We often talk about the trade-offs between security and convenience, especially as it pertains to Web 2.0. Much of the technologies utilized by Web 2.0 sites were built for collaboration and a rich user experience, which has really fueled the explosion of social networking sites like MySpace, Facebook, and others. Today I bit the bullet Read more…
It’s been three months since we began shipping ePolicy Orchestrator 4.0, and I’m proud to report that we’re hearing great customer success stories. Enterprises are telling us that version ePO 4.0 is a clean, ready-to-ship software package with excellent overall performance. According to one large enterprise customer, ePO is now considered to be in “better Read more…
Last Thursday, McAfee Avert Labs picked up another zero-day vulnerability targeting the JustSystems Ichitaro office application in the wild, the fourth since August 2006. Targeted attacks were directed at multiple enterprise and government users of Ichitaro in Japan, using two versions of a maliciously crafted Ichitaro document. Both exploits install the same BackDoor-DLI Trojan payload. Read more…
When scanning machines for vulnerabilities, version information is one of the most common pieces of information to rely on. If you know the version of the OS or installed software, you know what that machine is vulnerable to. This is trivial when scanning with an authenticated connection. But if authentication is not an option, other Read more…
This is what we at Avert Labs hope will happen after the 27th of December 2007. In fact, on the date in question, General Elections in the country of Kenya will be held, including presidential and parliamentary. With the elections gone, we hope to see the disappearance of the W32/Voterai family of worms. As you Read more…
For a long time, we spoke regularly about IFRAME injection. This year, many pages belonging to legitimate sites were secretly modified. Many will remember the Italian Job and the thousands of infected sites in the realm of tourism, the car industry, movies and music. The people behind these attacks love to use highly topical issues Read more…
Recently, I had some friends complain about problems with Real Media files (*.rm/*.rmvb). According to them, after downloading and playing rmvb files, the Real Media Player launched a malicious webpage without prompting. Later, they noticed their OS running noticeably slower. And later still, they found their IM account passwords modified and online gaming accounts stolen. Read more…
You may have seen a number of news reports in the past day or two on the active exploitation of a Microsoft Access vulnerability. Here is one story by PC World. The US-CERT’s current activity Web page, “a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the Read more…
Avert Labs recently discovered a worm subsequently named W32/Heiku (http://vil.nai.com/vil/content/v_143663.htm). Written in Visual Basic, the worm behaves much like any other piece of malware: It creates numerous copies of itself in the file system and creates registry entries to ensure those copies run at startup. It has a destructive payload – deleting files/directories. It causes Read more…
Leading companies are borrowing a page from Eastern philosophy to achieve “intelligent security” – moving from point product solutions into a secure, optimized state. Security practitioners have been struggling with too many tools, consoles and reports to be effective. To truly be successful as a security practice, you must have maturity with regard to policies, Read more…