Recent Posts

Showing posts with label Virus. Show all posts
Showing posts with label Virus. Show all posts

Saturday, June 9, 2012

Another Breach Reveals Weak Passwords: Protect YoursSelf!!

It has been 18 months since more than 188,000 passwords for subscribers to Gawker were snatched by hackers and posted to the Web, but consumers don't seem any more inclined to protect their passwords now than they were then.
An analysis of the most common passwords found among the millions posted to the Net after digital desperadoes clipped them from LinkedIn reveals similarities between them and the favorites of Gawker users.
For example, consecutive numbers are popular with both groups. Two of the top ten passwords for LinkedIn members were 1234 and 12345, while three passwords in the Gawker top ten were 12345, 123456 and 12345678.
Gawker's top ten also had a non-consecutive number, 111111, and an alpha numeric consecutive, abc123. Other top ten passwords for the site were less obvious, but not very strong either: lifehacker, monkey, and consumer.
LinkedIn members tended to stay away from old standbys of lazy password pickers like password and qwerty -- both in the Gawker top ten -- and focused on business (job and work were in their top ten), sex (sex and ilove) or religion (god and angel).
It's obvious that really short passwords were acceptable to LinkedIn, as evidenced in "the" making its members' top ten list. Using the name of a site for a password is also a common practice among hasty password pickers. But we all know how busy business people can be and apparently many LinkedIn members didn't have time to complete the name of the site in the password field and just used "link" instead.
If you're concerned about whether or not your password was compromised in the LinkedIn breach and haven't been informed yet by the network about it, you can check out your password at LastPass or LeakedIn.
If you're looking for tips on creating a strong password, there are plenty of folks on the Net that can advise you on that subject, including Microsoft and Google. See also PCWorld's tips at "Create a Different, Secure, Easy-to-Remember Password for Every Site.")
If you're wondering how strong the passwords you're using are, you can test them at How Secure Is My Password? For example, a password like 123456 would be cracked almost instantly.
By the way, if all this information about strong passwords makes your head hurt, How Secure has a companion site that will create for you strong passwords like 4shkenaz!Sp!tt!ng, which would take a desktop PC 14 quadrillion years to crack.

Thursday, June 7, 2012

LinkedIn Hacked : What You Need to Know ?

LinkedIn users awoke to a nasty surprise today as word spread that hackers breached LinkedIn's servers and leaked passwords for nearly 6.5 million user accounts. LinkedIn didn't acknowledge the hack until midday Wednesday afternoon, when the company finally confirmed that a certain number of member passwords had indeed been compromised.

Who's Behind the Hack?


A user on a public Russian forum is taking credit for the hack, but no one has been able to verify if he or she is really behind this whole mess.

When Did the Hack Take Place?


We don't know when the hack took place, but according to Ars Technica, the hackers posted the data over the course of three days.

What, Exactly, Was Released?


The user posted approximately 6.5 million hashed passwords to the forum, and according to security software firm Sophos, at least 60 percent of those passwords have already been cracked. Thus far no usernames have been released, which either can mean that the hackers didn't manage to download them or they are keeping the usernames for themselves. Either way, that's a lot of leaked private data.

So Is My Account Compromised?


Yes and no. The passwords were all hashed using SHA-1 and so they won't be readable outright. Unfortunately SHA-1 isn't entirely foolproof and can still be cracked through the use of brute-force attacks. These would require the attacker to insert several million words or phrases into the SHA-1 algorithm and compare the results against the list of leaked passwords. Since we don't know whether or not the hackers have usernames as well, it's best to assume the worst and consider your account hacked.

What's the Worst That Can Happen?


For one thing, hackers would have control of your account and contacts. If you use the same username and password combo on other sites, then there is a risk that those accounts are now compromised as well.

What About LinkedIn Pro Users? Do I Need to Worry About My Credit Card Info?


LinkedIn hasn't said anything about whether any financial information associated with LinkedIn pro accounts was compromised, so we don't yet know for certain. In either case, you should always keep a close eye on your financial statements to make sure that nobody is using your accounts without your authorization.

What Can I Do Protect Myself?

 In a blog post, LinkedIn says that it will email all the users whose accounts were affected by the hack and give them instructions as to what to do next. The company warns that you should not click on any email links asking you to change your password, as that could be someone attempting to steal your information.


If you used the same password or username on other websites (which you really shouldn't do), it might be a good idea to good ahead and change those for good measure. If you need help in building a better password, check out our comprehensive guide on the matter.

For still more tips, see our overview of what to do if you ever become a victim of a data breach. So change your passwords, don't click on any suspicious links, and stay safe out there, folks.

Monday, June 4, 2012

Bank Trojan: 'Tinba' Burrows into Browsers to Steal Logins!!

 
Researchers have spotted a new banking Trojan subbed 'Tinba' that appears to have hit on a simple tactic for evading security - be as small as possible.
An astonishing 20KB in size, Tinba ('Tiny Banker') retains enough sophistication to match almost anything that can be done by much larger malware types.
Its main purpose is to burrow into browsers in order to steal logins, but it can also use 'obfuscated' (i.e disguised) web injection and man-in-the-browser to attempt to finesse two-factor web authentication systems.
A particularly interesting feature is the way it tries to evade resident security, injecting itself into the Windows svchost.exe and explorer.exe processes, as well as Internet Explorer and Firefox to give itself access to traffic passing through those.
The malware connects to one or more of four command & control domains on an RC4-encrypted channel.
None of this is particularly unusual as malware goes but the getting this sort of feature set out of 20kb (including all injection routines) is the work of a developer that believes size matters and the smaller the better.
Reminiscent of the old-school viruses written in x84 assembler two decades ago, low detection rates among antivirus programs suggest that the technique could herald a new wave of diminutive malware attacks.
Infection levels are unknown but banking malware is often almost invisible until it suddenly isn't as victims come to light.
"Yes, Tinba proves that malware with data stealing capabilities does not have to be 20MB of size," said Peter Kruse of the Danish security firm CSIS that first noticed Tinba.
Kruse is referring, of course, to another piece of malware being celebrated for its enormous size, Flame. Publicised in the same few days, the contrast between little and large is apt - and sobering.

Wednesday, May 30, 2012

The Flame Virus: Your Questions Answered !!

The Flame Virus: Your FAQs Answered
A frightening computer virus called Flame is on the loose in Iran and other parts of the Middle East, infecting PCs and stealing sensitive data. Now, the United Nations' International Telecommunications Union warns that other nations face the risk of attack.
But what is Flame, exactly, and is it cause for concern among ordinary PC users? Here's what you need to know about what Kaspersky calls “one of the most complex threats ever discovered.”

The Raven (2012) CAM 250 MB [Jumbofiles eXclusive], Click hare

Flame Virus: The Basics

Kaspersky describes Flame as a backdoor and a Trojan with worm-like features. The initial point of entry for the virus is unknown -- spearphishing or infected websites are possibilities -- but after the initial infection, the virus can spread through USB sticks or local networks.
Flame is meant to gather information from infected PCs. As Kaspersky's Vitaly Kamlyuk told RT, the virus can sniff out information from input boxes, including passwords hidden by asterisks, record audio from a connected microphone and take screenshots of applications that the virus deems important, such as IM programs. It can also collect information about nearby discoverable Bluetooth devices. The virus then uploads all this information to command and control servers, of which there are about a dozen scattered around the world.
The virus is reminiscent of the Stuxnet worm that wreaked havoc on Iran in 2010, but Kaspersky says Flame is much complex, with its modules occupying more than 20 MB of code. “Consider this: it took us several months to analyze the 500K code of Stuxnet. It will probably take year to fully understand the 20MB of code of Flame,” the firm said.

What Are Flame's Origins?

The Flame Virus: Your FAQs Answered
Flame has been in the wild since 2010, according to Kaspersky, but its creation date is unclear. The virus was discovered a month ago after Iran's oil ministry learned that several companies' servers had been attacked. That finding led to more evidence of attacks on other government ministries and industries in Iran.
Iran has claimed that the attacks also wiped the hard drives of some machines, but Kaspersky claims that the malware responsible, called Wiper, isn't necessarily related. Wiper attacks were isolated to Iran, while Flame has been found in other countries.
Flame's creator is also unknown, but a nation-state was likely behind it. The virus is not designed to steal money from bank accounts, and is much more complex than anything commonly used by “hacktivists,” so a nation-created virus is the only other possibility that makes sense.

Who is at Risk?

The United Nations' International Telecommunications Union is now warning other nations to “be on alert” for the virus, which could potentially be used to attack critical infrastructure. In a statement to Reuters, the U.S. Department of Homeland Security said it was “notified of the malware and has been working with our federal partners to determine and analyze its potential impact on the U.S.”
Security firms have not been warning of any direct risk to average Internet users. Sophos' Graham Cluley noted that Flame has only been discovered in a few hundred computers. “Certainly, it's pretty insignificant when you compare it to the 600,000 Mac computers which were infected by the Flashback malware earlier this year,” Cluley wrote in a blog post.

Sunday, May 13, 2012

Android PC Drive-by Malware Attack: Trojan Mimics

Researchers have noticed one of the first examples of Android "drive-by" malware from an ordinary website, a dangerous type of automatic attack more commonly used to infect Windows PCs.
Discovered by security company Lookout Mobile Security on a number of webistes, the decidedly odd "NotCompatible" Trojan is distributed using a web page containing a hidden iFrame.
Any Android browser visiting an affected page (the attack ignores PC browsers) will automatically start downloading the malware without the user being aware that this has happened. (See also "5 Free Android Security Apps: Keep Your Smartphone Safe.")
This isn't quite a PC drive-by attack because the user still needs to install the app, at which point it relies on the user having ticked the "Unknown Sources" box (in most cases this box would be unticked) that allows non-market apps to be installed.
The rough equivalent of this layer on a Vista or Windows 7 PC would be the User Access Control (UAC) which is usually circumvented using social engineering or by misrepresenting the nature of the application.
NotCompatible eschews such tricks beyond simply claiming to be a security update. It's not sophisticated but it might fool some users, some of the time.

Malware's Mission Unclear

The purpose of the infection is a bit of a mystery.
"This specific sample, while relatively well constructed, does not appear to go to great lengths to hide its intended purpose: it can be used to access private networks," said Lookout's blog.
"This feature in itself could be significant for system IT administrators: a device infected with NotCompatible could potentially be used to gain access to normally protected information or systems, such as those maintained by enterprise or government."
The affected sites appeared to have low volumes of traffic but the company believed the exploit iFrame was being served on other sites it had yet to identify, it said.
The warning is stark; mobile malware creators are experimenting with what is possible for this class of malware and have found a way to get mobile malware on to devices without them having to visit third-party app sites as has been the case up to now. 


Sunday, April 29, 2012

FBI Steps Up 'Internet Destruction' For You!!


FBI and Internet DoomsdayPC users infected with a strain of malware called DNS Changer will face their own personal Internet doomsday in July unless they disinfect their computers, the FBI warns.
Users have until July 9 to rid themselves of the DNS Changer malware, which can infect Windows PCs and Macs alike. After that, the FBI will throw a switch that prevents infected computers from accessing the Internet.
It's not as Big Brother as it sounds. DNS Changer is a Trojan that surfaced in 2007 and infected millions of machines. The malware would redirect computers to hacker-created Websites, where cyber-criminals sold at least $14 million in advertisements. DNS Changer also prevented computers from updating or using anti-virus software, leaving them vulnerable to even more malicious software.
Last November, in one of the biggest cybersecurity takedowns ever, the FBI arrested six Estonian nationals that allegedly ran the clickjacking fraud, and seized the rogue DNS servers where infected users were being redirected. The FBI has put up surrogate servers in place of the malicious ones, but only temporarily.
Now, the FBI wants to shut down those servers. Doing so would prevent infected PCs from reaching the Web, because they'll be trying to redirect through servers that no longer exist. Although the Feds aren't shutting down the Internet, they will be severing the link on which infected users have relied.
The FBI originally planned to shut down the malicious servers in March, but last month a federal judge ordered an extension to July to give users, businesses and governments more time to deal with DNS Changer. As of February, half of all Fortune 500 companies owned computers infected with DNS Changer, according security firm Tacoma. The DNS Changer Working Group estimates that more than 350,000 devices are still infected.
If users don't rid themselves of DNS Changer before the July 9 server shut down, they'll have to load anti-virus software on their computers by disc or USB drive. That could be a major headache for users who don't have access to a second PC for downloading anti-virus software.
To find out if you're infected, visit the DNS Changer Check-Up site, which checks the DNS resolution of your PC without installing any additional software. For infected users, the DNS Changer Working Group has a list of anti-virus software that can fix the problem, and Avira offers a repair tool specifically for DNS Changer.


Please Click Ads, To Support Us

For More Click Hare

Download Sexy Girls Images, Click Hare