Monthly Archives: January 2010

Privacy is not dead, in fact it's more important than ever

Image (1) privacy250.jpg for post 2778

My wife has recently had an issue that illustrates why privacy is important, even in 2010. And without further commentary I share with you Mrs. Wisniewski's guest blog. I'm a full-time student. About two weeks ago, I started getting bizarre Read more…

Share

Leet Chrome bug finders can bag $1337 reward from Google

Image (1) leet-reward.jpg for post 15778

Google has launched a new initiative to encourage vulnerability researchers to report any security holes they find in the Google Chrome browser. Anyone who find a bug in Chrome or Chromium, the open source code used as the foundations of Read more…

Share

Twitter list spam

Image (1) twitter-list-spam.jpg for post 15776

Like many other people I'm on Twitter. Unlike most of the other websites which fall under the social networking umbrella, I've found it an essential part of my professional life - helping me share information about breaking internet threats and Read more…

Share

Facebook unnamed app: Hackers poison search results

Image (1) fbook-unnamed.jpg for post 15766

Thanks to Clu-blog reader Jamie for contacting me regarding a scare that is currently spreading bewteen Facebook users. Users of the social-networking site are warning each other of what is rumoured to be a rogue application, spying on their activities Read more…

Share

Second man admits involvement in Scientology DDoS attack

Default image

A second man has admitted his role in a distributed denial-of-service attack (DDoS) against websites belonging to the highly controversial Scientology organisation that struck the sites in January 2008. According to media reports, 20-year-old Brian Thomas Mettenbrink of Nebraska has Read more…

Share

TechCrunch hacked again, as intruders turn potty-mouthed

Image (2) techcrunch-hacked-again.jpg for post 15760

Top technology blog TechCrunch has been hacked for the second time in 24 hours, with visitors being greeted by an offensive message directed at site founder Michael Arrington. Part of the message posted by the hacker reads: So Arrington, how Read more…

Share

Troj/JSRedir-AK morphs into Troj/JSRedir-AR

Troj/JSRedir-AK morphs into Troj/JSRedir-AR

On Friday, while researching the blog on Troj/JSRedir-AK I noticed a website with an infection of Troj/JSRedir-AK and a new piece of malware (Troj/JSRedir-AR). Like Troj/JSRedir-AK, Troj/JSRedir-AR has two distinct forms: injected into HTML files as a malicious <SCRIPT> tag Read more…

Share

TechCrunch hit by hack attack, says 'we'll be back soon'

Image (1) techcrunch-hacked.jpg for post 15752

TechCrunch, one of the world's top blogs, has been hacked. At approximately 6:20am GMT the site was replaced with this message, linking to a site containing links to adult and pirated material: As far as we can tell at this Read more…

Share

Rogue customer service from rogue antivirus

Image (1) fakeav-efficiency.png for post 20039

Not only do you get the best in rogue antivirus protection... ... you get the best in rogue customer service as well. Unsatisfied customers are invited to perpetuate their own victimization -- by contacting the very same scammers who conned Read more…

Share

Oil companies attacked, espionage not just for Google

Image (1) cuttingbarrel250.jpg for post 3040

The Christian Science Monitor reported today that Marathon Oil, ConocoPhillips, and ExxonMobil were compromised in 2008 by hackers. This attack follows the pattern outlined in the press this month about the Operation Aurora, attacks on Google, Adobe, and other unnamed Read more…

Share

Troj/JSRedir-AK: 40% of a month's malware

Troj/JSRedir-AK: 40% of a month's malware

It has been a month since we added detection for Troj/JSRedir-AK and figures generated today show that over 40% of all web-based detections have been from this malicious code. [Graph shows malware hosted on websites from 2009-12-22 11:00:00 to 2010-01-21 Read more…

Share

Johnny Depp has NOT died in a car crash, but hackers exploit rumours

Image (1) johnny-depp.jpg for post 15744

Hollywood movie actor Johnny Depp, famous for his roles in Edward Scissorhands, Sleepy Hollow and Pirates of the Caribbean, became the unwitting star of an internet hoax.

Share

Hotmail password phishing again

Image (1) hotmail1.jpg for post 25030

I am a very lucky guy. In fact, I must be the luckiest person in the world since spammers like to send all kinds of lucky spam to me. These days, I get inundated with lucky spam. The last spam I Read more…

Share

Can we *prove* China is behind Operation Aurora?

Can we *prove* China is behind Operation Aurora?

Is it possible to prove that the recent hacks against Google, Adobe, and others were sponsored by the Chinese government? It's not that easy. You see, although there's unlikely to be anyone with a better motive for cracking into the Read more…

Share

Continued Sinowal activity

Continued Sinowal activity

After one of my recent blog postings concerning the recent zero day IE vulnerability [1], I received a few questions and comments thanks to one of the comments I made: Finally, and perhaps most worryingly, this type of advice feeds Read more…

Share

Firefox 3.6 checks your plugins are up to date

Image (2) firefox-plugin-check.jpg for post 15737

Yesterday, Mozilla released the latest version of its web browser Firefox and it comes with a rather nice-sounding security feature. Firefox 3.6 claims to be faster than ever before, but that's not why it's caught my attention. The new functionality Read more…

Share

Operation Aurora: Microsoft knew about Internet Explorer flaw for four months

Image (1) bandage.jpg for post 15732

On Thursday there were sighs of relief from all corners as Microsoft released a security patch for a vulnerability that had been exploited by hackers. The patch fixed a critical zero-day vulnerability in versions of Internet Explorer that would have Read more…

Share

Top 20 website passwords you shouldn't be using

Image (1) keys.jpg for post 15727

The folks at Imperva have released a report examining the 32 million passwords that were exposed in a breach of the RockYou website last year. What they discovered (and it matches the findings of other studies conducted in the past) Read more…

Share

Mal/Badsrc-C: Why is Kitchenaid.com still infected?

Image (1) logo_ka.jpg for post 24990

Update: SophosLabs can confirm that the website has now been cleaned up. In August last year, SophosLabs first noticed that a Sophos customer was blocked from visiting a page on the KitchenAid website due to a detection of Mal/Badsrc-C. Over Read more…

Share

Virus Bulletin 2010 Conference - call for papers

Image (1) vb2010.jpg for post 15723

Those awfully nice people at Virus Bulletin magazine are asking for people to submit papers for the VB2010 conference they will be holding later this year. The conference leapfrogs around the world from city to city, and this time it Read more…

Share