Zscaler Australia & New Zealand http://blog.zdemo.net Most recent posts at Zscaler Australia & New Zealand posterous.com Thu, 04 Aug 2011 16:32:00 -0700 Cybercrooks exploit interest in Harry Potter ebook site • The Register http://blog.zdemo.net/cybercrooks-exploit-interest-in-harry-potter http://blog.zdemo.net/cybercrooks-exploit-interest-in-harry-potter
Malware-slingers are tapping into the buzz around a new Harry Potter site to mount a variety of scams designed to either defraud, infect or otherwise con would-be victims.

Proving that the bad guys out there are quick to adapt to anything that might drive traffic and thus dollars, the buzz around the upcoming pottermore.com site is providing a lot of opportunity for new scams.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Tue, 19 Jul 2011 15:47:00 -0700 Zscaler Research: Brazilian bank targeted by phishing site and DNS poisoning http://blog.zdemo.net/zscaler-research-brazilian-bank-targeted-by-p http://blog.zdemo.net/zscaler-research-brazilian-bank-targeted-by-p
Santander, a well-known banking site, has often been the target of phishers. In fact, Santander UK often makes the top-10 list of most popular targets according to Phishtank. Last week, we found a phishing site for the Brazilian branch, santander.com.br, that was receiving traffic from a DNS cache poisoning attack.

This shows just how dangerous DNS cache poisoning can be. Pay close attention to the subtle signs, such as the "secure" indicator in your browser to show the page has been encrypted. If in any doubt actually click on that little padlock and verify the certificate is from who you think it is.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Tue, 21 Jun 2011 23:56:00 -0700 Zscaler Research: Patching Flash - CVE-2011-2110 post-mortem http://blog.zdemo.net/zscaler-research-patching-flash-cve-2011-2110 http://blog.zdemo.net/zscaler-research-patching-flash-cve-2011-2110
Last week I blogged about the CVE-2011-2110 Adobe Flash vulnerability being actively exploited in the wild. Adobe released its patch exactly a week ago (Tuesday, June 14) ... I wanted to do a follow up to identify the patch rate within our enterprise customers.

Mike's follow-up review of the numbers of vulnerable Flash installations after Adobe's update released last week... scary numbers of vulnerable systems out there.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Tue, 21 Jun 2011 04:07:00 -0700 Zscaler Research: Zscaler Safe Shopping available for Opera http://blog.zdemo.net/zscaler-research-zscaler-safe-shopping-availa-12585 http://blog.zdemo.net/zscaler-research-zscaler-safe-shopping-availa-12585
Zscaler Safe Shopping is already available for Firefox, Firefox Mobile (aka Fennec) and Google Chrome. Now, you can also download the extension for your Opera 11 browser. A version for Safari will be available soon as well.

Julien has been busy - he's now ported his Safe Shopping browser plugin to Opera, joining the existing versions for Firefox, Firefox Mobile and Chrome.

Opera users should download it now from https://addons.opera.com/addons/extensions/details/zscaler-safe-shopping/1.0/...

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Sun, 19 Jun 2011 23:46:00 -0700 Zscaler Research: The "Dad walks in on Daughter.. EMBARRASSING!" Facebook scams http://blog.zdemo.net/zscaler-research-the-dad-walks-in-on-daughter http://blog.zdemo.net/zscaler-research-the-dad-walks-in-on-daughter
The "Dad walks in on Daughter.. EMBARRASSING!" Facebook scams have become very prevalent. I listed a few examples on our new blog, Zscaler Analyst Scrapbook. I'll go into more detail in this post.

There's no end to the scam attempts on Facebook. As ever, be very careful what you click on, and make sure your security solutions are up to date and effective.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Sun, 19 Jun 2011 23:43:00 -0700 Zscaler Research: Oh Flash! CVE-2011-2110 0-Day http://blog.zdemo.net/zscaler-research-oh-flash-cve-2011-2110-0-day http://blog.zdemo.net/zscaler-research-oh-flash-cve-2011-2110-0-day
This past Tuesday, June 14, a vulnerability (CVE-2011-2110) in the Adobe Flash Player was patched. This vulnerability is actively being exploited in the wild - prior to the patch, the earliest exploitation that we have seen in our logs thus far, dates back to early last Thursday (June 9th).

Flash and Acrobat are still topping the charts of active exploits - make sure your Flash Player is up to date!

