Security

Articles about Security on omid.dev — guides, topics, and notes from the field.

Microsoft Hack

Published: December 10, 2009 Reading time: 2 min

Basically, the rogue antispy was directing the victim to a genuine Microsoft address, but was modifying the html on the fly as it came back from the real Microsoft page. It made it read that Microsoft was recommending that the victim should buy the rogue. That’s a pretty good trick that will catch a lot of folks, and it reminded us of another one that we frequently see. It works like this… The victim attempts to reach Microsoft, or receives a link like http://go.microsoft.com/?linkid=9480113 and if you go there on a normal computer, you see a page like this (click to enlarge)… ...

Continue Reading

New rogue: SafetyAntiSpyware

Published: December 10, 2009 Reading time: 1 min

SafetyAntispyware is a new rogue anti-spyware application. However, the functionality follows the same pattern as other rogues. First, it will detect some fake infections. Then it will ask the user to license the product to remove these “threats”. It will also keep reminding the user about these fake infections and will urge the user to activate the software. For more information Click Here.

Continue Reading

SecurityTool rogue is trying to be a moving target

Published: December 9, 2009 Reading time: 1 min

The SecurityTool rogue security product, which first turned up early in October, is still active and trying to avoid countermeasures by setting up 12-24 download sites per day. It comes in two flavors online scanner scam: and fake codec scam: For more information Click Here.

Continue Reading

Beware of fake Microsoft updates coming through email

Published: December 9, 2009 Reading time: 3 min

Email is still the most common method used for security update notifications from all major vendors, but it is also the most commonly used trigger for launching the chain of infection attacks by malware writers. When I came to work today I found in my Inbox a message from Microsoft with the Security Bulletin Advance Notification for December. I immediately clicked on one of the links to visit the yet to be published December Security Bulletin and investigate how many critical vulnerabilities will be fixed this month. ...

Continue Reading

It pays to read the fine print (literally)

Published: December 9, 2009 Reading time: 1 min

This is a new one: bribeware. They’ll pay you a dollar to install their product. Nice idea, but unfortunately in this case it comes bundled with malware. We detect it as C4DLMedia, a group of installers that include adware and agents that change browser home pages. It’s considered a “moderate” risk. I wonder if Microsoft considered this for VISTA. C4DL Media might have a marketing problem with the dollar bribe though. In places where a dollar is worth enough to make this worth the effort there probably isn’t any Internet connectivity.

Continue Reading

Turscar ríomhphoist – Spam Email (in Irish)!

Published: December 9, 2009 Reading time: 2 min

According to the 2002 Census of the Population, 42% of the population of Ireland has the ability to speak Irish. Irish has also had official and working language status at the EU level since January 1, 2007. Recently, some examples of spam messages in Irish—the official language of the Republic of Ireland—have been observed. While the Irish translation is generally pretty good in this example, there are some anomalies between how certain phrases have been constructed. For example: ...

Continue Reading

FIFA World Cup Tickets Scams Available Now

Published: December 9, 2009 Reading time: 2 min

We recently alerted our readers to spam campaigns using the H1N1 vaccination program to prompt recipients to open the mail. And we have frequently mentioned that crooks love to take advantage of news, disasters, and other events. Now that the final draw for the FIFA World Cup in South Africa next year has taken place, it is time to remind you that sports events are no exception to the rule. I’ve already found some examples. The first is a fake lottery. In this case, the source claims the recipient has won a large sum of money from the South African Football Association. After contacting the lottery manager, the victim of the scam will be asked to pay “processing fees” or “transfer charges” so that the winnings can be distributed. Don’t expect to ever see a payment. ...

Continue Reading

New social engineering technique: use Microsoft support to sell rogues

Published: December 9, 2009 Reading time: 1 min

Sunbelt analyst Adam Thomas came across this ugly new social engineering technique when he analyzed the DefenceLab rogue security product. It does the usual scare-ware stuff: a fake scan and fake “Windows Security Center” alert: Then it directs the potential victim to a Microsoft Support page, but injects html code into the page in his or her browser to make it appear as though Microsoft is suggesting the purchase of the rogue. This is the real Microsoft page: ...

Continue Reading

Conficker Worm — Patch Now, Not Later

Published: April 1, 2009 Reading time: 3 min

Conficker (also known as Downadup) has dominated security headlines for months. Today — April 1, 2009 — media coverage peaks because variant Conficker.C is programmed to check a larger set of domain names for update instructions. The worm has not melted the internet overnight, but the attention is useful if it pushes lagging patches out the door. Defense is mostly discipline, not mystery. How It Spreads Conficker exploits failures administrators have warned about for years: ...

Continue Reading

Passwords used by the Conficker worm

Published: January 15, 2009 Reading time: 1 min

It’s not possible to emphasise enough the importance of using sensible passwords on your network. Not just on the areas of your network that you don’t want your users to traipse through, but also on the default network shares that are present on installations of commonly used operating systems. The Windows versions Conficker targeted — NT, 2000, XP, and 2003 — are all end of life and no longer receive security updates. The lesson still applies to any machine with open shares today. ...

Continue Reading