Microsoft Windows Vista Community Forums - Vistaheads
Driver Scanner 2009 - Free Scan Now



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Overzlobbed, (Sun, Nov 18th)

Security News



Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Reply
  #1 (permalink)  
Old 11-18-2007
Steve's Avatar
Steve Steve is offline
Moderator
 
Join Date: Sep 2006
Location: Emerald Isle
Posts: 46,133
Steve is a jewel in the roughSteve is a jewel in the roughSteve is a jewel in the rough
Thanks: 7
Thanked 24 Times in 11 Posts
Overzlobbed, (Sun, Nov 18th)
Tomorrow, it will be a year since we first ran an analysis of the ZLOB family of trojans in the ISC diary. The write-up from back then is still an interesting read. While investigating today a few .edu sites with links to the latest ZLOB variant, it occurred to me how different these pages were compared to one year ago: Yes, there was obfuscation of JavaScript. But not too much - certainly not enough to cause any virus scanner to reject the page outright. Yes, there were the sleazy links, thousands of them, interlinking the pages to cause a good ranking in search engines. But there were none (none!) of the embedded IFRAMES with the latest collection of browser- and application exploits that such pages used to contain in the past, Zlob or not.
Thinking it over, this sort of makes sense: if you want to trick a user into (voluntarily!) downloading and installing a piece of malware that claims to be a video codec, you probably don't want to scare the user away from the sites that draw him into the spyderweb by having other malware or exploit attempts lighting up the user's anti-virus. The Zlob approach of propagating malware seems to have been quite successful for the bad guys: Not only are they still going strong more than a year after the first report, they also branched out to include Mac-OSX (diary) earlier this month.
Since the codec binaries change frequently and AV coverage is notoriously poor, the probably best defense in a corporate environment is to have a web filter in place that blocks access to porn pages. What used to be seen as a mere compliance measure to not to run afoul of sexual harassment rules at the workplace has long since turned into a cornerstone of most companies' malware defense.

More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Google XSS, (Sun, Nov 11th) Steve Security News 0 11-12-2007 01:02
Cyber Jihad? Yeah, right..., (Sun, Nov 11th) Steve Security News 0 11-11-2007 03:21
Daylight Saving Time Reminder for North America (with some exceptions), (Sun, Nov 4th) Steve Security News 0 11-04-2007 04:41
IE adoption rate, (Sun, Mar 18th) Steve Security News 0 03-19-2007 07:56
Sun Alert Notification Dated March 10th, 2007, (Sun, Mar 11th) Steve Security News 0 03-11-2007 22:30


All times are GMT +1. The time now is 05:26.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119