(BUSINESS WIRE)--Damballa Inc., the company transforming the fight against cyber threats, today announced the discovery of a new botnet that offers pay-for-delivery Distributed Denial of Service (DDoS) attacks. The ‘IMDDOS’ Botnet, named after the commercial name on the botnet website, has grown to be one of the largest active global botnets in less than four months from initial testing. According to Damballa, the infected hosts used in the DDoS attacks have become unwitting participants in the botnet and are widespread. The vast majority of infected hosts are in China, with the United States being in the top 10 countries affected. Internet Service Providers (ISPs) worldwide were affected, including the majority of North American ISPs, and a number of major corporate networks are hosting bot agents for the IMDDOS Botnet.
“The commercial nature of this botnet and the rapid growth and ultimate size are what make this discovery interesting”
The IMDDOS Botnet offers a commercial service for delivering DDoS attacks against any desired target. Hosted in China, this publicly available service is available for lease to anyone willing to establish an online account, input the domain(s) they wish to attack, and pay for the service. Throughout the Damballa period of study, the botnet grew large very quickly. Following testing by the criminal operators in April 2010, it reached a production peak of activity with 25,000 unique Recursive DNS (RDNS) lookups per hour attempting to resolve to the botnet’s command-and-control (CnC) servers. Damballa is currently working with ISPs and law enforcement officials to contain and nullify the threat.
A 16-page analysis of the discovery can be viewed at: www.damballa.com/IMDDOS. This analysis includes details of the technical infrastructure of the botnet and associated malware as well as an animated illustration of the IMDDOS Botnet’s global growth and impact from early testing stage to peak activity rendered in hourly increments.
A Denial of Service (DoS) attack is a technique used to overwhelm a website/domain in an effort to reduce its responsiveness or completely eliminate its ability to respond to new connection attempts. DoS attacks have historically been used to ‘take down’ political sites, abuse sites, commercial business websites and even military command centers as part of a coordinated targeted campaign.
A DDoS attack utilizes multiple PCs or servers to initiate a coordinated attack against a targeted system. The more assets involved in the attack, the larger the flood of requests and data that can be targeted at the victim. To create a very large army of assets that can launch DDoS attacks, botnets are used to rally and command unwitting victim machines into participating in the attacks.
“The commercial nature of this botnet and the rapid growth and ultimate size are what make this discovery interesting,” stated Gunter Ollmann, vice president of research for Damballa. “The public website hosting the DDoS service offering, with various ‘plans’ and attack options, speaks to the ease with which anyone can leverage criminal infrastructure. The malware used is simplistic, yet it was successful in spreading rapidly. And while it appears to be primarily a DDoS delivery platform, the size of the botnet reached impressive proportions, certainly large enough to wreak major havoc on any victim organization should it be pointed in the right direction.”
This discovery was made possible due to a global array of Damballa sensors, which provide worldwide visibility into CnC activity, combined with the understanding and quantification of statistical heuristics that can explain, and most importantly, quickly detect, the malicious nature of this botnet operation. Damballa tracks thousands of botnet operators and their growing cache of botnets every day. Each criminal botnet building campaign is observed, analyzed, automatically catalogued and categorized using a sophisticated array of clustering and machine learning systems. As the criminal botnet operators attempt to grow the botnet, their investments and modifications to their CnC hosting infrastructure are tracked and used as markers for eventual attribution. Damballa customers benefit from this advanced knowledge of the threat, being alerted to the presence of the malware and being able to terminate the CnC communications.
“Botnets are recognized by industry experts as being the delivery mechanism of choice for the vast majority of today’s cyber threats that plague corporate and ISP networks,” said Val Rahmani, CEO of Damballa. “Botnets and other cyber threats are attacking corporate networks and service providers at an alarmingly high rate and are causing security teams around the world to reevaluate their security investments. Damballa leads the security industry in delivering solutions that detect and terminate botnets and cyber threats, and our research and product teams are constantly innovating and bringing more powerful and automated weapons to the war against cybercrime.”
-----
Community News You Can Use
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
Showing posts with label attacks. Show all posts
Showing posts with label attacks. Show all posts
Tuesday, September 14, 2010
Friday, September 3, 2010
GFI Software Announces Top 10 Malware Threats for August
(BUSINESS WIRE)--GFI Software, a leading IT solutions provider for small and medium-sized enterprises, today announced the top 10 most prevalent malware threats for the month of August 2010. The report, compiled from monthly scans performed by GFI's award-winning anti-malware solution, VIPRE® Antivirus, and its antispyware tool, CounterSpy®, is a service of GFI Labs™.
