<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Search results for 'app:weblogs' matching tag 'General Security News'</title><link>http://msmvps.com/search/SearchResults.aspx?q=app:weblogs&amp;tag=General+Security+News&amp;orTags=0&amp;o=DateDescending</link><description>Search results for 'app:weblogs' matching tag 'General Security News'</description><dc:language>en-US</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Seagate settles class action: cash back over misleading hard drive capacities</title><link>http://msmvps.com/blogs/donna/archive/2007/10/29/seagate-settles-class-action-cash-back-over-misleading-hard-drive-capacities.aspx</link><pubDate>Mon, 29 Oct 2007 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1273084</guid><dc:creator>donna</dc:creator><description>&lt;p&gt;The world&amp;#39;s largest hard disk manufacturer will offer customers 5% cash back on disk drives bought over the last six years in order to settle a legal action over the measurement of hard drive capacity.  &lt;p&gt;But the real story starts way back, when marketers decided 24 bytes didn&amp;#39;t mean much. In modern terms, it&amp;#39;s equivalent to a fraction of a cent, or the weight of a feather atop a two tonne truck. &lt;p&gt;Story at &lt;a title="http://apcmag.com/7449/seagate_offers_cash_to_customers_for_missing_megabytes" href="http://apcmag.com/7449/seagate_offers_cash_to_customers_for_missing_megabytes"&gt;http://apcmag.com/7449/seagate_offers_cash_to_customers_for_missing_megabytes&lt;/a&gt; via &lt;a href="http://www.dozleng.com/updates/index.php?showtopic=16141"&gt;CoU&lt;/a&gt;. &lt;p&gt;You can file your claim at &lt;a title="http://www.harddrive-settlement.com/" href="http://www.harddrive-settlement.com/"&gt;http://www.harddrive-settlement.com/&lt;/a&gt;&lt;/p&gt;</description></item><item><title>10 CoU Members will receive ESET's NOD32 antivirus</title><link>http://msmvps.com/blogs/donna/archive/2007/10/29/10-cou-members-will-receive-eset-s-nod32-antivirus.aspx</link><pubDate>Mon, 29 Oct 2007 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1273072</guid><dc:creator>donna</dc:creator><description>&lt;p&gt;Calendar of Updates thanks &lt;a href="http://www.eset.com"&gt;ESET&lt;/a&gt; for donating 10 e-license of NOD32 antivirus!&lt;/p&gt; &lt;p&gt;&lt;a title="http://www.dozleng.com/updates/index.php?s=92f54afb76e576c8a18ddf003e07e992&amp;amp;showtopic=16139" href="http://www.dozleng.com/updates/topic16139"&gt;http://www.dozleng.com/updates/topic16139&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Storm Worm variant now using Kittycard.exe as filename</title><link>http://msmvps.com/blogs/donna/archive/2007/10/27/storm-worm-variant-now-using-kittycard-exe-as-filename.aspx</link><pubDate>Sat, 27 Oct 2007 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1267715</guid><dc:creator>donna</dc:creator><description>&lt;p&gt;Kittycard.exe is now of&amp;nbsp;one the filename use&amp;nbsp;by this Storm Worm.&lt;/p&gt;
&lt;p&gt;Email received today:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://msmvps.com/blogs/donna/WindowsLiveWriter/StormWormvariantnowusingKi.exeasfilename_A70/kitty1028_2.jpg"&gt;&lt;img style="BORDER-RIGHT:0px;BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height="58" alt="kitty1028" src="http://msmvps.com/blogs/donna/WindowsLiveWriter/StormWormvariantnowusingKi.exeasfilename_A70/kitty1028_thumb.jpg" width="244" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;The new filename is Kittycard.exe:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://msmvps.com/blogs/donna/WindowsLiveWriter/StormWormvariantnowusingKi.exeasfilename_A70/kitty1028a_2.jpg"&gt;&lt;img style="BORDER-RIGHT:0px;BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height="166" alt="kitty1028a" src="http://msmvps.com/blogs/donna/WindowsLiveWriter/StormWormvariantnowusingKi.exeasfilename_A70/kitty1028a_thumb.jpg" width="244" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Half