Sunday, 29 January 2012

Facebook Security Phishing Attack In The Wild


Facebook Security Phishing Attack In The Wild

By David Jacoby
David JacobyAt the time of writing there is a new Facebook phishing attack going on. It will not just try to steal your Facebook credentials; it will also try to steal credit card information and other important information such as security questions.
This Facebook phishing attack is pretty interesting because it does not just try to trick the victim into visiting a phishing website. It will reuse the stolen information and login to the compromised account and change both profile picture and name. The profile picture will be changed to the Facebook logo and the name will be translated to “Facebook Security” but containing special ascii characters replacing letters such as “a” “k” “S” and “t”.
Once an account is compromised it will also send out a message to all contacts of the compromised account. The message looks like this:
Facebook
"Last Warning: Your Facebook account will be turned off Because someone has reported you. Please do re-confirm your account security by: => http://apps-xxxx-xxxxx-user.de.vuThank you. The Facebook Team"/
When clicking on the link you will be redirected to a website which looks very similar to Facebook, and asks you for personal information such as: Name, Email, Password, Webmail system, Password to email etc. When submitting this form the details will be sent to the attacker, and they can automatically login to your Facebook account and compromise it.
Facebook
After the victim submitted the information another webpage will appear, this page states that you need to confirm your identify with a payment and asks for your Card Number.
Facebook
The last page of the phishing scam will try to confirm your Credit card information including CSC/CVV code.
Facebook
These scams are just getting more popular and we really recommend not giving out personal information, especially not email, password and credit card information over social medias. It is also recommend that you contact your security vendor and the social media vendor if you encounter these sites.

Saturday, 24 December 2011

Watch out for fake virus alerts


Watch out for fake virus alerts

Example of a warning from a rogue security program known as AntivirusXP
Rogue security software, also known as "scareware," is software that appears to be beneficial from a security perspective but provides limited or no security, generates erroneous or misleading alerts, or attempts to lure users into participating in fraudulent transactions.


How does rogue security software get on my computer?

Rogue security software designers create legitimate looking pop-up windows that advertise security update software. These windows might appear on your screen while you surf the web.
The "updates" or "alerts" in the pop-up windows call for you to take some sort of action, such as clicking to install the software, accept recommended updates, or remove unwanted viruses or spyware. When you click, the rogue security software downloads to your computer.
Rogue security software might also appear in the list of search results when you are searching for trustworthy antispyware software, so it is important to protect your computer.

What does rogue security software do?

Rogue security software might report a virus, even though your computer is actually clean. The software might also fail to report viruses when your computer is infected. Inversely, sometimes, when you download rogue security software, it will install a virus or other malicious software on your computer so that the software has something to detect.
Some rogue security software might also:
  • Lure you into a fraudulent transaction (for example, upgrading to a non-existent paid version of a program).
  • Use social engineering to steal your personal information.
  • Install malware that can go undetected as it steals your data.
  • Launch pop-up windows with false or misleading alerts.
  • Slow your computer or corrupt files.
  • Disable Windows updates or disable updates to legitimate antivirus software.
  • Prevent you from visiting antivirus vendor websites.
Rogue security software might also attempt to spoof the Microsoft security update process. Here's an example of rogue security software that's disguised as a Microsoft alert but that doesn't come from Microsoft.

Example of a warning from a rogue security program known as AntivirusXP.
For more information about this threat, including analysis, prevention and recovery, see the Trojan:Win32/Antivirusxp entry in the Microsoft Malware Protection Center encyclopedia.
Here is the legitimate Microsoft Windows Security Center:
Screenshot of legitimate Microsoft Windows Security Center
Screenshot of legitimate Microsoft Windows Security Center.

To help protect yourself from rogue security software:

  • Install a firewall and keep it turned on.
  • Use automatic updating to keep your operating system and software up to date.
  • Install antivirus and antispyware software such as Microsoft Security Essentials and keep it updated. For links to other antivirus programs that work with Microsoft, see Microsoft Help and Support List of Antivirus Vendors.
  • If your antivirus software does not include antispyware software, you should install a separate antispyware program such asWindows Defender and keep it updated. (Windows Defender is available as a free download for Windows XP and is included in Windows Vista.)
  • Use caution when you click links in email or on social networking websites.
  • Use a standard user account instead of an administrator account.
  • Familiarize yourself with common phishing scams.

