<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; Various</title>
	<atom:link href="http://blog.mxlab.eu/category/various/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 28 Jul 2010 23:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; Various</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Emails offering PDF Reader 2010 lead to unsecure payment site</title>
		<link>http://blog.mxlab.eu/2010/07/27/emails-offering-pdf-reader-2010-lead-to-unsecure-payment-site/</link>
		<comments>http://blog.mxlab.eu/2010/07/27/emails-offering-pdf-reader-2010-lead-to-unsecure-payment-site/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 23:54:56 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Email security]]></category>
		<category><![CDATA[Various]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[Adobe PDF]]></category>
		<category><![CDATA[PDF Reader 2010]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=965</guid>
		<description><![CDATA[MX Lab intercepted some emails with the subject &#8220;Upgrade New PDF Acrobat Reader/Writer For Windows And Mac&#8221; from the email address &#8220;Adobe &#60;newsletter@adobe-upgrade-2010.com&#62;&#8221;. Notice the use of Adobe in the email. In the email, an offer is made to download the new PDF Reader 2010 for Windows and Mac. This is the body of the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=965&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted some emails with the subject &#8220;Upgrade New PDF Acrobat Reader/Writer For Windows And Mac&#8221; from the email address &#8220;Adobe &lt;newsletter@adobe-upgrade-2010.com&gt;&#8221;. Notice the use of Adobe in the email. In the email, an offer is made to download the new PDF Reader 2010 for Windows and Mac.</p>
<p>This is the body of the email:</p>
<blockquote><p>PDF Reader 2010 &#8211; New Version for Windows and Mac<br />
The latest PDF Reader: Open, Edit  Create PDF Files</p>
<p>What&#8217;s new in this version :</p>
<p>-Open, edit and view all PDF files.<br />
-Enhanced performance with faster loading and zooming.<br />
-Collect your data and combine it into a high quality document.</p>
<p>hxxp://www.adobe-upgrade-2010.com/</p>
<p>Thank you for choosing us, the worldwide leader in PDF Reader<br />
Solutions.</p>
<p>Best Regards,</p>
<p>Tommy Johnson<br />
PDF Reader 2010</p></blockquote>
<p>When visiting this web site, it all makes perfect sense, it&#8217;s a company that offers a PDF Reader/Writer that can do more than the Adobe Reader on its own. But when you go further you will notice some issues with the web site and the offer.</p>
<p>When following the URL in the email, you get redirected to hxxp://2010-pdf-pro.com/.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_1.gif" alt="" width="450" height="246" /></p>
<p>It seems like you can download the software for free, there is no pricing information on the web site, so you go forward with the Download button.</p>
<p>The Download button leads to the page hxxp://2010-pdf-pro.com/join.asp but you will get a redirect again to the domain hxxp://secure-signup.ru/. Do not get fooled by the domain name secure-signup.ru. The browser session is not secured at all while most genuine web shops already have a secured session through https:// when you sign up for a service or software.</p>
<p>The site asks you to fill in your email address twice for confirmation, your first and last name and country.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_2.gif" alt="" width="450" height="338" /></p>
<p>When continuing to step 2 you will get the membership choices and here we have it: the PDF Reader 2010 comes not for free. You will need to choose from some 1, 2 or 3 year online access and support.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_3.gif" alt="" width="450" height="340" /></p>
<p>When you have made your choice you can continue the process by validating your credit card. Notice that you haven&#8217;t filled in any details regarding invoicing. The web forms did not ask for your address, zip or postcode to create an invoice or proof of purchase.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_4.gif" alt="" width="450" height="421" /></p>
<p>On the web form to validate your credit card, you still have no secure https:// connection. This means that your details are send over the internet without any encryption at all and can be read by anyone. What&#8217;s worse, your credit card details are now in the hands of a person or group with bad intentions.</p>
<p>Update 29 July 2010:</p>
<p>On the 27th we did fill in a dummy email address to test the webforms on the web sites above and today we received a mailing with the following content:</p>
<blockquote><p>Dear valued customers,</p>
<p>We are pleased to announce the newest version of PDF Reader 2010 which will enable you to view, create, edit and print PDF documents. The PDF format as a global exchange document format is created by Adobe and is the most efficient way to exchange information.</p>
<p>Simply visit the link below and enter your PDF reader code:</p>
<p>PDF Reader Code: 5013<br />
Go here to receive the latest 2010 version</p>
<p>Thank you for choosing us, the worldwide leader in PDF Reader solutions.</p>
<p>Mike Robertson<br />
PDF Reader Support</p>
<p>Copyright PDF Reader 2010 &#8211; All rights reserved</p>
<p>You are currently subscribed to sm-pdf as geert@betransport.com<br />
Safely unsubscribe from sm-pdf at any time.</p>
<p>Media Internet Consultants &#8211; Edif. Neptuno, Planta Baja, Ave. Ricardo J. Alfaro, Tumba Muerto, n/a, Panama</p></blockquote>
<p>Behind &#8220;Go here to receive the latest 2010 version&#8221; is the link hxxp://list.directmediafive.com/t/2549518/64766653/4988/0/ that will redirect you to hxxp://new-pdf-reader.com/1/promo/index.asp?aff=11677&amp;camp=pdf_x1</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_5.gif" alt="" width="450" height="346" /></p>
<p>The web form is now somewhat different and allows you to fill in your PDF Reader code 5013. Based on this you get a certain discount. When we wanted to leave the page an go back one page, we got a pop up windows with an 50% reduction in the price, offered for a 24 hour period with a count down counter on the site.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_7.gif" alt="" width="450" height="394" /></p>
