Saturday, July 4, 2009

Waledac Independence Day Theme Campaign In The Wild

There's a Waledac campaign going on under Independence Day theme. According to Websense, malicious email messages that are sent use subjects and content related to Independence Day, Fourth of July and fireworks shows.

The malicious Web sites in the current attack also have a July 4 or fireworks theme within the domain name. Sites look like YouTube site with a video on it. When user clicks the video (s)he is offered an .exe file that would install the latest variant of Waledac.

Source

Thursday, July 2, 2009

Firefox 3.5 Released

Mozilla released version 3.5 of its popular Firefox web browser on Tuesday 30/6. New version contains lots of improved features and some new ones are included too. More about the features can be read here.

New version is available for download here.

Monday, June 29, 2009

Malware Riding on Michael Jackson's Death

The tragic death of Michael Jackson, the "King of Pop", has made bad guys to take advantage of the situation. The most recent attacks try to make news hungry users install irc bot with backdoor capability to their systems.

Michael Jackson Malware

Michael Jackson Video Leads to Malware Download

Wednesday, June 24, 2009

New Version of Shockwave Player Available

There has been released a new version of Adobe Shockwave Player. Version 11.5.0.600 fixes a critical vulnerability which could allow an attacker to take control of the affected system.

Adobe recommends Shockwave Player users on Windows uninstall Shockwave version 11.5.0.596 and earlier on their systems, restart, and install Shockwave version 11.5.0.600.

More information:
Adobe's security bulletin
Secunia advisory

Vulnerability In Google Chrome

There has been found a vulnerability in Google Chrome -web browser:
CVE-2009-2121: Buffer overflow processing HTTP responses
Google Chrome is vulnerable to a buffer overflow in handling certain responses from HTTP servers. A specially crafted response from a server could crash the browser and possibly allow an attacker to run arbitrary code.


The vulnerability is categorized as critical and affects users of Google Chrome versions below 2.0.172.33. Users of vulnerable versions can update browser to patched version with in-built automatic updater or alternatively install new version from Google Chrome homepage.

More info here.

Saturday, June 20, 2009

Security Update For Foxit Reader Available

Foxit software has released an update to Foxit Reader 3.0 that fixes following two vulnerabilities:
1. Fixed a problem related to negative stream offset (in malicious JPEG2000 stream) which caused reading data from an out-of-bound address. We have added guard codes to solve this issue.
2. Fixed a problem related to error handling when decoding JPEG2000 header, an uncaught fatal error resulted a subsequent invalid address access. We added error handling code to terminate the decoding process.


Instructions for updating are provided here.

Thursday, June 18, 2009

Nine-Ball Compromises more than 40,000 Legitimate Web Sites

Websense reports about a large mass injection attack that has so far compromised thousands of web sites. "We have been tracking the Nine-Ball mass compromise since 6/03/2009. To date, over 40,000 legitimate Web sites have been compromised with obfuscated code that leads to a multi-level redirection attack, ending in a series of drive-by exploits that if successful install a trojan downloader on the user's machine", writes Websense.

This is the third time within a short period when a big amount of web sites gets compromised. Earlier two mass injections were made by Gumblar and Beladen.