If you think you might have rogue security software on your computer:

Scan your computer. Use your antivirus software or do a free scan with the Microsoft Safety Scanner. The safety scanner checks for and removes viruses, eliminates junk on your hard drive, and improves your PC's performance.
Get help from a Microsoft partner. If you have trouble removing the software yourself, you can enter your zip code to find experts in your area

Thursday, 15 December 2011

Facebook virus alert


Facebook virus alert: Worm hidden in image of two blondes

By  | November 29, 2011, 1:55pm PST
Summary: A new worm is spreading on Facebook: once downloaded, it tempts the user into opening it by masquerading as a screensaver with a thumbnail image of two blonde women.
A new piece of malware is spreading across Facebook by leveraging either stolen account credentials or possibly a rogue app. This one is a worm that is being shared via malicious links on the social network, according to the Danish website CSIS, which listed the following domains as sources for the malware:
vinamost.net
ferry.coza
maximilian-adam.com
bacolodhouseandlot.com
servi ceuwant.com
centralimoveisbonitoms.com.br
weread.in.th
villamatildabb.com
fionagh-bennet-music.co.uk
ukseikatsu.com
bzoe-salzkammergut.at
delicescolres.com
dekieviten.nl
If one of your Facebook friends has had his or her account compromised, you may be tempted to click on a link seemingly posted by them. What appears to be a screensaver, with a thumbnail image of two blonde women, will be downloaded onto your computer.
This is in fact a worm: do not download it and do not open it. If you think you have been affected, please read Facebook virus or account hacked? Here’s how to fix it.
When the file is opened, it attempts to download further malware, including a popular Trojan called Zeus. This type of malware can take over your computer and/or attempt to steal your banking information.
The malware’s code is written in Visual Basic 6.0 and includes ways of tricking users on virtual machines. The source appears to be a compromised Israeli website, which is no longer hosting the file in question. Still, hackers can always use additional websites to continue spreading their malware.
As a general word of caution, don’t click on everything your Facebook friends share on the social network. I have contacted Facebook to learn if it has blocked any unusual activity related to this latest worm and if it has any more information to offer.
Update: “Almost all of the domains listed in the article were already blocked by our mitigation efforts, however, we are constantly monitoring the situation and are in the process of blocking domains as we discovered them,” a Facebook spokesperson said in a statement. “We have internal systems in place configured specifically to monitor for variations of the spam and are working with others across the industry to pursue both technical and legal avenues to fight the bug.

Patch Tuesday December 2011


Patch Tuesday December 2011

Kurt Baumgartner
Kaspersky Lab Expert
Posted December 14, 13:10  GMT
Tags: Microsoft WindowsMicrosoft Internet ExplorerMicrosoft,Vulnerabilities and exploits
0.4
 

Microsoft finishes out this year of patching with a heavy release that's all over place. While techs were notified of an anticipated 14 bulletins, 13 were released for the month of December. Headline grabbing events and code are addressed in one of them, and while fewer are labelled "Critical", are they any less important?
Many speculative bits have been spilled on the group behind Stuxnet and its precursor Duqu, with our own researchers posting at least a half dozen Securelist writeups on Duqu findings alone. MS11-087 patches up the delivery vector for Duqu itself. This kernel mode vulnerability was publicly identified and confirmed at the beginning of November, but could well have been used quietly in attacks around the world for a year or more.
The targeted functionality provides TrueType font parsing capabilities for the OS, and the group abused these components by delivering exploits in the form of Word Documents attached to emails interesting to their individual victims, a technique known as spear-phishing. The flawed code has been known to impact only a very select set of systems throughout the world.
The other headline grabbing event and code that was anticipated to be released is known as the SSL BEAST vulnerability. We covered the potential hysteria surrounding the Ekoparty conference demo in Argentina a couple of months ago, where a researcher demonstrated SSL being cracked on a Windows system. There were no public reports whatsoever of this flaw being attacked, and Microsoft is delaying its release to ensure that its browser cannot be hacked in this way without compatibility issues, following the lead of Google Chrome and Firefox.
A slew of other patches were released this time around, with Internet Explorer, Powerpoint, and other components, including the Chinese font producing Pinyin IME component, all being updated. It's interesting that even Microsoft considers exploit code likely to be published for at least a dozen of them, but does not consider many of them critical for admins to patch. One that stands out as a candidate for "Critical" in my book is the Active Directory problem. Organizations that have been under persistent targeted attacks may consider this one to be very urgent, with Domain Controllers and Active Directory of high interest to their adversaries in past attacks.

Gulf Manorama | Gulf News | Latest News

Gulf Manorama | Gulf News | Latest News