Subscribe:

Wednesday, September 14, 2011

She Wore Only Fishnet Stockings. How Much Could She Possibly Hide?

I spent a few hours surfing porn. I didn’t get hot but I sure got bothered.
In a recent survey, 72% of participants admitted they searched for and accessed adult-content sites. On the other hand, an Internet research on the safety of URLs leading to pornographic sites showed that 29 percent of the 1,000 tested links were infected. Simple math says that adult content sites are among the most likely to infect your computer with viruses or other malware.
Just another scary statistic?
I decided to spend a while surfing porn to test it. I started searching for a video that included a “girl” and an “action.” A girl named Suzana was first to answer my query. Wearing nothing but fishnet stockings, she couldn’t possibly have much to hide. Right?
Wrong. Just when Suzana was about to answer my query, in stepped the antivirus software.


 Darling Suzana was hiding a nice piece of malware.
Identified by Bitdefender as a variant of Kazy Trojan, this piece of malicious code injects itself in to the explorer.exe process and opens a backdoor that allows unauthorized access to and control over the affected system.
It also attempts to read the keys and serial numbers of various pieces of software , while also logging the passwords to the victim’s ICQ, Messenger, POP3 mail accounts, and protected storage.
Beginner’s luck? Challenge accepted! Let’s see if Suzana’s really the one and only girl who can make my dreams come true.
So I cast my fishing net farther, with the classic “porn” search word.
Bad luck! (or is it good???) I get deeper into x-rated troubles as that 29 percent of red-light infected links seems comes to ugly reality. Another try and I’m about to bring a whole load of Trojans aboard. It’s that easy!


I rest my case.
In order to stay safe, Bitdefender recommends that you never open files without checking them as well as that you install and update a complete internet security solution.
Stay happy, but safe!

Monday, August 29, 2011

3 Reasons Why Computer Security Fails

Discover the main culprits behind security incidents

Lack of Awareness

In their day-to-day routine, regular users aren't actually aware of computer security implications until something wrong actually happens. To be more specific, you can't realize the magnitude or the impact of cybercrime activities before having your e-mail account hacked or your on-line banking session intercepted and accounts emptied. It's pretty much the same as with car accidents – you hear people talking about them, you see them on TV and read about them in newspapers, but until you are effectively involved in one (God forbid!), you don't know what they’re all about.
Attacks aiming to exploit security breaches are more likely to target public or private organizations, rather than individual users (the stakes are higher with the former). As usually businesses operate with  networks rather than with standalone workstations, the possibility of their being entirely compromised increases in proportion to several factors, some of the most important being: the number of users, users’ degree of computer security literacy, the nature of the defense policies in effect, the architecture of the security strategy at work and, last but not least, the type of organization and its activities. Just open the technology section of any newspaper or search the Internet and you will get a pretty clear picture about…

Misunderstanding Computer Security

Once awareness of today's security risks is raised, the appropriate strategy that matches the specific security needs of the business should be applied next. Technically speaking, there are three major rules of thumb which could offer a good starting point for any company (and individual, for that matter) in tailoring its data security choices. Disregarding any of them means creating the opportunity for a potential breach.
First off, any protection is better than no protection at all. When dealing with e-threats, having no defensive solution installed on a system is like leaving all doors and windows wide open while you are on vacation.
Second, protection should be chosen based on security necessities – that is although they struggle with the same e-threats, home and corporate users may have slightly different expectations in this respect.
Third, there is no such thing as “enough” security. This implies that security is a continuous process, rather than the simple installation of an antivirus on a computer. It’s a permanent application of on-line safety principles as well as the capacity to anticipate and respond to newly emerging e-threats. At least from this point of view, security is a mid- to long term investment and it does not end with the deployment of a simple defensive solution.

Neglecting the Human Factor

Probably the most important reasons of all is the human factor. The reduced level of awareness, the lack of IT&C security education and the absence of security policies reinforcement, especially in the public sector and large corporations are responsible for most of the damages, both in terms of compromising systems and networks, but also when it comes to disclosing sensitive data, information theft and even malware dissemination.


Thursday, August 25, 2011

Illegal Keygen for Reputed Antivirus Comes Bundled with Malware

Care to install a “virused” antivirus?
It is common practice for crooks to use pirated software as a means of disseminating malware. It’s an approach that has been used for years and it still works as a charm. Any new software product launch is awaited and included into this malware distribution cycle. A much anticipated movie or software product becomes the perfect lure for users who are inclined towards piracy rather than legal product or service acquisition.
This is exactly the scenario we spotted last week, when crooks started using the latest Internet Security avtivirus product from Trustport as bait for malware dissemination. They tampered with an illegal keygen (identified by our labs as Application.Keygen.BW) in order to bind it with a piece of backdoor malware  that is also deployed on the users’ systems along with an illegal key for the AV product.
This keygen spreads via P2P sharing services, USB media, instant messaging services or e-mail clients and users may end up downloading serious trouble on their systems as this particular illicit tool does a lot more than it is supposed to do.
The piece of malware inside the keygen is identified by Bitdefender as Trojan.Agent.ASDM and starts its wrongdoing by injecting itself into explorer.exe and adding a list of exceptions to the locally installed firewall. Afterwards, it deploys a keylogger and a backdoor component on the compromised computer. Depending on how you’re using your computer, this piece of malware does the following:
-          steals passwords cached in various web browsers such as Mozilla Firefox or Internet Explorer;
-          spies on the users’ habits and gathering critical information about the compromised computer and, worst of all, showing great interest for all that has to do with e-banking accounts and money transactions;
-          downloading further malware either via internet or from ftp accounts; the sample we analyzed is capable of downloading and installing  Zeus BOT, SpyNet RAT, Bandook RAT, Scwarze Sonne RAT, Apocalypse RAT, Bff BOT, Solitude RAT, PoisonIvy,  Cybergate, which hints to a possible cooperation between Trojan.Agent.ASDMand other cyber-criminal gangs.;
-          captures video and audio  streams from the users’ computer webcams;
-          logs conversations that take place on social networks or instant messenger;
It is safe to say that there’s an extremely high chance that pirated software leads to malware and it’s definitely a risk not worth taking.
This article is based on the technical information provided courtesy of Doina Cosovan, BitDefender VirusAnalyst.
All product and company names mentioned herein are for identification purposes only and are the property of, and may be trademarks of, their respective owners.

Wednesday, August 24, 2011

Microsoft asks for ban of Motorola's smartphones

Microsoft is presenting a case before the International Trade Commission (ITC) in which they claim Motorola Mobility is using technology in their Android-based smartphones that was derived from Microsoft products. The world’s largest software maker is asking the ITC to halt imports of certain Motorola phones.
Bloomberg reports that the trial began on Monday in Washington and that Microsoft claims Motorola infringed on seven patents. Microsoft singled out the Droid 2, Droid X, Cliq XT, Devour, Backflip and Charm handsets among those guilty of infringement. The ITC does have the ability to halt imports if they feel a product violates US patent rights.
“We have a responsibility to our employees, customers, partners and shareholders to safeguard our intellectual property,” David Howard, Microsoft’s corporate vice president and deputy general counsel for litigation, said in an e-mail. “Motorola is infringing our patents and we are confident that the ITC will rule in our favor.”
Motorola is defending themselves against the patent suit and a company spokeswoman said they have also brought legal actions of their own against Microsoft in the US and Europe for the same reasons.
This is the first of what is likely to be many more lawsuits brought upon Motorola Mobility since Google agreed to buy the company for $12.5 billion last week. The main reason Google made the purchase was to acquire a wealth of patents from Motorola Mobility to protect themselves as well as the Android platform. Interestingly enough, Google isn’t named in the complaint.
The judge in the case is scheduled to make a decision on November 4 and the ITC has until March 5, 2012 to complete their investigation.

