Site Archives Blog Entry
Types of Malicious DNS
We’ve covered the basics of what DNS is and how it works, now we’re going to discuss the ways it can be compromised and used against you.
DNS: An Introduction
Over the next few weeks, we’re going to be delving into the topic of DNS: what it is, and how malicious attackers can use it against you.
Patch Management Beyond WSUS
Lately, with the latest outbreak of malware mostly targeting user applications, I have been discussing the patching process with several IT administrators. Frequently I will hear, “We don’t need to worry about patching, that is what WSUS (Windows System Update Services) is for.” We agree that WSUS is a wonderful and easy process for updating your Microsoft components, but there are other applications on workstations and servers that need critical security updates. These updates can be performed manually, or could be included into third party patching software, like Lumension (formerly PatchLink).
Microsoft Security Update Guide
Microsoft has published a great security update guide that I think would benefit financial institutions. It discusses 6 great steps for network administrators on Windows networks:
- Get to know the security update release process
- Learn how to evaluate risk
- See how to migrate security risks
- Understand how quickly you need to apply updates
- Assess your update
- Get ongoing security
You can find the guide here.
Domain Registrar Scam
Gladiator has received reports that an old email scam regarding domain registry has resurfaced, and the amount of scam-related emails sent to website owners has picked up greatly. Basically, the scammers will send a deceptive email to a user at the organization, usually the person whose name is listed as registering the website or the CEO of the organization, if this information is listed on the public-facing website. The email states that the organization’s domain registration is going to expire in Asia, and directs the organization to send money to a domain registrar in order to keep others from buying the domain space. (A perfect example of one of these scam emails can be seen by clicking here.) Most of the scam email examples that Gladiator has seen have been sourced from China or other nations in Asia. Basically, these scammers are instigating fear on the part of the unsuspecting user by suggesting that his organization may lose its domain space (.com address) unless he acts as they direct.
Malware Infection Methods: Drive-by Downloads
Now that the Internet has been around for some time, users are starting to become more adept at protecting themselves from Web-based threats. Users have learned that certain parts of the Web or Web pages, like advertisements, can pose a security threat and, therefore, will avoid clicking on them. Unfortunately, the malware writers have also noticed the trend and continue to come up with new ways of distributing their malicious applications. The most popular method used for the past year is called Drive-by Downloads. The term Drive-by Download means users become infected simply by surfing an exploited Web page and are completely unaware of the malicious file download occurring in the background. Web browser exploits (such as IE, Firefox, Safari, etc.) and other third party application exploits (such as Adobe Reader, Microsoft Excel, etc.) can potentially allow remote code execution, which can lead to a malicious file download which is completely invisible to the user. Fake pop-ups that look legitimate, often cleverly masqueraded as anti-virus solutions, are also a popular method of tricking a user into either clicking on the pop-up to close it or following the instructions on the pop-up, both of which result in malicious file downloads.
Holiday Malware Risks
Happy Holidays! This is just a reminder that the Holidays are always a very active time for the “bad guys.” Malware writers and phishers prey on our cheery attitudes and overactive messaging habits to slip in malicious emails. There are a few popular attacks that pop up like clockwork around the holidays each year, and so you should make your users aware of these attacks.
Find It Quickly
Find what you're looking for quickly by using our keyword search. Can't find it? Try our links below.
Monthly Archives
Find posts by the month they were written.
- February 2012
- January 2012
- December 2011
- November 2011
- October 2011
- September 2011
- August 2011
- July 2011
- June 2011
- May 2011
- April 2011
- March 2011
- February 2011
- January 2011
- December 2010
- November 2010
- October 2010
- September 2010
- August 2010
- July 2010
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
- July 2008
- May 2008
- April 2008
- March 2008
- January 2008
- December 2007
- November 2007