<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>techcosupport.com &#187; Security</title>
	<atom:link href="http://techcosupport.com/press/category/support/security-support/feed/" rel="self" type="application/rss+xml" />
	<link>http://techcosupport.com/press</link>
	<description>Techco Support Site - Helping your business grow through Technology, Training and Coaching</description>
	<lastBuildDate>Fri, 30 Dec 2011 10:40:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Visa Scam Email Circulating</title>
		<link>http://techcosupport.com/press/visa-scam-email-circulating/</link>
		<comments>http://techcosupport.com/press/visa-scam-email-circulating/#comments</comments>
		<pubDate>Sun, 27 Nov 2011 20:19:21 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Support]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Scam]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=1033</guid>
		<description><![CDATA[<p>The spam filters are currently picking out a Visa Scam Email circulating at the moment which is claiming that your card has been blocked for security reasons. If your email browser will render the html, it looks something like this Visa Scam Screenshot:</p> <p class="wp-caption-text">Visa Scam Screenshot</p> <p>Analysis of the content shows a hyperlink which <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/visa-scam-email-circulating/">Visa Scam Email Circulating</a></span>]]></description>
			<content:encoded><![CDATA[<p>The spam filters are currently picking out a <strong>Visa Scam Email circulating</strong> at the moment which is claiming that your card has been blocked for security reasons. If your email browser will render the html, it looks something like this Visa Scam Screenshot:</p>
<div id="attachment_1034" class="wp-caption aligncenter" style="width: 310px"><a href="http://techcosupport.com/press/wp-content/uploads/2011/11/Visa-Scam-Screenshot.png"><img class="size-medium wp-image-1034" title="Visa Scam Screenshot" src="http://techcosupport.com/press/wp-content/uploads/2011/11/Visa-Scam-Screenshot-300x255.png" alt="Visa Scam Screenshot" width="300" height="255" /></a><p class="wp-caption-text">Visa Scam Screenshot</p></div>
<p>Analysis of the content shows a hyperlink which claims to point to visa.ca, but in fact is a link to an IP address in the Republic of Korea. Launching the link will only get you a page that looks like this:</p>
<div id="attachment_1035" class="wp-caption aligncenter" style="width: 310px"><a href="http://techcosupport.com/press/wp-content/uploads/2011/11/Visa-Scam-Link-Screenshot.png"><img class="size-medium wp-image-1035" title="Visa Scam Link Screenshot" src="http://techcosupport.com/press/wp-content/uploads/2011/11/Visa-Scam-Link-Screenshot-300x128.png" alt="Visa Scam Link Screenshot" width="300" height="128" /></a><p class="wp-caption-text">Visa Scam Link Screenshot</p></div>
<p>If you have received any of this type of email, and want to find out where the masked link is actually pointing, you could try looking it up via <a title="ipchecking.com/" href="http://ipchecking.com/" target="_blank">ipchecking.com</a>. However, the best advice with this scam is to press delete, and save your mailbox space.</p>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/visa-scam-email-circulating/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/visa-scam-email-circulating/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bredolab Botnet Still Active</title>
		<link>http://techcosupport.com/press/bredolab-botnet-still-active/</link>
		<comments>http://techcosupport.com/press/bredolab-botnet-still-active/#comments</comments>
		<pubDate>Wed, 09 Nov 2011 19:25:07 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=1012</guid>
		<description><![CDATA[<p>More Tax Payment malware news today, with a resurgence of the Bredolab botnet. </p> <p>Our MessageLabs Anti-Virus Service reported a suspicious email, similar to the Tax Spam Malware Warning yesterday. The message title once again was Your Tax Payment ID [Random Number] is failed</p> <p>This time Symantec reported it as Trojan.Bredolab, which is a likely <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/bredolab-botnet-still-active/">Bredolab Botnet Still Active</a></span>]]></description>
			<content:encoded><![CDATA[<p>More Tax Payment <strong>malware</strong> news today, with a resurgence of the <strong>Bredolab botnet</strong>.  </p>
<p>Our MessageLabs Anti-Virus Service reported a suspicious email, similar to the <a href="http://techcosupport.com/press/tax-spam-malware-warning/" title="Tax Spam Malware Warning" target="_blank">Tax Spam Malware Warning</a> yesterday.  The message title once again was Your Tax Payment ID [Random Number] is failed</p>