Firefox 7 beta now available, final build due next month

A beta version of Mozilla’s Firefox 7 is now available for Windows, Mac and Linux. Despite releasing version 6 of the popular browser earlier this week, it’s the next iteration that many expect to solve persistent memory leak issues that have plagued the software for years.
Firefox 7 will introduce MemShrink, an initiative that began in June to eradicate the browser's memory inconsistencies. Mozilla developer Nicholas Nethercote claims that Firefox 7 uses less memory than the past three versions, between 20 and 50 percent less in some instances.
In addition to MemShrink, the new build also features better Javascript garbage collection. It's said to work more frequently now and should free up more memory when multiple tabs are open. The upcoming browser also implements Azure Direct2D for Canvas which increases canvas-based animations in HTML5.
There are also tools built into Firefox 7 that will help developers measure load times. Synchronization of bookmarks and passwords is said to be faster, too.
Version 7 is part of Mozilla’s recent rapid deployment of browsers. The developer released Firefox 5 in June and earlier this week it quietly launched Firefox 6 a day ahead of the planned release date.
Mozilla’s browser has been criticized for needing large amounts of RAM and then not freeing that memory once windows or tabs have been closed. Nethercote acknowledges these shortcomings, indicating that some versions were more efficient than others. He praised Firefox versions 3, 3.5 and 3.6 but said things deteriorated with version 4 partly because of all its new features, aggressive JavaScript garbage collection and image decoding.
The final version of Firefox 7 should be available by September 27.

Sunday, August 21, 2011

Gaming community highly exposed to bitcoin-mining Trojan

While distributed denial of service and spam sending are still some of the most effective ways of monetizing a large-scale Botnet, cyber-criminal gangs have also turned their attention towards the increasingly popular peer-to-peer currency system known as Bitcoin.
The first week of August brought under our scope a miner Trojan identified by Bitdefender as Trojan.Antiminer.A, that highjacks compromised machines with the purpose of creating a botnet of infected PCs and uses their resources to produce virtual money. The Trojan silently deploys a legit Bitcoin miner that uses the GPU of the machine to compute virtual currency.
Inspired by the fact that the Bitcoin (BTC) parity is one to 15 US dollars, the crooks have laid eyes on computer systems with powerful GPUs to make easy money. The gaming community is therefore highly exposed since the modern games on the market require powerful GPUs to support the latest developments in the visual effects industry.
“If you happen to download cracked games via Torrent or other P2P sharing services, chances are that you may become a victim of this lucrative Trojan bundled with a genuine GPU miner. We advise you to start checking your system for signs of infection, especially if you are constantly losing frames-per-second,” advises Catalin Cosoi, head of BitDefender Threats Lab.  “The Trojan’s mission is dramatically facilitated by the fact that hardcore gamers do not run antivirus solutions as these are traditionally perceived as bottlenecks on high-performance computers,” he continued.
It may be true that a single miner – be it powered by the most advanced GPU on the market – calculates a limited number of Bitcoins per day. That is why the masterminds behind this operation target a large number of compromised computers that act like an extensive capable of processing large amount of hashes that are transformed into Bitcoins. It is obvious that more computers produce more virtual money while, at the same time, increasing statistically the chances of getting the randomly-awarded bounty of 50 coins for participation in the pool’s effort.
If the Bitcoin system needs any clarification at all, then you should know that it is a cryptographic virtual currency meant to help people make transactions over the Internet while keeping the utmost privacy of their identity. These trades can be made under the mask of anonymity, where there’s no real identity associated to the online persona. Plus there is no bank or state authority to govern over the production or use of this digital cash either.
This attack is just one take at the big pot of money that revolves around Bitcoin. There have been a series of incidents in which cyber-criminals tried to tamper with the system to their own advantage and we expect to see increased malicious activity related to Bitcoin mining on the computing resources of unwary users.
All product and company names mentioned herein are for identification purposes only and are the property of, and may be trademarks of, their respective owners.
Download now the removal tool for Trojan.Antiminer.A!


Worried about your money while on-line? You should be!

