Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 16 January 2008

Storm Loves You!

Posted on 21:37 by Unknown
The Storm Worm (yes, I know its not a worm, but that's what its called!) has mutated once again and is back in the full swing of "SP" mode, or "Storm Propagation" mode.

Beginning around 3 AM on January 15th, we started seeing new spam messages attempting to infect people with the Storm malware by tricking them into viewing a dangerous website.

Not sure if this is a COMPLETE list of subjects and bodies, but I'm seeing quite a few of them. I'm guessing you can mix and match some of the nouns and adjectives in the subjects below. I'm also guessing that the subjects and bodies may be interchangable.

The big news is that the URLs are no longer using Fast Flux domain names, which means that the Storm folks have to go back to using IP addresses as URLs.

Here are some of the Subjects used by the current storm campaign.

A Is For Attitude
A Kiss So Gentle
A Rose for My Love
A Toast My Love
A Token of My Love
Come Dance with Me
Come Relax with Me
Destiny
Eternity of Your Love
Hugging My Pillow
I am Complete
I Love Thee
I Love You Soo Much
In Your Arms
Inside My Heart
Last Night
Love Remains
Magic Power of Love
Miracle of Love
Our Journey
Our Love is Free
Pages from My Heart
Sending You All My Love
Sent with Love
The Mood for Love
When Love Comes Knocking
When You Fall in Love
You... In My Dreams
You're my Dream
You're the One
Your Love has Opened


Bodies:

A Is For Attitude (URL)
A Dream is a Wish (URL)
A Toast My Love (URL)
Come Dance with Me (URL)
Eternity of Your Love (URL)
Hugging My Pillow (URL)
If Loving You (URL)
I Love Thee (URL)
I Love You Soo Much (URL)
Inside My Heart (URL)
Last Night (URL)
Our Journey (URL)
Our Love is Strong (URL)
Our Love Nest (URL)
Sending You All My Love (URL)
Sent with Love (URL)
Miracle of Love (URL)
Path We Share (URL)
The Miracle of Love (URL)
The Mood for Love (URL)
The Moon & Stars (URL)
Words in my Heart (URL)
You're In My Thoughts (URL)
Wrapped in Your Arms (URL)
You're In My Thoughts (URL)

A few IPs I've got spam for:

24.13.25.195
24.29.57.5
24.98.163.49
24.147.84.166
24.158.201.51
24.182.164.166
58.8.154.229
59.93.124.61
61.254.150.135
62.30.214.249
64.130.186.121
64.131.210.85
65.127.69.227
65.189.144.143
66.56.162.236
66.65.246.186
67.170.38.85
68.52.93.226
68.91.149.33
69.153.229.224
69.236.21.121
70.119.36.227
70.237.140.25
70.237.219.11
70.251.159.54
71.224.194.223
71.228.87.148
75.18.129.8
75.46.65.147
75.74.12.93
75.132.167.64
75.176.123.128
75.181.155.252
76.86.247.98
76.87.138.125
76.108.103.196
76.211.9.128
76.223.80.123
76.117.96.98
76.255.55.200
77.244.67.25
79.120.46.50
79.176.169.98
116.126.30.18
125.184.241.30
190.47.48.223
190.50.109.86
190.172.254.93
200.8.248.51
200.126.102.5
201.223.179.88
208.38.67.197
218.238.54.74
218.190.195.185
220.77.192.117
220.79.184.205

--

--------------

Gary Warner
Director of Research in Computer Forensics
The University of Alabama at Birmingham
Read More
Posted in | No comments

Friday, 11 January 2008

New IRS Virus page taxes users

Posted on 20:27 by Unknown
A phishing site hosts fraudulent bank pages, and an IRS look-alike virus

A new round of spam, first noticed on January 8th, has been observed by anti-phishing researchers at the University of Alabama at Birmingham. In many ways the spam is typical phishing emails, trying to trick users into visiting a fraudulent website. This family of emails uses the domains listed below to host several different phishing campaigns, each in a different subdirectory. For example:

/_mem_bin/formslogin.asp = Intelligent Finance
/default.aspx = NatWest Bank
/confirm.asp = Royal Bank of Scotland

But in addition to the traditional phishing, or bank fraud websites, which try to steal userids and passwords for online banking accounts, this spam campaign also includes a fake Internal Revenue Service website - and it isn't asking for your password!

/importantpubs/index.htm = Internal Revenue Service

After giving a warning to "Business/Corporate Treasury Managers and Accountants", the fraudulent IRS website claims to have "important recent changes to business and corporate tax laws".




