Google Search

Showing posts with label photos. Show all posts
Showing posts with label photos. Show all posts

Thursday, July 4, 2013

Uncool hacker blamed for unrevealing swimsuit photos of singer Victoria Justice

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Victoria JusticeAmerican singer Victoria Justice is not happy that someone (she blames a hacker) has leaked swimsuit photos of her onto the internet.

I've never heard of Victoria Justice, which may mean that the 20-year-old singer isn't targeting my particular demographic, but she's clearly famous enough to make headlines when she claims that the photos published of her were stolen by a hacker.

Media who covered the story described the leaked photos as "semi-racy... but nothing of the R-rated variety, showing Victoria fully clothed but in a bathing suit".

Clearly, however, Justice - who has her own show on Nickelodeon called "Victorious" - was not amused and is seeking, err, justice.

Hacking & stealing is NOT COOL. #RespectPeoplesPersonalProperty #Karma

And she's right, of course, hacking into someone's private accounts and stealing photos is *not* cool. And it's even less cool for websites to take the stolen images and to publish them on the net.

And yet it seems to keep on happening, and the websites appear to get away with it Scott free.

For instance, we've seen "news" websites publishing intimate snaps of Scarlett Johansson, Mila Kunis, Christina Aguilera, and many other celebrities in the past without any apparent consequences.

Although hackers can receive harsh penalties for accessing celebrity accounts and stealing photos, we don't hear anything about the gossip websites that willingly went public with the stolen material.

So I was at least pleased to see Victoria Justice take the magazine that published the snaps of her in her swimsuit to task via Twitter, and was pleased to hear that the magazine subsequently removed the pics from their site.

Follow @gcluley

Image of Victoria Justice courtesy of jake.auzzie/Flickr (Creative Commons)


View the original article here

Sunday, April 7, 2013

Ex-President Bush doxed - family photos, personal email, bathtub portraiture leaked

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

George H W Bush George H W Bush

A hacker using the alias "Guccifer" has claimed responsibility for hacking the Bushes, aka the political family that gave the US its 41st president (George H.W. Bush) and its 43rd president (George W. Bush).

In email exchanges with The Smoking Gun, the hacker indicated last week that he (the male gender having been indicated by The Smoking Gun's coverage) had breached at least six email accounts, including:

The AOL account of Dorothy Bush Koch, daughter of George H.W. Bush and sister of George W. Bush;Willard Heminway, 79, an old friend of the 41st president; CBS sportscaster Jim Nantz, a longtime Bush family friend; former first lady Barbara Bush’s brother; and George H.W. Bush’s sister-in-law.

The Smoking Gun reports that the hacker claims to have stolen and published private material, including "interesting mails" about George H.W. Bush's recent hospitalization, "Bush 43," and other Bush family members.

The doxed material allegedly contains a confidential October 2012 list of home addresses, cell phone numbers, and emails for dozens of Bush family members, including both former presidents, their siblings, and their children.

Intimate details were stolen, including a four-digit code needed to enter a Bush home security gate, as well as correspondence about the need to write a eulogy for the elder Bush, who was hospitalized and assumed to be on his death bed at the time.

Bush emails

Photos of George W.'s self-portraits were also published.

If you can't live without having experienced the 43rd president's knobby knees sticking out of a bathtub or ex-presidential lathering in a steamy shower, the internet can now ease your need. No worries, the paintings are safe for work.

Guccifer also posted private photos of the Bush family, which The Smoking Gun republished.

The hacker told The Smoking Gun that "The feds" began investigating him a "long time ago," and that he has hacked "hundreds of accounts."

He also downplayed the FBI/Secret Service investigation that's sure to come, saying:

"I have an old game with the f**king bastards inside, this is just another chapter in the game."

What hubris, to pick on innocent people in the execution of a "game".

Regardless of whether you approve of the political agenda of the Bush dynasty, you've got to feel sorry for those whose personal correspondence, photos and artwork gets pulled into the glaring light of the public eye just to satisfy some guy's ego.

The takeaway: take care of what you send electronically. We're all fair game to be picked on by bullies like Guccifer.

If you don't want to see your words and images held up for public scrutiny and ridicule, think twice before you hit send.

