November 6th, 2009 :: Rick Wilhelm
Adobe recently posted a notice of a security update available for its Shockwave. These are for vulnerabilities discovered in the 11.5.1.601 (and older) version of the software. If this sounds familiar, it might be because a previous post in this blog described vulnerabilities in the 11.5.0.596 (and older) version of Shockwave.
You can find out what [...]
Continue Reading
October 15th, 2009 :: Rick Wilhelm
There are enough software patches being released these days that users can easily become numb to the noise. But if you review the list of vulnerabilities addressed by the latest patches released by Microsoft and Adobe on October 12, you’ll wake up quickly.
The Microsoft list is compelling, including a “critical” fix for all supported releases [...]
Continue Reading
August 6th, 2009 :: Rick Wilhelm
After being identified by security researchers as having links to a phishing botnet, the ISP Real Host had its servers (located in Latvia) cut off from the Internet by Swedish telecom operator TeliaSonera.
This is another in a series of efforts by the Internet research community to fight botnets and online malware by denying access to [...]
Continue Reading
July 25th, 2009 :: Rick Wilhelm
On Friday we alerted approximately 4,343 of our more than 10,000 E-Commerce merchants that their customers’ information may have been affected by a data security issue. The issue has been fixed and more details are available at http://www.careandprotect.com
At this point, we have no reports or other reasons to believe that any credit card account information [...]
Continue Reading
July 2nd, 2009 :: Rick Wilhelm
From Google’s perch in the Internet infrastructure, it sees a lot of spam, which makes its Q2 2009 spam report stand out as interesting reading.
The volume of spam detected continues to be erratic, as shown in this picture from Google:
The large dip around the beginning of June is most likely due to the FTC’s takedown [...]
Continue Reading
June 25th, 2009 :: Rick Wilhelm
Adobe has announced the availability of a security update for the Shockwave player for Windows. It is designed to patch a reported vulnerability in Shockwave 11.5.0.596 and earlier versions.
The announcement doesn’t say so, to see if you have Shockwave or to find out what version of Shockwave is installed, visit: http://www.adobe.com/shockwave/welcome/
The details of the announcement [...]
Continue Reading
June 19th, 2009 :: Rick Wilhelm
URL obfuscation is the term used to describe a technique for disguising a URL to make it look like one a user trusts. It’s frequently used as part of a phishing email to thwart a user’s ability to detect a URL that is going to a “bad” site (one that distributes malware or engages in [...]
Continue Reading
June 17th, 2009 :: Rick Wilhelm
The net has been abuzz with discussion about the “peoples war” on the Internet that is seeking to disrupt various Iranian government web sites and help opposition activists with their news dissemination. These involve both attempting to overload web sites with DDOS traffic and setting up anonymous proxies that allow previously blocked users to reach [...]
Continue Reading
June 16th, 2009 :: Rick Wilhelm
On the evening of June 14th, as news of the Iran election results spread, a movement on Twitter emerged to recruit ordinary users to DDOS the websites of Iran’s state-run media. (Simply put, users were to visit the targeted web sites repeatedly in an attempt to consume all server resources.) This was applying the logic [...]
Continue Reading
June 11th, 2009 :: Rick Wilhelm
In a recently released study, the Ponemon Institute reports a dismal view of data security compliance policy. As summarized in a press release and a blog posting, the study reports that lack of compliance with security policies is very widespread. For example:
Over 47% of respondents report sharing passwords
60% report sending file attachments from a [...]
Continue Reading
Recent Comments