<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Donna's SecurityFlash</title><link>http://msmvps.com/blogs/donna/default.aspx</link><description>PC &amp;amp; Internet Security Blog</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Opera 10.01 Remote Array Overrun (Arbitrary code execution)</title><link>http://msmvps.com/blogs/donna/archive/2009/11/20/opera-10-01-remote-array-overrun-arbitrary-code-execution.aspx</link><pubDate>Fri, 20 Nov 2009 16:20:30 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1741023</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1741023</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1741023</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/20/opera-10-01-remote-array-overrun-arbitrary-code-execution.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;Topic : Opera 10.01 Remote Array Overrun (Arbitrary code execution)     &lt;br /&gt;SecurityAlert : 73      &lt;br /&gt;CVE : CVE-2009-0689      &lt;br /&gt;SecurityRisk : High&amp;#160;&amp;#160;&amp;#160; (About)      &lt;br /&gt;Remote Exploit : Yes      &lt;br /&gt;Local Exploit : Yes      &lt;br /&gt;Exploit Given : Yes      &lt;br /&gt;Credit : SecurityReason Research      &lt;br /&gt;Date : 20.11.2009      &lt;br /&gt;Affected Software :       &lt;br /&gt;- - Opera 10.01      &lt;br /&gt;- - Opera 10.10 Beta      &lt;br /&gt;NOTE: Prior versions may also be affected. &lt;/p&gt;    &lt;p&gt;Opera fix:&amp;#160; The vulnerability was fixed in the latest release candidate Opera RC3 &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Vulnerability details in &lt;a href="http://securityreason.com/achievement_securityalert/73"&gt;http://securityreason.com/achievement_securityalert/73&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Note:&amp;#160; For users who have the new beta build: Opera v10.10 Build 1892 (BETA), you should check with Opera ASA if it&amp;#39;s affected&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1741023" width="1" height="1"&gt;</description></item><item><title>Zero-day vulnerabilities in Firefox extensions discovered</title><link>http://msmvps.com/blogs/donna/archive/2009/11/20/zero-day-vulnerabilities-in-firefox-extensions-discovered.aspx</link><pubDate>Fri, 20 Nov 2009 16:12:49 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1741021</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1741021</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1741021</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/20/zero-day-vulnerabilities-in-firefox-extensions-discovered.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;One of the reasons behind Firefox&amp;#39;s popularity is the availability of a vast library of extensions. Users use them to modify the browser to their liking and make their browsing experience easier and more pleasant. The problem is, unbeknown to them, these extensions are exposing them to risk. &lt;/p&gt;    &lt;p&gt;At the SecurityByte &amp;amp; OWASP AppSec Conference in India, Roberto Suggi Liverani and Nick Freeman, security consultants with security-assessment.com, offered insight into the substantial danger posed by Firefox extensions. &lt;/p&gt;    &lt;p&gt;Mozilla doesn&amp;#39;t have a security model for extensions and Firefox fully trusts the code of the extensions. There are no security boundaries between extensions and, to make things even worse, an extension can silently modify another extension. &lt;/p&gt;    &lt;p&gt;Any Mozilla application with the extension system is vulnerable to same type of issues. Extensions vulnerabilities are platform independent, and can result in full system compromise. &lt;/p&gt;    &lt;p&gt;The researchers believe that the weakest link in the chain is the human factor. Many add-on developers do it for a hobby and are not necessarily aware of how dangerous a vulnerable extension can be. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;More in &lt;a href="http://www.net-security.org/secworld.php?id=8527"&gt;http://www.net-security.org/secworld.php?id=8527&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1741021" width="1" height="1"&gt;</description></item><item><title>Dumb code could stop computer viruses in their tracks</title><link>http://msmvps.com/blogs/donna/archive/2009/11/20/dumb-code-could-stop-computer-viruses-in-their-tracks.aspx</link><pubDate>Fri, 20 Nov 2009 14:11:31 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1741010</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1741010</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1741010</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/20/dumb-code-could-stop-computer-viruses-in-their-tracks.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;On the day a new computer virus hits the internet there is little that antivirus software can do to stop it until security firms get round to writing and distributing a patch that recognises and kills the virus. Now engineers Simon Wiseman and Richard Oak at the defence technology company Qinetiq&amp;#39;s security lab in Malvern, Worcestershire, UK, have come up with an answer to the problem. &lt;/p&gt;    &lt;p&gt;Their idea, which they are patenting, is to intercept every file that could possibly hide a virus and add a string of computer code to it that will disable any virus it contains. Their system chiefly targets emailed attachments and adds the extra code to them as they pass through a mailserver. A key feature of the scheme is that no knowledge of the virus itself is needed, so it can deal with new, unrecognised &amp;quot;zero day&amp;quot; viruses as well as older ones.