<feed version="0.3"
      xmlns="http://purl.org/atom/ns#"
      xmlns:dc="http://purl.org/dc/elements/1.1/">
  <author>
    <name>F-Secure Antivirus Research Team</name>
    <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
  </author>
  <copyright mode="escaped"
             type="text/html">Copyright (c) 2007 F-Secure Corporation. All Rights Reserved.</copyright>
  <entry>
    <id>tag:www.f-secure.com,2009-11-20:%2Fweblog%2Farchives%2F00001821.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			F-Secure is organizing the next &amp;lt;b&amp;gt;CARO Technical Workshop&amp;lt;/b&amp;gt;. It will be held in the end of May in Helsinki, Finland. Previous workshops have been in Iceland, The Netherlands and Hungary.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Call for Papers is open. We&amp;apos;re looking for technical presentation relevant to the topic of &amp;lt;b&amp;gt;Big Numbers&amp;lt;/b&amp;gt; in malware field.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;a href=&amp;quot;http://caro2010.org&amp;quot;&amp;gt;&amp;lt;img border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/caro2010web.png&amp;quot; alt=&amp;quot;caro2010 CARO 2010&amp;quot;&amp;gt; &amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;For more information, please see &amp;lt;a href=&amp;quot;http://caro2010.org&amp;quot;&amp;gt;CARO2010.org&amp;lt;/a&amp;gt;. 			 &amp;lt;p&amp;gt;On 19/11/09 At 12:51 PM&amp;lt;/p&amp;gt;</content>
    <issued>2009-11-20T05:40:09Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00001821.html"
          rel="alternate"
          type="text/html" />
    <modified>2009-11-20T05:40:09Z</modified>
    <title mode="escaped"
           type="text/html">Call for Papers: CARO2010 Workshop</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2009-11-20:%2Fweblog%2Farchives%2F00001820.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			Maintaining your computer can be a chore sometimes, especially if you&amp;apos;re the kind of person that&amp;apos;s always on the go. Keeping all the programs on a computer up-to-speed with the latest updates can be a hassle. Periodically &amp;apos;housecleaning&amp;apos; the system (like defragging the hard drive) in order to optimize performance is even less exciting.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;So we&amp;apos;d like to help with that. We recently launched the trial version of a single tool that handles both these tasks - Updater and Tuneup - on the &amp;lt;a href=&amp;quot; http://www.f-secure.com/en_EMEA/downloads/beta-programs/home-office/updater-and-tuneup/index.html&amp;quot;&amp;gt;Technology Preview&amp;lt;/a&amp;gt; page, and we&amp;apos;d like to get some feedback on how well your machine performs after using the tool. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img src=&amp;quot;http://www.f-secure.com/weblog/archives/updater.PNG&amp;quot; alt=&amp;quot;updater&amp;quot; width=&amp;quot;700&amp;quot;/&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img src=&amp;quot;http://www.f-secure.com/export/system/fsgalleries/is2010/FSC_IS2010_Left_200x240.png&amp;quot; align=&amp;quot;left&amp;quot;&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;The name says it all really - the Updater component keeps track of vulnerable applications installed on your machine and notifies you when updates are available; while Tuneup takes care of the housekeeping - defragging the hard drive, checking the registry, etc - so your machine stays optimized for speed.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;And to say thanks for the trouble, we&amp;apos;re offering the following items as prizes to users who give feedback:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;bull;&amp;amp;nbsp;&amp;lt;b&amp;gt;5 boxes of F-Secure Internet Security 2010&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;bull;&amp;amp;nbsp;&amp;lt;b&amp;gt;15 &amp;lt;a href=&amp;quot;http://campaigns.f-secure.com/vip2010&amp;quot;&amp;gt;VIP Cards&amp;lt;/a&amp;gt; for F-Secure Internet Security 2010 and F-Secure Mobile Security&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Giveaway is by lucky draw.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;The trial version is free, and the Technology Preview period closes at end January 2010.&amp;lt;br /&amp;gt; 			 &amp;lt;p&amp;gt;On 19/11/09 At 06:38 AM&amp;lt;/p&amp;gt;</content>
    <issued>2009-11-20T05:40:09Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00001820.html"