“Our research group is analyzing new rogues too, but what we’re seeing through ThreatNet indicates that VIPRE is preventing these rogue downloads.”
GFI VIPRE ThreatNet™ statistics for the month of August show that GFI customers were under attack throughout the month primarily by the same Trojan horse programs that have persisted for several months. In fact, the top four threats were unchanged in order from the month of July. Trojans detected as Trojan.Win32.Generic!BT were still the chief detection, slightly down to 25.11 percent of total detections. This particular Trojan detection has been in the top spot for some time: in July with 29.08 percent and in June with 27.16 percent of the total detections.
The number two detection, Trojan-Spy.Win32.Zbot.gen is a detection of password-stealing Trojans with many versions. The third largest detection, Trojan.Win32.Generic.pak!cobra, is a generic detection for a variety of malware that can infect 32- and 64-bit Windows installations.
“Detections of this malicious code indicate that botnet operators continue to try to infect machines and use them in their spamming networks,” said Francis Montesino, manager of the malware processing team, GFI Labs. “Our ThreatNet detections for the month also agree with other reports we’ve heard in the last few weeks that have found a high level of traffic in rogue security products. These are often referred to as scareware. We’re seeing a multitude of detections of the downloaders and installers that are associated with the rogues.
Montesino continued, “Our research group is analyzing new rogues too, but what we’re seeing through ThreatNet indicates that VIPRE is preventing these rogue downloads.”
The top 10 results represent the number of times a particular malware infection was detected during VIPRE and CounterSpy scans that report back to ThreatNet, GFI’s community of opt-in users. These threats are classified as moderate to severe based on method of installation among other criteria established by GFI Labs. The majority of these threats propagate through stealth installations or social engineering.
The top 10 most prevalent malware threats for the month of August are:
1. Trojan.Win32.Generic!BT 25.11%
2. Trojan-Spy.Win32.Zbot.gen 4.23%
3. Trojan.Win32.Generic.pak!cobra 3.61%
4. INF.Autorun (v) 3.27%
5. Trojan.Win32.Generic!SB.0 2.01%
6. BehavesLike.Win32.Malware (v) 1.04%
7. Worm.Win32.Downad.Gen (v) 0.96%
8. Trojan.Win32.Malware.a 0.93%
9. Trojan.Win32.Meredrop 0.92%
10. Exploit.PDF-JS.Gen (v) 0.84%
-----
Community News You Can Use
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
“Our research group is analyzing new rogues too, but what we’re seeing through ThreatNet indicates that VIPRE is preventing these rogue downloads.”
GFI VIPRE ThreatNet™ statistics for the month of August show that GFI customers were under attack throughout the month primarily by the same Trojan horse programs that have persisted for several months. In fact, the top four threats were unchanged in order from the month of July. Trojans detected as Trojan.Win32.Generic!BT were still the chief detection, slightly down to 25.11 percent of total detections. This particular Trojan detection has been in the top spot for some time: in July with 29.08 percent and in June with 27.16 percent of the total detections.
The number two detection, Trojan-Spy.Win32.Zbot.gen is a detection of password-stealing Trojans with many versions. The third largest detection, Trojan.Win32.Generic.pak!cobra, is a generic detection for a variety of malware that can infect 32- and 64-bit Windows installations.
“Detections of this malicious code indicate that botnet operators continue to try to infect machines and use them in their spamming networks,” said Francis Montesino, manager of the malware processing team, GFI Labs. “Our ThreatNet detections for the month also agree with other reports we’ve heard in the last few weeks that have found a high level of traffic in rogue security products. These are often referred to as scareware. We’re seeing a multitude of detections of the downloaders and installers that are associated with the rogues.
Montesino continued, “Our research group is analyzing new rogues too, but what we’re seeing through ThreatNet indicates that VIPRE is preventing these rogue downloads.”
The top 10 results represent the number of times a particular malware infection was detected during VIPRE and CounterSpy scans that report back to ThreatNet, GFI’s community of opt-in users. These threats are classified as moderate to severe based on method of installation among other criteria established by GFI Labs. The majority of these threats propagate through stealth installations or social engineering.
