<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/atom10full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:gd="http://schemas.google.com/g/2005" gd:etag="W/&quot;DU4ER306fyp7ImA9WxdWFkQ.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661</id><updated>2008-07-10T06:51:46.317-07:00</updated><title>iAntiVirus Blog</title><subtitle type="html">Blog discussing the latest discoveries and research involving viruses, spyware and malware on Mac OS X systems.</subtitle><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/" /><link rel="next" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default?start-index=26&amp;max-results=25" /><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default" /><author><name>PC Tools</name><uri>http://www.blogger.com/profile/10564926695081949965</uri><email>noreply@blogger.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>45</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><link rel="self" href="http://feeds.feedburner.com/iantivirus" type="application/atom+xml" /><feedburner:emailServiceId xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">1572359</feedburner:emailServiceId><feedburner:feedburnerHostname xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">http://www.feedburner.com</feedburner:feedburnerHostname><entry gd:etag="W/&quot;DU4ER3o4eCp7ImA9WxdWFkQ.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-1507983389152222216</id><published>2008-07-10T06:44:00.000-07:00</published><updated>2008-07-10T06:51:46.430-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-07-10T06:51:46.430-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="database update" /><category scheme="http://www.blogger.com/atom/ns#" term="smart update" /><category scheme="http://www.blogger.com/atom/ns#" term="iAntiVirus" /><title>New update</title><content type="html">&lt;p&gt;Hi everyone, there is a new database available so please run Smart Update if you haven't already.&lt;/p&gt;&lt;p&gt;This update includes two new detections (Trojan-PSW.OSX.Corpref.A and Exploit.OSX.ARDAgent) plus a variant of an existing threat.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/07/new-update.html" title="New update" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/1507983389152222216/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/1507983389152222216" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/1507983389152222216?v=2" /><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;C04DQ3s9fCp7ImA9WxdXGUs.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-6228229594103580173</id><published>2008-07-01T18:22:00.001-07:00</published><updated>2008-07-01T18:26:12.564-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-07-01T18:26:12.564-07:00</app:edited><title>Thanks for the feedback</title><content type="html">Hi everyone, just a quick note to thank you for the feedback you've been giving on the &lt;a href="http://www.pctools.com/forum/forumdisplay.php?f=66"&gt;iAntiVirus forum&lt;/a&gt;!&lt;br /&gt;&lt;br /&gt;Your comments are appreciated and we've taken some of your suggestions on board for the next build of iAntiVirus beta.&lt;br /&gt;&lt;br /&gt;Stay tuned and keep the comments coming, updates will be announced here soon.</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/07/thanks-for-feedback.html" title="Thanks for the feedback" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/6228229594103580173/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/6228229594103580173" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/6228229594103580173?v=2" /><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;C0EMQ3Y-fSp7ImA9WxdXGUs.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-2332919276510619789</id><published>2008-06-30T18:59:00.000-07:00</published><updated>2008-07-01T18:21:22.855-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-07-01T18:21:22.855-07:00</app:edited><title>iAntiVirus in the press</title><content type="html">Hi everyone, iAntiVirus has been picked up by various news sources :)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.macworld.com/article/134219/2008/06/iantivirus.html"&gt;Macworld&lt;/a&gt;, &lt;a href="http://www.technewsworld.com/story/security/63614.html"&gt;TechNewsWorld&lt;/a&gt;, &lt;a href="http://www.bmighty.com/blog/antenna/archives/2008/06/pc_tools_launch.html?cid=antenna"&gt;bMighty.com&lt;/a&gt;, &lt;a href="http://www.networkworld.com/news/2008/063008-iantivirus-launches-for.html"&gt;NetworkWorld.com&lt;/a&gt;, &lt;a href="http://www.betanews.com/article/PC_Tools_launches_beta_of_iAntivirus_for_Leopard/1214943099"&gt;BetaNews&lt;/a&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/06/iantivirus-in-press.html" title="iAntiVirus in the press" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/2332919276510619789/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/2332919276510619789" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/2332919276510619789?v=2" /><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;Dk8BQ345cCp7ImA9WxdXFU4.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-4945232668448367393</id><published>2008-06-26T19:37:00.000-07:00</published><updated>2008-06-26T19:47:32.028-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-06-26T19:47:32.028-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="antivirus beta release" /><category scheme="http://www.blogger.com/atom/ns#" term="iAntiVirus" /><title>iAntiVirus public beta 2</title><content type="html">Hi everyone, we've recently released iAntiVirus beta 2!&lt;br /&gt;&lt;br /&gt;Changes in this version:&lt;br /&gt;1. Addresses a scan issue reported by 2 of our external beta testers.&lt;br /&gt;2. Installer includes the latest virus definitions&lt;br /&gt;&lt;br /&gt;You can update by downloading and installing the package from &lt;a href="http://www.iantivirus.com/"&gt;www.iantivirus.com&lt;/a&gt;, or by simply running Smart Update if you are already an iAntiVirus user:&lt;br /&gt;&lt;br /&gt;1. Click the Smart Update icon on the top right of the iAntiVirus main window.&lt;br /&gt;2. Click "Upgrade now" at the upgrade available prompt:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_7dsFHfVnnA8/SGRTt8m0WkI/AAAAAAAAAAY/W1CkexmqCXE/s1600-h/SU+1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_7dsFHfVnnA8/SGRTt8m0WkI/AAAAAAAAAAY/W1CkexmqCXE/s320/SU+1.jpg" alt="" id="BLOGGER_PHOTO_ID_5216386317230037570" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;3. Wait for the upgrade to be downloaded:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_7dsFHfVnnA8/SGRT45Vq_gI/AAAAAAAAAAg/0_T3I9Ih3UE/s1600-h/SU+2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_7dsFHfVnnA8/SGRT45Vq_gI/AAAAAAAAAAg/0_T3I9Ih3UE/s320/SU+2.jpg" alt="" id="BLOGGER_PHOTO_ID_5216386505331375618" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;4. Enter your password when prompted:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_7dsFHfVnnA8/SGRUKNcA0WI/AAAAAAAAAAo/a9uiqwL9Jbs/s1600-h/SU+3.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_7dsFHfVnnA8/SGRUKNcA0WI/AAAAAAAAAAo/a9uiqwL9Jbs/s320/SU+3.jpg" alt="" id="BLOGGER_PHOTO_ID_5216386802784457058" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;5. iAntiVirus will restart and you will be running the latest version currently available :)</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/06/iantivirus-public-beta-2.html" title="iAntiVirus public beta 2" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/4945232668448367393/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/4945232668448367393" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/4945232668448367393?v=2" /><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;D0MGRHkzcCp7ImA9WxdXE0s.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-3202967844774769328</id><published>2008-06-24T20:35:00.000-07:00</published><updated>2008-06-24T20:43:45.788-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-06-24T20:43:45.788-07:00</app:edited><title>Requesting comments</title><content type="html">&lt;p&gt;The iAntiVirus beta was released recently and we are looking forward to everyone's comments!&lt;/p&gt;&lt;p&gt;Please leave any feedback you may have on the &lt;a href="http://www.pctools.com/forum/forumdisplay.php?f=66"&gt;forum&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;If you haven't already done so, download iAntiVirus v1.0b from &lt;a href="http://iantivirus.com/download/"&gt;the iAntiVirus website.&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Tell us what you like, dislike and also what you would like to see in future versions!&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Thanks &lt;/p&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/06/requesting-comments.html" title="Requesting comments" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/3202967844774769328/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/3202967844774769328" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/3202967844774769328?v=2" /><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;A0EARXY5cCp7ImA9WxdXEkU.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-3332250341083940942</id><published>2008-06-23T23:32:00.000-07:00</published><updated>2008-06-23T23:40:44.828-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-06-23T23:40:44.828-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="iAntiVirus" /><title>iAntiVirus update</title><content type="html">Hi everyone,&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The iAntiVirus database has been updated to include a trojan which has been seen in the wild exploiting the Apple Remote Desktop vulnerability.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Please be sure to run Smart Update and get the latest protection!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/06/iantivirus-update.html" title="iAntiVirus update" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/3332250341083940942/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/3332250341083940942" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/3332250341083940942?v=2" /><author><name>NSArchitect</name><uri>http://www.blogger.com/profile/10052529130215654134</uri><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;D0QNRns4eip7ImA9WxdQFkU.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-3352780270822526442</id><published>2008-06-16T21:00:00.000-07:00</published><updated>2008-06-16T23:49:57.532-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-06-16T23:49:57.532-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="installing antivirus tools" /><category scheme="http://www.blogger.com/atom/ns#" term="OS X advance user guide" /><category scheme="http://www.blogger.com/atom/ns#" term="Leopard security configuration" /><category scheme="http://www.blogger.com/atom/ns#" term="Security Mac OS X" /><category scheme="http://www.blogger.com/atom/ns#" term="Hardening OS X" /><title>Apple Guide In Securing Mac OS X</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/SFdedxAycaI/AAAAAAAAAfE/f_geA2mgJA4/s1600-h/Mac+OS+X+Security.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/SFdedxAycaI/AAAAAAAAAfE/f_geA2mgJA4/s400/Mac+OS+X+Security.png" alt="" id="BLOGGER_PHOTO_ID_5212738959170498978" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: left;"&gt;Apple has released a comprehensive security configuration guide for users of Mac OS X v10.5 and later. [Download &lt;a href="http://images.apple.com/server/macosx/docs/Leopard_Security_Config_20080530.pdf"&gt;here&lt;/a&gt;]&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;The document is in PDF format and it contains more than 200 pages of detailed instructions and recommendations for Mac OS X "advance" users.&lt;br /&gt;&lt;br /&gt;While most Mac users are complacent in securing their computer against online or digital threats, this intensive document under Advance Security Management advises Mac OS X users to install Antivirus Tools and Intrusion Detection Systems.