By the way, the Bushes are far from the first Republican politicans to have suffered at the hands of hackers. Perhaps most memorably, Sarah Palin had her private Yahoo email account broken into when she was campaigning to be vice-president. On that occasion, the hacker ended up with a prison sentence.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Thursday, January 31, 2013

Carly Rae Jepsen nude photos hacker suspect arrested

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Carly Rae Jepsen. Image from ShutterstockBack in July, word reached Naked Security that nude photos of pop starlet Carly Rae Jepsen had allegedly been stolen from her personal computer, sparking an investigation by police.

According to media reports, a
25-year-old man is said to have now turned himself in to Vancouver police in relation to the theft.

Christopher David Long has been charged with fraudulently obtaining telecommunications services, unauthorized use of computer, mischief to data, identity fraud, and possession of stolen property.

It is alleged that Long was attempting to sell images of the "Call Me Maybe" singer to various websites.

Which, if true, reminds me rather of the case of Christopher Chaney who hacked into the email accounts of various female stars, including Mila Kunis, Christina Aguilera and Scarlett Johansson.

Clearly everyone - celebrity or not - should be ensuring that they use strong, hard-to-crack passwords and defend your computers with up-to-date security software.

But if you still worry that you could potentially fall victim to a hacker stealing naked pictures of yourself, here is my further advice. (I originally offered it to Mila Kunis, but it actually works for anyone who is worried that hackers may steal their nude photographs):

Cut-out-and-keep reminder

Long has been released from custody and is due to appear in court on January 4th 2013.

Follow @gcluley

Carly Rae Jepsen image from Shutterstock.


View the original article here

Saturday, December 15, 2012

Just how well do Android privacy apps hide your sexy photos and secret texts?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Android appsDo you have photographs on your smartphone that you don't want others to see? If an app publisher tells you that they will keep your secrets safe would you trust them?

The best advice when it comes to privacy and photos is "don't take a photo that you don't want your teacher/boss/mum/dad to see".

But as this advice is not always heeded, the next best thing is to keep them safe from prying eyes should anyone borrow, steal or find your phone.

Encouraged by a recent article on the shortcomings of the Snapchat safe sexting app, I tried a few apps that promise to protect your privacy, but often fail to do anything of the kind. These examples are all based on tests I conducted on an Android smartphone, but many of the apps are also available for iPhone.

Secret Pictures

First I tested Secret Pictures which describes itself thus:

"Prevent your pictures from letting others know! ... Pictures vanish from Gallery and are locked behind easy-to-use PIN pad. Protect your private pictures ... Secret Pictures locks your private pictures with your PIN. Only you can see the pictures in Secret Pictures."

It sounds very much like your pictures are protected, hidden from view, secured, etc.

But all it really does is move photos to a poorly hidden directory from where the photos can be viewed and shared. All it takes is a file browser and your privacy is ruined!

Photo Safe

Next is Photo Safe which markets itself with the slogan

"Protect Your Privacy! ... No one touches your private data without permission!"

Again, the app gives a definite impression that your hidden photos are safe from prying eyes, and again the app moves your photos out of the gallery - but this time the directory is not even hidden.

Instead the PhotoSafe app renames the file you want to hide in a weak attempt to disguise it, putting some extra characters after the file extension.

This photo is not hidden, protected or secured

You can either rename the file or instruct the phone that the file is an image, and once again it is viewable and shareable just like any normal photo.

KeepSafe Vault

Next in my list was KeepSafe Vault. This app describes itself as the

"Best hide pictures & video app on Android ... Selected pictures vanish from your photo gallery, and stay locked behind an easy-to-use PIN pad. With KeepSafe, only you can see your hidden pictures. Privacy made easy!"

I started to see a recurring theme in the promises that these apps make.

This one has similar failings as the first two apps, using a weakly hidden directory and renaming the images, again easily overcome with nothing more than a file browser.

Hide Pictures and Text messages

It's not all doom and gloom though. There are some apps for hiding the pictures and text messages on your Android which live up to their promises although they all seem to come with some trade-off. You really don't get something for nothing when it comes to apps.

