<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and Privacy &#187; Exploits</title>
	<atom:link href="http://hijack-this.co.uk/category/exploits/feed/" rel="self" type="application/rss+xml" />
	<link>http://hijack-this.co.uk</link>
	<description>My ramblings on how to protect yourself online</description>
	<lastBuildDate>Thu, 01 Dec 2011 08:19:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Make sure your Java is up to date</title>
		<link>http://hijack-this.co.uk/2011/12/make-sure-your-java-is-up-to-date/</link>
		<comments>http://hijack-this.co.uk/2011/12/make-sure-your-java-is-up-to-date/#comments</comments>
		<pubDate>Thu, 01 Dec 2011 08:19:43 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security advice]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=600</guid>
		<description><![CDATA[&#160; Public Java Exploit Amps Up Threat Level — Krebs on Security: http://krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/?utm_source=feedburner&#38;utm_medium=feed&#38;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29 &#8220;An exploit for a recently disclosed Java vulnerability that was previously only available for purchase in the criminal underground has now been rolled into the open source Metasploit exploit framework. Metasploit researchers say the Java attack tool has been tested to successfully [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="mso-fareast-font-family: 'Times New Roman';"><span style="font-family: Times New Roman; font-size: small;">Public Java Exploit Amps Up Threat Level — Krebs on Security:<br />
</span><a href="http://krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">http://krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29</span></a><br />
<span style="font-family: Times New Roman; font-size: small;"><br />
&#8220;An exploit for a recently disclosed <strong>Java</strong> </span><a title="CVE-2011-3544" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3544" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">vulnerability</span></a><span style="font-family: Times New Roman; font-size: small;"> that was previously only available for purchase in the criminal underground has now been rolled into the open source </span><a href="http://metasploit.com/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">Metasploit</span></a><span style="font-family: Times New Roman; font-size: small;"> exploit framework. Metasploit researchers say the Java attack tool has been tested to successfully deliver payloads on a variety of platforms, including the latest <strong>Windows</strong>, <strong>Mac</strong> and <strong>Linux</strong> systems.&#8221;</p>
<p>&#8220;The exploit attacks </span><a title="NIST CVE Listing" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3544" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">a vulnerability</span></a><span style="font-family: Times New Roman; font-size: small;"> that exists in <em>Oracle Java SE JDK and JRE 7 and 6 Update 27</em> and earlier. If you are using <em>Java 6 Update 29</em>, or <em>Java 7 Update 1</em>, then you have </span><a title="KrebsOnSecurity: Critical Java Update Fixes 20<br />
      Flaws" href="http://hijack-this.co.uk/2011/10/critical-java-update-fixes-20-flaws/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">the latest version</span></a><span style="font-family: Times New Roman; font-size: small;"> that is patched against this and 19 other security threats. If you are using a vulnerable version of Java, it’s time to update. Not sure whether you have Java or what version you may be running? Check out </span><a title="Java Home<br />
      Page" href="http://java.com/en/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">this link</span></a><span style="font-family: Times New Roman; font-size: small;">, and then click the “Do I have Java?” link below the big red “Free Java Download” button. Apple </span><a href="http://krebsonsecurity.com/2011/11/adobe-apple-microsoft-mozilla-issue-critical-patches/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">issued its own update</span></a><span style="font-size: small;"><span style="font-family: Times New Roman;"> to fix this flaw and other Java bugs earlier this month.&#8221; </span></span></span></p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F12%2Fmake-sure-your-java-is-up-to-date%2F&amp;title=Make%20sure%20your%20Java%20is%20up%20to%20date" id="wpa2a_2"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/12/make-sure-your-java-is-up-to-date/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Fixit for Duqu 0 day exploit</title>
		<link>http://hijack-this.co.uk/2011/11/microsoft-fixit-for-dequ-0-day-exploit/</link>
		<comments>http://hijack-this.co.uk/2011/11/microsoft-fixit-for-dequ-0-day-exploit/#comments</comments>
		<pubDate>Fri, 04 Nov 2011 07:53:54 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security advice]]></category>
		<category><![CDATA[Tips & Settings]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=594</guid>
		<description><![CDATA[Temporary fixit &#38; workaround for 0 day exploit relating to duqu malware Fixit &#38; unfixit here http://support.microsoft.com/kb/2639658 Advisory with manual &#8220;fixes&#8221;  http://technet.microsoft.com/en-us/security/advisory/2639658 My considered advice is that you won&#8217;t need it and you should wait until Microsoft issue a full patch So far all attacks have been directly targetted against specific companies or Government departments,  That might change [...]]]></description>
			<content:encoded><![CDATA[<p>Temporary fixit &amp; workaround for 0 day exploit relating to duqu malware</p>
<p>Fixit &amp; unfixit here <a href="http://support.microsoft.com/kb/2639658">http://support.microsoft.com/kb/2639658</a></p>
<p>Advisory with manual &#8220;fixes&#8221;  <a href="http://technet.microsoft.com/en-us/security/advisory/2639658">http://technet.microsoft.com/en-us/security/advisory/2639658</a></p>
<p>My considered advice is that you won&#8217;t need it and you should wait until Microsoft issue a full patch<br />
So far all attacks have been directly targetted against specific companies or Government departments,  That might change as the skiddies get hold of the exploit</p>
<p>Using the fixit might make some applications/ word docs  or websites not display correctly ( or even at all )  if they use embedded True type fonts &amp; they haven&#8217;t been set to gracefully fall back on standard system fonts</p>
<p>If we start to see general attacks, then I will update this &amp; suggest using the fixit</p>
<p>An additional workaround to prevent Websites attacking you by using embedded fonts is to set Internet Explorer font downloads to prompt instead of allow . That way you at least get an alert if a font is being downloaded and you can make an educated opinion as to whether it is likely to be malicious</p>
<ul>
<li>Open Internet Explorer</li>
<li>On the Tools menu, click Options and then click the Security tab.</li>
<li>Select Custom and click Settings.</li>
<li>Scroll to the Downloads section.</li>
<li>Change the Font Download setting from  Enable to Prompt</li>
</ul>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F11%2Fmicrosoft-fixit-for-dequ-0-day-exploit%2F&amp;title=Microsoft%20Fixit%20for%20Duqu%200%20day%20exploit" id="wpa2a_4"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/11/microsoft-fixit-for-dequ-0-day-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>new Fake AV techniques</title>
		<link>http://hijack-this.co.uk/2011/07/new-fake-av-techniques/</link>
		<comments>http://hijack-this.co.uk/2011/07/new-fake-av-techniques/#comments</comments>
		<pubDate>Fri, 29 Jul 2011 17:21:26 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Security advice]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=558</guid>
		<description><![CDATA[http://xylibox.blogspot.com/2011/07/trojanfakeavlvt.html once you get past the colourful language from the analyst, it is a very good read &#38; shows what we are up against. Please forgive any errors in language as he doesn&#8217;t have English as a first language This particular one has the ability to replace your existing antivirus with itself &#38; make you [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://xylibox.blogspot.com/2011/07/trojanfakeavlvt.html">http://xylibox.blogspot.com/2011/07/trojanfakeavlvt.html</a></p>
<p>once you get past the colourful language from the analyst, it is a very good read &amp; shows what we are up against. Please forgive any errors in language as he doesn&rsquo;t have English as a first language</p>
<p>This particular one has the ability to replace your existing antivirus with itself &amp; make you think that you are still protected when you aren&rsquo;t and it installs Zero access rootkit</p>
<p>This is definitely something to watch out for</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F07%2Fnew-fake-av-techniques%2F&amp;title=new%20Fake%20AV%20techniques" id="wpa2a_6"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/07/new-fake-av-techniques/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 2011 Adobe updates</title>
		<link>http://hijack-this.co.uk/2011/06/june-2011-adobe-updates/</link>
		<comments>http://hijack-this.co.uk/2011/06/june-2011-adobe-updates/#comments</comments>
		<pubDate>Thu, 16 Jun 2011 14:15:44 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[adobe]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=526</guid>
