4/2/11

LizaMoon Virus hits alot of websites

'LizaMoon' Mass SQL Injection Attack Escalates Out of Control - eWeek.com

A mass SQL
injection attack that initially compromised 28,000 Websites has spiraled out of
control. At the last count, more than a million sites have been compromised,
with no end in sight.
Security firm
Websense has been tracking the "LizaMoon" attack since it started March 29. The
company's malware researchers dubbed the attack LizaMoon after the first domain
that victims were redirected to. At the redirected site, users saw a warning
dialog that they had been infected with malware and a link to download a fake
antivirus.
The users are
shown a number of threats supposedly on their computer, but the fake AV,
Windows Stability Center, won't remove them until the user pays up, in a "very
traditional rogue AV scam," wrote Patrik Runald, the Websense researcher who
has been following the attack over the past few days.
The list of
redirect URLs has ballooned in the days since, as Websense updated its list
March 31 with 20 additional sites, making this one of the biggest mass-injection
attacks ever.
More than
500,000 URLs have been injected with LizaMoon, according to Runald. If all the
domains used in the attack are considered, eWEEK found about 2.9 million
results on Google Search that have been compromised.
"Google Search
results aren't always great indicators of how prevalent or widespread an attack
is as it counts each unique URL, not domain or site," Runald said. It is safe
to consider hundreds of thousands of domains have been hit, he said.
Websense
researchers are still trying to figure out how the SQL injection attack is
happening. Somehow, legitimate Websites have been compromised in a way that one
line of code has been embedded on the site. That code is a simple redirect, and
executes when the user loads the page. The bulk of the action happens on the
redirected page, where a script containing Javascript code kicks off the fake
AV scam.
Commenters
asked Websense why researchers were so convinced it was a SQL injection on
multiple Websites and not a mass cross-site-scripting attack. The researchers
said they'd been contacted by people who have seen the code in their Microsoft
SQL Server 2003 and 2005 databases. The vulnerabilities weren't within the
database software, but "most likely in the Web systems used by these sites,
such as outdated CMS and blog systems," Runald said.
Considering
the large number of sites infected, users all around the world are affected,
with victims in the United Kingdom, Kuwait, India, Australia, Turkey, Brazil,
Israel, Mexico, Taiwan and Chile, among others, according to figures from
Websense Threatseeker Network. The bulk of the victims, at 47 percent, appear
to be from the United States.
The domains
used in this attack, including the redirect URLs and the server where the
malware is hosted, are all associated with one of four IP addresses, according
to Dancho Danchev, an independent security expert.
While the 20 or so domains being used as the redirect URL rotate between two IP
addresses, Danchev has identified more than 120 India-based or Cocos Island-based
domains all pointing to one malware host server, and 50 India-based domains
going to another.
The domains
have all been registered using automatically registered accounts at Gmail,
Danchev said. The first domain on the list was registered as far back as
October 2010, and new domains have been added since LizaMoon exploded,
according to Runald.
First, the
good news: Users are hit with the Windows Stability Center scam only once, so
visiting the site repeatedly doesn't repeat the attack.
The bad news:
Not many antivirus programs seem to be able to detect the Windows Stability
Center. VirusTotal is a service that checks malware samples against 43 major
antivirus products to see which products can detect it. As of April 1, only 17 out of the 43 tested block Windows Stability
Scanner. At least, security companies are moving on this threat: It was only 13 out of 43 March 31.

3/29/11

BuyWithMe - 54% off at AMC Theatres®

BuyWithMe - 54% off at AMC Theatres®
Here's the Deal

Whether you prefer predictably sweet romances (No Strings Attached), edge-of-your-seat thrillers (Black Swan), or heart-pounding action movies (Drive Angry), there’s no better place to get your cinematic fix than at AMC Theatres®, the company that opened the first multiplex theatre and introduced the glorious cup holder armrest. And now you can see your fave flicks for less: $24 gets you four AMC Silver Experience™ tickets to any AMC® theatre location (up to $52 value).

Read more...
Deal Terms

Limit 1 voucher per person.
Limited quantity available, so don't delay in purchasing.
All sales are final.
Your tickets will be mailed to the address you provide at BWM checkout within 7-10 business days; all shipping and processing fees are included.
Tickets are eligible for any AMC®, but shipping is only available to RI, NH, NJ, NY, CT, MA, DC, VA, TX, WA, CA, AZ, IL, WI, PA, MD, GA.
Once you receive your tickets in the mail, they can be redeemed for admission at any AMC Theatres® location; not valid for online or kiosk purchasing, or reserved seating.
Good at any AMC®, AMC Showplace, Loews®, Cineplex Odeon, Magic Johnson, and Star theatres, excluding Canadian theatres.
Not valid for special engagements.
Valid only for movies that are two weeks out from their original release date.
Extra charges may apply for 3D, IMAX®, ETX, alternative content, and premium services and locations.
Shows and seating subject to availability.
No age restriction to redeem, but movies are subject to MPAA age restrictions, based on MPAA rating.
Movie ticket photocopies are not allowed.
Movie tickets have no cash value and are not valid for cash back.
Cannot be combined with other offers or promotions.
AMC Theatres® movie tickets do not expire.

3/28/11

Best Options for Convenience-Store Food - Men's Fitness

Best Options for Convenience-Store Food - Men's Fitness

Best Options for Convenience-Store Food
You can still eat smart on the go—even when your options are limited
by Brian Dalek

Any road trip leads to the unavoidable stop at the QuikTrip, 7-Eleven, or one of thousands of other convenience stores across America. If you’re not watching what you eat, that can spell trouble. Lauren Antonucci, R.D., a nutritionist and the owner/director of Nutrition Energy in New York City, suggests looking for something with protein or fiber to keep you awake, plus a drink to keep you hydrated behind the wheel. If the store doesn’t have any of those options, hit the road immediately and look for a smarter choice next time you pull over.

Breakfast Bests
No time to pack a breakfast? Antonucci suggests a protein-packed Greek yogurt like Chobani. If you need something heartier, some stores have eggwhite wrap sandwiches. “Just try to avoid the ones with sausage, cheese, and bacon,” she says.

Hydrate
Skip the fountain cappuccino, even if you think the jolt of caffeine might help you stay awake. Anything low calorie, like Propel or sparkling water, is the smarter choice. Those liquids will help keep your muscles and brain operating at their peak. “Since most of us aren’t race car drivers, we don’t need to worry about replacing calories,” Antonucci says.

Search for Fruit
Sure, it’s not Whole Foods, but sometimes you can find an apple or banana by the counter. “As long as it’s edible,” she says, “you can’t pick a better option.”

Snack Smart
Craving something sweet? Ditch the candy bar and opt for an energy bar with at least 10 grams of protein, instead. (We like the Carb Conscious bars from Supreme Protein.) Feeling more savory? Avoid crackers and go for canned nuts or a bag of low-sodium jerky instead.

Never Supersize
When you’re stuck in a car with an entire bag of chips or candy, no good can come of it, says Antonucci. In fact, studies show the longer you’re near junk food, the more likely you are to stick your hand into it. If you have to buy it, get a single-serving pack.