[...] &lt;/p&gt;    &lt;p&gt;&amp;quot;This is not based on virus signature detection, so it is not something malware writers can imagine their way around,&amp;quot; Wiseman says. Qinetiq, which has just acquired the military networking firm Boldon James, plans to exploit the trick in future secure mailservers.&amp;#160; &amp;quot;It sounds like it might have some promise,&amp;quot; says Ross Anderson, a software security engineer at the University of Cambridge. But he adds: &amp;quot;I&amp;#39;m not sure that injecting raw machine code into attachments will be a panacea.&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.newscientist.com/article/mg20427355.600-dumb-code-could-stop-computer-viruses-in-their-tracks.html"&gt;http://www.newscientist.com/article/mg20427355.600-dumb-code-could-stop-computer-viruses-in-their-tracks.html&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1741010" width="1" height="1"&gt;</description></item><item><title>New York voting machines hit by malware to lead to allegations of voter fraud and machine failures</title><link>http://msmvps.com/blogs/donna/archive/2009/11/20/new-york-voting-machines-hit-by-malware-to-lead-to-allegations-of-voter-fraud-and-machine-failures.aspx</link><pubDate>Fri, 20 Nov 2009 13:52:29 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1741006</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1741006</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1741006</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/20/new-york-voting-machines-hit-by-malware-to-lead-to-allegations-of-voter-fraud-and-machine-failures.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;Voting machines in a New York town have been hit by a virus casting doubt on the accuracy of counts retrieved from any of the machines. &lt;/p&gt;    &lt;p&gt;According to the Gouverneur Times Cathleen Rogers, the democratic elections commissioner in Hamilton County, claimed that a problem had been found with their voting machines the week prior to the election, and the ‘virus&amp;#39; had been fixed by a technical support representative from Dominion, the manufacturer. [...] &lt;/p&gt;    &lt;p&gt;In Symantec&amp;#39;s 2010 security predictions, it claimed that highly specialised malware was uncovered in 2009 that was aimed at exploiting certain ATMs, indicating a degree of insider knowledge about their operation and how they could be exploited. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.scmagazineuk.com/new-york-voting-machines-hit-by-malware-to-lead-to-allegations-of-voter-fraud-and-machine-failures/article/158190/?"&gt;http://www.scmagazineuk.com/new-york-voting-machines-hit-by-malware-to-lead-to-allegations-of-voter-fraud-and-machine-failures/article/158190/?&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Security Trends to Watch in 2010&lt;/strong&gt; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;- Antivirus is Not Enough     &lt;br /&gt;- Social Engineering as the Primary Attack Vector      &lt;br /&gt;- Rogue Security Software Vendors Escalate Their Efforts      &lt;br /&gt;- Social Networking Third-Party Applications Will be the Target of Fraud      &lt;br /&gt;- Windows 7 Will Come into the Cross-Hairs of Attackers      &lt;br /&gt;- Fast Flux Botnets Increase      &lt;br /&gt;- URL-Shortening Services Become the Phisher’s Best Friend      &lt;br /&gt;- Mac and Mobile Malware Will Increase      &lt;br /&gt;- Spammers Breaking the Rules      &lt;br /&gt;- As Spammers Adapt, Spam Volumes Will Continue to Fluctuate      &lt;br /&gt;- Specialized Malware      &lt;br /&gt;- CAPTCHA Technology Will Improve      &lt;br /&gt;- Instant Messaging Spam &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.symantec.com/connect/blogs/don-t-read-blog"&gt;http://www.symantec.com/connect/blogs/don-t-read-blog&lt;/a&gt;    &lt;br /&gt;&lt;a href="http://www.symantec.com/podcasts/detail.jsp?podid=b-2010_security_outlook"&gt;http://www.symantec.com/podcasts/detail.jsp?podid=b-2010_security_outlook&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1741006" width="1" height="1"&gt;</description></item><item><title>Students Signing Up For Computer Hacking</title><link>http://msmvps.com/blogs/donna/archive/2009/11/20/students-signing-up-for-computer-hacking.aspx</link><pubDate>Fri, 20 Nov 2009 13:45:52 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1741005</guid><dc:creator>donna</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1741005</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1741005</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/20/students-signing-up-for-computer-hacking.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;The threat of cyber attacks on businesses and governments has led to a rapid increase in the number of universities offering students the chance to learn how to hack computer networks.