<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.maximumpc.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Maximum PC exploit RSS Feed</title>
 <link>http://www.maximumpc.com/tags/exploit</link>
 <description>used for category lists, takes arguments</description>
 <language>en</language>
<item>
 <title>Some Linksys and Netgear Routers Vulnerable to New Exploit</title>
 <link>http://www.maximumpc.com/article/news/some_linksys_and_netgear_routers_vulnerable_new_exploit</link>
 <description>&lt;!--paging_filter--&gt;&lt;p&gt;Two security researchers on Saturday have warned that if you use cPanel to administer your website or certain Linksys or Netgear routers, you&#039;re leaving yourself open to web-based attacks that could potentially take control of your systems.&lt;/p&gt;
&lt;p&gt;The attacks are based on CSRF, or cross-site request forgery, which can be exploited simply by surfing to the &#039;wrong&#039; website, say Russ McRee of HolisticInfoSec.org and Mike Bailey of Skeptikal.org.&lt;/p&gt;
&lt;p&gt;&amp;quot;CSRF is bad stuff,&amp;quot; Bailey said at the Defcon hacker conference in Las Vegas. &amp;quot;It&#039;s a very under-appreciated vulnerability, and it&#039;s all over the place. Because it usually gets rated as a pretty minimal issue, it almost never gets fixed, and that means we have these kinds of holes all over.&amp;quot;&lt;/p&gt;
&lt;p&gt;When visiting a malicous website while logged in to the program, the attack is able to trick cPanel into carrying out sensitive commands by duping the device into thinking they came from the victim. And it doesn&#039;t look like this will be fixed anytime soon. &lt;/p&gt;
&lt;p&gt;&amp;quot;The response I got from cPanel was we can&#039;t fix this because it&#039;s a feature,&amp;quot; Bailey said. &amp;quot;Apparently, they&#039;re worried it&#039;s going to break integration with third party billing software, so they can&#039;t fix this.&amp;quot; &lt;/p&gt;
&lt;p&gt;Much more info &lt;a href=&quot;http://www.theregister.co.uk/2009/08/02/unholy_trinity_csrf/&quot;&gt;here&lt;/a&gt;. &lt;/p&gt;
&lt;p align=&quot;center&quot;&gt;&lt;img src=&quot;/files/u69/Linksys_Router.png&quot; width=&quot;405&quot; height=&quot;254&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-size: xx-small&quot;&gt;Image Credit: Linksys &lt;/span&gt;&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/some_linksys_and_netgear_routers_vulnerable_new_exploit#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8927">cpanel</category>
 <category domain="http://www.maximumpc.com/geek_tested/exploit">exploit</category>
 <category domain="http://www.maximumpc.com/geek_tested/hardware">hardware</category>
 <category domain="http://www.maximumpc.com/geek_tested/linksys">Linksys</category>
 <category domain="http://www.maximumpc.com/geek_tested/netgear">netgear</category>
 <category domain="http://www.maximumpc.com/geek_tested/router">Router</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/vulnerability">vulnerability</category>
 <pubDate>Mon, 03 Aug 2009 09:43:49 -0500</pubDate>
 <dc:creator>Paul Lilly</dc:creator>
 <guid isPermaLink="false">7271 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>World&#039;s First Cell Phone Botnet Could be Coming Soon</title>
 <link>http://www.maximumpc.com/article/news/worlds_first_cell_phone_botnet_could_be_coming_soon</link>
 <description>&lt;!--paging_filter--&gt;&lt;p&gt;You knew it would happen sooner or later, we&#039;re just a little surprised it took this long for hackers to release a botnet running on mobile phones. According to Symantec, a piece of malicious software called Sexy Space may be the first documented case.&lt;/p&gt;
&lt;p&gt;Like most botnets, Sexy Space relies on quite a bit of user interaction to be effective. Those who ultimately become a zombie in the botnet first receive a text message saying &amp;quot;A very sexy girl, Try it now!&amp;quot; Inside the message is a link that must be clicked, which then asks the potential victim to download software. The software then scours through the user&#039;s contact list and sends an SMS with the same message to each person. &lt;/p&gt;
&lt;p&gt;Symantec says that this particular botnet is being controlled by a central server, but it remains unclear whether or not the phones respond to remote commands.&lt;/p&gt;
&lt;p&gt;We&#039;re undoubtedly preaching to the choir on this one, but be wary of any rogue text messages, especially when they ask you to click a link and download software.&lt;/p&gt;
