IT News & Technology update

Provide comprehensive update related to Computer, technology, software, anti virus and another electric device

Facebook application employed in white-hat hack

Written by IT News on 2:48 PM

A group of researchers from the Foundation for Research & Technology Hellas, Institute of Computer Science Greece, have shown the threat which can be exploited through Facebook. The scientists created a simple application, called "Picture of the Day", who promised to show an impressive National Geographic picture per day.

The researchers were able to show what they had been suspected from the start - that people are enthusiastic about each new gadget, allow itself to be blinded by it and forget about taking at least minimal safeguards against the threat. The same happened to the subjects of this experiment - which did not know that they were actually tracked. When someone clicks on the picture, their computer became a bot on a network created by researchers.

"We have placed a special code to the application source code, so that each time a user looks at the photo, HTTP requests generated in the direction of a victim host. Detailed application embeds four hidden pictures with inline images hosted on the victim. Every time a user clicks inside the application, inline images are taken from the victim, causing the victim to serve a request for 600 Kbytes, but the user is not aware of that fact (the photos are never shown). "The team explained in a recent report issued.

Even the Greek scientists do not advertise in any way app they had created; gossip on the "Picture of the Day" made rounds among its peers, and then spread unexpectedly quickly. During the first day of the experiment, the machinery of about 1000 unwary people from all over the world were bots.

"We have shown that applications that live within a social network can easily and quickly attract a large user-base (in the order of millions of users) that can be redirected to attack victim’s host. We experimentally determined user-base to be distributed, and a worldwide scale. Finally, we have shown that victims of a FaceBot attack may be the subject of an attack that will cause it to serve information to the size of gigabytes per day. "researchers said, underscoring that their attacks had virtually harmless, which is certainly not the case of a real botnet offensive.

McAfee got Final Report on the SPAM Experiment

Written by IT News on 5:23 PM

The McAfee team has recently completed an analysis of all data from SPAM (short for spam constantly All month) and one report is available. Entitled "Global SPAM Diaries", the report contains detailed and comprehensive presentation of all the McAfee findings.

Jeff Green, senior vice president of McAfee comments: "What I have gained over the last 30 days? Well, at least my itch of this template that curiosity, click on each and everything about World Wide Web just to see the result. Clearly a click of the moment in the window or signing up for diet advice in the form of a newsletter, as expected foolish. I will continue to be more diligent payer much more attention when I enter my personal email address and my contact information."


People from ten countries took part in the experiment (5 each), and depending on the McAfee report of the United States came in the early rankings. U.S. participants were given a total of 23233 spam messages that are about 22% of the total amount of spam received during the entire month. Brazil and Italy came in number 2 and 3, but the difference between the two is rather small (Italy needed only 246 messages to catch up to Brazil, which has a total of 15856 messages). Germany came in last with only 2331 messages, or 2%.

With respect to the participants, Bill on the U.S. came in number 1, 9160 with a total of spam messages. Giuseppe of Italy and Brazil on Geraldo came in number 2 and 3. Just as in the country rankings, the difference between the second and third place is too small. Geraldo needed only 490 more spam messages to catch up with Giuseppe which have a total of 6490. At least spam participant was John from Australia, which have a total of 3759 messages.

All that the amount of spam led to all kinds of malicious software installed on their machines and a significant reduction of computing power.

Guy Roberts, director of AVERT Labs: "Many of our players noticed that their computers were slowing, this means that while they were surfing, unbeknownst to them, Web sites were installing malicious software. In fact that in only 30 days they commented on noticeable change in the power of their computers demonstrates how much malicious software is installed without the knowledge of innocent people. "

The experiment began on 1 - Your May 2008 and a total of 50 people took part in it. In the McAfee team instructed them to leave aside all precautions and surfing the web. Of course laptops and electronic addresses are generously provided by McAfee. The purpose of the experiment is to see how many spam messages will be received for a period of 30 days and how that will affect the consumer.

Instant Messengers Suffer Massive Hit

Written by IT News on 5:29 PM

The user simply as couriers and the companies which are constantly improving on a monthly basis, some of these applications are quite strong. However, such an impressive popularity does not necessarily mean that they are 100 percent sure, because the new data, instant messaging, May is one of the most popular targets for hackers today. Akonix Systems has an interesting research which showed that the attempts by malicious instant messaging have almost tripled in April.


"In this month of the increase in IM attacks, the pirates also continue to have access to the companies because they provide instant messaging and unified communications platforms for the new year," said Don Montgomery, Vice President of Marketing at Akonix . "Companies need to recognize that the introduction of new instruments of cooperation and increases the risk of an attack, as each new application, a new instrument of infection."

The worst is that no fewer than 21 attacks, aimed at the instant-messaging software are new, which means that certain security of May have difficulties when trying to deal with them. Akonix, which states, an increase of 162 percent was registered in March, underlines once more the need to improve security measures.

