Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

You practice safe computing, so why do you still see malware?

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » General Discussion Donate to DU
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 02:45 AM
Original message
You practice safe computing, so why do you still see malware?
Quite regularly, I get feedback from our customers that they've found malware on their computer, and don't know how it got there.

While you may think this is due to malware exploiting unpatched bugs in the Windows operating system, it isn't: these customers are predominantly using OS X, and they usually have all the latest patches applied. However, the malware they're finding is indeed often for MS Windows operating systems.

So are they infected? How did it happen? How COULD it happen?

The real story is both simple and a bit disturbing: our scanners are detecting these files in a few key locations: the email cache folder, email attachments folder, web cache folder, web downloads folder, and the Java web cache folder. See a pattern here?

These people are victims of drive-by downloads and malicious spam campaigns. Without visiting any shady parts of the internet, they have managed to pick up a collection of malware that, if successfully run, would likely result in their computer becoming part of a botnet.

EXAMPLES


Troj/Gida-A: drive-by Adobe Flash download that downloads and installs botnet software

Exp/MS04-028: drive-by JPEG download (can also show up as a false positive in partial jpeg images as it's an exploit detection) that can execute privileged code on un-patched Windows computers

Mal/JavaDldr-B: drive-by Java download that downloads and installs more malware

Mal/Iframe-AA: drive-by JavaScript in hidden IFrame that redirects the user to a page that detects what their system is vulnerable to, and attempts to exploit those specific vulnerabilities with the aim that the target joins a botnet

Mal/Iframe-AD: drive-by malicious HTML IFrame used in SEO-poisoned search results (often image searches)

Via email:

Mal/BredoZp-B: BredoLab botnet-generated, arrives via email

Mal/ChepVil-A: BredoLab botnet-generated, arrives via email

Troj/Invo-Zip: Zeus botnet-generated, arrives via email. Can also show up as a false positive in incomplete temporary zip files, as it's an exploit detection.

http://nakedsecurity.sophos.com/2011/11/12/you-practice-safe-computing-so-why-do-you-still-see-malware/?utm_source=facebook&utm_medium=status+message&utm_campaign=naked+security
Printer Friendly | Permalink |  | Top
cliffordu Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 03:03 AM
Response to Original message
1. Gee... I just did a search of my entire hard drive and
didn't find ANY of these. I wonder why.

I use OSX and LINUX

Maybe I'm just lucky

Printer Friendly | Permalink |  | Top
 
dixiegrrrrl Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 09:42 AM
Response to Reply #1
18. " the malware they're finding is indeed often for MS Windows operating systems."
Edited on Sun Nov-13-11 09:43 AM by dixiegrrrrl
We have been on Linux/FF for a couple of years now. I love it.
Printer Friendly | Permalink |  | Top
 
cliffordu Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 03:14 AM
Response to Original message
2. Anndddd...according to THAT VERY ARTICLE....
"Now, seeing that most of the software won't run under their current configuration, this isn't as much of an issue... but that assumption only lasts as long as their configuration isn't being targeted."


Terra Terra Terra.
Printer Friendly | Permalink |  | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 07:52 AM
Response to Reply #2
15. A Mac system that passes these infections on to a windows computer
is then a carrier. Just because the virus didn't infect a Mac doesn't mean the Mac user can't forward the infected file to someone else.
My beef with Mac users is their smug superiority attitude that doesn't bother with security because "Macs don't get viruses"
That is fine up to the point where the infected email is sent on to someone else.

The most common cause of infections is the ID ten T error. I've had ONE virus in the last five years or longer and that was because I trusted a disk someone gave me.
Printer Friendly | Permalink |  | Top
 
RebelOne Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 02:29 PM
Response to Reply #15
20. Have had a Mac for years and never had a virus ( I know, never say never).
I have had a few glitches, but nothing that could not be cured by restarting the computer.
Printer Friendly | Permalink |  | Top
 
Bonobo Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 03:25 AM
Response to Original message
3. It's a good thing only Windows users get their computer functionality destroyed by that crap.
Another drive by against OS X is fine, but let's not be deceptive.

Mac users simply don't see the performance drop that Windows users regularly do.

You can try to dress it up however you like, but those are the facts.
Printer Friendly | Permalink |  | Top
 
Logical Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 08:12 AM
Response to Reply #3
16. LOL..hang around MAC help desk for a week and get back to me.
Printer Friendly | Permalink |  | Top
 
nenagh Donating Member (657 posts) Send PM | Profile | Ignore Sun Nov-13-11 03:28 AM
Response to Original message
4. Thank you....
Would you answer an idiot's question? Which would I run to find malware? A virus scan or an Anti Spyware scan?

Many thanks...
Printer Friendly | Permalink |  | Top
 
cliffordu Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 04:06 AM
Response to Reply #4
5. All you need to do is run Windoze.
you'll find all the malware you'll ever need....

Printer Friendly | Permalink |  | Top
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 04:17 AM
Response to Reply #4
6. Microsoft Security Essentials and Super Anti-Spyware will do the trick
Along with the free AVG link scanner which will alert you to infected pages


http://linkscanner.avg.com/



Printer Friendly | Permalink |  | Top
 
Ichingcarpenter Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 04:48 AM
Response to Reply #6
7. So everyone should change to windows
because you hate OSX and linux.
Printer Friendly | Permalink |  | Top
 
meegbear Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 05:21 AM
Response to Reply #7
10. As opposed to everyone changing to OSX and linux ...
because you hate windows.
Printer Friendly | Permalink |  | Top
 
Ichingcarpenter Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 05:22 AM
Response to Reply #10
11. I don't hate windows I use it for gaming
on my iMac.

I'm just tried of these crap posts..
Printer Friendly | Permalink |  | Top
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 07:39 AM
Response to Reply #10
14. Neither of which will ever have more than 5% of the software market
If Linux is so easy, why isn't it used in schools? :shrug:
Printer Friendly | Permalink |  | Top
 
pintobean Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 09:14 AM
Response to Reply #6
17. Thank you, very much.
That is one of the most useful computer related posts I've come across.
:)
Printer Friendly | Permalink |  | Top
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 02:20 PM
Response to Reply #17
19. And you are quite welcome....
Printer Friendly | Permalink |  | Top
 
krispos42 Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 04:55 AM
Response to Original message
8. A good hosts file will help prevent that stuff
I have a bunch of ad sites blocked, so my computer can't "see" the sites. If the website I visit tries to direct me to a bad site, I simply get redirected to my own computer.

I believe it also keeps any collected information that malware gets from being sent back to so sites... the hosts file tried to redirect the information back to my computer.

:-)
Printer Friendly | Permalink |  | Top
 
DainBramaged Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 07:37 AM
Response to Reply #8
13. That has to be for those who understand site blocking and how to initialize it
AVG link scanner is for the computer illiterate and for us.
Printer Friendly | Permalink |  | Top
 
Ichingcarpenter Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 05:19 AM
Response to Original message
9. Sophos is trying to make money for windows security
and trashes OSX and linux



Sophos is a developer and vendor of security software and hardware, including anti-virus, anti-spyware, anti-spam, network access control, encryption software and data loss prevention for desktops, servers, email systems and other network gateways.


Printer Friendly | Permalink |  | Top
 
JCMach1 Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-13-11 05:31 AM
Response to Original message
12. Server side too... I have found out the hard way that Wordpress is pretty damn vulnerable
:(

It is ticking me off as we speak!
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Dec 26th 2024, 07:52 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » General Discussion Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC