Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Thursday, 10 January 2013

Fake "Facebook Security Team" account asks for your credentials

Help Net Security
Bookmark and Share
An account posing as that of the Facebook Security Team has been spotted sending warnings to page administrators, trying to fool them into believing that their Facebook account will be suspended due to a violation of the social network's Terms of Service:


The message offers a link for verifying the account, and it takes users to a third party Facebook application that requests them to enter their Facebook page name, email or phone and password.

If entered and submitted, that information is automatically sent to the scammers behind this phishing scheme and used to hijack the account.

If you have fallen for the trick, try to access your account. If you are able to do so, change your password immediately. If you have already been locked out, report the compromise and Facebook will help you regain control of the account.

"Anytime you see a Facebook page in the following format:apps.Facebook.com/app_name_here/, you should know that you are NOT dealing with an application created by Facebook," Facecrooksadvises. "Scammers use official sounding page names, applications and links to make their schemes appear legitimate to unsuspecting and ill-informed users."

Thursday, 20 September 2012

Ditch Internet Explorer, experts warn after new flaw



Internet Explorer
By Reuters and Barry Collins
Posted on 18 Sep 2012 at 09:31

Security experts are urging users to stop using Internet Explorer, following the discovery of a new flaw that makes PCs vulnerable to malicious code hosted on websites.  The security flaw affects Internet Explorer 9 and earlier versions of the browser, although IE10 - which is bundled with Windows 8 - is not affected. Microsoft said attackers can exploit the bug to infect the PC of somebody who visits a malicious website and then take control of the victim's computer.

For consumers it might be easier to simply click on Chrome
The software maker advised customers to install what it rather cryptically calls the Enhanced Mitigation Experience Toolkit (EMET) to prevent hackers gaining access to their systems, buying it time to fix the bug and release a new, more secure version of Internet Explorer. The company did not say how long that will take, but several security researchers said they expect the update within a week.

The EMET software must be downloaded, installed and then manually configured to protect computers from the newly discovered threat, according to the posting from Microsoft. The company also advised customers to adjust several Windows security settings to thwart potential attackers, but cautioned that doing so might impact the PC's usability.  Some security experts said it would be too cumbersome for many PC users to implement the measures suggested by Microsoft. Instead they advised Windows users to temporarily switch from Internet Explorer to rival browsers such as Google' Chrome, Firefox or Opera.

"For consumers it might be easier to simply click on Chrome," said Dave Marcus, director of advanced research and threat intelligence with Intel Corp's McAfee security division.  Marc Maiffret, chief technology officer of the security firm BeyondTrust, said it may not be feasible for some businesses to install Microsoft's EMET tool on their PCs. He said the security software has in some cases proven to be incompatible with existing programs already running on networks.

Tod Beardsley, an engineering manager with the security firm Rapid7, said that at first blush it appeared that the EMET may not be particularly effective in thwarting potential attacks.  Microsoft officials declined to comment on the skepticism that those security experts expressed about the effectiveness of the EMET software.

Discovered last week
Eric Romang, a researcher in Luxembourg, discovered the flaw in Internet Explorer, when his PC was infected by a piece of malicious software known as Poison Ivy that hackers use to steal data or take remote control of PCs.
When he analysed the infection, he learned that Poison Ivy had gotten on to his system by exploiting a previously unknown bug, or "zero-day" vulnerability, in Internet Explorer.

"Any time you see a zero-day like this, it is concerning," said Liam O Murchu, a research manager with antivirus software maker Symantec Corp. "There are no patches available. It is very difficult for people to protect themselves."  

Zero-day vulnerabilities are rare, mostly because they are hard to identify - requiring highly skilled software engineers or hackers with lots of time to scrutinise code for holes that can be exploited to launch attacks. Security experts only disclosed discovery of eight major zero-day vulnerabilities in all of 2011, according to Symantec.

Symantec and other major antivirus software makers have already updated their products to protect customers against the newly discovered bug in Internet Explorer. Yet, O Murchu said that may not be sufficient to ward off adversaries.

"The danger with these types of attacks is that they will mutate and the attackers will find a way to evade the defenses we have in place," he said.

Read more: Ditch Internet Explorer, experts warn after new flaw | News | PC Pro http://www.pcpro.co.uk/news/377041/ditch-internet-explorer-experts-warn-after-new-flaw#ixzz26zLpEwwl

Thursday, 19 January 2012

McAfee warns of flaw in own security


McAfee warns of flaw in own security software

spam
By Reuters
Posted on 19 Jan 2012 at 08:35
Security firm McAfee has warned a flaw in one of its products could leave customers' PCs vulnerable.
The company, which was acquired by Intel, disclosed the flaw in a message to customers on its website, saying hackers could use affected computers to distribute spam.
McAfee spokesman Ian Bain said at least one customer had fallen victim to such an attack, which leveraged a flaw in a service offering known as McAfee SaaS for Total Protection.
The web-based service protects customers from viruses hidden in emails and websites. Bain said the flaw was in a piece of software that McAfee customers install on their PCs to enable them to use the service.
While the flaw could enable hackers to send spam from machines of McAfee SaaS for Total Protection customers, it does not grant them access to data on an affected PC, Bain said.
He said that the company's engineers were working to fix the bug and expected to have it fixed today.
In April 2010, a glitch included in a regular release of McAfee's anti-virus software mistakenly identified part of Microsoft's popular Windows XP operating system as a virus, triggering personal computer outages at many of its customers, including more than 100 large corporations.


Read more: McAfee warns of flaw in own security software | Security | News | PC Pro http://www.pcpro.co.uk/news/security/372301/mcafee-warns-of-flaw-in-own-security-software#ixzz1jvH5swJa