Each of the links which claim to be a new document with important tax information actually is a link to a virus! With file names like:

ALL_TAXPAYERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
ESTATE_AND_TRUST_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
EXCISE_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
EXEMPT_ORG_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
FOREIGN_ISSUES_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
INDIVIDUALS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
IRA_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE

the virus attempts to trick users into opening the file. If successful, the user will think he is getting information to share his taxes with the IRS, but actually the user will begin to share their information with criminals instead!

Some of the domains hosting this virus so far:

New Sites
jan77.net
aut33.com
pid28.com
com61.net
inf32.net
sid24.net
chcpi.com
chk08.net
dll57.com
idp56.us
user94.net
Older sites
ssl--jan08.com
ssl--site.com
ssl-jan08site.com
url-sslsite.com
update-ssl.com
url-ssl.com
confirm--07jan.com
6jan-update.in
securesafesite.net
myupdatesite.net
comssl.net
secure--confirm.net
06jan--confirm.net
7jan--verify.net

REMEMBER! The IRS is not going to send you an email to warn you about new documents or ask you to login. Several major anti-virus products do not yet detect this virus! Be safe! Do not click on links sent to you in email. If you need new tax documents, visit the real website at: http://www.irs.gov/.



As we have seen in so much recent malware, the websites are being rotated to include hosting on many servers. Here are the sites which are serving the malware according to our most recent query, but there may be many many more.


83.9.136.40 - Warsaw, Poland
77.253.113.235 - Warsaw, Poland
24.93.127.106 - Columbus, Ohio
69.201.136.16 - New York, New York
128.118.145.125 - Penn State University
87.209.100.8 - Amsterdam, the Netherlands
144.162.93.16 - Dallas County Community College
80.85.229.201 - Tarnow, Poland

_-_
gary warner
http://www.cis.uab.edu/forensics/

Read More
Posted in | No comments

Thursday, 3 January 2008

Ralsky: Going Down

Posted on 15:17 by Unknown
***IMPORTANT UPDATE*** January 11, 2008!
Today Alan Ralsky was taken into custody - arrested after arriving from Germany and taken into custody.
**********************

Congratulations to First Assistant US Attorney Terrence Berg and his colleagues in Detroit for being willing to prosecute one of the top spammers, as revealed in a 41-count indictment unveiled today in Detroit!

According to the January 3, 2008 announcement by the US Department of Justice today, Scott Bradley and Judy Devenow were in court after being arrested today to hear the charges. John Hui was arrested in New York on January 2nd. The other defendants are at large and being sought. (Hint: You might check the Dominican Republic? Oh wait. Wrong spammer. That was Rizler.)

The full list of defendents is given below:

Alan M. Ralsky, 52, of West Bloomfield, Michigan

Scott K. Bradley, 46, of West Bloomfield, Michigan

Judy M. Devenow, 55, of Lansing, Michigan

John S. Bown, 47, of Poway, California

William C. Neil, 45, of Fresno, California

Anki K. Neil, 36, of Fresno, California

James E. Bragg, 39, of Queen Creek, Arizona

James E. Fite, 34, of Whittier, California

Peter Severa, age unknown, of Russia

How Wai John Hui, 49, of Vancouver, Canada and Hong Kong

Francis A. Tribble, of Los Angeles, California

Ralsky, who has his own Wikipedia page became one of the most famous spammers after an interview with the Detroit News in 2002. Pictures of his ill-gotten mansion are available at Archive.org.

The FBI raided Ralsky's home in 2005, and apparently today's indictments are the conclusion of that investigation, which DOJ says is now three years old!

While a total pricetag may never be placed on all of Ralsky's illegal profits, DOJ says he earned $3 Million just in the summer of 2005!

Ralsky has long been on the excellent Spamhaus Registry of Known Spam Offenders and was featured in the book "Spam Kings". Brian McWilliams, the author of Spam Kings, called Ralsky "the most successful spammer" in this Tech Soup Interview in 2004. Partly because he was still in business after the successful 2001 Verizon lawsuit against him. Three years later and he's still spamming!

Joel Kurth did an excellent profile on Ralsky in August of 2002 for the Detroit News, where Ralsky admits to maintaining a 150 million email address mailing list (though he points out there were 87 million email addresses that he does NOT send spam to because they unsubscribed.)

I wonder how many millions more people he's offended since 2002?