&amp;#160; The degrees have been set to feed the expanding industry of &amp;quot;ethical hacking&amp;quot;, in which companies pay hackers to infiltrate their systems and expose weaknesses. &lt;/p&gt;    &lt;p&gt;The prospect of a lucrative career in the security services, police, defence and IT industries has fuelled the popularity in the courses, with hundreds of undergraduates and graduate students already enrolled. &lt;/p&gt;    &lt;p&gt;The ethical hacking degree at Abertay University in Dundee was set up in 2006 and was the first of its kind in the UK.&amp;#160; Since then, other courses have been set up at Coventry, Northumbria and Sunderland, with more in the pipeline at Glasgow Caledonian, Edinburgh Napier and Leeds Metropolitan amongst others. &lt;/p&gt;    &lt;p&gt;Colin McLean, the programme tutor in Ethical Hacking and Countermeasures at Abertay, told Sky News that teaching his students to hack networks means they will have the skills to protect banks, businesses and the critical national infrastructure against cyber attacks. &lt;/p&gt;    &lt;p&gt;&amp;quot;The current people in those jobs are not protecting against hackers,&amp;quot; he said. &lt;/p&gt;    &lt;p&gt;&amp;quot;There should be jobs for people who know exactly what hackers are doing and obviously how to stop the hackers as well.&amp;quot; &lt;/p&gt;    &lt;p&gt;Critics have warned of the dangers of arming young people with knowledge that could so easily be turned to criminal endeavour. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://news.sky.com/skynews/Home/Technology/More-Universities-Offer-Hacking-Courses-As-Govts-And-Frims-Look-To-Counter-Cyber-Criminal-Threat/Article/200911315458299"&gt;http://news.sky.com/skynews/Home/Technology/More-Universities-Offer-Hacking-Courses-As-Govts-And-Frims-Look-To-Counter-Cyber-Criminal-Threat/Article/200911315458299&lt;/a&gt;? &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1741005" width="1" height="1"&gt;</description></item><item><title>MS discovers flaw in Google plug-in for IE</title><link>http://msmvps.com/blogs/donna/archive/2009/11/20/ms-discovers-flaw-in-google-plug-in-for-ie.aspx</link><pubDate>Fri, 20 Nov 2009 11:33:35 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740961</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1740961</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1740961</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/20/ms-discovers-flaw-in-google-plug-in-for-ie.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;Microsoft has helped discover a flaw in the Google Chome Frame plug-in for Internet Explorer users. &lt;/p&gt;    &lt;p&gt;The plug-in allows suitably coded web pages to be displayed in Internet Explorer using the Google Chrome rendering engine. Redmond warned that the plug-in made IE less secure as soon as it became available back in September, an argument bolstered by the discovery of a cross-origin bypass flaw in the add-in &lt;/p&gt;    &lt;p&gt;Successfully exploiting the flaw creates a means for hackers to bypass security controls though not to go all the way and drop malware onto vulnerable systems. &lt;/p&gt;    &lt;p&gt;Google acknowledged the flaw and urged users to update to version 4.0.245.1 of Google Chrome Frame. All users should be updated automatically to the latest version of the software, which also tackles a number of performance and stability glitches. Chief among these are problems handling iFrames, as explained in Google&amp;#39;s security advisory &lt;a href="http://googlechromereleases.blogspot.com/2009/11/google-chrome-frame-update-bug-fixes.html"&gt;here&lt;/a&gt;. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.theregister.co.uk/2009/11/20/google_plug_in_bug/"&gt;http://www.theregister.co.uk/2009/11/20/google_plug_in_bug/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740961" width="1" height="1"&gt;</description></item><item><title>IE8 bug makes 'safe' sites unsafe</title><link>http://msmvps.com/blogs/donna/archive/2009/11/20/ie8-bug-makes-safe-sites-unsafe.aspx</link><pubDate>Fri, 20 Nov 2009 11:31:43 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740960</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1740960</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1740960</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/20/ie8-bug-makes-safe-sites-unsafe.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;The latest version of Microsoft&amp;#39;s Internet Explorer browser contains a bug that can enable serious security attacks against websites that are otherwise safe. &lt;/p&gt;    &lt;p&gt;The flaw in IE 8 can be exploited to introduce XSS, or cross-site scripting, errors on webpages that are otherwise safe, according to two Register sources, who discussed the bug on the condition they not be identified. Microsoft was notified of the vulnerability a few months ago, they said. &lt;/p&gt;    &lt;p&gt;Ironically, the flaw resides in a protection added by Microsoft developers to IE 8 that&amp;#39;s designed to prevent XSS attacks against sites. The feature works by rewriting vulnerable pages using a technique known as output encoding so that harmful characters and values are replaced with safer ones. A Google spokesman confirmed there is a &amp;quot;significant flaw&amp;quot; in the IE 8 feature but declined to provide specifics.[...] &lt;/p&gt;    &lt;p&gt;Late on Thursday afternoon, Microsoft told The Register: &amp;quot;Microsoft is investigating new public claims of a vulnerability in Internet Explorer. We&amp;#39;re currently unaware of any attacks trying to use the claimed vulnerability or of customer impact.