Monthly Archives: May 2008

Phishers Embed Forms as Hooks

Alex Eckelberry at “Sunbelt”:http://www.sunbelt-software.com/ “noted”:http://sunbeltblog.blogspot.com/2008/05/evolution-of-phishing-embedded-forms.html a nifty phishing development: embedded forms. Phishers are spoofing forms from reputable sources- think PayPal, large banks, etc. Considering the “advances”:http://blogs.stopbadware.org/articles/2008/04/18/spam-targets-a-wide-field-of-users in phishing: correllating name, position, and email addresses for high-level corporate interests; these emails … Continue reading

Tagged , | Comments Off

Comcast Falls Prey To Tricksters

Yesterday evening, I was wondering why an e-mail of mine to a friend using Comcast’s e-mail bounced. Then I saw a message on a listserv I use asking if anyone else had experienced difficulty sending e-mail to Comcast addresses. Thirty … Continue reading

Tagged , , | Comments Off

A Flash in the Pan

It “appears”:http://trailofbits.com/2008/05/28/flash-zero-day-attacks-wow/ that someone took advantage of an unpatched hole in Adobe Flash player, along with a SQL injection attack, to initiate a drive-by download to visitors of some 20,000 websites. The target? “It turns out that the whole attack … Continue reading

Tagged , , | Comments Off

ING’s E-Banking Tool

Brian Krebs at the Washington Post “recently wrote”:http://blog.washingtonpost.com/securityfix/2008/05/ing_tool_provides_safe_ebankin_1.html about a new software tool developed by Trusteer and provided by ING to help its customers bank online more securely, even when using PCs that may be compromised by spyware. At an … Continue reading

Tagged , , , | Comments Off

Bad Guys Get Caught

Allysa Myers at McAfee “blogged about”:http://www.avertlabs.com/research/blog/index.php/2008/05/21/more-crimeware-arrests/ this “FBI press release”:http://newhaven.fbi.gov/dojpressrel/2008/nh051908.htm announcing criminal charges against 38 alleged baddies from the U.S. and overseas. bq. According to the indictment, the Romania-based members of the enterprise obtained thousands of credit and debit card … Continue reading

Tagged , , , | Comments Off

Badware Alert: Uniscope Toolbars (MySpace Guardian, Amber Alert Toolbar, BizRate Bar)

StopBadware.org released a “badware alert”:http://www.stopbadware.org/reports/reportdisplay?reportname=uniscopetoolbar05222008 about the Uniscope Toolbars today. These toolbars are produced and distributed by RPM Performance Media, and include variants such as “MySpace Guardian”, “Amber Alert Toolbar”, and “BizRate Bar” : bq. We find that the Uniscope … Continue reading

Tagged , | Comments Off

Google’s new resource for owners of compromised sites

Google has rolled out a new resource for owners of compromised websites that it flags as potentially dangerous in its search results. “Google Diagnostics”:http://googleonlinesecurity.blogspot.com/2008/05/safe-browsing-diagnostic-to-rescue.html shows information about malware and malware-distributing behaviors that Google has observed on the site within the … Continue reading

Tagged , , , , | Comments Off

Safari Security Questioned; SBW Encourages Action

You may recall that StopBadware.org recently “played a role”:http://blogs.stopbadware.org/articles/2008/04/17/apple-responds-to-community-concerns in successfully encouraging Apple to improve its disclosure in pushing the Safari web browser to users through its Apple Software Update application. Now, Nitesh Dhanjani, a security researcher, “writes”:http://www.oreillynet.com/onlamp/blog/2008/05/safari_carpet_bomb.html about his … Continue reading

Tagged , , , , , | Comments Off

Badware Alert: Spyware Striker Pro

[update: On April 24, 2009, we archived this alert, as a newer version of the software did not appear to exhibit the badware behaviors we reported.] StopBadware.org released a badware alert about Spyware Striker Pro today: We find that Spyware … Continue reading

Tagged , | Comments Off

Drive-By-Download Follows on Heels of Fake Media Download

Over the last several weeks, users downloaded more than they were bargaining for from several P2P networks. “TechNewsWorld”:http://www.technewsworld.com/story/Trojan-Infected-MP3s-Have-PC-Users-Singing-the-Blues-62936.html?welcome=1210700213 reported on “McAfee’s Avert Labs”:http://www.mcAfee.com that more than 500,000 computers have been infected. Users download a faux-mp3 file from a legitimate music … Continue reading

Tagged , , , , , | Comments Off