• Viral clickjacking 'Like' worm hits Facebook users

    Updated: 2010-05-31 12:08:25
    Hundreds of thousands of Facebook users have fallen for a social-engineering trick which allowed a clickjacking worm to spread quickly over Facebook this holiday weekend. Affected profiles can be identified by seeing that the Facebook user has apparently "liked" a link: Messages seen being used by the spammers include: "LOL This girl gets OWNED after a POLICE OFFICER [...]

  • An Overview of Exploit Packs

    Updated: 2010-05-29 08:01:38
    Today’s cybercriminals frequently use “exploit packs” to easily snare victims for their botnets. Users with underprotected computers who visit booby-trapped websites become the latest botnet zombies. I often receive requests asking me which exploit packs are current and which vulnerabilities they use. To answer these inquiries, I’ve created a table that lists the exploits referenced by [...]

  • Naughty Camera Prank virus hits Facebook users

    Updated: 2010-05-29 02:00:11
    Reports are coming in that a new attack is spreading virally across Facebook disguised as a video - the third Saturday in a row that the social network has been assaulted in this fashion. The attacks come in the form of a message, sent by a rogue Facebook application (using names such as HD Media, Xziox [...]

  • Lessons from Google Wi-Fi Gaffe

    Updated: 2010-05-28 15:00:12
    Lately, Google has been apologizing for mistakenly collecting data from unprotected Wi-Fi networks with the fleet of vans the company has sent out for its StreetView service.  Some have pointed out that, by leaving their wireless networks unprotected, companies had no reason to expect their data would not be collected somehow. And so we have another [...]

  • BP's Twitter account hacked by pranksters

    Updated: 2010-05-28 09:46:17
    BP has admitted that its official Twitter account was compromised temporarily yesterday by hackers who posted a joke about its attempts to stem the devastating oil leak that has polluted the Gulf of Mexico. According to a report from Business Insider, an unauthorised posting appeared on the BP America Twitter account at about 8.00am UK time [...]

  • Security Concerns Less Considered

    Updated: 2010-05-27 15:24:10
    Concern about security threats and such as malware and data loss is common and certainly warranted. But understanding of where threats come from varies. Most know Phishing, Spam, Adware, and PUPs are likely culprits and understand that any given site may become infected. But many don’t realize that some content types, even those welcomed into [...]

  • Poll: 93% say Facebook should make you 'opt-in' to sharing rather than 'opt-out'

    Updated: 2010-05-27 12:52:54
    Some of you will be waking up today to find that Facebook's privacy settings have been updated (don't panic if you're a Facebook user and you don't see the new settings yet - they're taking a while to roll out). Inevitably there has been much debate about this latest development in the ongoing Facebook privacy saga. To [...]

  • Japanese duo arrested over Hentai extortion virus

    Updated: 2010-05-27 12:19:15
    According to media reports, two men have been arrested in Japan in connection with computer malware which stole personal information and posted it on the internet. The men are said to have not only created the malware, but also been behind a fraudulent scheme whereby they contacted victims offering to remove their personal data from the [...]

  • Facebook privacy settings revamped: good news and bad news

    Updated: 2010-05-26 20:54:52
    First, the good news. Facebook has simplified its privacy settings. The incredibly popular social networking site has kept the promise it made last week and come up with an attractive and seemingly simpler replacement for what was a terrifying labyrinth of privacy options. And there are some positive changes here. For instance, now you'll be able to [...]

  • Nick Clegg appears to backtrack over intervention in Gary McKinnon case

    Updated: 2010-05-26 14:39:29
    Nick Clegg, the Deputy Prime Minister of the UK, has shocked supporters of Gary McKinnon, by saying that the newly elected British Goverment may not be able to prevent the extradition of the self-confessed NASA hacker. According to newspaper reports, Nick Clegg told BBC Radio Five Live: "What I haven't got power to do, neither has the [...]

  • Genealogy Research – aka stalking

    Updated: 2010-05-26 12:35:18
    Have you ever looked into researching your family tree? Have you noticed what kind of information you can find out about people, especially older people who have been around since the 1930 census (and pretty soon, the 1940 census)? Upon death, social security numbers are published in the Social Security Death Index, and [...]

