Archive for 2010

PayPal 2.7 for iOS: Catch Me If You Can

November 1, 2010 - More and more banking services are being outsourced to mobile devices. Example: PayPal version 2.7 for iOS now includes a check capture feature that lets you snap a photo of a check for deposit in your PayPal (continue reading...) Read more

Facebook: Giving You More Control?

November 1, 2010 - Facebook CEO, Mark Zuckerberg, has announced on their blog that the site will soon be offering new features and controls. The features include New Facebook Groups, a Dashboard for Applications, and the ability to Download Your Information. (continue reading...) Read more

Configuration File Details of Trojan.Zbot.B

October 31, 2010 - As my colleague Kazumasa Itabashi outlined in this blog, TrojanZbot.B, a.k.a. Zeus Botnet, attempts to download files from URLs with random-looking domain names generated by the Trojan based on the system time. When it accesses these domains (continue reading...) Read more

Boonana Threat Analysis

October 31, 2010 - Our interim analysis of a version of the malware we detect as Java/Boonana.A or Win32/Boonana.A (depending on the particular component of this multi-binary attack) differs in some characteristics from other reports we've seen. The most dramatic difference is in the social (continue reading...) Read more

October roundup – "90 Second News"

October 31, 2010 - Don't just read the latest computer security news - watch it in just 90 seconds! This month: international success for law enforcement; rumour of the month pimps Adobe's shares by 17%; Google's CEO puts his privacy foot in his mouth (continue reading...) Read more

NHS Security: a Retrospective View

October 31, 2010 - While this is probably of marginal interest to anyone outside the UK, even those who look upon the UK's National Health Service as convincing proof that state-sponsored healthcare is a Bad Thing, I had an interesting chat with Dan Raywood (continue reading...) Read more

Educating users for a safer internet

October 30, 2010 - In the United States, October is National Cybersecurity Awareness Month. I have always viewed this as an opportunity to help everyday users take the next step (continue reading...) Read more

Sophos Security Chet Chat 32

October 29, 2010 - My first post on the new blog... so exciting! I have had a rather traumatic travel week, but thankfully arrived home safely and have many thoughts to blog about. For this week's (continue reading...) Read more

McAfee Channel Partners Share Experiences

October 29, 2010 - I would like to thank all of the partners who were able to join us at Partner Day and FOCUS this year! The events had largest turn out and highest level of partner engagement that we have seen yet. One (continue reading...) Read more

Spammers get creative: spoofing email from social networking sites and using visual tricks

October 29, 2010 - Posted on behalf of Mathew Nisbet, Malware Data Analyst Spammers can be quite creative Spammers will try anything to get their spam past your filters and into your inbox. We've seen many tricks involving random text hidden in the body, use (continue reading...) Read more

Halloween Likejacking Campaign

October 29, 2010 - I've already described (Facebook) "likejacking" in a past blog post, and we mentioned a likejacking campaign in early October here. The latest one going around has the title:"OMFG!! The 10 Most WEIRD Facts About HALLOWEEN! (continue reading...) Read more

PDF exploit in action

October 29, 2010 - Naked ladies as bait, one more time One of the much-discussed PDF file exploits is circulating in SEO poisoned links. We found it by following links that popped up from a search for “Vanessa Hudgens (continue reading...) Read more

Exploitation using publicly available Base64 encode/decode code

October 29, 2010 - Earlier, I blogged about malicious hidden Iframes using publicly available Base64 encode/decode scripts. Recently, we have seen additional malicious JavaScript hosted on one website, using another publicly available Base64 encode/decode scheme. Here is the initial (continue reading...) Read more

All Tricks & No Treat for Anti-Spam Engines

October 29, 2010 - Spammers don't appear to be running out of tricks off their sleeves when it comes to bypassing anti-spam engines. Websense Security Labs™ ThreatSeeker™ Network found that spammers had slightly changed their tactics on the recent World Pharmacy campaign.  (continue reading...) Read more

Another 1.5 million Twitter links scanned

October 28, 2010 - In March 2010, I analyzed about 1 million links taken from public tweets on Twitter. I showed that the number of malicious links was less than 1%. I have scanned another 1.5 million links in the past 3 (continue reading...) Read more

Is Your Firewall Making You Less Secure?

October 28, 2010 - Gartner estimates that 65% of all successful cyberattacks exploit misconfigured systems. With hundreds or even thousands of rules installed on most enterprise firewalls there is a serious risk that vulnerabilities are being masked behind the complexity of the firewall rule (continue reading...) Read more

Strong Third Quarter Financial Results For McAfee

October 28, 2010 - Today, McAfee reported excellent Q3 financial performance with strong results across nearly all areas of our business. We’re proud to report: - Q3 revenue of $523 million, up eight percent year-over-year - Q3 deferred revenue of $1.4 billion, up eight (continue reading...) Read more

“Pump & Dump” Spam Turns to Indian Stocks

October 28, 2010 - Symantec has come across a spam campaign for an Indian stock, perhaps for the first time. As usually seen in typical stock spam message, this particular email claims that the stock price for this company will rise by 500% because (continue reading...) Read more

iBots? Mobile phone network 0wnage

October 28, 2010 - Some of the most interesting research on mobile botnets is being done in the lab.  Security researchers Collin Mulliner and Jean Pierre Seifert have put together a robust Proof-of-Concept (PoC) iPhone botnet. Their research was presented at the 5th International Conference (continue reading...) Read more

Mozilla updates Firefox

October 28, 2010 - Cross-platform vulnerability patched  Mozilla has updated its Firefox browser to patch the high-profile vulnerability (CVE-2010-3765) that was discovered Tuesday. (continue reading...) Read more

Copyright © 2012 The Security Blog. All rights reserved.