<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/xsl/atom.xsl" ?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <author>
  <name>Sophos Plc.</name>
  <email>webmaster@sophos.com</email>
  </author>
  <icon>http://feeds.sophos.com/favicon.ico</icon>
  <id>http://feeds.sophos.com/en/atom1_0-sophos-sophoslabs-blog.xml</id>
  <link href="http://feeds.sophos.com/en/atom1_0-sophos-sophoslabs-blog.xml" rel="self" type="application/atom+xml" hreflang="en" title="SophosLabs blog � 2008� May" />
  <rights type="text">&#169; Copyright 1997-2008, Sophos Plc
</rights>
  <title type="html">SophosLabs blog � 2008� May</title>
  <updated>2008-05-12T16:41:24Z</updated>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/05/1401.html</id>
    <link href="http://www.sophos.com/security/blog/2008/05/1401.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Poetic Justice" />
    <title type="html">Poetic Justice</title>
    <updated>2008-05-12T16:41:24Z</updated>
    <summary type="html">Oh how we sail, in this wonderful place
where vision is obscured, and they have no face
yet the winds blow strong, and they never relent
the storm of spam that we all are sent.
The spam fiends currently propogating en masse have added a poetic touch to their efforts to be man&amp;#8217;s saviour. Now, adverts for virility medication [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/05/1398.html</id>
    <link href="http://www.sophos.com/security/blog/2008/05/1398.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Give Them an Inch and They’ll Try to Rule!" />
    <title type="html">Give Them an Inch and They’ll Try to Rule!</title>
    <updated>2008-05-11T15:50:06Z</updated>
    <summary type="html">A classic case of impudent opportunism, more and more malware are now using standard Microsoft Windows Operating System files to do their bidding.
Last year there were examples of malware modifying WINLOGON.EXE, a critical system file, to load a malicious DLL. The entrypoint code is modified to call LoadLibraryA on the Trojan DLL and then execution [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/05/1397.html</id>
    <link href="http://www.sophos.com/security/blog/2008/05/1397.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="CARO On Packers and Obfuscators" />
    <title type="html">CARO On Packers and Obfuscators</title>
    <updated>2008-05-10T06:50:51Z</updated>
    <summary type="html">Last week several SophosLabs staff attended the 2nd International CARO workshop to discuss packers and obfuscators and how the anti-malware industry is dealing with them.
It was interesting to see the various approaches being explored and employed by vendors in dealing with hard-to-do packer and obfuscator technology in the anti-malware arena.
Sophos has been actively detecting a [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/05/1385.html</id>
    <link href="http://www.sophos.com/security/blog/2008/05/1385.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="SQL sorcery" />
    <title type="html">SQL sorcery</title>
    <updated>2008-05-09T16:13:18Z</updated>
    <summary type="html">Since I last blogged about a recent spate of aggressive SQL injection attacks [1], we have seen continued activity, with sites across the globe being hit. Amongst the casualties are numerous well known brands. This lunchtime I decided to pull together some data on the sites we have seen hit in these attacks since late [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/05/1360.html</id>
    <link href="http://www.sophos.com/security/blog/2008/05/1360.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Mister Swizzor’s Wacky Dialog Box Adventure" />
    <title type="html">Mister Swizzor’s Wacky Dialog Box Adventure</title>
    <updated>2008-05-09T13:08:09Z</updated>
    <summary type="html">Mr Swizzor had a problem. He knew that anti-malware engine heuristics thought that GUI applications without windows and buttons and text boxes were worrisome, because creating a GUI application without a GUI is a bit silly. But if he put windows and buttons and text boxes in his Trojan, those nasty anti-virus companies might decide that [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/05/1377.html</id>
    <link href="http://www.sophos.com/security/blog/2008/05/1377.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Free MP3s? Nothing in life is free" />
    <title type="html">Free MP3s? Nothing in life is free</title>
    <updated>2008-05-08T15:09:50Z</updated>
    <summary type="html">A couple of days ago McAfee posted an interesting blog entry detailing the aggressive use of fake MP3 files to trick victims into installing a potentially unwanted application (PUA). The article gathered some press, not least because the fake MP3 files were assigned a threat level of &amp;#8216;medium&amp;#8217; for McAfee&amp;#8217;s home users.
