Showing posts sorted by date for query Symantec. Sort by relevance Show all posts
Showing posts sorted by date for query Symantec. Sort by relevance Show all posts

Anonymous Tricked Their Supporter Into Installing Zeus Trojan - Said Symantec

Anonymous Tricked Their Supporter Into Installing Zeus Trojan - Said Symantec

Remember the Operation Megaupload (#OpMegaupload) the largest attack ever where 5,635 Anon people bring down the websites of Universal Music, the U.S. Department of Justice and the Recording Industry Association of America while using one of the world's most popular and vastly used DDoSer LOIC.
Now Security software company Symantec have discovered that a piece of Anonymous-recommended DDoS software called Slowloris contained an insidious Trojan that was stealing financial info from people using it. According to the official blog post of Symantec on the 20th day of January after Kim Dotcom was arrested, Anonymous was frequently shearing few pastebin links which was containing the download link of Slowloris which led to a trojanized copy that installed the Zeus trojan on users' systems. The compromised download then replaced itself with a clean version of the tool to avoid detection. 

"It is worth highlighting how Anonymous supporters have been deceived into installing Zeus botnet clients purportedly for the purpose of DoS attacks. The Zeus client does perform DoS attacks, but it doesn’t stop there. It also steals the users' online banking credentials, webmail credentials, and cookies."
"When the Trojanized Slowloris tool is downloaded and executed by an Anonymous supporter, a Zeus (also known as Zbot) botnet client is installed. After installation of the Zeus botnet client, the malware dropper attempts to conceal the infection by replacing itself with the real Slowloris DoS tool. Zeus is an advanced malware program that cannot be easily removed. The Zeus client is being actively used to record and send financial banking credentials and webmail credentials to the botnet operator. Additionally, the botnet is being used to force participation in DoS attacks against Web pages known to be targets of Anonymous hacktivism campaigns."

Full information can be found Here



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

‎pcAnywhere Exploit- More Than 200,000 Windows PCs Can Be Hijacked

pcAnywhere Exploit More Than 200,000 Windows PCs Can Be Hijacked 
According to a researcher hackers have made pcAnywhere hackers exploiting bugs in the Symantec software which can hijack as many as 200,000 systems connected to the Internet. Also Rapid7 developer of Metasploit confirmed that an estimated 150,000-to-200,000 PCs are running an as-yet-unpatched copy of the Symantec software, and are thus vulnerable to be hijacked by remote attacks, which could commandeer the machine's keyboard and mouse, and view what's on the screen.This bug has been found just after Symantec took the unprecedented step of telling pcAnywhere users to disable or uninstall the program because attackers had obtained the remote access software's source code. According to an exclusive report of Computer World- 
Credit Card Data at Risk:-
About 2.5% of those vulnerable Windows PCs, or between 3,450 and 5,000 systems, are running a point-of-sale system - Windows PCs are often paired with cash registers by small businesses - potentially putting credit card data at risk, said HD Moore, chief security officer at Rapid7.
Moore reached those conclusions by scanning the internet for the TCP port the software leaves open for incoming commands, running more targeted scans for evidence of the remote access software, then using the number of programs that identify themselves as older than the patched editions to estimate the extent of the problem.
Some of the computers returned queries with replies consistent with specific point-of-sale software, Moore said. Point-of-sale software often relies on pcAnywhere for remote support, not for transmitting credit card data, but by exploiting pcAnywhere, a cybercriminal could control the machine and easily harvest the information. "These point-of-sale systems are an attractive target for break-in," said Moore.
Exploitable Bugs:-
DoS attacks can sometimes be leveraged to execute remote code. The source code leak also ups the risk to pcAnywhere users, Moore maintained, even though Symantec has patched some flaws. With the source code at their disposal and the software's problems highlighted in the media, researchers on both sides of the law will spend time looking for vulnerabilities, he said. And some of that research may result in new, exploitable bugs.
An anonymous researcher has already published findings from his examination of the pcAnywhere source code. Although his description on the InfoSec Institute website did not claim any new vulnerabilities, he noted that the source code also revealed the workings of LiveUpdate, the Symantec service used to update much of its software, including its consumer antivirus programs, such as Norton Antivirus. "We now know how their LiveUpdate system works thanks to the included architecture plans and full source code," said the researcher. Symantec did not immediately reply to a request for comment on Moore's research or Norman's DoS proof-of-concept.



