Security

Articles about Security on omid.dev — guides, topics, and notes from the field.

Can you really see who viewed your Facebook profile? Rogue application spreads virally

Published: November 28, 2010 Reading time: 3 min

SophosLab: Once again, a rogue application is spreading virally between Facebook users pretending to offer you a way of seeing who has viewed your profile. As we’ve described a couple of times before, plenty of Facebook users would *love* to know who has been checking them out online.. but unfortunately scammers are aware of this, and use the lure of such functionality as a way to trick you into making bad decisions. ...

Continue Reading

Comment on Stuxnet and more Windows 0-days

Published: November 28, 2010 Reading time: 2 min

Over the last few days, some news organizations have been saying that Stuxnet source code is available on the black market, and that clearly therefor there is an impending Internet Armageddon. This is patently silly, on a number of levels, but silly none-the-less. First thing is that I flat-out don’t believe Stuxnet source is available for sale on the black market or anywhere. Remember how often I say that if something sounds too good to be true, it’s not true? Well, the opposite applies too. If something sounds too bad to be true, it’s not true either. We really don’t know who built Stuxnet, or who the intended target was, be we may rest assured that whoever put that much work into it, isn’t selling it, at any price. It’s actually more probable that some no-honor-among-thieves bad guy is scamming fellow bad guys. “Sure, this is Stuxnet source code. Prove otherwise.” ...

Continue Reading

Closer look at W32/Ramnit.C

Published: November 28, 2010 Reading time: 3 min

Thomas Wegele, Virus Researcher from Avira wrote: In this month’s ITW malware set from the Wildlist organization two new variants of W32/Ramnit appeared. W32/Ramnit is a Worm spreading via infected executable files and infected HTML Files. It is a quite widespread malware – which is why we decided to dig deeper into it. Upon execution the malware creates a new file in the directory where it was started. This file is named “mgr.exe”. It then gets executed and creates a copy of itself in “C:%ProgramDir%\Microsoft\WaterMark.exe” which also gets executed after creation and in turn infects the EXE, DLL and HTML files found on the system and tries to connect to a server. ...

Continue Reading

Beware the Justin Bieber erection Facebook scam

Published: November 24, 2010 Reading time: 3 min

That’s possibly the most unlikely headline I’ve ever had to write in my computer security career, but never mind.. My guess is that regular readers of the Naked Security site might not be ardent fans of Justin Bieber – but chances are that some of you have young daughters or nieces who can’t get enough of the pint-sized pop hamster. If that’s the case then they might be intrigued by a message that is spreading virally across the Facebook social network claiming to be footage of… and how can I put this delicately? I don’t think I can.. Justin Bieber with an erection. ...

Continue Reading

Christmas Tree app virus hoax spreads on Facebook

Published: November 24, 2010 Reading time: 2 min

Thousands of Facebook users are warning each other about a Christmas Tree virus said to be spreading in the form of a rogue application on the social network. The only problem with this warning? It’s utterly bogus. Here’s a typical message being shared widely on Facebook: WARNING!!!!!!…..DO NOT USE THE Christmas tree app. on Facebookplease be advised it will crash your computer. Geek squad says its oneof the WORST trojan-viruses there is and it is spreading quickly.Re-post and let your friends know. THANKS PLEASE REPOST! ...

Continue Reading

Safe holidays season

Published: November 24, 2010 Reading time: 2 min

Avira TechBlog: Thanksgiving and according holidays are very close – a time in which many people have the time to do (online) shopping. The cyber criminals are eager for their share, so it’s time to remember some safety measures. We are expecting to see spam and phishing campaigns luring the recipients to visit malicious web sites. These web sites usually look quite legal and official. As precaution, don’t follow links from emails to online stores and online payment systems, but use bookmarks or type in the addresses directly into the browser’s address bar. And of course just visit shops which you already know. Some scams can be identified by very low prices – if they look too good to be true, they usually are! ...

Continue Reading

VirusTotal Google Chrome browser extension a.k.a. VTchromizer

Published: November 19, 2010 Reading time: 1 min

VirusTotal has just coded a Google Chrome browser extension to interact with VirusTotal. The extension adds an option to the context menu to analyze links with VirusTotal’s URL analysis engine. Unlike the VTzilla Firefox extension, it does not embed an additional “Scan with VirusTotal” option in the browser’s file download dialog (mainly because Chrome’s API does not allow to do so). Having said this, it does include a top menu bar popup that enables quick VirusTotal searches and direct submission of the page being viewed to VirusTotal. ...

Continue Reading

Hidden second Wi-Fi network with the Thomson TWG870U router

Published: November 13, 2010 Reading time: 2 min

Righard Zwienenberg from Norman Security Center Blog posted something interesting, Thanks to Mr. Fagerlid for Sharing: There is some commotion in The Netherlands. Telecom/ISP provider UPC is providing its customers with the Thomson TWG870U router, a Docsis 3.0 router. On the tweakers.net forum (Dutch language), a user discovered that the router, which is also providing Wireless Access, has a second hidden wireless network. Problem here is that: ...

Continue Reading

More than 100 security fixes in Mac OS X 10.6.5

Published: November 12, 2010 Reading time: 1 min

Apple has issued the latest update to its Mac OS X operating system, bringing Snow Leopard users up to Mac OS X 10.6.5. Enhancements include improved Microsoft Exchange reliability, and a variety of performance and stability improvements. But what’s probably most interesting to you is that the update also includes important security fixes. Well over 100 different vulnerabilities are reportedly patched by Mac OS X 10.6.5 – if you want to see the gory details (or at least, those details which Apple is prepared to make public) view their knowledgebase article. ...

Continue Reading

Female hacker charged with stealing nude photos of Grady Sizemore

Published: November 12, 2010 Reading time: 2 min

In 2009, naked photographs of American baseball star Grady Sizemore circulated on the internet after being stolen from the email account of his then girlfriend, Playboy Playmate Brittany Binger. A total of 15 photos were circulated – some showing Sizemore posing in his bathroom mirror wearing a suit, but others that showed him nude or only partially clothed. In one of the pictures, still easily available on the web, the Cleveland Indians’ star is using a coffee mug to protect his err.. modesty. ...

Continue Reading