mardi 13 novembre 2012

Nouvelle alerte phishing ING

Sujet du mail : ING Alert - Uw Internet Bankieren is geblokkeerd
From : ING sfernandez@inia.gob.ve

Premier indice : l'adresse email, qui n'appartient pas à ing.


Les headers


Authentication-Results: mx.google.com; spf=neutral (google.com: 193.109.184.93 is neither permitted nor denied by best guess record for domain of sfernandez@inia.gob.ve) smtp.mail=sfernandez@inia.gob.ve
Received: (qmail 12895 invoked by uid 507); 13 Nov 2012 15:26:39 +0100
X-Spam-Checker-Version: SpamAssassin 3.2.5 (2008-06-10) on
 louis.schedom-europe.net
X-Spam-Level: *****
X-Spam-Status: No, score=5.9 required=15.0 tests=FH_DATE_PAST_20XX,
 HTML_IMAGE_ONLY_20,HTML_MESSAGE,RAZOR2_CHECK,RCVD_IN_SORBS_WEB
 autolearn=disabled version=3.2.5

Received: (qmail 10796 invoked by uid 507); 13 Nov 2012 15:26:35 +0100
Received: from canaima.inia.gob.ve (190.202.124.227)
  by eline.schedom-europe.net with SMTP; 13 Nov 2012 15:26:29 +0100
Received: from localhost (localhost.localdomain [127.0.0.1])
 by canaima.inia.gob.ve (Postfix) with ESMTP id 947A010433B5;
 Tue, 13 Nov 2012 09:51:21 -0430 (VET)
X-Virus-Scanned: amavisd-new at inia.gob.ve
Received: from canaima.inia.gob.ve ([127.0.0.1])
 by localhost (canaima.inia.gob.ve [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id DCWfzo76t63Z; Tue, 13 Nov 2012 09:51:21 -0430 (VET)
Received: from canaima.inia.gob.ve (canaima.inia.gob.ve [190.202.124.227])
 by canaima.inia.gob.ve (Postfix) with ESMTP id 3F08910433A7;
 Tue, 13 Nov 2012 09:51:20 -0430 (VET)
Date: Tue, 13 Nov 2012 09:51:20 -0430 (VET)
From: ING 
Message-ID: <1684019547 .5094.1352816480172.javamail.root=".5094.1352816480172.javamail.root" canaima.inia.gob.ve="canaima.inia.gob.ve">
Subject: ING Alert - Uw Internet Bankieren is geblokkeerd
MIME-Version: 1.0
Content-Type: multipart/alternative; 
 boundary="----=_Part_5093_708474645.1352816480169"
X-Originating-IP: [41.71.190.169]
X-Mailer: Zimbra 6.0.9_GA_2686 (zclient/6.0.9_GA_2686)
To: undisclosed-recipients:;


================
En footer de l'email, on fait même mention à la librairie SSL utilisée par leur logiciel HomeBank

Copyright © 2012 ING - Alle rechten voorbehouden | ING Electronic Banking products include SSLEay 0.8.1 ©


===========
Des conseils sur le site d'ing

Que faire si vous détectez une tentative de phishing ?

  1. Contactez le Home'Bank Helpdesk (02/464.60.02), même si vous n'avez pas introduit de données confidentielles.
  2. Envoyez une copie du message à be-irm-phishing@ing.be

Comment installer Steam sous Ubuntu ?

Toutes les infos sur le site de Korben
http://korben.info/installer-beta-steam-linux.html

N'oubilez pas de checker les commentaires pour quelques
liens de démos à télécharger ...

mardi c'est ... patch day Microsoft


Beaucoup de failles critiques.
Patchs à installer au plus vite ....

  • Windows XP: 3x critical
  • Windows Vista: 4x critical, 1x moderate
  • Windows 7: 4x critical, 1x moderate
  • Windows 8: 3x critical
  • Windows RT:  1x critical, 1x important
  • Windows Server 2003: 3x critical
  • Windows Server 2008: 3x critical, 2x moderate
  • Windows server 2008 R2: 3x critical, 2x moderate
  • Windows Server 2012: 3x critical



source
http://www.ghacks.net/2012/11/13/microsoft-security-bulletins-for-november-2012-released/
https://technet.microsoft.com/en-us/security/bulletin/ms12-075