Host Security for SCADA and ICS Systems Part 2

February 23rd, 2012


Today’s discussion is part two in our series on critical infrastructure with Eric Knapp, Director of Critical Infrastructure Markets in McAfee’s global business development group. If you haven’t yet listened to or read part one, you might want to stop at this point and view that podcast here, or read the full transcript here in Read more...

Password management for non-obvious accounts

February 23rd, 2012


A continuation on: Time to check your DNS settings? After 7 March 2012, lots of people potentially can be hit as their systems are infected by a DNS Changer. Several government-CERTs have already warned their users. Rather than using the ISP’s DNS Servers, the malware has changed the settings to use DNS Servers controlled by the ... Read More...

Twitter report: Daily Updates for 2012-02-23

February 22nd, 2012
  • News of the World hacker named after court block lifted: Murdoch editor Andy Coulson fingered as key contact A m… http://t.co/sAQhCAVF #
  • PDF Malware Writers Keep Targeting Vulnerability: We keep seeing new waves of PDF file-based attacks that exploi… http://t.co/zGqORMsB #
  • IBM arms robo-sysadmin QRadar with virus know-how: X-Force gear combs through 13 billion threats a day IBM is be… http://t.co/IhecR7Yp #
  • Security platform uses virtual machine introspection: CounterTack announced three new solutions available on Eve… http://t.co/CfBG758c #
  • Los Angeles Police Site Hacked by CabinCr3w: The official website of the Los Angeles County Police Canine Associ… http://t.co/JbgU2X0c #
  • Akamai protects enterprises from DDoS and application security attacks: Akamai Technologies introduced Akamai Ko… http://t.co/xCVx0OXN #
  • TeamHav0k Finds XSS in British, French, and US Government Sites: Operation XSS, the operation launched by the gr… http://t.co/Gn3Ivf40 #
  • “Dropper” Trojan Hijacks Critical DLL File to Avoid Detection: The latest pieces of malware are not only develop… http://t.co/XOY8eilD #
  • Nightline Takes "A Trip to The iFactory": Nightline, a U.S. news program, will air what's being billed as a spec… http://t.co/6DKQMTC5 #
  • Users don't bother changing default passwords: Most people working with sensitive information want stricter secu… http://t.co/ICisGTWM #
  • Beware Changelog spammed-out malware attack: Internet users are receiving emails claiming to contain a changelog… http://t.co/tTrERGzg #
  • Experts: Many 4-Digit PINs Not Hard to Guess: Security researchers from University of Cambridge performed a stud… http://t.co/y1Nm8dgO #
  • Spam crashes to historic low as malware explodes on mobiles: Android Trojans soar, Mac viruses fall off a cliff … http://t.co/4nlOSmB0 #
  • IRS releases its top ‘Dirty Dozen’ tax scams: Ushering in tax season, the U.S. Internal Revenue Service (IRS) ha… http://t.co/kVB3w5Yj #
  • Anonymous Denies Targeting the DNS Root Servers: This is what happens when there is no clear hierarchy in a grou… http://t.co/oqOWEHpo #
  • New Zeus/SpyEye makes bots function as C&C servers: The latest build of the Zeus/SpyEye malware shows a change t… http://t.co/6EKNSWcI #
  • Protect Yourself from “SMiShing”: “SMiShing” is a silly word—even sillier than “phishing,” but equally dangerous… http://t.co/dWmj13MY #
  • iOS 5 Flaw Allows Unfettered Access to User's Contacts, Calls: A passcode flaw in Apple’s iOS 5 could allow unau… http://t.co/M8B0KDf5 #
  • XSS Flaw in Skype Shop May Allow Hackers to Steal User Accounts: Georgian security researcher Ucha Gobejishvil i… http://t.co/TRGg7gKd #
  • ASLR on Android 4 found wanting: A mitigation technique, ASLR, was added to Android 4 Ice Cream Sandwich and adv… http://t.co/Kn9Wf4r7 #
  • Waves of Attacks Target Adobe Reader Bug From 2010: Thanks to the wonderful tendency of users not to update thei… http://t.co/OLXSeDNY #
  • ACTA to Be Examined by the European Court of Justice: The recent protestS that have taken place worldwide and th… http://t.co/o862Qjvz #
  • YouPorn passwords available for download, thousands of users exposed: Want a free password for one of the world'… http://t.co/55Xq9BOW #
  • Indian govt to ask Yahoo, Google to route emails through servers in India: Web mail service providers such as Go… http://t.co/VzwjrR51 #
  • Grumble-flick chat site exposes flirts' privates: Oh, put it away – no, too late The email addresses and passwor… http://t.co/FlRHmQCI #
  • http://t.co/3h52IXhe security – step by step howto: I recently signed up for http://t.co/3h52IXhe, a hip, trendy p… http://t.co/RRfb2J4O #
  • NIST, Maryland Plan New Cybersecurity Center: The US National Institute of Standards and Technology (NIST) annou… http://t.co/bjOAAaif #
  • Gatekeeper and the Choice of Security for Mac Users: Context is a funny thing. In most segments of society, Appl… http://t.co/aBQh5d1e #
  • Rovnix Reloaded: new step of evolution: [More research from our colleagues in Russia]
    In the beginning of Februa… http://t.co/sUfnDf0P #
  • Twilight author’s official website attacked: Stephenie Meyer, author of the wildly popular Twilight series, can … http://t.co/cnTppppk #