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Symantec Released pcAnywhere Security Recommendations After Security Breach

After Security Breach Symantec Released pcAnywhere Security Recommendations
Few days ago Norton has confirmed that their Network was breached in 2006 and in that attack hackers have stolen the source code of Norton Antivirus Corporate Edition, Norton Internet Security, Norton Utilities, Norton GoBack & pcAnywhere.
Now the company has published a white paperPDF in which it warns against using the remote PC control software at all, since malicious parties could use the source code to identify and exploit security vulnerabilities to compromise PCs that use the program. In addition, an attacker with cryptography knowledge could conduct man-in-the-middle attacks on encrypted connections and create unauthorized connections to remote machines, thereby potentially gaining access to whole networks.
Symantec plans to eradicate the known vulnerabilities in pcAnywhere step by step. A patch was released earlier this week, but it doesn't fix the problem described above. Those who absolutely need the product should make sure to always have the latest updates and follow the security recommendationsPDF in the white paper.


-Source (Symantec, The-H)



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Symantec Network Was Breached On 2006 & At That Attack The Code Was Stolen


Few days ago a hacker group named The Lords of Dharmaraja has managed to steal the source code of Norton anti-virus. Symantec, the anti-virus maker, has confirmed that hackers have stolen a “segment” of its flagship product. They have also said that some of its code had been lifted from the server of a third party. But after investigation the security firm has found that its network had indeed been compromised. Symantec spokesman Cris Paden said on Tuesday that unknown hackers breached its network back in 2006 and obtained the source code to Norton Antivirus Corporate Edition, Norton Internet Security, Norton Utilities, Norton GoBack and pcAnywhere. 
The only real threat at this time resides with customers using pcAnywhere, Symantec's software that facilitates remote access of PCs. "Symantec is currently in the process of reaching out to our pcAnywhere customers to make them aware of the situation and to provide remediation steps to maintain the protection of their devices and information," the company reports.
Symatec admitted that it previously offered up the source code of its products in compliance with the Indian government so that officials could make sure the software didn't contain spyware or other malicious programs. Save for the firm's current caution with pcAnywhere as revealed on Tuesday, Symantec wasn't too worried about a possible code leak given the stolen software is six years old.


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

FBI Is Paying Attention To The US-China Commission Data Breach Issue



US-China Commission Data Breach issue is again on high node. Now Federal Bureau of Investigation (FBI) is investigating claims made by an Indian computer hacking group that India’s intelligence services intercepted the communications of the US-China Economic and Security Review Commission.

The documents posted on the Internet about a month ago and allege to be from the Indian government’s Directorate General of Military Intelligence and include about 10 emails from the Congressionally mandated Commission from September and October 2011. The commission reports to Congress annually on national security, trade and economic issue with China.

The Commission released their annual report to Congress in November 2011 this year. One federal law enforcement official indicated that the Indian government may have been snooping for early details on the assessments of the Commission if the documents are genuine.
While the emails do appear to be genuine the document has not been authenticated. Emails and phone calls made to the Indian embassy in Washington were not returned on Wednesday.
The alleged Indian military intelligence memo can be found Here
Though An FBI spokeswoman declined to comment on the investigation. The documents include an e-mail received by Michael Danis, the Commission’s executive director concerned General Electric’s business and joint ventures in China. The documents posted on the Internet were allegedly obtained by a group called the Lords of Dharamraja which has also compromised the source code on Symantec’s popular Norton antivirus software.
The document that is allegedly from the Indian intelligence service claims that the emails were obtained by using backdoors from mobile device manufacturers Apple, Research in Motion and Nokia. In the United States the Communications Assistance for Law Enforcement Act mandates that the FBI and police must have “backdoor” access to phone and internet communications with a lawful court order. The Bureau has been pushing for expanded surveillance powers with new technology such as Skype and Twitter in what they have termed their “Going Dark” program.
The inquiry into the data breach at the Commission follows the disclosure last month that China had infiltrated the US Chamber of Commerce computer system targeting the work by the Chamber’s Asia policy analysts.


-Source (ABC News)



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Symantec Confirms Norton Source Code Has Been Hacked



A hacker group named The Lords of Dharmaraja has managed to steal the source code of Norton anti-virus. Symantec, the anti-virus maker, has confirmed that hackers have stolen a “segment” of its flagship product. The group said it would make the source code available. 
The firm said that the code relates to two older enterprise products, one of which is no longer in production. But it said the breach was on a third-party network rather than its own, and will “not affect any current Norton product”.
A Google cache of the hackers' post on Pastebin says, "As of now we start sharing with all our brothers and followers information from the Indian Militaty Intelligence servers."
It continues, "Now we release confidential documentation we encountered of Symantec corporation and its Norton AntiVirus source code which we are going to publish later on."
The group claims it has the source code of a dozen software companies. The Symantec document posted is dated 28 April 1999 but doesn't contain any source code. Symantec has launched an investigation into the security breach and will provide updates when more facts and details are discovered. "Furthermore, there are no indications that customer information has been impacted or exposed at this time. However, Symantec is working to develop remediation process to ensure long-term protection for our customers' information. We will communicate that process once the steps have been finalized," it said in a statement.
Rob Rachwald, director of security at Impervia, said that this breach is “quite embarrassing on Symantec’s part”. He added that should the source code be recent and hackers find serious vulnerabilities, it could be possible to exploit the product itself. “But that is a big if and no one but Symantec knows what types of weaknesses hackers could find”, he added.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

