Wednesday, June 6, 2007

Seattle "Spam King" arrested for fraud

Federal prosecutors charged Robert A. Soloway on Wednesday with 35 violations of U.S. cybercrime statues, including wire fraud, identity theft, money laundering and violations of the CAN-SPAM Act.

Soloway, who owned and operated Newport Internet Marketing Corp., allegedly offered to sell "broadcast e-mail" software and services to clients and spammed tens of millions of e-mail messages to advertise the Web sites from which he sold his products, claimed the U.S. Attorney for the Western District of Washington in a statement. Soloway used other people's e-mail addresses to make it seem as if other people sent the bulk e-mail messages, prosecutors stated in court filings. Using false information in the header of an e-mail can be a violation of the CAN-SPAM Act and constitutes aggravated identity theft, if the e-mail address belongs to someone else.

"Spam is a scourge of the Internet, and Robert Soloway is one of its most prolific practitioners," said Jeffrey C. Sullivan, United States Attorney for the Western District of Washington. "Our investigators dubbed him the "Spam King" because he is responsible for millions of spam emails."

The volume of spam seen on the Internet has risen, despite the passage of the CAN-SPAM Act. The lion's share of spam is now sent through bot nets -- networks of compromised PCs controlled by a single person or group. Using the bot nets, the most powerful groups are capable of taking companies offline, as happened to anti-spam firm Blue Security.

The prosecution has requested a ruling against Soloway, which would allow the government to seize $772,998, which it claims are the proceeds of Soloway's allegedly illegal activities.
(securityfocus)

Be Master In Google Yahoo Banking USA Indonesia Bojonegoro Nando007 NandoBJN NanangBJN Computer Hardware Software Download Free Laptop Desktop Science Technology High Insurance Email SMS MMS Handphone Nokia Siemen PC World

Insecure plug-ins pose danger to Firefox users

A security weakness in the update mechanism for third-party add-ons to the Firefox browser could give an attacker the ability to exploit unsecured downloads and install malicious code on the victim's computer, a security researcher warned on Wednesday.
The vulnerability affects any third-party add-ons that use an unsecured download site as part of the update process, according to Indiana University graduate student Christopher Soghoian, who released an advisory on the issue Wednesday. While using the standard secure communications protocol available in major browsers, known as secure sockets layer (SSL) encryption, could prevent the attacks, many major companies -- such as Google, Yahoo, Facebook, LinkedIn, and AOL -- failed to do so, Soghoian said.

"Many of companies have world-class in-house security teams, so their worst sin is not consulting their own experts, who would have undoubtedly shot down any attempt to update code over an insecure and untrustworthy connection," Soghoian said in an e-mail interview with SecurityFocus.

Soghoian, who attracted the attention of the U.S. Department of Homeland Security last year when he created an online boarding-pass generator, posted an advisory and video of the attack to his Web site on Wednesday, a month and a half after notifying Mozilla and Google of the issue.

Vulnerability researchers have increasingly targeted Firefox as the open-source browser's popularity has grown. The group improved the browser's security with its latest version, Firefox 2.0, released last October. Both Microsoft and Mozilla have argued that their own browser protects Internet users better.

In April, Soghoian decided to use a network sniffer to capture the data that Firefox sent out over the network as it was starting up. He quickly noticed that several extensions sent requests to check for new updates using plain Hypertext Transfer Protocol (HTTP) packets, without any sort of security.

"The insecure update requests stuck out like a sore thumb, and within a couple of hours, I had a working demo which proved that it was possible to hijack the extension upgrade process," Soghoian said.

Such requests could be intercepted by an attacker, if the victim used a wireless network or an untrusted wired network, he said. In particular, an attacker that had access to or control over the local domain name service (DNS) server could easily subvert the patch process. The attacker could then respond to the update request with a malicious add-on that could monitor the victim's Internet connection and steal sensitive information.

The Mozilla Foundation acknowledged the issue, but stressed that any updates downloaded from its servers user SSL and are checked against a hash.

"We strongly recommend that add-on developers require SSL for updates to prevent the attack described above," Window Snyder, chief security officer for Mozilla, stated in a post to the group's developer blog.

The Mozilla Foundation released on Wednesday a patch for both version 1.5 and version 2.0 of the browser, fixing a critical memory corruption flaw.

