Blog

Writing on software engineering, Linux, health, and the things I build and learn along the way.

Writing from the Field

Fresh exploit served up with ads

Published: March 23, 2010 Reading time: 2 min

Hi folks, One of our researchers recently discovered that the Liberty exploit kit included a fairly new exploit from November 2009 … http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3867 . The fact that there was something fairly new in terms of exploits was interesting to start with, but then we looked at the text on the exploit page…. Lehman Brothers?! Coffee Party??!! Holy Activists, Batman!!! It’s politically motivated!!!! Then we looked at the stats page (all these toolkits come with a sophisticated admin page), and saw that the top referrer was ad.yieldmanager.com! Holy Advertisers, Batman! Activists who know how to use exploit kits, _and_ the ad network!!! ...

Continue Reading

Icelandic Volcano Erupts, Fake Antivirus Spews Forth

Published: March 22, 2010 Reading time: 3 min

Yesterday there was a volcanic eruption in Iceland, near the Eyjafjallajoekull glacier, that has led the Icelandic authorities to declare a state of emergency in southern Iceland. People living nearby have been evacuated in case of glacial melt water flooding and the airspace near the now active volcano is effectively closed off. As you have probably already guessed, any event which commands a high level of public interest will be pounced on quickly by the makers of fake antivirus software in order to make a quick buck. This incident is no exception. ...

Continue Reading

A Fishy Defacement

Published: March 22, 2010 Reading time: 1 min

Generally speaking, most website defacements I see tend to look the same with political activist Y decrying political activist Z, or leet hax0rs posting up a mile-long shoutout list to their crew. This one is, er, a little different – a defacement of what appears to have been a site involved in fish logistics and / or preservation, fish2see(dot)dk. I can only imagine the horror on the face of the site admin who woke up this morning to be confronted by this: ...

Continue Reading

Phishers cast their nets at Neopets Users

Published: March 22, 2010 Reading time: 1 min

If you have children that play Neopets, you might want to warn them about this website or insert it into a blocklist of your choosing. The site is Neopoints(dot)tk, and promises lots of free Neopoints related items, with the help of a cute mascot called “Tuma the Draik”. I think there was a Norwegian prog rock group from the 70s called that, but I could be wrong. Of particular note here is the fact the site claims to offer “free magic paintbrushes”. These items are incredibly rare in Neopets land, and an excited child could easily wander into this particular trap as a result. ...

Continue Reading

Germany’s CERT warns against Firefox use

Published: March 22, 2010 Reading time: 1 min

BürgerCERT, Germany’s government information security organization, is recommending that Web users NOT use the Firefox browser until Mozilla fixes a vulnerability in it March 30. No malicious use has been found yet, however a researcher posted proof-of concept code for exploiting the previously unknown vulnerability. A malicious operator could use the vulnerability to run arbitrary code. Mozilla is expected to post version Firefox 3.6.2 to fix the problem. In January, the governments of France and Germany urged users to stop using Microsoft’s Internet Explorer browser until the company fixed the vulnerability that was blamed, at least in part, for the attacks from China on Google and more than two dozen other companies. ...

Continue Reading

Google quits censoring search in China

Published: March 22, 2010 Reading time: 5 min

Google’s decision to stop censoring search results in China may lead the Chinese government to block access to its sites. Google on Monday announced it has stopped censoring search results in China. The announcement came amid speculation that the search giant would pull out of China entirely and sets up a showdown with the Communist leadership there. In a 3:03 p.m. ET post on its official blog, Google said it stopped running the censored Google.cn service on Monday and was routing its Chinese users to an uncensored version of Google based in Hong Kong. ...

Continue Reading

Google.cn is Dead Now

Published: March 22, 2010 Reading time: 1 min

Google.cn is now redirecting to google.com.hk [ Hong Kong google servers ] – this has happened after the cyber attack on google china servers in december. right now if you try to access the google china web, news and image search are being redirected to google.com.hk Below is short snippet of the update about this on google official blog So earlier today we stopped censoring our search services—Google Search, Google News, and Google Images—on Google.cn. Users visiting Google.cn are now being redirected to Google.com.hk, where we are offering uncensored search in simplified Chinese, specifically designed for users in mainland China and delivered via our servers in Hong Kong. Users in Hong Kong will continue to receive their existing uncensored, traditional Chinese service, also from Google.com.hk. Due to the increased load on our Hong Kong servers and the complicated nature of these changes, users may see some slowdown in service or find some products temporarily inaccessible as we switch everything over. ...

