Pirated Windows 7 RC builds botnet

June 15, 2009

A pirated version of Windows 7 Release Candidate infected with a Trojan horse has created a botnet with tens of thousands of bots under its control, according to researchers at security firm Damballa.

The software, which first appeared on April 24, spread as quickly as several hundred new bots per hour, and controlled roughly 27,000 bots by the time Damballa took over the network's command and control server on May 10, the firm said Tuesday.

The pirated software was spread via popular piracy sites and online forums, Damballa said.

The software is primarily designed to download and install other malicious packages under a "pay-per-install" scheme, under which the botmasters are paid based on the number of other pieces of malware they cause to be installed, Damballa said.

Infected installations are continuing to appear at a rapid rate, according to the company.

"We continue to see new installs happening at a rate of about 1,600 per day with broad geographic distribution," Tripp Cox, Damballa's vice president of engineering, said in a statement. "Since our takedown (of the command and control server), any new installs of this pirated distribution of Windows 7 RC are inaccessible by the botmaster."

However, the botmaster still controls the existing installations, Damballa said. The infected systems are mainly concentrated in the U.S., with 10 percent, and the Netherlands and Italy, with 7 percent each.

Windows 7 RC has been used as a lure by other malware distributors since its launch on May 5, according to security experts. On Monday, Trend Micro said it found the Trojan horse TROJ_DROPPER.SPX masquerading as a copy of the release candidate.

Botnets are one of the most serious threats on the Internet, according to security experts, and are typically used to carry out denial-of-service attacks or phishing schemes or to send junk mail. Last month, SecureWorks researcher Joe Stewart suggested that technology was not enough to stop botnets, arguing that the IT industry should look to new law-enforcement measures.

The legitimate version of Windows 7 RC is available from Microsoft's Web site.

 

Google fine-tunes : new filters + visualized results

June 15, 2009

Marissa Mayer, vice president of search products and experience, led a parade of the company's product managers on stage at Searchology 2009 to demonstrate the new features, known as Google Search Options, Google Squared, and Rich Snippets. Search Options will be rolling out gradually on Tuesday, giving searchers ways to filter their results based on factors like timeliness, result type such as image or videos, or a desire to see search results in visual form.

The announcements "center around how can you find more, and what can you do with it," Mayer said. Google last held a Searchology event in 2007, when it introduced Universal Search, blending regular search results with images, video, and news results.

Building on Universal Search, Mayer and Nundu Janakiram, an associate product manager, showed how Search Options allows users searching for information on the Hubble Telescope, for example, to filter their results with a "Show Options" link at the very top of the search results page. Clicking on that link brings up a new page with a list of options on the side, somewhat akin to the current Google News user interface.

By opting for the most recent information on the space telescope, the subject of a current NASA mission, users will be given a mix of news and blog results. If they prefer, they can click a filter that will sort those stories with images pulled from those stories.

Other options include new ways to visualize search results, such as the News Timeline introduced last month, as well as something called Wonder Wheel that visually represents data as rays of a star spreading out from the center of a search result.

Google Squared is the newest addition to Google Labs. This project allows searchers to create a spreadsheet based on Web results. Users can filter the data accessed through the Google Squared search, request additional categories to create a custom spreadsheet with the results that matter the most to them, and even fact-check the results by accessing the source of the data as well as alternate sources.

The other enhancement discussed Tuesday is called Rich Snippets, which is a partnership between Google and certain publishers, including CNET, to display information from Web pages within the box that encompasses a search result. Google is backing open standards called RDFa markup and Microformats markup that allow Web publishers to highlight aspects of their Web page to show in the search results.

Rich Snippets

Rich Snippets is a partnership between Google and certain publishers, including CNET, to display information from Web pages within the box that encompasses a search result.

The CNET example used in the presentation displayed the number of stars assigned by a CNET reviewer to a GPS device in the search results for a particular product. Likewise, Yelp's user-generated restaurant ratings will show up in the search result for a certain restaurant.

The feature is closely related to Yahoo's SearchMonkey, which the Google rival released a year ago. SearchMonkey allows outside developers to create their own SearchMonkey extensions to spotlight content, but to try to encourage use by more publishers, Yahoo has been working to make SearchMonkey easier to use.

 

Microsoft patches critical PowerPoint hole

June 15, 2009

Microsoft on Tuesday released a patch aimed to fix a critical vulnerability in PowerPoint that had already led to exploits.

The vulnerability is listed as critical for Office 2000, but rated only as important for Office XP, Office 2003, and Office 2007. However, the hole had already formed the basis of targeted attacks, prompting Microsoft to issue a warning last month.

Although Microsoft says the hole is now patched in the Windows version of PowerPoint, the software maker said it is still working on fixes for the Mac version of Office as well as for Microsoft Works, the company's entry-level productivity suite.

"The updates for Office for Mac and Microsoft Works 8.5 and 9.0 users are still in development," Microsoft security response communications lead Christopher Budd said in a statement. "Microsoft plans to issue updates for these software when testing is complete and we can ensure high quality. We are releasing this security update on an incremental basis because of active targeted exploitation toward Windows platform users."

Without the patch, the vulnerability can be exploited by getting a person to open a PowerPoint file rigged for the attack, Microsoft has said. When the file is opened, PowerPoint will access an invalid object in memory. That then allows an attacker to remotely execute code on the system.

The fix was released as part of the company's regularly scheduled monthly Patch Tuesday.

The software maker said that with the update, the ability to open PowerPoint 4.0 file formats will be disabled by default in Microsoft Office PowerPoint 2000 and Microsoft Office PowerPoint 2002. (Microsoft has already disabled that option by default in PowerPoint 2003 Service Pack 3 and that capability does not exist in PowerPoint 2007.)

Microsoft said that the vulnerability is not rated critical for PowerPoint 2002 and later versions because they prompt a user before opening a document, meaning that the vulnerability "requires more than a single user action to complete the exploit."

Symantec said in a statement that the PowerPoint fix related largely to flaws in older file formats. "Because taking advantage of these vulnerabilities requires a user to open a maliciously crafted PowerPoint file, e-mail is likely the most probable method attackers would use to try and exploit these," said Alfred Huger, vice president of Symantec Security Response, in a statement. "Another possibility is for an attacker to lure a victim into downloading the file from a misleading or compromised Web site. At that point, the attacker would then have complete control over everything the user's account has permission to do on the system."

One security analyst warned that corporate IT staff should be paying attention not just to Microsoft, but also to a variety of security updates being issued by other software makers.

"Although Microsoft only dropped one patch for PowerPoint this month, IT administrators shouldn't get the wrong impression and breathe easy given the light load," said Lumension security analyst Paul Henry. "In addition to Microsoft, other vendors including Google, F-Secure, Adobe, HP, Symantec and Mozilla (to name a few) released a slew of patches for popular software applications."

Henry posted a list of the other updates and blogged on the subject.

"It is important to remember that historically, popular applications and files like Adobe PDF files or Word, Excel or PowerPoint files have been great vehicles for targeted attacks because those attachments are so socially acceptable and are simply expected attachments within corporate email," Henry said. "While we are relieved about the PowerPoint patch, we live in an environment where compromised applications have now become a delivery mechanism for additional downloaded and executed malware such as key-loggers and rootkits. The most effective risk mitigation, therefore, continues to be application control to prevent a compromised application from downloading and running any unauthorized software (including malware) on a user's PC."

 



Best Communitation Website
Which communication website is best?

Myspace
Facebook
Twitter
Furry-paws
Youtube


Make a free website with Yola