Thursday, September 3, 2009

What does spam cost?

Network World - Spam costs organizations $712 per employee/per year, according to Nucleus Research. However, these staggering numbers don't even take into consideration one of spam's latest victims: enterprise mobile users. Spam targeted at smart phones is on the rise and becoming a growing security and productivity concern.

Protecting the inboxes of Blackberries, iPhones and other mobile devices requires new thinking. Spam, viruses and phish getting through to a desktop inbox is troublesome enough, but on a mobile device these threats present a unique set of security concerns and consequences, some of which are only just beginning to surface.

Web attacks still a problem

This report is well a bit scary. One thing to consider, Rossini.com filters many of these virus programs at a server level before they get to you. This is just one of the many features we offer you at Rossini.com!

New Malicious Web Links Up More Than 500 Percent In First Half 2009
Vulnerabilities level off, phishing is down, IBM XForce report says

Aug 26, 2009 | 02:42 PM
By Tim Wilson
DarkReading

There has been a 508 percent increase in the number of new malicious Web links discovered in the first half of 2009, according to a security research report issued earlier today.

According to the IBM X-Force 2009 Mid-Year Trend and Risk Report, the malware problem is no longer limited to malicious domains or untrusted Web sites. The X-Force report notes an increase in the presence of malicious content on trusted sites, including popular search engines, blogs, bulletin boards, personal Web sites, online magazines, and mainstream news sites.

The X-Force report also reveals that the level of veiled Web exploits, especially PDF files, are at an all-time high, pointing to increased sophistication of attackers, according to IBM. PDF vulnerabilities disclosed in the first half of 2009 surpassed disclosures from all of 2008.

"From Q1 to Q2 alone, the amount of suspicious, obfuscated, or concealed content monitored by the IBM ISS Managed Security Services team nearly doubled," the report says.

"The trends highlighted by the report seem to indicate that the Internet has finally taken on the characteristics of the Wild West, where no one is to be trusted," says X-Force Director Kris Lamb. "There is no such thing as safe browsing today...we've reached a tipping point where every Website should be viewed as suspicious, and every user is at risk."

The X-Force report found a significant rise in Web application attacks with the intent to steal and manipulate data and take command and control of infected computers. For example, SQL injection attacks -- attacks where criminals inject malicious code into legitimate Web sites -- rose 50 percent from Q4 2008 to Q1 2009 and then nearly doubled from Q1 to Q2.

The report also says that vulnerabilities have reached a plateau. There were 3,240 new vulnerabilities discovered in the first half of 2009 -- an 8 percent decrease over the first half of 2008. The annual disclosure rate appears to be fluctuating between 6,000 and 7,000 new disclosures each year, IBM says.

Phishing has decreased dramatically, the report says. Analysts believe that banking Trojans are taking the place of phishing attacks geared toward financial targets. In the first half of 2009, 66 percent of phishing was targeted at the financial industry, down from 90 percent in 2008. Online payment targets make up 31 percent of the share.

Nearly half of all vulnerabilities remain unpatched, IBM says. Similar to the end of 2008, nearly half (49 percent) of all vulnerabilities disclosed in the first half of 2009 had no vendor-supplied patch at the end of the period.

Do you Skype?

Trojan Could Enable Attackers To Eavesdrop On Skype Calls
Exploit saves conversations as MP3 files to make detection more difficult, researchers say

Aug 28, 2009 | 04:55 PM
By Tim Wilson
DarkReading

Security researchers at Symantec have observed the public availability of source code for a Trojan that targets users of the Skype voice over IP service.

The Trojan has the ability to record audio from the computer -- including any Skype calls in progress -- and store the files locally in an encrypted MP3 file, where they can later be transmitted to the attacker.

The Trojan, which Symantec calls Trojan.Peskyspy, can be downloaded to a computer by tricking the user with an email scam or other social engineering tactic, Symantec says. Once a machine has been compromised, the threat can exploit an application that handles audio processing within a computer and save the call data as an MP3 file.

The MP3 is then sent over the Internet to a predefined server, where the attacker can listen to the recorded conversations, Symantec reports. "Recording the call as an MP3 keeps the size of the audio files low and means there is less data to be transferred over the network, helping to speed up the transfer and avoid detection," the company says.

The Trojan targets Windows API "hooks" -- a technique used to alter the planned behavior of an application, which Microsoft designed for use by audio applications. The Trojan compromises the machine and then uses the hooking technique to eavesdrop on a conversation before it even reaches Skype or any other audio application, Symantec says.

"At the moment, the risk posed by this threat is quite low, and Symantec has not seen any evidence of this spreading at this early time," the researchers say. "However, with source code now publicly available, malware writers can incorporate this type of functionality into their own customized threats."

Attack of the Tweets

Attack Of The Tweets: Major Twitter Flaw Exposed
U.K. researcher says vulnerability in Twitter API lets an attacker take over a victim's account -- with a tweet

Aug 27, 2009 | 03:54 PM
By Kelly Jackson Higgins
DarkReading

A newly exposed cross-site scripting (XSS) vulnerability in Twitter lets an attacker wrest control of a victim's account merely by sending him or her a tweet.

U.K. researcher James Slater reported the serious flaw earlier this week, and now says Twitter's fix in response to his disclosure doesn't actually fix the problem. "It seems they've made a pretty amateurish attempt to fix the issue, completely missing the massive problem staring them in the face," Slater said in his blog.

The attack basically exploits an input validation weakness in a field of the form used for adding third-party Twitter clients, such as TweetDeck and Twitterific. The form doesn't fully vet what can go in that box, Slater said, so an attacker can put JavaScript tags there as well as raw HTML code, for instance. "Whatever I type in that box will appear at the end of my tweets," he blogged in a follow-up post. "Anyone who sees that tweet will then be viewing that code."

