<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and PrivacyMalware</title>
	<atom:link href="http://hijack-this.co.uk/category/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://hijack-this.co.uk</link>
	<description>My ramblings on how to protect yourself online</description>
	<lastBuildDate>Thu, 12 Aug 2010 07:31:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Fake Microsoft Malicious Software Removal tool</title>
		<link>http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/</link>
		<comments>http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/#comments</comments>
		<pubDate>Wed, 11 Aug 2010 16:57:37 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[scams]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=311</guid>
		<description><![CDATA[It was brought to my attention by sUBs, a malware researcher who developed Combofix ( a tool to help remove persistant malware threats &#38; rogue scamware from infected computers) that a fake Microsoft malicious software removal tool is spreading This total piece of scamware is designed to imitate the genuine MMSRT &#38; has the usual [...]]]></description>
			<content:encoded><![CDATA[<p>It was brought to my attention by sUBs, a malware researcher who developed Combofix ( a tool to help remove persistant malware threats &amp; rogue scamware from infected computers) that a fake Microsoft malicious software removal tool is spreading<br />
This total piece of scamware is designed to imitate the genuine MMSRT &amp; has the usual fake detections &amp; then entices you buy the latest rogue scamware Shield EC Antivirus which our good friends <a href="http://sunbeltblog.blogspot.com/2010/07/shield-ec-rogue-security-product-that.html" target="_blank">Sunbelt Software have blogged about.</a><br />
The last screen clearly shows that they want you to buy this useless scamware</p>

<a href='http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/rogue_1/' title='Rogue_1'><img width="150" height="106" src="http://hijack-this.co.uk/wp-content/uploads/2010/08/Rogue_1-150x106.png" class="attachment-thumbnail" alt="Rogue_1" title="Rogue_1" /></a>
<a href='http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/rogue_1a/' title='Rogue_1A'><img width="150" height="137" src="http://hijack-this.co.uk/wp-content/uploads/2010/08/Rogue_1A-150x137.png" class="attachment-thumbnail" alt="Rogue_1A" title="Rogue_1A" /></a>
<a href='http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/rogue_1b/' title='Rogue_1B'><img width="150" height="137" src="http://hijack-this.co.uk/wp-content/uploads/2010/08/Rogue_1B-150x137.png" class="attachment-thumbnail" alt="Rogue_1B" title="Rogue_1B" /></a>
<a href='http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/rogue_1c/' title='Rogue_1C'><img width="150" height="137" src="http://hijack-this.co.uk/wp-content/uploads/2010/08/Rogue_1C-150x137.png" class="attachment-thumbnail" alt="Rogue_1C" title="Rogue_1C" /></a>

<p>The installer for this piece of malware is detected by several Antiviruses currently as shown on this <a href="http://www.virustotal.com/file-scan/report.html?id=73b0e3dc9a74f97892194efe47886957232a2e72374a0a57bccb64b81bff29e6-1281535897" target="_blank">Virus Total </a>report page</p>
<p>If you are unfortunate to be infected by this piece of scamware, it can be difficult to remove. Don&#8217;t fall for all the other scams on the net saying you need to buy other software to remove it. Ask for help on our malware cleaning forum <a href="http://thespykiller.co.uk" target="_blank">http://thespykiller.co.uk</a></p>
By the time  your rss reader get this post here is <strong> 1 </strong>comments ,Welcome you come to leave your opinion !<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/08/fake-microsoft-malicious-software-removal-tool/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Microsoft Security Response Center (MSRC) : Investigating a new win32hlp and Internet Explorer issue:</title>
		<link>http://hijack-this.co.uk/2010/03/the-microsoft-security-response-center-msrc-investigating-a-new-win32hlp-and-internet-explorer-issue/</link>
		<comments>http://hijack-this.co.uk/2010/03/the-microsoft-security-response-center-msrc-investigating-a-new-win32hlp-and-internet-explorer-issue/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 07:18:34 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[microsoft]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=291</guid>
		<description><![CDATA[The Microsoft Security Response Center (MSRC) : Investigating a new win32hlp and Internet Explorer issue: http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx Hi everyone, On Friday 2/26/2010, an issue was posted publicly that could allow an attacker to host a maliciously crafted web page and run arbitrary code if they could convince a user to visit the web page and then [...]]]></description>
			<content:encoded><![CDATA[<p>The Microsoft Security Response Center (MSRC) : Investigating a new win32hlp and Internet Explorer issue:</p>
<p><a href="http://" target="_blank">http://blogs.technet.com/msrc/archive/2010/02/28/investigating-a-new-win32hlp-and-internet-explorer-issue.aspx</a></p>
<p>Hi everyone,<br />
On Friday 2/26/2010, an issue was posted publicly that could allow an attacker to host a maliciously crafted web page and run arbitrary code if they could convince a user to visit the web page and then get them to press the F1 key in response to a pop up dialog box. We are not aware of any attacks seeking to exploit this issue at this time and in the current state of our investigation, we have determined that users running Windows 7, Windows Server 2008 R2, Windows Server 2008, and Windows Vista, are not affected by this issue.<span id="more-291"></span></p>
<p>The issue in question involves the use of VBScript and Windows Help files in Internet Explorer. Windows Help files are included in a long list of what we refer to as “unsafe file types”. These are file types that are designed to invoke automatic actions during normal use of the files. While they can be very valuable productivity tools, they can also be used by attackers to try and compromise a system. To help customers better understand unsafe file types, we have published a white paper on the topic which you can find by clicking this link.<br />
Once we have completed our investigation, we will take appropriate action to protect customers. To minimize risk to computer users, Microsoft continues to encourage responsible disclosure. Reporting vulnerabilities directly to vendors without further disclosure helps ensure that customers receive comprehensive, high-quality updates before cyber criminals learn of – and work to exploit – a vulnerability. Responsible disclosure protects the computer ecosystem and individual computer users from harm.<br />
Anyone believed to have been affected can visit: <a href="http://" target="_blank">http://www.microsoft.com/protect/support/default.mspx</a> and should contact the national law enforcement agency in their country. Those in the United States can contact Customer Service and Support at no charge (for computer security related issues) using the PC Safety hotline at 1-866-727-2338 (PCSAFETY). Customers outside of the United States can visit <a href="http://" target="_blank">http://support.microsoft.com/international</a> to find local support information.<br />
We continue to encourage customers to follow the “Protect Your Computer” guidance of enabling a firewall, applying all software updates and installing anti-virus and anti-spyware software. Additional information can be found at: <a href="http://" target="_blank">www.microsoft.com/protect</a>.<br />
We will provide more information on this issue as it becomes available.<br />
Thanks,<br />
Jerry Bryant<br />
Sr. Security Communications Manager Lead<br />
*This posting is provided &#8220;AS IS&#8221; with no warranties, and confers no rights.*</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/03/the-microsoft-security-response-center-msrc-investigating-a-new-win32hlp-and-internet-explorer-issue/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Advisory 979682 Released</title>
		<link>http://hijack-this.co.uk/2010/01/security-advisory-979682-released/</link>
		<comments>http://hijack-this.co.uk/2010/01/security-advisory-979682-released/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 09:37:24 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=282</guid>
		<description><![CDATA[Security Advisory 979682 Released Today we released Security Advisory 979682 to address an Elevation of Privilege (EoP) vulnerability in the Windows kernel, affecting all currently supported versions of 32-bit Windows. 64-bit versions of Windows, including Windows Server 2008 R2, are not affected. The advisory provides customers with actionable guidance to help with protections against exploit [...]]]></description>
			<content:encoded><![CDATA[<h2>Security Advisory 979682 Released</h2>
<p>Today we released <a href="http://www.microsoft.com/technet/security/advisory/979682.mspx" target="_blank">Security Advisory 979682</a> to address an Elevation of Privilege (EoP) vulnerability in the Windows kernel, affecting all currently supported versions of 32-bit Windows.<strong> 64-bit versions of Windows, including Windows Server 2008 R2, are not affected</strong>. The advisory provides customers with actionable guidance to help with protections against exploit of this vulnerability.</p>
<p>To exploit this vulnerability, an attacker must already have valid logon credentials and be able to log on to a system locally, meaning they must already have an account on the system. An attacker could then elevate their privileges to the administrative level and run programs of their choice on the system.</p>
