Exploit Prevention Labs BlogAs Chief Researcher for Exploit Prevention Labs, I come across some really interesting bad-guy behavior patterns that on the whole don't bode well for the future of a trusted Internet. I'll be posting my thoughts on some of the most interesting stuff I find to this blog.google defames saints ... bolts of lightning fall- February 25, 2008 I'm kidding, I'm kidding!!!!!!! Update number 2: Feb 26, 2008, 6:30am est Dang, that was quick. Some of the sites, such as St Kilda, and the Geelong Cats sites, are now correctly marked as clean. They're not all correct though ... the Brisbane Lions site is still incorrectly marked as dangerous, for example, but that was still quick for the others, and we hope that all will shortly be corrected. Shout-outs to google for reacting quickly! Update number 1: Some of our team in the Austrhttp://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/exploit-preventi... Another gov site hacked- February 22, 2008 Hi folks, Who can see what's wrong with this picture Looks pretty reasonable, doesn't it Here's what you see if you have a suitable monitoring tool... a href="http:bp3.blogger.http://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/exploit-preventi... This is kind of funny- February 21, 2008 Hi folks, We've been following up on the new Neosploit that we reported last night. This was actually a pretty high-profile site, so we wanted to notify them. We couldn't find a contact point on the hacked domain, but we found another subdomain that had an online support chat option, and we gave it a try. The conversation was sufficiently funny that we grabbed a screen capture (anonymized to protect the innocent). You might have to double-click it to read it, but it's worthwhile... a hrehttp://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/exploit-preventi... New Neo Now- February 20, 2008 (Sorry... the alliteration bug bit me) Last night, as the title suggests, we found a new version of Neosploit. It has two new exploits, one uses a clsid of EEE78591-FE22-11D0-8BEF-0060081841DE, which appears to be the ActiveVoice ActiveX dll from Microsoft, and the other clsid is 5F810AFC-BB5F-4416-BE63-E01DD117BD6C, which is the Music Jukebox control from Yahoo. The most recent ActiveVoice exploit seems to be from about June 2http://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/exploit-preventi... MalwareAlarm- February 7, 2008 MalwareAlarm is so common now, we decided to give it it's own vid. Remember, it's not really scanning your pc, it's just pretending to, but it does a very good job of pretending. Enjoy... Cheers, Rogerhttp://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/exploit-preventi... UK .gov site hacked- February 6, 2008 Note: One of our users, John Thomson (no relation as far as I know :-) ) noticed this first and brought it to our attention. His blog entry is here ... http:www.roundtripsolutions.comblog20080206317forth-road-bridge-website-hacked Sorry John! :-) Hi folks, Sometime between the 1st Feb 2008, and the 3rd of Feb 2008, the official website for the Forth Estuary Transport Authority was hacked an obfuscated iframe, using Neosploit encoding, was injected. a href="http:bp1.bloghttp://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/exploit-preventi... |