          rel="alternate"
          type="text/html" />
    <modified>2009-11-20T05:40:09Z</modified>
    <title mode="escaped"
           type="text/html">Updater and Tuneup Technology Preview</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2009-11-20:%2Fweblog%2Farchives%2F00001819.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			I just got my hands on a new promo item our Marketing department came out with, which looks quite interesting:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/mikado.jpg&amp;quot; alt=&amp;quot;mikado&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;It&amp;apos;s Mikado, an old European stick game. Basically, the idea is to carefully pick up sticks without moving the pile, in order to gain points; player with the most points wins.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;OK, so the game is rather cute, but it is supposed to convey a serious message - that IT security can be as simple as this game. Most people have the impression that IT security is complex, highly technical, frighteningly arcane, and difficult to manage. &amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;To be fair, most people have good reason to think so. Even the language is difficult, like the latest from the Pentagon&amp;apos;s cyber security people - the Global Information Grid Customizable Operational Picture (GIGCOP), which is just one component of their new security system (The Register &amp;lt;a href=&amp;quot;http://www.theregister.co.uk/2009/11/10/raytheon_netops_sa_deal/&amp;quot;&amp;gt;article&amp;lt;/a&amp;gt;).&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;And even if all the &amp;apos;technical&amp;apos; things are under control, sometimes it is possible to slip up on the &amp;quot;easy&amp;quot; stuff, like maintaining proper physical security - as in maybe not letting people use a slipper as a doorstop for a hi-tech server room. Really - that was reported in an &amp;lt;a href=&amp;quot;http://thestar.com.my/news/story.asp?file=/2009/11/6/nation/5051971&amp;amp;amp;sec=nation&amp;quot;&amp;gt;article&amp;lt;/a&amp;gt; from The Star.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;But it doesn&amp;apos;t actually have to be that way. We&amp;apos;d like to have our products (and tools and services) be easy to use, and that&amp;apos;s what we&amp;apos;re increasingly working towards. Which I think is fairly neatly captured by drawing a parallel with Mikado.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt; 			 &amp;lt;p&amp;gt;On 17/11/09 At 09:14 AM&amp;lt;/p&amp;gt;</content>
    <issued>2009-11-20T05:40:09Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00001819.html"
          rel="alternate"
          type="text/html" />
    <modified>2009-11-20T05:40:09Z</modified>
    <title mode="escaped"
           type="text/html">IT Security as Easy as Mikado...</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2009-11-20:%2Fweblog%2Farchives%2F00001817.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			Microsoft just released a patch to address the License Logging Server Heap Overflow Vulnerability (CVE-2009-2523). This vulnerability affects the License Logging Service (LLS), a feature which according to Microsoft is &amp;quot;designed to help customers manage licenses for Microsoft server products that are licensed in the Server Client Access License (CAL) model.&amp;quot;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;More details on LLS at:&amp;lt;br /&amp;gt;&amp;lt;a href=&amp;quot;http://support.microsoft.com/kb/824196&amp;quot;&amp;gt;Description of the License Logging Service in Windows Server operating systems&amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;This vulnerability only affects Microsoft Windows 2000 Server Service Pack 4 and is rated Critical since this service is enabled by default in that OS. It is also accessible via anonymous network connection and exploiting this vulnerability can lead to extensive heap memory corruption which could possibly lead to remote code execution. It no longer affects the newer MS Server systems since this service has already been removed since Windows Server 2008.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;More details of this patch are at these locations:&amp;lt;br /&amp;gt;&amp;lt;a href=&amp;quot;http://www.microsoft.com/technet/security/bulletin/ms09-064.mspx&amp;quot;&amp;gt;Microsoft Security Bulletin MS09-064&amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;a href=&amp;quot;http://blogs.technet.com/srd/archive/2009/11/10/details-on-the-license-logging-service-vulnerability.aspx&amp;quot;&amp;gt;Details on the License Logging Service vulnerability&amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;It&amp;apos;s time to patch those old 2K servers. 			 &amp;lt;p&amp;gt;On 11/11/09 At 12:27 AM&amp;lt;/p&amp;gt;</content>
