Archive for November, 2007

Miscreants subvert search results to punt malware

Wednesday, November 28th, 2007

Using botnets to plant links and nurture zombie farms
Miscreants have set out to poison search results with links to malware infested sites via a new campaign.…

Read more…

Celebrity spam gang whips up a storm

Wednesday, November 28th, 2007

Stealth botnet responsible for huge spam surge
A copycat spam gang has launched an effort to compromise PCs that rivals the botnet created by the infamous Storm Worm Gang.…

Read more…

Exploit Released for Unpatched QuickTime Flaw

Wednesday, November 28th, 2007

Instructions for exploiting a previously undocumented security hole in Apple’s QuickTime media player software are now available online, and security firms are warning that it may not be long before we start seeing criminal groups taking advantage of the flaw to break into vulnerable computers. According to an advisory from the US-CERT, the vulnerability stems from a weakness in the way QuickTime handles a type of media-streaming communications called the “real time streaming protocol” (RTSP). Attackers could exploit the flaw merely by convincing users to click on a poisoned link, open a malicious e-mail attachment, or visit a specially crafted Web page. US-CERT says the vulnerability is present in QuickTime versions 4.0 through 7.3 (the latest version) on both Windows and Mac systems. Interestingly, researchers at Symantec say they tested the publicly available exploit code for this flaw and found that it failed to work properly against Internet Explorer [...]

Read more…