YOUR IT - Technology for you

No. 1 Story

Telstra adds one million mobile services, but Sensis plummets

Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.

read more

iPhone bait in malware attack

Your IT - Mobility

Spam messages claiming the recipient has won an iPhone are being used to attract victims to a web site that tries to install a rootkit and spambot malware by exploiting ten ActiveX vulnerabilities.

According to Secure Computing, the original message states "Congratulations, you have won a new iPhone from our store!"

A variety of tricks have been used to make life harder for security  researchers, including tracking visits and then redirecting returning visitors to a clean page.

"Because of the popularity of the iPhone brand this is the first in what’s bound to be a series of scams involving the iPhone," said Paul Henry, vice president of technology evangelism at Secure Computing.

"This threat is particularly insidious in that scripts within the HTML code returned to the user contain exploit code for multiple vulnerabilities to improve the malicious hacker's chances of gaining the necessary access to install the rootkit/spam bot malware."

Other security companies have detected various iPhone-related spams. On June 29, Sophos reported a campaign offering $600 towards an iPhone in exchange for completing a survey. "I wonder how long it will take before we see e-mail luring people to a malicious website by offering free iPhones?" pondered 'Dimitry' of SophosLabs Canada.

The answer turned out to be "Not very."

Loading comments ...

- sponsored feature -

The Death of Traditional BI: What’s Next?

How to Make Business Discovery Work for Your Business IP PABX BUYING GUIDE

Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more