10 safety tips for on-line banking and shopping Several years ago, I've worked with a very gifted teacher who wrote a wonderful IT&C manual that I've edited. As we were going through the final revision, she came up with the idea of adding a motto for each chapter. Although I was a bit reluctant at that time, eventually I agreed. And it turned out just fine, as the high school kids that actually used this book liked it too. A week ago, as I was reading an article about e-banking applications that aren't actually working on all types of browsers, I've suddenly remembered two of the most simple and apparently contradicting statements that my author used in her manual. One of them - “If you aren't on-line, you don't exist” - opened the Internet chapter. The other - “The only way to stay safe is off-line” - introduced the Security section. If we play a bit with their meaning and we are (not-so-fallaciously) speculating it, we get the following assertion: “As long as you are on-line, you are in danger”, which makes more sense than the sophism “You're safe if you don't exist”.
However, banks and e-commerce Web sites tell us a different story. That we are effectively safe and secure while we access on-line our deposits and accounts and that we shouldn't worry at all. If you don't trust me, listen to this guy. Fast forward to 15:10 and you will see that even a hacker says so. He's actually kidding and even banks and on-line merchants are partially kidding, no matter how reputable they are, by saying that everything is fine when it comes to e-banking and e-commerce. And mark my words, you shouldn't take that for granted. Why is that? For the same reason that you shouldn't cross a street without looking left, then right (or vice-versa, if you leave in UK and other places where traffic works in reverse), and even if the light is green (or says 'WALK').
If so, what should we do? Not using e-banking or e-commerce at all? It doesn't make any sense, especially for a 21st-century-extremelly-busy-and-technology-dependent-person right? Right. Well, I'm not saying that we shouldn't using them at all. That would be just as locking yourself inside the house and hiding under the bed because there are cars running outside on the same street you are supposed to cross. Just be careful. And here are some tips:
1. Use a dedicated machine. Get a cheap netbook, laptop or desktop configuration and use it solely for e-banking and e-commerce. Password-protect it, so that you limit the access (you wouldn't want kids to mess around with it), and always connect it to the Internet through a wired connection instead of WiFi to avoid traffic interception. Refrain from shopping or banking on-line from public computers or via wireless unsecured network connections, such as those in coffee shops or airports. Also, it would be a good idea not to buy or make any transaction while on bus, subway or any crowded places – one can never tell who's looking over your shoulder.
2. Ideally, your e-commerce/e-banking-dedicated machine should not run Windows – use a Linux distribution or MacOS. Don't get me wrong, I'm no one's advocate here, but as Windows is the most widely-spread operating system in the world, chances to get infected or compromised are higher. If you don't believe me, then read this story. However, if it is more convenient for you to run Windows or MacOS, then installing a security suite with at least a Firewall, Antispyware and Antimalware is a must. Check this out: BitDefender Facebook fans get 6 extra months of protection for free with the best defensive solution currently on the market, BitDefender Internet Security 2011! Pretty cool, isn't it? By the way, no matter what OS is on that machine, update it frequently. Do the same for your browser and for your security suite. It's crucial in keeping malware and attackers away from your system!
3. Beware of phishing or vishing attempts – banks and retailers will never ask you to change login credentials or other important account details on the phone or via e-mail and sms. If you have any suspicion, make a visit to the bank or try to call them back at the number provided in the contract or agreement you signed (for phone calls it will be a good idea to write down the name of the person who called you and ask for him or she, to see if that person actually exists within that organization).
4. As your Internet browser is your gateway to any on-line financial transaction, clean its cache before and after going on-line, regardless of your operating system. Empty cookies and all plug-in data, as well as all automatically filled data it may save. Disable Autocomplete and Save Passwords options. Moreover, you should refrain from storing any transaction details on your computer. Additionally, you may want to add a free cross-browser controller, such as BitDefender TrafficLight extension, to make your Web surfing even safer.
5. Use on-screen keyboard. Search for it in accessibility tools of your OS and click with your mouse the screen instead of typing on your keyboard. It can spare you the trouble of keystrokes being intercepted by keyloggers.
6. Always manually introduce the address of your bank or on-line retailer in the browser's address bar to avoid redirection towards phishing pages mimicking the genuine page. One single misspelled letter and you could end up handling to cybercriminals all your login credentials on a silver plate.
7. Before proceeding, make sure that the Web page where you enter sensitive data (user name, password, transaction confirmation number, credit card number, CVC and other data) is encrypted. Normally, you should see a locked padlock somewhere in your browser and a page prefix that is https:// in the address bar.
8. For e-banking, you should check with your bank for at least a two-factor authentication procedure – usually based on a security-token. As for online shopping, before making any transactions, enroll your credit card in a supplementary verification program, usually provided free of charge, such as 3-D Secure.
9. Add an insurance to your on-line transactions. It could cost you a bit extra, but it's worthing. Better safe than sorry/broke!
10. Always do some reconnaissance before subscribing or buying online. Find out what others have to say about the e-banking service you want to enroll or a Web site you want to shop from. Ask relatives, friends, your lawyer and bank adviser or simply search on the Internet.
 
Safe e-banking and e-commerce everybody!
 
All product and company names mentioned herein are for identification purposes only and are the property of, and may be trademarks of, their respective owners.

Source: malwarecity.com