Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Industry News > Software News

Reply
 
LinkBack Thread Tools
Old 08-08-08   #21 (permalink)
Networking Nut
 
yawnbox's Avatar
 
intel ati

Join Date: Aug 2006
Location: WA, USA
Posts: 646

Rep: 57 yawnbox is acknowledged by some
Unique Rep: 54
Hardware Reviews: 3
Trader Rating: 0
Default

sorry to say, this is much bigger than facebook and myspace.

Massive faux-CNN spam blitz uses legit sites to deliver fake Flash
More than 1,000 hacked sites serving up phony update; Adobe issues warning


source: http://www.computerworld.com/action/...icleId=9111858

Quote:
August 6, 2008 (Computerworld) More than a thousand hacked Web sites are serving up fake Flash Player software to users duped into clicking on links in mail that's part of a massive spam attack masquerading as CNN.com news notifications, security researchers said today.

The bogus messages, which claim to be from the CNN.com news Web site, include links to what are supposedly the day's Top 10 news stories and Top 10 news video clips from the cable network. Clicking on any of those links, however, brings up a dialog that says an incorrect version of Flash Player has been detected and that tells users they needed to update to a newer edition, said Sam Masiello, vice president of information security at Denver-based security company MX Logic Inc.

One distinguishing feature of the attack, Masiello added, is the endless loop it uses to frustrate victims. If user clicks "Cancel" in the dialog that prompts for an update, another pop-up appears, said Masiello, that tells the victim that they have to download it to view the video. Clicking "Cancel" there returns the user to the first dialog.

"It puts you in this perpetual loop, so your only options are to kill your browser [session] or be browbeaten into installing it," said Masiello.

MX Logic has detected more than 160 million spam messages in the fake CNN.com attack in the past 48 hours, he said. "It's not slowed down at all," Masiello said.

Yesterday, Bulgarian security researcher Dancho Danchev reported finding more than 1,000 hacked sites hosting the fake Flash Player update.

Hackers are getting brazen and apparently aren't afraid to disclose the addresses of the sites they've compromised by embedding them in the spam they're spreading, he said. "Malicious attackers have been building so much confidence in this risk-forwarding process of hosting their campaigns, that they would start actively spamming the links residing within low-profile legitimate sites across the Web," Danchev said in a blog post on Tuesday.

Adobe Systems Inc. is aware of the malware posing as its Flash Player, and on Monday it warned users to ignore any updates that didn't originate on its own servers. "Do not download Flash Player from a site other than Adobe.com," said David Lenoe, the company's product security program manager, in an entry on Adobe Product Security Incident Response Team's PSIRT blog. "This goes for any piece of software (Reader, Windows Media Player, QuickTime, etc.) -- if you get a notice to update, it's not a bad idea to go directly to the site of the software vendor and download the update directly from the source. If the download is from an unfamiliar URL or an IP address, you should be suspicious."

People who approved the download of the bogus flash.exe file instead received a Trojan horse -- identified by multiple names, including Cbeplay.a -- that in turn "phones home" to a malicious server to grab and install additional malware, said Danchev.

Masiello said MX Logic is still investigating, and it has not been able to pin down what malware -- other than the fake Flash Player -- was actually installed on victims' PCs.
__________________
||||||||||||||||||||||||

BackTrack Linux Facebook group:
http://www.facebook.com/group.php?gid=2229950641

i love the smell of new hard drives in the morning

System: y.box
CPU
Intel E5405 Xeon (x2)
Motherboard
Supermicro X7DAE+
Memory
Micron 8GB (2x4GB FB)
Graphics Card
Asus 3870 X2 1GB
Hard Drive
2x Seagate 1.5TB, RAID-1
Power Supply
CM RS900
Case
U2-UFO Horizon
CPU cooling
Thermalright HR-01 X
OS
Windows Vista x64
yawnbox is offline   Reply With Quote
Old 08-08-08   #22 (permalink)
4.0 GHz
 
arekieh's Avatar
 
intel ati

Join Date: Nov 2007
Location: █♣█
Posts: 4,214

Rep: 182 arekieh is acknowledged by manyarekieh is acknowledged by many
Unique Rep: 126
Folding Team Rank: 1281
Hardware Reviews: 11
Trader Rating: 17
Default

ouch owned ouch

System: OVER 9000!!!!!!!!!!!
CPU
E6750 @ 3.9ghz @ 1.5v
Motherboard
MSI P35 Neo2 FRI
Memory
Patriot 800mhz @ 1000mhz 4-4-4-12
Graphics Card
PowerColor HD 4870
Hard Drive
1TB Samsung F1
Sound Card
Onboard
Power Supply
OCZ GameXtream 700W
Case
Silverstone FT01
CPU cooling
TRUE 120 (w/ 2xAntec Tricool)
GPU cooling
Xigmatek Battleaxe (w/ 2xVantec Stealth)
OS
Vista Ultimate x64
Monitor
Samsung Syncmaster 21.6"
arekieh is offline I fold for Overclock.net arekieh's Gallery   Reply With Quote
Old 08-08-08   #23 (permalink)
Overclocker in Training
 
