Archive for 2010

Microsoft Releases Security Advisory 2458511

November 2, 2010 - Hi everyone, Today we released Security Advisory 2458511 to address a new vulnerability that could impact Internet Explorer users if they visit a website hosting malicious code. As of now, the impact of this vulnerability is extremely limited and we (continue reading...) Read more

Firesheep, Idiocy, Ethics and the Law

November 2, 2010 - This isn’t a highly technical post by any means, but in a follow up I will explain some basics for less technical users and provide some information on protection. Recently a Firefox extension called Firesheep was released. Firesheep makes account hijacking (continue reading...) Read more

Continue to Stop.Think.Connect

November 2, 2010 - What a great month…and the activities aren’t over yet!  Reflecting back over Cyber Security Awareness Month, I saw many encouraging ways that security professionals are taking on this “shared responsibility” to educate.  I spent some quality time with the security executives (continue reading...) Read more

GFI Malware Minute weekly video feature

November 2, 2010 - The GFI Malware Minute video is available for your viewing pleasure on the Sunbelt Software YouTube channel (and below). Malware Minutes are short videos (1-2 minutes) that provide a weekly roundup of top stories from the GFI Sunbelt Software (continue reading...) Read more

The AMTSO subscription model: a clarification

November 2, 2010 - The AMTSO press release about its newly announced cheap subscription model, which I previously referred to here, has been misunderstood in some quarters. I therefore tried to clarify the issues in my latest Security Week article: (continue reading...) Read more

Stuxnet Paper Updated

November 2, 2010 - Speculation continues to rage about Stuxnet, now rumoured to have infected an English nuclear powerplant , though French owners EDF have denied it. But at least the estimable Rob Rosenberger shares my dislike of what he calls "this fetish for sexy computer news" (continue reading...) Read more

Tenable Network Security Podcast – Episode 56

November 2, 2010 - Welcome to the Tenable Network Security Podcast - Episode 56 Hosts: Paul Asadoorian, Product Evangelist & Kelly Todd, Compliance Analyst Announcements Several new blog posts have been published this week, including: Plugin Spotlight: D-Link DCC Protocol Security Bypass Integrating Nikto with Nessus (continue reading...) Read more

Who has your vote? Malicious Adobe and Firefox updates join the rogue AV election!

November 2, 2010 - I wonder how much longer rogue AV will ride the wave of major news?  Having recently blogged about Rogue AV riding the US Midterm Elections wave, we spotted further activity on what appeared to be blank pages from the Black (continue reading...) Read more

The "movie" rings

November 2, 2010 - If you've recently looked for information on a movie or its trailer, you've probably stumbled upon a website which claims to provide free streaming or downloads. The promise of these sites is rather dubious since this activity would be illegal. (continue reading...) Read more

SecCon 2010 – The Hackers Come to Town

November 2, 2010 - SecCon is Cisco’s internal security conference aimed at raising security awareness within the company’s development community. On Oct 4th – 7th we completed the third Cisco SecCon and it was a big success. At this year's conference we had (continue reading...) Read more

Latest eSafe Update

November 2, 2010 - Latest signatures: SV393 Latest signatures date: July 3, 2011 Latest Applifilter: 67 Latest eSafe Version: 8.5.25.0 Read more

Yes, you need anti-virus on your Mac.. and now it’s free

November 2, 2010 - Sophos has today announced the world's first free business-strength anti-virus program for Macs. In a pretty exciting move, we're making a version of our Mac anti-virus product (used by big (continue reading...) Read more

"My name is FBI Brad…"

November 2, 2010 - Every now and again, a 419 scam mail comes through that fairly boggles the mind. This is one such mail. This is to let you know about scam If you know you have  been scam before, this is (continue reading...) Read more

HTML Injections by Trojan.Zbot.B

November 1, 2010 - Following on from my previous blog exploring the structure of the Trojan.Zbot.B configuration files, we will now take a closer look at another command contained in the configuration file. In this case we will examine a command (continue reading...) Read more

Detecting Firesheep

November 1, 2010 - Firesheep, a Firefox plugin to do session hijacking ("sidejacking") by snooping on a LAN/WLAN and identifying session cookies passed in the clear over HTTP was released last week at Toorcon. To my surprise, this tool received a (continue reading...) Read more

Join us in Miami, Florida for Anatomy of an Attack

November 1, 2010 - I am very excited to invite those of you in southern Florida to our seminar this week " (continue reading...) Read more

IRS Fully Reliant on Social Security Numbers

November 1, 2010 - On the Policy, Practice & Procedures page of their website, the IRS addresses the public’s concern regarding Social Security numbers on checks:  “Complete Social Security Numbers (SSN) on Checks or Money Orders Remitted to IRS Issue: Tax Professionals and clients have (continue reading...) Read more

Rogue AV rides the US Midterm Elections wave

November 1, 2010 - On the eve of the 2010 US Midterm Elections, Websense Security Labs™ ThreatSeeker™ Network has discovered that some search terms related to the ongoing event return sites employing black hat SEO.  Websense customers are protected against this attack through our (continue reading...) Read more

Virus Bulletin Seminar

November 1, 2010 - Our friends at Virus Bulletin are hosting a seminar later this month that looks as if it should be worth a visit. Of course, security seminars are ten a penny, but this one is organized by the security-knowledgeable but vendor-agnostic (continue reading...) Read more

Pumpkin/jack-o-lantern stencils online SEO poisoning

November 1, 2010 - A seasonal SEO poisoning theme leads to FakeVimes scanner scam (click on graphic to enlarge) Over the weekend our analyst Adam (continue reading...) Read more

Copyright © 2012 The Security Blog. All rights reserved.