Watch out !! from “Winamp” “Without a Doubt” spam at Facebook

May 15, 2010 by admin  
Filed under Security News

If you got some posts from your friends in your facebook wall that says “YOUR NAME, THIS IS WITHOUT DOUBT THE SEXIEST VIDEO EVER! :P :P :P …” with a link “Candid Camera Prank! [HQ]“, like this picture.

If you click on the link then “Allow”  it will get your private information and posts at all your friends wall the same message, see this picture.

To protect your self when you receive the same message in your wall, don’t click on the link and click on Remove button on the right.

 

Take Care, Virus Experts Team.

 

Facebook disables chat after security hole discovered

May 6, 2010 by admin  
Filed under Security News

Facebook has taken down its instant messaging-style system which allows members to chat real-time with each other after claims that the system suffers from a serious security problem.

 

According to a report by TechCrunch, a security flaw allows your Facebook friends to secretly spy on your private live chats as well as any see any pending friend requests that you have made.

 

Facebook chat disabled

In the past Facebook has insisted that privacy is its “highest priority”, but there isgrowing concern that the site has played fast and loose with the personal information of its 400 million users, encouraging them to share too much private data online and changing privacy settings to be more “open”.

 

A video has been posted on YouTube which allegedly demonstrates the security hole:

 

The news that Facebook has disabled its chat system suggests that they are working on fixing the security problem. Hopefully it will be resolved quickly.

 

But even if this security issue is fixed promptly there are other security issues on Facebook, as with any other social network, that need to be considered if you plan on continuing to use the site. Make sure you read our guidelines for better security and privacy on Facebook.

 

Oh, and you might want to become a Fan of Sophos on Facebook too to ensure you are kept up-to-date with the latest security news.

 

by Graham Cluley, Sophos

 

 

Twitter fights back against spam, phishing, and other malicious links

March 11, 2010 by admin  
Filed under Security News

In a move that should be welcomed by many users, Twitter has announced that it is introducing a new feature to combat the many malicious and malware URLs that are distributed via the micro-blogging site.

 

In a blog entry posted by Del Harvey, Twitter’s Director of Trust and Safety, it was revealed that the site will start using its own URL shortener (twt.tl) for Twitter messages sent privately between two users via a direct message (DM), giving it the opportunity to “detect, intercept, and prevent the spread of bad links across all of Twitter”.

 

As Sophos’s Chet Wisniewski told DarkReading, the new http://twt.tl shortened url appears to be only evoked with email notifications for direct messages at this time.

 

Details of how Twitter is determining if a link is potentially malicious or not do not appear to have been released at this time, and it would certainly be great if Twitter would post some more information on how the system will work and what users can expect to see.

 

It’s also to be hoped that this new service will be rolled-out to other areas of Twitter too. We’ve seen many times in the past that phishing and spam attacks on Twitter don’t tend to restrict themselves purely to DMs, but will also often be found in the public timeline too, as the following YouTube video demonstrates:

 

(Enjoy this video? You can check out more on the SophosLabs YouTube channel and subscribe if you like)


The problem of dangerous links being distributed via Twitter has been growing for some time, with some 70% of people polled by Sophos reporting that they have been on the receiving end of spam and malware attacks via social networks in the last year.

 

The news of Twitter’s new twt.tl short url facility follows a few months after bit.ly announced that it would protect users against visiting webpages that may contain a malware, spam or phishing threat using technology from security vendors such as Sophos.

 

* Image source: wonderferret’s Flickr photostream (Creative Commons)


By Graham Cluley, Sophos

 


IE8 Security Review (Video)

March 8, 2010 by admin  
Filed under Security Channel

YouTube Preview Image

 

Features: What’s new in Internet Explorer 8 ?

Stay safer online

Browse with more confidence knowing Internet Explorer 8 helps protect you from evolving online threats right out of the box . The new SmartScreen filter and other built-in security features help you stay safe by protecting against deceptive and malicious websites which can compromise your data, privacy, and identity.

 

Learn more

 

Video of Twitter phishing: The BZPharma ‘LOL this is funny’ attack (Video)

February 24, 2010 by admin  
Filed under Security Channel

Twitter users are being warned about a widespread phishing attack spreading across the system, designed to steal the usernames and passwords of unsuspecting members.

