Wednesday, December 16, 2015
New virus, old methods
A number of years ago I wrote this post:
http://ct1600.blogspot.com/2010/07/virus-evolution.html
And last friday I had a blast from the past. I forget the name but it was a modern .exe file infecter. The idea was to get it on a mapped drive.install autorun.inf so that the workstation would automatically run it, and then siphon off data.
Real old school virus method that you don't see around much anymore.
It does show, however, that you still have to look at all angles, new and old alike...
http://ct1600.blogspot.com/2010/07/virus-evolution.html
And last friday I had a blast from the past. I forget the name but it was a modern .exe file infecter. The idea was to get it on a mapped drive.install autorun.inf so that the workstation would automatically run it, and then siphon off data.
Real old school virus method that you don't see around much anymore.
It does show, however, that you still have to look at all angles, new and old alike...
Tuesday, April 5, 2011
Another "The Internet doesn't forget"
or "How to flush your career"
http://booksandpals.blogspot.com/2011/03/greek-seaman-jacqueline-howett.html
Reviewer gives an honest review of a book and it's author goes nuts.
http://booksandpals.blogspot.com/2011/03/greek-seaman-jacqueline-howett.html
Reviewer gives an honest review of a book and it's author goes nuts.
Tuesday, November 9, 2010
Cooks Source Magazine
Taking a break from tech topics for a moment here…
I’m sure you’ve heard of the Cooks Source plagiarism fiasco by now. Recap:A writer finds out her online article was printed in a magazine without her knowledge or permission. She contacts the editor, asks nicely for an apology in the magazine and a $130 donation to a college’s school of journalism. In response, she’s told that:
1) Everything on the internet is public domain (Untrue)
2) The editor (Judith Griggs) should charge her (Monica) for the time it took to edit the piece.
SO, the original author posts the email exchange on her blog, and word spreads. Chaos ensues, and CSM/Judith finds herself at the center of a shitstorm of epic proportions.
How could this have been avoided? Some say that paying the $130 dollars would have avoided it. In reality, somewhere down the road someone else would have found their article plagiarized too and it could have snowballed from there. It seems that the only way this could have been completely avoided was to do the right thing and not plagiarize in the first place. I know, such a simple answer, but some take the low road…
Addition: Judith will be toast. It is reported that one of the companies she ripped off was Disney. Their legal team is well trained in this sort of thing...
Frank
Saturday, July 17, 2010
Scammers
It never ceases to amaze me what some people will do to try to scam others.
From my work email:
Return-Path:
Delivered-To:
Received: (qmail 19706 invoked by uid 80); 17 Jul 2010 21:09:49 -0000
Received: from unknown (HELO mx2..com) ()
by 209.237.134.211 with SMTP; 17 Jul 2010 21:09:49 -0000
Received: from vrrmedia.webair.com (surf.webair.com [deleted ip])
by mx2. (8.12.11.20060308/8.12.11) with ESMTP id o6HL9mD7010292
for; Sat, 17 Jul 2010 17:09:48 -0400
Received: from vrrmedia.webair.com (localhost.webair.com [127.0.0.1])
by vrrmedia.webair.com (8.13.3/8.13.3) with ESMTP id o6HL9aWV065617
for; Sat, 17 Jul 2010 17:09:39 -0400 (EDT)
(envelope-from peterke-www@vrrmedia.webair.com)
Received: (from peterke-www@localhost)
by vrrmedia.webair.com (8.13.3/8.13.3/Submit) id o6HL9Zkn065571;
Sat, 17 Jul 2010 17:09:35 -0400 (EDT)
(envelope-from peterke-www)
Date: Sat, 17 Jul 2010 17:09:35 -0400 (EDT)
Message-Id: <201007172109.o6hl9zkn065571@vrrmedia.webair.com>
To:
Subject: SEND YOUR PROVABLE DETAILS IMMEDIATELY
From: GOOGLE INC
Reply-To: mr.lazslobock1@gmail.com
MIME-Version: 1.0
Content-Type: text/plain
Content-Transfer-Encoding: 8bit
X-Custom-SpamThreshold: 16
X-SpamScore: 11
X-MailHub-Apparently-To:
X-Antivirus: avast! (VPS 100717-0, 07/17/2010), Inbound message
X-Antivirus-Status: Clean
Dear Award winner
This is to inform you that you have won yourself an Award of One Million Five Hundred Thousand Pounds (GBP1,500,000) in the Google 11 Years Anniversary Awards as organized by the Anniversary Centre of Google Inc., held on May 21st, 2010 in London, United Kingdom.
The Anniversary Centre of Google Inc selected your email id as of one it's 20 chosen fortunate winner to receive this award.
The Anniversary Centre of Google Inc as a part of their for-profit philanthropic wing (GOOGLE.ORG) promotion. Awards MUST be claimed by the email owner ONLY, not later than 30 days from the day of notification.
Award Reference code: GOOGLE568A2010
File number: G255
Send your complete personal information with your Award Ref. and File no. to us to enable us process your Prize;
1. Full name, 2. Country, 3. Contact Address, 4.Sex, 5. Age, 6. Occupation, 7. Telephone/Fax no., 8. Email. Yahoomail/gmail
Director of Peoples Operations: Mr. Laszlo Block
E-Mail: mr.lazslobock1@gmail.com , laszlobock1@gmail.com
Tel: +44
Fax: +44
Please do not reply if you are NOT the owner of this email address
Congratulations!! Sincerely Yours,
Google Management
===
I deleted my addy, their ip and phone number, but the rest is unchanged. These people are scum, preying on the naive.
Frank
From my work email:
Return-Path:
Delivered-To:
Received: (qmail 19706 invoked by uid 80); 17 Jul 2010 21:09:49 -0000
Received: from unknown (HELO mx2.
by 209.237.134.211 with SMTP; 17 Jul 2010 21:09:49 -0000
Received: from vrrmedia.webair.com (surf.webair.com [deleted ip])
by mx2.
for
Received: from vrrmedia.webair.com (localhost.webair.com [127.0.0.1])
by vrrmedia.webair.com (8.13.3/8.13.3) with ESMTP id o6HL9aWV065617
for
(envelope-from peterke-www@vrrmedia.webair.com)
Received: (from peterke-www@localhost)
by vrrmedia.webair.com (8.13.3/8.13.3/Submit) id o6HL9Zkn065571;
Sat, 17 Jul 2010 17:09:35 -0400 (EDT)
(envelope-from peterke-www)
Date: Sat, 17 Jul 2010 17:09:35 -0400 (EDT)
Message-Id: <201007172109.o6hl9zkn065571@vrrmedia.webair.com>
To:
Subject: SEND YOUR PROVABLE DETAILS IMMEDIATELY
From: GOOGLE INC
Reply-To: mr.lazslobock1@gmail.com
MIME-Version: 1.0
Content-Type: text/plain
Content-Transfer-Encoding: 8bit
X-Custom-SpamThreshold: 16
X-SpamScore: 11
X-MailHub-Apparently-To:
X-Antivirus: avast! (VPS 100717-0, 07/17/2010), Inbound message
X-Antivirus-Status: Clean
Dear Award winner
This is to inform you that you have won yourself an Award of One Million Five Hundred Thousand Pounds (GBP1,500,000) in the Google 11 Years Anniversary Awards as organized by the Anniversary Centre of Google Inc., held on May 21st, 2010 in London, United Kingdom.
The Anniversary Centre of Google Inc selected your email id as of one it's 20 chosen fortunate winner to receive this award.
The Anniversary Centre of Google Inc as a part of their for-profit philanthropic wing (GOOGLE.ORG) promotion. Awards MUST be claimed by the email owner ONLY, not later than 30 days from the day of notification.
Award Reference code: GOOGLE568A2010
File number: G255
Send your complete personal information with your Award Ref. and File no. to us to enable us process your Prize;
1. Full name, 2. Country, 3. Contact Address, 4.Sex, 5. Age, 6. Occupation, 7. Telephone/Fax no., 8. Email. Yahoomail/gmail
Director of Peoples Operations: Mr. Laszlo Block
E-Mail: mr.lazslobock1@gmail.com , laszlobock1@gmail.com
Tel: +44
Fax: +44
Please do not reply if you are NOT the owner of this email address
Congratulations!! Sincerely Yours,
Google Management
===
I deleted my addy, their ip and phone number, but the rest is unchanged. These people are scum, preying on the naive.
Frank
Thursday, July 1, 2010
Virus evolution
Originally, Virus writers were experimenting to see if they could do something specific. There was one, for instance, that would make the user type “Happy Birthday Joshi” on a specific date. Unfortunately, in this case, the author made a mistake. On that date, any 3 ½ in floppy disks in the machine at the time would be wiped clean.
As time went on, Virus Writers became more malicious. Their goal was to infect as many computers as possible. Once infected, the virus would try to spread through Network Shares. These were easy to catch, for the most part, since they also tried to copy to printer shares. It was obvious that something was going on when a shared printer suddenly started printing garbage characters.
The next evolution was when the internet became big. Virus Writers then started writing ‘mass mailing’ viruses where your computer got infected and immediately sent out emails to everyone in the user’s address book, enticing them to click on the attachment.
The most recent evolution brought money into the picture. This style uses ActiveX, which is a component of Internet Explorer. If someone either typos a website name and ends up at an infected website, they go to a hijacked website, or a legitimate site runs an infected Banner Advertisement, an ActiveX script runs. This opens a 1 pixel by 1 pixel Internet Explorer window in the background, without the user’s knowledge, and downloads a virus install executable directly to their computer. Once downloaded, it runs the executable. After a short wait, the malware notifies the user that their computer is ‘infected’ with hundreds of spyware/malware ‘infections’, offering to scan further. Sometimes it changed the background image, too. The virus then says that it can fix the computer, but you need to pay a certain amount to register the software. (Usually $35 to $55)
The software does nothing but make the computer a “zombie”, controlled by someone else. ‘Registering’ also opens the user up for Identity Theft.
All computers should have legitimate antivirus software installed. However, the antivirus software is only as good as its latest definitions. If the computer is running current up to date definitions, and someone were to release a new version of a virus, it is still possible to get infected by it. For instance, someone writes a virus and releases it right now. It can be up to 1 to 2 days before the antivirus vendors get a copy, figure out how it works, how to detect it, and how to remove it. During that time, the computer could be infected, and not know it since it doesn’t yet know what to look for.
It has been a long trip since this all started. Who knows what the futre trend will be, but one thing is certain. Viruses and other malware will still be around.
As time went on, Virus Writers became more malicious. Their goal was to infect as many computers as possible. Once infected, the virus would try to spread through Network Shares. These were easy to catch, for the most part, since they also tried to copy to printer shares. It was obvious that something was going on when a shared printer suddenly started printing garbage characters.
The next evolution was when the internet became big. Virus Writers then started writing ‘mass mailing’ viruses where your computer got infected and immediately sent out emails to everyone in the user’s address book, enticing them to click on the attachment.
The most recent evolution brought money into the picture. This style uses ActiveX, which is a component of Internet Explorer. If someone either typos a website name and ends up at an infected website, they go to a hijacked website, or a legitimate site runs an infected Banner Advertisement, an ActiveX script runs. This opens a 1 pixel by 1 pixel Internet Explorer window in the background, without the user’s knowledge, and downloads a virus install executable directly to their computer. Once downloaded, it runs the executable. After a short wait, the malware notifies the user that their computer is ‘infected’ with hundreds of spyware/malware ‘infections’, offering to scan further. Sometimes it changed the background image, too. The virus then says that it can fix the computer, but you need to pay a certain amount to register the software. (Usually $35 to $55)
The software does nothing but make the computer a “zombie”, controlled by someone else. ‘Registering’ also opens the user up for Identity Theft.
All computers should have legitimate antivirus software installed. However, the antivirus software is only as good as its latest definitions. If the computer is running current up to date definitions, and someone were to release a new version of a virus, it is still possible to get infected by it. For instance, someone writes a virus and releases it right now. It can be up to 1 to 2 days before the antivirus vendors get a copy, figure out how it works, how to detect it, and how to remove it. During that time, the computer could be infected, and not know it since it doesn’t yet know what to look for.
It has been a long trip since this all started. Who knows what the futre trend will be, but one thing is certain. Viruses and other malware will still be around.
Saturday, June 26, 2010
Imagine this
You're sitting at your computer, surfing the web. Suddenly, you get a notice. "Your computer is infected with 1,722 variants of spyware and malware. Do you want to scan?". The program won't take no for an answer either. Somewhere along the way, it asks you for money and your credit card number. What do you do?
If you give it the info, you have just been scammed and opened yourself to Identity Theft at a future date. Your computer is also infected with a fake/rouge antivirus malware. The way it works is simple. You go to a site that was either compromised, a typo, or an infected banner ad was shown. A 1 pixel by 1 pixel Internet Explorer window opened in the background, went to the malware site, and using activex? downloaded and installed the malware on your computer in the background...without your permission or knowledge. Some even end up being used by spammers and scammers to ply their trade.
Obviously, this is money driven, so once again...if there was no market for it? No one would be creating this crap.
Something to think about this weekend.
Peace,
Frank
If you give it the info, you have just been scammed and opened yourself to Identity Theft at a future date. Your computer is also infected with a fake/rouge antivirus malware. The way it works is simple. You go to a site that was either compromised, a typo, or an infected banner ad was shown. A 1 pixel by 1 pixel Internet Explorer window opened in the background, went to the malware site, and using activex? downloaded and installed the malware on your computer in the background...without your permission or knowledge. Some even end up being used by spammers and scammers to ply their trade.
Obviously, this is money driven, so once again...if there was no market for it? No one would be creating this crap.
Something to think about this weekend.
Peace,
Frank
Wednesday, May 27, 2009
2008 Server
Figuring that I would have to learn this OS sooner or later, I finally bit the bullet. I installed the 60 day trial version 2 days ago. So far, it is similar in configuration to 2000/2003 server, BUT Active Directory on this has 3 options. 2000 server functionality, 2003 functionality, and 2008 functionality. As a result, it appears that this server OS could easily be integrated into an existing AD network...which I plan to try at a later date.
The version I installed was 2008 Standard, since I deal mostly with 200x standard servers, and some 2003 SBS servers. Like it's predecessors, you promote it to DC status with the dcpromo tool...and nothing from your end seems to have changed much (except the functionality level, of course).
So far the only problems I've had were the lack of drivers. That, however, would not be an issue in the 'real world', since most businesses are going to use new hardware, instead of my first-gen P4 IBM Netvista. :) I couldn't easily find 2008 Server drivers for my 3com 3c905c-tx NIC, which is even older, so I decided to try the Vista based ones. (They seemed to work...or 3com included 2008 server in them without updating their documentation)
Overall, the gui is s
etup like Vista by default...without the annoying "Whatever is trying to do something. Do you want to allow this?" crap. The pagefile is no longer being defined by default, and is set for 'system managed' (unlike in XP), making that tweak for you. MSC/MMC for the server is pictured to the left.
Obviously, the resource usage will be lower on something a little bit newer than this...lol
I'll be experimenting with the group policies next...
Peace,
Frank
The version I installed was 2008 Standard, since I deal mostly with 200x standard servers, and some 2003 SBS servers. Like it's predecessors, you promote it to DC status with the dcpromo tool...and nothing from your end seems to have changed much (except the functionality level, of course).
So far the only problems I've had were the lack of drivers. That, however, would not be an issue in the 'real world', since most businesses are going to use new hardware, instead of my first-gen P4 IBM Netvista. :) I couldn't easily find 2008 Server drivers for my 3com 3c905c-tx NIC, which is even older, so I decided to try the Vista based ones. (They seemed to work...or 3com included 2008 server in them without updating their documentation)
Overall, the gui is s
etup like Vista by default...without the annoying "Whatever is trying to do something. Do you want to allow this?" crap. The pagefile is no longer being defined by default, and is set for 'system managed' (unlike in XP), making that tweak for you. MSC/MMC for the server is pictured to the left.Obviously, the resource usage will be lower on something a little bit newer than this...lol
I'll be experimenting with the group policies next...
Peace,
Frank