<p>When going further through the process, we did got an https:// connection for sending the credit card details. But based on the facts above and mentioned in this article, I would not recommend anyone doing this. There are too many variables that gives us the idea that buying on this site will result in troubles.</p>
<p>The mailing also contains an unsubscribe URL using hxxp://list.directmediafive.com/. It gives you the idea that this is a genuine company. But what is quite interesting, is that when visiting the domain http://www.directmediafive.com/ directly, you will get a web page of a parked domain.</p>
<p>We have used the unsubscribe URL included in the mailing and will now see what happens during the next few days.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/965/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/965/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/965/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/965/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/965/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/965/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/965/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/965/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/965/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/965/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=965&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/07/27/emails-offering-pdf-reader-2010-lead-to-unsecure-payment-site/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_1.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_2.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_3.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_4.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_5.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_7.gif" medium="image" />
	</item>
		<item>
		<title>Directory scam: Registration of the World Business Directory 2010/2011</title>
		<link>http://blog.mxlab.eu/2010/03/09/registration-of-the-world-business-directory-20102011/</link>
		<comments>http://blog.mxlab.eu/2010/03/09/registration-of-the-world-business-directory-20102011/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 10:05:14 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Various]]></category>
		<category><![CDATA[directory scam]]></category>
		<category><![CDATA[EU Business Services Ltd]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[World Business Directory]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=778</guid>
		<description><![CDATA[MX Lab reported in 2009 about the misleading marketing trick that the World Business Directory uses. Guess what, they are back! MX Lab received a new registration form from the World Business Directory and again, we want to point out a few things before you sign their contract. The email comes from info@companyworld2010.com, with the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=778&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab reported in 2009 about <a href="http://blog.mxlab.eu/2009/06/03/world-business-guide-is-using-misleading-marketing-trick/" target="_blank">the misleading marketing trick that the World Business Directory uses</a>. Guess what, they are back!</p>
<p>MX Lab received a new registration form from the World Business Directory and again, we want to point out a few things before you sign their contract.</p>
<p>The email comes from info@companyworld2010.com, with the subject &#8220;Registration of the World Business Directory 2010/2011&#8243; and this is the email content:</p>
<blockquote><p>Dear Madam/Sir,</p>
<p>In order to have your company registered in the World Business<br />
Directory for 2010/2011, please print, complete and return the<br />
enclosed form (PDF file) to the following address:</p>
<p>World Business Directory<br />
Suite 149 &#8211; Rosden House &#8211; 372 Old Street<br />
EC1V 9AU / London &#8211; United Kingdom<br />
E-mail: office@companyworld2010.com<br />
Fax: +44 207 806 8157</p>
<p>Updating is free of charge!</p>
<p>To unsubscribe, please send an email to<br />
unsubscribe@companyworld2010.com</p></blockquote>
<p>Attached is a PDF file named world-businessdirectory.pdf.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100309_wbdir.gif" alt="" width="450" height="619" /></p>
<p>The 1st point that needs your attention is the text block 1:</p>
<blockquote><p>To update your company profile, please print, complete and return<br />
this form (Updating is free of charge). Only sign if you want to<br />
place an insertion.</p></blockquote>
<p>As you can read, updating is free of charge but if you want your company get listed in this directory you will need to sign and have to pay.</p>
<p>What is the price of this directory you may ask yourself? Well, you have to go to text block 2 with the very small letters and this includes:</p>
<blockquote><p>I WILL HAVE AN INSERTION INTO ITS DATA BASE FOR THREE YEARS. THE PRICE PER YEAR IS GBP 980.</p></blockquote>
<p>And there you have it, this contract will cost your business a total amount of GBP 2940 over 3 years. After the 3 years subscription you can stop your contract if you inform them on time:</p>
<blockquote><p>THE SUBSCRIPTION WILL BE AUTOMATICALLY EXTENDED EVERY YEAR FOR ANOTHER YEAR, UNLESS SPECIFIC WRITTEN NOTICE IS RECEIVED BY THE SERVICE PROVIDER OR THE SUBSCRIBER TWO MONTHS BEFORE THE EXPIRATION OF THE SUBSCRIPTION.</p></blockquote>
<p>A few arguments from our side that this is a scam:</p>
<p>The from email address contains the domain companyworld2010.com and when trying to see if there is a site online we got the notification &#8220;This account has been suspended&#8221;. We might see new emails from the World Business Directory appear with other domains.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100309_wbdir_2.gif" alt="" width="450" height="208" /></p>
<p>When getting some WHOIS information on the domain we got the following:</p>
<table border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td></td>
<td colspan="4">
<pre>Registrant:
 international group c/o Free Private Reg
 P.O. Box 81024
 Burnaby, BC V5H 4K2
 CA

 Domain name: COMPANYWORLD2010.COM

 Administrative Contact:
    boot, cornelis  companyworld2010.com@freeprivateregistration.com
    P.O. Box 81024
    Burnaby, BC V5H 4K2
    CA
    852-3594-1708
 Technical Contact:
    Hostmaster, Domain  hostmaster@doteasy.com
    Suite 210 - 3602 Gilmore Way
    Burnaby, BC V5G 4W9
    CA
    (604) 434-4307    Fax: (604) 608-6832

 Registrar of Record: In2net Network Inc.
