Microsoft Outlook Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 10 August 2009

Pro-Georgian blogger was the target of Internet attacks

Posted on 11:53 by Unknown
by Michael Smith (Veshengro)

The cyber assaults of early August 2009 that temporarily derailed the websites Twitter, Facebook and LiveJournal were, according to Internet security company F-Secure, aimed at a pro-Georgian blogger.

The massive distributed-denial-of-service (DDoS) attacks were intended, so it would appear, to silence a blogger known as "Cyxymu" hammered Twitter, Facebook, LiveJournal and even YouTube, F-Secure researcher Mikko Hyponnen said in a message at the firm's website.

"Launching DDoS attacks against services like Facebook is the equivalent of bombing a TV station because you don't like one of the newscasters," Hyponnen wrote.

"The amount of collateral damage is huge. Millions of users of Twitter, LiveJournal, and Facebook have been experiencing problems because of this attack."

Facebook reported on Friday that it had isolated the trouble and service for its more than 250 million users had returned to normal.

I must say that I am a user of Twitter and of Facebook and had not even noticed that there has been a problem.

Cyxymu pages at Facebook and LiveJournal were targeted in the cyber assault, according to the Palo Alto, California-based social-networking hotspot.

Facebook said in a release that the attack appeared to have been directed at an individual who has a presence on a number of sites, rather than at the sites themselves.

"Specifically, the person is an activist blogger and a botnet was directed to request his pages at such a rate that it impacted service for other users."

Internet security specialists say the source of the attacks may never be determined with certainty if no one claims responsibility.

"Whoever is behind this attack, they had significant bandwidth available," Hyponnen said.

"Our best guess is that these attacks were done by nationalistic Russian hackers who wanted to silence a visible online opponent."

In "tweets" at popular micro-blogging service Twitter, Cyxymu blames Russian authorities out to stifle his online commentary.

The attacks may have had the opposite effect, with the number of people signed on to follow Cyxymu tweets more than quadrupling to 1,437 in the wake of the cyber assaults.

"My twitter is online!" a tweet proclaimed on Friday at the Twitter page of Cyxymu, who listed his location as Tbilisi. "Thank you all for support after ciber (sic) attack from Russia!"

Twitter and Facebook have teamed with US Internet powerhouse Google to investigate the attacks.

Google, who owns the online video-sharing website YouTube and also a Blogger service that were reportedly hit by cyber attacks.

Mountain View, California-based Google deflected the assaults and "prevented substantive impact to our services," a company spokesman said.

Classic DDoS attacks involve legions of zombie computers, machines infected with viruses, which are commanded to simultaneously visit a website.

Such a massive onslaught of demand can overwhelm website computer servers, slowing service or knocking it offline.

An everyday chatting tool for many, Twitter has also become a weapon for dissidents to circumvent censorship in places where freedom of speech is suppressed.

"The open exchange of information can have a positive impact globally and our job is to keep Twitter services running reliably to the best of our ability," Stone said.

The problem that we have been seeing here , though I must say it bypassed me entirely and |I did not happen to notice anything of it, shows how vulnerable computer systems, large and small, are to cyber attacks of any kind and how easy it could be to incapacitate not just, say, Twitter or Facebook or Blogger, but the national and international infrastructure of communication.

It must be said that many users are to blame as their computers are being turned into zombies in botnets due to their non-existent computer security procedures. Too many users have no idea as to the need to keep anti-virus and other anti-malware software updated on an at least once-daily basis though more often is better still.

Many users are also unaware of the fact that for personal use some of the best anti-virus and anti-malware software can be gotten entirely free for the asking from a variety of official sources on the Net, such as the AVG anti-virus, for instance.

In addition to that, in order to avoid nasty sited when following links, say, in Twitter, Finian also has made available free a browser tool that will verify links as safe, questionable or as dangerous and this tool certainly if very recommended.

While this will never stop such cyber attacks every additional secured PC around the world helps to cut down on the zombies.

© 2009
<>
Read More
Posted in | No comments

Finjan Prevents Zero-Day Exploit of Adobe Acrobat Reader and Flash Player Vulnerability

Posted on 11:49 by Unknown
San Jose, California – July 2009 (Eskenzi PR) – Finjan discovered a new 0-day exploit “in the wild”. This time, cybercriminals are exploiting a vulnerability in Adobe Acrobat Reader and Flash player.

The zero-day vulnerability found (CVE-2009-1862) can be exploited to download and execute malicious code on the victim’s PC. Adobe announced that an update will be available on July 31, 2009 which will leave end users’ PCs until then unprotected.

