<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and Privacy &#187; Warnings and Alerts</title>
	<atom:link href="http://hijack-this.co.uk/category/warnings-and-alerts/feed/" rel="self" type="application/rss+xml" />
	<link>http://hijack-this.co.uk</link>
	<description>My ramblings on how to protect yourself online</description>
	<lastBuildDate>Thu, 05 Apr 2012 14:34:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Unsecured wireless networks can get you into serious trouble</title>
		<link>http://hijack-this.co.uk/2012/04/unsecured-wireless-networks-can-get-you-into-serious-trouble/</link>
		<comments>http://hijack-this.co.uk/2012/04/unsecured-wireless-networks-can-get-you-into-serious-trouble/#comments</comments>
		<pubDate>Tue, 03 Apr 2012 12:10:38 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security advice]]></category>
		<category><![CDATA[Tips & Settings]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=615</guid>
		<description><![CDATA[&#160; A federal lawsuit filed by Liberty Media Holdings – a San Diego adult content company – promises to keep the lawyers and copyright experts busy in the months ahead. The lawsuit – which accuses around 50 individuals of using their Internet connection, or allowing their connection to be used by a third party to file-share [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p>A federal lawsuit filed by Liberty Media Holdings – a San Diego adult content company – promises to keep the lawyers and copyright experts busy in the months ahead. The lawsuit – which accuses around 50 individuals of using their Internet connection, or allowing their connection to be used by a third party to file-share an adult movie – is interesting because it will test whether people who leave their wireless network on open access can be held liable if a third party uses it to download copyrighted content.</p>
<p> A growing number of businesses are now offering guest access to their company network for site visitors and contractors. This is acceptable if the access is controlled through the use of a password and audit logging system – complete with acceptable usage policies – but many companies avoid the cost of these controls by simply opening up their wireless network on a password-free basis. Although this saves a few dollars a month on subscription fees, it is a very dangerous game because the legal liability risks are quite high.</p>
<p> This will likely be a test case about the wider use of unsecured wireless networks &amp; could have wide reaching Implications for all of us, not just US based members but worldwide as other legal authorities follow or adopt the  likely US outcome</p>
<p> Will this end up stopping city wide free wireless or “free” hotspots that don’t ask for user name &amp; password to connect. Could it further go down to the Average clueless user who leaves his/her home wireless unsecured or lets his friend or neighbour connect (without putting explicit restrictions on what that guest can do on the network), even though that is against the majority of ISPs T&amp;C</p>
<p> <a href="http://www.infosecurity-magazine.com/view/24809/comment-businesses-need-to-wake-up-to-open-wireless-access-risks/">http://www.infosecurity-magazine.com/view/24809/comment-businesses-need-to-wake-up-to-open-wireless-access-risks/</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2012%2F04%2Funsecured-wireless-networks-can-get-you-into-serious-trouble%2F&amp;title=Unsecured%20wireless%20networks%20can%20get%20you%20into%20serious%20trouble" id="wpa2a_2"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2012/04/unsecured-wireless-networks-can-get-you-into-serious-trouble/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Flash player Update 27 March 2012</title>
		<link>http://hijack-this.co.uk/2012/03/adobe-flash-player-update-27-march-2012/</link>
		<comments>http://hijack-this.co.uk/2012/03/adobe-flash-player-update-27-march-2012/#comments</comments>
		<pubDate>Wed, 28 Mar 2012 08:32:29 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[adobe]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security advice]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=612</guid>
		<description><![CDATA[There seems to have been a security update to 11.2.202.228 but I can find no release notes or information why the update has been issued except general gossip to say to fix undisclosed vulnerabilities Some users have reported problems with installing the update via adobe web based install so an alternative method is to use [...]]]></description>
