Archive for December, 2005

Yahoo! Messenger worm

Thursday, December 22nd, 2005
yahoo messenger

The Santa Claus worm doesn’t care whether you’ve been naughty or nice, but it’s making a list of PCs to infect this holiday season, according to a threat alert released by security firm IMlogic today.

A new instant-messaging worm called IM.GiftCom.All is making the rounds this holiday season. Rated as a “medium” threat by IMlogic, the worm attempts to get users of the instant-messaging networks run by America Online, Yahoo, and Microsoft to visit a seemingly festive Web site featuring Santa Claus.


The message comes from someone already present on a user’s “buddy list,” said Art Gilliland, vice president of products for IMlogic. It contains a supposed link to a URL (uniform resource locator) starting with “santaclause.aol.com/a?|”

However, clicking on that link takes users to a different Web site and triggers the download of a malicious file to a user’s PC, Gilliland said. That file is created using rootkit techniques, making it extremely difficult to detect with conventional antivirus or operating system tools, he said. Once resident on a system, the file tries to shut down antivirus software and collects personal information that can be redistributed over the Internet.

IMlogic has not recorded an instance where that personal information was actually sent out to the Internet, but the program does log information, Gilliland said.

Don’t Click!

Users are advised to avoid clicking on anything sent through an instant-messaging system unless they have verified that the file or picture is legitimate and the sender intended to pass it along, Gilliland said. IMlogic recently identified an instant-messaging bot that produces canned assurances that a file is legitimate when the recipient replies to check its authenticity, so it’s important to take extra care to verify the sender’s intentions, he said.

Yahoo! widgets 3

Tuesday, December 13th, 2005
yahoo widgets

What Is the Yahoo! Widget Engine?

The Yahoo! Widget Engine (formerly known as Konfabulator) is a JavaScript runtime engine for Windows and Mac OS X that lets you run little files called Widgets that can do pretty much whatever you want them to. Widgets can be alarm clocks, calculators, can tell you your WiFi signal strength, will fetch the latest stock quotes for your preferred symbols, and even give your current local weather.

What sets Yahoo! Widget Engine apart from other scripting applications is that it takes full advantage of today”s advanced graphics. This allows Widgets to blend fluidly into your desktop without the constraints of traditional window borders. Toss in some sliding and fading, and these little guys are right at home in Windows XP and Mac OS X.

The format for these Widgets is completely open and easy to learn so creating your own Widgets is an extremely easy task.

For the “skinning” crowd, Yahoo! Widget Engine is a dream come true. You can easily change the look, feel, layout, even functionality of a Widget so that it matches your lifestyle, your desktop, or the pants or skirt you have on that day.


Download Yahoo! Widgets

Yahoo! IM Phishing Attack Surfaces

Tuesday, December 13th, 2005
yahoo 360

Instant messaging security firm IMLogic warned of a new phishing attack making its way through the Yahoo! Messenger network on Monday. The attack, IM.Marphish2.Yahoo, attempts to steal personal information by duping a user into believing that they are in violation of Yahoo’s Terms of Service. The user is instructed to contact the “abuse department” through a URL that points to the 2wahms.com domain.


When visited, the page looks similar to a Yahoo login page. However, once a user enters their personal information, the site steals the users username and password. IMLogic says that the effectiveness of such attacks is improving as they continue to build upon previous efforts and blend different methods together to further confound traditional anti virus programs.By Ed Oswald, BetaNews