Twitter report: Daily Updates for 2012-02-23

February 22nd, 2012
  • News of the World hacker named after court block lifted: Murdoch editor Andy Coulson fingered as key contact A m… http://t.co/sAQhCAVF #
  • PDF Malware Writers Keep Targeting Vulnerability: We keep seeing new waves of PDF file-based attacks that exploi… http://t.co/zGqORMsB #
  • IBM arms robo-sysadmin QRadar with virus know-how: X-Force gear combs through 13 billion threats a day IBM is be… http://t.co/IhecR7Yp #
  • Security platform uses virtual machine introspection: CounterTack announced three new solutions available on Eve… http://t.co/CfBG758c #
  • Los Angeles Police Site Hacked by CabinCr3w: The official website of the Los Angeles County Police Canine Associ… http://t.co/JbgU2X0c #
  • Akamai protects enterprises from DDoS and application security attacks: Akamai Technologies introduced Akamai Ko… http://t.co/xCVx0OXN #
  • TeamHav0k Finds XSS in British, French, and US Government Sites: Operation XSS, the operation launched by the gr… http://t.co/Gn3Ivf40 #
  • “Dropper” Trojan Hijacks Critical DLL File to Avoid Detection: The latest pieces of malware are not only develop… http://t.co/XOY8eilD #
  • Nightline Takes "A Trip to The iFactory": Nightline, a U.S. news program, will air what's being billed as a spec… http://t.co/6DKQMTC5 #
  • Users don't bother changing default passwords: Most people working with sensitive information want stricter secu… http://t.co/ICisGTWM #
  • Beware Changelog spammed-out malware attack: Internet users are receiving emails claiming to contain a changelog… http://t.co/tTrERGzg #
  • Experts: Many 4-Digit PINs Not Hard to Guess: Security researchers from University of Cambridge performed a stud… http://t.co/y1Nm8dgO #
  • Spam crashes to historic low as malware explodes on mobiles: Android Trojans soar, Mac viruses fall off a cliff … http://t.co/4nlOSmB0 #
  • IRS releases its top ‘Dirty Dozen’ tax scams: Ushering in tax season, the U.S. Internal Revenue Service (IRS) ha… http://t.co/kVB3w5Yj #
  • Anonymous Denies Targeting the DNS Root Servers: This is what happens when there is no clear hierarchy in a grou… http://t.co/oqOWEHpo #
  • New Zeus/SpyEye makes bots function as C&C servers: The latest build of the Zeus/SpyEye malware shows a change t… http://t.co/6EKNSWcI #
  • Protect Yourself from “SMiShing”: “SMiShing” is a silly word—even sillier than “phishing,” but equally dangerous… http://t.co/dWmj13MY #
  • iOS 5 Flaw Allows Unfettered Access to User's Contacts, Calls: A passcode flaw in Apple’s iOS 5 could allow unau… http://t.co/M8B0KDf5 #
  • XSS Flaw in Skype Shop May Allow Hackers to Steal User Accounts: Georgian security researcher Ucha Gobejishvil i… http://t.co/TRGg7gKd #
  • ASLR on Android 4 found wanting: A mitigation technique, ASLR, was added to Android 4 Ice Cream Sandwich and adv… http://t.co/Kn9Wf4r7 #
  • Waves of Attacks Target Adobe Reader Bug From 2010: Thanks to the wonderful tendency of users not to update thei… http://t.co/OLXSeDNY #
  • ACTA to Be Examined by the European Court of Justice: The recent protestS that have taken place worldwide and th… http://t.co/o862Qjvz #
  • YouPorn passwords available for download, thousands of users exposed: Want a free password for one of the world'… http://t.co/55Xq9BOW #
  • Indian govt to ask Yahoo, Google to route emails through servers in India: Web mail service providers such as Go… http://t.co/VzwjrR51 #
  • Grumble-flick chat site exposes flirts' privates: Oh, put it away – no, too late The email addresses and passwor… http://t.co/FlRHmQCI #
  • http://t.co/3h52IXhe security – step by step howto: I recently signed up for http://t.co/3h52IXhe, a hip, trendy p… http://t.co/RRfb2J4O #
  • NIST, Maryland Plan New Cybersecurity Center: The US National Institute of Standards and Technology (NIST) annou… http://t.co/bjOAAaif #
  • Gatekeeper and the Choice of Security for Mac Users: Context is a funny thing. In most segments of society, Appl… http://t.co/aBQh5d1e #
  • Rovnix Reloaded: new step of evolution: [More research from our colleagues in Russia]
    In the beginning of Februa… http://t.co/sUfnDf0P #
  • Twilight author’s official website attacked: Stephenie Meyer, author of the wildly popular Twilight series, can … http://t.co/cnTppppk #

