Tuesday, December 22, 2009

Facts to Know to Keep Your Computer Safe from Viruses

http://isc.sans.org/

A virus is a computer program that is intended to do harm. A virus can delete information on your computer or use your e-mail to send viruses to other computers.

Malware is a computer program such as a Trojan Horse or a Worm.

A Trojan Horse is when a computer virus pretends to be something that it is not. EX: screen savers or computer games. If something sound too good to be true, then don’t trust it.

A Worm is a computer virus that moves through ports and uses the computer network.

A DNS code is an address that changes the number code into words so we can remember them.

A router is a device that ships and delivers information and a router switch is the same thing but it is more efficient.

If you get an unexpected email from somebody you don’t know don’t open it.

If there is an attachment to an email you can open it as long as you have the file checked with Anti-Virus protection software.

There are many ways to be protected from a virus like thru a firewall and anti-virus programs like Norton, and Mac-Updates that are already on a Mac.

Firewalls don’t accept some things because they don’t fit the criteria.

Be careful when going to game sites or other sites that let you download things because you may get a virus.

Remember, nothing is free. Beware of free stuff, programs, games, etc. that are offered on the Internet. These usually contain viruses.

Anything that connects to the internet can contact a virus this includes your cell phone and Xbox.

Friday, December 18, 2009

China Jails Trojan Virus Authors in Cybercrime Crackdown

A Chinese court Wednesday sentenced 11 members of a malware ring for writing and distributing Trojan horse viruses meant to steal online game account passwords, according to state media.

The people, who stole login information for more than 5 million game accounts, were given prison sentences of up to three years and were fined a total of 830,000 Chinese yuan (US$120,000), China's Xinhua news agency said. Dozens of other members of the ring, which is suspected of 30 million yuan ($4.4 million) in crime, are expected to be sentenced soon, Xinhua said.

http://www.pcworld.com/businesscenter/article/184909/china_jails_trojan_virus_authors_in_cybercrime_crackdown.html

Friday, December 11, 2009

Shmoocon 2010

Feb 5 - 7, Wardman Park Marriott, Washington DC, USA




Different • ShmooCon is an annual East coast hacker convention hell-bent on offering three days of an interesting atmosphere for demonstrating technology exploitation, inventive software & hardware solutions, and open discussions of critical infosec issues. The first day is a single track of speed talks, One Track Mind. The next two days, there are three tracks: Break It!, Build It!, and Bring It On!.

Affordable • ShmooCon is about high-quality without the high price. Space is limited! ShmooCon has sold out every year, so unless taking a chance on an eBay auction to get your ticket sounds like fun, register early!

Accessible • ShmooCon is in Washington, D.C., at the Marriott Wardman Park Hotel, just a few steps from the D.C. Metro. Fly into DCA, IAD, or BWI, or take a train to Union Station, and you are just a quick cab ride away from the con.

Entertaining • Brain melting from all the cool tech you are learning? Check out some of the contests running at ShmooCon, including the Hacker Arcade and Hack-Or-Halo. In years past, we have also thrown massive parties at a local area hot-spot, so expect that to happen again too!


http://www.shmoocon.org/registration.html

Thursday, December 3, 2009

BlackBerry Products PDF Distiller Code Execution Vulnerabilities

Hackers can use maliciously rigged PDF files to hack into corporate systems hosting the BlackBerry Attachment Service, according to a warning from the makers of the popular smartphone.

Research in Motion (RIM) issued an advisory with patches for multiple flaws in the PDF distiller service and warned and an attacker could exploit the issues by simply e-mailing a booby-trapped PDF file to a BlackBerry user.

These vulnerabilities could enable a malicious individual to send an email message containing a specially crafted PDF file, which when opened for viewing on a BlackBerry smartphone that is associated with a user account on a BlackBerry Enterprise Server, could cause memory corruption and possibly lead to a Denial of Service (DoS) condition or arbitrary code execution on the computer that hosts the BlackBerry Attachment Service component of that BlackBerry Enterprise Server.