&lt;br /&gt;&lt;br /&gt;Definitely, Apple acknowledges the importance of hardening computers and in today's prevalent threats such as Zlob's DNSChanger for Mac, it is no doubt that these internet security tools will certainly help users in keeping their computer safe.&lt;br /&gt;&lt;br /&gt;This is &lt;span style="font-style: italic;"&gt;Methusela Cebrian Ferrer &lt;/span&gt;and I'm now signing off.&lt;br /&gt;&lt;br /&gt;Stay Safe Online!&lt;br /&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/06/apple-guide-in-securing-mac-os-x.html" title="Apple Guide In Securing Mac OS X" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/3352780270822526442/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/3352780270822526442" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/3352780270822526442?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;CkMGSH87eip7ImA9WxdRE0o.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-4649221476495546730</id><published>2008-06-01T17:32:00.000-07:00</published><updated>2008-06-01T18:33:49.102-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-06-01T18:33:49.102-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Security Update 2008-003" /><category scheme="http://www.blogger.com/atom/ns#" term="OS X security update" /><category scheme="http://www.blogger.com/atom/ns#" term="Mac OS X 10.5.3" /><title>Critical: Mac OS X 10.5.3 and Security Update 2008-003</title><content type="html">&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_5MH3NxS8hN8/SENE6o8cB-I/AAAAAAAAAe0/9ByHl6yJ084/s1600-h/apple_update.PNG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_5MH3NxS8hN8/SENE6o8cB-I/AAAAAAAAAe0/9ByHl6yJ084/s400/apple_update.PNG" alt="" id="BLOGGER_PHOTO_ID_5207081368384440290" border="0" /&gt;&lt;/a&gt;Apple released its third security update for this year where it fixes 40 security vulnerabilities found in different components of Mac OS X operating system.&lt;br /&gt;&lt;br /&gt;It was just two months ago when Apple released its gigantic update fixing over 90 vulnerabilities. That security fixes is still unbeatable compare to this month update.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://support.apple.com/kb/HT1897"&gt;Security Update 2008-03&lt;/a&gt; addresses 16 critical vulnerabilities which may lead to arbitrary code execution.&lt;br /&gt;&lt;br /&gt;This latest update affects the following:&lt;br /&gt;&lt;div  style="font-family:georgia;"&gt;  &lt;ul&gt;&lt;li&gt;&lt;span class="225422301-02062008"&gt;&lt;strong&gt;AFP  Server&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="225422301-02062008"&gt;&lt;strong&gt;Apache&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="225422301-02062008"&gt;&lt;strong&gt;Apple Pixlet  Video&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="225422301-02062008"&gt;&lt;strong&gt;ATS&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="225422301-02062008"&gt;&lt;strong&gt;CFNetwork&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="225422301-02062008"&gt;&lt;strong&gt;CoreFoundation&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="225422301-02062008"&gt;&lt;strong&gt;CoreGraphics&lt;/strong&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;CoreTypes&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;CUPS&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Flash Player Plug-in&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Help Viewer&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;iCal&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;International Components for  Unicode&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Image Capture&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Image Capture&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;ImageIO&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Kernel&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;LoginWindow&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Mail&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;ruby&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Single Sign-On&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Wiki Server&lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt; &lt;strong style="font-family: lucida grande;"&gt;&lt;/strong&gt; &lt;div&gt;Mac users can manually download the patch from &lt;a href="http://www.apple.com/support/downloads/"&gt;Apple Downloads&lt;/a&gt;.&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/06/critical-mac-os-x-1053-and-security.html" title="Critical: Mac OS X 10.5.3 and Security Update 2008-003" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/4649221476495546730/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/4649221476495546730" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/4649221476495546730?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;D0YBQHk4fSp7ImA9WxdSF0o.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-8498689197990931132</id><published>2008-05-25T20:11:00.000-07:00</published><updated>2008-05-25T21:12:31.735-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-05-25T21:12:31.735-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="os x scanner" /><category scheme="http://www.blogger.com/atom/ns#" term="antivirus beta release" /><category scheme="http://www.blogger.com/atom/ns#" term="Mac OS X application" /><title>iAntiVirus Beta Release Coming Soon</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_5MH3NxS8hN8/SDoxmY8cB9I/AAAAAAAAAes/ynoKyNvI3wA/s1600-h/iAntiVirus+Beta.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_5MH3NxS8hN8/SDoxmY8cB9I/AAAAAAAAAes/ynoKyNvI3wA/s400/iAntiVirus+Beta.png" alt="" id="BLOGGER_PHOTO_ID_5204526854980765650" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;PC Tools will soon release iAntiVirus Beta version. This scanner has a powerful features that catches and removes known malwares in real-time. It also detects new threats in Mac OS X including keyloggers and hacktools.&lt;br /&gt;&lt;br /&gt;With today's emerging threats, this product will definitely ensure your Mac remains safe and virus free.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/05/iantivirus-beta-release-coming-soon.html" title="iAntiVirus Beta Release Coming Soon" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/8498689197990931132/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/8498689197990931132" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/8498689197990931132?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;C0UGSH44fSp7ImA9WxdTFUo.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-6809098289982261700</id><published>2008-05-11T20:59:00.000-07:00</published><updated>2008-05-11T22:47:09.035-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-05-11T22:47:09.035-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="fraudsters" /><category scheme="http://www.blogger.com/atom/ns#" term="get-messenger" /><category scheme="http://www.blogger.com/atom/ns#" term="password stealer" /><category scheme="http://www.blogger.com/atom/ns#" term="email spam" /><category scheme="http://www.blogger.com/atom/ns#" term="msn worm" /><category scheme="http://www.blogger.com/atom/ns#" term="instant messaging spammer" /><category scheme="http://www.blogger.com/atom/ns#" term="scanmessenger" /><category scheme="http://www.blogger.com/atom/ns#" term="checkmessenger3" /><category scheme="http://www.blogger.com/atom/ns#" term="SPIM" /><category scheme="http://www.blogger.com/atom/ns#" term="msnblocklist" /><category scheme="http://www.blogger.com/atom/ns#" term="MSN scam" /><title>Identity Theft And Your MSN Account</title><content type="html">&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_5MH3NxS8hN8/SCfA3ONCxgI/AAAAAAAAAdk/mh4QIPDI9Fc/s1600-h/msn.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_5MH3NxS8hN8/SCfA3ONCxgI/AAAAAAAAAdk/mh4QIPDI9Fc/s400/msn.png" alt="" id="BLOGGER_PHOTO_ID_5199336349760669186" border="0" /&gt;&lt;/a&gt;There are more MSN fraudsters roaming around and this time they are serving twenty different languages.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;Last February, I posted this topic "&lt;a href="http://blog.iantivirus.com/2008/02/your-msn-account-has-been-0wn3d.html"&gt;Your MSN Account Has Been 0WN3D&lt;/a&gt;".&lt;br /&gt;&lt;br /&gt;These are phising sites that employs social engineering technique to lure MSN users in giving out their email address and password.&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;As an effect, the MSN stolen identity can remotely perform instant messaging and email spamming to all contacts as well as it can sneak your personal messages.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/SCfUKeNCxoI/AAAAAAAAAek/fvHkxPyRXzU/s1600-h/MSN_phishers.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/SCfUKeNCxoI/AAAAAAAAAek/fvHkxPyRXzU/s400/MSN_phishers.PNG" alt="" id="BLOGGER_PHOTO_ID_5199357571194078850" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;As of the moment, the following IP addresses and domain names are actively serving these MSN phising sites.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/SCfE7-NCxiI/AAAAAAAAAd0/9zBQjybQVAo/s1600-h/Domain_Names.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/SCfE7-NCxiI/AAAAAAAAAd0/9zBQjybQVAo/s400/Domain_Names.png" alt="" id="BLOGGER_PHOTO_ID_5199340829411558946" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://picasion.com/pic2/9303b291672ab2814358424c5108366c.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px;" src="http://picasion.com/pic2/9303b291672ab2814358424c5108366c.gif" alt="" border="0" /&gt;&lt;/a&gt;Be careful and stay away from these sites!&lt;br /&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/05/identity-theft-and-your-msn-account.html" title="Identity Theft And Your MSN Account" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/6809098289982261700/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/6809098289982261700" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/6809098289982261700?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;CEIEQnk5eSp7ImA9WxZaFk4.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-4592751702058805903</id><published>2008-04-30T22:17:00.000-07:00</published><updated>2008-05-01T02:01:43.721-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-05-01T02:01:43.721-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="tricks" /><category scheme="http://www.blogger.com/atom/ns#" term="facebook trojan" /><category scheme="http://www.blogger.com/atom/ns#" term="youtube look-a-like" /><category scheme="http://www.blogger.com/atom/ns#" term="MySpace spammers" /><category scheme="http://www.blogger.com/atom/ns#" term="macvideo" /><category scheme="http://www.blogger.com/atom/ns#" term="fake youtube" /><category scheme="http://www.blogger.com/atom/ns#" term="porn4mac" /><category scheme="http://www.blogger.com/atom/ns#" term="social networks" /><title>Fake YouTube Installs OS X TrojanDNSChanger</title><content type="html">&lt;div style="text-align: justify;"&gt;"&lt;span style="font-style: italic;"&gt;.. I clicked on a normal-looking link to a BlogSpot blog. Instead of taking me to the blog it took me to a website that looks 100% identical to a YouTube page. Where a video would normally start playing it instead said "Video ActiveX Error" and a DMG entitled "1234" that was approximately 750kb automatically downloaded to my computer."&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;Question: &lt;span style="font-style: italic;"&gt;How did you get that link ? &lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;Answer: I found it on the wall of a Facebook group.  &lt;span style="font-size:85%;"&gt;[Read MacRumors Forum]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;~~ooOOoo~~&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;a href="http://blog.iantivirus.com/2008/01/analysis-of-osx-trojan-dns-changer.html"&gt;TrojanDNSChanger&lt;/a&gt; for Mac is getting in the wild and it is desperately trying to get into users by using channels with wide or massive audience such as social networks.&lt;br /&gt;&lt;br /&gt;This incident has been around for a week where a malicious link will redirect users to a Fake YouTube website and without user intervention it automatically download a DMG file, which is the Trojan DNSChanger for Mac.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/SBmAuy9yjvI/AAAAAAAAAdM/Jl1DqrT56fk/s1600-h/FakeYouTube.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/SBmAuy9yjvI/AAAAAAAAAdM/Jl1DqrT56fk/s400/FakeYouTube.png" alt="" id="BLOGGER_PHOTO_ID_5195325186591854322" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;**Take Note: The installer filename changes everyday. &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;The installer name usually displays: "MacVideo" or "Porn4Mac".&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_5MH3NxS8hN8/SBmD1C9yjwI/AAAAAAAAAdU/FQPJddhpGeE/s1600-h/Porn4Mac.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_5MH3NxS8hN8/SBmD1C9yjwI/AAAAAAAAAdU/FQPJddhpGeE/s400/Porn4Mac.png" alt="" id="BLOGGER_PHOTO_ID_5195328592500920066" border="0" /&gt;&lt;/a&gt;Although this trojan requires manual installation, it is still possible that some Mac users will get hooked to this trick.&lt;br /&gt;&lt;br /&gt;Always be on the look-out for this type of dodgy websites.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/04/fake-youtube-installs-os-x.html" title="Fake YouTube Installs OS X TrojanDNSChanger" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/4592751702058805903/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/4592751702058805903" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/4592751702058805903?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;CEYEQXYzfyp7ImA9WxZaFUw.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-6550766426592669529</id><published>2008-04-27T19:25:00.000-07:00</published><updated>2008-04-29T16:35:00.887-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-04-29T16:35:00.887-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="phishing" /><category scheme="http://www.blogger.com/atom/ns#" term="malicious URL" /><category scheme="http://www.blogger.com/atom/ns#" term="multiple vulnerabilities" /><category scheme="http://www.blogger.com/atom/ns#" term="Safari exploit" /><category scheme="http://www.blogger.com/atom/ns#" term="URL spoofing attack" /><category scheme="http://www.blogger.com/atom/ns#" term="spinning wheel of death" /><title>Zero Day Exploit: Safari Address Bar URL Spoofing</title><content type="html">&lt;div style="text-align: justify;"&gt;There is a zero day threat to all Safari users both in Windows and Mac, where a remote attacker can hide the actual URL address of the web page in the browser location bar. Let's see how this works ...&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;Since URL and web page spoofing is very common to phishing, I created this sample email with crafted URL on it.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_5MH3NxS8hN8/SBawhS9yjrI/AAAAAAAAAcs/G1FCpadRrVg/s1600-h/link.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_5MH3NxS8hN8/SBawhS9yjrI/AAAAAAAAAcs/G1FCpadRrVg/s400/link.PNG" alt="" id="BLOGGER_PHOTO_ID_5194533306291621554" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;I clicked the link and here's what I got in Safari 3.1 for Windows.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/SBa00C9yjtI/AAAAAAAAAc8/ot-cjPm0cKU/s1600-h/webpage01.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/SBa00C9yjtI/AAAAAAAAAc8/ot-cjPm0cKU/s400/webpage01.PNG" alt="" id="BLOGGER_PHOTO_ID_5194538026460679890" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Here's the screenshot in Mac.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_5MH3NxS8hN8/SBa34y9yjuI/AAAAAAAAAdE/7vRu3Ww7gQo/s1600-h/mac_safari.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_5MH3NxS8hN8/SBa34y9yjuI/AAAAAAAAAdE/7vRu3Ww7gQo/s400/mac_safari.png" alt="" id="BLOGGER_PHOTO_ID_5194541406599941858" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;So, what happened here?&lt;br /&gt;&lt;br /&gt;A security flaw was found in Safari, when you input a URL containing a  special characters  followed by "@" which indicates the actual hostname. The special characters was crafted long enough to hide the URL of the page.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/SBayxi9yjsI/AAAAAAAAAc0/H5R5XBsuQ4k/s1600-h/webpage.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/SBayxi9yjsI/AAAAAAAAAc0/H5R5XBsuQ4k/s400/webpage.PNG" alt="" id="BLOGGER_PHOTO_ID_5194535784487751362" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;As most of Safari users experience the spinning wheel of death, it is evident that there are multiple vulnerabilities that lies within this application.&lt;br /&gt;&lt;br /&gt;Is there available security patch/fix ? None, at the moment. So, please refrain from clicking or browsing untrusted websites.&lt;br /&gt;&lt;br /&gt;Juan Pablo Lopez Yacubian has recently discovered this vulnerability.&lt;br /&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/04/zero-day-exploit-safari-address-bar-url.html" title="Zero Day Exploit: Safari Address Bar URL Spoofing" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/6550766426592669529/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/6550766426592669529" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/6550766426592669529?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;DU8MR3w5eCp7ImA9WxZbF0g.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-1586558113858971107</id><published>2008-04-20T20:36:00.000-07:00</published><updated>2008-04-20T23:04:46.220-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-04-20T23:04:46.220-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Apple Fix" /><category scheme="http://www.blogger.com/atom/ns#" term="secured default behavior" /><category scheme="http://www.blogger.com/atom/ns#" term="psychology of security" /><category scheme="http://www.blogger.com/atom/ns#" term="zango in rapidshare" /><category scheme="http://www.blogger.com/atom/ns#" term="apple software update 2.1" /><category scheme="http://www.blogger.com/atom/ns#" term="piggybacking" /><category scheme="http://www.blogger.com/atom/ns#" term="Stealth Safari" /><category scheme="http://www.blogger.com/atom/ns#" term="install zango rapidlibrary" /><title>Apple Fixed The Piggybacking Issue In SU</title><content type="html">&lt;div style="text-align: justify;"&gt;Couple of weeks ago, I blogged about this "&lt;a href="http://blog.iantivirus.com/2008/04/safari-31-piggybacks-in-sofware-update.html"&gt;Safari 3.1 Piggybacks In Sofware Update&lt;/a&gt;".&lt;br /&gt;&lt;br /&gt;There was a series of reaction specifically those who understands information security, criticizing about Safari 3.1 piggybacking or stealth installation through Software Update.&lt;br /&gt;&lt;br /&gt;Now, the interesting news is that Apple fixed this issue in Windows Apple Software Update version 2.1 &lt;span style="font-size:78%;"&gt;&lt;span style="font-family:courier new;"&gt;[READ ZDNet]&lt;/span&gt;&lt;/span&gt;.  I reckon earlier last week, the software update tool still includes Safari 3.1 in the list. However today, this is what i found out.&lt;br /&gt;&lt;br /&gt;To manually update, click "Apple Software Update" from Windows Program menu.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/SAwYygpE6tI/AAAAAAAAAcM/5-pAMoEWaIQ/s1600-h/SU03.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/SAwYygpE6tI/AAAAAAAAAcM/5-pAMoEWaIQ/s400/SU03.PNG" alt="" id="BLOGGER_PHOTO_ID_5191551726486088402" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Notice "Apple Software Update for Windows", this is an update to get the latest SU version 2.1.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/SAwX1ApE6rI/AAAAAAAAAb8/eJKj84A31dY/s1600-h/SU.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/SAwX1ApE6rI/AAAAAAAAAb8/eJKj84A31dY/s400/SU.PNG" alt="" id="BLOGGER_PHOTO_ID_5191550669924133554" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Let's install and check it ...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/SAwX_ApE6sI/AAAAAAAAAcE/RRIUUsQ4pic/s1600-h/SU01.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/SAwX_ApE6sI/AAAAAAAAAcE/RRIUUsQ4pic/s400/SU01.PNG" alt="" id="BLOGGER_PHOTO_ID_5191550841722825410" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Here's the new look. Apple fixed the issue by creating two sections: (1) Updates (2) New Software. It simply shows that Safari 3.1 is no longer piggybacking in software updates since it has its own category as New Software. Good!&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/SAwaygpE6vI/AAAAAAAAAcc/XLrtJuVJ35c/s1600-h/SU02.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/SAwaygpE6vI/AAAAAAAAAcc/XLrtJuVJ35c/s400/SU02.PNG" alt="" id="BLOGGER_PHOTO_ID_5191553925509343986" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;But wait, how come the tick boxes were already filled-in by default?&lt;br /&gt;&lt;br /&gt;Perhaps, this update is a complete conformity to information security if they also changed this default behavior to "NO".&lt;br /&gt;&lt;br /&gt;Speaking of default behavior, the latest changes in RapidLibrary requires users to install Zango to access a free content but here's the catch... Click "OK" to cancel and "Cancel" to continue.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/SAwoAgpE6wI/AAAAAAAAAck/0wB3p5hHn48/s1600-h/zango.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/SAwoAgpE6wI/AAAAAAAAAck/0wB3p5hHn48/s400/zango.PNG" alt="" id="BLOGGER_PHOTO_ID_5191568459678673666" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Funny, this is Psychology of Security &lt;span style="font-size:78%;"&gt;[Reference: &lt;a href="http://www.schneier.com/essay-155.html"&gt;Bruce Schneier&lt;/a&gt;]&lt;/span&gt;.&lt;br /&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/04/apple-fixed-piggybacking-issue-in-su.html" title="Apple Fixed The Piggybacking Issue In SU" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/1586558113858971107/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/1586558113858971107" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/1586558113858971107?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;C08GRHY9fSp7ImA9WxZbE04.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-656943935244830776</id><published>2008-04-15T21:03:00.000-07:00</published><updated>2008-04-16T00:43:45.865-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-04-16T00:43:45.865-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="OS X vulnerabilities" /><category scheme="http://www.blogger.com/atom/ns#" term="Q1 Virus Roundup" /><category scheme="http://www.blogger.com/atom/ns#" term="Q1 Mac Threats" /><category scheme="http://www.blogger.com/atom/ns#" term="apple security update" /><category scheme="http://www.blogger.com/atom/ns#" term="Mac malwares" /><category scheme="http://www.blogger.com/atom/ns#" term="rogue in Mac" /><title>Q1 Mac Threats RoundUp</title><content type="html">The first quarter of this year has gone so fast but for Mac threats everything just started. Let's take a review on Q1 notable threats, the overall perspective on malware categories and OS X reported vulnerabilities and fixes.&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;font-size:100%;" &gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-size:130%;"&gt;Q1 Notable Threats&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Trojan.OSX.DNSChanger&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Description: This is a malicious Trojan that uses social engineering technique to entice users to manually install the program. It arrives to users as a disguised video codec and associates itself with shared and downloadable videos. During installation, this Trojan modifies users’ DNS IP address to point to its own malicious servers. Infected user will suddenly experience unusual results in its entire web browsing activity.