<p>This time Symantec reported it as Trojan.Bredolab, which is a likely resurfacing of a Bredolab botnet.</p>
<p>The Bredolab botnet was partially dismantled in November 2010 through the seizure by Dutch law enforcement agents of 143 command and control servers, effectively removing the botnet herder&#8217;s ability to control the botnet centrally.  Although the botnet&#8217;s size and capacity has been severely reduced by the law enforcement intervention.</p>
<p>A PC infected with Bredolab shows a number of effects as the malware:</p>
<ul>
<li>Downloads more malware on to the compromised computer</li>
<li>Lowers the security settings on the infected computer</li>
<li>May result in file deletion</li>
</ul>
<p>If your anti virus software or mail gateway informs you that it has detected Bredolab, follow the instructions and do not open any affected files.  To make sure that your machine does not get infected keep your anti virus software switched on and the signatures up to date.</p>
<p>Further resources </p>
<ul>
<li><a href="http://www.symantec.com/security_response/writeup.jsp?docid=2009-052907-2436-99" title="Symantec Labs Trojan.Bredolab" target="_blank">Symantec Labs Trojan.Bredolab</a></li>
<li><a href="http://en.wikipedia.org/wiki/BredoLab_botnet" title="xxx" target="_blank">BredoLab botnet on Wikipedia</a></li>
<li><a href="http://www.zdnet.com/blog/security/dutch-police-shut-down-bredolab-botnet/7573" title="xxx" target="_blank">Dutch police shut down Bredolab botnet</a></li>
</ul>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/bredolab-botnet-still-active/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/bredolab-botnet-still-active/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tax Spam Malware Warning</title>
		<link>http://techcosupport.com/press/tax-spam-malware-warning/</link>
		<comments>http://techcosupport.com/press/tax-spam-malware-warning/#comments</comments>
		<pubDate>Tue, 08 Nov 2011 21:52:39 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Tax]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=1005</guid>
		<description><![CDATA[<p>The spam filters are currently working overtime catching dubious email messages about tax payments having failed. As you might expect, this is a Tax Spam Malware Warning, so take care before opening anything that tells you that Your Tax Payment failed.</p> <p>This email, which purports to be from US tax payment service Electronic Federal Tax <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/tax-spam-malware-warning/">Tax Spam Malware Warning</a></span>]]></description>
			<content:encoded><![CDATA[<p>The <strong>spam</strong> filters are currently working overtime catching dubious email messages about tax payments having failed. As you might expect, this is a <strong>Tax Spam Malware Warning</strong>, so take care before opening anything that tells you that Your Tax Payment failed.</p>
<p>This email, which purports to be from US tax payment service Electronic Federal Tax Payment System (EFTPS), claims that the recipient&#8217;s tax payment has been rejected due to a submission error. The message, which includes a sender address and link that are seemingly valid EFTPS addresses, asks the recipient to click a link in order to review details about the error. </p>
<p>Obviously the email is not from the EFTPS, and the link in the message has been disguised so that it appears to point to the genuine EFTPS website. In fact, it is a phishing scam designed to steal personal information from recipients. A sample of the email appear below:<br />
<code><br />
<blockquote>
Your Tax Payment ID [random number] is failed</p>
<p>Your Federal Tax Payment ID: 32127292 has been rejected.<br />
Return Reason Code R21 - The identification number used in the Company Identification Field is not valid.</p>
<p>Please, check the information  to get details about your company payment in transaction contacts section:</p>
<p>attach name = report.18653.pdf</p>
<p>In other way forward information to your accountant adviser.<br />
EFTPS:<br />
The Electronic Federal Tax Payment System<br />
PLEASE NOTE: Your tax payment is due regardless of EFTPS online availability. In case of an emergency, you can always make your tax payment by calling the EFTPS.</p></blockquote>
<p></code></p>
<p>Attempting to open the attached file will result in a malware loader executing.  This is detected by Sophos Anti-Virus as &#8216;Virus/Spyware Mal/FakeAV-OQ.</p>
