| 

Phishers Dislike Facebook Timeline

  • Post author: Omid Farhang
  • Post published: March 10, 2012
  • Reading Time: 2 min
  • Word Count: 256 words

Symantec Connect: Phishers regularly introduce new types of fake applications with the motive of improving their chance to harvest user credentials. In February 2012, Symantec observed a phishing site recommending a fake application that allegedly removes ā€œTimelineā€ profile for Facebook users. The phishing site was hosted on a free web hosting site. The phishing site embedded the Facebook Timeline promotion video from YouTube, with the claim ā€œRemove Timeline Nowā€. According to this phishing site, users will have their ā€œTimelineā€ removed from their Facebook profile and get back their old profile pageā€”only after they enter their login credentials. To make the fake application look more authentic, phishers added that it was protected by an antivirus product with the logo of the antivirus brand placed below the login form. After user credentials are entered, the phishing page redirects to a page which displays a screenshot from the Facebook Timeline promotion video. If users fell victim to the phishing site by entering their login credentials, phishers would have successfully stolen their information for identity theft purposes. ...

Continue Reading Phishers Dislike Facebook Timeline

Microsoft's Patch Tuesday will close a critical Windows vulnerability

  • Post author: Omid Farhang
  • Post published: March 10, 2012
  • Reading Time: 1 min
  • Word Count: 171 words

The H-Security: Next weekā€™s Patch Tuesday sees Microsoft planning to publish a total of six bulletins, including one that addresses a critical vulnerability in all versions of Windows from Windows XP service pack 3 to Windows 7 service pack 1 and Windows Server 2008 R2. The rating means that the hole enables attackers to infect a system via the internet and inject malicious code. Other bulletins will address a privilege elevation flaw which affects the same span of Windows versions. ...

Continue Reading Microsoft's Patch Tuesday will close a critical Windows vulnerability

Facebook Scam: OMG ā€“ I just hate RIHANNA after watching this video

  • Post author: Omid Farhang
  • Post published: March 9, 2012
  • Reading Time: 2 min
  • Word Count: 294 words

SophosLabs: Messages are spreading between Facebook users, claiming that members of the social network have lost all respect for popular songstress Rihanna after watching a video. However, if youā€™re careless enough to click on the link you will find yourself lured into a survey scam that attempts to earn affiliate cash for fraudsters. A typical message trying to tempt users into falling for the scam looks like this: ...

Continue Reading Facebook Scam: OMG ā€“ I just hate RIHANNA after watching this video

This time, the bad guys want your tax accountant

  • Post author: Omid Farhang
  • Post published: March 9, 2012
  • Reading Time: 2 min
  • Word Count: 323 words

avast: While taxpayers are the regular target of springtime malware schemes, this year the bad guys are aiming for the accountants. A series of imposter emails are threatening recipients with the removal of their professional accreditation if they fail to respond promptly. The tax-phish appear to be from organizations such as the American Institute of Certified Public Accountants(AICPA), Better Business Bureau(BBB), and Intuit tax services. After clicking on the email, users are redirected through a hacked legitimate site to the final malware distribution center where their computer can download fake antivirus or another malware package selected by the bad guys. ...

Continue Reading This time, the bad guys want your tax accountant

Google is globally switching its search to HTTPS by default

  • Post author: Omid Farhang
  • Post published: March 9, 2012
  • Reading Time: 1 min
  • Word Count: 127 words

The H-Online: Google has announced on its Inside Search blog that it is enabling SSL encryption by default on its global search pages. The US site Google.com has been switching users to the secured HTTPS protocol since last year and now, to improve security and privacy for all its users, the company is rolling the behavior out to its international properties such as google.co.uk. As is the case on the US site, this only affects users who are signed into their Google account when visiting the site. The company expects to roll out this feature to the different local Google search pages ā€œover the next few weeksā€. Google hopes that this move will encourage other companies to adopt SSL more broadly across their web sites as well. ...

Continue Reading Google is globally switching its search to HTTPS by default

Dropbox Abused by Spammers

  • Post author: Omid Farhang
  • Post published: March 8, 2012
  • Reading Time: 2 min
  • Word Count: 320 words

Symantec Connect: Recently we noticed spammers abusing Dropbox, a popular cloud-based, file-hosting and synchronization tool, to spread spam. Dropbox accounts have a public folder where files can be placed and made publicly available. This function is useful to spammers, as it effectively turns Dropbox into a free hosting site. Spammers have abused URL shortening and free hosting sites for some time. Dropbox also provides a URL shortening service, which spammers have also abused. ...

Continue Reading Dropbox Abused by Spammers

Google opens a pharmacy? It's spam of the day

  • Post author: Omid Farhang
  • Post published: March 8, 2012
  • Reading Time: 2 min
  • Word Count: 251 words

SophosLabs: Is Google really extending its online empire, and opening an online pharmacy? Of course not. So donā€™t believe spammed-out emails like the following: Do you notice how the spammers have changed the ā€œoā€s in Google to Cialis and Viagra tablets? Very creative. Part of the spam message reads as follows: Weā€™ve just launched a pharmaceutical interfaces for Google, as well as several new features that will improve the Google experience for the people buying pills and using pharmaceutical interfaces. ...

Continue Reading Google opens a pharmacy? It's spam of the day

Panda Security cleans up defaced websites after LulzSec arrest revenge attack

  • Post author: Omid Farhang
  • Post published: March 7, 2012
  • Reading Time: 3 min
  • Word Count: 617 words

SophosLabs/NakedSecurity: With alleged Anonymous hackers belonging to the LulzSec group arrested and charged yesterday, and the startling relevation that prominent hacker Sabu had been working undercover for the FBI for months, hacktivists defaced a number of websites belonging to anti-virus firm Panda Security overnight. The hackers changed two dozen pandasecurity.com subdomains to include a YouTube video, showing a pot pourri of Anonymous/LulzSec activity during 2011, and posted what appeared to be the username and password details of over 100 Panda employees. ...

Continue Reading Panda Security cleans up defaced websites after LulzSec arrest revenge attack

Chrome security update and researchers' bonuses

  • Post author: Omid Farhang
  • Post published: March 5, 2012
  • Reading Time: 2 min
  • Word Count: 267 words

The H-Security: Google has released a new stable version of its Chrome browser. The update fixes seventeen high severity vulnerabilities and updates the bundled Flash player. Google referred users to Adobe for details of the Flash Player update, and as usual, revealed few details about the seventeen holes that it closed in the release. It did, though, say that the researchers earned between $500 and $3000 for their vulnerability disclosures. ...

Continue Reading Chrome security update and researchers' bonuses

New automated sandbox for Android malware

  • Post author: Omid Farhang
  • Post published: March 4, 2012
  • Reading Time: 1 min
  • Word Count: 110 words

ISC Diary: One of the things that Iā€™ve been working on lately is building an automated malware analysis environment to handle Android malware similar to the one I built for Windows malware.Ā Iā€™m not quite there yet, but I was quite pleased to here about the new service being offered by the folks at Die UniversitƤt Erlangen-NĆ¼rnberg.Ā This is still a research project, so if you choose to use it, be understanding.Ā Donā€™t expect 24Ɨ7 uptime and letā€™s try not to DoS them.Ā That said, Iā€™m looking forward to seeing how well it works and how the dynamic analysis will work once it is actually in production. ...

Continue Reading New automated sandbox for Android malware