Showing posts with label IT security. Show all posts
Showing posts with label IT security. Show all posts

Friday, 11 November 2011

Biggest Cyber Takedown in History

Cyber Gang broken - six arrests - are you infected?

Cyber criminals alleged to have made £9million (US$14m) from advertising fraud have been caught and their operations disrupted in what some are calling the "biggest cyber criminal take down in history" Six gang members that were arrested are Estonians while the seventh member, a Russian, escaped.

The FBI alleges the gang infected more than four million computers worldwide with malicious code that redirected users to online ads on websites where the gang would get a cut of the advertising revenue. Victims would typically be trying to visit sites such as Amazon, Netflix and ESPN but would instead end up on sites displaying adverts put together by the gang.

Are you affected?

Our friends at trend micro have kindly provided information here.


This will tell you how to obtain DNS numbers which you can check at this FBI webpage.


Cork Monkey is simply passing on information from others here and if you have any doubts as to carrying out the instructions on these sites or what to do if you are infected our advice would be to seek assistance from a professional or a friendly computer whizz.
In fact Cork Monkey would suggest you do not click on theses links at all but look these locations up independently and do not - repeat DO NOT get into the habit of clicking on links where people are offering antivirus or malware help. Get into the habit of looking things up for yourself.
These links are fine as far as I know - there are no downloads here just instructions but it is worth adopting good habits!
WHY
This too could be a scam. I am not in the malware business, but I would say that wouldn't I. Instead of loading a cleanup tool you could be persuaded to download malware, come under my control and be part of my master plan to take over the world..... So how to combat this - like I said - if someone says they are from the FBI no harm accessing the webpage via the real FBI website. Need Trend Micro get their webaddress  for yourself and access the information directly. If you trust these links then fine but do  so at your own risk.
Keep safe out there.  
(:-(|)CM

Thursday, 3 November 2011

Word files vulnerable to Duqu

In the beginning was a vulnerability in word ....

According to a recent report the Duqu trojan has been spread with the help of infected Microsoft Word documents. The research says the Trojan exploits a vulnerability in Word files which makes it possible to modify a computers protection in their favour. Duqu infections are confirmed in eight countries and suspected in four others including the UK.

Crysys (The Laboratory of Cryptography and Systems Security) analysed forensics data of suspect files and in at least one case has obtained proof that a file contained a Duqu installer and used a Zero Day Exploit (ZDE).  Crysys believe that it is possible that Duqu is also spread by other means, however they do not have evidence to confirm this.
Speak Like a Geek   - A zero-day exploit refers to a computer threat making use of a previously unknown software error that will enable a hostile hacker to gain permissions they should not have.- -
Cavalry on the way
Microsoft have said they are aware of the issue and are currently preparing a software patch to deal with it. "Microsoft is working with our partners to provide protections for a vulnerability used in targeted attempts to infect computers with the Duqu malware," a company statement said. "We will be providing a security update for customers through our update process."
Targeted attacks on the rise
This is the latest exploit in a new wave of targeted attacks that include last years Stuxnet worm and the PoisonIvy Trojan that ealier this week was reported to have targeted a number of chemical companies. Stuxnet appeared to be after control of industrial systems and Duqu could be designed to send back information from industrial control systems.
This is a worrying trend and Commercial and Industrial espionage are thought to be the motive behind this type of attacks but as yet, despite some media claims, no-one has been able to trace the source of any of the attacks.
CM