		<description><![CDATA[As if you needed more updates this week&#8230; APSB11-16 &#8211; Security Advisory for Adobe Reader (v10.1) and Acrobat (v10.1 et al.) http://www.adobe.com/support/security/bulletins/apsb11-16.html APSB11-17 &#8211; Security Update Available for Adobe Shockwave Player v11.6.0.626 http://www.adobe.com/support/security/bulletins/apsb11-17.html APSB11-18 &#8211; [Yes, yet another] Security update available for Adobe Flash&#160; Player (v10.3.181.26) http://www.adobe.com/support/security/bulletins/apsb11-18.html]]></description>
			<content:encoded><![CDATA[<p>As if you needed more updates this week&#8230;</p>
<p>APSB11-16 &#8211; Security Advisory for Adobe Reader (v10.1) and Acrobat (v10.1 et al.)<br />
	<a href="http://www.adobe.com/support/security/bulletins/apsb11-16.html" target="_blank">http://www.adobe.com/support/security/bulletins/apsb11-16.html</a></p>
<p>APSB11-17 &#8211; Security Update Available for Adobe Shockwave Player v11.6.0.626<br />
	<a href="http://www.adobe.com/support/security/bulletins/apsb11-17.html" target="_blank">http://www.adobe.com/support/security/bulletins/apsb11-17.html</a></p>
<p>APSB11-18 &#8211; [Yes, yet another] Security update available for Adobe Flash&nbsp; Player (v10.3.181.26)<br />
	<a href="http://www.adobe.com/support/security/bulletins/apsb11-18.html" target="_blank">http://www.adobe.com/support/security/bulletins/apsb11-18.html</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F06%2Fjune-2011-adobe-updates%2F&amp;title=June%202011%20Adobe%20updates" id="wpa2a_8"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/06/june-2011-adobe-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another new URGENT Adobe flash security update</title>
		<link>http://hijack-this.co.uk/2011/06/another-new-urgent-adobe-flash-security-update/</link>
		<comments>http://hijack-this.co.uk/2011/06/another-new-urgent-adobe-flash-security-update/#comments</comments>
		<pubDate>Mon, 06 Jun 2011 08:24:34 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[adobe]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=499</guid>
		<description><![CDATA[http://www.adobe.com/support/security/bulletins/apsb11-13.html An important vulnerability has been identified in Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.3.185.22 and earlier versions for Android. This universal cross-site scripting vulnerability (CVE-2011-2107) could be used to take actions on a user&#8217;s behalf on any website or webmail provider, if the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.adobe.com/support/security/bulletins/apsb11-13.html" target="_blank">http://www.adobe.com/support/security/bulletins/apsb11-13.html</a><br />
An important vulnerability has been identified in Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.3.185.22 and earlier versions for Android. This universal cross-site scripting vulnerability (CVE-2011-2107) could be used to take actions on a user&#8217;s behalf on any website or webmail provider, if the user visits a malicious website. There are reports that this vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message.<br />
Adobe recommends users of Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris update to Adobe Flash Player 10.3.181.22 (10.3.181.23 for ActiveX). Adobe expects to make available an update for Flash Player 10.3.185.22 for Android during the week of June 6, 2011.</p>
<p>Adobe is still investigating the impact to the Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.2) and earlier 10.x and 9.x versions of Adobe Reader and Acrobat for Windows and Macintosh operating systems. Adobe is not aware of any attacks targeting Adobe Reader or Acrobat in the wild.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F06%2Fanother-new-urgent-adobe-flash-security-update%2F&amp;title=Another%20new%20URGENT%20Adobe%20flash%20security%20update" id="wpa2a_10"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/06/another-new-urgent-adobe-flash-security-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cybercriminals Hoping You’ll Bite iPhone 5 Bait</title>
		<link>http://hijack-this.co.uk/2011/05/cybercriminals-hoping-you%e2%80%99ll-bite-iphone-5-bait/</link>
		<comments>http://hijack-this.co.uk/2011/05/cybercriminals-hoping-you%e2%80%99ll-bite-iphone-5-bait/#comments</comments>
		<pubDate>Wed, 25 May 2011 07:20:24 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Iphone]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[fake software]]></category>
		<category><![CDATA[keylogger]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=480</guid>
		<description><![CDATA[Online criminals know there are enough gadget hounds out there to make a scam surrounding any shiny new Apple device a surefire moneymaker. To that end, they’ve already begun sending out phishing emails for the iPhone 5. The phishing emails appear to be official emails from Apple.com, with the title “Finally. The amazing iPhone 5. [...]]]></description>
			<content:encoded><![CDATA[<p>Online criminals know there are enough gadget hounds out there to make a scam surrounding any shiny new Apple device a surefire moneymaker. To that end, they’ve already begun sending out phishing emails for the iPhone 5.</p>
<p>The phishing emails appear to be official emails from Apple.com, with the title “Finally. The amazing iPhone 5. Now available in black edition.” The body of the message shows a hand holding a transparent iPhone, followed by an enticing offer to “check it out,” according to <a title="MacRumors" href="http://www.macrumors.com/2011/05/22/phishing-and-malware-emails-posing-as-apple-and-the-iphone-5-launch/" target="_blank">MacRumors</a>.</p>
<p>Although there’s been much speculation about the next generation iPhone, Apple has not set a release date for it. In fact, Apple hasn’t even announced it yet, but that isn’t stopping this cleverly crafted Mac-themed scam from spreading.</p>
<p>So what are you checking out when you click the link to see the new iPhone 5?</p>
<p>You won’t receive any info about the smartphone, but you will enable a rigged Windows file to run malicious code on your computer. And you’ll also be taken to a phony Apple Web page that asks for your Apple ID and other sensitive information.</p>
<p>Apple announces new products, especially ones of this magnitude, in highly publicized press conferences. So if you receive an unsolicited email purporting to have information about the new iPhone 5, ignore it, DELETE IT WITHOUT EVEN READING IT.</p>
<p>story from: <a href="http://www.securitynewsdaily.com/cybercriminals-hoping-youll-bite-iphone-5-bait-0813/">http://www.securitynewsdaily.com/cybercriminals-hoping-youll-bite-iphone-5-bait-0813/</a></p>
<p>This malware is quite well detected by many antivirus companies, but not all. It is a fairly standard Zapchast IRC trojan that will attempt to download lots of other crap &amp; malware to your computer.</p>
<p>It also appears to try to  perform a DDOS flood attack against several other competing Mirc users and channels to block their channels, so no doubt will turn out to be connected to the typical fake AV scams and stealing your money</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F05%2Fcybercriminals-hoping-you%25e2%2580%2599ll-bite-iphone-5-bait%2F&amp;title=Cybercriminals%20Hoping%20You%E2%80%99ll%20Bite%20iPhone%205%20Bait" id="wpa2a_12"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/05/cybercriminals-hoping-you%e2%80%99ll-bite-iphone-5-bait/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>new malware spam- order.zip</title>
		<link>http://hijack-this.co.uk/2011/05/new-malware-spam-order-zip/</link>
		<comments>http://hijack-this.co.uk/2011/05/new-malware-spam-order-zip/#comments</comments>
		<pubDate>Tue, 10 May 2011 11:07:51 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=462</guid>
		<description><![CDATA[There is a new spam bot out there sending a malware link. see  screenshot all emails so far appear to originate from a Ukrainian server noc.maximuma.net  91.196.148.8  which may or may not have been hacked, but web searches suggest that lots of spam &#38; malware is being distributed via that server hosting company So far I [...]]]></description>
			<content:encoded><![CDATA[<div>There is a new spam bot out there sending a malware link. see  screenshot</div>
<div>
<div id="attachment_463" class="wp-caption aligncenter" style="width: 310px"><a class="thickbox" rel="462" href="http://hijack-this.co.uk/wp-content/uploads/2011/05/order.jpg" ><img class="size-medium wp-image-463" title="order" src="http://hijack-this.co.uk/wp-content/uploads/2011/05/order-300x148.jpg" alt="screen shot of spam email" width="300" height="148" /></a><p class="wp-caption-text">screenshot of typical spam email </p></div>
</div>
<div>all emails so far appear to originate from a Ukrainian server noc.maximuma.net  91.196.148.8  which may or may not have been hacked, but web searches suggest that lots of spam &amp; malware is being distributed via that server hosting company</div>
<div>So far I have seen several different sites hosting the malware and the senders &amp; recipient email addresses are all random or spoofed</div>
<div>At present antivirus detection is very sporadic but samples have been sent to all known AV companies  so I do expect a better detection rate very shortly</div>
<div>The current payload is always order.zip, which when extracted pretends to be order.doc  but has a lot of spaces then .exe so simply clicking on it will infect you</div>
<div>It appears to be a downloader or installer for one of the fake Antivirus programs, that currently plague us.</div>