The Nitro Attacks Stealing Secrets from the Chemical Industry


Symantec prepares a a report on the ongoing malware report and named it "Nitro Attacks". By using this an attacker can pull secretes information from chemical industries, companies, the attack is mainly based on social engineering. 
An Analysis report is Saying:-
This "nitro" attack has an interesting blend of malware techniques that does show some ingenuity. It used a socially engineered email message with a malicious attachment. While the malware component of the attack was a recycled version of the common remote access Trojan (RAT) PoisonIvy, it was often packaged in an encrypted archive to evade email gateway detection. Nitro portrayed itself as a necessary Adobe Flash or anti-virus update, using your desire to be secure to trick you into installing the malware. Like many other targeted attacks that have come to light recently, this one attacks our weakest link, our humanity.
One of the behaviors of the Trojan was to collect password hashes from compromised Windows computers. If you haven't already gotten the memo, it is an extremely bad idea to give your users administrative rights.
Malware cannot access the Windows cache of passwords, which almost always has admin credentials included, if it does not have administrative rights. Simply restricting permissions would be enough to stunt the spread of an attack like this. Additionally, the behavior of this malware is quite easy for HIPS or behavioral anti-virus to detect and block. With the multitude of techniques being used by the bad guys, analyzing the behavior of applications is critical.
The command and control for this Trojan was located on a virtual hosted server in the United States. Symantec's investigation shows that the person who owns this instance, Covert Grove, is based in the Hebei region of China. In too many high profile organizations, IT security and their users have an adversarial relationship. Additionally, IT often does not use the full capabilities of the tools they are purchasing out of fear of false positives. Blocking suspicious attachments, using proactive detection technologies and educating users could all stop this type of attack from succeeding. If you weren't one of the victims, this is a great lesson on what you should be doing to protect against the next attack.

For more info & to download the symantec report click Here

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Indian Authorities Seized Their Servers Linked With "Duqu" Virus


Indian authorities seized computer equipment from a data center in Mumbai as part of an investigation into the Duqu malicious software that some security experts warned could be the next big cyber threat. Two workers at a web-hosting company called Web Werks told Reuters that officials from India's Department of Information Technology last week took several hard drives and other components from a server that security firm Symantec Corp told them was communicating with computers infected with Duqu.
News of Duqu first surfaced last week when Symantec said it had found a mysterious computer virus that contained code similar to Stuxnet, a piece of malware believed to have wreaked havoc on Iran's nuclear program. Government and private investigators around the world are racing to unlock the secret of Duqu, with early analysis suggesting that it was developed by sophisticated hackers to help lay the groundwork for attacks on critical infrastructure such as power plants, oil refineries and pipelines. The equipment seized from Web Werks, a privately held company in Mumbai with about 200 employees, might hold valuable data to help investigators determine who built Duqu and how it can be used. But putting the pieces together is a long and difficult process, experts said.
"This one is challenging," said Marty Edwards, director of the U.S. Department of Homeland Security's Industrial Control Systems Cyber Emergency Response Team. "It's a very complex piece of software." He declined to comment on the investigation by authorities in India, but said that his agency was working with counterparts in other countries to learn more about Duqu. Two employees at Web Werks said officials from India's Department of Information Technology came to their office last week to take hard drives and other parts from a server.
They said they did not know how the malware got on to Web Werks' server. "We couldn't track down this customer," said one of the two employees, who did not want to be identified for fear of losing their jobs. An official in India's Department of Information Technology who investigates cyber attacks also declined to discuss the matter. "I am not able to comment on any investigations," said Gulshan Rai, director of the Indian Computer Emergency Response Team, or CERT-In.