<p>The gramatical errors should give you a clue to the bogus source of this Tax Spam Malware. Do not click on any links in this email or download any attachments. Flag as spam and press delete!</p>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/tax-spam-malware-warning/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/tax-spam-malware-warning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Scripts Added To Websites</title>
		<link>http://techcosupport.com/press/malware-scripts-added-to-websites/</link>
		<comments>http://techcosupport.com/press/malware-scripts-added-to-websites/#comments</comments>
		<pubDate>Sun, 06 Nov 2011 22:19:31 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Script]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=994</guid>
		<description><![CDATA[<p>A couple of our customers have experienced hacks to their websites this last week, with malicious code (or malware) added to several pages. Normal visitors to the site have a little extra script added when they load the page, which good antivirus software will identify as a malware script. Kaspersky Labs identifies the Trojan loader <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/malware-scripts-added-to-websites/">Malware Scripts Added To Websites</a></span>]]></description>
			<content:encoded><![CDATA[<p>A couple of our customers have experienced hacks to their <strong>websites</strong> this last week, with malicious code (or <strong>malware</strong>) added to several pages.  Normal visitors to the site have a little extra <strong>script</strong> added when they load the page, which good antivirus software will identify as a <strong>malware script</strong>.  Kaspersky Labs identifies the <strong>Trojan</strong> loader as Heur: Trojan <strong>Script</strong> Generic, which is a generic <strong>Trojan</strong> loader identified by a heuristic algorithm.  Alternatively, it may be identified as as Blackhole Exploit kit by other AV products.</p>
<p>Analysis of samples of the inserted code show some common strings, which can be used to find the script on an <strong>infected website</strong>.  This appears to have been inserted by an automated script loader, probably a bot using brute force to guess FTP passwords.</p>
<blockquote><p>
<code>< b o d y>< d i v id="w3stats"><br />
< s c r i p t language="JavaScript" type="text/javascript"><br />
<strong>window.w3ssss</strong>=function(){<br />
=== Script Link and other code removed ===<br />
CheckBody();<br />
< / s c r i p t >< / b o d y >< / h t m l ></code></p></blockquote>
<p>A quick Google search reveals that quite a few sites have had this little addition.  If you find that you have been infected, carry out the following actions as soon as possible:</p>
<ul>
<li>Search the code on each page for the string &#8220;window.w3ssss&#8221;</li>
<li>Remove the offending code from all of the pages where it has been installed</li>
<li>Change all your site passwords, including FTP</li>
<li>Monitor the site regularly for reinfection</li>
</ul>
<p>Thousands of website owners are unaware that their sites are hacked and infected with malware scripts.  Here are a few useful links to help:</p>
<ul>
<li><a href="https://www.google.com/search?q=window.w3ssss" title="Search Google for hacked sites" target="_blank">Search Google for hacked sites</a></li>
<li><a href="http://sitecheck.sucuri.net/scanner/" title="xxx" target="_blank">Free website malware &#038; blacklist scan</a></li>
<li><a href="http://www.unmaskparasites.com/" title="xxx" target="_blank">Check your site using Unmask Parasites</a></li>
</ul>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/malware-scripts-added-to-websites/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/malware-scripts-added-to-websites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spear Phishing Attack Warning</title>
		<link>http://techcosupport.com/press/spear-phishing-attack-warning/</link>
		<comments>http://techcosupport.com/press/spear-phishing-attack-warning/#comments</comments>
		<pubDate>Thu, 13 Oct 2011 18:59:32 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spear Phishing]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=976</guid>
		<description><![CDATA[<p>A warning which is currently circulating in security circles concerns a Spear Phishing attack masquerading as a company virus warning. The object is to trick users into installing malware on their computers which would compromise their security.</p> <p>Phishing is a way of attempting to acquire sensitive information such as usernames, passwords and credit card details <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/spear-phishing-attack-warning/">Spear Phishing Attack Warning</a></span>]]></description>
