The Digital Rag
Real World Information in a Virtual World
Sign Up!
Login
Welcome to The Digital Rag
Sunday, May 19 2013 @ 07:21 AM PDT
eMail Article To a Friend View Printable Version Subscribe to 'Digital Rag News'

threat level YELLOW - Microsoft Excel via Internet Explorer exploit happening

The Internet Storm Center has just raised their threat level to Yellow
(from green) due to an active exploit "in the wild" of a major security
problem with Internet Explorer and the components that allow Microsoft
Office documents like spreadsheets (Excel) to take over your computer.

The details are at http://isc.sans.org/diary.html?storyid=6778
but the bottom line is that until Microsoft puts out a fix and your
machine is patched (you do have automatic updates on, don't you!!!) it
is possible that you may receive a Microsoft document with embedded HTML
code in it that will infect your computer. This can be done simply by
visiting the wrong web site and clicking on an ad or other link.

I've long said that before you open any document you receive you should
check with the person who sent it to you to ensure that they really did
send it - and that THEY MADE IT - not just passed it on from someone
else.

There are all manner of PowerPoint and Word documents being sent around
with pictures and such in them that are inspirational or funny or timely
or...

BUT - the bad guys are sending stuff like this out too - and they can
and many times do contain viruses. This is just the latest of a bunch of
exploits that attack Microsoft's software and web facilities.

Just remember - Microsoft's systems were originally designed to work in
a FRIENDLY network environment - they simply did not design them to be
used in the hostile environment of the internet- that was added later,
and they're still trying to fix all the holes and design problems that
don't fit with a hostile network environment.

If you really MUST open these things I cannot urge you enough to
download and install Open Office (http://download.openoffice.org) -
that's what I use, and it is not as closely tied into the operating
system as the Microsoft Office components are so has far less likelihood
(not none - just far less) of being a virus carrier.

richard

eMail Article To a Friend View Printable Version Subscribe to 'Digital Rag News'

Adobe PDF Compromise - and Parking Ticket Scam

Newsletter Postings

Adobe's Version 8 and 9 PDF readers - Acrobat and Reader - will be patched March 11 according to my information sources. In th mean time you should watch out!

And hey - when was the last time you got a parking ticket that installed malware on your computer? Just wait!


eMail Article To a Friend View Printable Version Subscribe to 'Digital Rag News'

Anti Virus 2009 and other nasty stuff

Newsletter Postings

The browser/phishing wars keep getting harder to beat. Now we have bogus "session expired" screens popping up when you're legitimately logged into your bank's web site. We also have nasty trojans that stop your system from getting help by blocking access to Microsoft Update and your favourite anti-virus sites.


eMail Article To a Friend View Printable Version Subscribe to 'Digital Rag News'

Nasty "Trojan horse" exploit already out for high priority Microsoft fix

Newsletter Postings

Microsoft yesterday took the non-typical step of issuing an update for most of their operating systems "out of band" - meaning not at the usual time of month. This particular exploit they are patching affects anything except Windows 95/8 it seems


eMail Article To a Friend View Printable Version Subscribe to 'Digital Rag News'

Vhishing and VOIP - authenticating who you are speaking to

Newsletter Postings

Over the weekend I received a phone call from someone purporting to be from a major credit card company offering me a great deal on balance transfers, etc.

Sometimes I brush these calls off but sometimes I let them ramble - both to learn about how they do what they do, and to in some cases teach them about how at least I (and hopefully you too) view their methods and expectations of what we will and won't give them in the way of information.

In this case I was mildly surprised - but not much - at what this person knew about me - name, company name, address, phone number (they used the business line, not the home one) etc.


eMail Article To a Friend View Printable Version Subscribe to 'Digital Rag News'

Flash Ads Infect Browser Clipboard - Nasty!

Newsletter Postings

Firefox, IE and Safari web browsers are all being attacked (yes, including Firefox on MAC and Linux) by a malicious/nasty Flash banner ad campaign including banners on some very popular sites.

