Showing posts with label News. Show all posts
Showing posts with label News. Show all posts

Tuesday, July 07, 2009

Google Chrome Operating System

The Google Chrome blog announced just recently that they are planing an operating system. Initially geared for netbooks, but I'm sure there's more in plan. I'm guessing they wpn't target full blown computers for awhile, but this is probably an extension of Android that Google aready has for the cell phone market.

Google Chrome OS is an open source, lightweight operating system that will initially be targeted at netbooks. Later this year we will open-source its code, and netbooks running Google Chrome OS will be available for consumers in the second half of 2010. Because we're already talking to partners about the project, and we'll soon be working with the open source community, we wanted to share our vision now so everyone understands what we are trying to achieve
Google Empire marches on.

Monday, July 06, 2009

Internet Explorer Video Active X Exploit

Been awhile since Windows had a zero day exploit that would allow the bad guys to take over your computer just by visiting a web site. Got one now. All you need to do is to visit a web site that has been set up to use this vulnerability with Internet Explorer and boom, they got you. Apparently, a flaw in Microsoft directShow( MSVIDCTL.DLL ) lets them do it. It does need to be IE 6 or 7 with Windows XP or Windows 2003. Yay! Vista and presumably Windows 7 aren't affected.


One way to avoid this is to not use IE. Firefox, Opera, Safari and other browsers aren't affected. The bad guys could try to open IE or trick you into opening it, so it's best to the video Active X advisory page and use the fix it button to turn off the part of IE that allows the exploit.

F-secure detects it as Exploit:W32/Agent.LBV. They have a write up and plug for their free beta of ISTP or ExploitShield that also protect you. Also has video link showing them trying to get infected with it and failing.

McAfee detects it as Exploit-MSDirectShow.b and has their write up here that says this has been around since last December and only has become widely know recently.

The Registry key that the Microsoft advisory page modifies is this. Best to not mess around in the registry. Might be more, but I'm not going to list them all.

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerActiveX Compatibility{0955AC62-BF2E-4CBA-A2B9-A63F772D46CF}]
"Compatibility Flags"=dword:00000400

More tech details at Microsoft Security Advisory 972890.

Tuesday, June 30, 2009

Firefox 3.5 final available

Probably not a secret to most, but the latest version of Firefox is out. A big update, since the version went from 3.0 to 3.5. Most of the changes are underneath, so they aren't readily apparent. I've run it for a few hours and haven't had any issues. Tried doing just about everything you can with a browser and it all went well.

Speed is one thing that Firefox 3.5 is touted as having over the older version. It seems like everyone is touting their new, even faster browser. I do notice that Firefox doesn't compare itself to other browsers like Safari and IE but the earlier 3.0 and 2 versions. Safari is still faster for me going loading new pages, but clicking back to ones in your history, it's still Firefox.

One thing you'll see that is new is the private browsing feature. Safari has had it for quite awhile. Google Chrome launched with it and spread awareness, even getting the nickname "porn mode". Nothing groundbreaking, but handy to have. You can always just clear your private data manually.

Firefox 3.5 does have one thing that no other browser has. It supports some video types natively, without the need for a plug-in or 3rd party add-on. However, it's only the open source Ogg file types. Most things people watch online aren't using this. you can see a demo of a video that also showcases the new features. If web developers make more use of Ogg files, then this could be good. My guess is that it won't mean much until more file types are supported. Wikipedia might be an exception.

Missing is a top sites feature, like Safari and Opera have. You can get it with add-ons for Firefox, but this is becoming a standard feature of these days. I didn't think it was a big deal when Opera had it and then when Safari 4 added it. Once i started using it, it was like tabbed browsing. How did I get by without it before?

Other features include geolocation, the ability to drag tabs to be their own window, and adding a window as a new tab in a different browser window.

Of course there is security. there's a whole list of features listed at the Mozilla Firefox security page. Private browsing and Forget This Site are the new ones listed. Many of the others, like antimalware and antiphising are listed as improved. I haven't tested those two filters, but they are likely to be weak as they have been in all browsers.

