<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Technologizer &#187; Malware</title>
	<atom:link href="http://technologizer.com/tag/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://technologizer.com</link>
	<description>Reviews, News, and Opinion About Personal Technology by Harry McCracken &#38; Friends</description>
	<lastBuildDate>Fri, 10 Feb 2012 06:45:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='technologizer.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Technologizer &#187; Malware</title>
		<link>http://technologizer.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://technologizer.com/osd.xml" title="Technologizer" />
	<atom:link rel='hub' href='http://technologizer.com/?pushpress=hub'/>
		<item>
		<title>The Mac&#8217;s Malware Problem Just Got A Lot Worse</title>
		<link>http://technologizer.com/2011/05/25/the-macs-malware-problem-just-got-a-lot-worse/</link>
		<comments>http://technologizer.com/2011/05/25/the-macs-malware-problem-just-got-a-lot-worse/#comments</comments>
		<pubDate>Thu, 26 May 2011 02:00:00 +0000</pubDate>
		<dc:creator>Ed Oswald</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Apple OS X]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://technologizer.com/?p=43819</guid>
		<description><![CDATA[Apple may have thought that its statement yesterday would get the Mac Defender mess under control. But the malware is back under a new name&#8211;MacGuard&#8211;and in a more dangerous form. ZDNet blogger Ed Bott, who&#8217;s known more for his reporting on Microsoft than on anything Apple, has been hot on this story since the get go. He reported [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=43819&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-43820" style="margin-left:8px;margin-right:8px;" title="mac-defender-alert" src="http://technologizer.files.wordpress.com/2011/05/mac-defender-alert.jpg?w=210&#038;h=158" alt="" width="210" height="158" />Apple may have thought that <a href="http://technologizer.com/2011/05/24/apple-responds-to-mac-defender-malware-mess/">its statement yesterday</a> would get the <a href="http://technologizer.com/2011/05/23/mac-protector-trojan/">Mac Defender mess</a> under control. But the malware is back under a new name&#8211;MacGuard&#8211;and in a more dangerous form.</p>
<p>ZDNet blogger Ed Bott, who&#8217;s known more for his reporting on Microsoft than on anything Apple, has been hot on this story since the get go. He reported Wednesday that as if on cue the Mac Defender creators <a href="http://www.zdnet.com/blog/bott/mac-malware-authors-release-a-new-more-dangerous-version/3385">have released a new version</a> of the malware application that requires no password at all to install.</p>
<p>See, Mac users -including myself&#8211;have accurately pointed out that basically all attempted malware for the Mac required the user to enter the administrative password. If you did that, it was <em>your own stupid fault</em> for getting infected. With MacGuard, it&#8217;s completely different.</p>
<p><span id="more-43819"></span></p>
<p>Here&#8217;s how these malware purveyors are getting around this: the application is now installing a downloader directly to the Applications folder, which requires no password and only clicking &#8220;Continue&#8221; to begin the install as long as you&#8217;re logged in as an Administrator.</p>
<p>Most Mac users are, since that&#8217;s the default OS X account. After that, the downloader automatically retrieves and installs MacGuard, which is almost the same as its earlier cousin Mac Defender.</p>
<p>Now with this taken care of, all that seemingly is left is these folks figuring out a way to fool the operating system into thinking that &#8220;Continue&#8221; button was pressed automatically, and you&#8217;d have malware on your Mac with no human intervention at all. Certainly now the malware problem from Apple has gone from an annoyance to a serious issue. Apple can no longer wait three weeks to address issues like this, like it seemingly did with Mac Defender.</p>
<p>Could Apple be headed for a repeat of the dark days of Windows in the early part of last decade where Microsoft ended up always being a step behind the attackers? Could be. The Mac Defender folks are proving there are ways into Mac OS, no matter what the Apple apologists may say.</p>
<p>I still agree that overall, OS X is a lot safer of an operating system than Windows will ever be, largely due to the fact that Microsoft must deal with a lot more legacy code than Apple does. Creaky old code is often the way in for these attackers.</p>
