Archive for August, 2007
DMZ meets Dubwar Documentary
Check this wicked video out I found on the one and only Drumz Of The South:
No commentsZeitGeist - The Movie
Thank you for your interest in Zeitgeist.
Zeitgeist was created as a not for profit expression to inspire people to start looking at the world from a more critical perspective and to understand that very often things are not what the population at large think they are.
The information in Zeitgeist was established over a year long period of research and the current Source page on this site lists the sources used / referenced.
http://zeitgeistmovie.com/
Please be aware that I posted this here for Information purposes only!
via (ZeitGeist)
No commentsRussian malware storm brewing?
![]()
Security researchers at Trend Micro Inc. have spotted a Russian server loaded with more than 400 different pieces of malware that may be poised to launch a large-scale attack through malicious Web sites hosted in Italy.
Chenghuai Lu, a senior threat analyst at the Tokyo-based antivirus vendor, recently uncovered a site with several hundred malicious programs and traced the site’s server to a Russian IP address. Among the harbored malware were examples of three Trojan families: Dropper.cko, Clicker.qu and Polycrypt.g. All three clans typically hijack Internet Explorer on compromised PCs and direct users to adult Web sites.
Meanwhile, another Trend Micro researcher, senior software engineer Feike Hacquebord, discovered a large number of Italian-language Web sites that at first glance appeared to be compromised with malicious IFRAMEs, inserts in the HTML coding of a page, often JavaScript, that can hijack a PC whose browser visits the site. On second look, however, the Italian-style sites do not appear to have been hacked but instead were created with the IFRAMEs in mind. According to Trend Micro, the IFRAMES point to the malware-packed Russian site found by Lu.
“Looking at these massive samples of malware, we can’t help to think that there’s something brewing in Russia,” said Carolyn Guevarra, a third researcher at Trend Micro, on the team’s blog yesterday. “We have just seen these cybercriminals pull the ‘Italian Job’ recently,” she added. “Are we now seeing a ‘Russian Uprising’ coming our way?”
Guevarra’s Italian comment refers to a large-scale attack about six weeks ago that involved more than 10,000 hacked sites hosted in that country. Those attacks were guided by Mpack, a multistrike exploit tool kit that hackers had deployed on one or more servers; the compromised sites secretly directed users to an Mpack-equipped server, which then tried a number of exploits on the PC.
Trend Micro has blocked the malicious Web sites for its customers and is working to develop more information on the possible attack plot. “More details soon,” Guevarra promised.
Via Computerworld
No commentsTrend Micro IDs Top Security Threats in 2007
![]()
Trend Micro Incorporated, a leader in network antivirus and Internet content security software and services, today published the TrendLabsSM Semi-annual Threat Roundup and Forecast. Analyzing malware trends that influence the economic growth of the malware world, the report demonstrates how malware attacks have changed in their style, motivation and target.
The era of the global malware outbreak is over. Today’s malware threats attempt to remain undetected and now often go after users in a specific region, country or group. These new attacks are of blended and sequential nature. They use combinations of malware, each of which plays a role in the delivery of the payload. Using the Web for delivery, update and entrenchments, such insidious attacks report back stolen information to the perpetrator, with the end goal of making money.
In the first six months of 2007, TrendLabs tracked several examples of just how the threat landscape has evolved, including “Storm” at the beginning of the year and the “Italian Job” most recently in June.
Via Topix
No commentsDrug detection machine launched across MK
![]()
Milton Keynes police and partners have launched a new machine into the cities’ licensed premises. The machine will be used to detect people contaminated with drugs, to stamp out illegal drugs and make a night out in Milton Keynes safer.
The Itemiser is a trace element machine which detects all prohibited drugs and also the levels of contamination. Clubbers’ hands and personal items such as mobile phones, purses and wallets are swabbed before the Itemiser gives a reading of what drugs they had come into contact with, if any.
The machine was trailed earlier this year in the city and it proved to be very successful. Funding was secured from the partners including:
Community Safety Partnership
Barwatch
Milton Keynes Council
Thames Valley Police
Partnership protocols have been set up with all partners and the Itemiser will be used across the city in all licensed premises. In agreement with the licenses, entry into their premises will only be allowed if people give permission to be tested by the machine.
The machine will be in operation in the immediate future with a zero tolerance attitude to anyone who is found to be contaminated with prohibited drugs. Anyone found to be contaminated will be searched and appropriate action will be taken. Anyone contaminated, but found with no drugs, will be refused entry to the premises; if however they are found in possession they will be arrested.
Lin Poizat, Police Area Licensing officer, said: “The Itemiser is a major advance in technology which we can employ in the fight against illegal drug use.
“It will allow police and partners, in association with barwatch and licensees, to take a robust and zero tolerance regime to anyone contaminated by prohibited drugs.
