Tuesday, September 7, 2010contact us

Archive for October, 2009


Friday, October 30th, 2009
The Growing Need For Good Login Protection
Phishing attacks are on the rise again, and the targets — Facebook, Twitter, and other social networking sites, as well as large webmail sites — all seem at a loss as to how to protect their clients. I read a fascinating article on Byron Acohido’s “Watchdog on Internet security” blog which goes into the growing threats in some detail (the article was too long to repost, it is excerpted below). But what all these attacks have in common is the growing need for some new thinking on login protection. Being able to filter out automated login attempts by ... more
del.icio.us:The Growing Need For Good Login Protection digg:The Growing Need For Good Login Protection reddit:The Growing Need For Good Login Protection fark:The Growing Need For Good Login Protection
Wednesday, October 28th, 2009
New Facebook Spam/Trojan Attack
Facebook users are under attack (again) from spam which tells them their passwords have been reset for security reasons. When the unsuspecting user clicks on an attachment (to see “your new password”), what they get instead is the Bredolab Trojan on their machine. This will then connect to a server, and download Cutwail, multiplying the malware loaded. Such social networking spam is a growing problem, but one that could be solved with better bot detection software. ZDNet has a blog post up with a nice image of the spam email, for those interested. EWeek has a ... more
del.icio.us:New Facebook Spam/Trojan Attack digg:New Facebook Spam/Trojan Attack reddit:New Facebook Spam/Trojan Attack fark:New Facebook Spam/Trojan Attack
Tuesday, October 27th, 2009
Proposed Legal Data-Breach Settlement Shot Down By Judge
Before we get started today, I have a quick update to yesterday’s column. It seems the Zeus/Zbot botnet Trojan horse is being disabled by a rival botnet, Bredo. A falling out amongst thieves, it seems. Anyway, MX Logic has a blog post on the situation, for those interested. Meanwhile, in the legal world, a federal judge has raised some eyebrows in a ruling which has denied a proposed settlement between TD Ameritrade and the 6.3 million customers who had their personal data breached by lax security at the company. TD Ameritrade had proposed a year of free ... more
del.icio.us:Proposed Legal Data-Breach Settlement Shot Down By Judge digg:Proposed Legal Data-Breach Settlement Shot Down By Judge reddit:Proposed Legal Data-Breach Settlement Shot Down By Judge fark:Proposed Legal Data-Breach Settlement Shot Down By Judge
Monday, October 26th, 2009
Zbot Botnet Unleashes Sophisticated Phishing Attack
The folks behind the Zbot botnet have gotten better at creating creative phishing attacks. Using a twist on the “you have an infection” tactic, the botnet spam not only warns of a Conficker infection (complete with convenient “cleanup tool” for you to run), but also has been trying an “upgrade your computer” email as well. The insidious thing is they’ve taken the trouble to create a very authentic-looking domain name which makes the user (at larger companies) think the message is coming directly from their own IT department. This shows a level of sophistication which isn’t usually seen ... more
del.icio.us:Zbot Botnet Unleashes Sophisticated Phishing Attack digg:Zbot Botnet Unleashes Sophisticated Phishing Attack reddit:Zbot Botnet Unleashes Sophisticated Phishing Attack fark:Zbot Botnet Unleashes Sophisticated Phishing Attack
Friday, October 23rd, 2009
Botnet Click Fraud On The Rise
Click fraud numbers were just released for the third quarter of 2009, and the usage of botnets to generate such fraud is on the rise — up to almost 43 percent of all click fraud is now automatically generated from botnets. This is up from around 27 percent a year ago, it should be noted. But the most insidious thing in the report is that these attacks are getting a lot more sophisticated, by spreading relatively low volumes of clicks across as wide a network of botnet-infected computers as possible, to “fake” more normal traffic patterns than the old, ... more
del.icio.us:Botnet Click Fraud On The Rise digg:Botnet Click Fraud On The Rise reddit:Botnet Click Fraud On The Rise fark:Botnet Click Fraud On The Rise