			<content:encoded><![CDATA[<p>A warning which is currently circulating in security circles concerns a <strong>Spear Phishing</strong> attack masquerading as a company virus warning.  The object is to trick users into installing malware on their computers which would compromise their security.</p>
<p><strong>Phishing</strong> is a way of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. Named after Fishing, (baiting a hook) the message could claim to be from a bank, online payment processor or a social media site.</p>
<p><strong>Spear Phishing</strong> (sometimes written as <strong>Spearphishing</strong>) is an e-mail spoofing fraud attempt that targets a specific organization, seeking unauthorized access to confidential data.  This is usually by impersonating a company employee via e-mail to steal usernames and passwords from colleagues and gain access to the company systems.  Spear phishing is commonly used to refer to any targeted email attack, not just limited to phishing. </p>
<p>The particular attack which is currently circulating attempts to trick users into believing they are downloading an approved anti-virus update from the company&#8217;s IT department, to combat a new kind of virus.  However, if they do succumb to temptation, they will install a Trojan horse.  According to the Sophos Naked Security blog post, Sophos anti-virus products detect the malware as Mal/Generic-L and Troj/Inject-QL.</p>
<p>If you ever receive an odd email recommending that you click on a link to install something, check with your IT department to see if the instruction is genuine. They would much rather you checked than put the network at risk from malware infection.</p>
<p>For more details of the Spear Phishing Attack Warning, including a sample email message, <a href="http://nakedsecurity.sophos.com/2011/10/11/sneaky-company-virus-warnings-malware/" title="click here to view the Sophos Sneaky fake company virus warning" target="_blank">click here to view the Sophos Sneaky fake company virus warning</a></p>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/spear-phishing-attack-warning/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/spear-phishing-attack-warning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Block Spam from WordPress Contact Page</title>
		<link>http://techcosupport.com/press/block-spam-from-wordpress-contact-page/</link>
		<comments>http://techcosupport.com/press/block-spam-from-wordpress-contact-page/#comments</comments>
		<pubDate>Tue, 11 Oct 2011 20:20:52 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Support]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[CAPTCHA]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=961</guid>
		<description><![CDATA[<p>Have you been having trouble with Spam from your Contact Page on your WordPress blog? This is a quick way to Block Spam from a WordPress Contact Page.</p> <p>Every good website has a Contact page to ensure that users can get questions answers, and customers can engage before buying goods and services. The trouble is <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/block-spam-from-wordpress-contact-page/">Block Spam from WordPress Contact Page</a></span>]]></description>
			<content:encoded><![CDATA[<p>Have you been having trouble with Spam from your Contact Page on your <strong>WordPress</strong> blog? This is a quick way to <strong>Block Spam from a WordPress Contact Page</strong>.</p>
<p>Every good website has a Contact page to ensure that users can get questions answers, and customers can engage before buying goods and services.  The trouble is that every bad robot spider trawling the web knows that too, and targets input forms and contact pages.  Pretty soon after putting your Contact Page live you can expect to start receiving emails about Viagra, poorly crafted meaningless comments containing back links, or just random strings of characters.  While the delete key handles these things quickly and efficiently, the net effect is to dilute our energy which should be directed a answering the real questions from our customers.  What we need is a better solution.</p>
<p><strong>What Stops The Bots?</strong><br />
To stop the spiders from even posting the contact form we need to install a WordPress <strong>CAPTCHA</strong> plugin.  A <strong>CAPTCHA</strong> (Completely Automated Public Turing test to tell Computers and Humans Apart) is a challenge-response test used to ensure that the response is not generated by a computer or Bot. It can be as simple as identifying if a picture of an animal is a cat or a dog, which is easy for a human, but a challenge for a Bot.  The most common forms use distorted images of letters and numbers, which the human eye can easily distinguish due to pattern matching capabilities within our brains. Go humans!</p>