You can download Firefox 3.5 at www.getfirefox.com now. The internal updater for Firefox 3.0 doesn't offer it, as of yet.

Tuesday, December 09, 2008

Spywareinfo Domain Now Linking Rogues

The domain spywareinfo.com once was one of the main sites to help with stopping spyware and helping people remove spyware. Once a good source of information and news, it began a slow decline in 2006 when the owner Mike Healan disappeared from the net for personal reasons. The domain was bought recently and is now hosting links to undesirable removal programs, including Antivirus 2009.

Spywareinfo's legacy still lives on. The forums were moved to their own domain and can be found at spywareinfoforum.com . An archive of the old spywareinfo site can be found at spywareinfoforum.info. While archive of spywareinfo is mostly old and out of date, the forums are current , up to date and a good place to go if you need help.

More on the change of ownership of spywareinfo:

Warning at the spywareinfoforum site.

DSLreports security forums discuss the change.

Analysis of the new links.

Sunday, December 07, 2008

Need An Update

My poor blog is almost dead. Silly work and real life keeping me from updating it.

Saturday, September 13, 2008

Is your Computer running slowly?

Whoops, three months went by without a post. Oh well, no time like now to get back to it.

Malware Removal just put up a page to help with keeping your Windows computer from slowing down and what you can do to keep it from slowing down.

We get a lot of people coming here complaining of slow running computers, and posting HijackThis logs for us to look at. They suspect that an infection is causing their problem. In a great many cases, Malware is not the cause of the problem, and a few simple procedures are all that it takes to resolve things.



Is your Computer running slowly

Monday, June 02, 2008

Internet Explorer Flaw Plus Safari Equals Trouble

An undisclosed vulnerability in Internet Explorer, combined with exploiting Safari for Windows' ability to download files without being prompted, apparently allows the bad guys to take over Windows. This affects XP, Vista and IE versions 6 and 7. The unnamed Internet Explorer bug has been around for awhile. Combined with the Windows version of Safari, where files can be downloaded without an option to prompt before doing so, the flaw can be used to take over Windows, reports Aviv Raff.

The flaw in Internet Explorer uses the calculator program in conjunction with Safari for Windows to make two moderate vulnerabilities into a critical one. Microsoft has issued a bulletin, but it doesn't really say too much. Even if Microsoft patches IE, there's still Safari's "carpet bomb" issue that can allow unwanted downloads. Right now, Apple doesn't appear to want to fix this. Simply adding the option to prompt for all downloads before doing the download would help prevent this. Stopbadware wrote on their blog to urge Apple to do so.

You have to visit a specially crafted web page for this exploit to work. So it is not an all out fiasco. So far, there is not a known use of this problem. Right now, the only guaranteed fix to prevent this is to uninstall Safari for Windows. This may not be a bad idea, since there could be more bugs like this that can be exploited in Safari for Windows, said Raff in an interview with Macworld.

Thursday, May 29, 2008

Service Pack 3 Available On CD

For those who are not on a good Internet connection or one where you are limited in bandwidth, you can get Service Pack 3 on CD now. You can also download a disk image or stand alone installer, which you can use to take home or save for a re-install. Having SP 3 available will help if you do need to re-install, so you won' have to go online and expose yourself to the evils of the Internet. You can check it out on Microsoft TechNet.

Saturday, November 24, 2007

MSN Messenger Trojan

An MSN trojan is infecting thousands of PC’s worldwide via an IRC botnet. The malware is being introduced by MSN Messenger files posing as pictures, mostly seeming to come from known contacts.

So you get a message saying ‘Hey, this is your pic’ or ‘Hey this is your pic on this site’ with a link to a picture rating site. Click on the link and you will find that your computer has been recruited into the botnet!

From e-Week

The Trojan is an IRC bot that’s spreading through MSN Messenger by sending itself in a .zip file with two names. One of the names includes the word “pics” as a double extension executable—a name generally used by scanners and digital cameras: for example, DSC00432.jpg.exe. The Trojan is also contained in a .zip file with the name “images” as a .pif executable—for example, IMG34814.pif.

