USLANMAM
USLANMAM öğesini iGoogle sayfanıza ekleyin.
UslanmaM En Kaliteli Bilgi Adresiniz
Geri git   USLANMAM > HABERLER > English News > Technology News
Google
 
UslanmaM Resim AlbümleriSosyal Gruplar
Kayıt ol Sosyal Gruplar Ajanda Konuları Okundu Kabul Et

Technology News Technology news for enterprise IT from InfoWorld

Yeni Konu aç  Cevapla
 
LinkBack Seçenekler Stil
Alt 08-20-2007, 06:00 PM   #1 (permalink)
Yeni Üye
 
USLANMAM - ait Kullanıcı Resmi (Avatar)
Standart Monster.com identity attack may claim more vicitims

(Linkleri Üyelerimiz Görebilir. UslanmaM Üyeliği İçin Tıklayın) - The 46000 people reportedly Linkleri Üyelerimiz Görebilir. UslanmaM Üyeliği İçin Tıklayın on job sites may be only a fraction of the victims of an ambitious multistage attack that has stolen data belonging to several hundred thousand people who posted resumes on Monster.com a researcher said this weekend.
Linkleri Üyelerimiz Görebilir. UslanmaM Üyeliği İçin Tıklayın
According to Symantec security analyst Amado Hidalgo a new Trojan horse called Infostealer.Monstres by Symantec has stolen more than 1.6 million records belonging to several hundred thousand people from Monster Worldwide's job search service. That data is then used to target the Monster.com users with credible phishing mail that plants more malware on their machines.
"We are investigating the reports related to this Trojan and will take any necessary steps indicated by that investigation" Monster.com spokesman Steve Sylven said Sunday in an e-mail.
The personal information filched from Monster.com includes names e-mail addresses home address phone numbers and resume identification numbers said Hidalgo who traced the data to a remote server used by the attackers to store the stolen information. Infostealer.Monstres ripped off Monster.com by using legitimate log-ins likely stolen from recruiters and human resource personnel who have access to the "Monster for employers" areas of the site.
Once inside the Trojan horse ran automated searches for resumes of candidates located in certain countries or working in certain fields. The results were then uploaded to the attackers' remote server.
"Such a large database of highly personal information is a spammer's dream" said Hidalgo. In fact that's exactly what the attackers are using their newly-acquired data for.
"The attackers first gather e-mail address and other personal information from resumes posted to Monster.com with Infostealer.Monstres" Hidalgo said. "Next they will try to infect the computers of those candidates by sending targeted Monster.com phishing mails which install [Banker.c or Gpcoder.e]."
The first piece of malware dubbed Banker.c by Symantec is a run-of-the-mill information-stealing Trojan horse that monitors the infected PC for log-ons to online banking accounts. When it sniffs a log-on in process Banker.c records the username and password then transmits the data back to hacker HQ. Gpcoder.e on the other hand is "ransomware" the name given to Trojan horses that encrypt files on the hacked computer then hold those files hostage until the user pays a fee to unlock the data.
Although both Banker.c and Gpcoder.e may be distributed in other ways -- SecureWorks last week said it had spotted something like the former coming from infected ads placed on job search sites -- Infostealer.Monstres' built-in mailing code and template lets it send messages posing as missives from Monster.com straight to the job-site users it finds in its automated searches.
Infostealer.Monstres' second-stage attack which uses Gpcoder is especially insidious. Realistic-looking e-mails that contain convincing personal information -- the very information stolen from Monster.com -- instruct the recipient to download a program called "Monster Job Seeker Tool." There is no tool of course; victims download the ransomware Gpcoder.e instead.
Hidalgo's research led him to conclude that the three pieces of code -- Infostealer.Monstres Banker.c and Gpcoder.e -- are related and probably the work of a single group.
"While their final purpose is different their modus operandi is very similar using identical file names creating the same system folder injecting code into the same processes and hooking the same system functions using root-kit techniques to gain control of network functionalities and to steal sensitive information" said Hidalgo. "They share code and a number of traits that could indicate they were developed by the same group or perhaps created Linkleri Üyelerimiz Görebilir. UslanmaM Üyeliği İçin Tıklayın."
Monster.com's Sylven defended the service's automated searches and said that although the company monitors database activity stolen credentials have been used in the past to access the system. Moreover he said it's difficult to tell a valid automated search generated by a real person from one cranked out by software. "Many of our larger customers rely heavily on our database and their use may be similar to programmatic or scripted access" said Sylven.
He could not confirm that the stolen accounts had been disabled although Hidalgo noted in a blog entry posted Friday afternoon that Symantec had notified Monster of the compromised log-ins. "When unusual access is detected we do terminate that access and investigate if possible" Sylven said.


Linkleri Üyelerimiz Görebilir. UslanmaM Üyeliği İçin Tıklayın

USLANMAM isimli Üye şimdilik offline konumundadır  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Alıntı ile Cevapla

Cevapla


Konuyu Toplam 1 Üye okuyor. (0 Kayıtlı üye ve 1 Misafir)
 
Seçenekler
Stil

Yetkileriniz
You may not post new threads
You may not post replies
Eklenti Ekleyemezsiniz
You may not edit your posts

BB code is Açık
Smileler Açık
[IMG] Kodları Açık
HTML-KodlarıKapalı
Trackbacks are Açık
Pingbacks are Açık
Refbacks are Açık
Gitmek istediğiniz klasörü seçiniz

Benzer Konular
Konu Konuyu Başlatan UslanmaM Cevaplar Son Mesaj
War Monster SuyunGizemi Siemens Oyunlar 0 07-29-2007 07:48 PM
Suicide Attack On Turkish Convoy In Afghanistan -turaaa Condemns Attack; Continu USLANMAM English News 0 07-18-2007 01:00 PM
SLanka rebels claim second air attack (AFP) USLANMAM World News 0 04-24-2007 02:10 AM
Attack On A Publishing House In Malatya -president Sezer Condemns Attack USLANMAM English News 0 04-19-2007 12:40 PM
Gay neighborhoods worry over identity (AP) USLANMAM National News 0 03-12-2007 07:50 PM


Bütün Zaman Ayarları WEZ +2 olarak düzenlenmiştir. Şu Anki Saat: 11:11 AM .
Üyelerimiz görüşlerini önceden onay olmadan anında yazabilmektedir, bu yazılardan dolayı doğabilecek her türlü sorumluluk yazan kullanıcılara aittir, UslanmaM yoneticileri itina ile icerik kontrolleri yapmaktadir, yine de UslanmaM' da yasalara aykırı unsurlar bulursanız İLETİŞİME veya 0555 582 46 56 numaralı telefona bildirebilirsiniz, gereği yapılacaktır.
English Explanation: Our users can give their opinions without getting any approval in our site, all the responsibilities which can rise from these articles belong to these users, the managers of UslanmaM control the contents very carrefully, but if you find any item opposite to the rules CONTACT or dial +90555 582 46 56