Author: Zachariah Boren

  • Bring your BIG idea to life!

    03.04.10 08:11 AM

    Enter now to see your little idea turned into a BIG Idea! CliffordThe Big Red Dog® is looking for individuals and/or community groupsdoing great things to make a difference in their community.

    The BE BIG!TM Campaignis designed to communicate that small, simple actions can make a BIGdifference. The campaign invites everyone, big and small, to takeaction and raise awareness for how Clifford The Big Red Dog's BIG IDEAS(Share, Play Fair, Have Respect, Work Together, Be Responsible, BeTruthful, Be Kind, Believe in Yourself, Be a Good Friend, Help Others)can make the world a better place.

    Clifford welcomes volunteers,schools or community partners to enter for a chance to see their BIGidea win $75,000 in community grants!

    Scholastic's "Be Big inYour Community" Contest launched on February 1, 2010 and will continueaccepting entries until June 30, 2010.

    30 finalists will be selected by a multi-tiered judging process:

    • One entry will be honored with a $25,000 community grant
    • Ten entries will be honored with a $2,500 community grant
    • Nineteen entries will be honored with a $1315.79 community grant

    Allprojects will be executed with the help of Scholastic, HandsOn Networkaffiliates and BE BIG's corporate sponsor, American Family Insurance!

    Enter Now!

    http://community.kiwanisone.org/blog…a-to-life.aspx

  • Malicious Web Site / Malicious Code: BBS of Sougou Compromised

    03.01.10 04:00 PM

    Websense® Security Labs? ThreatSeeker? Network has discovered that the BBS of Sougou has been compromised.

    The Sougou BBS home page and other pages on the site have been injected with a malicious script. The script creates an IFrame that redirects users to an exploit site: a 5-day old domain at [snip]ow.info. The latter performs some checks before delivering the exploits, in order to subvert any analysis attempts.

    At the time of writing this alert, the BBS of Sougou is still injected with the malicious script, but the exploit site is down. This could change at any moment.

    This is the injected code in the home page and its contents:

    Here is the exploit page:

    Websense Messaging and Websense Web Security customers are protected against this attack.

    http://securitylabs.websense.com/con…erts/3574.aspx

  • 2009 Kiwanis Chatsworth Holiday Parade

    On December 13, 2009 the Kiwanis Club Of Chatsworth hosted the 26th Annual Chatsworth Holiday Parade & Festival.

    Chatsworth Kiwanis are part of a worldwide organization of volunteers dedicated in providing positive change to one community, one child at a time. We meet at Los Toros Mexican Restaurant located at 21743 Devonshire St. on Tuesday at 7:00 pm. Take this opportunity to fellowship and network and see where you an affect positive change in your community.

    2009 Kiwanis Chatsworth Holiday Parade Photos

    – (slideshow) 5 sec

    Parade Started @ 1:00 PM
    Traveling East on Devonshire St. from
    Jordan Ave to Lurline Ave

    Festival: 12:00PM – 5:00PM
    @ Mason Ave and Devonshire St

    Live Music, Performers, Holiday Shopping, Arts and Crafts, Pictures with Santa, Children’s Area, Award Ceremony and much more !