The files are infiltrating new systems by using either known contacts from which the Trojan has harvested instant messaging names, as well as from the systems of unknown users.

The infection vector—an IM program—isn’t new. But the Trojan is the first that eSafe has tracked that has tried to scan for VNC (Virtual Network Computing) instances, likely in order to multiply the botnet’s number of connections.

Use your common sense when chatting with friends, don’t click on links or open files sent from friends or otherwise unless you are 100% sure that your friend intended to send you the link. They won’t be offended if you decline to click…. !

Here is some good advice from Get Safe Online about using Instant Messaging Safely

Wednesday, November 14, 2007

NutnWorks.com (formerly Security Central)

For various reasons my friends at Security Central (or http://security-central.us/forums/) have felt it necessary to change name and move domain.

You can find the team at Nutnworks.com or if you want a direct link to the forums then click here.

Nothing else has changed.. you will still get great security news and support there… although the nice green skin has been disabled for the time being as there is still a little bit of work that needs to be done on that.

Please update your bookmarks and give Larry and Paul some support by paying them a visit now and then.

Monday, November 12, 2007

Get Safe Online Awareness Week

Get Safe Online is a cracking site full of useful information in language that we can all understand, it’s the site I recommend to friends and colleagues who aren’t exactly computer nuts like me. The site is sponsored by the UK Government and various industry partners including Microsoft.

Unfortunately it also seems to be one of the best kept secrets on the internet. I very rarely see links to the site in my travels and certainly see very little about it in other types of media.

Hopefully this will change soon. The BBC ran a story today about the risks of identity theft and fraud when using social networking sites and Get Safe Online was heavily featured in the article.

This week is Get Safe Online Awareness week and the Get Safe Online campaign will be travelling around the country offering independent, expert advice on how you can stay safe and secure when using the internet.

  • Tuesday 13th November - Bristol & Edinburgh
  • Wednesday 14th November - Cardiff & Newcastle
  • Thursday 15th November - Birmingham & Manchester

If you have a web site or a blog then why not share a link?  The site will provide banners and script snippets in their supporters kit and they will also link to your site.. and as we all know… Google loves links!!! Get Safe Online Link information here.

Thursday, November 01, 2007

October's Top Twenty

Want to know what was doing the rounds last month?

Online Scanner Top Twenty for October

Summary:-

  • New: Packed.Win32.NSAnti.r, Trojan-Downloader.VBS.Psyme.ga, Trojan.Win32.VB.atg, Trojan-Downloader.Win32.AutoIt.q, not-a-virus:Porn-Dialer.Win32.AdultBrowser.
  • Moved up: not-a-virus:AdWare.Win32.BHO.cc, Email-Worm.Win32.Rays, IM-Worm.Win32.Sohanad.t, IM-Worm.Win32.Sohanad.as, Worm.Win32.AutoIt.c
  • Moved down: Trojan.Win32.Dialer.qn, Trojan-Downloader.Win32.Small.ddp, not-a-virus:Monitor.Win32.Perflogger.ca, not-a-virus:PSWTool.Win32.RAS.a, not-a-virus:Monitor.Win32.Perflogger.ad, Trojan-Spy.Win32.Perfloger.ab
  • No change: Email-Worm.Win32.Brontok.q, Virus.VBS.Small.a, Trojan.Win32.Obfuscated.en

Virus Top Twenty for October

Summary:-

  • New: Trojan-Spy.HTML.Fraud.ay, Exploit.Win32.PDF-URI.k, Virus.Win32.Virut.a
  • Went up: Worm.Win32.Feebs.gen, Email-Worm.Win32.NetSky.t, Net-Worm.Win32.Mytob.t, Net-Worm.Win32.Mytob.u
  • Went down: Email-Worm.Win32.NetSky.aa, Email-Worm.Win32.Mydoom.l, Email-Worm.Win32.Bagle.gt, Email-Worm.Win32.Nyxem.e, Net-Worm.Win32.Mytob.c, Email-Worm.Win32.NetSky.b, Net-Worm.Win32.Mytob.dam, Exploit.Win32.IMG-WMF.y, Trojan-Spy.HTML.Paylap.bg
  • Re-entry: Email-Worm.Win32.LovGate.w

Monday, October 29, 2007

ESET Smart Security and ESET NOD32 Antivirus V3.0 Launched

I’m not a big fan of Security Suites… for my own reasons, they may suit some people but they don’t really suit me.

