Monday, May 28, 2012

MOBILE APP COMING SOON



MORE MAL-DROID COMING YOUR WAY!

Not to say I didn't tell you so, but, here we are again. Credit for this info came to me via Trendmicro's Blog:

"Recently ZTE acknowledged the existence of a vulnerability in its Android-based smartphone Score M. The said vulnerability, if exploited, can allow attackers to operate with root privileges—a scenario that can mean an attacker will have complete control over the affected phone. We have taken some time to analyze this backdoor in order to help affected users remove it from their Score M handsets." (WBY - ya gotta love this one, the backdoor is called and "ELF"). Read the rest HERE, and, photo credit for the Droid picture goes to SHADOWINKDESIGN.COM.

Wednesday, May 23, 2012


DO YOU KNOW WHAT DEVICES ARE ON YOUR NETWORK?

[Usually, in regards to small business networks the answer is - "NO"]


Many times, as an IT consultant my job is to figure out why something that has worked from day one, has suddenly stopped. I'll use a network device scanner of one sort or the other and then ask questions like: "What is this Asus device with a 192.168.1. 153?"; Is it a Router? Is it a wireless device or perhaps a PC? And somewhere between the 2nd and possibly 6th question the person who has been deemed responsible for the companies network sez...."I dunno".

No, this is not an exception, but more the norm. A small business gets a network setup and then years (and many replacement or additions later) no one really knows what is doing what on the network. To be fair with the designated "Network Guy", it's really not his fault. He (or she) is probably more of a company administrator that tries to take care of the overall needs of its employees. This is where I come in. I take inventory of every physical piece of equipment I can find, compare it to the list of equipment "Discovered" on the network, determine what each device does, then map it all out into a nice VISIO-converted-to-PDF document so the designated person can answer these questions.

Whether you company has 4 or 5 computers, or 50, it would be a good idea, as well as a good time to have your network appraised, and mapped out.

'Nuff Said

Sunday, May 20, 2012

EXCEPT FOR THIS HEADING, COMPLETE CREDIT GOES TO TRENDMICRO'S MALWARE BLOG:



The continuing increase in visitors to the Pinterest site may be a primary cause why it’s becoming a hit for cybercriminals’ scams and schemes. In March, we spotted scammers using popular brands to lure users into “pinning” fake posts that led to surveys scams. This new wave of survey scams I found came from my search using “pinterest” as keyword.

Users who re-pin the posts from the sample above will most likely spread the post.
In addition, I also spotted posts using URL shorteners such as bit.ly and goo.gl. When clicked, the shortened URLs/the fake posts lead to any of the following URLs:
  • http://pinterest.co{BLOCKED}t.info/?419
  • http://pinterest.com-{BLOCKED}key.info/Thank-You/fb/
  • http://pinterest.co{BLOCKED}s.info
  • http://pinterest.{BLOCKED}one.info
  • http://pinterestgift.{BLOCKED}hing.info
  • http://pinterests.{BLOCKED}onus.info
Upon clicking the link, users are redirected to a Pinterest-like webpage offering prizes, vouchers, gift cards and others:

Made to resemble like a typical Pinterest webpage, the fake site features a search field, add+, an about. However, these are mere images and are not clickable. The clickable links are those that redirect to survey scams such as Body Age Quiz.

After a user fills out the fields required in the scam page, users are also required to enter their mobile numbers. Users who do provide their numbers will receive a code on their mobile phones and will continue to receive unwanted messages, charges and other scams via text message.
And Via Email, Too
Another thing I’ve noticed is that the fake site requires an email address:

Users entering their email addresses are brought to complete several steps to get the supposed offer. Users receive an email claiming to be from Pinterest. The email urges the user to click on the link found in the message body to confirm the subscription. Clicking on the link redirects the user to a Pinterest-like scam page. Again, all the clickable links lead to the same scam pages.

Upon closer investigation of these attacks, I noticed that before users are redirected to the fake Pinterest sites, the connection passes through ad-tracking sites. This way, the number of visitors are tracked, determining the supposed earnings of the scammers. Based on our data, the fake Pinterest URLs are being visited since May 2. Fake Pinterest posts hosting scams are likely to spread within Pinterest via users who re-pin the posts. The “offers” in these fake Pinterest posts look enticing after all. Plus, some users would want to ask the rest of the Pinterest community to verify such offers, like this user.
Pinterest has since removed some of the fake Pinterest posts. Trend Micro users are also protected from these scams by the web reputation technology in our Smart Protection Network™.

Friday, May 18, 2012

JUST WHEN I THOUGHT I WAS FINISHED AND READY TO SHOWER AND HEAD OFF TO WORK:

"WORM"


Yup, I said it. Folks, there's a new "Worm" in town and it's ripping through the Internet as I type! This guys preferred vehicle of infection is via FACEBOOK private messages, as well as Instant Messengers (oh, I'm sure you can think of a few you use). According to Trendmicro:

 "Once executed, this malware (detected as WORM_STECKCT.EVL) terminates services and processes related to antivirus (AV) software, effectively disabling AV software from detection or removal of the worm. WORM_STECKCT.EVL also connects to specific websites to send and receive information. Another noteworthy routine is that this worm downloads and executes another worm, one detected as WORM_EBOOM.AC. Based on our analysis, WORM_EBOOM.AC is capable of monitoring an affected user’s browsing activity such as message posting, deleted posted messages and private messages sent on the following websites such as Facebook, Myspace, Twitter, WordPress, and Meebo. It is also capable of spreading through the mentioned sites by posting messages containing a link to a copy of itself."

The rest of the story is HERE.


LOOKING FORWARD - I SEE MICROSOFT WINDOWS 8 COMING TO PC'S THIS FALL

[Note: I did not say I was looking forward to it]



Yeah, everyone and their brother has heard, or read a lot about this new version. I'm more of sidelines kinda guy who will wait before I stick my toe in the water (It took a couple years to get me on Windows 7). Being a security Blog, I thought I'd mention an article I just read about enhanced security in Win8, the first of which comes as no surprise: Unlike previous versions of Windows, Win8 will have an anti-virus program already installed and it sure looks a lot like Security Essentials (it is) which Microsoft has offered without charge for about 2 years now. Read the full story HERE, which will inform you of other security improvements.

Tuesday, May 15, 2012

AND ONLY A DAY LATER....

Yesterday I mentioned the first 802.11AC wireless router.

Today, NETGEAR has announced a USB adapter for your PC to take advantage of the new 11AC speeds. Their own wireless routers are still supposed to be on schedule for mid-summer, while this adapter won't be on shelves until August.Expect the price to be around $70.