&amp;quot; &lt;/p&gt;    &lt;p&gt;Once its investigation is finished, the company will &amp;quot;take appropriate action,&amp;quot; including issuing a patch or guidance on how users can protect themselves against exploits. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/"&gt;http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740960" width="1" height="1"&gt;</description></item><item><title>Cisco's free iPhone app grabs security feeds</title><link>http://msmvps.com/blogs/donna/archive/2009/11/20/cisco-s-free-iphone-app-grabs-security-feeds.aspx</link><pubDate>Fri, 20 Nov 2009 11:23:46 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740959</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1740959</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1740959</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/20/cisco-s-free-iphone-app-grabs-security-feeds.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;Cisco has made available a free iPhone app that can be used to receive more than a dozen security-related information feeds in customizable form related both to Cisco products and to general security topics, such as newly detected threats. &lt;/p&gt;    &lt;p&gt;The Cisco SIO To Go iPhone application draws from the wealth of information continuously generated in Cisco&amp;#39;s security intelligence operations (SIO) that monitor and consolidate information drawn from sensors and other sources about security threats worldwide. Michael Weir, manager of marketing for security, says the tool is Cisco&amp;#39;s first iPhone app specifically for security; a few others were designed for use with Cisco&amp;#39;s WebEx service and utilities. &lt;/p&gt;    &lt;p&gt;&amp;quot;It&amp;#39;s data that&amp;#39;s valuable and actionable for you,&amp;quot; says Weir about Cisco SIO To Go, which lets users select from a range of information, including risk reports or news-related events. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.networkworld.com/news/2009/111909-cisco-iphone-app-security.html"&gt;http://www.networkworld.com/news/2009/111909-cisco-iphone-app-security.html&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740959" width="1" height="1"&gt;</description></item><item><title>Up Close and Technical look at SocialPet</title><link>http://msmvps.com/blogs/donna/archive/2009/11/20/up-close-and-technical-look-at-socialpet.aspx</link><pubDate>Fri, 20 Nov 2009 11:21:58 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740958</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1740958</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1740958</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/20/up-close-and-technical-look-at-socialpet.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;SocialPet, a new product from Jetmetric, lets administrators send fake phishing e-mails to selected employees to determine which ones know enough to ignore the messages and which don&amp;#39;t - posing a threat to company security. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.eweek.com/c/a/Security/Up-Close-and-Technical-look-at-SocialPet/"&gt;http://www.eweek.com/c/a/Security/Up-Close-and-Technical-look-at-SocialPet/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740958" width="1" height="1"&gt;</description></item><item><title>Job Spam Uses Twitter</title><link>http://msmvps.com/blogs/donna/archive/2009/11/20/job-spam-uses-twitter.aspx</link><pubDate>Fri, 20 Nov 2009 11:18:33 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740957</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1740957</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1740957</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/20/job-spam-uses-twitter.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;TrendLabs researchers were alerted to the discovery of spammed messages that contained Twitter URLs. The spam uses subjects such as N3 Earn Extra Income! 7L, C2 Exrtra Income Daily 4P, and Q0 $$$ Oppurtunity 6O. It informs users about supposed work-from-home opportunities for Google that pay good sums of money. It then entices users to click the Twitter URL to view the details of the bogus &amp;#39;opportunities.&amp;#39; &lt;/p&gt;    &lt;p&gt;When users click the link, they will land in the sender&amp;#39;s Twitter page where another URL is posted in a tweet along with a message that encourages them to work online. The said URL points to a bogus site about working online and some success stories. This spam attack used Twitter as a technique to lure users into clicking the link. Since Twitter is a trusted source, users may think the email they received is legitimate. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://blog.trendmicro.com/job-spam-uses-twitter/"&gt;http://blog.trendmicro.com/job-spam-uses-twitter/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740957" width="1" height="1"&gt;</description></item><item><title>Malicious Java Applet Poses as Carrie Prejean Video</title><link>http://msmvps.com/blogs/donna/archive/2009/11/20/malicious-java-applet-poses-as-carrie-prejean-video.aspx</link><pubDate>Fri, 20 Nov 2009 11:15:56 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740956</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1740956</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1740956</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/20/malicious-java-applet-poses-as-carrie-prejean-video.