Make it your homepage

Add to favorites

Site map

Ukrainian Information Security Center - all about IT security



Navigation

Microsoft Certified Partner

Read RSS


IT Security
Subscribe to news Subscribe to articles




RSS to email








Advertising


News for 12 February 2009 Year

  • 22:12 Microsoft announces industry alliance, $250k reward to combat Conficker
  • Microsoft has announced an alliance of various industry partners whose goal is to fight the Conficker worm. The announcement is short on actionable methods for stopping the worm, but it does include one gem: a $250,000 (US) bounty for information leading to the capture of those responsible for the worm. Microsoft is taking the Conficker [...]

    >>>

  • 21:48 Heartland data breach hit 160 banks (and rising)
  • How deep does the rabbit hole go?

    More than 160 banks have been affected by the information security breach at US payment processor Heartland Security.

    >>>

  • 21:34 IBM, HP, and EMC call for encryption key juggler standard
  • Push unified protocol though open standards org

    Any key management platform will be able to communicate across all of a company's encryption systems - if IBM, Hewlett-Packard, Thales, and EMC have their way.

    >>>

  • 20:36 Should Microsoft decouple IE from Patch Tuesday?
  • A security researcher wants Microsoft to follow the lead of other browser makers and start fixing Internet Explorer security problems outside of the Patch Tuesday cycle to help contain the Windows malware epidemic. [ Microsoft: Consistent exploit code likely for IE vulnerabilities ] According to Wolfgang Kandek, chief technology officer at vulnerability management firm Qualys, IE’s dominant [...]

    >>>

  • 20:15 MS puts up $250K bounty for Conficker author
  • Zombie masterminds wanted undead or alive

    Microsoft is offering a $250,000 reward for information that leads to the arrest and conviction of the virus writers behind the infamous Conficker (Downadup) worm.

    >>>

  • 19:45 Anti-piracy service for iPhone developers
  • Kali Anti-Piracy is a service for the iPhone developers that protects their applications from being pirated. Evidently, the piracy rate currently is quite high due to the fact that there are nume... >>>

  • 19:07 IEEE approves 1902.1 standard for wireless visibility networks
  • The IEEE has approved a new wireless standard, IEEE 1902.1, "Standard for Long Wavelength Wireless Network Protocol," which improves upon the visibility network protocol known as RuBee. RuBee is a bid... >>>

  • 18:55 Video: Electronic Driver's Licence Cloning for $250
  • This is the video of Chris Paget's presentation for Shmoocon V, which was held February 6th - 8th 2009 in Washington DC. This talk outlines a number of security weaknesses in the RFID system used i... >>>

  • 18:55 Video: Electronic Driver's Licence Cloning for $250
  • This is the video of Chris Paget's presentation for Shmoocon V, which was held February 6th - 8th 2009 in Washington DC. This talk outlines a number of security weaknesses in the RFID system used i... >>>

  • 18:11 Scareware scammers Rickroll Digg
  • Bot comment blitz intensifies

    Digg.com has become the latest Web 2.0 service to be abused by hackers in order to punt malware.

    >>>

  • 16:12 Win 7 and smartphones targeted in Pwn2own challenge
  • Hacker security shootout shindig

    An annual hacking challenge has put the security of browsers and smartphones in the firing line.

    >>>

  • 08:30 Article: Q&A: Government Security for Mobile Devices
  • Joseph Hagin is the Former Deputy White House Chief of Staff. In that role he had a high-level of concern about hacking and other security concerns related to Blackberrys and other devices. He put in... >>>

  • 08:30 Article: Q&A: Government Security and Mobile Devices
  • Joseph Hagin is the Former Deputy White House Chief of Staff. In that role he had a high-level of concern about hacking and other security concerns related to Blackberrys and other devices. He put in... >>>

  • 08:30 Article: Q&A: Government Security and Mobile Devices
  • Joseph Hagin is the Former Deputy White House Chief of Staff. In that role he had a high-level of concern about hacking and other security concerns related to Blackberrys and other devices. He put in... >>>

  • 07:32 Congressman twitters secret trip to Iraq
  • Sophos is warning computer users of the far reaching consequences associated with the irresponsible use of social networking sites like Twitter, following news that a high ranking member of the US Hou... >>>

  • 07:30 Survey: 92% have security software but how many are aware of the threats?
  • F-Secure announced results from its annual Online Wellbeing Survey. This third-party survey of Internet users aged 20-40 in the United States, Canada, UK, France, Germany and for the first time It... >>>