<p><strong>How To Block Spam from a WordPress Contact Page</strong><br />
If you are using the Contact Form 7 plugin, there is a <strong>Really Simple CAPTCHA</strong> plugin which integrates right in to the Contact Form 7.  While not strongly secure, it will at least stop the script kiddies and bots having an open door. To install it carry out the following steps:</p>
<ul>
<li>In the Plugins section of the Dashboard, click on <strong>Add New</strong> </li>
<li>Search for plugins by keyword Term <strong>Really Simple CAPTCHA</strong></li>
<li>Next to Really Simple CAPTCHA, click on <strong>Install Now</strong></li>
</ul>
<p><strong>What Else Can Block Spam</strong><br />
If the Really Simple CAPTCHA plugin does not meet the requirements, there are a number of other measures we can use to block Spam from WordPress contact pages, including:</p>
<ul>
<li>
Secure CAPTCHA, which uses hard to break and easy to read secure CAPTCHA images from SecureCAPTCHA.net.</li>
<li>Contact Form by ContactMe.com, which is a fully customizable contact form which automatically adds your contacts to a free online contacts database.</li>
<li>Fast Secure Contact Form which supports sending mail to multiple departments, and redirects to any URL after the message is sent.</li>
</ul>
<p>Hopefully using one of these methods we can see the back of spam contacts from the contacts page, and get back to the business of responding to or customers and genuine visitors.</p>
<p>Finally, some useful Resources to help block Spam from a WordPress Contact Page</p>
<ul>
<li><a href="http://wordpress.org/extend/plugins/tags/captcha" title="WordPress.org CAPTCHA List" target="_blank">WordPress.org CAPTCHA List</a></li>
<li><a href="http://wordpress.org/extend/plugins/contact-form-with-captcha/" title="Contact Form With Captcha" target="_blank">Contact Form With Captcha</a></li>
<li><a href="http://en.wikipedia.org/wiki/CAPTCHA" title="xxx" target="_blank">CAPTCHA From Wikipedia, the free encyclopedia</a></li>
</ul>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/block-spam-from-wordpress-contact-page/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/block-spam-from-wordpress-contact-page/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Keylogger virus infects drone plane command centre</title>
		<link>http://techcosupport.com/press/keylogger-virus-infects-drone-plane-command-centre/</link>
		<comments>http://techcosupport.com/press/keylogger-virus-infects-drone-plane-command-centre/#comments</comments>
		<pubDate>Sun, 09 Oct 2011 20:00:00 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Drones]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=945</guid>
		<description><![CDATA[<p>The hot news on the blogosphere at the moment is the revelation that a Keylogger virus has infected the drone plane command centre at Creech air force base in Nevada. </p> <p>Keylogging (or Keystroke logging) is the action of tracking (or logging) the keys struck on the keyboard, typically in a covert manner so that <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/keylogger-virus-infects-drone-plane-command-centre/">Keylogger virus infects drone plane command centre</a></span>]]></description>
			<content:encoded><![CDATA[<p>The hot news on the blogosphere at the moment is the revelation that a Keylogger virus has infected the drone plane command centre at Creech air force base in Nevada. </p>
<p>Keylogging (or Keystroke logging) is the action of tracking (or logging) the keys struck on the keyboard, typically in a covert manner so that the person using the keyboard is unaware.  The Keylogger virus is used to capture users&#8217; passwords, credit card details and bank account numbers as people type them in. The data is then sent over the web to fraudsters.  Security officials are currently unable to completely remove the virus, as it keeps reinstalling itself, suggesting that the attack vector has not been plugged.</p>
<p>Creech air force base in Nevada is the command centre for the remotely piloted aircraft used in Afghanistan including the Predator drone spyplane-bomber.  The Predator is a medium-altitude, long-endurance unmanned aircraft system which is used in Afghanistan and, more controversially, across the border in Pakistan.</p>
<p>This is the latest security breach for the hi-tech remotely piloted vehicle system; the US military has previously found out that Iraqi insurgents were able to capture and record the footage being sent to troops and back to the airbase by cameras on the drones.  The insurgents hacked into video feeds, which were not encrypted, using a $26 piece of Russian software named SkyGrabber.  Apparently The encryption for the feeds were removed for performance reasons.</p>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/keylogger-virus-infects-drone-plane-command-centre/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/keylogger-virus-infects-drone-plane-command-centre/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ACH Spam With Malware Attachment</title>
