Saturday, December 29, 2007

Date rape drugs cause ripples.


The fear of date rape has reared its ugly head in Mumbai with a drug bust at the Mumbai airport. But it's not just drug cartels you need to watch out for, it's date rape drugs being sold for a song over the counter. NDTV finds out how easy it is to purchase this deadly chemical.

What better way to bring in the New Year than to say cheers! But beware, not every clink of the glass has an innocent ring. Lacing your cocktail could be deadly substances as date-rape drugs are causing ripples in Mumbai party circles.

And now, raising the alarm is a seizure of Ketamine hydrochloride. Nine kg of a chemical powder used to make date-rape drugs was seized at the Mumbai airport. It's the fourth seizure in two months and the enforcement agencies are worried.

Dilip Srirao, DCP, Anti Narcotics Cell said, ''What's more frightening is the easy availability of Ketamine, used to make injectible anaesthetics, a prescription drug not meant to be sold over the counter.''

Shockingly, NDTV found the anesthetic freely available. We merely walked into a South Mumbai medical store, asked for Ketamine and walked out with a bottle, no questions asked.

Taking matters to another level are the reports of at least four Mumbai-based pharmaceutical firms accused of faking invoices to import Ketamine in bulk.

A substance when converted into date-rape drugs fetches crores of rupees, drugs that go by the name Roffies and Liquid X.

Malware Sites Exploit Bhutto Assassination

Within hours after former Pakistani Prime Minister Benazir Bhutto's assassination, malware authors took advantage of the tragedy by spreading malicious Websites of the event that made the top of the Google rankings.

"We've come to understand that almost any high impact media event is going to be used as a social engineering tool for malware," said Dave Marcus, security research and communications manager at McAfee. "It's such a horrible event, but at the end of the day, it's a very good social engineering tactic."

The Websites take advantage of the tragedy by enticing users to download a fake codec, purporting to be a video of Bhutto's assassination. When users visit the sites, they download a piece of information-stealing malicious code, instead of a video, to their machines.

"They entice users through posing as news for the events," said Dan Hubbard, vice president of security research for San Diego-based Websense, a security company specializing in Web and content filtering, via e-mail. "(The sites) are malicious however, and behind the scenes, attempt to infect users who have unpatched PCs and install Trojan Horses for financial gain."

The compromised sites contain malicious scripts injected into the Web pages that redirect visitors to the 3322 domain, which security researchers have detected in other high profile attacks.

"It's not cutting edge malware," Marcus added. "It's not even a new piece of malware. It's just a popular piece of malware."

So far, at least 10 blogger Web sites have been found to host the fake video, and security experts say that there are likely numerous others that contain malware under the Google search results for "Benazir Bhutto."

Security researchers say that in the past, attackers have typically taken advantage of subjects that receive high amounts of traffic on search engines, such as international media events. Attackers will often disseminate malware by duping a search engine's algorithm and manipulating keyword searches to get their malicious sites at, or close to, the top of the search engine's rankings.

"This is happening more and more often, not just with Google, with all search engines," said Hubbard.

While security professionals say that the company has been alerted to the problem, Google did not immediately respond to queries.

"If it's a high impact media event, chances are it's going to be pushing out malware," said Marcus. "It's not Google's fault. It's just that the attackers are using the free service that Google provides."

To protect PCs from being affected by this kind of attack, experts recommend that users keep all of their security software updated and only visit valid sources when searching for news.

"Don't just rely on a Google Web site which aggregates news," said Marcus.

Friday, December 28, 2007

File Corruption Bug Bites Windows Home Server

The honeymoon between Microsoft and the partners and customers who've been gleefully awaiting the arrival of Windows Home Server may be over, thanks to a serious data corruption glitch in the software.

Using certain applications to save digital files to Windows Home Server could cause files to become corrupted, according to Microsoft, which last week said the issue had affected "a few people" on its community forums, and posted a Knowledge Base article outlining the issue.

Microsoft didn't offer a timetable for a fix, but recommended that users not use the following applications to save data to Windows Home Server: Windows Vista Photo Gallery, Windows Live Photo Gallery, Microsoft Office OneNote 2007, Microsoft Office OneNote 2003, Microsoft Office Outlook 2007, Microsoft Money 2007, and SyncToy 2.0 Beta.

Based on Windows Server 2003, Windows Home Server lets users connect multiple PCs in the same household and allows them to store, manage, back up, and remotely access their digital content.

While interest in Windows Home Server has been strong, Tom DeRosier, co-owner of CPU Guys, a Hanson, Mass., system builder, says data corruption problems could cause some users to think twice before entrusting their digital content to Microsoft.

"Anytime you have data corruption, it's a serious issue. But what makes this even worse is the fact that with digital photos, people usually copy them off their cameras to the server and then delete them from the card, which means they're operating without a backup," said DeRosier.

Microsoft expects Home Server to fit well into the toolbox of home integrators because it's versatile enough to be wrapped into a smart home solution along with home automation and networking technologies.

Microsoft last month issued its second update for Windows Home Server, which fixed minor issues with the software's remote access functionality. The first Windows Home Server update, released in September, covered issues in home network router/firewall and broadband providers' software.

Wednesday, December 26, 2007

Microsoft Unleashes Windows XP SP3 Release Candidate

Microsoft Tuesday unveiled the first release candidate for Windows XP service pack 3 (SP3), moving the long awaited final batch of tweaks and fixes for XP closer to reality.

Originally slated for release in 2006, XP SP3 has been pushed back on numerous occasions, and this marks the first time it has been available for public download.

