Blogs
The Websense Security Labs Blog delivers the most current information about breaking security research topics and today's advanced Internet threats. Websense Security Labs investigates and publishes information about outbreaks, new threats and other relevant Web security topics to protect organizations from converging risks to their data from Web, email and user based attacks.
SEARCH BLOG
Dissecting Shellcode in Malicious Web Sites
08.29.08 - 01:25 PM
Today’s blog shows how we can debug the shellcode that we find in malicious Web sites. You might ask: what does this shellcode do? And how can I debug it? One way to find out is to write a quick C program that has the shellcode bytes in a buffer. Then, we define a pointer function to point to the code and execute it!
08.26.08 - 05:15 PM
Here in the Labs, we've recently discovered a new spam worm spreading. It is usually sent with spam that tries to deceive users into clicking a malicious URL contained in the message. Once clicked, the URL redirects users to malicious Web sites that result in an ActiveX Object error. The intention of this error is to manipulate users to download files infected with a virus.
Finding the virtual address of COM object functions
08.22.08 - 03:00 PM
Some of us know tools that can take a COM Object module (also known as an ActiveX Control)
and show us information about it, such as the names of its objects and functions.
Two examples of such tools are the OlyView and TLB Viewer.
But what if we want to know additional information, such as the virtual address inside the
module that handles each function of our object?Read more »
08.21.08 - 03:00 PM
Most of our blog readers are probably quite familiar with the use of redirectors by malicious groups to automatically redirect a user upon visiting a page. Generally, this is done so that users are presented with a link they are more familiar with, but that has been compromised in some way. For example, they may have added a few, very subtle lines of code that redirect the user to a more malicious Web site, less known to the user, and in many cases more dynamic in both content and location.
Spam and Malware Ecosystem Targeting Brazilian Users with YouTube and Adobe Flash Themes
08.21.08 - 08:50 AM
Websense has discovered an ecosystem representing the combined tactics of spammers and malware authors targeting Brazilian users. This ecosystem comprises automated bots, templates of spam content with links encouraging users to watch a video on YouTube (Brazilian site). Through these email campaigns, the spammers invite targeted users to a fake page that resembles the Adobe Flash Player download site (Brazilian version), encouraging users to download the Adobe Flash installer which is actually a malicious executable.
Read more »
Facebook Viral Social Networking Spam
08.18.08 - 05:00 PM
Websense Security Labs has been tracking various Facebook attacks for many years. We've had to create numerous tools and methods to detect these types of attacks because most Web 2.0 social networking sites are difficult to track due to limited public access to most accounts. Most social networking accounts can only be viewed if the account holder explicitly accepts or requests another account to be added as a "friend". A generic Web crawler and even a search engine Web crawler would not be able to mine the pages on a social networking site due to lack of permission.
We've used our HoneyJax system , which we've spoken about in the past, to track malicious activity in the social networking world.Read more »
CNN and MSNBC Olympic spoof emails - 5 million spam messages per hour
08.14.08 - 04:55 PM
Over the last week in the Labs, we have alerted on and discovered a series of news alert spoofed emails which spread malware when links in the emails are clicked. Malicious emails of this news-related, social engineering tactic have been circulating for the last few months. They have evolved into attempts to entice end users to click on their malicious links by presenting news story links for users to click. Until these two recent examples of social engineering with the CNN and MSNBC spoof emails, the illegitimate emails were easy to spot. They simply were one line emails with outlandish headlines.Read more »
Georgia-Russia conflict: Impact on the Threat Webscape
08.13.08 - 11:30 AM
If you have been following recent news, you have probably seen that the top stories are covering the conflict in Georgia. In the Security Labs, we have seen evidence of attacks that are typical of so-called cyber-warfare attacks. Certainly, DDoS attacks and defacements are not new and have been used by those with malicious intent during events such as public riots or events of a politicial nature.Read more »
08.12.08 - 05:47 PM
This month, Microsoft released 11 security bulletins of which 6 were rated critical. Microsoft has finally patched the Snapshot Viewer ActiveX control vulnerability, which we have previously blogged about when we discovered hundreds of sites silently infecting their visitors with modified proof-of-concept exploit code. The window of exposure for this web-borne attack is at least 1 month and 5 days, given that it was first publicly announced on July 7th and only patched today.Read more »
08.11.08 - 12:00 AM
On Day 2 at BlackHat USA, there were a few talks that several Websense researchers were highly anticipating. One of the talks was by JavaScript guru Billy Hoffman, titled "Circumventing Automated JavaScript Analysis Tools". At Websense Security Labs we see a lot of malicious JavaScript, and we are always looking for new information and research in this area. Billy Hoffman has always been a great source of information regarding JavaScript and its malicious use.Read more »
Previous Posts
August 2008
Archives
+ July 2008+ June 2008
+ May 2008
+ April 2008
+ March 2008