&lt;p align=&quot;center&quot;&gt;&lt;img src=&quot;/files/u69/Cellphone_Virus.png&quot; width=&quot;350&quot; height=&quot;274&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-size: xx-small&quot;&gt;Image Credit: chosun.com &lt;/span&gt;&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/worlds_first_cell_phone_botnet_could_be_coming_soon#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8752">botnet</category>
 <category domain="http://www.maximumpc.com/geek_tested/cell_phone">cell phone</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/3960">cellphone</category>
 <category domain="http://www.maximumpc.com/geek_tested/exploit">exploit</category>
 <category domain="http://www.maximumpc.com/geek_tested/mobile">mobile</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/smartphone">Smartphone</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <pubDate>Mon, 20 Jul 2009 12:55:51 -0500</pubDate>
 <dc:creator>Paul Lilly</dc:creator>
 <guid isPermaLink="false">7082 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>Mozilla Patches TraceMonkey Exploit with Firefox 3.5.1</title>
 <link>http://www.maximumpc.com/article/news/mozilla_patches_tracemonkey_exploit_firefox_351</link>
 <description>&lt;!--paging_filter--&gt;&lt;p&gt;If you&#039;re a Firefox user, be sure to grab the &lt;a href=&quot;http://arstechnica.com/open-source/news/2009/07/firefox-351-released-to-patch-tracemonkey-vulnerability.ars&quot;&gt;latest update&lt;/a&gt; bringing Firefox 3.5 to 3.5.1. A number of security and stability issues have been addressed in the newest release, but its main purpose was to patch a critical security vulnerability in the browser&#039;s TraceMonkey JavaScript engine. Prior to the patch, the bug could cause Firefox to crash when typing text into an input box on certain websites.&lt;/p&gt;
&lt;p&gt;&amp;quot;This is a JS engine bug dealing with deep bailing not properly restoring the return value from the result of the (fast native) escape function. We then try to do something with the uninitialized memory and crash in the interpreter,&amp;quot; wrote Mozilla&#039;s Blake Kaplan in a comment on the bug report. &lt;/p&gt;
&lt;p&gt;It didn&#039;t take long for researchers to discover that the bug was exploitable and could be used to execute arbitrary code. It&#039;s also been squashed in the 3.5.1 update, however researchers have discovered a similar bug that remains. According to Mozilla, it is looking into the issue, but so far doesn&#039;t believe the newly discovered bug is exploitable. &lt;/p&gt;
&lt;p align=&quot;center&quot;&gt;&lt;img src=&quot;/files/u69/Firefox351.png&quot; width=&quot;316&quot; height=&quot;266&quot; /&gt; &lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/mozilla_patches_tracemonkey_exploit_firefox_351#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/geek_tested/browser">browser</category>
 <category domain="http://www.maximumpc.com/geek_tested/exploit">exploit</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/8750">firefox 3.5.1</category>
 <category domain="http://www.maximumpc.com/geek_tested/mozilla">Mozilla</category>
 <category domain="http://www.maximumpc.com/geek_tested/patch">patch</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <pubDate>Mon, 20 Jul 2009 06:39:03 -0500</pubDate>
 <dc:creator>Paul Lilly</dc:creator>
 <guid isPermaLink="false">7080 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>Microsoft Releases Workaround for Video ActiveX Vulnerability That Can Pwn Your PC</title>
 <link>http://www.maximumpc.com/article/news/microsoft_releases_workaround_video_activex_vulnerability_can_pwn_your_pc</link>
 <description>&lt;!--paging_filter--&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u21826/Video_ActiveX_DS_Vuln.png&quot; alt=&quot;Microsoft rolls out workaround for Video ActiveX vulnerability in IE6, IE7&quot; width=&quot;410&quot; height=&quot;107&quot; /&gt;&lt;/div&gt;
&lt;p&gt;&amp;#160;&lt;/p&gt;
&lt;p&gt;This week, Microsoft announced that DirectShow ActiveX code in Internet Explorer 6 and 7 that was reserved for future use has finally been used - &lt;a href=&quot;http://news.cnet.com/8301-1009_3-10280141-83.html&quot;&gt;by malware providers&lt;/a&gt;. The DirectShow Video ActiveX control in the msvidctr.dll file can be used to take over your system if you visit an infected website. According to Symantec, thousands of websites (primarily in China and other parts of Asia) have been affected.&lt;/p&gt;