The attack takes the form of copying a URL that points to a nasty site onto the browser's Clipboard - where cut/paste operations are stored.


eMail Article To a Friend View Printable Version Subscribe to 'Digital Rag News'

Digital Rag - New Mail Facilities and some tips

Newsletter Postings

Welcome to our new mail-list software. Like "Mailman" this too is open source software - called phpList from tincan limited in the UK. I've been using Mailman for quite a number of years and will continue to use it for what it was meant for - mail lists where members correspond with one another.
On the other hand, many of my customers need mail list software for sending out messages - marketing information, answers to questions, bulletins, support information, etc. where all the traffic is outgoing, and where the fact that someone has read a particular message and acted upon it (feedback) needs to be tracked somehow.


eMail Article To a Friend View Printable Version Subscribe to 'Digital Rag News'

Update your Browser!!!

Newsletter Postings

A recent study found that at least 45.2% of web users were not using the most secure version of their chosen browser, be it Internet Explorer, Firefox, Safari or whatever. But it gets better... most of them (577 million out of 637 million in the survey) are using an old version of Internet Explorer. The rest include 38 million users of Firefox, 17 million users of Safari and about 5 million users of Opera.

You're not one of those with an old version - are you???


eMail Article To a Friend View Printable Version Subscribe to 'Digital Rag News'

Linksys and D-link Firewall/Router owners - beware of the latest attack!!

Newsletter PostingsSeveral of my daily reading sources have pointed out new attacks on popular consumer firewall/router hardware including those of Linksys and D-link although not limited in any way to these ones.

The malware changes the DNS hosts to ones the bad-uglies control - and so instead of going where you think you are going when you browse the Internet, you go instead where the crooks want you to go with no obvious way of knowing you are in the wrong place.

The attack works because the malware tries to (and is successful) hack the router's web interface from one of the "protected" computers inside your Local Area Network (LAN). How the malware (DNSChanger Trojan) gets onto the inside computer is not specifically stated, probably because there are several ways currently being used:
1 - infected legitimate web sites that a user visits
2 - lots of e-mail methods including "phishing" and "social engineering" to get people to visit an infected site or download the malware directly.
3 - trying to view a video the system (itself compromised) tells you that you need a new video CODEC - and the codec is instead the trojan

eMail Article To a Friend View Printable Version Subscribe to 'Digital Rag News'

Adobe Flash Player - still being exploited

Newsletter Postings

I read a bulletin from the Internet Storm Center http://isc.sans.org/diary.php?storyid=4465 a couple of days ago about the fact that there are active exploits (nasty advertising links and videos) already on the net for a vulnerability that has just surfaced with all current and previous versions of Adobe's flash player.

It turns out this is an old attack and that the affected player versions are still being used by many people. You should check your IE and Firefox (and other) browsers separately for the version of the Adobe flash player they use. This can be done by browsing to this address: http://kb.adobe.com/selfservice/viewContent.do?externalId=tn_15507

In my case my Firefox on Linux is 9.0.124.0 - which is the correct/latest one - my Windoze box is down for the count after a power burp a couple of days ago - but I'll check it as soon as I have it back up. It's a good thing I don't rely on Windows eh???

What's New

Stories

No new stories

Comments last 2 days


Trackbacks last 2 days

No new trackbacks

Older Stories

Monday 28-Nov


Friday 07-Oct


Tuesday 04-Oct


Thursday 15-Sep


Saturday 10-Sep


Tuesday 30-Aug


Saturday 20-Aug


Thursday 18-Aug


Sunday 14-Aug

?

Ads by Clickochet

G+ Public Posts

There was a problem reading this feed (see error.log for details).
?

G+

?

Facebook Page

RSS Feed

Richard's Digital Rag

Poll

How do you like to find out news about the internet and computers?

  •  Newspaper
  •  Radio
  •  TV
  •  Web Search
  •  Favourite Web Site(s)
  •  Pod Cast
  •  Video Online
  •  Email List(s)
  •  RSS - Syndication
  •  Word of mouth
This poll has 0 more questions.
Results
Other polls | 53 votes | 0 comments