| 

Malicious warez site offers Firefox 4.0 beta download scam

  • Post author: Omid Farhang
  • Post published: August 29, 2010
  • Reading Time: 1 min
  • Word Count: 176 words

Like a lot of seedy stuff, this started with a Twitter post:. The current working version of Mozilla’s Firefox browser is 3.6.8. Version 4 is in beta testing. You get them FREE from Mozilla.. Why would you need a crack (program with its password broken) or a keygen (application that generates a password for a password-protected program) for something that is FREE? Well, there’s a sucker born every minute and the folks at this warez (pirated software) site are betting there are a lot of them using Twitter. ...

Continue Reading Malicious warez site offers Firefox 4.0 beta download scam

The bad guys are going after the Pirates

  • Post author: Omid Farhang
  • Post published: August 29, 2010
  • Reading Time: 1 min
  • Word Count: 189 words

File-sharing organization Pirate Bay has been controversial for a long time, like maybe the length of its entire existence. It’s been in the news recently because a number of governments are trying to shut it down. That’s a situation ripe for social engineering. We found this scheme this morning: a number of typo-squatting sites carrying the following. (Note: the REAL Pirate Bay site is thepiratebay.org.) What would lead a victim to this? The phony site piratebay.com (below) comes up as the third result on a Google search for “piratebay” or fourth for “pirate bay.” ...

Continue Reading The bad guys are going after the Pirates

Facebook Dislike button scam spreads virally

  • Post author: Omid Farhang
  • Post published: August 16, 2010
  • Reading Time: 2 min
  • Word Count: 352 words

Have you seen a message like this on Facebook? I just got the Dislike button, so now I can dislike all of your dumb posts lol!! If so, don’t click on the link. It’s the latest survey scam spreading virally across Facebook, using the tried-and-tested formula used in the past by other viral scams including “Justin Bieber trying to flirt”, “Student attacked his teacher and nearly killed him”, “the biggest and scariest snake” and the “world’s worst McDonald’s customer”. ...

Continue Reading Facebook Dislike button scam spreads virally

Two Steps Away from a Free iPad

  • Post author: Omid Farhang
  • Post published: August 14, 2010
  • Reading Time: 2 min
  • Word Count: 247 words

Honestly, how many times have you won free stuff by clicking on links? And no
 those spam, trojan, and spyware do not count as free stuff. We recently found a scam that promises a free iPad to application testers. Apparently, the site lures the person into joining an iPad application testing program while the site owner makes profit from SMS fee charges and affiliation programs. To enroll in the program, “testers” are required to complete two steps. ...

Continue Reading Two Steps Away from a Free iPad

Google: 11,000 domains carrying rogue security products

  • Post author: Omid Farhang
  • Post published: April 17, 2010
  • Reading Time: 2 min
  • Word Count: 261 words

Niels Provos of the Google Security Team has blogged about the rise of malicious web sites carrying rogue security products, which the Google team calls “Fake AV.” Google has been engaged in a constant battle against the sites because the operators who peddle them have been refining their techniques for poisoning Google search engine results in order to victimize Google users by drawing them to malicious download sites. He wrote: “we conducted an in-depth analysis of the prevalence of Fake AV over the course of the last 13 months, and the research paper containing our findings, ‘The Nocebo Effect on the Web: An Analysis of Fake AV distribution’ is going to be presented at the Workshop on Large-Scale Exploits and Emergent Threats (LEET) in San Jose, CA on April 27th.” ...

Continue Reading Google: 11,000 domains carrying rogue security products

From XSS to root: Lessons Learned From a Security Breach

  • Post author: Omid Farhang
  • Post published: April 14, 2010
  • Reading Time: 3 min
  • Word Count: 449 words

In an excellent blog, the people from Apache did a very good job analyzing and documenting how a security breach happened–going through all the stages of the attack and drawing conclusions. Should you ever become the unfortunate victim of an attack, this blog offers an example of how to document it! I quote:”If you are a user of the Apache-hosted JIRA, Bugzilla, or Confluence, a hashed copy of your password has been compromised.” So if you are a user, please act accordingly after reading this blog 😉 ...

Continue Reading From XSS to root: Lessons Learned From a Security Breach

Faceparty password sites really want you to click on things

  • Post author: Omid Farhang
  • Post published: April 14, 2010
  • Reading Time: 3 min
  • Word Count: 523 words

“Faceparty is a UK based social networking site allowing users to create online profiles and interact with each other using forums and messaging facilities similar to email” – Wikipedia Faceparty does things a little differently to other social networking sites, however. Unlike most places where you register a username and password then start telling people how your farm is doing, to join Faceparty you need to send a text message to the tune of £25 / $38(!) and then enter your one time use password onto this page (warning: quite a few swearwords, because the site is indeed down with the kids). ...

Continue Reading Faceparty password sites really want you to click on things

Heads up – 0day ITW – Rihanna is a lure

  • Post author: Omid Farhang
  • Post published: April 14, 2010
  • Reading Time: 2 min
  • Word Count: 299 words

On April 9th, Tavis Ormandy published a proof of concept about how to use the latest version of Java to compromise a pc. You can read about it here. He notified Sun, but they weren’t concerned enough to break their patch cycle, so he published the code. The problem is that when Sun released Java 6, update 10 in April 2008, they introduced a new feature (it’s not a bug, it’s a feature folks) called Java Web Start. In order to make it easier for developers to install software, they created a method to execute a program from a website. ...

Continue Reading Heads up – 0day ITW – Rihanna is a lure

Please give me your username and password

  • Post author: Omid Farhang
  • Post published: April 14, 2010
  • Reading Time: 1 min
  • Word Count: 119 words

Yesterday evening our spamtraps started receiving the email below in a mass mailing action. The email was immediately flagged as spam even before reaching our spamtraps. No wonder since it has no To:-field, it has a different Reply-to:- than the From:-field and it comes from a DSL line IP address. If the user replies to the email, the return address is set to [email protected]. Nice try, but the email is just to generic to be actually taken seriously by anyone. I expect to see targeted emails in the next days (as we’ve already seen last year). ...

Continue Reading Please give me your username and password

Barcelona vs. Real Madrid Black Hat SEO attack

  • Post author: Omid Farhang
  • Post published: April 12, 2010
  • Reading Time: 2 min
  • Word Count: 226 words

Of course I’m talking about football. When I say football I mean the game that is played with one ball thas is kicked with the foot, not the other game that is known as football in the US even though it’s played using the hands. Anyway I don’t like football at all, it’s too boring fo me. But, at least in Europe, everyone loves football. And one of the best national championships is the Spanish one, with the 2 biggest teams being Real Madrid and F.C. Barcelona. Every time they play against each other, millions of people watch that game, and news about it are going around all the time. Last Saturday they played in Madrid, and being this such a popular match, cybercriminals couldn’t miss this opportunity. ...

Continue Reading Barcelona vs. Real Madrid Black Hat SEO attack