To know more about Duqu Click Here


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Duqu Hits The Nuclear Program of Iran


Few days before we have talked about Duqu, the next generation cyber attack tool. Here Duqu shows his 1st magic by hitting the nuclear program of Tehran
Iran’s nuclear program comes under another cyber threat withDuqu,’ a worm that gathers intelligence data and assets from entities. The new threat comes after Stuxnet, a virus allegedly produced by the United States and Israel that slowed Iran’s first nuclear plant Bushehr before it was inaugurated last month. First there was the Stuxnet computer virus that wreaked havoc on Iran’s nuclear program. Now “Duqu” appears to be quite similar, according to researchers on Oct. 18.
“Duqu’s purpose is to gather intelligence data and assets from entities, such as industrial control system manufacturers, in order to more easily conduct a future attack against another third party,” security software firm Symantec said on its website. It was named Duqu because it creates files with “DQ” in the prefix. The U.S. Department of Homeland Security said it was aware of the reports and was taking action.
 


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Duqu, The Next-Generation Cyber Attack Weapon



Researchers found an alarm for a new piece of malware with “striking similarities” to Stuxnet, the mysterious computer worm that targeted nuclear facilities in Iran. The new malware, identified as Duqu, is a highly specialized Trojan capable of gathering intelligence data and assets from entities, such as industrial control system manufacturers, in order to more easily conduct a future attack against another third party.
“The attackers are looking for information such as design documents that could help them mount a future attack on an industrial control facility,” according to Symantec’s security response team. 
Symantec said it got a copy of the in-the-wild malware from an unnamed research lab with strong international connections. The company found that parts of Duqu are “nearly identical to Stuxnet” but noted that the malware has a completely different goal.
Duqu is essentially the precursor to a future Stuxnet-like attack. The threat was written by the same authors (or those that have access to the Stuxnet source code) and appears to have been created after the last recovered Stuxnet file. Duqu’s purpose is to gather intelligence data and assets from entities, such as industrial control system manufacturers, in order to more easily conduct a future attack against another third party. The attackers are looking for information such as design documents that could help them mount a future attack on an industrial control facility.
The company said Stuxnet and Duqu shared the same modular structure, injection mechanisms, and a driver that is digitally signed with a compromised key. Unlike Stuxnet, Symanted said the new malware does not contain any code related to industrial control systems.  It was built to be a  remote access Trojan (RAT) that does not self-replicate.
“The threat was highly targeted toward a limited number of organizations for their specific assets. However, it’s possible that other attacks are being conducted against other organizations in a similar manner with currently undetected variants,” Symantec warned.
The attackers used Duqu to install another infostealer that could record keystrokes and gain other system information. The attackers were searching for assets that could be used in a future attack. In one case, the attackers did not appear to successfully exfiltrate any sensitive data, but details are not available in all cases. Two variants were recovered and, in reviewing our archive of submissions, the first recording of one of the binaries was on September 1, 2011. However, based on file compile times, attacks using these variants may have been conducted as early as December 2010.
Noted that Duqu uses HTTP and HTTPS to communicate to a command and control server which is currently operational.

To know more about Duqu and to see the similarities between Stuxnet and Duqu Click Here


-News Source (ZD net, Yahoo, Symantec) 


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Facebook Has Been Blocked By Norton & Declared Fb a Phishing Site


Symantec has withdrawn an update to its Norton consumer security software that branded Facebook a phishing site on Wednesday. The snafu meant that users of Norton Internet Security were blocked from accessing the social networking site and were told a "fraudulent web page" had been blocked, as illustrated in a discussion thread on Symantec's support forums here.
While wags might joke that Facebook is all about persuading punters to supply personal information to a website that ought not to be trusted, it's a bit of a stretch to even compare Zuckerberg's Reservation to a fraudulent banking site. Symantec responded to the problem within hours. From the looks of support forum postings affected users were left dazed and confused rather than seriously inconvenienced or aggrieved by the screw-up.
Security firms update their signature definition files to detect either rogue applications or questionable websites at increasing frequency in order to keep up with malware production rates. Plenty of effort is put into the quality assurance process across the industry but even so mistakes sometimes occur. False positives are a cross-industry problem that affects all vendors.

-News Source (The Register & Norton) 




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Due to Cyber Crimes India is Loosing 4 Billion Dollar Per Year


Cybercrime leads to annual losses of around $ 4 billion or Rs 18,000 crore in direct financial losses, and an additional $3.6 billion or Rs 16,200 crore is spent in resolving the crime in India, states a recent study done by Symantec, the maker of Norton computer security software.
Globally the financial losses due to cybercrimes was found to be $114 billion annually, and an additional $274 billion was lost, based on the value victims  placed on time lost due to their cybercrime experiences. The study claims that cybercrime costs the world significantly more than the global black market in marijuana, cocaine and heroin combined ($288 billion) and it affected more than two thirds(69 percent) of online adults.

