Researcher Offers Malware Analysis Tool

Friday, July 18th, 2008

The problem with hunting for malware is that most currently available analysis tools tip off the attacker that you're doing it. But at next month's Black Hat conference, a researcher will release a tool that is harder to detect -- and harder to avoid -- than the malware analyzers currently ...

YAMSIA (Yet Another Massive SQL Injection Attack)

Friday, July 18th, 2008

Clever mnemonics aside, last week we have seen another large scale SQL injection attack (or YAMSIA, if you prefer), this time being orchestrated by a botnet that has become known as Asprox—but first, a history lesson. The code behind the Asprox botnet seems to have been around for quite some time ...

New Worm Transcodes MP3s to Try to Infect PCs

Friday, July 18th, 2008

A new kind of malicious software could pose a danger to Windows users who download music files on peer-to-peer networks. The new malware inserts links to dangerous Web pages within ASF (Advanced Systems Format) media files. "The possibility of this has been known for a little while but this is the first ...

Darik’s Boot and Nuke Securely Wipes Your System in an Emergency

Thursday, July 17th, 2008

Free, open-source boot disk utility Darik's Boot and Nuke (DBAN) automatically and completely deletes the content of every hard disk it can find on your computer when you run it. Sure you can fire up DBAN for emergency system wipes next time the feds come knocking on your door, but ...

Microsoft Office Security Team Enlists Bots, Pen Tests

Thursday, July 17th, 2008

Storm, Srizbi, and... Microsoft? Microsoft’s Office application security team actually runs its own internal botnet, which, among other things, “fuzzes” for vulnerabilities in Office applications. Microsoft’s botnet isn’t anywhere near the size of Srizbi (over 300,000 bots at last count) nor any of the other mega-botnets -- it’s just a couple ...