<p>I&#8217;d be interested in hearing from users running into MacGuard in the wild. If you see it, let us know here so we can stay on top of this story.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technologizer.wordpress.com/43819/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technologizer.wordpress.com/43819/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technologizer.wordpress.com/43819/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technologizer.wordpress.com/43819/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technologizer.wordpress.com/43819/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technologizer.wordpress.com/43819/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technologizer.wordpress.com/43819/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technologizer.wordpress.com/43819/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technologizer.wordpress.com/43819/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technologizer.wordpress.com/43819/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technologizer.wordpress.com/43819/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technologizer.wordpress.com/43819/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technologizer.wordpress.com/43819/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technologizer.wordpress.com/43819/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=43819&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://technologizer.com/2011/05/25/the-macs-malware-problem-just-got-a-lot-worse/feed/</wfw:commentRss>
		<slash:comments>46</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3fae6987702d8d79d8609b011e09a637?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">Ed Oswald</media:title>
		</media:content>

		<media:content url="http://technologizer.files.wordpress.com/2011/05/mac-defender-alert.jpg?w=300" medium="image">
			<media:title type="html">mac-defender-alert</media:title>
		</media:content>
	</item>
		<item>
		<title>Cybercrooks use Amazon to Run Botnet</title>
		<link>http://technologizer.com/2009/12/10/cybercrooks-use-amazon-to-run-botnet/</link>
		<comments>http://technologizer.com/2009/12/10/cybercrooks-use-amazon-to-run-botnet/#comments</comments>
		<pubDate>Fri, 11 Dec 2009 00:28:10 +0000</pubDate>
		<dc:creator>David Worthington</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://technologizer.com/?p=20800</guid>
		<description><![CDATA[Robert McMillan of the IDG News Service is reporting that cyber criminals gained access to an Amazon Web Services (AWS) account, and used Amazon&#8217;s cloud infrastructure to manage and run its botnet. Expect more cloud-based attacks such as this one in the future. The botnet was a Zeus bot (Zbot) variant. The Zeus trojan is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=20800&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Robert McMillan of the IDG News Service is <a href="http://www.pcworld.com/businesscenter/article/184159/hackers_find_a_home_in_amazons_ec2_cloud.html">reporting</a> that cyber criminals gained access to an Amazon Web Services (AWS) account, and used Amazon&#8217;s cloud infrastructure to manage and run its botnet. Expect more cloud-based attacks such as this one in the future.</p>
<p>The botnet was a Zeus bot (Zbot) variant. The Zeus trojan is a  program that criminals use to gather personal and financial data from its victims.</p>
<p>Hackers that create trojans such as Zeus are becoming increasingly organized and function like corporations, according to a security <a href="http://technologizer.com/2009/11/02/malware-inc-the-criminals-behind-the-attacks/">recent report</a> published by Microsoft. That structure enables regular malware release schedules, and gives criminals the ability to exploit complex vulnerabilities in software&#8211;even as operating systems become more secure.</p>
<p>Law enforcement has made some progress toward shutting down the data centers that criminals use to host their infrastructure, but the crooks are seemingly one step ahead, and have now migrated to Web-based services. IDG reports that unnamed law enforcement officials have begun to worry that stolen credit cards could be used to purchase cloud computing services such as AWS.</p>
<p>That&#8217;s a given. I hope that cloud providers take action to discover malware on their server, and have the capacity to shut it down before serious damage can be done. They have a responsibility to do so.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technologizer.wordpress.com/20800/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technologizer.wordpress.com/20800/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technologizer.wordpress.com/20800/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technologizer.wordpress.com/20800/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technologizer.wordpress.com/20800/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technologizer.wordpress.com/20800/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technologizer.wordpress.com/20800/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technologizer.wordpress.com/20800/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technologizer.wordpress.com/20800/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technologizer.wordpress.com/20800/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technologizer.wordpress.com/20800/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technologizer.wordpress.com/20800/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technologizer.wordpress.com/20800/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technologizer.wordpress.com/20800/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=20800&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://technologizer.com/2009/12/10/cybercrooks-use-amazon-to-run-botnet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/262868df0e44c7410b5099d919991983?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">David Worthington</media:title>
