<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>Shanktified! &#187; Virus Warning</title> <atom:link href="http://www.shanktified.com/archives/category/security/virus-warning/feed" rel="self" type="application/rss+xml" /><link>http://www.shanktified.com</link> <description>The personal thoughts, opinions and typos of Ron Shank</description> <lastBuildDate>Mon, 26 Apr 2010 18:09:09 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>[now fixed] Facebook refuses to fix obvious security flaw</title><link>http://www.shanktified.com/archives/facebook-refuses-to-fix-obvious-security-flaw</link> <comments>http://www.shanktified.com/archives/facebook-refuses-to-fix-obvious-security-flaw#comments</comments> <pubDate>Tue, 26 Aug 2008 01:39:48 +0000</pubDate> <dc:creator>Ron Shank</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Tech Support]]></category> <category><![CDATA[Virus Warning]]></category> <category><![CDATA[Facebook]]></category> <category><![CDATA[Internet Security]]></category> <category><![CDATA[MySpace]]></category><guid
isPermaLink="false">http://www.shanktified.com/archives/facebook-refuses-to-fix-obvious-security-flaw/</guid> <description><![CDATA[[ UPDATE:  Facebook has reversed itself and fixed this vulnerability ] ZDNet.com reports: The Register’s Dan Goodin has the scoop on an obvious security vulnerability that’s being ignored by the powers at Facebook. The issue, as demonstrated by this proof-of-concept, shows how a social network application can be rigged to hijack a Facebook user’s session [...]]]></description> <content:encoded><![CDATA[<p><strong>[ UPDATE:  Facebook has reversed itself and fixed this vulnerability ] </strong></p><p><a
href="http://blogs.zdnet.com/security/?p=1793">ZDNet.com</a> reports:</p><blockquote><p>The Register’s Dan Goodin has the scoop on an obvious security vulnerability that’s being ignored by the powers at Facebook.</p><p>The issue, as demonstrated by this proof-of-concept, shows how a social network application can be rigged to hijack a Facebook user’s session identification cookies, deliver pop-up messages or change the color of Facebook pages.  <span
id="more-450"></span></p><p>“With a little extra work, an attacker could probably do much more, including send and read messages from a user’s account, change privacy settings and add or delete Facebook friends,” according to the report.</p><p>When I tested the code while logged in to Facebook, it worked as advertised and proves conclusively that Facebook fails to sanitize the content of third-party applications.  This exposes Facebook’s massive user base to a variety of hacker attacks.</p></blockquote><p><a
href="http://blogs.zdnet.com/security/?p=1793">Wanna know what other web worms are squirming through Facebook, My Space and More?</a></p> <img
src="http://www.shanktified.com/?ak_action=api_record_view&id=450&type=feed" alt="" />]]></content:encoded> <wfw:commentRss>http://www.shanktified.com/archives/facebook-refuses-to-fix-obvious-security-flaw/feed</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>The ugly truth: Satan, social networks and security</title><link>http://www.shanktified.com/archives/the-ugly-truth-satan-social-networks-and-security</link> <comments>http://www.shanktified.com/archives/the-ugly-truth-satan-social-networks-and-security#comments</comments> <pubDate>Mon, 25 Aug 2008 21:34:04 +0000</pubDate> <dc:creator>Ron Shank</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Tech Support]]></category> <category><![CDATA[Virus Warning]]></category> <category><![CDATA[Facebook]]></category> <category><![CDATA[Internet Security]]></category> <category><![CDATA[MySpace]]></category><guid
isPermaLink="false">http://www.shanktified.com/?p=440</guid> <description><![CDATA[This is mostly a geek-read, so let me sum it up for you.  The more apps you add to facebook and myspace, the less safe you are.  Don&#8217;t add people you don&#8217;t know well (ouch, log in my own eye) and use unique passwords for each account. This or this may help. &#8220;A quick (and [...]]]></description> <content:encoded><![CDATA[<p>This is mostly a geek-read, so let me sum it up for you.  The more apps you add to facebook and myspace, the less safe you are.  Don&#8217;t add people you don&#8217;t know well (ouch, log in my own eye) and use unique passwords for each account. <a
href="http://keepass.info/">This</a> or <a
href="http://www.keepassx.org/">this</a> may help.</p><blockquote><p>&#8220;A quick (and very much incomplete) hall of shame here includes MySpace, LiveJournal, and Hi5, all of which we’re surprised haven’t sunk into the East Bay under the weight of their own pwnability.&#8221;</p></blockquote><p><a
href="http://blogs.zdnet.com/feeds/?p=199&amp;page=2">More here &gt;&gt; The ugly truth: Satan, social networks and security</a>.</p> <img
