Friday, February 8, 2008

Fake Critical Windows Vista Update Installs Malware

Free Image Hosting at www.ImageShack.usAttacks that are using Windows Updates in order to spread malware and compromise Microsoft platforms are nothing more than an integral part of the luxuriant threat environment that preys on unsuspecting users. But generally the attacks masquerading as Microsoft Updates are nothing more than social engineering tricks devised to essentially convince the end user to become an active
participant in the compromising of the system. In this context, the level of authenticity of emails allegedly delivering Windows updates is rather low, as such a practice was never deployed by the Redmond company.

In this context, attackers are now seeking to replicate as closely as possible the actual experience that Windows users do associate with the Redmond company. Such as the Microsoft Update. The actual Microsoft Windows Update site can be found here and it is sensitive to the context of the operating system, meaning that when a Vista user will visit the website, the page will change to reflect the platform. Security outfit F-Secure has warned Windows users of the existence of a spoofed Microsoft Update site that spreads malware.

Fake Microsoft Update Site
Free Image Hosting at www.ImageShack.us
The fake Microsoft Update website urges users to immediately install a Critical security update for Windows 2000, Windows Server 2003, Windows XP and Windows Vista. The social engineering scheme is put together to effectively scare the user into installing malware on their machine.

"Watch out for this one. It's not the real Microsoft Update site. Note the real URL (cfm48.com) and the spelling errors ('Please intall'). If you click the Urgent Install button, you'll get a file called WindowsUpdateAgent30-x86-x64.exe, which is not signed by Microsoft. (i.e. Click the button — Download a Trojan-Dropper.) The dropper is now detected as Trojan-Dropper:W32/Agent.DYD, and the dropped malware was already detected as Backdoor:W32/Agent.CVU; this is functionally the same as the earlier Backdoor:W32/Agent.CTH," a F-Secure security expert revealed.

Seize the Best Graffiti Spots via Google Maps

Free Image Hosting at www.ImageShack.us
That’s the name of the website that shows you the best places you could "spray" your contribution to urban art. Based on an offline art project exhibited in Berlin, in 2007, the switching to the Internet can’t do the movement anything but good, as long as it unites every artist’s vision in a global work of art.

Discarded by many, including invariably the local authorities, Graffiti is,
according to Wikipedia, the name for images or lettering scratched, scrawled, painted or marked in any manner or property. Among most of the objections being raised against it, Graffiti is most often scorned at for being an act of unwanted vandalism that the owners of the surfaces being painted have to deal with.

The GraffitiforGod.org website explains how the name came to be and the history of the project: "The idea of mapping roof graffiti was inspired by 'Wax+' and 'Nemo', whose piece can already be seen on Google Maps in Berlins Center. In the style of medieval maps where Jerusalem often stood at the centre of the geographical drawings and God as the heavenly observer from above, this piece marks the centre of 'Graffiti for God'."

Among other things noted on the Google Maps mashup, there are police stations, hospitals, religious institutions and closely monitored areas, so if you see the legend and any of those in the area you were going to tag, or start a more complex piece of work, you’d better scamper ‘cause it ain’t going to be easy to explain to the officers what you were doing with a half-empty spray can in front of a half-painted wall. Chances are, you’re not going to come up with something good enough.

Graffiti aficionados, gear up and head to Google Maps to choose the best site for your message, where even God will see it.