Archive for March, 2010

Journey to the Center of the PDF Stream

March 27, 2010 - Malware authors use numerous unconventional techniques in their attempts to create malicious code that is not detected by antivirus software. As malicious code analysts, though, it is our job to analyze their creations, and as such we have to be (continue reading...) Read more

IRS Malspam Campaign

March 26, 2010 - As we have documented in the past, a new (actually, it's the same as the old one) Fake IRS notification malspam campaign has started up again.   The attack starts with a spam e-mail which appears to be from the Internal (continue reading...) Read more

A Conviction of the Firewall Industry

March 26, 2010 - In today’s firewall market, you have a lot of choices. When was the last time someone was fired for buying a firewall? A firewall is typically a infrastructure purchase and considered a best practice. Firewalls have been around for almost (continue reading...) Read more

Help The Homeless, Feed the Phishers?

March 26, 2010 - Well, this is unfortunate. In the UK, we have something called “The Big Issue”, which is a magazine designed to help the homeless get back into society via a legitimate income. It sells around 300,000 copies a week and is (continue reading...) Read more

“If I Can Dream” Website Defaced

March 26, 2010 - The website for If I Can Dream, a popular American reality TV show, was hacked today and the calendar section defaced with messages from a hacker. If I Can Dream is the latest in a string of reality TV talent (continue reading...) Read more

Hacking forum or a sting operation?

March 26, 2010 - Though it is true that malware is getting more and more sophisticated I am sometimes surprised by the lack of skills coming from wannabe botnet operators. Today, I stumbled upon a hacker’s forum which nicely demonstrates just how low is (continue reading...) Read more

Site carries uncensored Chinese opinion on Google

March 26, 2010 - Cracks in the Great Firewall of ChinaSlashdot.org had a brief story this morning about pro-Google comments of Chinese Web users that were carried on the ChinaSMACK web site. (continue reading...) Read more

Protecting Browsers with Defense In Depth Techniques

March 26, 2010 - Posted on half of Pete LePage on the Internet Explorer team. Protecting Windows customers is an absolute priority for the Internet Explorer engineering team.  That's why we work hard to make sure our browser has some of the best safety and (continue reading...) Read more

Sport news website ‘Send this page to a friend’ service being abused by 419 scammers

March 26, 2010 - By Dan Bleaken, Malware Data Analyst, Symantec Hosted Services MessageLabs Intelligence analysts found a 419 scam today that is a little different from the majority of 419s. The basic premise of a 419 scam (also commonly referred to as an advance fee (continue reading...) Read more

Fake updates install backdoors

March 26, 2010 - Our good friends at Hanoi, Viet Nam, -based security firm Bkis have written about an interesting malcode lure: Trojans masquerading as updates for popular applications such as Adobe, Java or Windows.The fake updates are distributed with icons of (continue reading...) Read more

Password Survey Results

March 26, 2010 - I am convinced that the readers of the Symantec Security Response blog are the smartest around! The results from our Password Survey prove it. Actually, the number of responses itself proves it to me. At best, I thought 20 or (continue reading...) Read more

Social media is exposure for password guessing

March 26, 2010 - The Inquirer security news site is reporting that the 25-year-old arrested by French police for hacking a Twitter data base and accessing U.S. President Barak Obama’s account guessed the admin’s password.The unemployed man, who went by the handle (continue reading...) Read more

Select Your Web Browser(s)

March 26, 2010 - I wasn't sure I'd see this Browser Choice update:I set my computer's Regional Options for the United States even though it's physically located in Finland (I'm an (continue reading...) Read more

Another Earthquake, Another FAKEAV

March 26, 2010 - Yesterday, a 6.0-magnitude earthquake shook the Philippine capital, causing a bit of concern among its inhabitants and their relatives from the rest of the country and abroad. As such, many tuned in to the Web for the latest news and (continue reading...) Read more

Afterbytes: Chinese Academics Paper on Cyberwar Sets Off Alarms in U.S.

March 26, 2010 - The article: Chinese Academics Paper on Cyberwar Sets Off Alarms in U.S.:Larry M. Wortzel, a military strategist and China specialist, told the House Foreign Affairs Committee on March 10 that it should be concerned because "Chinese researchers at the (continue reading...) Read more

New Fake IRS Email Notice Leads to ZBOT

March 25, 2010 - TrendLabs senior advance threat researcher Ivan Macalintal found spammed messages claiming to come from the Internal Revenue Service (IRS). The email message warns recipients of either under-reporting, or not reporting, their incomes in line with the tax season (April). It (continue reading...) Read more

Free SQL Injection Scanner – SQLFury

March 25, 2010 - An Adobe Air based SQL injection scanner, using blind SQL injection techniques to extract information from a target database. SQLFury supports MySQL, PostgreSQL, Oracle, and Microsoft SQL Server.  For more details or to download, visit (continue reading...) Read more

Apple Diversifies Into Online Pharmaceuticals

March 25, 2010 - Spammers have decided that in order for Apple to meet sky-high growth expectations from its shareholders, Apple needs to diversify into selling drugs online. The spam looks similar to the following message below: Apple (continue reading...) Read more

Mac Malware – fact or fiction?

March 25, 2010 - One of the questions I am most often asked has to do with the supposed “immunity” of Mac. The first thing I always explain is that no system is invulnerable, and that in the case of Apple, it is not (continue reading...) Read more

Firefox, IE8 and Safari hacked at CanSecWest

March 25, 2010 - Fast action at Pwn2OwnIn the Pwn2Own hacking contest at the CanSecWest security conference in Vancouver, Canada, security researchers and hackers quickly hacked three of the major browsers to take control of (continue reading...) Read more

Copyright © 2012 The Security Blog. All rights reserved.