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;McAfee Labs has observed various spam runs exploiting the recent sensational Carrie Prejean news. The Prejean video is rapidly becoming one of the most searched-for topics ever on the net since the existence of the tape became common knowledge. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Read more on how the attack works in &lt;a href="http://www.avertlabs.com/research/blog/index.php/2009/11/19/malicious-java-applet-attack-surfaces-as-carrie-prejean-video/"&gt;http://www.avertlabs.com/research/blog/index.php/2009/11/19/malicious-java-applet-attack-surfaces-as-carrie-prejean-video/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740956" width="1" height="1"&gt;</description></item><item><title>Evil Maid wanted, B.S. in Computer Science a plus</title><link>http://msmvps.com/blogs/donna/archive/2009/11/20/evil-maid-wanted-b-s-in-computer-science-a-plus.aspx</link><pubDate>Fri, 20 Nov 2009 11:10:58 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740955</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1740955</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1740955</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/20/evil-maid-wanted-b-s-in-computer-science-a-plus.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;Some weeks ago, Polish researcher Joanna Rutkowska published an attack on the TrueCrypt Full-Disk Encryption (FDE) software, which allows an attacker with access to an unattended PC to install a password sniffer in a first strike, and to steal the PC including the FDE password in a second strike. &lt;/p&gt;    &lt;p&gt;She coined the term &amp;quot;&lt;a href="http://theinvisiblethings.blogspot.com/2009/10/evil-maid-goes-after-truecrypt.html"&gt;evil maid attack&lt;/a&gt;&amp;quot; for this kind of incident, as it specifically applies to scenarios in which a traveller leaves a portable PC unattended in a hotel room, and a person who has access, but not necessarily dedicated technical skills (e.g. a room maid) actually executes the attack. &lt;/p&gt;    &lt;p&gt;Technically, this person (in the absence of any reliable data on popular names for room maids, let’s just call her Trudy) inserts a bootable medium (e.g. a CD-ROM or USB stick), turns the laptop on, and consequently the bootable malware code on the medium gets executed. &lt;/p&gt;    &lt;p&gt;This code then installs a transparent key logger in the Master Boot Record (MBR) of the hard disk. Later, the unsuspecting owner turns on his laptop, enters the passphrase and boots up. Without his knowledge, the keylogger intercepts the passphrase and stores it on the hard disk. &lt;/p&gt;    &lt;p&gt;Finally, Trudy only needs to steal the laptop and to hand it over to the person who targeted the victim. Both steps don&amp;#39;t require any particular technical knowledge, and can be performed by a person instructed/bribed by the master attacker. &lt;/p&gt;    &lt;p&gt;It&amp;#39;s not only TrueCrypt which is susceptible to this kind of attack, but basically all pure software FDE products. These products don&amp;#39;t employ any additional hardware (e.g. TPM chip) to maintain the integrity of the boot process. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;There are several ways to mitigate them quite efficiently (in Mac and Windows), find out in &lt;a href="http://www.sophos.com/blogs/gc/g/2009/11/20/guest-blog-evil-maid-wanted-bs-computer-science/"&gt;http://www.sophos.com/blogs/gc/g/2009/11/20/guest-blog-evil-maid-wanted-bs-computer-science/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740955" width="1" height="1"&gt;</description></item><item><title>Europe’s heartland in large-scale credit card theft</title><link>http://msmvps.com/blogs/donna/archive/2009/11/20/europe-s-heartland-in-large-scale-credit-card-theft.aspx</link><pubDate>Fri, 20 Nov 2009 10:55:46 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740954</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1740954</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1740954</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/20/europe-s-heartland-in-large-scale-credit-card-theft.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;Initial reports of a possible large scale breach of credit card data from a payment processing company in Spain are sketchy at best and the lack of information is not helping to allay the concerns of credit card customers across Europe. &lt;/p&gt;    &lt;p&gt;In a &lt;a href="http://www.zka-online.de/zka/pressemitteilungen/volltext/backpid/26/article/zu-den-umtauschaktionen-von-kreditkarten-wegen-des-verdachts-einer-datenluecke-bei-einem-spanischen-d-1.html?tx_ttnews%5BpS%5D=1230764400&amp;amp;tx_ttnews%5BpL%5D=1262300399&amp;amp;tx_ttnews%5Barc%5D=1&amp;amp;cHash=50a1cee77a"&gt;statement&lt;/a&gt; released today, the Zentraler Kreditausschuss (Central Credit Committee) explained that German banks were acting in response to a warning issued by Visa and Mastercard over a potential data theft at a Spanish company. The Spanish company in question has not yet been identified as it is the subject of police investigations but it is widely believed to be a payment processing company responsible for dealing with payments made in Spain using credit cards issued in foreign countries. &lt;/p&gt;    &lt;p&gt;In what is being described as a &amp;quot;primarily preventative measure&amp;quot; many German banks have begun cancelling more than 100,000 credit cards, notifying the card holders and issuing replacements. The mass replacement of cards is not restricted to Germany; banks in Austria Sweden and Finland have also begun to reissue credit cards according to &lt;a href="http://www.wiwo.de/finanzen/banken-lassen-100-000-kreditkarten-austauschen-414346/"&gt;reports&lt;/a&gt;. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://countermeasures.trendmicro.eu/europes-heartland-in-large-scale-credit-card-theft/"&gt;http://countermeasures.trendmicro.eu/europes-heartland-in-large-scale-credit-card-theft/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740954" width="1" height="1"&gt;</description></item><item><title>AVIRA AntiVir Announcement:  New Update Scheme</title><link>http://msmvps.com/blogs/donna/archive/2009/11/19/avira-antivir-announcement-new-update-scheme.aspx</link><pubDate>Thu, 19 Nov 2009 22:42:51 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740848</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1740848</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1740848</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/19/avira-antivir-announcement-new-update-scheme.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;Today Avira changed the update scheme in order to improve update speed and size.     &lt;br /&gt;Because of this, update servers are/will be very crowded (download size is about 30 Mb). Please be patient and use the following command to update: &lt;/p&gt;    &lt;p&gt;&amp;quot;C:\Program Files\Avira\AntiVir Desktop\update.exe&amp;quot; /DM=&amp;quot;0&amp;quot; &amp;quot;/NOMESSAGEBOX /receivetimeout=180&amp;quot; &lt;/p&gt;    &lt;p&gt;For 64 bit systems, the command is: &lt;/p&gt;    &lt;p&gt;&amp;quot;C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe&amp;quot; /DM=&amp;quot;0&amp;quot; &amp;quot;/NOMESSAGEBOX /receivetimeout=180&amp;quot; &lt;/p&gt;    &lt;p&gt;(copy/paste this entirely in Start -&amp;gt; Run and press Enter). &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://forum.avira.com/wbb/index.php?page=Thread&amp;amp;postID=875394#post875394"&gt;http://forum.avira.com/wbb/index.php?page=Thread&amp;amp;postID=875394#post875394&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740848" width="1" height="1"&gt;</description></item><item><title>Finally! Mozilla will kill buggy add-ons for Firefox</title><link>http://msmvps.com/blogs/donna/archive/2009/11/19/finally-mozilla-will-kill-buggy-add-ons-for-firefox.aspx</link><pubDate>Thu, 19 Nov 2009 14:30:57 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740776</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1740776</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1740776</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/19/finally-mozilla-will-kill-buggy-add-ons-for-firefox.aspx#comments</comments><description>&lt;p&gt;Mozilla Security Team said:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;We hate crashes. When Firefox crashes, we try to get you back on your feet as quickly as possible, but we’d much rather you not crash in the first place. In Firefox 3.6, we are changing the way that some third party software hooks into Firefox which should eliminate a good chunk of those crashes without sacrificing our extensibility in any way. In the process, we’ll also be giving you greater control over the code that runs in your browser.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a title="http://blog.mozilla.com/security/2009/11/16/component-directory-lockdown-new-in-firefox-3-6/" href="http://blog.mozilla.com/security/2009/11/16/component-directory-lockdown-new-in-firefox-3-6/"&gt;http://blog.mozilla.com/security/2009/11/16/component-directory-lockdown-new-in-firefox-3-6/&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;That&amp;#39;s good news.&amp;#160; That&amp;#39;s why I am Opera user where no add-ons. It simply works.. the browser.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740776" width="1" height="1"&gt;</description></item><item><title>Police make "trojan" virus arrests</title><link>http://msmvps.com/blogs/donna/archive/2009/11/19/police-make-quot-trojan-quot-virus-arrests.aspx</link><pubDate>Thu, 19 Nov 2009 13:53:28 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740770</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1740770</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1740770</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/19/police-make-quot-trojan-quot-virus-arrests.