Showing posts with label stolen credit card number. Show all posts
Showing posts with label stolen credit card number. Show all posts

Saturday, 13 December 2008

IE zero day bites broader group of users

Researchers are warning that the unpatched security vulnerability in Microsoft's Internet Explorer affects more versions of the browser than previously thought, and that steps users must take to prevent exploitation are harder than first published.

According to an updated advisory from Redmond, the bug that's been actively exploited since Tuesday bites versions 5.01, 6, and 8 of the browser, which is by far the most widely used on the web. A previous warning from Microsoft only said that IE 7 was susceptible to the attacks. IE is susceptible when running on all supported versions of the Windows operating systems, Microsoft also says.

What's more, while there is some protection from Vista's User Account Control, the measure doesn't altogether prevent the attack, according to this post on the Spyware Sucks blog. Microsoft and others have suggested that those who must use IE in the next few weeks set the security level to high for the internet security zone or disable active scripting. These are sensible measures, but they don't guarantee you won't be pwned, according to this post from the Secunia blog.

Secunia goes on to revise what it says is the cause of the vulnerability. Contrary to earlier reports that pinned the blame on the way IE handles certain types of data that use the extensible markup language, or XML, format, the true cause is faulty data binding, meaning exploit code need not use XML.

Microsoft has yet to say whether it plans to issue a fix ahead of next month's scheduled release. For the moment, the volume of in-the-wild attacks remains relatively modest and limited mostly to sites based in China. But because attackers are injecting exploits into legitimate sites that have been compromised, we continue to recommend that users steer clear of IE until the hole has been closed.

Plenty of other researchers have weighed in with additional details about the flaw. Links from SANS, Sophos, and Hackademix here, here and here.®

Spyware - Eradicate It Now

Spyware removal has become a tedious work. As the spyware threat has worsened, a number of techniques have emerged to counteract it. Among these are

• programs designed to remove or to block spyware
• educating the users in such a way that spyware removal no longer is needed
• user practices which reduce the chance of getting spyware on a system.

Spyware remains a costly problem even with all new technology used to combat them. If a large number of spyware programs have infected a Windows computer, the only way to save the computer may be to back up user data, and fully reinstalling the operating system.

Anti-spyware programs

One of the markets most popular anti-spyware programs, Adwarealert will help you find and ultimately rid your computer of unwanted spyware software.

Many programmers and some commercial firms have released products designed to remove or block spyware. Steve Gibson's OptOut, , practially invented a growing category. Programs such as,

• Adwarealert
• Lavasoft's Ad-Aware SE
• Patrick Kolla's Spybot - Search & Destroy

rapidly gained popularity as effective tools to remove, and in some cases intercept, spyware programs.

Recently Microsoft bought the GIANT Anti-Spyware software, renaming it as Windows AntiSpyware beta and releasing it as a free download for Windows XP, Windows 2000, and Windows 2003 users. The renamed software for now exists as a time-limited beta test product that will expire at the end of July 2006. Microsoft is continuously developing and updating this product.

Antispyware protection, removal and antivirus

Major anti-virus firms such as Symantec, McAfee and Sophos have come later to the table, adding anti-spyware features to their existing anti-virus products.

In the beginning, anti-virus firms did not want to add anti-spyware functions, citing lawsuits brought by spyware authors against the authors of web sites and programs which described their products as "spyware".

However, recent versions of these major firm’s home and business anti-virus products do include anti-spyware functions. The spyware is treated differently from viruses though.

Symantec Anti-Virus, for instance, categorizes spyware programs as "extended threats" and now offers real-time protection from them (as it does for viruses). The drawback with these programs is that they are very complex and in many cases produce more hurdles to jump over then you as a user really need.

Like most anti-virus software, anti-spyware software requires a frequently-updated database of threats. As new spyware programs are released, anti-spyware developers discover and evaluate them, making "signatures" or "definitions" which allow the software to detect and remove the spyware.

If a spyware program is not blocked and manages to get itself installed, it may resist attempts to terminate or uninstall it. Some programs work together: when an anti-spyware scanner (or the user) terminates one running process, the other one starts up the killed program again, making it virtually impossible to clean the computer.

Some spyware will detect attempts to remove registry keys during the spyware removal and immediately add them again. Usually, booting the infected computer in safe mode allows an anti-spyware program a better chance of removing persistent spyware.

The most extreme way of cleaning is to move the hard drive to another computer, boot on the normal boot disk that computer has, and then clean the infected disk. You can also mount the infected disk over the local network and scan & clean it to remove as much spyware as possible.

It doesn’t matter what way you choose to clean your computer, but using a good spyware removal program will make your life much easier …

Thursday, 11 December 2008

In Midst of Economic Meltdown, Malware Business is Booming


1.9 million job losses, a dollar worth less than the Canadian and Australian dollar, the collapse of the auto industry, the complete meltdown of credit. What a year it’s been for we working stiffs!

If you, as many ‘mericans already have, find yourself on the job hunt in the near future, forget about real estate, investment, Avon sales or tool and die work. Apparently, the boom industry in 2009 will be in the crimeware sector. Hopefully, with corresponding spikes in the antivirus industry (please don’t leave me to the spammers!).

According to industry insiders, 2008 saw a 258% spike in the URLs spreading contagions via phishing tactics. Classic scams like emulating login portals to harvest valuable personal data, passwords and usernames are becoming more common as cyber criminals perfect their craft. Malicious tapeworms, retroviruses, MoBo-VD, circuitry eating zombie nets and Trojan donkey-kits are proliferating rapidly.

If you do a lot online banking, social networking, or even MMORPGing think twice before throwing your social security number, birthday, maiden name and blood type around the internet. Phishing tactics are no longer as transparent as the koobface worm we’re still seeing on Facebook.

These dweeb and nerd criminals manage to make some convincing mimic logon pages and tricky programs. Red flags to look for include any obviously ex-Soviet URLs (.ru, .az, .kz, .by .cz, .tm et al), key misspellings (think Homtail, hotmale, or hottamale instead of hotmail), and anything that has a .exe within a hundred feet of it.

If, on the other hand, you’re looking to get involved in the profitable crimeware industry, there are great opportunities out there. Why not work as the overlord of a zombie botnet? Trading in stolen credit card numbers would be a refreshing career change, no? Just be prepared to feel my wrath, and the wrath of anyone else who has ever lost personal information!

If you’re not feeling ambitious enough for a fast track career in malware development, you’re probably going to want arm yourself with up-to-date antivirus and antispyware software. Check out our software reviews to keep your identity secure.