<p>To help mitigate exploit of this vulnerability, customers who do not require NT Virtual DOS Mode (NTVDM) or support for 16-bit applications, can disable the NTVDM subsystem. Information on this workaround can be found in the Advisory.</p>
<p>We are not currently aware of any active attacks against this vulnerability and believe risk to customers, at this time, is limited. We continue to recommend customers review the mitigations and workarounds detailed in the Security Advisory.</p>
<p>We are also working with our <a href="http://www.microsoft.com/security/msrc/mapp/overview.mspx" target="_blank">Microsoft Active Protections Program (MAPP)</a> <a name="_GoBack"></a>partners to help provide broader protections for customers.</p>
<p>Our teams are continuing to work on an update and we will take appropriate action to protect customers when the update has met the quality bar for broad distribution. That may include releasing the update out-of-band.</p>
<p>The Security Advisory will be updated with any new developments so if you are not already subscribed to our <a href="http://technet.microsoft.com/en-us/security/dd252948.aspx" target="_blank">comprehensive alerts</a>, please do so in order to be alerted by email when new information is added.</p>
<p>We will also keep customers apprised of any additional details and updates through the <a href="http://blogs.technet.com/msrc" target="_blank">MSRC Blog.</a></p>
<p>Thanks,</p>
<p>Jerry Bryant</p>
<p>via <a href="http://blogs.technet.com/msrc/archive/2010/01/20/security-advisory-979682-released.aspx" target="_blank">http://blogs.technet.com/msrc/archive/2010/01/20/security-advisory-979682-released.aspx</a></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/01/security-advisory-979682-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Warning IE 0 day exploit</title>
		<link>http://hijack-this.co.uk/2010/01/warning-ie-0-day-exploit/</link>
		<comments>http://hijack-this.co.uk/2010/01/warning-ie-0-day-exploit/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 09:15:55 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[microsoft]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/2010/01/warning-ie-0-day-exploit/</guid>
		<description><![CDATA[http://siblog.mcafee.com/cto/operation-%E2%80%9Caurora%E2%80%9D-hit-google-others/ http://www.avertlabs.com/research/blog/index.php/2010/01/14/more-details-on-operation-aurora/ http://www.microsoft.com/technet/security/advisory/979352.mspx I will  keep you posted when I hear more best advice at this time is make sure antivirus is updated to protect, watch where you surf &#38; consider an alternative browser or set IE protection to high However bear in mind these have all been targeted attacks against specific companies &#38; institutions [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://siblog.mcafee.com/cto/operation-%E2%80%9Caurora%E2%80%9D-hit-google-others/" target="_blank">http://siblog.mcafee.com/cto/operation-%E2%80%9Caurora%E2%80%9D-hit-google-others/</a></p>
<p><a href="http://www.avertlabs.com/research/blog/index.php/2010/01/14/more-details-on-operation-aurora/" target="_blank">http://www.avertlabs.com/research/blog/index.php/2010/01/14/more-details-on-operation-aurora/</a></p>
<p><a href="http://www.microsoft.com/technet/security/advisory/979352.mspx" target="_blank">http://www.microsoft.com/technet/security/advisory/979352.mspx</a></p>
<p>I will  keep you posted when I hear more</p>
<p>best advice at this time is make sure antivirus is updated to protect, watch where you surf &amp; consider an alternative browser or set IE protection to high</p>
<p>However bear in mind these have all been targeted attacks against specific companies &amp; institutions so less likely to affect the average user, at least until the skiddies get their hands on the exploit</p>
<p>OK if you are still using IE 6 or 7 on any version of windows</p>
<p>use the fixit Microsoft have issued <a href="http://support.microsoft.com/kb/979352" target="_blank">http://support.microsoft.com/kb/979352</a></p>
<p><strong>You do not need this fix if you are using Internet Explorer 8 on Windows XP Service Pack 3 (SP3) or on Windows Vista SP1 or later versions ( including Windows 7 ) . This is because Internet Explorer 8 opts-in to DEP by default on these platforms. </strong></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/01/warning-ie-0-day-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WOW  wowmatrix keylogger</title>
		<link>http://hijack-this.co.uk/2009/11/wow-keylogger/</link>
		<comments>http://hijack-this.co.uk/2009/11/wow-keylogger/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 11:00:42 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[games]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[world of warcraft]]></category>
