Security

Articles about Security on omid.dev — guides, topics, and notes from the field.

Adobe Patch Tuesday news: auto updater coming

Published: April 9, 2010 Reading time: 1 min

Adobe has announced that it will release an updater along with Adobe Reader and Acrobat versions 9.3.2 and 8.2.2 on patch Tuesday next week. On the Adobe blog, Steve Gottwals wrote: “…we have been testing a new updater technology with select beta customers since our October 13, 2009 quarterly update. The purpose of the new updater is to keep end-users up-to-date in a much more streamlined and automated way. “During our quarterly update on January 12, 2010, and then again for an out-of-cycle update on February 16, 2010, we exercised the new updater with our beta testers. This allowed us to test a variety of network configurations encountered on the Internet in order to ensure a robust update experience. That beta process has been a successful one, and we’ve incorporated several positive changes to the end-user experience and system operation. Now, we’re ready for the next phase of deployment.” ...

Continue Reading

Election results? Our survey says…

Published: April 9, 2010 Reading time: 1 min

…”click here to view”. Yes, it seems almost anything is a target for money generating survey spam. In this case, we start with a Youtube video: And we finish with this: Even better, these “fill in a survey to see the content” websites now pop up an additional message as you try to leave the page: “Help keep this content free. Please take one minute to complete a SPAM-free market research survey to gain access to this special content.” ...

Continue Reading

Benign Feature, Malicious Use

Published: April 9, 2010 Reading time: 2 min

An interesting and unknown feature used by sysadmins around the world in some large corporate networks is the use of proxy-auto config (pac) files. This benign feature is accepted by all modern browsers and is described in detail here. It contains a function to redirect your connection to a specific proxy server. Unfortunately this simple and smart proxy technique are being largely used by brazilian malware writers to redirect infected users to malicious hosts serving phishing pages of financial institutions. A .pac script URL is configured in the browser, in the field “Use automatic configuration script”: ...

Continue Reading

The mobile game with a Trojan thrown in for free

Published: April 9, 2010 Reading time: 2 min

TSince 27 March a new game called 3D Antiterrorist has been cropping up on quite a few international freeware sites offering downloads for Windows Mobile smartphones. As well as the game itself, the 1.5 MB archive contains the file reg.exe which is actually a Trojan that calls premium rate international numbers and leaves smartphone owners significantly out of pocket. As of 8 April this malicious program has been detected by Kaspersky Lab as Trojan.WinCE.Terdial.a. Let’s take a closer look at what happens. ...

Continue Reading

Can the Focus of Spam Email be Used as an Economic Indicator?

Published: April 9, 2010 Reading time: 3 min

The National Bureau of Economic Research has previously indicated that the United States has been in a recession since December 2007. What is interesting to note here is that Symantec first reported that spammers were showing an interest in the slowdown of the economy in October and November of 2007, so this begs the question, “Can the focus of spam email be used as an economic indicator or barometer?” Let’s take a brief look at the recession (thus far) by looking through Symantec’s spam folder (a.k.a. the Symantec Global Intelligence Network). ...

Continue Reading

Google has just rewarded me with $1 million!!

Published: April 9, 2010 Reading time: 3 min

I don’t believe it!! This morning I’ve received an email sent by Google notifying me that I´ve won $950,000, so I think this will be the last post I’m going to write 😉 Well, I haven’t taken part in any promotion of this kind and I’ve never heard that Google gives prizes just like that, but I can consider it as if I won the lottery. Here you have the content of the message: ...

Continue Reading

Spammers Distributing Free Passes for IPL Matches

Published: April 9, 2010 Reading time: 2 min

The Indian Premier League 2010 is a huge attraction for the cricket-crazy population in India. These matches are packed with all the ingredients to entertain, and are capable of satisfying viewers’ hunger for more and more cricket matches. People are ready to buy tickets in all possible ways just to watch their local and international cricket stars play. Symantec was anticipating a spamming campaign against ticket sales during the initial period of the sporting extravaganza; however, it is just halfway through the event and still not too late to lure email users with offers related to IPL tickets. ...

Continue Reading

Patch Tuesday next week

Published: April 8, 2010 Reading time: 1 min

Microsoft has put the PC-using world on notice that next Tuesday there will be 11 bulletins released addressing 25 vulnerabilities in Windows, Exchange and Office. Jerry Bryant, Group Manager of Microsoft’s Response Communications, said: “I also want to point out to customers that we will be closing the following open Security Advisories with next week’s updates: — Microsoft Security Advisory 981169 – Vulnerability in VBScript could allow remote code execution. ...

Continue Reading

iPad Spam has entered the building

Published: April 8, 2010 Reading time: 1 min

It was only a matter of time before the merest of “iPad” mentions on sites such as Twitter would result in autospammed messages like this: These bots will fire a message claiming “we need someone to test and keep one iPad” (or simply “Free iPad here”) to anyone discussing the latest gadget to hit the streets, sending you to various promotional sites like the one below: ...

Continue Reading

Number of infected computers spikes in Korea

Published: April 7, 2010 Reading time: 1 min

Hong Kong-based security firm Network Box reported that Korea was the country of origin for 31.1 percent of the malware on the Internet in March. In February the country only pumped out 8.9 percent, leading researchers to theorize that there has been a huge increase in infected machines there pushing out phishing spam. Network Box includes phishing in its calculations of monthly malware statistics. They also include North and South Korea as one country in their categories, but say the lack of public computers in the North means that South Korea is the country of origin for the bulk of the statistic. ...

Continue Reading