Vision Jinx's Security Weblog

Loading Videos, Please stand by...

Welcome to Vision Jinx Networks
Initializing Borg Regeneration Matrix...

Monday, September 17, 2007

TD Ameritrade info stolen

TD Ameritrade info stolen - Full Story

"We've gotten several reports about a new article that's been posted around about Ameritrade. TD Ameritrade Holding Corp. said Friday one of its databases was hacked and contact information for its more than 6.3 million customers was stolen. -- Quote from Article Ameritrade has put out some info on their website, make sure you check it out!"

Source: isc.sans.org

Is Microsoft Doing a Stealth Update?

Is Microsoft Doing a Stealth Update? - Full Story

"We have received several emails from readers today regarding concern over reports that Microsoft had begun patching files on Windows XP and Vista without users' knowledge. It was reported that even though the user had turned off auto-updates some of the files were still being updated."

Source: isc.sans.org

Saturday, July 28, 2007

Life isn't beautiful - spammed out screensaver installs rootkits and Trojan horse

Life isn't beautiful - spammed out screensaver installs rootkits and Trojan horse - Full Story

"The emails, which are being seen in inboxes worldwide, claim that the recipient has been sent a screensaver by a friend and tells the user to open the attachment (called bsaver.zip). Clicking on the file contained inside the ZIP attachment infects users with the Troj/Agent-FZB Trojan horse, which drops two rootkits to try and hide from security software."

Source: sophos.com

Wednesday, July 25, 2007

E-cards don't like virtual environments

E-cards don't like virtual environments - Full Story

"The biggest malware threat we're dealing with at the moment is definitely the Storm worm. Unless your e-mail address is ultra secret, you probably received more than a couple of infamous e-card e-mails asking you to visit a strange URL address that can potentially lead to your machine being infected"

Source: isc.sans.org

Tuesday, July 24, 2007

D'oh! Spammers exploit interest in The Simpsons Movie

D'oh! Spammers exploit interest in The Simpsons Movie - Full Story

"The spammed emails claim that recipients will receive a $500 Visa Gift card for participating in an online survey. Each email contains a graphic of Homer Simpson sitting on his sofa wearing a Superman crop-top and tighty-whities."

Source: sophos.com

Facebook founders sued for "stolen" site, again

Facebook founders sued for "stolen" site, again - Full Story

"Three former Harvard classmates of Facebook founder Mark Zuckerberg will face him in Massachusetts district court next week, claiming for a second time that the social networking site's original development team stole the idea and source code for Facebook after Zuckerberg worked for them in 2003."

Source: securityfocus.com

FBI installs spyware to gather evidence

FBI installs spyware to gather evidence - Full Story

"A former Washington high school student received 90 days in juvenile detention this week after pleading guilty to charges stemming from a rash of bomb threats and being tracked down by the Federal Bureau of Investigation through the use of a Trojan horse that identified his computer."

Source: securityfocus.com

Saturday, April 07, 2007

The Gmail Hacker Scam

The Gmail Hacker Scam - Full Story

"Just when you thought your Gmail was safe, hackers have found a way to hijack your email accounts. This was revealed some months ago when Gmail customer support started getting concerned letters about the amount of spam received in their Gmail accounts"

Source: blog.internet-network-security.com

Friday, March 30, 2007

Microsoft knew of Windows .ANI flaw since December 2006

Microsoft knew of Windows .ANI flaw since December 2006 - Full Story

"A private security research outfit says it notified Microsoft about the animated cursor (.ani) code execution vulnerability since December 2006, a full four months ahead of yesterday's discovery of Internet Explorer drive-by attacks."

Source: blogs.zdnet.com

Phone That Takes AAA Battery Will Prevent Dying Cell Syndrome

Phone That Takes AAA Battery Will Prevent Dying Cell Syndrome - Full Story

"A major European electronics company is introducing a new cell phone designed to forever end those annoying 'my battery's about to die' emergencies we've all been faced with."

Source: citynews.ca

Fake website peddles killer pills

Fake website peddles killer pills - Full Story

"According to reports in Canadian newspapers, Marcia Bergeron died of poisoning after taking pills labeled as anti-anxiety medication and sedatives purchased from an internet site that used fake endorsements from medical agencies."

Source: sophos.com

TJX theft tops 45.6 million card numbers

TJX theft tops 45.6 million card numbers - Full Story

"Information from at least 45.6 million credit cards had been stolen by unknown attackers who had breached the company's computer transaction processing systems between July 2005 and mid-January 2007..."

Source: securityfocus.com

Grum worm poses as Internet Explorer beta download

Grum worm poses as Internet Explorer beta download - Full Story

"The emails, which claim to come from admin@microsoft.com and have the subject line "Internet Explorer 7 Downloads", display an image which invites users to download beta 2 of Internet Explorer 7. However, users who click on the image will download a file called ie7.0.exe which is infected by the W32/Grum-A worm."

Source: sophos.com

Blog trackback spam swamps websites with pornographic links

Blog trackback spam swamps websites with pornographic links - Full Story

"According to media reports, Newsbreak was hit by a flood of links to the illicit websites posted by unknown spammers. The website has now suspended the trackback feature of its site, and users are now asked to log on before posting any comments."

Source: sophos.com

TJ Maxx retail giant admits hackers stole 45 million credit card details

TJ Maxx retail giant admits hackers stole 45 million credit card details - Full Story

"Sophos, a world leader in IT security and control, has reminded consumers of the importance of checking their credit card statements after it was revealed that retail giant TJX has had details of at least 45.6 million credit cards stolen from it by hackers."

Source: sophos.com

Hacking contest takes aim at Apple

Hacking contest takes aim at Apple - Full Story

"Security researchers that want to take a shot a hacking the Mac OS X will get their chance at an upcoming security conference and could take home a fully loaded MacBook Pro."

Source: securityfocus.com

Microsoft confirms animated-cursor flaw

Microsoft confirms animated-cursor flaw - Full Story

"Microsoft confirmed on Thursday that attacker could take control of a user's system by exploiting a flaw in the way the company's Windows software handles animated-cursor files."

Source: securityfocus.com

Detecting and filtering out windows animated cursor exploitation attempts

Detecting and filtering out windows animated cursor exploitation attempts - Full Story

"I recommend a defense in depth approach. Do not rely on just one level of detection or filtering use as many as feasible."

Here is a great article on this. It covers the following:

- Antivirus:
- IDS rules:
- Domains/IPs currently being used in exploitation:
- MD5s for malware related to ANI exploitation:

Source: isc.sans.org

IE7.0.exe Exploit

IE7.0.exe Exploit - Full Story

"We've received a number of reports of spam appearing to come from 'admin@microsoft.com' containing a link to a file called IE7.0.exe... This is what VirusTotal has to say about it:"

Source: isc.sans.org

Monday, March 12, 2007

Microsoft's Live OneCare is the Last Choice

Microsoft's Live OneCare is the Last Choice - Full Story

"According to several tests conducted over the past few months, Microsoft's security application, 'Live OneCare' takes last position on the list of security applications available today."

Also, "Microsoft has admitted that its Live OneCare security suite is accidentally deleting some users' Outlook and Outlook Express emails."

Source: techtree.com

Back to Top
© Copyright 2006-2007 VisionJinx.Net - All Rights Reserved
Information contained on this site is copyrighted material. It is illegal to copy or redistribute this information in any way without the written consent of
VisionJinx.Net
Site Design by VisionJinx.Net