		<category><![CDATA[wowmatrix]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=227</guid>
		<description><![CDATA[I was notified of a google advert for a fake wowmatrix site. The original genuine wowmatrix is seen by many games players as not completely within the rules of the games Wowmatrix is an addon that makes it easier to update and install other tweaks and addons to your game. Obviously using a fake version [...]]]></description>
			<content:encoded><![CDATA[<p><br />
I was notified of a google advert for a fake wowmatrix site. The original genuine wowmatrix is seen by many games players as not completely within the rules of the games<br />
Wowmatrix is an addon that makes it easier to update and install other tweaks and addons to your game. Obviously using a fake version that downloads false addons &#038; tweaks and installs them leaves you open to a lot of problems. </p>
<p>The advert on google looks like a search listing and it is only apparant that it is a sponsored listing or advert on close inspection</p>
<p><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/wowmatrix.PNG"><img class="size-medium wp-image-228 aligncenter" title="wowmatrix" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/wowmatrix-300x148.PNG" alt="wowmatrix" width="300" height="148" /></a><span id="more-227"></span></p>
<p>if you look at the screenshots of the 2 sites, you will see that there is very little difference between them and an unwary visitor can soon get infected</p>
<p>Don&#8217;t get caught out by it and get your passwords stolen. The downloads on the fake site are recognized by several antiviruses as a password stealer and downloads lots of other trojans and malware</p>
<p>the genuine site is on the left, the fake site on the right</p>
<table border="0">
<tbody>
<tr>
<td><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/genuine_wowmatrix.PNG"><img title="genuine_wowmatrix" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/genuine_wowmatrix-300x297.PNG" alt="genuine_wowmatrix" width="300" height="297" /></a></td>
<td><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/fake_wowmatrix1.PNG"><img title="fake_wowmatrix" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/fake_wowmatrix1-300x291.PNG" alt="fake_wowmatrix" width="300" height="291" /></a></td>
</tr>
</tbody>
</table>
<p style="text-align: left;"><strong>I strongly recommend using <a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank">ROBOFORM </a>which keeps all passwords in a secure encrypted database that only you (not a keylogger or malware) can access and use it to create safe secure passwords</strong></p>
<p><a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank"><img src="http://www.roboform.com/affiliates/banners/728x90-warning3-free.gif" border="0" alt="RoboForm: Learn more..." width="728" height="90" /></a></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/wow-keylogger/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Lottery Spam</title>
		<link>http://hijack-this.co.uk/2009/11/microsoft-lottery-spam/</link>
		<comments>http://hijack-this.co.uk/2009/11/microsoft-lottery-spam/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 11:01:04 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[fake software]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=221</guid>
		<description><![CDATA[We seem to have a new batch of the Microsoft lottery spam emails again These have a @live.com email address with what at first glance looks like it could be a proper microsoft or MSN email address ( they of course are not genuine Microsoft or associated with Microsoft in any way) DO NOT fall [...]]]></description>
			<content:encoded><![CDATA[<p>We seem to have a new batch of the Microsoft lottery spam emails again</p>
<p>These have a @live.com email address with what at first glance looks like it could be a proper microsoft or MSN email address ( they of course are not genuine Microsoft or associated with Microsoft in any way)</p>
<p>DO NOT fall for the scam &amp; try to ring the 070240****** number . it is a premium rate number that will have along recorded message on it and cost you £0.50 per minute</p>
<p>You won&#8217;t get any money from these scammers but they will get money from you</p>
<p>I have blanked out the full email address and phone number from the image to save the unwary</p>
<p><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/MSlotteryscam.PNG"><img class="aligncenter size-medium wp-image-222" title="MSlotteryscam" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/MSlotteryscam-247x300.PNG" alt="MSlotteryscam" width="247" height="300" /></a></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/microsoft-lottery-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Advisory 977544 vulnerability affecting SMB Protocol</title>
		<link>http://hijack-this.co.uk/2009/11/microsoft-security-advisory-977544-vulnerability-affecting-smb-protocol/</link>