Ironically, an amateur developer coding up a plug-in for Firefox will be much less likely to have to worry about the issue than a large company. Because most smaller developers use the Mozilla Foundation's Add-ons download site, they are more likely to be secure.

Google, for example, not only uses an unsecured connection to check for and download updates, but also suppresses any notification that an update is being installed, Soghoian said. The company has already created a patch and will automatically be updating Google Toolbar users soon, a representative said.

"We were notified of a potential vulnerability in some updates for Firefox extensions," the representative said in a statement sent to SecurityFocus. "A fix was developed for the Google extensions and users will be automatically updated with the patch shortly. We have received no reports that this vulnerability was exploited."

Soghoian, who spent last summer interning at Google, hopes that the search giant will also reconsider its decision to update users without notification. Firefox users now need to take a critical look at the third-party add-ons installed on their browser, and having as much information as possible helps, Soghoian said.

"As a matter of general policy, vendors really should not have their software silently install updates without asking the user's permission -- it is asking for trouble," he stated in his advisory.

The Mozilla development team is currently considering ways that they could prevent insecure updates in the next version of the browser, Firefox 3.0, the group said on its blog.
(securityfocus)

Be Master In Google Yahoo Banking USA Indonesia Bojonegoro Nando007 NandoBJN NanangBJN Computer Hardware Software Download Free Laptop Desktop Science Technology High Insurance Email SMS MMS Handphone Nokia Siemen PC World

Online thieves nab $450,000 from town coffers

A keylogger on the computer of the Carson, Calif., treasurer enabled online thieves to transfer nearly half a million dollars to other bank accounts, according to news reports.

The thieves made two transfers: The first on May 23 for $90,000 and the next for $358,000 on the following day, according to a report in the Los Angeles Times. Carson Treasurer Karen Avilla noticed the transfers on May 24 and, with the help of the town's bank, froze all but $45,000 of the money. A computer forensics team from the bank found a Trojan horse on her city-issued laptop, according to a report in ComputerWorld.

"We're vigilant in checking our (bank) balances daily," she told ComputerWorld. "I think the only thing you can do (to keep your money safe) is look at it with your own two eyes."

Following legislation that requires companies and organizations to disclose data breaches, news of online thieves making off with people's data have become commonplace. The theft of funds from companies is far less likely to be reported. A massive breach of retail giant TJX Companies' processing systems led to the loss of information on at least 45.6 million credit and debit cards.

The U.S. Secret Service is currently tracking the path of the $45,000 missing from the accounts, media reports stated.

(securityfocus)


Be Master In Google Yahoo Banking USA Indonesia Bojonegoro Nando007 NandoBJN NanangBJN Computer Hardware Software Download Free Laptop Desktop Science Technology High Insurance Email SMS MMS Handphone Nokia Siemen PC World

Search engines reduce risky results, says report

The chance of encountering a questionable or malicious site among search results dropped to 4 percent in May, as most search engines continue to work to cull dubious sponsored links, stated a report published on Monday by SiteAdvisor, a subsidiary of security firm McAfee.

The report surveyed the SiteAdvisor ratings of the top-5 search engines, which represent 93 percent of all searches on the Internet, and found that those that linked to risky Web sites dropped to 4 percent of all results, compared to 5 percent a year earlier. Most of the improvement came from better vetting of the sponsored links that the search engines place in a prominent position for a fee. This year, 6.9 percent of such links were considered risky, down from 8.5 percent a year ago.

"These differences indicate search engines’ control over the sites they promote," the report stated. "Search engines can look the other way while dubious ads run rampant, but they can also set and enforce tough editorial policies to keep bad ads out."

SiteAdvisor regularly scans sites that account for the lion's share of all Web traffic, rating dangerous pages as 'red', questionable pages as 'yellow', and legitimate sites as 'green'. In March 2006, the company found that sites accounting for 5 percent of all Web traffic attempted to upload hostile programs to a visitor's computer, or acted in some other malicious way. Sites that accounted for another 2 percent of traffic received the company's yellow rating.

In the latest survey, America Online's search engine had the fewest risky search results at 2.9 percent, while Yahoo's search engine had the most at 5.4 percent

(securityfocus)

Be Master In Google Yahoo Banking USA Indonesia Bojonegoro Nando007 NandoBJN NanangBJN Computer Hardware Software Download Free Laptop Desktop Science Technology High Insurance Email SMS MMS Handphone Nokia Siemen PC World

List