<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Donna's SecurityFlash</title><link>http://msmvps.com/blogs/donna/default.aspx</link><description>PC &amp;amp; Internet Security Blog</description><dc:language>en</dc:language><generator>CommunityServer 2008 SP1 (Build: 30619.63)</generator><item><title>Apple Safari Cross-Domain Cookie Injection Vulnerability</title><link>http://msmvps.com/blogs/donna/archive/2008/07/23/apple-safari-cross-domain-cookie-injection-vulnerability.aspx</link><pubDate>Wed, 23 Jul 2008 19:07:17 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641919</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1641919</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1641919</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/23/apple-safari-cross-domain-cookie-injection-vulnerability.aspx#comments</comments><description>&lt;p&gt;&lt;strong&gt;Affected Software:&lt;/strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;Safari 3.x&lt;br /&gt;Safari for Windows 3.x  &lt;p&gt;A vulnerability has been discovered in Apple Safari, which can be exploited by malicious people to bypass certain security restrictions.  &lt;p&gt;The problem is that websites are allowed to set cookies for certain country-specific secondary top-level domains. This can e.g. be exploited to fix a session by setting a known session ID in a cookie, which the browser sends to all web sites operating under an affected domain (e.g. co.uk, com.au).  &lt;p&gt;The vulnerability is confirmed in Apple Safari for Windows 3.1.2. Other versions may also be affected.  &lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;:&amp;nbsp; Do not browse untrusted web sites or follow untrusted links.  &lt;p&gt;&lt;a href="http://secunia.com/advisories/31128/"&gt;http://secunia.com/advisories/31128/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641919" width="1" height="1"&gt;</description></item><item><title>The Planet offers free backup, discounted data protection and firewalls</title><link>http://msmvps.com/blogs/donna/archive/2008/07/23/the-planet-offers-free-backup-discounted-data-protection-and-firewalls.aspx</link><pubDate>Wed, 23 Jul 2008 19:04:54 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641918</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1641918</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1641918</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/23/the-planet-offers-free-backup-discounted-data-protection-and-firewalls.aspx#comments</comments><description>&lt;p&gt;The Planet announced three new promotions that offer enhanced data protection and security for Planet Alpha dedicated server customers. For a limited time, new orders of Network Backup and EVault Backup are free for the first 90 days. Both solutions are hosted on The Planet’s world-class managed storage infrastructure and are available in 10GB - 80GB or larger capacities for mission-critical environments.&lt;/p&gt; &lt;p&gt;&lt;a title="http://www.net-security.org/secworld.php?id=6344" href="http://www.net-security.org/secworld.php?id=6344"&gt;http://www.net-security.org/secworld.php?id=6344&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641918" width="1" height="1"&gt;</description></item><item><title>DNS Flaw Unfixed as Experts Argue Protocol</title><link>http://msmvps.com/blogs/donna/archive/2008/07/23/dns-flaw-unfixed-as-experts-argue-protocol.aspx</link><pubDate>Wed, 23 Jul 2008 19:03:02 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641917</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1641917</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1641917</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/23/dns-flaw-unfixed-as-experts-argue-protocol.aspx#comments</comments><description>&lt;p&gt;Speculation continues as to what the ultimate systemic Domain Name System (DNS) flaw could be. This flaw apparently allows Web surfers to be spoofed, directing them to fake Web sites to gain passwords and load malware on their computers.  &lt;p&gt;The flaw was first revealed by Dan Kaminsky, a researcher at security firm IOActive Inc., although Kaminsky largely withheld the technical details of the exploit.  &lt;p&gt;In a Friday morning press conference, Kaminsky said that many of the patches released by various IT vendors and security firms reacting to his bug discovery (reported by CNet News.com) are at best temporary fixes to a more pervasive problem. Kaminsky added that he would be disclosing further findings at the Black Hat security conference in Las Vegas next month.  &lt;p&gt;&lt;a href="http://redmondmag.com/news/article.asp?EditorialsID=10069"&gt;http://redmondmag.com/news/article.asp?EditorialsID=10069&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641917" width="1" height="1"&gt;</description></item><item><title>Beware Fake Anti-Mailware With Fake Editors Choice Awards</title><link>http://msmvps.com/blogs/donna/archive/2008/07/23/beware-fake-anti-mailware-with-fake-editors-choice-awards.aspx</link><pubDate>Wed, 23 Jul 2008 18:58:10 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641915</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1641915</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1641915</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/23/beware-fake-anti-mailware-with-fake-editors-choice-awards.aspx#comments</comments><description>&lt;p&gt;From Larry Seltzer of PC Mag:  &lt;blockquote&gt; &lt;p&gt;This isn&amp;#39;t news, but it&amp;#39;s worth reminding everyone: there is a large category of malicious programs that present themselves as antispyware or antivirus programs. Having already established that they will lie about these things, they may lie about others. For instance, we recently came across one which claims to have won a number of awards, including the PC Magazine Editors&amp;#39; Choice.&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;a href="http://blogs.pcmag.com/securitywatch/2008/07/beware_fake_antimailware_with.php"&gt;http://blogs.pcmag.com/securitywatch/2008/07/beware_fake_antimailware_with.php&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641915" width="1" height="1"&gt;</description></item><item><title>Security flaws in online banking sites found to be widespread</title><link>http://msmvps.com/blogs/donna/archive/2008/07/23/security-flaws-in-online-banking-sites-found-to-be-widespread.aspx</link><pubDate>Wed, 23 Jul 2008 18:54:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641913</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1641913</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1641913</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/23/security-flaws-in-online-banking-sites-found-to-be-widespread.aspx#comments</comments><description>&lt;p&gt;More than 75 percent of the bank Web sites surveyed in a University of Michigan study had at least one design flaw that could make customers vulnerable to cyber thieves after their money or even their identity.  &lt;p&gt;Atul Prakash, a professor in the Department of Electrical Engineering and Computer Science and doctoral students Laura Falk and Kevin Borders examined the Web sites of 214 financial institutions in 2006. They will present the findings for the first time at the Symposium on Usable Privacy and Security meeting at Carnegie Mellon University July 25.  &lt;p&gt;&lt;a href="http://www.ns.umich.edu/htdocs/releases/story.php?id=6652"&gt;http://www.ns.umich.edu/htdocs/releases/story.php?id=6652&lt;/a&gt; via &lt;a href="http://blogs.zdnet.com/security/?p=1536"&gt;http://blogs.zdnet.com/security/?p=1536&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641913" width="1" height="1"&gt;</description></item><item><title>Hackers attack businesses, blogs and Web 2.0 sites</title><link>http://msmvps.com/blogs/donna/archive/2008/07/23/hackers-attack-businesses-blogs-and-web-2-0-sites.aspx</link><pubDate>Wed, 23 Jul 2008 18:51:24 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641912</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1641912</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1641912</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/23/hackers-attack-businesses-blogs-and-web-2-0-sites.aspx#comments</comments><description>&lt;p&gt;IT security and control firm Sophos has published new research into the first six months of cybercrime in 2008. The Sophos Security Threat Report examines existing and emerging security trends and has identified that criminals are increasingly using creative new techniques in their attempt to make money out of internet users.  &lt;ul&gt; &lt;li&gt;Website infection rate three times faster than 2007&lt;/li&gt; &lt;li&gt;Sophos has identified that the number one host for malware on the web is Blogger (Blogspot.com), which allows computer users to make their own websites easily at no charge. &lt;/li&gt; &lt;li&gt;Business websites attacked, office workers at risk, Web 2.0 introduces new threats&lt;br /&gt;Thousand of webpages belonging to Fortune 500 companies, government agencies and schools have been infected, putting visiting surfers at risk of infection and identity theft. High profile entertainment websites such as those belonging to Sony PlayStation, Euro 2008 ticket sales companies, and UK broadcaster ITV are amongst the many to have suffered from the problem. &lt;/li&gt; &lt;li&gt;Attacks via email file attachments, however, have