The top 10 most prevalent malware threats for the month of August are:
1. Trojan.Win32.Generic!BT 25.11%
2. Trojan-Spy.Win32.Zbot.gen 4.23%
3. Trojan.Win32.Generic.pak!cobra 3.61%
4. INF.Autorun (v) 3.27%
5. Trojan.Win32.Generic!SB.0 2.01%
6. BehavesLike.Win32.Malware (v) 1.04%
7. Worm.Win32.Downad.Gen (v) 0.96%
8. Trojan.Win32.Malware.a 0.93%
9. Trojan.Win32.Meredrop 0.92%
10. Exploit.PDF-JS.Gen (v) 0.84%
-----
Community News You Can Use
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
Monday, June 21, 2010
Fraudulent Telephone Calls Allowing Fraudsters Access to Consumer Financial and Brokerage Accounts
The FBI Newark Divisionreleased a warning to consumers concerning a new scheme using telecommunicationsdenial-of-service (TDoS)attacks.
The FBI determined fraudsters compromised victim accounts and contacted financial
institutions to change the victim profile information (i.e. email addresses, telephone
numbers and bank account numbers).
The TDoS attacks used automated dialing programs and multiple accounts to overwhelm
victims' cell phones and land lines with thousands of calls. When victims answered
the calls they heard dead air (nothing on the other end), an innocuous recorded
message, advertisement, or a telephone sex menu. Calls were typically short in duration
but so numerous that victims changed their phone numbers to terminate the attack.
These TDoS attacks were used as a diversion to prevent financial and brokerage institutions
from verifying victim account changes and transactions. Fraudsters were afforded
adequate time to transfer funds from victim brokerage and financial online accounts.
Protection from TDoS attacks and other types of fraud requires consumers to be vigilant
and proactive. In Newark’s Public Service Announcement (PSA),
they recommend consumers protect themselves by:
* Implement security measures for all financial accounts by placing fraud alerts with
the major credit bureaus if you believe they were targeted by a TDoS attack or other
forms of fraud.
* Use strong passwords for all financial accounts and change them regularly.
* Obtain and review your annual credit report for fraudulent activity.
If you were a target of a TDoS attack, immediately contact your financial institutions,
notify your telephone provider, and promptly report it to the IC3 website at: www.IC3.gov. The IC3 complaint database links complaints to assist in referrals to the appropriate law enforcement agency for
case consideration. The complaint information is also used to identity emerging
trends and patterns.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
The FBI determined fraudsters compromised victim accounts and contacted financial
institutions to change the victim profile information (i.e. email addresses, telephone
numbers and bank account numbers).
The TDoS attacks used automated dialing programs and multiple accounts to overwhelm
victims' cell phones and land lines with thousands of calls. When victims answered
the calls they heard dead air (nothing on the other end), an innocuous recorded
message, advertisement, or a telephone sex menu. Calls were typically short in duration
but so numerous that victims changed their phone numbers to terminate the attack.
These TDoS attacks were used as a diversion to prevent financial and brokerage institutions
from verifying victim account changes and transactions. Fraudsters were afforded
adequate time to transfer funds from victim brokerage and financial online accounts.
Protection from TDoS attacks and other types of fraud requires consumers to be vigilant
and proactive. In Newark’s Public Service Announcement (PSA),
they recommend consumers protect themselves by:
* Implement security measures for all financial accounts by placing fraud alerts with
the major credit bureaus if you believe they were targeted by a TDoS attack or other
forms of fraud.
* Use strong passwords for all financial accounts and change them regularly.
* Obtain and review your annual credit report for fraudulent activity.
If you were a target of a TDoS attack, immediately contact your financial institutions,
notify your telephone provider, and promptly report it to the IC3 website at: www.IC3.gov. The IC3 complaint database links complaints to assist in referrals to the appropriate law enforcement agency for
case consideration. The complaint information is also used to identity emerging
trends and patterns.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
Labels:
attacks,
automated,
dialing,
fayette front page,
fbi,
fraud,
georgia,
georgia front page,
tdos,
telecommunications,
victims
Friday, January 22, 2010
Consumer Watchdog Lauds Clinton's Call for Open Internet, Stresses Need for Online Consumer Privacy Safeguards
/PRNewswire/ -- Secretary of State Hillary Clinton's condemnation of cyber attacks and censorship is an important endorsement of a free global Internet, but just as important to ensuring the Internet's contribution to democracy and economic growth is a commitment to consumer privacy, Consumer Watchdog said today.