		<link>http://techcosupport.com/press/ach-spam-with-malware-attachment/</link>
		<comments>http://techcosupport.com/press/ach-spam-with-malware-attachment/#comments</comments>
		<pubDate>Sun, 18 Sep 2011 20:05:01 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=922</guid>
		<description><![CDATA[<p>The spam filters have been busy over the last couple of days, with a number of Emails with the title of ACH NOTIFICATION and ACH Payment [Number] Rejected. In each case the email contains an attachment purporting to be a self extracting PDF file.</p> <p>Of course, on closer examination the supposed self extracting PDF file <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/ach-spam-with-malware-attachment/">ACH Spam With Malware Attachment</a></span>]]></description>
			<content:encoded><![CDATA[<p>The spam filters have been busy over the last couple of days, with a number of Emails with the title of ACH NOTIFICATION and ACH Payment [Number] Rejected.  In each case the email contains an attachment purporting to be a self extracting PDF file.</p>
<p>Of course, on closer examination the supposed self extracting PDF file is a malware down-loader, no doubt ready and waiting to connect you to one or more bot nets.  This is a common scenario with a spammed-out trojan down-loader triggering the execution of multiple pieces of malware on the unwitting user&#8217;s computer.  In this case, Sophos anti virus detects the file and identifies it as Mal/BredoZp-B.  For a detailed analysis of the activities of the spam payload, see the article on the ACH spam campaign by M86 security labs via the link below.</p>
<p>Automated Clearing House (ACH) is an electronic network for financial transactions in the United States.  As usual with this type of spam and associated malware, ACH have no connection with the email, so there is little point in blocking the sender&#8217;s address, in our case ach.01 at nacha.org.</p>
<p>Once again our advice is that you should not open any unexpected emails, or unsolicited attachments, as in this case it will attempt to infect your Windows computer.  Just press delete and double check that your anti-virus software is up to date.</p>
<p>Resources relating to ACH Spam With Malware Attachment:</p>
<ul>
<li><a href="http://techcosupport.com/spamsamples/AchNotification.html" title="Sample ACH Notification email (Deactivated)" target="_blank">Sample ACH Notification email (Deactivated)</a></li>
<li><a href="http://nakedsecurity.sophos.com/2011/08/30/fdic-notification-malware/" title="Sophos Naked Security blog entry FDIC notification malware attack spammed out" target="_blank">Sophos Naked Security blog entry FDIC notification malware attack spammed out</a></li>
<li><a href="http://labs.m86security.com/2011/09/an-analysis-of-the-ach-spam-campaign/" title=" M86 security labs analysis of the ACH spam campaign" target="_blank">M86 security labs analysis of the ACH spam campaign</a></li>
</ul>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/ach-spam-with-malware-attachment/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/ach-spam-with-malware-attachment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Uniform Traffic Ticket Malware Spam</title>
		<link>http://techcosupport.com/press/uniform-traffic-ticket-malware-spam/</link>
		<comments>http://techcosupport.com/press/uniform-traffic-ticket-malware-spam/#comments</comments>
		<pubDate>Thu, 01 Sep 2011 20:20:31 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Support]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=887</guid>
		<description><![CDATA[<p>If you live anywhere except the City of New York you may have been surprised to receive an email recently, which claims to come from the New York State Department of Motor Vehicles. Even if you aren&#8217;t based in the United States, or even don&#8217;t drive a car, you may well see the posting which <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/uniform-traffic-ticket-malware-spam/">Uniform Traffic Ticket Malware Spam</a></span>]]></description>
			<content:encoded><![CDATA[<p>If you live anywhere except the City of New York you may have been surprised to receive an email recently, which claims to come from the New York State Department of Motor Vehicles.  Even if you aren&#8217;t based in the United States, or even don&#8217;t drive a car, you may well see the posting which poses as a &#8220;<strong>Uniform Traffic Ticket</strong>&#8221; and says that you are charged with speeding at 7:25 AM on the 5th July 2011.</p>