However I was excited to learn that ESET has launched ESET Smart Security and ESET Nod32 Antivirus v3.0 today.

Bournemouth, UK (29th October 2007) – ESET, the leader in proactive threat protection, today announced ESET Smart Security, a new, integrated security solution for consumers and SMEs, built on ESET’s award-winning advanced heuristic ThreatSense® detection system and the ESET NOD32 scanning engine. Unlike security suites that combine standalone products, ESET Smart Security tightly integrates the antispyware, antispam and firewall features, with the new version of ESET’s flagship ESET NOD32 Antivirus scanning engine. This tight integration allows each module to share information with the other to evaluate and classify every threat appropriately.

“Threats no longer appear in the form of pure viruses or spam or phishing. They now come as ‘blended’ threats which require an integration and intelligence among individual security features. Smart computer users are looking for the best level of integrated protection with the minimal amount of inconvenience,” said Phil Hochmuth, senior analyst at the Yankee Group. “This drives users to look for malware solutions that provide great protection, are easy to install, don’t slow down their computers, and work completely behind the scenes.”

Full blurb here

If you are interested in some of the issues that came up as it was being tested then check out the official support forums at Wilders

Wednesday, October 24, 2007

Direct Revenue is Dead

Take it away Paperghost!

I’ll just have a little dance about whilst everyone involved in this great result enjoys the feeling of a good job jobbed as my mum used to say! Photo Sharing and Video Hosting at Photobucket

Tuesday, October 02, 2007

Botmasters Take Heed – You Are Being Put On Notice

As an active member of the security community I am painfully aware of the constant attack that our servers suffer. Most of the time this can be managed, but sometimes it gets just a little too much.

Back in February of this year, my friends at Castlecops suffered a massive DDoS attack, but even though it spoiled Paul and Robin’s valentines day celebrations.. they kept the site going.

Today, Greg King of Fairfield in California was arrested and charged with being responsible for the DDoS against CastleCops last February.

Read what Robin has to say in her announcement here.

Good guys = 1 Bad guys = 0

Update - Excellent write up at The Register

Monday, October 01, 2007

Media Motor Gets Slammed by FTC

The Federal Trade Commission slammed Media Motor with a $330,000 fine and a possible forfeiture of $3,595,925 in money that was "ill-gotten" according to the FTC. While the whole amount should be turned over, it is good to see that another malware maker has been slammed for ripping people off.

Back in November, the FTC charged ERG Ventures, LLC with tricking people into downloading Media Motor by hiding it in free downloads. Screen savers and video files were two of the most common types of files. Even today, many spyware programs use free videos to get their crap onto your computer. The Zlob trojan, responsible for the likes of SpyAxe, SpyFalcon and VirusRescue, used videos and a fake codec to get on your computer. Anyways, once Media Motor got on your computer, it would your home page, track you, try to disable your antispyware programs and generally be a pain to get rid of.

Here's an excerpt from the FTC report describing the penalties that Media Motor is subject to:

The order will permanently bar the defendants from distributing software that interferes with consumers’ computers, including software that tracks consumers’ Internet activity or collects other personal information; generates disruptive pop-up advertising; tampers with or disables other installed programs; or installs other advertising software onto consumers’ computers. The defendants will also be required to fully disclose the name and function of all software they install on consumers’ computers in the future, and to provide consumers with the option to cancel the installation after viewing the disclosure.


You can read the full report on the FTC media Motor press release here.

