Dropbox’s URL shortener abused by spammers

Spammers are abusing a Dropbox feature that lets users share a shortened link, directing people to websites selling questionable pharmaceuticals, according to security vendor Symantec.

Dropbox, the file-sharing and synchronisation service, has a public folder that is dedicated to sharing content. Dropbox’s URL (uniform resource locator) shortening service can be used to create links to content in that public folder.

Spammers have seized on this and are creating shortened links to images stored in the public folder. The images contain a link to online pharmaceutical retailers, wrote Nick Johnston, a senior software engineer at Symantec.

We saw over 1,200 unique Dropbox URLs being used in spam over a 48-hour period, Johnston wrote. We have informed Dropbox, providing them with the full list of URLs — via redwolf.newsvine.com

E-health record will be hacked, says AusCERT

One of Australia’s top IT security organisations has warned that the Federal Government’s flagship e-health records project is likely to be broken into, with Australians’ medical and identity information to be used for fraud and other criminal activities.

AusCERT, Australia’s Computer Emergency Response Team, which is not associated with the Government, in its submission to an inquiry about the legislation dated in January (PDF), criticised the Government’s Personally Controlled Electronic Health Records (PCEHR) Bill (2011). In its commitment to protecting the privacy and security of Australian Internet users, AusCERT has expressed concern that miscreants could potentially use the PCEHR for identity theft and fraud. The submission was first reported by the AustralianIT.

AusCERT opines that enabling accessibility to personal identifying information in the form of the PCEHR from personal computers over the Internet will only worsen an ongoing problem that will make Australians vulnerable to fraud and identity theft. The submission focuses on the use of untrustworthy end point computers and mobile devices, which when compromised, will enable attackers exert full control over the PCEHR to look at or change its contents with the same privileges as the owner or authorised users — via redwolf.newsvine.com

iiNet applies for .iinet TLD

iiNet will become the first Australian telecommunications company to apply for its own top-level domain (TLD), seeking to obtain the .iinet TLD.

The applications for TLDs close on 12 April, and iiNet has announced that it will partner with ARI Registry Services to get hold of the .iinet TLD.

The initial application will set iiNet back US$185,000, and, if iiNet gets its TLD, it will be required to pay an annual fee of US$25,000. The first TLDs will come into use in 2013 — via redwolf.newsvine.com

Mysterious code stumps researchers

Kaspersky security researchers analysing the Duqu malware have unexpectedly hit a wall, stumped by code that appears to be written in an unknown programming language, and are now appealing to the public for anyone that might recognise it to come forward.

Kaspersky Lab’s analysis has already revealed that Duqu is likely created by the same authors as Stuxnet, by revealing the similarities between the platforms used to create both trojans. However, in their most recent research, security experts Igor Sourmenkov and Costin Raiu have come across code that doesn’t appear to be written in any language they’ve seen before.

The Duqu trojan uses a dynamic link library (DLL) to communicate with a command and control server after it has infected a victim’s machine. This DLL operates independently of Duqu’s other modules and provides the trojan with several vectors through which it can phone home, such as through an HTTP server, via a proxy or through other network sockets.

It also delivers stolen information from the victim’s machine to the command and control server and enables Duqu to spread to other machines on the network — via redwolf.newsvine.com

Silver Eyes / Cafe Racer Dreams

The twelfth build from CRD of Spain shows how: it’s a 2009 Triumph Bonneville with a strong café racer slant. A few well-thought-out tweaks to the Hinckley twin have had a radical effect on its appearance — and desirability — via Bike EXIF

This 14-Year-Old Girl Just Bought A House In Florida

Meet Willow Tufano, age 14: Lady Gaga fan, animal lover, landlord.

One day, she went to a house that an investor wanted to flip. It was filled with all kinds of stuff! Willow says. I was like, ‘I can sell this stuff if he’d want to let me have it.’

That was fine with the investor. So Willow sold the furniture and appliances from the house on Craigslist. She did the same thing with a bunch more houses. After a while, she was clearing about $500 a month, and saving a lot of it.

One day, Willow’s mom, Shannon, saw a two-bedroom, concrete-block home on auction for $12,000 — down from $100,000 at the peak of the bubble. Shannon was telling her husband about the house, when Willow piped up.

I was like, ‘What if I bought a house? That would be crazy,’ Willow says.

Willow wound up splitting the house with her mom. Willow plans to buy her mom out in the next few years, and put her name on the title when she turns 18 — via redwolf.newsvine.com

Bomb Runner / Rough Crafts

The Bomb Runner is the second in a planned series of Guerilla bikes, which will have Rough Crafts‘ signature blacked-out look and components, but different build styles. The base bike is a 2011-model Sportster Forty-Eight 1200, but this time it has a different silhouette, a higher rear shock and tail section, a lightly modified frame, and a more aggressive lean-forward look — via Bike EXIF

Secret of the flashing Amazon jungle Drobo Explained

Drobo, the stylish desktop and small rackable storage box supplier, is finally adding flash drives to its rack-mounted box plus Amazon cloud storage for backup.

Drobo’s B1200i 12-slot, iSCSI SAN product for small and medium business users was announced with SSD support in February 2011. Thirteen months later, it has arrived — SSD qualification is a lengthy process — via redwolf.newsvine.com

Spider army on the retreat from NSW floodwaters

Arachnophobes beware. There is a silent army on the move in flooded New South Wales.

Floodwaters have stirred up what appears to be millions of spiders around Wagga Wagga and the creepy crawlies are heading for higher ground.

Residents taking refuge from flood and spider in the Red Steer pub say you cannot walk down the road without swarms of tiny brown spiders crawling up your legs, and in their escape they have left entire paddocks and trees swathed in silver silk — via redwolf.newsvine.com