Surprisingly, even with its tight internet security rules China is unable to escape cybercriminal activities. In  China, the direct losses due to cybercrime is around $25 billion, even higher than that of India.
“Over the past 12 months, three times as many adults surveyed have suffered from online crime versus offline crime, yet less than a third of respondents think they are more likely to become a victim of cybercrime than physical world crime in the next year,” said Gaurav Kanwal, Country Sales Manager for India and SAARC, Consumer Business Unit, Symantec.
According to the report, the most common types of cybercrimes are computer viruses and malware, followed by online scams and phishing. In India, four in five online adults have been a victim of cyber crime, and males aged between 18 and 31 years old are most likely to become victims of cyber-attack on cell phones.

Though, 74 per cent Indian users are aware of cybercrimes, many are not taking the necessary precautions. Over 41 per cent of the respondents revealed that they don’t have an up to date security software suite to protect their personal information online. Only half of the respondents reviewed their credit card statements regularly for fraud and 61 per cent don’t use complex passwords or change them regularly.
“Cybercrime is much more prevalent than people realize. Over the past 12 months, three times as many adults surveyed have suffered from online crime versus offline crime, yet less than a third of respondents think they are more likely to become a victim of cybercrime than physical world crime in the next year,” said Adam Palmer, Norton Lead Cybersecurity Advisor
Fighting cybercrime is a shared responsibility. It requires  us to be more alert and take the necessary precautions to ensure complete online security.

To see the the Norton report click Here
-News Source (Symantec & Buzzom)


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Norton Cyber Crime Report: The cost of Global Cybercrime is 114 Billion Dollar Annually


Cybercrime Cost Canadians $840 million Last Year For the first time a Norton study calculates the cost of global cybercrime: $114 billion annually.

(i) Based on the value victims surveyed placed on time lost due to their cybercrime experiences, an additional $274 billion was lost.

(ii) In Canada, more than 7.3 million people fell victim to cybercrime last year, suffering CAD$840 million in direct financial losses and an additional CAD$4.7 billion in time spent resolving the crime. With 431 million adult victims globally in the past year and at an annual price of $388 billion globally based on financial losses and time lost, cybercrime costs the world significantly more than the global black market in marijuana, cocaine and heroin combined ($288 billion).

(iii) According to the Norton Cybercrime Report 2011 more than two thirds of online adults (69 percent) have been a victim of cybercrime in their lifetime. Every second 14 adults become a victim of cybercrime, resulting in more than one million cybercrime victims every day.

(iv) For the first time, the Norton Cybercrime Report reveals that 10 percent of adults online have experienced cybercrime on their mobile phone. In fact, the Symantec Internet Security Threat Report, Volume 16

(v) reported there were 42 percent more mobile vulnerabilities in 2010 compared to 2009 - a sign that cybercriminals are starting to focus their efforts on the mobile space. The number of reported new mobile operating system vulnerabilities increased, from 115 in 2009 to 163 in 2010. In addition to threats on mobile devices, increased social networking and a lack of protection are likely to be some of the main culprits behind the growing number of cybercrime victims.
Canada not immune to digital dangers There are close to 20,000 Canadian adults falling victim to cybercrime everyday - that's about 14 every minute.
Most are experiencing computer virus or malware attacks, or responding to online scams. Largely, Canadians are cognizant of online dangers with 77 percent of respondents noting the possibility of cybercrime is something they are always aware of when online. However, some are not taking the necessary precautions with 35 percent of Canadian adults revealing they don't have up-to-date security software.
"Canadians are becoming more aware that cybercrime is real and can affect anyone, but some work needs to be done to further educate them on how to protect themselves," said Lynn Hargrove, Director of Consumer Solutions, Symantec Canada "This survey is important because it shows the costs of cybercrime and people tend to do something to protect themselves when they see it can have a big impact on their bottom line." Male, Millennial, Mobile The study identifies men between 18 and 31 years old who access the Internet from their mobile phone as even more likely victims: in this group four in five (80 percent) have fallen prey to cybercrime in their lifetime. Globally, the most common - and most preventable - type of cybercrime is computer viruses and malware with 54 percent of respondents saying they have experienced it in their lifetime. Viruses are followed by online scams (11 percent) and phishing messages (10 percent). Earlier this year the Symantec Internet Security Threat Report, Volume 16, found more than 286 million unique variations of malicious software ("malware") compared to the 240 million reported in 2009, representing a 19 percent increase.