Twitter report: Daily Updates for 2012-02-23

February 22nd, 2012
  • News of the World hacker named after court block lifted: Murdoch editor Andy Coulson fingered as key contact A m… http://t.co/sAQhCAVF #
  • PDF Malware Writers Keep Targeting Vulnerability: We keep seeing new waves of PDF file-based attacks that exploi… http://t.co/zGqORMsB #
  • IBM arms robo-sysadmin QRadar with virus know-how: X-Force gear combs through 13 billion threats a day IBM is be… http://t.co/IhecR7Yp #
  • Security platform uses virtual machine introspection: CounterTack announced three new solutions available on Eve… http://t.co/CfBG758c #
  • Los Angeles Police Site Hacked by CabinCr3w: The official website of the Los Angeles County Police Canine Associ… http://t.co/JbgU2X0c #
  • Akamai protects enterprises from DDoS and application security attacks: Akamai Technologies introduced Akamai Ko… http://t.co/xCVx0OXN #
  • TeamHav0k Finds XSS in British, French, and US Government Sites: Operation XSS, the operation launched by the gr… http://t.co/Gn3Ivf40 #
  • “Dropper” Trojan Hijacks Critical DLL File to Avoid Detection: The latest pieces of malware are not only develop… http://t.co/XOY8eilD #
  • Nightline Takes "A Trip to The iFactory": Nightline, a U.S. news program, will air what's being billed as a spec… http://t.co/6DKQMTC5 #
  • Users don't bother changing default passwords: Most people working with sensitive information want stricter secu… http://t.co/ICisGTWM #
  • Beware Changelog spammed-out malware attack: Internet users are receiving emails claiming to contain a changelog… http://t.co/tTrERGzg #
  • Experts: Many 4-Digit PINs Not Hard to Guess: Security researchers from University of Cambridge performed a stud… http://t.co/y1Nm8dgO #
  • Spam crashes to historic low as malware explodes on mobiles: Android Trojans soar, Mac viruses fall off a cliff … http://t.co/4nlOSmB0 #
  • IRS releases its top ‘Dirty Dozen’ tax scams: Ushering in tax season, the U.S. Internal Revenue Service (IRS) ha… http://t.co/kVB3w5Yj #
  • Anonymous Denies Targeting the DNS Root Servers: This is what happens when there is no clear hierarchy in a grou… http://t.co/oqOWEHpo #
  • New Zeus/SpyEye makes bots function as C&C servers: The latest build of the Zeus/SpyEye malware shows a change t… http://t.co/6EKNSWcI #
  • Protect Yourself from “SMiShing”: “SMiShing” is a silly word—even sillier than “phishing,” but equally dangerous… http://t.co/dWmj13MY #
  • iOS 5 Flaw Allows Unfettered Access to User's Contacts, Calls: A passcode flaw in Apple’s iOS 5 could allow unau… http://t.co/M8B0KDf5 #
  • XSS Flaw in Skype Shop May Allow Hackers to Steal User Accounts: Georgian security researcher Ucha Gobejishvil i… http://t.co/TRGg7gKd #
  • ASLR on Android 4 found wanting: A mitigation technique, ASLR, was added to Android 4 Ice Cream Sandwich and adv… http://t.co/Kn9Wf4r7 #
  • Waves of Attacks Target Adobe Reader Bug From 2010: Thanks to the wonderful tendency of users not to update thei… http://t.co/OLXSeDNY #
  • ACTA to Be Examined by the European Court of Justice: The recent protestS that have taken place worldwide and th… http://t.co/o862Qjvz #
  • YouPorn passwords available for download, thousands of users exposed: Want a free password for one of the world'… http://t.co/55Xq9BOW #
  • Indian govt to ask Yahoo, Google to route emails through servers in India: Web mail service providers such as Go… http://t.co/VzwjrR51 #
  • Grumble-flick chat site exposes flirts' privates: Oh, put it away – no, too late The email addresses and passwor… http://t.co/FlRHmQCI #
  • http://t.co/3h52IXhe security – step by step howto: I recently signed up for http://t.co/3h52IXhe, a hip, trendy p… http://t.co/RRfb2J4O #
  • NIST, Maryland Plan New Cybersecurity Center: The US National Institute of Standards and Technology (NIST) annou… http://t.co/bjOAAaif #
  • Gatekeeper and the Choice of Security for Mac Users: Context is a funny thing. In most segments of society, Appl… http://t.co/aBQh5d1e #
  • Rovnix Reloaded: new step of evolution: [More research from our colleagues in Russia]
    In the beginning of Februa… http://t.co/sUfnDf0P #
  • Twilight author’s official website attacked: Stephenie Meyer, author of the wildly popular Twilight series, can … http://t.co/cnTppppk #