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Sun, 19 Jun 2011 23:41:00 -0700 Zscaler Research: PasteHtml.com, a heaven for phishing pages http://blog.zdemo.net/zscaler-research-pastehtmlcom-a-heaven-for-ph http://blog.zdemo.net/zscaler-research-pastehtmlcom-a-heaven-for-ph
The ultimate dream of a phisher it to be able to set up thousands of phishing sites freely, anonymously, and quickly. Luckily for them, PasteHtml.com offers a service which empowers them to do just that. It is a "Free anonymous web hosting" site, which allows anyone to create any page with a simple POST request.

Trust the phishers and scammers to find a way to abuse a useful service. Be careful of any site that links you out to hosting services such as pastehtml.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Sun, 19 Jun 2011 23:38:00 -0700 Zscaler Research: Incognito exploit kit http://blog.zdemo.net/zscaler-research-incognito-exploit-kit http://blog.zdemo.net/zscaler-research-incognito-exploit-kit
Recently, I have noticed a significant increase in the usage of the Incognito exploit kit. Similar to the Blackhole exploit kit, Incognito also targets vulnerabilities in Java and Adobe products.

Use of the Incognito exploit kit is on the rise. Incognito attempts to exploit known vulnerable ActiveX controls, the Java Deployment Toolkit and Acrobat Reader.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Tue, 14 Jun 2011 21:02:26 -0700 Zscaler security advisory - Microsoft security bulletins for June http://blog.zdemo.net/zscaler-security-advisory-microsoft-security http://blog.zdemo.net/zscaler-security-advisory-microsoft-security
Security Advisory - June 2011 Microsoft Patches.pdf Download this file

Zscaler, working with Microsoft through their MAPPs program, has proactively deployed protections for twenty-two web-based client side vulnerabilities included in the June 2011 Microsoft patch cycle.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Mon, 13 Jun 2011 04:15:00 -0700 Zscaler Analyst Scrapbook: 178.18.243.219 serving Balckhole expoit kit http://blog.zdemo.net/zscaler-analyst-scrapbook-17818243219-serving http://blog.zdemo.net/zscaler-analyst-scrapbook-17818243219-serving
multiple domains using IP "178.18.243.219" were found to be Blackhole exploit kit. Further analysis confirmed distribution of evil contents using these domains.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Mon, 13 Jun 2011 04:11:00 -0700 Zscaler Research: Zscaler Analyst Scrapbook http://blog.zdemo.net/zscaler-research-zscaler-analyst-scrapbook http://blog.zdemo.net/zscaler-research-zscaler-analyst-scrapbook
Very often while we're conducting log analysis across our cloud in order to add security protections (signatures, black listing, reputation scoring, etc.) we find interesting scraps of information. While this information may not be interesting to the masses - it may help those working in security operations centers (SOCs) or other roles to add similar protections for their users.

The Analyst Scrapbook can be found at http://scrapbook.zscaler.com. If you're a regular follower of the Research blog, you're going to want to add this one to your reader list as well.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Mon, 13 Jun 2011 04:03:00 -0700 Zscaler Research: .co.tv domains serving heavily obfuscated malicious code http://blog.zdemo.net/zscaler-research-cotv-domains-serving-heavily http://blog.zdemo.net/zscaler-research-cotv-domains-serving-heavily
Following a previous post on a malicious Google News search, we identified additional domains related to this attack, also serving malicious code. The method of infection remains the same by injecting a malicious script, which will redirect victims to one of several malicious domains.

Umesh has indentified 27 additional domains that are being used to host malicious code related to the compromised news search results. As ever, exercise vigilance when looking at search results.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Mon, 13 Jun 2011 04:01:00 -0700 Zscaler Research: Google news search results for Laurence Fishburne leading to malicious sites http://blog.zdemo.net/zscaler-research-google-news-search-results-f http://blog.zdemo.net/zscaler-research-google-news-search-results-f
One of our blog readers, Mr. Jon Leathery informed me yesterday about a link in a Google News search leading to a malicious website. “Laurence Fishburne leaving CSI”, was a popular topic recently and was being taken advantage of to spread malware.

It's not just the normal search results that are being poisoned; news searches are also being manipulated to direct browsers to malware.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Mon, 13 Jun 2011 03:56:00 -0700 Zscaler Research: Blackhat spam SEO leading directly to a virus download http://blog.zdemo.net/zscaler-research-blackhat-spam-seo-leading-di http://blog.zdemo.net/zscaler-research-blackhat-spam-seo-leading-di
Attackers usually use some form of social engineering technique to fool users into downloading and executing a malicious executable - they scare users with a fake antivirus page, they present users with a video that requires a new software or codec update, they claim the user's browser or Flash version is out of date, etc. Last week, I found several Google search results for popular terms leading directly to a virus download.

The results here were a little scary - only five anti-virus engines out of 42 detected this threat. While AV is an important part of a defensive strategy, it's simply not the right tool to keep users protected online.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Mon, 13 Jun 2011 03:53:00 -0700 Zscaler Research: Buying software online is getting more and more risky http://blog.zdemo.net/zscaler-research-buying-software-online-is-ge http://blog.zdemo.net/zscaler-research-buying-software-online-is-ge
Google searches for popular software (Windows, Microsoft Office, etc.) often contain links to fake online stores since at least December 2010. Google has done very little to clean up the search results.

Julien's latest research into blackhat SEO shows an increase in malicious search results for popular shopping terms. Might be a good time to grab a copy of the Safe Shopping plugin!

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Mon, 13 Jun 2011 03:33:00 -0700 Zscaler Research: Zscaler Safe Shopping now available for Google Chrome http://blog.zdemo.net/zscaler-research-zscaler-safe-shopping-now-av http://blog.zdemo.net/zscaler-research-zscaler-safe-shopping-now-av
I had previously released Zscaler Safe Shopping for Firefox and Firefox mobile to warn users when they are visiting such sites. The extension is now available for Google Chrome.

All you Chrome fans out there can now rejoice and take advantage of some extra browser protection - Julien's Safe Shopping plugin is now available in the Chrome Web Store.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Thu, 09 Jun 2011 04:36:13 -0700 Zscaler takes part in IPv6 Day http://blog.zdemo.net/zscaler-takes-part-in-ipv6-day http://blog.zdemo.net/zscaler-takes-part-in-ipv6-day
Zscaler PR - Zscaler Participates in World IPv6 Day[1].pdf Download this file

Everyone is talking about the move to IPv6, but there isn't really a whole heap of action for the most part. World IPv6 Day, sponsored by the Internet Society, is aimed to motivate companies to prepare their networks and services for migration to supporting IPv6.

At Zscaler, we're proud to have successfully participated in the World IPv6 Day on June 8, showing that our cloud infrastructure is not only robust and scalable, but also supports the network addressing scheme of the future.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Fri, 27 May 2011 20:43:00 -0700 Zscaler positioned as a leader in the Magic Quadrant for Secure Web Gateway http://blog.zdemo.net/zscaler-positioned-as-a-leader-in-the-magic-q http://blog.zdemo.net/zscaler-positioned-as-a-leader-in-the-magic-q
The Magic Quadrant is a graphical representation of a marketplace at and for a specific time period. It depicts Gartner's analysis of how certain vendors measure against criteria for that marketplace, as defined by Gartner. Vendors in the Magic Quadrant are evaluated based on ability to execute and completeness of vision.

All of us at Zscaler are immensely proud of achieving the most visionary position in the "Leader's" quadrant of the latest Gartner Magic Quadrant for Secure Web Gateway products and services. This recognition of not only our unique technology and cloud architecture, but also of our ability to bring our service to a global market validates all our efforts and shows that we're a serious contender in the security market.

The full report can be downloaded from our web site at http://www.zscaler.com/magic_quadrant_2011.html.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Wed, 25 May 2011 05:31:00 -0700 Osama alive scam snowballs on Twitter http://blog.zdemo.net/osama-alive-scam-snowballs-on-twitter http://blog.zdemo.net/osama-alive-scam-snowballs-on-twitter
Fraudsters wasted little time running scams based on the death of Osama bin Laden, so it's no big surprise that they are now running cons based on the conspiracy theory that the former head of al Qaida is alive.

More Osama scams, this time using Twitter as the initial vector.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Mon, 23 May 2011 17:00:00 -0700 Cybercrooks turn Eve Online into botnet battlefield • The Register http://blog.zdemo.net/cybercrooks-turn-eve-online-into-botnet-battl http://blog.zdemo.net/cybercrooks-turn-eve-online-into-botnet-battl
Crooks using online games to farm virtual currencies that they can sell for real money have turned internet spaceship game Eve Online into a battlefield for botnets.

Gamers beware... it's not just Facebook that's full of trojans and scammers.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks