31
Jan

Grew/Nyxem/Blackmal Worm File Deletion on Feb. 3

Antivirus companies warn users about the dangerous payload of the Grew/Nyxem/Blackmal worm. On February 3, 2006 and on the 3rd month thereafter, or 30 minutes after the computer has been restarted, it is scheduled to delete and overwrite common document files (.DOC, .XLS, .PPT, .ZIP and others) with the string “DATA Error [47 0F 94 93 F4 K5]”.

Also, it disables the mouse and the keyboard, deletes files and registry entries of antivirus products, and closes AV windows so that users can’t use them.

Trend Micro’s description for this worm is here.

Best bet: update your AV product then perform a full scan on all of your hard drives. Back up your important or sensitive documents.

27
Jan

Yet Again Another Yahoo! Phishing Attempt

Thanks to Rocky for pointing another desperate attempt to steal Yahoo! login credentials. This link is sent via Yahoo! Messenger. Here’s how the page looks like:


Image hosting by Photobucket

(Click the image to enlarge)

Take note of the URL and the usual Yahoo! Geocities ads at the right.

When a user enters his credentials and clicks on Sign In, the trouble begins. The user is directed at another page of similar nature, only that the pictures are different.


Image hosting by Photobucket

Same link, different page. When you try logging in again, you are directed to an login error message page.


Image hosting by Photobucket

So what happens to the data entered? Now, when you click on Sign In for the first time, Internet Explorer’s status bar displays this:


Image hosting by Photobucket

It is sent to a CGI script! Uh oh. The URL of the CGI script is not apparent when you view the HTML source, since the link was encoded using HTML hexadecimal notation. We can suppose that the CGI script is a mailing script, where it sends the stolen info to an email address which was encoded in the HTML form using the tag. In this image, I highlighted the relevant info that made me arrive at the supposition made earlier.

Image hosting by Photobucket

In the form tag, there is an ACTION attribute, and it is set to a long series of characters in HTML hexadecimal notation. It points to the link you saw in the status bar image. There are four INPUT tags of type HIDDEN – that means these form objects are not visible to the user. Take note of the one whose value is set to a certain email address.

The link was spread via Yahoo! Messenger. Maybe it was a social engineering technique – one user enticing another to send the link. Maybe it was a malware that was somehow capable of interfacing with YM. Checking on the address bar of the browser is no guarantee. There are very good phishing sites that are able to interpose a window so that the true URL is hidden.

Good thing Yahoo! Geocities is ad-supported.

Be careful, again.

21
Jan

LiveJournal Accounts Hijacked Due to XSS Holes

In a blog, a group of hackers known as “Bantown” has hacked “900,000 LJ accounts” to demonstrate that LiveJournal (LJ) is susceptible to cross-site scripting (XSS) through JavaScript. As an LJ user, this is troubling. While LJ claims that these holes were plugged, Bantown claims there are several holes still unplugged.

One of LJ’s solution is to use a new user subdomain.

LJ users: either have a backup blog (try Blogspot, or WordPress.com) or back up your entries. As on how to back up your entries: frankly, the only way I know is copy-paste. Also, Multiply has a feature where you can import your LJ blog to your Multiply blog (if you have an account).

The blog entry is here. Said link is also quoted at the LJ Infosec community.

11
Jan

A New Cellphone – Dead After A Year

What would you do if you find yourself having bought a new cellphone that was the first and the last in line?

Introducing the Nokia 7710:
Continue reading

5
Jan

Mr. Columnist, Just Plant Trees

Let me rant against a certain columnist in a certain newspaper (nope, I won’t be naming the columnist nor the newspaper).

Sen. Ping Lacson is upset that GMA is claiming credit for the strong peso. Actually, it’s not GMA who’s saying it but Toting Bunye who is paid to tell lies like that fellow Comical Ali, Saddam Hussein’s spokesman who, during the closing days of the Iraq invasion by the US allied forces, was insisting that the American troops were getting a beating and about to retreat.

Hay. Mr. Columnist: Mr. Liar-Liar Bunye is acting in behalf and as an extension of GMA. Who are you kidding.

He also ranted against UNICEF and other related organizations:

There are many organizations receiving such tax-free funds from kind donors who do not seem to require any audited or verifiable report on the expenditures. How about a financial report from the Unicef so we don’t suspect that the funds are merely going to salaries and perks of the people behind this organization? For example, P20,000/day was spent for child protection. Who were the children protected and who were paid to protect them and how much? The sum of P7,575,961.32 was spent for education. Can we get a list of the children and the schools which received the funds and how much each? P18,193,313.80 was spent as relief to communities affected by tsunami and typhoon. Again, can we see the list of communities? Were they given cash or goods? P7,966,367 was channeled to unspecified projects where assistance was most needed. Hey how about some real accounting report?

So he wants exactness and specificity. But take note of the next:

There’s no use railing against the GMA administration. As long as there is no credible opposition party with alternative programs to offer, the masses will just ignore all those reported scandals, corruption and misgovernance. The much vaunted NPs and LPs are perceived as no better, nothing more than a bunch of politicians just waiting for the chance to get into power. As one memorable “trapo [traditional politician]” was quoted as saying, “You people in the administration have all been stealing us blind all these years, how about giving us a chance naman?”

Tell me if he is consistent or not. He wants UNICEF to state the names of its beneficiaries, as if he was a major donor. Fine, that is good. But to quote a certain trapo and not even have the balls to state the name is pushing his unfairness too far. Di ba, kung gusto mo specific reports from others, why can’t you be so specific yourself? You are actually implying that UNICEF and other orgs are just making reports to cover their asses. And here you are, covering your ass by not telling the name of the trapo that you quoted. Are you afraid of libel?

We need to know so that (1) we won’t elect him if he runs for an office, or (2) we would not listen to him ever.

Hay, opinions. Good columnists are CONSISTENT (think de Quiros). Guys like Mr. Columnist are just killing trees.

3
Jan

A New Year Quote

This new year, may people ponder on this quote by Hellen Keller:

Science may have found a cure for most evils; but it has found no remedy for the worst of them all – the apathy of human beings.