ZDNet Must Read:
Mozilla Firefox hit by malware add-ons
Mozilla says a pair of malicious Firefox add-ons slipped by its security checks and infected approximately 4,600 Windows computers over the last five months.... Continued »
Category: Research
January 21st, 2010
And the most popular password is...
It is “123456,” based on the analysis of 32 million breached passwords, obtained from last month’s RockYou.com server breach, from which researchers from Imperva were able to analyze the insecure practices used by millions of users when choosing their passwords.
What did their analysis conclude? Short passwords, lack of lower-capital-numeric characters mix, and trivial dictionary words, which every decent brute forcing/password recovery application can find out in a matter of minutes.
Key findings include:
January 21st, 2010
Microsoft knew of IE zero-day flaw since last September
Microsoft today admitted it knew of the Internet Explorer flaw used in the attacks against Google and Adobe since September last year.
The flaw was in the Microsoft Security Response Center’s (MSRC) queue to be fixed in the the next batch of patches due in February but the targeted zero-day attacks against U.S. companies forced the company to release an emergency, out-of-band IE update.
December 15th, 2009
Report: Google's reCAPTCHA flawed
UPDATED: According to a Google representative from the Google Global Communications & Public Affairs who contacted me - “While the report is newly released, its substance is not current and seems to include some misunderstandings of the reCAPTCHA technology according to some of our engineers. Therefore, the so-called flaws described in the report, are not related to the reCAPTCHA that people use today.”
In a newly released report, security researcher claims that Google’s reCAPTCHA, one of the most widely adopted free CAPTCHA services, contains weaknesses that would allow a 10,000 infected hosts botnet the ability to achieve 10 recognition successes every second, allowing it to register 864,000 new accounts per day.
In response, a Google spokesman stated that the report relies on data collected in early 2008, and doesn’t take into consideration the effectiveness of the current technology used against machine solvers.
More from the report:
December 4th, 2009
How many people fall victim to phishing attacks?
According to a recently released report, based on a sample of 3 million users collected over a period of 3 months, approximately 45% of the time, users submitted their login information to the phishing site they visited.
The study, exclusively monitored users who successfully reached a live phishing site that was not blocked by their browser’s built-in anti-phishing protection or filtered as fraudulent one (Phishing experiment sneaks through all anti-spam filters), and found out that on average, 12.5 out of one million customers sampled for a particular bank, visited the phishing site.
Here are some of the key findings from the report:
December 1st, 2009
Clientless SSL VPNs expose corporate users to attacks
Cli
entless SSL VPN products from multiple vendors operate in a way that breaks fundamental browser security mechanisms, according to a warning from the U.S. Computer Emergency Response Team (US-CERT).
This security problem, discussed since at least 2006, could let an attacker could use these devices to bypass authentication or conduct other web-based attacks. Clientless VPN products from Juniper Networks, Cisco Systems, SonicWall and SafeNet are confirmed vulnerable. Read the rest of this entry »
November 30th, 2009
New ransomware attack blocks Internet access
Security researchers have stumbled upon a new piece of ransomware that blocks an infected computer from accessing the Internet until a fee is paid via SMS (text message). Read the rest of this entry »
November 13th, 2009
Man-in-the-middle attacks demoed on 4 smartphones
Security researchers from SMobile Systems have released a paper detailing successful man-in-the-middle attacks against several smartphones.
The SSL enabled log in sessions on the tested, Nokia N95, HTC Tilt, Android G1 and iPhone 3GS devices was sniffed using the publicly available SSLstrip tool, with the attack taking place over insecure Wi-Fi network, now prevalent literally everywhere.
Here’s the scenario they used, and possible mitigation approaches:
October 19th, 2009
'Evil Maid' USB stick attack keylogs TrueCrypt passphrases
Security researcher Joanna Rutkowska has released a PoC (proof of concept) of a keylogger that is capable of logging TrueCrypt’s disk encryption passphrase enabling the attacker to successfully decrypt the hard drive’s content.
Dubbed, the ‘evil maid’ attack due to its ‘plug-and-exploit’ functionality requiring 1-2 minutes for the infection process to the take place, works with the latest TrueCrypt versions 6.0a - 6.2a.
Here’s how it works, and TrueCrypt’s response:
October 9th, 2009
New Adobe PDF flaw under attack; Patch coming Tuesday
Adobe has confirmed a critical, unpatched vulnerability in its PDF Reader/Acrobat software is being exploited by malicious attackers.
The vulnerability affects Adobe Reader and Acrobat 9.1.3 and earlier versions on Windows, Macintosh and UNIX. Adobe described the in-the wild attacks as limited and targeted, suggesting PDF documents rigged with exploits are being attached to e-mails and sent to business targets.