"Too many online companies ignore a consumer's right to control information gathered about their behavior on the Internet," said John M. Simpson, a consumer advocate with the nonpartisan, nonprofit consumer group. "Consider Google; they track your every move as you use their services and surf the Web just so they can mine the accumulated data and serve up targeted ads."
Consumer Watchdog said Clinton's speech demonstrated the State Department is playing a key role in ensuring an open Internet globally, but said the Federal Trade Commission must act to ensure consumer privacy is guaranteed within the United States.
Clinton's high-profile speech on Internet policy came after a recent incident in which hackers, widely believed to be tied to the Chinese government, gained access to Google and at least 30 other corporate computer networks. Google revealed the cyber attacks and said it would no longer self-censor search results on its China Internet search engine, Google.cn.
Cyber attacks and censorship undermine the free flow of information on the Internet and must be thwarted, Consumer Watchdog agreed. Equally important to a vibrant cyber economy, the group said, is that consumers are able to trust online companies not to abuse their privacy. Too often privacy guarantees are given short shrift in the drive for profits.
"For instance, Google tells us they are a technology company that wants to organize the world's information and make it accessible," said Simpson. "In analyzing Google's every move we need to understand they are fundamentally an advertising business. Most of what they do is to maximize those revenues."
Documents filed with the SEC show that 97 percent of the Internet giant's revenue came from advertising in the third quarter of 2009. The documents show that 53 percent of its revenue came from outside the United States.
"Google was right to end its misguided self-censorship in the face of the Chinese cyber attacks and good for them," said Simpson. "But while I'm concerned about the Chinese attacks, I'm even more concerned about the private data gold mine Google and other online companies have gathered about us, what they do with it and whom they share it with. Consumers must have control of what data is gathered, how it is used, how long its kept and whether it is even gathered."
Meanwhile, the FTC is holding a series of roundtable discussions to discuss online privacy issues. The second in the three-part series is next Thursday in Berkeley, Ca. Read about the Privacy Roundtable: http://www.ftc.gov/bcp/workshops/privacyroundtables/
Consumer Watchdog, formerly the Foundation for Taxpayer and Consumer Rights is a nonprofit, nonpartisan consumer advocacy organization with offices in Washington, DC and Santa Monica, Ca. Our website is: www.ConsumerWatchdog.org.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
"Too many online companies ignore a consumer's right to control information gathered about their behavior on the Internet," said John M. Simpson, a consumer advocate with the nonpartisan, nonprofit consumer group. "Consider Google; they track your every move as you use their services and surf the Web just so they can mine the accumulated data and serve up targeted ads."
Consumer Watchdog said Clinton's speech demonstrated the State Department is playing a key role in ensuring an open Internet globally, but said the Federal Trade Commission must act to ensure consumer privacy is guaranteed within the United States.
Clinton's high-profile speech on Internet policy came after a recent incident in which hackers, widely believed to be tied to the Chinese government, gained access to Google and at least 30 other corporate computer networks. Google revealed the cyber attacks and said it would no longer self-censor search results on its China Internet search engine, Google.cn.
Cyber attacks and censorship undermine the free flow of information on the Internet and must be thwarted, Consumer Watchdog agreed. Equally important to a vibrant cyber economy, the group said, is that consumers are able to trust online companies not to abuse their privacy. Too often privacy guarantees are given short shrift in the drive for profits.
"For instance, Google tells us they are a technology company that wants to organize the world's information and make it accessible," said Simpson. "In analyzing Google's every move we need to understand they are fundamentally an advertising business. Most of what they do is to maximize those revenues."
Documents filed with the SEC show that 97 percent of the Internet giant's revenue came from advertising in the third quarter of 2009. The documents show that 53 percent of its revenue came from outside the United States.
"Google was right to end its misguided self-censorship in the face of the Chinese cyber attacks and good for them," said Simpson. "But while I'm concerned about the Chinese attacks, I'm even more concerned about the private data gold mine Google and other online companies have gathered about us, what they do with it and whom they share it with. Consumers must have control of what data is gathered, how it is used, how long its kept and whether it is even gathered."