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;Detectives have made the first arrests in Europe to tackle a &amp;quot;trojan&amp;quot; computer virus which is believed to have infected tens of thousands of computers across the world, London police said on Wednesday. &lt;/p&gt;    &lt;p&gt;The ZeuS or Zbot trojan, a type of sophisticated malicious computer programme, has been used to collect millions of lines of data from machines allowing those responsible to obtain a mass of personal information. &lt;/p&gt;    &lt;p&gt;The Metropolitan Police said the trojan was configured so that once installed in an affected computer, it recorded users&amp;#39; bank details and passwords, credit card numbers and other information such as passwords for social networking sites. &lt;/p&gt;    &lt;p&gt;The financial gains for the criminals and the potential losses to individuals and institutions affected were very substantial, detectives said. &lt;/p&gt;    &lt;p&gt;Police said a man and a woman, both aged 20, had been arrested on November 3 in Manchester. They have been released on police bail pending further inquiries. &lt;/p&gt;    &lt;p&gt;&amp;quot;The ZeuS trojan is a piece of malware used increasingly by criminals to obtain huge quantities of sensitive information from thousands of compromised computers around the world,&amp;quot; said Detective Inspector Colin Wetherill of the Met Police&amp;#39;s Central e-Crime Unit.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a title="http://www.reuters.com/article/internetNews/idUSTRE5AH43Y20091118" href="http://www.reuters.com/article/internetNews/idUSTRE5AH43Y20091118"&gt;http://www.reuters.com/article/internetNews/idUSTRE5AH43Y20091118&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740770" width="1" height="1"&gt;</description></item><item><title>Avast! Antivirus 'aswRdr.sys' Driver Local Privilege Escalation Vulnerability</title><link>http://msmvps.com/blogs/donna/archive/2009/11/19/avast-antivirus-aswrdr-sys-driver-local-privilege-escalation-vulnerability.aspx</link><pubDate>Thu, 19 Nov 2009 13:48:24 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740769</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1740769</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1740769</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/19/avast-antivirus-aswrdr-sys-driver-local-privilege-escalation-vulnerability.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;Avast! Antivirus is prone to a local privilege-escalation vulnerability.     &lt;br /&gt;Local attackers can exploit this issue to execute arbitrary code with superuser privileges and completely compromise the affected computer. Failed exploit attempts will result in a denial-of-service condition. &lt;/p&gt;    &lt;p&gt;Vulnerable:&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;br /&gt;Avast! Antivirus Professional Edition 4.8.1356       &lt;br /&gt;Avast! Antivirus Professional Edition 4.8.1351       &lt;br /&gt;Avast! Antivirus Professional Edition 4.8.1335       &lt;br /&gt;Avast! Antivirus Professional Edition 4.8.1169       &lt;br /&gt;Avast! Antivirus Professional Edition 4.7.1098       &lt;br /&gt;Avast! Antivirus Professional Edition 4.7.1043       &lt;br /&gt;Avast! Antivirus Professional Edition 4.7.844       &lt;br /&gt;Avast! Antivirus Professional Edition 4.7.827       &lt;br /&gt;Avast! Antivirus Professional Edition 4.6.691       &lt;br /&gt;Avast! Antivirus Professional Edition 4.6.665       &lt;br /&gt;Avast! Antivirus Professional Edition 4.6.652       &lt;br /&gt;Avast! Antivirus Professional Edition 4.6.603       &lt;br /&gt;Avast! Antivirus Professional Edition 4.6       &lt;br /&gt;Avast! Antivirus Professional Edition 4.0       &lt;br /&gt;Avast! Antivirus Home Edition 4.8.1356       &lt;br /&gt;Avast! Antivirus Home Edition 4.8.1351       &lt;br /&gt;Avast! Antivirus Home Edition 4.8.1335       &lt;br /&gt;Avast! Antivirus Home Edition 4.8.1169       &lt;br /&gt;Avast! Antivirus Home Edition 4.7.1098       &lt;br /&gt;Avast! Antivirus Home Edition 4.7.1043       &lt;br /&gt;Avast! Antivirus Home Edition 4.7.869       &lt;br /&gt;Avast! Antivirus Home Edition 4.7.844       &lt;br /&gt;Avast! Antivirus Home Edition 4.7.827       &lt;br /&gt;Avast! Antivirus Home Edition 4.6.691       &lt;br /&gt;Avast! Antivirus Home Edition 4.6.691       &lt;br /&gt;Avast! Antivirus Home Edition 4.6.665       &lt;br /&gt;Avast! Antivirus Home Edition 4.6.655       &lt;br /&gt;Avast! Antivirus Home Edition 4.6.652       &lt;br /&gt;Avast! Antivirus Home Edition 4.6       &lt;br /&gt;Avast! Antivirus Home Edition 4.0 &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/37031/discuss"&gt;http://www.securityfocus.com/bid/37031/discuss&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740769" width="1" height="1"&gt;</description></item><item><title>How to hack China for just $1,800</title><link>http://msmvps.com/blogs/donna/archive/2009/11/19/how-to-hack-china-for-just-1-800.aspx</link><pubDate>Thu, 19 Nov 2009 13:45:07 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740768</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1740768</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1740768</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/19/how-to-hack-china-for-just-1-800.