October 8th, 2009
Click fraud facilitating Bahama botnet steals ad revenue from Google
Originally exposed as a botnet redirecting and monetizing hijacked traffic to over 200,000 parked domains primarily located in the Bahamas, researchers from ClickForensics have recently found evidence on active DNS hijacking of Google properties allowing cybercriminals to steal revenue from Google by pulling search results and displaying them on a bogus homepage (Cybercriminals promoting malware-friendly search engines) which serves ads from pay-per-click ad networks (Microsoft’s Bing invaded by pharmaceutical scammers) maintained by similar cybercrime enterprises.
Here’s how Bahama’s click fraud scheme steals ad revenue from Google and its advertisers according to ClickForensics:
Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.
Subscribe to Zero Day via Email alerts or RSS.
SponsoredWhite Papers, Webcasts, and Downloads
- Driving business agility through SOA connectivity and integration IBM Corp. This paper describes some of the business and IT issues that enterprises ... Download Now
- Smarter Products: The Building Blocks for a Smarter Planet IBM Corp. Businesses are delivering a new generation of smarter products that are ... Download Now
- Sole-sourcing BI from your ERP vendor: IT convenience or strategic business decision? IBM During the last several years, the pressure of commoditization and the ... Download Now
Recent Entries
- Patch Tuesday: Microsoft plugs critical Windows worm holes
- Adobe screw-up leaves Flash flaw unpatched for 16 months
- Oracle rushes out patch for gaping server hole
- Mozilla Firefox hit by malware add-ons
- Does Blippy really pose a security risk?
Blogs From Our Sponsors
Most Popular Posts
- Report: 48% of 22 million scanned computers infected with malware
- And the most popular password is...
- Code execution holes in iPhone OS, iPod Touch
- Bogus IQ test with destructive payload in the wild
- MS Patch Tuesday heads-up: 13 bulletins, 26 vulnerabilities
- RealPlayer haunted by 11 critical vulnerabilities
Top Rated
- And the most popular password is...+34 votes
- Microsoft readies emergency IE patch to counter public exploits+33 votes
- Report: 48% of 22 million scanned computers infected with malware+32 votes
- Microsoft confirms 17-year-old Windows vulnerability+31 votes
- Microsoft says Google was hacked with IE zero-day+31 votes
- MS Patch Tuesday heads-up: 13 bulletins, 26 vulnerabilities+26 votes
- Bogus IQ test with destructive payload in the wild+22 votes
- Mozilla Firefox hit by malware add-ons+21 votes
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- The best support in the Linux business
-
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.

- Learn more >>
- Topline - A Dashboard for IT Leaders
-
Visit the one-stop destination for IT decision-makers to learn more about the top issues that you face every day. Find cost-effective solutions to real-life IT problems. Search the valuable repository of the resources and tools you need every day to keep your IT infrastructure running smoothly.
- Learn more >>
Archives
Favorite Links
ZDNet Blogs
- A Developer's View
- All About Microsoft
- The Apple Core
- Between the Lines
- BriefingsDirect
- Collaboration 2.0
- Dev Connection
- Digital Cameras & Camcorders
- Ed Bott's Microsoft Report
- Emerging Tech
- Enterprise Web 2.0
- Forrester Research
- Googling Google
- GreenTech Pastures
- Hardware 2.0
- Home Theater
- iGeneration
- Irregular Enterprise
- IT Project Failures
- Laptops & Desktops
- Lawgarithms
- Linux and Open Source
- Managing L'unix
- The Mobile Gadgeteer
- On Sustainability
- The Semantic Web
- Service Oriented
- Smartphones and Cell Phones
- Social Business
- Social CRM: The Conversation
- Software & Services Safari
- Software as Services
- Storage Bits
- Team Think
- Tech Broiler
- Technology and the Global Supply Chain
- Tom Foremski: IMHO
- The ToyBox
- Virtually Speaking
- The Web Life
- ZDNet Education
- ZDNet Government
- ZDNet Healthcare
- Zero Day
White Papers, Webcasts, and Downloads
- Volume Activation Planning Guide Microsoft Volume Activation helps Volume Licensing customers automate and manage the ... Download Now
- Unrivaled support from Novell, now available for Red Hat Novell If Linux is going to power your mission-critical applications, you'd ... Download Now
- Easily Monitor Virtual/Physical/Cloud and Save Budget. up.time - Free Trial Uptime Software Need Deep Systems Management for Virtual/Physical/Cloud that Saves you ... Download Now
SmartPlanet
- Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
- More from IBM
- How to Drive Better Business Outcomes with Exceptional Web Experiences Download the eBook
- Driving Business Agility through SOA Connectivity & Integration Read the White Paper from IBM
- Linking Decisions and Information for Organizational Performance Read the Tom Davenport study





