Language Selection

English French German Italian Portuguese Spanish

Bogus blogs snare fresh victims

Filed under
Security

The bogus web journals are being used as traps that infect visitor's machines with keylogging software or viruses.

Filtering firm Websense said it had found hundreds of bogus blogs baited with all kinds of malicious software to snare the unwary.
Websense warned that the baited blogs could get past traditional security measures that try to protect people from malicious programs.

The company said blogs were being used because they inadvertently offered lots of help to computer criminals.

Blogs are free and simple to use, offer users lots of storage space, can be used anonymously and most do not scan stored files for viruses and other malicious programs.

Websense said it had seen examples of some computer criminals creating a legitimate looking weblog, loading it with keylogging software or viral code, and then sending out the address of it through instant messenger or spam e-mail.

"These aren't the kind of blog websites that someone would stumble upon and infect their machine accidentally," said Dan Hubbard, Websense's research director. "The success of these attacks relies upon a certain level of social engineering to persuade the individual to click on the link."

Estimates indicate that there could be more than 200 bogus blogs in existence that are being used to attack net users.

Full Story.

More in Tux Machines

5 Best Android Phones [May, 2015]

Those looking for a new Android phone in the month of May are going to find themselves staring at a number of solid options. With that in mind, we want to help narrow things down for those that are need of some assistance. Here, we take a look at the device’s we think represent the best Android phones for May, 2015. Last month, Samsung and HTC released their new 2015 flagships into the wild. The Samsung Galaxy S6 Edge, Samsung Galaxy S6, and HTC One M9 join a crowded field of competitors tempting those looking for a new Android phone this month. They will soon be joined by an LG G4, a device that’s set to replace the popular LG G3 in June. Read more

diff -u: What's New in Kernel Development

Alexander Holler wanted to make it much harder for anyone to recover deleted data. He didn't necessarily want to outwit the limitless resources of our governmental overlords, but he wanted to make data recovery harder for the average hostile attacker. The problem as he saw it was that filesystems often would not actually bother to delete data, so much as they would just decouple the data from the file and make that part of the disk available for use by other files. But the data would still be there, at least for a while, for anyone to recouple into a file again. Alexander posted some patches to implement a new system call that first would overwrite all the data associated with a given file before making that disk space available for use by other files. Since the filesystem knew which blocks on the disk were associated with which files, he reasoned, zeroing out all relevant data would be a trivial operation. Read more

8 Linux Security Improvements In 8 Years

At a time when faith in open source code has been rocked by an outbreak of attacks based on the Shellshock and Heartbleed vulnerabilities, it's time to revisit what we know about Linux security. Linux is so widely used in enterprise IT, and deep inside Internet apps and operations, that any surprises related to Linux security would have painful ramifications. In 2007, Andrew Morton, a no-nonsense colleague of Linus Torvalds known as the "colonel of the kernel," called for developers to spend time removing defects and vulnerabilities. "I would like to see people spend more time fixing bugs and less time on new features. That's my personal opinion," he said in an interview at the time. Read more

Linux from Square One

Despite the fact I have a different view of which distros are best for kids — Qimo (pronounced “kim-o,” as in the last part of eskimo, not “chemo”) tops the list, as it should, but the French distro Doudou (add your own joke here) is unfortunately left out — the link there is informative. So for those who are just getting their proverbial feet wet in Linux, this is a godsend. Read more