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;A Chinese domain name that is for sale could be misused, security experts say &lt;/p&gt;    &lt;p&gt;Fraudsters may have a hot deal waiting for them in the form of an obscure Chinese domain name that&amp;#39;s for sale on the Internet. &lt;/p&gt;    &lt;p&gt;The wpad.cn domain is for sale, according to a note posted on the Web site. That fact probably doesn&amp;#39;t mean much to most people, but to Duane Wessels it&amp;#39;s a big deal. He says that if it fell into criminal hands it could be misused for phishing or other types of fraud. &lt;/p&gt;    &lt;p&gt;Wessels, the president of Measurement Factory, owns five wpad domains -- wpad.com, wpad.net, wpad.org, wpad.biz and wpad.us. Between them, he gets 5 million hits per day. Most of them come from Windows computers erroneously looking for network configuration information, thanks to a decade-old Windows bug that Microsoft first fixed in 1999. &lt;/p&gt;    &lt;p&gt;Nobody knows why sites like Wessels&amp;#39; continue to get so much traffic long after Microsoft patched the flaw. He thinks it may come from old versions of Windows, obscure programs with built-in Web components, or perhaps even misconfigured servers on the network. Microsoft did not respond to a query about the issue on Tuesday. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.networkworld.com/news/2009/111809-how-to-hack-china-for.html"&gt;http://www.networkworld.com/news/2009/111809-how-to-hack-china-for.html&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740768" width="1" height="1"&gt;</description></item><item><title>64-bit Windows safer, claims Microsoft</title><link>http://msmvps.com/blogs/donna/archive/2009/11/19/64-bit-windows-safer-claims-microsoft.aspx</link><pubDate>Thu, 19 Nov 2009 13:18:39 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740759</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1740759</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1740759</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/19/64-bit-windows-safer-claims-microsoft.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;Windows users running 64-bit versions of the operating system are less likely to get infected by attack code, Microsoft&amp;#39;s security team said yesterday. &lt;/p&gt;    &lt;p&gt;But that doesn&amp;#39;t mean they won&amp;#39;t, countered an outside security researcher. &lt;/p&gt;    &lt;p&gt;&amp;quot;64-bit Windows has some of the lowest reported malware infection rates in the first half of 2009,&amp;quot; said Joe Faulhaber of the Microsoft Malware Protection Center in a post to the group&amp;#39;s blog yesterday. &amp;quot;64-bit malware is still exceedingly rare in the wild.&amp;quot; &lt;/p&gt;    &lt;p&gt;Faulhaber cited statistics gleaned from Microsoft&amp;#39;s Malicious Software Removal Tool (MSRC), a free malware detection and deletion utility the company updates and pushes to users monthly. According to Microsoft&amp;#39;s data, the 64-bit version of Windows XP was 48% less likely to be infected than the 32-bit edition during the first half of 2009; PCs running Vista 64-bit, meanwhile, were 35% less likely to be infected than Vista 32-bit. &lt;/p&gt;    &lt;p&gt;That&amp;#39;s not necessarily true, said Alfred Huger, formerly with Symantec and currently vice president of engineering at security start-up Immunet. &amp;quot;There&amp;#39;s a lot of 64-bit malware,&amp;quot; said Huger. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Continued in &lt;a href="http://www.computerworld.com/s/article/9141017/64_bit_Windows_safer_claims_Microsoft"&gt;http://www.computerworld.com/s/article/9141017/64_bit_Windows_safer_claims_Microsoft&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Read the blog of MSRC in &lt;a href="http://blogs.technet.com/mmpc/archive/2009/11/16/whats-another-32bits-to-malware.aspx"&gt;http://blogs.technet.com/mmpc/archive/2009/11/16/whats-another-32bits-to-malware.aspx&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740759" width="1" height="1"&gt;</description></item><item><title>Malware writers feeding on Twilight mania</title><link>http://msmvps.com/blogs/donna/archive/2009/11/19/malware-writers-feeding-on-twilight-mania.aspx</link><pubDate>Thu, 19 Nov 2009 13:17:52 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740758</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1740758</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1740758</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2009/11/19/malware-writers-feeding-on-twilight-mania.aspx#comments</comments><description>&lt;blockquote&gt;   &lt;p&gt;Online scammers get their teeth into unsuspecting victims &lt;/p&gt;    &lt;p&gt;Growing interest about the Twilight vampire series is making life risky for fans seeking information online, experts have warned. &lt;/p&gt;    &lt;p&gt;Security firm PC Tools documented a growing number of attacks and scams related to the popular book and movie series. The company expects such attacks to increase with the release of the New Moon sequel. &lt;/p&gt;    &lt;p&gt;PC Tools said that many of the attacks follow familiar patterns, such as fake video sites. Scammers have loaded comment and forum pages with spam messages linking users to sites which claim to offer exclusive videos of New Moon. &lt;/p&gt;    &lt;p&gt;Rather than watching a bootleg of the movie, however, users are subjected to the classic &amp;#39;fake codec&amp;#39; attack in which the user is duped into installing a Trojan application disguised as a video player or plug-in. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.v3.co.uk/v3/news/2253535/malware-writers-feeding"&gt;http://www.v3.co.uk/v3/news/2253535/malware-writers-feeding&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740758" width="1" height="1"&gt;</description></item></channel></rss>