All TechBlog Health Electronics Cozy Corner

Iowa bank compromised, serving exploits

Author: Omid Farhang Published: April 9, 2010 Reading Time: 1 min

Northwestern Bank Online – Orange City is compromised and should not be visited until it’s clean. Embedded in the side is a malicious iframe, as you can see in this screen shot: (Testing the site with Wapawet doesn’t work, since it chokes on the javascript emulation. However, the iframe is malicious.)

Continue Reading Iowa bank compromised, serving exploits

Adobe Patch Tuesday news: auto updater coming

Author: Omid Farhang Published: April 9, 2010 Reading Time: 1 min

Adobe has announced that it will release an updater along with Adobe Reader and Acrobat versions 9.3.2 and 8.2.2 on patch Tuesday next week. On the Adobe blog, Steve Gottwals wrote: “…we have been testing a new updater technology with select beta customers since our October 13, 2009 quarterly update. The purpose of the new updater is to keep end-users up-to-date in a much more streamlined and automated way. “During our quarterly update on January 12, 2010, and then again for an out-of-cycle update on February 16, 2010, we exercised the new updater with our beta testers. This allowed us to test a variety of network configurations encountered on the Internet in order to ensure a robust update experience. That beta process has been a successful one, and we’ve incorporated several positive changes to the end-user experience and system operation. Now, we’re ready for the next phase of deployment.” ...

Continue Reading Adobe Patch Tuesday news: auto updater coming

YouTube Returns Blogs Some Link Love

Author: Omid Farhang Published: April 9, 2010 Reading Time: 1 min

You may have noticed that certain YouTube videos have a link below them pointing to a popular blog. This little “As seen on” link is Google’s way to thank blogs that have promoted popular videos on their site. If you’re wondering why this or that site hasn’t been linked, it’s hard to say, since there are no clear guidelines as to when a site will be given a link-back. From YouTube’s official blog: ...

Continue Reading YouTube Returns Blogs Some Link Love

Election results? Our survey says…

Author: Omid Farhang Published: April 9, 2010 Reading Time: 1 min

…”click here to view”. Yes, it seems almost anything is a target for money generating survey spam. In this case, we start with a Youtube video: And we finish with this: Even better, these “fill in a survey to see the content” websites now pop up an additional message as you try to leave the page: “Help keep this content free. Please take one minute to complete a SPAM-free market research survey to gain access to this special content.” ...

Continue Reading Election results? Our survey says…

Denial of availability and UK anti-piracy law

Author: Omid Farhang Published: April 9, 2010 Reading Time: 2 min

There could be a denial-of-availability risk to the enterprise in the new anti-piracy law passed by the British Parliament yesterday. Employees using company machines to swap pirated files could trigger a suspension of Internet service. The law is aimed at repeat offenders, however, employee misuse of company resources or botnet takeovers of machines for use as file-trading servers are a significant threat. At minimum, unintentionally offenders will have some paperwork to deal with when their ISP lets them know they’re in violation. ...

Continue Reading Denial of availability and UK anti-piracy law

Google Gets Sued by Photographers Over Google Books

Author: Omid Farhang Published: April 9, 2010 Reading Time: 2 min

.Google Books, although an admittedly noble project as Google has framed it, is also a beleaguered one. Attacked first by writers and publishers, the immense online library is now the subject of a lawsuit brought by several professional photographers’ organizations. The American Society of Media Photographers, one of these groups, issued a statement today saying, “The suit[…] relates to Google’s illegal scanning of millions of books and other publications containing copyrighted images and displaying them to the public without regard to the rights of the visual creators.” ...

Continue Reading Google Gets Sued by Photographers Over Google Books

FarmVille’s Newest Money-Maker: Brand-Sponsored Crops

Author: Omid Farhang Published: April 9, 2010 Reading Time: 1 min

Next week, FarmVille players will have the ability to grow peanuts, thanks to ad agency Saatchi and Saatchi and an Israeli candy brand. We’re told this is the first time a FarmVille crop has been directly linked to a brand. Saatchi Interactive in Tel Aviv is working on a rollout campaign for Elite Taami Nutz, a peanut-filled variant of a popular Israeli chocolate bar. The new crop will roll out with a simultaneous farm design competition on April 14. The peanuts cost 20 credits to buy, sell for 78 credits and can be harvested in 16 hours. ...

Continue Reading FarmVille’s Newest Money-Maker: Brand-Sponsored Crops

No Multitasking for iPhone 3G and Early iPod Touch Models

Author: Omid Farhang Published: April 9, 2010 Reading Time: 2 min

One of the finer points Steve Jobs let loose at the end of the iPhone OS 4.0 announcement today is that only the iPhone 3GS and iPod touch third generation (the most recent iteration from fall 2009) will have the capacity to support the iPhone OS 4.0’s new multitasking features. In other words, owners of the iPhone 3G, iPhone 2G, and first or second generation iPod touch models will not be able to multitask. ...

Continue Reading No Multitasking for iPhone 3G and Early iPod Touch Models

Apple reinvents multitasking for the iPhone

Author: Omid Farhang Published: April 9, 2010 Reading Time: 2 min

Multitasking, the feature that has been the absolute top of every iPhone user’s want list –which, by proxy became a major marketing point for both Android and webOS — has made its way to iPhone OS 4. “We figured out how to implement multitasking for third party apps and avoid those things [battery life and lag]. So that’s what took so long,” said Apple CEO Steve Jobs this morning. While it’s not actually full background processing, Apple has devised a way to reproduce the feeling. The company provided 7 APIs to developers which constitute the always-on services that apps can communicate with. These include: background audio, VoIP, Background Location, push notifications, local notifications, task completion, and fast app switching. ...

Continue Reading Apple reinvents multitasking for the iPhone

Benign Feature, Malicious Use

Author: Omid Farhang Published: April 9, 2010 Reading Time: 2 min

An interesting and unknown feature used by sysadmins around the world in some large corporate networks is the use of proxy-auto config (pac) files. This benign feature is accepted by all modern browsers and is described in detail here. It contains a function to redirect your connection to a specific proxy server. Unfortunately this simple and smart proxy technique are being largely used by brazilian malware writers to redirect infected users to malicious hosts serving phishing pages of financial institutions. A .pac script URL is configured in the browser, in the field “Use automatic configuration script”: ...

Continue Reading Benign Feature, Malicious Use