  • 07:06 First Windows 7 universal IPSec VPN client
  • NCP engineering has developed the first universal IPSec VPN client for Windows 7. Now available, the beta version of the NCP Secure Entry Client will provide users and IT administrators with a flexibl... >>>

  • 07:03 New book: "Network Know-How"
  • Network Know-How is every computer user's guide to designing, mapping, and maintaining a trouble-free network. Author and veteran networking consultant John Ross takes readers through the nuts and bol... >>>

  • 07:03 New book: "Network Know-How"
  • Network Know-How is every computer user's guide to designing, mapping, and maintaining a trouble-free network. Author and veteran networking consultant John Ross takes readers through the nuts and bol... >>>

  • 06:54 Off the wire: Book review - Hacking VoIP
  • VoIP has given us an affordable alternative to telecommunications providers that were charging us a small fortune for telephone calls, especially those made to international destinations. The average ... >>>

  • 06:51 Off the wire: Research shows identity fraud affecting nearly ten million Americans
  • Spammers are gearing up for Valentines Day with an influx of unsolicited advertising, but are also getting in early with a wave of sinister e-mail messages designed to infect hopeful Valentines reci... >>>

  • 03:43 New Windows virus attacks PHP, HTML, and ASP scripts
  • Virut gets around

    Researchers have identified a new strain of malware that can spread rapidly from machine to machine using a variety of infection techniques, including the poisoning of webservers, which then go on to contaminate visitors.

    >>>

  • 03:38 Malware Center: Study on the celebrity names most frequently used by malicious code
  • With the Oscars just around the corner, PandaLabs, the malware analysis and detection laboratory, has drawn up a ranking of the celebrity names most frequently used in 2008 by cyber-crooks in maliciou... >>>

  • 01:09 Review: Hacking VoIP: Protocols, Attacks, and Countermeasures
  • Author: Himanshu Dwivedi Pages: 220 Publisher: No Starch Press ISBN: 1593271638 Introduction Voice over Internet Protocol (VoIP) has given us an affordable alternative to telecommunicatio... >>>

  • 00:49 Valentines Day attracts malicious spam
  • Spammers are gearing up for Valentines Day with an influx of unsolicited advertising, but are also getting in early with a wave of sinister e-mail messages designed to infect hopeful Valentines reci... >>>

  • 00:40 Six safety tips to protect yourself from identity fraud
  • The 2009 Identity Fraud Survey Report by Javelin Strategy & Research offers safety tips for consumers that want to protect themselves from identity fraud. 1. Be Vigilant - Monitor your accounts reg... >>>

  • 00:33 Fugitive VOIP hacker cuffed in Mexico
  • More than 10 million minutes hijacked

    A fugitive hacker accused of illegally rerouting millions of dollars worth of VOIP calls through telecommuncations companies' networks has been apprehended in Mexico.

    >>>

  • 00:31 Research shows identity fraud affecting nearly ten million Americans
  • The 2009 Identity Fraud Survey Report released today by Javelin Strategy & Research confirms that the number of identity fraud victims has increased 22 percent to 9.9 million adults in the United ... >>>

  • 00:26 Fake Codec Serving Domains from Digg.com's Comment Spam Attack
  • The following assessment details all the redirectors, fake codec serving domains, as well as related fake security software domains used in the Digg.com' comment spam attack.



    The complete list of the domain redirectors used in the comment spam attack:
    worldnews-video .com - 459,000 bogus comments
    youtube-top-video .com - 98,000 bogus comments
    new-videos .info - 92,500 bogus comments
    film-man .com - 50,700 bogus comments
    last-sex-news .com - 26, 000 bogus comments
    video-news .cn - 25, 500 bogus comments
    last-porno-news .com - 21,500 bogus comments
    fresh-video-news .com - 10,900 bogus comments
    broken-tv .com - 10,000 bogus comments
    video-trailers .net - 8,370 bogus comments
    exclusive-videos .net - 7860 bogus comments
    funkytube .net - 6,170 bogus comments
    shocking-stars .net - 2,600 bogus comments
    cinemacafe .tv - 1560 bogus comments
    watch-video .cn - 3000 bogus comments
    vidstream .cn - 397 bogus comments
    divgg .com - 174 bogus comments
    golden-portal .us - 3040 bogus comments
    tubedirects .net - 290 bogus comments
    funkytube .net - 6,480 bogus comments
    watchepisodes .cn - 331 bogus comments