		</media:content>
	</item>
		<item>
		<title>Malware Inc.: The Criminals Behind the Attacks</title>
		<link>http://technologizer.com/2009/11/02/malware-inc-the-criminals-behind-the-attacks/</link>
		<comments>http://technologizer.com/2009/11/02/malware-inc-the-criminals-behind-the-attacks/#comments</comments>
		<pubDate>Mon, 02 Nov 2009 17:00:06 +0000</pubDate>
		<dc:creator>David Worthington</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://technologizer.com/?p=19167</guid>
		<description><![CDATA[Malware makers&#8211;the criminals responsible for viruses and worms &#8211;have become increasingly organized and sophisticated, according to a Microsoft security report that was released today. Gamers, the gullible, USB drive users, and people who don&#8217;t patch their PCs are their biggest targets. Cybercriminals are organized like corporations, and follow regular software release cycles, said Jeff Williams, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=19167&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Malware makers&#8211;the criminals responsible for viruses and worms &#8211;have become increasingly organized and sophisticated, according to a<a href="http://www.microsoft.com/sir"> Microsoft security report </a> that was released today. Gamers, the gullible, USB drive users, and people who don&#8217;t patch their PCs are their biggest targets.</p>
<p>Cybercriminals are organized like corporations, and follow regular software release cycles, said Jeff Williams, principal group program manager for the Microsoft Malware Protection Center: &#8220;They are working for monetary gain.&#8221;</p>
<p>The report, entitled, Microsoft Security Intelligence Report Volume 7, is based upon data collected worldwide from January through June 2009. The data was obtained through Microsoft&#8217;s security products, Hotmail, and Windows Update, Williams said. &#8220;It shows differences from region to region, and provides a comprehensive view of the threat landscape.&#8221;</p>
<p>Globally, Microsoft found that the number of trojan downloaders has fallen markedly over the past year; although, they did remain the most common threat. That gain was offset by a rise in instances of worms, password stealers and monitoring tools, according to the report.</p>
<p>Malware has been increasingly targeting online gamers, and there has been a major uptake in fraudulent security software, Williams said. Criminals create trojan software that purports to protect users from malware, but does nothing more than steal personal information and obtain credit card information through false premise.</p>
<p>Criminals have also begun the practice of bundling malware, and making &#8220;pay for play&#8221; arrangements with one another, Williams said. Another trend Williams noted is the misuse of autoplay in Windows, and using removable media like USB jump drives as an attack vector to get inside of protected enterprise environments.</p>
<p>Microsoft recommends that customers should use trusted anti virus software, a Web browser with anti-phishing technology, and keep their operating systems up-to-date. Security software, combined with increased industry and government cooperation, has helped Microsoft better protect customers over the past year, Williams said.</p>
<p>However, Microsoft is playing a game of multidimensional chess against an opponent that is profit-driven. Improvements in security have induced cyber criminals to exploit more complex software vulnerabilities, and those vulnerabilities have become the new chosen mechanisms for propagating worms of worms, Williams acknowledged.</p>
<p>&#8220;They left a note in a worm telling us that they would take more direct action in the future. Criminals are becoming more aggressive,&#8221; Williams said. Simply put, when one door closes, they find another.</p>
<p>With Windows becoming more secure, third party applications are being targeted with rising frequency, Williams noted. To combat that threat, Microsoft has delivered <a href="http://www.sdtimes.com/link/33493">free security tools</a> to developers, along with documentation on the steps that it takes internally to create secure software.</p>
<p>Thankfully, other major software companies including HP and IBM have bought security firms, and are making efforts to secure their software. A lot of the industry still lags, but steady progress is being made.</p>
<p>A security expert once told me that hackers were the highwaymen of our century. Highwaymen were thieves that preyed upon travelers during the Elizabethan era. They became obsolete when society created toll roads&#8211;closing off their route of escape&#8211;and increased police patrols. The crime was not worth the time.</p>