Meanwhile, the FTC is holding a series of roundtable discussions to discuss online privacy issues. The second in the three-part series is next Thursday in Berkeley, Ca. Read about the Privacy Roundtable: http://www.ftc.gov/bcp/workshops/privacyroundtables/
Consumer Watchdog, formerly the Foundation for Taxpayer and Consumer Rights is a nonprofit, nonpartisan consumer advocacy organization with offices in Washington, DC and Santa Monica, Ca. Our website is: www.ConsumerWatchdog.org.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
Labels:
attacks,
censorship,
clinton,
cyber,
fayette,
fayette front page,
georgia,
georgia front page,
internet,
policy,
privacy
Thursday, January 14, 2010
China News from U.S. Hit by Denial of Service Cyber Attack Originating from China
/PRNewswire/ -- Concurrent with the Chinese cyber attack on Google's gmail, VerticalNews China was the subject of a denial of service (DoS) attack on Wednesday that originated from China. The company also publishes the popular China Weekly News, and both titles are available on the Internet.
VerticalNews China is a product of NewsRx, a 25-year-old news publisher headquartered in Atlanta. The attack was quickly stopped when the company's IP service identified the source and blocked it. VerticalNews China can be found at www.VerticalNews.com.
"Your VerticalNews site was getting a denial-of-service attack (DoS attack) from someone in China. We went ahead and quickly blocked the source IP address at the router level," according to NewsRx's IP service located in Bowie, Maryland.
"In a DoS attack, they are not hacking into your machine, but are preventing it from being usable to everyone else by sending very high volumes of traffic in very short amounts of time. I think you may have been targeted because of your VerticalNews China coverage."
VerticalNews China covers day-to-day business news, medical research, manufacturing and technology developments in China. It does not have a political agenda, but is a major supplier of detailed, in-depth news about China. Today's issue is fairly typical of its coverage, including articles on the number of gas stations in China; a report that Liberty Mutual Group Insurance has received permission to open an office in Zhejiang; that CBI China will host the third annual China Petrochemical Summit; that Shanda Interactive Entertainment Limited has received an award; and a report that forecasts Asia Pacific jet fleet growth will expand 80%, led by China.
"I do know that the large-scale attack originated in China, and now that we know it can happen, we've taken steps to hopefully prevent future disruptions," said Susan Hasty, publisher at NewsRx, the parent company of VerticalNews. "We have every intention to continue coverage of vital news about China."
VerticalNews China and VerticalNews India were launched by NewsRx in 2009, to expand the company's coverage of the Far East. The content is also available at the online sites of Lexis Nexis, Dialog, ProQuest and Gale through the additional VerticalNews titles China Weekly News, China Business Newsweekly, Journal of India, India Business Newsweekly, and Asia Business Newsweekly.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
VerticalNews China is a product of NewsRx, a 25-year-old news publisher headquartered in Atlanta. The attack was quickly stopped when the company's IP service identified the source and blocked it. VerticalNews China can be found at www.VerticalNews.com.
"Your VerticalNews site was getting a denial-of-service attack (DoS attack) from someone in China. We went ahead and quickly blocked the source IP address at the router level," according to NewsRx's IP service located in Bowie, Maryland.
"In a DoS attack, they are not hacking into your machine, but are preventing it from being usable to everyone else by sending very high volumes of traffic in very short amounts of time. I think you may have been targeted because of your VerticalNews China coverage."
VerticalNews China covers day-to-day business news, medical research, manufacturing and technology developments in China. It does not have a political agenda, but is a major supplier of detailed, in-depth news about China. Today's issue is fairly typical of its coverage, including articles on the number of gas stations in China; a report that Liberty Mutual Group Insurance has received permission to open an office in Zhejiang; that CBI China will host the third annual China Petrochemical Summit; that Shanda Interactive Entertainment Limited has received an award; and a report that forecasts Asia Pacific jet fleet growth will expand 80%, led by China.
"I do know that the large-scale attack originated in China, and now that we know it can happen, we've taken steps to hopefully prevent future disruptions," said Susan Hasty, publisher at NewsRx, the parent company of VerticalNews. "We have every intention to continue coverage of vital news about China."
VerticalNews China and VerticalNews India were launched by NewsRx in 2009, to expand the company's coverage of the Far East. The content is also available at the online sites of Lexis Nexis, Dialog, ProQuest and Gale through the additional VerticalNews titles China Weekly News, China Business Newsweekly, Journal of India, India Business Newsweekly, and Asia Business Newsweekly.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage
Labels:
attacks,
china,
chinese,
cyber,
denial,
dos,
fayette,
fayette front page,
georgia,
georgia front page,
google,
verticalnews
Tuesday, June 9, 2009
TweetGrade Tames Twitter Universe to Help End Users Know Who They Can Trust
(BUSINESS WIRE)--Purewire, Inc., a SaaS-based secure Web gateway vendor that protects business and social interactions on the Web, today announced the launch of TweetGrade™ (www.tweetgrade.com), the authority in online user reputation on Twitter®. TweetGrade provides a quantitative assessment of a user’s reach and influence in the Twitter community, and it helps people understand a user’s online reputation, legitimacy and safety.