			<content:encoded><![CDATA[<p>There seems to have been a security update to 11.2.202.228 but I can find no release notes or information why the update has been issued except general gossip to say to fix undisclosed vulnerabilities</p>
<p>Some users have reported problems with installing the update via adobe web based install so an alternative method is to use the full installers on <a href="http://www.adobe.com/products/flashplayer/distribution3.html" target="_blank">http://www.adobe.com/products/flashplayer/distribution3.html</a></p>
<p>I understand that some antiviruses including Eset/Nod have conflicts with the adobe web based installer</p>
<p>Edit:<br />
details here<br />
<a href="http://forums.adobe.com/message/4296259">http://forums.adobe.com/message/4296259</a></p>
<p>it isn&#8217;t a security fix but a whole new version of flashplayer with additional capabilities</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2012%2F03%2Fadobe-flash-player-update-27-march-2012%2F&amp;title=Adobe%20Flash%20player%20Update%2027%20March%202012" id="wpa2a_4"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2012/03/adobe-flash-player-update-27-march-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Essentials Anti-Virus ( MSE) update problems</title>
		<link>http://hijack-this.co.uk/2012/03/microsoft-security-essentials-anti-virus-mse-update-problems/</link>
		<comments>http://hijack-this.co.uk/2012/03/microsoft-security-essentials-anti-virus-mse-update-problems/#comments</comments>
		<pubDate>Fri, 23 Mar 2012 07:09:38 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Security advice]]></category>
		<category><![CDATA[Tips & Settings]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=607</guid>
		<description><![CDATA[There have been problems with MSE ( Microsoft Security Essentials Anti-Virus) updating itself, either through the program or via Windows update the last 2 days. It will continually tell you that you are up to date when you are in fact several definition updates behind Currently at 7 am GMT on 23 March 2012 the [...]]]></description>
			<content:encoded><![CDATA[<p>There have been problems with MSE ( Microsoft Security Essentials Anti-Virus) updating itself, either through the program or via Windows update the last 2 days. It will continually tell you that you are up to date when you are in fact several definition updates behind<br />
Currently at 7 am GMT on 23 March 2012 the latest published definitions are 1.123.212.0<br />
MSE or WU will only give 1.123.194.0<br />
Yesterday it was 4 definition sets behind</p>
<p>The way to update is to do a manual update from <a href="http://www.microsoft.com/security/portal/definitions/howtomse.aspx" target="_blank">http://www.microsoft.com/security/portal/definitions/howtomse.aspx</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2012%2F03%2Fmicrosoft-security-essentials-anti-virus-mse-update-problems%2F&amp;title=Microsoft%20Security%20Essentials%20Anti-Virus%20%28%20MSE%29%20update%20problems" id="wpa2a_6"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2012/03/microsoft-security-essentials-anti-virus-mse-update-problems/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Make sure your Java is up to date</title>
		<link>http://hijack-this.co.uk/2011/12/make-sure-your-java-is-up-to-date/</link>
		<comments>http://hijack-this.co.uk/2011/12/make-sure-your-java-is-up-to-date/#comments</comments>
		<pubDate>Thu, 01 Dec 2011 08:19:43 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security advice]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=600</guid>
		<description><![CDATA[&#160; Public Java Exploit Amps Up Threat Level — Krebs on Security: http://krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/?utm_source=feedburner&#38;utm_medium=feed&#38;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29 &#8220;An exploit for a recently disclosed Java vulnerability that was previously only available for purchase in the criminal underground has now been rolled into the open source Metasploit exploit framework. Metasploit researchers say the Java attack tool has been tested to successfully [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="mso-fareast-font-family: 'Times New Roman';"><span style="font-family: Times New Roman; font-size: small;">Public Java Exploit Amps Up Threat Level — Krebs on Security:<br />