<p>Software is exceedingly more complex than road building, and modern operating systems are some of the most advanced things man has ever created. It&#8217;s not really possible to make software that is entirely secure. Even still, I have confidence that enough progress will be made to raise the risks and reduce the gains of cybercrime.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technologizer.wordpress.com/19167/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technologizer.wordpress.com/19167/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technologizer.wordpress.com/19167/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technologizer.wordpress.com/19167/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technologizer.wordpress.com/19167/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technologizer.wordpress.com/19167/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technologizer.wordpress.com/19167/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technologizer.wordpress.com/19167/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technologizer.wordpress.com/19167/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technologizer.wordpress.com/19167/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technologizer.wordpress.com/19167/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technologizer.wordpress.com/19167/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technologizer.wordpress.com/19167/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technologizer.wordpress.com/19167/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=19167&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://technologizer.com/2009/11/02/malware-inc-the-criminals-behind-the-attacks/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/262868df0e44c7410b5099d919991983?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">David Worthington</media:title>
		</media:content>
	</item>
		<item>
		<title>All Your Apple Belong To Us: First Mac Botnet?</title>
		<link>http://technologizer.com/2009/04/16/all-your-apple-belong-to-us-first-mac-botnet/</link>
		<comments>http://technologizer.com/2009/04/16/all-your-apple-belong-to-us-first-mac-botnet/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 03:55:29 +0000</pubDate>
		<dc:creator>Ed Oswald</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://technologizer.com/?p=10967</guid>
		<description><![CDATA[Ryan Naraine at ZDNet has a shocker: Symantec has said it has evidence of the first known Botnet comprised of Mac computers that are attempting to launch denial-of-service attacks. The root cause appears to be a cracked copies of iWork &#8217;09 and Adobe Photoshop CS4 that also includes an additional payload with the Botnet code. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=10967&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Ryan Naraine at ZDNet <a href="http://blogs.zdnet.com/security/?p=3157">has a shocker</a>: Symantec has said it has evidence of the first known Botnet comprised of Mac computers that are attempting to launch denial-of-service attacks. The root cause appears to be a cracked copies of iWork &#8217;09 and Adobe Photoshop CS4 that also includes an additional payload with the Botnet code.</p>
<p>These applications are apparently making the rounds on BitTorrent. Moral of the story here? Stop using pirated apps.</p>
<p>OSX.Iservice and OSX.Iservice.B are the names of the files, which essentially obtain the password of the Mac machine allowing the hackers to take control. Estimates of affected Macs number in the thousands, Symantec estimates.</p>
<p>So much for the &#8216;Macs are immune&#8217; meme. While this doesn&#8217;t point to an actual vulnerability just yet, it indicates that Macs like every other computer can be used for malicious purposes.</p>
<p>Of course the Apple faithful will be quick to yell this down, but I don&#8217;t think dismissing this is a good idea. So suck it up people and download a Mac virus scanner. Yes, you do need it.</p>
<p>I think the above is enough proof that the threat is real, no?</p>
<p><strong>Update:</strong> Commenter Dave Barnes brought up another good program for detecting unwanted outgoing data: <a href="http://www.obdev.at/products/littlesnitch/index.html">Little Snitch</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technologizer.wordpress.com/10967/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technologizer.wordpress.com/10967/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technologizer.wordpress.com/10967/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technologizer.wordpress.com/10967/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technologizer.wordpress.com/10967/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technologizer.wordpress.com/10967/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technologizer.wordpress.com/10967/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technologizer.wordpress.com/10967/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technologizer.wordpress.com/10967/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technologizer.wordpress.com/10967/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technologizer.wordpress.com/10967/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technologizer.wordpress.com/10967/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technologizer.wordpress.com/10967/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technologizer.wordpress.com/10967/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=10967&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://technologizer.com/2009/04/16/all-your-apple-belong-to-us-first-mac-botnet/feed/</wfw:commentRss>