Users are likely to [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/05/1372.html</id>
    <link href="http://www.sophos.com/security/blog/2008/05/1372.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Safe sofa surfing?" />
    <title type="html">Safe sofa surfing?</title>
    <updated>2008-05-08T07:28:47Z</updated>
    <summary type="html">With the newer and ever more popular generation of games consoles it&amp;#8217;s not just about playing the game anymore, it&amp;#8217;s also about having the ability to browse the net from the comfort of your sofa in-between games or whenever takes your fancy.
Whether or not this form of surfing will ever become as popular as browsing [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/05/1369.html</id>
    <link href="http://www.sophos.com/security/blog/2008/05/1369.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Greetings from the EICAR conference" />
    <title type="html">Greetings from the EICAR conference</title>
    <updated>2008-05-06T07:42:42Z</updated>
    <summary type="html">The 17th annual EICAR conference is being held in Laval, France. Despite our worries about getting there it was actually quite an easy journey. French rail system is excellent.
This year SophosLabs have presented a couple of papers, both documenting research we did at the begining of the year. Boris and I presented our work on [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/05/1364.html</id>
    <link href="http://www.sophos.com/security/blog/2008/05/1364.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Make the Sophos Spam Pledge - as spam email turns 30 years old" />
    <title type="html">Make the Sophos Spam Pledge - as spam email turns 30 years old</title>
    <updated>2008-05-01T08:19:16Z</updated>
    <summary type="html">Today sees the 30th anniversary of the first ever spam message.
The message was sent by Gary Thuerk, an over-enthusiastic sales and marketing representative of DEC, to all 393 users of ARPANET (which later became the internet as we know it today).
In those 30 years, spam has progressed from a minor nuisance to a significant problem of bandwidth, users&amp;#8217; [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/05/1365.html</id>
    <link href="http://www.sophos.com/security/blog/2008/05/1365.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Even Rocket Scientists fall prey to malware" />
    <title type="html">Even Rocket Scientists fall prey to malware</title>
    <updated>2008-05-01T07:39:42Z</updated>
    <summary type="html">It may not have been a Rocket Scientist but the report on The Register  that a NASA employee was conned into installing malware, should be a wake-up call that it could happen to anyone in any company.
Though the malware was not named, looking at the DOJ press release raises a few concerns:
&amp;#8220;As a result [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/04/1363.html</id>
    <link href="http://www.sophos.com/security/blog/2008/04/1363.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="GTA IV - free!!" />
    <title type="html">GTA IV - free!!</title>
    <updated>2008-04-30T14:40:27Z</updated>
    <summary type="html">Yesterday saw the release of Grand Theft Auto IV (GTA IV), arguably the most eagerly awaited game of the year. Never ones to drag their feet, spammers are already hoping to catch gamers out with the offer of a free copy of the game for PS3. Heck, they&amp;#8217;re even throwing in a Playstation 3 as [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/04/1361.html</id>
    <link href="http://www.sophos.com/security/blog/2008/04/1361.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="More poisoned adverts - Yahoo!" />
    <title type="html">More poisoned adverts - Yahoo!</title>
    <updated>2008-04-30T14:03:07Z</updated>
    <summary type="html">Over the weekend the Spyware Sucks blog talked about Yahoo! serving up poisoned adverts via one of their websites. Subsequent posts suggested that Sandi Hardmeier had not received a favorable resolution after informing Yahoo! of this issue. On Monday The Register highlighted this issue.
Currently, the malicious adverts are still on Yahoo! servers and can be [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/04/1359.html</id>
    <link href="http://www.sophos.com/security/blog/2008/04/1359.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Game Over!" />
    <title type="html">Game Over!</title>
    <updated>2008-04-28T16:21:53Z</updated>
    <summary type="html">Many people with even a vague interest in security will be aware of Defcon. The Vegas-based hacker conference is held as a yearly event where security experts and enthusiasts alike are able to present and attend lectures addressing various issues in modern IT security.