  • Scaremongering scientist claims to have infected himself with computer virus

    Updated: 2010-05-26 10:53:14
    A British scientist at the University of Reading is claiming to be the first human to be "infected with a computer virus". According to a report on BBC News, Dr Mark Gasson, a senior research fellow working at the university's Cybernetic Intelligence Research Group, implanted an RFID chip containing what he claimed to be virus code [...]

  • Second man jailed for Scientology DDoS attack

    Updated: 2010-05-25 17:46:26
    Even if you don't like someone (or a particular organisation) that's not a reason to commit a criminal act. In January 2008, a distributed denial-of-service attack (DDoS) struck websites websites belonging to the highly controversial Scientology organisation - flooding them with internet traffic, and making them inaccessible to the outside world. Yesterday, as The Register reports, a [...]

  • Students' personal data exposed after USB drive stolen

    Updated: 2010-05-25 01:56:21
    A school in Woodbridge, Virginia, held a meeting with parents last night to discuss the loss of a USB flash drive containing personal information about students. Lake Ridge Middle School posted an advisory on its website explaining that the USB drive was used by by school administrators "to contact parents in the event of an emergency [...]

  • Announces: Kingsoft Office 2010 Version released!

    Updated: 2010-05-24 09:57:57
    Today Kingsoft Office 2010 Version is released ! The new version is available for Windows®, providing complete office productivity suite which contains Kingsoft Writer, Kingsoft Presentation and Kingsoft Spreadsheets. With the newest version of the Top 1 Selling Office software in China and Japan, Kingsoft Office continues to make high efficiency and performance accessible to users who want to Create Professional and Ideal Documents.

  • Kingsoft Office 2010 Version Launch Date Revealed

    Updated: 2010-05-23 04:35:14
    Great Worth will release Kingsoft Office 2010 in May 24th,2010- Monday.

  • Digital Signatures DII Workshop

    Updated: 2010-05-21 21:09:11
    This week, I registered for the next Document Interop Initiative (DII) workshop being held at Microsoft. (Details here) The meet-up is centered around the new XML Advanced Electronic Signatures (XAdES) support in Office 2010. In my opinion, this is a great step forward for Office’s digital signature support, as XAdES provides the appropriate XML [...]

  • VLC Media Player

    Updated: 2010-05-20 23:55:35
    Roger's Information Security Blog Hi , welcome to my blog . It started out as a place to be able to post links and news so I could find them again . I began adding my own commentary , and its proven surprisingly popular . Thanks for stopping by . Dont forget to use the search if Google dropped you off at this page and you dont see what you're looking . for VLC Media Player By Roger on May 20, 2010 5:55 PM No Comments No TrackBacks VLC Media Player is a multimedia player by the VideoLan project . People tend to use it because its not buggy and bloated like a lot of media players and it seems to play anything you throw at . it While working on VLC 1.1, members of the project found a vulnerabilities that could allow attackers to execute arbitrary code on a targeted computer . This fix was

  • To Buy Shiny New Products Or Not To Buy

    Updated: 2010-05-20 17:09:24
    I got a chance to see the Metasploit Express beta in action last week at NoVa Hackers. I was planning on writing about my impressions, but there is plenty out there from people who have spent a good deal more time in front of the beta than I have. Instead, I’m going [...]

  • Email Message Size Limits - The Update

    Updated: 2010-05-19 15:06:22
    Roger's Information Security Blog Hi , welcome to my blog . It started out as a place to be able to post links and news so I could find them again . I began adding my own commentary , and its proven surprisingly popular . Thanks for stopping by . Dont forget to use the search if Google dropped you off at this page and you dont see what you're looking . for Email Message Size Limits The Update By Roger on May 19, 2010 9:06 AM No Comments No TrackBacks The Microsoft Exchange team wrote a blog back in 2006 summarizing the need to email message . limits Email size limits help protect you against denial of service attacks . Intentional or not Internal sender or external , a large message can consume all available resources . The problem can be aggravated by Antivirus for Exchange . It only has

