<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PC CyberTek &#187; 0day</title>
	<atom:link href="http://www.pccybertek.com/category/0day/feed" rel="self" type="application/rss+xml" />
	<link>http://www.pccybertek.com</link>
	<description>The cyberspace visitor's information center</description>
	<lastBuildDate>Wed, 12 May 2010 21:57:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Fake Apple Store Order E-mail</title>
		<link>http://www.pccybertek.com/2010/04/fake-apple-store-order-e-mail</link>
		<comments>http://www.pccybertek.com/2010/04/fake-apple-store-order-e-mail#comments</comments>
		<pubDate>Sun, 11 Apr 2010 05:15:36 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[0day]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[e-mail]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/?p=401</guid>
		<description><![CDATA[Time to add another fake e-mail to the long list of social engineering e-mail scams. This one looks like this. Subject 4912-3337 Apple AppStore Confirmation Sender Apple Up-To-Date Add contact Apple Store Call 1-800-MY-APPLE #4368-66525 Order Details You can also contact Apple Store Customer Service or visit online for more information. Visit the Apple Online [...]]]></description>
			<content:encoded><![CDATA[<p>Time to add another fake e-mail to the long list of social engineering e-mail scams. This one looks like this.</p>
<blockquote><p>
Subject 	4912-3337 Apple AppStore Confirmation<br />
Sender 	Apple Up-To-Date Add contact</p>
<p>Apple Store<br />
Call 1-800-MY-APPLE</p>
<p>#4368-66525<br />
<a href="http://">Order Details</a></p>
<p>You can also contact Apple Store Customer Service or visit online for more information.</p>
<p>Visit the Apple Online Store to purchase Apple hardware, software, and third-party accessories.<br />
Copyright 2010 Apple Inc. All rights reserved. </p>
</blockquote>
<p>This one wants you to click on the order details link, which I have removed, but if you look at the &#8220;Order Details&#8221; link more closely, you will see that it doesn&#8217;t go to the apple store but links to some place called goofbomb. I don&#8217;t feel like testing out my anti-virus or risk getting a 0-day virus or some malware, let&#8217;s just assume it&#8217;s a bad place. So keep your eyes out for this and other e-mails that claim you have purchased something, or missed a delivery, and gives you a link to your &#8220;order&#8221; or has an attachment for you to open. Quite a few of these going around these days.</p>
<p>Surf Safe</p>
<!-- AdSense Now! V1.77 -->
<!-- Post[count: 2] -->
<div class="adsense adsense-leadout" style="float:right;margin: 12px;"><script type="text/javascript"><!--
google_ad_client = "pub-8003034946906995";
/* Cybertek Post Gray 180x150 */
google_ad_slot = "3953975798";
google_ad_width = 180;
google_ad_height = 150;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div>]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2010/04/fake-apple-store-order-e-mail/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Another Adobe Acrobat Reader 0-Day Exploit</title>
		<link>http://www.pccybertek.com/2010/01/another-adobe-acrobat-reader-0-day-exploit</link>
		<comments>http://www.pccybertek.com/2010/01/another-adobe-acrobat-reader-0-day-exploit#comments</comments>
		<pubDate>Thu, 07 Jan 2010 11:13:57 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[0day]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[adobe acrobat pdf patch]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/?p=322</guid>
		<description><![CDATA[Here we go again. This isn&#8217;t news hot off the press, but I decided I should post about it here just in case some of you have missed it. There has been another Adobe Acrobat Reader exploit, CVE 2009-4324. Since it was first disclosed back in the middle of December, it has grown even nastier. The [...]]]></description>
			<content:encoded><![CDATA[<p>Here we go again. This isn&#8217;t news hot off the press, but I decided I should post about it here just in case some of you have missed it. There has been another Adobe Acrobat Reader exploit, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4324">CVE 2009-4324</a>. Since it was first disclosed back in the middle of December, it has grown even nastier. The <a href="http://www.isc.sans.org">Internet Storm Center</a> over at <a href="http://www.sans.org">sans.org</a> has a good <a href="http://isc.sans.org/diary.html?storyid=7903" target="_blank">analysis</a> of one of the current variants.</p>
