Obama mania spawns malware

Opinion
Nov 6, 20083 mins

* Patches from Adobe, Ubuntu, Mandriva, Gentoo * Malware exploiting Obama win * Report: 'Foreign entity' hacked Obama, McCain PCs, and other interesting reading

Malware authors know a good thing when the see it and usually waste little time pouncing on the opportunity. Barack Obama’s presidential election win spawned a wave of Obama-themed malware attacks that try to lure viewers to a fake video of his victory speech. Of course, the fake video really installs a backdoor Trojan and steals data from the victim’s machine. Also this week, Adobe finally patched a bug in its PDF applications after the flaw was initially reported five months ago.

Adobe patches 8 bugs in popular PDF apps

Adobe Systems patched its Reader application for the fifth time this year, plugging eight security holes, including one reported to the company more than five months ago. Computerworld, 11/4/2008.

Adobe: Security Update available for Adobe Reader 8 and Acrobat 8

Core Security: Adobe Reader Javascript Printf Buffer Overflow

**********

Four new patches from Ubuntu:

system-tools-backends (poor password store encryption)

Kernel (multiple flaws)

Kernel (regression error)

enscript (stack overflows, denial of service)**********

Two new fixes from Mandriva:

net-snmp (denial of service)

Kernel for 2009.0 (multiple flaws)**********

Two new updates from Gentoo:

Opera (multiple flaws)

libspf2 (buffer overflow, code execution)**********

Today’s malware news:

Poker in the ZBotToni ran into an interesting ZBot sample yesterday. During his analysis, he was surprised to discover a big bunch of poker sites among the configuration file’s targets. Why online poker? Because the sites payout real money, and often lots of it. F-Secure, 11/5/2008.Malware exploiting Obama winNot surprisingly, malware authors have jumped on the Barack Obama presidential election win to spread their evil code. Network World Security blog, 11/5/2008.

**********

From the interesting reading department:

Report: ‘Foreign entity’ hacked Obama, McCain PCsComputer systems used by the election campaigns of both President-elect Barack Obama and his Republican rival John McCain were broken into earlier this year, and a large number of files related to the evolving policy positions of the two candidates were stolen, according to a story posted online Wednesday by Newsweek magazine. Computerworld, 11/5/2008.Once thought safe, WPA Wi-Fi encryption is crackedSecurity researchers say they’ve developed a way to partially crack the Wi-Fi Protected Access (WPA) encryption standard used to protect data on many wireless networks. IDG News Service, 11/6/2008.The dangers of short URLsIt isn’t news to anyone that clicking random links in e-mail or on web pages can lead to Bad Things — malware infestation, launching various scripting attacks, or even the dreaded Rick Roll. But what about things you want to click, but can’t see where they lead due to the ubiquitous URL shortening utilities? Uncommon Sense Security, 11/3/2008.Spammers Ride the Economic Roller-Coaster in October 2008As the gut-wrenching roller coaster that world economies have experienced over the last 90 days continues, it is not surprising that spammers are still attempting to tap into the economic angle to try and deliver their spam messages. Symantec Security Response, 11/5/2008.Phishing scams could follow bank collapseCustomers trying to claim deposits from a collapsed Icelandic bank could be at a higher risk over the next few weeks of falling victim to phishing scams, according to security analysts. Network World, 11/5/2008.Managing the Social-Networking Data SieveTwitter, Facebook, LinkedIn and other social networking sites practically beg you to reveal even more information about yourself. Log on and you’re asked: What are you doing? What are you doing right now? What are you working on? CIO, 11/05/2008.