Proaktiv IT-sikkerhet

Sikkerhetssenter

Nyeste artikler - Malware discussion

Handling an infected computer as an infected human being

2010-03-11

The RSA Conferences are among of the most important annual security conferences. This year's US conference was held in San Francisco 1 - 5 March. One of the speakers was Microsoft's Scott Charney, Corporate Vice President Trustworthy Computing. His speech covered several interesting topics, of which we will discuss one: the ability, usefulness and implications of treating infected computers in a similar manner as infected human beings.

mer >>

Code injection

2010-03-01

Code injection is a protection mechanism used by malware in order to avoid detection. The injector stores the malware as an encrypted resource, which it decrypts and injects into a running process. The injector may also contain various checks for virtual machines and system tools in order to hinder analysis.

mer >>

W32/Zimuse

2010-02-10

Zimuse is a family of worms that performs destructive overwrites of the Master Boot Record of disk drives on the infected system. If the current system date and time matches certain conditions, the worm overwrites the Master Boot Record of available drives with its own data. The worm will also try to delete some of the important files of the Windows Operating system. The file is run-time compressed using PECompact arrives on the system either as a standalone file (possibly from a malicious download or e-mail) or by infected removable devices (e.g., USB sticks).

mer >>

Aurora Attack - Zero day exploit in IE6

2010-02-04

Aurora attacks, which is known to be originated from china, is a major attack in the recent past which used an Internet explorer exploit code to attack companies like Google and Adobe and succeeded in stealing some intellectual properties.

mer >>

Nyeste blogg-innlegg [EN]

Shockwave Flash (SWF) Exploit

2010-03-04
Impact: Moderate Application: Adobe Flash Player 9.0.115.0 and earlier Vulnerability identifier: APSB08-11 CVE Number: CVE-2007-0071 Vulnerability details Adobe Flash Player is vulnerable to buffer ov...
mer >>

Internet Explorer (6/7/8) Remote Code Execution - Remote User Add Exploit

2010-03-04
Objective A malicious web site can be crafted using an exploit code that will allow IE (Internet Explorer) to be compromised and allow code to be executed on your computer. The more severe vulnerabili...
mer >>

Google Buzz and Reader CSRF Vulnerability

2010-02-26
Google recently launched a Twitter-like application called Google Buzz. We have established that the application is quite vulnerable to persistent CSRF attacks when data is pulled from external data f...
mer >>