-
E-mail trojan attack on Booking.com and online auction website Allegro.pl clients
During the last few days, we have observed an attack on Polish users of auction website Allegro.pl and a hotel reservation portal – Booking.com. These attacks were directed at Polish users. Victims received a personalized e-mail that informed them that their account has been blocked either due to the …
Read more -
A look on the VBKlip “battlefield”
On multiple occasions we informed about a new threat to Polish online banking users, which we named VBKlip. This is a new kind of malware that substitutes the bank account number that has been copied to the clipboard. This works when we try to, e.g. pay a bill, and …
Read more -
Polish team wins NATO exercise
Locked Shields is an readiness testing exercise where security specialists teams from 17 countries compete defending a realistically simulated network from outside attacks. This year the winning team was from Poland, and it included representatives of CERT Polska. Other competitors were coming from Estonia, Finland, NATO CIRC, Italy, Spain, Germany …
Read more -
Annual cert.pl report
We have published our annual report, describing CERT Polska activities in 2013. The highlights of the document are: our botnets takeover summary, our malware analyses results, stopping rogue registrar Domain Silver Inc. and results of botnet sizes estimations done using new methodology. Full document in English can be downloaded HERE …
Read more -
Estimating size of the botnets in Poland
Annual CERT Polska report will soon be available on our website for download. This year we decided not only to include statistical data (which will be moved to a separate section), but also describe trends and events that were important according to us and were observed in the last year …
Read more -
Testing Heartbleed from the client-side perspective
In the last week or so infosec headlines were dominated by reports in the OpenSSL vulnerability (CVE-2014-0160). We blogged on what the situation looked like in regard to Polish services and address space (and TOR as well). It is worth noting however that the OpenSSL library is used not only …
Read more -
11 April 2014 CERT Polska
Heartbleed in TOR (and in Poland)
In the last few days the most popular vulnerability seems to be CVE-2014-0160. This two years old vulnerability was in OpenSSL library, versions 1.0.1a-f, and allows to read a part of the memory of the process. The use of this library is very prevalent not only in the …
Read more -
07 April 2014 CERT Polska
Honeynet Project Workshop CrackMe Solution
We have announced a CrackMe challenge, which allowed you to win a free pass for the Honeynet Workshop 2014 in Warsaw. Today, we closed the challenge, because the winners have already submitted 10 flags. The winners are Dariusz Tytko (from Poland) and @_zairon_, who also posted his solution to our …
Read more -
SECURE 2014 Call for Speakers is Now Open
SECURE 2014 is a conference dedicated entirely to IT security and addressed to administrators, security team members and practitioners in this field. SECURE’s unique feature is the organisers’ commitment to providing participants with reliable information about everything that is current and meaningful in IT security. A high professional level …
Read more -
02 April 2014 CERT Polska
Win a Honeynet Workshop pass! (UPDATE)
Do you want to attend the Honeynet Workshop Conference in Warsaw? If you solve our CrackMe and you will be the first one to do, you can win a free conference pass. The task is to find “flags” – strings connected to the file that we made specifically for this competition …
Read more