Security

Articles about Security on omid.dev — guides, topics, and notes from the field.

Hotmail phishing: Don't send us the wrong password or we'll suspend your account!

Published: January 14, 2012 Reading time: 2 min

SophosLabs: Have you been told to verify your Hotmail account? Did you receive a message saying that Hotmail’s email servers were congested, and so they were removing all unused accounts? If so, I hope you responded to the email with a roll of the eyes and a quick stab of the delete button. Because if you didn’t, you might have been at risk of having your login credentials stolen. ...

Continue Reading

Visa looks into Eastern European security breach

Published: December 17, 2011 Reading time: 3 min

SophosLabs: Visa is investigating a potential security breach that may have compromised payment cards of Eastern Europeans. Although Visa hasn’t disclosed which countries were hit, the Romanian state-owned CEC Bank has blocked and reissued 17,000 cards on suspicion that they had been compromised. CEC Bank said in a statement that “a number” of cards issued by banks both in Romania and abroad might have been compromised via an international database. ...

Continue Reading

Keep your Facebook friends close and your antivirus closer

Published: November 18, 2011 Reading time: 2 min

Microsoft Malware Protection Center: Facebook malware attacks are not new. Scams spreading via status updates have been around for a long time, but in recent weeks one threat has been getting creative in terms of social engineering. Backdoor:Win32/Caphaw.A can intercept URL requests in both Firefox and Internet Explorer and it has been observed to post very personable updates on friends’ walls in Facebook, gaining access if the user is logged in. ...

Continue Reading

Stop Censorship: Help us stop the Internet Blacklist Legislation

Published: November 17, 2011 Reading time: 1 min

Protect the Internet Help us stop the Internet Blacklist Legislation Mozilla: On November 16th, Congress holds hearings on the first American Internet censorship system. This bill can pass. If it does, the Internet and free speech will never be the same. Join us to stop this bill. Why? A few infringing links are enough to justify censoring an entire site, blocking good content along with the bad. ...

Continue Reading

Persistent XSS Vulnerability in White House Website

Published: November 4, 2011 Reading time: 1 min

The Hacker News: Alexander Fuchs, A German Security Researcher Discover Persistent XSS Vulnerability in Official website of White House. “The petition system is vulnerable. Every Petition i start or join will execute my code. I could join all petitions and my code will be executed on all users who visit the petition system.” He said. Read full story in German: http://www.1337core.de/2011/die-whitehouse-gov-lol-petition/ The XSS Demo is here: https://wwws.whitehouse.gov/petitions/!/petition/security/WxgwM7DS Advisory: http://vulnerability-lab.com/get_content.php?id=308 What is XSS? http://en.wikipedia.org/wiki/Cross-site_scripting

Continue Reading

Duqu exploits previously unknown vulnerability in Windows kernel

Published: November 3, 2011 Reading time: 2 min

The H-Online Security: Microsoft has confirmed a report from Budapest-based Laboratory of Cryptography and System Security (CrySyS), which claimed that the Duqu bot spreads by exploiting a zero day vulnerability in the Windows kernel. How it spreads had previously been unknown. CrySyS discovered the Windows vulnerability whilst analysing the installer. The bot, which anti-virus software firm Symantec believes is related to Stuxnet, infects target systems using a specially crafted Word file which injects the malware into the system using a kernel exploit. Microsoft is already working on a patch. ...

Continue Reading

Facebook Scam: Girl killed herself on Halloween

Published: November 3, 2011 Reading time: 2 min

SophosLabs: Scammers have put a new spin on an old Facebook scam, claiming that a girl killed herself on Halloween after her father posted a message on her wall. Facebook users are sharing messages with their friends, claiming to link to the salacious content. Girl-Killed-Herself-on-Halloween-After-Dad-Posted-This-on-Her-Wall [LINK] This is unbelievable.. shocking.. The messages are currently spreading very quickly on Facebook, as – at the moment at least – Facebook’s built-in security systems are not blocking them. ...

Continue Reading

MyBB downloads were infected

Published: October 25, 2011 Reading time: 2 min

The H-Security: In a blog posting, the MyBB development team has confirmed that the download package for version 1.6.4 of MyBB had been modified to include malicious code. Unknown attackers were able to exploit a vulnerability in the MyBB web site’s CMS (content management system) to inject and execute PHP code. The attackers placed a contaminated version of MyBB, containing a backdoor, on the server. It is unclear exactly when the hack took place, meaning that all downloads of 1.6.4 prior to 6 October could be affected. Users with MyBB systems are advised to check their installations and apply a patch. For rapid disinfection, the developers are advising users to replace the /index.php file with a clean version and to delete the /install/ directory. ...

Continue Reading

Hoax: The Pink Profile Pic Facebook virus hoax

Published: October 25, 2011 Reading time: 2 min

SophosLabs: Have you noticed the profile pics of some of your Facebook friends have acquired a pink tinge? Rumours have hit the social networking site that the Facebook app that turns your profile picture pink carries “keylogger malware” that can spy on your keypresses, and steal your passwords – not just from Facebook, but from online banks you may log into as well. One warning reads as follows: ...

Continue Reading