 

Messages include

Lol. this is me??
lol , this is funny.
Lol. this you??

followed by a link in the form of

http://example.com/?rid=http://twitter.verify.bzpharma.net/login

where ‘example.com’ can vary. As we have seen many variations of the URL in its entirety, you would be wise to avoid clicking on any links which refer to bzpharma.net at the very least.

 

Watch this YouTube video for more details:

(Enjoy this video? You can check out more on the SophosLabs YouTube channel and subscribe if you like)


Although Twitter has urged users to be vigilant about the threat being distributed via private direct messages, it’s clear that dangerous links are also being posted in public feeds. This means that you can stumble across the links even if you aren’t sent it directly, or even if you are not a signed-up user of Twitter.

 

It appears what is happening is that the messages are being shared more widely because of third-party services like GroupTweet which extend the standard Twitter direct message (DM) functionality and allow private messages to be sent to multiple users *and* optionally made public.

 

As a result, as you can see in the video above, we have found Twitter accounts that have warned their followers about the phishing attack, only to subsequently fall victim to it themselves!

 

Regardless of how you come to click on the dangerous link, if you do enter your username and password on the fake Twitter login page your details will be phished and placed in the hands of hackers.

 

Twitter phishing website on bzpharma.net

The page then displays a “fail whale” screen, claiming that Twitter is over capacity, before taking you back to the real Twitter main page. As a result, compromised Twitter users may not realise that their login details have been stolen.

 

Interestingly, the bzpharma.net site doesn’t just appear to have been set up for Twitter phishing. It appears to also have been created for stealing the online identities of the Bebo social networking site too:

 

Bebo phishing page on bzpharma.net

If you have been tricked by the phishing attack and accidentally handed over your username and password, change your password immediately.

 

We’re going to see many more attacks against social networks in the future I’m afraid. Last month, Sophos published its Security Threat Report revealing that there had been an astonishing 70% rise in the number of users reporting spam and malware attacks via social networks in the last year.

 

Update: The phishing campaign appears to be bearing fruit for the hackers as they are now distributing spam selling herbal viagra from the compromised accounts. Learn more now.

 

By Graham Cluley, Sophos

 

Facebook privacy settings: What you need to know

December 11, 2009 by admin  
Filed under Security News

Facebook is making big changes to its privacy settings that may mean millions of people begin to expose information that they previously considered to be restricted to only their Facebook friends to the entire internet.


This YouTube video explains more.

 

Facebook is recommending that users adopt a series of new privacy settings that would reveal their personal data to anyone on the internet. Chances are that when you login to Facebook today you’ll be advised to make various pieces of your personal information available for “Everyone” to see.

To get a clear picture of what Facebook means by everyone (and its implications) you should check out the revised Facebook privacy policy:

 

"Information set to 'everyone' is publicly available information, may be accessed by everyone on the Internet (including people not logged into Facebook), is subject to indexing by third party search engines, may be associated with you outside of Facebook (such as when you visit other sites on the internet), and may be imported and exported by us and others without privacy limitations."

"The default privacy setting for certain types of information you post on Facebook is set to 'everyone.' You can review and change the default settings in your privacy settings. If you delete 'everyone' content that you posted on Facebook, we will remove it from your Facebook profile, but have no control over its use outside of Facebook."


 

So, let’s make this clear. If you make your information available to “everyone”, it actually means “everyone, forever”. Because even if you change your mind, it’s too late – and although Facebook say they will remove it from your profile they will have no control about how it is used outside of Facebook.

 

There’s a real danger that people will go along with Facebook’s recommendations without considering carefully the possible consequences.

 

by Graham Cluley, Sophos

 

Simple Tips For Better Web Password Security (Video)

October 30, 2009 by admin  
Filed under Security Channel

Simple tips for better web password security from Sophos Labs on Vimeo.

 

Paypal SCAM (phishing-attack) In Action (Video)

September 18, 2009 by admin  
Filed under Security Channel


For more information about Paypal SCAM (phishing-attack) ( Click Here )



Combofix – Malware Removal Made Easy (Video By mrizos)

August 17, 2009 by admin  
Filed under Removal Tips,Tools and Videos

Case Conficker ( Know More About Conficker,Downadup,Downup and Kido Worm ) (Video)

April 20, 2009 by admin  
Filed under Security Channel

Case Conficker / Downadup / Downup / Kido
Mikko Hypponen & Patrik Runald
F-Secure Corporation

Species Conference
February 2, 2009
Amsterdam