of malware scanners via VirusTotal.com will detect it while half did not:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://msmvps.com/blogs/donna/WindowsLiveWriter/StormWormvariantnowusingKi.exeasfilename_A70/kitty1028b_2.jpg"&gt;&lt;img style="BORDER-RIGHT:0px;BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height="43" alt="kitty1028b" src="http://msmvps.com/blogs/donna/WindowsLiveWriter/StormWormvariantnowusingKi.exeasfilename_A70/kitty1028b_thumb.jpg" width="244" border="0" /&gt;&lt;/a&gt; &lt;a href="http://msmvps.com/blogs/donna/WindowsLiveWriter/StormWormvariantnowusingKi.exeasfilename_A70/kitty1028c_2.jpg"&gt;&lt;img style="BORDER-RIGHT:0px;BORDER-TOP:0px;BORDER-LEFT:0px;BORDER-BOTTOM:0px;" height="244" alt="kitty1028c" src="http://msmvps.com/blogs/donna/WindowsLiveWriter/StormWormvariantnowusingKi.exeasfilename_A70/kitty1028c_thumb.jpg" width="207" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For you... to read&lt;/strong&gt;:&lt;/p&gt;
&lt;p&gt;The Storm Worm: &lt;a title="http://www.schneier.com/blog/archives/2007/10/the_storm_worm.html" href="http://www.schneier.com/blog/archives/2007/10/the_storm_worm.html"&gt;http://www.schneier.com/blog/archives/2007/10/the_storm_worm.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Just How Bad Is the Storm Worm:&lt;/p&gt;
&lt;p&gt;&lt;a title="http://blog.washingtonpost.com/securityfix/2007/10/the_storm_worm_maelstrom_or_te.html" href="http://blog.washingtonpost.com/securityfix/2007/10/the_storm_worm_maelstrom_or_te.html"&gt;http://blog.washingtonpost.com/securityfix/2007/10/the_storm_worm_maelstrom_or_te.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;My previous blog entries on Kitty (Storm Worm) :&lt;/p&gt;
&lt;p&gt;&lt;a href="http://msmvps.com/blogs/donna/archive/2007/10/21/2-more-kitty-storm-worm-gone-undetected-by-many-scanner.aspx"&gt;2 more Kitty&lt;/a&gt;, &lt;a href="http://msmvps.com/blogs/donna/archive/2007/10/22/kitty-detection-improving.aspx"&gt;Kitty Detection Improving&lt;/a&gt;, &lt;a href="http://msmvps.com/blogs/donna/archive/2007/10/21/norton-blocked-kitty-finally-less-av-detects-it-including-nod32.aspx"&gt;Norton blocked Kitty&lt;/a&gt;, &lt;a href="http://msmvps.com/blogs/donna/archive/2007/10/12/kitty-kitty.aspx"&gt;Kitty Kitty&lt;/a&gt;&lt;/p&gt;</description></item><item><title>What's with the malicious PDF file?</title><link>http://msmvps.com/blogs/donna/archive/2007/10/27/what-s-with-the-malicious-pdf-file.aspx</link><pubDate>Sat, 27 Oct 2007 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1266931</guid><dc:creator>donna</dc:creator><description>&lt;p&gt;Symantec wrote:&amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;em&gt;the PDF file will download ldr.exe file&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;F-Secure reports:&lt;/p&gt; &lt;p&gt;&lt;em&gt;&lt;strong&gt;The PDF is spiced with CVE-2007-5020 exploit that downloads ms32.exe that downloads more components.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt; &lt;p&gt;So I grab both .exe files (ms2.exe and ldr.exe) and uploaded it to Virustotal.com.&amp;nbsp; The AVs should protect and detect users from it if it failed to detect and block the malicious PDF file.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;&lt;font color="#ff0000"&gt;Scan results:&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Only 50% of malware scanners will detect the ms2.exe as malicious.&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;&lt;strong&gt;71.88% of malware scanners will detect the ldr.exe as malicious.