<p>People may be tempted to open the attachment out of curiosity, or even alarm if they have been driving in New York City, but do not, or you may end up with a computer infected with malware.  </p>
<p>However, the message is certainly not from New York State Police and the attachment does not contain a speeding ticket. In fact, the attachment contains a trojan that, if opened, can install itself on the user’s computer. Typically, such trojans are able to contact a remote server and download further malware that can steal information from the infected computer and allow criminals to control it from afar.</p>
<p>The email sender address has been reported as automailer.nnn, no-reply.nnn and info.nnn, all purportedly at nyc.gov.  It goes without saying that the New York State Police and the New York State Department of Motor Vehicles have nothing to do with this email, and this should be treated as all Viruses and Spyware.  The New York State Police Computer Crime Unit has issued a <strong>Hoax E-mail Alert</strong> dealing with the <strong>Uniform Traffic Ticket Malware Spam</strong>.</p>
<p>The attached file, which is called something like Ticket-O64-211.zip, Ticket-728-2011.zip, or just Ticket.zip, is designed to download further malicious code onto your computer and compromise your security.  Sophos anti-virus products detect the malware payload as Mal/ChepVil-A, while the CyberCrime &#038; Doing Time Blog identifies that the malware connects to a Russian domain and downloads files called &#8220;/ftp/g.php&#8221; and &#8220;pusk3.exe&#8221;.</p>
<p>The <strong>Uniform Traffic Ticket Malware Spam</strong> email is probably the work of a Botnet, which is a group of computers infected with malicious software and controlled as a group without the owners&#8217; knowledge.  The network of private computers, sometimes known as zombies or robots, run autonomously and automatically to send out spam emails to encourage users to open virus or Trojan infected attachments. This means that it is pointless blocking the sender, as the sender address is forged, and unrelated to the actual computer used to send the email. </p>
<p>We recommend that you delete the e-mail it and not forward it to anyone else. Make sure that you have active anti-virus software, and have your firewall switched on.  Of course you should only open e-mails from familiar and trusted sources;  if you really have been speeding in New York City, the New York State Department of Motor Vehicles will certainly find a way to let you know!</p>
<p>For further information on this subject:</p>
<ul>
<li><a href="http://garwarner.blogspot.com/2011/08/new-york-city-uniform-traffic-ticket.html" title="Click here to see an image of the email on CyberCrime &#038; Doing Time Blog" target="_blank">Click here to see an image of the email on CyberCrime &#038; Doing Time Blog</a></li>
<li><a href="http://www.facebook.com/SophosSecurity" title="Check out the Sophos Security Facebook page" target="_blank">Check out the Sophos Security Facebook page</a></li>
<li><a href="http://troopers.ny.gov/Public_Information/2011_News_Releases/07-06-11_Hoax_E-mail_Alert.cfm" title=" See the New York State Police Computer Crime Unit Hoax E-mail Alert" target="_blank">See the New York State Police Computer Crime Unit Hoax E-mail Alert</a></li>
</ul>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/uniform-traffic-ticket-malware-spam/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/uniform-traffic-ticket-malware-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Data Protection Audit Report Published</title>
		<link>http://techcosupport.com/press/google-data-protection-audit-report-published/</link>
		<comments>http://techcosupport.com/press/google-data-protection-audit-report-published/#comments</comments>
		<pubDate>Wed, 17 Aug 2011 06:30:35 +0000</pubDate>
		<dc:creator>bgt</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[DP Audit]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[ICO]]></category>

		<guid isPermaLink="false">http://techcosupport.com/press/?p=864</guid>
		<description><![CDATA[<p>Have you ever seen the the ICO auditers? If your company was to receive a call from them, how well do think you would fare?</p> <p>This week the UK Information Commissioner&#8217;s Office (ICO) has published an Executive Summary of its Data Protection Audit Report on Google, following the revelation that Google were inadvertently collecting wi-fi <span style="color:#777"> . . . &#8594; Read More: <a href="http://techcosupport.com/press/google-data-protection-audit-report-published/">Google Data Protection Audit Report Published</a></span>]]></description>