The embedded code can perform any tasks the Twitter Website can perform, including redirecting a user to another page, sending tweets, changing account information, or adding or deleting followers, he said.

"Simply by seeing one of these tweets, code can be run inside your browser impersonating you and doing anything that your browser can do. Perhaps it may simply redirect you to a pornographic website? Or maybe delete all of your tweets? Send a message to all of your friends? Maybe it would delete all of your followers, or worse still, just send the details needed to log in to your account off to another website for someone to use at their leisure," Slater said.

Twitter's patch basically prevents people from putting spaces in that box, he said, which didn't go far enough. It left the door open for attackers to put any other code there, he said.

The best defense from this attack, he says, is to run a Twitter third-party client rather than logging into Twitter's Website directly, and to "unfollow" people you don't know or don't trust. "If you don't see their tweets they can't harm you," Slater blogged.

Twitter had not responded to media inquiries about the bug as of this posting.

It has been a tough summer for Twitter security-wise. Researcher Aviv Raff hosted the Month of Twitter Bugs in July, aimed at exposing vulnerabilities in third-party Twitter applications. Among other problems, Twitter was hit by a massive DDoS attack earlier this month that knocked the popular microblogging site offline for hours, and then a researcher discovered a Twitter profile being used as the command center for a botnet. The profile was sending updates and malware to bots.

Sears has a problem!

Flaw In Sears Website Left Database Open To Attack
Business-logic flaw in Sears.com Web application could have let hackers brute-force attack the retailer's gift card database

Sep 01, 2009 | 03:49 PM
By Kelly Jackson Higgins
DarkReading

A newly discovered vulnerability on Sears.com could have allowed attackers to raid the retail giant's gift card database.

Alex Firmani, owner of Merge Design and a researcher, this week revealed a major security hole on Sears.com that could allow an attacker to easily steal valid gift cards -- a heist he estimates could be worth millions of dollars. Firmani says he alerted Sears about the flaw, and that Sears has since "plugged" the hole by removing the feature that let customers verify and check their gift-card balances.

The vulnerability was a business logic flaw in a Web application that handles gift card account inquiries; Firmani was able to stage a brute-force attack that could grab all valid, active Sears and Kmart gift cards from the company's database.

Firmani says the site wasn't auditing verification requests, which allowed him to verify gift card and PIN combinations using a homegrown PHP script that automatically submitted the requests. "I wrote a PHP script to hammer their verification server. It happily replied with thousands of verification responses per minute," he says.

The Sears application relied on client-side cookies to halt brute-force verification attempts, which Firmani says wasn't effective. "They should know where the verification requests come from, log them all, and be able to disable the verifications when they have a malicious attack," he says. "It doesn't appear to me that they had any server-side control over how many verifications were done."

Jeremiah Grossman, CTO of WhiteHat Security, says this type of flaw is probably fairly common on retailer Websites. And unlike a cross-site scripting or SQL injection bug, this business logic flaw is different: "It basically lets an attacker defraud Sears.com directly," Grossman says.

Firmani's discovery came on the heels of reports of multiple cross-site scripting (XSS) vulnerabilities on Sears' Web pages that were abused by an attacker to deface the Website.

"I thought this was notable with Sears being a Fortune 50 company," he says. "I have not tested many other large retailers, but I would hope most of them take better care than this. For smaller sites that write their own gift-card verification code, I'd expect just as many are vulnerable."

Firmani, who says he discloses Website flaws to site owners in order to highlight common Web application security issues, suggests that Sears require a valid user account login before allowing a verification request to be sent. "You could then record the number of verification requests and lock out any offending accounts automatically and without relying on client-side cookie," he wrote in his disclosure paper. "Recording requests server-side would be a more reliable way of handling repeat request offenders."

Another option is recording to a server-side database IP addresses of users verifying their gift cards, he said, as well as using a "number-used once" scheme in the verification form or logging all verification requests and using a script to shut down the response server if more than a specifically designated number of requests arrive per minute, he said.

"Security these days is less about what version of Apache you're running and more about custom-written Web applications. With Web apps given unfettered database access, it becomes a simple matter of exploiting less-than-solid Web application programming," Firmani says. "Finding holes in home-brewed Web app code is much easier than exploiting a root-escalation bug on a Linux server, but both often have similar database access."

Facebook troubles??

Facebook scam tricks Missouri woman

Beware scammers posing as friends.

A Missouri woman was tricked into wiring about $4,000 to someone in England after receiving faked messages from a friend on Facebook asking for help.

The Associated Press reports that Jayne Scherrman of Cape Girardeau wired about $4,000 to someone in England in response to faked messages supposedly from a friend on Facebook.

Police think someone took over the Facebook account of another Cape Girardeau County resident, Grace Parry, changed the password so she couldn't get to her account, and send messages saying she and her husband were stranded in London and needed money.

Scherrman, a dentist, said Parry and her minister husband went on mission trips, so she didn't think it unusual that they would be in England, or might need money till they could get home.

Parry, who hadn't traveled to England in years, eventually tried to access her account to warn other friends but couldn't, the AP reported. She asked Facebook to suspend her account, and her husband posted warnings about the scam, including one Scherrman received after she'd sent the money.

The police said people should remember to change their passwords often for Facebook and other online services, and to be careful about posting personal information.
Submitted by Greg Hack on September 3, 2009 - 7:19am.

Wednesday, September 2, 2009

New virus on the net today!

A new virus on the net watch out for an e-mail from DHL do not open that tracking code attachment. The attachment has a virus!