The exploit was detected “in the wild” by Finjan’s Malicious Code Research Center (MCRC). As with the previous 0-day attacks reported by MCRC, Finjan’s unified secure web gateway (SWG) successfully detected and prevented the attempt to exploit the vulnerability and execute the code. By utilizing its patented real-time content inspection technology, Finjan’s SWG proactively prevented the attack without any update.

Web security products utilizing real-time code analysis technologies are the preferred solution to block such 0-day attacks and exploits. Yuval Ben-Itzhak, Finjan CTO explains: “Finjan customers are protected from these kinds of zero-day attacks, since Finjan’s Vital Security™ Web Gateway is able to detect such an exploit and block it without the need to have prior knowledge of the specific technique used by cybercriminals.”

For more information about this zero-day exploit and a snapshot of the actual code as found in-the-wild, please visit Finjan’s blog at: http://www.finjan.com/MCRCblog.aspx?EntryId=2307

For more information on Adobe Security Advisory about this vulnerability: http://www.adobe.com/support/security/advisories/apsa09-03.html

Finjan’s MCRC specializes in the detection, analysis and research of web threats, including Crimeware, Web 2.0 attacks, Trojans and other forms of malware. Our goal is to be steps ahead of hackers and cybercriminals, who are attempting to exploit flaws in computer platforms and applications for their profit. In order to protect our customers from the next Crimeware wave and emerging malware and attack vectors, Finjan MCRC is a driving force behind the development of Finjan's next generation of security technologies used in our unified Secure Web Gateway solutions. For more information please also visit our info center and blog.

For more information about Finjan, please visit: www.finjan.com.
For alerts, please follow us on Twitter at www.twitter.com/SecureTweets

<>
Read More
Posted in | No comments

Sunday, 9 August 2009

Microsoft and Yahoo cooperate on Search

Posted on 08:52 by Unknown
Bing now to be the search engine for Yahoo. Help!

by Michael Smith (Veshengro)

Bing, the reincarnation of Live Search, which was the reincarnation of MSN Search is now going to be the search engine in use by Yahoo and this is not a good idea, I would say. Bing or whatever its name was or may be in the future is not ever going to be competition for Google and Yahoo Search was better than MSN ever so, why the merger, I ask.

Will this co-operation/merger between Microsoft and Yahoo be good for the users?

Firstly I would say that this may turn a lot of current Yahoo users off and against the company and secondly I am not sure whether the monopoly commissions somewhere should not take a closer look at this. Mind you, not that that would ever bother Microsoft for they have taken no notice whatsoever so far of what, for instance, the European Union has told it to do.

However, it must also be seriously doubted that those two even combined can ever get anywhere near Google, as search engine or otherwise.

As a search engine MSN Search, in its various guises and incarnations, including its latest reincarnation as “Bing”, has always been rather mediocre and lagging behind Yahoo Search even and can never come anywhere close to Google and compete with it.

Unless something of a miracle happens this merger is going to be a wasted exercise and may lead to users abandoning Yahoo, for example.

There are enough users who have a gripe against Microsoft but still use Yahoo, even though Yahoo uses web beacons, for instance, as homepage, for email and such and this “joint venture” of Yahoo with MSN could very well be the straw that breaks the camel's back and might lead to an exodus of users from Yahoo to elsewhere.

I personally am amongst other a Yahoo user with an email account, yahoo groups and My Yahoo homepage, using the latter also as an aggregation agent for RSS feeds and such. However, due tot he fact that Yahoo email cannot be collected onto email clients anymore I have migrated my business email to Gmail and may, sooner or later, also take my homepage to Google.

While Gmail has a strange interface when it comes to the webmail part it downloads just like any old-fashioned POP3 to most email clients and that is just what many of us need.

Since the merger there seem to be also quite a lot of small annoying hiccups on Yahoo such as on Mail when one tries to delete a message one needs two attempts often. Not very helpful when one is in a hurry to do things.

So, I do not see this merger as a good thing for users and neither for Yahoo.

© 2009
<>
Read More
Posted in | No comments

DESlock+ Achieves ‘Five Star’ Accolade

Posted on 08:50 by Unknown
SC Magazine recognises DES’ “intuitive way of handling removable media”

London, UK: (C8 Consulting Ltd) - Data Encryption Systems Limited (DES), the UK-based leader in software copyright protection, data encryption, secure messaging and data storage solutions, is pleased to announce that its flagship product, DESlock+ Version 4.0, has just received a five star rating in leading IT security magazine, SC Magazine. This is the highest accolade the magazine awards products under review.