(vi) "There is a serious disconnect in how people view the threat of cybercrime," said Adam Palmer, Norton Lead Cybersecurity Advisor.
"Cybercrime is much more prevalent than people realize. Over the past 12 months, three times as many adults surveyed have suffered from online crime versus offline crime, yet less than a third of respondents think they are more likely to become a victim of cybercrime than physical world crime in the next year. And while 89 percent of respondents agree that more needs to be done to bring cybercriminals to justice, fighting cybercrime is a shared responsibility. It requires us all to be more alert and to invest in our online smarts and safety." The disconnect between awareness and action is further illustrated by the fact that while 74 percent of respondents say they are always aware of cybercrime, many are not taking the necessary precautions. Forty-one percent of adults indicated they don't have an up to date security software suite to protect their personal information online. In addition, less than half review credit card statements regularly for fraud (47 percent), and 61 percent don't use complex passwords or change them regularly. Among those who access the Internet via their mobile phone, only 16 percent install the most up to date mobile security.

For More information and to see the Norton cyber crime report click Here

-News Sourec (Norton & Tmcnet)


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Facebook Released Official Security Guide


We all are aware of that Facebook the largest growing social network is under multiple attacks from various corners. If you dig history then you can surely remember that  famous hacker group Anonymous send threat to Facebook that they will hit FB. So avoid such hack attacks and give user more security Facebook released their official security guide. Facebook’s official Security Guide is a short – 14 pages in all – guide, written by former Senior Director of Internet Safety at Symantec Linda McCarthy, security research engineer at Purdue University Keith Watson and teacher and editor Denise Weldon-Siviy.


Some Very Basic Tips:-

  • Avoiding the scammers
  • Using advanced security settings
  • Recovering a hacked Facebook account
  • Stopping imposters.
  • Document is self explanatory and very easy to understand. A must read guid for everyone who uses facebook or does not.

To Download the Facebook Official Security Guide Click Here


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Symantec Web Gateway 5.0 (Malware Protector)


Symantec Web Gateway protects organizations against multiple types of Web-borne malware, prevents data loss over Web and gives organizations the flexibility of deploying it as either a virtual appliance or on physical hardware. Powered by Insight, Symantec’s innovative reputation technology, Web Gateway relies on a global network of over 175 million of users to identify new threats before they cause disruption in organizations.

Key Features:-

  • Backed by Symantec Global Intelligence Network
  • Powered by Symantec Insight Technology
  • Integrates Award-winning Symantec AntiVirus engine
  • Seamless integration with Symantec Data Loss Prevention
  • Application control capabilities
  • URL filtering with flexible policy setting
  • Virtual or physical appliance deployment option
  • SSL Decryption capabilities
  • Multiple layers of malware protection

Key Benefits:-

1. Protection

  • Backed by Symantec’s Global Intelligence Network with real time updates to bolster protection
  • Integrates Symantec’s Award-winning AntiVirus engine
  • Powered by Symantec Insight providing proactive protection against new, targeted, or mutating threats

2. Control

  • Integration with Symantec Data Loss Prevention Network Prevent for Web allows for a robust Web and Data Loss prevention solution from a single vendor
  • Application controls provides administrators with multiple policy settings ensuring users are given access to applications which adhere to company guidelines
  • URL filtering list gives administrators ability to monitor, block, or allow access to over 100+ million sites organized within 62 different categories

3. Management

  • Multiple deployment options give customers ability to deploy Web Gateway as a physical appliance, virtual appliance, or a combination of both
  • Powerful reporting capabilities with out of the box reports and administration through a secure browser with a simple dashboard view
  • Proxy and caching capability meeting unique needs of customer network requirements

To Download the the Trail Version Click Here

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

TDL is Targeting Windows PC, Experts are saying that "it is almost indestructible"


