Thursday, September 10, 2009
McAfee security hint
A good article follow this link to McAfee: http://home.mcafee.com/AdviceCenter/Default.aspx?id=rs_na_sarticle1&cid=64250
Wednesday, September 9, 2009
Thought for the day
I really have to express what I think when a company wants to use a persons services and says I will try you for 90 days. I want to see what you can do. The problem is and I believe even though money is money if you do not charge for your hard work you are cheating both yourself and your client. Moral of the story is, you get what you pay for! Both parties have to be happy with the deal or you both end up sad in the end.
Friday, September 4, 2009
I love wireless!
Wireless vulnerability assessment solution helps protect wireless networks from outside threats, reduces third-party consultation costs, and ensures regulatory compliance and reporting
Aug 21, 2009 | 11:36 AM
SCHAUMBURG, Ill., Aug. 18 -- The Enterprise Mobility Solutions business of Motorola, Inc. (NYSE: MOT) , today announced the Motorola AirDefense Wireless Vulnerability Assessment solution, a patented wireless security technology aimed at proactively assessing the security posture of wireless networks. This innovative solution provides a completely new method to secure wireless networks against real-world threats by introducing active wireless testing capable of evaluating every deployed wireless access point. Through this revolutionary approach, the Wireless Vulnerability Assessment solution enables IT administrators to remotely find and secure vulnerabilities in their wireless network and automates regulatory compliance reporting, helping customers reduce operating expenses, streamline reporting and increase the resiliency of their wireless networks.
Aug 21, 2009 | 11:36 AM
SCHAUMBURG, Ill., Aug. 18 -- The Enterprise Mobility Solutions business of Motorola, Inc. (NYSE: MOT) , today announced the Motorola AirDefense Wireless Vulnerability Assessment solution, a patented wireless security technology aimed at proactively assessing the security posture of wireless networks. This innovative solution provides a completely new method to secure wireless networks against real-world threats by introducing active wireless testing capable of evaluating every deployed wireless access point. Through this revolutionary approach, the Wireless Vulnerability Assessment solution enables IT administrators to remotely find and secure vulnerabilities in their wireless network and automates regulatory compliance reporting, helping customers reduce operating expenses, streamline reporting and increase the resiliency of their wireless networks.
Watch out when you search the net
Be Careful With Your Search Results
Posted by Sean-Paul Correll at 01 September 09 07:29
Blackhat SEO (BHSEO) is currently one of the most prevalent distribution methods for Malware on the Internet. It’s also one of the most dangerous methods because of the user-implied trust in search results. A Forrester research study conducted in 2008 showed that 50 percent of Internet users trust content delivered by search engines. It’s no surprise that cyber criminals have been using malicious search results as a main monetization stream.
The Rogueware campaign we blogged about last week turned into a full blown BHSEO attack targeting relevant news topics such as, the California wildfires, Ted Kennedy’s death, DJ AM’s death, Mega Millions Lottery, Hurricane Danny, UFC 102, CNN and BBC breaking news among thousands of search terms and 123,000 links. Upon clicking one of many malicious links in the top ranking search results, the victim is put through several redirections and finally taken to a fake scan website designed to infect and extort money.
Posted by Sean-Paul Correll at 01 September 09 07:29
Blackhat SEO (BHSEO) is currently one of the most prevalent distribution methods for Malware on the Internet. It’s also one of the most dangerous methods because of the user-implied trust in search results. A Forrester research study conducted in 2008 showed that 50 percent of Internet users trust content delivered by search engines. It’s no surprise that cyber criminals have been using malicious search results as a main monetization stream.
The Rogueware campaign we blogged about last week turned into a full blown BHSEO attack targeting relevant news topics such as, the California wildfires, Ted Kennedy’s death, DJ AM’s death, Mega Millions Lottery, Hurricane Danny, UFC 102, CNN and BBC breaking news among thousands of search terms and 123,000 links. Upon clicking one of many malicious links in the top ranking search results, the victim is put through several redirections and finally taken to a fake scan website designed to infect and extort money.
Thursday, September 3, 2009
What does spam cost?
Network World - Spam costs organizations $712 per employee/per year, according to Nucleus Research. However, these staggering numbers don't even take into consideration one of spam's latest victims: enterprise mobile users. Spam targeted at smart phones is on the rise and becoming a growing security and productivity concern.
