It is now safe to update :)...
Microsoft Releases Critical Internet Explorer Patch
By Thomas Claburn
InformationWeek
January 21, 2010
Microsoft on Thursday released an out-of-band patch, MS10-002, to address eight vulnerabilities in Internet Explorer, a move prompted by the revelation last week that a series of cyber attacks from China on Google and some 33 other companies relied on a flaw in Microsoft's browser.
The eight vulnerabilities are rated "critical" in most cases and have an Exploitability Index rating of 1, meaning that exploit code is likely.
In fact, proof-of-concept exploit code has already been reported and malicious exploit code is circulating online.
Microsoft is urging customers to install this update as soon as possible. The vulnerabilities affect Internet Explorer versions 5-8 and Windows 2000, XP, Vista, 7, Server 2003, and Server 2008. The company maintains that it has only seen limited and targeted attacks against Internet Explorer 6. But other security companies see broader risk affecting users of Internet Explorer 7 and 8.
Symantec on Wednesday said that it had detected a new exploit that attempts to leverage one of Internet Explorer's current vulnerabilities.
Friday, 22 January 2010
DarkMarket Ringleader Pleads Guilty in London
By Kim Zetter
Threat Level
Wired.com
January 21, 2010
A former ringleader of a top internet carding site run secretly by the FBI has pleaded guilty in the United Kingdom.
Renukanth Subramaniam, aka JiLsi, was a former Pizza Hut delivery guy who helped run one of the leading English-language criminal sites, DarkMarket. The site operated as an international cyber-bazaar for more than 2,000 hackers, carders and identity thieves until it was closed in 2008.
Members of the site traded in stolen bank card and identification data.
They bought and sold specialized equipment for skimming card and PIN numbers, and for cloning data to blank cards. The activities on DarkMarket are estimated to have resulted in fraud amounting to tens of millions of dollars.
Subramaniam, a Sri Lankan–born British citizen who was arrested in 2007, pleaded guilty last week to charges of conspiracy to defraud and five counts of distributing false information. The conspiracy charge alone carries a possible 10-year prison term. Judge John Hillen warned that Subramaniam “inevitably” faces a “substantial custodial sentence.”
Threat Level
Wired.com
January 21, 2010
A former ringleader of a top internet carding site run secretly by the FBI has pleaded guilty in the United Kingdom.
Renukanth Subramaniam, aka JiLsi, was a former Pizza Hut delivery guy who helped run one of the leading English-language criminal sites, DarkMarket. The site operated as an international cyber-bazaar for more than 2,000 hackers, carders and identity thieves until it was closed in 2008.
Members of the site traded in stolen bank card and identification data.
They bought and sold specialized equipment for skimming card and PIN numbers, and for cloning data to blank cards. The activities on DarkMarket are estimated to have resulted in fraud amounting to tens of millions of dollars.
Subramaniam, a Sri Lankan–born British citizen who was arrested in 2007, pleaded guilty last week to charges of conspiracy to defraud and five counts of distributing false information. The conspiracy charge alone carries a possible 10-year prison term. Judge John Hillen warned that Subramaniam “inevitably” faces a “substantial custodial sentence.”
Users still make hacking easy with weak passwords
By Jaikumar Vijayan
Computerworld
January 21, 2010
In a report likely to make IT administrators tear out their hair, most users still rely on easy passwords, some as simple as "123456," to access their accounts.
A report released today by database security vendor Imperva Inc. serves as another reminder of why IT administrators need to enforce strong password policies on enterprise applications and systems.
Imperva's report is based on an analysis of 32 million passwords that were exposed in a recent database intrusion at RockYou Inc., a developer of several popular Facebook applications. The passwords, which belonged to users who had registered with RockYou, had been stored by the company in clear text on the compromised database. The hacker responsible for the intrusion later posted the entire list of 32 million passwords on the Internet.
An analysis of that list provides the latest confirmation that a majority of users still don't care about the strength of their passwords if they are left to choose them on their own.
[...]
Computerworld
January 21, 2010
In a report likely to make IT administrators tear out their hair, most users still rely on easy passwords, some as simple as "123456," to access their accounts.
A report released today by database security vendor Imperva Inc. serves as another reminder of why IT administrators need to enforce strong password policies on enterprise applications and systems.
Imperva's report is based on an analysis of 32 million passwords that were exposed in a recent database intrusion at RockYou Inc., a developer of several popular Facebook applications. The passwords, which belonged to users who had registered with RockYou, had been stored by the company in clear text on the compromised database. The hacker responsible for the intrusion later posted the entire list of 32 million passwords on the Internet.
An analysis of that list provides the latest confirmation that a majority of users still don't care about the strength of their passwords if they are left to choose them on their own.
[...]
Router glitch cripples California DMV network
By Elinor Mills
InSecurity Complex
CNET News
January 21, 2010
The California Department of Motor Vehicles department suffered a network outage on Thursday due to an equipment glitch, a state official said.
A router switch malfunctioned, said Bill Maile, spokesman for Office of Technology Services for the state of California.
"It's very rare," he said. "Our staff quickly diagnosed the problem and re-routed network traffic to restore connectivity."
The network was down for about two hours and was restored at about 1:40 p.m. PST, according to Maile.
InSecurity Complex
CNET News
January 21, 2010
The California Department of Motor Vehicles department suffered a network outage on Thursday due to an equipment glitch, a state official said.