		<slash:comments>25</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3fae6987702d8d79d8609b011e09a637?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">Ed Oswald</media:title>
		</media:content>
	</item>
		<item>
		<title>Malware is Messing with Facebook Users</title>
		<link>http://technologizer.com/2009/02/27/malware-is-messing-with-facebook-users/</link>
		<comments>http://technologizer.com/2009/02/27/malware-is-messing-with-facebook-users/#comments</comments>
		<pubDate>Fri, 27 Feb 2009 22:04:53 +0000</pubDate>
		<dc:creator>David Worthington</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web 2.0]]></category>

		<guid isPermaLink="false">http://technologizer.com/?p=8573</guid>
		<description><![CDATA[A rogue application has struck Facebook for the second time within a week, reports Trend Micro&#8217;s Malware Blog. The malware uses social engineering to hoodwink Facebook users into installing it, and then proceeds to harvest their personal information. But don&#8217;t panic yet &#8211; it&#8217;s not that easy to do. When a user installs the application, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=8573&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A rogue application has struck Facebook for the second time within a week, reports Trend Micro&#8217;s <a href="http://blog.trendmicro.com/a-second-rogue-facebook-application-in-just-a-week/">Malware Blog</a>. The malware uses social engineering to hoodwink Facebook users into installing it, and then proceeds to harvest their personal information. But don&#8217;t panic yet &#8211; it&#8217;s not that easy to do.</p>
<p>When a user installs the application, it propagates itself by spamming their friends profiles with fake but official sounding notices that they have violated the Facebook terms of service. In order to avoid &#8220;penalties,&#8221; the user is instructed to install the application. If the would-be victim falls for it, the cycle repeats.</p>
<p>Trend Micro has pointed out the obvious: Facebook should review its application hosting policy. The firm also recommended that users take responsibility for what they are installing, and to do some research beforehand.</p>
<p>One possible solution is a verification process for applications, but the problem would have to be more prevalent to justify its costs, said Caleb Sima, an HP executive that is the former co-founder and CTO of SPI Dynamics.</p>
<blockquote><p>&#8220;Really, I don&#8217;t have much to say about this as I have been expecting it for a while. Its no different then email. I send you a link to a program you allow it to install it takes your contacts list and spams it out. There is nothing new here. Its just applied as a Facebook app or message.&#8221;</p></blockquote>
<p>He also predicted that malware could start arising with any type of &#8216;app stores.&#8217;</p>
<p>The silver lining is that Faceobok applications are much harder to write and distribute than e-mails are, so it won&#8217;t be as big of a problem, Sima explained. Vigilance is the best course of action, he added. &#8220;Ultimately I don&#8217;t think there is much that Facebook can do about it besides act quickly to remove rogue apps when they are reported.&#8221;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technologizer.wordpress.com/8573/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technologizer.wordpress.com/8573/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technologizer.wordpress.com/8573/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technologizer.wordpress.com/8573/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technologizer.wordpress.com/8573/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technologizer.wordpress.com/8573/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technologizer.wordpress.com/8573/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technologizer.wordpress.com/8573/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technologizer.wordpress.com/8573/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technologizer.wordpress.com/8573/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technologizer.wordpress.com/8573/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technologizer.wordpress.com/8573/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technologizer.wordpress.com/8573/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technologizer.wordpress.com/8573/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=8573&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://technologizer.com/2009/02/27/malware-is-messing-with-facebook-users/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/262868df0e44c7410b5099d919991983?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">David Worthington</media:title>