src="http://www.shanktified.com/?ak_action=api_record_view&id=440&type=feed" alt="" />]]></content:encoded> <wfw:commentRss>http://www.shanktified.com/archives/the-ugly-truth-satan-social-networks-and-security/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Trojan Horse SHeur.bzpu is a backdoor trojan</title><link>http://www.shanktified.com/archives/trojan-horse-sheurbzpu-is-a-backdoor-trojan</link> <comments>http://www.shanktified.com/archives/trojan-horse-sheurbzpu-is-a-backdoor-trojan#comments</comments> <pubDate>Mon, 04 Aug 2008 15:39:27 +0000</pubDate> <dc:creator>Ron Shank</dc:creator> <category><![CDATA[Tech Support]]></category> <category><![CDATA[Virus Warning]]></category><guid
isPermaLink="false">http://www.shanktified.com/archives/trojan-horse-sheurbzpu-is-a-backdoor-trojan/</guid> <description><![CDATA[We thought it might be an AVG false positive, but thanks to a helpful comment from Martyn (here)  we now know that&#8217;s not the case. SHeur.bzpu is a backdoor trojan http://www.microsoft.com/security/portal/SearchResults.aspx?query=SHeur.bzpu Backdoor:Win32/Nuwar.gen!D Aliases: SHeur.BCFX (AVG) Description: Backdoor:Win32/Nuwar.gen!D is a generic detection for a backdoor trojan that allows unauthorized access to an infected computer. The trojan [...]]]></description> <content:encoded><![CDATA[<p>We thought it might be an AVG false positive, but thanks to a helpful comment from Martyn (<a
href="http://www.shanktified.com/archives/trojan-horse-sheurafj-false-positive-within-quickbooksquickin/#comment-39726">here</a>)  we now know that&#8217;s not the case.</p><p><strong>SHeur.bzpu is a backdoor trojan</strong></p><p><a
href="http://www.microsoft.com/security/portal/SearchResults.aspx?query=SHeur.bzpu  ">http://www.microsoft.com/security/portal/SearchResults.aspx?query=SHeur.bzpu</a></p><blockquote><p>Backdoor:Win32/Nuwar.gen!D</p><p>Aliases: SHeur.BCFX (AVG)</p><p>Description: Backdoor:Win32/Nuwar.gen!D is a generic detection for a backdoor trojan that allows unauthorized access to an infected computer. The trojan receives commands indirectly from a remote attacker via its connection to a malicious peer-to-peer network. This trojan also contains advanced stealth…</p></blockquote><blockquote><p>Published Date: 06/16/2008</p><p>Severity Rating: Medium</p></blockquote> <img
src="http://www.shanktified.com/?ak_action=api_record_view&id=413&type=feed" alt="" />]]></content:encoded> <wfw:commentRss>http://www.shanktified.com/archives/trojan-horse-sheurbzpu-is-a-backdoor-trojan/feed</wfw:commentRss> <slash:comments>15</slash:comments> </item> <item><title>Optimus Media News » FBI Warns of Storm Worm Virus</title><link>http://www.shanktified.com/archives/optimus-media-news-%c2%bb-fbi-warns-of-storm-worm-virus</link> <comments>http://www.shanktified.com/archives/optimus-media-news-%c2%bb-fbi-warns-of-storm-worm-virus#comments</comments> <pubDate>Thu, 31 Jul 2008 13:54:50 +0000</pubDate> <dc:creator>Ron Shank</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Tech Support]]></category> <category><![CDATA[Virus Warning]]></category> <category><![CDATA[FBI vs Facebook]]></category> <category><![CDATA[Virus Alert]]></category><guid
isPermaLink="false">http://www.shanktified.com/archives/optimus-media-news-%c2%bb-fbi-warns-of-storm-worm-virus/</guid> <description><![CDATA[The Federal Bureau of Investigation and its partner, the Internet Crime Complaint Center (IC3), have received reports of recent spam e-mails spreading the Storm Worm malicious software, known as malware. These e-mails, which contain the phrase “F.B.I. vs. facebook,” direct e-mail recipients to click on a link to view an article about the FBI and [...]]]></description> <content:encoded><![CDATA[<p>The Federal Bureau of Investigation and its partner, the Internet Crime Complaint Center (IC3), have received reports of recent spam e-mails spreading the Storm Worm malicious software, known as malware. These e-mails, which contain the phrase “F.B.I. vs. facebook,” direct e-mail recipients to click on a link to view an article about the FBI and Facebook, a popular social networking website. The Storm Worm virus has also been spread in the past in e-mails advertising a holiday e-card link. Clicking on the link downloads malware onto the Internet connected device, causing it to become infected with the virus and part of the Storm Worm botnet.</p><p>“The spammers spreading this virus are preying on Internet users and making their computers an unwitting part of criminal botnet activity. We urge citizens to help prevent the spread of botnets by becoming web-savvy. Following some simple computer security practices will reduce the risk that their computers will be compromised,” said Special Agent Richard Kolko, Chief, FBI National Press Office.</p><p>Everyone should consider the following:</p><blockquote><p>* Do not respond to unsolicited (spam) e-mail.</p><p>* Be skeptical of individuals representing themselves as officials soliciting personal information via e-mail.</p><p>* Do not click on links contained within an unsolicited e-mail.</p><p>* Be cautious of e-mail claiming to contain pictures in attached files, as the files may contain viruses. Only open attachments from known senders.</p><p>* Validate the legitimacy of the organization by directly accessing the organization’s website rather than following an alleged link to the site.</p><p>* Do not provide personal or financial information to anyone who solicits information.</p></blockquote><p><a
