Archive for the 'Security' Category

Messenger now blocks links to YouTube

Within the last 12 hours Microsoft has started blocking all messages that link to YouTube. Messages are not received and the sender gets the dreaded “The following message could not be delivered to all recipients” error.

In the past, Microsoft has taken measures to stop propagation of viruses by blocking messages containing phrases such as gallery.php, download.php, .scr and .pif. I see no virus here.

YouTube now joins the list of blocked sites including eBuddy and MediaFire. eBuddy was supposedly blocked because of advertising messages when starting a new conversation, and MediaFire blocked to try stop distribution of the leaked Windows Live Messenger 9.0.

I’m completely baffled as to why a block would be placed against YouTube, and eagerly await an explanation. Trying to hamper competition like this just seems ridiculous, it’s not like this would go unnoticed, lots of users are complaining on forums already.

Workaround? Try the domain youtube.info instead, or remove the http://www.

Beware of IceCold ReLoaded / MSN Freezer

Tools claiming to be able to freeze Windows Live ID accounts, preventing access to Hotmail, Messenger, and other MSN/Windows Live services, usually carry a virus or trojan with them. In the cases I’ve seen, targeted accounts do get temporarily frozen, but the person doing the freezing will get unknowingly infected.

One such program gaining a bit of exposure recently (although over 3 years sold) is IceCold ReLoaded, as seen here:

IceCold ReLoaded

Do not trust hack tools like this, while some may do what they say, it can be a cover to do something else behind your back.

Just how easy is phishing?

For the past week or so I have ran some tests to see how well phishing works on regular, non-tech geeks. It appears that a lot of people actually fall for phishing, even when the URL of the phishing site is totally different to that of what the ‘phisher’ trying to mimic. So far roughly 5 of my friend’s mates have fallen for phishing.

For those of you that don’t really know what phishing is, here’s a screen shot of the phishing site: (click for full size)

Phishing site

I just wanted to tell people that looks may be deceiving and not to always trust sites that say that they’ll give you something for free, such as emoticons or display pictures.

Nothing is free…

Symantec makes new bid to secure IM

Security software maker Symantec is hoping to cash in on enterprise customers’ growing headaches around managing and protecting instant messaging applications, including the freely available IM clients so popular among today’s users. While corporate messaging systems made by companies including Microsoft and IBM have long been pitched as the best answer to security issues raised by the proliferation of freely available IM software made by companies such as AOL, Google and Yahoo, Symantec said it is hoping to help address the fact that those applications still find a way onto the desktops of millions of workers every day.

To combat the problem, the company is introducing Symantec IM Manager 8.0, its latest IM and real-time communications management package, which promises to help secure both types of messaging systems. The new product will be made available to customers sometime before the end of this month, the firm said.

In addition to fighting the many types of threats being launched over IM networks, including viruses and phishing attacks, the software maker said the product can also help companies deploy and enforce messaging security policies. The package also promises to aid firms working under federal compliance regulations to keep a closer eye on information being shared via IM.

Read more at eWeek