<div>You can see a quick automatic  analysis on the <a title="Anubis website" href="http://anubis.iseclab.org/?action=result&amp;task_id=176c30921b571e7c405639cb597aeeefa&amp;format=html" target="_blank"><span style="color: #0000ff;">Anubis website</span></a> From previous experience of this sort of malware and the locations it installs itself to , I would not be at all surprised if the malware shown in the Anubis report also installs the TDL4 bootkit</div>
<div>Update: they have changed the email slightly to something that resembles a previous attack attempt and included a &#8220;your  credit card will be charged with xxxxx $</div>
<div>That always gets the unwary to follow the link, to check if it is their card that has been falsely charged</div>
<div>
<div id="attachment_469" class="wp-caption aligncenter" style="width: 310px"><a class="thickbox" rel="462" href="http://hijack-this.co.uk/wp-content/uploads/2011/05/order2.jpg" ><img class="size-medium wp-image-469" title="order2" src="http://hijack-this.co.uk/wp-content/uploads/2011/05/order2-300x216.jpg" alt="" width="300" height="216" /></a><p class="wp-caption-text">Revised updated email, showing alleged credit card charge</p></div>
<p>Results are coming in from many antivirus companies now, saying that it is a version of the spyeyes crimeware toolkit. Spyeyes is well described  in this <a title="Symantec Blog" href="http://www.symantec.com/connect/blogs/spyeye-bot-versus-zeus-bot" target="_blank"><span style="color: #0000ff;">Symantec blog</span></a></p>
<p>&nbsp;</p>
</div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F05%2Fnew-malware-spam-order-zip%2F&amp;title=new%20malware%20spam-%20order.zip" id="wpa2a_14"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/05/new-malware-spam-order-zip/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Microsoft is aware of nine fraudulent digital certificates issued by Comodo</title>
		<link>http://hijack-this.co.uk/2011/03/microsoft-is-aware-of-nine-fraudulent-digital-certificates-issued-by-comodo/</link>
		<comments>http://hijack-this.co.uk/2011/03/microsoft-is-aware-of-nine-fraudulent-digital-certificates-issued-by-comodo/#comments</comments>
		<pubDate>Wed, 23 Mar 2011 17:50:02 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Skype]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=456</guid>
		<description><![CDATA[The full advisory can be found on the Web at: http://www.microsoft.com/technet/security/advisory/2524375.mspx. =========================== SUMMARY =========================== Microsoft is aware of nine fraudulent digital certificates issued by Comodo, a certification authority present in the Trusted Root Certification Authorities Store on all supported versions of Microsoft Windows. Comodo advised Microsoft on March 16, 2011 that nine certificates had been [...]]]></description>
			<content:encoded><![CDATA[<p>The full advisory can be found on the Web at: <a href="http://www.microsoft.com/technet/security/advisory/2524375.mspx">http://www.microsoft.com/technet/security/advisory/2524375.mspx</a>.</p>
<p>===========================<br />
SUMMARY<br />
===========================<br />
Microsoft is aware of nine fraudulent digital certificates issued by Comodo, a certification authority present in the Trusted Root Certification Authorities Store on all supported versions of Microsoft Windows. Comodo advised Microsoft on March 16, 2011 that nine certificates had been signed on behalf of a third party without sufficiently validating its identity. These certificates may be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against all Web browser users including users of Internet Explorer.</p>
<p>Certificates for the following Web properties are affected:</p>
<p>• login.live.com<br />
• mail.google.com<br />
•www.google.com<br />
• login.yahoo.com (3 certificates)<br />
• login.skype.com<br />
• addons.mozilla.org<br />
• &#8220;Global Trustee&#8221;</p>
<p>Comodo has revoked these certificates, and they are listed in Comodo’s current Certificate Revocation List (CRL). In addition, browsers which have enabled the Online Certificate Status Protocol (OCSP) will interactively validate these certificates and block them from being used.</p>
<p>An update is available for all supported versions of Windows to help address this issue. For more information about this update, see Microsoft Knowledge Base Article 2524375 (<a href="http://support.microsoft.com/kb/2524375">http://support.microsoft.com/kb/2524375</a>).</p>
<p>Typically, no action is required of customers to install this update, because the majority of customers have automatic updating enabled and this update will be downloaded and installed automatically. For more information, including how to manually install this update, see the Suggested Actions section of this advisory.</p>
<p>===========================<br />
RECOMMENDATIONS<br />
===========================<br />
