ISC StormCast for Monday, May 20th 2013 http://isc.sans.edu/podcastdetail.html?id=3317, (Mon, May 20th), Port 51616 - Got Packets?, (Sun, May 19th), SSL: Another reason not to ignore IPv6, (Fri, May 17th)Best Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES SECURITY & PRIVACY
GFI WebMonitor, Internet content filtering tool for SMBs. Download free trial now! 
Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Reccomendations
Latest Viruses / Threats
Advertise With Us !
Downloads
VyprVPN
VyprVPN Personal VPN lets you browse securely

2013/5/19 18:37:30 | 11 reads

(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.


2013/5/19 7:06:38 | 8 reads

We're looking for any info or packets that target port 51616.   After witnessing a spike yesterday on his network and checking that our port data [1] corroborated his event, Andrew has written in asking what we know.     The most useful snapshot of port activity can be seen in this graph image.  I ran the graphs as far back as 2006 and nothing more signifcant was illust...


2013/5/17 10:09:08 | 11 reads

Currently, many public web sites that allow access via IPv6 do so via proxies. This is seen as the "quick fix", as it requires minimum changes to the site itself. As far as the web application is concerned, all incoming traffic is IPv4.  The most obvious issue here is logging, in that the application only "sees" the proxies IP address, unless it inspects headers added ...


Symantec Security Response | 2013/5/17 4:30:57 | 5 reads

Today, Trend Micro published a report about a targeted attack campaign they’re calling SafeNet (the campaign’s name is unrelated to the security company of the same name).read more


2013/5/16 20:37:41 | 6 reads

(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.


Symantec Security Response | 2013/5/16 19:22:31 | 12 reads

ESET recently blogged about a targeted cyber/espionage attack that appears to be originating from India. Multiple security vendors have been tracking this campaign. The attack appears to be no more than four years old and very broad in scope.read more


2013/5/16 17:02:07 | 5 reads

  Like with .biz, I sometimes have the impression that .su and .cc could be sinkholed in their entirety, because the bad domains seem to vastly outnumber whatever (if any) good is running under these TLDs as well. Earlier today, ISC reader Michael contacted us with information that several PCs on his network had started to communicate with iestats.cc, emstats.su, ehistats.su, e-protection...


2013/5/16 14:51:14 | 4 reads

As an add-on to ISC Handler Lenny Zeltser's earlier diary on extracting certificates from signed Windows binaries, here's how to do the same on a Mac. Given that today's blog over at F-Secure documents a screenshot-taking Mac spyware that is signed with a developer ID, signed bad .apps might actually be more prevalent than expected. To verify and extract signatures and certificate...


2013/5/16 12:00:01 | 2 reads

Dear Valued Customer,PayPal security team is sending you this notification message because we seem to be having errors in the proper verification of your account. This might be due to one of the following reasons:*A recent Change in your Account Details*An Internal error within our servers CLICK HERE to rectify these Errors.Regards,PayPal Online Security Team....


2013/5/16 12:00:01 | 3 reads

DEAR ACCOUNT HOLDER,Online access to your PayPal account has been suspended. due to invalid account information provided.To have your online account reinstated, you need to verify your online service access.Click here for verificationPlease note that accounts not verify within 72HRS of suspension are subject to termination.RegardsPAYPAL...