Hundreds of infected machines per hour

November 24th, 2007 No Comments »

A new MSN Messenger botnet is growing by hundreds of computers per hour.   This Trojan is another IRC bot variant that is spreading through MSN Messenger by sending itself in a zip file under two file names, both masquerading as digital camera images, one ending with .exe and the other with .pif.  These attachments may come through messages from a known contact on your “buddy list”.   This is the first Trojan found to date that scans for VNC connections (remote access) likely looking to increase the botnet’s number of connections.

Tags: , ,

Author: Christopher

(No Ratings Yet)
Loading ... Loading ...

Microsoft finally patches URI handling flaws

November 14th, 2007 No Comments »

If you heard of maliciously rigged PDF files, then you probably have been waiting for Microsoft to patch this vulnerability that they originally blamed FireFox for back in July. Known attack vectors exist in these applications while used with Internet Explorer 7:

  • Mozilla Firefox (2.0.0.5 and lower)
  • Skype (3.5.0.238 and lower)
  • Adobe Acrobat 8.1
  • Miranda 0.7
  • Netscape 7.1
  • MIRC chat for windows

Back early in October, Microsoft released Security Advisory 943521 about the vulnerability and reports of remote code execution with the promise of a new patch. As of today, the patch is released as security bulletin MS07-061.

Windows XP & Windows 2003 Servers using Internet Explorer 7 should update as soon as possible to this patch.

Tags: ,

Author: Christopher

(No Ratings Yet)
Loading ... Loading ...

Top 5 Hacker Attacks - October 2007

November 9th, 2007 No Comments »

Top 5 attacks used by U.S. hackers

  1. Internet Explorer 6 Buffer Overflow
  2. Generic File Inclusion
  3. Mambo register_globals Emulation Layer Overwrite
  4. Microsoft Windows COM Object Handling Vulnerability
  5. Internet Explorer HTML Help Remote Code Execution

Top 5 Attacks used by Foreign hackers

  1. HTTP overflow attack
  2. Generic File Inclusion
  3. WebDAV Overflow Attempt
  4. Mambo register_globals Emulation Layer Overwrite
  5. phpBB Activity Module File Inclusion
Tags: , ,

Author: Christopher

(No Ratings Yet)
Loading ... Loading ...

Virus Top 20 for October 2007

November 2nd, 2007 No Comments »
  • Email-Worm.Win32.NetSky.q
  • Trojan-Spy.HTML.Fraud.ay
  • Email-Worm.Win32.NetSky.aa
  • Worm.Win32.Feebs.gen
  • Email-Worm.Win32.Mydoom.l
  • Exploit.Win32.PDF-URI.k
  • Email-Worm.Win32.NetSky.t
  • Email-Worm.Win32.Bagle.gt
  • Email-Worm.Win32.Nyxem.e
  • Net-Worm.Win32.Mytob.c
  • Email-Worm.Win32.NetSky.x
  • Email-Worm.Win32.Scano.gen
  • Net-Worm.Win32.Mytob.t
  • Virus.Win32.Virut.a
  • Net-Worm.Win32.Mytob.u
  • Email-Worm.Win32.LovGate.w
  • Net-Worm.Win32.Mytob.dam
  • Exploit.Win32.IMG-WMF.y
  • Trojan-Spy.HTML.Paylap.bg

Data from Kaspersky Lab

Tags: ,

Author: Christopher

(No Ratings Yet)
Loading ... Loading ...