&lt;br /&gt;&lt;br /&gt;This trojan is currently seen in-the-wild.&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;RogueAntiSpyware.OSX.MacSweeper&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Description: MacSweeper is a rogue application which uses deceptive sales and marketing techniques to get onto the users’ system. It usually arrives to users as an pop-up advertisements, where it redirect users to download the file.&lt;br /&gt;&lt;br /&gt;This is the first rogue application for Mac OS X.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;RogueAntiSpyware.OSX.Imunizator&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Description: Imunizator is a re-branded version of MacSweeper. It is an exact copy of MacSweeper except for its new name.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Application.OSX.LogKext&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Description: LogKext is a free and powerful kernel base Keylogger in Mac OS X. This keylogger has a full stealth capabilities and it is controlled by a command-line client called logKextClient. A new version was recently released in public.&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;font-size:130%;" &gt;Percentage per Malware Categories&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/SAWeR8IkdsI/AAAAAAAAAbM/KlGuJf9KOtc/s1600-h/OSX+Cat.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/SAWeR8IkdsI/AAAAAAAAAbM/KlGuJf9KOtc/s400/OSX+Cat.png" alt="" id="BLOGGER_PHOTO_ID_5189728176651400898" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_5MH3NxS8hN8/SAWeIsIkdrI/AAAAAAAAAbE/G8VlgLq70UA/s1600-h/MacOS+Cat.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_5MH3NxS8hN8/SAWeIsIkdrI/AAAAAAAAAbE/G8VlgLq70UA/s400/MacOS+Cat.png" alt="" id="BLOGGER_PHOTO_ID_5189728017737610930" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;span style="font-size:130%;"&gt;OS X Vulnerabilities&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/SAWG18IkdmI/AAAAAAAAAac/_wzi1gJijqk/s1600-h/Q1+Vulnerabilities.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/SAWG18IkdmI/AAAAAAAAAac/_wzi1gJijqk/s400/Q1+Vulnerabilities.PNG" alt="" id="BLOGGER_PHOTO_ID_5189702406847624802" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_5MH3NxS8hN8/SAWG9MIkdnI/AAAAAAAAAak/7SfyZklM3mo/s1600-h/unpatched.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_5MH3NxS8hN8/SAWG9MIkdnI/AAAAAAAAAak/7SfyZklM3mo/s400/unpatched.PNG" alt="" id="BLOGGER_PHOTO_ID_5189702531401676402" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_5MH3NxS8hN8/SAWHLsIkdoI/AAAAAAAAAas/a5U8jYOZqZ0/s1600-h/VulneCount.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_5MH3NxS8hN8/SAWHLsIkdoI/AAAAAAAAAas/a5U8jYOZqZ0/s400/VulneCount.png" alt="" id="BLOGGER_PHOTO_ID_5189702780509779586" border="0" /&gt;&lt;/a&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/04/q1-mac-threats-roundup.html" title="Q1 Mac Threats RoundUp" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/656943935244830776/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/656943935244830776" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/656943935244830776?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;Ck4ASH0-fCp7ImA9WxZUFEU.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-8899188989836059798</id><published>2008-04-06T01:33:00.000-07:00</published><updated>2008-04-06T04:22:29.354-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-04-06T04:22:29.354-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="wget -U" /><category scheme="http://www.blogger.com/atom/ns#" term="dnschanger" /><category scheme="http://www.blogger.com/atom/ns#" term="Mac User-Agent" /><category scheme="http://www.blogger.com/atom/ns#" term="how to download DMG in windows" /><category scheme="http://www.blogger.com/atom/ns#" term="pupper" /><title>How To Download  DNSChanger DMG In Windows?</title><content type="html">&lt;div style="text-align: justify;"&gt;Last December 27, I blogged about Trojan DNSChanger entitled "&lt;a href="http://blog.iantivirus.com/2007/12/mac-os-x-2007-year-ender-for-zlob.html"&gt;Mac OS X: 2007 Year Ender for Zlob&lt;/a&gt;", which I mentioned the following:&lt;br /&gt;&lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;Zlob &amp;amp; Fake Codec History&lt;br /&gt;&lt;/li&gt;&lt;li&gt; List of Zlob distribution domains&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Trojan DNSChanger checks whether the user is downloading in Windows or Mac.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Network Information that leads to Russian Business Network(RBN)&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;January 2, when I wrote a follow-up article entitled "&lt;a href="http://blog.iantivirus.com/2008/01/impersonating-mac-browser-to-download.html"&gt;Impersonating Mac Browser&lt;/a&gt;". This article explains how Trojan DNSChanger serves the right executable to the requesting user and how to impersonate Mac browser to download the right DMG file.&lt;br /&gt;&lt;br /&gt;January 10, when I posted "&lt;a href="http://blog.iantivirus.com/2008/01/analysis-of-osx-trojan-dns-changer.html"&gt;Analysis of OSX Trojan DNS Changer&lt;/a&gt;".&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Why I am discussing this again?&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Because, there is an increase prevalence of this threat that captures more attention of malware analysts. Just recently, I received an email that says "New DNS Changer" with an attachment "jetcodec1000.dmg".  But, unfortunately the DMG file was not properly downloaded, instead the file contains MZ header which means Windows executable.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/R_iV7MQAuRI/AAAAAAAAAZU/OB3O9uwdJ3o/s1600-h/jetcodec.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/R_iV7MQAuRI/AAAAAAAAAZU/OB3O9uwdJ3o/s400/jetcodec.PNG" alt="" id="BLOGGER_PHOTO_ID_5186059815050328338" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Unfortunately, it was the same story posted in ISC Diary "&lt;a href="http://isc.sans.org/diary.html?storyid=4229"&gt;When is a DMG file not a DMG file&lt;/a&gt;".&lt;br /&gt;&lt;br /&gt;So, how to download  DNSChanger DMG file in Windows?&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;When you visit any of Trojan DNSChanger websites, your browser sends a User-Agent information to the server, which contain details about your operating system, web browser you use, application version and language preference. Base from this information, the malicious server decides whether to serve PE file for Windows or DMG file for Mac.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_5MH3NxS8hN8/R_ieGcQAuSI/AAAAAAAAAZc/e2HWgJ5IgMs/s1600-h/capture.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_5MH3NxS8hN8/R_ieGcQAuSI/AAAAAAAAAZc/e2HWgJ5IgMs/s400/capture.PNG" alt="" id="BLOGGER_PHOTO_ID_5186068804416878882" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;This means that you cannot download the right file by simply modifying the URL. In this case, you need to impersonate by changing your User-Agent info to this value:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-family:courier new;"&gt;Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-us)&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;To perform this task, you can either use Wget for Windows or Malzilla.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Using Wget&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Example,&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center; font-family: courier new;"&gt;[c:\] wget -U "Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-us)" http://&lt;http&gt;jetcodec.com/download/jetcodec1000.dmg &lt;/http&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;**Note: -U means user-agent&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;This site (jetcodec.com) is not available today. But there's another site that is up today and I can show you how this works.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/R_iqSsQAuVI/AAAAAAAAAZ0/-jgi15TSMyU/s1600-h/wget.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/R_iqSsQAuVI/AAAAAAAAAZ0/-jgi15TSMyU/s400/wget.PNG" alt="" id="BLOGGER_PHOTO_ID_5186082209009809746" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/R_irfsQAuWI/AAAAAAAAAZ8/JRWGQFBVvtU/s1600-h/gamecodec.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/R_irfsQAuWI/AAAAAAAAAZ8/JRWGQFBVvtU/s400/gamecodec.PNG" alt="" id="BLOGGER_PHOTO_ID_5186083531859736930" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Using Malzilla&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/R_ikHMQAuUI/AAAAAAAAAZs/rF0e_OrmE7A/s1600-h/malzilla.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/R_ikHMQAuUI/AAAAAAAAAZs/rF0e_OrmE7A/s400/malzilla.PNG" alt="" id="BLOGGER_PHOTO_ID_5186075414371547458" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_5MH3NxS8hN8/R_isWcQAuXI/AAAAAAAAAaE/YMXKcYnDTL0/s1600-h/malz.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_5MH3NxS8hN8/R_isWcQAuXI/AAAAAAAAAaE/YMXKcYnDTL0/s400/malz.PNG" alt="" id="BLOGGER_PHOTO_ID_5186084472457574770" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;I just created a &lt;a href="http://www.youtube.com/iThreatResearcher"&gt;YouTube&lt;/a&gt; account and started to upload demo videos, hopefully this week I can upload a video for this one.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/04/how-to-download-dnschanger-dmg-in.html" title="How To Download  DNSChanger DMG In Windows?" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/8899188989836059798/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/8899188989836059798" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/8899188989836059798?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;CkMNQnc7eip7ImA9WxZUEkw.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-3862234247211904474</id><published>2008-04-02T16:41:00.000-07:00</published><updated>2008-04-03T01:14:53.902-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-04-03T01:14:53.902-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="safari 3.1" /><category scheme="http://www.blogger.com/atom/ns#" term="apple software update" /><category scheme="http://www.blogger.com/atom/ns#" term="tailgating" /><category scheme="http://www.blogger.com/atom/ns#" term="piggybacking" /><title>Safari 3.1 Piggybacks In Sofware Update</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/R_Qb2sQAuNI/AAAAAAAAAY0/b_e_XGytQtA/s1600-h/safari_piggybacks.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/R_Qb2sQAuNI/AAAAAAAAAY0/b_e_XGytQtA/s400/safari_piggybacks.PNG" alt="" id="BLOGGER_PHOTO_ID_5184799697415485650" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-style: italic;"&gt;"Piggybacking is a method used to gain unauthorized access to the computer. This occurs when an authorize application allows &lt;/span&gt;&lt;span style="font-style: italic;"&gt; another non-related or unauthorized application to pass through or get into user's system."&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Couple of weeks ago while I was working in my infect machine, I got this alert message from Apple Software Update. I was a little bit busy so I just minimize the window. Last monday, I had the chance to check and read what it says. Surprisingly, I found Safari 3.1 in the list which I know I haven't installed any of its version. So, what's happening here ?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/R_SNgMQAuQI/AAAAAAAAAZM/wFtue0w1JoQ/s1600-h/piggyback.