PDA

View Full Version : Be careful with links here:



Mtnjim
02-28-2007, 02:53 PM
A variant of

the Trojan horse attacks known as Storm Worm emerged Monday, targeting people who post blogs and notices to bulletin

boards.

Storm Worm emerged in January and raged across the globe in the form of e-mails with attachments that,

when opened, loaded malicious software onto victims' PCs, commandeering the machines so they could be used for

further attacks.

The new Storm Worm variant attacks the machines of unsuspecting users when they open an e-mail

attachment, click on a malicious e-mail link or visit a malicious site, said Dmitri Alperovitch, principal research

scientist at Secure Computing.

But the twist comes when these people later post blogs or bulletin board notices.

The software will insert into each of their postings a link to a malicious Web site, said Alperovitch, who rates the

threat as "high."

"We haven't seen the Web channel used before," he said. "In the past, we've seen malicious

links distributed to people in a user's address book and made to look like it's an instant message coming from

them."

The danger in this most recent case, he added, is that the user is actually posting a

legitimate blog or bulletin board notice, unaware that a malicious link has been slipped into the text of the

posting.

belgareth
02-28-2007, 03:00 PM
Thanks for posting that. We've

seen it a few times but I didn't realize it was so widely spread.

Have you run across Spydawn yet? What a pain

in the butt!

Mtnjim
02-28-2007, 03:25 PM
Have you run

across Spydawn yet? What a pain in the butt!

Not yet, but then again I lock down our machines pretty

tight and our anti virus software is pretty good, it checks for updates every 2 hours.

belgareth
02-28-2007, 04:22 PM
I don't have that privilage.

Clients do some amazing things to their computers, usually exactly what I told them not to do. Then, when they've

screwed it up really well they can't understand why it took three hours to fix it and I couldn't just tell them

what to do over the phone.

For everybody else:
Spydawn downloads to your computer when you think you are

downloading an audio or video codex. It has a high threat level because it communicates with the outside on its own

and can send your personal information. It creates pop ups that tell you your computer is infected and needs to be

scanned by their program. That simply downloads more garbage to your computer.