<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5074766823662728299</id><updated>2012-02-15T22:50:00.067-08:00</updated><title type='text'>NETWORK SECURITY AND THREATS</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>58</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-2577759458444124502</id><published>2009-02-28T18:25:00.000-08:00</published><updated>2011-08-10T06:26:16.973-07:00</updated><title type='text'>HOW TO FIND AN INFECTED COMPUTER</title><content type='html'>&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&amp;nbsp; Here r the symptoms of an infected computer&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;slow system starting&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;high cpu usage&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;high ram usage&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;system hangs&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;The first thing u should do is to open the task manager.U can open it by right clicking on the task bar and select it or press ctrl+alt+del.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;In the task manager u can see the performance,process etc.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;My XP task manager looks like this&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-LXF_Yiey2KY/TkDZsrU_WHI/AAAAAAAAAz4/v4JIVXNlnqQ/s1600/untitled.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-LXF_Yiey2KY/TkDZsrU_WHI/AAAAAAAAAz4/v4JIVXNlnqQ/s320/untitled.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-2RmvoaH2QDA/TkDaBFbZqMI/AAAAAAAAAz8/IVjsgtGQ9lU/s1600/untitled+2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://4.bp.blogspot.com/-2RmvoaH2QDA/TkDaBFbZqMI/AAAAAAAAAz8/IVjsgtGQ9lU/s320/untitled+2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Now u can see the CPU and RAM usage.&amp;nbsp;Initially&amp;nbsp;XP has less CPU usage.The RAM usage is only 200mb.If the cpu usage is constantly 100% or the ram usage is high then it is infected.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;We can find the virus easily by checking the processes.If any process is using high cpu or ram then that is a virus.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Sometimes svchost.exe may be using high cpu and ram.This is not a virus.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Some common process in XP are csrss.exe, ctfmon.exe, explorer.&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;exe, lsass.&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;exe.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;services.&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;exe, smss.exe, spoolsv.exe, svchost.&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;exe, system ,system idle process ,taskmgr.exe ,&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;winlogon.&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;exe.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;If we start an application then its process also runs.EG:chrome.exe, firefox.exe, hitman.exe etc&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Any process except this using high cpu or ram can be a virus.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;We can end this process by rt clicking.A warning msg will open,select yes.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;After this we have to end the start up of virus.For this click start-&amp;gt;run-&amp;gt;type msconfig&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-3OmG_BAVRv0/TkKEVdiC7rI/AAAAAAAAA0A/W-Jv7w_sKxE/s1600/untitled.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://4.bp.blogspot.com/-3OmG_BAVRv0/TkKEVdiC7rI/AAAAAAAAA0A/W-Jv7w_sKxE/s320/untitled.JPG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;Search for the process, that is virus.Disable it by clicking it.then click ok.Restart ur system.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;If this does not stop the virus we have to find the virus file.It is located in the c:\ or system drive.&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;In&amp;nbsp;C:\WINDOWS or C:\WINDOWS\system32 we can find the virus file.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-2577759458444124502?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/2577759458444124502/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=2577759458444124502' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/2577759458444124502'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/2577759458444124502'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2011/08/how-to-find-infected-computer.html' title='HOW TO FIND AN INFECTED COMPUTER'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-LXF_Yiey2KY/TkDZsrU_WHI/AAAAAAAAAz4/v4JIVXNlnqQ/s72-c/untitled.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-4137441741059773018</id><published>2009-02-28T10:13:00.000-08:00</published><updated>2009-03-28T10:16:12.620-07:00</updated><title type='text'>GHOST ADWARE</title><content type='html'>&lt;h3&gt;Name: Adware.Win32.Ghost Keylogger&lt;/h3&gt;                      &lt;p&gt;&lt;b&gt;Risklevel:&lt;/b&gt; Severe Risk&lt;/p&gt;                      &lt;p&gt;&lt;b&gt;Company:&lt;/b&gt; Sureshot Software - http://keylogger.net/&lt;/p&gt;                      &lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;/p&gt;        &lt;p&gt;Ghost Keylogger is a keylogger that is an invisible that records every keystroke. It monitors the Internet activity by logging the addresses of visited homepages.&lt;/p&gt;                      &lt;p&gt;&lt;b&gt;Characteristics:&lt;/b&gt;&lt;/p&gt;        &lt;ul&gt;&lt;li&gt;It is an invisible that records every keystroke.&lt;/li&gt;&lt;li&gt;It monitors the Internet activity by logging the addresses of visited homepages.&lt;/li&gt;&lt;/ul&gt;                      &lt;p&gt;&lt;b&gt;Installation:&lt;/b&gt; Installed through EXE&lt;/p&gt;                      &lt;b&gt;Process:&lt;/b&gt; syncconfig.exe&lt;br /&gt;&lt;p&gt;&lt;b&gt;Used folders:&lt;/b&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;C:\Program Files\Sync Manager Demo\agent&lt;/li&gt;&lt;li&gt;C:\Program Files\Sync Manager Demo&lt;/li&gt;&lt;/ul&gt;               &lt;p&gt;&lt;b&gt;Used files:&lt;/b&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;C:\Program Files\Sync Manager Demo\manual.html&lt;br /&gt;[30026 Bytes] HTML Document&lt;/li&gt;&lt;li&gt;C:\Program Files\Sync Manager Demo\agent\syncagent.exe&lt;br /&gt;[626688 Bytes] Application&lt;/li&gt;&lt;li&gt;C:\Program Files\Sync Manager Demo\agent\syncagent.dll&lt;br /&gt;[258048 Bytes] Application Extension&lt;/li&gt;&lt;li&gt;C:\Program Files\Sync Manager Demo\syncconfig.exe&lt;br /&gt;[663552 Bytes] Application&lt;/li&gt;&lt;li&gt;C:\Program Files\Sync Manager Demo\faq.html&lt;br /&gt;[29722 Bytes] HTML Document&lt;/li&gt;&lt;li&gt;C:\Program Files\Sync Manager Demo\agent\syncagent.cfg&lt;br /&gt;[2641 Bytes] Microsoft Office Outlook Configuration File&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-4137441741059773018?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/4137441741059773018/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=4137441741059773018' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/4137441741059773018'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/4137441741059773018'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/ghost-adware.html' title='GHOST ADWARE'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-7964213090690319830</id><published>2009-02-24T23:55:00.000-08:00</published><updated>2009-02-07T08:49:23.854-08:00</updated><title type='text'>PRESENT SITUATION</title><content type='html'>PRESENT SITUATION&lt;br /&gt;&lt;br /&gt;As the volume of financial and other data transactions increase over the Internet, the potential for harm from network threats also increases. As a consequence, complex security measures that were once required by only Fortune 500 companies such as regular security audits are increasingly a necessity even for the smallest of companies.&lt;br /&gt;&lt;br /&gt;As we continue to become an ever more networked society, the financial benefits attainable by hacking a network increase. As a result, it should come as no surprise that the number of attacks and the creativity spent in trying to breach a network continue to increase. Consequently, those that are tasked with defending networks must continue to educate themselves and their workforce on the newest types of attacks and make the necessary preparations to prevent against them.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-7964213090690319830?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/7964213090690319830/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=7964213090690319830' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/7964213090690319830'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/7964213090690319830'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/01/conclusion.html' title='PRESENT SITUATION'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-4504801116659496262</id><published>2009-02-24T23:54:00.001-08:00</published><updated>2009-02-21T02:02:25.933-08:00</updated><title type='text'>ZOMBIE COMPUTERS AND BOTNETS</title><content type='html'>Zombie Computers and Botnets&lt;br /&gt;If you've ever wondered who is sitting around sending out all those spam emails, the answer may be you. A recent New York Times article estimates that as much as 80 percent of spam messages are sent out by the computers of ordinary individuals who have no idea their computers have been converted into 'zombies'. A 'zombie' computer is simply a computer infected with malware that causes it to act as a tool of a spammer by silently sending out thousands of emails from the owner's email address.&lt;br /&gt;&lt;br /&gt;Infected 'zombie' computers, are organized by spammers into small groups called 'botnets'. These 'botnets' then send out spam that may include phishing attempts, viruses and worms. Unfortunately for network managers and business owners, the 'zombie' malware threat is expected to continue to grow both in number and variety over the next few years. Currently, 'zombies' are used to send out the following types of malware:&lt;br /&gt;&lt;br /&gt;Spamming and phishing attacks. This classic form of 'Zombie' computers is still the most common.&lt;br /&gt;&lt;br /&gt;Click fraud in advertising networks. Using a hidden program, zombie computers emulate human clicking on ads at a website or weblog. While Google said in Dec 2006 that click fraud for their AdSense contextual ad network is less than 2 percent, some advertisers have much higher estimates. Whatever the actual figure, creating click fraud zombies is currently a multi-million dollar industry, so do not expect it to stop soon.&lt;br /&gt;&lt;br /&gt;DoS attacks. Your company may have malicious competitors, or spiteful former employees who will stoop to any level to bring your company down. In this instance, your enemy might launch a Denial-of-Service attack (DoS) which is an attack designed to make the hosted pages of a website or network become unavailable to customers or employees. For instance, a spiteful former employee may launch a Dos attack on your biggest selling day of the year. Consequently, your company will lose all the business it might have had that day as customers are unable to access your Web site.&lt;br /&gt;&lt;br /&gt;Pump and dump stock schemes. In this scheme, spammers buy up a large block of a penny stock (especially sub-$1 per share), then use their 'Zombies' to spam millions of people with emails about the stock in the hopes that a few fools will take the bait and buy a few thousand shares, thus raising the price. After the price spike, the spammer then sells off his holdings and makes a quick buck.&lt;br /&gt;&lt;br /&gt;Prevention&lt;br /&gt;Because ‘botnets’ typically work silently on ‘zombie’ computers and are often enabled by the secret installation of Trojan horses, it is very difficult to tell whether a computer has been infected. Preventing ‘botnets’ from turning your network computers into 'zombies' requires that you educate your employees to keep all forms of security software up to date, and to run a virus scan regularly, preferably nightly. In addition to nightly scanning, train your employees to look for sudden unusual behavior of your computer(s), such as persistent slowdowns, crashing, as a sign that they may be infected. If, despite your best efforts, a network computer becomes infected, treatment can vary wildly, from a simple scanning for and deleting the botnet, to a reformatting of the computer's hard drive.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-4504801116659496262?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/4504801116659496262/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=4504801116659496262' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/4504801116659496262'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/4504801116659496262'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/01/10-zombie-computers-and-botnets.html' title='ZOMBIE COMPUTERS AND BOTNETS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-8119620069827700424</id><published>2009-02-24T23:54:00.000-08:00</published><updated>2009-02-21T02:35:22.242-08:00</updated><title type='text'>SHARED COMPUTERS</title><content type='html'>Shared Computers&lt;br /&gt;In the IT community, it is often said that shared computers are like public bathrooms, they may appear clean, but are usually chock full of viruses. Thankfully, the danger of shared computers is one network threat that you can largely render harmless by limiting the activities that you and your employees perform.&lt;br /&gt;&lt;br /&gt;Prevention&lt;br /&gt;If you or your employees use public computers, don't permit them to log into important online accounts, especially those containing financial details. You never know when a keylogger might be lying in wait, ready to steal your password and then your company’s money. Going beyond just avoiding accessing sensitive data through public computers, if you can avoid it, forbid your employees from logging into any network accounts at all on any public computers. While enforcement of this policy is difficult, simply educating your staff on the dangers of using public computers is often sufficient to eliminate most of these incidents.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-8119620069827700424?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/8119620069827700424/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=8119620069827700424' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/8119620069827700424'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/8119620069827700424'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/01/9-shared-computers.html' title='SHARED COMPUTERS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-7691688095493387112</id><published>2009-02-24T23:53:00.000-08:00</published><updated>2011-08-28T04:52:22.571-07:00</updated><title type='text'>HARDWARE LOSS AND RESIDUAL DATA FRAGMENTS</title><content type='html'>Hardware Loss and Residual Data Fragments&lt;br /&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp;Over the past few months, a number of government laptops have been stolen and the story has made national news. The government is so concerned, not because of the cost of replacing a few laptops, but from the network vulnerabilities that the loss of this hardware threatens to cause. In fact, hardware loss is a large cause of the more than 10 million cases of identity theft suffered by Americans each year.&lt;br /&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp;These types of problems are not what we commonly think of as network security threats, but stolen or sold laptops and computers pose one of the biggest threats for networks. Businesses often sell older computers without completely wiping the drives clean of data, including system passwords. Just as with stolen computers, this information can then be easily used to gain access to the network and compromise the security of the entire system.&lt;br /&gt;&lt;br /&gt;Prevention&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Thankfully, the threat of hardware loss and residual data fragments can be minimized by taking a few rather straightforward steps:&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Encrypt sensitive company data, especially the laptops and files of executives who are most likely to be targeted. When traveling through foreign airports the problem can be especially acute, as laptops of prominent individuals are sometimes taken aside under the guise of "security", and their hard drives are quickly mirrored and used to blackmail the company. Despite the obvious benefits of securing data, however, a recent survey found that 64 percent of companies were more concerned about data loss than the cost of replacing hardware, however, only 12 percent were actually using encyrption.&lt;br /&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; Wipe/shred files on old hard drives before they leave your organization. This is as much an issue of data compliance regulations as it is of network security. No matter what your motivation, however, failing to clean discarded hardware can leave your entire network vulnerable.&lt;br /&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; Develop a policy for keeping track of employees use of smartphones and USB memory cards around sensitive data. Simply letting employees know that you have such a policy and are monitoring the use of these devices will go a long way to preventing their misuse and protecting the network.&lt;br /&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Use an RFID-based Asset Management system for computers, laptops, and other sensitive hardware to keep tabs on their whereabouts in your premises.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-7691688095493387112?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/7691688095493387112/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=7691688095493387112' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/7691688095493387112'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/7691688095493387112'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/01/8-hardware-loss-and-residual-data.html' title='HARDWARE LOSS AND RESIDUAL DATA FRAGMENTS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-6691622541667919032</id><published>2009-02-24T23:52:00.001-08:00</published><updated>2009-04-08T04:54:01.303-07:00</updated><title type='text'>PASSWORD ATTACKS</title><content type='html'>Password Protection&lt;br /&gt;Passwords are undeniably a huge part of your online security. You'll find that almost every website that you visit that deals with online transactions, emailing, and shopping use passwords to verify you are who you say you are. This means that you not only need to choose a password that cannot easily be figured out, but you should also keep it safe and secure and not share it with anyone. Do not use the same password for all of your accounts and attempt to come up with a password that contains letters, numbers, and special characters.&lt;br /&gt;&lt;br /&gt;Password Attacks&lt;br /&gt;&lt;br /&gt;A 'Password Attack' is a general term that describes a variety of techniques used to steal passwords to accounts.&lt;br /&gt;&lt;br /&gt;Brute-force. One of the most labor intensive and unsophisticated methods hackers use to steal passwords is to try to guess a password by repeatedly entering in new combinations of words and phrases compiled from a dictionary. This 'dictionary attack' can also be used to try to guess usernames as well, so developing difficult to guess usernames and passwords is increasingly vital to network security.&lt;br /&gt;&lt;br /&gt;Packet sniffers. As discussed above, Packet Sniffers glean data electronically from a compromised network.&lt;br /&gt;&lt;br /&gt;IP-spoofing. Similar to 'Honeypots', this attack involves the interception of data packets by a computer successfully pretending to be a trusted server/ resource.&lt;br /&gt;&lt;br /&gt;Trojans. Trojans are actually invasive, as discussed above, and of these methods, are the most likely to be successful, especially if they install keyloggers.&lt;br /&gt;&lt;br /&gt;Prevention&lt;br /&gt;Automated testing (e.g., dictionary scanning), human behavior (e.g., lack of diversity in usernames and passwords), and other security flaws make it easier for password attackers to succeed. Unfortunately, there is no one single method to prevent against password attacks, though combining network traffic analysis along with the old stalwarts of email scanning, virus protection, firewalls and an educated work force can all together form a strong defense for any network.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-6691622541667919032?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/6691622541667919032/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=6691622541667919032' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/6691622541667919032'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/6691622541667919032'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/01/7-password-attacks.html' title='PASSWORD ATTACKS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-8579592248745406160</id><published>2009-02-24T23:52:00.000-08:00</published><updated>2011-08-28T04:50:22.691-07:00</updated><title type='text'>MALICIOUSLY CODED WEB SITES</title><content type='html'>Maliciously-Coded Web sites&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&amp;nbsp; &amp;nbsp; Maliciously-coded Web sites can take many different forms, from installing Trojan horses to redirecting you to an unrequested site. But one of the most threatening forms of maliciously-coded websites, those that are designed to steal passwords, are on the rise [4]. A very common form of these Web sites takes advantage of human's charitable instincts by setting up traps in what appear to be sites that allow you to make donations to victims of natural disasters such as Hurricane Katrina. Hackers set up a fake sign-in page, and then encourage unsuspecting victims to enter their credit card number and other personal information.&lt;/div&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp;In addition to stealing personal information, maliciously-coded websites are also often designed for the following purposes:&lt;br /&gt;installation of keyloggers&lt;br /&gt;adware/ spyware/ reading cookies&lt;br /&gt;drive-by downloads&lt;br /&gt;XSS - cross--site scripting to utilize web browser flaws for other intentions.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Prevention&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;In order to protect your network, you should encourage your employees to purchase information only from security certified sites, and to use PayPal instead of a credit card whenever possible, since by doing so they will not have to reveal their credit card information to another site. In addition to limiting the number of times credit card information is typed into a website, paying by PayPal is also helpful because maliciously-coded sites are less likely to accept PayPal payments since the owners of that PayPal account are easier to trace to an address or bank account.&lt;br /&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Further, you should instruct your employees to never sign up for new Web 2.0 applications without using a different username and password than they ordinarily use for sensitive data. Creating a regular browser patch and plugin update schedule will also ensure that your virus and email protections are up to date. Finally, you should systematically set the browser security settings of all your network computers to a higher than default setting. While this step will not eliminate the possibility that your employees will stumble upon maliciously-coded sites, it will reduce the incidence of that occurrence.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-8579592248745406160?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/8579592248745406160/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=8579592248745406160' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/8579592248745406160'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/8579592248745406160'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/01/6-maliciously-coded-web-sites.html' title='MALICIOUSLY CODED WEB SITES'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-1581614793030630320</id><published>2009-02-24T23:50:00.001-08:00</published><updated>2009-02-21T02:40:47.039-08:00</updated><title type='text'>PACKET SNIFFERS</title><content type='html'>Packet Sniffers&lt;br /&gt;&lt;br /&gt;Packet sniffers capture data streams over a network, thus allowing for the capture of sensitive data like usernames, passwords and credit card numbers. The result, unsurprisingly, is the loss of data, trade secrets, or online account balances. For network managers specifically, even bigger losses can come from lawsuits due to noncompliance of data protection regulations.&lt;br /&gt;&lt;br /&gt;While Packet sniffers have been used in rather harmless ways, such as by law enforcement and by corporations for data protection compliance purposes (HIPAA, SOX/ Sarbox, Gramm-Leach-Bliley Act), the real concern for network owners is packet sniffers more malicious forms.