</span><a href="http://krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">http://krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29</span></a><br />
<span style="font-family: Times New Roman; font-size: small;"><br />
&#8220;An exploit for a recently disclosed <strong>Java</strong> </span><a title="CVE-2011-3544" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3544" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">vulnerability</span></a><span style="font-family: Times New Roman; font-size: small;"> that was previously only available for purchase in the criminal underground has now been rolled into the open source </span><a href="http://metasploit.com/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">Metasploit</span></a><span style="font-family: Times New Roman; font-size: small;"> exploit framework. Metasploit researchers say the Java attack tool has been tested to successfully deliver payloads on a variety of platforms, including the latest <strong>Windows</strong>, <strong>Mac</strong> and <strong>Linux</strong> systems.&#8221;</p>
<p>&#8220;The exploit attacks </span><a title="NIST CVE Listing" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3544" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">a vulnerability</span></a><span style="font-family: Times New Roman; font-size: small;"> that exists in <em>Oracle Java SE JDK and JRE 7 and 6 Update 27</em> and earlier. If you are using <em>Java 6 Update 29</em>, or <em>Java 7 Update 1</em>, then you have </span><a title="KrebsOnSecurity: Critical Java Update Fixes 20<br />
      Flaws" href="http://hijack-this.co.uk/2011/10/critical-java-update-fixes-20-flaws/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">the latest version</span></a><span style="font-family: Times New Roman; font-size: small;"> that is patched against this and 19 other security threats. If you are using a vulnerable version of Java, it’s time to update. Not sure whether you have Java or what version you may be running? Check out </span><a title="Java Home<br />
      Page" href="http://java.com/en/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">this link</span></a><span style="font-family: Times New Roman; font-size: small;">, and then click the “Do I have Java?” link below the big red “Free Java Download” button. Apple </span><a href="http://krebsonsecurity.com/2011/11/adobe-apple-microsoft-mozilla-issue-critical-patches/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">issued its own update</span></a><span style="font-size: small;"><span style="font-family: Times New Roman;"> to fix this flaw and other Java bugs earlier this month.&#8221; </span></span></span></p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F12%2Fmake-sure-your-java-is-up-to-date%2F&amp;title=Make%20sure%20your%20Java%20is%20up%20to%20date" id="wpa2a_8"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/12/make-sure-your-java-is-up-to-date/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Fixit for Duqu 0 day exploit</title>
		<link>http://hijack-this.co.uk/2011/11/microsoft-fixit-for-dequ-0-day-exploit/</link>
		<comments>http://hijack-this.co.uk/2011/11/microsoft-fixit-for-dequ-0-day-exploit/#comments</comments>
		<pubDate>Fri, 04 Nov 2011 07:53:54 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security advice]]></category>
		<category><![CDATA[Tips & Settings]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=594</guid>
		<description><![CDATA[Temporary fixit &#38; workaround for 0 day exploit relating to duqu malware Fixit &#38; unfixit here http://support.microsoft.com/kb/2639658 Advisory with manual &#8220;fixes&#8221;  http://technet.microsoft.com/en-us/security/advisory/2639658 My considered advice is that you won&#8217;t need it and you should wait until Microsoft issue a full patch So far all attacks have been directly targetted against specific companies or Government departments,  That might change [...]]]></description>
			<content:encoded><![CDATA[<p>Temporary fixit &amp; workaround for 0 day exploit relating to duqu malware</p>
<p>Fixit &amp; unfixit here <a href="http://support.microsoft.com/kb/2639658">http://support.microsoft.com/kb/2639658</a></p>
<p>Advisory with manual &#8220;fixes&#8221;  <a href="http://technet.microsoft.com/en-us/security/advisory/2639658">http://technet.microsoft.com/en-us/security/advisory/2639658</a></p>
