Security

Articles about Security on omid.dev — guides, topics, and notes from the field.

Avira know better what to put and where

Published: October 18, 2010 Reading time: 1 min

Sometimes we encounter childish messages from the authors in the body of malware. A variant of the TDSS family we got recently is even going a step further by offering a convenient location for a malware signature. The samples include the message “Put your signature here”, which is shown when run inside a debugger. While in many cases signatures could be still useful for detection, Avira prefer to use other technologies which are more generic and proactive. This is especially the case with malware families like TDSS/Alureon, whose authors continuously adapt their creations so they are able to work around even proactive detection in a short time. This variant is detected as TR/Crypt.XPACK.Gen3.

Continue Reading

RealPlayer Security Updates Published

Published: October 18, 2010 Reading time: 1 min

RealNetworks, Inc. have published product upgrades addressing vulnerabilities in RealPlayer SP 1.1.4 and earlier. The vulnerabilities may allow an attacker to execute arbitrary code. Windows users of RealPlayer SP 1.1.4 and earlier are advised to upgrade to the latest version here For more information, visit RealNetworks’ security advisory here

Continue Reading

New Likejacking-Attack on Facebook

Published: October 18, 2010 Reading time: 1 min

Currently a new likejacking-attack is running on Facebook. If a user clicks on the link of a friend which is reads “I Will NEVER TEXT Again After Seeing THIS!! on CLICK HERE TO SEE.”, she or he will automatically “like” that link too due to some clever scripting on the attacking website. A second like-link says “This American GUY must be Stoned to Death for doing this to a GIRL (NO SURVEYS)! … on CLICK HERE TO SEE.”. This is another variant of the same likejacking-attack. ...

Continue Reading

Facebook Privacy Breach: Users' Info Leaked To Advertising, Tracking Firms

Published: October 18, 2010 Reading time: 1 min

The information being transmitted is one of Facebook’s basic building blocks: the unique “Facebook ID” number assigned to every user on the site. Since a Facebook user ID is a public part of any Facebook profile, anyone can use an ID number to look up a person’s name, using a standard Web browser, even if that person has set all of his or her Facebook information to be private. For other users, the Facebook ID reveals information they have set to share with “everyone,” including age, residence, occupation and photos. ...

Continue Reading

Facebook apps transmitted personal info

Published: October 18, 2010 Reading time: 1 min

NEW YORK — The Wall Street Journal is reporting that 10 popular Facebook applications have been transmitting users’ personal identifying information to dozens of advertising and Internet tracking companies. The newspaper said Monday that the breach also includes users who set all their information to be completely private. And in some cases, it says, the apps provided access to friends’ names. A Facebook spokesman told the Journal on Sunday that the company would introduce new technology to contain the breach. It’s not clear how long the breach went on. ...

Continue Reading

Hackers Access 107K Student Records At UNFL

Published: October 18, 2010 Reading time: 1 min

The good news is that overseas hackers apparently did not change the grades of more then 100 thousand University of North Florida students when they broke into the computer system in September. The bad news is that personal information like names and social security numbers for those students may now be in the hands of those hackers. The FBI is investigating the attack, which was discovered by the university in a routine check of the server. According to University officials, the hacker had access to the system between September 24th and September 29th, but the University did not say when the breach was discovered. The Florida Times-Union newspaper said the university learned of the attack in September but did not notify potential victims because they were still investigating ...

Continue Reading

Gene Simmons Websites Taken Down By Hackers

Published: October 16, 2010 Reading time: 1 min

Some people didn’t like his comments about downloading… Two of Gene Simmons’ official sites were shut down after hacker attacks by a group called Anonymous, associated with the 4chan.org forum. The attacks were in response to comments by Simmons about how the music industry should have been tougher with illegal downloaders. Both SimmonsRecords.com and GeneSimmons.com were taken offline briefly due to the attacks. Simmons had made the comment, “The music industry was asleep at the wheel, and didn’t have the balls to sue every fresh-faced, freckle-faced college kid who downloaded material. And so now we’re left with hundreds of thousands of people without jobs. There’s no industry.” ...

Continue Reading

ZeuS baddies copy Conficker tactics

Published: October 16, 2010 Reading time: 1 min

Variants of the infamous ZeuS cybercrime toolkit have begun using the tactics of the infamous Conficker worm in a bid to get ahead of security defences. The so-called Licat worm, which is “strongly linked” to ZeuS, represents a likely attempt to reinforce botnets following recent arrests of suspected bank fraud money mules, as well as hackers tied to ZeuS in the UK, US and Ukraine over the last month or so. ...

Continue Reading

Help keep your account safe with the Gmail security checklist

Published: October 16, 2010 Reading time: 1 min

Posted by Diana Phan, Gmail Support Team October is National Cyber Security Awareness month and a good time for a reminder about why hijackers do what they do and how you can protect your account. Check out the Online Security blog to learn about common hijacking techniques and security practices that will help you stay one step ahead of the bad guys. To help ensure your Gmail account is safe, take a minute to visit the Gmail help center and complete their new security checklist.

Continue Reading

Facebook Introduces Disposable Passwords

Published: October 15, 2010 Reading time: 2 min

Accessing Facebook from a public computer or Internet cafe can now be done more securely. Moving to enhance online security, Facebook on Tuesday said that it will soon offer users the ability to receive one-time passwords on their mobile phones and that it has already enabled the ability to sign out of Facebook remotely. “We’re launching one-time passwords to make it safer to use public computers in places like hotels, cafes or airports,” said Facebook product manager Jake Brill in a blog post. “If you have any concerns about security of the computer you’re using while accessing Facebook, we can text you a one-time password to use instead of your regular password.” ...

Continue Reading