Rob Stringer
Security labs have discovered a variant of malicious spam that is engineered to report an exploded bomb within the recipient’s vicinity.
The ‘waledac’ variant, containing an apparent link to a Reuters website, shows the geolocation of the explosive as corresponding to the users IP address.
The story, perhaps designed off the back of recent terrorism-related events, claims that 12 people have been killed in the blast, and over 40 wounded, and contains such leading subject titles as "Why did it happen in your city?", "Take Care!" and "Are you and your friends in good health?"
Links to Wikipedia and Google are also included to convince the recipient of the veracity of the report.
"This is a clever piece of social engineering,” says Graham Cluley, senior technology consultant at Sophos. "If you visit the webpage from Southampton, Bristol or London it is likely to claim that the bomb blast has occurred there. There are the usual clues that the observant computer user will recognise as spam - poor spelling and grammar being the key one - but the danger is that other less wary users won't notice this and will become engrossed in the story without realising that their PC is being infected as they read."
This news article was submitted at infosecurity-magazine.com
Search
Search results below
Wednesday, April 8, 2009
Tuesday, April 7, 2009
Kids responsible for Estonia attack
Kids responsible for Estonia attack
Ian Grant, ComputerWeekly
The distributed denial of service attack that took down Estonia was run by a bunch of kids, it has emerged.
Two years ago, the former Soviet satellite found its banking and government websites paralysed for several weeks by a distributed denial-of-service (DDoS) attack.
The incident prompted a massive reorganisation and upgrade of network security and early warning systems among Nato members, and Nato even set up a cyber-security research house in Estonia.
At the time Russia was suspected of orchestrating the attack, but Moscow always denied it, and indeed Estonian officials never accused the Kremlin directly.
Yesterday, Konstantin Goloskokov (22) claimed he and some friends set up the attack to protest the removal of a Red Army monument from a downtown site in Estonia's capital Tallinn. The move had earlier led to rioting by pro-Soviet protesters.
Goloskokov told Reuters the attack was an act of civil disobedience, and, therefore, completely legal. "I was not involved in any cyber-attack," he said.
Goloskokov, a pro-Soviet activist, said he and his friends had set up the botnet that overloaded Estonian websites, causing them to crash.
"The fact that they could not withstand this is, strictly speaking, the fault of those people who, from a technical point of view, did not equip them properly," he told Reuters.
This article first appeared on the web-site of Computer Weekly, at
http://www.computerweekly.com/Articles/2009/03/13/235262/kids-responsible-for-estonia-attack.htm
Ian Grant, ComputerWeekly
The distributed denial of service attack that took down Estonia was run by a bunch of kids, it has emerged.
Two years ago, the former Soviet satellite found its banking and government websites paralysed for several weeks by a distributed denial-of-service (DDoS) attack.
The incident prompted a massive reorganisation and upgrade of network security and early warning systems among Nato members, and Nato even set up a cyber-security research house in Estonia.
At the time Russia was suspected of orchestrating the attack, but Moscow always denied it, and indeed Estonian officials never accused the Kremlin directly.
Yesterday, Konstantin Goloskokov (22) claimed he and some friends set up the attack to protest the removal of a Red Army monument from a downtown site in Estonia's capital Tallinn. The move had earlier led to rioting by pro-Soviet protesters.
Goloskokov told Reuters the attack was an act of civil disobedience, and, therefore, completely legal. "I was not involved in any cyber-attack," he said.
Goloskokov, a pro-Soviet activist, said he and his friends had set up the botnet that overloaded Estonian websites, causing them to crash.
"The fact that they could not withstand this is, strictly speaking, the fault of those people who, from a technical point of view, did not equip them properly," he told Reuters.
This article first appeared on the web-site of Computer Weekly, at
http://www.computerweekly.com/Articles/2009/03/13/235262/kids-responsible-for-estonia-attack.htm
Subscribe to:
Posts (Atom)