&lt;br /&gt;&lt;br /&gt;Packet sniffers work by monitoring and recording all the information that comes from and goes to your computer over a compromised network. So in order to be effective, the packet sniffer must first have access to the network you are using. The most common way to do this, is through using something called honeypots. Honeypots are simply unsecured wifi access points that hackers setup and trap people into using them. Typically, these honeypots are setup in public places such as airports, and the wifi network is titled something like "Free Public Wi-Fi". Unsuspecting individuals then sign onto the corrupted network and the packet sniffer then grabs their personal information when they enter things like their credit card info into a site.&lt;br /&gt;&lt;br /&gt;Prevention&lt;br /&gt;Education is simply the best policy to deal with the threat of packet sniffers. Once your employees know to never access the internet through an unsecured connection, and are made aware of the fact that packet sniffers exist, they are much less likely to fall victim to this hacking technique. Because a single victim of packet sniffing among any employee can compromise sensitive network data, it is important that everyone learn how to identify honeypots and how to secure their own home wifi networks. In addition, make sure that your employees use a variety of different sign on names and passwords to access various levels of network security. That way, if login information is compromised, the damage can at least be limited in scope.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-1581614793030630320?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/1581614793030630320/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=1581614793030630320' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1581614793030630320'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1581614793030630320'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/01/5-packet-sniffers.html' title='PACKET SNIFFERS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-8931954838694278995</id><published>2009-02-24T23:50:00.000-08:00</published><updated>2009-03-07T08:36:50.859-08:00</updated><title type='text'>PHISHING</title><content type='html'>Phishing&lt;br /&gt;&lt;br /&gt;Anyone who has ever used PayPal or does their banking online has probably received dozens of emails with titles such as, "URGENT: Update Account Status". These emails are all attempts by a spammer to "phish" your account information. Phishing refers to spam emails designed to trick recipients into clicking on a link to an insecure website. Typically, phishing attempts are executed to steal account information for e-commerce sites such as eBay, payments processors such as PayPal, or regular financial institutions' websites. A phishing email supplies you with a link to click on, which will take you to a page where you can re-enter all your account details, including credit card number(s) and/or passwords. Of course, these sites aren't the actual bank's site, even though they look like it.&lt;br /&gt;&lt;br /&gt;Your company's mobile phones may not be safe either, as SMS messaging is now frequently used as a new type of phishing called SMiShing. Once the SMiShing, is successful, other malware such as Trojans are sometimes released onto the mobile phone. These Trojans then make silent high cost text messages which go onto the sender's bill.&lt;br /&gt;&lt;br /&gt;Some criminals are also using VoIP or VoIM software to send vishing messages. These try to confuse people into calling the provided number - usually an automated VoIP Call-In number - and revealing credit card details, which are recorded in audio form.&lt;br /&gt;&lt;br /&gt;Prevention&lt;br /&gt;Phishing in all its varieties is a huge and growing problem for network security managers and business owners. As we all become more interconnected and access more and more personal information through networks, there become more and more opportunities for phishers to attack. To protect one's network, it is becoming increasingly vital that you educate your employees about the most common ways in which hackers try to phish your account information. Even though simplistic phishing attempts like the PayPal scam now seem obvious to regular internet users, a single phishing attack can compromise an entire network's security if the employee is tricked into giving his network account information. Even after educating your work force, you should consider adding a header to your network browser that reminds users never to enter personal information solicited through an email, and you should certainly use a sophisticated email filter to limit the number of phishing attacks that your employees must navigate around.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-8931954838694278995?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/8931954838694278995/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=8931954838694278995' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/8931954838694278995'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/8931954838694278995'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/01/4-phishing.html' title='PHISHING'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-6847004085949497183</id><published>2009-02-24T23:49:00.000-08:00</published><updated>2009-03-07T08:39:44.181-08:00</updated><title type='text'>SPAM</title><content type='html'>Spam&lt;br /&gt;&lt;br /&gt;Depending on the source cited, spam makes up 70 to 84 percent of daily emails sent throughout the world. All that spam results in billions of dollars in lost productivity and creates an ever increasing need for IT resources to filter out this irritating and potentially malicious menace.&lt;br /&gt;&lt;br /&gt;Spam email takes a variety of forms, ranging from unsolicited emails promoting products like Viagra, to coordinated spam attacks designed to take up so much bandwidth on a network so as to cause it to crash. A more recent trend is image spam, which eats up even more bandwidth than its textual cousin, and often circumvents contextual spam filters which analyze the message text to look for indications that the email is spam. Another brand new technique that spammers are using is called "news service" spam, which uses legitimate headlines such as "Howard Stern Earns $83M Bonus" to trick recipients into opening spam emails that are filled with spammy drug advertisements. These and other new spam trends constantly threaten the productivity of email and the security of IT networks.&lt;br /&gt;&lt;br /&gt;Prevention&lt;br /&gt;When it comes to fighting spam, fortunately, a great deal of spam can be filtered out by a good email filter. And much of what slips through can be avoided by staying current on the latest techniques that spammers use. In addition, however, you should protect your network from email spam by requiring your employees to use separate accounts for their personal internet use, and demand that company accounts not be used to sign up for any online service or freebie. In addition, when creating company email accounts make sure to use a naming system which is not easily guessable (e.g., JSmith@domain.com), as spammers are increasingly going through common name lists in order to harvest emails to spam.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-6847004085949497183?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/6847004085949497183/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=6847004085949497183' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/6847004085949497183'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/6847004085949497183'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/01/3-spam.html' title='SPAM'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-1527942744294331516</id><published>2009-02-24T23:47:00.000-08:00</published><updated>2009-04-07T00:58:55.961-07:00</updated><title type='text'>TROJAN HORSES</title><content type='html'>Trojan Horses&lt;br /&gt;&lt;br /&gt;A Trojan horse is a malware attack that disguises itself as something innocent, such as a computer game, or a YouTube search results page. A recent example of a devastating Trojan horse used an email with a link that supposedly connected the reader to a video of the Saddam Hussein hanging, but instead just infected them with malware. Once installed on a computer, the 'Saddam' Trojan horse then downloaded and installed a keylogger onto the infected computer. This keylogger was used to record every keystroke by a computer’s user, thus stealing financial account information and passwords.&lt;br /&gt;&lt;br /&gt;The 'Saddam' Trojan horse is noteworthy only because it was so successful, but the actual methods that it used to infect computer networks are not unique. In fact, Trojans are particularly dangerous because they all appear so innocuous on the surface. Often Ttrojans imbed themselves on a particular website (usually adult, gaming, or gambling), hide in downloaded free software, or, as in the "Saddam" Trojan horse, a person might be infected by clicking on a link sent to them in an email.&lt;br /&gt;&lt;br /&gt;Prevention&lt;br /&gt;Because hackers are so creative in coming up with new and different types of Trojan horses, training employees on what to look for will not prevent Trojan horses from infecting your network. Instead, you may want to consider blocking users from downloading freeware, blocking links imbedded in emails, and using a whitelist to create a list of approved websites that employees may visit. Because Trojans are much easier to prevent than they are to cure, with an infected computer sometimes requiring a complete reformatting of the hard drive, taking these drastic preventative measures may be warranted for some companies.The methods for dealing with Trojans are generally the same as for those for dealing with viruses. Most virus scanners attempt to deal with some of the common Trojans with varying degrees of success, there are also specific "anti-Trojan" scanners available, and your best weapon is common sense yet again. Score another point for safe computing!&lt;br /&gt;&lt;br /&gt;A Trojan Horse meets the definition of virus that most people use, in the sense that it attempts to infiltrate a computer without the user’s knowledge or consent. A Trojan horse, similar to its Greek mythological counterpart, often presents itself as one form while it is actually another. A recent example of malware acting as a Trojan horse is the recent e-mail version of the “Swen” virus, which falsely claimed to be a Microsoft update application.&lt;br /&gt;Trojans typically do one of two things: they either destroy or modify data the moment they launch, such as erase a hard drive, or they attempt to ferret out and steal passwords, credit card numbers, and other such confidential information.&lt;br /&gt;&lt;br /&gt;Trojan Horses can be a bigger problem than other types of viruses as they are design to be destructive or disruptive, as opposed to viruses and worms where the coder may not intend to do any harm at all. Essentially this distinction does not matter in the real world. You can lump viruses, Trojans and worms together as "things I don't want on my computer or my network".&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-1527942744294331516?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/1527942744294331516/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=1527942744294331516' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1527942744294331516'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1527942744294331516'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/01/2-trojan-horses.html' title='TROJAN HORSES'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-3658874451160396059</id><published>2009-02-21T09:15:00.000-08:00</published><updated>2009-04-25T02:48:40.227-07:00</updated><title type='text'>GAME.EXE</title><content type='html'>game.exe (Game Dialler) - Details&lt;br /&gt;&lt;br /&gt;The game.exe process will take over your modem and attempt to 'dial out' to (potentially overseas or toll-rate) telephone numbers in order to download adult content and store it on your computer.&lt;br /&gt;&lt;br /&gt;game.exe is considered to be a security risk, not only because antivirus programs flag Game Dialler as a virus, but also because a number of users have complained about its performance.&lt;br /&gt;&lt;br /&gt;Game Dialler is likely a virus and as such, presents a serious vulnerability which should be fixed immediately! Delaying the removal of game.exe may cause serious harm to your system and will likely cause a number of problems, such as slow performance, loss of data or leaking private information to websites.&lt;br /&gt;&lt;br /&gt;game.exe is considered to be a security risk, not only because spyware removal programs flag Game Dialler as spyware, but also because a number of users have complained about its performance.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;game.exe is considered to be a security risk, not only because Adware Removal programs flag Game Dialler as Adware, but also because there can be privacy issues associated with this product.&lt;br /&gt;&lt;br /&gt;Game Dialler is likely adware and as such, presents an unnecessary risk which should be eliminated! Removing game.exe may cause a number of problems, such as slow performance, loss of data or leaking private information.&lt;br /&gt;&lt;br /&gt;Removing Game Dialler may be difficult.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;game.exe is related to aconti.exe, arr.exe, dvdkeyauth.exe, fastdown.exe, infus.exe, movieplace.exe, sws.exe, win32us.exe,&lt;br /&gt;&lt;br /&gt;You should visit our Anonymous Surfing section to make sure your system is not giving away information like that of game.exe.&lt;br /&gt;GAME.EXE - Disclaimer&lt;br /&gt;&lt;br /&gt;Every attempt has been made to provide you with the correct information for game.exe or GAME DIALLER. Many spyware / malware programs use filenames of usual, non-malware programs. If we have included information about game.exe that is inaccurate, we would greatly appreciate your help by updating the Process Information database and we will do our best to correct it.&lt;br /&gt;&lt;br /&gt;You should verify the accuracy of information we provided about game.exe. Game Dialler may have had a status change since this page was published.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-3658874451160396059?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/3658874451160396059/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=3658874451160396059' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/3658874451160396059'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/3658874451160396059'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/04/gameexe.html' title='GAME.EXE'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-2589693345408220140</id><published>2009-02-19T03:03:00.000-08:00</published><updated>2009-05-19T03:05:09.877-07:00</updated><title type='text'>HACKING IN LINUX</title><content type='html'>&lt;h1&gt; Hack attacks on Linux on the rise&lt;/h1&gt;                              &lt;b&gt; Hackers are increasingly targeting Web servers based on the Linux operating system, while the number of successful attacks on Windows systems decreases, according to a new report from a U.K. systems integrator. &lt;/b&gt; &lt;p&gt; The study by &lt;a href="http://mi2g.com/"&gt;Mi2g&lt;/a&gt; also found that successful attacks on U.K. and U.S. government sites have decreased, which may be due to tougher laws and improved security. &lt;/p&gt;&lt;p&gt; In the past, hackers and virus writers have largely focused their efforts on the Windows platform, as its dominance on desktop PCs makes it a ready target. However, Linux has a large share of the Web server market, and Linux server applications are often vulnerable to attack because of mismanagement, according to the study. &lt;/p&gt;&lt;p&gt; Mi2g has recorded 7,630 successful attacks on Linux systems in the first six months of this year, up sharply from last year's 5,736 attacks. In the meantime, successful attacks on Windows systems running Microsoft's Internet Information Server (IIS) have fallen by 20 percent from 11,828 in the first half of 2001 to 9,404 in the first half of this year. &lt;/p&gt;&lt;p&gt; The total number of successful attacks for the first six months of the year rose by 27 percent, from 16,007 on 2001 to 20,371 in 2002. &lt;/p&gt;&lt;p&gt; The information is based on Mi2g's own research, which includes information on more than 6,000 hacker groups and records of more than 60,000 hacking events since 1995. The database includes the Computer Security Issues and Trends Survey from the Computer Security Institute and the FBI. &lt;/p&gt;&lt;p&gt; The firm urged Linux system administrators to be more vigilant about patching known security bugs. "A quick response in addressing all weaknesses as soon as they are known has now become critical," D.K. Matai, Mi2g's chairman and chief executive, said in a statement. &lt;/p&gt;&lt;p&gt;Mi2g said that successful attacks on U.S. government systems were down sharply, from 204 in the first half of last year to 54 in the first half of 2002. In the United Kingdom, government sites were hit 12 times in the first half of this year, compared with 38 times for the first six months of 2001. &lt;/p&gt;&lt;p&gt; The security firm attributed this drop partly to improved security in the wake of last September's terrorist attacks and partly to an amendment to the Cyber Security Enhancement Act passed in February 2002. The amendment gives a life imprisonment sentence to hackers who put lives at risk. &lt;/p&gt;&lt;p&gt; Mi2g is a systems integrator focused on security. The firm is based in London and mostly deals with companies in the banking and insurance sectors. &lt;/p&gt;&lt;p&gt; &lt;i&gt;ZDNet U.K.'s Matthew Broersma reported from &lt;a href="http://news.zdnet.co.uk/"&gt;London&lt;/a&gt;&lt;/i&gt;.        &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-2589693345408220140?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/2589693345408220140/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=2589693345408220140' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/2589693345408220140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/2589693345408220140'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/hacking-in-linux.html' title='HACKING IN LINUX'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-7326445545522231240</id><published>2009-02-19T02:54:00.000-08:00</published><updated>2009-05-19T03:03:18.733-07:00</updated><title type='text'>ATTACKS IN LINUX</title><content type='html'>&lt;h1&gt;Attacker attempts to plant Trojan in Linux&lt;/h1&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;An unknown intruder attempted to insert a Trojan horse program into the code of the next version of the Linux kernel, which is stored in a publicly accessible database.&lt;/strong&gt;&lt;/p&gt;         &lt;p&gt;Security features of the source-code repository, known as BitKeeper, detected the illicit change within 24 hours, and the public database was shut down, a key developer said on Thursday. The public database was used only to provide the latest beta, or test version, of the Linux kernel to users of the Concurrent Versions System (CVS), which is a program designed to manage source code.&lt;/p&gt;          &lt;p&gt;The changes, which would have introduced a security flaw to the kernel, never became a part of the Linux code and, thus, were never a threat, said Larry McVoy, founder of software company BitMover and primary architect of the source-code database BitKeeper.&lt;/p&gt;          &lt;p&gt;"This never got close to the development tree," he said. "BitKeeper is really paranoid about integrity, and it turns out that was key to finding this Trojan horse."&lt;/p&gt;          &lt;p&gt;Linus Torvalds, the original creator of Linux and the lead developer of the kernel, uses BitKeeper to keep track of changes in the core software for the operating system. On a daily basis, the software exports those changes to public and private databases other developers use.&lt;/p&gt;          &lt;p&gt;An intruder apparently compromised one server earlier, and the attacker used his access to make a small change to one of the source code files, McVoy said. The change created a flaw that could have elevated a person's privileges on any Linux machine that runs a kernel compiled with the modified source code. However, only developers who used that database were affected -- and only during a 24-hour period, he added.&lt;/p&gt;          &lt;p&gt;"The first thing we did was fix the difference," he said. "It took me five minutes to find the change."&lt;/p&gt;          &lt;p&gt;When BitKeeper exports the source code to other servers, it checks the integrity of every file, matching a digital fingerprint of its official version of the file with the version on the remote machine. That comparison caught the change to the code stored on the server.&lt;/p&gt;          &lt;p&gt;The changes looked like they were made by another developer, but that programmer said he hadn't submitted them, McVoy said.&lt;/p&gt;          &lt;p&gt;The recent incident raises questions about the security of open-source development methods, particularly how well a development team can guarantee that any changes are not introducing intentional security flaws. While Microsoft code has had similar problems, closed development is widely considered to be harder to exploit in that way.&lt;/p&gt;          &lt;p&gt;Linus Torvalds addressed the issue in a post to the Linux kernel mailing list.&lt;/p&gt;          &lt;p&gt;"A few things do make the current system fairly secure," he stated. "One of them is that if somebody were to actually access the (BitKeeper) trees (software repositories) directly, that would be noticed immediately."&lt;/p&gt;          &lt;p&gt;A critical security flaw was found in CVS in January, but it's unknown whether the attacker used the vulnerability to gain access to the CVS database.&lt;/p&gt;          &lt;p&gt;BitKeeper's McVoy hopes the current incident will quash objections raised by some members of the development who don't want to add a new feature that would require all changes to be digitally signed.&lt;/p&gt;          &lt;p&gt;Even so, he said, the open-source development model is likely to have quickly turned up any security flaws.&lt;/p&gt;          &lt;p&gt;"A Trojan horse is just a bug that a person has put into the system deliberately," he said. "The open-source security model is that everyone is using this stuff, so bugs get found and get fixed. That's one of the reasons that you are not hearing me freak about this."&lt;/p&gt;          &lt;p&gt;McVoy said the disk from the compromised server has been saved for later analysis, but any decision to contact law enforcement belongs to Torvalds and others. Torvalds could not be immediately reached for comment.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-7326445545522231240?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/7326445545522231240/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=7326445545522231240' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/7326445545522231240'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/7326445545522231240'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/attacks-in-linux.html' title='ATTACKS IN LINUX'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-5597383618702272492</id><published>2009-02-19T02:46:00.000-08:00</published><updated>2011-08-28T04:43:41.737-07:00</updated><title type='text'>KHATRA.EXE</title><content type='html'>&lt;h2&gt;Khatra.exe (Khatra) Trojan Virus File Information&lt;/h2&gt;&lt;table border="0" style="text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt; &lt;th&gt;&lt;a href="http://www.virusremovalguru.com/wp-content/uploads/2008/12/smaller.jpg"&gt;&lt;img alt="Danger" class="size-full wp-image-776" height="52" src="http://www.virusremovalguru.com/wp-content/uploads/2008/12/smaller.jpg" title="smaller" width="59" /&gt;&lt;/a&gt;&lt;/th&gt; &lt;th&gt;Khatra.exe is a dangerous file which creates activities on a user’s computer which may be highly undesirable. This file is unsafe.&lt;/th&gt; &lt;/tr&gt;&lt;/tbody&gt; &lt;/table&gt;Type: Trojan Virus&lt;br /&gt;Location: C:\WINDOWS\system32\khatra.exe&lt;br /&gt;Risk Level: Moderate&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;IT CAN MAKE UNEXPECTED CHANGES TO UR SYSTEM.&lt;/li&gt;&lt;li&gt;IT CAN DISABLE CONTROL PANEL AND CREATES A FILE IN EACH FOLDER OF UR DRIVE.&lt;/li&gt;&lt;li&gt;THIS  FILE MAY BE OF SIZE 600 KB THUS FILLING HALF OF UR HARD DISK.&lt;/li&gt;&lt;li&gt;IT ALSO RUNS IN UR TASK MANAGER AND USES UR MEMORY.&lt;/li&gt;&lt;li&gt;IT SPREADS MAINLY THROUGH PEN DRIVES.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;br /&gt;It is recommended that you remove any malicious software such as Khatra.exe  from your computer immediately.&lt;br /&gt;&lt;br /&gt;The file "khatra.exe" is known to be created under the following filenames:          &lt;br /&gt;&lt;table cellpadding="10" cellspacing="0" class="frame"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;table cellpadding="5" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;%AllUsersProfile%\desktop.exe&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;%AllUsersProfile%\favorites.exe&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;%AppData%\microsoft\cd burning\khatra.exe&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;%CommonDesktopDir%\desktop.exe&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;%CommonFavorites%\favorites.exe&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;%DesktopDir%\desktop.exe&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;%System%\khatra.exe&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;%UserProfile%\desktop.exe&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;%Windir%\khatarnakh.exe&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;%Windir%\system\ghost.exe&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;%Windir%\xplorer.exe&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;c:\inetpub.exe&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;c:\inetpub\inetpub.exe&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;c:\inetpub\wwwroot\wwwroot.exe&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;c:\khatra.exe&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Notes:&lt;/strong&gt;         &lt;br /&gt;&lt;ul&gt;&lt;li&gt;%AllUsersProfile% is a variable that specifies the all users' profile folder. By default, this is C:\Documents and Settings\All Users (Windows NT/2000/XP).&lt;/li&gt;&lt;li&gt;%AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.&lt;/li&gt;&lt;li&gt;%CommonDesktopDir% is a variable that refers to the file system directory that contains files and folders that appear on the desktop for all users. A typical path is C:\Documents and Settings\All Users\Desktop (Windows NT/2000/XP).&lt;/li&gt;&lt;li&gt;%CommonFavorites% is a variable that refers to the file system directory that serves as a common repository for all users' favorite items. A typical path is C:\Documents and Settings\All Users\Favorites (Windows NT/2000/XP).&lt;/li&gt;&lt;li&gt;%DesktopDir% is a variable that refers to the file system directory used to physically store file objects on the desktop. A typical path is C:\Documents and Settings\[UserName]\Desktop.&lt;/li&gt;&lt;li&gt;%System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).&lt;/li&gt;&lt;li&gt;%UserProfile% is a variable that specifies the current user's profile folder. By default, this is C:\Documents and Settings\[UserName] (Windows NT/2000/XP).&lt;/li&gt;&lt;li&gt;%Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table cellpadding="2" cellspacing="0" style="width: 790px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;img alt="" src="http://www.threatexpert.com/resources/gd.gif" style="border: medium none;" /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table cellpadding="0" cellspacing="0" class="frame"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="color: #505050; font-size: small; font-weight: bold; padding: 5px 0px 5px 10px;"&gt;The file "khatra.exe" has the following possible country of origin:&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table cellpadding="10" cellspacing="0" class="frame"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;table cellpadding="5" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan="2"&gt;&lt;strong&gt;Origin&lt;/strong&gt;&lt;/td&gt;&lt;td style="width: 200px;"&gt;&lt;strong&gt;Number of Incidents&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td style="width: 16px;"&gt;&lt;img alt="" src="http://www.threatexpert.com/resources/small_flags/united_kingdom.gif" /&gt;&lt;/td&gt;&lt;td&gt;United Kingdom&lt;/td&gt;&lt;td&gt;63&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table cellpadding="2" cellspacing="0" style="width: 790px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;img alt="" src="http://www.threatexpert.com/resources/gd.gif" style="border: medium none;" /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table cellpadding="0" cellspacing="0" class="frame"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="color: #505050; font-size: small; font-weight: bold; padding: 5px 0px 5px 10px;"&gt;The following threats are known to be associated with the file "khatra.exe":&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;table cellpadding="5" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Threat Alias&lt;/strong&gt;&lt;/td&gt;&lt;td style="width: 200px;"&gt;&lt;strong&gt;Number of Incidents&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;Generic.dx [McAfee]&lt;/td&gt;&lt;td&gt;60&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Trojan-Dropper.Win32.Autoit.k [Kaspersky Lab]&lt;/td&gt;&lt;td&gt;60&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;Trojan-Dropper.Win32.Autoit [Ikarus]&lt;/td&gt;&lt;td&gt;42&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;W32.SillyFDC [Symantec]&lt;/td&gt;&lt;td&gt;21&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;Virus.Win32.Sality [Ikarus]&lt;/td&gt;&lt;td&gt;15&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Trojan Horse [Symantec]&lt;/td&gt;&lt;td&gt;12&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;W32/Autoit-BP [Sophos]&lt;/td&gt;&lt;td&gt;12&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Email-Worm.Win32.Agent.kd [Kaspersky Lab]&lt;/td&gt;&lt;td&gt;9&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;Trojan:Win32/Malagent [Microsoft]&lt;/td&gt;&lt;td&gt;9&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;W32.Harakit [Symantec]&lt;/td&gt;&lt;td&gt;9&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;Mal/Generic-A [Sophos]&lt;/td&gt;&lt;td&gt;6&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Email-Worm.Agent!sd6 [PC Tools]&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;Email-Worm.Win32.Runouce.b [Kaspersky Lab]&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Mal/Inet-Fam [Sophos]&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;PE_Chir.B [Trend Micro]&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Trojan-Dropper.Autoit!sd6 [PC Tools]&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;Virus.Win32.VB.bb [Ikarus]&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Virus:Win32/Virut.L [Microsoft]&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;W32/Chir.b@MM [McAfee]&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;W32/Chir-B [Sophos]&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr style="background-color: #f3f3f3;"&gt;&lt;td&gt;Win32.Virut.Gen.5 [PC Tools]&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Win32/ChiHack.6652 [AhnLab]&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;a href="http://www.oral8.cn/viruscom/viruscom_59050.html" style="color: #cc3300;"&gt;How to remove KHATRA.EXE&lt;/a&gt;&lt;br /&gt;&lt;h1 class="style11"&gt;&lt;a href="http://www.oral8.cn/viruscom/viruscom_59050.html" style="color: #cc3300;"&gt;KHATRA.EXE removal&lt;/a&gt;&lt;/h1&gt;KHATRA.EXE  and detail of &lt;a href="http://www.oral8.cn/viruscom/viruscom_59050.html" style="color: #cc3300;"&gt;KHATRA.EXE&lt;/a&gt;:&lt;br /&gt;KHATRA.EXE description :The filename KHATRA.EXE was last seen on 02.13.2009, and it is considered unsafe. This threat is associated with the malware group Win32.Autoit.BP. Threat name Win32.Autoit.BP Filename [System32Root]\khatra.exe Filesize Unknown Last seen 02.13.2009 Status Known to RemoveIT Pro as unsafe. This file can perform following behavior. - File is created as process on the disk. - This process can create, delete or modify files on the disk.&lt;br /&gt;KHATRA.EXE remove instruction  &lt;br /&gt;1. Temporarily Disable System Restore,  Reboot computer in SafeMode;  &lt;br /&gt;&lt;br /&gt;2. Locate KHATRA.EXE virus files and uninstall KHATRA.EXE files program. Follow the screen step-by-step screen instructions to complete uninstallation of KHATRA.EXE. &lt;br /&gt;&lt;br /&gt;3. Delete/Modify any values added to the registry related with KHATRA.EXE,Exit registry editor and restart the computer;      &lt;br /&gt;&lt;br /&gt;4.Clean/delete all KHATRA.EXEinfected file(s):KHATRA.EXE and related,or rename KHATRA.EXE virus files;       &lt;br /&gt;&lt;br /&gt;5.Please delete all your IE temp files with KHATRA.EXE manually,run a whole scan with antivirus program ;&lt;br /&gt;enable 'show all hidden files..' option in windows explorer view menu and&lt;br /&gt;&lt;br /&gt;6.Search all your harddrive files and folders for '*.exe' with size&amp;lt;1mb and delete only '&lt;folder&gt;.exe' files having folder symbol(name of the folder).&amp;nbsp;&lt;/folder&gt;&lt;br /&gt;&lt;br /&gt;THEN FORMAT UR OS DRIVE.USE NOD32 OR AVAST FOR BETTER RESULTS.&lt;br /&gt;&lt;div class="style13 style17 style13"&gt;&lt;br /&gt;Need help for remove KHATRA.EXE? Post you problem on&lt;strong&gt;&lt;a href="http://help.antiviruses123.com/" style="color: #cc3300;"&gt; Free Virus Remove Help forum&lt;/a&gt; URL:&lt;a href="http://help.antiviruses123.com/" style="color: #cc3300;"&gt;http://help.antiviruses123.com&lt;/a&gt;&lt;/strong&gt;. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-5597383618702272492?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/5597383618702272492/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=5597383618702272492' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/5597383618702272492'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/5597383618702272492'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/khatraexe.html' title='KHATRA.EXE'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-6624453598512496416</id><published>2009-02-18T08:30:00.001-08:00</published><updated>2009-02-18T08:30:53.566-08:00</updated><title type='text'>HOAXES</title><content type='html'>&lt;table id="enciclo_tabla" border="0" cellpadding="0" cellspacing="0" width="100%"&gt;&lt;tbody&gt;&lt;tr class="encabeza"&gt;&lt;td&gt;&lt;strong&gt;Hoax&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Brief description&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt; &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000121&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;PIN1234&lt;/a&gt;&lt;/td&gt;&lt;td align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000121&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;It generates a false alarm by reporting the existence of a trick...&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="confondo"&gt;&lt;td&gt; &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000119&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Xato100&lt;/a&gt;&lt;/td&gt;&lt;td align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000119&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;It generates a false alarm by reporting that a virus that does not...&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt; &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000118&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Ericsson&lt;/a&gt;&lt;/td&gt;&lt;td align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000118&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;It tries to get users to forward the message with the false promise...&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="confondo"&gt;&lt;td&gt; &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000117&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Copa del Mundo 2006&lt;/a&gt;&lt;/td&gt;&lt;td align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000117&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;It generates a false alarm by reporting that a virus that does not...&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt; &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000116&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Invitacion&lt;/a&gt;&lt;/td&gt;&lt;td align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000116&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;It generates a false alarm by reporting that a virus that does not...&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="confondo"&gt;&lt;td&gt; &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000114&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Hoax/Tsunami in South Asia&lt;/a&gt;&lt;/td&gt;&lt;td align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000114&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;It appeals to well-meaning users trying to get them to forward the...&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt; &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000115&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;ICE hoax&lt;/a&gt;&lt;/td&gt;&lt;td align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000115&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;It generates a false alarm by reporting the existence of threats...&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="confondo"&gt;&lt;td&gt; &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000112&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Athens2004&lt;/a&gt;&lt;/td&gt;&lt;td align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000112&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;It generates a false alarm by reporting that a virus that does not...&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt; &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000108&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Llamadas Perdidas&lt;/a&gt;&lt;/td&gt;&lt;td align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000108&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;It generates a false alarm by reporting that several telecom...&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="confondo"&gt;&lt;td&gt; &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000106&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Frog and Fish warnings&lt;/a&gt;&lt;/td&gt;&lt;td align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000106&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;It generates a false alarm by reporting that there are two jokes...&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt; &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000096&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Bonsai Kittens&lt;/a&gt;&lt;/td&gt;&lt;td align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000096&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;It attempts to trick users into forwarding the message to as many...&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="confondo"&gt;&lt;td&gt; &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000095&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Girls of Playboy&lt;/a&gt;&lt;/td&gt;&lt;td align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=1000095&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;It generates a false alarm by reporting that a virus that does not...&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-6624453598512496416?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/6624453598512496416/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=6624453598512496416' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/6624453598512496416'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/6624453598512496416'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/hoaxes.html' title='HOAXES'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-8311705274959397313</id><published>2009-02-17T08:38:00.000-08:00</published><updated>2009-02-17T08:40:08.440-08:00</updated><title type='text'>W32 THREATS</title><content type='html'>&lt;span style="font-family:arial;"&gt;W32.HLLW.Cebe: This worm spreads through the KaZaa and iMesh file-sharing networks.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;W32.Swen.A@mm: This mass-mailing worm uses its own SMTP engine to spread.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;W32.Sobig.A@mm: This worm sends itself to all the addresses it finds in the .txt, .eml, .html, .htm, .dbx, and .wab files.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;W32.Blaster.Worm: This worm exploits a DCOM RPC vulnerability using TCP port 135.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-8311705274959397313?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/8311705274959397313/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=8311705274959397313' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/8311705274959397313'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/8311705274959397313'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/w32-threats.html' title='W32 THREATS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-4230283633172154978</id><published>2009-02-16T08:18:00.000-08:00</published><updated>2009-03-07T09:26:06.620-08:00</updated><title type='text'>INSIDE THREATS</title><content type='html'>&lt;span style="font-family:arial;"&gt;      Security threats that originate from inside a network can be more harmful than outside threats. Inside threats are especially dangerous and can often be overlooked by network administrators. Computers that reside on the inside network typically have a high degree of access to inside resources. Also, employees and trusted users are likely to have critical information about the network, including passwords.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;High profile inside threats include disloyal and disgruntled employees who use their inside access to destroy, steal, or tamper with data. These types of attacks cannot be completely protected against. However, well defined security policies can minimize the risks from this type of threat. For example, organizations should avoid using just a handful of passwords to protect all computer resources. Large companies should establish clear procedures for removing employee accounts and passwords in the event that an employee leaves the company.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;The most harmful inside threat is a typical end user of a network. Unaware end users can crash a network by carelessly opening e-mail attachments, installing unauthorized software, mounting disks from home, or even browsing the web. The typical cause of inside attacks is an end user who opens an e-mail attachment only to copy a virus to the computer. Many viruses thrive on the corporate network. E-mail viruses typically mail themselves to accounts listed in e-mail address books. Many corporations keep staff e-mail lists loaded on every computer, where a virus can quickly spread to all members of a company. Viruses can also seek out and infect shared files and folders, which are common on corporate networks.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;A growing problem for corporate networks is the widespread popularity of instant messaging and peer-to-peer file sharing. Employees may download instant message software, such as Microsoft Messenger or America Online (AOL) Instant Messenger. The instant message software is used to chat in real time with co workers, friends, and family. Other users may download peer-to-peer file sharing software based on Gnutella or some other technology. Both instant messaging and peer-to-peer file sharing programs can be used to transfer virus-infected files to the local computer. Both of these types of programs listen for connections originating from the Internet. Chat and file sharing applications may be vulnerable to other forms of exploitation. &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-4230283633172154978?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/4230283633172154978/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=4230283633172154978' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/4230283633172154978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/4230283633172154978'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/inside-threats.html' title='INSIDE THREATS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-3816397583329659409</id><published>2009-02-15T02:43:00.000-08:00</published><updated>2009-03-15T03:02:25.188-07:00</updated><title type='text'>PICTURES</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_Q92aoloWYdM/SbzSI3GBlPI/AAAAAAAAAEI/FE164jZBj3I/s1600-h/securnoc_diagram_large.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5313352710060348658" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 286px; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_Q92aoloWYdM/SbzSI3GBlPI/AAAAAAAAAEI/FE164jZBj3I/s320/securnoc_diagram_large.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://1.bp.blogspot.com/_Q92aoloWYdM/SbzSIs247uI/AAAAAAAAAEA/5iJ9rZqqHy8/s1600-h/outsourced_network_security_services_clip_image002.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5313352707312512738" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 298px; CURSOR: hand; HEIGHT: 320px; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_Q92aoloWYdM/SbzSIs247uI/AAAAAAAAAEA/5iJ9rZqqHy8/s320/outsourced_network_security_services_clip_image002.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://4.bp.blogspot.com/_Q92aoloWYdM/SbzR4qc_PSI/AAAAAAAAAD4/fOYcNw6Inic/s1600-h/MALWARE.bmp"&gt;&lt;img id="BLOGGER_PHOTO_ID_5313352431789096226" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 216px; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_Q92aoloWYdM/SbzR4qc_PSI/AAAAAAAAAD4/fOYcNw6Inic/s320/MALWARE.bmp" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://3.bp.blogspot.com/_Q92aoloWYdM/SbzR4UYnz5I/AAAAAAAAADw/e_tgLe55Nb4/s1600-h/FIREWALL.bmp"&gt;&lt;img id="BLOGGER_PHOTO_ID_5313352425865203602" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 246px; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_Q92aoloWYdM/SbzR4UYnz5I/AAAAAAAAADw/e_tgLe55Nb4/s320/FIREWALL.bmp" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://3.bp.blogspot.com/_Q92aoloWYdM/SbzR3hGOE_I/AAAAAAAAADo/M_4PvvgDHdI/s1600-h/FIRE.bmp"&gt;&lt;img id="BLOGGER_PHOTO_ID_5313352412097811442" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 240px; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_Q92aoloWYdM/SbzR3hGOE_I/AAAAAAAAADo/M_4PvvgDHdI/s320/FIRE.bmp" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://4.bp.blogspot.com/_Q92aoloWYdM/SbzOVhRTyTI/AAAAAAAAADQ/cFygh0Q-8iA/s1600-h/network-security-small.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5313348529493887282" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 234px; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_Q92aoloWYdM/SbzOVhRTyTI/AAAAAAAAADQ/cFygh0Q-8iA/s320/network-security-small.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://2.bp.blogspot.com/_Q92aoloWYdM/SbzOVfl2uZI/AAAAAAAAADI/WAvoe6OgUKU/s1600-h/network-centric_security_processes.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5313348529043192210" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 240px; TEXT-ALIGN: center" alt="" src="http://2.bp.blogspot.com/_Q92aoloWYdM/SbzOVfl2uZI/AAAAAAAAADI/WAvoe6OgUKU/s320/network-centric_security_processes.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://1.bp.blogspot.com/_Q92aoloWYdM/SbzOVH-GjlI/AAAAAAAAADA/rJjjUPGBjac/s1600-h/firewall_env.gif"&gt;&lt;img id="BLOGGER_PHOTO_ID_5313348522702442066" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 192px; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_Q92aoloWYdM/SbzOVH-GjlI/AAAAAAAAADA/rJjjUPGBjac/s320/firewall_env.gif" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://4.bp.blogspot.com/_Q92aoloWYdM/SbzOUrqn6YI/AAAAAAAAAC4/jnfPofqf_K8/s1600-h/elements1.gif"&gt;&lt;img id="BLOGGER_PHOTO_ID_5313348515104549250" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 202px; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_Q92aoloWYdM/SbzOUrqn6YI/AAAAAAAAAC4/jnfPofqf_K8/s320/elements1.gif" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://3.bp.blogspot.com/_Q92aoloWYdM/SbzOUNOs_lI/AAAAAAAAACw/D1XhC6Q_bOY/s1600-h/diagram_network_security.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5313348506934378066" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 320px; CURSOR: hand; HEIGHT: 243px; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_Q92aoloWYdM/SbzOUNOs_lI/AAAAAAAAACw/D1XhC6Q_bOY/s320/diagram_network_security.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-3816397583329659409?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/3816397583329659409/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=3816397583329659409' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/3816397583329659409'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/3816397583329659409'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/03/pictures.html' title='PICTURES'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Q92aoloWYdM/SbzSI3GBlPI/AAAAAAAAAEI/FE164jZBj3I/s72-c/securnoc_diagram_large.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-9040338087358021457</id><published>2009-02-13T11:31:00.000-08:00</published><updated>2009-05-03T23:21:49.354-07:00</updated><title type='text'>SPYWARE</title><content type='html'>&lt;div align="left"&gt;&lt;span&gt;Spyware&lt;br /&gt;Threat                Type           First appeared&lt;br /&gt;1  Gator               Adware       Sep 11, 2003&lt;br /&gt;2  Virtumonde    Spyware     Oct 08, 2004&lt;br /&gt;3  SaveNow         Adware       Sep 11, 2003&lt;br /&gt;4  ClientMan       Spyware     Jul 27, 2004&lt;br /&gt;5  WUpd              Adware      Sep 03, 2004&lt;br /&gt;6  ActiveSearch  Adware      Oct 28, 2004&lt;br /&gt;7  BaiduBar         Adware      May 02, 2005&lt;br /&gt;8  MarketScore  Spyware    Sep 17, 2004&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;SPYWARE EXPLOIT USER INFORMATION&lt;br /&gt;The spyware problem is an invasion of privacy, although different from cookies, technically speaking. Spyware is a program that runs on your computer and again, tracks your habits, tailors these patterns for advertisements, etc. Because it is a computer program, rather than just a bit of text in a cookie, spyware can also do some nasty things to ensure that the spyware keeps running and keeps influencing what you see.&lt;br /&gt;&lt;br /&gt;HOW DO I KNOW IF SPYWARE IS RUNNING ON THE COMPUTER?&lt;br /&gt;You can use detection programs such as Ad Aware and others. Similar to anti-virus software, these programs compare a list of known spyware with files on your computer and can remove any that it detects, but again, what some consider unacceptable is perfectly acceptable to others.&lt;br /&gt;&lt;br /&gt;HOW DOES SPYWARE INSTALL ITSELF ON COMPUTERS?