    <issued>2009-11-20T05:40:09Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00001817.html"
          rel="alternate"
          type="text/html" />
    <modified>2009-11-20T05:40:09Z</modified>
    <title mode="escaped"
           type="text/html">Windows 2K Server Patch Update</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2009-11-20:%2Fweblog%2Farchives%2F00001816.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			Here&amp;apos;s an example of a Youtube video that is used to drive traffic to a &amp;quot;XBOX&amp;quot; phishing site.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/livetp2.png&amp;quot; alt=&amp;quot;live.xbox.co.uk.tp&amp;quot;&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;The actual phishing site looks like this:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/livetp.png&amp;quot; alt=&amp;quot;live.xbox.co.uk.tp&amp;quot;&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;The URL is fairly convincing. Turns out &amp;lt;b&amp;gt;.TP&amp;lt;/b&amp;gt; is the country code for East Timor.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;But why would &amp;lt;b&amp;gt;anybody&amp;lt;/b&amp;gt; phish for accounts of some &amp;lt;b&amp;gt;online game&amp;lt;/b&amp;gt;?&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Because you can sell XBOX Live accounts for real-world cash:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/livetp3.png&amp;quot; alt=&amp;quot;ebay&amp;quot;&amp;gt;&amp;lt;br /&amp;gt; 			 &amp;lt;p&amp;gt;On 10/11/09 At 11:30 AM&amp;lt;/p&amp;gt;</content>
    <issued>2009-11-20T05:40:09Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00001816.html"
          rel="alternate"
          type="text/html" />
    <modified>2009-11-20T05:40:09Z</modified>
    <title mode="escaped"
           type="text/html">Why would anybody phish for XBOX accounts?</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2009-11-20:%2Fweblog%2Farchives%2F00001815.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			So, there are these apparent MySpace phishing e-mails going around (&amp;quot;...&amp;lt;i&amp;gt;please be informed that you are required to update your MySpace account, Please update your MySpace account by clicking here...&amp;lt;/i&amp;gt;&amp;quot;)&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;When you follow the link, you end up to this MySpace look-a-like page, hosted on various .uk domains:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;644&amp;quot; height=&amp;quot;456&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/deaaas1.png&amp;quot; alt=&amp;quot;Zeus&amp;quot;&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Once you log on, the bad guys gain access to your MySpace credentials.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Why do they want them?&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;So they can pose as you on MySpace and send malicious links to your friends &amp;amp;mdash; who will surely follow them, as they know you and trust you&amp;amp;hellip;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;But in this case, this is not the only thing they are after. After logging on, you get this prompt:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;644&amp;quot; height=&amp;quot;460&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/deaaas2.png&amp;quot; alt=&amp;quot;Zeus&amp;quot;&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;b&amp;gt;A New MySpace Update Tool&amp;lt;/b&amp;gt;? Really? As an executable file?&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Hmm&amp;amp;hellip; and of course it&amp;apos;s not. The file (md5: 4c7693219eaa304e38f5f989a8346e51) turns out to be yet another Zeus / Zbot banking trojan variant.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;F-Secure Anti-Virus blocks access to the malicious domains and detects the malware. 			 &amp;lt;p&amp;gt;On 09/11/09 At 02:27 PM&amp;lt;/p&amp;gt;</content>
    <issued>2009-11-20T05:40:09Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00001815.html"
          rel="alternate"
          type="text/html" />
    <modified>2009-11-20T05:40:09Z</modified>