&lt;p&gt;Who&#039;s vulnerable? According to Microsoft Knowledge Base article &lt;a href=&quot;http://support.microsoft.com/kb/972890&quot;&gt;972890&lt;/a&gt;, &lt;strong&gt;Windows Server 2003, Windows XP SP2, Windows XP SP3, and Windows XP 64-bit edition&lt;/strong&gt; are at risk if they haven&#039;t upgraded to IE8. IE8 is not vulnerable because the DirectShow ActiveX control being exploited was disabled in IE8. But, if you&#039;re still running IE7 (or - horrors! - IE6), what now?&lt;/p&gt;
&lt;p&gt;Although Microsoft doesn&#039;t have a software patch, it&#039;s offering the next best thing: &lt;a href=&quot;http://support.microsoft.com/kb/972890&quot;&gt;visit&lt;/a&gt; KB article 972890 to download and run Microsoft Fix it control 50287 to work around the problem (the same site also offers Microsoft Fix it control 50288 to disable the workaround). The woraround and disable workaround controls are distributed in .msi installer files. Microsoft also recommends the workaround for &lt;strong&gt;Windows Vista&lt;/strong&gt; and &lt;strong&gt;Windows Server 2008&lt;/strong&gt; users who are still running &lt;strong&gt;IE7&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;If you want to learn more about what the workaround changes, you can &lt;a href=&quot;http://www.microsoft.com/technet/security/advisory/972890.mspx&quot;&gt;visit&lt;/a&gt; the Microsoft Security Advisory (972890) page. This page lists the CLSID values that must be changed. This information can be incorporated into a .reg file, or can be distributed to multiple PCs in a domain using Group Policy. For additional information, &lt;a href=&quot;http://www.securityfocus.com/bid/35558&quot;&gt;see&lt;/a&gt; Security Focus article 35558.&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/microsoft_releases_workaround_video_activex_vulnerability_can_pwn_your_pc#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/exploit">exploit</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/geek_tested/operating_system">operating system</category>
 <category domain="http://www.maximumpc.com/geek_tested/os">OS</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/vulnerability">vulnerability</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/4469">Windows Server 2003</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/3375">Windows Server 2008</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows_vista">Windows Vista</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows_xp">windows xp</category>
 <pubDate>Tue, 07 Jul 2009 19:40:58 -0500</pubDate>
 <dc:creator>Mark Edward Soper</dc:creator>
 <guid isPermaLink="false">6911 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>Fearing Exploit, Microsoft Patches PowerPoint</title>
 <link>http://www.maximumpc.com/article/news/fearing_exploit_microsoft_patches_powerpoint</link>
 <description>&lt;!--paging_filter--&gt;&lt;p&gt;Hackers have targeted everyone from QuickTime users to &lt;a href=&quot;/article/daily_news_brief_hackers_prey_on_epilepsy_patients&quot;&gt;epilepsy patients&lt;/a&gt;, so is anyone really suprised to see them now going after PowerPoint users?&lt;/p&gt;
&lt;p&gt;That&#039;s the latest word from Microsoft, who noted that Mac users running PowerPoint are also vulnerable (no matter what Justin Long says), although there has been no evidence that hackers have tried to attack the platform. The &amp;quot;critical&amp;quot; vulnerability relies on the intended victim opening an infected PowerPoint file either downloaded from the web or received as an email attachment.&lt;/p&gt;
&lt;p&gt;&amp;quot;At that point, the attacker would then have complete control over everything the user&#039;s account has permission to do on the system,&amp;quot; said Alfred Huger, a senior researcher with Symantec.&lt;/p&gt;
&lt;p&gt;Patches have been released for Windows users, but not for Mac computers. However, Microsoft did say it was working on one. &lt;/p&gt;
&lt;p align=&quot;center&quot;&gt;&lt;img src=&quot;/files/u69/Hacker_PowerPoint.png&quot; width=&quot;411&quot; height=&quot;337&quot; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-size: xx-small&quot;&gt;Image Credit: poweredtemplates.com &lt;/span&gt;&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/fearing_exploit_microsoft_patches_powerpoint#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/geek_tested/exploit">exploit</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/3071">Powerpoint</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <pubDate>Fri, 15 May 2009 15:56:40 -0500</pubDate>