reduced in 2008. Only one in every 2,500 emails examined in the first six months of 2008 was found to contain a malicious attachment, compared to one in 332 in the same period of 2007. &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Complete article at &lt;a href="http://sophos.com/pressoffice/news/articles/2008/07/security-report.html"&gt;http://sophos.com/pressoffice/news/articles/2008/07/security-report.html&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641912" width="1" height="1"&gt;</description></item><item><title>Asprox computer virus infects key government and consumer websites</title><link>http://msmvps.com/blogs/donna/archive/2008/07/23/asprox-computer-virus-infects-key-government-and-consumer-websites.aspx</link><pubDate>Wed, 23 Jul 2008 18:43:23 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641911</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1641911</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1641911</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/23/asprox-computer-virus-infects-key-government-and-consumer-websites.aspx#comments</comments><description>&lt;p&gt;Cyber-criminals have attacked key government and consumer websites, allowing them to steal the personal details of anyone browsing the sites, The Times has learnt.  &lt;p&gt;Eastern European hackers are suspected of placing the Asprox virus on more than a thousand British websites, including those run by the NHS and a local council, in the past two weeks.  &lt;p&gt;Experts described the Asprox virus as an alarming departure from commonplace viruses, which tend to be spread through rogue e-mails and unregulated websites.  &lt;p&gt;Unlike other viruses, Asprox sits undetected on mainstream sites, with any visitor at risk of being infected. The virus automatically installs itself on a visitor&amp;#39;s computer, allowing a hacker to access financial information.  &lt;p&gt;&lt;a href="http://technology.timesonline.co.uk/tol/news/tech_and_web/the_web/article4381034.ece"&gt;http://technology.timesonline.co.uk/tol/news/tech_and_web/the_web/article4381034.ece&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641911" width="1" height="1"&gt;</description></item><item><title>RIPN and PCWorld.com response on IP Hijacking in PCWorld.com's IP address</title><link>http://msmvps.com/blogs/donna/archive/2008/07/22/ripn-and-pcworld-com-response-on-ip-hijacking-in-pcworld-com-s-ip-address.aspx</link><pubDate>Tue, 22 Jul 2008 01:35:29 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641681</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1641681</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1641681</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/22/ripn-and-pcworld-com-response-on-ip-hijacking-in-pcworld-com-s-ip-address.aspx#comments</comments><description>&lt;p&gt;I blog it the &lt;a href="http://msmvps.com/blogs/donna/archive/2008/07/20/pcworld-com-victim-of-dns-cache-poisoning.aspx"&gt;other day&lt;/a&gt; and the response by the 2 company is at &lt;a title="http://www.dozleng.com/updates/index.php?showtopic=16134" href="http://www.dozleng.com/updates/index.php?showtopic=16134"&gt;http://www.dozleng.com/updates/index.php?showtopic=16134&lt;/a&gt;&lt;/p&gt; &lt;p&gt;The impact of this type of issue to users are:&lt;/p&gt; &lt;p&gt;Disruption&lt;br /&gt;Deception&lt;br /&gt;Disclosure &lt;p&gt;So it&amp;#39;s good that pcworld.com is now on it and taking security measures to avoid it in happening again. &lt;p&gt;We normally block bad domains and bad IP address.&amp;nbsp; Whenever a good IP address get hijack by another &amp;#39;entity&amp;#39; (domain), we still trust the owner of legitimate IP address but we need to take action by continue blocking it until we are positive that the owner of the legitimate IP address is &amp;quot;on&amp;quot; it by protecting their content and visitors. &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641681" width="1" height="1"&gt;</description></item><item><title>PCWorld.com victim of DNS Cache poisoning?