Congratulations again, Detroit, CCIPS, and thanks to the FBI, Postal Inspectors, and IRS Agents who assisted in bringing this to indictment.

Now if they can just get the other 8 co-defendants into custody . . .
Read More
Posted in | No comments

Wednesday, 2 January 2008

And on January 1st EVERYBODY SPAM!

Posted on 04:43 by Unknown
Its been a while since I've looked at a virus with a date-triggered behavior change, but that seems to be the case with the one I'm currently looking into.

I spent most of the day yesterday playing with a new spamming virus which "triggered" on January 1st to begin spamming "VPXL" male organ enlargement pills, after being dormant on a machine for almost two weeks.

I would very much appreciate any reports (which will be kept anonymous) regarding how wide-spread this virus may be, or whether anyone can identify the original point of infection.

This is currently the most widely spread spam campaign being observed by our Spam Data Mine at UAB. Its the same group that has been previously using the brands "King Replica" for counterfeit watches and "EliteHerbal" for pills.

The machine I was studying became infected on December 17th, after a "drive-by infection" sent it to the website "www.injectpanel.com" where it hit a file called "/us/ret.php", which caused it to download "index[1].exe". (We are working to get this site shutdown already).

Infected machines will be easily identified (now that Jan 1 has passed), by an enormous number of outbound SMTP connections.

Infected machines will probably have a large number of files in their root directory ending in ".tmp". Some of these files may be 42,496 bytes in size, which are copies of the .exe, while others will be 0 bytes in size.

Infected machines ARE rootkitted, with a couple files of true interest:
c:\windows\system32\wsnpoem\audio.dll
c:\windows\system32\wsnpoem\video.dll

(I found these with "RootKit Revealer", a Most Useful Tool!)

Infected machines will contact on each boot "www.injectpanel.com", and may also connect on each boot "www.botsys.net".

AV vendor PREVX had received 11 copies of this virus since December 18th, most commonly called "index[1].exe".

VirusTotal received its first copy on December 30th, and had a 43% detection. It was NOT detected by ClamAV, F-Prot, McAfee, NOD, Sunbelt, or Symantec. As of Jan 1, it showed 53% detection. (17 of 32 AV products could detect the virus.)

The copy I was dealing with had the MD5:

b7f085411871026218cc30b4a6c0363e

Other secondary infections have been seen being "dropped" from injectpanel.com. Including "Nurech" (AKA "Chepvil"), which also showed only a 13 of 32 detection rate on Jan 1.

Nurech places a large number of files in the Windows\System32 directory.
Some example names were:
imapi.exe
mnmsrvc.exe
msdtc.exe
netdde.exe
alg.exe.tmp
cisvc.exe.tmp

These will be copied to a "numbered" temp file, such as:

124671.exe
147359.exe

which can be found in memory and in the C:\Windows\Temp\ directory.

The file size of these files is "8,704".

MD5 for Nurech = 337915d40c893b64ef57fe3866dadb8f

If anyone else is experiencing these viruses, I'd love to learn any more details you might be able to share, but most importantly I'm trying to gage how widespread the infection is.

Windows XP Machines infected with Nurech may demonstrate the characteristic of "falling off" networks, getting stuck in an "acquiring network device" state. (Which may be an overwhelmed TCP stack from the many many copies of "svchost" that are trying to drive TCP connections.)

Thanks for any help!

Gary Warner
Director of Research in Computer Forensics
http://www.cis.uab.edu/forensics/
Read More
Posted in | No comments

Wednesday, 26 December 2007

A Stormy Christmas and a Botnet New Year

Posted on 09:46 by Unknown
The newest round of Storm Worm Propagation emails has come out, and its
again, largely undetected malware.

The main URLs we are seeing at this point are:

uhavepostcard.com <== (majority use this one)

happycards2008.com <== (all of these dated today)

There are more than 100 samples using these two URLs so far. The first
was received December 24th at 12:10 PM. The most recent was received
just moments ago.

