Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)
![]() ![]() |
Mar 21 2007, 01:02 PM
Post
#1
|
|
![]() AplusWebMaster ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,566 Joined: 30-December 03 From: USA Member No.: 1,643 Operating System: WinXP |
FYI...
> http://www.secureworks.com/research/threat...zi/?threat=gozi March 15, 2007 ~ "Russian malware authors are finding new ways to steal and profit from data which used to be considered safe from thieves because it was encrypted using SSL/TLS. Originally, this analysis intended to provide insight into the mechanisms used to steal that data, but it became an investigation into the growing trend of malware sold not as a product, but as a service. Eventually it lead to an alarming find and resulted in an active law enforcement investigation... Hosted web sites for recreational community forums and small businesses were found to host this exploit code. Because searches in known exploit and malware database produced no results, these were located with a script designed to "spider" some IP address ranges for hosted servers that are commonly compromised and used for this purpose. Since it is almost always hosted on the main page, only that page was searched... Based on domain names, we were able to retrieve the names of companies and organizations whose customers were affected. We found that over 5,200 home PC users, with 10,000 account records, were compromised and account and login information for applications offered by over 300 organizations was stolen through these infected home PCs. The information stolen contained everything from bank, retail and payment services account numbers, as well as social security numbers and other personal information. The records retrieved included account numbers and passwords from clients of many of the top global banks and financial services companies (over 30 banks and credit unions were represented), the top US retailers, and the leading online retailers. The stolen data also contained numerous user accounts and passwords for employees working for federal, state and local government agencies, as well national and local law enforcement agencies. The stolen data also contained patient medical information, via healthcare employees and healthcare patients, whose username and passwords had been compromised via their home PC. SecureWorks has contacted several of the companies affected and is working through various other channels, including law enforcement, to notify the remaining affected parties... A network-based IPS (intrusion prevention system) with well-designed countermeasures for these general types of exploits would have prevented the trojan executable from ever reaching a PC behind its protection, no matter how infrequently patched or updated... SecureWorks Research provides the following Snort rules as a public service..." (More detail at the URL above.) |
|
|
|
Mar 23 2007, 03:33 AM
Post
#2
|
|
![]() AplusWebMaster ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,566 Joined: 30-December 03 From: USA Member No.: 1,643 Operating System: WinXP |
|
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
2 | jincz | 34 | Today, 03:48 PM Last post by: LDTate |
|||
![]() |
20 | Ushio11 | 124 | Today, 02:45 PM Last post by: Rorschach112 |
|||
![]() |
11 | Sten | 75 | Today, 02:36 PM Last post by: Rorschach112 |
|||
![]() |
0 | monkeylicious | 5 | Today, 12:24 PM Last post by: monkeylicious |
|||
|
Time is now: 20th November 2008 - 05:17 PM |