Security

Articles about Security on omid.dev — guides, topics, and notes from the field.

Security chip that does encryption in PCs hacked

Published: February 11, 2010 Reading time: 5 min

SAN FRANCISCO – Deep inside millions of computers is a digital Fort Knox, a special chip with the locks to highly guarded secrets, including classified government reports and confidential business plans. Now a former U.S. Army computer-security specialist has devised a way to break those locks. The attack can force heavily secured computers to spill documents that likely were presumed to be safe. This discovery shows one way that spies and other richly financed attackers can acquire military and trade secrets, and comes as worries about state-sponsored computer espionage intensify, underscored by recent hacking attacks on Google Inc. ...

Continue Reading

New Rogue: SafePcAV

Published: February 8, 2010 Reading time: 1 min

The creators behind the rogue antispyware appliaction WiniGuard have released yet another clone of their software. This one is called SafePcAV. SafePcAV spreads by showing fake online scanners. Once installed it will show hundreds of false infections. To remove these infections it requires the user to pay and license the software. If your computer is infected with this you must remove it soon, Click Here to learn how to remove it.

Continue Reading

Phishing Using Pornographic Content as Bait

Published: February 8, 2010 Reading time: 2 min

Symantec has observed a new trend in phishing in which the phishing Web page contains pornographic content. The phishing site states that the end user can obtain free pornography after logging in or signing up. These offers tempt users into entering their credentials in the hopes of obtaining pornography. The attackers use several offers of pornography as bait. Some of the offers are adult chat, social networking with adult personals for sexual favors, blogs with free pornography, and so on. The screenshot below is an example of a phishing website using a leading information services brand. The site states that they provide email alerts for sex parties: ...

Continue Reading

Phony Firefox update comes with Hotbar adware

Published: February 7, 2010 Reading time: 2 min

Our good friends at Broomfield, Colo., security firm eSoft have found an interesting scam to trick Internet users into installing the Hotbar adware: a fake Firefox download site. The eSoft researchers are theorizing that an affiliate of Pinball Publisher Network (PPB). is responsible. Pinball bought the Zango assets after that pestilent operation failed last spring. However Sunbelt Software Spyware Research Manager Eric Howes did some more digging and found that PPN offers the download file on a site they own so affiliates can send customers victims there for downloads. ...

Continue Reading

New IE Information Disclosure Advisory…

Published: February 7, 2010 Reading time: 1 min

Microsoft has announced in Advisory (980088) that there has been a publicly disclosed vulnerability in Internet Explorer, versions 5 through 8. Users not running Internet Explorer in Protected Mode are at risk of having information, in files with predictable names, accessed by attackers. This vulnerability cannot be exploited to execute remote code or used for a denial-of-service attack. The largest group of users at risk are Windows XP users running IE without Protected Mode enabled. Internet Explorer on Vista and Windows 7 has Protected Mode enabled by default. ...

Continue Reading

Spammers dangle iPad carrot

Published: February 7, 2010 Reading time: 1 min

New, shiny products always tend to catch people’s attention, and spammers are continually looking for ways to do exactly that. So it’s not surprising to see spam tempting people with the promise of a new iPad, and a FREE one at that: The image they’ve used is very sketchy too, patched together from other existing Apple products and bearing little resemblance to the pictures released so far. However much you might want an iPad, don’t get lured in by spam like this.

Continue Reading

You’d think a company pursuing an IPO in this economy would clean upits act

Published: February 7, 2010 Reading time: 2 min

You’d think that a company trying to raise several hundred million with an initial public offering of stock would tell their affiliates to be on their best behavior for a while. For example, maybe they’d discourage them from hacking government web sites to attract search engine hits on the word “bestiality,” then redirect browsers to the company’s site. The sites: The code: ...

Continue Reading

Major U.S. crackdown on work-at-home fraud coming?

Published: February 7, 2010 Reading time: 2 min

The U.S. Federal Trade Commission today announced that next Tuesday they will hold a news conference to make public details of “a law enforcement sweep cracking down on job and work-at-home fraud fueled by the economic downturn.” The media advisory said that the news conference would feature the director of the FTC’s bureau of Consumer Protection David C. Vladeck, an assistant attorney general and the Ohio Attorney General. The advisory listed as “also attending” representatives of the U.S. Postal Inspection Service, Monster.com and Microsoft. ...

Continue Reading

Job opportunity without a single name

Published: February 7, 2010 Reading time: 2 min

Today we received some job hiring emails that looked like this: It has been formatted nicely and appears to have come from a large job search website. The message reads as follows: Dear Job Seeker, Upon reviewing your resume on Careerbuilder.com we have decided to offer you a job opportunity with our company. The job position is for a Payment Manager/Payments Processor in your area with no obligation to relocate. ...

Continue Reading

Phishing scam steals carbon credits

Published: February 5, 2010 Reading time: 1 min

Wired magazine has run a story on a phishing scam in Europe, New Zealand and Japan that resulted in the loss of 250,000 carbon credit permits worth $4 million from six companies. The phishing emails spoofed the German Emissions Trading Authority and said that the victim companies needed to re-register their accounts with the authority. When victims entered their information on a fraudulent web page from the link in the phishing emails the scammers accessed their accounts, transferred emissions credits to accounts they controlled then sold them. The amount the scammers made hasn’t been disclosed. ...

Continue Reading