Showing posts with label Hackers. Show all posts
Showing posts with label Hackers. Show all posts

Microsoft urges users to stop using safari on windows

Sunday, June 1, 2008 |

Microsoft security advisory: Blended Threat from Combined Attack Using Apple’s Safari on the Windows Platform
Microsoft

Microsoft on
May 30, 2008 issued an advisory that warned windows users to not use apple's safari web browser until a patch is available that could stop the attackers to hack computers.
Microsoft Security Response Center (MSRC) issued a security advisory, which it called a "blended threat".
It is caused by a combination of a bug in Apple's Safari Web browser and the vulnerability in the way the Windows XP and Vista handle executable (exe) files on the desktop. This allows the remote execution of malicious code on all supported Windows XP and Vista when the Safari web browser for Windows is installed. This bug was disclosed 2 weeks ago by a researcher Nitesh Dhanjani.

Safari lacks an option to require a user's permission to download a file. Attackers, could populate a malicious site with a code that Safari that would automatically download to the desktop, which is the default location.

Nitesh Dhanjani


A combination of the default download location in Safari and how the Windows desktop handles executables creates a blended threat in which files may be downloaded to a user’s machine without prompting, allowing them to be executed. Safari is available as a stand-alone install or through the Apple Software Update application.

An attacker could trick users into visiting a specially crafted Web site that could download content to a user’s machine and execute the content locally using the same permissions as the logged-on user.

Microsoft

High bandwidth : The evil side

|

Scientists across the world are devising new techniques and are exploring other protocols to serve one purpose, a high bandwidth. Internet service providers are competing with each other to provide higher bandwidths to customers at competitive prices. The world is on the internet highway, where the speed limit is continuously increasing. We live, talk and socialize on the internet. Some of us met their life partners on the internet. Wow! what a life changing experience. Amidst all this positivity and development, there have been many people who have been affected. Some positively and a few negatively. The most affected people have been the movie producers. Their movies have been stolen, ripped and are available for download on forums across the world. For the internet user with a high bandwidth and a less price, it would take a few minutes to download the DVD rip of a movie. A movie once downloaded, will surely be circulated across and once his friends see the movie, they wouldn't actually spend money to go to the theater to watch them. If you are more patient, a week or two (maximum) after the movies release, pirated copies are available for less than $1. With high bandwidth comes the risk of huge file transfers (illegal). Recently some chinese suckers (hackers), hacked Indian defense websites, stealing vital information. I feel hacking is an achievement (of evil) in itself and hackers being the lord voldermort (the evil guy) of harry potter. Some times this evil is used by us, when we use and watch pirated stuff. It will take some hard work and smart effort by the antivirus and web security companies to curb the ill effect of high bandwidth

How to Avoid Phishing

Wednesday, April 23, 2008 |

In computing, phishing is an attempt to criminally and fraudulently acquire sensitive information, such as usernames, passwords and credit card details, by masquerading as a trustworthy entity in an electronic communication. eBay, PayPal and online banks are common targets.
Read more here

What makes NOD32 one of the best antivirus

Saturday, February 23, 2008 |

Posted on February 23, 2008.

NOD32 eyeWhat is NOD32 ?

  • NOD32 is an antivirus package made by the Slovak company Eset.
  • Versions are available for Microsoft Windows, Linux, FreeBSD, and other platforms.
  • A NOD32 Enterprise Edition is available that consists of NOD32 AntiVirus and NOD32 Remote Administrator.
  • The NOD32 Remote Administrator program allows a network administrator to monitor anti-virus functions, push installations and upgrades to unprotected PCs on the network, and update configuration files from a central location.

NOD32 was born in the early 1990s when computer viruses were becoming increasingly prevalent.

NOD32 screenshotWhat does it provide ?

  • AMON (Antivirus MONitor) - scans files as they are accessed by the system, preventing a virus from executing on the system.
  • DMON (Document MONitor) - scans Microsoft Office documents and files for macro viruses as they are opened and saved by Office applications.
  • IMON (Internet MONitor) - intercepts traffic on common protocols such as POP3 and HTTP to detect and intercept viruses before they are saved to discs.
  • EMON (E-mail MONitor) - An auxiliary module for scanning incoming/outgoing e-mails via the MAPI interface, such as Microsoft Outlook and Microsoft Exchange Client.
  • XMON (MS eXchange MONitor) - scans incoming and outgoing mail when NOD32 is running and licensed for Microsoft Exchange Server - ie, running on a server environment. This module is not present on workstations at all.

What makes it the best ?

  • NOD32 is written largely in assembly code, which contributes to its low use of system resources and high scanning speed.
  • NOD32 can process more than 23MB per second while scanning on a Pentium 4 based PC.
    It uses less than 20MB of memory in total.The physical RAM used is often just a third of that.
  • According to a 2005 Virus Bulletin test, NOD32 performs scans two to five times faster than other antivirus competitors.
  • In a networked environment NOD32 clients can update from a central “mirror server” on the network, reducing bandwidth usage since new definitions need only be downloaded once by the mirror server as opposed to once for each client.
  • In addition to signature files, NOD32’s scan engine uses heuristic detection (called “ThreatSense” by Eset) to provide better protection against newly released viruses.

Also Visit: ESET website

Microsoft reveals hole in Excel

Sunday, January 20, 2008 |

Microsoft has revealed that hackers have found a way to infiltrate older versions of its Excel program to take control of infected computer systems.

Earlier in the week, the software major said it's investigating reports of such attacks though hasn't yet determined whether it will go ahead and patch the bug, and if so, when.

Q) How will it infiltrate the anti-virus cordon and how can you protect your PC from it ?
Ans) The modus operandi is: you may either get a specially crafted Excel file as an email attachment or may end up visiting a compromised Web site -- either ways, you could be inviting hackers to arbitrarily take control of your PCs for furthering their malicious cause, be it stealing passwords and other personal information or sending out spam.

Microsoft Office Excel 2003 Service Pack 2, Excel Viewer 2003, Excel 2002, Excel 2000, and Excel 2004 for Mac, are all vulnerable to this form of attack, Microsoft said.

The way to go for users, as advised by Redmond, is to use a tool named 'Microsoft Office Isolated Conversion Environment', which scans files for bad code before opening them.

Meanwhile, more recent versions of Excel such as Excel 2007, Excel 2007 SP 1, and Excel 2008 for Mac are believed not to be vulnerable.