    video-sensation .com - 1,500 bogus comments
    bestlive-tv .cn - 216 bogus comments
    svtube .cn - 222 bogus comments
    onlyhotvideos .com - 413 bogus comments
    celebnudestars .net - 326 bogus comments
    usatvshows .us - 41 bogus comments
    vidstream .cn - 398 bogus comments
    divgg .com - 171 bogus comments
    tubedirects .net - 285 bogus comments
    yuotnbe .com - 370 bogus comments
    omeia .info - 769 bogus comments
    video.stumbulepon .com - 669 bogus comments
    shocking-stars .net - 2,650 bogus comments
    sowonder .net - 3000 bogus comments
    sex-tapes-celebs .com - 2,210 bogus comments
    video-sensation .com - 1,690 bogus comments

    Currently active download locations for the fake codecs, and the rogue security software:
    vivaextra .com
    tube-xxx-tv2009 .com
    onlinestreamsofware .com
    demoextra .com
    best-tube-2008 .net
    tubeportalsoftware2008 .com
    tubesoftwareviewer2008 .com
    exefilesdownload2009 .com
    tubesoftwareviewer2009 .com
    uporntube-07 .com
    tubeporn08 .com
    uporn-tube .com
    uporntube2009 .com
    porn-tube09 .com
    tubeporn09 .com
    xxxporn-tube .com
    porntubenew .com
    ultra-extra .com
    xp-police .com
    xp-police-av .com
    xp-police-2009 .com
    antiviralscanner14 .com

    Detection rates for the codecs/rogue security software:
    viewtubesoftware.40020.exe
    Result: 8/39 (20.51%)
    File size: 71680 bytes
    MD5...: ef26250b946a63112659c94eed016e0d
    SHA1..: 902fd30cd4a7465c9f5271971604d273ed74a60c

    viewtubesoftware.400201.exe
    Result: 7/39 (17.95%)
    File size: 62464 bytes
    MD5...: 1d4c3a6d2cc8c645652f7090636e5a4b
    SHA1..: ccc1994a521d9e8a053a345b9d9cc28a63415845

    Install.exe
    Result: 5/39 (12.82%)
    File size: 77830 bytes
    MD5...: 64557f21c50b6c063cc96ba661bcd27c
    SHA1..: 5a765a92de07af756c96c83139be8ddace117ef1

    install1.exe
    Result: 4/39 (10.26%)
    File size: 73222 bytes
    MD5...: 890bf32b34b7abab7aa7ea049215c429
    SHA1..: 8c311a8b6096914f758bcaf82aca465bcc885110

    The first comments including links to these domains have been posted at Digg.com on January, 2008 - over an year ago.
    >>>

  • 00:25 Secure wireless router Z100G brings enterprise level protection to home wireless networks
  • Check Point released version 8.0 of the Check Point ZoneAlarm Secure Wireless Router Z100G. The new version includes new security features and enhancements, providing advanced enterprise level protect... >>>

  • 00:20 Compliance through unified policy auditing from McAfee
  • McAfee announced its new Total Protection for Compliance solution which combines the power of the McAfee Vulnerability Manager appliance and the McAfee Policy Auditor software with McAfee ePolicy Orch... >>>

  • 00:02 Off the wire: Name and Shame, or socially responsible use of your log data
  • Your logs contain an ever-growing mass of data on spammers. How about making an effort to make that data useful to others?... >>>

  • 00:00 Privacy on Facebook
  • Excellent advice.

    >>>

  • 00:00 Cheating at Disneyworld
  • Interesting discussion of different ways to cheat and skip the lines at Disney theme parks. Most of the tricks involve their FastPass system for virtual queuing:

    Moving toward the truly disingenuous, we've got the "FastPass Switcheroo." To do this, simply get your FastPass like normal for Splash Mountain. You notice that the return time is two hours away, in the afternoon. Wait two hours, then return here and get another set of FP tickets, this time for later in the evening. But at this moment, your first set of FP tickets are active. Use them to get by the FP guard at the front, but when prompted to turn in your tickets at the front of the FP line, hand over the ones for this evening instead. 99.9% of the time, they do not look at these tickets whatsoever in this point in the line; they just add them to the pile in their hand and impatiently gesture you forward. All the examining of the tickets takes place at the start of the line, not the end. Voila, you've cheated the system. After this ride, you can get off and immediately ride again, since you've held on to the afternoon FPs and can use them in the normal fashion now.
    >>>




The latest news