User-Agent: *
Allow: /

Custom Search
Tampilkan postingan dengan label malware. Tampilkan semua postingan
Tampilkan postingan dengan label malware. Tampilkan semua postingan

Kamis, 08 Januari 2009

Is Windows 7 a security timebomb?

By Davey Winder in Editorial

Posted in Windows, Microsoft on January 5, 2009 at 11:29 am

Permalink | Author Profile

We already know a lot about Windows 7, mainly because details of the new Microsoft OS have been leaking like crazy for the past four months. We know it will scale to 256 processors and could well feature some kind of instant on functionality. We know that it is unlikely to be the death of XP although Vista is a different proposition.

We know that some people have already got a legit free copy and that a beta is due real soon now. We also know that a pirate version of Windows 7 is doing the rounds as a Torrent from the likes of Pirate Bay.



We know that many people will be tempted into downloading this to take a sneak peek at the new OS, and we also know that this is a very bad idea. Funnily enough, we are not alone in reaching this conclusion, and Rob Rachwald of Fortify Software has pretty much the same reasoning us we do.

Look, forget for a moment the whole software theft, copyright issues, breaking the law stuff. What worries Rachwald, and us, is the fact that you could be opening yourself up to a whole slew of security risks by installing something as low level as an OS when that OS is not even an official Beta but rather a dodgy copy downloaded from a pirate site.

“Reports suggest that pirate versions of an early build of Windows 7, which is under alpha test with developers, is available for file-sharing on the Internet. Given the low level at which this operating system installs on a PC, we recommend users give the version a very wide berth because of the associated security risks” Rachwald says.

But it seems the message is not getting through, and there are unconfirmed reports that many tens of thousands of people have downloaded and installed Build 7000 of Windows 7 from Torrent sites, all with no idea if the build has been tampered with by hackers in some way.

What we do not know is just what malware might be hiding in the close on 2.5 Gb of download.

Not to mention the small matter that, as Rachwald warns “It’s highly unlikely that any IT security application will protect the new operating system from internally-coded malware, so the fall-out from trying an unofficial version of the new operating system could be quite severe.”


source : www.itpro.co.uk



Read More...

Top 10 security predictions for 2009 Part. 1

What will next year hold in the ever-changing world of IT security?

By Asavin Wattanajantra, 6 Jan 2009 at 18:05

New tech means new ways for criminals to attack systems. Next year will see hackers get smart about cloud computing, social networking and more. Here's our top ten threats to keep an eye on...

Malware 2.0

Malware will increasingly target Web 2.0 as well as cloud services. New cloud-based services - such as Amazon Web Services and Microsoft Azure - are vulnerable new targets for cybercriminals or spammers.



The cloud could be used simply to send spam, but it also could launch sophisticated attacks such as hosting malicious code for downloads.

Web 2.0 has also created an environment where malware can change depending on an event or a situation. Separate harmless bits of malware can be constructed to combine and maliciously attack.

A good example of this is with mash-ups, where data from many websites can be reconstructed to create something malicious.

Malware-as-a-service becomes more common, which will allow automated malware to be bought and sold to order. This will be a big problem, as it lowers the technical level needed for criminals to become online fraudsters.

An explosion in new malware variants and web threats

Anti-virus vendor Symantec claims that new strains of malware consisting of millions of distinct threats can propagate as a single, core piece of malware. This will create a number of unique malware instances.

Indeed, research has shown we have now reached an inflection point where we are now more malicious programs than legitimate ones. Businesses and vendors need to move away from signatures and concentrate on detection methods, such as the reputation-based approach.

As web services keep increasing, and as browsers start to move towards a uniform standard for scripting language, expect new web-based threats.

Social networking spam

As the year went on, criminals were gradually moving from email-based spam to different techniques. One of these was social networking spam, where websites such as Facebook and MySpace were targeted.

Personal information is gold to the bad guys, and they will learn better tricks to persuade users to give away their details and find ways to access private accounts.

The rise in popularity of social networking sites that allow user-generated content will be a problem. Web spam will increase as will malicious posting into user-forums and blogs.

Security firm Websense claims that new web attack toolkits have emerged that allows attackers to discover posts and/or have vulnerabilities. Bots may also add more HTTP post functionality among their many capabilities.

source : www.itpro.co.uk

Read More...
free counters