  • GuardianEdge 9.5.1, Windows 7 and Me

    Updated: 2010-05-19 01:51:13
    Roger's Information Security Blog Hi , welcome to my blog . It started out as a place to be able to post links and news so I could find them again . I began adding my own commentary , and its proven surprisingly popular . Thanks for stopping by . Dont forget to use the search if Google dropped you off at this page and you dont see what you're looking . for GuardianEdge 9.5.1, Windows 7 and Me By Roger on May 18, 2010 7:51 PM No Comments No TrackBacks Long time readers , and anyone who has ever Googled Guardian Edge recall my intense dissatisfaction with GuardianEdge 8.7 and Vista on my Toshiba Laptop Everything old is new . again GuardianEdge released 9.5.1 last month so we finally have support for Hard Disk Encryption with preboot authentication on Windows 7. The short version of the

  • Hardening Adobe Reader

    Updated: 2010-05-18 18:13:09
    PDF files have become commonplace on the Internet and in the business world, but they have also become favorite tools for attackers to deliver malicious payloads. While some problems may be mitigated by using an alternative PDF reader, many people have little choice but to use the standard Adobe Reader. In that situation, you can [...]

  • McAfee Threats Report Released for First Quarter 2010

    Updated: 2010-05-18 15:08:31
    Today we released the McAfee Threats Report for the First Quarter 2010. In it we reveal that USB worms have taken the No. 1 spot for malware worldwide! Spam trends show that email subjects vary greatly from country to country with diploma spam, out of China and other Asian countries, on the rise. Disasters, earthquake [...]

  • 50 Percent of Enterprise XP running SP2

    Updated: 2010-05-15 20:04:52
    Roger's Information Security Blog Hi , welcome to my blog . It started out as a place to be able to post links and news so I could find them again . I began adding my own commentary , and its proven surprisingly popular . Thanks for stopping by . Dont forget to use the search if Google dropped you off at this page and you dont see what you're looking . for 50 Percent of Enterprise XP running SP2 By Roger on May 15, 2010 2:04 PM No Comments No TrackBacks According to Qualys , 50 of enterprise Windows XP computers are still running Service Pack 2. This was reported by Byron Acohido in a USA Today . article This matters because MIcosoft will stop providing security patches for computers with this service pack in July . If you're running XP , you must have service pack 3 to continue to get

  • This week’s in review

    Updated: 2010-05-15 00:12:01
    Did you know that two thirds of all phishing attacks are sourced from a single group? This seems like a staggering statistic, except for the fact that we’ve already seen this before. Maybe those plans for world domination just might pay off… This whole Facebook privacy scare seems to finally be taking its toll on the [...]

  • Malware: To create or not create. THAT is the question!

    Updated: 2010-05-14 15:57:27
    The Anti-Malware Testing Standards Organization (AMTSO) has published a paper on its website that addresses one of the most controversial subjects in anti-virus testing – Issues involved in the “creation” of samples for testing. Many people within AMTSO (and I want to remind all our blog readers that this organization includes people from academic institutions, publishers, [...]

  • Kingsoft Office 2010 Advance Notice

    Updated: 2010-05-14 05:56:57
    New version of Kingsoft Office 2010 will be release very soon in May , 2010 .

  • Kish Cypher

    Updated: 2010-05-14 05:09:16
    The Kish cypher is categorized as a technique for secure communication, similar in application to Quantum encryption and Public Key cryptography. The simplified explanation is that it works by measuring the resistance of the communication medium (i.e. a circuit, or some wire) between 2 parties. One party can “send” messages by changing the resistance of [...]

  • Facebook Strengthens Logon Security

    Updated: 2010-05-14 00:51:59
    Lately Facebook has been all over the news regarding security and privacy issues. Today Facebook replied, by announcing some new tools, settings, and measures to allow users to better protect their logons. In his blog, Facebook’s Lev Popov describes the new settings and features in nice detail. In a nutshell, users now have the ability to [...]

  • Ending XP Service Pack 2 and Windows 2000 security support and its implications

    Updated: 2010-05-13 15:55:48
    I was just reading Byron Acohido’s writeup on Microsoft ending security support for patches for Windows XP Service Pack 2 and Windows 2000. Now as I work for a vendor myself I completely understand why Microsoft is going EOL (or is it EOS for end-of-support?? I forget…) for these operating systems – better, more robust [...]

