Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Monday, April 6, 2009

The Conficker Eye Chart - Really!

This Conficker Eye Chart is brilliant!

Information Security can get a bit drab and boring. Especially when the auditors start poking around and you are arguing about the minutiae of your security policy. And especially when you look at the designers with their Apples and the programmers pumping out new Web 2.0 frontiers.

But sometimes, someone out there comes up with something so silly but effective that it just has to be blogged about.

The Conficker Eye Chart is simple - it tries to download images from Sites that Conficker blocks. If you can't see them then it could be that you are infected.

But you really have to see it. I wish I had come up with that one!

Monday, November 5, 2007

You have to take your (white) hat off to these hackers.... and a lot else too!

The Washington Post has an article on an interesting new piece of malware.

Captchas are those weird little blocks with numbers and letters all jumbled up and fairly difficult to read. They are there to check whether the user is a human or a computer pretending to be a human. They essentially prevent hackers from automating things that server owners would prefer them not to automate.

An example is - when you sign up for a mail account you have to decipher the captcha so that you can have the email account. This is to prevent spammers from signing up with free accounts 100 or 1000 at a time and using them to send spam, repeating the process when they are shut down. captchas have a lot of negative points but they have been rather effective.

The new malware is essentially a picture of a blond lady who will do a strip show for you. The catch is that you need to decipher some captchas, for each one she has less and less clothing. This sounds like a nice trade-off but each captcha that you enter basically signs a spammer up for a free email account. They are using you (being a human) as the middle man.

I hate spammers with a passion but I have to admit that this is a piece of genius.

Friday, June 29, 2007

MS07-0056 and Chutzpah


For those of you that know what chutzpah is...scroll down a bit.

For those of you that don't know this beautiful Yiddish term, it is broadly defined as "insolence," "audacity," and "impertinence". But as with all Yiddish terms, the meaning is deeper than just that. It is someone who does something so bad and with so much courage that you hate him for what his done but admire the fact he had the guts to do it.

My best version of chutzpah is the thief that stole a whole bunch of clothes from a department store and the next day tried to exchange the ones that didn't fit.

So, MS07-0056.

If you are a security expert or just someone that patches regularly (which you SHOULD be doing!) you may recognise that MS07-0056 looks very similar to a Microsoft Advisory number. Almost, but not quite. Microsoft advisory numbers ar MS, the two digit year , dash and a three digit number.

Ms07-0056 is a fake version of an email advisory from Microsoft, complete with their logo and formal looking, no-nonsense, go-patch-now look. The email is very cleverly crafted and has a link at the bottom to fake patch which is really malware.

While phishing is not new and fake emails telling one to download stuff is not new, the fact that patch notifications are being used to distribute malware is just way over the line of what is bad and what is total chutzpah.

While we are on the topic.. you are still reading right.. I want to throw in some other examples of chutzpah: fake antivirus and spyware checkers, or even real ones that are themselves spyware.

We, as security professionals, drone on and on and on about people patching, installing spyware and antivirus tools and using them and keeping them up to date. And along come the enemy and attack us and at the same time sow doubt in our defenses.

The rule is still the same though....treat every link in every email as suspect.

And keep your antivirus up-to-date!