    Thank You !!!!
    ——————–
    Assemblyman Cameron Smyth 38 Dristict
    Bent Up Cycles
    Big Band
    Birmingham Charter High School
    Bob Michaels
    Bomber WWII
    Boy Scouts Pack 226
    C.E.M.P.
    Candy Cat
    Canoga Park Rifle Drill Team
    Carolyn Miller
    Chabad Of Chatsworth
    Kevin Huling
    Chatsworth Business District
    Chatsworth Chiefs Track Field
    Chatsworth Coordinating Council
    Chatsworth High School Band
    Chatsworth Hills Academy
    Chatsworth Historical Society
    Chatsworth Junior Baseball League
    Chatsworth Karate Studio
    Chatsworth Kiwanis Key Club
    Chatsworth Kiwanis
    Chatsworth Neighborhood Council
    Chatsworth Post Office
    Chatsworth Sports
    Chatsworth/Porter Ranch Chamber of Commerce
    Chime Charter Middle School
    Church Of Rocky Peak
    Classic Chevy Of Southern California
    Cleveland Dance & Drill Team
    Cub Scouts Pack 466
    Equestrian Trails
    Eternal Youth
    Fire Engine 29
    Imagine It
    International Taekwondo College
    John Eudes Church
    Jose Ruiseco
    Joseph Sulzinger
    Kay Elder
    Kennedy High School Cougars Band
    Kings Taekwondo
    Kiwanis Clubs Division 25
    Kiwanis DIV25 Lt. Gov Nicolas Lucia Montano
    Krav Maga
    La County Sheriff Dept. Mounted Posse
    Lapd – Senior Lead Officer Dan Del Valle
    Lapd – Devonshire Mounted Guard
    Lawrence Middle School
    Los Toros
    Marage Patka Dance Studio
    Miss Ajax Troop 1622
    Mitch Englander
    Oryla Ramey
    Our Community School
    Relay For Life
    Saju Francis Kaithathara
    San Juan Eudes
    Santa
    Sausage Masters
    Search & Rescue
    St. John Eudes
    Sue & Bill Moeller
    Teremok Pre-School
    The Farm
    Veterans Industries – Dr. Pat Lamparello
    Woodland Hills Shrine Club

  • Malicious Web Site / Malicious Code: Blackhat SEO turns to PDF with Chile and Hawaii

    02.27.10 04:00 PM

    Over 13% of all searches on Google looking for popular and trending topics will lead to malicious links and searching for the latest news on the earthquake in Chile and the tsunami hitting Hawaii are no exception. Both are now used to lure people into downloading fake antivirus products.

    Usually the links in the search results look like ordinary links pointing to regular web pages. This time the bad guys have changed tactics to make their search results look even more convincing, by tricking Google into thinking it’s a PDF file.


    As you can see above Google tells you the file format is PDF and not HTML. That’s not true, it is infact a regular HTML page that when visited will redirect the user to a page that looks like this – just another rogue AV fake scanning page. This one, just like the majority or rogue AV sites we have seen this week, is in the .IN TLD which is the top-level domain for India.

    By making the search result look like a PDF it gives the link more authenticity. Perhaps it’s a research paper or at least a more well written article. The likelihood that a user will click on these type of links is probably higher than if it were just another random web link.

    This is the first time we’ve seen the attackers use this approach but considering how aggressive the rogue AV gangs are, it’s not a surprise that they continue to refine their techniques to get people to "buy" their products.

    The Rogue AV file itself is currently detected by 26.20% of the antivirus engines used by VirusTotal.

    Websense® Messaging and Websense Web Security customers are protected against this attack.

    http://securitylabs.websense.com/con…erts/3568.aspx

  • Malicious Web Site / Malicious Code: Searching For Joannie Rochette Leads To Rogue AV

    02.25.10 04:00 PM

    Websense Security Labs? ThreatSeeker? Network has detected that the black hat Search Engine Optimization (SEO) techniques are abusing the name of an Olympic figure skater who is very popular in recent news.

    Joannie Rochette is a Canadian figure skater and the 2009 world silver medallist. In the 2010 Winter Olympics in Vancouver, despite the loss of her mother just 48 hours before her competition, she delivered a sensational performance and qualified to compete for gold.

    The bad guys still took advantage of this tragic incident and used it in the infamous Black SEO poisoning attacks. Searching for Joannie Rochette in reputable search engines leads to rogue AV.

    This use of the Black SEO technique is even more pertinent now that the results have been announced, with Rochette receiving a bronze medal for her performance.

    Once the victim clicks on the poisoned search results, he/she is redirected to the rogue AV page, and a fake Anti-virus executable asks for the victim’s confirmation before being downloaded.

    This isn’t the first time Black SEO attacks target events and figures related to the olympics this year.

    Websense® Messaging and Websense Web Security customers are protected against this attack.

    http://securitylabs.websense.com/con…erts/3561.aspx

  • Malicious Web Site / Malicious Code: Bloom Box Black SEO

    02.21.10 04:00 PM

    Websense Security Labs? ThreatSeeker? Network has detected that search terms related to the Bloom Energy and its Bloombox Fuel Cell have become the latest target for Blackhat SEO poisoning attacks.

    Bloom Box is a breakthrough technology in the energy sector that could revolutionize the way electricity is generated today. As people become interested in finding more information on this technology, related search terms are currently gaining momentum, and as they do so Blackhat SEO attacks are starting to climb up the search result listings.

    At the moment, according to the VirusTotal report only 10% of antivirus products are detecting the threat.

    Video of the Bloom Box SEO in action:

    Websense® Messaging and Websense Web Security customers are protected against this attack.

    http://securitylabs.websense.com/con…erts/3554.aspx

  • Cirque du Soleil tickets selling fast

    02.19.10 11:44 AM

    Cirque du Soleil will bring adventure to the 95th Annual Kiwanis International Convention with performances from its production of KÀ. An epic confrontation between good and evil, the show combines acrobatic performances, martial arts techniques, dance, puppetry and multimedia to tell the story of twins who embark on a perilous journey.

    Don't miss your chance to see Cirque du Soleil live in Vegas! This event will sell out. Register today to attend the 2010 Kiwanis convention and choose Cirque du Soleil for an evening of entertainment in the ticketed events section of the registration form.

    http://community.kiwanisone.org/blog…ling-fast.aspx

  • Do-it-yourself: create a club brochure

    02.19.10 11:26 AM

    Promote your club with Kiwanis International's new customizable brochure. The trifold template has space for you to list your club's name, contact information, meeting place and time and service projects and is available in the following languages:

    Members may print the brochures on their personal computers or take them to a print shop.

    http://community.kiwanisone.org/blog…-brochure.aspx

  • Malicious Web Site / Malicious Code: Microsoft’s Ninemsn Australia Web Site Compromis

    02.15.10 04:00 PM

    Websense Security Labs? ThreatSeeker? Network has detected that the ninemsn support Web site (ninemsn.com.au) has been compromised and injected with malicious code. The malicious code was identified to be part of the Gumblar mass injections, and the injected code is hidden deep within the ninemsn ad engine, served on request. The injected code leads to a site that has also been compromised by Gumblar. The compromised code is hidden specifically within the "Women’s Weekly" banner script. Other ad banners are not affected.

    Screenshot of the Web site:

    Screenshot of the ad element:

    At this time, the malicious code isn’t available or reachable, but this could change at any time. An interesting implication is that this ad can be dynamically served on multiple Web pages within ninemsn. This is unlike a typical injection where Web sites are compromised in a single static page; in this case, the infected banner ad can be pulled to various locations within the site, serving its malicious purpose silently.

    Ninemsn, a joint venture between PBL Media and Microsoft, is one of the most visited portal Web sites (Alexa traffic rank 573) delivering online and mobile content, news, information, entertainment, and social networking capabilities.

    We contacted Microsoft when we discovered the attack and the ad banner has now been removed from the ninemsn support Web site.

    Websense® Messaging and Websense Web Security customers are protected against this attack.

    http://securitylabs.websense.com/con…erts/3552.aspx

  • Get your club’s new members connected quickly

    02.12.10 07:26 AM

    What does your Kiwanis club do to welcome new members into the fold? No doubt you go out of your way to make them feel special. One way to welcome new Kiwanians is to connect them as soon as possible to all the benefits of a global organization.

    When reporting new memberships to Kiwanis International, be sure your club secretary includes the new member's e-mail address. Kiwanis International will then send the member a link to a Web site geared for new Kiwanians. This new-member welcome page provides a ton of information and resources to help members jump-start their year.

    And did you know that anyone in your club can download a new member card at www.KiwanisOne.org/membercards? Coming soon-a multi-card layout to complement your growth goals!

    http://community.kiwanisone.org/blog…d-quickly.aspx

  • Kiwanis Service Leadership Programs’ winter meeting: What’s the buzz?

