Monday, April 20, 2009
First Mac botnet found
The Mac OS has been overdue for malware attention by hackers and "safe" only due to much lower market share than IBM-clone PCs. Mac users can expect to see more such attacks.
Friday, April 03, 2009
Beware Antivirus 2009
A type of software that tricks you into installing it, then demands payment "or else" is called ransomware. And it's spreading.
One nasty piece of ransomeware seems to be a legitimate program called Antivirus2009. But after you install the software, it encrypts several document types. Then when you try to open one of the encrypted files, it pops up an alert and offers to sell you FileFix Pro 2009, which it says can decrypt the file.
So you get duped into downloading the fix. But it decrypts only one document. After that, it demands that you pay $50 to buy the software to decrypt the rest of your files (that the Antivirus 2009 encrypted).
Beware of "something for nothing". Be paranoid. Check out reviews of software at trusted sites before you download and install any.
Wednesday, February 04, 2009
Malware worms its way into social networking
So with increasingly sophisticated social engineering, criminals are successfully attacking social networking services. Angry Facebook members created a special facebook page for victims of the Koobface worm.
Malicious software "scrapes" Facebook for all the user data it can find. People who give out real names, addresses, email addresses, and other information may find it cropping up in the hands of criminals. We teach kids to be wary of strangers, but then we turn around are and much too trusting in our online behavior ourselves. Parents, schools, and churches all need to start educating kids and even other adults about being wary of online personas and of being careful not to release personal information. Criminals now "mine" data from multiple sites to "fill in the picture" about victims identities and personal information.
Government agencies normally let their employees do personal surfing, yet they are starting to block access from the government offices to social networking sites. Why? It just too unsafe, at least for now.
Part of the challenge is that in order for social networking sites to be "fun", they have to encourage their members to share information. The default for most social networking sites is to be "open" rather than to have tight security. And most people are much more gullible online than in the "real world". So social networking sites like FaceBook and MySpace may continue to be a rich feeding ground for criminals.
If you insist on risking use of a social networking site, it might be a good idea to subscribe to a service that tracks your credit card actions as well as actions taken that relate to your credit rating. For example, you'd get an alert if someone was applying for a loan or credit card and using your credit record. And make sure to keep your Antivirus, AntiSpyware, and Firewall software up to date. You might also want to add prayer to the list. You may need it.
Wednesday, January 28, 2009
Be paranoid!
A case in point is the recent malware that pretends to be about President Obama (or for you Irish folks, O'Bama). The Microsoft Malware Protection Center (MMPC) blog has more about this Waledac Trojan, including pictures of an email and the malicious web page.
Remember, it's perfectly OK to be paranoid -- the bad guys really out to get you!
Saturday, December 20, 2008
Infected web pages increase
During 2008, the rate at which the number of web pages infected with malicious software (malware) increased rose from one every 14 seconds to one ever 4.5 seconds. [See "Forecast: Security Threats for 2009"]
So what can you do?
- Don't "assume" a web site is safe to visit.
- Don't "assume" a link in an email is safe to click on.
- Don't "assume" an email from a friend was really sent by them.
- Use anti-phishing software, antivirus software, and anti-spam software.
- Keep all your computer programs updated. If there is a security patch available for any of your programs, install the patch.
- Use a program like Secunia's free Personal Software Inspector to check for program updates.
- Use a program like Driver Detective to check for updates to program driver files.
Firefox less secure?
- From March to September 2005 (yes, even as early as 2005), FireFox had 40 vulnerabilities to IE's 10. [ZDNet article]
- From April through September 2005, the number of published Firefox exploits was 11 compared to IE's 6.
- The most recent FireFox-related security problem is that some Russian criminals are using it to add malicious software as a "Plug-In". The malware detects when you connect to any of over 100 banks and then steals your account name and password, sending them to the criminals. [read the SC Magazine article]
- In terms of vulnerability numbers reported in March 2008, Opera had the most, followed by Safari, FireFox, then Internet Explorer.
The biggest problem with malware is not the browser, it's the person using the browser. People are either too trusting of links and unknown sites or just think they will never get attacked.
Friday, November 28, 2008
Beware nasty Mebroot trojan
Beware of malware called Sinowal (also as Mebroot) captures bank and similar data. A gang of Internet criminals have been using this and even morphing the malware to temporarily fool antivirus software.
