Archive for month: January, 2009
30 January, 2009 (12:49) | General, Malware, Security, Software, tools | By: admin
Sophos recently released an emergency boot disk for cleaning up pesky infections. The 85 MB iso boots straight into a Sophos Antivirus menu with 5 options: Scan for Viruses (detect only) Disinfect Viruses Delete Viruses Keyboard Layout Bash Shell Simple, easy and free (with eval credentials). Update: Testing shows that this disk is missing support [...]
Tags: Antivirus, boot disk, emergency cleanup, Sophos | 2 comments
30 January, 2009 (09:29) | General, Microsoft, Security, Software | By: admin
Found a great article while browsing Schneier on Security. This chunk was real interesting because I see this behavior associated with variants of Troj/Virtum (Virtumundo). make a poller which continuously polls about every 10 seconds or so to see if the BHO was there and alive. If it was, great. If it wasn’t, [ the [...]
Tags: Malware, virtum, virtumundo | No comments
26 January, 2009 (14:53) | General, Malware, Microsoft, Security, Software, Web, network | By: admin
Symantec has a great write up of Conficker and how it attempts to spread across the network. I wish more organizations would publish detailed information like this. Update: Added 5 more links from Symantec including a resolve tool for clearing Conficker. Downadup: Small Improvements Yield Big Returns Downadup: A Lock with No Key Downadup: Geo-location, [...]
Tags: conficker, exploit, MS08-067, removal, symantec, virus, worm | No comments
26 January, 2009 (12:28) | General, Security, Software, Web | By: admin
If you’re using an installer package to deploy Sophos Antivirus, you’ll have the invalid manifest error if the package was created prior to Dec 11th. Unless there is any custom scripting, the fix is very simple. Following the instructions from the Sophos Website, simply open the archive (zip, rar etc…) and replace the contents of [...]
Tags: cert, invalid manifest, manifest, sau, Sophos, sophos autoupdate, updating | No comments
22 January, 2009 (09:23) | General, Security, Software, Web, tools | By: admin
Lenny Zeltser, a handler at SANS Internet Storm Center wrote a great article on Data Mining Twitter. I spent the next three hours trying out a few techniques outlined in the article. One item of interest made me laugh because it’s something I regularly do. As you gather information on Twitter, be mindful of others [...]
Tags: data mining, misdirection, Twitter | No comments
22 January, 2009 (07:11) | General, Hardware | By: admin
My trusted brand of Hard Drives, Seagate is having major issues with their Barracuda 7200.11. With reported failure rates of 30%, Seagate is now offering free data recovery for those drives.
Tags: barracude, data recovery, faulty, hd failure, seagate | No comments
21 January, 2009 (21:11) | General, Malware, Microsoft, Security, Software, network | By: admin
Nearly three months after the release of MS08-067, W32/Conficker is still spreading. Here are a series of links to understand and combat the threat. Microsoft Malware Protection Center MSRT Released Addressing Conficker US-CERT Technical Cyber Security Alert TA09-020A
Tags: Malware, Microsoft, MS08-067, W32/Conficker, worm | 1 comment
20 January, 2009 (06:30) | General, Malware, Microsoft, Security, Software, Web, network | By: admin
TechRepublic has a great article today on botnet recruiting methods and basic defense. Check it out here.
Tags: botnet, Malware, Microsoft, network, Security | No comments
19 January, 2009 (22:56) | General, Security, Web, network | By: admin
My favorite folks at SANS ISC are reporting the start of a DDOS attack that is using open DNS servers to amplify their attack. You can test your DNS servers from their site here.
Tags: DDOS | No comments
16 January, 2009 (14:13) | General, Security, Software | By: admin
If your Sophos Antivirus clients have mysteriously stopped updating on Jan 16th, here’s the link for you. A new security certificate was put in place for all clients starting Dec 11th. If your clients haven’t updated since then, all further updates will fail until you take the corrective steps in the link above. A failure [...]
Tags: Antivirus, invalid manifest, Software, Sophos | 1 comment