href="http://optimusmedia.com/news/archives/31">More here: Optimus Media News » FBI Warns of Storm Worm Virus</a>.</p> <img
src="http://www.shanktified.com/?ak_action=api_record_view&id=402&type=feed" alt="" />]]></content:encoded> <wfw:commentRss>http://www.shanktified.com/archives/optimus-media-news-%c2%bb-fbi-warns-of-storm-worm-virus/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>New Worm Infects Audio Files</title><link>http://www.shanktified.com/archives/new-worm-infects-audio-files</link> <comments>http://www.shanktified.com/archives/new-worm-infects-audio-files#comments</comments> <pubDate>Wed, 16 Jul 2008 15:43:05 +0000</pubDate> <dc:creator>Ron Shank</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Virus Warning]]></category><guid
isPermaLink="false">http://www.shanktified.com/?p=308</guid> <description><![CDATA[WMA&#8217;s (windows media audio) are carrying a trojan/worm.   When I have to clean someone PC, it&#8217;s usually because they were downloading illegal music downloads.  Click here to read the rest of the story.]]></description> <content:encoded><![CDATA[<p>WMA&#8217;s (windows media audio) are carrying a trojan/worm.   When I have to clean someone PC, it&#8217;s usually because they were downloading illegal music downloads.  <a
href="http://optimusmedia.com/news/?p=14">Click here to read the rest of the story. </a></p> <img
src="http://www.shanktified.com/?ak_action=api_record_view&id=308&type=feed" alt="" />]]></content:encoded> <wfw:commentRss>http://www.shanktified.com/archives/new-worm-infects-audio-files/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Trojan Horse SHeur.AFJ (false positive within Quickbooks/Quickin)</title><link>http://www.shanktified.com/archives/trojan-horse-sheurafj-false-positive-within-quickbooksquickin</link> <comments>http://www.shanktified.com/archives/trojan-horse-sheurafj-false-positive-within-quickbooksquickin#comments</comments> <pubDate>Sat, 14 Jul 2007 14:22:23 +0000</pubDate> <dc:creator>Ron Shank</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Tech Support]]></category> <category><![CDATA[Virus Warning]]></category> <category><![CDATA[Internet Safety]]></category> <category><![CDATA[Virus Alert]]></category><guid
isPermaLink="false">http://www.shanktified.com/archives/trojan-horse-sheurafj-false-positive-within-quickbooksquickin/</guid> <description><![CDATA[There are a growing number of reports that this is a false positive within AGV. I&#8217;ll update you with more soon, but for now check out this excellent post on the topic (translated to English here). Complete with screen shots and search engine analysis. Please leave a comment if you have any information to share. [...]]]></description> <content:encoded><![CDATA[<p>There are a growing number of reports that this is a false positive within AGV.</p><p>I&#8217;ll update you with more soon, but for now check <a
href="http://www.jonnyken.com/infoblog/2007/07/13/virus-novo-na-praca-trojan-horse-sheurafj/" target="_blank">out this excellent post</a> on the topic (<a
href="http://64.233.179.104/translate_c?hl=en&amp;u=http://www.jonnyken.com/infoblog/2007/07/13/virus-novo-na-praca-trojan-horse-sheurafj/&amp;prev=/search%3Fq%3Dsheur%2Btrojan%2Bhorse%26start%3D10%26hl%3Den%26rls%3DHPIA,HPIA:2006-36,HPIA:en%26sa%3DN">translated to English here</a>).  Complete with screen shots and search engine analysis.</p><p><strong>Please leave a comment if you have any information to share</strong>. <a
href="http://forum.grisoft.cz/freeforum/read.php?4,103761,103961">Unlike the AVG Forum</a>, stupid questions will not be deleted nor the questioners abused.  We were all stupid at some point so, chill-out folks.</p><p>Update: I have found AVG to do find this with multiple PCs in separate locations.  It&#8217;s definitely a false positive (misreading from the AVG software).   (A note to AVG users, don&#8217;t let this bother you, I&#8217;ve been using AVG for years and I think this is only the 2nd time Its found a false positive.)</p><p>Another Update: AVG will not quarantine Quickbooks files, but it will quarantine Quicken files automatically (in many cases).  If you get a message that says the files were deleted you can get them out of AVG&#8217;s Virus Vault.</p><p>Update #3: <a
href="http://quickbooksgroup.com/webx/forums/QuickBooks%20Performance%20Issues%20and%20Program%20Errors/52960">I see that the folks at Quickbooks are aware of the issue and are working with AVG to repair it</a>.</p> <img
src="http://www.shanktified.com/?ak_action=api_record_view&id=222&type=feed" alt="" />]]></content:encoded> <wfw:commentRss>http://www.shanktified.com/archives/trojan-horse-sheurafj-false-positive-within-quickbooksquickin/feed</wfw:commentRss> <slash:comments>40</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced (User agent is rejected)
Database Caching 7/17 queries in 0.008 seconds using disk: basic

Served from: www.shanktified.com @ 2012-02-08 11:33:08 -->