Windows Secrets contributing editor Woody Leonhard likens Mebroot to "a parasitic operating system that runs inside Windows". [Disclaimer: I subscribe to the paid version of "Windows Secrets" newsletter. Prior to that subscribed for years to the paid version of Fred Langa's "LangaList" newsletter, which is now integrated into Brian Livingston's "Windows Secrets" newsletter. I highly recommend Windows Secrets anyone concerned about or interested in PCs.]
Leonhard says that his experience is that a lot of systems get infected with Mebroot (Sinowal) because the owners did not keep up with Adobe Reader, Adobe Flash, or Apple Quicktime security patches. You can manually check for such patches, set the apps to automatically check for updates, or (even better), install the free Secunia Personal Software Inspector (PSI) and scan for programs that need updating.
In October 2008 Brian Krebs, Washington Post, alerted readers to the "virtual heist" going on. Mebroot infects the Master Boot Record (MBR) of your PC and sends personal data to its "owners". Krebs says that the criminals have stolen over half a million credit and debit card account in the past few years.
While Symantec lists the malware's risk as low, if your data gets stolen, it won't be a little thing to you. Here are some actions Symantec and I recommend to reduce your risk of malware infections:
- Use a firewall
- Enforce complex passwords for all users of your computer
- Use the lowest level access privileges.
- Never use an Administrator-level login account as your normal one. Always login as a lower level account and then "Runas" or login as the Administrator level only as needed. Vista security is a big advance in making this type security easier. Yes, you get pop-ups to login as Administrator, but that's much better than manually running a "runas" command and you don't need to know the runas command line syntax.
- Disable Auto-play
- Turn off "File Sharing"
- Turn off and remove unnecessary system services
- Always keep your programs patched (You can use the free Secunia PSI to monitor patch status)
- Don't open email attachments unless you were expecting them. Contact the sender separately (not by a "Reply") and see if they really did send you that email and attachment.
- Turn off Bluetooth via Windows Control Panel if you are not using it.
- If you really need to use Bluetooth, make sure every Bluetooth device's visibility is set to "Hidden".
Saturday, October 20, 2007
Malicious emails contain fake Youtube link
The emails arrive with headers such as, "LOL, that is too cool..."
The email claims to be a video of you that has been discovered. The message contains a fake link to youtube.com. The link acually sends you to a malicious website that downloads and runs malware.
Thursday, September 27, 2007
Adobe Reader vulnerable
Until this vulnerability is patched, do not open a PDF file you get unless it's from a trusted source and you were expecting the file.
If the source is trusted but the file unexpected, contact the sender before opening the PDF.
Wednesday, July 04, 2007
Microsoft Malware Protection Center
The site officially launches in "early July", but the links to threat information are already active.
Wednesday, April 11, 2007
Free Anti-Rootkit software
Now comes Anti-Rootkit Free from Grisoft, makers of AVG Antivirus Free Edition.
A test of the fast scan on a home computer took 10 minutes. The interface is attractive yet very simple to use.
Wednesday, January 24, 2007
Warning: Mailicious emails, web sites
- As a file installed on your computer by other malware (malicious software) or
- As a file you unwittingly download when visiting malicious URLs.
A killer at 11, he's free at 21 and kill again!
Naked teens attack home director.
230 dead as storm batters Europe.
Radical Muslim drinking enemies's blood.
Chinese missile shot down Russian satellite
Saddam Hussein alive!
Venezuelan leader: "Let's the War beginning".
Fidel Castro dead.
Be paranoid -- people really are out to get you!
Get more information at Symantec Security Response ...
Friday, November 24, 2006
Tis the season ... to be paranoid
The attack arrives in your inbox as a message (perhaps looking like it's from a friend) with a link to a "Greeting Card". If you click on the link, you may even see some sort of online greeting. But along with the greeting comes a Trojan. You have been attacked.
Prevention tips:
- Don't open email messages from strangers
- Don't assume a message from a friend is really from that person, especially if it has links or an attachment you didn't expect to receive.
- If you get a message like above from a friend, send them a separate email and ask if they really sent the one with the link or attachment.
- Don't "reply" to a suspicious message -- you could be replying to the attacker.
- When in doubt, delete.