Security company Websense warns in its alert about spam that is disguised as an official email sent from Orkut, Google-owned social network.
A spoofed personal message, in Portuguese, is sent from a user allegedly on the Orkut network seeking love. The message contains several links that appear to lead to the official Orkut Web site. "Clicking on a link actually leads to a malicious executable file, which is a Trojan Downloader named "imagem.exe"", is told in the Websense alert. "The malicious file opens the legitimate Orkut network login page, and in the background downloads a password stealing Trojan named "msn.exe"."
Websense says that the trojans used in this attack are hosted on a compromised labor union web site from southern Brazil.
Wednesday, November 26, 2008
Amount Of Spam Rising Again
Amount of spam messages decreased to the one third of normal for a couple of weeks when criminal operator's lines were disconnected. Restart of botnets has been going on since Monday and spam amounts are rising rapidly again. Amounts would be even higher but the worst botnet is still offline.
American McColo operator operates many controller servers of the world's biggest botnets. According to security companies closure of McColo sent at least Srizbi, Asprox and Rustock botnets offline.
During couple of weeks criminals have moved some of their controlling operations to other parts of the world, to Russia for example. Criminals even used a backup connection they successfully got by tricking internet service operator TeliaSonera to transfer data to new host in Russia. Last Sunday spam amounts decreased to minimal level but rapid increase began on Monday. According to Messagelabs security company (now part of Symantec) the reason behind increase is that Asprox and Rustock botnets have returned online. Also, Cutwail and Mega-D botnets have increased their posting amounts.
Though the spam amount is increasing it's still under half of the peak a few weeks ago. Security companies say that's because the worst botnet Srizbi is still offline. Messagelabs says that even half of the world's spam is sent thru Srizbi. Security researchers have estimated that Srizbi would consist of even over 300,000 PC computers connected to the internet.
American McColo operator operates many controller servers of the world's biggest botnets. According to security companies closure of McColo sent at least Srizbi, Asprox and Rustock botnets offline.
During couple of weeks criminals have moved some of their controlling operations to other parts of the world, to Russia for example. Criminals even used a backup connection they successfully got by tricking internet service operator TeliaSonera to transfer data to new host in Russia. Last Sunday spam amounts decreased to minimal level but rapid increase began on Monday. According to Messagelabs security company (now part of Symantec) the reason behind increase is that Asprox and Rustock botnets have returned online. Also, Cutwail and Mega-D botnets have increased their posting amounts.
Though the spam amount is increasing it's still under half of the peak a few weeks ago. Security companies say that's because the worst botnet Srizbi is still offline. Messagelabs says that even half of the world's spam is sent thru Srizbi. Security researchers have estimated that Srizbi would consist of even over 300,000 PC computers connected to the internet.
Sunday, November 23, 2008
Microsoft's Removal Tool Cleans Fake Security Software
Microsoft added its Malicious Software Removal Tool (MSRT) for November to target fake security software (that has plagued Windows users all over the world. Looks like tool is doing its job. Last Wednesday Microsoft released some results in its Malware Protection Center Blog. According to the results nearly a million PCs were cleaned of fake security software (recognized as "W32/FakeSecSen by MSRT) during the period from November 11 to November 19.
This is one of the biggest clean-up job that Microsoft has ever done. In June 2008, MSRT sniffed out 1.2 million PCs infected with a family of password stealers, while in February, it scrubbed the Vundo Trojan from about a million machines. Over several months at the end of last year, MSRT hit the then-notorious Storm Trojan hard, cleaning it from a half-million PCs.
Source
This is one of the biggest clean-up job that Microsoft has ever done. In June 2008, MSRT sniffed out 1.2 million PCs infected with a family of password stealers, while in February, it scrubbed the Vundo Trojan from about a million machines. Over several months at the end of last year, MSRT hit the then-notorious Storm Trojan hard, cleaning it from a half-million PCs.