    <title mode="escaped"
           type="text/html">When Phishing Isn&amp;apos;t Phishing</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2009-11-20:%2Fweblog%2Farchives%2F00001814.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			We have located the first iPhone worm, dubbed as &amp;lt;b&amp;gt;Ikee&amp;lt;/b&amp;gt;. It&amp;apos;s currently spreading in the wild, but it&amp;apos;s only able to infect devices that have been &amp;quot;&amp;lt;a href=&amp;quot;http://en.wikipedia.org/wiki/Jailbreak_%28iPhone_OS%29&amp;quot;&amp;gt;jailbroken&amp;lt;/a&amp;gt;&amp;quot; by their owners. Jailbreaking removes iPhone&amp;apos;s protection mechanisms, allowing users to run any software they want.&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;Affected users will find that their iPhone wallpaper has been altered to a picture of Rick Astley (of &amp;lt;a href=&amp;quot;http://en.wikipedia.org/wiki/Rickroll&amp;quot;&amp;gt;Rickroll&amp;lt;/a&amp;gt; fame) and the message &amp;quot;ikee is never going to give you up&amp;quot;.&amp;lt;br /&amp;gt;&amp;lt;center&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;320&amp;quot; height=&amp;quot;480&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/photo.jpg&amp;quot; alt=&amp;quot;ikee iPhone worm&amp;quot;&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;/center&amp;gt;&amp;lt;br /&amp;gt;The worm targets users who have jailbroken their phone but have not changed their default root login password. It will search for vulnerable iPhones by scanning a handful of IP ranges &amp;amp;mdash; most of which are in Australia. At the moment, we have no confirmed reports of Ikee outside of Australia.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;After Ikee infects a phone, it disables the SSH service, preventing reinfection.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;To protect your jailbroken iPhone, change your root password. &amp;lt;a href=&amp;quot;http://www.f-secure.com/weblog/archives/cydia.htm&amp;quot;&amp;gt;Here&amp;apos;s how&amp;lt;/a&amp;gt;.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;The creator of the worm has released full source code of the four existing variants of this worm. This means that there will quickly be more variants, and they might have nastier payload than just changing your wallpaper or might try password cracking to gain access to devices where the default password has been changed.&amp;lt;br /&amp;gt; &amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;582&amp;quot; height=&amp;quot;320&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/ikee1.png&amp;quot; alt=&amp;quot;ikee&amp;quot;&amp;gt; 			 &amp;lt;p&amp;gt;On 08/11/09 At 06:21 PM&amp;lt;/p&amp;gt;</content>
    <issued>2009-11-20T05:40:09Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00001814.html"
          rel="alternate"
          type="text/html" />
    <modified>2009-11-20T05:40:09Z</modified>
    <title mode="escaped"
           type="text/html">First iPhone Worm Found</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2009-11-20:%2Fweblog%2Farchives%2F00001813.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			This is a post from our blog in May 2007:&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;a href=&amp;quot;http://www.f-secure.com/weblog/archives/00001200.html&amp;quot;&amp;gt;&amp;lt;img width=&amp;quot;550&amp;quot; height=&amp;quot;347&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/vanbot.png&amp;quot; alt=&amp;quot;Vanbot&amp;quot;&amp;gt; &amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Yesterday, three people were sentenced for writing the above malware (it&amp;apos;s a variant of the &amp;lt;a href=&amp;quot;http://www.f-secure.com/v-descs/backdoor_w32_vanbot_br.shtml&amp;quot;&amp;gt;Vanbot family&amp;lt;/a&amp;gt;) and other attacks &amp;amp;mdash; including some DDoS action.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;The sentences were: 45 days jail, 40 days jail, and 0 days jail, respectively. The sentences were probationary, so nobody actually went to jail. In addition, some fines were written.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;All the three convicted were underage.  			 &amp;lt;p&amp;gt;On 07/11/09 At 12:06 PM&amp;lt;/p&amp;gt;</content>
    <issued>2009-11-20T05:40:09Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00001813.html"
          rel="alternate"
          type="text/html" />
    <modified>2009-11-20T05:40:09Z</modified>
    <title mode="escaped"
           type="text/html">Sentencing</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2009-11-20:%2Fweblog%2Farchives%2F00001812.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			Our &amp;lt;a href=&amp;quot;http://www.f-secure.com/weblog/archives/00001774.html&amp;quot;&amp;gt;Health Check 2.0 Beta&amp;lt;/a&amp;gt; was released about eight weeks ago.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;637&amp;quot; height=&amp;quot;438&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/F-Secure_HealthCheck2.png&amp;quot; alt=&amp;quot;F-Secure Health Check 2.0 Beta&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Try &amp;lt;a href=&amp;quot;http://www.f-secure.com/en_EMEA/downloads/beta-programs/home-office/healthcheck/index.html&amp;quot;&amp;gt;Health Check&amp;lt;/a&amp;gt;.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;script src=&amp;quot;http://www.f-secure.com/links/health-check.js&amp;quot; type=&amp;quot;text/javascript&amp;quot; &amp;gt;&amp;lt;/script&amp;gt; &amp;lt;noscript&amp;gt;This is an &amp;lt;a href=&amp;quot;http://www.f-secure.com&amp;quot;&amp;gt;Antivirus Software&amp;lt;/a&amp;gt; from F-Secure Corporation&amp;lt;br /&amp;gt;&amp;lt;/noscript&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;hr&amp;gt; 			 &amp;lt;p&amp;gt;On 06/11/09 At 02:32 PM&amp;lt;/p&amp;gt;</content>
    <issued>2009-11-20T05:40:09Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00001812.html"
          rel="alternate"
          type="text/html" />
    <modified>2009-11-20T05:40:09Z</modified>
    <title mode="escaped"
           type="text/html">Try Health Check 2 Beta, complete survery, chance to win an iPod.</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2009-11-20:%2Fweblog%2Farchives%2F00001811.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			One thing that I have always found fascinating about Japan is definitely its rich and unique culture. However, there is just one other thing &amp;amp;mdash; vending machines. You not only find them everywhere, you can buy all sorts of things, including adult movies, from them (except for a security product, but that&amp;apos;s probably just a matter of time).&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Anyway, &amp;lt;a href=http://www.aavar.org/avar2009&amp;gt;AVAR 2009&amp;lt;/a&amp;gt; was held in Kyoto, Japan this time around and the turnout was just amazing, especially when coupled with very interesting presentations on how the threat landscape has been evolving and what every vendor is doing to tackle it.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;498&amp;quot; height=&amp;quot;360&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/AVAR2009_bird.jpg&amp;quot; alt=&amp;quot;AVAR2009, swan&amp;quot; /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;For the first time, there were two concurrent sessions running. This year&amp;apos;s keynote was by &amp;lt;b&amp;gt;Jimmy Kuo&amp;lt;/b&amp;gt; (Microsoft), and he presented the key findings from &amp;lt;a href=http://www.microsoft.com/sir&amp;gt;Microsoft&amp;apos;s Security Intelligence Report v7&amp;lt;/a&amp;gt;.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Interestingly, this time around there were several presentations on cloud-based security, one of which was by &amp;lt;b&amp;gt;Dr. Igor Muttik&amp;lt;/b&amp;gt; (McAfee). In it, he mentioned the benefits of having antivirus technology in-the-cloud, as well as concerns surrounding privacy issues. One interesting fact he shared was McAfee verifies the robustness of their servers every Friday by DDoS-ing themselves. Coincidentally, that&amp;apos;s when McAfee products are scheduled by default to run a full scan.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Also, &amp;lt;b&amp;gt;Stefan Tanase&amp;lt;/b&amp;gt; (Kaspersky) gave an entertaining presentation about how there has been a exponential growth in attacks on social media on Facebook and Twitter. &amp;lt;b&amp;gt;Tony Lee&amp;lt;/b&amp;gt; (Microsoft) too highlighted the same fact, as Microsoft found that the attacks on social media are dominating the threat landscape.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Signing off,&amp;lt;br /&amp;gt;Fei&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;595&amp;quot; height=&amp;quot;461&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/AVAR2009_performance.jpg&amp;quot; alt=&amp;quot;AVAR2009, performance&amp;quot; /&amp;gt; 			 &amp;lt;p&amp;gt;On 06/11/09 At 06:21 AM&amp;lt;/p&amp;gt;</content>