The review, which was published as part of a Group Test on various encryption tools, was published in SC Magazine US, and can also be found online at the SC Magazine website. DES achieved full marks for performance, features, support and value for money and gained an overall rating of five stars.

Nathan Ouellette, product reviewer at SC Magazine, comments: “A unique feature that we liked is the way DESlock+ handles removable media such as USB drives. Users are able to utilise USB tokens without having to encrypt the entire drive. An encrypted folder is created on the stick and any PC with the DESlock+ client software installed will mount the drive from the encrypted folder, making the root folder of the drive equate to the encrypted data. Data is visible or hidden depending on whether the host has the agent installed.”

DESlock+ Version 4.0 was launched at this year’s Infosecurity Show, and has since been gaining a lot of interest. The product adds full-disk and policy-driven removable storage encryption to the well established granular encryption features of DESlock+. The revised back-end updates to the software now allow for a greater degree of control and policy enforcement from the DESlock+ Enterprise Server module and Administration Console. The product is also in the process of qualifying for a US government standard, FIPS 140-2 approval, with certification imminent.

David Tomlinson, Managing Director at DES, explains: “We are delighted that the hard work we have put into product development over the past year has paid off. As a relatively small company, we are very proud to have been tested against the rest of the industry and to have come out with top marks - even beating some of the bigger brand products on the market, such as BeCrypt and Credant. This review demonstrates what we already knew, and that’s that DESlock+ is a market leader when it comes to encryption.”

DESlock+ Version 4.0 is available immediately, with prices starting at just £45 per licence for business users (based on the purchase of 1000+ licences). Prices vary according to the size of the order, so for full pricing options, or to get a quote, please visit: www.des.co.uk, or contact the DES sales team on: 01823 352357 or via email at: sales@des.co.uk.

Since 1985, Data Encryption Systems has been the UK’s most successful manufacturer of software protection dongles, software copyright protection systems, and secure handset reprogramming accessories. Data Encryption Systems markets and supports products used by tens of thousands of businesses worldwide to protect applications, copyrighted materials, medical records, government files and other confidential and personal information. The company’s flagship product, DESlock+, has been awarded SC Magazine’s Best Buy for three years running. DESlock+ licences, the DESlock+ Administrator’s Tool and USB hardware tokens can be purchased at the company’s website: http://www.deslock.com.

<>
Read More
Posted in | No comments

Friday, 7 August 2009

Instant message dangers are growing

Posted on 09:58 by Unknown
One in 78 links sent via Instant Messenger is now to malicious content

by Michael Smith (Veshengro)

According to findings by the security company MessageLabs 1 in 78 links sent via instant messaging (IM) programs is to malicious content, and it does not matter, it would seen, which service is being used.

The company said this was an increase of 78 per cent over the past six months.

Paul Wood, intelligence senior analyst at MessageLabs said the increase in threats was down to hackers breaking through Captcha technology. And you all thought that was a safe way, didn't you.

This technology, which involves the user having to read a distorted image of a word and enter that text correctly, is often used when people register for an IM account.

“Bypassing Captcha technology enables the bad guys to create large numbers of fake but valid online accounts", said Mr Wood. "

These are used by spammers to send malicious links via IM that redirect victims to spam websites and sometimes compromised websites.”

The report also found that levels of spam, or junk email, were unchanged since May, remaining at 90.4 per cent. The company said this was largely due to the several hours during which Cutwail, one of the largest and most active botnets, was inoperative following the shutdown of California-based internet service provider, Pricewert LLC on 5 June, 2009.

It must also be said, though, regardless of the fact that so many spammers and malicious accounts are being set up on IMs users especially also must learn to be more vigilant. In addition to that, if using, say, Twitter, then there are is great piece of technology available free from Finian, another security firm, to install into your browser that will check all links sent.

On IM the best advice is that if you do not know the person then do not accept any links for him or her. As simple as that. Do not be open to anyone and everyone to add you as a contact. Make sure first that you know the person and, above all, have good anti-malware software installed on your PC and maintain good OpSec.

© 2009
<>
Read More
Posted in | No comments

Google promises end to viruses - Fortify says: don't be hasty

Posted on 09:56 by Unknown
(Eskenzi PR) - Google's engineering director has promised that his company's forthcoming Chrome operating system will see "the end of malware," but, says Fortify Software, the application vulnerability specialist, users shouldn't forget their software may also be flawed.

"You can have the most bug-free operating system in the world – which is what energy companies have in the shape of the SCADA-compliant embedded firmware that drives their critical systems - but if the software has bugs in it, you're dead in the water," said Richard Kirk, Fortify's director.