		<comments>http://hijack-this.co.uk/2009/11/microsoft-security-advisory-977544-vulnerability-affecting-smb-protocol/#comments</comments>
		<pubDate>Sat, 14 Nov 2009 10:08:56 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[microsoft]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=219</guid>
		<description><![CDATA[Microsoft Security Advisory 977544 Released Today Microsoft released Security Advisory 977544 to provide information, including customer guidance, on a publicly reported Denial-of-Service (DoS) vulnerability affecting Server Messaging Block (SMB) Protocol. This vulnerability, in SMBv1 and SMBv2, affects  Windows 7 and Windows Server 2008 R2. Windows Vista, Windows Server 2008, Windows XP, Windows Server 2003 and [...]]]></description>
			<content:encoded><![CDATA[<h2>Microsoft Security Advisory 977544 Released</h2>
<p>Today Microsoft released <a href="http://www.microsoft.com/technet/security/advisory/977544.mspx">Security Advisory 977544</a> to provide information, including customer guidance, on a publicly reported Denial-of-Service (DoS) vulnerability affecting Server Messaging Block (SMB) Protocol. This vulnerability, in SMBv1 and SMBv2, affects  Windows 7 and Windows Server 2008 R2. Windows Vista, Windows Server 2008, Windows XP, Windows Server 2003 and Windows 2000 are not affected.</p>
<p>It needs to be made  clear that this is a DoS vulnerability that is unrelated to Microsoft Security Bulletin <a href="http://go.microsoft.com/fwlink/?LinkId=163970">MS09-050</a> which addressed a remote code execution vulnerability in the SMBv2 protocol. This vulnerability would not allow an attacker to take control or install malware on a user’s system, but could cause the affected system to stop responding until manually restarted.</p>
<p><a href="http://blogs.technet.com/msrc/archive/2009/11/13/microsoft-security-advisory-977544-released.aspx">http://blogs.technet.com/msrc/archive/2009/11/13/microsoft-security-advisory-977544-released.aspx</a></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/microsoft-security-advisory-977544-vulnerability-affecting-smb-protocol/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing</title>
		<link>http://hijack-this.co.uk/2009/11/phishing/</link>
		<comments>http://hijack-this.co.uk/2009/11/phishing/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 11:49:39 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=214</guid>
		<description><![CDATA[I mentioned previously HERE that the criminals doing these phishing attacks are changing tactics to make it harder for the antiphishing measures to block them We are seeing many more phishing attempts using the same technique of sending an HTML page as an attachment to an email and asking you, the victim, to fill in the [...]]]></description>
			<content:encoded><![CDATA[<p>I mentioned previously <a href="http://hijack-this.co.uk/?p=176">HERE</a> that the criminals doing these phishing attacks are changing tactics to make it harder for the antiphishing measures to block them</p>
<p>We are seeing many more phishing attempts using the same technique of sending an HTML page as an attachment to an email and asking you, the victim, to fill in the form</p>
<p>Many people are falling for this, even more than those who click on  link in an email. <span id="more-214"></span></p>
<p>Once again we warn that Banks, Building Societies, HMRC, Finance Companies, Ebay, Paypal and Government Departments will not send an email with a PDF to fill or a web page form to fill in asking for user name, password, date of birth, address, Mothers maiden name, Place of birth, favorite color or anything else that can be used to steal your identity. Most of all they <strong>NEVER, NEVER, NEVER</strong> ask for your credit or debit card details, pin number or log in password.</p>
<p><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/barclay_phish.png"><img class="alignleft size-medium wp-image-215" title="barclay_phish" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/barclay_phish-229x300.png" alt="barclay_phish" width="229" height="300" /></a></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Shockwave Player Multiple Vulnerabilities</title>
		<link>http://hijack-this.co.uk/2009/11/adobe-shockwave-player-multiple-vulnerabilities/</link>
		<comments>http://hijack-this.co.uk/2009/11/adobe-shockwave-player-multiple-vulnerabilities/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 08:28:06 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=204</guid>
		<description><![CDATA[ Affected: Adobe Shockwave Player versions 11.x Description: Adobe Shockwave Player, with over 450 million users, is a multimedia player that allows Adobe Director applications to be published and viewed by a browser that is installed with a Shockwave plug-in.  Multiple vulnerabilities have been reported in Adobe Shockwave Player, which be triggered by a specially crafted [...]]]></description>