    02.12.10 07:23 AM

    Last month, more than 200 Kiwanis Service Leadership program district administrators, chairmen and coordinators met in Denver, Colorado, with Kiwanis International staff from Circle K, Key Club, Key Leader, Builders Club, Kiwanis Kids and Aktion Club to share news and ideas. Keynote speaker Dan Roam, author of The Back of the Napkin: Solving Problems and Selling Ideas with Pictures put everyone in a creative spirit. The goal of the gathering? To make sure the buzz and ideas energize Service Leadership clubs around the world. Here are a few of the hot topics:

    Social media: Are you using it to communicate with your clubs? Here are some links to social media resources:

    • Twitter in plain English
    • Social media in plain English
    • How to Sign up for Facebook

    Growth: Did you catch all the new growth materials at www.kiwanis.org/charter? Plus: Support your SLPs with the valuable tools at www.kiwanisone.org/advisor.

    Teamwork: How's it working for your club? Get tips, share ideas and find resources at Kiwanisteambuilding.wikispaces.com

    Next year's SLP district administrator's conference be January 21-23 (that's 2011).

    http://community.kiwanisone.org/blog…-the-buzz.aspx

  • Malicious Web Site / Malicious Code: Spammers already using Google Buzz

    02.10.10 04:00 PM

    With all the buzz this week about Google Buzz, we were just waiting for malicious activity to show up on the newly launched service. We didn’t quite expect it to happen this fast. Today we saw the first spam using Google Buzz to spread a message about smoking:

    The spammer is already following 237 people, and we can only imagine that he or she has sent similar messages to all of them. This particular message leads to a site hosted on a free Web hosting service talking about how to quit smoking.

    When Twitter was launched, it took a while before it was used to send spam and other malicious messages. In this case, it only took two days. It’s clear that the bad guys have learned from their experience using social networks to distribute these type of messages.

    We hope that Google is geared up for dealing with the volume of spam it’s bound to see on the new service. Until then, we advise users to be careful, as usual, when clicking on unknown links.

    http://securitylabs.websense.com/con…erts/3551.aspx

  • Malicious Web Site / Malicious Code: Zeus targeted attacks continue

    02.10.10 04:00 PM

    Websense Security Labs? ThreatSeeker? Network has discovered a follow up attack on Zeus campaign targeting government departments. Its research shows that once again the campaign is targeting workers from government and military departments globally.

    Figure 1 – Zeus Campaign:

    The Websense ThreatSeeker Network has seen thousands of emails pretending to be from a reputable figure within the Central Intelligence Agency (see Figure 2). The email subject is: "Russian spear phishing attack against .mil and .gov employees"

    Figure 2 – Content of the email:

    Jeffery Carr, the spoofed victim himself, has published a comment regarding this attack:

    The spoofed emails capitalize on the last Zeus attack, and claim that installing the Windows update via the links provided will aid protection against Zeus attacks. The binary file downloaded from these links is identified as a Zeus bot and holds 35% AV detection rate. Once again URLs in the email messages lead to a malicious file hosted on a compromised host, and also on a popular file hosting service. Once installed, the bot has identical functionality to the one mentioned in the previous alert. After The Zeus Rootkit component is installed the C&C server at update[removed].com is contacted to download an encrypted configuration file. Another data stealing component gets downloaded and installed from the same C&C in the shape of a Win32 Perl script compiled with Perl2Exe – this data-stealing component has only a 5% AV detection rate. Then the bot starts to connect with a credential-based FTP server at pack[removed].com to upload stolen data. The Zeus bot is normally designed to steal banking credentials; however it has also been seen in targeted attacks to steal other sensitive data.

    Websense® Messaging and Websense Web Security customers are protected against this attack.

    http://securitylabs.websense.com/con…erts/3550.aspx

  • 02.09.10 02:45 PM – LA Parks

    02.09.10 02:45 PM

    SIX FREE WAYS FOR HEALTHY LIVING
    Dedication of South Park’s Outdoor Fitness Zone

    Los Angeles – The Department of Recreation and Parks in partnership with Councilwoman Jan Perry, Kaiser Permanente, The Trust for Public Land (TPL) and the Community Redevelopment Agency of Los Angeles (CRA/LA) dedicated an Outdoor Fitness Zone at South Park on Thursday, January 14, 2010.

    General Manager Jon Kirk Mukri, Councilwoman Jan Perry, Kaiser Permanente’s Diana Bonta, CRA/LA Commissioner Alejandro Ortiz and TPL California State Director Sam Hodder were all on hand to help cut the red ribbon and officially open the Fitness Zone to local exercisers. Two legendary Dodgers, Bobby "Babo" Castillo and Kenny "KT" Landreaux made a special appearance to sign autographs and emphasize the importance of exercise at the Dedication Ceremony.

    South Park’s new Fitness Zone is the first of six Fitness Zones to open in the South Los Angeles area. The five other locations are 48th Street Park, Slauson Recreation Center, Gilbert Lindsay Recreation Center, Fred Roberts Recreation Center and Trinity Recreation Center.

    According to the L.A. County Department of Public Health, 37.8 percent of adults are obese in the community surrounding South Park. The Fitness Zone will provide much-needed free physical activity opportunities for the entire neighborhood.

    The new Fitness Zone is an easy-to-use outdoor gym designed to improve general health through weight loss, cardiovascular endurance, increased flexibility and strength building. The exercise equipment is designed to be durable, vandal resistant and used in various configurations. The Fitness Zone is free and can be used by teenagers and adults of all fitness levels.

    The outdoor exercise area has eight pieces of equipment: a cross-country ski machine, an upper body workout station, horizontal bars, leg press machine, lat pull-down machine, seated arm machine, incline crunch bench and lying leg curl machine. All of the machines have American’s with Disability Act compliant surfacing and bilingual instructions decals.

    Studies have shown that providing free and easy to use exercise equipment dramatically increases the opportunity to engage in physical activity. The Department of Recreation and Parks is proud to be a partner in providing healthy opportunities and living choices.

    South Park is located at 345 East 51st Street in Los Angeles 90011. For more information on this location or the Department please call (213) 202-2700 or visit our website at http://www.laparks.org/.

    MEDIA CONTACTS:
    Jane Kolb: (213) 202-2694
    Amy A. Garcia: (213) 202-2689

    LA Parks News and Information …

  • Young disaster victims need Kiwanis’ help

    02.09.10 09:02 AM

    Paul G. Palazzolo, Kiwanis International President and Elmer Austermann Jr., Kiwanis International Foundation President call for support of the Kiwanis International Disaster Relief Fund. Read the letter.

    http://community.kiwanisone.org/blog…anis-help.aspx

  • Matthew Morris joins Kiwanis International Foundation as Chief Fundraising Officer

    02.08.10 12:37 PM

    INDIANAPOLIS—Kiwanis International is pleased to announce that Matthew Morris has joined the Kiwanis International Foundation as its chief fundraising officer.

    In this role, Morris is focusing on guiding the New Beginning Campaign—a fundraising campaign where Kiwanis International will match all gifts up to a total of $750,000—and fundraising for Kiwanis’ next Worldwide Service Project, which will be announced at the Kiwanis International Convention in Las Vegas, NV, in June. The Worldwide Service Project campaign is expected to secure approximately $100 million for a global health initiative. Visit www.kiwanis.org/wsp for more information.

    “Matt’s experience securing major gifts is impressive,” said the foundation’s Chief Operating Officer Linda Brimmer. “He will be a tremendous asset to our organization and will help us reach our fundraising goals.”

    Morris is responsible for the strategic direction and creation of successful major gift campaigns, providing quality and efficient donor services to members and non-members, ensuring all donor communication and information needs are implemented and serving as an advocate for the vision, mission and values of the organization and the Kiwanis International Foundation.

    Morris previously served as senior development director at Indiana University Foundation, where he supported major gifts fundraising in Central Indiana, Greater Cincinnati and Washington, DC; participated on the principal gifts team, securing lead gifts for Indiana University; managed the major gifts portfolios of more than 100 individuals; and oversaw major gifts fundraising for the IU School of Journalism, during which more than $6 million was raised as part of the campus’ Matching the Promise Campaign.

    A graduate of the Indiana University School of Journalism and an avid runner, Morris lives in Fishers with his wife and two daughters.