  • Jumping on the Cloud (In)security Bandwagon

    Updated: 2010-05-12 22:33:48
    A column published this week by Robert Westervelt states that federal CISOs who are delaying broad cloud-based deployments are doing so because they are concerned about security.  This is a sentiment that has been echoed several times before.  In Late 2009 Colt Telecom Group commissioned a study with research firm Portio which stated that 68% [...]

  • VPN Split Tunneling

    Updated: 2010-05-12 15:34:04
    Roger's Information Security Blog Hi , welcome to my blog . It started out as a place to be able to post links and news so I could find them again . I began adding my own commentary , and its proven surprisingly popular . Thanks for stopping by . Dont forget to use the search if Google dropped you off at this page and you dont see what you're looking . for VPN Split Tunneling By Roger on May 12, 2010 9:34 AM 4 Comments No TrackBacks VPN Split Tunneling allows a user to VPN into the corporate network and pass data over the encrypted tunnel to the there while at the same time still talk to local resources and go directly to the internet . The alternative is to always tunnel and send almost everything through the VPN . The idea of always tunnel VPN is sacrosanct to many VPN admins and I

  • Patch Tuesday

    Updated: 2010-05-12 03:25:01
    Roger's Information Security Blog Hi , welcome to my blog . It started out as a place to be able to post links and news so I could find them again . I began adding my own commentary , and its proven surprisingly popular . Thanks for stopping by . Dont forget to use the search if Google dropped you off at this page and you dont see what you're looking . for Patch Tuesday By Roger on May 11, 2010 9:25 PM No Comments No TrackBacks Here's a roundup of patch . Tuesday Microsoft Patches There are two patches this month from Microsoft . One in Outlook Express Microsoft Mail . One in Microsoft Visual Basic for Applications Adobe released an update for . ColdFusion A security update for . Shockwave This one is listed as critical . Not a bang-your-head-on-the-desk as last month , but I could have

  • No One is Immune to Security Issues

    Updated: 2010-05-07 23:02:52
    Earlier this week, blogger and author Cory Doctorow published an account of how he fell victim to a phishing scheme: I run an up-to-date version of a very robust flavor of GNU/Linux called Ubuntu, which has a single, easy-to-use interface for keeping all my apps patched with the latest fixes. My browser, Firefox, is far less [...]

  • Taking an Aggressive Stance Against Fake Anti-virus

    Updated: 2010-05-06 22:15:46
    Researchers at McAfee Labs aggressively work to stay on top of the new wave of fake anti-virus software, identifying new blends to ensure our customers are protected. In some cases these domains carry a full page of malicious pornography links. Malware authors use multiple forms to create and get their fake applications installed in your computers. [...]

  • DLP – Data Loss Prevention

    Updated: 2010-05-06 12:47:13
    With the release of OpenDLP, more and more people are hearing about DLP. What is it and how does it work? Fundamentally, security is about protecting important data – whatever that data happens to be – a formula, a trade secret, social security numbers, etc. We have all kinds of tools and techniques to [...]

  • Happy Blogaversary

    Updated: 2010-05-06 11:50:34
    6 years ago I started blogging. I keep hearing people disparaging blogging. The kids today think blogging is too lengthy, just tweet it. The CEO thinks he doesn't have time to read a blog, so put it in a podcast. The tech guy says who uses RSS anymore. The Facebook "Like" button is taking over the web as the new way to share a link. I'm still having fun with it. I still have people stopping by to make me part of their day. Thank you readers. Here's too another year of making our computers safer and protecting our data.

  • McAfee Recognized for Excellence

    Updated: 2010-05-04 23:13:00
    I am pleased to announce a few honors that McAfee has earned over the past couple of weeks, particularly those that relate to messaging security, my responsibility. We learned today that McAfee has once again earned a VBSpam award in the latest round of comparative testing performed by Virus Bulletin. This award was given to both products [...]

  • Back to Basics: No Tech Hacking at 30,000 feet

    Updated: 2010-05-04 20:28:59
    Sometimes I travel for work. Sometimes I travel for pleasure. Sometimes when I travel for pleasure I bring my work along so as to maximize the number of days a year I can spend traveling for pleasure. How about you? Recently I was on a plane, and it came to my attention that [...]

Current Feed Items | Previous Months Items

Apr 2010 | Mar 2010 | Feb 2010 | Jan 2010 | Dec 2009 | Nov 2009