Monthly Archives: February 2010

Malware attack spammed out disguised as email settings file

Image (1) settings-file.jpg for post 15901

Sophos is intercepting a large number of malicious emails that have been spammed out around the world, posing as a new settings files for internet users' email systems. However, attached to the emails is a Trojan horse. Each email is Read more…

Share

New spam wave hits Twitter: "Get bigger and have sex longer"

Image (1) get-bigger-sex-longer.jpg for post 15898

Many Twitter users still haven't got over this weekend's BZPharma LOL phishing attack, and now a new campaign is being spammed out from compromised accounts directing users to a site selling herbal viagra to improve sexual performance. A typical spam Read more…

Share

Hiding in plain sight

Hiding in plain sight

There are many forms of malcode concealment, from the "obfuscated beyond recognition" to "in plain sight" yet seldom have we seen hijacking of compiler runtime stubs (although infection of compilers, ala Induc, has already been explored and exploited [2,3]) Obfuscation Read more…

Share

Sexy Twitter spammer promotes adult websites

Sexy Twitter spammer promotes adult websites

I am quite used to strangers following me on Twitter, and normally I presume they're doing it to keep up with the latest security news. However, occasionally my followers have no interest in information security, but lots of interest in Read more…

Share

Video of Twitter phishing: The BZPharma 'LOL this is funny' attack

Image (2) bebo-phishing-small.jpg for post 15885

Twitter users are being warned about a widespread phishing attack spreading across the system, designed to steal the usernames and passwords of unsuspecting members. Messages include Lol. this is me?? lol , this is funny. Lol. this you?? followed by Read more…

Share

The first good BSoD

Image (1) tdssbsod.jpg for post 2780

Perhaps this title should read "Blue screen of blessing." Yes, you are reading that correctly. BSoDs can occasionally have a back-handed benefit. Last Tuesday after Microsoft released its latest batch of patches, complaints started streaming in that there was a Read more…

Share

European Internet Explorer users invited to choose another browser

Image (1) browser-select.jpg for post 15879

Starting next week, European users of Internet Explorer may expect to see an invitation to choose an alternative browser for surfing the worldwide web. As part of a settlement of a long-running anti-competition dispute with the European Union, Microsoft has Read more…

Share

What the Zeus!? Kneber botnet unmasked

Image (1) zeus.jpg for post 15871

Media reports from yesterday about a "broad new hacking attack" against corporations and government agencies gained a lot of attention. Here are just a handful of the heart-stopping headlines we saw: More than 75,000 computer systems hacked in one of Read more…

Share

73% of adults have received a scam email in the last year

Image (1) scamnesty-bin.jpg for post 15868

Well done to the British Office of Fair Trading for dreaming up an imaginative method to raise awareness of scams amongst the general public. Aside from providing a contact email address for internet users to report scam websites and messages, Read more…

Share

Tour de France cheat accused of hacking into doping lab

Image (1) floyd-landis.jpg for post 15861

A US cyclist who was stripped of his title of Tour de France winner in 2006, after being found with unusual levels of testosterone in his body, is wanted in connection with an alleged hack attack against the French anti-doping Read more…

Share

Please Rob Me site exposes danger of sharing too much information online

Image (1) please-rob-me.jpg for post 15857

Users of sites like Twitter and Foursquare will be all-too-familiar with seeing messages from friends broadcasting their current location and - through implication - that they're not at home. A new website called Please Rob Me mashes together content from Read more…

Share

Anatomy of a scam

Image (1) advance-fee-launch.png for post 1451

Advance fee fraudsters (AFFsters) trick well-meaning people out of millions of dollars a year. Basic AFF works exactly as the name suggests. "Hello, victim! Please send me money up front! Your rewards come later." Except, of course, they don't. More Read more…

Share

MP feels the heat after 'scum-sucking' tweet

Image (1) david-wright.jpg for post 15854

British MP David Wright has found himself in hot water this week after being accused of posting an offensive message about his Tory party rivals on Twitter. The Member of Parliament for Telford, Shropshire, made the headlines when a message Read more…

Share

Critical security update for Adobe Reader and Acrobat

Image (2) adobe-links.jpg for post 15842

Adobe has issued a security bulletin urging users of its Adobe PDF Reader and Acrobat products to update their software before hackers take advantage of two critical vulnerabilities. Adobe Reader 9.3 for Windows, Macintosh and UNIX, Adobe Acrobat 9.3 for Read more…

Share

A bad first week for Google Buzz

Image (1) google-buzz.jpg for post 15838

I've just returned from vacation to find that the everyone is buzzing about.. well, Google Buzz. Google's launch of a Twitter-style social network, embedded into its popular Gmail service, was always bound to make headlines of course, but it became Read more…

Share

Furthermore, a grand piano ruminates,

Image (1) coffee-spam-0.png for post 25147

Now and then, a photon from a bartender throws the grizzly bear of an inferiority complex at a resplendent CEO. When you see the worldly maelstrom, it means that a fruit cake starts reminiscing about lost glory. When a pine Read more…

Share

Fake Conflicker.B Infection Alert puts internet users at risk

Image (1) conficker-b-malware.jpg for post 15833

The global network of spamtraps controlled by the experts inside SophosLabs are seeing a swarm of attacks today, posing as an email warning about the Conficker worm. Here is a typical message that has been spammed out by hackers: Subject: Read more…

Share

ISPs, Governments and Cybercrime

Default image

In the past two weeks, all three arms of Australian government – the legislature, the executive and the judiciary – have been in the international IT spotlight. In a globally-watched lawsuit, the Australian movie industry took local ISP iiNet to Read more…

Share

Olympic SEO Poisoning

Image (1) nodar-kumaritashvilii.jpg for post 25142

A tragedy occurred on Friday morning when Nodar Kumaritashvilii of Georgia died during a luge training run for the Vancouver 2010 Olympics. As we've seen with many other high profile deaths lately, it was only a matter of minutes before Read more…

Share

Password safety - Grader.com saved by Twitter OAuth

Image (1) padlock300.jpg for post 2779

The news is finally out as to how worried Twitter.Grader.com users need to be over the hack I reported last week. Dharmesh Shah blogged on the lessons he learned from the attacks on his site. It turns out that the Read more…

Share