<p>There are still a couple days before Adobe releases a patch, which will finally be released on Jan 12. Adobe suggests you disable Java support until then. This is not the first time this has happened. What I&#8217;m suggesting is that even after this is patched, just keep Java disabled. If you open a PDF file that requires Java support, you could always turn it back on. With so many exploits in the wild, and how long it takes for the anti virus vendors to discover them, this one won&#8217;t be fixed for almost a month since it was first disclosed publicly, it&#8217;s better safe than sorry. Just disable Java support for good. Here&#8217;s how to disable Java support in Adobe Acrobat Reader</p>
<p>quoted from Adobe.com</p>
<blockquote><p>
SOLUTION</p>
<p>Customers using Adobe Reader or Acrobat versions 9.2 or 8.1.7 can utilize the JavaScript Blacklist Framework to prevent this vulnerability. Please refer to the TechNote for more information.</p>
<p>Customers who are not able to utilize the JavaScript Blacklist functionality can mitigate the issue by disabling JavaScript in Adobe Reader and Acrobat using the instructions below:<br />
1. Launch Acrobat or Adobe Reader.<br />
2. Select Edit>Preferences<br />
3. Select the JavaScript Category<br />
4. Uncheck the &#8216;Enable Acrobat JavaScript&#8217; option<br />
5. Click OK</p>
<p>Customers using Microsoft DEP (&#8220;Data Execution Prevention&#8221;) functionality available in certain versions of Microsoft Windows are at reduced risk in the following configurations:</p>
<p>All versions of Adobe Reader 9 running on Windows Vista SP1 or Windows 7<br />
Acrobat 9.2 running on Windows Vista SP1 or Windows 7<br />
Acrobat and Adobe Reader 9.2 running on Windows XP SP3<br />
Acrobat and Adobe Reader 8.1.7 running on Windows XP SP3, Windows Vista SP1, or Windows 7<br />
With the DEP mitigation in place, the impact of this exploit has been reduced to a Denial of Service during our testing.
</p></blockquote>
<p>Watch your docs and surf safe</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2010/01/another-adobe-acrobat-reader-0-day-exploit/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake Adobe Flash Player</title>
		<link>http://www.pccybertek.com/2009/09/fake-adobe-flash-player</link>
		<comments>http://www.pccybertek.com/2009/09/fake-adobe-flash-player#comments</comments>
		<pubDate>Fri, 11 Sep 2009 10:27:22 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[0day]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[fix]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[fake adobe player]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/?p=258</guid>
		<description><![CDATA[There is a fake adobe flash player updater that monitors your google searches. It looks just like the adobe flash installer. I&#8217;m not sure where I picked it up, but luckily I found this fake adobe flash player on a computer running firefox. Good thing I run NOD 32. I have been getting a notice [...]]]></description>
			<content:encoded><![CDATA[<p>There is a fake adobe flash player updater that monitors your google searches. It looks just like the adobe flash installer. I&#8217;m not sure where I picked it up, but luckily I found this fake adobe flash player on a computer running firefox. Good thing I run NOD 32. I have been getting a notice that NOD 32 was blocking an outbound connection <img src="http://pccybertek.moesarts.com/wp-content/uploads/2009/09/fake_flash.jpg" alt="fake_flash" title="fake_flash" width="350" height="432" class="alignleft size-full wp-image-259" /></p>
<p>I found out that I was infected by this Fake <a href="http://blog.misec.net/2009/08/25/fake-adobe-flash-player-monitors-your-google-searches/">Adobe Flash Player</a></p>
<p>While that website does tell you how to figure out if you have it or not, it doesn&#8217;t really tell you how to remove it, unless you buy their program. So I&#8217;m currently in the process of removing it. If you do have it, you&#8217;ll want to stop it right now! I&#8217;ve found that by going into Firefox&#8217;s extensions (Tools -> Addons -> extensions) you can disable Adobe Player 0.2 and restart Firefox. After doing this, I no longer got the warning for NOD 32 that it&#8217;s blocking the connection that msjupdate site, which I don&#8217;t know why it hasn&#8217;t been shut down yet.<br />
I found socks.exe was running and when I looked for that file, I found it in my Windows/system folder with a creation date of 09-09-09, so I stopped socks.exe and renamed it socks.bak I would have deleted it but just in case it wasn&#8217;t installed by this Trojan, I figure it&#8217;s better to rename it. If some legit program I have starts complaining that socks.exe is missing, I can always rename it back to socks.exe</p>
<p>Once I&#8217;ve figured out how to completely remove it, I will update this post. In the meantime, disabling it will work. It&#8217;s after 3AM and I should have been in bed hours ago, but this was too important not to immediately warn you about it and give you at least a way of stopping it until I can post removal instructions. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2009/09/fake-adobe-flash-player/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Word Press Login Security Issue</title>
