Security

Articles about Security on omid.dev — guides, topics, and notes from the field.

Hotmail Always-On Encryption Breaks Microsoft’s Own Apps

Published: November 10, 2010 Reading time: 3 min

Oh look, Microsoft is late to the party again? They are finally launching full-session SSL encryption to Hotmail a mere 2 years after Google did the same thing for Gmail. It looks like the release of FireSheep really has had an impact on web-application vendors due to the amount of mainstream media coverage it got and the sheer number of downloads. At least they are doing something and I hope more vendors follow and give users an option to force full-session HTTPS connections for all web properties. ...

Continue Reading

avast!: One in eight malware infections via USB

Published: November 6, 2010 Reading time: 1 min

With the expanding amounts of storage available on cell phones, mp3 players, digital cameras, and gaming devices it’s no surprise that malware is increasingly being transmitted over USB. avast! Software is reporting that out of 700,000 attacks reported by its Community IQ system in October, one in eight were exchanged over USB connections. “Cyber-criminals are taking advantage of people’s natural inclination to share with their friends and the growing memory capacity of USB devices,” says avast! virus analyst Jan Sirmer. ...

Continue Reading

No p*rn for you, naughty boy!

Published: November 6, 2010 Reading time: 1 min

There are always peculiar things malware researchers discover while analyzing new samples. VirusTotal 24/43 Let’s remember the filename as HD Porn TV for later😉 Our victim runs it thinking they will see the latest porno in HD quality. Instead they get a new browser ‘theme’ with a Turkish flavor: Internet Explorer: Firefox: The bad guys hijack Winsock: And filter traffic through: ...

Continue Reading

AV scam: is it a rogue or is it AVG’s free edition for sale?

Published: November 6, 2010 Reading time: 2 min

Tom Kelchner, Sunbelt blog: Alert reader Laurie (my boss actually) forwarded a copy an email she received from a friend. It said the sender was “…pleased to announce the newest version of Antivirus 2010 for Windows.” There was a link to click, of course. Something called “Antivirus 2010” for sale in November is very odd for three reasons: It’s nearly 2011 and legitimate AV companies are putting out their 2011 versions. There was a rogue security product last year called “Antivirus 2010.” (VIPRE detection: FraudTool.Win32.Antivirus2010 (v)) Although a lot of companies make a product named Anti-Virus 2010, they usually put their name in front of it, such as “Kaspersky Anti-Virus 2010” or “Norton AntiVirus 2010.” The Antivirus 2010 rogue graphic interface from 2009: ...

Continue Reading

Microsoft tempts antitrust lawyers with expanded antivirus offering

Published: November 5, 2010 Reading time: 5 min

Ed Bott’s Microsoft Report posted something interesting in ZDNet: You want a good, solid, free antivirus program? Microsoft Security Essentials fills the bill nicely. Unfortunately, even though it was officially released more than a year ago, it’s still one of the best-kept secrets in personal computing. Its installed base of 30 million users worldwide might sound big in raw numbers, but it’s a drop in the bucket compared to the billion-plus Windows PCs in use. ...

Continue Reading

Webcam cyber-sextortionist preyed on over 200 women

Published: November 4, 2010 Reading time: 3 min

A perverted hacker who spied upon more than 200 women via their webcams and microphones, after infecting their computers with malware, was arrested earlier this year by the FBI after a two year investigation. The 31-year-old man broke into victims’ personal computers, and stole personal information. Threatening to share the private information with their parents and email contacts, the man pressured the young women (some of them still young teenagers) into providing him with risqué pictures and videos. ...

Continue Reading

Workaround for vulnerability affecting Internet Explorer

Published: November 4, 2010 Reading time: 1 min

Microsoft has released a security advisory concerning a vulnerability affecting Internet Explorer versions 6, 7 and 8. This vulnerability may allow an attacker to execute arbitrary code. Full details here. Visit Microsoft’s page here to get full instructions. You can find the workarounds under the “Suggested Actions” twisty. The workarounds include overriding the Web site CSS with a user-defined style sheet, deploying the Enhanced Mitigation Experience Toolkit, enabling Data Execution Prevention (DEP) for Internet Explorer 7 and setting Internet and Local intranet security zone settings to “High” to block ActiveX Controls and Active Scripting in these zones.

Continue Reading

Sophos: malware on the Mac is real, here's a free antivirus

Published: November 3, 2010 Reading time: 2 min

Sophos has released a free antivirus product for consumers using Mac OS: Sophos Anti-Virus Home Edition for Mac. Although commercial antivirus products for Macs have been available for some time, Sophos’ offer is one of the very few free ones. The Internet security firm took its existing enterprise antivirus software and slimmed it down to reduce complexity. Interestingly, the company has no plans to release an equivalent free version for Windows. Windows threats are in the millions while the number of strains of Mac malware is in the thousands. ...

Continue Reading

New Vulnerability in Adobe Flash and Reader

Published: November 1, 2010 Reading time: 1 min

Avira TechBlog: Adobe warns of a new vulnerability in Flash Player and in Reader. The problem is within authplay.dll and the corresponding .lib in the Unix versions. It allows attackers to inject malicious code like Trojans with specially prepared documents or Flash objects. The company works on a patch which it plans to release on the 9th of November. Until then, deleting the authplay library helps to prevent a successful attack. Flash or Reader will crash then when a file requests the services from authplay, but this is clearly better than having an infected system.

Continue Reading