Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

John McDonald

John McDonald
Member for: 6 years 33 weeks
Contact: Send this user an email
Member for: 6 years 33 weeks
Contribution Stats
0
Solutions
0
Forum Threads
2
Comments
15
Blog Entries
0
Ideas
0
Articles
0
Videos
0
Downloads
0
Events
0
Groups Joined

John McDonald's Activity

Show:
New blog entry 30 Jun 2011
Microsoft 社にいる友人が最近、同社で Popureb と呼ばれているカテゴリから見つかった、ブートキットのトロイの木馬の新しい亜種に関する ブログ記事を書いています 。この亜種 Win32/Popureb.E は、悪質なマスターブートレコード(MBR)や他の悪質なコンポーネントの除去を妨げるドライバコンポーネントを組み込みます。 Microsoft 社のブログに書かれた以下の 1 文が意味するところをすばやく察知したテクニカルライターがいます。 「お使いのシステムが Trojan:Win32/Popureb.E に感染した場合は、Windows 回復コンソ
New blog entry 30 Jun 2011
先日、このブログの別の担当者から、6 月のマイクロソフト月例パッチで公開された脆弱性のひとつが現在 悪用され、被害が出ている という報告がありました。こうした場合の常として、シマンテックでは何が起きるかを観察するために、ハニーポットコンピュータでこの悪用による危殆化を再現してみることにしました。 この悪用について最初に注目したのは、調査のために転送されてきた、あるユーザー宛の電子メールメッセージです。このメッセージは利用者の多い Web メールサービス上にホストされているアカウントから送信され、送信者は中国の大学生と称していますが、文法は誤りだらけでした。メールは、特定の話題に
New blog entry 29 Jun 2011
A colleague of mine recently wrote about one of the June “Microsoft Tuesday” vulnerabilities being exploited in the wild . Because we're a bit like that, we decided to allow the exploit to compromise one of our honeypot computers so we could observe what happened. The exploit first cam
New blog entry 29 Jun 2011
Our friends at Microsoft recently blogged about a new variant of a bootkit Trojan from the family they call Popureb. The variant, Win32/Popureb.E, introduced a driver component to prevent a malicious master boot record (MBR) and other malicious components from being cleaned. At least one
New blog entry 15 Jun 2010
Recap If you missed Parts I and II of this blog series, you can find them here and here . I finished Part II promising to reveal the organization behind this sorry saga.   Following the trail The trail really wasn’t very hard to follow. When we looked up some of the IP a
New blog entry 11 Jun 2010
Recap I left off promising to reveal the mysterious application that was consuming my friend Derek’s bandwidth and trying to figure out how it got on his computer in the first place. Please note that all images (except one from this point on) were not actually taken from Derek’s comput
New blog entry 02 Jun 2010
Introduction We post a lot of blogs here about all kinds of threats, including pervasive botnets, rootkits, rogue apps, the latest flavor of spam doing the rounds, and so on and so forth. So, for a change I thought I’d talk about something a bit more personal that happened closer to home—s
New blog entry 03 May 2010
Email hoaxes are nothing new, dating back at least as far as 1994 with what is widely believed to have been the first email hoax—referred to as the "Goodtimes virus" or the "Goodtimes virus hoax" after the subject of the email. The message in the early version was short and to
New blog entry 11 Apr 2010
Almost a year has passed since we last blogged about a new undocumented vulnerability in JustSystems’ Ichitaro software and along with the ever stunning new pink and white blossoms of spring, 2010’s first offering has surfaced. As we have reported on several occasions over the years (see below) Ic
New blog entry 21 Dec 2009
Theft As we discussed in Part I , the primary purpose of Qakbot is to steal information from the compromised computer. In addition to targeting login details for FTP, POP3 and IMAP, the worm also attempts to steal Cookies - not only regular browser session cookies but also Flash cookies.
New blog entry 22 Nov 2009
It's only been a couple of short weeks since the iPhone background-changing incident that took the world by storm (well, parts of Australia at least), but already a Dutch ISP has reported  what would be the first malicious iPhone worm to be seen in the wild. Unfortunate news to be sure
New blog entry 01 Oct 2009
There has been a flurry of news articles over the past few days on what the media appears to have labeled the Mariposa botnet, after the name a Canadian information security firm used for this particular threat. The ‘butterfly’ in the title of this article refers to the fact that the threat is bel
New blog entry 19 Aug 2009
It seems someone has it in for Delphi. Or at least older Delphi environments and programs compiled using them. As has been reported, there is a threat on the loose that targets Delphi development environments, specifically versions 4 through 7. To provide some brief background, Delphi is a so
New blog entry 29 Jul 2009
A lot of water has passed under the proverbial bridge since the Donut virus of 2002. W32.Donut was of course a concept virus (named "dotNET" by its creator) to demonstrate weaknesses in the Microsoft .NET architecture that, at the time, was brand new. Although Microsoft started devel
New blog entry 17 Mar 2009
Well, it's that time of year again. April is the first month of the fiscal year in Japan, and a time when people look forward to the breath-taking beauty of cherry blossoms—known as sakura in Japan—slowly covering the country from end to end for an all-too-brief few weeks. Unfortunately i