		</media:content>
	</item>
		<item>
		<title>Parking Ticket Scam Leads to Malware</title>
		<link>http://technologizer.com/2009/02/05/parking-ticket-scam-leads-to-malware/</link>
		<comments>http://technologizer.com/2009/02/05/parking-ticket-scam-leads-to-malware/#comments</comments>
		<pubDate>Thu, 05 Feb 2009 16:08:29 +0000</pubDate>
		<dc:creator>Ed Oswald</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://technologizer.com/?p=7700</guid>
		<description><![CDATA[Give these hackers some credit: this malware scam takes an offline world incovenience &#8212; the parking ticket &#8212; and turns it into a way to dupe users into installing malware on their computers. These fake parking tickets have begun appearing on cars around Grand Forks, North Dakota, which directed users to a website. The yellow [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=7700&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Give these hackers some credit: this malware scam takes an offline world incovenience &#8212; the parking ticket &#8212; and turns it into a way to dupe users into installing malware on their computers.</p>
<p>These fake parking tickets have begun appearing on cars around Grand Forks, North Dakota, which directed users to a website.</p>
<p>The yellow flier reads:</p>
<blockquote><p>PARKING VIOLATION This vehicle is in violation of standard parking regulations. To view pictures with information about your parking preferences, go to [website redacted]</p></blockquote>
<p>Once on the website, pictures of cars in the area are shown, with the license plate information removed of course (oh, what nice hackers, eh?). In order to &#8220;find&#8221; your vehicle, the site asks the user to download a toolbar.</p>
<p>A trojan horse is installed by the toolbar, which directs information to childhe.com. That domain has already been fingered as malicious by several antivirus companies, including <a href="https://safeweb.norton.com/report/show?name=childhe.com">Symantec</a>.</p>
<p>From here the user would get several fake infection warnings, which then would prompt for the install of even more malware. You got to give these folks credit: this is probably the most ingenious scam I&#8217;ve seen yet when it comes to virus and malware trickery.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technologizer.wordpress.com/7700/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technologizer.wordpress.com/7700/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technologizer.wordpress.com/7700/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technologizer.wordpress.com/7700/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technologizer.wordpress.com/7700/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technologizer.wordpress.com/7700/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technologizer.wordpress.com/7700/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technologizer.wordpress.com/7700/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technologizer.wordpress.com/7700/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technologizer.wordpress.com/7700/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technologizer.wordpress.com/7700/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technologizer.wordpress.com/7700/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technologizer.wordpress.com/7700/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technologizer.wordpress.com/7700/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=7700&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://technologizer.com/2009/02/05/parking-ticket-scam-leads-to-malware/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3fae6987702d8d79d8609b011e09a637?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">Ed Oswald</media:title>
		</media:content>
	</item>
		<item>
		<title>Fox News: Pentagon Target of Cyber Attack</title>
		<link>http://technologizer.com/2008/11/21/fox-news-pentagon-target-of-cyber-attack/</link>
		<comments>http://technologizer.com/2008/11/21/fox-news-pentagon-target-of-cyber-attack/#comments</comments>
		<pubDate>Fri, 21 Nov 2008 21:22:40 +0000</pubDate>
		<dc:creator>Ed Oswald</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://technologizer.wordpress.com/?p=4193</guid>
