Monthly Archives: October 2008

The least pleasant aspect of my job

Image (1) 20080910_775.gif for post 22654

The least pleasant aspect of working at SophosLabs is that some of the images in spam or in the spammed URIs are of a disturbing/graphic/illegal nature. We report emails and websites to the UK based Internet Watch Foundation (IWF) and Read more…

Share

More information about critical Microsoft security vulnerability

More information about critical Microsoft security vulnerability

As anticipated in the blog entry I made earlier today, Microsoft has published a highly critical patch (known as MS08-067) for Windows users. Vanja in our labs has described the issue in greater detail on the SophosLabs blog and there Read more…

Share

MS08-067 - an out-of-band Windows critical security update

Default image

When Microsoft decides to release an out of band security update only a week after the regular monthly update you can be sure that we are dealing with a serious issue. You can read more about it in Microsoft Security Read more…

Share

IT staff await critical security update from Microsoft

Image (1) ms-alert.jpg for post 12783

IT system administrators are being warned today about a critical security vulnerability in versions of Windows, which could allow hackers to install malicious code (such as a worm) without user intervention. According to Microsoft versions of its Windows 2000, Windows Read more…

Share

Safari not-so-goody

Safari not-so-goody

If you're anything like me then you'll have a favourite browser that you use most of the time. Even if you have more than one installed on your desktop, my bet is that there's one you use in preference and Read more…

Share

AKILL's hacker accomplice served with three month sentence

Default image

A University of Pennsylvania student has escaped charges related to possessing child pornography, but been sentenced to three months in prison for his part in a worldwide botnet of compromised computers. 22-year-old Ryan Goldstein pleaded guilty to his involvement in Read more…

Share

Fancy a scratch? Anti-virus service by scratch card

Image (2) antv1.jpg for post 22651

This is a new one on me. Today in our spam traps we discovered a UAE company who have a novel approach to providing an anti-virus service. So novel that we had to have a little chat with them before realising Read more…

Share

Ohio Secretary of State's website hacked

Ohio Secretary of State's website hacked

Jennifer Brunner, Secretary of State of Ohio, has confirmed that her official website was hacked earlier this week by unknown intruders. Ms Brunner, a member of the Democrat party, says that no sensitive information was breached in the attack on Read more…

Share

Miley Cyrus hacker gets a visit from the FBI

Miley Cyrus hacker gets a visit from the FBI

A hacker who posted candid photographs of Hannah Montana star Miley Cyrus on the internet was the subject of an FBI raid yesterday. 19-year-old Josh Holly, of Murfreesboro, Tennessee, boasted that he had broken into the Disney teen queen's email Read more…

Share

Results of McAfee-sponsored West Coast Labs anti-virus test

Results of McAfee-sponsored West Coast Labs anti-virus test

Allow me to blow Sophos's trumpet for just one second, in a rather cheeky way, by talking about a recently published anti-virus test. This malware detection test is a bit different from others - as it was sponsored by one Read more…

Share

Two minutes of spam with Google Earth

Default image

Next week we'll be publishing our regular report into the top "dirty dozen" nations - in other words, those countries where the most compromised machines are found relaying spam to the rest of us. It's often a surprise to people Read more…

Share

Korean sex spy jailed for five years

Korean sex spy jailed for five years

In September I blogged about Won Jeong Hwa. Under the cover of touring South Korean military bases to lecture on the evils of Kim II Sung's North Korean communist regime, Miss Won seduced army officers in exchange for military secrets. Read more…

Share

Nicolas Sarkozy et le poisson

Default image

Poor old Nicolas Sarkozy. He's got a lot on his plate. Not only is he busy being President of la belle France and keeping the ravishing man-eating supermodel Carla Bruni entertained, but he's also had his bank account hacked! We've Read more…

Share

Breaking news: Tom Cruise isn't dead

Breaking news: Tom Cruise isn't dead

The last couple of days have seen a flurry of reports debunking a fast-spreading internet rumour that Tom Cruise had fallen to his death while filming in New Zealand. According to the hoax news story, the pint-sized sofa-bouncing film star Read more…

Share

Teen who brought down anti-virus website let off the hook

Default image

Earlier this week I blogged about a secondary school student who had been arrested after a distributed denial-of-service (DDoS) attack against websites in Vietnam. Word has just reached me via local media reports that the authorities have allowed the student Read more…

Share

Teenage hacker admits Scientology DDoS attack

Default image

A teenage hacker has admitted his involvement in a distributed denial-of-service (DDoS) attack against websites belonging to the highly controversial Scientology organisation. 18-year-old Dmitriy Guzner, of Verona, New Jersey, played a role in a crippling assault which flooded websites belonging Read more…

Share

Mobile malware sends premium rate SMS messages

Mobile malware sends premium rate SMS messages

The world of mobile malware isn't completely dormant. Although we have been waiting almost ten years now for the dire predictions of some security companies to come true about the tidalwave of mobile malware waiting for us "real soon now", Read more…

Share

Who creates email hoaxes and why?

Who creates email hoaxes and why?

The resurgence of the Marks & Spencer voucher hoax that I wrote about earlier this week got me thinking. Who is behind all these hoaxes and chain letters, and why were they created? "They don't know better" There is no Read more…

Share

Crafty little redirect used by malware

Crafty little redirect

As discussed previously, redirection - the ability to guide/control user traffic - plays a critical role in today's malware [1]. In this post I will describe a crafty way of redirecting users from a web page. Not new by any Read more…

Share

Serious Badsrc malware magic

Image (1) tutorial.jpg for post 22630

At the end of last week SophosLabs discovered that Adobe's website was linking to a site infected with Mal/Badsrc-C. The infection had been encountered by a business partner of ours who - thankfully - had been defended from the infection Read more…

Share