“The Itemiser will be part of the ongoing Safer Streets campaign and will be used for the foreseeable future, making Milton Keynes a safer place to enjoy a night out.”
via MKDNB
4 commentsTrend Micro announces SecureCloud
![]()
Trend Micro announces SecureCloud
![]()
Expanding on its consumer-software-as-a-service efforts, Trend Micro announced on Sunday SecureCloud for small and midsize businesses and the enterprise market. The idea is to provide clients with a range of services without requiring them to install software.
Services available include e-mail reputation, e-mail hosting, and botnet ID service. The latter will allow ISPs to filter command and control messages sent by customer’s compromised machines. One feature on the site is an IP reputation search; type in an IP address and Trend Micro will tell you whether the address can be trusted.
At present only two servers in the U.S.–east and west–are up and running. Plans include additional servers in Europe/Middle East/Africa region in the third quarter, Taiwan in the fourth quarter, and Japan in first quarter of 2008.
via News.com
No commentsWORM_SDBOT Variant Spreading via MSN Messenger
Another great find by the Trend Micro Team!
![]()
3 commentsA new variant of WORM_SDBOT has just turned up. This variant, detected by Trend as WORM_SDBOT.EXT, has been observed to spread copies of itself via MSN’s instant messaging application.
As with any IM-borne malware, the worm sends an interesting message to an unsuspecting recipient to trick him/her into downloading it into the system. A copy of the worm is sent directly with the message itself, as a zip file. This technique is quite different from other worms like WORM_SOHANAD, which include a URL link in the message from where the actual malware can be downloaded.
Once it has been successfully downloaded and executed, the worm is known to compromise security. Acting much like a backdoor, it connects to the IRC server vpn.basecore.info and joins the IRC channel VPN. Remote malicious users with access to WORM_SDBOT.EXT can issue various commands that would allow them to download files, terminate processes running on the system and create/open/execute/delete files.
Credits go to Jonell Baltazar of TMIRT for analysis and to Lalaine Gregorio of Content Security for the screenshot.
New Ichitaro zero-day exploit discovered
![]()
Yet another interesting exploit discovered by Trend Labs….
No commentsTrendLabs has received several reports a malicious Ichitaro document taking advantage of an as-yet undetermined vulnerability to drop a Trojan on target machines. Ichitaro is a popular Japanese word processing application.
The said exploit, which Trend Micro will detect as TROJ_TARODROP.Q, drops a Trojan to be detected as TROJ_SMALL.GQM. Based on initial analysis, TROJ_SMALL.GQM has the capability to drop other files onto the system, thus exposing the compromised machine to other attacks. More details about these malware will be posted shortly in the Trend Micro Virus Encyclopedia.
Note that this is not the first time a Japanese application was exploited by malware authors to perform their malicious deeds. Around the same time last year, the first Ichitaro exploit — TROJ_MDROPPER.BL — was detected (several variants has since followed). More recently, a vulnerability in the Japanese archiving application Lhaca was exploited by TROJ_LHDROPPER.A to drop a backdoor program.
Video: Kanye West and Daft Punk - Stronger
Gotta love the fusion between these two groups of artists!
No commentsBTK - Not In the Mood Paranoia Mix 008
![]()
BTK Paranoia Mix
Download the mix here:
Tracklisting:
01. Commix - Be True (Metalheadz)
02. Deep Inc - Seven Stars (Innerground)
03. CLS & Wax - Primal Rage (Spin Recordings dub)
04. Icicle & Nymfo - Hand Rolled Cigarettes (Renegade Recs dub)
05. BTK - My Soul For Your Love (dub)
06. Bungle feat. Total Science & Ayah - Snake Eyes (CIA)
07. Loxy & Munk - Devils Advocate VIP (RH dub)
08. Alpha Omega - Klash (Gremlinz Vip) (TOV dub)
09. Nitrox & Kay - CongoMan (Diablo Recs dub)
10. C.A.B.L.E. - New Infectionn (Innerground dub)
11. Identity - Malice (dub)
12. Infiltrata - Psalm (Hospital dub)
13. Identity & Atom - Reflection (Salvage dub)
14. VC & Nocturnal - Welcome to ShankTown VIP (RH dub)
15. Fission - Futuro (dub)
16. Pylon & Soccom - Katalyst (dub)
17. Cooh - Noisy Sneaker (Sinuous dub)
18. Temper D - Peace and Quiet (dub)
19. Christian FIsher & Murphy - Miss You (BTK & Define Remix) (dub)
20. Vengeanze - Lo Parto To (Y No Pago) (Future Sickness dub)
21. Raiden - Alterego (Identity Remix) (N/A)
22. Infiltrata, Identity & Breaker - Make Life Illa (OhmResistance dub)
23. Gremlinz - Annexed VIP (Renegade Hardware dub)
24. C.A.B.L.E. - Strangeland (CIA Deep Kut dub)
25. Absolute Zero & Subphonics - The Code (Gremlinz & Castor Rmx) (RH dub)
26. Skitty - Victim (dub)
27. EBK - Skatter (Renegade Hardware dub)
28. Identity - Sharp (dub)
29. Snake & Wolfelord Himself - Monday to Friday (dub)
30. Gremlinz, Manifest & Verb - Dem (13Music dub)