What's Breaking News Tonight?
What's New?
The new black hole exploit kit has been out and we've had a chance to deconstruct it. Before we get super geeky, some general observations about the innovation in this kit:
- Malware developers continue to use the latest tools to encrypt their malware to evade anti-virus (AV) software. As usual, the encryption signature is new, avoiding AV--our analysis showed that 70 percent of AV software would miss this altogether. This serves as a not-so-gentle reminder the fundamental problem with signature based AV--it changes every week with the use of a new encryption algorithm.
- Hackers are deploying resiliency. In the past, we've seen hackers deploy a single exploit server. In this case, there were four that could be redirected if any of the URLs was taken down.
What are BEPs?
An exploit kit, a browser exploit pack (BEP) is a toolkit that automates the exploitation of client side vulnerabilities.
The toolkit is a bundle of PHP and HTML files with a list of exploit files (including JAVA, PDF, Browsers, Adobe Flash Player ...etc) designed to target the operating system, browser or other client side application. Toolkits are usually heavily obfuscated using some known or unknown obfuscation and crypto algorithms tools to avoid detection by anti-virus vendors.
Black hole is yet another web exploit kit developed by Russian hackers. Blackhole is a very powerful kit with a number of recent exploits including Java and Adobe PDF exploits. One blog published (with updates) a great overview of the most known exploit packs.
The professionals can see that at least for the next few months the GOP is burdened with a handful of shopworn candidates who cannot be collectively cobbled into a winner.
When asked by TIME Magazine whether Mitt Romney is a job creator or destroyer, Warren Buffett said that while businesses shouldn't hang on to people they don't need, "I don't like what private-equity firms do in terms of taking out every dime they can and leveraging [companies] up so that they really aren't equipped, in some cases, for the future." Voters need to understand the kind of economy Mitt Romney's experience entails - and it doesn't sound like the kind of economy that's built to last.
Trusted vendors on
DarkMarket offered a smorgasbord of personal data, viruses, and card-cloning
kits at knockdown prices. Going rates were:
Dumps Data from magnetic stripes on batches of 10 cards.
Standard cards: $50. Gold/platinum: $80. Corporate: $180.
Card
verification values Information
needed for online transactions. $3-$10 depending on quality.
Full
information/change of billing Information needed for opening or taking over account details.
$150 for account with $10,000 balance. $300 for one with $20,000 balance.
Skimmer Device to read card data. Up to $7,000.
Bank logins 2% of available balance.
Hire of
botnet Software robots
used in spam attacks. $50 a day.
Credit card
images Both sides of
card. $30 each.
Embossed
card blanks $50 each.
Holograms $5 per 100.




















