• Fake Resume Spam Leads to Malware Infection

    Updated: 2010-06-30 20:48:34
    We just noticed a new wave of fake resume spam that redirects users to a malicious site. We see the resume pages were uploaded to innocent sites in top-level domains of various countries, perhaps in an attempt to internationalize the spam campaign. The pages contain a small piece of obfuscated JavaScript code that translates into a [...]

  • Guest blog: Adobe, make my day. Disable JavaScript by default

    Updated: 2010-06-30 16:05:39
    Sophos principal virus researcher Vanja Svajcer guest blogs about the latest security updates from Adobe. Over to you Vanja... Users around the world will be pleased to learn that Adobe has managed to release an accelerated security update for Adobe Reader and Acrobat (APSB10-15) before the planned release date (13th July). The latest version of Adobe [...]

  • New Clothes for ‘Canadian Pharmacy’ Spam

    Updated: 2010-06-30 15:49:39
    It has been a little while since we heard something new from the pharmacy spam corner, but right on time at the end of Q2, they are back–and with reinforcements! Our researchers have found an enormous number of spam URLs, and they are all related to some well-known malicious IPs ranges–194.xx.xx.x2 and 194.xx.xx.x4. The first IP range [...]

  • Out of Office

    Updated: 2010-06-30 05:30:33
    Are out of office (OOF) messages a security risk?   (Microsoft uses the acronym OOF for Out of Facilitiey.   I’ll be using that rather than OoO for out of office). I’ve felt that the anti-OOF forces are the kind of ludite people who still agitate for a return to text only email. Maybe I should reconsider. Out of [...]

  • Guest blog: Win a free iPad in our data security survey

    Updated: 2010-06-29 17:05:51
    Clearly Sophos's Carole Theriault is enjoying the power of guest-blogging. Here she is again, doing a favour for our UK marketing department who have an Apple iPad that they're dying to give away. The floor is yours Carole... Want the chance to win a free iPad? I know I'd love one - a couple of weeks ago [...]

  • Guest blog: Musings on Obama's 'kill-switch for the internet'

    Updated: 2010-06-29 16:25:16
    Guest blogger Carole Theriault, a senior security consultant at Sophos, ruminates on the big red switch that President Obama might want installed in the Oval Office. Over to you Carole... Proposed US legislation, now approved by the US Senate committee, has been making headlines this month. Bill S.3480, also known as the Protecting Cyberspace as a National [...]

  • SSL Ciphers, what are those?

    Updated: 2010-06-29 12:26:28
    I don’t know if it’s PCI compliance fever season or what, but I’ve been asked a lot about “weak SSL ciphers” lately. Mostly, having to do with “what the heck are those anyway?” If you don’t have a decent grasp of SSL, start with my previous article on SSL. If you think [...]

  • Watching World Cup 2010 Online Can Lead to Scams

    Updated: 2010-06-28 23:57:55
    Just in case you are looking for websites to watch the 2010 FIFA World Cup matches online, you will also find many questionable websites offering live football streams! Many of these sites will ask you to install software to get access to a P2P-based streaming network. Some of the common types of software offering such [...]

  • How to using Advanced Filter in Kingsoft Spreadsheets 2010

    Updated: 2010-06-26 15:14:25
    How to using Advanced Filter in Kingsoft Spreadsheets 2010

  • DNSSEC .ORG TLD Signature

    Updated: 2010-06-26 08:20:56
    The .ORG top level domain (TLD) recently received its DNSSEC signature, and now has the ability to provide integrity information about its underlying domains. This is important because it’s the first TLD to get signed. This also means it might be somewhat of a guinea pig, as any uncaught issues or bugs will probably show [...]

  • Social Networking, Privacy Concerns Worry Europeans

    Updated: 2010-06-26 01:32:03
    This week I’ve seen several interesting articles and posts about the effect and consequences of social networking sites within Europe. Here are a few links: European Parliament Dagens Nyheter IDG Sweden Travolution McAfee recognizes the development of social networking as a fundamental business tool as well as a personal tool. What we find particularly interesting are the increased concerns [...]

  • Great Worth Promotes to use Legitimate software- Kingsoft Office At Philippine Companies and Government

    Updated: 2010-06-25 14:40:55
    Great Worth Promotes use Legitimate software

  • Guest blog: Does Apple stand at a security crossroads?

    Updated: 2010-06-25 08:53:58
    Ben Jupp, a Sophos technical specialist who lives and breathes all-things Mac, Linux and Unix, ponders Apple's attitude to security. Over to you Ben.. Apple gets a pretty rough press when it comes to security and to be honest I think it's deserved. This isn't to say that I think Apple never thinks about security; [...]

  • Meghna Naidu isn't pregnant, she's been hacked

    Updated: 2010-06-24 16:56:13
    Glamorous Bollywood actress Meghna Naidu has contacted the computer crime police in Mumbai, after her email and Facebook account were compromised by a hacker. 31-year-old Naidu, who I'm reliably informed is well known as a "sizzling hot Bollywood babe" in the subcontinent, lodged a complaint with the Cyber Crime Investigation Cell (CCIC) after friends reported receiving [...]

  • Inside the Carding Underworld

    Updated: 2010-06-24 16:45:42
    Carder.cc is a German online forum dedicated to helping criminals in trading stolen credit card and login details obtained via their carding or phishing activities. Because such forums are a source of income for their administrators (who are also involved in this black market), the best-known forums are forever engaged in underground infighting to stay [...]

  • Italian Phishing Scam Targets Customers of CartaSi

    Updated: 2010-06-24 16:28:23
    Spam never ceases to amaze me. The latest phishing scam I’ve seen is spammers impersonating CartaSi, the Italian financial institution. The message subject is “Effettuare l’aggiornamento dei dati,” which means to proceed with the data or information update. This email even carries an introduction that educates users about phishing on the web. The scammers provide [...]

  • Hacking Pages in Firefox with the HackBar

    Updated: 2010-06-24 15:24:29
    A few months ago, I described how the Firefox add-on HttpFox could be used for basic traffic monitoring. Another helpful add-on that complements nicely with HttpFox is called HackBar. HackBar adds a toolbar underneath the main address bar that can be toggled on or off with the F9 key. When enabled, the toolbar provides a miniature [...]

  • 'Peeping Tom' arrested for webcam blackmail attack spree

    Updated: 2010-06-24 12:12:27
    FBI agents have arrested a man accused of hacking into more than 100 computers, and using personal information stolen from them to extort sexually explicit videos of young women and teenage girls. 31-year-old Luis Mijangos, of Santa Ana, California, was apprehended by the authorities after a six-month long investigation into his involvement in computer hacking, identity [...]

  • Targeted Trident cyber-attack against defence company

    Updated: 2010-06-24 10:27:23
    Targeted attacks occur when cybercriminals launch malware against a specific organisation, industry or government department. In recent years we've often seen these distributed in the form of booby-trapped Word documents or malformed Adobe PDF files. Overnight we intercepted an attack against a firm working in the defence industry (which we will not name for obvious [...]

  • How to using Filter in Kingsoft Spreadsheets 2010

    Updated: 2010-06-23 15:04:07
    How to using Filter in Kingsoft Spreadsheets 2010?

  • Guest blog: Taking your protection with you

    Updated: 2010-06-23 08:04:56
    Rich Baldry, a product manager based in our Vancouver offices, discusses an exciting new security feature that will benefit everybody who browses the web away from their office. Over to you Rich.. The Winter Olympics may have been and gone, but here at Sophos Vancouver, we’re still pretty excited. In case you missed it, Sophos recently announced [...]

  • Cybercrime forum suspects arrested by British police

    Updated: 2010-06-23 01:31:23
    Britain's Police Central e-crime Unit (PCeU) have announced today that they have arrested two men as part of an eight month investigation into what is said to be the world's largest English-speaking online cybercrime forum. The underground website consisted of online forums where up to 8000 malicious hackers traded stolen bank account details, PIN details, phished [...]

  • Waka Waka FIFA 2010: Targeted PDF Attack Uses World Cup as Bait

    Updated: 2010-06-22 15:40:49
    Malware authors have long taken advantage of high-profile incidents and trends to infect naive Internet users with malware. Historically, we have come across innumerable incidents like Michael Jackson’s demise or the Benazir Bhutto assassination as an avenue to spread malware. We have seen instances from recent times where FIFA World Cup themes have been extensively used [...]

  • McAfee Survey: Secret Life of Teens

    Updated: 2010-06-22 12:56:53
    Today McAfee released the results from our survey “Secret Life of Teens,” which provides a detailed snapshot of online teen behavior. It reveals that 85 percent of teens go online somewhere other than at home and under the supervision of their parents, nearly a third (32 percent) of teens say they don’t tell their parents [...]

  • McAfee, Parental Controls, and Apple Devices = Safer Kids Online

    Updated: 2010-06-22 01:19:30
    Today we announced our McAfee® Family Protection iPhone®, iPod touch® and iPad™ Edition. McAfee now provides strong parental controls to keep young people safe when they are browsing the Internet on an Apple mobile device. McAfee released McAfee Family Protection for the PC in June 2009. According to data released by Admob in 2010, [...]

  • Step Back I’m Certified – GCIA

    Updated: 2010-06-18 20:58:13
    Today I passed the GIAC Certified Intrusion Analyst (GCIA).  The blog title refers to a Dilbert strip that I keep on the wall with my certifications.   As I recall Certification Man says to Dilbert “Step back from that server, I’m certified!”  In the next panel he says, “funny, that’s all I recall from the certification [...]

  • HTTPS Everywhere

    Updated: 2010-06-18 15:05:38
    A beta release of HTTPS Everywhere was released today. It’s a collaborative project between those at the Tor project and the EFF. Many sites on the web offer some limited support for encryption over HTTPS, but make it difficult to use. For instance, they may default to unencrypted HTTP, or fill encrypted pages [...]

  • Researching DLP Solutions

    Updated: 2010-06-17 19:30:03
    I recently had a project to help spec out a DLP project for a customer from a high-level perspective. Having never done anything with DLP previously I embarked on a research mission. What I found was interesting. There’s not much out there on the intarwebs. As such, I thought I’d offer [...]

  • Are Comparative Tests of AV Products Useful?

    Updated: 2010-06-16 21:16:54
    For a comparative review of anti-malware products to be useful to you, it has to be correct, comprehensive, and objective. Unfortunately, producing a good test is not a simple task. You may think that it is, but it is not. It is like with cars – some are more reliable, some drink more petrol, some handle [...]

  • GuardianEdge 9.5.1 Patch 1

    Updated: 2010-06-16 06:47:16
    GuardianEdge 9.5.1 patch 1 was released to address the Dell issues that I previously wrote about. Support provided client installer packages so I could quickly see if this also fixed the issue I had with the Toshiba (sadly it did not).   Not sure if I’m going to get a chance to verify this patch resolves the Dell [...]

  • Maintaining Security with Enterprise Virtualization

    Updated: 2010-06-11 15:00:22
    Recently at Gemini we evaluated basic security implications of deploying a particular large-scale desktop virtualization package. Many people have heard of “virtual machines” that enable you to run different operating systems concurrently on one physical computer. But enterprise virtualization solutions go far beyond that scenario, enabling companies to do everything from stream specific applications from [...]

  • Thanks for Nothing Google

    Updated: 2010-06-10 20:46:58
    Yesterday I wrote about the importance of using good passwords because people are trying to bruteforce your email and social networking accounts.  Today I logged into GMail and received a dire red letter message. “your email has been accessed from the United States.”     Upon reviewing the Gmail account activity log, I see access to my [...]

  • OpenVPN and two-factor authentication

    Updated: 2010-06-10 12:02:49
    Many people have used OpenVPN for a simple and effective VPN solution, but did you know that you can use it for real two-factor VPN authentication? How you do that depends on the two-factor solution you are using. There is support for PKCS11 token stores, and Windows CAPI, with patches submitted for OS [...]

  • Yes, You really do need a good password

    Updated: 2010-06-10 02:54:34
    Mark Kellner, a technology reporter at the Washington Times, bravely owns up to using crappy passwords.   Most users think they have nothing to hide and nothing of value.   “Who would possibly be interested in me” they ask.   So “why”, they ask, “should I bother with a good password.” Kellner’s Gmail account was compromised by an IP [...]

  • GuardianEdge 9.51 issues with some Dell

    Updated: 2010-06-07 20:29:44
    I’ve been doing more testing with GuardianEdge 9.5.1 since my last post on the subject.   A Dell E6500 with Windows 7 64 bit wouldn’t get to the GuardianEdge pre-boot authentication screen.  I attributed that to issues specific to Windows 7 64 bit and possibly a OEM drive partition.   So I went ahead and tried to upgrade [...]

  • Pardon Our Dust

    Updated: 2010-06-06 02:51:49
    I decided to move over to WordPress.  Currently I’m working on keeping thinks up and running with a minimum of 404s.  Once all of that is cleared away I’ll be looking for something besides the default theme. Commenting is set to moderate first time posters.   I dont know if wordpress is smart enough to recognise old posters.   [...]

Current Feed Items | Previous Months Items

May 2010 | Apr 2010 | Mar 2010 | Feb 2010 | Jan 2010 | Dec 2009