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/R_SNgMQAuQI/AAAAAAAAAZM/wFtue0w1JoQ/s400/piggyback.PNG" alt="" id="BLOGGER_PHOTO_ID_5184924655193995522" border="0" /&gt;&lt;/a&gt;As shown in the figure above, the QuickTime program I installed checks for updates. Then, the server replied with the update information. However, it doesn't end there, the server exploited the communication to perform an unauthorized task, which is to offer Safari 3.1 installer.&lt;br /&gt;&lt;br /&gt;This is completely unacceptable behavior and a breach to information security.&lt;br /&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/04/safari-31-piggybacks-in-sofware-update.html" title="Safari 3.1 Piggybacks In Sofware Update" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/3862234247211904474/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/3862234247211904474" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/3862234247211904474?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;A0EERH07fCp7ImA9WxZUEUo.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-3226846682803355790</id><published>2008-04-01T21:57:00.000-07:00</published><updated>2008-04-02T16:40:05.304-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-04-02T16:40:05.304-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="iMunizator.com" /><category scheme="http://www.blogger.com/atom/ns#" term="OS X vulnerabilities" /><category scheme="http://www.blogger.com/atom/ns#" term="PWN2OWN result" /><category scheme="http://www.blogger.com/atom/ns#" term="hack MacBook Air  OSX" /><category scheme="http://www.blogger.com/atom/ns#" term="antispywaredeluxe.com" /><category scheme="http://www.blogger.com/atom/ns#" term="safari zero day" /><title>March OSX News Makers</title><content type="html">&lt;span style="font-weight: bold; font-style: italic;"&gt;March 18 &lt;/span&gt;- Apple Released Its Gigantic Update.&lt;br /&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;&lt;a href="http://support.apple.com/kb/HT1249"&gt;Security Update 2008-002&lt;/a&gt; fixes &lt;span style="font-weight: bold;"&gt;95 security vulnerabilities&lt;/span&gt; found in different components of Mac OS X operating system.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://docs.info.apple.com/article.html?artnum=307563"&gt;Safari 3.1&lt;/a&gt;  fixes &lt;span style="font-weight: bold;"&gt;13 security vulnerabilities&lt;/span&gt; found in Safari for Mac (10) and Windows (3).&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;March 20 &lt;/span&gt;&lt;span style="font-style: italic;"&gt;- &lt;/span&gt;&lt;span&gt;"iMunizator" The 2nd Rogue In Mac&lt;/span&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;iMunizator a rebranded version of &lt;a href="http://blog.iantivirus.com/2008/01/deeper-look-on-macsweeper.html"&gt;MacSweeper&lt;/a&gt;.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_5MH3NxS8hN8/R_MzsMQAuLI/AAAAAAAAAYk/jXMmHoKblVs/s1600-h/imunizator.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://bp1.blogger.com/_5MH3NxS8hN8/R_MzsMQAuLI/AAAAAAAAAYk/jXMmHoKblVs/s400/imunizator.png" alt="" id="BLOGGER_PHOTO_ID_5184544430329215154" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/R_My_cQAuJI/AAAAAAAAAYU/dJ40WGmQB-E/s1600-h/macsweeper.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/R_My_cQAuJI/AAAAAAAAAYU/dJ40WGmQB-E/s400/macsweeper.png" alt="" id="BLOGGER_PHOTO_ID_5184543661530069138" border="0" /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;It was first seen in &lt;a href="http://discussions.apple.com/thread.jspa?messageID=6873328&amp;amp;#6873328"&gt;Apple Discussions&lt;/a&gt; web site, where someone asked this question "What is iMunizator?"&lt;/li&gt;&lt;li&gt;Difference between the two:&lt;/li&gt;&lt;ul style="text-align: justify;"&gt;&lt;ul&gt;&lt;li&gt;iMunizatorSetup.dmg file size is 1.49Mb while MacSweeper 1.52Mb.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;iMunizator company is iMunizator.com while MacSweeper is KiVVi Software.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;iMunizator executable file size is 407,036 bytes while MacSweeper 407,468 bytes.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;iMunizator resource folder does not contain TODO.txt.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;If Last time, MacSweeper is sharing NS server with Cleanator (a known rogue program in windows) this time iMunizator.com neighbor is AntiSpywaredeluxe.com [67.205.72.9] which is also a rogue program in Windows. iMunizator.com network information below:&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_5MH3NxS8hN8/R_M5PsQAuMI/AAAAAAAAAYs/NpM5piJzsZc/s1600-h/imu-network.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_5MH3NxS8hN8/R_M5PsQAuMI/AAAAAAAAAYs/NpM5piJzsZc/s400/imu-network.PNG" alt="" id="BLOGGER_PHOTO_ID_5184550537772710082" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;March 27 &lt;/span&gt;&lt;span&gt;- Mac OS X Hacked in 2 Minutes &lt;/span&gt;&lt;span style="font-size:78%;"&gt;Read [CNET News]&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;&lt;a href="http://cansecwest.com/post/2008-03-20.21:33:00.CanSecWest_PWN2OWN_2008"&gt;CanSecWest PWN2OWN 2008 contest&lt;/a&gt; targets Linux, Vista and OSX.&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;ul&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;VAIO VGN-TZ37CN running Ubuntu 7.10&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;Fujitsu U810 running Vista Ultimate SP1&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;span&gt;MacBook Air running OSX 10.5.2&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;March 26 (1st Day) when the contest started. However, nobody was able to hacked any of these three operating systems in a limited resources and confined local network connection.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;March 27 (2nd Day) when the attackers were given internet connection.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;March 28 (3rd Day) when the attackers were allowed to use popular software to exploit.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;The results are as follows:&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;ul&gt;&lt;ul&gt;&lt;li&gt;On the 2nd day, Mac OS X was successfully hacked in 2 minutes using a zero-day exploit in Safari.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;On the 3rd day, Vista was successfully hacked after 7 hours using zero-day exploit in Adobe Flash.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Linux stays intact and won against hackers.&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/04/march-osx-news-makers.html" title="March OSX News Makers" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/3226846682803355790/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/3226846682803355790" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/3226846682803355790?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;CkEDQ3k4fip7ImA9WxZWGUw.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-8420674367259860363</id><published>2008-03-18T20:22:00.000-07:00</published><updated>2008-03-19T00:11:12.736-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-03-19T00:11:12.736-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="os x scanner" /><category scheme="http://www.blogger.com/atom/ns#" term="process scanner" /><category scheme="http://www.blogger.com/atom/ns#" term="real time detection" /><category scheme="http://www.blogger.com/atom/ns#" term="mac antivirus" /><title>iAntivirus Protects Your Mac</title><content type="html">&lt;div style="text-align: justify;"&gt;PC Tools will soon release iAntivirus security software for Mac users. The product displays a Mac-like simplicity and elegance, yet with powerful features that catches and removes known malwares in real-time.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;Internet Downloads&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;A good example here is &lt;a href="http://blog.iantivirus.com/2008/01/analysis-of-osx-trojan-dns-changer.html"&gt;Trojan DNSChanger&lt;/a&gt;. This threat has been in the internet for more than four months now and it's continually eluding security analyst by changing its domain names, IP addresses and ways in delivering this trojan to mac users.&lt;br /&gt;&lt;br /&gt;iAntivirus on-guard catches this threat in real time.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/R-CLCqHGLtI/AAAAAAAAAXs/Bjb27k_shyI/s1600-h/TrojanDNSChanger.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/R-CLCqHGLtI/AAAAAAAAAXs/Bjb27k_shyI/s400/TrojanDNSChanger.png" alt="" id="BLOGGER_PHOTO_ID_5179292449256124114" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;&lt;br /&gt;Files Through Messengers&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Let say someone you know or close to you sent you a file through messenger. Without your knowledge, the file is a Backdoor server component which the sender wishes you to install so that the client component which is on the attacker side could perform unauthorized  task to your machine. Here's the impressive real time catch of iAntivirus.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/R-CT7KHGLuI/AAAAAAAAAX0/83GL5ycIbms/s1600-h/Messenger.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/R-CT7KHGLuI/AAAAAAAAAX0/83GL5ycIbms/s400/Messenger.png" alt="" id="BLOGGER_PHOTO_ID_5179302216011755234" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;Files In Your USB Flash Drive&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In our daily computing activities, USB flash or portable drives plays important role in storing, exchanging and transferring files. You often get out of control when too much files are stored and worst if one day you are dragging malicious files to your local hard drive.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_5MH3NxS8hN8/R-CYd6HGLvI/AAAAAAAAAX8/rvBueITktPE/s1600-h/FlashDrive.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_5MH3NxS8hN8/R-CYd6HGLvI/AAAAAAAAAX8/rvBueITktPE/s400/FlashDrive.png" alt="" id="BLOGGER_PHOTO_ID_5179307211058720498" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;Running Process&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Perhaps, a  &lt;a href="http://blog.iantivirus.com/2008/01/snoop-sneak-sniff.html"&gt;keylogger&lt;/a&gt; running in background. &lt;span style="font-style: italic; font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/R-CfbqHGLwI/AAAAAAAAAYE/cJ-H-GgXOCQ/s1600-h/RunningProcess.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/R-CfbqHGLwI/AAAAAAAAAYE/cJ-H-GgXOCQ/s400/RunningProcess.png" alt="" id="BLOGGER_PHOTO_ID_5179314868985409282" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Are you excited to have a copy of this?&lt;br /&gt;&lt;br /&gt;Then drop your &lt;a href="http://www.iantivirus.com/"&gt;email address&lt;/a&gt; and we will notify you once iAntivirus beta version is available.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/03/iantivirus-protects-your-mac.html" title="iAntivirus Protects Your Mac" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/8420674367259860363/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/8420674367259860363" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/8420674367259860363?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;D0MBQHg9fip7ImA9WxZWE00.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-6522762773320746117</id><published>2008-03-10T16:29:00.000-07:00</published><updated>2008-03-12T00:04:11.666-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-03-12T00:04:11.666-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="anti-phising" /><category scheme="http://www.blogger.com/atom/ns#" term="PayPal" /><category scheme="http://www.blogger.com/atom/ns#" term="web forgery" /><category scheme="http://www.blogger.com/atom/ns#" term="malware protection" /><category scheme="http://www.blogger.com/atom/ns#" term="Safari security feature" /><category scheme="http://www.blogger.com/atom/ns#" term="one-click" /><category scheme="http://www.blogger.com/atom/ns#" term="citibank phish" /><title>Should Safari Join The Rat Race?