&lt;br /&gt;Common tactics for surreptitious installation include rolling up advertising programs into "free" shareware program downloads, and once the spyware is installed it can download advertisements 24 hours a day and overlay them on Web sites and programs you are using. Anti-spyware programs can combat spyware from being installed, but the best strategy is to discriminate what you choose to download and install.&lt;br /&gt;&lt;br /&gt;CAN SPYWARE SEND TRACKED INFORMATION TO OTHER PEOPLE?&lt;br /&gt;Some forms of spyware monitor a target’s Web use or even general computer use and sends this information back to the spyware program's authors for use as they see fit. To fight this kind of problem, a spyware removal tool is obviously helpful, as is a firewall that monitors outgoing connections from your computer. Other forms of spyware take over parts of your Web browsing interface, forcing you to use their own search engines where they can track your browsing habits and send pop-up advertisements to you at will.&lt;br /&gt;The biggest concern regarding spyware is that most of them are poorly written or designed. Many people first realize their computer is running when it noticeably slows down or stops responding, especially when doing certain tasks such as browsing Web sites or retrieving email. In addition, poorly written spyware can often cause your computer to function incorrectly even after it has been removed.&lt;br /&gt;&lt;span class="art_title"&gt;&lt;br /&gt;Are Spyware Threats Taking Over Your Computer?&lt;br /&gt;&lt;/span&gt;&lt;div id="body"&gt;&lt;p&gt;Are you fed up with the amount of spyware that roams onto your computer? Most of the time you can't really do anything about the threats but deal with them. Furthermore, most people do not realize that most of the simple things they do while on their computer is what makes their computer becomes affected with various spyware threats.&lt;/p&gt;&lt;p&gt;For instance have you ever downloaded a type of program off the internet whether it was from a secured website or from another person? Most of the time people may not know that when they download something of interest off the internet whether it is free or paid for, it may include spyware threats that are attached within the program. Usually, when the spyware threats are included in these programs they are stated within the license agreement that most people are too lazy to read. They are more quick to install the program that they dont take the time to read the license agreement to find out if any type of threat will be included with the program.&lt;/p&gt;&lt;p&gt;If you are a big fan of downloading off of the internet then you may have some experience with spyware threats being on your computer from some files that you may have downloaded. Have you ever experienced those continuous pop-ups that may appear while you are on the internet? Again, your computer has been infected with spyware. This can be very frustrating to deal with because as you surf the internet the pop-ups just keep on rolling and rolling whenever you click on something new.&lt;/p&gt;&lt;p&gt;Spyware threats can be a pain to deal with and they just make your computer slower and slower to the point where you don't even want to get onto your computer anymore. Most people compensate this problem by shelling out hundreds of dollars just to get their computer cleaned.&lt;/p&gt;&lt;/div&gt;&lt;br /&gt;&lt;span class="art_title"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-9040338087358021457?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/9040338087358021457/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=9040338087358021457' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/9040338087358021457'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/9040338087358021457'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/01/spyware-threat-type-first-appeared-1.html' title='SPYWARE'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-727927122126241335</id><published>2009-02-13T11:23:00.000-08:00</published><updated>2009-03-07T09:28:46.346-08:00</updated><title type='text'>MOST ACTIVE VIRUSES</title><content type='html'>&lt;div align="left"&gt;&lt;table id="enciclo_tabla" border="0" cellpadding="0" cellspacing="0" width="100%"&gt;&lt;tbody&gt;&lt;tr class="encabeza"&gt;&lt;td&gt;&lt;strong&gt;Virus&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;PCs infected&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Threat Level&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;First appeared&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;    &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=173377&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;1    MaliciousP&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=173377&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;7.34%    &lt;/a&gt;&lt;/td&gt;&lt;td href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=173377&amp;amp;sind=0"&gt;&lt;img src="http://www.pandasecurity.com/img/puntos_1.gif" title="Low Threat" height="13" width="34" /&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=173377&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Sep 06, 2007&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="confondo"&gt;    &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=204292&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;2    Conficker.C&lt;/a&gt;&lt;/td&gt;&lt;td class="confondo"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=204292&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;5.39%    &lt;/a&gt;&lt;/td&gt;&lt;td class="confondo" href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=204292&amp;amp;sind=0"&gt;&lt;img src="http://www.pandasecurity.com/img/puntos_2.gif" title="Moderate Threat" height="13" width="34" /&gt;&lt;/td&gt;&lt;td class="confondo"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=204292&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Dec 31, 2008&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;    &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=205240&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;3    Lineage.KMF&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=205240&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;3.69%    &lt;/a&gt;&lt;/td&gt;&lt;td href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=205240&amp;amp;sind=0"&gt;&lt;img src="http://www.pandasecurity.com/img/puntos_2.gif" title="Moderate Threat" height="13" width="34" /&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=205240&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Jan 29, 2009&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="confondo"&gt;    &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=189792&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;4    AdsRevenue&lt;/a&gt;&lt;/td&gt;&lt;td class="confondo"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=189792&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;3.57%    &lt;/a&gt;&lt;/td&gt;&lt;td class="confondo" href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=189792&amp;amp;sind=0"&gt;&lt;img src="http://www.pandasecurity.com/img/puntos_1.gif" title="1" height="13" width="34" /&gt;&lt;/td&gt;&lt;td class="confondo"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=189792&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Mar 10, 2008&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;    &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=53087&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;5    Virtumonde&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=53087&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;3.14%    &lt;/a&gt;&lt;/td&gt;&lt;td href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=53087&amp;amp;sind=0"&gt;&lt;img src="http://www.pandasecurity.com/img/puntos_2.gif" title="Moderate Threat" height="13" width="34" /&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=53087&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Oct 08, 2004&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="confondo"&gt;    &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=40682&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;6    MyWay&lt;/a&gt;&lt;/td&gt;&lt;td class="confondo"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=40682&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;2.34%    &lt;/a&gt;&lt;/td&gt;&lt;td class="confondo" href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=40682&amp;amp;sind=0"&gt;&lt;img src="http://www.pandasecurity.com/img/puntos_1.gif" title="1" height="13" width="34" /&gt;&lt;/td&gt;&lt;td class="confondo"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=40682&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Sep 11, 2003&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;    &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=143883&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;7    Downloader.MDW&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=143883&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;2.32%    &lt;/a&gt;&lt;/td&gt;&lt;td href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=143883&amp;amp;sind=0"&gt;&lt;img src="http://www.pandasecurity.com/img/puntos_3.gif" title="High Threat" height="13" width="34" /&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=143883&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Jan 02, 2007&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="confondo"&gt;    &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=194318&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;8    Xor-encoded.A&lt;/a&gt;&lt;/td&gt;&lt;td class="confondo"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=194318&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;1.76%    &lt;/a&gt;&lt;/td&gt;&lt;td class="confondo" href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=194318&amp;amp;sind=0"&gt;&lt;img src="http://www.pandasecurity.com/img/puntos_1.gif" title="1" height="13" width="34" /&gt;&lt;/td&gt;&lt;td class="confondo"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=194318&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Jun 02, 2008&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;    &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=143979&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;9    Lineage.BZE&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=143979&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;1.59%    &lt;/a&gt;&lt;/td&gt;&lt;td href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=143979&amp;amp;sind=0"&gt;&lt;img src="http://www.pandasecurity.com/img/puntos_2.gif" title="Moderate Threat" height="13" width="34" /&gt;&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=143979&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Jan 02, 2007&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="confondo"&gt;    &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=205474&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;10    Autorun.INF&lt;/a&gt;&lt;/td&gt;&lt;td class="confondo"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=205474&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;1.47%    &lt;/a&gt;&lt;/td&gt;&lt;td class="confondo" href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=205474&amp;amp;sind=0"&gt;&lt;img src="http://www.pandasecurity.com/img/puntos_1.gif" title="Low Threat" height="13" width="34" /&gt;&lt;/td&gt;&lt;td class="confondo"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=205474&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Feb 04, 2009&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;span&gt;&lt;br /&gt;Most Active Viruses&lt;br /&gt;Virus                               PCsinfected      First appeared&lt;br /&gt;1  AdsRevenue               5.91%                  Mar 10, 2008&lt;br /&gt;2  Virtumonde                5.14%                  Oct 08, 2004&lt;br /&gt;3  AutoRun.DJ               1.52%                  Oct 24, 2007&lt;br /&gt;4  Downloader.MDW    1.34%                  Jan 02, 2007&lt;br /&gt;5  Xor-encoded.A          1.30%                 Jun 02, 2008&lt;br /&gt;6  Antivirus2009          1.24%                 Jul 19, 2008&lt;/span&gt;&lt;span&gt;&lt;br /&gt;7  GetaCodec.A             0.96%                 Nov 06, 2008&lt;br /&gt;8  HideWindow.S          0.88%                Jun 25, 2006&lt;br /&gt;9  MaliciousP                0.85%                Sep 06, 2007&lt;br /&gt;10  Lineage.BZE          0.84%                Jan 02, 2007&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-727927122126241335?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/727927122126241335/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=727927122126241335' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/727927122126241335'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/727927122126241335'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/01/most-active-viruses-virus-pcsinfected.html' title='MOST ACTIVE VIRUSES'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-6417848559487727578</id><published>2009-02-13T11:00:00.000-08:00</published><updated>2009-02-21T09:09:28.676-08:00</updated><title type='text'>LATEST THREATS</title><content type='html'>&lt;div align="left"&gt;&lt;table id="enciclo_tabla" cellspacing="0" cellpadding="0" width="100%" border="0"&gt;&lt;tbody&gt;&lt;tr class="encabeza"&gt;&lt;td&gt;&lt;strong&gt;Threat&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Type&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Threat level&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;First appeared&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205738&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;1 MS09-005&lt;/a&gt;&lt;/td&gt;&lt;td valign="top" align="left" width="100"&gt;&lt;a href="javascript:abre(" entorno="0#VULNERA')&amp;quot;"&gt;Vulnerability&lt;/a&gt;&lt;/td&gt;&lt;td href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205738&amp;amp;sind=0"&gt;&lt;img title="Low Threat" height="13" src="http://www.pandasecurity.com/img/puntos_1.gif" width="34" /&gt;&lt;/td&gt;&lt;td valign="top" align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205738&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Feb 11, 2009&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="confondo"&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205737&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;2 MS09-004&lt;/a&gt;&lt;/td&gt;&lt;td valign="top" align="left" width="100"&gt;&lt;a href="javascript:abre(" entorno="0#VULNERA')&amp;quot;"&gt;Vulnerability&lt;/a&gt;&lt;/td&gt;&lt;td href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205737&amp;amp;sind=0"&gt;&lt;img title="Low Threat" height="13" src="http://www.pandasecurity.com/img/puntos_1.gif" width="34" /&gt;&lt;/td&gt;&lt;td valign="top" align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205737&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Feb 11, 2009&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205736&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;3 MS09-003&lt;/a&gt;&lt;/td&gt;&lt;td valign="top" align="left" width="100"&gt;&lt;a href="javascript:abre(" entorno="0#VULNERA')&amp;quot;"&gt;Vulnerability&lt;/a&gt;&lt;/td&gt;&lt;td href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205736&amp;amp;sind=0"&gt;&lt;img title="Low Threat" height="13" src="http://www.pandasecurity.com/img/puntos_1.gif" width="34" /&gt;&lt;/td&gt;&lt;td valign="top" align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205736&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Feb 11, 2009&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="confondo"&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205735&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;4 MS09-002&lt;/a&gt;&lt;/td&gt;&lt;td valign="top" align="left" width="100"&gt;&lt;a href="javascript:abre(" entorno="0#VULNERA')&amp;quot;"&gt;Vulnerability&lt;/a&gt;&lt;/td&gt;&lt;td href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205735&amp;amp;sind=0"&gt;&lt;img title="Low Threat" height="13" src="http://www.pandasecurity.com/img/puntos_1.gif" width="34" /&gt;&lt;/td&gt;&lt;td valign="top" align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205735&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Feb 11, 2009&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205692&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;5 Waledac.J&lt;/a&gt;&lt;/td&gt;&lt;td valign="top" align="left" width="100"&gt;&lt;a href="javascript:abre(" entorno="0#GUSANO')&amp;quot;"&gt;Worm&lt;/a&gt;&lt;/td&gt;&lt;td href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205692&amp;amp;sind=0"&gt;&lt;img title="Low Threat" height="13" src="http://www.pandasecurity.com/img/puntos_1.gif" width="34" /&gt;&lt;/td&gt;&lt;td valign="top" align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205692&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Feb 10, 2009&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="confondo"&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205603&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;6 NoVideo.A&lt;/a&gt;&lt;/td&gt;&lt;td valign="top" align="left" width="100"&gt;&lt;a href="javascript:abre(" entorno="0#TROYANO')&amp;quot;"&gt;Trojan&lt;/a&gt;&lt;/td&gt;&lt;td href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205603&amp;amp;sind=0"&gt;&lt;img title="Low Threat" height="13" src="http://www.pandasecurity.com/img/puntos_1.gif" width="34" /&gt;&lt;/td&gt;&lt;td valign="top" align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205603&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Feb 08, 2009&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205546&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;7 Autorun.INJ&lt;/a&gt;&lt;/td&gt;&lt;td valign="top" align="left" width="100"&gt;&lt;a href="javascript:abre(" entorno="0#GUSANO')&amp;quot;"&gt;Worm&lt;/a&gt;&lt;/td&gt;&lt;td href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205546&amp;amp;sind=0"&gt;&lt;img title="Low Threat" height="13" src="http://www.pandasecurity.com/img/puntos_1.gif" width="34" /&gt;&lt;/td&gt;&lt;td valign="top" align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205546&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Feb 06, 2009&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="confondo"&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205521&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;8 Sinowal.VZR&lt;/a&gt;&lt;/td&gt;&lt;td valign="top" align="left" width="100"&gt;&lt;a href="javascript:abre(" entorno="0#TROYANO')&amp;quot;"&gt;Trojan&lt;/a&gt;&lt;/td&gt;&lt;td href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205521&amp;amp;sind=0"&gt;&lt;img title="Low Threat" height="13" src="http://www.pandasecurity.com/img/puntos_1.gif" width="34" /&gt;&lt;/td&gt;&lt;td valign="top" align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205521&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Feb 05, 2009&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205500&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;9 Sality.AO&lt;/a&gt;&lt;/td&gt;&lt;td valign="top" align="left" width="100"&gt;&lt;a href="javascript:abre(" entorno="0#VIRUS')&amp;quot;"&gt;Virus&lt;/a&gt;&lt;/td&gt;&lt;td href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205500&amp;amp;sind=0"&gt;&lt;img title="Low Threat" height="13" src="http://www.pandasecurity.com/img/puntos_1.gif" width="34" /&gt;&lt;/td&gt;&lt;td valign="top" align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205500&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Feb 05, 2009&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="confondo"&gt;&lt;td&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205289&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;10 MSNWorm.FU&lt;/a&gt;&lt;/td&gt;&lt;td valign="top" align="left" width="100"&gt;&lt;a href="javascript:abre(" entorno="0#GUSANO')&amp;quot;"&gt;Worm&lt;/a&gt;&lt;/td&gt;&lt;td href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205289&amp;amp;sind=0"&gt;&lt;img title="Low Threat" height="13" src="http://www.pandasecurity.com/img/puntos_1.gif" width="34" /&gt;&lt;/td&gt;&lt;td valign="top" align="left"&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=205289&amp;amp;sind=0&amp;amp;sitepanda=particulares"&gt;Jan 30, 2009&lt;/a&gt;&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;span style="font-size:0;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:verdana;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:verdana;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;span style="font-family:verdana;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-6417848559487727578?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/6417848559487727578/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=6417848559487727578' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/6417848559487727578'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/6417848559487727578'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/01/latest-threats-threat-type-first_13.html' title='LATEST THREATS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-3864256381271853587</id><published>2009-02-08T04:58:00.000-08:00</published><updated>2009-04-08T04:59:32.757-07:00</updated><title type='text'>PACKET ATTACK</title><content type='html'>The Packet Fragmentation Attack&lt;br /&gt;Packet fragmentation can be utilized to get around blocking rules on some firewalls.&lt;br /&gt;This is done by cheating with the value of the Fragment Offset. The trick is to set the value of the Fragment Offset on the second packet so low that instead of appending the second packet to the first packet, it actually overwrites the data and part of the TCP header of the first packet.&lt;br /&gt;Let's say you want to `telnet` into a network where TCP port 23 is blocked by a packet filtering firewall. However, SMTP port 25 is allowed into that network.&lt;br /&gt;What you would do is to send two packets:&lt;br /&gt;The first packet would:&lt;br /&gt;• Have a Fragmentation Offset of 0. &lt;br /&gt;• Have the DF bit equal to 0 to mean "May Fragment" and the MF bit equal to 1 to mean "More Fragments." &lt;br /&gt;• Have a Destination Port in the TCP header of 25. TCP port 25 is allowed, so the firewall would allow that packet to enter the network. &lt;br /&gt;The second packet would:&lt;br /&gt;• Have a Fragmentation Offset of 1. This means that the second packet would actually overwrite everything but the first 8 bits of the first packet. &lt;br /&gt;• Have the DF bit equal to 0 to mean "May Fragment" and the MF bit equal to 0 to mean "Last Fragment." &lt;br /&gt;• Have a Destination Port in the TCP header of 23. This would normally be blocked, but will not be in this case! &lt;br /&gt;The packet filtering firewall will see that the Fragment Offset is greater than zero on the second packet. From this data, it will deduce that the second packet is a fragment of another packet and it will not check the second packet against the rule set.&lt;br /&gt;When the two packets arrive at the target host, they will be reassembled. The second packet will overwrite most of the first packet and the contents of the combined packet will go to port 23.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-3864256381271853587?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/3864256381271853587/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=3864256381271853587' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/3864256381271853587'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/3864256381271853587'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/packet-attack.html' title='PACKET ATTACK'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-5739301262266993511</id><published>2009-02-08T04:57:00.000-08:00</published><updated>2009-04-08T04:58:13.741-07:00</updated><title type='text'>TCP ATTACKS</title><content type='html'>The TCP Sequence Prediction Attack&lt;br /&gt;TCP is a reliable connection-oriented layer 4 (Transport Layer) protocol. Packet transfer between hosts is accomplished by the layers below layer 4 and TCP takes responsibility to making certain the packets are delivered to higher layers in the protocol stack in the correct order. To accomplish this reordering task, TCP uses the sequence number field.&lt;br /&gt;To successfully mount a TCP sequence prediction attack, you must first listen to communications between two systems, one of which is your target system. Then, you issue packets from your system to the target system with the source IP address of the trusted system that is communicating with the target system.&lt;br /&gt;The packets you issue must have the sequence numbers that the target system is expecting. In addition, your packets must arrive before the packets from the trusted system whose connection you are hijacking. To accomplish this, it is often necessary to flood the trusted system off of the network with some form of denial of service attack.&lt;br /&gt;Once you have taken over the connection, you can send data to allow you to access the target host using a normal TCP/IP connection. The most simple way to do this is:&lt;br /&gt;echo "+ +" &gt; /.rhosts &lt;br /&gt;This specific technique relies upon inherent weaknesses in the BSD Unix `r` services. However, SunRPC, NFS, X-Windows, and many other services which rely upon IP address authentication can be exploited with a TCP sequence prediction attack.&lt;br /&gt;Why are TCP Sequence Prediction Attacks Possible?&lt;br /&gt;An excerpt from RFC 793 (Transmission Control Protocol) concerning the generation of TCP sequence numbers:&lt;br /&gt;When new connections are created, an initial sequence number (ISN) generator is employed which selects a new 32 bit ISN. The generator is bound to a (possibly fictitious) 32 bit clock whose low order bit is incremented roughly every 4 microseconds. Thus, the ISN cycles approximately every 4.55 hours. Since we assume that segments will stay in the network no more than the Maximum Segment Lifetime (MSL) and that the MSL is less than 4.55 hours we can reasonably assume that ISN's will be unique.