</title><link>http://msmvps.com/blogs/donna/archive/2008/07/20/pcworld-com-victim-of-dns-cache-poisoning.aspx</link><pubDate>Sun, 20 Jul 2008 06:53:39 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641518</guid><dc:creator>donna</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1641518</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1641518</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/20/pcworld-com-victim-of-dns-cache-poisoning.aspx#comments</comments><description>&lt;p&gt;I sent email to nic contact of pcworld.com today but if anyone has contact with them, please inform them of the issue:&lt;/p&gt; &lt;p&gt;DNS resolver:&lt;/p&gt; &lt;p&gt;removespyware.ru&amp;#39;s IP address is resolved as 70.42.185.10&lt;/p&gt; &lt;p&gt;70.42.185.10 is pcworld.com&lt;/p&gt; &lt;p&gt;&lt;a title="http://www.dozleng.com/updates/index.php?showtopic=16134" href="http://www.dozleng.com/updates/index.php?showtopic=16134"&gt;http://www.dozleng.com/updates/index.php?showtopic=16134&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641518" width="1" height="1"&gt;</description></item><item><title>Latest Firewall Challenge results</title><link>http://msmvps.com/blogs/donna/archive/2008/07/18/latest-firewall-challenge-results.aspx</link><pubDate>Fri, 18 Jul 2008 07:54:53 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641320</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1641320</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1641320</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/18/latest-firewall-challenge-results.aspx#comments</comments><description>&lt;p&gt;1. Outpost Firewall Pro 2009&lt;br /&gt;2. Online Armor&lt;br /&gt;3. Comodo Firewall &lt;br /&gt;4. ProSecurity &lt;blockquote&gt; &lt;p&gt;Outpost Firewall Pro 2009 6.5.2355.316.0597 leads the challenge with 99%, tightly followed by the paid version of Online Armor Personal Firewall 2.1.0.131 with 98% and the best free product – Comodo Firewall Pro 3.0.22.349 with 95%. ProSecurity 1.43, which will be replaced by Real-time Defender in the future, is on the third place with 93%. All these products reached the Excellent protection level. Online Armor Personal Firewall 2.1.0.131 Free and Kaspersky Internet Security 7.0.1.325 are close to the excellent results. &lt;/p&gt; &lt;p&gt;Among the newly tested products, Ashampoo FireWall FREE 1.20 and Webroot Desktop Firewall 5.5.10.20 reached the best network performance results. The worst results were measured with G DATA InternetSecurity 2008.  &lt;p&gt;It seems that Firewall Challenge tests make a big difference between really good products and the rest of the world. Most of the products are filtered in very low levels which means that they probably miss some critical features.  &lt;p&gt;However, it is crucial to know what does it mean if a product succeeds in our tests and what does it mean if it fails. Before you start interpreting the results, you should be familiar with the information on the index page, especially with the methodology and rules. You should also know which kind of products do we test before you start to interpret the results.&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;a title="http://www.matousec.com/projects/firewall-challenge/results.php" href="http://www.matousec.com/projects/firewall-challenge/results.php"&gt;http://www.matousec.com/projects/firewall-challenge/results.php&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641320" width="1" height="1"&gt;</description></item><item><title>3rd Party ads in CNET have been hijacked</title><link>http://msmvps.com/blogs/donna/archive/2008/07/17/3rd-party-ads-in-cnet-have-been-hijacked.aspx</link><pubDate>Thu, 17 Jul 2008 17:38:51 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641244</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1641244</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1641244</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/17/3rd-party-ads-in-cnet-have-been-hijacked.aspx#comments</comments><description>&lt;p&gt;&lt;a title="http://www.dozleng.com/updates/index.php?showtopic=16111" href="http://www.dozleng.com/updates/index.php?showtopic=16111"&gt;http://www.dozleng.com/updates/index.php?showtopic=16111&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641244" width="1" height="1"&gt;</description></item><item><title>Firefox 3.0.1 with security fixes</title><link>http://msmvps.com/blogs/donna/archive/2008/07/17/firefox-3-0-1-with-security-fixes.aspx</link><pubDate>Thu, 17 Jul 2008 04:27:03 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641178</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1641178</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1641178</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/17/firefox-3-0-1-with-security-fixes.aspx#comments</comments><description>&lt;p&gt;They announced the 2 &lt;a href="http://msmvps.com/blogs/donna/archive/2008/07/16/mozilla-security-advisories.aspx"&gt;yesterday&lt;/a&gt; and announced another one:&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.mozilla.org/security/announce/2008/mfsa2008-36.html"&gt;MFSA 2008-36&lt;/a&gt; Crash with malformed GIF file on Mac OS X&lt;/p&gt; &lt;p&gt;Get v3.0.1 now to take advantage of the security fixes and other program fixes.&amp;nbsp; Release notes &lt;a href="http://en-us.www.mozilla.com/en-US/firefox/3.0.1/releasenotes/"&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641178" width="1" height="1"&gt;</description></item><item><title>Malware and Phished Colonial Bank website</title><link>http://msmvps.com/blogs/donna/archive/2008/07/16/malware-and-phished-colonial-bank-website.aspx</link><pubDate>Wed, 16 Jul 2008 17:38:08 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641117</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1641117</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1641117</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/16/malware-and-phished-colonial-bank-website.aspx#comments</comments><description>&lt;p&gt;Phishing E-mail: Colonial Vendors and Business Associates&lt;/p&gt; &lt;p&gt;Phishing E-mail: Colonial Bank WebBiz Alert - Update&lt;/p&gt; &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/phishedcolonial_5F00_2.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="244" alt="phishedcolonial" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/phishedcolonial_5F00_thumb.jpg" width="196" border="0" /&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/phishedcolonial2_5F00_2.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="244" alt="phishedcolonial2" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/phishedcolonial2_5F00_thumb.jpg" width="196" border="0" /&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;Phished website with link to malware (auto-download)&lt;/p&gt; &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/phishedcolonialmalware_5F00_2.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="169" alt="phishedcolonialmalware" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/phishedcolonialmalware_5F00_thumb.jpg" width="244" border="0" /&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;Only 9 malware scanner will detect the malicious file:  &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/colonialmalwarevt_5F00_2.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="214" alt="colonialmalwarevt" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/colonialmalwarevt_5F00_thumb.jpg" width="244" border="0" /&gt;&lt;/a&gt;  &lt;p&gt;&lt;a href="http://www.virustotal.com/analisis/71edda93864f8daa8abbb2b113f3282a"&gt;http://www.virustotal.com/analisis/71edda93864f8daa8abbb2b113f3282a&lt;/a&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641117" width="1" height="1"&gt;</description></item><item><title>Mozilla Security Advisories</title><link>http://msmvps.com/blogs/donna/archive/2008/07/16/mozilla-security-advisories.aspx</link><pubDate>Wed, 16 Jul 2008 10:48:39 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641073</guid><dc:creator>donna</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1641073</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1641073</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/16/mozilla-security-advisories.aspx#comments</comments><description>&lt;ul&gt; &lt;li&gt;&lt;strong&gt;&lt;a href="http://www.mozilla.org/security/announce/2008/mfsa2008-35.html"&gt;MFSA 2008-35&lt;/a&gt;&lt;/strong&gt; Command-line URLs launch multiple tabs when Firefox not running&lt;/li&gt; &lt;li&gt;&lt;a href="http://www.mozilla.org/security/announce/2008/mfsa2008-34.html"&gt;&lt;strong&gt;MFSA 2008-34&lt;/strong&gt;&lt;/a&gt; Remote code execution by overflowing CSS reference counter&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;a title="http://www.mozilla.org/security/announce/" href="http://www.mozilla.org/security/announce/"&gt;http://www.mozilla.org/security/announce/&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;a title="http://www.mozilla.org/projects/security/known-vulnerabilities.html" href="http://www.mozilla.org/projects/security/known-vulnerabilities.html"&gt;http://www.mozilla.org/projects/security/known-vulnerabilities.html&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641073" width="1" height="1"&gt;</description></item><item><title>Rogue Software: Antivirus Master</title><link>http://msmvps.com/blogs/donna/archive/2008/07/15/rogue-software-antivirus-master.aspx</link><pubDate>Tue, 15 Jul 2008 22:19:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1641030</guid><dc:creator>donna</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1641030</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1641030</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/15/rogue-software-antivirus-master.aspx#comments</comments><description>&lt;p&gt;Antivirus Master - Rogue Product&lt;br /&gt;Date Published: Tuesday, July 15, 2008&lt;br /&gt;Category : Rogue Security Software &lt;br /&gt;Also known as: FraudTool.Win32.UltimateAntivirus.m [Kaspersky]&lt;br /&gt;&lt;a href="http://ca.com/au/securityadvisor/pest/pest.aspx?id=453137639"&gt;http://ca.com/au/securityadvisor/pest/pest.aspx?id=453137639&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Site to block using hosts file and if you are using Outpost Firewall, add it in &lt;a href="http://www.dozleng.com/updates/index.php?act=calendar&amp;amp;cal_id=1&amp;amp;code=showevent&amp;amp;event_id=44637"&gt;IP Blocklist&lt;/a&gt;:&lt;br /&gt;anvimaster.com - &lt;a href="http://www.networksolutions.com/whois/results.jsp?domain=anvimaster.com"&gt;whois result here&lt;br /&gt;&lt;/a&gt;anvi-scanner.com - &lt;a href="http://www.networksolutions.com/whois/results.jsp?domain=anvi-scanner.com"&gt;whois result here&lt;/a&gt;&lt;br /&gt;scanner.anvi-scanner.com &lt;/p&gt;
&lt;p&gt;Note: &lt;a href="http://www.dozleng.com/updates/index.php?act=calendar&amp;amp;cal_id=1&amp;amp;code=showevent&amp;amp;event_id=44637"&gt;today&amp;#39;s update on IP Blocklist&lt;/a&gt; includes the above to be block by Outpost Firewall.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1641030" width="1" height="1"&gt;</description></item><item><title>Updated: CoU Updates Search engine in browser's search bar</title><link>http://msmvps.com/blogs/donna/archive/2008/07/15/updated-cou-updates-search-engine-in-browser-s-search-bar.aspx</link><pubDate>Tue, 15 Jul 2008 14:14:30 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1640896</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1640896</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1640896</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/15/updated-cou-updates-search-engine-in-browser-s-search-bar.aspx#comments</comments><description>&lt;p&gt;I have added CoU Calendar search engine for &lt;strong&gt;Internet Explorer 7, Firefox and Opera&lt;/strong&gt; browsers today so I can search using the built-in search bar any posted updates in CoU&amp;#39;s Calendar. For CoU members and visitors (guests) who want this also, please follow the guide at &lt;a href="http://www.dozleng.com/updates/index.php?showtopic=16074"&gt;http://www.dozleng.com/updates/index.php?showtopic=16074&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640896" width="1" height="1"&gt;</description></item><item><title>CoU Updates Search engine in browser's search bar</title><link>http://msmvps.com/blogs/donna/archive/2008/07/15/cou-updates-search-engine-in-browser-s-search-bar.aspx</link><pubDate>Tue, 15 Jul 2008 08:25:07 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1640863</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1640863</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1640863</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/15/cou-updates-search-engine-in-browser-s-search-bar.aspx#comments</comments><description>&lt;p&gt;I have added CoU Calendar search engine in IE and Opera browsers today so I can search using the built-in search bar any posted updates in CoU&amp;#39;s Calendar. For CoU members and visitors (guests) who want this also, please follow the guide at &lt;a title="http://www.dozleng.com/updates/index.php?showtopic=16074" href="http://www.dozleng.com/updates/index.php?showtopic=16074"&gt;http://www.dozleng.com/updates/index.php?showtopic=16074&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640863" width="1" height="1"&gt;</description></item><item><title>Sick of Storm Worm news? I'm not</title><link>http://msmvps.com/blogs/donna/archive/2008/07/14/sick-of-storm-worm-news-i-m-not.aspx</link><pubDate>Mon, 14 Jul 2008 16:41:29 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1640757</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1640757</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1640757</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/14/sick-of-storm-worm-news-i-m-not.aspx#comments</comments><description>&lt;p&gt;I am not really sick of hearing about Storm Worm news because it&amp;#39;s not like EICAR test file yet.&amp;nbsp; Why? Because with EICAR test file, all antivirus will detect it as EICAR but for Storm Worm, um.. not:&lt;/p&gt; &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/stormworm_5F00_2.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="115" alt="stormworm" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/stormworm_5F00_thumb.jpg" width="244" border="0" /&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;It will offer secret_archive.exe file when user visits or clicks such links:&lt;/p&gt; &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/stormworm2_5F00_2.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="90" alt="stormworm2" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/stormworm2_5F00_thumb.jpg" width="244" border="0" /&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;So it is really not like EICAR like yet.&amp;nbsp; Scanners still need to do more work to be able to detect all variants of Storm Worm:&lt;/p&gt; &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/stormwormvt_5F00_2.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="215" alt="stormwormvt" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/stormwormvt_5F00_thumb.jpg" width="244" border="0" /&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;&lt;a title="http://www.virustotal.com/analisis/b0d43f3fa36f76695a0e30ee846322df" href="http://www.virustotal.com/analisis/b0d43f3fa36f76695a0e30ee846322df"&gt;http://www.virustotal.com/analisis/b0d43f3fa36f76695a0e30ee846322df&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Well, malware scanners have excuse, EICAR test file has no variant.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640757" width="1" height="1"&gt;</description></item><item><title>In the wild: Rogue Antivirus XP 2008 SPAM</title><link>http://msmvps.com/blogs/donna/archive/2008/07/14/in-the-wild-rogue-antivirus-xp-2008-spam.aspx</link><pubDate>Mon, 14 Jul 2008 16:34:41 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1640755</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1640755</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1640755</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/14/in-the-wild-rogue-antivirus-xp-2008-spam.aspx#comments</comments><description>&lt;p&gt;The campaign by bad guys to spread their rogue antivirus program&amp;#39;s installer of Antivirus XP 2008 is not only thru trojan infection but also via email SPAM:&lt;/p&gt; &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/roguespam_5F00_2.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="151" alt="roguespam" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/roguespam_5F00_thumb.jpg" width="244" border="0" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Going to the bad link will try to auto-download the installer of Rogue antivirus XP 2008&amp;#39;s installer. &lt;/p&gt; &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/roguespam2_5F00_2.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="176" alt="roguespam2" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/roguespam2_5F00_thumb.jpg" width="244" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640755" width="1" height="1"&gt;</description></item><item><title>In the Wild: UPS Packet Service malware SPAM - ups_invoice.zip</title><link>http://msmvps.com/blogs/donna/archive/2008/07/14/ups-packet-service-malware-spam.aspx</link><pubDate>Mon, 14 Jul 2008 16:26:29 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1640754</guid><dc:creator>donna</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1640754</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1640754</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2008/07/14/ups-packet-service-malware-spam.aspx#comments</comments><description>&lt;p&gt;It&amp;#39;s in the wild - SPAM with infected file ups_invoice.zip and my inbox has 4 of it today:&lt;/p&gt; &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/ups_5F00_2.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="116" alt="ups" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/ups_5F00_thumb.jpg" width="244" border="0" /&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/ups2_5F00_2.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="63" alt="ups2" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/ups2_5F00_thumb.jpg" width="244" border="0" /&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;63% of malware scanner will detect the infected file, if user mistakenly download retrieve this unwanted email or save or touch that file:&lt;/p&gt; &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/upsvt_5F00_2.jpg"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" height="209" alt="upsvt" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/donna/upsvt_5F00_thumb.jpg" width="244" border="0" /&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;Scan result:&amp;nbsp; &lt;a title="http://www.virustotal.com/analisis/07d607ef1cfcd0b67fe27595a71a9452" href="http://www.virustotal.com/analisis/07d607ef1cfcd0b67fe27595a71a9452"&gt;http://www.virustotal.com/analisis/07d607ef1cfcd0b67fe27595a71a9452&lt;/a&gt;&lt;/p&gt; &lt;p&gt;NOTE:&amp;nbsp; If you will google &amp;quot;UPS Packet&amp;quot; or UPS Paket&amp;quot;, you will see the same message posted in newsgroup and forums :(&lt;/p&gt; &lt;p&gt;....really in the wild so be careful guys.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1640754" width="1" height="1"&gt;</description></item></channel></rss>