Take, for instance, Hide Pictures & Text Messages:

" lets you hide or encrypt almost anything on your phone including photos, videos, contacts, text messages, and other apps."

For once, when they say they encrypt the content they actually mean it. You can still browse to the directory where files are stored but any feasible attempt to open them outside of the app results in a "Load failed!" error message.

The app lets you hide its own icon too so people won't even know that you have an app for hiding stuff.

All this functionality does come at a price though.

After an initial number of free uses you have to pay in order to be able to encrypt or hide further files.

Due to the extra functionality you will also need to hand over a lot of access permissions to your phone and given that you're looking for extra security and privacy, this may be something that you have reservations about.

Private Gallery

Another promising looking app is Private Gallery which also seems to encrypt your photos meaning they can not easily be viewed outside of the app.

This app is free but it's supported by adverts from an ad network that compromises on security by transmitting the location and identification data from your phone in the clear.

The app also requires some permissions which seem unnecessary given its purpose (for instance, the ability to dial numbers and view/edit your browser history).

Again, if you're in the market for added security and privacy then these concessions may concern you.

Vaulty

The last app I tried was Vaulty which also seems to live up to its promises.

Vaulty looks a little more considerate in that it asks for a more acceptable list of permissions. It also offers a decent balance of functionality in the free version with optional extras in paid-for plugins. If I had a need for a photo/text message privacy app I'd probably go for this one as it seems to ask for the least in return for the most.

Looking into the history of Vaulty highlighted a different problem though.

An automatic update from the developer borked the app for many users, rendering their encrypted files inaccessible. The fault was corrected in a rushed patch but it still demonstrates that should this happen again your protected photos and files might not always be recoverable.

Of course, this risk applies equally to any app which encrypts your data.

In summary, not all apps are created equal and two apps that appear to offer the same service might in fact give very different levels of functionality.

Android tabletSooner or later I expect we'll see an app developer being held accountable for leaked secrets. After all, they promised the unsuspecting user that they would protect those secrets.

It would be better if the descriptions of these Android apps properly reflected what each app does and does not do. At least then users can make an informed choice about how much they wish to trust the app, and whether it is sufficient for the intended purpose.

And, of course, my advice echos those who have gone before me - there is really no situation where you absolutely have to store on your phone naked photographs of yourself.

If you have a photograph or sensitive information that you don't want others to see then try to avoid putting it on a device that others are likely to use.

If you're still determined to go ahead then avoid having anything identifiable in the frame, both of yourself and in the background of the picture.

That way you can at least pretend that it's not you in the photograph when it falls into the wrong hands.

Follow @thegaryhawkins
Follow @NakedSecurity


View the original article here

Tuesday, December 11, 2012

Blackhole malware attack spread via 'Your photos' email

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Blackhole photo. Image from ShutterstockA malware attack has been spammed out widely via email to internet users, posing as a message about photos.

In the attack, cybercriminals attempt to trick unsuspecting users into opening an attached file in their browser, redirecting them to a webpage hosted on a Russian website that takes advantage of the Blackhole exploit kit.

The notorious Blackhole exploit kit then attempts to infect visiting computers through a wide number of vulnerabilities.

Here's a typical message that has been spammed out - in this case, pretending to come from a LinkedIn user:

Malicious email

Subject: Your Photos

Message body:
Hi,
I have attached your photos to the mail (Open with Internet Explorer)

The attached file has a name of Image_DIG[random number].htm. If you make the mistake of opening the file attachment in your web browser you will see a "please wait" message:

Please wait a moment. You will be forwarded..

Internet Explorer or Mozilla Firefox compatible only

Webpage

Sophos detects this HTML file proactively as Mal/JSRedir-M. What isn't obvious to most computer users is that behind-the-scenes obfuscated JavaScript code is redirecting the user's browser to a Blackhole exploit site.

Obfuscated JavaScript code

More and more of the attacks that the folks at SophosLabs are intercepting involve the Blackhole exploit kit, underlining the importance of keeping your computer's anti-virus software and software patches up-to-date as well as learning to exercise caution about opening unsolicited attachments or clicking on unknown links.

Learn more: Exploring the Blackhole exploit kit

http://twitter.com/gcluley

Black hole illustration image from Shutterstock.


