<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; panda</title>
	<atom:link href="http://www.darknet.org.uk/tag/panda/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Tabnapping Attack On The Increase</title>
		<link>http://www.darknet.org.uk/2010/07/tabnapping-attack-on-the-increase/</link>
		<comments>http://www.darknet.org.uk/2010/07/tabnapping-attack-on-the-increase/#comments</comments>
		<pubDate>Tue, 06 Jul 2010 10:50:00 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[aza raskin]]></category>
		<category><![CDATA[browser vulnerability]]></category>
		<category><![CDATA[panda]]></category>
		<category><![CDATA[panda labs]]></category>
		<category><![CDATA[phishing amazon]]></category>
		<category><![CDATA[phishing facebook]]></category>
		<category><![CDATA[phishing gmail]]></category>
		<category><![CDATA[phishing paypal]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[spammers]]></category>
		<category><![CDATA[stealing passwords]]></category>
		<category><![CDATA[tab napping]]></category>
		<category><![CDATA[tab stealing]]></category>
		<category><![CDATA[tabnapping]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2794</guid>
		<description><![CDATA[This is an interesting new attack, I saw a live demo of it a while back here: Tabnabbing: A New Type of Phishing Attack. All you need to do is let the page load, then browse to another tab for 5 seconds or more and you&#8217;ll see the favicon change to Gmail and the page [...]]]></description>
			<content:encoded><![CDATA[<p>This is an interesting new attack, I saw a live demo of it a while back here: <a href="http://www.azarask.in/blog/post/a-new-type-of-phishing-attack/">Tabnabbing: A New Type of Phishing Attack</a>. All you need to do is let the page load, then browse to another tab for 5 seconds or more and you&#8217;ll see the favicon change to <a href="http://www.darknet.org.uk/tag/gmail/">Gmail</a> and the page will load a Gmail image.</p>
<p>And apparently the use of this attack is on the rise in the wild according to <a href="http://www.darknet.org.uk/tag/panda/">Panda Labs</a>. It&#8217;s a pretty interesting phishing attack and although it&#8217;s unable to change the URL in the address bar I believe a lot of people rely on visual cues and may not notice the URL doesn&#8217;t match the page content.</p>
<blockquote><p>The use of Tabnapping, the recently-identified phishing technique, is on the rise, says Panda Labs.</p>
<p>Tabnabbing exploits tabbed browser system in modern web browsers such as Firefox and Internet Explorer, making users believe they are viewing a familiar web page such as Gmail, Hotmail or Facebook. Cybercriminals can then steal the logins and passwords when users enter them on the these hoax pages.</p>
<p>According to Panda&#8217;s latest Quarterly Report on IT Threats, the technique is likely to be employed by more and more cybercriminals and users should close all tabs they are not actively using. </p></blockquote>
<p>I think this could be quite effective, especially for the less technical crown on Facebook and using services like Hotmail and Gmail. It could even extend into targeted localized attacks on online banking systems.</p>
<p>Apparently all browsers are susceptible to this including Chrome, Firefox, Internet Explorer and Opera (on Windows XP anyway). More details in a <a href="http://www.pcadvisor.co.uk/news/index.cfm?NewsID=3224745">PC Advisor</a> article here.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Panda also revealed the number of Trojans being used on the web has surged, and they now account for just under 52 percent of all malware. The number of viruses on the web has also increased. Viruses account for 24 percent of all malware on the web.</p>
<p>The security firm said Taiwan had the most number of infection, with just over 50 percent of all global malware infections happening in the country, while Russia and Turkey came close behind.</p>
<p>Panda also revealed attacks on social networks, fake antivirus software and poisoned links in search engines continued to be popular techniques used by cyber criminals. </p></blockquote>
<p>Using the recent <a href="http://www.darknet.org.uk/2010/05/76-of-users-exposing-their-browsing-histories/">history disclosure bug</a> in most browsers, sneaky attackers could actually scan a users browser to confirm which sites a user has visited then create the tabnapping site according to that &#8211; reinforcing its effectiveness.</p>
<p>Perhaps this is something that can be addressed in Firefox as the person who developed this technique is the Creative Lead for Firefox &#8211; Aza Raskin.</p>
<p>Source: <a href="http://www.networkworld.com/news/2010/070110-tabnapping-on-the.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Tabnapping+Attack+On+The+Increase+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2794+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/07/tabnapping-attack-on-the-increase/&amp;t=Tabnapping+Attack+On+The+Increase" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/07/tabnapping-attack-on-the-increase/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/07/tabnapping-attack-on-the-increase/&amp;title=Tabnapping+Attack+On+The+Increase" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/07/tabnapping-attack-on-the-increase/&amp;title=Tabnapping+Attack+On+The+Increase" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/07/tabnapping-attack-on-the-increase/&amp;title=Tabnapping+Attack+On+The+Increase" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/07/tabnapping-attack-on-the-increase/&amp;title=Tabnapping+Attack+On+The+Increase" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F07%2Ftabnapping-attack-on-the-increase%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/07/tabnapping-attack-on-the-increase/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>zCodec Video Codec is a TROJAN</title>
