Thursday, December 31, 2009

Why I browse using Firefox with NoScript: Fox Sports Web Site, NY Times ads Infected

Just one more reason to do all your Internet surfing as a non-administrative user, with Firefox, and using both the NoScript add-on and the Adblock Plus add-on:

Fox Sports Web Site Infected, Injected Code Serves Exploits | CyberInsecure.com
Security researchers warn that the Fox Sports website has been compromised by unknown attackers, who injected malicious code into a custom error page. There are two separate offensive script tags, each of them created by a different infection.

The page was detected by the ThreatSeeker Network system developed and operated by Websense, a Web security vendor. Security researchers investigating the suspicious link determined that it was pointing to a custom “Page not Found” document, displayed in case of a 404 error.

Webmasters deploy such pages in order to help visitors who are looking for a Web resource that is no longer available. They include suggestions or search boxes that can be used to find the new location of the document.

The msn.foxsports.com website is operated by the Fox Sports division of the Fox Broadcasting Company and according to Alexa, it is in the top 330 websites in the world as far as traffic goes. This website is ranked at position 88 in the United States and is part of the MSN network.


New York Times Site Pop-Up Says Your Computer Is Infected as documented here at NYTimes.com:

Note to Readers
Some NYTimes.com readers have seen a pop-up box warning them about a virus and directing them to a site that claims to offer antivirus software. We believe this was generated by an unauthorized advertisement and are working to prevent the problem from recurring. If you see such a warning, we suggest that you not click on it. Instead, quit and restart your Web browser. Questions and comments can be sent to webeditor@nytimes.com.


Seriously, if you're out there surfing, you really need to surf as a non-admin user to limit the damage malware can do to your computer. IE users should purchase and USE Sandboxie.

Monday, December 21, 2009

New free tool from Nirsoft to manage your Flash Cookies

New free tool from Nirsoft to manage your Flash Cookies. I use the BetterPrivacy add-on for Firefox to remove my Flash cookies and prevent cross-session tracking of what I do, and CCleaner is a good tool for manual clean-up of Flash Cookies. Adobe's tool to manage Flash Cookies is very poor compared to these tools

View the Flash cookies (Local Shared Object /.sol files) stored in your computer
FlashCookiesView is a small utility that displays the list of cookie files created by Flash component (Local Shared Object) in your Web browser. For each cookie file, the lower pane of FlashCookiesView displays the content of the file in readable format or as Hex dump.
You can also select one or more cookie files, and then copy them to the clipboard, save them to text/html/xml file or delete them.


More Flash Cookie links:

Sunday, December 20, 2009

Microsoft: How to install, reinstall, and uninstall Windows

Don't know how useful it will be to J. Random User, but Microsoft has a page out on the Third "R" of Windows, how to Reinstall Windows (The first two "R"s are "Retry" and "Reboot" -- if it doesn't work at that point, it's time to "Reinstall").  Can't tell you how many times I have installed Windows, but it's more times than I have fingers and toes ;-) [including at least once in the last 6 hours].

Install, reinstall, and uninstall Windows - Help & How-to - Microsoft Windows

Friday, December 18, 2009

Online Comics carry Adobe PDF infection ...

The final paragraph of this story has my preferred option: uninstall Adobe Reader and install Foxit Reader.  If you do that, please email me asking for my Foxit Reader Registry Hack which turns off the Foxit advertising panel and disables Javascript with two clicks.

Security Fix - Hackers exploit Adobe Reader flaw via comic strip syndicate
Hackers broke into an online comic strip syndication service Thursday, embedding malicious code that sought to exploit a newly discovered security flaw in Adobe Reader and Acrobat, Security Fix has learned.

On Monday, Adobe Systems Inc. said it was investigating reports that criminals were attacking Internet users via a previously unknown security flaw in its Adobe Reader and Acrobat software. Experts warned that the flaw could be used to foist software on unsuspecting users who visit a hacked or booby-trapped Web site.

... Adobe said it does not plan to issue a software update to fix the flaw until Jan. 12, 2010.

Adobe says turning off Javascript in Adobe Reader and Acrobat should help mitigate the threat from this vulnerability (instructions on how to do that are available here).

Alternatively, Internet users may want to consider uninstalling Adobe Reader in favor of another free PDF reader program, such as Foxit Reader.

Wednesday, December 16, 2009

Adobe to leave Reader unpatched for FOUR MORE WEEKS

We have to wait for a month for this to be fixed???  I'm hoping that if enough "in-the-wild" attacks surface, we'll see a patch sooner.

Adobe PDF attack update: Patch coming Jan 12 | Zero Day | ZDNet.com
Here’s a quick update to the Adobe PDF Reader/Acrobat zero-day story that broke yesterday after the company confirmed that an unpatched vulnerabilities was being attacked in the wild.

First up, an exploit has been fitted into the Metasploit point-and-click penetration testing tool and there are predictions that exploit code will be widely available within a day or two.

More importantly, Adobe has finally provided official mitigation guidance and announced plans to ship a patch for this vulnerability on January 12th, 2010.

Update Firefox to 3.5.6

Zero Day | ZDNet.com: Mozilla patches critical, high-risk Firefox vulnerabilities
Mozilla has shipped Firefox 3.5.6 with patches for at least 11 documented security vulnerabilities.

The most serious issue could lead to remote code execution attacks, according to warning from the open-source browser software maker. In other scenarios, the bugs could cause denial-of-service or URL spoofing attacks.

Details at the Zero-Day link above, and at Mozilla's Security Advisories for Firefox 3.5 page.

Tuesday, December 15, 2009

Adobe Reader Security Advisory today - disable JavaScript NOW

Adobe today issued a security advisory for Acrobat Reader, and there are widespread reports in the trade press that this is actively being exploited today. If you haven't already disabled Javascript in Adobe Reader, do so.  Instructions are summarized below.

Adobe - Security Advisories: APSA09-07 - Security Advisory for Adobe Reader and Acrobat
Adobe has confirmed a critical vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions that could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild. Adobe recommends customers follow the mitigation guidance below until a patch is available.

.... Customers who are not able to utilize the JavaScript Blacklist functionality can mitigate the issue by disabling JavaScript in Adobe Reader and Acrobat using the instructions below:
1. Launch Acrobat or Adobe Reader.
2. Select Edit>Preferences
3. Select the JavaScript Category
4. Uncheck the 'Enable Acrobat JavaScript' option
5. Click OK