Monthly Archives: June 2008

SQL attacks: now using .MOBI domains and installing scareware

Image (1) xp-sec-center.png for post 19842

Everyday, I look through the domains we detect as Troj/Iframe-AG because they are the domains associated with the SQL injections that have been plaguing the web over the last few months (1, 2, 3 and 4). This morning I saw Read more…

Share

Viral Versioning

Default image

We've seen increased numbers of viruses this year, not least from the Sality family, and that's included a fair amount of battling with corrupt infections (1, 2). But while analysing the code, I was reminded of an unusual quirk of Read more…

Share

Crime is winning the day

Default image

Just a typical day at Sophoslabs. I wouldn't say quiet exactly, because we never are these days, but nothing especially new, just variations on familiar themes. On the spam front there's been a large number of phishing campaigns as usual. Read more…

Share

World of Warcraft strikes back against game-related cybercrime

World of Warcraft fights phishing

Blizzard, the company behind the popular online role-playing game "World of Warcraft", has announced that it is producing a hardware token device to help protect its gamers against cybercriminals. In a trick nabbed from an increasing number of online banks, Read more…

Share

Advantage, Hackers?

Default image

SophosLabs is identifying more and more websites all the time which are being poisoned with SQL injection attacks. The latest high profile site to catch their attention is the Association of Tennis Professionals, which is carrying scripts designed to infect Read more…

Share

Must reads: If you do anything today...

Sophos at AusCERT 2010 – #DecoDeme

Two recently published articles are definitely worth a read. Microsoft SQL Injection advisory In a previous post [1], I discussed the fact that the recent surge in SQL injection attacks warranted more attention, to alert administrators to the issue. Without Read more…

Share

Game, set and match.

Sophos at AusCERT 2010 – #DecoDeme

Today is the first day of Wimbledon 2008, one of the four grand slams. With a large global audience, viewing figures for these top tournaments are huge. Similarly, the volume of users browsing the various web sites associated with world Read more…

Share

Storm is not gone

Khobe "vulnerability" – no earth shaker

On this quiet Sunday one thing worth mentioning is definitely a new Storm campaign that was spotted in our traps about an hour ago. This time the social engineering technique combines adverts for an alleged pornographic content hosted on a Read more…

Share

Poetic spam? damn..

Default image

We've recently seen an unusually poetic attempt at drawing people in to the 'get rich quick' scams in our spam queues. Someone seems to have actually put a little effort in here; Time is getting short, so you can't afford to Read more…

Share

Install Anti-Virus Software on a Webserver? No need mate!

Image (1) message.jpg for post 19835

When we contact the owners of websites that have been hacked to serve up malware, we often encounter the response "Install Anti-Virus Software on a Webserver? No need mate!". This response is fairly common, and not just from the Linux Read more…

Share

RECon'08 wrap-up

Image (1) recon.gif for post 19834

Several analysts from Sophos recently attended the RECon'08 Reverse Engineering conference held in Montreal. Although not an "anti-virus industry" conference, the quality of trainers, presenters and delegates was outstanding and gave us a chance to mingle and talk to other Read more…

Share

Breaking (malware) news: New earthquake in China! Olympic games under threat of failure!

Image (1) earthquakemal1.png for post 19833

With the Olympic games in Beijing a little over a month away, spammers and malware authors are coming up with new campaigns to take advantage of this highly anticipated event. Today, we received a new spam campaign that reports a Read more…

Share

Scramble! Scramble! SQL injection - time for an alert?

Default image

Sadly, it would appear the recent SQL injection shenanigans [1] are continuing apace. Back in May, I took a look at a couple of weeks' worth of data on the sites we had seen that had fallen victim to the Read more…

Share

The World-Wide iPhone Exchange

Default image

Sophos has just returned from the Apple WorldWide Developer Conference, an annual meet-up of Mac (and this year, iPhone) developers eager to discover and discuss information about what's new in writing software for their favourite platform. If you missed the Read more…

Share

End of the internet - again?

Default image

Every day while I am driving to work I listen to the excellent Today programme on BBC Radio 4. Long time ago when I moved to England I was surprised that a station with almost no musical content was so Read more…

Share

Firefox 3 imminent!

Default image

Today is the day for the release of the Firefox 3 - the first major update from Mozilla since, mmm, Firefox 2. Anyhow, it is eagerly anticipated by many, including those of us who have been using the beta releases Read more…

Share

Harbouring a Criminal

Default image

Several companies have used rootkits for allegedly bona fide purposes. The most notable was when a certain well-known electronics and media company, a personyfication (sic) of reliability some might say, used a third-party driver as part of their Digital Rights Read more…

Share

Happy Father's Day! Have some malware..

Public privacy

Our spamtrap networks have been hit with a new malware attack posing to be an e-card from Regards.com service: The link takes you to a compromised page on a PHP-based forum site, which in turn performs a HTTP redirect to Read more…

Share

Spammer TicketMaster

Default image

With the 2008 European Soccer Championships taking place from June 7 to June 29, 2008, in Switzerland, spammers are taking advantage of it due to the limited availability of game tickets. Today on one of our European spam feeds, we Read more…

Share

Bot Master Bentley Behind Bars - A Small Victory

Default image

When I give presentations or tours of SophosLabs one of the most common questions I am asked is "Do you work with law enforcement agencies to track down the malware authors" my usual response is that "Yes but our help Read more…

Share