| 

‘Fileless' malware installs into RAM

  • Post author: Omid Farhang
  • Post published: March 20, 2012
  • Reading Time: 2 min
  • Word Count: 337 words

Exploit found in Russian adware invades process, doesn’t install files The Register: Researchers at Kaspersky Labs have found malware which, unusually, does not install any files on its victims PCs. The researchers aren’t quite sure how unusual it is, describing it as both “unique” and “very rare”, but no matter how scarce this type of malware is it does sound rather nasty as it “
 uses its payload to inject an encrypted dll from the web directly into the memory of the javaw.exe process.” That mode of operation means Windows and MacOS are both affected by the exploit, which is hard for many antivirus programs to spot given it runs within a trusted process. ...

Continue Reading ‘Fileless' malware installs into RAM

Apple's new iPad is great, but it's not free, nor called iPad 3

  • Post author: Omid Farhang
  • Post published: March 19, 2012
  • Reading Time: 2 min
  • Word Count: 328 words

SophosLabs: Only hours after the launch of Apple’s newest iPad we are beginning to see spammers trying to use the excitement over its release to ensnare innocent people into their scams. The scammers are sending out emails with the subject “Where do we send your Free iPad 3, just Test & Keep! See details”. The email contains an image with the text “TEST & KEEP an iPad 3 FREE – Click here”. ...

Continue Reading Apple's new iPad is great, but it's not free, nor called iPad 3

Firefox, Thunderbird and SeaMonkey updates fix critical vulnerabilities

  • Post author: Omid Farhang
  • Post published: March 15, 2012
  • Reading Time: 2 min
  • Word Count: 297 words

The H-Online: In the latest round of updates of its suite of internet applications, Mozilla has detailed the security fixes in the Firefox 11 browser, Thunderbird 11 email and news client and SeaMonkey 2.8 “all-in-one internet application suite”. There are also fixes for the “enterprise” and legacy versions of Firefox and Thunderbird. These fixes include a correction to a memory error in Array.join() which had been fixed last month, but was exploited during the Pwn2Own contest by Vincenzo Iozzo. ...

Continue Reading Firefox, Thunderbird and SeaMonkey updates fix critical vulnerabilities

Pidgin IM client 2.10.2 closes DoS holes

  • Post author: Omid Farhang
  • Post published: March 15, 2012
  • Reading Time: 1 min
  • Word Count: 207 words

The H-Online: Version 2.10.2 of the open source Pidgin instant messaging program has been released. According to its developers, the maintenance and security update brings a number of changes and addresses two denial-of-service (DoS) vulnerabilities that could be exploited by an attacker to cause the application to be terminated. These remote crashes are caused when the MSN server sends messages that are not UTF-8 encoded and also when some types of nickname changes occur in chat rooms using the XMPP protocol. Versions up to and including 2.10.1 are affected. Pidgin 2.10.2 fixes these issues and all users are advised to upgrade. ...

Continue Reading Pidgin IM client 2.10.2 closes DoS holes

Digital Playground porn passwords exposed by hackers

  • Post author: Omid Farhang
  • Post published: March 13, 2012
  • Reading Time: 3 min
  • Word Count: 437 words

SophosLabs: A group of hackers are claiming to have stolen the details of more than 70,000 users of the Digital Playground porn website. The group, calling itself “The Consortium”, appears to have scooped up some 40,000 financial details (including credit card numbers, names, CCV numbers, and expiration dates) as well as the email addresses and passwords of 72,000 users. According to the hackers, who appear to be affiliated with the Anonymous movement, the sensitive information was not encrypted. ...

Continue Reading Digital Playground porn passwords exposed by hackers

Nude Heather Morris pictures – hacker blamed

  • Post author: Omid Farhang
  • Post published: March 13, 2012
  • Reading Time: 2 min
  • Word Count: 309 words

SophosLabs: Heather Morris, famous for playing cheerleader Brittany in the popular “Glee” TV show, is said to be the latest celebrity to have had nude photos leak onto the web. The naked pictures are alleged to have been stolen by hackers from the 25-year-old actress’s mobile phone. Of course, Heather Morris isn’t the first celebrity to have fallen victim to a nude photo hacker. Nude photos and videos of Vanessa Hudgens, the star of “High School Musical”, surfaced on the net in 2011, after it was claimed the actress’s Gmail account was hacked. ...

Continue Reading Nude Heather Morris pictures – hacker blamed

Scam for FC Barcelona Fans

  • Post author: Omid Farhang
  • Post published: March 13, 2012
  • Reading Time: 2 min
  • Word Count: 340 words

Symantec Connect: Phishers often choose baits with the motive of targeting a large audience. Using popular celebrities as bait is a good example. Phishers understand that choosing celebrities with a large fan base would target the largest audience and supply more duped users. This month phishers are using the same strategy but, instead of targeting a popular celebrity, they associated their phishing site with the popular FC Barcelona football club. FC Barcelona is the world’s second richest football club and has a large fan following. The phishing site, hosted on a free web hosting site, has since been removed and is no longer active. However, though phishing sites are frequently short-lived, internet users should be aware that other phishing sites using this or a similar template could easily be encountered in future. ...

Continue Reading Scam for FC Barcelona Fans

Critical vulnerabilities in XnView fixed

  • Post author: Omid Farhang
  • Post published: March 13, 2012
  • Reading Time: 1 min
  • Word Count: 161 words

The H-Online: Version 1.98.8 of the popular XnView image viewer and converter has been released to close security holes in the software. According to an advisory from security service provider Secunia, the update addresses three “highly critical” vulnerabilities that could be exploited by an attacker to execute arbitrary code and compromise a victim’s system. These include a stack-based buffer overflow caused by a boundary error when parsing a directory name while browsing folders such as those from an extracted archive file, and, a heap-based buffer overflow when processing image content using the FlashPix plugin (Xfpx.dll). A second heap-based buffer overflow caused when processing image data in Personal Computer eXchange (PCX) files has also been fixed. For an attack to be successful, a user must first open a specially crafted file. ...

Continue Reading Critical vulnerabilities in XnView fixed

Safari update closes security holes

  • Post author: Omid Farhang
  • Post published: March 13, 2012
  • Reading Time: 2 min
  • Word Count: 272 words

Apple has released version 5.1.4 of its Safari web browser for Windows and Mac OS X. According to the company, the maintenance and security update addresses more than 80 vulnerabilities. The update also includes includes various stability and performance improvements as well as fixes for other non-security related bugs. A majority of the security holes closed in 5.1.4 were found in the WebKit browser engine used by Safari. These include several cross-site scripting (XSS), cross-origin and HTTP authentication problems, as well as numerous memory corruption bugs that could be exploited by an attacker, for example, to cause unexpected application termination or arbitrary code execution. ...

Continue Reading Safari update closes security holes

Firefox 11 release postponed due to security issues [Updated]

  • Post author: Omid Farhang
  • Post published: March 13, 2012
  • Reading Time: 2 min
  • Word Count: 314 words

H-Online: The Firefox team has announced that they are postponing the release of Firefox 11, originally planned for today, because of a security report which the team wants to evaluate to make sure the issue will not impact on their code. Jonathan Nightingale, Mozilla’s Senior Director of Firefox Engineering, also Microsoft’s monthly Patch Tuesday security update, also scheduled for today, as a reason to hold back on releasing the new Firefox version. ...

Continue Reading Firefox 11 release postponed due to security issues [Updated]