 Record last updated on 05-Mar-2010.
 Record expires on 05-Mar-2011.
 Record created on 05-Mar-2010.

 Domain servers in listed order:
    DNS8.DOTEASY.COM   65.61.199.14
    DNS7.DOTEASY.COM   65.61.198.14

 Domain status: clientTransferProhibited
                clientUpdateProhibited</pre>
</td>
</tr>
</tbody>
</table>
<p>The registrant information is rather vague and points to a PO Box and the administrative contact has the same address. The domain freeprivateregistration.com in the email address of the administrative contact is just a domain alias from doteasy.com. These details must be fake.</p>
<p>In 2009, the PDF document needed to be returned to an address in The Netherlands, in this 2010/2011 edition it needs to be returned to an address in London, UK.</p>
<p>When visiting their site at <a href="http://www.world-businessdirectory.com/" target="_blank">http://www.world-businessdirectory.com/</a> on the &#8216;About us&#8217; page we found the following text:</p>
<blockquote><p>The World Business Directory online is product of EU Business Services Ltd, a corporation organized and existing under the laws of Nevis, West Indies.</p></blockquote>
<p>We also  found the UK address on the &#8216;Contact us&#8217; page.</p>
<p>Our recommendation is: <strong>don&#8217;t sign the document and don&#8217;t do business with this company</strong>.</p>
<p>Follow these guidelines if  you are a victim of this directory scam:</p>
<ul>
<li>Do not pay, even if they imply to take your case to court.</li>
<li>If you have paid a certain amount, stop the next payments. Expect that you won&#8217;t get a refund either.</li>
<li>Send them a letter informing them you have been misled and telling them to cancel the contract.</li>
<li>If possible, report to (local) authorities.</li>
</ul>
<p>Additional information:</p>
<p><a href="http://stopecg.org/world_business_directory.htm" target="_blank">Stop EU Business Services Ltd Trading As World Business Directory</a><br />
<a href="http://www.stopwbd.za.org/" target="_blank">Stop world-businessdirectory.com</a></p>
<p>On the <a href="http://www.richardcorbett.org.uk/directoryscams.htm" target="_blank">web site of Richard Corbett</a> you can find some background information about directory scams and what to do when you are a victim of such a scam.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/778/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/778/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/778/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/778/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/778/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=778&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/03/09/registration-of-the-world-business-directory-20102011/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100309_wbdir.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100309_wbdir_2.gif" medium="image" />
	</item>
		<item>
		<title>ZBot trojan aims AIM users</title>
		<link>http://blog.mxlab.eu/2010/01/21/zbot-trojan-aims-aim-users/</link>
		<comments>http://blog.mxlab.eu/2010/01/21/zbot-trojan-aims-aim-users/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 21:20:47 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Various]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[zbot]]></category>
		<category><![CDATA[AIM trojan]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=736</guid>
		<description><![CDATA[MX Lab intercepted a few emails regarding AOL Instant Messenger accounts but in fact, the included URL leads to a web site that hosts malware. The malware is know as Trojan-Spy.Win32.Zbot.gen (Kaspersky), PWS:Win32/Zbot.gen!R (Microsoft) or Trojan.Zbot!gen3 (Symantec). The email comes from the spoofed address AIM &#60;no_reply_instant_messenger@aol.com&#62; with possible subjects like: Your AIM account is flagged as inactive [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=736&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted a few emails regarding AOL Instant Messenger accounts but in fact, the included URL leads to a web site that hosts malware. The malware is know as Trojan-Spy.Win32.Zbot.gen (Kaspersky), PWS:Win32/Zbot.gen!R (Microsoft) or Trojan.Zbot!gen3 (Symantec).</p>
<p>The email comes from the spoofed address AIM &lt;no_reply_instant_messenger@aol.com&gt; with possible subjects like:</p>
<p>Your AIM account is flagged as inactive<br />
Your AIM account will be deleted<br />
YourAOL Instant Messenger account will be deleted</p>
<p>Body of the email:</p>
<blockquote><p>Dear AOL Instant Messenger user,</p>
<p>Your AIM account is flagged as inactive. Within the following 72 hours it’ll be deleted from the system.</p>
<p>If you plan to use this account in the future, you have to download and launch the latest update for the AIM. This update is critical.</p>
<p>In order to install the update use the following link  . This link is generated exclusively for your account and is available within a certain period of time. As soon as this link is not available anymore you will get another letter.</p>
<p>Thank you,</p>
<p>AIM Service Team</p>
<p>This e-mail has been sent from an e-mail address that is not monitored. Please do not reply to this message. We are unable to respond to any replies.</p></blockquote>
<p>The email contains the link to the web site hxxp://update.aol.com.terfkiof.net.pl/products/aimController.php?code=2902***&amp;email=***r@r***.com. Note: it is possible that other links are being used in this campaign.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100121_AIM_ZBot.jpg" alt="" width="450" height="358" /></p>
<p>This web site informs you to download the file aimupdate_7.1.6.475.exe (size: 128 kB). When executed you will infect your computer with ZBot &#8211; a banking trojan that disables firewall, steals sensitive financial data (credit card numbers, online banking login details), makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system.</p>
<p>The file %System%\sdra64.exe is created on an infected system, along with a hidden directory %System%\lowsec and the hidden files: %System%\lowsec\local.ds, %System%\lowsec\user.ds and %System%\lowsec\user.ds.lll</p>
<p>The trojan can request data from the following URLs:</p>
<p>* http://nekovo.ru/cbd/nekovo.bri<br />
* http://nekovo.ru/ip.php</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/24e2084aca074a43881abce1edee78c230b86b22a14956f018df0a6451a73dc1-1264091581" target="_blank">permlink</a> and MD5: d267e1ccc1a30134ab965fcaa39d145c. At the time of writing, only 9 of the 41 AV engines did detect the trojan. Our recommendation is therefore not to follow the URL and certainly not to download and install this so called AIM update.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/736/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/736/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/736/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/736/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/736/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/736/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/736/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/736/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/736/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/736/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=736&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/01/21/zbot-trojan-aims-aim-users/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100121_AIM_ZBot.jpg" medium="image" />
	</item>
		<item>
		<title>SpamAssassin 2010 bug caused by &#8220;old&#8221; rule</title>
		<link>http://blog.mxlab.eu/2010/01/05/spamassassin-2010-bug-caused-by-old-rule/</link>
		<comments>http://blog.mxlab.eu/2010/01/05/spamassassin-2010-bug-caused-by-old-rule/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 12:48:28 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Various]]></category>
		<category><![CDATA[Spamassassin]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=718</guid>
		<description><![CDATA[SpamAssassin, a tool that is widely used as open-source anti spam detection system, had an issue on Janaury 1, 2010 with a rule that compares the date of an email message to detect emails from the future which could be an indicator of spam. For the readers that are not familiar with SpamAssassin here is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=718&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>SpamAssassin, a tool that is widely used as open-source anti spam detection system, had an <a href="https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6269" target="_blank">issue</a> on Janaury 1, 2010 with a rule that compares the date of an email message to detect emails from the future which could be an indicator of spam.</p>
<p>For the readers that are not familiar with SpamAssassin here is a brief explanation on how SpamAssassin works. SpamAssassin will check each incoming message and will check the message based on rules. These rules contains information on what to search for and defines a score when a similarity is found.</p>
<p>The rule FH_DATE_PAST_20XX checks if a message is sent in the near future and will increase the score  with 3.2 points if this is true. Apparently, the search date was 01-01-2010.</p>
<p>This caused that all messages had an increased score by 3.2 by default. Combined with other rules, the score per message can increase further and eventually the message can be labeled as spam by SpamAssassin, depending on the configuration, that leads to many false positives.</p>
<p>The date for the rule has been changed to 01-01-2020 according to the <a href="http://wiki.apache.org/spamassassin/Rules/FH_DATE_PAST_20XX" target="_blank">SpamAssassin Wiki</a>.</p>
<p>More information:</p>
<p><a href="https://secure.grepular.com/blog/index.php/2010/01/01/spamassassin-2010-bug/" target="_blank">Mike Cardwell Blog</a><br />
<a href="http://it.slashdot.org/story/10/01/02/0027207/SpamAssassin-2010-Bug" target="_blank">IT Slashdot</a></p>
<p>I do hope that the SpamAssassin admins change the rule on time to avoid a 2020 bug in their rule set.</p>
<p>In case you&#8217;re wondering&#8230;. no, MX Lab does not use SpamAssassin so our services were not affected by this issue.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/718/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/718/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/718/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/718/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/718/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/718/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/718/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/718/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/718/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/718/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=718&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/01/05/spamassassin-2010-bug-caused-by-old-rule/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Best wishes for 2010</title>
		<link>http://blog.mxlab.eu/2010/01/01/best-wishes-for-2010/</link>
		<comments>http://blog.mxlab.eu/2010/01/01/best-wishes-for-2010/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 15:13:17 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Various]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=715</guid>
		<description><![CDATA[We also would like to use the opportunity to thank all the readers of the MX Lab blog for their visits on our blog and the posted comments. We are commited to contribute further in email security related articles and we will also use Twitter to inform about email based threats and certain aspects of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=715&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>We also would like to use the opportunity to thank all the readers of the MX Lab blog for their visits on our blog and the posted comments. We are commited to contribute further in email security related articles and we will also use <a href="http://twitter.com/mxlab" target="_blank">Twitter</a> to inform about email based threats and certain aspects of our business.</p>
<p>MX Lab wishes everyone a virus and spam-free 2010.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/715/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/715/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/715/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/715/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/715/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/715/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/715/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/715/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/715/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/715/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=715&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/01/01/best-wishes-for-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>MX Lab on Twitter</title>
		<link>http://blog.mxlab.eu/2009/10/23/mx-lab-on-twitter/</link>
		<comments>http://blog.mxlab.eu/2009/10/23/mx-lab-on-twitter/#comments</comments>
		<pubDate>Fri, 23 Oct 2009 00:10:38 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Various]]></category>
		<category><![CDATA[tweets]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=600</guid>
		<description><![CDATA[Follow the MX Lab tweets on Twitter at http://twitter.com/mxlab/. Stay up to date with the latest news regarding email security in general.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=600&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Follow the MX Lab tweets on Twitter at <a href="http://twitter.com/mxlab/" target="_blank">http://twitter.com/mxlab/</a>. Stay up to date with the latest news regarding email security in general.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/600/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/600/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/600/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/600/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/600/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/600/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/600/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/600/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/600/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/600/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=600&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/10/23/mx-lab-on-twitter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Letter from Ondernemings-Portaal België</title>
		<link>http://blog.mxlab.eu/2009/10/22/letter-from-ondernemings-portaal-belgie/</link>
		<comments>http://blog.mxlab.eu/2009/10/22/letter-from-ondernemings-portaal-belgie/#comments</comments>
		<pubDate>Thu, 22 Oct 2009 00:21:11 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Various]]></category>
		<category><![CDATA[Ondernemings-Portaal België]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=591</guid>
		<description><![CDATA[My company Pixel Design and MX Lab received today a letter from Ondernemings-Portaal België, in Dutch, regarding our presence on their business portal http://www.ondernemings-portaal-belgie.be or http://www.portail-des-entreprises-de-belgique.be/. The way this company works is more or less similar to the World Business Guide or Belgisch Internet Register (DAD). Page one is the introduction letter and page two is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=591&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>My company Pixel Design and MX Lab received today a letter from Ondernemings-Portaal België, in Dutch, regarding our presence on their business portal <a href="http://www.ondernemings-portaal-belgie.b" target="_blank">http://www.ondernemings-portaal-belgie.b</a>e or <a href="http://www.portail-des-entreprises-de-belgique.be/" target="_blank">http://www.portail-des-entreprises-de-belgique.be/</a>.</p>
<p>The way this company works is more or less similar to the <a href="http://blog.mxlab.eu/2009/06/03/world-business-guide-is-using-misleading-marketing-trick/">World Business Guide</a> or <a href="http://blog.mxlab.eu/2007/03/22/belgisch-internet-register/">Belgisch Internet Register (DAD)</a>. Page one is the introduction letter and page two is the registration form with the company details that will be used in the pubication.</p>
<p>The letter does state the following:</p>
<blockquote><p>Indien de door ons ingevuld gegevens niet correct of onvolledig zouden zijn, hebt u de mogelijkheid om uw gegevens te corrigeren: de basisgegevensinvoer (naam, postcode, plaats) onder www.ondernemings-portaal-belgië submenu-item: registratie. Hiervoor worden geen kosten berekend!</p></blockquote>
<p>For the non Dutch speaking readers, the above mentions that you can correct your basic details like name, zip and city on the web site without any costs.</p>
<blockquote><p>Wilt u meer communicatiegegevens dan de basisgegevensinvoer publiceren, dan gebruikt u het bijgevoegde formulier en stuurt het aan ons terug. Aangezien wij geen kamer-aangesloten- of overheidsafhankelijke onderneming zijn, zijn er aan deze publicatie kosten verbonden.</p></blockquote>
<p>If you want to publish more data than the basic details like name, zip and city then you need to take extra costs into account.</p>
<blockquote><p>Indien u per vergissing als exploitant van een privé internet pagina werd aangeschreven of niet wenst gepubliceerd te worden, gelieve dit dan in het daartoe bestemde vak linksonder aan te duiden en het formulier aan ons terug te sturen.</p></blockquote>
<p>If you don&#8217;t want your details published on their web site because your company does not exist anymore, you don&#8217;t want a publication or you are a private person, you need to mark this on the first paper and send this back to Ondernemings-Portaal België with the registration form.</p>
<p>Now here is catch. The place where you can mark that you don&#8217;t want to publish your basic details is on the first page. The registration form with your details is on page two. On page two you are asked to sign and put the date on it. Now, if they receive it and they throw page one in the trashcan &#8211; something you can&#8217;t check &#8211; you have signed their contract for publication. The &#8216;not publish&#8217; option is not on their registration form so it can be abused.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20091022_ondportaalbe.jpg" alt="" width="450" height="309" /></p>
<p>The costs are not mentioned on the first page but is stated on the second page and this is € 987 per year and the contract is for 3 years! So be aware that this is a costly advertisment.</p>
<p>Beside that, when you are in dispute with the company be aware that their establishment is located in Germany under the name TVV Tele Verzeichnis Verlag GmbH, Hamburg, and that German law applies to the contract.</p>
<p>Unizo, the Union of Independent Entrepreneurs in Belgium, has dedicated <a href="http://www.unizo.be/reclameronselaars/" target="_blank">a whole section on their web site</a> regarding these advertising recruiters (site in Dutch) with lots of examples.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/591/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/591/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/591/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/591/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/591/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/591/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/591/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/591/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/591/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/591/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=591&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/10/22/letter-from-ondernemings-portaal-belgie/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20091022_ondportaalbe.jpg" medium="image" />
	</item>
		<item>
		<title>Make sure your WordPress installation is up to date</title>
		<link>http://blog.mxlab.eu/2009/09/09/make-sure-your-wordpress-installation-is-up-to-date/</link>
		<comments>http://blog.mxlab.eu/2009/09/09/make-sure-your-wordpress-installation-is-up-to-date/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 17:36:35 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Various]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[Wordpress update]]></category>
		<category><![CDATA[Wordpress security]]></category>
		<category><![CDATA[blogs]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=538</guid>
		<description><![CDATA[Maybe interesting reading for users who have their own WordPress installation older than version 2.8.4. &#8220;The newly discovered worm is pretty sneaky to say the least. In a nutshell, it crawls the web looking for vulnerable WordPress installations, makes itself an administrator account, takes full control of the website and posts malware and spam to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=538&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Maybe interesting reading for users who have their own WordPress installation older than version 2.8.4.</p>
<p>&#8220;The newly discovered worm is pretty sneaky to say the least. In a nutshell, it crawls the web looking for vulnerable WordPress installations, makes itself an administrator account, takes full control of the website and posts malware and spam to it. It’s also been reported that it will sometimes disable Defensio and other anti-spam plugins. It can be very hard to detect the new malicious administrator user since it hides itself from the users list using Javascript.&#8221;</p>
<p><a href="http://securitylabs.websense.com/content/Blogs/3472.aspx" target="_blank">Read the full story</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/538/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/538/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/538/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/538/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/538/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/538/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/538/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/538/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/538/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/538/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=538&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/09/09/make-sure-your-wordpress-installation-is-up-to-date/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Shortened URLs: the real dangers behind and how to avoid troubles</title>
		<link>http://blog.mxlab.eu/2009/07/17/shortened-urls-the-real-dangers-behind-and-how-to-avoid-troubles/</link>
		<comments>http://blog.mxlab.eu/2009/07/17/shortened-urls-the-real-dangers-behind-and-how-to-avoid-troubles/#comments</comments>
		<pubDate>Fri, 17 Jul 2009 19:41:59 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Various]]></category>
		<category><![CDATA[URL-shortening]]></category>
		<category><![CDATA[shortened URl]]></category>
		<category><![CDATA[URL]]></category>
		<category><![CDATA[TinyURL]]></category>
		<category><![CDATA[bit.ly]]></category>
		<category><![CDATA[Cligs]]></category>
		<category><![CDATA[is.gd]]></category>
		<category><![CDATA[preview short URL]]></category>
		<category><![CDATA[preview shortened URL]]></category>
		<category><![CDATA[short URL]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=497</guid>
		<description><![CDATA[URL-shortening services such as TinyURL and Bit.ly are popular when it comes down to shorten long URLs that have the possibility to break or are simply too long when inserted in email, posts on Twitter, blogs and so on. The potential dangers and risks The dark side is that with these shortening services you are [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=497&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>URL-shortening services such as TinyURL and Bit.ly are popular when it comes down to shorten long URLs that have the possibility to break or are simply too long when inserted in email, posts on Twitter, blogs and so on.</p>
<p><strong>The potential dangers and risks</strong></p>
<p>The dark side is that with these shortening services you are no longer able to see directly where your browser will be pointed to. Shortened URLs could lead to the following security risks:</p>
<ul>
<li>web sites that host malware, trojans and other malicious programs</li>
<li>web sites that could exploit security risks in a browser or system</li>
<li>web sites that contain phishing attempts and try to steal personal information</li>
<li>web sites that contain phishing attempts by social interaction</li>
<li>web sites that are being used in spam campaigns</li>
</ul>
<p><strong>A real example of shortened URL abuse</strong></p>
<p>MX Lab has intercepted a message from Sefedin Abazi &lt;sabazi@hotmail.com&gt; with the subject &#8220;Fotos 26/06&#8243;. This is the message  content:</p>
<blockquote><p>7:37:25 PM Fotos 26/06 :<br />
Imagens anexadas:  <span style="text-decoration:underline;"><span style="color:#0000ff;">DSC_332.jpg</span></span> &#8211;  <span style="color:#0000ff;"><span style="text-decoration:underline;">DSC_333.jpg</span></span> &#8211;  <span style="color:#0000ff;"><span style="text-decoration:underline;">DSC_334.jpg</span></span><br />
Videos Hotmail.com: <span style="text-decoration:underline;"><span style="color:#0000ff;">www.hotmail.com/videos</span></span><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
See all the ways you can stay connected to friends and family</p></blockquote>
<p>With this email it looks like someone has sent you some foto&#8217;s and perhaps your curiosity is triggered you click on the short URL. The names of the photos and the video link contains the shortened URL link: hxxp://cli.gs/21YUde (do not use please).</p>
<p>By clicking on the shortened URL, your browser will make a connection to hxxp://fotos.live.fromru.su and will download the file xupload.exe.</p>
<p>When submitting the file to Virus Total (<a href="http://www.virustotal.com/analisis/41264e7b2d94a74dfc1dad8b9220a67e096a0d0735d5bf1903b7ed06441d8959-1247850872" target="_blank">permlink</a> and MD5: 41e441403bae688961d276b2ab1f9bca) we found out that the malware is known as Gen:Trojan.Heur.B090E1F4F4 (by GData), W32/Obfuscated.B!genr (by Norman), W32/Trojan-disguised-based!Maximus (by F-Prot) or Mal/Generic-A (Sophos). The major problem is that 21 of the 41AV engines did not detect the malware.</p>
<p>Without going too much in the technical details of the malware, we could conclude that downloading and executing the  xupload.exe could lead to a suprise.</p>
<p>Furthermore, some URL-shortening services not only shorten the URL but are also tracking the usage of the generated URLs. This way the &#8220;distributor&#8221; can gather resources on how many times a malicious shortened URL is being used, in what country, and so on.</p>
<p><strong>How to preview a shortened URL</strong></p>
<p>By previewing the short URL you can determine if your destination is safe enough to visit.</p>
<p><strong><span style="color:#808080;">TinyURL</span></strong><br />
For some URL-shortening services there is a preview feature where you can submit the shortened URL to and view the full URL before visiting the site.  For TinyURL you can visit <a href="http://tinyurl.com/preview.php" target="_blank">http://tinyurl.com/preview.php</a> directly. A second method is to place &#8220;preview.&#8221; before tinyurl.com. For example http://tinyurl.com/mfhxxj becomes http://preview.tinyurl.com/mfhxxj.</p>
<p><strong><span style="color:#808080;">bit.ly</span></strong><br />
The service bit.ly  (<a href="http://bit.ly/" target="_blank">http://bit.ly/</a>) is using a different approach. You will need to install a plug in for Firefox and hover over a shortened URL to get a tooptip with page title, long URL, and any click data about the page the URL links to. There is also <a href="https://addons.mozilla.org/en-US/firefox/addon/10297" target="_blank">a Firefox plug</a> in available.</p>
<p><strong><span style="color:#808080;">is.gd</span></strong><br />
is.gd has information on their <a href="http://is.gd/instructions.php" target="_blank">instructions page</a> on how to enable or disable previews by using a cookie on your computer. You can also add a hyphen (dash) to the end of the shortened URL. For example http://is.gd/1D6db is the shortened URL. By using http://is.gd/1D6db- your browser will be taken to a preview page first.</p>
<p><strong><span style="color:#333333;"><span style="color:#808080;">Snipurl </span><span style="font-weight:bold;"><span style="color:#808080;">/ Snipr</span></span><span style="font-weight:bold;"><span style="color:#808080;"> / Snurl</span></span><span style="font-weight:bold;"><span style="color:#808080;"> / Sn.im</span></span></span></strong><br />
Adding the string &#8220;peek.&#8221; before the snipurl.com part of an shirt URL to find out where the link leads. http://snipurl.com/nh0l0 can be changed into http://peek.snipurl.com/nh0l0 for a preview.</p>
<p><span style="color:#333333;"><strong><span style="color:#808080;">BudURL</span></strong></span><br />
Simply add a &#8220;?&#8221; to the end of a BudURL  to preview it. For example http://budurl.com/ehnw?</p>
<p><strong><span style="color:#333333;"><span style="color:#808080;">short.ie</span><br />
<span style="font-weight:normal;"><span style="color:#000000;">Same technique as with the POPrl. Insert &#8220;/see&#8221; after the short.ie/ portion of the URL. For example change http://short.ie/ij6nvk into http://short.ie/see/ij6nvk.</span></span></span></strong></p>
<p><strong><span style="color:#808080;">kl.am</span></strong><br />
Go to http://kl.am and click on the checkbox next to &#8220;Preview mode: OFF&#8221; to turn preview on.</p>
<p><strong><span style="color:#808080;">Tinyarro.ws / ta.gd</span></strong><br />
Tinyarro.ws is giving a preview by default. There is a countdown enabled so you have time to preview the full URL and cancel the redirection if needed.</p>
<p><strong><span style="color:#808080;">ExpandMyURL</span></strong><br />
The web site <a href="http://expandmyurl.com/" target="_blank">Expand My URL</a> allows you to preview short URLs from TinuURL, bit.ly and is.gd.</p>
<p><strong><span style="color:#808080;">LongURL</span></strong><br />
This <a href="http://longurl.org/" target="_blank">web site</a> can provide a preview for +200 URL-shortener services and includes tinyurl.com, is.gd, ping.fm, ur1.ca, bit.ly, snipurl.com, tweetburner.com, metamark.net, url.ie, x.se, 6url.com, yep.it, piurl.com and <a href="http://longurl.org/services" target="_blank">more</a>. LongURL is also available <a href="https://addons.mozilla.org/en-US/firefox/addon/8636" target="_blank">as a Firefox plugin</a>.</p>
<p>It is possible that non al URL shortener services that offers some kind of preview feature are listed here. If you find others, please let me know to include them.</p>
<p>Updated: 07-18-2009: added LongURL and some links to Firefox extensions.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/497/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/497/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/497/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/497/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/497/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/497/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/497/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/497/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/497/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/497/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=497&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/07/17/shortened-urls-the-real-dangers-behind-and-how-to-avoid-troubles/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>World Business Guide is using misleading marketing trick</title>
		<link>http://blog.mxlab.eu/2009/06/03/world-business-guide-is-using-misleading-marketing-trick/</link>
		<comments>http://blog.mxlab.eu/2009/06/03/world-business-guide-is-using-misleading-marketing-trick/#comments</comments>
		<pubDate>Wed, 03 Jun 2009 11:14:54 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Various]]></category>
		<category><![CDATA[directory]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[World Business Guide]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=470</guid>
		<description><![CDATA[Today, MX Lab received an email regarding the &#8220;World BusinessGuide&#8221; directory. At first there seems nothing wrong with the mailing but when looking further there are some points that need your attention. The messages is from &#8220;World Business Register&#8221; with different email addresses in use: info@easyhomecorporation.com info@easycitycorporation.com info@bigorganization4you.com www@companyregpro.net www@companyregstore.net www@easycompregonline.com www@bestcompregpro.com The subject is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=470&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Today, MX Lab received an email regarding the &#8220;World BusinessGuide&#8221; directory. At first there seems nothing wrong with the mailing but when looking further there are some points that need your attention.</p>
<p>The messages is from &#8220;World Business Register&#8221; with different email addresses in use:</p>
<p>info@easyhomecorporation.com<br />
info@easycitycorporation.com<br />
info@bigorganization4you.com<br />
www@companyregpro.net<br />
www@companyregstore.net<br />
www@easycompregonline.com<br />
www@bestcompregpro.com</p>
<p>The subject is &#8220;Business Registration 2009/2010&#8243;. The body of the email:</p>
<blockquote><p>Ladies and Gentlemen.</p>
<p>In order to have your company inserted in the registry of World Businesses<br />
for 2009/2010 edition, please print, complete and submit the enclosed<br />
form (PDF file) to the following address:</p>
<p>WORLD BUSINESS GUIDE<br />
P.O. Box 2021<br />
3500 GA Utrecht<br />
The Netherlands</p>
<p>email: register@wbgtoday.net<br />
FAX: +31 20 524 8107</p>
<p>Updating is free of charge!</p>
<p>If you are not the intended recipient, please submit an email to<br />
unsubscribe@wbgtoday.net<br />
Your request shall be dealt with accordingly.</p></blockquote>
<p>Attached is a PDF document that needs to be printed, filled in and sent to an PO Box address in The Netherlands.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090603_wbguide.jpg" alt="" width="450" height="637" /></p>
<p>When reading the PDF document carefully you can find the following:</p>
<blockquote><p>I WILL HAVE AN INSERTION INTO ITS DATA BASE FOR THREE YEARS. THE PRICE PER YEAR IS EURO 995.</p></blockquote>
<p>While the email itself states &#8220;<strong>Updating is free of charge!</strong>&#8221; you will have to pay <strong>€ 995 each year</strong> with a minimum 3 year period by signing the document. This is quite misleading if you ask me.</p>
<p>A few more observations that should warn you about a possible scam:</p>
<ul>
<li>the email is sent from easyhomecorporation.com while there is no web site on this place so the registration of this domain is purely for spoofine the real origin.</li>
<li>and more important, the document needs to be sent to a PO Box in The Netherlands while the company is International Directories Group Ltd  located in Spain according to the document.</li>
</ul>
<p>In the past we have received similar letters by regular post here in Belgium and some organisations like Unizo have <a href="http://www.unizo.be/viewobj.jsp?id=385661" target="_blank">instructions</a> (in Dutch) on how to report the illegal and deceptive practices to the authorities.</p>
<p>If you have received such a email, or regular mail, don&#8217;t sign the document, sent it to the trash or report to your local authorities.</p>
<p>[Update March, 9th 2010] MX Lab received a new registration PDF from the World Business Directory. <a href="http://blog.mxlab.eu/2010/03/09/registration-of-the-world-business-directory-20102011/">Read the article</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/470/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=470&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/06/03/world-business-guide-is-using-misleading-marketing-trick/feed/</wfw:commentRss>
		<slash:comments>40</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20090603_wbguide.jpg" medium="image" />
	</item>
	</channel>
</rss>