Review Microsoft Security Advisory 2524375 for an overview of the issue, details on affected components, suggested actions, frequently asked questions (FAQ), and links to additional resources. MSRA Security Partners who are experiencing issues believed to be related to the issues described in this advisory should contact us via e-mail or by calling 888-HELPSEC with your custom Access ID.</p>
<p>===========================<br />
ADDITIONAL RESOURCES<br />
===========================<br />
• Microsoft Security Advisory 2524375 – Fraudulent Digital Certificates Could Allow Spoofing –<a href="http://www.microsoft.com/technet/security/advisory/2524375.mspx">http://www.microsoft.com/technet/security/advisory/2524375.mspx</a></p>
<p>• Microsoft Security Response Center (MSRC) Blog: <a href="http://blogs.technet.com/msrc">http://blogs.technet.com/msrc</a></p>
<p>More details on <a href="http://blogs.comodo.com/it-security/data-security/the-recent-ca-compromise/" target="_blank">Comodo blog</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F03%2Fmicrosoft-is-aware-of-nine-fraudulent-digital-certificates-issued-by-comodo%2F&amp;title=Microsoft%20is%20aware%20of%20nine%20fraudulent%20digital%20certificates%20issued%20by%20Comodo" id="wpa2a_16"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/03/microsoft-is-aware-of-nine-fraudulent-digital-certificates-issued-by-comodo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The problem with the Prefetch function in Firefox and Chrome</title>
		<link>http://hijack-this.co.uk/2011/01/the-problem-with-the-prefetch-function-in-firefox-and-chrome/</link>
		<comments>http://hijack-this.co.uk/2011/01/the-problem-with-the-prefetch-function-in-firefox-and-chrome/#comments</comments>
		<pubDate>Mon, 31 Jan 2011 11:01:23 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[protection]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=421</guid>
		<description><![CDATA[Did you know that Firefox and Chrome both have a feature that fetches pages and links that it thinks you might be going to click on? This can slow down your computer and browsing dramatically. The majority of problems come up when using a search engine, particularly Google with its &#8220;preview function&#8221;. The pre-fetch function [...]]]></description>
			<content:encoded><![CDATA[<p>Did you know that Firefox and Chrome both have a feature that fetches pages and links that it thinks you might be going to click on? This can slow down your computer and browsing dramatically. The majority of problems come up when using a search engine, particularly Google with its &#8220;preview function&#8221;.<br />
The pre-fetch function in these browsers silently loads every link in the background and caches ( stores) the pages in your internet temporary files folder used by Firefox or Chrome. So far Internet Explorer has resisted the temptation to do this.<br />
<strong>It also has another major problem when using security software that blocks dangerous or known malicious IP numbers or web addresses</strong>. You either get constant alerts about malicious pages attempting to infiltrate your computer or pop up warnings saying xxxx address or IP number has been blocked. Some security softwares will block you from the original page that you are attempting to visit because of the preloaded link to a potentially malicious site, that can lead to major problems with search engines. In 99% of the time, you have absolutely no intention of ever visisting that site, it is just Firefox or Chrome being <em>helpful</em> and preloading the pages for you<span id="more-421"></span></p>
<p><strong>Here’s how to disable the Firefox prefetch setting</strong>.</p>
<p>1. Type about:config in the address bar and press ENTER. Agree to the warning that changing settings can cause problems</p>
<p>2. Locate and double-click the entry for<br />
network.prefetch-next</p>
<p>3. Set it to false to disable this feature. Double-clicking on the setting will change it.</p>
<div id="attachment_432" class="wp-caption alignleft" style="width: 649px"><img class="size-full wp-image-432 " title="FF_disable-prefetch" src="http://hijack-this.co.uk/wp-content/uploads/2011/01/FF_disable-prefetch.png" alt="" width="639" height="504" /><p class="wp-caption-text">How to disable prefetch in Firefox</p></div>
<p><strong>This is how to disable the prefetch function in Chrome:</strong><br />
1. Click the wrench in the upper-right corner.</p>
<p>2. Select Options<br />
<img class="aligncenter size-full wp-image-425" title="chrome_select_options" src="http://hijack-this.co.uk/wp-content/uploads/2011/01/chrome_select_options.gif" alt="" width="247" height="256" /><br />
3. Select the Under the hood tab.</p>
<p>4. Uncheck &#8220;Use DNS pre-fetching to improve page load performance&#8221; . and then close the options page</p>