More than four million PCs have been enrolled in a botnet security experts say is almost "indestructible". The botnet, known as TDL, targets Windows PCs and is difficult to detect and shut down. targeting
Code that hijacks a PC hides in places security software rarely looks and the botnet is controlled using custom-made encryption.
Security researchers said recent botnet shutdowns had made TDL's controllers harden it against investigation.
The 4.5 million PCs have become victims over the last three months following the appearance of the fourth version of the TDL virus. The changes introduced in TDL-4 made it the "most sophisticated threat today," wrote Kaspersky Labs security researchers Sergey Golovanov and Igor Soumenkov in a detailed analysis of the virus. "The owners of TDL are essentially trying to create an 'indestructible' botnet that is protected against attacks, competitors, and anti-virus companies," wrote the researchers.
Recent successes by security companies and law enforcement against botnets have led to spam levels dropping to about 75% of all e-mail sent, shows analysis by Symantec.
A botnet is a network of computers that have been infected by a virus that allows a hi-tech criminal to use them remotely. Often botnet controllers steal data from victims' PCs or use the machines to send out spam or carry out other attacks.
The TDL virus spreads via booby-trapped websites and infects a machine by exploiting unpatched vulnerabilities. The virus has been found lurking on sites offering porn and pirated movies as well as those that let people store video and image files. The virus installs itself in a system file known as the master boot record. This holds the list of instructions to get a computer started and is a good place to hide because it is rarely scanned by standard anti-virus programs.
The biggest proportion of victims, 28%, are in the US but significant numbers are in India (7%) and the UK (5%). Smaller numbers, 3%, are found in France, Germany and Canada.
However, wrote the researchers, it is the way the botnet operates that makes it so hard to tackle and shut down.
The makers of TDL-4 have cooked up their own encryption system to protect communication between those controlling the botnet. This makes it hard to do any significant analysis of traffic between hijacked PCs and the botnet's controllers.
In addition, TDL-4 sends out instructions to infected machines using a public peer-to-peer network rather than centralised command systems. This foils analysis because it removes the need for command servers that regularly communicate with infected machines.
"For all intents and purposes, [TDL-4] is very tough to remove," said Joe Stewart, director of malware research at Dell SecureWorks to Computerworld. "It's definitely one of the most sophisticated botnets out there."
However, the sophistication of TDL-4 might aid in its downfall, said the Kaspersky researchers who found bugs in the complex code. This let them pry on databases logging how many infections TDL-4 had racked up and was aiding their investigation into its creators.

-News Source (BBC)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

URL Shorteners Have been Exploited Malware Writers


URL shorteners (such as bit.ly) have escalated in popularity thanks to services like Twitter where every character counts. However they come at a security cost.
Spammers have been using them to for some time, and anyone who frequents twitter will have seen the pornography industry using them. However Symantec’s Nick Johnston reports on a worrying trend, using them to hide malware using so-called drive-by attacks. He reports on one exploit.
The attack abused at least five different URL shortening sites. The message claimed to be from an inter-bank funds transfer service, claiming that a funds transfer had been cancelled. To find out why the transfer was cancelled, recipients were encouraged to click on a link supposedly pointing to a PDF file, but actually pointing to a shortened URL. This shortened URL then redirects to a site with several drive-by exploits.
A drive-by attack is one that exploits security flaws in browsers and causes them to download and execute malicious code simply by visiting a page. They do not require a user to click on anything or download files. In the example cited, the page exploited holes in PDF documents, Java and a Windows Help Center exploit. Expect more of this, warns Symantec.
We saw hundreds of unique shortened URLs being used to link to this malware, and expect to see malware authors using this technique in future.
There are browser plug-ins for Firefox and Chrome that will expand shortened URLs so you can see the destination site before clicking on the link. It is expected that

To See the Symantec Report Click HERE

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Security Essentials is on the first place in North America



Microsoft (17.07 percent), AVG (15.63 percent), and Symantec (14.47 percent) were found to be the top three antivirus vendors in North America, according to the latest quarterly antivirus market share report released by OPSWAT. Microsoft increased its market share from OPSWAT's previous antivirus report to surpass Symantec and become the North American leader. AVG held steady in the second position, and Symantec fell to third.
Worldwide, the top three antivirus vendors detected were Avast (12.37 percent), AVG (12.37 percent), and Avira (12.29 percent). Microsoft was fourth (11.24 percent), followed by ESET Software (9.98 percent).
The software company analyzed more than 43,000 opt-in reports from endpoints worldwide. The reports, generated by OPSWAT's AppRemover and Am I OESIS OK? tools, utilize the detection capabilities of the OESIS Framework to list the applications installed on the endpoint computer. The full 8-page document, titled Q2 2011 Antivirus and Instant Messenger Market Share Report, includes data on the leading antivirus vendors and products in North America and worldwide, Windows OS usage in North America and worldwide, instant messaging market share worldwide, and instant messaging usage in North America and Europe.
The rest of the data wasn't too surprising: Windows 7 usage continues to increase in North America and worldwide, showing a steady trend away from Windows Vista. In both North America and worldwide, Windows XP remains the dominant Windows operating system. The top three worldwide IM applications are Windows Live Messenger, Skype, and Yahoo! Messenger. The report does not, however, account for Web-based instant messaging services such as Google Chat or Facebook. This is because it only looks at installed applications, and those services run in the browser.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Every 14 Programs Downloaded by Windows Users Turns out to be Malicious