&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Screenshots of the result at &lt;a title="http://www.dozleng.com/updates/index.php?showtopic=16119&amp;amp;st=0&amp;amp;gopid=69908&amp;amp;#entry69908" href="http://www.dozleng.com/updates/index.php?showtopic=16119"&gt;http://www.dozleng.com/updates/index.php?showtopic=16119&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Security experts blast New Jersey AG</title><link>http://msmvps.com/blogs/donna/archive/2007/10/27/security-experts-blast-new-jersey-ag.aspx</link><pubDate>Sat, 27 Oct 2007 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1266731</guid><dc:creator>donna</dc:creator><description>&lt;p&gt;Security experts are saying that a well-intentioned effort by the New Jersey Office of the Attorney General to combat phishing may backfire.  &lt;p&gt;Earlier this week, State Attorney General Anne Milgram called on four banks -- Bank of America, Citibank, Washington Mutual, and New Jersey-based Sun National Bank -- to provide her with details on how they respond to phishing incidents.  &lt;p&gt;&lt;a href="http://www.networkworld.com/news/2007/102607-security-experts-blast-new-jersey.html"&gt;http://www.networkworld.com/news/2007/102607-security-experts-blast-new-jersey.html&lt;/a&gt;&lt;/p&gt;</description></item><item><title>SANS Internet Storm Center: Request for info, IPs, exploit examples on PDF mailto documents</title><link>http://msmvps.com/blogs/donna/archive/2007/10/27/sans-internet-storm-center-request-for-info-ips-exploit-examples-on-pdf-mailto-documents.aspx</link><pubDate>Sat, 27 Oct 2007 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1266510</guid><dc:creator>donna</dc:creator><description>&lt;blockquote&gt; &lt;p&gt;we are looking for examples of the PDFs being sent out&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=3566"&gt;http://isc.sans.org/diary.html?storyid=3566&lt;/a&gt;&lt;/p&gt; &lt;p&gt;I send one copy of the PDF file to you guys and the IP info where the email was sent out.&amp;nbsp; Hope you got it :)&lt;/p&gt;</description></item><item><title>In the wild: Malicious PDF files; Which AV will detect it?</title><link>http://msmvps.com/blogs/donna/archive/2007/10/26/in-the-wild-malicious-pdf-files.aspx</link><pubDate>Fri, 26 Oct 2007 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1265552</guid><dc:creator>donna</dc:creator><description>&lt;p&gt;If you haven&amp;#39;t update your Adobe Reader to v8.1.1, you better to do it NOW.&lt;/p&gt; &lt;p&gt;The vulnerability is being exploited now and yup, it&amp;#39;s in the wild because I received copies already.&amp;nbsp; Screenshots at &lt;a title="http://www.dozleng.com/updates/index.php?showtopic=16119" href="http://www.dozleng.com/updates/index.php?showtopic=16119"&gt;http://www.dozleng.com/updates/index.php?showtopic=16119&lt;/a&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;Adobe fixed the security issue by releasing v8.1.1.&amp;nbsp; See their advisory &lt;a href="http://www.adobe.com/support/security/bulletins/apsb07-18.html"&gt;here&lt;/a&gt; and please update NOW.&lt;/p&gt; &lt;p&gt;Microsoft updated their &lt;a href="http://www.microsoft.com/technet/security/advisory/943521.mspx"&gt;security advisory&lt;/a&gt; on the above due to increased of threat level.&lt;/p&gt; &lt;p&gt;Read the write-up of Symantec on what they detected and blocked in the email I received : &lt;a href="http://securityresponse.symantec.com/security_response/writeup.jsp?docid=2007-102318-0451-99"&gt;Bloodhound.Exploit.163&lt;/a&gt; - Bloodhound.Exploit.163 is a heuristic detection for PDF files attempting to exploit the Adobe Acrobat Mailto Unspecified PDF File Security Vulnerability&lt;/p&gt; &lt;p&gt;See also: &lt;a href="http://blogs.technet.com/robert_hensing/archive/2007/10/26/it-begins-pdf-spam-run.aspx"&gt;http://blogs.technet.com/robert_hensing/archive/2007/10/26/it-begins-pdf-spam-run.aspx&lt;/a&gt; (Thanks to MVP Susan Bradley for the link)&lt;/p&gt; &lt;p&gt;Update:&amp;nbsp; Go to &lt;a title="http://www.dozleng.com/updates/index.php?showtopic=16119" href="http://www.dozleng.com/updates/index.php?showtopic=16119"&gt;http://www.dozleng.com/updates/index.php?showtopic=16119&lt;/a&gt; to see the VirusTotal.com scan result to find out which malware scanners is FAST in detecting malicious files that is IN THE WILD.