    About Kiwanis International
    Founded in 1915, Kiwanis is a global organization of volunteers dedicated to changing the world one child and one community at a time. Kiwanis International and its service leadership programs for young people, including Circle K International, Key Club International, Key Leader, Builders Club, Kiwanis Kids, Kiwanis Junior and Aktion Club dedicate more than 19 million volunteer hours and invest US$100 million to strengthen communities and serve children annually. The Kiwanis International family comprises 600,000 adult and youth members in 70 countries and geographic areas. For more information about Kiwanis International, please visit www.kiwanis.org.

    http://community.kiwanisone.org/blog…g-officer.aspx

  • Malicious Web Site / Malicious Code: Zeus Campaign Targeted Government Departments

    02.07.10 04:00 PM

    Websense Security Labs? ThreatSeeker? Network has discovered a new Zeus campaign (a banking data stealing Trojan) which is now targeting government departments. Our research shows that the campaign has especially targeted workers from government and military departments in the UK and US: we found most victims’ email addresses end with .gov.

    Figure 1 – Zeus Campaign:

    Our ThreatSeeker? Network has seen thousands of emails which pretend to be from the National Intelligence Council (see Figure 2). The email subjects include: "National Intelligence Council"
    "RE: National Intelligence Council"
    "Report of the National Intelligence Council"

    Figure 2 – Content of the email:

    The spoofed emails lure victims to download a document about the "2020 project"; this is actually a Zeus bot. The Web sites which host the bot look very trustworthy: one of them is a compromised organization Web site and the other is located on a popular file hosting service. The bot has rootkit capabilities and connects to C&C servers at update*snip*.com and pack*snip*.com to report back on a successful infection and to download some archives with DLLs, it also modifies the hosts file to prevent updates from popular anti-virus vendors.

    Websense® Messaging and Websense Web Security customers are protected against this attack, however the anti-virus detection rate for this bot is currently at 26/40.

    http://securitylabs.websense.com/con…erts/3546.aspx

  • Malicious Web Site / Malicious Code: Bollywood Hungama Web Site Compromised

    02.07.10 04:00 PM

    Websense Security Labs? ThreatSeeker? Network has detected that the the Web site of Bollywood Hungama (Bollywoodhungama.com) has been compromised and injected with malicious code. The malicious code was identified to be part of the Gumblar mass injections, and there are multiple injections at the site’s path level. While the main page was injected, the malicious code has been removed. A number of pages at the path level, however, still remain injected. The injected code leads to a site that has also been compromised by Gumblar. At this time, the malicious code isn’t available or reachable, but this could change at any time.

    Bollywood Hungama is a leading entertainment Web site (Alexa rank 1,592). The site provides news related to the Indian film industry, emphasizing Bollywood, film reviews, and box office reports.

    Screenshot of the Web site:

    Screenshot of injected code in one of the pages:

    Websense® Messaging and Websense Web Security customers are protected against this attack.

    http://securitylabs.websense.com/con…erts/3548.aspx

  • Get set for Key Leader this spring!

    02.05.10 06:32 AM

    It may still feel like winter, but the sap is running in the trees. It's that time of year. Time to prepare for new beginnings, fresh starts and warm vibes. Make it happen in your club-and make it happen with a teen in your community. Start making plans to sponsor a Key Leader participant today! Check out this spring's offerings.

    http://community.kiwanisone.org/blog…is-spring.aspx

  • Foundation grant targets children in Haiti

    02.05.10 06:27 AM

    The Kiwanis International Foundation (KIF) has awarded a $10,000 grant from its Disaster Relief Fund to Sleeping Children Around the World to provide bed kits for children in Haiti. The grant was requested by Aktion Club, which adopted Sleeping Children Around the World as its service initiative about three years ago.

    A massive earthquake struck Haiti on January 12, reducing most of its capital and the surrounding area to rubble. This most recent grant brings the amount of money the foundation has earmarked for disaster relief there to more than $40,000.

    Founded in 1970, Sleeping Children Around the World has been providing bed kits to children in need around the world, mostly in underdeveloped and developing countries. Each bed kit includes a mat or mattress, pillow, sheet, blanket, mosquito net (if needed), clothes outfit, towel and school supplies. The foundation grant will be enough to provide about 300 bed kits to kids with the most needs in Haiti.

    Since partnering with Sleeping Children Around the World, Aktion Clubs have raised more than $50,000, including matching funds from the foundation.

    http://community.kiwanisone.org/blog…-in-haiti.aspx