Showing posts with label attack. Show all posts
Showing posts with label attack. Show all posts

Tuesday, September 21, 2010

Twitter under attack, stop using Twitter.com until the problem is fixed.

If you're an user of Twitter, you probably observed today that many of the persons you follow are tweeting strange things. The idea is that there's an exploit in Twitter.com responsible for that. More exactly, the website fails to disallow the "onMouseOver" JavaScript command, which means that if you move the mouse over the offending tweet, you'll automatically retweet that tweet or you will be redirected to another website.

This is how a message like that looks like (DO NOT click on that links!!):
http://a.no/@"onmouseover=";$('textarea:first').val(this.innerHTML);$('.status-update-form').submit()" style="color:#000;background:#000;/
or another one:
http://t.co/@"onmouseover="document.getElementById('status').value='RT Unlevin ';$('.status-update-form').submit();"class="modal-overlay"/
It seems that most third party clients aren't affected by the exploit. Stop using Twitter's official website for now, as the strange messages are still coming in. Anyway, DO NOT click on the websites that tweets are linking to, they can possibly try to insert malicious code in your computer.

Twitter didn't announce anything about this until now, but they'll surely notify users when Twitter.com is safe, so follow status.twitter.com for latest news.

Friday, February 26, 2010

Many Twitter accounts were compromised. Again!

After the problem that Twitter had the latest weekend with that phishing attack, Twitter faces now with another one. It consists into sending people DM's with the following content: "hey, i've been having better sex and longer with this here" or "Get bigger and have sex longer", followed by a link that changes continuously. It is not certain on which website you will be redirected to by clicking that link.

This attack is important because anyone can be affected and if you receive one of that DM's from someone you know and trust, your first intention will be to open it. It is not sure, but this attack may have connection to the earlier one.

If you think that your account has been compromised, change your password immediately.

Sunday, February 21, 2010

Twitter is under a phishing attack.

In this period an attack is developing on Twitter. It consists into receiving direct messages containing "lol, is that you" or "lol, this is funny, followed by a link. When you enter the link, you will be asked to enter your user and password, and, after this procedure, your account will start sending the same messages. If you got the message, you shouldn't worry, but if your account starts sending these types of messages by its own, change your password immediately.

The messages will take you to a page from allinonecontracting.com, which links after to bzpharma.net. Anything you're doing, do NOT click on these links.

Saturday, January 16, 2010

What do you think about the latest attack against Google ?

As you probably know already, a few days ago there was an attack which came from China, against about 38 companies (announced till now), the most discussed being against Google. Many experts say that the attack has been one of the most sophisticated that took place in the last years. After Google confirmed the attack, they said that they think about closing their business in China. But this thing is almost impossible to happen (the probably said that because they were angry after the attack). The attack attempt to get access to Gmail accounts of Chinese human rights activists, which failed, says Google.


Another company attacked is Adobe, but it has less importance, everybody being focused especially on the attack against Google. The attack seems to came through Internet Explorer, many users being warned to stop using Internet Explorer until Microsoft launches a patch to fix the vulnerability which affects all versions (come on.... how many users are regularly updating Windows/Internet Explorer ?).

Tuesday, January 5, 2010

hi5update.exe, a new virus on HI5.

A new virus that attacks HI5 has been seen for the first time a few days ago. Users reported that it requests them to download "hi5update.exe" which will steal their password after installation. It has also been reported that the virus can be found on a few Romanian websites. The main idea is that you should NOT download an executable file which is named "hi5update.exe". I found informations about this virus from Romanian bloggers, who already submitted it to anti-virus companies in order to help them to offer users protection as soon as possible.


If you're already infected, try to do the following:

1)delete from C:\Windows\system32:
  • winlog.exe
  • boot.exe
2)delete from registry the following keys:
  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \Font
3) Get Kaspersky Virus Removal Tool 2010 from Softpedia, and run it: http://www.softpedia.com/get/Antivirus/Kaspersky-Virus-Removal-Tool.shtml .

More informations can be found here: http://devirusare.com/2010/01/03/hi5update-exe-devirusare/ (for Romanian users, others can use Google Translate).