<p>My considered advice is that you won&#8217;t need it and you should wait until Microsoft issue a full patch<br />
So far all attacks have been directly targetted against specific companies or Government departments,  That might change as the skiddies get hold of the exploit</p>
<p>Using the fixit might make some applications/ word docs  or websites not display correctly ( or even at all )  if they use embedded True type fonts &amp; they haven&#8217;t been set to gracefully fall back on standard system fonts</p>
<p>If we start to see general attacks, then I will update this &amp; suggest using the fixit</p>
<p>An additional workaround to prevent Websites attacking you by using embedded fonts is to set Internet Explorer font downloads to prompt instead of allow . That way you at least get an alert if a font is being downloaded and you can make an educated opinion as to whether it is likely to be malicious</p>
<ul>
<li>Open Internet Explorer</li>
<li>On the Tools menu, click Options and then click the Security tab.</li>
<li>Select Custom and click Settings.</li>
<li>Scroll to the Downloads section.</li>
<li>Change the Font Download setting from  Enable to Prompt</li>
</ul>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F11%2Fmicrosoft-fixit-for-dequ-0-day-exploit%2F&amp;title=Microsoft%20Fixit%20for%20Duqu%200%20day%20exploit" id="wpa2a_10"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/11/microsoft-fixit-for-dequ-0-day-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>new Fake AV techniques</title>
		<link>http://hijack-this.co.uk/2011/07/new-fake-av-techniques/</link>
		<comments>http://hijack-this.co.uk/2011/07/new-fake-av-techniques/#comments</comments>
		<pubDate>Fri, 29 Jul 2011 17:21:26 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Security advice]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=558</guid>
		<description><![CDATA[http://xylibox.blogspot.com/2011/07/trojanfakeavlvt.html once you get past the colourful language from the analyst, it is a very good read &#38; shows what we are up against. Please forgive any errors in language as he doesn&#8217;t have English as a first language This particular one has the ability to replace your existing antivirus with itself &#38; make you [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://xylibox.blogspot.com/2011/07/trojanfakeavlvt.html">http://xylibox.blogspot.com/2011/07/trojanfakeavlvt.html</a></p>
<p>once you get past the colourful language from the analyst, it is a very good read &amp; shows what we are up against. Please forgive any errors in language as he doesn&rsquo;t have English as a first language</p>
<p>This particular one has the ability to replace your existing antivirus with itself &amp; make you think that you are still protected when you aren&rsquo;t and it installs Zero access rootkit</p>
<p>This is definitely something to watch out for</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F07%2Fnew-fake-av-techniques%2F&amp;title=new%20Fake%20AV%20techniques" id="wpa2a_12"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/07/new-fake-av-techniques/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 2011 Adobe updates</title>
		<link>http://hijack-this.co.uk/2011/06/june-2011-adobe-updates/</link>
		<comments>http://hijack-this.co.uk/2011/06/june-2011-adobe-updates/#comments</comments>
		<pubDate>Thu, 16 Jun 2011 14:15:44 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[adobe]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=526</guid>
		<description><![CDATA[As if you needed more updates this week&#8230; APSB11-16 &#8211; Security Advisory for Adobe Reader (v10.1) and Acrobat (v10.1 et al.) http://www.adobe.com/support/security/bulletins/apsb11-16.html APSB11-17 &#8211; Security Update Available for Adobe Shockwave Player v11.6.0.626 http://www.adobe.com/support/security/bulletins/apsb11-17.html APSB11-18 &#8211; [Yes, yet another] Security update available for Adobe Flash&#160; Player (v10.3.181.26) http://www.adobe.com/support/security/bulletins/apsb11-18.html]]></description>
			<content:encoded><![CDATA[<p>As if you needed more updates this week&#8230;</p>
<p>APSB11-16 &#8211; Security Advisory for Adobe Reader (v10.1) and Acrobat (v10.1 et al.)<br />
	<a href="http://www.adobe.com/support/security/bulletins/apsb11-16.html" target="_blank">http://www.adobe.com/support/security/bulletins/apsb11-16.html</a></p>
<p>APSB11-17 &#8211; Security Update Available for Adobe Shockwave Player v11.6.0.626<br />