"The plans of Linus Upson, Google's engineering director, outlined in the latest New Scientist magazine are laudable and, if they turn out to be correct, will make computing a lot safer for everyone, but the plethora of software that is available - and being developed all the
time - makes the task of eradicating viruses impossible," he added.

According to Kirk, this isn't to decry Google's plans for a secure operating system, although he noted that the company's plans took a battering this week when two flaws were revealed in the Chrome browser application.

The irony of Upson's plans is that embedded firmware versions of Windows are already in active use on SCADA-compliant systems in critical government and utility grids the world over, he explained.

The downside of using an embedded operating system is that it cannot be easily updated, but that is a small price to pay for a more secure computing environment, the Fortify director went on to say.

"Google's promise of a flaw-free operating system with Chrome is a really great idea and we applaud that, but our business is based on helping software developers boost the security of their applications during the code audit stage," he said.

"And given that our clients anticipate code auditing to be an integral part of their development plans for some time to come, I think Google's promise to eradicate viruses is a bit on the optimistic side," he added.

For more Google's no-virus operating system plans: http://preview.tinyurl.com/nt8m3k

For more on Fortify Software: http://www.fortify.com

<>
Read More
Posted in | No comments

Monday, 3 August 2009

Criminals could capture data from wireless keyboards

Posted on 11:17 by Unknown
A piece of Open-source software could be hijacked by criminals to steal people's personal data, according to security firm

by Michael Smith (Veshengro)

Cyber-criminals could use so-called “sniffer” software to steal sensitive data from users of wireless keyboards, so says Symantec, the makers of Norton Security software.

The security firm said that an open-source project, dubbed Keykeriki, which has been developed by a group called Remote-Exploit.org and theoretically is intended to be used as an educational tool or to test the security of wireless keyboard transmissions, could be dangerous to users of wireless keyboards.

This is because the software and schematics can be downloaded from the Internet, there is nothing to stop criminals using it as a remote keystroke logger that can capture every keystroke without having to install malware onto a PC, said Symantec.

“The criminal implications of this are immediate and obvious. It would mean that someone would be able to remotely capture every keystroke made without having to install anything on to the system and capture personal, sensitive information such as passwords and bank details,” said Symantec.

The company “strongly recommends” using wired keyboards in the office and public places to avoid making critical data vulnerable.

I must say though that this appears, yet again, to be an attack by the proprietary software companies and those that love closed codes on Open Source software.

While it may be a case that cyber-criminals could use the software and even change the code as it is an open source application I am sure there are other keyloggers out there that are in use by such criminals that have been written by this or that member of their criminal fraternity.

To blame the fact that the software is Open Source is, in my opinion, once again, as said, an attack on Open Source.

On the other hand I can but agree with Symantec's recommendation to use wired keyboards. Not only are those safer in use as no signals being transmitted – via the ether – that could be “sniffed out” and also wire keyboards are (1) cheaper and (2) greener.

While wireless keyboards and rodents may be nice as there are no wires cluttering up the desk I personally prefer wired keyboards and mice and that for the previously mentioned reasons, including and especially the security aspect.

But before we all go off the deep end here I think we must also consider that the range of wireless keyboards is not really all that great and the “sniffer” would have to be rather close to the transmitter and transmissions of such a wireless device. Most wireless devices do not cover more than a few yards and unless the “sniffer”, as said, is very, very sensitive it should not be able to do much at all.

Obviously one must be careful and, as Symantec stated, it is therefore best to use wired keyboards, for security alone.