<div id="attachment_426" class="wp-caption aligncenter" style="width: 510px"><img class="size-full wp-image-426" title="chrome_disable_prefetch" src="http://hijack-this.co.uk/wp-content/uploads/2011/01/chrome_disable_prefetch.png" alt="" width="500" height="534" /><p class="wp-caption-text">Disable prefetch in Chrome</p></div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F01%2Fthe-problem-with-the-prefetch-function-in-firefox-and-chrome%2F&amp;title=The%20problem%20with%20the%20Prefetch%20function%20in%20Firefox%20and%20Chrome" id="wpa2a_18"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/01/the-problem-with-the-prefetch-function-in-firefox-and-chrome/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Beware of New year e-cards</title>
		<link>http://hijack-this.co.uk/2011/01/beware-of-new-year-e-cards/</link>
		<comments>http://hijack-this.co.uk/2011/01/beware-of-new-year-e-cards/#comments</comments>
		<pubDate>Sat, 01 Jan 2011 17:18:00 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[fake software]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[protection]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=412</guid>
		<description><![CDATA[Please avoid all untrusted Happy New Year e-card links. The Shadowserver Foundation is warning of a new malicious and advanced botnet that has just been discovered and ressembles the Storm Worm designs. New Fast Flux Botnet for the Holidays: Could it be Storm Worm 3.0/Waledac 2.0? http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20101230 Those of us here at Shadowserver hope you&#8217;re [...]]]></description>
			<content:encoded><![CDATA[<p>Please avoid all untrusted Happy New Year e-card links.  The Shadowserver Foundation is warning of a new malicious and advanced botnet that has just been discovered and ressembles the Storm Worm designs.</p>
<p>New Fast Flux Botnet for the Holidays: Could it be Storm Worm 3.0/Waledac 2.0?<br />
<a href="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20101230">http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20101230</a><br />
Those of us here at Shadowserver hope you&#8217;re having a wonderful holiday season and are ready to bring in the new year. We were trying to relax and enjoy relatively quiet times until we noticed a new spam campaign that recently started. At first it looked like your regular old holiday e-card scams that have been around for years. </p>
<p>However, upon closer inspection it looks like we could be dealing with the next generation of Storm Worm or Waledac. If you consider Waledac to be Storm Worm 2.0, this looks like it could be version 3.0 or at least Waledac 2.0. There are no real version numbers of course, but we don&#8217;t have anything else to call it yet. What&#8217;s it involve you ask? </p>
<p> CHARACTERISTICS OF NEW BOTNET </p>
<p>Well here&#8217;s the list of what we&#8217;ve seen so far: </p>
<p>* Large scale Spam campaigns sending out e-mails with links<br />
* New malicious domains that are fast flux! (TTL of 0 and name servers that frequently update IPs)<br />
* Links are to several hacked websites hosting HTML pages that refresh to new malicious domains<br />
* Links are also directly to new malicious domains<br />
* Malicious domains hosting links to fake flash player and refreshes to exploit pages<br />
* Malware installs that begin beaching to several hosts over HTTP (what we dubbed HTTP2p with Waledac)<br />
* Malware that&#8217;s been updated to look a bit more like legitimate than past variants<br />
* A very buggy network that is not often available (upstream devices not available)<br />
* Changing/Updated binaries</p>
<p>  AVOID THESE E-CARD MESSAGES: </p>
<p>Let&#8217;s start with the Spam Campaign. We&#8217;ve seen a multitude of subject lines and bodies. Below you&#8217;ll find a list of subjects we&#8217;ve seen and an example e-mail message. These are coming from all over the Internet with spoofed sender addresses. </p>
<p> Greeting for you!<br />
 Greeting you with heartiest New Year wishes<br />
 Greetings to You<br />
 Happy New Year greetings e-card is waiting for you<br />
 Happy New Year greetings for you<br />
 Happy New Year greetings from your friend<br />
 Have a happy and colorful New Year!<br />
 l want to share Greeting with you<br />
 New Year 2011 greetings for you<br />
 You have a greeting card<br />
 You have a New Year Greeting!<br />
 You have received a greetings card<br />
 You&#8217;ve got a Happy New Year Greeting Card!</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F01%2Fbeware-of-new-year-e-cards%2F&amp;title=Beware%20of%20New%20year%20e-cards" id="wpa2a_20"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/01/beware-of-new-year-e-cards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