A router switch malfunctioned, said Bill Maile, spokesman for Office of Technology Services for the state of California.
"It's very rare," he said. "Our staff quickly diagnosed the problem and re-routed network traffic to restore connectivity."
The network was down for about two hours and was restored at about 1:40 p.m. PST, according to Maile.
Tuesday, 19 January 2010
ISPs could cut spam easily, says expert
By John E. Dunn
Techworld
18 January 10
Two simple techniques could be used to strangle botnets, a security expert has claimed. First, block email port 25 by default. Second, tell users when they are spewing spam from compromised PCs.
According to Trend Micro's CTO, Dave Rand, who is leading a campaign to reform the way ISPs approach the matter of botnets and spam, the two countries that adopted such techniques, The Netherlands and Turkey, have seen a huge reduction in the numbers of botnetted PCs.
According to his own figures and analysis, Turkey went from having around 1.7 million compromised PCs per month to only 35,000 after implementing techniques through its major ISP, Turk Telekom.
"They went from the number one spam source in the world to off the charts, said Rand. "They don't appear in the top 50 now."
Or alternativly, you can purchase 'Caretaker Antispam' available from iremove.nl
Techworld
18 January 10
Two simple techniques could be used to strangle botnets, a security expert has claimed. First, block email port 25 by default. Second, tell users when they are spewing spam from compromised PCs.
According to Trend Micro's CTO, Dave Rand, who is leading a campaign to reform the way ISPs approach the matter of botnets and spam, the two countries that adopted such techniques, The Netherlands and Turkey, have seen a huge reduction in the numbers of botnetted PCs.
According to his own figures and analysis, Turkey went from having around 1.7 million compromised PCs per month to only 35,000 after implementing techniques through its major ISP, Turk Telekom.
"They went from the number one spam source in the world to off the charts, said Rand. "They don't appear in the top 50 now."
Or alternativly, you can purchase 'Caretaker Antispam' available from iremove.nl
Companies Fight Endless War Against Computer Attacks
By STEVE LOHR
The New York Times
January 17, 2010
The recent computer attacks on the mighty Google left every corporate network in the world looking a little less safe.
Google's confrontation with China - over government censorship in general and specific attacks on its systems - is an exceptional case, of course, extending to human rights and international politics as well as high-tech spying. But the intrusion into Google's computers and related attacks from within China on some 30 other companies point to the rising sophistication of such assaults and the vulnerability of even the best defenses, security experts say.
"The Google case shines a bright light on what can be done in terms of spying and getting into corporate networks," said Edward M. Stroz, a former high-tech crime agent with the F.B.I. who now heads a computer security investigation firm in New York.
Computer security is an ever-escalating competition between so-called black-hat attackers and white-hat defenders. One of the attackers. main tools is malicious software, known as malware, which has steadily evolved in recent years. Malware was once mainly viruses and worms, digital pests that gummed up and sometimes damaged personal computers and networks.
Malware today, however, is likely to be more subtle and selective, nesting inside corporate networks. And it can be a tool for industrial espionage, transmitting digital copies of trade secrets, customer lists, future plans and contracts
The New York Times
January 17, 2010
The recent computer attacks on the mighty Google left every corporate network in the world looking a little less safe.
Google's confrontation with China - over government censorship in general and specific attacks on its systems - is an exceptional case, of course, extending to human rights and international politics as well as high-tech spying. But the intrusion into Google's computers and related attacks from within China on some 30 other companies point to the rising sophistication of such assaults and the vulnerability of even the best defenses, security experts say.
"The Google case shines a bright light on what can be done in terms of spying and getting into corporate networks," said Edward M. Stroz, a former high-tech crime agent with the F.B.I. who now heads a computer security investigation firm in New York.
Computer security is an ever-escalating competition between so-called black-hat attackers and white-hat defenders. One of the attackers. main tools is malicious software, known as malware, which has steadily evolved in recent years. Malware was once mainly viruses and worms, digital pests that gummed up and sometimes damaged personal computers and networks.
Malware today, however, is likely to be more subtle and selective, nesting inside corporate networks. And it can be a tool for industrial espionage, transmitting digital copies of trade secrets, customer lists, future plans and contracts
Poisoned PDF pill used to attack US military contractors
By John Leyden
The Register
18th January 2010
Unidentified hackers are running an ongoing cyber-espionage attack targeting US military contractors
Booby-trapped PDF files, posing as messages from the US Department of Defense, were emailed to US defence contractors last week. The document refers to a real conference due to be held in Las Vegas in March.
Opening the malicious PDF file attached to the spoofed emails triggers an attempt to exploit an Adobe Reader vulnerability only patched by the software firm last Tuesday (12 January).
The infection of vulnerable systems opens up a backdoor that connects to a server hosted in Taiwan, though the hackers who set up the attack may potentially be located anywhere.
The Register
18th January 2010
Unidentified hackers are running an ongoing cyber-espionage attack targeting US military contractors
Booby-trapped PDF files, posing as messages from the US Department of Defense, were emailed to US defence contractors last week. The document refers to a real conference due to be held in Las Vegas in March.
Opening the malicious PDF file attached to the spoofed emails triggers an attempt to exploit an Adobe Reader vulnerability only patched by the software firm last Tuesday (12 January).
The infection of vulnerable systems opens up a backdoor that connects to a server hosted in Taiwan, though the hackers who set up the attack may potentially be located anywhere.
Subscribe to:
Posts (Atom)