&lt;br /&gt;The developers of the BSD Unix TCP/IP stack did not follow these recommendations. TCP/IP stacks based upon BSD Unix increase the sequence number by 128,000 every second and by 64,000 for every new TCP connection. This is significantly more predictable than the algorithm specified in the RFC.&lt;br /&gt;Defending Against TCP Sequence Prediction Attacks&lt;br /&gt;TCP sequence prediction attacks can be effectively stopped by any router or firewall that is configured not to allow packets from an internal IP address to originate from an external interface.&lt;br /&gt;These does not fix the TCP sequence prediction vulnerability, it simply prevents TCP sequence prediction attacks from being able to reach their targets.&lt;br /&gt;Diagram of the TCP Header&lt;br /&gt;                        TCP Header Format&lt;br /&gt;                        -----------------&lt;br /&gt;&lt;br /&gt; 0                   1                   2                   3&lt;br /&gt; 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1&lt;br /&gt;+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+&lt;br /&gt;|          Source Port          |       Destination Port        |&lt;br /&gt;+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+&lt;br /&gt;|                        Sequence Number                        |&lt;br /&gt;+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+&lt;br /&gt;|                    Acknowledgment Number                      |&lt;br /&gt;+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+&lt;br /&gt;|  Data |           |U|A|P|R|S|F|                               |&lt;br /&gt;| Offset| Reserved  |R|C|S|S|Y|I|            Window             |&lt;br /&gt;|       |           |G|K|H|T|N|N|                               |&lt;br /&gt;+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+&lt;br /&gt;|           Checksum            |         Urgent Pointer        |&lt;br /&gt;+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+&lt;br /&gt;|                    Options                    |    Padding    |&lt;br /&gt;+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+&lt;br /&gt;|                             data                              |&lt;br /&gt;+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+&lt;br /&gt;Every packet-based network has an MTU (Maximum Transmission Unit) size. The MTU is the size of the largest packet which that network can transmit.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Packets larger than the allowable MTU must be divided into multiple smaller packets, or fragments, to enable them to traverse the network.&lt;br /&gt;Network Standard MTU&lt;br /&gt;Ethernet&lt;br /&gt;1500&lt;br /&gt;Token Ring 4096&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-5739301262266993511?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/5739301262266993511/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=5739301262266993511' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/5739301262266993511'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/5739301262266993511'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/tcp-attacks.html' title='TCP ATTACKS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-723310137921413726</id><published>2009-02-08T04:51:00.000-08:00</published><updated>2009-04-08T04:52:23.555-07:00</updated><title type='text'>DOS ATTACKS</title><content type='html'>Types of Denial of Service (DoS) attacks&lt;br /&gt;These are a few of the classic denial of service attacks. Most of these rely upon weaknesses in the TCP/IP protocol. Vendor patches and proper network configuration have made most of these denial of service attacks difficult or impossible to accomplish.&lt;br /&gt;Flood Attack&lt;br /&gt;The earliest form of denial of service attack was the flood attack. The attacker simply sends more traffic than the victim could handle. This requires the attacker to have a faster network connection than the victim. This is the lowest-tech of the denial of service attacks, and also the most difficult to completely prevent.&lt;br /&gt;Ping of Death Attack&lt;br /&gt;The Ping of Death attack relied on a bug in the Berkeley TCP/IP stack which also existed on most systems which copied the Berkeley network code. The ping of death was simply sending ping packets larger than 65,535 bytes to the victim. This denial of service attack was as simple as:&lt;br /&gt;ping -l 86600 victim.org&lt;br /&gt;SYN Attack&lt;br /&gt;In the TCP protocol, handshaking of network connections is done with SYN and ACK messages. The system that wishes to communicate sends a SYN message to the target system. The target system then responds with an ACK message. In a SYN attack, the attacker floods the target with SYN messages spoofed to appear to be from unreachable Internet addresses. This fills up the buffer space for SYN messages on the target machine, preventing other systems on the network from communicating with the target machine.&lt;br /&gt;Teardrop Attack&lt;br /&gt;The Teardrop Attack uses IP's packet fragmentation algorithm to send corrupted packets to the victim machine. This confuses the victim machine and may hang it.&lt;br /&gt;Smurf Attack&lt;br /&gt;In the Smurf Attack, the attacker sends a ping request to a broadcast address at a third-party on the network. This ping request is spoofed to appear to come from the victims network address . Every system within the broadcast domain of the third-party will then send ping responses to the victim.&lt;br /&gt;&lt;br /&gt;Distributed Denial of Service (DDoS) attacks&lt;br /&gt;A Distributed Denial of Service (DDoS) attack is a denial of service attack which is mounted from a large number of locations across the network.&lt;br /&gt;DDoS attacks are usually mounted from a large number of compromised systems. These systems may have been compromised by a trojan horse or a worm, or they might have been compromised by being hacked manually.&lt;br /&gt;These compromised systems are usually controlled with a fairly sophisticated piece of client-server software such as Trinoo, Tribe Flood Network, Stacheldraht, TFN2K, Shaft, and Mstream.&lt;br /&gt;The Mydoom worm attempted DDoS attacks against SCO and Microsoft from the systems which it infected.&lt;br /&gt;DDoS attacks can be very difficult to defend against.&lt;br /&gt;IP address spoofing denotes the action of generating IP packets with fake source IP addresses  in order to impersonate other systems or to protect the identity of the sender. Spoofing can also refer to forging or using fake headers on emails or netnews to - again - protect the identity of the sender and to mislead the receiver or the network as to the origin and validity of sent data.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-723310137921413726?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/723310137921413726/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=723310137921413726' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/723310137921413726'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/723310137921413726'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/dos-attacks.html' title='DOS ATTACKS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-8259113066351281963</id><published>2009-02-08T04:47:00.000-08:00</published><updated>2009-04-08T04:49:19.038-07:00</updated><title type='text'>POP UP MALWARE</title><content type='html'>Dirty tricks&lt;br /&gt;Imagine this: You visit a website and up pops a message, "Your computer is not secure -- click here for a free spyware scan." Anxious, if not alarmed, you click the link. You approve a "small download", the program starts, and you're told you have 87 spyware programs on your computer.&lt;br /&gt;Little do you know that it's a scammer's dirty trick -- the download included spyware that now reports everything you do on your computer, including account numbers and passwords that you enter. To top it off, there is an offer to remove the 87 infected items for just $39.95. That's just one example of the kind of scams you run into on the Internet these days.&lt;br /&gt;Blocking popups&lt;br /&gt;Just clicking the "No" button, or even the "X" in the upper-right corner of some popups can trigger an attack. The easiest and safest way to close unwanted popups is by using "Ctrl-W". [Hold down the "Ctrl" key and then press the "W" key]. That should close the popup safely. The best thing to do is block them in the first place though. :-)&lt;br /&gt;The Firefox popup blocker does a superb job blocking undesired popups. It also allows the ones you want in response to links that you click. The latest version of Internet Explorer in SP2 for Windows XP does nearly as well as Firefox. Pop-Up Sentry is a very effective stand-alone popup blocker. &lt;br /&gt;More online&lt;br /&gt;Test your popup blocker, as well as find links to free popup software. (Which you won't need if you switch to Firefox.) If you like to play, turn off your popup blocker and experience how bad popups can be. The tests are brought to you by WebAttack -- now called SnapFiles.&lt;br /&gt;PC Today has a comprehensive and easy to read report on popup blockers, including the blockers that are included in Firefox and Internet Explorer.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-8259113066351281963?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/8259113066351281963/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=8259113066351281963' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/8259113066351281963'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/8259113066351281963'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/pop-up-malware.html' title='POP UP MALWARE'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-3858340402619457356</id><published>2009-02-08T04:45:00.000-08:00</published><updated>2009-04-08T04:46:27.318-07:00</updated><title type='text'>HACKERS</title><content type='html'>Hackers&lt;br /&gt;To hack (maliciously) is to use your skill and knowledge to trespass in other computers. Hackers have easy access to hacking tools and heuristic methods from the Internet underground. They often use "social engineering" rather than technology to insinuate their way into computers and computer networks.&lt;br /&gt;Social engineering is the skill of getting passwords or other information about systems from people who should know better. The hacker poses as someone with a legitimate purpose for getting in and many people fall for it.&lt;br /&gt;Hacking is largely a social malignancy -- not a technical problem. Don Parker, a seasoned security expert put it this way: &lt;br /&gt;"Remote computing freed criminals from the historic requirement of proximity to their crimes. Anonymity and freedom from personal victim confrontation increased the emotional ease of crime, i.e., the victim was only an inanimate computer, not a real person or enterprise. Timid people could become criminals..."&lt;br /&gt;The most common hacks&lt;br /&gt;"The majority of the successful operating system attacks come from only a few software vulnerabilities. This can be attributed to the fact that attackers are opportunistic, take the easiest and most convenient route, and exploit the best-known flaws with the most effective and widely available attack tools." -- quote from SANS Institute&lt;br /&gt;You're exposed to hackers every time you're on the Internet. When you're online you PC has an Internet address assigned to it. Crackers can easily find your PC and break in. They do that while you're busy surfing, or reading your e-mail.&lt;br /&gt;You wouldn't know they're trying and probably won't know if they succeed until later if ever. For example, they might make off with your bank account number and PIN. You wouldn't know until the money was gone. Your bank would be dubious about your protest though.&lt;br /&gt;Most hackers aren't out to get you personally. They want to use your computer for their own nefarious purposes, but they'll usually go away if yours is well protected. Some of the things they want your computer for:&lt;br /&gt;1. Hide their intrusion to sensitive computers by going through yours. &lt;br /&gt;2. Store and distribute spam, porn, pirated music, and warez (bogus software). &lt;br /&gt;3. Attack their enemies.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-3858340402619457356?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/3858340402619457356/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=3858340402619457356' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/3858340402619457356'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/3858340402619457356'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/hackers.html' title='HACKERS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-1658739769907883285</id><published>2009-02-08T04:41:00.000-08:00</published><updated>2009-04-08T04:43:06.437-07:00</updated><title type='text'>DOWNLOADING SAFELY</title><content type='html'>How to Download Software (Safely)&lt;br /&gt;There are two kinds of people who download software -- those who have picked up a virus or other computer infection, and those who will. You need to be very careful to put it off as long as possible. I've downloaded and installed scores of programs but so far none have bit me. &lt;br /&gt;First things first: software categories&lt;br /&gt;Commercial: Mainstream software offered for download by big companies. Some is even free or free for home use. Most of it is priced in the "boxed software" range. The same software is usually available in stores as well as online.&lt;br /&gt;Freeware: Some freeware rivals the capability of commercial software, but usually it's smaller programs developed by individuals or shareware developers. Warning: freeware can be addictive -- it's free -- easy to download -- often excellent -- and there are thousands of programs to try. :-)&lt;br /&gt;Many freeware programs are superb, but a few are written poorly. Freeware can also conceal "spyware", viruses or Trojans and other parasites. Avoid problems by using your common sense and by following the rules for safe downloading listed below.&lt;br /&gt;Shareware: Usually modestly priced, intermediate in size and closer to commercial software in features. Some shareware is the best software written. The usual price range is $10 to $30. Often there's both a freeware and shareware version of the same software. The freeware version may run ads and/or limit functions. Shareware can often be used for 30 days or so on a free trial basis. After that time it will shut down unless you buy a registration code to keep it working.&lt;br /&gt;Updates &amp; Extensions: "Filters", "codecs", "modules", updates, etc., that augment or revise the capabilities of Windows and other programs, mostly browsers. They're usually free, and they are often offered when you click a link that won't work without the new software. They're often needed by Multimedia programs like Windows Media Player and RealPlayer. Be very sure the site is trustworthy before you proceed though.&lt;br /&gt;Imperatives for downloading :-)&lt;br /&gt;1. Use your common sense: Be very, very suspicious of any unsolicited invitation to download something wonderful or urgently important. These offers often appear as a flashy ad or popup window. Some will arrive as spam, some of it very clever, and often with an attachment. &lt;br /&gt;2. Never download a file -- including pictures and music -- unless you know the source is trustworthy. Download software only from well-known companies (Microsoft, Symantec, Intuit, etc.) or from other trustworthy sources, such as those listed in the section below. &lt;br /&gt;3. Never download a file via BitTorrent or other file-sharing networks. Period. &lt;br /&gt;4. "Google" it: Let's say the program is called Spyban. Go to Google and enter "Spyban spyware" (without the quotes) and see what you get. &lt;br /&gt;5. Read the description and recommendations at the download site, or at the program's website. You don't want to install something that won't be compatible with your needs or your computer. &lt;br /&gt;6. Before you install any software you download, make sure that you have a current backup of your documents and system. &lt;br /&gt;7. Take precautions against viruses, Trojans, adware and the like. It's no longer a sure thing, but it's still good practice to scan files for viruses, worms and other malware before you open them -- no matter what the source. [see handling files safely] &lt;br /&gt;Safe places to download software from&lt;br /&gt;SiteAdvisor is a new service that checks websites for suspicious activity. SiteAdvisor helps protect you from all kinds of Web-based security threats -- spyware, adware, spam, viruses, browser-based attacks, phishing, online fraud and identity theft. Note: SiteAdvisor does not protect against Phishing, as that is a different kind of attack.&lt;br /&gt;These major download sources are trustworthy. They usually have ratings of the programs (often written by the supplier however). Check a with a couple of them to compare notes. &lt;br /&gt;Tucows :: MajorGeeks.com :: WebAttack :: NoNags :: Jumbo! :: Pricelessware :: WinPlanet :: ZDNet Downloads :: CNET&lt;br /&gt;Gizmo's community-based (I'm an editor there) Best-ever Freeware Utilities site features the "best of the best" freeware. Gizmo also maintains a list of the best freeware/shareware download sites.&lt;br /&gt;I created some special search engines that you can use to find programs at trustworthy sources.&lt;br /&gt;You'll find over 5000 programs at Microsoft's Free Downloads Center. Lots of games, but many other programs as well. The Ultimate List of Windows Software from Microsoft may make it easief to find what you want.&lt;br /&gt;Download managers&lt;br /&gt;Warning: Download managers, Zip programs, and of all things, anti-spyware programs are often used as bait for adware and spyware. Don't forget the "rules to download by" when you're considering one of them.&lt;br /&gt;I no longer use a special download manager. Firefox has a built-in download manager. It lets you save the files where you want (set up in options), download multiple files at the same time, and easily pause and resume any download. That's good enough for me. :-) I also follow a process to keep my downloads well organized. ;-)&lt;br /&gt;Ed Bott suggests a simple but effective way to keep track of not only downloads, but the essential information that goes with them.&lt;br /&gt;http://www.edbott.com/weblog/?p=693 -- getting them organized&lt;br /&gt;http://www.edbott.com/weblog/?p=1254 -- keeping them organized&lt;br /&gt;If you do a lot of downloading, especially on dial-up, you might appreciate a download manager. They let you pause downloads, and resume interrupted ones without losing the part you've already downloaded. They'll also help you keep track of the files you download.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-1658739769907883285?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/1658739769907883285/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=1658739769907883285' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1658739769907883285'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1658739769907883285'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/downloading-safely.html' title='DOWNLOADING SAFELY'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-3414144447386125205</id><published>2009-02-08T04:39:00.000-08:00</published><updated>2009-04-08T04:41:10.590-07:00</updated><title type='text'>EMAIL ATTACHMENTS</title><content type='html'>The Perils of Email Attachments&lt;br /&gt;Synopsis&lt;br /&gt;Email attachments are one of the easiest ways to vandalize or invade a computer. The human element is often the weakest part of the system. Amazingly, many previous victims continue to open dodgy attachments. &lt;br /&gt;1. Be suspicious of any attachment you were not expecting -- even though it's from someone you know. &lt;br /&gt;2. Be doubly suspicious of attachments that have been forwarded to you -- even by someone you know. &lt;br /&gt;3. Be paranoid about attachments from anyone you don't know. &lt;br /&gt;A worm could have sent the message in the first case. Here's how: The message came from an infected PC -- one belonging to them or someone who has their address. Your friends address was used in the "From:" field to disarm you. In the 2nd case, you clearly have no idea where the file came from originally. In the 3rd case, it's spam or more likely an attack.&lt;br /&gt;Attachments, and the messages that carry them, get more diabolical all the time. Finding new ways to fool people is a collective obsession. Even seasoned computer users get taken in. Now there are even ways to include hostile code in digital music, images or videos.&lt;br /&gt;Examples&lt;br /&gt;1. A reasonable sounding message informs you that your computer is infected with the latest worm in the news, and offers to remove it. When you open the attachment, it disables your antivirus program and firewall. Then it installs the worm it claimed to be scanning for. Finally it reports that your computer is free of the worm. Now the worm uses your computer to send bogus messages to more victims. Nice!&lt;br /&gt;2. Your friend emails you a cute attachment with the file name "kitty.exe". In their message, they tell you they've tried it themselves, it's really cute, and it's "OK to open". You check with your friend, and yes indeed, he or she did send it, and they assure you "it doesn't have a virus."&lt;br /&gt;Trouble is, it contains a delayed action Trojan-horse along with the cute kitty. When you open it, the kitty does something cute, but the Trojan is installed on your computer too. You and your friend will not find out about the Trojan until later, if ever.&lt;br /&gt;3. An email arrives that appears to come from Microsoft. The Microsoft heading and icons are genuine. The message contains a sincere and urgent plea for you to patch your copy of Windows immediately. The patch is conveniently attached to the message.&lt;br /&gt;Trouble is, the attachment terminates your antivirus program and firewall, and does other things so that you can't remove it. Now you have a nice new Trojan horse in your PC. Microsoft provides a guideline for determining if a message "from" Microsoft is genuine.&lt;br /&gt;4. Attackers often disguise malicious attachments by using double extensions, for example, "message.txt.lnk" or "picture.gif.vbe". Unless you've changed your Windows configuration though, *.lnk, *.vbe and several other extensions are always hidden. The file names that you see are just "message.txt" or "picture.gif".&lt;br /&gt;Those files -- *.txt and *.gif files -- seem safe enough. Windows knows they are *.lnk or *.vbe files though, not text or picture files at all. When you "open" them though, Windows blindly does exactly what the attacker had in mind, and the damage is done.&lt;br /&gt;5. Demonstration: It's a myth that non-executable files are always safe. It's easy to hide malicious content in music or video files. Download and run example.mp3 to see a convincing but perfectly safe demonstration of this. (*.mp3 is a popular music file format.) That is... if you trust me.&lt;br /&gt;Nothing dramatic happens, but there's more going on than just the music, eh? You'll need to have Windows Media Player installed, and be online to see the results. This is just an example. I'm sure there's a lot of brigands and bandits figuring out how to plant hostile content in more file types.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-3414144447386125205?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/3414144447386125205/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=3414144447386125205' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/3414144447386125205'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/3414144447386125205'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/email-attachments.html' title='EMAIL ATTACHMENTS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-8104575188170689771</id><published>2009-02-08T04:35:00.000-08:00</published><updated>2009-04-08T04:36:50.284-07:00</updated><title type='text'>FAKE EMAILS</title><content type='html'>Key facts about fake email messages&lt;br /&gt;1. A sensible business will *never* ask you to reply to an email with your date of birth, credit card data, password, or other personal data. Never reply to one that does. If an email provides a link to a Web site to supply the information, don't use it. Open your browser and go there by your usual route.&lt;br /&gt;2. Almost anything in the headers of an email message can be "spoofed", including the "From" and "Reply To" addresses. A bogus message may appear to come from a legitimate business, or from someone you know. Be a little paranoid about any message you wouldn't have expected to see.&lt;br /&gt;3. You will never get email warnings about viruses and worms unless you have subscribed to an alert service or a newsletter. Bogus warnings often direct you to do something that damages your computer. Other's have attachments that are supposed to protect you against the threat, but install Trojan-horses instead.&lt;br /&gt;4. Many bogus email messages are disguised as solutions to problems that are plausible or in the news -- charge account problems, investigations, loss of benefits, identity theft, anthrax, computer viruses, etc. They usually call for urgent action. Of course, they don't have your best interest in mind.&lt;br /&gt;&lt;br /&gt;Master counterfeiters&lt;br /&gt;Criminals have adopted the tricks of spammers and worm writers. In some cases joined with spammers directly. It's easy to send out millions of fake email messages using that technology. They try to make the messages look just like one you'd expect.&lt;br /&gt;The "From" address is invariably "spoofed". That's trivially easy to do. You can probably do it yourself. The messages are sometimes very skillfully written. Stealing the graphics and images from a real webpage, say Homeland Security, and composing a message in HTML format can produce an even more convincing counterfeit. It looks just like what you'd expect.&lt;br /&gt;It's very hard to tell some fake email messages from a real ones. But your instincts, along with safe email practices can help.&lt;br /&gt;Email defense&lt;br /&gt;1. Configure your email client correctly. &lt;br /&gt;2. Know what to watch out for. Especially phish hooks. &lt;br /&gt;3. Never click a link in a spam message -- even to "opt-out" of future email. &lt;br /&gt;4. Handle your email safely. &lt;br /&gt;5. Install anti-virus and anti-malware software.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-8104575188170689771?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/8104575188170689771/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=8104575188170689771' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/8104575188170689771'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/8104575188170689771'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/fake-emails.html' title='FAKE EMAILS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-6249728660655821704</id><published>2009-02-08T04:29:00.000-08:00</published><updated>2009-04-08T04:33:55.736-07:00</updated><title type='text'>MALWARE IN MUSIC OR VIDEO FILES</title><content type='html'>There's a simple way to include malicious content in music or video files. The file can then be simply linked from a webpage. The link can even be hidden. To see a demo, download and run example.mp3 -- you can trust me, I'm a grandfather -- to see a convincing but perfectly safe demonstration. (*.mp3 is a popular compressed file format used for music.)&lt;br /&gt;         You'll need Windows Media Player to play the sound and see the results. In addition to the music, three more browser windows will open -- unless you have your security settings set too high. These windows will just display some perfectly safe content. If this little file can do that, just imagine what a crook or malcontent could do with a file they concoct.&lt;br /&gt;&lt;br /&gt;McAfee is warning file-sharers that they may be at risk due to a Trojan horse posing as an MP3 or MPEG file.&lt;br /&gt;&lt;br /&gt;The security firm said Tuesday that it had detected a half million instances of the malware since Friday, dubbed "Downloader-UA.h." It is calling the incident the most significant malware outbreak in three years.&lt;br /&gt;A check of McAfee's virus map showed the majority of infections have occurred in the US during the past 24 hours, although high rates of infection are being reported in Mexico, Venezuela, Brazil, Australia, and much of Western Europe.&lt;br /&gt;&lt;br /&gt;It appears as if the files are located on Gnutella and Limewire under a variety of names. When loaded, the file redirects through the player to a download of a file called PLAY_MP3.exe.&lt;br /&gt;&lt;br /&gt;Once this file loads, it shows up a EULA, and if accepted, the files "FBrowsingAdvisor" and "SurfingEnhancer" are installed. The file PlayMP3.exe is also installed, but instead of it being an actual local MP3 player, the application loads up a webpage with the Wimpy Flash MP3 player with several dozen songs available.&lt;br /&gt;&lt;br /&gt;The two previous files are believed to load some type of adware, which instead of blocking popups like the EULA claims deliver them to the end user.&lt;br /&gt;&lt;br /&gt;McAfee rated the issue a "medium" risk, the first time its given any piece of malware such a high rating since 2005.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-6249728660655821704?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/6249728660655821704/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=6249728660655821704' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/6249728660655821704'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/6249728660655821704'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/04/malware-in-music-or-video-files.html' title='MALWARE IN MUSIC OR VIDEO FILES'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-1939352318832697254</id><published>2009-02-08T04:22:00.000-08:00</published><updated>2009-04-08T04:22:40.163-07:00</updated><title type='text'>FEW TIPS</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CFIROZ%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CFIROZ%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CFIROZ%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="0" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="0" name="Hyperlink"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="0" name="Normal (Web)"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:Wingdings; 	panose-1:5 0 0 0 0 0 0 0 0 0; 	mso-font-charset:2; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:0 268435456 0 0 -2147483648 0;} @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:"Trebuchet MS"; 	panose-1:2 11 6 3 2 2 2 2 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:647 0 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:"Times New Roman";} h4 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-link:"Heading 4 Char"; 	mso-margin-top-alt:auto; 	margin-right:0in; 	mso-margin-bottom-alt:auto; 	margin-left:0in; 	mso-pagination:widow-orphan; 	mso-outline-level:4; 	font-size:15.0pt; 	font-family:"Times New Roman","serif"; 	color:blue;} span.Heading4Char 	{mso-style-name:"Heading 4 Char"; 	mso-style-unhide:no; 	mso-style-locked:yes; 	mso-style-link:"Heading 4"; 	mso-ansi-font-size:15.0pt; 	mso-bidi-font-size:15.0pt; 	color:blue; 	font-weight:bold;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:420611313; 	mso-list-template-ids:2108084436;} @list l0:level1 	{mso-level-number-format:bullet; 	mso-level-text:; 	mso-level-tab-stop:.5in; 	mso-level-number-position:left; 	text-indent:-.25in; 	mso-ansi-font-size:10.0pt; 	font-family:Symbol;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman","serif";} &lt;/style&gt; &lt;![endif]--&gt;  &lt;h4 style="margin: 3.75pt 0in;"&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;Don't get hooked&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h4&gt;  &lt;p class="MsoNormal" style="margin-bottom: 6pt; margin-left: 27pt; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt; font-family: Symbol; color: rgb(17, 17, 17);"&gt;&lt;span style=""&gt;·&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: rgb(17, 17, 17);"&gt;A sensible business should never send a message asking for personal details. Never follow links in an email message that directs you to take some action -- even if the message looks perfectly legitimate. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 6pt; margin-left: 27pt; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt; font-family: Symbol; color: rgb(17, 17, 17);"&gt;&lt;span style=""&gt;·&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: rgb(17, 17, 17);"&gt;If the message has a general salutation like "Dear Valued Customer" or "Please Confirm" instead of being specifically addressed to you by name, do not click any links. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 6pt; margin-left: 27pt; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt; font-family: Symbol; color: rgb(17, 17, 17);"&gt;&lt;span style=""&gt;·&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: rgb(17, 17, 17);"&gt;If there are spelling or grammar mistakes -- if the email just doesn't look professional, do not click any links. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 6pt; margin-left: 27pt; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt; font-family: Symbol; color: rgb(17, 17, 17);"&gt;&lt;span style=""&gt;·&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: rgb(17, 17, 17);"&gt;Hover your mouse pointer over links in the body of the email. The real destination of the links should be displayed. If the address looks strange or unlikely, do not click any of the links. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 6pt; margin-left: 27pt; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-size: 10pt; font-family: Symbol; color: rgb(17, 17, 17);"&gt;&lt;span style=""&gt;·&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: rgb(17, 17, 17);"&gt;If you just can't resist checking out an urgent request or warning use your browser go directly to the proported Web site directly, or contact the organization by phone.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-1939352318832697254?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/1939352318832697254/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=1939352318832697254' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1939352318832697254'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1939352318832697254'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/few-tips.html' title='FEW TIPS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-1482284452466052667</id><published>2009-02-08T03:35:00.000-08:00</published><updated>2009-04-08T03:42:57.406-07:00</updated><title type='text'>FAKERY</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CFIROZ%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;o:smarttagtype namespaceuri="urn:schemas-microsoft-com:office:smarttags" name="place"&gt;&lt;/o:smarttagtype&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CFIROZ%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CFIROZ%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="0" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="0" name="Hyperlink"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="0" name="Normal (Web)"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if !mso]&gt;&lt;object classid="clsid:38481807-CA0E-42D2-BF39-B33AF135CC4D" id="ieooui"&gt;&lt;/object&gt; &lt;style&gt; st1\:*{behavior:url(#ieooui) } &lt;/style&gt; &lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:"Trebuchet MS"; 	panose-1:2 11 6 3 2 2 2 2 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:647 0 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:"Times New Roman";} h4 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-link:"Heading 4 Char"; 	mso-margin-top-alt:auto; 	margin-right:0in; 	mso-margin-bottom-alt:auto; 	margin-left:0in; 	mso-pagination:widow-orphan; 	mso-outline-level:4; 	font-size:15.0pt; 	font-family:"Times New Roman","serif"; 	color:blue; 	font-weight:bold;} a:link, span.MsoHyperlink 	{mso-style-unhide:no; 	color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} p 	{mso-style-unhide:no; 	mso-margin-top-alt:auto; 	margin-right:0in; 	mso-margin-bottom-alt:auto; 	margin-left:0in; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:"Times New Roman";} span.Heading4Char 	{mso-style-name:"Heading 4 Char"; 	mso-style-unhide:no; 	mso-style-locked:yes; 	mso-style-link:"Heading 4"; 	mso-ansi-font-size:15.0pt; 	mso-bidi-font-size:15.0pt; 	color:blue; 	font-weight:bold;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;h4&gt;&lt;span style=";font-family:&amp;quot;;" &gt;Fakery&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h4&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=";font-family:&amp;quot;;" &gt;It's easy to get used to taking email at face value. Much of spam you see is obviously of no value. However, well designed counterfeit email looks very legitimate. Almost anything about an email message can be faked. Who it's "To:", who it's "From:", where it originated, The "Reply To:" address, etc. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style=";font-family:&amp;quot;;" &gt;Usually the Subject, To, and From addresses and the content is plausible.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style=";font-family:&amp;quot;;" &gt;Some worms even generate convincing fake messages automatically. Most of the time there is something slightly "off" about the message. The subject may not match what you'd expect from the sender for example. But some of them will fool you.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style=";font-family:&amp;quot;;" &gt;[&lt;a href="http://www.michaelhorowitz.com/bademails.html"&gt;"bad" email messages&lt;/a&gt;]&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style=";font-family:&amp;quot;;" &gt;You can learn more about rip-offs at the &lt;a href="http://cybercoyote.org/security/av-email.shtml"&gt;counterfeit email&lt;/a&gt; and &lt;a href="http://cybercoyote.org/security/av-web.shtml"&gt;bogus website&lt;/a&gt; pages. You're up against organized criminals and skillful con artists, who know all the tricks of the trade. You'll need to be more astute than they are cunning.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;h4&gt;&lt;span style=";font-family:&amp;quot;;" &gt;Examples&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h4&gt;  &lt;p&gt;&lt;span style=";font-family:&amp;quot;;" &gt;"Toll free" scams are vicious. A bogus message announces an unclaimed prize, a vacation offer or whatnot. All you need to do to take advantage of it is to call what looks like a toll free number. Trouble is, it's not really a toll-free number. The call goes to an offshore location, and can cost hundreds if not thousands of dollars in just a few minutes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style=";font-family:&amp;quot;;" &gt;The "&lt;a href="http://www.consumerwebwatch.org/news/Barrett/419fraud.htm"&gt;Nigerian&lt;/a&gt;" scam is both amusing and a serious ripoff. This and other "419" scams have fleeced victims of more than $150 Million so far. Update: The perpetrator, or at least one perpetrator of this scam was recently nabbed in &lt;st1:place st="on"&gt;Southeast Asia&lt;/st1:place&gt;. [&lt;a href="http://www.snopes.com/inboxer/scams/nigeria.htm"&gt;more&lt;/a&gt;]&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-1482284452466052667?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/1482284452466052667/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=1482284452466052667' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1482284452466052667'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1482284452466052667'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/fakery.html' title='FAKERY'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-1732226900662256049</id><published>2009-02-07T11:16:00.000-08:00</published><updated>2009-06-07T11:20:30.777-07:00</updated><title type='text'>SECURITY IN WIRELESS NETWORK</title><content type='html'>Computer users looking for convenience and mobility switch to &lt;a title="high speed internet" href="http://www.satelliteinternetfamily.com/" target="_blank"&gt;high speed Internet&lt;/a&gt;. This includes going wireless  which allows business travelers to use wireless blackberries to check their emails, vacationers to upload snapshots on their wireless laptops to show friends at home, consumers to make online payments from the comfort of their bed, and much more.&lt;p&gt;A wireless network can link up computers in different parts of your home, without a the need of a cord or a physical medium. To find out what you need to go wireless read our article &lt;a href="http://www.spamlaws.com/wc-networking.html"&gt;What is Wireless Network?&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Although, accessing the Internet wireless, proves convenient it also has its downside of being susceptible to hackers, particularly if you don't take the steps to secure your wireless network. So, learn some easy and quick steps to &lt;a href="http://www.spamlaws.com/secure-wireless.html"&gt; secure your network&lt;/a&gt; and about &lt;a title="information systems security" href="http://www.isc2.org/"&gt;information systems security&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;With the convenience of wireless Internet, &lt;a title="satellite internet" href="http://www.high-speed-internet-access-guide.com/" target="_blank"&gt;satellite Internet&lt;/a&gt; or any Internet connection for your family, comes the issue of  &lt;a href="http://www.spamlaws.com/children.html"&gt; child security&lt;/a&gt;. Make sure you know what websites you're children are accessing to keep them safe from predators lurking around in chat rooms, social networking sites, and to prevent them from surfing sites with adult conduct.&lt;/p&gt;&lt;h1&gt;10 Tips for Wireless Home Network Security&lt;/h1&gt;&lt;p&gt;Many folks setting up wireless home networks rush through the job to get their Internet connectivity working as quickly as possible. That's totally understandable. It's also quite risky as numerous security problems can result. Today's &lt;a href="http://compnetworking.about.com/cs/wireless80211/g/bldef_wifi.htm"&gt;Wi-Fi&lt;/a&gt; networking products don't always help the situation as configuring their security features can be time-consuming and non-intuitive. The recommendations below summarize the steps you should take to improve the security of your home wireless network.&lt;/p&gt;&lt;h3&gt;1. &lt;a href="http://compnetworking.about.com/cs/wirelessproducts/qt/adminpassword.htm"&gt;Change Default Administrator Passwords (and Usernames)&lt;/a&gt;&lt;/h3&gt;At the core of most Wi-Fi home networks is an access point or router. To set up these pieces of equipment, manufacturers provide Web pages that allow owners to enter their network address and account information. These Web tools are protected with a login screen (username and password) so that only the rightful owner can do this. However, for any given piece of equipment, the logins provided are simple and very well-known to hackers on the Internet. Change these settings immediately.&lt;div class="lsItm"&gt;&lt;h3&gt;2. &lt;a href="http://compnetworking.about.com/cs/winxpnetworking/ht/wpainwindowsxp.htm"&gt;Turn on (Compatible) WPA / WEP Encryption&lt;/a&gt;&lt;/h3&gt;All Wi-Fi equipment supports some form of &lt;i&gt;encryption&lt;/i&gt;. Encryption technology scrambles messages sent over wireless networks so that they cannot be easily read by humans. Several encryption technologies exist for Wi-Fi today. Naturally you will want to pick the strongest form of encryption that works with your wireless network. However, the way these technologies work, all Wi-Fi devices on your network must share the identical encryption settings. Therefore you may need to find a "lowest common demoninator" setting.&lt;div class="lsLks"&gt;&lt;a href="http://compnetworking.about.com/cs/winxpnetworking/ht/wpainwindowsxp.htm"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="lsItm"&gt;&lt;h3&gt;3. &lt;a href="http://compnetworking.about.com/cs/wirelessproducts/qt/changessid.htm"&gt;Change the Default SSID&lt;/a&gt;&lt;/h3&gt;Access points and routers all use a network name called the &lt;a href="http://compnetworking.about.com/cs/wireless/g/bldef_ssid.htm"&gt;SSID&lt;/a&gt;. Manufacturers normally ship their products with the same SSID set. For example, the SSID for Linksys devices is normally "linksys." True, knowing the SSID does not by itself allow your neighbors to break into your network, but it is a start. More importantly, when someone finds a default SSID, they see it is a poorly configured network and are much more likely to attack it. Change the default SSID immediately when configuring wireless security on your network.&lt;div class="lsLks"&gt;&lt;a href="http://compnetworking.about.com/cs/wirelessproducts/qt/changessid.htm"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="lsItm"&gt;&lt;h3&gt;4. &lt;a href="http://compnetworking.about.com/cs/wirelessproducts/qt/macaddress.htm"&gt;Enable MAC Address Filtering&lt;/a&gt;&lt;/h3&gt;Each piece of Wi-Fi gear possesses a unique identifier called the &lt;i&gt;physical address&lt;/i&gt; or &lt;i&gt;MAC address&lt;/i&gt;. Access points and routers keep track of the MAC addresses of all devices that connect to them. Many such products offer the owner an option to key in the MAC addresses of their home equipment, that restricts the network to only allow connections from those devices. Do this, but also know that the feature is not so powerful as it may seem. Hackers and their software programs can fake MAC addresses easily.&lt;div class="lsLks"&gt;&lt;a href="http://compnetworking.about.com/cs/wirelessproducts/qt/macaddress.htm"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="lsItm"&gt;&lt;h3&gt;5. &lt;a href="http://compnetworking.about.com/cs/wirelessproducts/qt/disablessidcast.htm"&gt;Disable SSID Broadcast&lt;/a&gt;&lt;/h3&gt;In Wi-Fi networking, the wireless access point or router typically broadcasts the network name (SSID) over the air at regular intervals. This feature was designed for businesses and mobile hotspots where Wi-Fi clients may roam in and out of range. In the home, this roaming feature is unnecessary, and it increases the likelihood someone will try to log in to your home network. Fortunately, most Wi-Fi access points allow the SSID broadcast feature to be disabled by the network administrator.&lt;div class="lsLks"&gt;&lt;a href="http://compnetworking.about.com/cs/wirelessproducts/qt/disablessidcast.htm"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="lsItm"&gt;&lt;h3&gt;6. &lt;a href="http://compnetworking.about.com/od/wirelesshotspots/qt/noautoconnect.htm"&gt;Do Not Auto-Connect to Open Wi-Fi Networks&lt;/a&gt;&lt;/h3&gt;Connecting to an open Wi-Fi network such as a free wireless hotspot or your neighbor's router exposes your computer to security risks. Although not normally enabled, most computers have a setting available allowing these connections to happen automatically without notifying you (the user). This setting should not be enabled except in temporary situations.&lt;div class="lsLks"&gt;&lt;a href="http://compnetworking.about.com/od/wirelesshotspots/qt/noautoconnect.htm"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="lsItm"&gt;&lt;h3&gt;7. &lt;a href="http://compnetworking.about.com/od/workingwithipaddresses/qt/staticipaddress.htm"&gt;Assign Static IP Addresses to Devices&lt;/a&gt;&lt;/h3&gt;Most home networkers gravitate toward using &lt;i&gt;dynamic IP addresses&lt;/i&gt;. &lt;a href="http://compnetworking.about.com/cs/protocolsdhcp/g/bldef_dhcp.htm"&gt;DHCP&lt;/a&gt; technology is indeed easy to set up. Unfortunately, this convenience also works to the advantage of network attackers, who can easily obtain valid IP addresses from your network's DHCP pool. Turn off DHCP on the router or access point, set a fixed IP address range instead, then configure each connected device to match. Use a &lt;i&gt;private IP address range&lt;/i&gt; (like 10.0.0.x) to prevent computers from being directly reached from the Internet.&lt;div class="lsLks"&gt;&lt;a href="http://compnetworking.about.com/od/workingwithipaddresses/qt/staticipaddress.htm"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="lsItm"&gt;&lt;h3&gt;8. &lt;a href="http://compnetworking.about.com/od/firewalls/tp/homefirewalls.htm"&gt;Enable Firewalls On Each Computer and the Router&lt;/a&gt;&lt;/h3&gt;Modern network routers contain built-in firewall capability, but the option also exists to disable them. Ensure that your router's firewall is turned on. For extra protection, consider installing and running &lt;i&gt;personal firewall software&lt;/i&gt; on each computer connected to the router.&lt;div class="lsLks"&gt;&lt;a href="http://compnetworking.about.com/od/firewalls/tp/homefirewalls.htm"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="lsItm"&gt;&lt;h3&gt;9. &lt;a href="http://compnetworking.about.com/cs/wirelessproducts/qt/locate_aprouter.htm"&gt;Position the Router or Access Point Safely&lt;/a&gt;&lt;/h3&gt;Wi-Fi signals normally reach to the exterior of a home. A small amount of signal leakage outdoors is not a problem, but the further this signal reaches, the easier it is for others to detect and exploit. Wi-Fi signals often reach through neighboring homes and into streets, for example. When installing a wireless home network, the position of the access point or router determines its reach. Try to position these devices near the center of the home rather than near windows to minimize leakage.&lt;div class="lsLks"&gt;&lt;a href="http://compnetworking.about.com/cs/wirelessproducts/qt/locate_aprouter.htm"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;h3&gt;10. &lt;a href="http://compnetworking.about.com/od/homenetworking/f/poweroffnetwork.htm"&gt;Turn Off the Network During Extended Periods of Non-Use&lt;/a&gt;&lt;/h3&gt;The ultimate in wireless security measures, shutting down your network will most certainly prevent outside hackers from breaking in! While impractical to turn off and on the devices frequently, at least consider doing so during travel or extended periods offline. Computer disk drives have been known to suffer from power cycle wear-and-tear, but this is a secondary concern for broadband modems and routers.&lt;br /&gt;&lt;br /&gt;If you own a wireless router but are only using it wired (Ethernet) connections, you can also sometimes &lt;a href="http://compnetworking.about.com/od/wirelessfaqs/f/router-wifi-off.htm"&gt;turn off Wi-Fi on a broadband router&lt;/a&gt; without powering down the entire network.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-1732226900662256049?