		<link>http://www.darknet.org.uk/2006/10/zcodec-video-codec-is-a-trojan/</link>
		<comments>http://www.darknet.org.uk/2006/10/zcodec-video-codec-is-a-trojan/#comments</comments>
		<pubDate>Mon, 16 Oct 2006 03:58:46 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[codec-trojan]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[panda]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[rootkits]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[video-codec]]></category>
		<category><![CDATA[virii]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[zcodec]]></category>
		<category><![CDATA[zcodec-trojan]]></category>
		<category><![CDATA[zcodec-virus]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/10/zcodec-video-codec-is-a-trojan/</guid>
		<description><![CDATA[For those that didn&#8217;t see, there is a new all singing all dancing &#8216;light-weight&#8217; Codec in town that is actually a trojan. Indeed it&#8217;s not the first time we&#8217;ve seen this kind of thing. The zCodec software actually messes with your DNS settings. Users looking for the latest and greatest video software may not just [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>For those that didn&#8217;t see, there is a new all singing all dancing &#8216;light-weight&#8217; Codec in town that is actually a trojan.</p>
<p>Indeed it&#8217;s not the first time we&#8217;ve seen this kind of thing.</p>
<p>The zCodec software actually messes with your DNS settings.</p>
<blockquote><p>Users looking for the latest and greatest video software may not just be in danger from media lawyers. Security firm Panda Software last week warned that zCodec, which claims to offer &#8220;up to 40 percent better (video) quality,&#8221; is in fact an adware program that can install Trojans, rootkits and other malicious software.</p>
<p>zCodec is freely available online and, as of Monday afternoon, was easy enough to find, offering downloads from its own website &#8211; zcodec.com. The site uses images from the films Sin City and Pulp Fiction, and claims zCodec will boost audio as well as video quality.</p>
<p>&#8220;zCodec is a multimedia compressor/decompressor which registers into the Windows collection of multimedia drivers and integrates with any application using DirectShow and Microsoft Video for Windows,&#8221; the site states.</p>
<p>Media players use codecs (compressor/decompressors) to compress and play back digital media files, but in the real world, for a codec to make any quality difference, a file must be encoded using that codec.</p></blockquote>
<p>As always do be vigilant when installing software and use a software or desktop firewall to patrol outgoing connections. You can also use something like TCPView to check on outgoing connections a little easier than using plain old netstat.</p>
<blockquote><p>Panda&#8217;s advisory last week revealed that the 100KB file is in fact adware, which &#8220;downloads and runs files, changes the DNS configuration and monitors accesses to several adult websites&#8221;.</p>
<p>zCodec, formally known as Adware/ZCodec or Adware/EMediacodec, affects most versions of Windows and was first detected last week, Panda said.</p>
<p>When run, the program alters the system&#8217;s DNS configuration in order to divert traffic to DNS servers of its choice, a technique sometimes used as part of a phishing scam or to rack up clicks for advertising schemes.</p>
<p>zCodec also accesses a particular IP address to randomly select and download one of a collection of files. The files that could be downloaded include Ruins.MB, a Trojan horse that uses rootkit techniques to conceal itself, Panda said. zCodec could also download an online casino program.</p>
<p>A second file launches every time the user starts Internet Explorer and monitors Web usage. Panda said its software can remove zCodec. </p></blockquote>
<p>Companies are getting really unscrupulous, what is going to come next I do wonder?</p>
<p></p>
<p>Source: <a href="http://www.techworld.com/security/news/index.cfm?newsID=6781">Techworld</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=zCodec+Video+Codec+is+a+TROJAN+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D336+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/10/zcodec-video-codec-is-a-trojan/&amp;t=zCodec+Video+Codec+is+a+TROJAN" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/10/zcodec-video-codec-is-a-trojan/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/10/zcodec-video-codec-is-a-trojan/&amp;title=zCodec+Video+Codec+is+a+TROJAN" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/10/zcodec-video-codec-is-a-trojan/&amp;title=zCodec+Video+Codec+is+a+TROJAN" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/10/zcodec-video-codec-is-a-trojan/&amp;title=zCodec+Video+Codec+is+a+TROJAN" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/10/zcodec-video-codec-is-a-trojan/&amp;title=zCodec+Video+Codec+is+a+TROJAN" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F10%2Fzcodec-video-codec-is-a-trojan%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/10/zcodec-video-codec-is-a-trojan/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