Protecting the inboxes of Blackberries, iPhones and other mobile devices requires new thinking. Spam, viruses and phish getting through to a desktop inbox is troublesome enough, but on a mobile device these threats present a unique set of security concerns and consequences, some of which are only just beginning to surface.
Protecting the inboxes of Blackberries, iPhones and other mobile devices requires new thinking. Spam, viruses and phish getting through to a desktop inbox is troublesome enough, but on a mobile device these threats present a unique set of security concerns and consequences, some of which are only just beginning to surface.
Web attacks still a problem
This report is well a bit scary. One thing to consider, Rossini.com filters many of these virus programs at a server level before they get to you. This is just one of the many features we offer you at Rossini.com!
New Malicious Web Links Up More Than 500 Percent In First Half 2009
Vulnerabilities level off, phishing is down, IBM XForce report says
Aug 26, 2009 | 02:42 PM
By Tim Wilson
DarkReading
There has been a 508 percent increase in the number of new malicious Web links discovered in the first half of 2009, according to a security research report issued earlier today.
According to the IBM X-Force 2009 Mid-Year Trend and Risk Report, the malware problem is no longer limited to malicious domains or untrusted Web sites. The X-Force report notes an increase in the presence of malicious content on trusted sites, including popular search engines, blogs, bulletin boards, personal Web sites, online magazines, and mainstream news sites.
The X-Force report also reveals that the level of veiled Web exploits, especially PDF files, are at an all-time high, pointing to increased sophistication of attackers, according to IBM. PDF vulnerabilities disclosed in the first half of 2009 surpassed disclosures from all of 2008.
"From Q1 to Q2 alone, the amount of suspicious, obfuscated, or concealed content monitored by the IBM ISS Managed Security Services team nearly doubled," the report says.
"The trends highlighted by the report seem to indicate that the Internet has finally taken on the characteristics of the Wild West, where no one is to be trusted," says X-Force Director Kris Lamb. "There is no such thing as safe browsing today...we've reached a tipping point where every Website should be viewed as suspicious, and every user is at risk."
The X-Force report found a significant rise in Web application attacks with the intent to steal and manipulate data and take command and control of infected computers. For example, SQL injection attacks -- attacks where criminals inject malicious code into legitimate Web sites -- rose 50 percent from Q4 2008 to Q1 2009 and then nearly doubled from Q1 to Q2.
The report also says that vulnerabilities have reached a plateau. There were 3,240 new vulnerabilities discovered in the first half of 2009 -- an 8 percent decrease over the first half of 2008. The annual disclosure rate appears to be fluctuating between 6,000 and 7,000 new disclosures each year, IBM says.
Phishing has decreased dramatically, the report says. Analysts believe that banking Trojans are taking the place of phishing attacks geared toward financial targets. In the first half of 2009, 66 percent of phishing was targeted at the financial industry, down from 90 percent in 2008. Online payment targets make up 31 percent of the share.
Nearly half of all vulnerabilities remain unpatched, IBM says. Similar to the end of 2008, nearly half (49 percent) of all vulnerabilities disclosed in the first half of 2009 had no vendor-supplied patch at the end of the period.
New Malicious Web Links Up More Than 500 Percent In First Half 2009
Vulnerabilities level off, phishing is down, IBM XForce report says
Aug 26, 2009 | 02:42 PM
By Tim Wilson
DarkReading
There has been a 508 percent increase in the number of new malicious Web links discovered in the first half of 2009, according to a security research report issued earlier today.
According to the IBM X-Force 2009 Mid-Year Trend and Risk Report, the malware problem is no longer limited to malicious domains or untrusted Web sites. The X-Force report notes an increase in the presence of malicious content on trusted sites, including popular search engines, blogs, bulletin boards, personal Web sites, online magazines, and mainstream news sites.
The X-Force report also reveals that the level of veiled Web exploits, especially PDF files, are at an all-time high, pointing to increased sophistication of attackers, according to IBM. PDF vulnerabilities disclosed in the first half of 2009 surpassed disclosures from all of 2008.
"From Q1 to Q2 alone, the amount of suspicious, obfuscated, or concealed content monitored by the IBM ISS Managed Security Services team nearly doubled," the report says.