Source
Tuesday, November 18, 2008
Vulnerable Adobe AIR
There has been found a vulnerability that could allow an attacker who successfully exploits this potential vulnerability to execute untrusted JavaScript with elevated privileges. An Adobe AIR application must load data from an untrusted source to trigger this potential vulnerability.
As a resolution Adobe recommends AIR users with version below 1.5 to update their software to 1.5 version. AIR 1.5 includes a Flash Player update to resolve the critical issues as outlined in Flash Player Security Bulletin APSB08-22, as well as issues included in Flash Player Security Bulletins APSB08-20 and APSB08-18.
Source
As a resolution Adobe recommends AIR users with version below 1.5 to update their software to 1.5 version. AIR 1.5 includes a Flash Player update to resolve the critical issues as outlined in Flash Player Security Bulletin APSB08-22, as well as issues included in Flash Player Security Bulletins APSB08-20 and APSB08-18.
Source
Friday, November 14, 2008
Version 3.2 of Safari Web Browser Fixes Several Vulnerabilities
Apple has fixed totally 11 vulnerabilities in its Safari web browser. All vulnerabilities are related to Safari for Windows. Four of the vulnerabilities affect also Safari for Mac OS X (CVE-2008-3644, CVE-2008-2303, CVE-2008-2317 and CVE-2008-4216).
Apple updates contain fixes to the 3rd party libraries (zlib, libxslt, libTIFF and ImageIO). Among those patched are also CoreGraphics, WebCore and WebKit. Several of these patched vulnerabilities can be exploited by luring user to specially crafted website.
Vulnerable are following Safari versions:
- Safari for Mac OS X v10.4.11 prior version 3.2
- Safari for Mac OS X v10.5.5 prior version 3.2
- Safari for Windows XP prior version 3.2
- Safari for Windows Vista prior version 3.2
Users with vulnerable Safari can obtain version 3.2 either through Apple Software Update application or at http://www.apple.com/safari/download
More information on the vulnerabilities:
Security content of Safari 3.2
CVE-2005-2096
CVE-2008-1767
CVE-2008-2303
CVE-2008-2317
CVE-2008-2327
CVE-2008-2332
CVE-2008-3608
CVE-2008-3623
CVE-2008-3642
CVE-2008-3644
CVE-2008-4216
Apple updates contain fixes to the 3rd party libraries (zlib, libxslt, libTIFF and ImageIO). Among those patched are also CoreGraphics, WebCore and WebKit. Several of these patched vulnerabilities can be exploited by luring user to specially crafted website.
Vulnerable are following Safari versions:
- Safari for Mac OS X v10.4.11 prior version 3.2
- Safari for Mac OS X v10.5.5 prior version 3.2
- Safari for Windows XP prior version 3.2
- Safari for Windows Vista prior version 3.2
Users with vulnerable Safari can obtain version 3.2 either through Apple Software Update application or at http://www.apple.com/safari/download
More information on the vulnerabilities:
Security content of Safari 3.2
CVE-2005-2096
CVE-2008-1767
CVE-2008-2303
CVE-2008-2317
CVE-2008-2327
CVE-2008-2332
CVE-2008-3608
CVE-2008-3623
CVE-2008-3642
CVE-2008-3644
CVE-2008-4216
Thursday, November 13, 2008
Vulnerabilities In Mozilla Firefox, SeaMonkey and Thunderbird
There have been found several vulnerabilities in Mozilla products. Firefox 2 update fixes totally eleven vulnerabilities. Firefox 3 and SeaMonkey new versions contain fixes to ten vulnerabilities of which five are critical. In Thunderbird there were found six vulnerabilities of which some are critical.
Vulnerabilities enable escalation of user privileges, obtaining sensitive information and a remote attacker cause a denial of service (crash) and possibly execute arbitrary code in target system.
Mozilla recommends disabling JavaScript until updates have been installed. Recommendation concerns especially Thunderbird email client for which hasn't update available yet. In Thunderbird JavaScript is disabled by default.