In addition to all-night parties, no-holds gambling and other Vegas orientated activities [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/04/1358.html</id>
    <link href="http://www.sophos.com/security/blog/2008/04/1358.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Infiltrating botnets" />
    <title type="html">Infiltrating botnets</title>
    <updated>2008-04-28T09:22:47Z</updated>
    <summary type="html">I read an interesting paper this morning written by folks at the University of Mannheim and Institut Eurecom. In the paper they present results of research in which they monitored the P2P botnet of Storm, with a view to understanding, measuring and potentially being able to disrupt it [1]. The work was presented in the [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/04/1355.html</id>
    <link href="http://www.sophos.com/security/blog/2008/04/1355.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Phish of the day" />
    <title type="html">Phish of the day</title>
    <updated>2008-04-26T15:11:28Z</updated>
    <summary type="html">Even in an otherwise quiet Saturday there are several phishing campaigns worth mentioning. The first is a campaign targeting Abbey UK bank. This is a standard but well orchestrated and sustained spamming using several newly created domains. A botnet (or few) is used to send  emails that vary both the Abbby owned domain name [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/04/1350.html</id>
    <link href="http://www.sophos.com/security/blog/2008/04/1350.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Happy Birthday SophosLabs Blog" />
    <title type="html">Happy Birthday SophosLabs Blog</title>
    <updated>2008-04-25T16:02:25Z</updated>
    <summary type="html">With all the excitement of my vacation and Infosec, the fact that the SophosLabs blog is now one year old escaped me.
I posted the first entry on April 19th last year following a malware attack using the tragedy at Virginia Tech.
Since then we have posted over 700 articles on a wide range of topics, everything from [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/04/1348.html</id>
    <link href="http://www.sophos.com/security/blog/2008/04/1348.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Do you recognise him?" />
    <title type="html">Do you recognise him?</title>
    <updated>2008-04-25T15:58:59Z</updated>
    <summary type="html">With no end of malware these days aggressively targeting peoples&amp;#8217; finances and personal data it was a surprise this morning to see a simple VBS script worm, apparently written with the sole aim of airing a personal grievance.
VBS/AutoRun-DQ displays the following picture:

Writing something like this just to express annoyance with an individual is an interesting, [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/04/1346.html</id>
    <link href="http://www.sophos.com/security/blog/2008/04/1346.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Fraudsters Target Fears Over Identity Theft" />
    <title type="html">Fraudsters Target Fears Over Identity Theft</title>
    <updated>2008-04-25T08:18:50Z</updated>
    <summary type="html">The internet is a great place for fraudsters to con naive computers users by appealing to their fears and desires.
Fake/fraudulent anti-malware (anti-virus, anti-spyware etc.) applications have been around for a long time and we see a regular influx of new variants.  More recently we&amp;#8217;ve seen a variation on this theme that targets current fears over [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/04/1345.html</id>
    <link href="http://www.sophos.com/security/blog/2008/04/1345.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Malware with a sprinkle of religious conscience?" />
    <title type="html">Malware with a sprinkle of religious conscience?</title>
    <updated>2008-04-24T03:24:23Z</updated>
    <summary type="html">Today was a most unusual day; I analyzed two malware samples which contained religious themes in two completely different contexts. Before I go ahead and talk about these two samples, I want to apologize if anyone is offended by my blog.
W32/Autorun-DP is a malware which targets an Indonesian audience. It is a run-of-the-mill Autorun worm [...]</summary>
  </entry>
  <entry>
    <id>http://www.sophos.com/security/blog/2008/04/1339.html</id>
    <link href="http://www.sophos.com/security/blog/2008/04/1339.html?_log_from=atom" rel="alternate" type="text/html" hreflang="en" title="Want to become invulnerable? Now you can!" />
    <title type="html">Want to become invulnerable? Now you can!</title>
    <updated>2008-04-23T23:47:09Z</updated>
    <summary type="html">Back when I was growing up, I remember playing video games such as Super Mario Brothers and thinking to myself, &amp;#8220;Boy, I wish I could get star power and become invulnerable!&amp;#8221;. Well dream no more, let me introduce you to the worlds first invulnerable stone as seen in a spam message today.

At USD $1,000 it [...]</summary>
  </entry>
</feed>