Wednesday, October 21st, 2009
A Victim of Comment Spam
This is a different kind of post for me, so I ask you to bear with me for a day here. Because I read something recently which showed in a poignant way the frustration felt by those with small blogs or interactive web sites when they have to deal with comment spam. It’s not a technical article, so I will only provide a small excerpt here, but the whole thing is short enough to read in a few minutes, so I encourage people to read the full post. The author is Danny Sullivan, who has been described as one ... more
del.icio.us:A Victim of Comment Spam digg:A Victim of Comment Spam reddit:A Victim of Comment Spam fark:A Victim of Comment Spam
Tuesday, October 20th, 2009
CNN Reports On Social Networking Cyberthieves
CNN ran an interesting story today on how social networking sites have been recently plagued with spam, phishing, and other online fraud. For those of us in the network security field, this is not exactly news — but stepping back a bit from such tunnel vision, we have to remember that it is indeed news to a lot of the users of such sites. So while the article itself is fairly basic and beginner-level when it comes to online security, what is interesting is that it is being presented to such a wide general-interest audience. So, for ... more
del.icio.us:CNN Reports On Social Networking Cyberthieves digg:CNN Reports On Social Networking Cyberthieves reddit:CNN Reports On Social Networking Cyberthieves fark:CNN Reports On Social Networking Cyberthieves
Friday, October 16th, 2009
Yahoo Settles Click Fraud Class-Action Suit With $20 Refunds
Yahoo has reportedly settled a class-action lawsuit against it, for the princely sum of twenty bucks. Well, twenty bucks each. But still, it seems they got off fairly cheaply. The suit claimed Yahoo was serving their ads up to some mighty shady sites, such as parked domains and typosquatting sites (which are slightly-misspelled URLs of legitimate sites). This led to a lot of click fraud, and a lot of angry advertisers. If you’re interested in the details, you can check out the court documents just filed in the case. Of course, there are third-party click fraud ... more
del.icio.us:Yahoo Settles Click Fraud Class-Action Suit With $20 Refunds digg:Yahoo Settles Click Fraud Class-Action Suit With $20 Refunds reddit:Yahoo Settles Click Fraud Class-Action Suit With $20 Refunds fark:Yahoo Settles Click Fraud Class-Action Suit With $20 Refunds
Thursday, October 15th, 2009
Cutwail Botnet Sending Out Bredolab Trojan
Cutwail has been, for the past year, the most successful botnet to inspire fear among security professionals, but up until now it hasn’t really done much in terms of actively sending out malware to the universe of infected sites it controls. That may all be changing. MessageLabs is reporting that the Cutwail botnet is now sending out the Bredolab Trojan, which takes complete control of targeted machines. The scheme is simple, and an old one — sending phishing-type requests out that inform hapless users that a package tracking number is having some problems, and all the end-user has ... more
del.icio.us:Cutwail Botnet Sending Out Bredolab Trojan digg:Cutwail Botnet Sending Out Bredolab Trojan reddit:Cutwail Botnet Sending Out Bredolab Trojan fark:Cutwail Botnet Sending Out Bredolab Trojan
Tuesday, October 13th, 2009
Comcast Getting Proactive About Viruses
Comcast has announced a new service for those who use them as an Internet Service Provider — virus detection, delivered to the end-user. So far, it is just a test program in Denver, but once it gets through beta, it will likely be provided to all Comcast customers. The way it works is fairly simple — if Comcast detects unusual activity from your computer, especially to known botnet sites, it will inform you of the fact through your browser, and direct you to their anti-virus site, so you can disinfect your machine. Of course, this isn’t the only ... more
del.icio.us:Comcast Getting Proactive About Viruses digg:Comcast Getting Proactive About Viruses reddit:Comcast Getting Proactive About Viruses fark:Comcast Getting Proactive About Viruses

ARCHIVES

CATEGORIES