KL’s Airport Gets Infected

By | November 22, 2011

image

If there’s one place you hope you won’t get infected by a computer virus, it’s an airport.

It’s not just that the virus may fiddle with your departure times; it’s the wider possibility that the virus may have infected more sensitive parts of the airport: ticketing, say, or—heaven forbid—flight control.

Kuala Lumpur International Airport—Malaysia’s main international airport—was on Friday infected by the W32.Downadup worm, which exploits a vulnerability in Windows Microsoft patched back in October. The worm, according to Symantec, does a number of things, creating an http server on the compromised computer, deletes restore points, downloads other file and then starts spreading itself to other computers.

image

Enlargement of the photo above. The notification says Symantec Antivirus has found the worm, but has not been able to clean or quarantine the file.

KL airport clearly isn’t keeping a tight rein on its security. The virus alert pictured above is at least 12 hours old and the vulnerability it exploits had been patched up a month before. Says Graham Cluley of UK-based security software company Sophos: “What’s disturbing to me is that over a month later, the airport hasn’t applied what was declared to be an extremely critical patch, and one which is being exploited by malware in the wild.”

What’s more worrying is that this isn’t the first time. It’s the first time I’ve noticed an infection on their departures/arrivals board, but one traveller spotted something similar a year and a half ago, with a Symantec Antivirus message popping up on one of the monitors. I saw a Symantec Antivirus message on one monitor that said it had “encountered a problem and needs to close”, suggesting that the worm had succeeded in disabling the airport’s own antivirus defences:

image

So how serious is all this? Cluely says: “Well, it’s obviously a nuisance to many people, and maybe could cause some disruption.. but I think this is just the most “visible” sign of what may be a more widespread infection inside the airport.  I would be more concerned if ticketing and other computer systems were affected by the same attack.”

He points to computer viruses affecting other airports in recent years: In 2003, Continental Airlines checkin desks were knocked out by the Slammer worm. A year later, Sasser was blamed for leaving 300,000 Australian commuters stranded, and BA flights were also delayed.

For me, the bottom line about airports and air travel is confidence. As a traveler I need to feel confident that the people deciding which planes I fly and when are on top of basic security issues. And that doesn’t mean just frisking me at the gate. It also means keeping the computer systems that run the airport safe. This is probably just sloppy computer habits but what if it wasn’t? What if it was a worm preparing for a much more targeted threat, aimed specifically at air traffic?

(I’ve asked KL International Airport and Symantec for comment.)

The Periphery of the Brand

By | November 22, 2011

(Updated Dec 8 with comment from IKEA)

image

I’m always amazed at how companies work really, really hard on their brand, and then blow it all on the periphery.

The pictures here are taken from the Milton Keynes branch of IKEA, an otherwise wonderful store that caters to kids, has the usual IKEA range of stuff and generally lives up to the company’s brand in spades.

image

Except at the entrance. The trash repository is right in front of the door, and is littered with cigarette butts, burger wrappers, ash, IKEA cups and a half-drunk glass of orange that, presumably, came from the IKEA cafeteria:

image

It stands out like a sore thumb, depressing newcomers and those leaving the store alike. At a guess it’s not maintained, or maintained enough, because it’s just beyond the scope of the store, and so is probably not, strictly speaking, the responsibility of the store. There’s probably no guideline for this sort of situation in the IKEA manual. But IKEA is the only user of the building, and the stuff being left here is all from IKEA shoppers—some of it sporting the IKEA logo.

The periphery of the brand is often just beyond the reach of all the normal boxes a manager would tick in ensuring the brand is looking good. But that is often the exact point of contact for a customer—coloring either their first impression or the lasting one they have when they leave.

IKEA have promised to address the problem: In an email, they said: “At IKEA Milton Keynes, we strive to maintain high standards of tidiness across our store both inside and out to give our customers the best possible shopping experience. On this occasion, the maintenance of the bin does not reflect these standards however, we are addressing this, and are stepping up measures to make the necessary improvements.”

Facebook Scams: Not Out of the Woods

By | November 22, 2011

Facebook may have just won a theoretical warchest from a spammer, but it’s not put its house in order when it comes to scams. Indeed, I suspect they’re getting worse. Now you can get infected without even having to visit your Facebook account.

What happens is that, if you have set your profile to receive email updates when someone sends you a message on Facebook, these trojan scams actually make their way direct into your inbox. Facebook is just the vector:

Here’s a message, as it looks in Gmail:

image

Click on that link and it takes you, not to the Facebook message page, but straight to the dodgy website. In this case the website is still active. It will have a name like YuoTube:

image

and a YouTube-like interface:

image

The message in the ‘player’ says “Your version of Flash Player is out of date.” Without you doing anything the download window will appear:

image

Of course, if you install that you’re in trouble. But are you in trouble if you’ve already visited the page? I’m still working on that.

The Undignified Death of Social Networks

By | November 22, 2011

I’m intrigued, and slightly depressed, at how social networking sites deteriorate so quickly into what are little more than scams. I think it started about a year ago, when a number of sites started pulling the stops out to build up membership.

Now, it seems, it’s all about the money. Take Quechup, for example, which has never had a very good reputation, though some say it’s undeserved. I don’t think anyone would try to argue that now.

I opened an account at Quechup about a year ago, and left it, with no friends. no connections, no activity (a bit like my real life.) I didn’t get anything until last month. In the past month I’ve received more than 30 messages. All of them from people I don’t know; all of them, from the subject line, spam:

image

So what’s the scam, then?

Well, if you’re fool enough to open one of these messages, that’s your limit. Suddenly your inbox looks like this:

image

The message is basically that you can’t open any messages until you upgrade your membership:

image 

Upgrading, of course, costs. Not a lot, but if you’re curious to find out who’s been scamming you, sorry, flirting with you, you have to cough up:

image

My question is this: Who is behind the spam in my inbox?

Admittedly, my profile is a bit provocative:

image

Still. One can’t help feeling that either the spam is being allowed by Quechup as a money-making exercise, or, the only other explanation I can think of, it’s spamming its members with silly messages in the hope they’ll be curious enough to upgrade and read them.

Either way, it’s a social network that’s dead from the neck up.

Sad, really.