	<a href="http://www.adobe.com/support/security/bulletins/apsb11-17.html" target="_blank">http://www.adobe.com/support/security/bulletins/apsb11-17.html</a></p>
<p>APSB11-18 &#8211; [Yes, yet another] Security update available for Adobe Flash&nbsp; Player (v10.3.181.26)<br />
	<a href="http://www.adobe.com/support/security/bulletins/apsb11-18.html" target="_blank">http://www.adobe.com/support/security/bulletins/apsb11-18.html</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F06%2Fjune-2011-adobe-updates%2F&amp;title=June%202011%20Adobe%20updates" id="wpa2a_14"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/06/june-2011-adobe-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another new URGENT Adobe flash security update</title>
		<link>http://hijack-this.co.uk/2011/06/another-new-urgent-adobe-flash-security-update/</link>
		<comments>http://hijack-this.co.uk/2011/06/another-new-urgent-adobe-flash-security-update/#comments</comments>
		<pubDate>Mon, 06 Jun 2011 08:24:34 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[adobe]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=499</guid>
		<description><![CDATA[http://www.adobe.com/support/security/bulletins/apsb11-13.html An important vulnerability has been identified in Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.3.185.22 and earlier versions for Android. This universal cross-site scripting vulnerability (CVE-2011-2107) could be used to take actions on a user&#8217;s behalf on any website or webmail provider, if the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.adobe.com/support/security/bulletins/apsb11-13.html" target="_blank">http://www.adobe.com/support/security/bulletins/apsb11-13.html</a><br />
An important vulnerability has been identified in Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris, and Adobe Flash Player 10.3.185.22 and earlier versions for Android. This universal cross-site scripting vulnerability (CVE-2011-2107) could be used to take actions on a user&#8217;s behalf on any website or webmail provider, if the user visits a malicious website. There are reports that this vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message.<br />
Adobe recommends users of Adobe Flash Player 10.3.181.16 and earlier versions for Windows, Macintosh, Linux and Solaris update to Adobe Flash Player 10.3.181.22 (10.3.181.23 for ActiveX). Adobe expects to make available an update for Flash Player 10.3.185.22 for Android during the week of June 6, 2011.</p>
<p>Adobe is still investigating the impact to the Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.2) and earlier 10.x and 9.x versions of Adobe Reader and Acrobat for Windows and Macintosh operating systems. Adobe is not aware of any attacks targeting Adobe Reader or Acrobat in the wild.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F06%2Fanother-new-urgent-adobe-flash-security-update%2F&amp;title=Another%20new%20URGENT%20Adobe%20flash%20security%20update" id="wpa2a_16"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/06/another-new-urgent-adobe-flash-security-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cybercriminals Hoping You’ll Bite iPhone 5 Bait</title>
		<link>http://hijack-this.co.uk/2011/05/cybercriminals-hoping-you%e2%80%99ll-bite-iphone-5-bait/</link>
		<comments>http://hijack-this.co.uk/2011/05/cybercriminals-hoping-you%e2%80%99ll-bite-iphone-5-bait/#comments</comments>
		<pubDate>Wed, 25 May 2011 07:20:24 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Iphone]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[fake software]]></category>
		<category><![CDATA[keylogger]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=480</guid>
		<description><![CDATA[Online criminals know there are enough gadget hounds out there to make a scam surrounding any shiny new Apple device a surefire moneymaker. To that end, they’ve already begun sending out phishing emails for the iPhone 5. The phishing emails appear to be official emails from Apple.com, with the title “Finally. The amazing iPhone 5. [...]]]></description>
			<content:encoded><![CDATA[<p>Online criminals know there are enough gadget hounds out there to make a scam surrounding any shiny new Apple device a surefire moneymaker. To that end, they’ve already begun sending out phishing emails for the iPhone 5.</p>