View the original article here

Wednesday, November 21, 2012

Nude photos of Justin Bieber a ruse: bellybutton tells the tale! Think before you click

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Justin BieberDon't click on that photo of Justin Bieber!

It's not him, fans say.

Sure, there's the trademark bird tattoo on the left hip, but the nipples are all wrong.

A photo distributed on the internet shows a headless naked male body engaged in what might perhaps be a sexual act with himself.

It was allegedly leaked when a thief made off with the singer's laptop and camera after a show in Washington.

The gadgets contain "a lot of personal footage," the star tweeted within hours of the theft:

There's just so much wrong with this picture, and I'm not talking about Justin Bieber's pink parts.

The first bit of wrongness has to do with anybody who'd actually risk their cyber security by clicking on an alleged celebrity photo.

The land of Twitter has plenty of skeptical Twitizens, but so too does it have far too many drooling fans eager to click on JB's charms.

Take Breanna, for example:

Hopefully, young fans like Breanna have wise friends who can educate them regarding malware, which loves to hitch a ride onto PCs using come-ons like nude celebrity pictures.

Earlier this week, Microsoft released its most recent Security Intelligence Report, which showed that photos, movies, software and other media are increasingly infested with Trojans and other attack vectors.

Anybody who goes out searching for nude photos of celebrities is just asking to be taken advantage of.

There's a long history of malware authors making the most of splashy celebrity-related headlines, whether it's the death of Michael Jackson or Amy Winehouse, Rihanna sex videos or a purported video of the killing of Osama Bin Laden.

Beyond the danger of clicking on what could be malware-laced photos, what in the world is Bieber doing storing personal footage on a laptop that hasn't been properly encrypted and secured with a strong password?

Sophos's Graham Cluley made this YouTube video a while back to explain how to choose a hard-to-crack but easy-to-remember password, but if you're tackling the task of security education for Beliebers, you might want to cut right to the part where he addresses password management software programs like 1Password, KeePass and LastPass, any of which will lift the task of remembering all their different passwords.

And with that accomplished, we will leave Bieber's fans to the task of bellybutton analysis.

But do point out to them that, as the Huffington Post shows, the star's belly button is clearly an outie.

Follow @LisaVaas

View the original article here

Saturday, October 27, 2012

Companies agree to stop spying, taking secret photos on rented home computers

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Webcam. Image from ShutterstockThe US Federal Trade Commission has reached a settlement with seven computer rental companies and a software firm over what the agency said was flagrant computer spying on customers of the rental stores.

In a statement Wednesday, the FTC said that DesignerWare LLC and seven rent-to-own computer stores agreed to cease using malware-like monitoring software to track rental PCs and from using information gathered by the spying software for debt collection purposes.

According to the FTC, the software captured screenshots of confidential and personal information, logged users' keystrokes, and in some cases took "webcam pictures of people in their homes, all without notice to, or consent from, the consumers."

The settlement stems from what an FTC complaint (PDF link) says was a years-long campaign of electronic spying by PC rent-to-own firms against customers using PC Rental Agent, a remote monitoring application made and marketed by DesignerWare that can disable or remotely wipe a rented computer, but also monitored a user’s online activity and physical location using a feature called "Detective Mode."

PC Rental Agent is installed on 420,000 systems worldwide through 1,617 rent to own stores in the United States, Canada and Australia.

According to an FTC complaint, the software was installed and operated without the knowledge or consent of renters. Ostensibly used to track lost or missing rental systems or disable computers in the possession of renters who had stopped or fallen behind on their payments, PC Rental Agent was used for far more nefarious types of surveillance in the hands of DesignerWare’s customers.

By instructing the firm to activate the Detective Mode feature, for example, the rent-to-own shops charged in the FTC complaint collected private and confidential information about the computer user.

Username and password. Image from ShutterstockThis included usernames and passwords for access to email accounts and social media websites, as well as screenshots of websites containing confidential information like medical records, Social Security Numbers and bank account numbers, the FTC said.

A feature added to the software in September, 2011, also enabled remote tracking of computers running the software by tracking the WiFi hotspots the system connects to against a public database of hotspots.

This was hardly a surprise to DesignerWare’s corporate customers.