 <dc:creator>Paul Lilly</dc:creator>
 <guid isPermaLink="false">6328 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>Redmond Reins in AutoRun, AutoPlay to Help Make Windows More Secure</title>
 <link>http://www.maximumpc.com/article/news/redmond_reins_autorun_autoplay_help_make_windows_more_secure</link>
 <description>&lt;!--paging_filter--&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u21826/header_arun-aplay.png&quot; alt=&quot;Microsoft makes AutoRun, AutoPlay more secure, starting with Windows 7 RC&quot; width=&quot;410&quot; height=&quot;208&quot; /&gt;&lt;/div&gt;
&lt;p&gt;AutoRun and AutoPlay, Microsoft&#039;s &amp;quot;dangerous duo&amp;quot; for launching programs from CD/DVD and other removable media types, have become among malware authors&#039; favorite infection vectors - and Microsoft has finally said, &amp;quot;enough already!&amp;quot;&lt;/p&gt;
&lt;p&gt;A research study by &lt;strong&gt;Forefront Client Security&lt;/strong&gt; &lt;a href=&quot;http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx&quot;&gt;cited&lt;/a&gt; by the &lt;strong&gt;Engineering Windows 7&lt;/strong&gt; blog determined that infections that can be started with AutoRun amounted to 17.7% of detected infections in the second half of 2008. &lt;/p&gt;
&lt;p&gt;Although AutoRun was originally designed strictly for optical media, it can be used for other types of media. For example, you can create an autorun.inf file that adds the program on the media to the AutoPlay menu Windows displays, and change the default icon to make the malware program mimic a legitimate program. Conficker used this method to spread, &lt;a href=&quot;http://blogs.egroup-us.com/?p=169&quot;&gt;as illustrated here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Starting in Windows 7 RC, Microsoft has changed how both AutoRun and AutoPlay work:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;AutoPlay no longer supports AutoRun on non-optical removable media. An autorun.inf file on a USB or other type of non-optical removable media will be disregarded. Only AutoPlay options that pertain to the types of files on the media will be listed.&lt;/li&gt;
&lt;li&gt;When AutoPlay displays programs present on the media, the dialog now states that those programs will be run from the media.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Microsoft&#039;s &lt;strong&gt;Security Research and Defense&lt;/strong&gt; blog provides &lt;a href=&quot;http://blogs.technet.com/srd/archive/2009/04/28/autorun-changes-in-windows-7.aspx&quot;&gt;sample dialogs and more details&lt;/a&gt; of how these changes work. The best news? Microsoft is planning to extend these security improvements to Windows Vista and XP users as well.&lt;/p&gt;
&lt;p&gt;Are there any downsides? For a vigorous discussion of programs and devices that might not work after this change, &lt;a href=&quot;http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#comments&quot;&gt;see the comment thread&lt;/a&gt; at the &lt;strong&gt;Engineering Windows 7&lt;/strong&gt; blog. To start a &lt;strong&gt;MaximumPC&lt;/strong&gt;-style discussion, you know what to do: click Comment and sound off! &lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/redmond_reins_autorun_autoplay_help_make_windows_more_secure#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/autoplay">AutoPlay</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/7880">AutoRun</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/6614">Conficker</category>
 <category domain="http://www.maximumpc.com/geek_tested/exploit">exploit</category>
 <category domain="http://www.maximumpc.com/geek_tested/malware">malware</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/geek_tested/operating_system">operating system</category>
 <category domain="http://www.maximumpc.com/geek_tested/os">OS</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/3243">windows 7</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows_vista">Windows Vista</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows_xp">windows xp</category>
 <category domain="http://www.maximumpc.com/geek_tested/worm">worm</category>
 <pubDate>Fri, 01 May 2009 19:04:35 -0500</pubDate>
 <dc:creator>Mark Edward Soper</dc:creator>
