TechBlog

Charities fight for piece of $5 million prize on Facebook

Published: January 21, 2010 Reading time: 4 min

(CNN) — This week, 100 charities are battling for votes on Facebook to win $1 million. The competition is a new approach to philanthropic giving and is led by JPMorgan Chase, which throughout the competition will donate a total of $5 million to 100 charities chosen by Facebook users. Traditionally, organizations would go through a grant process, and Chase would choose who would get its money and how much. However, late last year, Chase decided to take a different approach and put the power of choosing charities into the hands of Americans. Chase took a database filled with 500,000 nonprofit organizations and uploaded the information on to Facebook. The bank then allowed “crowdsourcing” to choose which charities should be recognized. The top 100 charities won $25,000 and advanced to the second round, where another vote will determine which organization will win $1 million. The five runners-up in the second round will receive $100,000 each. Another $1 million will be given to a single charity chosen from the original group by a Chase board of directors set up to oversee this competition. The concept of crowdsourcing corporate giving via online communities and voting was first used by American Express in 2007. In the Members Project, American Express would donate $5 million to charities submitted and selected by card members. But Chase has taken a huge leap by moving the entire competition to Facebook. “We wanted to find a way where we could hear from the communities we were operating in and hear what was important to them,” said Chase Community Giving foundation President Kim Davis. The philanthropic arm of the large bank donates annually $100 million to organizations around the world, Davis said. “This, for us, is very much about testing out a new way of doing corporate philanthropy for the firm.” More than a million fans have participated in the Facebook program. Along the way, obscure charities have joined better-known ones near the top of the rankings. Because the winners of the first round worked hard to organize their online communities, smaller charities with get-out-the-vote passion were able to compete with larger organizations. Thus, the final 100 charities range from the large Susan G. Komen for the Cure (which claims on its Web site to be the “world’s largest grassroots network of breast cancer survivors and activists”) to the Feel Your Boobies foundation, started by a woman in her garage, who wants to increase awareness of breast cancer screenings in young women. As of midday Thursday, the top vote-getting charity on the contest’s Facebook page was Invisible Children Inc., a nonprofit that seeks to combat child-related violence in Africa through documentary storytelling. Other companies are starting to pick up on crowdsourcing corporate philanthropy. ...

Continue Reading

“Aurora” update brief DoS

Published: January 21, 2010 Reading time: 1 min

Early this afternoon Microsoft released an out-of-band security bulletin patching the vulnerabilities in Internet Explorer. The fix has been at the top of the news since the vulnerabilities it treats are believed to have led to the compromise of Google and about 30 other companies last week in what has been called the “Aurora” attack. The governments of France and Germany suggested that Internet users switch to a different browser until the vulnerability was fixed. ...

Continue Reading

Web users still don’t select good passwords

Published: January 21, 2010 Reading time: 2 min

Security firm Imperva of Redwood Shores, Calif., found a unique way to gage the quality of the passwords that Web users select: they analyzed the 32 million passwords in the unencrypted file of passwords that miscreants stole from the servers of RockYou.com in December and posted on the Internet. RockYou creates and distributes entertainment widgets that work with social networking networks. What they found wasn’t good, according to their report. “Key findings: — About 30% of users chose passwords whose length is equal or below six characters. _ _ — Moreover, almost 60% of users chose their passwords from a limited set of alpha-numeric characters. _ _ _— Nearly 50% of users used names, slang words, dictionary words or trivial passwords (consecutive digits, adjacent keyboard keys, and so on). _ _ _ The most common password among Rockyou.com account owners is “123456”. ...

Continue Reading

Targeted Attack using "Operation Aurora" as the lure

Published: January 21, 2010 Reading time: 1 min

Now here’s an interesting turn of events. In the middle of all the attention to the “Operation Aurora” attacks, we’re now seeing new targeted attacks that are using this very event as the lure to get the targets to open a malicious attachment! Here’s the email we saw: The attachment Chinese cyberattack.pdf (md5: 238ecf8c0aee8bfd216cf3cad5d82448) is a PDF file which exploits the CVE-2009-4324 vulnerability in Adobe Reader (again, this is the one which was patched last week). ...

Continue Reading

Intelligence sector hit by a targeted attack

Published: January 21, 2010 Reading time: 1 min

We just blogged about a highly targeted attack against military contractors. Now we saw one against the intelligence sector. This attack was done with a PDF file. Again. It was targetting the CVE-2009-4324 vulnerability. Again. When opened, the PDF file (md5: c3079303562d4672d6c3810f91235d9b) looked like this: What really happens in the background? Just like last time, the exploit code drops a backdoor in a file called Updater.exe (md5: 02420bb8fd8258f8afd4e01029b7a2b0). Now, what is the document talking about? President’s day? DNI Information Sharing Environment? We don’t know, but a quick web search tells us that apparently there is going to be an Intelligence fair & expo in Germany next month. ...

Continue Reading

Microsoft Vulnerabilities

Published: January 21, 2010 Reading time: 1 min

Microsoft is releasing an out-of-band update for their IE vulnerability. Internet Explorer 6 is affected and is being actively exploited in the wild. The patch will be released on the 21st, today, see Microsoft’s Security Bulletin for additional details. Also in Microsoft news, Security Advisory (979682). There’s a vulnerability in Windows kernel privilege escalation. The vulnerability affects all versions of Windows (NT 3.51 up to Windows 7), on non x64-based systems, unless 16-bit application support is disabled. ...

Continue Reading

Microsoft will patch Internet Explorer today

Published: January 21, 2010 Reading time: 1 min

Microsoft has said it will issue an out-of-band patch today for critical vulnerabilities in Internet Explorer that allow remote execution of code. The company said yesterday it would not wait until the February “Patch Tuesday” to fix the vulnerabilities. The much discussed “Aurora” vulnerabilities in IE have been held at least partially responsible for cyber attacks on Google and more then two dozen other major companies. The attacks on Google were aimed at Gmail accounts of dissidents and Google’s source code. The attacks on the other companies were aimed at stealing intellectual property. ...

Continue Reading

Facebook Privacy Doesn't Really Exist

Published: January 16, 2010 Reading time: 2 min

Facebook recently rolled out new privacy settings that provides additional publishing controls. For example, Facebook users can now publish a photo to a selected list of friends. Clicking the “lock” icon opens the Custom Privacy settings. Once a photo is selected and the privacy options are set, the next step is to Share. As you can see, the default setting is set for Only Friends and this particular post is set for Only Me. ...

Continue Reading

Haiti Earthquake: Another Rogue Rides the News

Published: January 16, 2010 Reading time: 1 min

A day after the disaster that struck the Caribbean nation of Haiti, Rogue perpetrators have once again been busy with their SEO poisoning schemes. Searching for terms related to this earthquake leads to a website that installs a Rogue into the system. It happens when an unsuspecting user searches for Haiti Earthquake details. Happily clicking the link leads to this page: Then this… And this… ...

Continue Reading