Affected versions include the BlackBerry Enterprise Server 5.0.0 running on Microsoft Windows version 2003 or 2008, BlackBerry Enterprise Server 5.0.0 running on Microsoft Windows 2000, BlackBerry Enterprise Server software versions 4.1.3 through 4.1.7, and BlackBerry Professional Software 4.1.4.


http://blogs.zdnet.com/security/?p=5030&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+ZDNetBlogs+%28ZDNet+All+Blogs%29

Tuesday, November 24, 2009

New Banking Trojan Horses Gain Polish

Criminals today can hijack active online banking sessions, and new Trojan horses can fake the account balance to prevent victims from seeing that they're being defrauded.

Traditionally, such malware stole usernames and passwords for specific banks; but the criminal had to access the compromised account manually to withdraw funds. To stop those attacks, financial services developed authentication methods such as device ID, geolocation, and challenging questions.

Unfortunately, criminals facing those obstacles have gotten smarter, too. One Trojan horse, URLzone, is so advanced that security vendor Finjan sees it as a next-generation program.
Greater Sophistication

Banking attacks today are much stealthier and occur in real time. Unlike keyloggers, which merely re­­cord your keystrokes, URLzone lets crooks log in, supply the required authentication, and hijack the session by spoofing the bank pages. The assaults are known as man-in-the-middle attacks because the victim and the attacker access the account at the same time, and a victim may not even notice anything out of the ordinary with their account.

http://www.pcworld.com/article/182889/banking_trojan_horses.html?tk=rss_news

Sunday, November 22, 2009

Microsoft Internet Explorer CSS Handling Code Execution Vulnerability (0day)

Title : Microsoft Internet Explorer CSS Handling Code Execution Vulnerability (0day)
VUPEN ID : VUPEN/ADV-2009-3301
CVE ID : GENERIC-MAP-NOMATCH
CWE ID : VUPEN VNS Only
CVSS V2 : VUPEN VNS Only
Rated as : Critical
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2009-11-21




A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by a dangling pointer in the Microsoft HTML Viewer (mshtml.dll) when retrieving certain CSS/STYLE objects via the "getElementsByTagName()" method, which could allow attackers to crash an affected browser or execute arbitrary code by tricking a user into visiting a malicious web page.

VUPEN has confirmed the vulnerability on fully patched Windows XP SP3 systems with Internet Explorer 7 and 6.

Affected Products

Microsoft Internet Explorer 7
Microsoft Internet Explorer 6

Solution

Disable Active Scripting in the Internet and Local intranet security zones.

VUPEN Security is not aware of any vendor-supplied patch.

References

http://www.vupen.com/english/advisories/2009/3301

Tuesday, November 17, 2009

Windows SMB Subject to Denial-of-Service Attack Windows 7

Microsoft is continuing to investigate holes in its Server Message Block (SMB) file-sharing protocol used in Windows.

Late Friday, Microsoft put out a yet another Security Advisory, saying it was looking into "new public reports of a denial-of-service vulnerability" in SMB.

The reported exploits touch SMBv1 and SMBv2 on Windows 7 and Windows Server 2008 R2 operating systems, according to the software giant.

Vista, Windows Server 2008, XP, Windows Server 2003 and Windows 2000 are not affected.

"Microsoft is aware of public, detailed exploit code that would cause a system to stop functioning or become unreliable," said Dave Forstrom, a spokesman for Microsoft Trustworthy Computing. "If exploited, this DoS vulnerability would not allow an attacker to take control of, or install malware on, the customer's system but could cause the affected system to stop responding until manually restarted."

Last Friday's advisory is the second such advisory since Redmond released one in September. This also marks the second time in as many months that news about vulnerabilities in the SMB program has emerged.

Forstrom said the default firewall settings on Windows 7 will help block attempts to exploit this latest DoS issue.

He added that while Microsoft is not currently aware of active attacks, customers should "review and implement the workarounds outlined in the advisory until a comprehensive security update is released."

http://mcpmag.com/articles/2009/11/16/windows-smb-subject-to-denial-of-service-attack.aspx

Hack the Box Blue

https://arcy24.medium.com/hack-the-box-blue-f5ae5b602a5c