- SophosLabs: Anatomy of a security hole - the break that broke sudo http://t.co/IsIQeuZ112 minutes ago
- SophosLabs: State of Utah outlines mistakes made allowing theft of 780K records http://t.co/KojHRCTC54 minutes ago
- gcluley: What can secure software development learn from Bill Shakespeare? http://t.co/aGpajSnrabout 1 hour ago
- SophosSupport: How to uninstall Sophos Mobile Security for Android: http://t.co/aQedSnXnabout 2 hours ago
- gcluley: TV tech hacked sports show's website to earn virtual cash http://t.co/zfPCm2mzabout 2 hours ago
Monthly Archives: July 2008
Scriptable SFX and Multi-Component malware
For the most part malware is easy to identify and categorise as it's often either an individual malicious file or a small collection of malicious files, but the scripting capabilities of most archivers and installers is changing this. As I Read more…
World war III has started! US has invaded Iran! Click here to see the firsthand video!
Don't worry readers, a new war hasn't started. What you see instead is the latest is the latest campaign from the Dorf (Storm) botnet. Just 4 days after after the Independence day fireworks campaign, the Dorf authors are back with Read more…
Hello Kitty, Goodbye Viruses?
I thought I had seen it all. I've been working professionally in the anti-virus business since January 1992, and in that time I've seen anti-virus companies quote the Moomins in their press releases, produce a rap song video and even Read more…
Siberia 2 - this time it's personal
An update for those of you following the saga that is Pushdo (1, 2). We're still seeing unusual API calls, but recent variants have two slight variations on this theme. Firstly they check memory for the presence or absence of Read more…
The niggling b's: Another chapter in the SQL injection story
Besides using Sophos Anti-Virus, a manual way of confirming a page having been hit by one of the recent SQL injection attacks was to run the following command: egrep -ri '\/\w\.js>' * The main script name has been b.js but Read more…
Javascript scanner - just what the doctor ordered.
A Javascript online threat scanner? Ok, not really, just another scam we have been seeing in recent weeks, which I took a closer look at over the weekend. A while back, I analysed all of the malicious Troj/Unif-B threats we Read more…
From Dorf: Happy 4th of July
Independence day has always been a big event for our neighbors south of the border. For the Dorf (Storm) authors, this is no exception. After staying dormant for a day, the Dorf botnet launched the latest campaign at 13:00 PST. Read more…
Sony PlayStation website malware infection - revisited
Yesterday's blog on "Sony PlayStation succumbs to SQL attack" raised some questions. Is the site still infected? What is scale of this attack? Who else has been hacked? Why mention Sony PlayStation? How can I protect my site? The good Read more…
Malicious MySpace Tom!
Everyone who's ever had a MySpace account knows Tom. Tom is everyone's friend, like it or not. So getting an email telling you Tom has sent you a message is a perfectly plausible notification for any MySpace user. If you Read more…
Avoiding SQL injection attacks
SophosLabs - the bloggers revealed
Since we started the SophosLabs blog back in April 2007 we've been asked a few times to share a little information about the people who post up here. The SophosLabs blog is updated around the clock, seven days a week, Read more…
What happens when we find an infected website?
Regular readers of the SophosLabs blog will be well aware of the recent large scale infection of web servers by SQL injection attacks. With the rise in compromised high-profile websites such as Sony PlayStation and the Association of Tennis Professionals, Read more…
Sony PlayStation site succumbs to SQL attack
Over the last few months we have mentioned the current wave of SQL injection attacks plaguing the web (1, 2, 3 and 4). Yesterday, we spotted that Sony's USA PlayStation website - a high profile website with a large number Read more…
Every 50 seconds, someone loses their laptop at a US airport
We've all heard the expression "in a blink of an eye", but when it is connected to the loss of expensive computer hardware containing your company's confidential data it becomes a startling statistic. PC World reports that over 12,000 laptops Read more…
Critical Microsoft update via Amazon EC2?
This past weekend a fairly typical malware campaign started to arrive on our global network of spam traps, using the common technique of disguising itself as an "Important Windows Update". Its characteristics are mostly what you would expect from spammed Read more…