An excerpt from an email exchange cited by the FTC in its complaint has DesignerWare co-founder Timothy Kelly pitching PC Rental Agent to a prospective customer by saying that it works "like malware" that could "steal credit cards or someone’s information."

The FTC said that the DesignerWare and its customers took that analogy a bit too far - violating federal laws by monitoring users without their consent, and using fraudulent means (a phony Windows registration page) to collect personal information about them.

Personal and financial information on victims was, in some cases, used by the rent-to-own companies to assist in bill collection, the FTC said. However, it also appears that the software was used for more prurient purposes, as well.

"Consumers are harmed by DesignerWare’s unwarranted invasion into their homes and lives and its capture of the private details of individual and family life, including, for example, images of visitors, children, family interactions, partially undressed individuals, and couples engaged in intimate activities," the FTC said.

Detective. Image from Shutterstock"Sharing these images with third parties can cause consumers financial and physical injury and impair their peaceful enjoyment of their homes," the FTC complaint reads.

As part of its settlement, the FTC banned DesignerWare and the seven rent-to-own stores named in the complaint from using monitoring software like Detective Mode and from using deception to gather information on customers.

It also prohibits the use of geo-location tracking without consumer consent and notice, and bar the use of fake software registration screens to collect personal information from consumers.

DesignerWare is barred in the settlement from providing others with the means to commit illegal acts and will be monitored by the FTC for compliance for the next 20 years, the FTC said.

Follow @paulfroberts
Follow @NakedSecurity

Webcam, detective, username and password images from Shutterstock.


View the original article here

Sunday, September 2, 2012

Facebook is finally deleting your 'deleted' photos

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Bin image courtesy of ShutterstockIt looks like the whole Facebook-not-deleting-your-photos-when-it-said-it-had saga might be coming to an end.

Back in February, we reported that the "Delete this photo" button wasn't actually deleting the photo from Facebook's content delivery networks, at least not for a long while anyway.

So despite the photo disappearing from your profile, if you plugged the image url straight into your browser you could still see it.

It's less shutting the door on the photo and more masking it with a beaded curtain.

Now the problem has been fixed, as Frederic Wolens from Facebook told Ars Technica:

As a result of work on our policies and infrastructure, we have instituted a 'max-age' of 30 days for our CDN links.

However, in some cases the content will expire on the CDN much more quickly.

I tried it myself and it instantly seemed to work:

Facebook photo deleted

This content is currently unavailable

The page you requested cannot be displayed at the moment. It may be temporarily unavailable, the link you clicked on may have expired, or you may not have permission to view this page.

This all sounds like good news. Although it's important to remember that if something has been ever posted on the internet, it's possible that someone could have grabbed it and posted it somewhere else.

So that nude photo of you riding a camel, carrying firecrackers in each hand and balancing a chair on your head might not have disappeared forever.

By the way, you can keep up to date on the latest changes to Facebook by liking the Sophos Naked Security Facebook page.

Follow @NakedSecurity

Bin image courtesy of Shutterstock


View the original article here

Friday, July 20, 2012

You pig! Malware-laced emails spammed out posing as incriminating photos

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A widespread malware attack has been spammed out, posing as incriminating photos of the recipient which could get them in trouble with their partner.

The emails, which have the subject line "You pig!", are designed to infect Windows users and carry a malware attachment posing as a digital photograph.

Malicious email

Subject: You pig!

Message body:
You should be stoping ignoring me or i will send this photos to your spouse!!!

Attached file: DCIM.zip

The emails can claim to come from a variety of different places, including LinkedIn, UPS and Hotmail.

Although the malware-laden emails are poorly spelt, it wouldn't be a surprise at all to hear that many people would be tricked by the aggressive tone to open the attachment. Unfortunately, the contents of the ZIP file are designed to infect Windows computers with a Trojan horse.

The subject line "You pig!" is certainly enough to make many people stop in their tracks, and wonder what has just arrived in their inbox.

SPAM®It strikes me that even those who rightly suspect the email is spam, might be bemused enough (considering the main ingredient of what Hormel Foods nearly called flappertanknibbles) to open the messages and explore further.