    <issued>2009-11-20T05:40:09Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00001811.html"
          rel="alternate"
          type="text/html" />
    <modified>2009-11-20T05:40:09Z</modified>
    <title mode="escaped"
           type="text/html">Greetings from AVAR 2009!</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2009-11-20:%2Fweblog%2Farchives%2F00001810.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			It seems like most people who have gone to watch the Michael Jackson &amp;lt;a href=http://www.thisisit-movie.com&amp;gt;This Is It&amp;lt;/a&amp;gt; movie have told me that it is really worth watching.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;However, we are &amp;lt;b&amp;gt;not&amp;lt;/b&amp;gt; too sure if Michael Jackson&amp;apos;s Official Website at &amp;lt;b&amp;gt;www.michaeljackson.com&amp;lt;/b&amp;gt; is actually worth visiting now.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;661&amp;quot; height=&amp;quot;537&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/mj_searchresults.jpg&amp;quot; alt=&amp;quot;MJ search results&amp;quot;/&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Well, it turned up on our systems, which indicate that some of the child pages have been compromised with malicious scripts.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;698&amp;quot; height=&amp;quot;546&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/mjsitej.jpg&amp;quot; alt=&amp;quot;MJ site&amp;quot;/&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;At the time of analysis, the malicious scripts were not leading users to malware (yet) &amp;amp;mdash; but they will probably remain there until someone cleans it up and fixes the vulnerable code as well.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;We will rate the site &amp;lt;b&amp;gt;SAFE&amp;lt;/b&amp;gt; in our &amp;lt;a href=&amp;quot;http://browsingprotection.f-secure.com&amp;quot;&amp;gt;Browsing Protection&amp;lt;/a&amp;gt; again once the site is cleaned up.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;a href=&amp;quot;http://browsingprotection.f-secure.com/swp/result?x=CDqZ1MMd*BD9zTUA8QGshViAtnfnpllO0Zx7CaRfWOX3Hkh91jwVEy07N2WdDS9o3fri8t-JEvFmWg6V-hWn-Q&amp;quot;&amp;gt;&amp;lt;img width=&amp;quot;750&amp;quot; height=&amp;quot;375&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/BrowsingProtection_MichaelJackson.png&amp;quot; alt=&amp;quot;Browsing Protection, michaeljackson.com&amp;quot; /&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Signing off,&amp;lt;br /&amp;gt;Fei&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;hr&amp;gt; 			 &amp;lt;p&amp;gt;On 05/11/09 At 03:59 PM&amp;lt;/p&amp;gt;</content>
    <issued>2009-11-20T05:40:09Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00001810.html"
          rel="alternate"
          type="text/html" />
    <modified>2009-11-20T05:40:09Z</modified>
    <title mode="escaped"
           type="text/html">This Is It!</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2009-11-20:%2Fweblog%2Farchives%2F00001809.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			Our blog has been nominated in the 2009 ComputerWeekly.com IT blog awards.&amp;lt;a href=&amp;quot;http://www.computerweekly.com/Articles/2009/11/03/238190/vote-in-the-computer-weekly-it-blog-awards-2009.htm&amp;quot;&amp;gt;&amp;lt;img align=&amp;quot;right&amp;quot; hspace=&amp;quot;11&amp;quot; width=&amp;quot;250&amp;quot; height=&amp;quot;197&amp;quot; border=&amp;quot;0&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/Computer_Weekly_IT_Blog_Awards_09.gif&amp;quot; alt=&amp;quot;ComputerWeekly.com, IT Blog Awards 09&amp;quot; /&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;We&amp;apos;re in the &amp;lt;b&amp;gt;IT Security&amp;lt;/b&amp;gt; category.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;If you like us, you can vote at &amp;lt;a href=&amp;quot;http://www.computerweekly.com/Articles/2009/11/03/238190/vote-in-the-computer-weekly-it-blog-awards-2009.htm&amp;quot;&amp;gt;ComputerWeekly.com&amp;lt;/a&amp;gt;.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Cheers!&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;P.S. What&amp;apos;s someone got to do to get nominated for the Twitter category, &amp;lt;a href=&amp;quot;http://blogs.zdnet.com/projectfailures/?p=6327&amp;quot;&amp;gt;get banned&amp;lt;/a&amp;gt; or something?&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;amp;nbsp; 			 &amp;lt;p&amp;gt;On 05/11/09 At 10:31 AM&amp;lt;/p&amp;gt;</content>
