Sponsored White Papers, Webcasts, and Downloads
- ZDNet Author Biography
Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and E-crime incident response. Dancho is also involved in business development, marketing research and competitive intelligence as an independent contractor. He's been an active security blogger since 2007, and maintains...- more about Dancho Danchev »
ZDNet Resources
- Vendor claims Acrobat 9 passwords easier to crack than ever
- Password recovery software vendor ElcomSoft claims that the password verification mechanism in the new Adobe Acrobat 9 is weaker than the one used in the previous version of Adobe's product, thereby allowing them to improve the brute forcing speed a hundred times faster. The company's claim comes right after Adobe's...
- Tags: Adobe Systems Inc., Password, Passphrase, Adobe Acrobat, ElcomSoft, Dancho Danchev
- Blog posts 2008-12-02
- IT expert executed in Iran
- Following Pakistan's recently introduced "Prevention of Electronic Crimes Ordinance 2008" according to which potential cyberterrorists would face the death penalty, a neighboring country, Iran, has recently executed an IT expert who confessed of being an Israeli spy for at least three years. After being recruited by Mossad during a business...
- Tags: Information Technology, Equipment, Iran, Government, Productivity, Real Estate, E-mail, Business Operations, Online Communications, Dancho Danchev
- Blog posts 2008-12-01
- AlertPay hit by a large scale DDoS attack
- Timing is everything. Millions of account holders at privately owned online payment gateway AlertPay.com weren't able to do business through the service yesterday, due to the fact that AlertPay was under a large scale DDoS attack, according to a notice left by a company representative. Seven hours of downtime right...
- Tags: Distributed Denial Of Service, AlertPay, Security, Dancho Danchev
- Blog posts 2008-12-01
- Microsoft's Live launches malware detection service for webmasters
- Playing catch-up with Google's Safe Browsing diagnostic, Google's warnings for potentially hackable sites, and Yahoo's SearchScan introduced through their partnership with McAfee, Microsoft's Live Search has updated their Webmaster tools to offer detection for embedded malware. Moreover, as a late entrant they simply had to differentiate, and they did it...
- Tags: Webmaster, Malware, Microsoft Corp., Site, Spyware, Adware & Malware, Cyberthreats, Viruses And Worms, Security, Dancho Danchev
- Blog posts 2008-11-26
- New worm exploiting MS08-067 flaw spotted in the wild
- Microsoft's Security Response Center and McAfee are warning on increased network scanning activity during the last couple of days courtesy of the very latest W32/Conficker.worm exploiting the already patched MS08-067 vulnerability. What's particularly interesting in the latest wave of copycat worms is that W32/Conficker.worm is patching the infected host in...
- Tags: Flaw, Malware, Worm, Tool, Cyberthreats, Spyware, Adware & Malware, Viruses And Worms, Productivity, Security, Dancho Danchev
- Blog posts 2008-11-26
- Google: no evidence of a Gmail vulnerability
- Following the speculations on the resurrection of what's thought to be an already fixed Gmail flaw which could assist in domain name hijackings, yesterday Google commented that their investigation indicated that the recent domain hijacks should be attributed to a phishing campaign, rather than to a Gmail flaw. The phishers...
- Tags: Google Inc., Google Gmail, Attacker, Vulnerability, Phishing, Cyberthreats, Spam, E-mail Providers, Security, Viruses And Worms, Spam And Phishing, Internet, Dancho Danchev
- Blog posts 2008-11-26
- Cybercriminals release Christmas themed web malware exploitation kit
- "Committing cybercrime around the Christmas tree" has always been a tradition for malicious attackers introducing new ways to scam the millions of online shoppers during the holidays. This Christmas isn't going to be an exception, but what has changed compared last couple of years is the tone of the Xmas...
- Tags: Web, Infection, Malware, Exploit, Christmas, Web Malware Exploitation Kit, Exploitation Kit, Security, Dancho Danchev
- Blog posts 2008-11-24
- Fake Windows XP activation trojan goes 2.0
- Known as Kardphisher and "in the wild" since April, 2007, last week the malware author of this trojan horse mimicking the Windows XP activation interface while collecting the credit card details the end user has submitted, has made significant changes to visual interface and usability of the trojan, consequently improving...
- Tags: Microsoft Windows XP, Credit Card, Trojan Horse, Malware, Social Engineering, Microsoft Windows, Spyware, Adware & Malware, Spyware, Sales Channel, Viruses And Worms, Financial Services, Security, Sales, Dancho Danchev
- Blog posts 2008-11-18
- Commercial vendor of spyware under legal fire
- Just like every decent marketer out there, vendors of commercial malware tools are very good at positioning their tools. However, their pitches often contradict with themselves in a way that what's promoted as a Remote Administration Tool, has in fact built-in antivirus software evading capabilities, rootkit functionality and tutorials on...