"The trends highlighted by the report seem to indicate that the Internet has finally taken on the characteristics of the Wild West, where no one is to be trusted," says X-Force Director Kris Lamb. "There is no such thing as safe browsing today...we've reached a tipping point where every Website should be viewed as suspicious, and every user is at risk."
The X-Force report found a significant rise in Web application attacks with the intent to steal and manipulate data and take command and control of infected computers. For example, SQL injection attacks -- attacks where criminals inject malicious code into legitimate Web sites -- rose 50 percent from Q4 2008 to Q1 2009 and then nearly doubled from Q1 to Q2.
The report also says that vulnerabilities have reached a plateau. There were 3,240 new vulnerabilities discovered in the first half of 2009 -- an 8 percent decrease over the first half of 2008. The annual disclosure rate appears to be fluctuating between 6,000 and 7,000 new disclosures each year, IBM says.
Phishing has decreased dramatically, the report says. Analysts believe that banking Trojans are taking the place of phishing attacks geared toward financial targets. In the first half of 2009, 66 percent of phishing was targeted at the financial industry, down from 90 percent in 2008. Online payment targets make up 31 percent of the share.
Nearly half of all vulnerabilities remain unpatched, IBM says. Similar to the end of 2008, nearly half (49 percent) of all vulnerabilities disclosed in the first half of 2009 had no vendor-supplied patch at the end of the period.
Do you Skype?
Trojan Could Enable Attackers To Eavesdrop On Skype Calls
Exploit saves conversations as MP3 files to make detection more difficult, researchers say
Aug 28, 2009 | 04:55 PM
By Tim Wilson
DarkReading
Security researchers at Symantec have observed the public availability of source code for a Trojan that targets users of the Skype voice over IP service.
The Trojan has the ability to record audio from the computer -- including any Skype calls in progress -- and store the files locally in an encrypted MP3 file, where they can later be transmitted to the attacker.
The Trojan, which Symantec calls Trojan.Peskyspy, can be downloaded to a computer by tricking the user with an email scam or other social engineering tactic, Symantec says. Once a machine has been compromised, the threat can exploit an application that handles audio processing within a computer and save the call data as an MP3 file.
The MP3 is then sent over the Internet to a predefined server, where the attacker can listen to the recorded conversations, Symantec reports. "Recording the call as an MP3 keeps the size of the audio files low and means there is less data to be transferred over the network, helping to speed up the transfer and avoid detection," the company says.
The Trojan targets Windows API "hooks" -- a technique used to alter the planned behavior of an application, which Microsoft designed for use by audio applications. The Trojan compromises the machine and then uses the hooking technique to eavesdrop on a conversation before it even reaches Skype or any other audio application, Symantec says.
"At the moment, the risk posed by this threat is quite low, and Symantec has not seen any evidence of this spreading at this early time," the researchers say. "However, with source code now publicly available, malware writers can incorporate this type of functionality into their own customized threats."
Exploit saves conversations as MP3 files to make detection more difficult, researchers say
Aug 28, 2009 | 04:55 PM
By Tim Wilson
DarkReading
Security researchers at Symantec have observed the public availability of source code for a Trojan that targets users of the Skype voice over IP service.
The Trojan has the ability to record audio from the computer -- including any Skype calls in progress -- and store the files locally in an encrypted MP3 file, where they can later be transmitted to the attacker.
The Trojan, which Symantec calls Trojan.Peskyspy, can be downloaded to a computer by tricking the user with an email scam or other social engineering tactic, Symantec says. Once a machine has been compromised, the threat can exploit an application that handles audio processing within a computer and save the call data as an MP3 file.
The MP3 is then sent over the Internet to a predefined server, where the attacker can listen to the recorded conversations, Symantec reports. "Recording the call as an MP3 keeps the size of the audio files low and means there is less data to be transferred over the network, helping to speed up the transfer and avoid detection," the company says.
The Trojan targets Windows API "hooks" -- a technique used to alter the planned behavior of an application, which Microsoft designed for use by audio applications. The Trojan compromises the machine and then uses the hooking technique to eavesdrop on a conversation before it even reaches Skype or any other audio application, Symantec says.
"At the moment, the risk posed by this threat is quite low, and Symantec has not seen any evidence of this spreading at this early time," the researchers say. "However, with source code now publicly available, malware writers can incorporate this type of functionality into their own customized threats."
Subscribe to:
Posts (Atom)