<p>The phishing emails appear to be official emails from Apple.com, with the title “Finally. The amazing iPhone 5. Now available in black edition.” The body of the message shows a hand holding a transparent iPhone, followed by an enticing offer to “check it out,” according to <a title="MacRumors" href="http://www.macrumors.com/2011/05/22/phishing-and-malware-emails-posing-as-apple-and-the-iphone-5-launch/" target="_blank">MacRumors</a>.</p>
<p>Although there’s been much speculation about the next generation iPhone, Apple has not set a release date for it. In fact, Apple hasn’t even announced it yet, but that isn’t stopping this cleverly crafted Mac-themed scam from spreading.</p>
<p>So what are you checking out when you click the link to see the new iPhone 5?</p>
<p>You won’t receive any info about the smartphone, but you will enable a rigged Windows file to run malicious code on your computer. And you’ll also be taken to a phony Apple Web page that asks for your Apple ID and other sensitive information.</p>
<p>Apple announces new products, especially ones of this magnitude, in highly publicized press conferences. So if you receive an unsolicited email purporting to have information about the new iPhone 5, ignore it, DELETE IT WITHOUT EVEN READING IT.</p>
<p>story from: <a href="http://www.securitynewsdaily.com/cybercriminals-hoping-youll-bite-iphone-5-bait-0813/">http://www.securitynewsdaily.com/cybercriminals-hoping-youll-bite-iphone-5-bait-0813/</a></p>
<p>This malware is quite well detected by many antivirus companies, but not all. It is a fairly standard Zapchast IRC trojan that will attempt to download lots of other crap &amp; malware to your computer.</p>
<p>It also appears to try to  perform a DDOS flood attack against several other competing Mirc users and channels to block their channels, so no doubt will turn out to be connected to the typical fake AV scams and stealing your money</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F05%2Fcybercriminals-hoping-you%25e2%2580%2599ll-bite-iphone-5-bait%2F&amp;title=Cybercriminals%20Hoping%20You%E2%80%99ll%20Bite%20iPhone%205%20Bait" id="wpa2a_18"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/05/cybercriminals-hoping-you%e2%80%99ll-bite-iphone-5-bait/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Different approach to scam phishing</title>
		<link>http://hijack-this.co.uk/2011/05/a-different-approach-to-scam-phishing/</link>
		<comments>http://hijack-this.co.uk/2011/05/a-different-approach-to-scam-phishing/#comments</comments>
		<pubDate>Wed, 11 May 2011 07:12:23 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=474</guid>
		<description><![CDATA[I wonder how effective the phishers will be sending this to countless people. I doubt that there are enough Irish speakers/readers in the world to make it worthwhile Translated it says Dear Applicant: We have noticed that you are entitled to a refund amount 361.43 Complete the tax refund 24h: Tax Return Form 2011 Thanks, [...]]]></description>
			<content:encoded><![CDATA[<div>I wonder how effective the phishers will be sending this to countless people.</div>
<div>I doubt that there are enough Irish speakers/readers in the world to make it worthwhile</div>
<div>Translated it says</div>
<div style="padding-left: 30px;">Dear Applicant:</div>
<div>We have noticed that you are entitled to a refund amount 361.43<br />
Complete the tax refund 24h: Tax Return Form 2011</div>
<div>Thanks,<br />
Irish Revenue</div>
<div>
<div id="attachment_475" class="wp-caption aligncenter" style="width: 310px"><a class="thickbox" rel="474" href="http://hijack-this.co.uk/wp-content/uploads/2011/05/Irish_revenue_scam.jpg" ><img class="size-medium wp-image-475" title="Irish_revenue_scam" src="http://hijack-this.co.uk/wp-content/uploads/2011/05/Irish_revenue_scam-300x178.jpg" alt="" width="300" height="178" /></a><p class="wp-caption-text">Irish revenue scam </p></div>
<p>&nbsp;</p>
<p>I have received 5 of these in the last hour. 2 from chinese servers but 3 from different domains on Fasthost.co.uk servers. It looks to me that either fasthosts have been hacked again or they have open relays on their servers allowing bots &amp; phishers to relay through them</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
</div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F05%2Fa-different-approach-to-scam-phishing%2F&amp;title=A%20Different%20approach%20to%20scam%20phishing" id="wpa2a_20"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/05/a-different-approach-to-scam-phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

