Showing posts with label anti-virus. Show all posts
Showing posts with label anti-virus. Show all posts

8.18.2007

Trojan software hidden on Job Search web-sites...

Very nice article by Brian Prince on a Trojan malware that has infected a number of web sites, allegedly including Monster.com and other job search web sites.

Some quotes from Brian:

"The hackers behind the attack are running ads on the sites and injecting those ads with the Trojan. When an user views or clicks on one of the malicious ads, their PC is infected..."
Moral of the story: Even reliable, trusted sites can inadvertantly host malicious material or host links to sites that do.
"...all the information entered into their browser, such as financial information entered before it reaches SSL protected sites, is captured and sent off to the hacker's server..."
Moral of the story: one of the best ways to get encrypted data is to get it before it gets encrypted...
Brian quotes Don Jackson of SecureWorks: "This Trojan uses its own packer…it compresses and changes the code around," he said. "This packer is unique to this Trojan. It was written specifically for it, and the construction kit that produces the executables is very, very good at putting instruction substitutions, giving a long string of instructions for a simple task and putting garbage code or null operations in there, so that it is hard for anti-virus. Anti-virus has not been able to pick a stub…that they can identify reliably from file to file."
No moral here...just fascinating how well the creators have considered the issue of camouflaging their presence.

Chalmer

2.08.2007

Hacked in 39 seconds...

Just a quick point of reference regarding how prevalent probes and scans are on the Internet.

When you connect to the Internet, your computer is almost immediately being scanned by the bad guys. The researchers in this article found that their test computers were assaulted 2,244 times in 24 hours, or an average of every 39 seconds.

What does the astute reader do to keep themselves safe? Keep your defenses up - anti-virus, firewalls, etc.

Chalmer

2.03.2007

Dolphin Stadium web site hacked...

There is an article in ZDNet about an exploit on the website for Dolphin Stadium.

Apparently, the web server was hacked and the bad guys changed the web page to include a single line of code. That one line of code directs your computer to visit the bad guy's web site, in the background, where it then downloads a piece of malicious software, including a Trojan keystroke logger and a backdoor.

  • The keystroke logger records every keystroke you make (including your passwords and user IDs).
  • The backdoor grants the bad guy full access to your computer.
Further investigation of this issue has shown that other websites related to the Super Bowl were also infected and...hundreds of unrelated websites have also been infected...including the U.S. government's Center for Disease Control's website.

Yet another classic illustration of why it is so important to keep your systems patched and protected with up-to-date anti-virus files, etc. It doesn't take a visit to a shady web site to catch a nasty computer disease.

Chalmer

2.01.2007

Using voice commands to take over your computer

Depending on who you ask, it might be an "exploit"...it might not. Speech recognition, that is.

It seems that computers with speech recognition capabilities are susceptible to accepting spoken commands. This has apparently been confirmed by Microsoft in relation to their new operating system, Vista.

Vista will accept spoken commands and execute them. What this means, is that a webpage, such as MySpace or a malicious computer program could play sounds that will interact with the speech recognition program, and initiate malicious activity on your computer, such as file deletions, etc.

Such a sound wave file would slip right by anti-virus software.

To be sure, there are a number of issues that need to be worked out...not the least of which is getting the commands to play when you are not at your computer to stop the process. But do not worry...it will not be long, before the bad guys figure out a way to do so...

One example...taken from the MySpace model...would be to play a typical wave file that has music for the first few minutes and then silence for 40 or 50 minutes, at which time the audio commands would begin to play.

Guess this could mean the end of the "open mike."

Another link related to this topic.

Chalmer

12.31.2006

New Year Resolutions: Anti-virus, Firewall and Anti-Spyware

Happy New Year!

With the New Year upon us and everyone in the throes of new resolutions, I propose three information security resolutions:

  • Set up anti-virus software
  • Set up a firewall
  • Set up anti-spyware software
All of these are fairly simple and well worth your effort. In the next few articles, we will discuss the hows and whys of these three resolutions. See you soon!

Chalmer

Google