Archive for 2010

Microsoft has patched more critical vulnerabilities than 2004 and 2005 combined

October 9, 2010 - Today Microsoft patched 23 vulnerabilities of which 15 are rated critical. One of the critical vulnerabilities, (MS06-040) Service Server vulnerability, can be remotely exploited by an anonymous user on all Windows operating systems and has been labeled a worm candidate. (continue reading...) Read more

US-VISIT was visited by a virus

October 9, 2010 - The US-VISIT network consists of mainframe servers and Windows-based workstations installed at nearly 300 strategic locations in the US like airports and seaports.  It is used by Department of Homeland Security (DHS) to take fingerprints and digital photos of visitors coming (continue reading...) Read more

SMIL Exploit – Silently Install Malware on Your Mobile Phone

October 9, 2010 - While the latest CommWarrior variants continues to entice mobile phone users into clicking "Yes" to grant it permission to install, Collin Mulliner published the first remote exploit for Windows Mobile phones using MMS as the attack vector, at the Defcon (continue reading...) Read more

Symbian ROM Image Leak; Phone Rootkits?

October 9, 2010 - It looks like mobile malware authors may be moving into the kernel.  Software that operates in the kernel has access to the entire system.  Hidden, undocumented functions can provide untraceable access to the filesystem.  Rootkits are generally used to hide (continue reading...) Read more

Detecting PLC Infections

October 8, 2010 - In this blog, I’m going to provide extra details about the PLC infection process and how an operator can determine if their PLC is infected.    First, recall that Stuxnet’s end-goal is the infection of particular types of Simatic PLCs. In (continue reading...) Read more

Facebook typo squatting: watch your typing

October 8, 2010 - ANY typo will take you somewhere you probably don’t want to goChris Boyd mentioned earlier today by email that he’d found a Facebook typo squatting site (facebok.com) and it appeared to redirect to a (continue reading...) Read more

Malicious PDFs: A summary of my VB2010 presentation="

October 8, 2010 - Last week, I presented at VB2010 a talk that was well received in the room and on the wires. A number of people have requested copies of or links to my (continue reading...) Read more

Malicious PDFs: A summary of my VB2010 presentation

October 8, 2010 - Last week, I presented at VB2010 a talk that was well received in the room and on the wires. A number of people have requested copies of or links (continue reading...) Read more

WOW MMORPG > 12 M

October 8, 2010 - World of Warcraft hits 12 million subscribers world wide Blizzard Entertainment has issued a (continue reading...) Read more

Flash Update Expected Today

October 8, 2010 - Last week, we mentioned Adobe's Flash Player advisory.Well, the advisory been updated and the vulnerability fix is expected to ship today: On 20/09/10 (continue reading...) Read more

Busy Four Months of Zero Days

October 8, 2010 - Reflecting on the past few months, it has been very busy with zero-day flaws affecting popular products. Last Tuesday, Adobe issued a patch for the SING table parsing exploit that affects Adobe Acrobat and Reader (CVE-2010-2883). This patch has (continue reading...) Read more

Patch Tuesday – Preview for October 2010

October 7, 2010 - Microsoft's Security Updates for October 2010 are divided into 16 bulletins fixing a total of 49 vulnerabilities. Four bulletins have a rating of "Critical" and affect all versions of Windows, including (continue reading...) Read more

Half Billion Records Breached in 5 Years

October 7, 2010 - In the late 90s and early 2000s, hacking had evolved from “phreaking” (hacking phone systems) to “cracking” (breaking into networks). At the time, hackers hacked for fun, for the challenge, and for fame and popularity within the hacking community. But (continue reading...) Read more

SecurityTool rogue begins using fake codec scam

October 7, 2010 - Our rogue specialist Patrick Jordan has found a new delivery mechanism for the rogue security product SecurityTool. It’s a fake Adobe Flash Player update (fake codec) on malicious web sites. Specifically, you might find this if you go looking (continue reading...) Read more

Is the DDoS cyber attack organized by Anonymous ongoing?

October 7, 2010 - As far as we know, it is. ‘Anonymous’ users, both those behind the original cyber protest and those who have joined the cause later, continue to encourage users in the attack against SGAE, Promusicae and the Spanish Ministry of (continue reading...) Read more

All in the (rogue) family

October 7, 2010 - Why go the trouble of writing new code if you can “borrow” it from somewhere else. Our rogue researcher (in more ways than one) Patrick Jordan has pointed out the similarities in design elements in Web pages used by online (continue reading...) Read more

Microsoft Security Bulletin Advance Notification

October 7, 2010 - Microsoft has issued its advance notification for October’s Patch Tuesday. The company said it will release 16 security bulletins next week. Microsoft (continue reading...) Read more

Shaq is Wack

October 7, 2010 - Online Gossip Magazine Radar Online is reporting that NBA star Shaquille O'Neal is facing a lawsuit accusing him of hacking, destroying evidence and indicating that he attempted (continue reading...) Read more

Imitation is not always the sincerest form of flattery

October 7, 2010 - Since its release in 2007, ESET Smart Security has received many accolades for its antimalware, antispam and firewall functions.  However, we have recently been the recipient of a very dubious honor; a rogue antivirus program which masquerades as our own (continue reading...) Read more

“This offer is available TODAY only!!!”

October 7, 2010 - Hmmm. That’s not what the source code says We started out the day fat fingering the spelling of “youtube.com” and ended up at the typo squatting site behind the URL “youube.com.” youube.com redirects you to (continue reading...) Read more

Copyright © 2012 The Security Blog. All rights reserved.