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/1732226900662256049/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=1732226900662256049' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1732226900662256049'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1732226900662256049'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/06/security-in-wireless-network.html' title='SECURITY IN WIRELESS NETWORK'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-1294592626187101600</id><published>2009-02-07T11:14:00.000-08:00</published><updated>2009-06-07T11:15:01.516-07:00</updated><title type='text'>FIRST VIRUS IN LINUX</title><content type='html'>&lt;h1&gt;&lt;strong&gt;The First Linux Virus&lt;/strong&gt;&lt;/h1&gt; &lt;p&gt;From the outside looking in, one would believe that viruses were an equal threat to all computer users. While this is true in a sense, some users are much more vulnerable than others. For years, Linux has been known as the more secure option for an operating system. Although the &lt;a title="windows" href="http://www.spamlaws.com/vista.html"&gt;Windows platform &lt;/a&gt;is designed with many useful features, Linux was designed with security in mind, making the system superior in the minds of its users.&lt;/p&gt;&lt;p&gt;Even though Linux isn't a prime target for malicious coders, it has been successfully exploited by a few computer infections. Staog was the first virus ever scripted for the Linux operating system. It was initially detected in the fall of 1996, with the exploited vulnerabilities being discovered shortly thereafter. Considering the system's strong design, experts in the software security industry were stunned.&lt;/p&gt; &lt;p&gt;Staog was able to exploit Linux despite the system's design which calls for users and applications to login before any questionable operations can occur. The virus functioned by exploiting vulnerabilities in the kernel, which enabled it to stay resident in the memory. From there, it infected executable binary files. Because it mainly relied on bugs, software upgrades made the system immune to the virus. This factor, along with its weak method of distributing itself, made Staog fairly easy to manage.&lt;/p&gt; &lt;p&gt;Staog was written by VLAD, a well known group from the hacking community. This Australian-based group is also responsible for scripting Boza, the first virus written for Windows 95. The first Linux virus has not been listed in the wild since the initial outbreak. Despite that brief threat of Staog, viruses typically have limited ability to change or severely impact the system.&lt;/p&gt; &lt;h2&gt;&lt;strong&gt;The Truth about Linux Viruses&lt;/strong&gt;&lt;/h2&gt; &lt;p&gt;One the biggest vulnerabilities of the Linux system are the users who have the misconception that it cannot be infected by &lt;a title="computer virus" href="http://www.spamlaws.com/virus-comtypes.html"&gt;computer viruses&lt;/a&gt;. Several people believe that any non-Windows system is secure and doesn't need the aid of additional software to ward off viruses. This is far from the truth and a major reason why more viruses are being written for the system.&lt;/p&gt; &lt;p&gt;Many security experts believe that the growth in Linux malware is the result of its evolution and popularity, particularly as a desktop system. Shane Coursen, a senior technical consultant for Kasperky Lab, believes that more users are turning to Linux because of the interest in learning how to write malware for the system.&lt;/p&gt; &lt;p&gt;Most viruses written for Linux pose a potential, yet minimal threat to the system. If a virus infected binary file is run, the entire system could be infected. The distribution of the infection depends on which particular user with what level of privileges executed the binary. A binary run under the systems root account would have the ability to infect the entire system.&lt;/p&gt; &lt;p&gt;There are many other solutions for protecting Linux other than anti-virus software. For instance, software repositories greatly reduces the chance of viruses and other malware. These repositories are throughly checked before distribution to ensure that they are malware free.&lt;/p&gt; &lt;p&gt;Just like with any system, the best protection against common threats is prevention. This includes carefully surfing the web and handling emails on your Linux computer.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-1294592626187101600?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/1294592626187101600/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=1294592626187101600' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1294592626187101600'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1294592626187101600'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/first-virus-in-linux.html' title='FIRST VIRUS IN LINUX'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-6498613218179388774</id><published>2009-02-07T11:10:00.000-08:00</published><updated>2009-06-07T11:12:25.929-07:00</updated><title type='text'>GOOD VIRUSES</title><content type='html'>&lt;h1 style="text-align: right;"&gt;&lt;strong&gt;Good Computer Viruses&lt;/strong&gt;: The Future?&lt;/h1&gt;&lt;div&gt; &lt;/div&gt;&lt;p style="text-align: left;"&gt;Even with all the damage viruses have inflicted over the years, a handful of experts believe that &lt;a title="computer virus" href="http://spamlaws.com/computer-virus.html"&gt;computer viruses&lt;/a&gt; could actually be used for good one day. How is this possible? Similar to the ethical worm, these viruses would mainly be used to distribute network patches to repair vulnerabilities. Here is a bit more on the theory.&lt;/p&gt;&lt;div style="text-align: left;"&gt; &lt;/div&gt;&lt;h2 style="text-align: left;"&gt;The Function of a "Good" Computer Virus&lt;script type="text/javascript"&gt;google_ad_slot = "9565114904"; google_ad_width = 300; google_ad_height = 250; //--&gt; &lt;/script&gt; &lt;script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"&gt; &lt;/script&gt;&lt;script&gt;window.google_render_ad();&lt;/script&gt;&lt;/h2&gt;&lt;h2 style="text-align: left;"&gt;First of all, the virus would have to exclude the primary function of a typical virus, which is running on a victimized machine without authorization. The propagation would be similar to the one used for malicious purposes, but instead deliver a good payload, opposed to one that is destructive. Because of this, experts believe that anyone found guilty of distributing a good virus should be charged with the same offense as someone distributing malicious code, though with reduced penalties, as the damage is liable to be not as severe.&lt;/h2&gt;&lt;div style="text-align: left;"&gt; &lt;/div&gt;&lt;div style="text-align: left;"&gt; &lt;/div&gt;&lt;p style="text-align: left;"&gt;However, this supposed good virus would not only spread and execute itself without permission, but also consume bandwidth, disk space, memory and processor cycles. All of these factors could possibly result in the denial of the those resources to system administrators, a condition more commonly termed as a DoS (denial-of-service) attack.&lt;/p&gt;&lt;div style="text-align: left;"&gt; &lt;/div&gt;&lt;h2 style="text-align: left;"&gt;Good vs. Malicious Viruses&lt;br /&gt;&lt;/h2&gt;&lt;div style="text-align: left;"&gt; &lt;/div&gt;&lt;p style="text-align: left;"&gt;Another problem would be distinguishing the good virus from malicious programs. While identifying a known virus is fairly easy with the right technology, separating it from the unknown good code may be difficult. Since a good number of legitimate programs have been known to damage and mistakenly remove files, this ability alone isn't enough to truly identify malware.  Perhaps this good virus would be limited to removing programs, as it can combine its code with an individual program. However, this would certainly be an inconvenience for those developing self-extracting archive software. Assuming this as the major obstacle, how would a good virus distinguish another from a malicious program?  Both would behave similarly with the tendency to damage or destroy other files. One would only hope that creators of these viruses carefully script their codes to identify other good variants, a task that seems difficult or next to impossible when considering polymorphism.&lt;/p&gt;&lt;div style="text-align: left;"&gt; &lt;/div&gt;&lt;p style="text-align: left;"&gt;Good viruses would have to be written to near perfection for a number of reasons. If they happen to mistakenly delete software and operating system patches, they would essentially be just as much trouble as malicious viruses. There is also the strong possibly of unscrupulous characters mutating the good virus with evil strains. These new strains are likely to be identified as good viruses, even though they contain a destructive payload, one capable of destroying all other identifiable good viruses.&lt;/p&gt;&lt;div style="text-align: left;"&gt; &lt;/div&gt;&lt;p style="text-align: left;"&gt;With so much still in the air, we may find ourselves reflecting on the day when good viruses first invaded our systems, strengthening the malicious epidemic. If these viruses of the future aren't written properly, they could inevitably improve the breed of destructive programs just before being wiped out by variants of their own code. While this is certainly a hot topic, many security experts believe that &lt;a title="spreading virus" href="http://spamlaws.com/spread-virus.html"&gt;spreading good viruses&lt;/a&gt; could eventually end up causing more harm than good.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-6498613218179388774?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/6498613218179388774/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=6498613218179388774' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/6498613218179388774'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/6498613218179388774'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/good-viruses.html' title='GOOD VIRUSES'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-2785922238296689248</id><published>2009-02-07T11:08:00.000-08:00</published><updated>2009-06-07T11:13:16.114-07:00</updated><title type='text'>TYPES OF VIRUS</title><content type='html'>&lt;h2&gt;Types of Viruses&lt;/h2&gt; &lt;p&gt;But what are the types of computer viruses and worms that you're computer can come into contact with? The list of viruses is quiet long and complex. So, we simplified the list by mentioning few broad categories of viruses that can put your computer and all your personal data on it, in danger. These computer viruses include:&lt;/p&gt; &lt;p&gt; &lt;/p&gt; &lt;h2&gt;Computer Viruses&lt;/h2&gt; &lt;p&gt;&lt;strong&gt;Boot Sector viruses: &lt;/strong&gt; A boot sector virus infects diskettes and hard drives. All disks and hard drives contain smaller sections called sectors. The first sector is called the boot. The boot carries the Mater Boot Record (MBR). MBR functions to read and load the operating system. So, if a virus infects the boot or MBR of a disk, such as a floppy disk, your hard drive can become infected, if you re-boot your computer while the infected disk is in the drive. Once your hard drive is infected all diskettes that you use in your computer will be infected. Boot sector viruses often spread to other computers by the use of shared infected disks and pirated software applications. The best way to disinfect your computer of the boot sector virus is by using antivirus software.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Program viruses: &lt;/strong&gt; A program virus becomes active when the program file (usually with extensions .BIN, .COM, .EXE, .OVL, .DRV) carrying the virus is opened. Once active, the virus will make copies of itself and will infect other programs on the computer.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Multipartite viruses: &lt;/strong&gt; A multipartite virus is a hybrid of a Boot Sector and Program viruses. It infects program files and when the infected program is active it will affect the boot record. So the next time you start up your computer it'll infect your local drive and other programs on your computer.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Stealth viruses: &lt;/strong&gt; A stealth virus can disguise itself by using certain tactics to prevent being detected by antivirus software. These tactics include altering its file size, concealing itself in memory, and so on. This type of virus is nothing new, in fact, the first computer virus, dubbed Brain, was a stealth virus. A good antivirus should be able to detect a stealth virus lurking on your hard drive by checking the areas the virus infected and evidence in memory.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Polymorphic viruses: &lt;/strong&gt; A polymorphic virus acts like a chameleon, changing its virus signature (also known as binary pattern) every time it multiples and infects a new file. By changing binary patterns, a polymorphic virus becomes hard to detect by an antivirus program.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Macro Viruses: &lt;/strong&gt; A macro virus is programmed as a macro embedded in a document. Many applications, such as Microsoft Word and Excel, support macro languages. Once a macro virus gets on to your computer, every document you produce will become infected. This type of virus is relatively new and may slip by your antivirus software if you don't have the most recent version installed on your computer. .&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Active X and Java Control: &lt;/strong&gt; Some users do not know how to manage and control their web browser to allow or prohibit certain functions to work, such as enabling or disabling sound, pop ups, and so on. Leaving your computer in danger of being targeted by unwanted software or adware floating in cyberspace.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-2785922238296689248?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/2785922238296689248/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=2785922238296689248' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/2785922238296689248'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/2785922238296689248'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/06/types-of-virus.html' title='TYPES OF VIRUS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-2324444873424395982</id><published>2009-02-07T09:51:00.000-08:00</published><updated>2009-03-07T09:53:01.742-08:00</updated><title type='text'>COMMON THREATS</title><content type='html'>&lt;p style="font-family: arial;" align="justify"&gt;&lt;u&gt;&lt;b&gt;Common Threats:&lt;/b&gt;&lt;/u&gt;&lt;/p&gt;  &lt;p style="font-family: arial;" align="justify"&gt;&lt;b&gt;Viruses&lt;/b&gt;: A virus is a software program which attaches  itself to another piece of software.  The virus inserts its code into a  file which when executed, runs the virus.  A boot virus is a program which  runs when the computer starts.&lt;/p&gt;  &lt;p style="font-family: arial;" align="justify"&gt;&lt;b&gt;Spyware&lt;/b&gt;: Spyware is software which works in the  background to gather a user's information and behavior.  This information  is then transmitted to another party.  Spyware works in the background  without a user's knowledge.  Some of the information can include the  operating system of the computer, the type of browser, the computer IP address  and where a user browses to.&lt;/p&gt;  &lt;p style="font-family: arial;" align="justify"&gt;&lt;b&gt;Trojan&lt;/b&gt;: A Trojan is a software program which runs in a  computer as a secret agent of the attacker.  Trojans do not replicate  themselves like worms or viruses.&lt;/p&gt;  &lt;p style="font-family: arial;" align="justify"&gt;&lt;b&gt;Worm&lt;/b&gt;: A worm is a program which replaces files.   They can be as destructive as viruses, and like a virus can replicate itself.&lt;/p&gt;  &lt;p style="font-family: arial;" align="justify"&gt;&lt;b&gt;Browser Hijacking&lt;/b&gt;: A browser hijacking occurs when a  browser gets set to a website which is not the user's choosing.  Sometimes  information gets rerouted to another site without the user's knowledge and makes  the Internet connection run slower.  Hijacks cna change a user's homepage.&lt;/p&gt;  &lt;p style="font-family: arial;" align="justify"&gt;&lt;b&gt;Spoofing&lt;/b&gt;: Spoofing if when an identity gets forged.   The attackers forge their IP address with the person they want to attack,  overloading the victim's Internet connection.&lt;/p&gt;  &lt;p style="font-family: arial;" align="justify"&gt;&lt;b&gt;Phishing&lt;/b&gt;: Phishing happens when a person send out  email masquerading as a trusted company or person.  Typically the email  states the user's account information needs to be updated and provides a link to  do so.  The link redirects the person to a webpage which looks legitimate,  but is not, and actually captures confidential information such as credit card  number, bank accounts and social security numbers.&lt;/p&gt;  &lt;p style="font-family: arial;" align="justify"&gt;&lt;b&gt;Adware&lt;/b&gt;: Adware is software which directs specific ads  to your computer.  This typically happens after you consent to loading some  free software program or browser helper.  Some Adware also tracks your  Internet browsing and reports this information back to a central server.&lt;/p&gt;  &lt;p style="font-family: arial;" align="justify"&gt;&lt;b&gt;Popup&lt;/b&gt;: A popup happens when a new browser window opens  up on it's own.  Sometimes so many popup windows can open, it renders the  computer useless.&lt;/p&gt;  &lt;p style="font-family: arial;" align="justify"&gt;&lt;b&gt;Hoax&lt;/b&gt;: A hoax is an email stating something untrue.   Common hoaxes include virus hoaxes which have the user delete an important file  located on their computer.&lt;/p&gt;  &lt;p style="font-family: arial;" align="justify"&gt;&lt;b&gt;Spam&lt;/b&gt;: Junk email which is usually unsolicited,  typically sent to hundreds or thousands of people.  Usually attempting to  sell items such as drugs or containing pornographic material.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-2324444873424395982?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/2324444873424395982/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=2324444873424395982' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/2324444873424395982'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/2324444873424395982'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/common-threats.html' title='COMMON THREATS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-7350756187777034244</id><published>2009-02-07T08:11:00.000-08:00</published><updated>2009-03-07T08:30:49.651-08:00</updated><title type='text'>REGSVR VIRUS</title><content type='html'>&lt;h1  style="text-align: left;font-family:arial;"&gt;&lt;span style="font-weight: normal;color:black;" &gt;&lt;a href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/"&gt;&lt;span style="text-decoration: none;color:black;" &gt;How to remove new folder exe or regsvr exe or autorun inf virus&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/h1&gt;&lt;div style="text-align: left;"&gt;  &lt;/div&gt;&lt;p style="font-family: arial; text-align: left;" class="MsoNormal"&gt;This virus is know popularly as regsvr.exe virus, or as new folder.exe virus and most people identify this one by seeing autorun.inf file on their pen drives, But trend micro identified it as &lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FDELF%2EFKZ&amp;amp;VSect=Sn" title="worm_delf"&gt;WORM_DELF.FKZ&lt;/a&gt;. It is spreading mostly using pen drives as the medium.&lt;/p&gt;&lt;div style="text-align: left;"&gt;  &lt;/div&gt;&lt;p style="font-family: arial; text-align: left;" class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;div style="text-align: left;"&gt;  &lt;/div&gt;&lt;ol style="font-family: arial; text-align: left;" start="1" type="1"&gt;&lt;li class="MsoNormal"&gt;&lt;strong&gt;Cut The Supply Line&lt;/strong&gt;      &lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;ol start="1" type="a"&gt;&lt;li class="MsoNormal"&gt;Search for &lt;em&gt;autorun.inf       file&lt;/em&gt;. It is a read only file so you will have to change it to normal       by right clicking the file , selecting the properties and &lt;em&gt;un-check       the read only option&lt;/em&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Open the file in       notepad and delete everything and save the file.&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Now change the file &lt;em&gt;status       back to read only&lt;/em&gt; mode so that the virus could not get access again.&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;a href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/autorun1/"&gt;&lt;span style="text-decoration: none;"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shapetype id="_x0000_t75" coordsize="21600,21600" spt="75" preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"&gt;        &lt;v:stroke joinstyle="miter"&gt;        &lt;v:formulas&gt;         &lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;         &lt;v:f eqn="sum @0 1 0"&gt;         &lt;v:f eqn="sum 0 0 @1"&gt;         &lt;v:f eqn="prod @2 1 2"&gt;         &lt;v:f eqn="prod @3 21600 pixelWidth"&gt;         &lt;v:f eqn="prod @3 21600 pixelHeight"&gt;         &lt;v:f eqn="sum @0 0 1"&gt;         &lt;v:f eqn="prod @6 1 2"&gt;         &lt;v:f eqn="prod @7 21600 pixelWidth"&gt;         &lt;v:f eqn="sum @8 21600 0"&gt;         &lt;v:f eqn="prod @7 21600 pixelHeight"&gt;         &lt;v:f eqn="sum @10 21600 0"&gt;        &lt;/v:formulas&gt;        &lt;v:path extrusionok="f" gradientshapeok="t" connecttype="rect"&gt;        &lt;o:lock ext="edit" aspectratio="t"&gt;       &lt;/v:shapetype&gt;&lt;v:shape id="_x0000_i1025" type="#_x0000_t75" alt="Autorun" href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/autorun1/" style="'width:112.5pt;height:112.5pt'" button="t"&gt;        &lt;v:imagedata src="file:///C:\DOCUME~1\Leka\LOCALS~1\Temp\msohtml1\01\clip_image001.jpg" href="http://amiworks.co.in/talk/wp-content/uploads/2008/03/autorun1-150x150.jpg"&gt;       &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;span style=""&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;Click &lt;em&gt;start-&gt;run       and type msconfig&lt;/em&gt; and click ok&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Go to startup tab look       for &lt;em&gt;regsvr and uncheck the option&lt;/em&gt; click OK.&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Click on &lt;em&gt;Exit       without Restart&lt;/em&gt;, cause there are still few things we need to do       before we can restart the PC.&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Now go to &lt;em&gt;control       panel -&gt; scheduled tasks&lt;/em&gt;, and &lt;em&gt;delete the At1 task&lt;/em&gt; listed       their.&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li class="MsoNormal"&gt;&lt;strong&gt;Open The Gates Of      Castle&lt;/strong&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;ol start="1" type="a"&gt;&lt;li class="MsoNormal"&gt;Click on &lt;em&gt;start       -&gt; run and type gpedit.msc &lt;/em&gt;and click Ok.&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;If you are Windows XP       Home Edition user you might not have gpedit.msc in that case download and       install it from &lt;a href="http://bogdan.org.ua/2007/11/15/windows-xp-he-home-edition-gpedit-msc-group-policy-editing-via-registry.html" title="Windows XP Home Edition: gpedit.msc"&gt;Windows XP Home Edition:       gpedit.msc&lt;/a&gt; and then follow these steps.&lt;a href="http://bogdan.org.ua/2007/11/15/windows-xp-he-home-edition-gpedit-msc-group-policy-editing-via-registry.html" title="Windows XP Home Edition: gpedit.msc"&gt;&lt;br /&gt;     &lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Go to &lt;em&gt;users       configuration-&gt;Administrative templates-&gt;system&lt;/em&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Find “&lt;em&gt;prevent access       to registry editing tools&lt;/em&gt;” and change the option to &lt;em&gt;disable&lt;/em&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;a href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/gpedit1/"&gt;&lt;span style="text-decoration: none;"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1027" type="#_x0000_t75" alt="Opening the gate of castle: Group Edit Policies" href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/gpedit1/" style="'width:112.5pt;height:112.5pt'" button="t"&gt;        &lt;v:imagedata src="file:///C:\DOCUME~1\Leka\LOCALS~1\Temp\msohtml1\01\clip_image003.jpg" href="http://amiworks.co.in/talk/wp-content/uploads/2008/03/gpedit1-150x150.jpg"&gt;       &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;span style=""&gt;&lt;img src="file:///C:/DOCUME%7E1/Leka/LOCALS%7E1/Temp/msohtml1/01/clip_image003.jpg" alt="Opening the gate of castle: Group Edit Policies" class="alignnone size-thumbnail wp-image-215" title="Opening the gate of castle: Group Edit Policies" shapes="_x0000_i1027" border="0" height="150" width="150" /&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Once you do this you       have registry access back.