- -------
Subjects include:

A fresh new year
A fresh new year...
As you embrace another new year
Blasting new year
Happy 2008 To You!
Happy 2008!
Happy New Year To (emailhere)
Happy New Year To You!
Happy New Year!
It's the new Year
Joyous new year
Lots of greetings on new year
Message for new year
New Hope and New Beginnings...
New Year Ecard
New Year Postcard
New Year wishes for you
Opportunities for the new year
Wishes for the new year

---------

A scan of the current malware on VirusTotal just now showed a 37.5%
detection rate. The version scanned was 142,337 bytes and had the MD5
checksum of:

44dc7307c81eb9fe0a0cf9147a9932ef

Notable non-detections include F-Prot, Kaspersky, McAfee, and Sophos

Those detecting named the malware as follows:

AntiVir = TR/Rootkit.Gen
Avast = Win32:Zhelatin-ASX
BitDefender = DeepScan:Generic.Malware.FMH@mmign.55A134E9
ClamAV = Trojan.Zhelatin
DrWeb = Trojan.Spambot.2386
Fortinet = W32/Tibs.G@mm
Microsoft = Backdoor:WinNT/Nuwar.B!sys
NOD32v2 = probably a variant of Win32/Fuclip
Panda = suspicious file
Prevx1 = Stormy:Worm-All Variants
Symantec = Trojan.Peacomm
Webwasher = Trojan.Rootkit.Gen

PREVX.com says this version was first seen on December 26th and has been
reported by one user in Spain. (That's where VirusTotal is, so I guess
that's me and others using VirusTotal.)

A Christmas version of the Storm Worm Propagation email may still be lurking in in-boxes as employees return from their holiday vacations. The Christmas version primarily used the malware domain:

merrychristmasdude.com

and used these subject lines. Visiting those sites now actually downloads the same "happy-2008.exe" malware as the New Year propagation uses, since these are in reality the same infected computers acting as the web hosts.

The Christmas subject lines were:

Christmas Email
Cold Winter Nights
Feel the Holiday Spirit
Find Some Christmas Tail
Ho Ho Ho.s
How.s It Goin
I love this Carol!
Jingle Bells, Jingle Bells
Looking for something hot this Christmas
Merry Christmas From your Secret Santa
Merry Christmas To All
Mrs. Clause
Mrs. Clause Is Out Tonight!
Santa Said, HO HO HO
Seasons Greetings
The Perfect Christmas
The Twelve Girls of Christmas
Time for a little Christmas Cheer.
Warm Up this Christmas
Your Secret Santa

The domain names for all of these are set up in a "round robin". For instance, I use "nslookup" to query "merrychristmasdude.com" ten times in a row and get the following list of IP replies:

66.78.160.196
24.126.208.180
86.125.107.157
70.249.186.39
79.172.83.168
91.142.197.135
62.43.161.233
78.60.109.65
91.122.89.214
75.58.60.145

A much longer list of IP addresses which answer queries for all three of these domain names:

12.207.192.66
12.215.209.21
12.219.197.139
12.227.173.1
24.165.167.150
24.181.224.249
24.181.42.5
24.182.40.236
24.2.46.250
24.210.99.223
24.3.160.88
24.95.77.206
58.226.226.6
58.8.20.129
59.112.81.137
59.113.187.86
59.12.125.252
59.15.71.112
59.3.40.145
59.86.244.147
59.92.78.2
59.93.39.233
59.95.191.39
60.249.4.119
60.50.100.42
60.53.25.73
60.56.115.109
60.9.222.137
61.15.254.115
61.32.177.59
61.72.147.153
61.80.150.87
62.65.232.246
64.85.228.164
65.189.233.73
65.31.39.88
66.142.52.23
66.31.113.211
67.164.126.186
67.173.35.121
67.177.191.148
67.181.90.28
67.186.43.176
67.187.30.81
68.127.51.120
68.167.71.243
68.187.46.125
68.204.186.99
68.248.237.55
68.54.157.173
68.54.234.64
68.63.133.158
68.79.7.249
68.80.244.129
68.81.122.156
68.81.195.121
69.154.137.176
69.183.216.161
69.215.175.83
69.225.12.176
69.226.25.20
69.247.40.180
69.248.212.75
69.254.83.191
70.115.222.172
70.126.163.174
70.243.43.6
70.245.14.188
70.249.186.39
71.200.198.181
71.205.208.104
71.224.88.232
71.227.249.98
71.230.219.209
71.230.66.163
71.237.134.222
71.86.54.0
71.96.13.37
72.40.18.255
72.48.192.221
72.8.101.213
74.128.121.44
74.138.172.43
74.164.251.210
74.75.193.213
75.131.212.194
75.132.160.97
75.21.75.238
75.35.110.9
75.35.252.137
75.37.39.88
75.50.232.119
75.61.64.23
75.68.231.167
75.73.216.43
75.85.190.206
76.107.42.125
76.111.115.55
76.119.119.58
76.15.46.122
76.171.99.77
76.173.57.101
76.212.92.117
76.22.76.57
76.229.114.65
76.243.202.32
76.25.147.99
76.254.139.102
76.65.181.160
76.68.144.93
77.41.47.214
77.48.16.49
77.57.127.78
77.99.143.61
78.107.182.172
78.107.190.69
78.92.91.186
79.112.4.123
79.120.35.238
79.120.56.38
79.126.167.63
79.139.178.64
79.165.162.240
79.182.0.73
80.73.89.69
81.190.78.83
81.210.133.54
82.1.108.104
82.181.41.160
82.233.232.162
82.79.129.214
83.5.77.234
83.54.12.240
84.10.43.106
84.126.102.227
84.31.89.195
85.180.66.14
86.102.1.205
86.125.170.161
86.61.66.60
86.63.107.2
87.207.117.102
87.8.161.149
88.156.9.155
88.164.68.15
89.110.51.47
89.137.201.205
89.161.22.219
89.178.170.110
89.20.119.182
89.215.180.33
89.228.40.58
89.36.102.75
89.38.163.176
90.150.126.235
90.150.215.50
90.157.92.141
91.106.18.142
91.122.147.67
91.122.19.127
91.18.246.67
98.194.162.228
98.196.29.67
99.145.19.221
99.241.144.189
117.199.240.218
121.1.85.140
121.124.15.53
121.146.205.123
121.150.127.150
121.158.220.126
121.162.87.237
121.165.21.31
121.172.10.95
121.173.45.111
121.179.107.71
121.246.163.37
121.246.86.244
121.247.143.131
121.247.165.149
121.247.66.110
121.96.253.35
122.164.35.171
122.202.44.89
122.32.53.35
122.36.84.38
122.50.173.172
122.99.16.4
123.201.0.167
123.202.81.199
123.203.20.137
123.215.177.241
123.236.114.63
124.120.35.98
124.120.36.238
124.125.116.171
124.199.33.113
124.244.198.114
124.82.112.191
125.137.205.157
125.208.107.18
125.233.65.153
125.235.36.97
125.24.82.14
168.243.219.228
190.17.101.223
190.21.9.139
195.189.153.21
196.217.102.238
200.84.241.161
200.94.163.191
201.172.192.141
201.222.110.245
201.231.140.173
201.241.57.55
201.255.181.193
201.27.179.128
203.223.220.24
203.255.10.96
206.45.91.55
209.102.185.215
210.105.165.204
210.109.244.10
211.109.96.223
211.195.3.79
211.201.18.155
211.204.48.194
211.54.167.69
213.169.180.110
217.123.175.129
218.156.143.96
218.174.73.42
220.118.185.247
220.121.81.72
220.19.166.13
220.225.184.83
220.76.90.93
220.78.225.208
221.147.22.23
222.114.18.22
222.238.245.88
222.98.228.236

Good luck, and thanks for any help terminating the three domain names in question:


Merry Christmas and Happy New Year, CyberCrime Fighters . . .

_-_
gary warner
http://www.cis.uab.edu/forensics/
Read More
Posted in | No comments

Thursday, 13 December 2007

"Google Referrer Only" malware sites

Posted on 03:55 by Unknown
This summary is not available. Please click here to view the post.
Read More
Posted in | No comments

Saturday, 8 December 2007

Off Topic: Browser and OS Trends

Posted on 07:18 by Unknown
WARNING!! I'm going a bit off topic today.

This post started off to be about JavaScript enabled browsing by end-users. Security professionals have long recommended that JavaScript be disabled by default, and enabled only for those sites which require JavaScript and which are trusted by the user as a "Trusted Site".

In Internet Explorer this is done in a fashion that confuses most end-users, by creating a "Trusted Zone" and setting different security properties in the Trusted Zone than in the Global Zone. (Directions for using Trusted Zones are here)

In FireFox, the best way to accomplish this is by running the Plug-In "No Script", which disables scripting by default and allows the user to click to enable scripts on Trusted Sites that seem broken if they scripting is disabled. (The NoScript homepage is here)

Bottom Line: Unless a site requires Java support and you trust it, you should not be browsing with Java Enabled!

Unfortunately, as I reviewed three groups of web statistics - from visitors to this blog, from visitors to my haiku poetry website, and from visitors to my genealogy website, Almost EVERYONE had Java enabled. Between 97.7% and 98.5%!!

Then I laughed at myself as I realized that I was using Google Analytics to do that measurement, and Google Analytics doesn't record the visit unless Java is enabled. Which now has me puzzling over how ANYONE was recorded who had no Java.

But I still had some interesting, though slighly off-topic results to share with you, Dear Reader . . .




If we watch the media in its various forms, we are being bombarded with a few basic messages:
- The Age of the Macintosh is upon us
- Linux Threatens Windows
- Windows Vista is the Path to Security
- Internet Explorer 7 is the Path to Security

I thought it would be interesting to look at some statistics to see if these messages reflect the reality of the Average Internet User.

After careful reflection, I realized I don't have the ability to measure The Average Internet User, so instead I looked at some Google Analytics for three websites that I have tagged. The three are of course English-language biased, but then so is most of the media I consume, so I think that's ok.



Sample One: People who read this blog.

This blog is about CyberCrime, and usually CyberCrime in the United States. One hopes that the readers are people who care about CyberCrime and perhaps by a bit of a stretch, protecting their computers.

For the sample period I looked at there were 3,400 unique visitors to this blog from 85 countries and all 50 states, but with 78% of the readers coming from the US.












Windows88.65%
Mac7.91%
Linux3.09%
Windows breakdown
XP83%
Vista10%
20005%
Server 20031%
980.8%











Internet Explorer58.01%
FireFox34.69%
Safari4.44%
Opera1.13%
IE breakdown
IE 7.x50.24%
IE 6.x49.42%
IE 5.x0.34%





Sample Two: People who visit my haiku poetry website.

The Haiku Poetry fans, as you might imagine, are a bit different than the readers here. 6,600 unique visitors from 98 countries and all 50 states, with only 54% of the readership coming from within the US.











Windows88.49%
Mac8.86%
Linux2.53%
Windows breakdown
XP85%
Vista6%
984%
20003%











Internet Explorer67.26%
FireFox24.57%
Safari5.64%
Mozilla1.43%
IE breakdown
IE 6.x58%
IE 7.x39%
IE 5.x2%



SLIGHTLY higher Macintosh adoption (not statistically significant), slightly lower Linux adoption (also not statistically significant), but a much greater chance of using "old" Internet Explorer, not being on Vista, and still running Windows 98.




Sample Group 3: People who visit my genealogy websites

This was the smallest group, with 1200 unique visitors representing 37 countries, but with 86% of the traffic coming from within the United States. Genealogists tend to be older and thriftier people than Security professionals. Probably on a "technology" basis, they are more similar to the haiku poets than the security professionals. I included this as a hope towards a "lower tech but US based" sample, to see whether the haiku poets trends were representing their tech level, or their nation of residence.












Windows88.7%
Mac5.67%
Linux5.25%
Windows breakdown
XP86.5%
Vista7.5%
20003.2%
Server 20031.3%
981.2%











Internet Explorer70.14%
FireFox20.35%
Mozilla4.4%
Safari3.48%
IE breakdown
IE 6.x50.15%
IE 7.x49.04%
IE 5.x.08%




Conclusions?

Macintosh users, from my unscientific study, still represent less than 9% of the installed user base.

Linux users are still a small enough number for the average webmaster to safely ignore them.

Vista still represents less than 10% of the installed user base.

FireFox has an impressive market share and must be considered by all webmasters, but trails both IE 6 and IE 7 when considered individually.

Despite the security benefits of IE7, slightly less than half of those who could use it are using it. (From my experience this is because many web-based applications still don't work in IE7.)

Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Help stop the Osama bin Laden Videos on Facebook
    If you have teenage friends, or friends with poor security practices, you will probably notice that your wall has recently filled up with in...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • A Dark and STORMy Night
    Just in time for the spookiest night of the year, the Storm botnet recruitment spam switched to a Halloween flavor. On the evening of Octobe...
  • TJX Update: The San Diego Indictments
    As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust". There wer...
  • Facebook Safety & Million Member Facebook Groups
    Two of my friends today invited me to join "Million User" facebook groups. Not that it matters really, but the two groups were: P...
  • Microsoft Security Intelligence Report 2H08
    The Microsoft Security Intelligence Report for the second half of 2008 has been released (the 184 PDF version, available from http://microso...
  • Operation Open Market: The Vendors
    When we wrote last week about Operation Open Market the court documents had not yet been released in a major multi-agency Identity Theft ca...
  • First 2008 Presidential Spam Campaign?
    Does Ron Paul suddenly have a strong support base among foreign computer owners with strange names and multiple personalities? or is it poss...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile