Blog

Writing on software engineering, Linux, health, and the things I build and learn along the way.

Writing from the Field

iRogue?

Published: March 18, 2010 Reading time: 2 min

Are Mac OS X rogues an emerging threat? For many years discussions of the potential for malware on Macs have ended with the conclusion: “there isn’t much yet, but as soon as Mac gets a big market share the dark side is going to start writing the code.” There are indications that the bad guys are working on it. There have been some blog posts suggesting that the dark side is working hard to create a Mac OS X compatible rogue. SCMagazine is carrying a piece quoting a spokesman for researchers at Intego. Apparently Intego researchers got proof-of-concept code for an OS X rogue from underground sources and determined that it didn’t quite work. However, they concluded that some sophisticated coding was going on: ...

Continue Reading

More Reader features in your pocket

Published: March 18, 2010 Reading time: 1 min

The more eagle-eyed Reader users have noticed a few tweaks being made to Reader’s mobile interface over the past few days: Google has brought over a few more features from the desktop version of Reader: magic ranking and search. Both can be found in the option drop-down menu. For better consistency with the desktop version, Google has made the titles of items be links to the original page The top of each item now has “collapse” and “next item” links. This way there’s always a consistent space for your thumb to hit so you can advance to the next item. Since Google know the best mobile content is short and sweet, they’re going to leave you with that. Feel free to get in touch with them on Twitter or on their help group with feedback on these changes.

Continue Reading

Google improves Maps for Android, rolls in bonus features

Published: March 18, 2010 Reading time: 2 min

Google has rolled out a significant update to the Google Maps application for Android 1.6+ devices, which includes a new search results page, support for multiple accounts, a new Latitude homescreen widget, and a new Maps live wallpaper for 2.1 devices. Previously, when you performed a search in Maps, you would have to choose a result from a list of markers on the map. When you clicked the marker, it would open a page with three tabs: Address, Details, and Reviews. Under the Address tab, there were options to Show the result on the map, get directions to it, call it, look at it in Street View, or add it as a contact. The other two tabs contain exactly what you’d expect, details and reviews. If you wanted to pick a different listing, you’d have to go back to the map view and pick a different marker. ...

Continue Reading

Facebook Suffers ‘Password Reset’ Scam

Published: March 18, 2010 Reading time: 2 min

Today has been quite a busy day for scammers. We have been tracking a global scam/spam run that targets Facebook users. The lure used in the run is a familiar one: Facebook Password Reset Confirmation! Customer Support. The email looks like the following [Just it won’t notify you it’s Spam, it’s my own Software 😉 ]: The activity on this particular scam run has been global from the beginning. The malware in the attachment is pretty much what one would expect: downloaders, password-stealing Trojan, fake-AV, or bot stuff, depending on which one you got. Check out the Artemis map of this malware: ...

Continue Reading

Chilean Earthquake Spawns Malware

Published: March 12, 2010 Reading time: 3 min

Most of us are familiar with how high profile news events are used for malware distribution. We’ve seen it many times such as with Tiger Woods’ scandal and the earthquake in Haiti. Now the recent earthquake in Chile is used to prey upon unsuspecting folks interested in what’s going on with the post-quake and tsunami. This shows we should really be careful in our choices of where we go to get information. Try any related search term or phrase related to “Chile Earthquake”, “Tsunami”, etc. I’ve done so and will walk us through a few examples of risky to malicious content that my search turned up. This type of malware distribution tends to target the broadest audience possible, so I entered the search term “Chile” and then let Google auto-complete my search to “Chile quake 2010 tsunami” to load what is a popular search phrase. Almost immediately, among some recognizable news site results are random blog posts touting words like “download” or “.exe”. We should be suspicious of these. ...

Continue Reading

Facebook Users Suffer From ‘Fram’

Published: March 12, 2010 Reading time: 3 min

About a year or so ago one of the “McMarketeers” decided it would be fun to run a campaign against “fram”–spam that friends send you. As you might guess, we in the Labs have no friends, so it was no problem for us to ridicule the idea. However, around the coffee machine the other day I got involved in a quick discussion about spam on Facebook. A long-term social networker genuinely thought that Facebook spam did not exist and that all the noise was from Facebookers playing games or using annoying apps. So I offered to write up an example. ...

Continue Reading

Big Safari fix

Published: March 12, 2010 Reading time: 1 min

Apple yesterday released a huge Safari update that fixes 16 vulnerabilities – six for Windows versions and ten for Mac OS X and Windows. The update, Safari 4.0.5, makes fixes in Tiger, Leopard, Snow Leopard and Windows versions. This is probably pretty significant. In November, the TheInquirer.net of the UK carried a piece about browser vulnerabilities that rated Firefox and Safari as the ones with the most vulnerabilities: ...

Continue Reading

Twitter starts Direct Message phishing filtering

Published: March 12, 2010 Reading time: 1 min

Del Harvey who leads Twitter’s Trust and Safety team blogged yesterday that the social networking/micro-blogging service has begun filtering all links in Twitter Direct Messages to stop phishing: “Since these attacks occur primarily on Direct Messages and email notifications about Direct Messages, this is where we have focused our initial efforts. For the most part, you will not notice this feature because it works behind the scenes but you may notice links shortened to twt.tl in Direct Messages and email notifications.” ...

Continue Reading

Consoles for old games come with new malcode

Published: March 12, 2010 Reading time: 2 min

Be on the lookout for websites offering up “free applications” which come with a nasty sting in the tail. Here’s a typical example: Appzkeygen(dot)com If you like videogame consoles, you may be a fan of emulators (programs that ape long dead consoles, allowing you to play old games on your PC – we’ll avoid the murky legal minefield that comes with this practice and instead focus on the malware). Below is a Playstation 2 emulator – no really, it is. Would they lie to you? ...

Continue Reading

Internet Explorer 0-day targeted in spam runs

Published: March 12, 2010 Reading time: 1 min

Hot on the heels of the Patch Tuesday announcements yesterday, came the announcement of a new zero-day in Internet Explorer (CVE-2010-0806). Whilst checking through some URLs supposedly serving up malicious code to exploit this vulnerability, I noticed a link to some spam runs from earlier in the week. On March 8th SophosLabs saw spam messages attempting to trick the recipient into visiting rogue web pages. Messages used at least two social engineering tricks to lure victims into clicking the malicious link. ...

Continue Reading

Twitter Spam: Getting slim with slim URLs

Published: March 12, 2010 Reading time: 1 min

A while ago I was writing about twitter spam and I was trying to make a brief definition of this kind of spam: It follows a lot of users , has 1 post and is followed only by a few persons. Well, this changed now, because the theme became much more interesting for the people on Twitter: how to loose weight. Ironically, the URLs on Twitter also make a diet – they always get “compressed” using link shortener services. ...

Continue Reading

Exploit Code for IE 0-day vulnerability

Published: March 12, 2010 Reading time: 1 min

Exploit code for the the zero-day vulnerability in Internet Explorer has been added to the Metasploit framework. According to an email HD Moore wrote to ZDNet’s Ryan Naraine, the exploit works quite reliable – successful 50% of the times on Windows XP with SP2 and SP3 with IE7 and deactivated Data Execution Prevention (DEP). The security hole got reported yesterday on Microsoft’s March 2010 Patch Tuesday. Drive-by-Download-Exploits are likely to appear now as the Metasploit framework is open source and the exploit can now be abused even by script kiddies. Time to change the default browser – Microsoft just released a new browser choice screen which allows for exactly that!

Continue Reading

Finding awesome stuff online with Google Reader Play

Published: March 12, 2010 Reading time: 2 min

I use Google Reader a lot — not only to stay on top of the news, but also to find interesting blog posts and articles. I’m always telling my friends about Google Reader, and while some of them love it, others don’t want to take the time to set it up. For those of you who fall into this second category, Google is announcing Google Reader Play, a new product that makes the best stuff in Reader more accessible for everyone. Reader Play is a new way to browse interesting stuff on the web, customized to the topics you’re interested in, with no setup required. ...

Continue Reading

Malicious Web Attack Using Executable With facebook.com in Name

Published: March 12, 2010 Reading time: 2 min

As we were working through URLs identified as suspicious due to our GTI technology, one of the URLs that presented itself was an average “.com” site that loaded a php. As we processed this – it was interesting to see that this php actually reached out to download a file that ended with the string facebook.com.exe — as this “.com” site was very social-network friendly – it would be easy to see how an average user, without web protection in place, would not even realize what was going on. ...

Continue Reading

Many Zeus botnet C&C servers taken down

Published: March 12, 2010 Reading time: 1 min

Swiss security blog Abuse.ch has reported that the worst Zeus botnet hosting ISP was taken off line yesterday, cutting the botnet’s number of servers from 249 to 181 – including the six worse ones. Abuse.ch wrote: “As you can see in the chart above, on March 9th 2010, the number of active ZeuS C&C servers dropped from 249 to 181! The first thing I thought was: There has to be some problem with the ZeuS Tracker cron script. I checked the script – everything looked ok. So the massive drop of ZeuS C&C server is fact. I noticed that six of the worst ZeuS hosting ISP suddenly disappeared from the ZeuS Tracker. _ _ “I verified the subnets of the affected ISP and came to the conclusion that Troyak-as (AS50215), the upstream provider for the six worst ZeuS hosting ISPs, was cut from the internet on 2010-03-09. ” ...

Continue Reading

Search