Sophos detects the malware inside the ZIP files as Troj/Agent-WXL and the ZIP files themselves as Troj/BredoZp-KP. If you are a user of a product from other vendors check that your software is up-to-date and intercepting the malware.

http://twitter.com/gcluley

View the original article here

Sunday, June 3, 2012

Apple's iCloud syncs stolen iPhone photos to nab thief

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Creative Commons photo of Disney's Wonder cruise ship courtesy of Justin ChampionKaty McCaffrey *had* an iPhone. Until it was stolen aboard the Disney cruise ship Wonder on her April vacation. What to do? As is frequently the case these days, the cloud holds the answer.

After returning home sans iPhone, McCaffrey discovered that photos were showing up in her Apple iCloud account from her missing device.

Taking advantage of the openness of social media and the ability for average folks to get the word out McCaffrey decided to post the photos to Facebook in an attempt to identify the thief.

Titled "Stolen iPhone Adventures" McCaffrey posted humorous captions on the photos allegedly being posted by a crew member named Nelson. The media caught wind of the story and tens of thousands flocked to the page bringing it to the attention of Disney.

It is unclear whether Nelson was in fact the thief, or if he simply purchased the stolen phone from someone else on board the ship. It isn't looking good for him at the moment though.

A Disney spokesperson told USA Today that they had recovered the phone and have placed the crew member on administrative leave and restricted him from guest areas on the ship.

The spokesperson also stated "We have a zero-tolerance policy for this type of behavior, We are taking aggressive action."

This story does raise some legitimate concerns about smartphone safety however. If your phone is stolen, you should immediately report it stolen and cancel the service to prevent the thief from racking up a large cellular phone bill.

Find my iPhoneMcCaffrey clearly was using Apple's iCloud service, so why did she not take advantage of the remote lock/remote wipe service that is part of iCloud?

Playing amateur detective rarely works out the way it appears to have this time and even without the photos the "Find my iPhone" app would likely have allowed law enforcement to locate the thief.

It would also appear that McCaffrey did not bother to secure her phone with a password. Last summer 70% of smartphone users admitted to not using a passcode in a Sophos survey.

The good news? McCaffrey will get her iPhone back and the thief will be investigated for the crime.

The lesson? Don't take chances like McCaffrey. While this story may be entertaining, you are far better off to secure your device, ensure your data is erased if it's stolen and take advantage of our free mobile security toolkit.

http://twitter.com/chetwisniewski

Creative Commons photo of Disney's Wonder cruise ship courtesy of Justin Champion.


View the original article here

Tuesday, October 25, 2011

Malware attack poses as bloody photos of Gaddafi's death

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

GaddafiThe death of Libyan dictator Colonel Gaddafi has almost inevitably resulted in cybercriminals taking advantage of the news story, and the general public's seeming interest in viewing ghoulish photos and videos of his last moments.

Malicious hackers have spammed out an attack posing as pictures of Gaddafi's death, tricking users into believing that they came from the AFP news agency and are being forwarded by a fellow internet user.

A typical message looks like this:

Gaddafi malware attack

Subject: Fw: AFP Photo News: Bloody Photos: Libya dictator Moammar Gadhafi's Death

Message body:

Libya dictator Moammar Gadhafi's Death

Libyan dictator Moammar Gadhafi, the most wanted man in the world, has been killed, the country's rebel government claimed Oct. 20. The flamboyant tyrant who terrorized his country and much of the world during his 42 years of despotic rule was cornered by insurgents in the town of Sirte, where Gadhafi had been born and a stronghold of his supporters.

Attached file: Bloody Photos_Gadhafi_Death.rar

Windows computer users who decompress the attached file are putting their PCs at risk of infection. The RAR archive file creates a malicious file called:

Bloody Photos_Gadhafi_Death\Gadhafi?rar.scr

Sophos anti-virus products detect the malware proactively as Mal/Behav-103.

Although there has been much speculation in the media about the possibility of Gaddafi-related malware attacks and scams, this is the first one that I've seen since the death of Gaddafi made news headlines around the world yesterday.

Internet users would be wise to remember to be very careful about the links they click on, and to be suspicious of unsolicited attachments.

http://twitter.com/gcluley

View the original article here