DuDeInThEmOoN42's Avatar
 
intel ati

Join Date: Dec 2007
Location: Minnesota
Posts: 283

Rep: 7 DuDeInThEmOoN42 Unknown
Unique Rep: 6
Trader Rating: 0
Default

I use facebook a lot (on it right now), and I haven't had any messages like this yet but i just changed my status to make people aware. I really hate things like these. Correct me if I am wrong, but don't you have to download the virus/worm after clicking the link? My friend was on my computer once and downloaded a virus that he thought was a picture from a friend on AIM. Luckily, people such as myself still rely on programs like Spy Sweeper..
__________________
When in doubt, overclock

Quote:
Originally Posted by pauldovi View Post
Nvidia...

"The Way it............. BSOD
CPU-Z Validation

GPU-Z Validation

System: LED Zeppelin
CPU
Q6600 G0 @ 3.4GHz - 1.367V
Motherboard
Intel DX38BT
Memory
4GB Corsair DDR3 1333MHz
Graphics Card
VisionTek 4870 X2
Hard Drive
Seagate Barracuda 500GB 32MB Cache 7200 RPM
Sound Card
Onboard 7.1 IDT *Barracuda soon*
Power Supply
750W Xigmatek +4 12V Rails
Case
Apevia X-Jupiter G Type
CPU cooling
Thermaltake Typhoon CL-P0114
GPU cooling
Stock - 50% Fan Speed
OS
Vista Home Premium x64
Monitor
Samsung 906CW 19" LCD
DuDeInThEmOoN42 is offline   Reply With Quote
Old 08-08-08   #24 (permalink)
Overclocker
 
r34p3rex's Avatar
 
intel ati

Join Date: Jun 2007
Location: Long Island, NY
Posts: 1,134

Rep: 35 r34p3rex is acknowledged by some
Unique Rep: 32
Trader Rating: 0
Default

I remember there was this typing speed app, and the average of facebook users was 35wpm. ahahah
__________________
[center]-=R34P3ReX's OCN Wallpaper Thread=-

System: i8xtREME! (ETA Nov. 2008)
CPU
Core i7 940
Motherboard
Asus Rampage II Extreme
Memory
6GB OCZ Extreme Edition DDR3 1600
Graphics Card
HD4870x2
Hard Drive
300GB Velociraptor
Sound Card
X-Fi Titanium
Power Supply
ABS Tagan ITZ 1100W
OS
Vista Ultimate x64
r34p3rex is offline   Reply With Quote
Old 08-09-08   #25 (permalink)
PC Gamer
 
-iceblade^'s Avatar
 
intel ati

Join Date: Apr 2008
Posts: 2,684

Rep: 146 -iceblade^ is acknowledged by many-iceblade^ is acknowledged by many
Unique Rep: 129
Trader Rating: 0
Default

pleh... facebook...

if you don't know who's sent you a message, don't open it, simple...
__________________
I did Latty's Linux Challenge and I now love Linux!

Currently playing (PC only): Left 4 Dead, Team Fortress 2, Rome Total War: Europa Barbarorum
Quote:
Originally Posted by Unstableiser, when asked if 2 is better than 1 View Post
As far as tits are concerned yes. Graphics cards? They should follow the same rule. However the 4870x2 defies this rule and has only one tit, but with two nipples.

System: Pandora
CPU
E2160 @ 3ghz
Motherboard
MSI Neo2-FR (P35)
Memory
2x1gb GeIL Black Dragon DDR800
Graphics Card
512MB Sapphire HD 4850 Dual Slot
Hard Drive
Western Digital 320gb sata II w/ 16mb cache
Sound Card
onboard
Power Supply
Hiper 580W
Case
CoolerMaster Elite 330
CPU cooling
Arctic Cooling Freezer 7 Pro
OS
Mint 5 / Home Premium x64 w/ SP1
Monitor
Yuraku 22" @ 1680x1050
-iceblade^ is offline   Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -4. The time now is 05:41 PM.


Overclock.net is a Carbon Neutral Site Creative Commons License Internet Security By ControlScan

Terms of Service / Forum Rules | Privacy Policy | Advertising | Become an Official Vendor
Copyright © 2008 Shogun Interactive Development. Most rights reserved.
Page generated in 0.30011 seconds with 8 queries