 <guid isPermaLink="false">6183 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>[Not So] Crazy - Redmond to Protect Pirated and Legit Window 7 Copies</title>
 <link>http://www.maximumpc.com/article/news/not_so_crazy_redmond_protect_pirated_and_legit_window_7_copies</link>
 <description>&lt;!--paging_filter--&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u21826/header_skull-Xbones_W7.png&quot; alt=&quot;Microsoft will update pirated and legit Windows 7 copies for security&#039;s sake&quot; width=&quot;410&quot; height=&quot;208&quot; /&gt;&lt;/div&gt;
&lt;p&gt;Softpedia &lt;a href=&quot;http://news.softpedia.com/news/Windows-7-Pirates-Will-Be-Kept-Safe-and-Cozy-by-Microsoft-110386.shtml&quot;&gt;reports&lt;/a&gt; that pirated copies of Windows 7 will be provided with security updates, update rollups, and even service packs. What is Microsoft thinking? Is Redmond promoting piracy?&lt;/p&gt;
&lt;p&gt;The idea of providing security and other updates to pirated copies as well as legit copies of Windows might seem crazy, but here&#039;s the reasoning, straight from Paul Cooke, director of Windows Client Enterprise Security:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Keeping a machine up to date is one of the first steps in helping ensure that they remain reliable, compatible, and safe from threats when they are online. Some of the most famous incidents of malicious software infection have come after security updates were publicly available from Microsoft - Blaster, Zotob, &lt;a href=&quot;/tags/Conficker&quot;&gt;Conficker&lt;/a&gt; and Sasser, just to name a few. Rest assured that we at Microsoft are committed to making sure that security updates are available to all of our users to help ensure a safe online experience for everyone.&lt;/p&gt;
&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Note that Cooke is laying the blame for many recent security problems where it belongs: &lt;strong&gt;on users and companies who will not upgrade their software to block such threats&lt;/strong&gt;. By continuing the recent policy of allowing users of non-genuine Windows to receive security updates, Microsoft is saying, in effect, &#039;don&#039;t blame us if unpatched systems are compromised.&#039; &lt;/p&gt;
&lt;p&gt;However, don&#039;t think that Redmond&#039;s turning a patched eye to either casual piracy or software counterfeiting. Pirated copies of Windows 7 won&#039;t be eligible for some of Microsoft&#039;s goodies, and Softpedia points out that counterfeit copies of Windows often come with a &amp;quot;free&amp;quot; bonus: malware.&lt;/p&gt;
&lt;p&gt;For your chance to sound off on security for software pirates, hit Comment.&lt;/p&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/not_so_crazy_redmond_protect_pirated_and_legit_window_7_copies#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/exploit">exploit</category>
 <category domain="http://www.maximumpc.com/geek_tested/microsoft">microsoft</category>
 <category domain="http://www.maximumpc.com/geek_tested/operating_system">operating system</category>
 <category domain="http://www.maximumpc.com/geek_tested/os">OS</category>
 <category domain="http://www.maximumpc.com/geek_tested/piracy">piracy</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/geek_tested/software">Software</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/5632">software piracy</category>
 <category domain="http://www.maximumpc.com/geek_tested/update">update</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/3243">windows 7</category>
 <category domain="http://www.maximumpc.com/geek_tested/windows_update">Windows Update</category>
 <pubDate>Thu, 30 Apr 2009 14:54:01 -0500</pubDate>
 <dc:creator>Mark Edward Soper</dc:creator>
 <guid isPermaLink="false">6166 at http://www.maximumpc.com</guid>
</item>
<item>
 <title>Twitter Users Hope Cure for Mikeyy Worm Lasts</title>
 <link>http://www.maximumpc.com/article/news/twitter_users_hope_cure_mikeyy_worm_lasts</link>
 <description>&lt;!--paging_filter--&gt;&lt;div style=&quot;text-align: center&quot;&gt;&lt;img src=&quot;/files/u21826/header-twitterworm.png&quot; alt=&quot;Over Easter weekend, Twitter users were besieged by the Mikeyy worm&quot; width=&quot;410&quot; height=&quot;151&quot; /&gt;&lt;/div&gt;
