSS Attack Targets Chinese Social Networking Site
  4. BKDR_REFPRON in New Mass Compromise
  5. More Recent Articles
  6. Search TrendLabs | Malware Blog - by Trend Micro

Mobile Users Unfazed by Web Threats

Users are under the impression that mobile phones are more secure than PCs, according to the latest Trend Micro survey. A number of users are found not practicing safe browsing when using their mobile phones.

The survey shows that 44% of over 1,000 respondents are lax when it comes to surfing using their mobile phones. The respondents are actually more concerned of losing data such as contact numbers via physical phone loss rather than information loss due to Web threats and phishing or spam attacks. In fact, only 23% utilize security software already installed in their phones. Some even believe there is no use for such software as mobile phones are not as prone to security risks.

Quite unfortunate is the fact that users’ assumption that mobile phones are spared of attacks by cybercriminals is very much incorrect, as mobile threats have been around for the past four years now. Trend Micro researchers often see Symbian malware such as SYMBOS_BESELO.A, SYMBOS_VIVER.A, SYMBOS_FEAKS.A, and SYMBOS_YXES.B infect Symbian-based phones. Other notable mobile malware include WINCE_INFOJACK.A and WINCE_CRYPTIC.A, which target Windows mobile phones. These so-called traditional mobile malware are still very much active up to this day as seen in the chart below.

Click for larger view

As mobile phones become more Web-based and as users more heavily rely on them to conduct their day-to-day business, potential risks brought about by phishing and other Web threats will become more rampant as well. Users are advised to be wary when browsing as this could lead them to malware infection and information loss. They are strongly urged to use security software to stay protected from malware infections.

Trend Micro protects mobile users with Trend Micro Mobile Security. It also offers Trend Micro Smart Surfing for iPhone to iPhone and iPod Touch users. These enable users to have worry-free surfing experiences, as they hinder access to malicious sites.

Post from: TrendLabs | Malware Blog - by Trend Micro

Mobile Users Unfazed by Web Threats



Firefox Add-on Spies on Google Search Results

Trend Micro threat analysts were alerted to the discovery of a spyware (detected as TSPY_EBOD.A) purporting to be an Adobe Flash Player update. Upon execution, the spyware creates a Firefox add-on called "Adobe Flash Player 0.2," the installer of which uses JavaScript (detected as JS_EBOD.A) and appears to spread via forum posts.



Click

The said add-on injects ads into the user’s Google search results pages. More disturbing, however, is its capability to monitor the user’s browsing activities, particularly his/her Google search queries using the Firefox browser. It then sends the information it gathers to http://{BLOCKED}jupdate.com.

We have seen a lot of malware target Internet Explorer in the past. This is probably one of the reasons why a huge number of users are opting to use alternative browsers such as Firefox, Chrome, Safari, and Opera instead. Though this used to be considered a safe computing practice before, it seems it no longer is with the proliferation of malware targetting the most popular alternative Internet browser—Firefox.

Users should be wary, as always, of downloading updates from unknown sources. They should also note that no browser is safe from malicious attacks as cybercriminals will do just about anything to infect users with their malicious code.

The Trend Micro Smart Protection Network already detects and consequently blocks the malicious code from running and the malicious add-on for being downloaded so Trend Micro product users need not worry.

Post from: TrendLabs | Malware Blog - by Trend Micro

Firefox Add-on Spies on Google Search Results



XSS Attack Targets Chinese Social Networking Site

Recently we’ve encountered a cross-site scripting attack that targeted the Chinese social networking site Renren. Fortunately for users, it was quite harmless as far as these kinds of threats go—but it could have been much, much worse.

Renren users received messages from their friends with a link that pointed to a video of the Pink Floyd song Wish You Were Here which is detected as SWF_EXECJS.A. When the user clicks the said link it executes SWF_EXECJS.A, which does show legitimate video of the song, as seen below:

Video
Figure 1. Legitimate video played by XSS attack

However as the video is shown, SWF_EXECJS.A connects to a URL to execute a script detected as JS_DLOADR.ATJ. JS_DLOADR.ATJ searches for cookies related to Renren and then sends out messages with a link to the same video to everyone on the user’s list of friends. These routine are all done automatically, without any input or consent from the user.

As it is, the attack was fairly limited, but it could have been much worse. It could have taken a page from KOOBFACE malware and sent out links to malicious sites, for example. Such attacks would be enough to put a truly ironic twist on the video used for this attack. As it is, all it did was annoy some people and embarrass Renren.

Similar attacks that do little have hit social networking sites before, most notably Orkut, which is owned by Google.

Both components of this attack are detected by the Smart Protection Network.

Post from: TrendLabs | Malware Blog - by Trend Micro

XSS Attack Targets Chinese Social Networking Site



BKDR_REFPRON in New Mass Compromise

compromised sites lead to backdoor Trend Micro threat analysts were alerted to another mass compromise attack affecting around 55,000 consumer-oriented sites spread throughout Canada, China, the United Kingdom, and India as of the first report.

This incident is a painful reminder of the persisting risk of unprotected Web-surfing. In this particular case, the malicious scripts injected in the legitimate sites lead to other sites that eventually resolve to the download of the following backdoor programs and components:

The backdoors drop other components and connect to other IP addresses to download other malware with further the risk for users.

Trend Micro Web Threat Protection-enabled products have already been blocking the infection chain starting with the injected scripts’ related domains and URLs down to the URLs hosting the malicious binaries.

As of this writing, searching for the offending script yields 99,000 results.

Post from: TrendLabs | Malware Blog - by Trend Micro

BKDR_REFPRON in New Mass Compromise



More Recent Articles




Click here to safely unsubscribe now from "TrendLabs | Malware Blog - by Trend Micro" or change your subscription or subscribe

 
Unsubscribe from all current and future newsletters powered by FeedBlitz
Your requested content delivery powered by FeedBlitz, LLC, 9 Thoreau Way, Sudbury, MA 01776, USA. +1.978.776.9498

 

Subscribe via email

Enter your email address:

Delivered by FeedBurner

Blog Archive