			<content:encoded><![CDATA[<p>Have you ever seen the the  ICO auditers? If your company was to receive a call from them, how well do think you would fare?</p>
<p>This week the UK Information Commissioner&#8217;s Office (ICO) has published an Executive Summary of its Data Protection Audit Report on Google, following the revelation that Google were inadvertently collecting wi-fi signals while mapping the country. According to their website, the ICO carries out consensual audits with data controllers to assess their processing of personal information.</p>
<p>Last year the ICO became aware that that Google Street View vehicles, which had been adapted to collect publicly available wi-fi radio signals, had mistakenly collected a limited amount of payload data, likely to include a very limited quantity of emails, URLs and passwords. Google agreed to facilitate a consensual audit by the ICO.</p>
<p>The framework that was included in the audit scope is as follows:</p>
<blockquote><p>Framework: Google will conduct an internal assessment and provide a confidential written report (“Privacy Report”) to the Commissioner. This Privacy Report will analyze Google’s implementation of the privacy process changes it outlined on October 22, 2010 as it applies to Google’s UK operations. The Information Commissioner’s Office may then validate the Privacy Report’s accuracy and findings via an in-person meeting to review the Privacy Report at Google’s U.S. headquarters or at the offices of Google’s UK subsidiary. Google shall provide the Privacy Report to the Commissioner before such meeting. </p></blockquote>
<p>Google has responded to the ICO report citing that the  findings provided &#8220;reasonable assurance that Google have implemented the privacy process changes outlined in the Undertaking.&#8221;  This was posted on the European Public policy Blog by Alma Whitten, Director of Privacy, Product and Engineering, whose appointment was announced on 22 October 2010.</p>
<p>While there are a few areas for improvement noted in the executive summary, there are none that would warrant the description of Earth shattering proportions. We would consider that any company that had been subject to a consensual audit by the Information Commissioner&#8217;s Office would be quite satisfied with the report.  Knowing how good Google are at marketing, they will probably want to make capital out of it too.</p>
<p>Before we leap to judge Google, it is worth pointing out that in UK, the Data Protection Act 1998 requires every data controller who is processing personal information in an automated form to notify the ICO, unless they are exempt. Failure to notify is a criminal offense, and entries have to be renewed annually. If you are required to notify but don’t renew your registration, you are committing a criminal offense.  Do you need to register?</p>
<p>If your company was to receive a visit from the Information Commissioner&#8217;s auditors, even with nine months notice like Google, how well do think you would fare?  How many pieces of personal data has your company inadvertently collected over the years, and are still retaining for no legitimate purpose? Perhaps it would be worth a visit to the ICO website to find out if you need to do something now?</p>
<p>For more on the story:</p>
<ul>
<li><a href="http://www.ico.gov.uk/what_we_cover/promoting_data_privacy/~/media/documents/library/Data_Protection/Notices/ico_audit_google_executive_summary.ashx" title="Read the executive summary of the Google audit report" target="_blank">Read the executive summary of the Google audit report</a></li>
<li><a href="http://googlepolicyeurope.blogspot.com/2011/08/ongoing-privacy-work.html" title="Read Google's response" target="_blank">Read Google&#8217;s response</a></li>
<li><a href="http://www.ico.gov.uk/for_organisations/data_protection/notification/need_to_notify.aspx" title="ICO Do I need to notify?" target="_blank">ICO: Do I need to notify</a>
</li>
</ul>
<div align="right" style="float: right; padding: 5px 0px 0px 5px;"><a name="fb_share" type="button" share_url="http://techcosupport.com/press/google-data-protection-audit-report-published/"></a><div style="display:none;"><a href="http://government-politics.forum1000.com">government,politics</a>&nbsp;<a href="http://news365live.com">news,politics</a>&nbsp;<a href="http://worldnews365online.com">news,politics</a></div></div>]]></content:encoded>
			<wfw:commentRss>http://techcosupport.com/press/google-data-protection-audit-report-published/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