</title><content type="html">&lt;div style="text-align: justify;"&gt;Few weeks ago, PayPal published a frequently asked question guide about "&lt;a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/cps/securitycenter/general/SaferBrowsersFAQ-outside"&gt;Safer Web Browsers&lt;/a&gt;".  The news maker part is this:&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Which browser have anti-phishing features?&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;- Microsoft Internet Explorer 7 or later&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;- Mozilla Firefox 2 or later&lt;br /&gt;- Opera 9.1 or later&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Yes, this is true Safari 3.1 is not capable of detecting phishing site and this is where PayPal is most worried about  - because they are always targeted by phishers.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/R9YqIqHGLjI/AAAAAAAAAWY/Hm27SBfUsjc/s1600-h/PayPal_Safari.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/R9YqIqHGLjI/AAAAAAAAAWY/Hm27SBfUsjc/s400/PayPal_Safari.png" alt="" id="BLOGGER_PHOTO_ID_5176371149940338226" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_5MH3NxS8hN8/R9Yrk6HGLkI/AAAAAAAAAWg/_wbs_w0a-Yc/s1600-h/PayPal_Firefox.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_5MH3NxS8hN8/R9Yrk6HGLkI/AAAAAAAAAWg/_wbs_w0a-Yc/s400/PayPal_Firefox.png" alt="" id="BLOGGER_PHOTO_ID_5176372734783270466" border="0" /&gt;&lt;/a&gt;Notice the two screenshots above, obviously Safari does not recognize anything while Firefox displays an alert message.&lt;br /&gt;&lt;br /&gt;Base from last year report, &lt;a href="http://www.antiphishing.org/"&gt;Anti-Phishing Working Group&lt;/a&gt; receives an average of 25,000 new phishing sites per month and 91.7% of this attacks are related to Financial Services.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_5MH3NxS8hN8/R9cPGKHGLlI/AAAAAAAAAWo/SHJ30QpMxf4/s1600-h/citibank_safari.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_5MH3NxS8hN8/R9cPGKHGLlI/AAAAAAAAAWo/SHJ30QpMxf4/s400/citibank_safari.png" alt="" id="BLOGGER_PHOTO_ID_5176622895153426002" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/R9cPNaHGLmI/AAAAAAAAAWw/umgnnYxrB8o/s1600-h/citibank_firefox.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/R9cPNaHGLmI/AAAAAAAAAWw/umgnnYxrB8o/s400/citibank_firefox.png" alt="" id="BLOGGER_PHOTO_ID_5176623019707477602" border="0" /&gt;&lt;/a&gt;This is the reason why we will be seeing more security features integrating to web browsers just like Internet Explorer 8 Beta 1 - which was released last week. There are two significant security features in this version:&lt;br /&gt;&lt;br /&gt;Safety Filter - It prevents known malicious sites from loading. However, this feature does not work in my testing. Perhaps, they are still working on it.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/R9dnyaHGLoI/AAAAAAAAAXA/tN7DzqHmGWc/s1600-h/SafetyFilter.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/R9dnyaHGLoI/AAAAAAAAAXA/tN7DzqHmGWc/s400/SafetyFilter.png" alt="" id="BLOGGER_PHOTO_ID_5176720412385881730" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Domain Name Highlighting - As shown in the example below, the real domain name is not citibank.com instead it is 8martofftoday.org. Absolutely, a phishing site! This feature is also available in Mozilla plug-in "&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/4014"&gt;Locationbar&amp;amp;sup2&lt;/a&gt;".&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_5MH3NxS8hN8/R9cfSKHGLnI/AAAAAAAAAW4/KB44GzuKnIE/s1600-h/IE8.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_5MH3NxS8hN8/R9cfSKHGLnI/AAAAAAAAAW4/KB44GzuKnIE/s400/IE8.PNG" alt="" id="BLOGGER_PHOTO_ID_5176640693497900658" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Mozilla Firefox 3 Beta 1 was previously announced and this version provides more security features including "Malware Protection", "Anti-virus Integration" and "One-click site info". Check the full release notes &lt;a href="http://www.mozilla.com/en-US/firefox/3.0b1/releasenotes/"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The continuous proliferation of threats in the internet has escalated user's security awareness. And this, factors into users' expectation that softwares and application should provide security features.  Beating up threats is just like a rat race and whether this is users' problem or not, the trend is now pressuring Safari to blend in.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/03/should-safari-join-rat-race.html" title="Should Safari Join The Rat Race?" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/6522762773320746117/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/6522762773320746117" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/6522762773320746117?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;AkIFQXkyeip7ImA9WxZXGE0.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-1378576314617834914</id><published>2008-03-05T20:10:00.001-08:00</published><updated>2008-03-06T05:01:50.792-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-03-06T05:01:50.792-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="third-party cookies" /><category scheme="http://www.blogger.com/atom/ns#" term="delete cookies" /><category scheme="http://www.blogger.com/atom/ns#" term="cookie logger" /><category scheme="http://www.blogger.com/atom/ns#" term="persistent cookies" /><category scheme="http://www.blogger.com/atom/ns#" term="tracking threat" /><category scheme="http://www.blogger.com/atom/ns#" term="clear text" /><category scheme="http://www.blogger.com/atom/ns#" term="cookie poisoning" /><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><category scheme="http://www.blogger.com/atom/ns#" term="Safari show cookies" /><title>Cookies A Threat To Your Privacy</title><content type="html">Do you wonder what is cookie all about and how it threatens your privacy ? Let's take a deeper look.&lt;br /&gt;&lt;br /&gt;A cookie is a text string of information that is sent by a website to your web browser and stores it to your hard disk so that the website will remember who you are.&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_5MH3NxS8hN8/R8uroXEPDbI/AAAAAAAAAVw/fm4GFcvLeGw/s1600-h/cookie_com.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_5MH3NxS8hN8/R8uroXEPDbI/AAAAAAAAAVw/fm4GFcvLeGw/s400/cookie_com.PNG" alt="" id="BLOGGER_PHOTO_ID_5173417306840042930" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Figure 1.0 shows how web browser request the web page to the server and how cookie is carried in the communication.&lt;br /&gt;&lt;br /&gt;Cookie by itself is just a piece of information and not a program code. It is not capable of harming user's computer, and they cannot act as a virus or worms. Cookies are created and used to allow server to store and retrieve state information. However, this small text file is rich in information, which may include your IP address, user name, email address, password, preferred language, shopping cart items and any strings that can be linked to your identity.&lt;br /&gt;&lt;br /&gt;==========&lt;br /&gt;Privacy Issue&lt;br /&gt;==========&lt;br /&gt;There's a privacy issue if the cookie is stored in users' computer without his/her knowledge or consent and this also includes affiliates or third-party cookies.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/R8uryHEPDcI/AAAAAAAAAV4/B2SGg_d12xw/s1600-h/cookies01.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/R8uryHEPDcI/AAAAAAAAAV4/B2SGg_d12xw/s400/cookies01.PNG" alt="" id="BLOGGER_PHOTO_ID_5173417474343767490" border="0" /&gt;&lt;/a&gt;Figure 2.0 shows how a third-party ad server tracks users' browsing habits and preferences to deliver a personalize advertisements.&lt;br /&gt;&lt;br /&gt;This privacy issue has been addressed through legislation by different countries such as Europe and US. Their position is to allow cookies provided that there is a privacy policy informing users that the website is serving cookies, how it is being served, how it is being used and how people can refuse or accept it.&lt;br /&gt;&lt;br /&gt;Here's a good example of privacy policy statement:&lt;br /&gt;&lt;br /&gt;http://www.bbc.co.uk/privacy/&lt;br /&gt;http://www.doleta.gov/privacy.cfm&lt;br /&gt;&lt;br /&gt;Also, this privacy issue has been discussed in RFC2965 - HTTP State Management Mechanism.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;&lt;span style="font-style: italic;"&gt;6. PRIVACY &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Informed consent should guide the design of systems that use cookies. A user should be able to find out how a web site plans to use information in a cookies and should be able to choose whether or not those policies are acceptable. Both the user agent and the origin server mus assist informed consent. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;So, what does it mean ? This means, websites that serves cookies without informed consent violates users' privacy.&lt;br /&gt;&lt;br /&gt;==============&lt;br /&gt;Security &amp;amp; Privacy&lt;br /&gt;==============&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;CLEAR TEXT&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;The cookie header and content are readable or in clear text format. Any sensitive or identifiable information is vulnerable and exposed to threats whether it is a malware, packet sniffers, cookie hijackers or another user of that pc.&lt;br /&gt;&lt;br /&gt;Check your cookies and see how much personal information are stored.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/R839_-f2wBI/AAAAAAAAAWA/gh0BC5sJ8Nk/s1600-h/cookie01.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/R839_-f2wBI/AAAAAAAAAWA/gh0BC5sJ8Nk/s400/cookie01.png" alt="" id="BLOGGER_PHOTO_ID_5174070822468763666" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Here's how to check it :&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;&lt;span&gt;Safari Users&lt;br /&gt;- Go to Preferences and click Show Cookies.&lt;br /&gt;&lt;br /&gt;Mozilla Firefox Users&lt;br /&gt;- Go to Tools, Option and Show Cookies.&lt;br /&gt;&lt;br /&gt;IE Users&lt;br /&gt;- Go to Tools, Internet Options, General tab&lt;br /&gt;- In Browsing History click Settings, View Files.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;PERSISTENT &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Persistent cookies does not expire soon enough even after the user ended the session. Thus, the website can build information or profile your browsing activity and preferences over time.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/R843Duf2wCI/AAAAAAAAAWI/7UmiPSZB7MU/s1600-h/cookie02.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/R843Duf2wCI/AAAAAAAAAWI/7UmiPSZB7MU/s400/cookie02.png" alt="" id="BLOGGER_PHOTO_ID_5174133559056056354" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;COOKIE POISONING &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Cookie poisoning simply means performing unauthorized modification of the values stored inside the cookie. This can be easily done using tools and information available from the internet. Most websites stores persistent, non-secure cookies while some are secured but still there are web site that employs poor encryption that could be easily decoded.&lt;br /&gt;&lt;br /&gt;A good example is performing tampering attack to a shopping cart to change the total shopping value to a huge discount.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_5MH3NxS8hN8/R89Gfuf2wDI/AAAAAAAAAWQ/4TmB6yyH1Bo/s1600-h/shop.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_5MH3NxS8hN8/R89Gfuf2wDI/AAAAAAAAAWQ/4TmB6yyH1Bo/s400/shop.PNG" alt="" id="BLOGGER_PHOTO_ID_5174432007743520818" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;THREATS&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Worms - Mass-mailing worms such as NetSky and Lohack is capable to search and harvest email address to all .TXT files and this includes users' cookies.