			<content:encoded><![CDATA[<p> Affected: Adobe Shockwave Player versions 11.x</p>
<p>Description: Adobe Shockwave Player, with over 450 million users, is a multimedia player that allows Adobe Director applications to be published and viewed by a browser that is installed with a Shockwave plug-in.</p>
<p> Multiple vulnerabilities have been reported in Adobe Shockwave Player, which be triggered by a specially crafted Shockwave content.  There is a error in the way the invalid index is used.  There are also a couple of issues caused by the inappropriate use of the invalid pointer.  And the last issue is a memory corruption error when processing string lengths.</p>
<p> In all the cases successful exploitation might allow an attacker to execute arbitrary code in the context of the logged on user.</p>
<p>There is not enough public information about these vulnerabilities.</p>
<p>Status: Vendor confirmed, updates available.</p>
<p>References:</p>
<p> Adobe Security Bulletin (APSB09-16)  <a href="http://www.adobe.com/support/security/bulletins/apsb09-16.html">http://www.adobe.com/support/security/bulletins/apsb09-16.html</a></p>
<p>Wikipedia Article on Adobe Shockwave  <a href="http://en.wikipedia.org/wiki/">http://en.wikipedia.org/wiki/</a></p>
<p>Adobe_Shockwave Product Home Page  <a href="http://www.adobe.com/products/shockwaveplayer/">http://www.adobe.com/products/shockwaveplayer/</a></p>
<p> SecurityFocus BID <a href="http://www.securityfocus.com/bid/36905">http://www.securityfocus.com/bid/36905</a></p>
<p><strong>Adobe recommends Shockwave Player users install Shockwave Player version 11.5.2.602 available here: </strong><a href="http://get.adobe.com/shockwave/"><strong>http://get.adobe.com/shockwave/</strong></a><br />
Remember: You need to install shockwave in Every Browser you use separately, if you wish to use it in your browser</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/adobe-shockwave-player-multiple-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More HMRC Phishing and very difficult to block</title>
		<link>http://hijack-this.co.uk/2009/10/more-hmrc-phishing-and-very-difficult-to-block/</link>
		<comments>http://hijack-this.co.uk/2009/10/more-hmrc-phishing-and-very-difficult-to-block/#comments</comments>
		<pubDate>Mon, 19 Oct 2009 12:51:26 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=176</guid>
		<description><![CDATA[I am getting concerned at the latest phishing attacks aimed at UK citizens who have to submit tax returns by November The Anti-phishing sites are unable to block the sites or warn you that you are on a phishing site  because the html is a web page on your computer so NEVER checked Even if [...]]]></description>
			<content:encoded><![CDATA[<p>I am getting concerned at the latest phishing attacks aimed at UK citizens who have to submit tax returns by November</p>
<p>The Anti-phishing sites are unable to block the sites or warn you that you are on a phishing site  because the html is a web page on your computer so NEVER checked</p>
<p>Even if you press submit, it bounces immediately to the genuine HMRC site so isn&#8217;t blocked <span id="more-176"></span><br />
Currently spreading in UK are emails pretending to come from HMRC ( Inland Revenue/Tax Office) telling you of a tax refund due to you. For a change they don&#8217;t ask you to follow a link directly but to open the attached HTML file ( web page) on your local computer to fill in the form</p>
<p><a href="http://hijack-this.co.uk/wp-content/uploads/2009/10/hmrc_email2.PNG"><img class="aligncenter size-medium wp-image-177" title="hmrc_email2" src="http://hijack-this.co.uk/wp-content/uploads/2009/10/hmrc_email2-300x243.PNG" alt="hmrc_email2" width="300" height="243" /></a></p>
<p>The webpage looks like</p>
<p><a href="http://hijack-this.co.uk/wp-content/uploads/2009/10/hmrc2.PNG"><img class="aligncenter size-medium wp-image-178" title="hmrc2" src="http://hijack-this.co.uk/wp-content/uploads/2009/10/hmrc2-276x300.PNG" alt="hmrc2" width="276" height="300" /></a></p>
<p>As usual the advice is be very wary, don&#8217;t save or open attached HTML files from anybody especially those that pretend to come from a Government department or  bank. They will <strong>ALWAYS</strong> be fraudulent</p>
<p>If you have unwittingly made a mistake &amp; entered your details:  get in touch with your bank immediately and inform them that your credit/debit card details have been stolen and  immediately report it to the police. Don&#8217;t let the police fob you off with &#8221; we don&#8217;t deal with that sort of thing&#8221;. Insist on a crime being reported and take &amp; keep the crime reference number</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/10/more-hmrc-phishing-and-very-difficult-to-block/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