		<description><![CDATA[Fox News is reporting that the Pentagon was the target of a cyber attack so severe that it has now banned the use of all external memory devices, such as flash drives and the like. Apparently, some type of worm or virus has been unleashed on the agency&#8217;s computer network, and is quickly spreading throughout [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=4193&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Fox News <a href="http://www.foxnews.com/politics/2008/11/20/pentagon-cyber-siege-unprecedented-attack/">is reporting</a> that the Pentagon was the target of a cyber attack so severe that it has now banned the use of all external memory devices, such as flash drives and the like. Apparently, some type of worm or virus has been unleashed on the agency&#8217;s computer network, and is quickly spreading throughout the system.</p>
<p>Officials are not specifing what type of worm or virus it may be, only saying an alert had been posted for it, and that it was &#8220;taking steps to mitigate the virus.&#8221; The computers affected are part of the Global Information Grid, or GIG, and for security reasons the Pentagon does not speak on the specifics of intrusions to that system.</p>
<p>A guess as to what the malware may be could be gleaned from a post to the Symantec Security Response blog <a href="https://forums.symantec.com/syment/blog/article?blog.id=malicious_code&amp;thread.id=220">from Wednesday</a>. It warns of an increase in USB-based malware attacks, and listed several different viruses and worms known to be using removable drives as a way to propogate themselves.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technologizer.wordpress.com/4193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technologizer.wordpress.com/4193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technologizer.wordpress.com/4193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technologizer.wordpress.com/4193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technologizer.wordpress.com/4193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technologizer.wordpress.com/4193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technologizer.wordpress.com/4193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technologizer.wordpress.com/4193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technologizer.wordpress.com/4193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technologizer.wordpress.com/4193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technologizer.wordpress.com/4193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technologizer.wordpress.com/4193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technologizer.wordpress.com/4193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technologizer.wordpress.com/4193/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=4193&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://technologizer.com/2008/11/21/fox-news-pentagon-target-of-cyber-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3fae6987702d8d79d8609b011e09a637?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">Ed Oswald</media:title>
		</media:content>
	</item>
		<item>
		<title>Die, Scareware, Die! Microsoft Takes on Windows Scammers</title>
		<link>http://technologizer.com/2008/09/30/die-scareware-die-microsoft-takes-on-windows-scammers/</link>
		<comments>http://technologizer.com/2008/09/30/die-scareware-die-microsoft-takes-on-windows-scammers/#comments</comments>
		<pubDate>Tue, 30 Sep 2008 08:59:26 +0000</pubDate>
		<dc:creator>Harry McCracken</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://technologizer.wordpress.com/?p=2491</guid>
		<description><![CDATA[Maybe I&#8217;ve been living under a rock or something, but I never heard the term scareware until today. But without knowing the name, I&#8217;ve sure seen a lot of the stuff over the years&#8211;utilities that use questionable tactics such as fake error messages to lead you think you&#8217;ve got a computer problem in order to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=2491&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-2492" title="registrycleanerxp" src="http://technologizer.files.wordpress.com/2008/09/registrycleanerxp.jpg" alt="" width="164" height="164" />Maybe I&#8217;ve been living under a rock or something, but I never heard the term <em>scareware</em> until today. But without knowing the name, I&#8217;ve sure seen a lot of the stuff over the years&#8211;utilities that use questionable tactics such as fake error messages to lead you think you&#8217;ve got a computer problem in order to lure you into buying them. Then they do little or nothing that makes your PC any better&#8211;assuming that they don&#8217;t do anything that actively screws it up, intentionally or unintentionally.</p>
<p>Such products are a scourge for Windows users&#8211;I&#8217;m not sure, incidentally, whether there&#8217;s such a thing as Mac scareware&#8211;and they must be a headache for Microsoft, too, since they&#8217;re one of the barnacles that degrades the experience of using Windows.</p>
<p><span id="more-2491"></span></p>
<p>So I can understand why Microsoft is <a href="http://voices.washingtonpost.com/securityfix/2008/09/microsoft_washington_state_tar.html?nav=rss_blog">partnering with the Washington State Attorney General&#8217;s Office to take on scareware developers</a>. The Washington AG is suing a company called Branch Software and its owner, James Read McCreary, over an omnipresent piece of scareware called <a href="http://registrycleanerxp.com/">Registry Cleaner XP</a>;  Paula Selis of the AG&#8217;s office told the Washington Post that Registry Cleaner XP claims it&#8217;s found the same 43 errors on every PC it scans, then says it&#8217;s fixed them all. Microsoft has also filed suits to determine who&#8217;s behind such pieces of scareware as Antivirus 2009, Malwarecore, WinDefender, WinSpywareProtect, and XPDefender.</p>
<p>Sunbelt Software&#8217;s Alex Eckelberry <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=government&amp;articleId=9115720&amp;taxonomyId=13&amp;intsrc=kc_top">told the IDG News Service&#8217;s Bob McMillan that the single most prevalent piece of scareware today is one called Antivirus XP 2008</a>. I shuddered a bit when I saw that name, since the app had recently wormed its way onto a friend&#8217;s PC&#8211;how, I&#8217;m not sure. Its fusillade of &#8220;virus warnings&#8221; and atempts to sell a paid version rendered the machine unusable; it was the most unpleasant malware attack I&#8217;ve personally witnessed in a long time, and it happened despite the fact that she was running real anti-virus software and a firewall.</p>
<p>I&#8217;m not an expert on the applicable laws here, but I do know that some scareware vendors are essentially digital grifters. Bravo to Microsoft for taking &#8216;em on; I hope the legal repercussions are severe enough to give other con men pause before they try scams of this sort.</p>
<p>Meanwhile, a few quick tips for avoiding scareware:</p>
<p style="padding-left:30px;">&#8211;<strong>Be skeptical of odd error messages that seemingly spring from nowhere. </strong>Especially if they recommnend you download and run software to fix &#8220;problems.&#8221;</p>
<p style="padding-left:30px;">&#8211;<strong>Be very cautious about downloads from sites you&#8217;ve never heard of. </strong>If a utility isn&#8217;t available at large and reputable sites such as <a href="http://registrycleanerxp.com/">Download.com</a>, it&#8217;s not a great sign.</p>
<p style="padding-left:30px;">&#8211;<strong>Use Google to do a quick check. </strong>Search for a utility&#8217;s name before you install it; if the results involve horror stories and instructions for removing it, don&#8217;t go anywhere near it.</p>
<p style="padding-left:30px;">-<strong>-If a utility claims to have received glowing reviews from testers such as PC World, verify &#8216;em.</strong> Go to the sites in question and search for reviews; it&#8217;s not unusual for scareware sites to simply fabricate favorable reviews and other honors.</p>
<p style="padding-left:30px;">&#8211;<strong>If a utility site is oddly out of date, be wary. </strong>The Registry Cleaner XP site, for example, makes no mention of Windows Vista and features testimonials that end in 2006.</p>
<p style="padding-left:30px;">&#8211;<strong>If you just plain feel uneasy about a utility, run. </strong>Scareware apps and the ads used to promote them are often aggresively cheesy. If it doesn&#8217;t feel good, don&#8217;t do it.</p>
<p style="padding-left:30px;">
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/technologizer.wordpress.com/2491/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/technologizer.wordpress.com/2491/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/technologizer.wordpress.com/2491/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/technologizer.wordpress.com/2491/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/technologizer.wordpress.com/2491/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/technologizer.wordpress.com/2491/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/technologizer.wordpress.com/2491/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/technologizer.wordpress.com/2491/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/technologizer.wordpress.com/2491/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/technologizer.wordpress.com/2491/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/technologizer.wordpress.com/2491/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/technologizer.wordpress.com/2491/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/technologizer.wordpress.com/2491/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/technologizer.wordpress.com/2491/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=technologizer.com&amp;blog=3849727&amp;post=2491&amp;subd=technologizer&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://technologizer.com/2008/09/30/die-scareware-die-microsoft-takes-on-windows-scammers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a7899e8595e484602ab4c4ff2062de99?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif" medium="image">
			<media:title type="html">Harry McCracken</media:title>
		</media:content>

		<media:content url="http://technologizer.files.wordpress.com/2008/09/registrycleanerxp.jpg" medium="image">
			<media:title type="html">registrycleanerxp</media:title>
		</media:content>
	</item>
	</channel>
</rss>