&lt;/p&gt;</description></item><item><title>Fake IRS page and email, See which browser will protect user from phished site</title><link>http://msmvps.com/blogs/donna/archive/2007/10/26/fake-irs-page-and-email-see-which-browser-will-protect-user-from-phished-site.aspx</link><pubDate>Fri, 26 Oct 2007 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1265339</guid><dc:creator>donna</dc:creator><description>&lt;p&gt;See &lt;a title="http://www.dozleng.com/updates/index.php?showtopic=16115" href="http://www.dozleng.com/updates/index.php?showtopic=16115"&gt;http://www.dozleng.com/updates/index.php?showtopic=16115&lt;/a&gt; for screenshots.&lt;/p&gt; &lt;p&gt;Result:&lt;/p&gt; &lt;p&gt;Opera: 2&amp;nbsp; &lt;img alt="Thumbs-down" src="http://messenger.msn.com/MMM2006-04-19_17.00/Resource/emoticons/thumbs_down.gif" /&gt;&amp;nbsp;&lt;img alt="Thumbs-down" src="http://messenger.msn.com/MMM2006-04-19_17.00/Resource/emoticons/thumbs_down.gif" /&gt;&lt;br /&gt;Firefox: 1 &lt;img alt="Thumbs-up" src="http://messenger.msn.com/MMM2006-04-19_17.00/Resource/emoticons/thumbs_up.gif" /&gt; and 1&amp;nbsp; &lt;img alt="Thumbs-down" src="http://messenger.msn.com/MMM2006-04-19_17.00/Resource/emoticons/thumbs_down.gif" /&gt;&lt;br /&gt;Internet Explorer: 2&amp;nbsp; &lt;img alt="Thumbs-up" src="http://messenger.msn.com/MMM2006-04-19_17.00/Resource/emoticons/thumbs_up.gif" /&gt;&amp;nbsp;&lt;img alt="Thumbs-up" src="http://messenger.msn.com/MMM2006-04-19_17.00/Resource/emoticons/thumbs_up.gif" /&gt;&lt;/p&gt;</description></item><item><title>Symantec took a closer look on rogue applications</title><link>http://msmvps.com/blogs/donna/archive/2007/10/26/symantec-took-a-closer-look-on-rogue-applications.aspx</link><pubDate>Fri, 26 Oct 2007 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1265267</guid><dc:creator>donna</dc:creator><description>&lt;p&gt;Symantec blog today on how rogue applications infiltrate user&amp;#39;s machine to earn money.&lt;br /&gt;It&amp;#39;s done by rogue apps thru System tray, Active Desktop, Dialogue box.  &lt;p&gt;Symantec provided some screenshots including a misleading application with a Windows Vista look.  &lt;p&gt;&lt;a href="http://www.symantec.com/enterprise/security_response/weblog/2007/10/we_pwn_your_desktop.html"&gt;http://www.symantec.com/enterprise/security_response/weblog/2007/10/we_pwn_your_desktop.html&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Free Software Tests for Bot Infections</title><link>http://msmvps.com/blogs/donna/archive/2007/10/26/free-software-tests-for-bot-infections.aspx</link><pubDate>Fri, 26 Oct 2007 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1265215</guid><dc:creator>donna</dc:creator><description>&lt;p&gt;PineApp has released a free zombie test that can instantly discover whether an organization’s computer network might be an unwitting spamming machine -- a “zombie” or “bot” -- that can send thousands of infected spam messages to other networks—without its knowledge.  &lt;p&gt;As a global provider of appliance-based solutions for email and network security, PineApp Corporation (&lt;a href="http://www.pineapp.com)"&gt;http://www.pineapp.com)&lt;/a&gt; has created the free diagnostic tool—Zombie Detection System™ (ZDS™)—to determine if a network is infected. Organizations can simply go to &lt;a href="http://www.rbltest.com/"&gt;http://www.rbltest.com/&lt;/a&gt;, enter the IP address and get an instant analysis.  &lt;p&gt;&lt;a href="http://www.darkreading.com/document.asp?doc_id=137353"&gt;http://www.darkreading.com/document.asp?doc_id=137353&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>