Security

Articles about Security on omid.dev — guides, topics, and notes from the field.

New IE Information Disclosure Advisory…

Published: February 7, 2010 Reading time: 1 min

Microsoft has announced in Advisory (980088) that there has been a publicly disclosed vulnerability in Internet Explorer, versions 5 through 8. Users not running Internet Explorer in Protected Mode are at risk of having information, in files with predictable names, accessed by attackers. This vulnerability cannot be exploited to execute remote code or used for a denial-of-service attack. The largest group of users at risk are Windows XP users running IE without Protected Mode enabled. Internet Explorer on Vista and Windows 7 has Protected Mode enabled by default. ...

Continue Reading

Spammers dangle iPad carrot

Published: February 7, 2010 Reading time: 1 min

New, shiny products always tend to catch people’s attention, and spammers are continually looking for ways to do exactly that. So it’s not surprising to see spam tempting people with the promise of a new iPad, and a FREE one at that: The image they’ve used is very sketchy too, patched together from other existing Apple products and bearing little resemblance to the pictures released so far. However much you might want an iPad, don’t get lured in by spam like this.

Continue Reading

You’d think a company pursuing an IPO in this economy would clean upits act

Published: February 7, 2010 Reading time: 2 min

You’d think that a company trying to raise several hundred million with an initial public offering of stock would tell their affiliates to be on their best behavior for a while. For example, maybe they’d discourage them from hacking government web sites to attract search engine hits on the word “bestiality,” then redirect browsers to the company’s site. The sites: The code: ...

Continue Reading

Major U.S. crackdown on work-at-home fraud coming?

Published: February 7, 2010 Reading time: 2 min

The U.S. Federal Trade Commission today announced that next Tuesday they will hold a news conference to make public details of “a law enforcement sweep cracking down on job and work-at-home fraud fueled by the economic downturn.” The media advisory said that the news conference would feature the director of the FTC’s bureau of Consumer Protection David C. Vladeck, an assistant attorney general and the Ohio Attorney General. The advisory listed as “also attending” representatives of the U.S. Postal Inspection Service, Monster.com and Microsoft. ...

Continue Reading

Job opportunity without a single name

Published: February 7, 2010 Reading time: 2 min

Today we received some job hiring emails that looked like this: It has been formatted nicely and appears to have come from a large job search website. The message reads as follows: Dear Job Seeker, Upon reviewing your resume on Careerbuilder.com we have decided to offer you a job opportunity with our company. The job position is for a Payment Manager/Payments Processor in your area with no obligation to relocate. ...

Continue Reading

Phishing scam steals carbon credits

Published: February 5, 2010 Reading time: 1 min

Wired magazine has run a story on a phishing scam in Europe, New Zealand and Japan that resulted in the loss of 250,000 carbon credit permits worth $4 million from six companies. The phishing emails spoofed the German Emissions Trading Authority and said that the victim companies needed to re-register their accounts with the authority. When victims entered their information on a fraudulent web page from the link in the phishing emails the scammers accessed their accounts, transferred emissions credits to accounts they controlled then sold them. The amount the scammers made hasn’t been disclosed. ...

Continue Reading

New Facebook Home Page, Important New Privacy Setting

Published: February 5, 2010 Reading time: 1 min

Facebook started rolling out a new home page and navigation menus earlier today. And whenever Facebook adds new features, in this case the Applications and Games dashboards, there’s usually a new privacy setting as well. This is what part of the new Applications dashboard looks like. All Facebook has raised some privacy concerns regarding the dashboard’s output. Do you really want all of your “friends” to know what applications you’ve been running? ...

Continue Reading

Trojan code sneaks into two Mozilla add-ons

Published: February 5, 2010 Reading time: 1 min

Mozilla yesterday posted a notice on its AMO blog (that’s an acronym for their add-on site addons.mozilla.org) that two add-ons have been found infected with Trojan code: Sothink Web Video Downloader v. 4.0 and all versions of Master Filer. Version 4.0 of Sothink Web Video Downloader contained Win32.LdPinch.gen and Master Filer contained Win32.Bifrose. According to the blog, Masterfiler was downloaded 600 times before it was removed from the site Jan. 25 and Sothink was downloaded more than 4,000 times before it was removed Feb. 2. ...

Continue Reading

It’s lame ransomware, but it could fool somebody

Published: February 4, 2010 Reading time: 1 min

Found this little gem today. It’s distributed with other malware, cracks and drive-by downloads. It purports to be a security warning from your Windows operating system. Notice the “Visa, MasterCard, etc” – it doesn’t even bother to list all the cards it accepts. The really cool thing about it is that it takes FAKE credit card numbers as well as real ones!

Continue Reading