The next time a website says to download new software to view a movie or fix a problem, think twice. There's a pretty good chance that the program is malicious.
In fact, about one out of every 14 programs downloaded by Windows users turns out to be malicious, Microsoft said Tuesday. And even though Microsoft has a feature in its Internet Explorer browser designed to steer users away from unknown and potentially untrustworthy software, about 5 percent of users ignore the warnings and download malicious Trojan horse programs anyway.
Five years ago, it was pretty easy for criminals to sneak their code onto computers. There were plenty of browser bugs, and many users weren't very good at patching. But since then, the cat-and-mouse game of Internet security has evolved: Browsers have become more secure, and software makers can quickly and automatically push out patches when there's a known problem.
So increasingly, instead of hacking the browsers themselves, the bad guys try to hack the people using them. It's called social engineering, and it's a big problem these days. "The attackers have figured out that it's not that hard to get users to download Trojans," said Alex Stamos, a founding partner with Isec Partners, a security consultancy that's often called in to clean up the mess after companies have been hacked.
Social engineering is how the Koobface virus spreads on Facebook. Users get a message from a friend telling them to go and view a video. When they click on the link, they're then told that they need to download some sort of video playing software in order to watch. That software is actually a malicious program.
Social-engineering hackers also try to infect victims by hacking into Web pages and popping up fake antivirus warnings designed to look like messages from the operating system. Download these and you're infected. The criminals also use spam to send Trojans, and they will trick search engines into linking to malicious websites that look like they have interesting stories or video about hot news such as the royal wedding or the death of Osama bin Laden.
"The attackers are very opportunistic, and they latch onto any event that might be used to lure people," said Joshua Talbot, a manager with Symantec Security Response. When Symantec tracked the 50 most common malicious programs last year, it found that 56 percent of all attacks included Trojan horse programs.
In enterprises, a social-engineering technique called spearphishing is a serious problem. In spearphishing, the criminals take the time to figure out who they're attacking, and then they create a specially crafted program or a maliciously encoded document that the victim is likely to want to open -- materials from a conference they've attended or a planning document from an organization that they do business with.

With its new SmartScreen Filter Application Reputation screening, introduced in IE 9, Internet Explorer provides a first line of defense against Trojan horse programs, including Trojans sent in spearphishing attacks.
IE also warns users when they're being tricked into visiting malicious websites, another way that social-engineering hackers can infect computer users. In the past two years, IE's SmartScreen has blocked more than 1.5 billion Web and download attacks, according to Jeb Haber, program manager lead for SmartScreen.
Haber agreed that better browser protection is pushing the criminals into social engineering, especially over the past two years. "You're just seeing an explosion in direct attacks on users with social engineering," he said. "We were really surprised by the volumes. The volumes have been crazy."
When the SmartScreen warning pops up to tell users that they're about to run a potentially harmful program, the odds are between 25 percent and 70 percent that the program will actually be malicious, Haber said. A typical user will only see a couple of these warnings each year, so it's best to take them very seriously.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

BitDefender Offers Insights Into Recently Discovered Facebook Vulnerability



Symantec discovered a security vulnerability that affected the way third party programs, such as games and other applications, accessed user data and information. According to BitDefender®, an award-winning provider of innovative internet security solutions, the entire issue is related to OAUTH, the secure authorization protocol, and the use of some deprecated parameters by different applications which are still not updating from OAUTH to its latest version, OAUTH2.0.
From this vulnerability, third parties, such as advertisers can get hold of access tokens, which open Facebook users' account information (such as basic information, profiles, pictures) and will sometimes give them the ability to perform different actions in the user's name.
"At the current time, it is unclear whether there actually was a data breach or not. Symantec discovered a security issue and notified Facebook accordingly," commented Catalin Cosoi, Head of the BitDefender Online Threats Lab. "This could mean that the issue was proactively discovered and Facebook fixed it before anyone lost any data. On the other hand, it could mean that it is a known vulnerability in the underground or unethical world and users' private data has been leaking for some time now."
Facebook has solved this issue as soon as possible, but this episode teaches all users two main lessons: (1) applications should have switched to the new authorization mechanism as soon as possible and (2) if any data was leaked, there's not much to be done now, since it is lost for good.
Although it should not be the case here, information extracted from social media can be easily converted into directed attacks, like phishing, highly social engineered spam messages and possibly even identity theft. Users should pay extra attention in the following months when it comes to all messages received and be very careful when asked to perform different actions, even if the messages/requests come from a trusted source.
"This information can be illicitly used by marketers and advertisers in order to better profile their users and to serve ads based on interests and views. As always, a good way for Facebook users to invalidate their current access tokens is for them to change their passwords," advised Cosoi.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...