General News

Sandboxing the Adobe Reader

Will this change really make Adobe Reader more reliable ? In order to be more reliable, they have to make everything more reliable. And Adobe doesn’t know how to do this. Here is the saga: Introduction: http://blogs.adobe.com/asset/2010/07/introducing-adobe-reader-protected-mode.html Part 1: http://blogs.adobe.com/asset/2010/10/inside-adobe-reader-protected-mode-part-1-design.html Part 2: http://blogs.adobe.com/asset/2010/10/inside-adobe-reader-protected-mode-%e2%80%93-part-2-%e2%80%93-the-sandbox-process.html Update: We published an article in the Techblog about this : http://techblog.avira.com/2010/11/05/the-adobe-reader-sandbox/en/

News

New entry in the TSC: Script in the middle

Thanks to Virus Bulletin, we have now a new entry in The Spammers’ Compendium: Script in the middle UO!Script in the Middle!JavaScript 14 October 2010 Description The email has an HTML document attached to it that contanis a for. Clicking submit will POST the user’s data to a website controlled by the crooks, which automatically […]

News

Guest blogger: Larry.Walsh: Security Idea: Recall the Internet

I totally agree with this blog post of Larry.Walsh (seen on from CompTIA). Source: http://blog.comptia.org/2010/10/13/security-idea-recall-the-internet/ Author: Larry.Walsh Microsoft’s Scott Charney says we should treat malware-infected PCs in the same manner as 19th century public health officials treated victims of typhoid, tuberculosis and cholera: quarantine. Yes, the head of Microsoft’s Trustworthy Computing believes malware infections are […]

News

QR Code of this website

QR Code of this website from bit.ly: (Taken from bit.ly and adding .qr at the end of the shortened URL) Taken from goo.gl: More about the QR codes can be found on Wikipedia: http://en.wikipedia.org/wiki/QR_Code A QR Code is a matrix barcode (or two-dimensional code), readable by QR scanners, mobile phones with a camera, and smartphones. […]

Spam & Phishing

Nigerian scams are modernizing

I sometimes laugh of these scammers, but sometimes I am quit amazed of their capability to adapt to the spam filters. My Google account caught this spam: In text, this is : Good Day, I am Mr. Ming Yang,Director of operations of the Hang Seng Bank Ltd,Sai Wan Ho Branch,Hong Kong.I am here-by seeking your […]

News Security

onMouseOver() Twitter security flaw (+Update)

A Twitter security flaw is being widely exploited on Twitter, showing remote content from third-party websites without user’s consent. The flaw uses a JavaScript function called onMouseOver() which creates an event when the mouse is passed over a text or link. Any user can use this flaw to create simple popups, redirect the page to […]

News

Softpedia about the Anti-Botnet initiative of eco and BSI

The Avira Techblog published today a new article of mine about the Anti-Botnet Initiative. Immediately after, Softpedia commented on the Anti-Botnet Initiative : “While running the Linux from the rescue system, Windows is completely inactive (not as in Safe mode) so the rootkits are also not active. This is actually the only reliable possibility to […]