Tech ARP Forums

Go Back   Tech ARP Forums > Site Updates & Promotions > News
Register
FAQ Members List Calendar Arcade Mark Forums Read

Google Web www.techarp.com forums.techarp.com

News Post your comments about the top news posted at Adrian's Rojak Pot!

Reply
 
LinkBack Thread Tools
Old 7th Aug 2008, 05:10 PM   #1 (permalink)
Administrator!
 
Dashken's Avatar
 
Join Date: 21 Apr 2003
Location: Penang
Posts: 29,763
Reputation: 2162
Dashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond reputeDashken has a reputation beyond repute
Rep Power: 56
Default Massive faux-CNN spam blitz uses legit sites to deliver fake Flash

Quote:
August 6, 2008 (Computerworld) More than a thousand hacked Web sites are serving up fake Flash Player software to users duped into clicking on links in mail that's part of a massive spam attack masquerading as CNN.com news notifications, security researchers said today.

The bogus messages, which claim to be from the CNN.com news Web site, include links to what are supposedly the day's Top 10 news stories and Top 10 news video clips from the cable network. Clicking on any of those links, however, brings up a dialog that says an incorrect version of Flash Player has been detected and that tells users they needed to update to a newer edition, said Sam Masiello, vice president of information security at Denver-based security company MX Logic Inc.

One distinguishing feature of the attack, Masiello added, is the endless loop it uses to frustrate victims. If user clicks "Cancel" in the dialog that prompts for an update, another pop-up appears, said Masiello, that tells the victim that they have to download it to view the video. Clicking "Cancel" there returns the user to the first dialog.

"It puts you in this perpetual loop, so your only options are to kill your browser [session] or be browbeaten into installing it," said Masiello.

MX Logic has detected more than 160 million spam messages in the fake CNN.com attack in the past 48 hours, he said. "It's not slowed down at all," Masiello said.

Yesterday, Bulgarian security researcher Dancho Danchev reported finding more than 1,000 hacked sites hosting the fake Flash Player update.

Hackers are getting brazen and apparently aren't afraid to disclose the addresses of the sites they've compromised by embedding them in the spam they're spreading, he said. "Malicious attackers have been building so much confidence in this risk-forwarding process of hosting their campaigns, that they would start actively spamming the links residing within low-profile legitimate sites across the Web," Danchev said in a blog post on Tuesday.

Adobe Systems Inc. is aware of the malware posing as its Flash Player, and on Monday it warned users to ignore any updates that didn't originate on its own servers. "Do not download Flash Player from a site other than Adobe.com," said David Lenoe, the company's product security program manager, in an entry on Adobe Product Security Incident Response Team's PSIRT blog. "This goes for any piece of software (Reader, Windows Media Player, QuickTime, etc.) -- if you get a notice to update, it's not a bad idea to go directly to the site of the software vendor and download the update directly from the source. If the download is from an unfamiliar URL or an IP address, you should be suspicious."

People who approved the download of the bogus flash.exe file instead received a Trojan horse -- identified by multiple names, including Cbeplay.a -- that in turn "phones home" to a malicious server to grab and install additional malware, said Danchev.

Masiello said MX Logic is still investigating, and it has not been able to pin down what malware -- other than the fake Flash Player -- was actually installed on victims' PCs.

Source - Massive faux-CNN spam blitz uses legit sites to deliver fake Flash
__________________
| Intel Core 2 Duo E6850 @ 3.2Ghz | ASUS P5B-E Plus | G.SKILL 2x1GB DDR2 800 | 6 HDDs (2TB+ only ) | NVIDIA GeForce 7600GT | Dell E248WFP 24" Widescreen |


Blog : Dashken's I-Blog
Gallery : Dashken's I-Paintings
Dashken is offline   Reply With Quote
SPONSOR

Old 8th Aug 2008, 10:17 PM   #2 (permalink)
Da Boss
 
Join Date: 10 Oct 2002
Location: In front of my ASUS F8V notebook!
Posts: 30,146
Reputation: 3081
Adrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond reputeAdrian Wong has a reputation beyond repute
Rep Power: 67
Default

Woah.. Thanks for the notice. I better watch out.
__________________
Dr. Adrian Wong
Tech ARP | Blog @ Tech ARP | The Free Trade Zone


DYKT : The only offshore account I have is at the sand bank?

Keep Tech ARP free! Visit our sponsors!

We need PROGRAMMERS and TECHNICAL WRITERS! Contact us if you are a hot shot programmer or technical writer!

My items for sale : 50x SD Card | Memory Stick PRO | Cyclone Energy Saver | Seiko SS watch | Tiger/Carlsberg beer jugs | Travel Speakers | Motorola V600 | Nokia N90 SOLD! | New Lowepro Mini Trekker AW

Other items for sale @ the FTZ : Zalman CNPS9500 LED @ $20 | Zalman CNPS7700 Cu @ $20 | Zalman CNPS7000 Cu @ $20 | Swarovski bracelet watches | Dell 17" LCD | Hi-Fi speakers | English DIVX movies | HP LaserJet toners! | Office chairs
Adrian Wong is offline   Reply With Quote
Old 8th Aug 2008, 10:30 PM   #3 (permalink)
"Little" Devil
 
PsYkHoTiK's Avatar
 
Join Date: 8 Apr 2004
Location: On the "throne"
Posts: 14,323
Reputation: 4003
PsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond reputePsYkHoTiK has a reputation beyond repute
Rep Power: 59
Default

I've been getting tons of those emails....
__________________
Intel SLAPL 4.3GHz @ 1.35v : 2x2GB OCZ Platinum DDR2 1066 : Asus P5K Premium : WD Raptor X : G92 8800GTS 512mb 800MHz Core *WIP* : XFi Platinum : Silverstone OP650 : Silverstone TJ-07 : Vista Ultimate Edition : Dtek FuZion CPU : Swiftech MCW60 : MCP655 : Thermochill PA120.3 w Scythe Ultra Kaze : Tygon R3603 1/2" ID 3/4" OD
CPU-Z: SLAPL : SLA9U : FX-55 : DDR 600 : VX
www.techarp.com
PsYkHoTiK is online now   Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
'Halo 3' set for merchandising blitz Dashken News 0 13th Aug 2007 09:11 PM
Bogus University being recognized as legit?? fyire News 5 10th Aug 2006 01:12 PM
You have until 4 August to download legit free ebooks.. djspinnet General Software 6 3rd Aug 2006 12:14 PM
AMD Launches Branding Blitz! Dashken News 3 6th Jan 2006 01:21 AM


All times are GMT +8. The time now is 05:04 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Copyright © 1998-2007 Tech ARP. All rights reserved.