Among the new-born IM threats, ARCserve, Imspread and QVOD were discovered all on the Web attacks on instant messaging technologies. However, the most popular are the threats and IRCBot Tiotua, according to Akonix, settled in about every three variants.

In addition to instant messaging, P2P networks have also been attacked by new threats. According to the same source, the attacks on the P2P services grew by 13 percent.

All these statistics do not do that the need for efficient and techniques for security and even though the chat on the Internet by an instant messaging-May sounds like a piece of cake, it could easily fit into a tragedy when someone succeeded in your Computers.

post tags: security, im ,worm, trojan

Hundreds of Stolen Credit Cards Published on a Google Hosted Page

Written by IT News on 1:35 AM

Blogger is again brought in the spotlight by illegal web operations
By: Bogdan Popa, Security and Search Engines Editor | softpedia.com

The blog in the images is look likes maintain by Indonesian people.

Ever thought that a popular service hosted by a huge company, such as Google, can turn into one of the most dangerous websites on the web, for hundreds of people? Maybe not, but today, it has been proved that such a thing can happen in a matter of seconds and can have some serious consequences for all the ones involved in it. The folks at KOAA.com today reported that a new Blogger account, hosting hundreds of stolen credit card accounts, has been spotted on the web and what's worse is that all the details could be accessed by anyone who has an Internet connection.

"We found a list of hundreds of credit card numbers and personal information on a website
hosted by Google. We contacted Google and within 30-minutes the web log, called a blog, was down. We've also contacted local and federal authorities, and a few people in Colorado Springs who's information was on the site", it was mentioned in the KOAA.com article.

As you can see in the adjacent picture and provided by security company Trend Micro, the blog included all the details needed to conduct an illegal web operation. And even if the Blogger account got shut down, don't be too amazed in case you discover other similar pages.

And the folks at Trend Micro proved us that numerous other websites could be at least as dangerous as today's example. "Soon after seeing this, I did some digging, and discovered a couple of other pages which were also hosting pages that simply contained (suspected) stolen credit & debit card numbers, names, addresses, ZIP codes, and CVV codes", Paul Ferguson of Trend Micro wrote in a blog post published today.

What I find really applaudable is Google's instant reaction that managed to shut down the page in approximately 30 minutes, as the first source mentioned above stated. So, next time you discover such pages, just hurry up and contact the authorities or the parent company hosting them.

IM Infection Spotted in the Wild

Written by IT News on 7:40 PM

WORM_IRCBOT.ARB detected by Trend Micro
By: Bogdan Popa, Security and Search Engines Editor | softpedia.com

We've seen many of these before, but since it is a new infection, it may be a really threat for your computer. With a continuously growing up popularity, the instant messenger and chatting applications reach every single computer in the world, fact that makes the unpatched and unprotected ones fully vulnerable to the threat. Security vendor Trend Micro has spotted a new worm that spreads itself through instant messaging and chatting application: WORM_IRCBOT.ARB.

Your computer may get infected extremely easy because the worm can be deployed once
the user visits a malicious website equipped with the infection. In addition, WORM_IRCBOT.ARB can be installed by another malware, Trend Micro explained. As many other worms, this infection creates special registry entries in order to be sure it is executed every time the operating system is loaded. And when I say operating system, I'm referring to Windows 98, ME, NT, 2000, XP and Server 2003.

And now, the juicy part. "It sends copies of itself to target recipients using certain instant messaging applications", Trend Micro added. This means the worm is able to spread itself by sending its files through instant messaging or chatting applications, where it may find some additional vulnerable computers. Since your contacts receive the file from you, a trusted source, they may download and install it which is at least dangerous if they're not protected.

And if that's not enough, listen to this: "it opens a random port to allow a remote user to connect to the affected system. Once a successful connection is established, the remote user executes commands on the affected system", the security company continued. In other words, the attacker is able to connect to your computer, execute commands and access the data. Scary...

There's not much to do in order to remain protected. All you need to do is to update your antivirus and be sure that the files you download or the websites you visit are clean and will not attempt to deploy any infection.

One More Christmas Infection Exploiting Windows Vulnerabilities

Written by IT News on 5:48 PM

WORM_DLOADER.TBW spotted in the wild
By: Bogdan Popa, Security and Search Engines Editor | softpedia.com

In case you thought you're safe this Christmas because you have applied the latest definitions for your security software, I'm sorry to disappoint you, but you're
not safe at all. And a recently-spotted worm comes to support this statement. WORM_DLOADER.TBW is a Windows infection discovered by security company Trend Micro, which affects most versions of the Microsoft operating system including 98, ME, NT, 2000, XP and Server 2003. What's worse is that the worm has a high distribution potential which underlines the fact that it can easily reach your computer, if you're one of the vulnerable guys.

In this case, 'vulnerable' doesn't refer to outdated antivirus or inexistent firewall. This time, it's all about a Windows vulnerability that may be exploited by the worm in order to get inside the system.

"This worm is a component of other malicious programs. It may be used by other malwares to perform its malicious routines. However, it requires other components in order to run properly. When executed together with other malware files, it takes advantage of the Server Service vulnerability to propagate across networks", Trend Micro wrote in the security notification published a few days ago.

The worm may be dropped on your system once you visit a malicious website equipped with the infection, or it can be included in other malware packages, the security vendor added.

The Windows vulnerability is pretty serious and can really represent a danger for your computer, according to an advisory released by Microsoft. "An attacker who successfully exploited the vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. We recommend that customers apply the update immediately", the Redmond-based firm wrote.

Find Windows vulnerabilities with a hex editor

Written by IT News on 11:03 AM

Kevin Beaver, CISSP, 09.18.2007

The hex editor is a long-time favorite investigative tool for forensics professionals. But the capabilities of the tool go

Security testing tips
Hacking Vista and planning for security breaches

Pen testing your VPN

beyond piecing together bits and bytes to prove a case. Used in the right context, a hex editor can actually uncover Microsoft Windows and application vulnerabilities that you may not have thought about, yet can't afford to overlook. In fact, the hex editor is one of the most underrated and overlooked security testing tools.

Here are just a few of the things you can do with a hex editor to root out security weaknesses in your Windows environment:

  • Check for passwords that may still be saved in Windows, Internet Explorer (IE) and other applications. Passwords left in memory can pose a risk and this technique demonstrates just how vulnerable logins and other private information can be -- especially on public computers that can be accessed by several people.
Figure 1: Using WinHex to search Firefox's memory range for sensitive information.

    If this isn't enough proof that a vulnerability exists, you can also search the computer's entire memory range for Windows application passwords or other sensitive information. Many times, I've been able to find sensitive information stored in memory by Web browsers even after the programs were closed. Searching all physical memory for this type of sensitive information is simple, fast and very revealing.

  • Search local system files, such as pagefile.sys and hiberfil.sys or the entire physical disk, for sensitive information. It's worked for me every time. This can really come in handy for spot checking computer hard drives that have supposedly been wiped before being disposed of or given away. Figure 2 shows the WinHex interface for searching local files.

Figure 2: Using WinHex to search logical drive C: for sensitive information.

  • Search for malware in memory or hidden data on disk that you wouldn't be able to see otherwise.
  • Search for "dirty" documents, such as Microsoft Word files that reveal sensitive information that should never leave the network. Those include file authors, draft verbiage, comments or third-party information that had supposedly been removed or were assumed to be non-existent since they're not visible in the native application. This comes in handy when searching for the files of those who forgot to enable the "Remove personal information from file properties on save" option.

Even with hex editors, it pays to have good tools. There are plenty of hex editors to go around. Check out the commercial alternative to WinHex called Hex Workshop or even the freebie XVI32. Don't even bother with the DOS/Windows debug tool that we used to have to rely on. Most of the hex editor features and capabilities you'll need are not there.

If you jump in head first with a hex editor, you'll be amazed at how powerful it is and what you can uncover. With this power comes some risk: A hex editor can and will modify anything on in memory or stored on disk, so be careful. The results can be beneficial or devastating. Either way, the power is in your hands.

Microsoft security update causes IE meltdown

Written by IT News on 10:09 AM

By SearchSecurity.com Staff | 18 Dec 2007 | SearchSecurity.com

The latest Microsoft MS07-069 update is causing Internet Explorer (IE) to freeze, according to some frustrated users.

Microsoft customers typically run into trouble after installing the software giant's monthly security updates, and this month is proving to be no exception.

Microsoft customer Bill Drake wrote on the Windows Vista Community site that after installing the update, he was getting an "'Internet Explorer has encountered a problem and must close" dialog box about 60% of the time.

"I suspect the KB942615 update should be coded to force a reboot and does not," he said. "Consequently, some part of the update that requires a reboot before the update is fully applied does not get done."

As a result, he wrote, installing the update without the reboot causes IE 6 to run in a "half-updated/half-not-updated" mode, which causes the connectivity problem.

MS07-069, a cumulative update for IE, was among the seven patch bulletins Microsoft released last week for its December 2007 security update. Other fixes addressed critical flaws attackers could exploit in DirectX and various versions of Windows to launch malicious code or gain extra system privileges on targeted machines.

It's not uncommon for glitches to appear after a Microsoft security update is installed. In the week following Microsoft's October 2007 update, for example, several users reported system difficulties after installing the fixes released in security bulletins MS07-057 and MS07-058.

Search This Blog

Ads and Sponsored by:



Want to subscribe?

Subscribe in a reader.