TechBlog

Are you reading this with Internet Explorer version 6?

Published: April 3, 2010 Reading time: 3 min

Virus Bulletin is reporting that a recent survey it conducted found that about one out of five people are still using the dangerously-out-of-date version six of Microsoft’s Internet Explorer. There are probably a number of reasons for this: — They are using IE6 at work with legacy systems that require IE6 (or IT never got around to updating the company’s browsers.) — They are using IE6 at home and don’t know that IE6 is frighteningly insecure. — They are using IE6 at home and don’t know that there is such a thing as an update to browser software. — They are using IE6 at home and don’t know there is such a thing as computer security. ...

Continue Reading

Adobe to launch Creative Suite 5 April 12

Published: April 3, 2010 Reading time: 2 min

A spokesperson for Adobe told us that on the morning of April 12 at 11:00 a.m. EDT, the company will hold a global online launch event for all of the components of its Creative Suite 5. Among the most anticipated new components — or as Adobe tends to present them in its periodic table, “elements” — is a vastly improved HD video rendering engine called Mercury. Unlike other manufacturers, Adobe tends to retain the cool names for its products and platforms even after public release. Mercury will utilize the graphics processing power of video cards to expedite the decoding and playback of HD-encoded formats, especially for the Premiere Pro editor. ...

Continue Reading

Rogue Toolbars Serve Up Facebook Phishing Pages

Published: April 3, 2010 Reading time: 3 min

There are a number of Toolbars out there in the wild with a nasty sting in the tail for anybody using them to login to Facebook. We’ve seen two of these so far; it’s possible there are more. Promoted as toolbars that allow you to cheat at popular Zynga games such as Mafia Wars, they appear to be normal at first glance with a collection of links to various websites and other features common to this type of program. ...

Continue Reading

iPad’s File System Suggests New Apple Devices on the Way

Published: April 3, 2010 Reading time: 1 min

Although Apple rivals the Fortress of Solitude when it comes to unreleased products — remember all of the speculation around the iPad? — the Cupertino-based company does leave clues about what is to come. A look into the iPad OS’s file system suggests that we can expect not one, but two iPhones in the near future, along with the next-generation iPod touch and the next-generation iPad. In the configuration, you can see a list of devices based on the iPhone OS model. However, there have been some new additions to this list following the iPad’s launch: iPhone3,2; iPhone3,3; iPod4,1 and iProd2,1. For reference, the current model of the iPhone is 3,1, the current iPod Touch is 3,1 and the current iPad is iPad 1,1. You may recall that Apple used the iProd 0,1 tag as a placeholder for the iPad before it was released. Our guess is that iProd 2,1 refers to the second generation iPad. ...

Continue Reading

Apple Diversifies Into Online Pharmaceuticals

Published: April 3, 2010 Reading time: 1 min

Spammers have decided that in order for Apple to meet sky-high growth expectations from its shareholders, Apple needs to diversify into selling drugs online. The spam looks similar to the following message below: Spammers have setup various hacked sites to redirect traffic to online drug stores. However, the spammers are probably frowning/pouting now as Sophos has once again thwarted their plans.

Continue Reading

Hacking forum or a sting operation?

Published: April 3, 2010 Reading time: 2 min

Though it is true that malware is getting more and more sophisticated I am sometimes surprised by the lack of skills coming from wannabe botnet operators. Today, I stumbled upon a hacker’s forum which nicely demonstrates just how low is the technical knowledge level of the forum members. A search for “Zeus” produces several hundred results, many of them surprisingly basic, looking for help with installing a Zeus server or an advice about the best bulletproof hosting. ...

Continue Reading

Fake updates install backdoors

Published: April 3, 2010 Reading time: 1 min

Our good friends at Hanoi, Viet Nam, -based security firm Bkis have written about an interesting malcode lure: Trojans masquerading as updates for popular applications such as Adobe, Java or Windows. The fake updates are distributed with icons of the application they’re impersonating. Analyst Nguyen Cong Cuong wrote: “In addition, on being executed, they immediately turn on the following services: DHCP client, DNS client, Network share and open port to receive hacker’s commands.” ...

Continue Reading

Social media is exposure for password guessing

Published: April 3, 2010 Reading time: 1 min

The Inquirer security news site were reporting that the 25-year-old arrested by French police for hacking a Twitter data base and accessing U.S. President Barak Obama’s account guessed the admin’s password. The unemployed man, who went by the handle “Hacker Croll.” is not a genius, the news site concluded. “Apparently it was a doddle to do. He simply guessed people’s passwords by working them out from information on their blogs or online pages they had created about themselves,” it said. ...

Continue Reading

Help The Homeless, Feed the Phishers?

Published: April 3, 2010 Reading time: 1 min

Well, this is unfortunate. In the UK, they have something called “The Big Issue”, which is a magazine designed to help the homeless get back into society via a legitimate income. It sells around 300,000 copies a week and is listed as the third-favourite newspaper of young British people aged 15 to 24, according to Wikipedia. At this moment in time, The Big Issue website is playing host to a French Paypal Phish – they have a zipped copy of the Phish uploaded to the server, and a live Phish directory too: ...

Continue Reading

Journey to the Center of the PDF Stream

Published: April 3, 2010 Reading time: 2 min

Malware authors use numerous unconventional techniques in their attempts to create malicious code that is not detected by antivirus software. As malicious code analysts, though, it is our job to analyze their creations, and as such we have to be constantly vigilant for the latest tricks that the malware authors employ. While looking at some PDFs yesterday, something suspicious caught my eye. The PDF file format supports compression and encoding of embedded data, and also allows multiple cascading filters to be specified so that multi-level compression and encoding of that data is possible. The PDF stream filters usually look something like this: ...

Continue Reading