		<link>http://www.pccybertek.com/2009/08/word-press-login-security-issue</link>
		<comments>http://www.pccybertek.com/2009/08/word-press-login-security-issue#comments</comments>
		<pubDate>Tue, 11 Aug 2009 18:56:08 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[0day]]></category>
		<category><![CDATA[blog support]]></category>
		<category><![CDATA[fix]]></category>
		<category><![CDATA[word press]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/?p=241</guid>
		<description><![CDATA[This just in from the Internet Storm Center Juha-Matti pointed out multple reports on a vulnerability in the widely used wordpress blog software that supposedly allows lets remote users reset the administrative password. They all lead to an original post on a full disclosure mailing list. You can get all the details from the original [...]]]></description>
			<content:encoded><![CDATA[<p>This just in from the Internet Storm Center</p>
<blockquote><p>Juha-Matti pointed out multple reports on a vulnerability in the widely used wordpress blog software that supposedly allows lets remote users reset the administrative password. They all lead to an original post on a full disclosure mailing list.</p></blockquote>
<p>You can get all the details from the original post &#8211; <a href="http://isc.sans.org/diary.html?storyid=6934">WordPress unauthenticated administrator password reset<br />
</a></p>
<p>You can find the fix <a href="http://core.trac.wordpress.org/changeset/11798">here</a></p>
<p>Basically you just need to change line 190 in wp-login.php from<br />
 <em><strong>if ( empty( $key )</strong></em><br />
to<br />
 <em><strong>if ( empty( $key ) || is_array( $key ) </strong>)</em><br />
If line 190 in wp-login.php doesn&#8217;t match the example, you should update Word Press.</p>
<p>I&#8217;ve already done it here and everything still works. I also tried it on a version of Word Press that isn&#8217;t the latest version. I had to search for the string that needed changing because it&#8217;s not on line 190 in the older version. I updated the info and everything is working there too.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2009/08/word-press-login-security-issue/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox Addons Insecure</title>
		<link>http://www.pccybertek.com/2009/08/firefox-addons-insecure</link>
		<comments>http://www.pccybertek.com/2009/08/firefox-addons-insecure#comments</comments>
		<pubDate>Sat, 01 Aug 2009 23:19:01 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[0day]]></category>
		<category><![CDATA[DefCon]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/?p=206</guid>
		<description><![CDATA[Unable to attend DefCon this year, I&#8217;ve been following it on twitter. There was a talk about how insecure Firefox extensions are. @ramereth word to the wise: DO NOT trust any firefox extension. assume they can grab and do anything including executing other code #defcon Just one of many tweets talking about how scary the [...]]]></description>
			<content:encoded><![CDATA[<p>Unable to attend DefCon this year, I&#8217;ve been following it on twitter. There was a talk about how insecure Firefox extensions are. </p>
<blockquote><p> @ramereth word to the wise: DO NOT trust any firefox extension. assume they can grab and do anything including executing other code #defcon</p></blockquote>
<p>Just one of many tweets talking about how scary the talk was. So until I can get more information on this, I&#8217;m disabling most of my Firefox extensions. Could this be Firefox&#8217;s vulnerability equivalent to Internet Explorer&#8217;s active-x? Ironically,  I&#8217;ve been using Google&#8217;s Chrome browser lately. I&#8217;m liking it more and more. I was just switching back to Firefox because it has a couple extensions I use a lot. But now that they might not be safe, it looks like Chrome is going to be set as my default browser. At least until I find out more about these Firefox extension exploits. </p>
<p>Seeing how this talk was given today, I suspect there will soon be a rash of these exploits and figured I should pass on the info I have even though it&#8217; sketchy at best at this point. To disable your extensions in Firefox, just go to Tools, then addons, then extensions, and uninstall or disable them. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2009/08/firefox-addons-insecure/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker Help and Resources</title>
		<link>http://www.pccybertek.com/2009/03/conficker-help-and-resources</link>
