Monthly Archives: January 2009

D'oh! Malware author leaves "to-do" list in code

Image (2) the-simpsons-d-oh-mini-posters-71133.jpg for post 19956

This morning I found yet more proof that your average malware author is male.  I don't think many people will take issue with the fact that the majority of men are not known for their ability to multi-task. When a Read more…

Share

The worm that turned

Image (2) usb.jpg for post 19955

Amidst growing concern for the destruction of habitat and the extiction of rare species, it is startling that worms, especially of the "USB" ilk, have had a population explosion, somewhat akin to the Cane Toad in Australia. The USB worm Read more…

Share

US military files on lost $15 MP3 player recovered

Default image

Earlier this week it was reported widely in the media that a New Zealand man had discovered confidential US military files on a $15 MP3 player he had bought at an Oklahoma thrift shop. 29-year-old Chris Ogle found on the Read more…

Share

Eighth grade "hacker" sues school district

Image (2) harris-v-pontotoc.gif for post 11997

If you were a student and you hacked into your school's computer system you would probably expect there to be some serious repercussions. In my day it could quite possibly have resulted in a swift thwack on the bottom with Read more…

Share

Google Chrome pretends to be Safari to outfox Hotmail

Image (1) chrome-logo.jpg for post 11996

The Google Chrome web browser has been updated to fix a "high severity" security vulnerability that could be exploited by data thieves. Version 1.0.154.46 of Chrome fixes a few security issues - including one involving the Adobe Reader plug-in that Read more…

Share

IE8: InPrivate browsing and plug-ins

Image (3) ip-add.gif for post 19954

As a quick follow up to my previous IE8 post, I would like to alert users to an easily overlooked consequence of using the new InPrivate browsing mode. Users will use the InPrivate browsing mode when they wish to leave Read more…

Share

FakeAV exploits GreyMatter vulnerability

Default image

With all the recent media flutter about Conficker [1,2,3,4] and the advice by security software vendors to patch and update, it's no wonder that the FakeAV crowd are doing good business, as detailed by Paul Ducklin. Playing on the media Read more…

Share

Wanted: Can you speak Klingon? No time wasters please

Image (1) klingon.jpg for post 11995

Pardon me for interrupting the normal stream of security-related stories here to ask something a little out of the ordinary, but I figured you folks wouldn't mind. Do you speak Klingon? Actually, most importantly, can you translate things into Klingon? Read more…

Share

Podcast: Cybercrime on Facebook and Twitter

Cybercrime on social networks

As we discussed in our recent security threat report, social networks like Facebook and Twitter are the new backdrops to the fight between good and evil on the internet. Spammers, hackers, malware authors and identity thieves are taking advantage of Read more…

Share

Motorists warned of "Zombies Ahead" on hacked road sign

Image (1) zombie-traffic.jpg for post 11993

Normally when I am writing about zombies and hackers I'm discussing the threat of cybercriminals commandeering innocent people's PCs to turn them into a spam-spewing botnet. This one is a bit different however. As reported by Fox News, hackers in Read more…

Share

Fannie Mae worker accused of planting malware timebomb

Image (2) urbana-technology-center.jpg for post 11992

According to media reports, a federal grand jury in Maryland has indicted a 35-year-old man for planting a malicious script, designed to destroy data on the US financial giant's servers. Rajendrasinh Babubhai Makwana, worked for three years as a software Read more…

Share

Debuggered

Image (1) bugger3.png for post 19952

In the recent article, Delete files that don't exist, Stephen described a malware using the registry to delete a certain file upon launching. The same registry key is used in another way now. By adding the following registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Read more…

Share

India's embassy in Spain victim of a malicious attack

Image (1) mac.jpg for post 19951

Sophoslabs has received reports (Passionate about Information Security and Dancho Danchev) that India's Embassy in Spain has been the victim of a malicious attack. We can confirm that the site is indeed infected with Mal/Iframe-F. The site embajadaindia.com imports content Read more…

Share

Boris Johnson, Mayor of London, supports NASA hacker

Image (1) boris-johnson.jpg for post 11991

Boris Johnson, the Mayor of London, has come out in support of Gary McKinnon, the British hacker who faces extradition to the United States. Boris, who is loved by many British people for his very public gaffes and his physical Read more…

Share

The Truth is that legitimate websites are serving malicious content

Image (1) pravda.jpg for post 19950

This morning SophosLabs noticed, via feedback from installation of WS1000 web security appliances, that the website Pravda.ru (which coincidentally celebrated its 10th birthday yesterday) has been serving up malicious content (Mal/Iframe-F). That doesn't seem a great way to celebrate your Read more…

Share

Coming to grips with encryption

Image (3) rich-baldry.gif for post 11990

Rich Baldry is a talented chap. He's not only a product manager based in our Vancouver offices, but he can also play the tuba and walk at the same time. Now he can add another skill to his repertoire, as Read more…

Share

Answers on a postcard please..

Image (1) moster-hacker.gif for post 11989

I'm always happy to get feedback on stories I've featured on the Clu-blog. At the moment you have to drop me an email, but I'm hopeful that soon I'll get the web wizards to give us a comment facility up Read more…

Share

IE8 Release Candidate now available

Default image

As of yesterday the much awaited first Release Candidate (RC1) of Internet Explorer 8 became available for download [1]. I won't bore you with all the details of the features new in this version - you can find that information Read more…

Share

Lil' Kim latest name to be added to the hacked celebrity line-up

Image (1) lil_kim.jpg for post 11988

What is with all these rap stars and computer security? No sooner do I finish blogging about the problems Kanye West is facing with his compromised Gmail, Twitter and MySpace accounts than I hear that his fellow rapper Lil' Kim Read more…

Share

Arrest for 'housebreaker who installed spyware'

Default image

According to media reports from Japan, police have arrested a man who is believed to have broken into a house and installed spyware on his victims' computer. Police claim that 37-year-old Takamasa Kondo stole a door key to a Tokyo Read more…

Share