Friday, August 31, 2012



.JAR
AND
SHYLOCK



"Shylock" was a nasty Java exploit several years ago. The holes that were exploited were patched by Oracle back then. Shylock got it's name because when the virus code was examined, Security engineers found references from Shakespeare's play, "The Merchant From Venice".

This is less of a history lesson, and more about the fact that "Shylock" is back, and perhaps, more dangerous than ever. A valid response from you may be: "If the holes were patched, what's the big deal?", and my answer is simple:not everyone updates their computer. I've been to more places than I care to remember where a users PC had Java versions 2-5 on them, and I'm not sure what else the new and improved Shylock takes advantage of either. I do know that it tries to change it's characteristics when downloaded to avoid detection.

You should take a few minutes to read the security blog post on Symantec's website, which also has an easy-to-follow graphical map which helps explain it better than mere words could do. Be sure not to miss exactly what this does, once it begins to nest in your PC. Surf well, surf safely.......

'Nuff Said,
Brian

[Symantec/Norton user for over two decades]

Thursday, August 30, 2012



ORACLE GETS OFF THEIR COLLECTIVE BUTTS




Yes, Oracle has issued a patch that according to RAPID7, stops an attack using the JAVA exploit we've been facing all week.

"It appears that it's effective in blocking the exploit," Tod Beardsley, the engineering manager for Metasploit, said early Thursday. "We just finished testing it 10 minutes ago." [source: Computer World]

The update -- designated "1.7.0_07-b10" -- was published along with a bare-bones release note on Oracles website, and followed that with an alert shortly after 1 p.m. ET.



ZERO DAY JAVA EXPLOIT 4 DAYS LATER




I have had several MAC calls this week for fear they had the JAVA exploit, but a quick check told me both computers were 1.6.0 and I told them not to update JAVA any further until this whole mess is settled out. Meanwhile, in the rest of the world:

Firefox is telling it's users to disable JAVA completely (I.E. users should do the same).
 
Security firms have found packages added to the exploit and if a computer is infected, the package opens and out jump a bunch of other Virus/Trojans.

From Computer World:

"Patrik Runald, director of security research at Websense, said his team had found more than 100 unique domains serving the Java exploit."

Other security firms are telling users to un-install JAVA entirely [ed. - something I did on Monday. I haven't had any problems without it, so until I do, it won't be re-installed]. Some reports say this "HOLE" won't be patched by Oracle until October.

Sharks are in the water, surf safer -
Brian

Monday, August 27, 2012














A Zero day Java7 exploit is putting Windows, Linux, and MAC users at risk right NOW, regardless of which browser is used! Computer World writes:

"The unpatched bug can be exploited through any browser running on any operating system, from Windows and Linux to OS X, that has Java installed, said Tod Beardsley, the engineering manager for Metasploit, the open-source penetration testing framework used by both legitimate researchers and criminal hackers."

Apparently the bug is not in Java 6, and security experts are advising users to disable JAVA immediately. Again, from Computer World:

"Mac owners can disable the Java plug-in from within their browsers, or remove Java 7 from their machines. To do the latter, select "Go to Folder" from the Finder's "Go" menu, enter "/Library/Java/JavaVirtualMachines/" and drag the file "1.7.0.jdk" into the Trash"

Windows users, can either un-install JAVA, or disable it via your browser. For I.E. browser users you cango to Tools\Internet Options\Security\Internet\ and disable active scripting.

Even having done this, try to avoid browsing sites you've never been on before, and hopefully you won't suffer a drive-by JAVA attack.

Thursday, August 23, 2012



CRISIS/MORCUT MALWARE IS VIRTUALLY HERE






Please forgive my play on words, as this is a no joking matter (but I couldn't help it). Malware known as "Crisis/Morcut" has jumped the barrier between the real and the virtual PC, much like Neo in the Matrix.

This Malware actually infects Windows PCs running VMware. Apparently computers, known to be infected, were snagged by a malicious JAVA applet (JAVA_AGENT.NTW). The two key components of this applet have their own special tasks: One infects MAC's, the other looks for Windows machines running the VMware. The MAC part opens up a backdoor to the computer, while the Windows partner is a "Worm", identified as "WORM_MORCUT.A".

We'll hear more about this in the days to come, but at least you know - it's coming.

Monday, August 20, 2012




IT'S TIME TO PUT YOUR THINKING CAP ON
[I AM]




First of all, if you didn't read the post from the 19th, please do as it help will verify the seriousness of the matter.

Infections, data theft, unbootable PC'S unfortunately become as common as those of us who suffer allergies in Houston. Just because you have an Anti-Virus software, does not exclude you from the class of infected users, and perhaps we should start thinking "Out-of-the-box" for ways to combat this. Yesterday's post was alarming enough, and now a report from NSS LABS in Austin Texas leaves me wondering "how do you keep from being infected?"

I realize, as you should, that the report was about some specific threats, and that some AV software which fared well, may not do as good against another type threat, but the answer is definitely not running more than one Anti-Virus on your PC.

I wasn't very happy where Norton fell amongst the 13 products tested, however it (the product) has yet to fail our family after a decade of use. The article about the test was picked up by PC WORLD, which is where I first read about it, then I went to the TSS website to download complete results. As the article on PC WORLD'S website pointed out:

"Antivirus firms will doubtless point out that the attacks were crafted in the lab, that the the vulnerabilities chosen were fairly recent, and that only two were looked at. Making judgements on the basis of such a narrowly-defined test offers only one indication among a number."

However, from reading both the article and Test report, I can no longer recommend a free anti-virus for you to use.

I can ask you "Would you rather pay $80 for an Anti-virus now, or possibly spend over $200 removing an infection and a chance of losing all of your pictures, music, and data?" (which could still happen, but with a far greater chance if you continue to use free anti-virus software).

You can read the PC WORLD article HERE.

'Nuff Said,
Brian

Sunday, August 19, 2012


SHAMOON
[HINT: It's NOT A WHALE]


Yes, your PC could be under attack by "Shamoon", it's the latest....(clue: picture to the right) Trojan that usually targets businesses, Government websites, etc. but anything can happen so be on alert. This Trojan is a destructive little bugger which gets the data it wants off your PC, then destroys it's path leaving your PC DOA. Yes, this could very well be a format hard drive situation, as it corrupts or removes your Master Boot Record (MBR). As of this writing, the largest Anti-Virus companies are hard at work on SHAMOON, however, they have yet to discover what data it is after and relaying to a remote server.

UPDATE:

"Shamoon" is also labeled as "Disttrack" by other Anti-Virus software and Trend Micro reports it overwrites any Document, Picture, Video, or Music on the computer rendering them useless and unrepairable. It has been known to use the file names "Clean.exe" or "Dvdquery.exe".

'Nuff Said,
Brian