Earlier this month, Microsoft launched the first release candiate for Windows Vista SP1. Microsoft plans to launch Windows XP SP3 sometime in the first half of next year, with Vista SP1 due in in the first quarter.

XP SP3 includes all of the fixes Microsoft has released since launching XP in 2001, as well as some minor new features that are part of Windows Vista. These include: support for Microsoft's Network Access Protection security technology; 'keyless activation', which lets IT administrators install SP3 without entering product keys for each copy; and detection of so-called 'black hole' network routers that can slow network performance.

J.R. Guthrie, president of Advantage Computers, a system builder in Tucson, Ariz., estimates that XP SP3 speeds up XP's performance by 15 percent. He adds that XP SP3 will greatly extend the lifetime of market demand for XP, probably even beyond the current Jan. 31, 2009, deadline Microsoft has set for system builders to sell machines equipped with Vista.

Service packs are always helpful to the channel because they take a lot of the hotfixes and put them through more stringent regression testing, says Michael Cocanower, president of solution provider ITSynergy, Phoenix.

Allan Walters, senior vice president at Saratoga Technologies, Johnson City, Tenn., said XP SP3 will greatly reduce administrative overhead. "When you do a brand new load with XP service pack 2, there are nearly 90 additional updates you have to download, so the fact that XP SP3 rolls everything into a single installer package is a major time saver," he said.

Tuesday, December 25, 2007

2007 A Record Year For Malware

The explosion of malware PC users saw in 2007 is going to get exponentially worse in 2008, security researchers say.

Researchers at McAfee Avert Labs estimated that unique malware will exceed 370,000 pieces by the end of this year, constituting the largest amount of malware on record. The 60 percent increase from 2006 indicates a trend that will likely result in at least 550,000 pieces of new malware by the end of 2008, security researchers say.

This trend has been consistent for the last three years, according to a recent McAfee chart. The chart indicated that the most significant spike in malware came between 2006 and 2007, where it rose from a little more than 220,000 to 370,000 new pieces. Between 2000 and 2003, malware remained relatively constant at about 60,000 new pieces, rising incrementally until 2004, when it spiked sharply upward from a little more than 100,000 to about 175,000 new pieces at the end of 2005.

One of the reasons for these large surges of malware is due to the number of variants that attackers release every day, security researchers say. Craig Schmugar, threat research manager at McAfee Avert Labs, said that analysts have noticed that malware authors are putting more effort into evading detection while keeping a high number of machines infected.

Individuals and businesses will continue to see more bots like the Nuwar Storm Worm, which became one of the most notorious viruses of 2007 because of its ability to constantly change as it replicated itself, he said.

"Groups like Nuwar Storm Worm are constantly trying to make their threats more pervasive," said Schmugar. "If they're releasing a thousand (variants) a day, it's more of a challenge and it requires different defense strategies."

Schmugar said he anticipated that malware would continue to rise in 2008 as more attackers learned from the success of their predecessors. "People are looking to the success of others. We expect that other authors who don't have the same success may look to see what the more successful threats are doing. It stands to reason that they would model those," he said.

Also next year, attackers will also be more likely to channel increased efforts into automating malware processes, which might entail a higher upfront cost but ultimately take less involvement to produce, Schmugar said.

"Over time when there hasn't been a publicized case, the malware authors get some complacency," said Schmugar. "At some point they will defeat the purpose of so many variants and they will have to move on to other technologies.

Google Stops Orkut Worm Attack

Google (NSDQ:GOOG) security personnel clamped down to stop the spread of a prolific spam worm launched on its social networking site Orkut.

"Google takes the security of our users very seriously. We worked quickly to implement a fix for the issue recently reported in Orkut. We also took steps to help prevent similar problems in the future. Service to Orkut was not disrupted during this time," a Google spokesperson said in a written statement.

The worm, which was reported yesterday by McAfee Avert Labs, had gained ground by spreading quickly from friend to friend. The virus affected the profiles of almost 400,000 of its members, most of which were from Brazil. While Google initially aimed Orkut toward users in the United States, the networking site has become incredibly popular in Brazilian communities.

"(The attack) was obviously very targeted at the Brazilian community specifically," said Dave Marcus, security and information manager at McAfee Avert Labs.

The worm was transmitted when members received malicious scraps written in Portuguese. When translated to English, one scrap read, "2008 is coming. I wish that it begins quite well for you."

Upon receiving the scraps, the members' browsers then downloaded and executed the embedded virus. After adding its victims to a community called "Infectados Pelo Virus Orkut" or "Those Infected by the Orkut Virus," the worm then started to send messages to members of the affected user's friends list.

The virus spread through Orkut's new tool that allows users to write messages containing HTML code. The ability to add Flash/Javascript content to Orkut scraps was only recently introduced.

So far, there has been no evidence that the worm maliciously harmed users' PCs, security researchers say. "All it does is it adds the user to this one particular Orkut group. As far as malware goes, it's rather innocuous," said Marcus. "On a scale of one to 10, it's pretty low."

McAfee security researchers said earlier today that some of the scraps had already disappeared, indicating that Orkut and Google had begun to address the problem.

The worm was symptomatic of a growing trend of malware that has flourished on social networking sites. Last month, MySpace sites for singer Alicia Keys and other musicians were targeted with an attack that installed malicious software on the PCs of members visiting the musicians' sites.

Another attack was launched last summer on the popular networking site Facebook, in which the perpetrators used small pop-up ads to force the user to purchase security software and download a computer virus.

These attacks raise the question of how to keep Web 2.0 sites secure, researchers say. While the spread of the Orkut worm appears to have abated, security analysts advise that members keep their antivirus software updated in order to remain protected against this and other viruses.