Vulnerable software:
- Mozilla Firefox prior version 2.0.0.18
- Mozilla Firefox prior version 3.0.4
- Mozilla Thunderbird prior version 2.0.0.18
- Mozilla SeaMonkey prior version 1.1.13
Solution:
Users are instructed to update their versions to following ones:
- Mozilla Firefox 2.0.0.18
- Mozilla Firefox 3.0.4
- Mozilla Thunderbird 2.0.0.18 (version is not released yet)
- Mozilla SeaMonkey 1.1.13
Update can be made with automatic update functionality in correspondent software product or by installing new versions from http://www.mozilla.com/ and http://www.seamonkey-project.org/.
More information on vulnerabilities:
- http://www.mozilla.org/security/announce/2008/mfsa2008-47.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-48.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-49.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-50.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-51.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-52.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-53.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-54.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-55.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-56.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-57.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-58.html
- CVE-2008-0017
- CVE-2008-4582
- CVE-2008-5012
- CVE-2008-5013
- CVE-2008-5014
- CVE-2008-5015
- CVE-2008-5016
- CVE-2008-5017
- CVE-2008-5018
- CVE-2008-5019
- CVE-2008-5021
- CVE-2008-5022
- CVE-2008-5023
- CVE-2008-5024
Vulnerabilities enable escalation of user privileges, obtaining sensitive information and a remote attacker cause a denial of service (crash) and possibly execute arbitrary code in target system.
Mozilla recommends disabling JavaScript until updates have been installed. Recommendation concerns especially Thunderbird email client for which hasn't update available yet. In Thunderbird JavaScript is disabled by default.
Vulnerable software:
- Mozilla Firefox prior version 2.0.0.18
- Mozilla Firefox prior version 3.0.4
- Mozilla Thunderbird prior version 2.0.0.18
- Mozilla SeaMonkey prior version 1.1.13
Solution:
Users are instructed to update their versions to following ones:
- Mozilla Firefox 2.0.0.18
- Mozilla Firefox 3.0.4
- Mozilla Thunderbird 2.0.0.18 (version is not released yet)
- Mozilla SeaMonkey 1.1.13
Update can be made with automatic update functionality in correspondent software product or by installing new versions from http://www.mozilla.com/ and http://www.seamonkey-project.org/.
More information on vulnerabilities:
- http://www.mozilla.org/security/announce/2008/mfsa2008-47.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-48.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-49.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-50.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-51.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-52.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-53.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-54.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-55.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-56.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-57.html
- http://www.mozilla.org/security/announce/2008/mfsa2008-58.html
- CVE-2008-0017
- CVE-2008-4582
- CVE-2008-5012
- CVE-2008-5013
- CVE-2008-5014
- CVE-2008-5015
- CVE-2008-5016
- CVE-2008-5017
- CVE-2008-5018
- CVE-2008-5019
- CVE-2008-5021
- CVE-2008-5022
- CVE-2008-5023
- CVE-2008-5024
Tuesday, November 11, 2008
Security Update For November 2008 From Microsoft
Microsoft released its monthly security update packet today. This month update contains 2 updates. One of those is critical and the other one important.
Critical update fixes several vulnerabilities in Microsoft XML Core Services. The most severe vulnerability could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
The important update fixes vulnerability in Microsoft Server Message Block (SMB). The vulnerability could allow remote code execution on affected systems. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
New version of Microsoft Windows Malicious Software Removal Tool is released too.
More information about the updates can be read here.
The easist way to get the updates is to use Microsoft automatic update service.
Critical update fixes several vulnerabilities in Microsoft XML Core Services. The most severe vulnerability could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
The important update fixes vulnerability in Microsoft Server Message Block (SMB). The vulnerability could allow remote code execution on affected systems. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
New version of Microsoft Windows Malicious Software Removal Tool is released too.
More information about the updates can be read here.
The easist way to get the updates is to use Microsoft automatic update service.
Subscribe to:
Posts (Atom)