Twitter report: Daily Updates for 2012-02-23

February 22nd, 2012
  • News of the World hacker named after court block lifted: Murdoch editor Andy Coulson fingered as key contact A m… http://t.co/sAQhCAVF #
  • PDF Malware Writers Keep Targeting Vulnerability: We keep seeing new waves of PDF file-based attacks that exploi… http://t.co/zGqORMsB #
  • IBM arms robo-sysadmin QRadar with virus know-how: X-Force gear combs through 13 billion threats a day IBM is be… http://t.co/IhecR7Yp #
  • Security platform uses virtual machine introspection: CounterTack announced three new solutions available on Eve… http://t.co/CfBG758c #
  • Los Angeles Police Site Hacked by CabinCr3w: The official website of the Los Angeles County Police Canine Associ… http://t.co/JbgU2X0c #
  • Akamai protects enterprises from DDoS and application security attacks: Akamai Technologies introduced Akamai Ko… http://t.co/xCVx0OXN #
  • TeamHav0k Finds XSS in British, French, and US Government Sites: Operation XSS, the operation launched by the gr… http://t.co/Gn3Ivf40 #
  • “Dropper” Trojan Hijacks Critical DLL File to Avoid Detection: The latest pieces of malware are not only develop… http://t.co/XOY8eilD #
  • Nightline Takes "A Trip to The iFactory": Nightline, a U.S. news program, will air what's being billed as a spec… http://t.co/6DKQMTC5 #
  • Users don't bother changing default passwords: Most people working with sensitive information want stricter secu… http://t.co/ICisGTWM #
  • Beware Changelog spammed-out malware attack: Internet users are receiving emails claiming to contain a changelog… http://t.co/tTrERGzg #
  • Experts: Many 4-Digit PINs Not Hard to Guess: Security researchers from University of Cambridge performed a stud… http://t.co/y1Nm8dgO #
  • Spam crashes to historic low as malware explodes on mobiles: Android Trojans soar, Mac viruses fall off a cliff … http://t.co/4nlOSmB0 #
  • IRS releases its top ‘Dirty Dozen’ tax scams: Ushering in tax season, the U.S. Internal Revenue Service (IRS) ha… http://t.co/kVB3w5Yj #
  • Anonymous Denies Targeting the DNS Root Servers: This is what happens when there is no clear hierarchy in a grou… http://t.co/oqOWEHpo #
  • New Zeus/SpyEye makes bots function as C&C servers: The latest build of the Zeus/SpyEye malware shows a change t… http://t.co/6EKNSWcI #
  • Protect Yourself from “SMiShing”: “SMiShing” is a silly word—even sillier than “phishing,” but equally dangerous… http://t.co/dWmj13MY #
  • iOS 5 Flaw Allows Unfettered Access to User's Contacts, Calls: A passcode flaw in Apple’s iOS 5 could allow unau… http://t.co/M8B0KDf5 #
  • XSS Flaw in Skype Shop May Allow Hackers to Steal User Accounts: Georgian security researcher Ucha Gobejishvil i… http://t.co/TRGg7gKd #
  • ASLR on Android 4 found wanting: A mitigation technique, ASLR, was added to Android 4 Ice Cream Sandwich and adv… http://t.co/Kn9Wf4r7 #
  • Waves of Attacks Target Adobe Reader Bug From 2010: Thanks to the wonderful tendency of users not to update thei… http://t.co/OLXSeDNY #
  • ACTA to Be Examined by the European Court of Justice: The recent protestS that have taken place worldwide and th… http://t.co/o862Qjvz #
  • YouPorn passwords available for download, thousands of users exposed: Want a free password for one of the world'… http://t.co/55Xq9BOW #
  • Indian govt to ask Yahoo, Google to route emails through servers in India: Web mail service providers such as Go… http://t.co/VzwjrR51 #
  • Grumble-flick chat site exposes flirts' privates: Oh, put it away – no, too late The email addresses and passwor… http://t.co/FlRHmQCI #
  • http://t.co/3h52IXhe security – step by step howto: I recently signed up for http://t.co/3h52IXhe, a hip, trendy p… http://t.co/RRfb2J4O #
  • NIST, Maryland Plan New Cybersecurity Center: The US National Institute of Standards and Technology (NIST) annou… http://t.co/bjOAAaif #
  • Gatekeeper and the Choice of Security for Mac Users: Context is a funny thing. In most segments of society, Appl… http://t.co/aBQh5d1e #
  • Rovnix Reloaded: new step of evolution: [More research from our colleagues in Russia]
    In the beginning of Februa… http://t.co/sUfnDf0P #
  • Twilight author’s official website attacked: Stephenie Meyer, author of the wildly popular Twilight series, can … http://t.co/cnTppppk #