&lt;br /&gt;&lt;br /&gt;Trojan - Banking related trojans are usually capable of stealing users' cookies.&lt;br /&gt;&lt;br /&gt;Backdoor - There are backdoor that steals cookies associated to ebay, paypal and banks.&lt;br /&gt;&lt;br /&gt;Exploit - This is usually employed using cross site scripting exploit, where a malicious user injects a code to a legitimate vulnerable website. So, all visitors of that website will get redirected where a malicious cookie stealer script awaits.&lt;br /&gt;&lt;br /&gt;A malicious user could use the stolen cookies to impersonate or steal user's identity online.&lt;br /&gt;&lt;br /&gt;Phishers - URL links that are spammed through emails, blogs, messengers and forums may also link to a malicious cookie stealer sites.&lt;br /&gt;&lt;br /&gt;=======&lt;br /&gt;Summary&lt;br /&gt;=======&lt;br /&gt;&lt;br /&gt;Cookie is just a small piece of information but if it contains your identity, it is something that you should care about. Stealing information usually happens in background, it means without your knowledge. Cookies are harmless by itself, but the threats that surrounds it are out there in-the-wild. Malicious and exploited sites are everywhere and your cookies is always at risk.&lt;br /&gt;&lt;br /&gt;For safety, everytime you input information online whether you are checking your email, doing net banking or shopping, you should always check your cookies and delete them together with your browsing history. There are available tools online that can help you perform this task as well.&lt;br /&gt;&lt;br /&gt;Get informed and stay safe!&lt;br /&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/03/cookies-threat-to-your-privacy.html" title="Cookies A Threat To Your Privacy" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/1378576314617834914/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/1378576314617834914" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/1378576314617834914?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;CU8CQng8eCp7ImA9WxZQGUQ.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-7475780567887534526</id><published>2008-02-25T14:54:00.000-08:00</published><updated>2008-02-25T18:44:23.670-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-02-25T18:44:23.670-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="msnlist" /><category scheme="http://www.blogger.com/atom/ns#" term="msn hacks" /><category scheme="http://www.blogger.com/atom/ns#" term="msn blocker" /><category scheme="http://www.blogger.com/atom/ns#" term="who blocks you" /><category scheme="http://www.blogger.com/atom/ns#" term="spamming bots" /><category scheme="http://www.blogger.com/atom/ns#" term="MSN scam" /><category scheme="http://www.blogger.com/atom/ns#" term="blockingyou" /><category scheme="http://www.blogger.com/atom/ns#" term="blockdelete" /><title>Your MSN Account Has Been 0WN3D</title><content type="html">&lt;div style="text-align: justify;"&gt;&lt;span style="font-style: italic;"&gt;"Social Engineering is a technique used to manipulate people into performing actions or divulging confidential information by gaining trust. It attempts to gain access to sensitive data such as password, login names and worst - credit card numbers. This method is very easy and high success rate - No wonder it is very popular and often used by hackers."&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;Do you want to know who's blocking you in MSN?&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/R8Nc2sxDEDI/AAAAAAAAAUw/H48BwWQ-Uw0/s1600-h/site.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/R8Nc2sxDEDI/AAAAAAAAAUw/H48BwWQ-Uw0/s400/site.png" alt="" id="BLOGGER_PHOTO_ID_5171078891951034418" border="0" /&gt;&lt;/a&gt;Whoblocksyou.com can figure out for you! Just visit the site, enter your MSN account and password, then you will get the list.&lt;br /&gt;&lt;br /&gt;It certainly looks and sounds real, BUT IT'S NOT!&lt;br /&gt;&lt;br /&gt;This site is a scam luring MSN users to provide their login credentials, then after that, it will take control over their account.&lt;br /&gt;&lt;br /&gt;Once the user entered his/her login credentials, a message box will be displayed claiming that "..users' privacy is 100% guaranteed". However, users' email address and password are sent over the network  in clear text form. So, where's the privacy here?&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/R8NkOsxDEGI/AAAAAAAAAVI/64kS-9kxVa8/s1600-h/packetdisclaimer.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/R8NkOsxDEGI/AAAAAAAAAVI/64kS-9kxVa8/s400/packetdisclaimer.PNG" alt="" id="BLOGGER_PHOTO_ID_5171087000849289314" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The disclaimer also mentioned that "we do not save your password..." but once you logged in to your MSN messenger account, you'll find some changes to your display name and personal messages.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_5MH3NxS8hN8/R8NUYcxDECI/AAAAAAAAAUo/5o1cTTGETYQ/s1600-h/whoblock.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_5MH3NxS8hN8/R8NUYcxDECI/AAAAAAAAAUo/5o1cTTGETYQ/s400/whoblock.PNG" alt="" id="BLOGGER_PHOTO_ID_5171069576166969378" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Even if you tried to fix this changes, it will keep on returning everytime you sign-in. This is absolutely annoying! Not only that, your friends will see this embarrassing changes as shown in the screenshot below.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/R8N24sxDEII/AAAAAAAAAVY/jkdgEMj7cN0/s1600-h/display.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/R8N24sxDEII/AAAAAAAAAVY/jkdgEMj7cN0/s400/display.PNG" alt="" id="BLOGGER_PHOTO_ID_5171107513613095042" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;If this can happen to your messenger, what more to your email account? Obviously, your MSN account has been 0WN3D. Beware of this trick!&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/02/your-msn-account-has-been-0wn3d.html" title="Your MSN Account Has Been 0WN3D" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/7475780567887534526/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/7475780567887534526" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/7475780567887534526?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;Ak4FQHsyeCp7ImA9WxZQGEQ.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-5535362778400986800</id><published>2008-02-20T15:03:00.000-08:00</published><updated>2008-02-24T16:21:51.590-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-02-24T16:21:51.590-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="StalkerTrack" /><category scheme="http://www.blogger.com/atom/ns#" term="phishing" /><category scheme="http://www.blogger.com/atom/ns#" term="warning message" /><category scheme="http://www.blogger.com/atom/ns#" term="password stealer" /><category scheme="http://www.blogger.com/atom/ns#" term="MySpace spammers" /><category scheme="http://www.blogger.com/atom/ns#" term="Crowdguard" /><category scheme="http://www.blogger.com/atom/ns#" term="featured pictures" /><category scheme="http://www.blogger.com/atom/ns#" term="tracking tool" /><title>MySpace Spammers Are Back</title><content type="html">What is Crowdguard.com ? This is the question asked by MySpace user after getting a message from a friend telling her to visit this site.&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_5MH3NxS8hN8/R7ztmMxDD6I/AAAAAAAAATo/_7Re1jpK1QI/s1600-h/crowdguard.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_5MH3NxS8hN8/R7ztmMxDD6I/AAAAAAAAATo/_7Re1jpK1QI/s400/crowdguard.png" alt="" id="BLOGGER_PHOTO_ID_5169267712832245666" border="0" /&gt;&lt;/a&gt;You need to login your MySpace email address and password to view your pictures. For some people this site seems harmless, but behind this page the objective is to lure people in giving out their Myspace credentials.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_5MH3NxS8hN8/R7zxvsxDD7I/AAAAAAAAATw/o_VGG8-2fek/s1600-h/source.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_5MH3NxS8hN8/R7zxvsxDD7I/AAAAAAAAATw/o_VGG8-2fek/s400/source.PNG" alt="" id="BLOGGER_PHOTO_ID_5169272274087514034" border="0" /&gt;&lt;/a&gt;Once you give your login credentials, a cgi script will take these informations to a remote server.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_5MH3NxS8hN8/R74JIMxDD8I/AAAAAAAAAT4/5uroljlkfoA/s1600-h/list02.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_5MH3NxS8hN8/R74JIMxDD8I/AAAAAAAAAT4/5uroljlkfoA/s400/list02.png" alt="" id="BLOGGER_PHOTO_ID_5169579458738458562" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;And, this message box will pop-up.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/R74NCcxDD9I/AAAAAAAAAUA/bJXSjajcc-8/s1600-h/pop.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/R74NCcxDD9I/AAAAAAAAAUA/bJXSjajcc-8/s400/pop.png" alt="" id="BLOGGER_PHOTO_ID_5169583758000721874" border="0" /&gt;&lt;/a&gt;To make the story short, the user will not be able to see any pictures - because there's none.  This site is phising for your login details so a remote attacker could use it and send spam bulletins or messages to your MySpace friends. It also generates web traffics for all visited sites.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Similar to Crowdguard is Stalkertrack.com. This site promises for free tracking tool that will let you track or "stalk" all profiles that visits your Myspace page.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_5MH3NxS8hN8/R747asxDD-I/AAAAAAAAAUI/8lVNRkpG1yM/s1600-h/Stalkertrack.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_5MH3NxS8hN8/R747asxDD-I/AAAAAAAAAUI/8lVNRkpG1yM/s400/Stalkertrack.png" alt="" id="BLOGGER_PHOTO_ID_5169634752147427298" border="0" /&gt;&lt;/a&gt;Once you entered your MySpace login details, this spammer will start using it to spam your friends.&lt;br /&gt;&lt;br /&gt;Not only that, your email address and password are sent to multiple IP addresses in clear text form.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_5MH3NxS8hN8/R75FbsxDD_I/AAAAAAAAAUQ/LAE0j-4eOuM/s1600-h/capture.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp1.blogger.com/_5MH3NxS8hN8/R75FbsxDD_I/AAAAAAAAAUQ/LAE0j-4eOuM/s400/capture.png" alt="" id="BLOGGER_PHOTO_ID_5169645764443574258" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;**Note: IP address may change. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;Do you wonder how many spams were already created in Myspace?&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/R75JEcxDEBI/AAAAAAAAAUg/AvmKxTbGm2I/s1600-h/GoogleResult.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/R75JEcxDEBI/AAAAAAAAAUg/AvmKxTbGm2I/s400/GoogleResult.png" alt="" id="BLOGGER_PHOTO_ID_5169649763058126866" border="0" /&gt;&lt;/a&gt;There are 4 million generated post relating to StalkerTrack and this number will keep increasing if more and more vulnerable MySpace users will get deceived by this trick.&lt;br /&gt;&lt;br /&gt;Stay away from these sites!&lt;br /&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/02/myspace-spammers-are-back.html" title="MySpace Spammers Are Back" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/5535362778400986800/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/5535362778400986800" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/5535362778400986800?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;CUAMQns9fCp7ImA9WxZQFEo.