As the popularity of Twitter continues to skyrocket, criminals are taking note as well. Most recently, a "Best Video" scam attacked Twitter users, posting an update (or tweet) on compromised accounts that directed followers to a video prompting the purchase of rogue anti-virus software. Attacks such as this make it imperative to know the reputation of those people with whom you interact online. TweetGrade assures this trust by providing evidence of Twitter account legitimacy, protecting users from malicious or illegitimate accounts that attempt to send spam or spread malware.
The Purewire research team evaluated the use of Twitter to demonstrate the power of the TweetGrade service, and based on a seven-million user sample has found data that point to two overall realities:
First, many Twitter users abandon their accounts shortly after creating them, and a significant percentage show no signs of account activity.
* 40 percent of Twitter users have not tweeted since their first day on Twitter, evidence that the account was most likely created and subsequently abandoned.
* Approximately 25 percent of Twitter users are not following anyone, while two-thirds are following fewer than 10 people, evidence that the account was created but is largely dormant.
Second, Twitter is used more as a mass medium for receiving information, rather than as a way to interact with others. Proof is shown by evaluating the followers and friends of Twitter users:
* More than one-third of Twitter users have not posted a single tweet, and almost 80 percent of users have fewer than 10 tweets, evidence that while Twitter is billed as a great collaboration tool, a large number of users are there to consume content, not distribute it.
* Approximately 30 percent of Twitter users do not have any followers, and 80 percent of Twitter users have fewer than 10 followers, evidence that for many users, their posts are not being widely tracked or read.
* 50 percent of Twitter users are following more people than they have as followers, and another 30 percent of Twitter users are following the same number of people that are following them, evidence that users are aggressively trying to attract followers by hoping they will “follow back” but have been unsuccessful.
Additional details are available on the Purewire Web Security Blog located at http://blog.purewire.com/.
“There is a lot of noise on the Web, especially on Twitter lately with the buzz around Oprah, CNN and Ashton Kutcher. That makes it hard to wade through everything and understand who you’re interacting with online,” said Dr. Steve Webb, research scientist at Purewire, Inc. “Purewire is all about deciphering Web activity so that users know what and who they can trust, and TweetGrade is the first service that takes a comprehensive look at a Twitter account’s true legitimacy. Through our experience with PurewireTrust.org and our patent-pending Purewire Trust technology, we are able to offer Twitter users the transparency needed to identify and sort out the associated security threats.”
How TweetGrade Works
TweetGrade evaluates Twitter users based on their interactions on Twitter. The analysis is centered on a variety of inputs such as frequency and content of tweets, number of followers, number of those following and activity level. Users receive a simple letter grade that ranges from an 'A+' to an 'F' to verify their reputation on Twitter and are able to share their TweetGrade with the Twitter community with a simple push of a button.
Purewire is in the process of integrating TweetGrade reputations into a user’s Purewire Trust reputation. PurewireTrust.org launched in March at DEMO 2009, where the company received a DEMOgod award for its innovation. Purewire Trust builds reputations that protect individuals in user-to-user relationships for communication (such as social networks like Facebook and LinkedIn), collaboration (such as applications like Twitter) and commerce (such as classified sites, Craigslist and eBay).
Purewire is offering access to PurewireTrust.org and TweetGrade.com free of charge as a contribution to the technology community in support of the company’s mission to improve the online experience for both consumers and enterprises. As PurewireTrust.org becomes more widely used, Purewire can incorporate this security reputation into its Purewire Web Security Service, to better identify and block Web security threats.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
As the popularity of Twitter continues to skyrocket, criminals are taking note as well. Most recently, a "Best Video" scam attacked Twitter users, posting an update (or tweet) on compromised accounts that directed followers to a video prompting the purchase of rogue anti-virus software. Attacks such as this make it imperative to know the reputation of those people with whom you interact online. TweetGrade assures this trust by providing evidence of Twitter account legitimacy, protecting users from malicious or illegitimate accounts that attempt to send spam or spread malware.
The Purewire research team evaluated the use of Twitter to demonstrate the power of the TweetGrade service, and based on a seven-million user sample has found data that point to two overall realities:
First, many Twitter users abandon their accounts shortly after creating them, and a significant percentage show no signs of account activity.