Twitter report: Daily Updates for 2012-02-23

February 22nd, 2012
  • News of the World hacker named after court block lifted: Murdoch editor Andy Coulson fingered as key contact A m… http://t.co/sAQhCAVF #
  • PDF Malware Writers Keep Targeting Vulnerability: We keep seeing new waves of PDF file-based attacks that exploi… http://t.co/zGqORMsB #
  • IBM arms robo-sysadmin QRadar with virus know-how: X-Force gear combs through 13 billion threats a day IBM is be… http://t.co/IhecR7Yp #
  • Security platform uses virtual machine introspection: CounterTack announced three new solutions available on Eve… http://t.co/CfBG758c #
  • Los Angeles Police Site Hacked by CabinCr3w: The official website of the Los Angeles County Police Canine Associ… http://t.co/JbgU2X0c #
  • Akamai protects enterprises from DDoS and application security attacks: Akamai Technologies introduced Akamai Ko… http://t.co/xCVx0OXN #
  • TeamHav0k Finds XSS in British, French, and US Government Sites: Operation XSS, the operation launched by the gr… http://t.co/Gn3Ivf40 #
  • “Dropper” Trojan Hijacks Critical DLL File to Avoid Detection: The latest pieces of malware are not only develop… http://t.co/XOY8eilD #
  • Nightline Takes "A Trip to The iFactory": Nightline, a U.S. news program, will air what's being billed as a spec… http://t.co/6DKQMTC5 #
  • Users don't bother changing default passwords: Most people working with sensitive information want stricter secu… http://t.co/ICisGTWM #
  • Beware Changelog spammed-out malware attack: Internet users are receiving emails claiming to contain a changelog… http://t.co/tTrERGzg #
  • Experts: Many 4-Digit PINs Not Hard to Guess: Security researchers from University of Cambridge performed a stud… http://t.co/y1Nm8dgO #
  • Spam crashes to historic low as malware explodes on mobiles: Android Trojans soar, Mac viruses fall off a cliff … http://t.co/4nlOSmB0 #
  • IRS releases its top ‘Dirty Dozen’ tax scams: Ushering in tax season, the U.S. Internal Revenue Service (IRS) ha… http://t.co/kVB3w5Yj #
  • Anonymous Denies Targeting the DNS Root Servers: This is what happens when there is no clear hierarchy in a grou… http://t.co/oqOWEHpo #
  • New Zeus/SpyEye makes bots function as C&C servers: The latest build of the Zeus/SpyEye malware shows a change t… http://t.co/6EKNSWcI #
  • Protect Yourself from “SMiShing”: “SMiShing” is a silly word—even sillier than “phishing,” but equally dangerous… http://t.co/dWmj13MY #
  • iOS 5 Flaw Allows Unfettered Access to User's Contacts, Calls: A passcode flaw in Apple’s iOS 5 could allow unau… http://t.co/M8B0KDf5 #
  • XSS Flaw in Skype Shop May Allow Hackers to Steal User Accounts: Georgian security researcher Ucha Gobejishvil i… http://t.co/TRGg7gKd #