		<comments>http://www.pccybertek.com/2009/03/conficker-help-and-resources#comments</comments>
		<pubDate>Tue, 31 Mar 2009 17:39:57 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[0day]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/?p=114</guid>
		<description><![CDATA[I&#8217;m going to post some helpful info about conficker in a bit. I&#8217;m at work right now and can&#8217;t. Will do it at lunch&#8230; Some real good and timely resources. Be sure to check back]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m going to post some helpful info about conficker in a bit. I&#8217;m at work right now and can&#8217;t. Will do it at lunch&#8230; Some real good and timely resources. Be sure to check back</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2009/03/conficker-help-and-resources/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Acrobat Reader Vulnerability &amp; Fix</title>
		<link>http://www.pccybertek.com/2009/02/adobe-acrobat-reader-vulnerability-fix</link>
		<comments>http://www.pccybertek.com/2009/02/adobe-acrobat-reader-vulnerability-fix#comments</comments>
		<pubDate>Tue, 24 Feb 2009 20:14:00 +0000</pubDate>
		<dc:creator>chris</dc:creator>
				<category><![CDATA[0day]]></category>
		<category><![CDATA[acrobat reader]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[fix]]></category>

		<guid isPermaLink="false">http://www.pccybertek.com/?p=51</guid>
		<description><![CDATA[It has been recently disclosed that Adobe Acrobat Reader is vulnerable to a virus attack. Known as Adobe Reader PDF File Handling Remote Code Execution Vulnerability. A .pdf file, which is what you are reading with acrobat, is created with some code in it that uses java to exploit your computer. After checking the usual [...]]]></description>
			<content:encoded><![CDATA[<p>It has been recently disclosed that Adobe Acrobat Reader is vulnerable to a virus attack. Known as <span style="font-style: italic;">Adobe Reader PDF File Handling Remote Code Execution Vulnerability</span>. A .pdf file, which is what you are reading with acrobat, is created with some code in it that uses java to exploit your computer.</p>
<p>After checking the usual exploit sites, I found several versions of this attack and proof of concepts. I tested them against several anti virus programs, and so far none of them detect it. I believe it is because of the way this attack is implemented. And I don&#8217;t think they will detect it since it&#8217;s not an &#8220;infected&#8221; file but a .pdf document. I could be wrong about this and maybe there will be some anti virus software that will detect it. Let me clarify this. The exploits I found were not detected. There is a trojan going around, called <span style="font-style: italic;">Pidief.E</span>, which uses this vulnerability to install a second piece of malware. This second piece of malware takes screen shots and installs a keylogger. The screen shots and what you have typed on your computer are uploaded somewhere so the bad guys can go through it, and look for user names, passwords, credit card numbers, etc.<br />This particular malware can be detected, it&#8217;s the others that are out there that are worrisome.</p>
<p>I was more concerned with finding a fix now, because Adobe has said the flaw will be closed by March 11th, through updates to Acrobat Reader 9. Updates for earlier versions will be released later.</p>
<p>For now I have found to fixes. The first is a &#8220;homebrew&#8221; patch from soucerfire and can be found <a href="http://vrt-sourcefire.blogspot.com/2009/02/homebrew-patch-for-adobe-acroreader-9.html">here.</a> While I applaud their efforts, replacing the .dll file with their patch could have unknown results. The second fix, which I have been implimenting all day it work today, is to disable java script in acrobat reader. This is easy enough to do. Simply run Adobe Acrobat Reader. Select edit and go down to teh bottom and select prefrences. Once prefrences is open, you will see JavaScript on the left side, under catagories. After you have selected JavaScript, you will see your options on the right. The first box that is checked says <span style="font-style: italic;">Enable Acrobat Java Script</span>. Just uncheck this box, and you are done.</p>
<p>If you open a .pdf file in the future and it asks you to re-enable java script, be sure to tell it no. And be sure to update Acrobat Reader when Adobe does post the update.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pccybertek.com/2009/02/adobe-acrobat-reader-vulnerability-fix/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	<img style='margin:0;padding:0;border:0;' width='1px' height='1px' src="http://pccybertek.moesarts.com/wp-content/plugins/mystat/mystat.php?act=time_load&id=181496&rnd=1431226897" /></channel>
</rss>