* 40 percent of Twitter users have not tweeted since their first day on Twitter, evidence that the account was most likely created and subsequently abandoned.
* Approximately 25 percent of Twitter users are not following anyone, while two-thirds are following fewer than 10 people, evidence that the account was created but is largely dormant.
Second, Twitter is used more as a mass medium for receiving information, rather than as a way to interact with others. Proof is shown by evaluating the followers and friends of Twitter users:
* More than one-third of Twitter users have not posted a single tweet, and almost 80 percent of users have fewer than 10 tweets, evidence that while Twitter is billed as a great collaboration tool, a large number of users are there to consume content, not distribute it.
* Approximately 30 percent of Twitter users do not have any followers, and 80 percent of Twitter users have fewer than 10 followers, evidence that for many users, their posts are not being widely tracked or read.
* 50 percent of Twitter users are following more people than they have as followers, and another 30 percent of Twitter users are following the same number of people that are following them, evidence that users are aggressively trying to attract followers by hoping they will “follow back” but have been unsuccessful.
Additional details are available on the Purewire Web Security Blog located at http://blog.purewire.com/.
“There is a lot of noise on the Web, especially on Twitter lately with the buzz around Oprah, CNN and Ashton Kutcher. That makes it hard to wade through everything and understand who you’re interacting with online,” said Dr. Steve Webb, research scientist at Purewire, Inc. “Purewire is all about deciphering Web activity so that users know what and who they can trust, and TweetGrade is the first service that takes a comprehensive look at a Twitter account’s true legitimacy. Through our experience with PurewireTrust.org and our patent-pending Purewire Trust technology, we are able to offer Twitter users the transparency needed to identify and sort out the associated security threats.”
How TweetGrade Works
TweetGrade evaluates Twitter users based on their interactions on Twitter. The analysis is centered on a variety of inputs such as frequency and content of tweets, number of followers, number of those following and activity level. Users receive a simple letter grade that ranges from an 'A+' to an 'F' to verify their reputation on Twitter and are able to share their TweetGrade with the Twitter community with a simple push of a button.
Purewire is in the process of integrating TweetGrade reputations into a user’s Purewire Trust reputation. PurewireTrust.org launched in March at DEMO 2009, where the company received a DEMOgod award for its innovation. Purewire Trust builds reputations that protect individuals in user-to-user relationships for communication (such as social networks like Facebook and LinkedIn), collaboration (such as applications like Twitter) and commerce (such as classified sites, Craigslist and eBay).
Purewire is offering access to PurewireTrust.org and TweetGrade.com free of charge as a contribution to the technology community in support of the company’s mission to improve the online experience for both consumers and enterprises. As PurewireTrust.org becomes more widely used, Purewire can incorporate this security reputation into its Purewire Web Security Service, to better identify and block Web security threats.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Labels:
atlanta,
attacks,
fayette front page,
georgia,
georgia front page,
interact,
purewire,
scam,
tweet,
tweetgrade,
twitter
Tuesday, February 3, 2009
Webroot Threat Advisory: Phony Warnings from the Federal Reserve Bank Aim to Swindle Americans
/PRNewswire/ -- Webroot, a leading security provider for the consumer, enterprise and SMB markets, has detected a phishing scam exploiting the names of the Federal Reserve Bank and other federal entities to fool consumers into clicking Web links that infect their PCs with spyware.
A phony e-mail from the Federal Reserve Bank warns of a "large-scale phishing attack" on banks and credit unions that took place January 21. A link to "more detailed information about affected banks and U.S. Treasury restrictions" leads to a fake Web site that infects victims' computers with malware designed to harvest their Web site and POP3 e-mail account usernames and passwords.
Webroot has identified the malware as Trojan-Backdoor-Graypigeon deploying malware via drive-by download. The cyber criminals behind the scam have recycled the e-mail message a number of times; the FDIC reported a previous version of the e-mail January 20. But the domains linked in the message continually change and suggest the message's origin may be legitimate. All point to one PC on China Railcom's IP address space that was hijacked to carry out the phishing attacks.
"Webroot has uncovered a new twist on phishing for financial gain," said Mike Kronenberg, chief technology officer, Consumer Business, Webroot. "In this case, phishers are capitalizing on widespread concern over the current state of the U.S. finance industry. Over 3.5 million Americans fell victim to phishing in 2007 according to recent research, and we can expect scammers to continue launching attacks against unsuspecting people. PC users should protect themselves by always avoiding unfamiliar URLs and questionable e-mails, and by having proven antispyware, antivirus and firewall software in place."