- Tags: Malware, FTC, Spyware, Adware & Malware, Cyberthreats, E-mail, Viruses And Worms, Spyware, Security, Online Communications, Dancho Danchev
- Blog posts 2008-11-18
- Anti fraud site hit by a DDoS attack
- The popular British anti-fraud site Bobbear.co.uk is currently under a DDoS attack distributed denial of service attack , originally launched last Wednesday, and is continuing to hit the site with 3/4 million hits daily from hundreds of thousands of malware infected hosts mostly based in Asia and Eastern Europe, according...
- Tags: Distributed Denial Of Service, Attack, Botnet, Security, Dancho Danchev
- Blog posts 2008-11-17
- $10k hacking contest announced
- Israeli software developer Gizmox is challenging hackers to try hacking into the company's Visual WebGui Platform, by offering a $10,000 incentive to those who manage to achieve the objectives of their contest launched at the beginning of the month. What's particularly interesting about the contest is the fact that the...
- Tags: Contest, Identity, Gizmox, Hacking, Semantic Web, Security, Internet, Dancho Danchev
- Blog posts 2008-11-12
- Google fixes critical XSS vulnerability
- All your accounting data are not belong to us. Hours after a proof of concept example detailing a XSS vulnetability at Google's account login page was posted at the XSS Project's clearing house, the company quickly took notice and fixed it. "Security researcher "Xylitol" is...
- Tags: Google Inc., Vulnerability, XSS, XSSed, Security, Dancho Danchev
- Blog posts 2008-11-12
- BBC hit by a DDoS attack
- The British Broadcasting Corporation (bbc.co.uk) was hit by a DDoS attack on Thursday, according to a statement sent to the Inquirer : "In a statement to the INQ, the BBC said the attack originated in a number of different countries but didn't specify which. When the Beeb's techies blocked...
- Tags: British Broadcasting Corp., Distributed Denial Of Service, Attack, Security, Dancho Danchev
- Blog posts 2008-11-11
- AVG and Rising signatures update detects Windows files as malware
- Yesterday, a signatures update pushed by AVG falsely labeled a critical Windows file as a banker malware, prompting the company to quickly fix the issue and issue a workaround, following end users complaints at its support forums. AVG's false positive causing downtime for Windows users is happening...
- Tags: Malware, Virus, AVG, Microsoft Windows, Cyberthreats, Spyware, Adware & Malware, Viruses And Worms, Operating Systems, Security, Software, Dancho Danchev
- Blog posts 2008-11-11
- Cyber terrorists to face death penalty in Pakistan
- According to a recently signed "Prevention of Electronic Crimes Ordinance 2008" in Pakistan, any person who commits cyberterrorism causing the death of other people will face death penalty or life imprisonment : "Whoever commits the offence of cyber terrorism and causes death of any person shall be punishable with...
- Tags: Dancho Danchev
- Blog posts 2008-11-10
- Koobface Facebook worm still spreading
- Originally spreading since July, the Koobface worm remains active according to a recent security alert issued by Websense : "The email reveals that infected user accounts are being used to post messages to Facebook friends lists. The content was an enticing message with a link that used a Facebook...
- Tags: Social Networking, Facebook, Malware, Worm, Spyware, Adware & Malware, Cyberthreats, Viruses And Worms, Security, Dancho Danchev
- Blog posts 2008-11-10
- Fake WordPress site distributing backdoored release
- Can you find five differences between these two sites? Wordpresz.org may indeed look like WordPress.org, but the 2.6.4 release it's distributing is on purposely backdoored in order to steal the content of cookies from those who have installed it, potentially leading to to hijacking of their WordPress blogging platforms for...
- Tags: Wordpress, Dancho Danchev
- Blog posts 2008-11-06
- Google and T-Mobile push patch for Android security flaw
- During the weekend, Google and T-Mobile pushed a patch fixing last week's disclosed security flaw affecting Google's Android. The flaw and the PoC were communicated to Google on October 20th, with the vulnerability itself made possible due to Android's use of outdated third-party software packages. ...
- Tags: Google Inc., Security Flaw, Google Android, T-Mobile, Security, Viruses And Worms, Dancho Danchev
- Blog posts 2008-11-04
- Black market for zero day vulnerabilities still thriving
- One would assume that popular sources for zero day vulnerabilities+Poc's such as Full-Disclosure, Bugtraq or Milw0rm are the primary sources for obtaining responsibly or irresponsibly released flaws. They'd be wrong. The black market for zero day vulnerabilities and the concept of over-the-counter OTC trade of zero day flaws, has been...
- Tags: Web, Vulnerability, Web Application, SQL Injection, Exploit, Day Vulnerability, E-shop, Security, Dancho Danchev
- Blog posts 2008-11-02
- Spammers targeting Bebo, generate thousands of bogus accounts
- The concept of building a fraudulent ecosystem by abusing legitimate services only is nothing new, and as we've already seen numerous times throughout the year, malicious attackers are actively embracing it. Bebo, the popular social networking site is currently under attack from spammers that are automatically registering thousands of bogus...
- Tags: Bebo, Spammer, Social Networking Site, Social Networking, Spam, Online Communications, Marketing, Advertising & Promotion, Security, Spam And Phishing, Dancho Danchev
- Blog posts 2008-10-31
White Papers and Webcasts