    <issued>2009-11-20T05:40:09Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00001809.html"
          rel="alternate"
          type="text/html" />
    <modified>2009-11-20T05:40:09Z</modified>
    <title mode="escaped"
           type="text/html">Vote 4 Us</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2009-11-20:%2Fweblog%2Farchives%2F00001808.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			The Swedish Signals Intelligence agency (Försvarets Radioanstalt FRA) is currently under a large-scale DDoS attack.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;At the moment &amp;lt;a href=&amp;quot;http://www.fra.se&amp;quot;&amp;gt;www.fra.se&amp;lt;/a&amp;gt; is inaccessible.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;img width=&amp;quot;417&amp;quot; height=&amp;quot;230&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/fra1.png&amp;quot; alt=&amp;quot;Försvarets radioanstalt&amp;quot;&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;FRA was in the news recently, as Sweden passed a law giving them legal permission to tap Internet traffic passing through Swedish national borders. For example, the &amp;lt;b&amp;gt;majority of Russian international Internet traffic passes through Sweden&amp;lt;/b&amp;gt;.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;The monitoring effectively started last month.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;a href=&amp;quot;http://downforeveryoneorjustme.com/www.fra.se&amp;quot;&amp;gt;&amp;lt;img width=&amp;quot;634&amp;quot; height=&amp;quot;188&amp;quot; border=&amp;quot;1&amp;quot; src=&amp;quot;http://www.f-secure.com/weblog/archives/fra2.png&amp;quot; alt=&amp;quot; Försvarets radioanstalt&amp;quot;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;We have no information on who&amp;apos;s behind the attacks.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Downtime stats are available &amp;lt;a href=&amp;quot;http://uptime.pingdom.com/site/month_summary/site_name/www.fra.se&amp;quot;&amp;gt;here&amp;lt;/a&amp;gt;.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;hr&amp;gt; 			 &amp;lt;p&amp;gt;On 04/11/09 At 10:02 AM&amp;lt;/p&amp;gt;</content>
    <issued>2009-11-20T05:40:09Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00001808.html"
          rel="alternate"
          type="text/html" />
    <modified>2009-11-20T05:40:09Z</modified>
    <title mode="escaped"
           type="text/html">DDoS on www.fra.se</title>
  </entry>
  <entry>
    <id>tag:www.f-secure.com,2009-11-20:%2Fweblog%2Farchives%2F00001807.html</id>
    <author>
      <name>F-Secure Antivirus Research Team</name>
      <email>weblog\@PLEASE-REMOVE-THIS.f-secure.com</email>
    </author>
    <content mode="escaped"
             type="text/html"> 			 			Microsoft has just released an update for their MS09-054 patch.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Note &amp;amp;mdash; It is critical &amp;lt;b&amp;gt;not&amp;lt;/b&amp;gt; to install this update if the system has not installed the previous MS09-054 patch, as the updated one could break Internet Explorer. Some customers were reported to have browsing-related errors after installing said patch.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;A fix is available via Windows Update, Microsoft Update and Automatic Updates.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;More details at: &amp;lt;a href=&amp;quot;http://support.microsoft.com/kb/976749&amp;quot;&amp;gt;http://support.microsoft.com/kb/976749&amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Response Team post by &amp;amp;mdash; Christine 			 &amp;lt;p&amp;gt;On 04/11/09 At 12:29 AM&amp;lt;/p&amp;gt;</content>
    <issued>2009-11-20T05:40:09Z</issued>
    <link href="http://www.f-secure.com/weblog/archives/00001807.html"
          rel="alternate"
          type="text/html" />
    <modified>2009-11-20T05:40:09Z</modified>
    <title mode="escaped"
           type="text/html">MS Post-Patch Update</title>
  </entry>
  <generator url="http://search.cpan.org/dist/XML-Atom-SimpleFeed"
             version="0.7">XML::Atom::SimpleFeed</generator>
  <link href="http://www.f-secure.com/weblog"
        rel="alternate"
        type="text/html" />
  <modified>2009-11-20T05:40:09Z</modified>
  <tagline mode="escaped"
           type="text/html">Weblog of F-Secure Antivirus Research Team</tagline>
  <title mode="escaped"
         type="text/html">F-Secure Antivirus Research Weblog</title>
</feed>