The malware and some of the domains identified as part of this scam are now blocked by Webroot(R) Internet Security Essentials.
-----
www.fayettefrontpage.com
Fayette Front Page
Community News You Can Use
Fayetteville, Peachtree City, Tyrone
www.georgiafrontpage.com
Georgia Front Page
A phony e-mail from the Federal Reserve Bank warns of a "large-scale phishing attack" on banks and credit unions that took place January 21. A link to "more detailed information about affected banks and U.S. Treasury restrictions" leads to a fake Web site that infects victims' computers with malware designed to harvest their Web site and POP3 e-mail account usernames and passwords.
Webroot has identified the malware as Trojan-Backdoor-Graypigeon deploying malware via drive-by download. The cyber criminals behind the scam have recycled the e-mail message a number of times; the FDIC reported a previous version of the e-mail January 20. But the domains linked in the message continually change and suggest the message's origin may be legitimate. All point to one PC on China Railcom's IP address space that was hijacked to carry out the phishing attacks.
"Webroot has uncovered a new twist on phishing for financial gain," said Mike Kronenberg, chief technology officer, Consumer Business, Webroot. "In this case, phishers are capitalizing on widespread concern over the current state of the U.S. finance industry. Over 3.5 million Americans fell victim to phishing in 2007 according to recent research, and we can expect scammers to continue launching attacks against unsuspecting people. PC users should protect themselves by always avoiding unfamiliar URLs and questionable e-mails, and by having proven antispyware, antivirus and firewall software in place."
The malware and some of the domains identified as part of this scam are now blocked by Webroot(R) Internet Security Essentials.
-----
www.fayettefrontpage.com
Fayette Front Page
Community News You Can Use
Fayetteville, Peachtree City, Tyrone
www.georgiafrontpage.com
Georgia Front Page
Labels:
atlanta,
attacks,
fayette front page,
federal reserve bank,
georgia,
georgia front page,
malware,
phishing,
scam,
security
Tuesday, December 9, 2008
FBI Warns of New Vishing Attacks Targeting Private Branch Exchange (PBX) Systems
The FBI has identified a new technique used to conduct vishing attacks where hackers exploit a known security vulnerability in Asterisk software. Asterisk is free and widely used software developed to integrate Private Branch Exchange (PBX) systems with Voice over Internet Protocol (VoIP) digital Internet voice calling services; however, early versions of the Asterisk software are known to have a vulnerability. The vulnerability can be exploited by cyber criminals to use the system as an auto dialer, generating thousands of vishing telephone calls to consumers within one hour.
Digium, the original creator and primary developer of Asterisk, released a Security Advisory, AST-2008-003, in March 2008, which contains the information necessary for users to configure a system, patch the software, or upgrade the software to protect against this vulnerability.
If a consumer falls victim to this exploit, their personally identifiable information (PII) will be compromised. To prevent further loss of consumers’ PII and to reduce the spread of this new technique, it is imperative that businesses using Asterisk upgrade their software to a version that has had the vulnerability fixed.
Further, consumers should not release personal information in response to unsolicited telephone calls. Providing your PII will compromise your identity.
“As with all types of scams, whether by computer, phone, or mail, using common sense can protect you,” said Special Agent Richard Kolko, Chief, National Press Office, Washington, D.C.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Digium, the original creator and primary developer of Asterisk, released a Security Advisory, AST-2008-003, in March 2008, which contains the information necessary for users to configure a system, patch the software, or upgrade the software to protect against this vulnerability.
If a consumer falls victim to this exploit, their personally identifiable information (PII) will be compromised. To prevent further loss of consumers’ PII and to reduce the spread of this new technique, it is imperative that businesses using Asterisk upgrade their software to a version that has had the vulnerability fixed.
Further, consumers should not release personal information in response to unsolicited telephone calls. Providing your PII will compromise your identity.
“As with all types of scams, whether by computer, phone, or mail, using common sense can protect you,” said Special Agent Richard Kolko, Chief, National Press Office, Washington, D.C.
-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Labels:
asterisk software,
atlanta,
attacks,
cyber crime,
digium,
fayette front page,
fayetteville,
fbi,
georgia,
georgia front page,
pbx,
peachtree city,
tyrone,
vishing
Subscribe to:
Posts (Atom)