Continue Reading

The Browser Choice Reloaded

Published: March 22, 2010 Reading time: 2 min

A little more than a week ago Microsoft started delivering a new Browser Choice for Windows to be compliant to the European Union law. There are plenty of web browsers to choose from, and my colleague Sorin Mustaca recommended Firefox. Usually a good choice, but currently users should be cautious about which browser they choose: Opera just released version 10.51 of their web browser. According to the changelog, it fixes a vulnerability which could lead to execution of injected code. Users of opera 10.50 should update as soon as possible. ...

Continue Reading

Merogo SMS worm

Published: March 22, 2010 Reading time: 1 min

We’re investigating a series of SMS Worms, found in the wild in China. Known as Trojan:SymbOS/MerogoSMS, these worms try to spread on Symbian Series 60 3rd Edition devices. Symbian continues to be by far the most common smartphone operating system in the world. These worms spread by sending text messages to other phones. These text messages contain variable messages (in Chinese), and a link to a website. If the link is followed, user is prompted to install an application – infecting the phone and restarting the SMS spreading. ...

Continue Reading

Google search reveals 3 million pages link to rogue AVs

Published: March 22, 2010 Reading time: 2 min

Do you know what the latest version of Adobe’s Flash Player is? If you don’t, you may very well fall for this: Flash Player 11? There are more than 3 million pages linking to this alleged version 11: Most pages are from unsanitized forums, but there is even a Google Ad for it! Ooooops…. The screen below depicts the social engineering trick: What appears to be an X-rated video with a Windows Media Player logo (that is odd!). ...

Continue Reading

IMF money-making scam

Published: March 22, 2010 Reading time: 1 min

I have seen a lot of these lately. This one currently doing the rounds tries to dupe the reader into thinking that the International Monetary Fund (IMF) wants to use their accounts to transfer money meant for charity. In the email. the IMF (supposedly) wants to transfer $10 Million into the reader’s account using NatWest Bank. The contact details within the Bank are given as follows: Name: Mr. Donald Miller (Co-founder) Office Address: 11 El Shams Bldgs., 8th District Nasr City E-mail: Bernisecharityfoundationimf ‘at’ gmail.com Tel: (+44) 7031-939-750 Fax: (+44) 7011830323 ...

Continue Reading

become a fan of Omid on Facebook

Published: March 22, 2010 Reading time: 1 min

You are invited to become a fan of Omid’s Network on Facebook. Those of you who already have a Facebook page; all you have to do is become a fan to view the Omid fan page in its entirety. But to participate fully you must join Facebook. If you do not already have a Facebook profile you will still be able to view photos and basic information (but c’mon, you know you have wanted to jump on the Facebook bandwagon – here’s a good reason why.) ...

Continue Reading

Bots, bots, and again bots

Published: March 22, 2010 Reading time: 4 min

Today we are going to take a closer look at bots and botnets. On the black market, selling bots and botnets is quite profitable, which makes creating them a popular activity for criminals. It helps that bot sources and creation kits are available on the Internet, allowing even script kiddies to create their own botnets. Another reason bots get created is that some people who get bored in their daily lives tend to do things that in their opinion might earn them respect or admiration in front of their peers or in various Internet chat rooms. ...

Continue Reading

Google’s Pacific submarine cable "Unity" nearly complete

Published: March 22, 2010 Reading time: 1 min

— 7.68 Terabits/s for growing Asian market — $300 million cost (from consortium of six companies) — 10,000 km length (Chikura in Japan to Los Angeles) — Increases capacity across Pacific by 20 percent — Dense Wavelength Division Multiplexing technology (960Gbps per fibre-optic pair with a maximum of eight fiber pairs) — construction time: two years Story here.

Continue Reading

Search