Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Latest Storm Worm e-card attack wishes a Happy Labor Day

Storm The e-card attacks continue and users should avoid all untrusted e-card and other links.

Latest Storm Worm e-card attack wishes a Happy Labor Day
http://www.avertlabs.com/research/blog/index.php/2007/09/04/labor-day-gift-from-nuwar/

quote:

In addition to the usual Microsoft exploits, QuickTime and WinZip buffer overflow exploits are also attempted on a user’s machine. Given the slim likelihood of vulnerable third party applications being up to date on a user’s machine, it increases the attacker’s chances of a successful exploitation.

Lightning Example:

To: Harry
Subject: Happy Labor Day
From: (REMOVED)
Date: Tue, 4 Sep 2007 16:23:27 +0200

Here is a special greeting, to see it, click here:

hxxp://ecards.com/funcard/Lday?fj02rx6l4zvugtzfkqub8tc
(spoofed and points to a numeric IP address embedded within the HTML)