The Federal Trade Commission is the branch of the US Federal Government that handles fraudulent Internet web sites and programs. You can file a complaint against any web site or computer program by visiting the FTC complaint page and filing a complaint. You can also call 1 877 382 4357 to complain as well.

Friday, September 14, 2007

Tom Coyote Is Now What the Tech

One of my favorite security and help sites, Tomcoyote.org, has changed names to What the Tech. The old Tom Coyote url will be redirected to the new site, but it is still a good idea to update your bookmarks.

Site: http://whatthetech.com
Forum: http://forums.whatthetech.com/forums.html

Monday, September 10, 2007

New Skype Worm

Whether you want to call it w32/Ramex.A or Bubbles, I couldn’t explain it any better than Chris Boyd (aka Paperghost) does.  So trolly on over to Spywareguide.com to see what he has to say with some pretty pictures too.

Saturday, September 08, 2007

Winpatrol Updated

When Winpatrol 2007 was released I thought it was fab and I absolutely adore Scotty in his blue Vista bubble. But not everyone agrees with me.

Winpatrol has listened to customer feedback and have today released a minor update that among other things will enable users to have the original black Scotty icon back in your system tray.

If you like Scotty as he is and you aren't having any problems with Winpatrol Plus features then there is no rush to download the update.

Check out Bits from Bill for all the latest Winpatrol News and more.

Friday, September 07, 2007

Microsoft Security Bulletin Advance Notification for September 2007

Microsoft have released an advance notification for the normal monthly updates that are due to be released next Tuesday. Don’t forget to prepare for the updates as I’ve outlined in an earlier entry - How To Prepare for Patch Tuesday.

On 11 September 2007 Microsoft is planning to release:
Security Updates

One Critical Bulletin in total.

  • One Microsoft Security Bulletin affecting Microsoft Windows 2000 Service Pack 4 with a Maximum Severity rating of Critical. This update will require a restart and will be detectable using the Microsoft Baseline Security Analyzer.

Four Important Bulletins in total.

  • One Microsoft Security Bulletin affecting Visual Studio with a Maximum Severity rating of Important. This update may require a restart and will be detectable using the Enterprise Update Scan Tool and Microsoft Baseline Security Analyzer.
  • One Microsoft Security Bulletin affecting Windows Services for UNIX, Subsystem for UNIX-based Applications, with a Maximum Severity rating of Important. This update will require a restart and will be detectable using the Enterprise Update Scan Tool and the Microsoft Baseline Security Analyzer.
  • One Microsoft Security Bulletin affecting MSN Messenger, Windows Live Messenger, with a Maximum Severity rating of Important. This update will not require a restart and will be detectable using the built-in mechanisms for automatic detection and deployment of updates for this software.
  • One Microsoft Security Bulletin affecting Windows SharePoint Server, with a Maximum Severity rating of Important. This update will not require a restart and will be detectable using the Microsoft Baseline Security Analyzer.

Microsoft Windows Malicious Software Removal Tool

  • Microsoft will release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services and the Download Center.Note that this tool will NOT be distributed using Software Update Services

Non-security High Priority updates on MU, WU,WSUS and SUS

  • Microsoft will release zero NON-SECURITY High-Priority Updates for Windows on Windows Update (WU)
  • Microsoft will release one NON-SECURITY High-Priority Updates on Microsoft Update (MU) and Windows Server Update Services (WSUS).

Microsoft Security Bulletin Advance Notification

Obtaining Other Security Updates

Updates for other security issues are available from the following locations:

  • Security updates are available from Microsoft Download Center. You can find them most easily by doing a keyword search for “security_patch”.
  • Updates for consumer platforms are available from Microsoft Update.
  • You can obtain the security updates offered this month on Windows Update, from Download Center on Security and Critical Releases ISO CD Image files. For more information, see Microsoft Knowledge Base Article 913086

Microsoft will host a Webcast to address customer questions on these bulletins on Wednesday, September 12, 2007, at 11:00 AM Pacific Time (US & Canada),for attendees to ask questions about the bulletins and get answers from the security experts.