&lt;p&gt;Over Easter weekend, many Twitter fans were getting worms instead of finding Easter Eggs, as the developer of a rival microblogging site (StalkDaily), &lt;a href=&quot;http://adjix.com/af5t&quot;&gt;one 17-year-old Michael &amp;quot;Mikeyy&amp;quot; Mooney&lt;/a&gt;, was busy drawing Twitter users to his site by using the so-called &amp;quot;Mikeyy&amp;quot; or &amp;quot;StalkDaily&amp;quot; worm to infect links and Twitter profiles. According to &lt;strong&gt;&lt;a href=&quot;http://www.pcworld.com/article/163054/twitter_worm_a_closer_look_at_what_happened.html&quot;&gt;PCWorld&lt;/a&gt;&lt;/strong&gt; and the &lt;a href=&quot;http://status.twitter.com/post/95332007/update-on-stalkdaily-com-worm&quot;&gt;Twitter status page&lt;/a&gt;, the infection has now been brought under control. But inquiring minds want to know, &amp;quot;what happened?&amp;quot; and &amp;quot;how can we stop a future attack?&amp;quot; &lt;/p&gt;
&lt;p&gt;Doing a Google search for &amp;quot;Mikeyy&amp;quot; or &amp;quot;TwitterWorm&amp;quot; isn&#039;t the best way to find out, though, as the F-Secure security blog points out that fake news sites are being used to &lt;a href=&quot;http://www.f-secure.com/weblog/archives/00001657.html&quot;&gt;infect curious searchers with (unrelated) malware&lt;/a&gt;. So what really happened?&lt;/p&gt;
&lt;p&gt;Mikeyy/StalkDaily used XSS (Cross-Site Scripting) and CSRF (Cross Site Request Forgery) attacks (we&#039;ve &lt;a href=&quot;/tags/xss&quot;&gt;discussed XSS&lt;/a&gt; a number of times here at MaximumPC.com). Website developer and Twitter expert Lynne Pope &lt;a href=&quot;http://lynnepope.net/stalkdaily-twitter-xss-lessons-learned&quot;&gt;offers an excellent analysis&lt;/a&gt; of how the Mikeyy/StalkDaily attacks worked, and how you can protect yourself from similar exploits in the future:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;The very first thing you must do to protect yourself is this - do not browse to any sites while logged on to another site. Leaving authentication cookies exposed is dangerous. Log off, then navigate away.&lt;/p&gt;
&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Ms. Pope also recommends:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Firefox fans should use &lt;a href=&quot;https://addons.mozilla.org/en-US/firefox/addon/722&quot;&gt;NoScript&lt;/a&gt; to prevent scripts from running without explicit permission.&lt;/li&gt;
&lt;li&gt;Use the Hosts file to block domains pointed to by malware.&lt;/li&gt;
&lt;li&gt;Use tools &lt;a href=&quot;http://longurl.org/tools&quot;&gt;available at LongURL.org&lt;/a&gt; to determine where short URLs are actually pointing to (Mikeyy/StalkDaily used bit.ly and tinyurl.com to conceal the actual websites used for spreading the worm).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Were you affected by the Mikeyy/StalkDaily worm? Hit Comment and tell us your war stories.&lt;/p&gt;
&lt;h6&gt;Twitter logo courtesy of &lt;a href=&quot;http://messofcommentary.wordpress.com/&quot;&gt;a MESS of commentary&lt;/a&gt;. &lt;/h6&gt;
</description>
 <comments>http://www.maximumpc.com/article/news/twitter_users_hope_cure_mikeyy_worm_lasts#comments</comments>
 <category domain="http://www.maximumpc.com/article_type/news_amp_views">News</category>
 <category domain="http://www.maximumpc.com/article_type/news/windows">Windows</category>
 <category domain="http://www.maximumpc.com/geek_tested/exploit">exploit</category>
 <category domain="http://www.maximumpc.com/geek_tested/javascript">JavaScript</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/7679">Lynn Pope</category>
 <category domain="http://www.maximumpc.com/geek_tested/malware">malware</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/7677">Mikeyy</category>
 <category domain="http://www.maximumpc.com/geek_tested/security">Security</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/7678">StalkDaily</category>
 <category domain="http://www.maximumpc.com/geek_tested/twitter">twitter</category>
 <category domain="http://www.maximumpc.com/geek_tested/vulnerability">vulnerability</category>
 <category domain="http://www.maximumpc.com/geek_tested/web_20">web 2.0</category>
 <category domain="http://www.maximumpc.com/taxonomy/term/2783">web browser</category>
 <category domain="http://www.maximumpc.com/geek_tested/worm">worm</category>
 <category domain="http://www.maximumpc.com/geek_tested/xss">XSS</category>
 <pubDate>Tue, 14 Apr 2009 18:47:08 -0500</pubDate>
 <dc:creator>Mark Edward Soper</dc:creator>
 <guid isPermaLink="false">5992 at http://www.maximumpc.com</guid>
</item>
</channel>
</rss>