  • ASLR on Android 4 found wanting: A mitigation technique, ASLR, was added to Android 4 Ice Cream Sandwich and adv… http://t.co/Kn9Wf4r7 #
  • Waves of Attacks Target Adobe Reader Bug From 2010: Thanks to the wonderful tendency of users not to update thei… http://t.co/OLXSeDNY #
  • ACTA to Be Examined by the European Court of Justice: The recent protestS that have taken place worldwide and th… http://t.co/o862Qjvz #
  • YouPorn passwords available for download, thousands of users exposed: Want a free password for one of the world'… http://t.co/55Xq9BOW #
  • Indian govt to ask Yahoo, Google to route emails through servers in India: Web mail service providers such as Go… http://t.co/VzwjrR51 #
  • Grumble-flick chat site exposes flirts' privates: Oh, put it away – no, too late The email addresses and passwor… http://t.co/FlRHmQCI #
  • http://t.co/3h52IXhe security – step by step howto: I recently signed up for http://t.co/3h52IXhe, a hip, trendy p… http://t.co/RRfb2J4O #
  • NIST, Maryland Plan New Cybersecurity Center: The US National Institute of Standards and Technology (NIST) annou… http://t.co/bjOAAaif #
  • Gatekeeper and the Choice of Security for Mac Users: Context is a funny thing. In most segments of society, Appl… http://t.co/aBQh5d1e #
  • Rovnix Reloaded: new step of evolution: [More research from our colleagues in Russia]
    In the beginning of Februa… http://t.co/sUfnDf0P #
  • Twilight author’s official website attacked: Stephenie Meyer, author of the wildly popular Twilight series, can … http://t.co/cnTppppk #

Megaupload’s Kim Dotcom bursts the jail bubble

February 22nd, 2012
File sharing entrepreneur Kim Dotcom, the larger-than-life figure who was controversially busted by the cops hiding in a panic room in his $30 million mansion in New Zealand, has finally convinced a court to grant him bail.

Gatekeeper and the Choice of Security for Mac Users

February 22nd, 2012

Context is a funny thing. In most segments of society, Apple is seen as an exemplary company, with an unrivaled record of innovation, much-admired ad campaigns and a stock price that is the envy of every company not named Google. But in the security community, Apple is regarded with some combination of disbelief, confusion and the disdain that once was reserved for Microsoft. 

read more

Rovnix Reloaded: new step of evolution

February 22nd, 2012


[More research from our colleagues in Russia] In the beginning of February we found a new modification of our “old friend” Win32/Rovnix (the dropper detected as Win32/Rovnix.B trojan), which is the first bootkit using VBR infection. An interesting fact is that Rovnix bootkit components were used in Win32/Carberp, the most widely spread banking trojan in Russia. ... Read More...