Search

Search results below

Wednesday, April 8, 2009

Bogus bomb, somewhere near you

Rob Stringer

Security labs have discovered a variant of malicious spam that is engineered to report an exploded bomb within the recipient’s vicinity.

The ‘waledac’ variant, containing an apparent link to a Reuters website, shows the geolocation of the explosive as corresponding to the users IP address.

The story, perhaps designed off the back of recent terrorism-related events, claims that 12 people have been killed in the blast, and over 40 wounded, and contains such leading subject titles as "Why did it happen in your city?", "Take Care!" and "Are you and your friends in good health?"

Links to Wikipedia and Google are also included to convince the recipient of the veracity of the report.

"This is a clever piece of social engineering,” says Graham Cluley, senior technology consultant at Sophos. "If you visit the webpage from Southampton, Bristol or London it is likely to claim that the bomb blast has occurred there. There are the usual clues that the observant computer user will recognise as spam - poor spelling and grammar being the key one - but the danger is that other less wary users won't notice this and will become engrossed in the story without realising that their PC is being infected as they read."

This news article was submitted at infosecurity-magazine.com

Tuesday, April 7, 2009

Kids responsible for Estonia attack

Kids responsible for Estonia attack

Ian Grant, ComputerWeekly


The distributed denial of service attack that took down Estonia was run by a bunch of kids, it has emerged.

Two years ago, the former Soviet satellite found its banking and government websites paralysed for several weeks by a distributed denial-of-service (DDoS) attack.

The incident prompted a massive reorganisation and upgrade of network security and early warning systems among Nato members, and Nato even set up a cyber-security research house in Estonia.

At the time Russia was suspected of orchestrating the attack, but Moscow always denied it, and indeed Estonian officials never accused the Kremlin directly.

Yesterday, Konstantin Goloskokov (22) claimed he and some friends set up the attack to protest the removal of a Red Army monument from a downtown site in Estonia's capital Tallinn. The move had earlier led to rioting by pro-Soviet protesters.

Goloskokov told Reuters the attack was an act of civil disobedience, and, therefore, completely legal. "I was not involved in any cyber-attack," he said.

Goloskokov, a pro-Soviet activist, said he and his friends had set up the botnet that overloaded Estonian websites, causing them to crash.

"The fact that they could not withstand this is, strictly speaking, the fault of those people who, from a technical point of view, did not equip them properly," he told Reuters.

This article first appeared on the web-site of Computer Weekly, at
http://www.computerweekly.com/Articles/2009/03/13/235262/kids-responsible-for-estonia-attack.htm

Monday, June 30, 2008

Detecting SSH tunnels

Italian researchers have published a paper on the Detection of Encrypted Tunnels across Network Boundaries.

Click here to read:
http://coderrr.wordpress.com/2008/06/28/detecting-ssh-tunnels/

Saturday, June 28, 2008

Beijing.Exe Storm Outbreak

A new spam outbreak attributed to the Storm Botnet has been hitting the Internet since Jun 18, 2008. The message warns of earthquakes hitting well known sites around the world causing significant destruction and loss of life and is being distributed from IP addresses hosted around the world. This site claims a quake measured in at 9.0 on the Richter scale has caused casualties and threatens the preparations for the upcoming Olympics hosted in China. The page contains links to a supposed video that actually downloads the Storm worm

Click below to read:
http://www.trustedsource.org/blog/125/BeijingExe-Storm-Outbreak

Former White House Advisor: Hackers Didn't Cause 2003 Blackout

Cyber security consultant Paul Kurtz threw some cold water this week on a report that Chinese hackers caused the massive 2003 northeastern U.S. blackout. He worked for the White House at the time of the outage.

Click below to read:

http://blog.wired.com/27bstroke6/2008/06/former-white-ho.html

Wards didn't tell consumers about credit card hack

An old name in retail was hit by a modern scourge - a hack of its customers' credit card numbers - but didn't inform the consumers, revealing how data breaches might be heavily undercounted even with new notification laws.

At least 51,000 records were exposed in the breach at the parent company of Montgomery Ward. The venerable Wards chain that began in 1872 went out of business in 2001, but in 2004 a catalog company, Direct Marketing Services Inc., bought the brand name out of bankruptcy. It now runs a Wards.com Web site along with six other sites, including three with Sears brands it has acquired: SearsHomeCenter.com, SearsShowplace.com and SearsRoomforKids.com.

Click below to read more:

http://apnews.myway.com//article/20080627/D91II9U82.html

Researchers Reveal Security Holes in Internet Explorer

Two security issues, one in Internet Explorer 7 and the other in Internet Explorer 6, could leave users open to attack.

Click on link to read more:

http://www.eweek.com/c/a/Security/Researchers-Reveal-Security-Holes-in-Internet-Explorer/