© 2009
<>
Read More
Posted in cyber crime | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Open Source Software in Business & Government
    by Michael Smith (Veshengro) Lots of Open Source in use in mainland Europe, including EU member states, very little in the UK and less still...
  • Infosecurity Europe 2011 Hall of Fame nominations now open
    London UK, February  2011 – The time is ripe to elevate the greatest movers and shakers in the world of information security as nominations ...
  • Tufin unveils new functionality & updated PCI DSS 2.0 compliance reporting
    TUFIN TECHNOLOGIES UNVEILS enhanced firewall operations management functionality and UPDATEd pci dss 2.0 compliance reporting New Perm...
  • Web 2.0 services are the next security hurdle says 360°IT – The IT Infrastructure Event
    Planning is are now well under way for the first 360°IT – The IT Infrastructure Event, due to take place at London's Earls Court this co...
  • Safer Internet Day - The role of Security within Social Networks
    Amichai Shulman – CTO and co-founder of Imperva Last week researchers unveiled a “ dating database ” consisting of 250,000 users. This was...
  • ISACA’s EuroCACS Examines Data Protection, Cloud Computing and Social Networking
    ISACA’s EuroCACS Examines Data Protection, Cloud Computing and Social Networking 20-23 March 2011, Manchester, UK Rolling Meadows, IL,...
  • Experts warn about risks of multi-tasking on new iPhone 4.0 OS
    Fortify Software warns companies to beware multi-tasking aspects of new iPhone 4.0 operating system Following a rash of news reports about...
  • Experts says trashed hard drive fiasco at Pfizer could have been avoided with Encryption
    Credant says trashed hard drive at Pfizer would not have happened if data had been encrypted Credant Technologies says that a security gaffe...
  • IT services provider, FORT, brings AVG to Irish market
    by Michael Smith (Veshengro) ISP customers to benefit from complete Internet security solution London, UK – AVG, the world’s most downloaded...
  • Lieberman Software and Q1 Labs Partner to stop insider threats
    Joins Q1 Labs Security Intelligence Partner Program London – February 1, 2011 Organisations seeking to eliminate the potential for anony...

Categories

  • ASUS
  • AVG Link Scanner
  • BeCrypt
  • book review
  • Brocade
  • Codenomicon
  • Columbian USB stick loss
  • computer recycling
  • Conficker worm
  • Credant Technologies
  • cyber crime
  • Cyber-Ark
  • Cyber-Ark®
  • Data Center
  • data encryption
  • DeviceLock
  • Digital Pathways
  • diskGenie
  • Eclypt
  • Eee PC
  • Eee PC Seashell 1008HA
  • F5 Networks
  • Facebook
  • Finjan
  • Finjan Inc.
  • Finjan MCRC
  • Firewall Management
  • Fortify
  • Fortify 360
  • Fortify Software
  • Fortify® Software
  • gadgets
  • Google
  • Google Chrome
  • green computing
  • green IT
  • IBM
  • Infosec
  • Infosec Europe 2009
  • Infosecurity Adviser
  • Infosecurity Europe
  • Infosecurity Europe 2009
  • Internet privacy
  • iStorage
  • iStorage diskGenie
  • iStorage Ltd.
  • Juniper Networks
  • Lakeland
  • Lapdesk
  • LLC
  • Logitech
  • malware
  • ManageEngine
  • McAfee International Ltd
  • MI6
  • MI6 data loss
  • Microsoft
  • MiFi™ 2352
  • Mio
  • Mobile Broadband
  • MS Office
  • National Cybersecurity Advisor
  • Navman
  • Navman Spirit
  • Netac
  • Novatel
  • Novatel Wireless Intelligent Mobile Hotspot 2352
  • OneClick IntelliPanel Desktop
  • online social media
  • open source
  • OpenOffice.org
  • Optenet
  • Origin Data Locker
  • Origin Storage
  • PNDs
  • product review
  • Red
  • SaaS
  • Sat Nav
  • saving energy
  • Security
  • Shavlik Technologies
  • SIS
  • spam
  • Stonewood Group
  • Storage Area Networks
  • Storage Expo
  • Storage Expo 2009
  • Sun Microsystems
  • Swine Flu
  • Syphan Technologies
  • Throwing Sheep in the Boardroom
  • Tufin Technologies
  • Twitter
  • U256
  • Unisys Security Index
  • USB drives
  • Vektor
  • VisionRacer
  • VisionRacer VR3
  • VMware
  • Weast
  • Web Apps Security
  • WebFilter PC Solution
  • WebSpy
  • XSS-driven attacks

Blog Archive

  • ▼  2012 (1)
    • ▼  January (1)
      • Cool Stand – Product Review
  • ►  2011 (67)
    • ►  December (1)
    • ►  April (1)
    • ►  March (14)
    • ►  February (30)
    • ►  January (21)
  • ►  2010 (192)
    • ►  December (20)
    • ►  November (22)
    • ►  October (19)
    • ►  September (5)
    • ►  August (8)
    • ►  July (5)
    • ►  June (22)
    • ►  May (13)
    • ►  April (11)
    • ►  March (13)
    • ►  February (27)
    • ►  January (27)
  • ►  2009 (240)
    • ►  December (25)
    • ►  November (9)
    • ►  October (21)
    • ►  September (19)
    • ►  August (30)
    • ►  July (35)
    • ►  June (30)
    • ►  May (21)
    • ►  April (42)
    • ►  March (8)
Powered by Blogger.

About Me

Unknown
View my complete profile