• Boosting Security Awareness in Colleges

    Updated: 2009-11-30 18:16:58
    Security breaches, laptop theft, and identity theft happen all the time, and these crimes increase every year. The need for people to become more aware of their digital presence and the threats surrounding it is vital. The pace at which these threats increase is much faster than our awareness grows, making a bad situation. One way [...]

  • UPDATE: OpenSolaris ISC Construction Kit v1.3

    Updated: 2009-11-30 16:15:42
    : Glenn Brunette's Security Weblog Update : Recent Cloud . Main UPDATE : OpenSolaris ISC Construction Kit v1.3 Monday Nov 30, 2009 I have been writing about the Immutable Service Container project for quite some time Since this project was publicly launched earlier this year , we have produced a number of updates , several presentations and podcasts as well as images that people could use on Amazon EC2 or with VirtualBox All of these updates had a singular goal to highlight what is possible when we refactor our existing strategies and processes to pre-integrate greater security capabilities by default into our operating system configurations . While our original goal was to focus on Cloud Computing and virtual machine image security , these concepts really apply more universally . Whether used in a traditional data center or the Cloud , there are significant benefits that can be realized when we begin to put all of the pieces into place . Certainly , I mean more than just patching or hardening , but looking at virtual machine security more comprehensively . With this as a backdrop , I am very happy to announce the availability of version 1.3 of the OpenSolaris Immutable Service

  • Man arrested for robbing RuneScape virtual characters

    Updated: 2009-11-30 08:38:57
    It has been revealed that British police have arrested a 23-year-old man accused of stealing virtual characters and goods from players of one of the world's most popular online games. The man, from the Avon & Somerset region, was arrested last Tuesday by officers of the Police Central e-Crime Unit (PCeU), after allegedly phishing the usernames [...]

  • Koobface Worm Asks for Captcha

    Updated: 2009-11-30 01:57:45
    We discussed in a recent blog how Google Reader has become an unwitting spam target. We now see the same behavior in a recent variant of Koobface. This variant uses the Google Reader page to host the malware. Once the user selects the Google link, a fake YouTube window appears, as shown below. When the user [...]

  • Hackers exploit Tiger Woods car accident to spread malware

    Updated: 2009-11-28 00:34:15
    Cybercriminals have wasted no time taking advantage of the news that the world's number one golfer, Tiger Woods, has been involved in a car accident outside his house in Florida. Hackers have created webpages claiming to contain video content related to the accident where Tiger Woods reportedly crashed his car into a fire hydrant and tree [...]

  • ICO warns of tougher penalties for future data leaks

    Updated: 2009-11-27 17:42:27
    The Information Commissioner's Office (ICO) is arguing in the British media that company board members need to wake up to the issues of securing personal information or risk substantial fines. The warning comes as it was revealed that a laptop containing the personal data of some 110,000 people, revealing their names and addresses, dates of birth [...]

  • Pakistan Computer Association (PCA) is seeking alternative to Microsoft Products

    Updated: 2009-11-27 08:30:46
    Nov 27th, 2009 From pakcomputerassociation.com Recently, in an attempt to find out an easy solution to piracy and in response to Microsoft’s campaign against software piracy, Pakistan Computer Association (PCA) has come up with a programme to find and promote alternative products to Microsoft computer programmes. Open Source system is one of them, including other alternative [...]

  • Bad news for NASA hacker Gary McKinnon - extradition seems imminent

    Updated: 2009-11-26 20:47:42
    According to media reports, British Home Secretary Alan Johnson has rejected a last-bid attempt by Gary McKinnon's supporters to prevent his extradition to the United States. Concerns have been raised that 43-year-old McKinnon, who was arrested almost eight years ago after allegedly hacking into computers belonging to the US Army, US Navy, US Air Force, Department [...]

  • Ubisoft confirms Splinter Cell website 'hack'

    Updated: 2009-11-26 16:24:54
    Tom Clancy's Splinter Cell is a phenomenally popular series of video games where players stealthily creep up behind the bad guys and silently ermm.. "despatch them". The trick to succeed is stay in the shadows, sneak up on the enemy on tiptoe, causing distractions to waltz past them or quietly "neutralise" them as a threat. The "stealth" [...]

  • DHL Tracking Number UOYKCUFSBERKNAIBR spells danger

    Updated: 2009-11-26 15:32:15
    The cyberscoundrels are up to their dirty rotten tricks again, sending fake emails pretending to be notifications from DHL that there is a parcel that you should pick up. Attached to the emails is a ZIP file called UOYKCUFSBERKNAIBR.zip which contains a malicious threat. Sophos detects the malware proactively as Mal/EncPk-LE. Users of other [...]

  • Ikee worm author gets job at iPhone app firm

    Updated: 2009-11-26 08:23:01
    The author of the world's first iPhone worm must be feeling pretty chirpy today, because he's managed to get himself a job as an iPhone application developer. 21-year-old Australian Ashley Towns, revealed that he was going to join mogeneration (What is it with companies who insist on being spelt in lowercase? Does anyone really think that [...]

  • Crumbs! A great night at the Computer Weekly Blog awards

    Updated: 2009-11-26 00:10:25
    I've had a good night's sleep, but I'm still feeling rather incredulous about what happened at last night's Computer Weekly awards in London. Winner: IT Security blog of the year - Graham Cluley's blog, Sophos Winner: Twitter user of the year - @gcluley Winner: Overall Best blog - Graham Cluley's blog, Sophos I feel honoured to have had so many people vote [...]

  • Highlights of Xcon 2009

    Updated: 2009-11-25 15:01:43
    This is my fourth time to attend Xcon (the Xfocus Information Security Conference), and the third time as a speaker. Xcon is the biggest and most influential nongovernmental computer security technical conference in China. Actually for most Chinese security researchers it’s not only a technical event, but also a big party where they can meet [...]

  • Who's next for a smartphone virus?

    Updated: 2009-11-25 13:23:40
    Since the late 1990s some doom-mongers in the computer security industry have been predicting a tidal wave of mobile phone viruses, impacting every hoody-wearing happy-slappy ringtone-downloading ASBO-carrying teenager in the land. The reality has been rather different. Although some cellphone malware has emerged it should be regarded as a tiny drop in the ocean compared [...]

  • US Ask Sri Lanka Better Enforce Intellectual Property Rights

    Updated: 2009-11-25 05:50:02
    Recently, Sri Lanka - The United States trade and investment agreements first round of negotiations was held in Sri Lanka. U.S. Deputy of Trade Representative for South Asian Affairs, formally request Sri Lanka to strengthen intellectual property protection, and the relaxation of U.S. imports of genetically modified food in the meeting. Sri Lanka was ranked the [...]

  • Make Your Password Secure

    Updated: 2009-11-25 00:01:06
    No matter how sophisticated security gets, we still need to handle the basics properly. One of the most basic tasks is to create and use secure passwords. You need them to log onto your computer, reach internal applications, and enter just about every website you visit. They are pervasive in our connected world. But how many [...]

  • NFL player David Clowney is Twitter-hacked

    Updated: 2009-11-24 13:31:28
    David Clowney is not unusual in being a 24-year-old who is hooked on Twitter. No, what makes David Clowney stand out from the crowd is that he's a talented American football player, who appears for the New York Jets. And now, like other celebrities before him, his Twitter account has been hacked. What is perhaps bizarre [...]

  • new SSL Vulnerabilities – how they work and what they mean

    Updated: 2009-11-24 10:04:13
    You may have heard about the latest SSL vulnerabilities over the last month, but how do they work and what does it mean to you (or your users)? When I earlier described how SSL works, I glossed over two SSL functions: session resumption and re-negotiation. These two functions allow a client or server to renegotiate [...]

  • Use the Office Keyboard shortcuts in Kingsoft Office 2009 for ensure your high-efficiency work

    Updated: 2009-11-24 03:35:14
    Using Kingsoft Office , You can quickly accomplish tasks you perform frequently by using shortcut keys — one or more keys you press on the keyboard to complete a task.   System:   Kingsoft Writer Help F1 Task window Ctrl+F1 New blank document Ctrl+N File   Open a document. Ctrl+O Save a document. Ctrl+S Print a document. Ctrl+P Choose the Save As command (File menu). F12 Edit   Copy text or graphics. Ctrl+C Cut text or graphics. Ctrl+X Paste the Office Clipboard [...]

  • Zero-Day IE Exploit Coming to a Browser Near You

    Updated: 2009-11-23 23:22:42
    Information regarding another zero-day vulnerability in the Internet Explorer web browser affecting version 6 and 7 has been published as Proof-of-Concept over the weekend. The vulnerability lies in a missing check when accessing a website’s Stylesheet markup information through the „getElementsByTagName“ script method. The current PoC exploit uses heap-spraying to write the malicious shellcode to [...]

  • Fly for $1 or Your Money Back!

    Updated: 2009-11-21 01:07:13
    It is the time of year to get together with family and friends, and that often involves flying. So, how about a promotional airline ticket for just $1? That sounds like an irresistable idea! Though it also sounds too good to be true. As you can imagine, there is something wrong here. Instead of flying for [...]

  • COFEE Break Turns Messy

    Updated: 2009-11-20 15:36:19
    A common challenge of cybercrime investigations is the need to conduct forensic analysis on a computer before it is powered down and restarted. As some active system processes and network data are volatile and may be lost after the computer is turning off, investigators were in search of a tool that could assist them in [...]

  • Curiosity as a Malicious PDF

    Updated: 2009-11-20 15:00:05
    What would you do if you saw an email in your inbox with a PDF named “U.S. ship thwarts second pirate attack November 18, 2009.pdf”? Would the title pique your curiosity? I hope not enough for you open the document! This PDF is the latest in the ugly line of exploit- and malware-ridden embedded PDFs that [...]

  • Netwox – The Network Toolbox

    Updated: 2009-11-20 04:50:05
    I don’t think it’s possible to have too many network security toolkits. Netwox is probably not as common some of the other toolsets included in some security-oriented live CD distros. However, it can certainly hold its own when it comes to capability and flexibility. Netwox stands for the Network Toolbox and the software includes over 222 [...]

  • Malicious Java Applet Poses as Carrie Prejean Video

    Updated: 2009-11-19 14:48:08
    McAfee Labs has observed various spam runs exploiting the recent sensational Carrie Prejean news. The Prejean video is rapidly becoming one of the most searched-for topics ever on the net since the existence of the tape became common knowledge. Source: Google Trends Java applets provide everything from interactive features to web applications to advertisements. Since the birth [...]

  • Kingsoft: Three Million New Viruses Detected In October 2009

    Updated: 2009-11-19 03:00:29
    from ChinaTechNews.com Chinese Internet security provider Kingsoft has published a report on China’s computer virus and Internet security situation in October 2009, stating that 3,031,921 new viruses were detected in mainland China during the month and 20,812,698 computers were affected by these viruses. Kingsoft Duba, the anti-virus branch of Kingsoft, said that Microsoft published 53 system patches [...]

  • Kingsoft Office achieve great successful Exhibit at PHILCONSTRUCT 2009, Philippine

    Updated: 2009-11-18 09:00:58
    Created on Nov.18th- By Great Worth November 12, 2009, Pasay City, Philippines — Great Worth with the Local Partner Exhibit powerful Office system software - Kingsoft Office to the Engineers, architects, manufacturer, Students  at PHILCONSTRUCT 2009.  This one of the biggest show in Philippines was held on the SMX Convention Center in Pasay City, between November [...]

  • Whose hands are your mobile apps in?

    Updated: 2009-11-13 22:05:31
    Another iPhone killer is here. DROID. Whether you’re a fan of either product, or you’re still thumbing away on your Blackberry or WinMo device, there’s one thing to be said. There are plenty of apps now. A couple years ago it was a pretty daunting task to get any sort of application on your device [...]

  • The McColo Effect: One Year Later

    Updated: 2009-11-11 22:26:40
    One year ago today email administrators were astonished to notice the amount of spam hitting their mail servers had plunged precipitously. Email volumes dropped off as much as 60 percent to 70 percent, and the reason wasn’t immediately obvious to anyone except for the folks who knew that McColo, a major spam-hosting ISP had been taken [...]

  • Kingsoft Office Help Shanxi Weiqida Pharmaceutical Solve the Legal Problems

    Updated: 2009-11-11 09:00:21
    Nov, 11th, 2009 from Kingsoft With the development of economy, more and more customers realized the importance to use legal software products. During this process, some good product with low cost will be accepted by more customers and will become more popular in the world. Kingsoft Office 2009 can be the right one. Recently, Shanxi Weiqida Pharmaceutical [...]

  • Kingsoft Spreadsheets Provide Free Grade Book Templates

    Updated: 2009-11-10 08:50:19
    You can easily to create a Grading Sheet with Kingsoft Spreadsheets. This function is great to Educational user. Kingsoft Spreadsheets serves as an excellent tool for tracking grades in the teacher’s course;  all you have to do is fill name and score of your students. When you change the score, the grades will change automatically.  [...]

  • Real or False Positive

    Updated: 2009-11-09 18:53:26
    Moments ago I received a virus alert for Downloader.SWF.Agent.bv on a user's web request. Referer: http://www.real.com/player/index.html Destination: http://ke-el.com/download/checkout_confirmation.php?s=ZJxmRSLB&id=3 That either means the user clicked on a link on real.com that took them to a virus page or the virus page is a element of the real.com page. Either way not good. I went to the real.com page and didn't see any funny business. It would be a good story if Real.com was infected. I think it had to be for my user to get this result, but I couldn't spot the trouble myself. Next I checked out the ke-el site. Scansafe detected that page as Gumblar.x. I opened the page up using a online HTTP viewer and say the following

  • Kingsoft Internet Security was Published on a well known Greek magazine “Computer Active” for November 2009

    Updated: 2009-11-09 03:00:06
    Created On Nov. 9th , 2009 The trial Version of Kingsoft Internet Security 9+ was Published on a well known Greek magazine “Computer Active” for this month - November 2009 . The readers and visitors can testing and using Kingsoft Internet Security. More information please check : http://www.computeractive.gr/default.php?pid=6&art_id=3018 About Kingsoft Internet Security:  Kingsoft Internet security (KIS) is an advanced anti-virus and [...]

  • Kingsoft Office Software Attended SADC exhibition in Mauritius

    Updated: 2009-11-05 02:30:39
    From 22 to 25 October , DOE Tech Co., Ltd as one of  local distributors of  Great Worth take part in the Southern African Development Community (SADC) exhibition in Mauritius and got a great success. With high compatibility with MS Office , powerful features and cost-effectiveness, Kingsoft Office is the optimal choice for people who are [...]

  • NEW: Solaris 10 Security Deep Dive Presentation

    Updated: 2009-11-04 17:36:40
    : Glenn Brunette's Security Weblog Immutable Service . Main Update : Recent Cloud . NEW : Solaris 10 Security Deep Dive Presentation Wednesday Nov 04, 2009 Today , I am very happy to announce the availability of a new Solaris 10 Security Deep Dive training . This version has been updated for Solaris 10 10 2009 also known as Update 8 From a security perspective , there have only been a few updates since my last posted version , but it is always good to be current . Items added in this new version include : ZFS user and group quotas , ZFS pre-defined ACL sets , NTPv4, and nss_ldap shadowAccount support . In addition , there was a bit of cleanup throughout and a new example was added for Trusted Extensions . As usual , I have made this content available in both OpenDocument Format ODF and PDF If you are using Microsoft Office , you can use the Sun MS Office ODF Plugin to read the source document . For those of you who have downloaded one of the previous versions , thank you There have been nearly 8,000 downloads of this presentation so far If you have not had a chance , I would encourage you to download and check out a copy today . It is really amazing how many new and updated

  • Security Updates for Shockwave

    Updated: 2009-11-04 03:36:28
    Adobe has released Adobe Shockwave 11.5.2.602 to fix multiple security vulnerabilities. You can install this version at http://get.adobe.com/shockwave/. if you've taken the time to license Shockwave for redistribution in your company, the MSI file isn't available on the licensed distribution site.

  • Kaspkersky False Positive in gosearch.gif

    Updated: 2009-11-02 20:03:12
    Kaspersky is detecting gosearch.gif as Trojan.JS.ramif.a. gosearch.gif is a standard magnifying glass icon used in Sharepoint as a search button. I submitted this to Kaspersky and they concur its a false positive, so hopefully updated defs will be out shortly.

Last Months Items