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-2152237744869814552</id><published>2008-02-19T14:37:00.000-08:00</published><updated>2008-02-19T18:16:23.564-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-02-19T18:16:23.564-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="affiliate commision" /><category scheme="http://www.blogger.com/atom/ns#" term="bundler.exe" /><category scheme="http://www.blogger.com/atom/ns#" term="active x exploit" /><category scheme="http://www.blogger.com/atom/ns#" term="malware retailer" /><category scheme="http://www.blogger.com/atom/ns#" term="webmasterpartnership" /><category scheme="http://www.blogger.com/atom/ns#" term="loaders.exe" /><category scheme="http://www.blogger.com/atom/ns#" term="referrals" /><category scheme="http://www.blogger.com/atom/ns#" term="os x trojan" /><title>Malware Retailer Update: Dear Partner</title><content type="html">&lt;div style="text-align: justify;"&gt;&lt;span style="font-style: italic;"&gt;The&lt;/span&gt;&lt;span style="font-style: italic;"&gt; news ...&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;Dear Partner,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;We have three great new for you - first we updated our loader, it now not visible for AV and from now we'll update exe few times per week - so it always stay invisible so keep updated!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Another one - now we have referral module ready - you can refer webmasters and earn 10% from their revenue! You can find links in your account area.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;And main news - we've rewrite installs counting module - now we have much better conversation - much more money for you - just try and see.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;span style="font-family:courier new;"&gt;Here is updated loader link for you: http://69.64.51.47/files/loaders2/adx.exe&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span style="font-family:courier new;"&gt;Sure you always can use not crypted exe and crypt by yourself, here is your link for NON encrypted exe: http://69.64.51.47/files/loaders-nc/adx.exe&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Thank you for your trust!&lt;br /&gt;&lt;br /&gt;Let's keep up good work!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;AV scanners result&lt;/span&gt;&lt;span style="font-style: italic;"&gt; ...&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/R7t9-sxDD5I/AAAAAAAAATg/ql7Pazk6OH0/s1600-h/VResult.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/R7t9-sxDD5I/AAAAAAAAATg/ql7Pazk6OH0/s400/VResult.PNG" alt="" id="BLOGGER_PHOTO_ID_5168863513460019090" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;This business is a "one stop shop" of malwares, where victims will definitely get a bunch of different threats including &lt;a href="http://blog.iantivirus.com/2008/01/malware-retailers-includes-trojan-for.html"&gt;Trojan DNSChanger&lt;/a&gt; for Mac users. &lt;span&gt;&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://blog.iantivirus.com/2008/01/pay-per-install-malware-retail-business.html"&gt;&lt;/a&gt;&lt;/span&gt;&lt;span&gt;&lt;a href="http://blog.iantivirus.com/2008/01/pay-per-install-malware-retail-business.html"&gt;$$ business&lt;/a&gt; &lt;a href="http://blog.iantivirus.com/2008/02/click-and-link-to-malware.html"&gt;continuous&lt;/a&gt;! &lt;/span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/02/malware-retailer-update-dear-partner.html" title="Malware Retailer Update: Dear Partner" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/2152237744869814552/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/2152237744869814552" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/2152237744869814552?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;DE4CSHo5eSp7ImA9WxZQE0Q.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-4047399246454907054</id><published>2008-02-17T19:48:00.000-08:00</published><updated>2008-02-18T20:56:09.421-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-02-18T20:56:09.421-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="rick astley" /><category scheme="http://www.blogger.com/atom/ns#" term="funny rick" /><category scheme="http://www.blogger.com/atom/ns#" term="joke in mac" /><category scheme="http://www.blogger.com/atom/ns#" term="clickme" /><category scheme="http://www.blogger.com/atom/ns#" term="rick roll" /><category scheme="http://www.blogger.com/atom/ns#" term="joke programs" /><category scheme="http://www.blogger.com/atom/ns#" term="never gonna give you up" /><title>Cross Platform Joke</title><content type="html">&lt;div style="text-align: justify;"&gt;Do you know what is a Joke Programs ?&lt;br /&gt;&lt;br /&gt;&lt;span&gt;Joke programs is designed to frighten or embarrass a user -- creating a virus like symptoms and causes interruption to people's work. This is the reason why most security software detects it. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This programs are not malwares and definitely poses no threat to computers. They could be in different file format such as executable binaries like .EXE, office documents like .PPT and web-base. Most known joke programs are limited to Windows OS, but with the spurring popularity of Mac, cross-platform is now a consideration.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: center;"&gt;&lt;span&gt;~~o~~&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span&gt;Last week in yahoo group somebody asked this question, "Can you access this site http://www.internetisseriousbusiness.com ?" Few minutes later, people started to send their replies and one member said "This is the worst thing I've done".&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: center;"&gt;&lt;span&gt;&lt;a href="http://blog.iantivirus.com/" title="RickRoll"&gt;&lt;img src="http://picasion.com/pic1/9747760b83ed80008664b6626c9ebc97.gif" alt="make avatar" border="0" height="311" width="400" /&gt;&lt;br /&gt;&lt;/a&gt;&lt;/span&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;So, what happened?&lt;br /&gt;&lt;br /&gt;Once you visited the site, it will resize your browser window to 640x480 and it will start moving to every corner of your computer screen while playing a music video "Never Gonna Give You Up" by Rick Astley.&lt;br /&gt;&lt;br /&gt;The annoying thing about this website is that it does not allow user to change the url link or close the window and everytime the user attempt to do so, it will display a message box with the song lyrics on it. So, the only way out is to manually terminate the process of your browser. How does that sound to you?&lt;br /&gt;&lt;br /&gt;Inspecting the source code of the page, you will see that it does not contain any malicious code that poses threat to its users. Instead, it is just an annoying web-base cross platform joke!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bp0.blogger.com/_5MH3NxS8hN8/R7pG3cxDD2I/AAAAAAAAATI/VERHY3NNoD8/s1600-h/source.PNG"&gt;Here&lt;/a&gt; is the source code of the page.&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;Furthermore, searching in Google using the keyword "We're no strangers to love by Rick" you will find the first result links to another page &lt;span style="font-style: italic;"&gt;http://smouch.net/lol &lt;/span&gt; that &lt;http: net="" lol=""&gt;does exactly the same.&lt;br /&gt;&lt;/http:&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_5MH3NxS8hN8/R7pVGMxDD4I/AAAAAAAAATY/yU1mLWwIxhk/s1600-h/google.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_5MH3NxS8hN8/R7pVGMxDD4I/AAAAAAAAATY/yU1mLWwIxhk/s400/google.png" alt="" id="BLOGGER_PHOTO_ID_5168537087355588482" border="0" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Stay away from these sites!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.blogger.com/blog.iantivirus.com/" title="Joke Program"&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;/a&gt;&lt;/div&gt;</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/02/cross-platform-joke.html" title="Cross Platform Joke" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/4047399246454907054/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/4047399246454907054" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/4047399246454907054?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry><entry gd:etag="W/&quot;DUMEQnw8cCp7ImA9WxZRGUg.&quot;"><id>tag:blogger.com,1999:blog-1155203086394184661.post-142964659223654877</id><published>2008-02-13T15:52:00.000-08:00</published><updated>2008-02-13T18:50:03.278-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-02-13T18:50:03.278-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="IP-base website" /><category scheme="http://www.blogger.com/atom/ns#" term="storm worm" /><category scheme="http://www.blogger.com/atom/ns#" term="valentine.exe" /><category scheme="http://www.blogger.com/atom/ns#" term="crapware" /><category scheme="http://www.blogger.com/atom/ns#" term="your valentine" /><category scheme="http://www.blogger.com/atom/ns#" term="spam email" /><category scheme="http://www.blogger.com/atom/ns#" term="junkware" /><category scheme="http://www.blogger.com/atom/ns#" term="falling in love" /><category scheme="http://www.blogger.com/atom/ns#" term="storm greetings" /><title>Happy Valentine's Day From Storm Worm</title><content type="html">&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_5MH3NxS8hN8/R7OhhMxDD0I/AAAAAAAAAS4/NpC-0DxxAJw/s1600-h/6gif.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp0.blogger.com/_5MH3NxS8hN8/R7OhhMxDD0I/AAAAAAAAAS4/NpC-0DxxAJw/s400/6gif.png" alt="" id="BLOGGER_PHOTO_ID_5166650789258792770" border="0" /&gt;&lt;/a&gt;Storm Worm has been waiting for this day. It's been spamming about Valentine's Day since early January with email subjects "Falling In Love with You", "Heavenly Love", "Sent with Love", "You're the One", "Our Love Will Last", "A Toast My Love", "Our Love is Strong" and "Your Love Has Opened" .&lt;br /&gt;&lt;br /&gt;The email content will always have a url link that points to a malicious website that displays a red heart.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://blog.iantivirus.com/" title="make avatar"&gt;&lt;img src="http://picasion.com/pic1/b99a8484df8a2f1ec509e41394e60a52.gif" alt="make avatar" border="0" height="217" width="300" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;div style="text-align: justify;"&gt;However this week, Storm Worm delivers eight different images for this awaited occasion.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://blog.iantivirus.com/" title="StormGreets"&gt;&lt;img src="http://picasion.com/pic1/5b52157496f6df2120958cd57c49a954.gif" alt="make avatar" border="0" height="254" width="300" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;A vulnerable user clicking an IP-based website from the spammed email will certainly experience Storm Valentine's Day greetings with a downloading executable "valentine.exe". This executable is a high risk mass-mailing worm currently affecting Windows platform.&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_5MH3NxS8hN8/R7OOzsxDDzI/AAAAAAAAASw/q0B5fWQwbVc/s1600-h/Picture+3.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_5MH3NxS8hN8/R7OOzsxDDzI/AAAAAAAAASw/q0B5fWQwbVc/s400/Picture+3.png" alt="" id="BLOGGER_PHOTO_ID_5166630216365444914" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;This threat does not affect Mac OS X users but definitely a piece of junk that will stay in the download folder.&lt;br /&gt;&lt;br /&gt;Stay safe online!</content><link rel="alternate" type="text/html" href="http://blog.iantivirus.com/2008/02/happy-valentines-day-from-storm-worm.html" title="Happy Valentine's Day From Storm Worm" /><link rel="replies" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/142964659223654877/comments/default" title="Post Comments" /><link rel="self" type="application/atom+xml" href="http://blog.iantivirus.com/feeds/posts/default/142964659223654877" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1155203086394184661/posts/default/142964659223654877?v=2" /><author><name>Methusela Cebrian Ferrer</name><email>noreply@blogger.com</email></author></entry></feed>