&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li class="MsoNormal"&gt;&lt;strong&gt;Launch The Attack At      Heart Of Castle&lt;/strong&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;ol start="1" type="a"&gt;&lt;li class="MsoNormal"&gt;Click on &lt;em&gt;start-&gt;run       and type regedit&lt;/em&gt; and click ok&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Go to &lt;em&gt;edit-&gt;find       and start the search for regsvr.exe&lt;/em&gt;,&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;a href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/gate1/"&gt;&lt;span style="text-decoration: none;"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1028" type="#_x0000_t75" alt="Launch the attack in the heart of castle: registry search" href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/gate1/" style="'width:112.5pt;height:112.5pt'" button="t"&gt;        &lt;v:imagedata src="file:///C:\DOCUME~1\Leka\LOCALS~1\Temp\msohtml1\01\clip_image004.jpg" href="http://amiworks.co.in/talk/wp-content/uploads/2008/03/gate1-150x150.jpg"&gt;       &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;span style=""&gt;&lt;img src="file:///C:/DOCUME%7E1/Leka/LOCALS%7E1/Temp/msohtml1/01/clip_image004.jpg" alt="Launch the attack in the heart of castle: registry search" class="alignnone size-thumbnail wp-image-216" title="Launch the attack in the heart of castle: registry search" shapes="_x0000_i1028" border="0" height="150" width="150" /&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Delete all the       occurrence of regsvr.exe; remember to &lt;em&gt;take a backup before deleting&lt;/em&gt;.       KEEP IN MIND &lt;strong&gt;regsvr32.exe is not to be deleted. &lt;/strong&gt;&lt;em&gt;Delete       regsvr.exe occurrences only&lt;/em&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;At one ore two places       you will find it after explorer.exe in theses cases only delete the       regsvr.exe part and not the whole part. E.g. &lt;strong&gt;Shell =       “Explorer.exe regsvr.exe” &lt;/strong&gt;the just delete the regsvr.exe and       leave the explorer.exe&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li class="MsoNormal"&gt;&lt;strong&gt;Seek And Destroy the      enemy soldiers&lt;/strong&gt;, no one should be left behind &lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;ol start="1" type="a"&gt;&lt;li class="MsoNormal"&gt;Click on &lt;em&gt;start-&gt;search-&gt;for       files and folders&lt;/em&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Their &lt;em&gt;click all       files and folders&lt;/em&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Type “&lt;em&gt;*.exe” &lt;/em&gt;as       filename to search for&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Click on ‘&lt;em&gt;when was       it modified&lt;/em&gt; ‘ option and &lt;em&gt;select the specify date&lt;/em&gt; option&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Type &lt;em&gt;from date&lt;/em&gt;       as 1/31/2008 and also type &lt;em&gt;To date&lt;/em&gt; as 1/31/2008&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;a href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/search2/"&gt;&lt;span style="text-decoration: none;"&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id="_x0000_i1029" type="#_x0000_t75" alt="Seek and destory enemy soldiers: the search option" href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/search2/" style="'width:112.5pt;height:112.5pt'" button="t"&gt;        &lt;v:imagedata src="file:///C:\DOCUME~1\Leka\LOCALS~1\Temp\msohtml1\01\clip_image005.jpg" href="http://amiworks.co.in/talk/wp-content/uploads/2008/03/search2-150x150.jpg"&gt;       &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;span style=""&gt;&lt;img src="file:///C:/DOCUME%7E1/Leka/LOCALS%7E1/Temp/msohtml1/01/clip_image005.jpg" alt="Seek and destory enemy soldiers: the search option" class="alignnone size-thumbnail wp-image-217" title="Seek and destory enemy soldiers: the search option" shapes="_x0000_i1029" border="0" height="150" width="150" /&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Now hit search and       wait for all the exe’s to show up.&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Once search is over &lt;em&gt;select       all the exe files and shift+delete&lt;/em&gt; the files, &lt;strong&gt;caution&lt;/strong&gt;       must be taken so that you don’t delete the legitimate exe file that you       have installed on 31&lt;sup&gt;st&lt;/sup&gt; January.&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Also selecting lot of       files together might make your computer unresponsive so delete them in       small bunches.&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;Also find and delete       regsvr.exe, svchost .exe( notice an extra space between the svchost and       .exe)&lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li class="MsoNormal"&gt;&lt;strong&gt;Time For Celebrations&lt;/strong&gt;      &lt;o:p&gt;&lt;/o:p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div style="text-align: left;"&gt;  &lt;/div&gt;&lt;p class="MsoNormal"  style="margin-left: 1in; text-indent: -0.25in; text-align: left;font-family:arial;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;1.&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-size:7;" &gt;      &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Now do a cold reboot (ie press the reboot button instead) and you are done.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;div style="text-align: left;"&gt;  &lt;/div&gt;&lt;p style="font-family: arial; text-align: left;" class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-7350756187777034244?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/7350756187777034244/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=7350756187777034244' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/7350756187777034244'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/7350756187777034244'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/03/regsvr-virus.html' title='REGSVR VIRUS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-3378082411434197134</id><published>2009-02-07T03:14:00.000-08:00</published><updated>2009-08-07T03:16:15.294-07:00</updated><title type='text'>XPLORER.EXE</title><content type='html'>&lt;b&gt;XPLORER.EXE&lt;br /&gt;xplorer.exe&lt;/b&gt; Xplorer.exe is W32.Romariory@mm.&lt;br /&gt;W32.Romariory@mm is a mass-mailing worm that spreads through removable devices and network shares. It masquerades as the Super Mario Brothers game.&lt;br /&gt;Related files:&lt;br /&gt;%Windir%\winlogon.exe&lt;br /&gt;%System%\msvbvm60.dll.exe&lt;br /&gt;C:\explorer.exe&lt;br /&gt;%UserProfile%\Application Data\Emma.exe&lt;br /&gt;%UserProfile%\Application Data\Alisa.exe&lt;br /&gt;%UserProfile%\My Documents\Mario Bross.exe&lt;br /&gt;%UserProfile%\My Documents\Solitaire Card.exe&lt;br /&gt;%UserProfile%\My Documents\Minesweeper.exe&lt;br /&gt;%System%\PANGKALP1NANG.EXE&lt;br /&gt;%System%\SMUNSA_PKP_GAME.EXE&lt;br /&gt;C:\Documents and Settings\All Users\Documents\Bola Pantul.exe&lt;br /&gt;C:\Documents and Settings\All Users\Documents\MyHearts.exe&lt;br /&gt;C:\Documents and Settings\All Users\Documents\FreeCard.exe&lt;br /&gt;%SystemDrive%\Game\Minesweeper.exe&lt;br /&gt;%SystemDrive%\Game\My Heart.exe&lt;br /&gt;%SystemDrive%\Game\Bola.exe&lt;br /&gt;%SystemDrive%\Game\Kartu.exe&lt;br /&gt;%SystemDrive%\Game\Legend.exe&lt;br /&gt;%SystemDrive%\Game\Smart.exe&lt;br /&gt;%SystemDrive%\Game\Crazy Mouse.exe&lt;br /&gt;%SystemDrive%\Game\Text Animation.exe&lt;br /&gt;%SystemDrive%\Game\Pink Panther.exe&lt;br /&gt;%SystemDrive%\Game\Start Hide.exe&lt;br /&gt;%SystemDrive%\Game\XP Button.exe&lt;br /&gt;%SystemDrive%\Game\Goncang.exe&lt;br /&gt;%SystemDrive%\Game\Kelap Kelip.exe&lt;br /&gt;%SystemDrive%\Game\Layar Jatuh.exe&lt;br /&gt;%SystemDrive%\Game\Dark Screen.exe&lt;br /&gt;%SystemDrive%\Mario.exe&lt;br /&gt;%UserProfile%\Application Data\Emira.ini&lt;br /&gt;%UserProfile%\Application Data\Aliciana.htt&lt;br /&gt;%Windir%\Tasks\At1.job (a scheduled task to run the worm everyday at a specified time)&lt;br /&gt;%Temp%\inf[RANDOM].tmp (a clean copy of the Super Mario Brothers game)&lt;br /&gt;C:\Program Files\mario.exe (clean copy of the Super Mario Brothers game)&lt;br /&gt;%SystemDrive%\xplorer.exe&lt;br /&gt;%SystemDrive%\desktop.ini&lt;br /&gt;%SystemDrive%\Alicia.htt&lt;br /&gt;Read more: &lt;a href="http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-080101-4437-99&amp;amp;tabid=2" target="_blank"&gt;http://www.symantec.com/enterprise/secur...&lt;/a&gt;&lt;br /&gt;Kill the process xplorer.exe and remove xplorer.exe from Windows startup using RegRun Reanimator.&lt;br /&gt;&lt;a href="http://www.regrun.com/" target="_blank"&gt;http://www.regrun.com&lt;/a&gt; &lt;p&gt; Removal: xplorer.exe is removed by RegRun. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-3378082411434197134?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/3378082411434197134/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=3378082411434197134' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/3378082411434197134'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/3378082411434197134'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/xplorerexe.html' title='XPLORER.EXE'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-384094103930264010</id><published>2009-02-07T00:53:00.000-08:00</published><updated>2009-04-07T00:58:19.485-07:00</updated><title type='text'>PREVENTING WORM INFECTIONS</title><content type='html'>&lt;h2&gt;Preventing Worm Infections&lt;br /&gt;&lt;/h2&gt; &lt;p&gt;In order prevent the infection of worms, viruses and other malicious programs, we strongly suggest the following the tips below:&lt;/p&gt; &lt;p&gt;- Avoid opening emails originating from unknown senders. Beware of emails containing holiday themes, relating to money or any of your accounts.&lt;/p&gt; &lt;p&gt;- Never click on links in an email message, even if they appear to come from a reliable source. Your best bet would be to copy and paste them into your address bar.&lt;/p&gt; &lt;p&gt;- Never open email attachments from unknown senders.&lt;/p&gt; &lt;p&gt;- Be careful of the sites you visit online as many of them are designed to deliver malware&lt;/p&gt; &lt;p&gt;- Install a firewall application to prevent intruders from loading malicious content on your computer.&lt;/p&gt; &lt;p&gt;- Defend you computer with &lt;a title="malware software" href="http://www.spamlaws.com/anti-virus-software-reviews.html"&gt;security software&lt;/a&gt; with the ability to detect known and evolving strains of malware.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-384094103930264010?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/384094103930264010/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=384094103930264010' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/384094103930264010'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/384094103930264010'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/04/preventing-worm-infections.html' title='PREVENTING WORM INFECTIONS'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-4255580020111450361</id><published>2009-02-07T00:50:00.000-08:00</published><updated>2009-04-07T00:59:50.016-07:00</updated><title type='text'>VALENTIN E WORM</title><content type='html'>&lt;h2&gt;Valentin E Worm&lt;br /&gt;&lt;/h2&gt; &lt;p&gt;Similar to the Nuware Worm, Valentin E is distributed via email. It contains subjects like "True Love," "Searching for True Love," and "Love Of My Life." The worm also includes an attached file titled "FRIENDS4U." When the targeted user opens the attachment, a copy of the worm is downloaded onto their computer. Its malicious code is installed onto the machine as a file with an SCR extension. If the user runs the file, Valentin E. displays a new desktop background to distract them, all while it propagates itself on the host machine. It then distributes email messages with copies of itself attached to further spread the infection to other computers.&lt;/p&gt; &lt;p&gt;Both Nuware and Valentin E are basically employing the same techniques used in may forms of malware, particularly worms and viruses. They send emails with attractive subjects, colorful Valentine's Day e-Cards, romantic desktop themes and more. This is all done to bait the user into running the attachment and unknowingly launching malware onto their systems.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-4255580020111450361?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/4255580020111450361/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=4255580020111450361' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/4255580020111450361'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/4255580020111450361'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/04/valentin-e-worm.html' title='VALENTIN E WORM'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-1026840400536319962</id><published>2009-02-07T00:48:00.000-08:00</published><updated>2009-04-07T01:00:32.833-07:00</updated><title type='text'>NUWAR OL WORM</title><content type='html'>&lt;h2&gt;Nuwar OL Worm&lt;/h2&gt;&lt;br /&gt;Nuwar OL is delivered to a user's inbox with subjects like "You Are In My Dreams," "I Love You So Much," "Inside My Heart Is You," etc. The contents of the message contains a website link, which downloads the malicious code when accessed. To disguises its activity, the worm redirects you to simple web page with the theme of a romantic greeting card. Once the computer is infected, the infection spreads by sending messages to names in the user's contact folder. The most severe impact of the Nuwar OL is slowing down the performance of a single computer or a network. Once detected, it is generally easy to remove.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-1026840400536319962?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/1026840400536319962/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=1026840400536319962' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1026840400536319962'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1026840400536319962'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/04/nuwar-ol-worm.html' title='NUWAR OL WORM'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-5352723963371396647</id><published>2009-02-07T00:33:00.000-08:00</published><updated>2009-04-07T00:55:44.762-07:00</updated><title type='text'>AUTORUN.INF</title><content type='html'>&lt;table width="95%" align="center" border="0" cellpadding="0" cellspacing="0"&gt;               &lt;tbody&gt;&lt;tr&gt;                 &lt;td&gt; &lt;!-- #BeginEditable "title" --&gt;                   &lt;h1&gt; Autorun.inf, What is it?                     &lt;hr size="1" noshade="noshade"&gt;                   &lt;/h1&gt;                   &lt;!-- #EndEditable --&gt; &lt;/td&gt;               &lt;/tr&gt;               &lt;tr&gt;                 &lt;td&gt;&lt;!-- #BeginEditable "body" --&gt;                   &lt;p&gt;Autorun.inf is the primary instruction file associated with                     the Autorun function. Autorun.inf itself is a simple text-based                     configuration file that tells the operating system which executable                     to start, which icon to use, and which additional menu commands                     to make available. In other words, autorun.inf tells Windows                     how to deal open the presentation and treat the contents of                     the CD. &lt;/p&gt;                   &lt;p&gt;The entire sequence is initiated when the "disk change notifcation"                     polling discovers a new disk in the CD or DVD ROM drive. Then,                     if the "Auto insert notification" feature is enabled (it is                     by default), Windows checks in the new disk's root directory                     for the existence of an "autorun.inf" file. If found, Windows                     then reads and follows the specific instructions this file                     defines. If no autorun.inf file is found, then Windows refers                     to the new disk by its serial number and executes the default                     actions associated with the (data or audio) content on the                     disk.                   &lt;/p&gt;&lt;p&gt;&lt;b class="bigBlue"&gt;The Autorun.inf file defines the following:&lt;/b&gt;                   &lt;/p&gt;                   &lt;table width="90%" align="center" border="0" cellpadding="5" cellspacing="0"&gt;                     &lt;tbody&gt;&lt;tr&gt;                       &lt;td valign="top" align="center"&gt;&lt;img src="http://autorun.moonvalley.com/images/bullet.gif" alt="Autorun.inf Defines the following:" width="8" height="13" /&gt;&lt;/td&gt;                       &lt;td&gt;The process or application that will automatically run                         when a disk is inserted&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td valign="top" align="center"&gt;&lt;img src="http://autorun.moonvalley.com/images/bullet.gif" alt="Automatically run when CD is inserted" width="8" height="13" /&gt;&lt;/td&gt;                       &lt;td&gt;Optionally, one can define the process or application                         that will run for specific Operating environments.&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td valign="top" align="center"&gt;&lt;img src="http://autorun.moonvalley.com/images/bullet.gif" alt="Icon Representing CD or DVD" width="8" height="13" /&gt;&lt;/td&gt;                       &lt;td&gt;The icon that will represent your application's CD or                         DVD when the drive is viewed with My Computer or Explorer.                       &lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td valign="top" align="center"&gt;&lt;img src="http://autorun.moonvalley.com/images/bullet.gif" alt="Menu Commands when CD-ROM is clicked" width="8" height="13" /&gt;&lt;/td&gt;                       &lt;td&gt;Menu commands displayed when the user right-clicks the                         CD-ROM icon from My Computer or Explorer.&lt;/td&gt;                     &lt;/tr&gt;                   &lt;/tbody&gt;&lt;/table&gt;                                              &lt;table width="95%" align="center" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;                 &lt;td&gt; &lt;!-- #BeginEditable "title" --&gt;                   &lt;h1&gt;How to Test Autorun.inf Without Burning to a CD                     &lt;hr size="1" noshade="noshade"&gt;                   &lt;/h1&gt;                   &lt;!-- #EndEditable --&gt; &lt;/td&gt;               &lt;/tr&gt;               &lt;tr&gt;                 &lt;td&gt;&lt;!-- #BeginEditable "body" --&gt;                   &lt;p&gt;It is possible to test an Autorun.inf file without burning                     all the necessary files onto CD-ROM, as long as the computer                     has autorun enabled on at least one of its removeable devices.                     More information on such procedures to enable autorun can                     be found &lt;a href="http://autorun.moonvalley.com/enable.htm"&gt;here&lt;/a&gt;.&lt;/p&gt;                   &lt;p&gt;By utilizing the following methods, constant refining of                     the Autorun.inf file is possible without the need to burn                     multiple CDs.&lt;/p&gt;                   &lt;p&gt;                   &lt;/p&gt;&lt;h2&gt;&lt;b&gt;Using removable media (Floppy/Zip/etc...)&lt;/b&gt;&lt;/h2&gt;                   &lt;p&gt;1. &lt;a href="http://autorun.moonvalley.com/enable.htm#autoFloppy"&gt;Enable&lt;/a&gt; autorun on                     the desired removable media drive.&lt;/p&gt;                   &lt;p&gt;2. Copy the autorun.inf and all dependant files onto the                     removable media.&lt;/p&gt;                   &lt;p&gt;3. Remove and insert the media.&lt;/p&gt;                   &lt;p&gt;                   &lt;/p&gt;&lt;h2&gt;&lt;b&gt;Using a Virtual Drive&lt;/b&gt;&lt;/h2&gt;                    &lt;p&gt;1. Download and install a virtual CD/DVD-ROM emulator, such                     as the tool available from &lt;a href="http://www.daemon-tools.cc/portal/download.php"&gt;Daemon-Tools&lt;/a&gt;.                   &lt;/p&gt;                   &lt;p&gt;2. Using CD-Burning software, such as provided by &lt;a href="http://www.nero.com/"&gt;Nero&lt;/a&gt;                     or &lt;a href="http://www.roxio.com/en/products/ecdc/index.jhtml"&gt;Roxio&lt;/a&gt;,                     create a CD project with the Autorun.inf file inserted into                     the root directory of the CD.&lt;/p&gt;                   &lt;p&gt;3. Save the project to a CD project file, usually with a                     .bin or .iso or .cdi extension, with the CD-Burning software.&lt;/p&gt;                   &lt;p&gt;4. Using the CD/DVD-ROM emulator, load the project file into                     the virtual drive. This has the same effect as physically                     inserting the CD with the Autorun.inf into the CD/DVD-ROM.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;             &lt;br /&gt;                &lt;table width="100%" border="0" cellpadding="3" cellspacing="0"&gt;                     &lt;tbody&gt;&lt;tr&gt;                       &lt;td colspan="2" bgcolor="#e1e3ea"&gt;&lt;b&gt;A simple Autorun.inf                         example:&lt;/b&gt;&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr align="center"&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;[autorun]                       &lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;open=autorun.exe&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;icon=autorun.ico&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td colspan="2" bgcolor="#e1e3ea"&gt;&lt;b&gt;A complex Autorun.inf                         example:&lt;/b&gt;&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td colspan="2" align="left" bgcolor="#ffffff"&gt;&lt;i&gt;This example                         is used in the following section for complete definition                         and descriptions. &lt;/i&gt;&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt; [autorun]                       &lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt; open=filename.exe                         /argument1&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;icon=\foldername\filename.dll,5&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;[autorun.mips]&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;open=filenam2.exe&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;icon=filename.ico&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt; [autorun.alpha]&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;open=filenam3.exe&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;icon=filename.ico&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt; [autorun.ppc]&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;open=filenam4.exe&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;icon=filename.ico&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;shell\install                         = &amp;amp;Install&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;shell\install\command                         = setup.exe&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;shell\uninstall                         = &amp;amp;UnInstall&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;shell\uninstall\command                         = Uninstall.exe&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;shell\readme                         = &amp;amp;Read Me&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;shell\readme\command                         = notepad readme.txt&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;shell\help                         = &amp;amp;Help&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr&gt;                       &lt;td width="11%" align="left" bgcolor="#ffffff"&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td width="89%" align="left" bgcolor="#ffffff"&gt;shell\help\command                         = helpfilename.hlp&lt;/td&gt;                     &lt;/tr&gt;                   &lt;/tbody&gt;&lt;/table&gt;                   &lt;hr size="1" noshade="noshade"&gt;                   &lt;b&gt;This section describes the configuration of the Autorun.inf                   file and each of the potential items.&lt;/b&gt;&lt;br /&gt;             &lt;br /&gt;                &lt;table width="100%" border="0" cellpadding="3" cellspacing="0"&gt;                     &lt;tbody&gt;&lt;tr valign="top" align="left" bgcolor="#e1e3ea"&gt;                       &lt;td width="40%"&gt;&lt;b&gt;Example Autorun File:&lt;/b&gt;&lt;/td&gt;                       &lt;td width="60%"&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="40%"&gt;[autorun]&lt;/td&gt;                       &lt;td width="60%" bgcolor="#f9f9fb"&gt;&lt;b&gt;[autorun]&lt;/b&gt; is the                         primary, required section name.&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td rowspan="3" width="40%"&gt;open=filename.exe /argument1&lt;/td&gt;                       &lt;td bgcolor="#ffffff"&gt;                         &lt;p&gt;&lt;b&gt;Open&lt;/b&gt; is the keyword to determine what action                           to take upon insert notification.&lt;/p&gt;                       &lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td bgcolor="#ffffff"&gt;&lt;b&gt;filename.exe&lt;/b&gt; is the value defining                         the application that will be automatically started.&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td bgcolor="#ffffff"&gt;&lt;b&gt;/argument1&lt;/b&gt; is the argument,                         parameter or switch passed to the application being run.                         Logically, any command line parameters used must be supported                         by the application.&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td rowspan="3" width="40%"&gt;icon=\foldername\filename.dll,5&lt;/td&gt;                       &lt;td bgcolor="#f9f9fb"&gt;                         &lt;p&gt;&lt;b&gt;Icon&lt;/b&gt; is the keyword to determine the icon used                           for the disk.&lt;/p&gt;                       &lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td bgcolor="#f9f9fb"&gt;&lt;b&gt;filename.dll&lt;/b&gt; is the value defining                         the file containing the icon.&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td bgcolor="#f9f9fb"&gt;&lt;b&gt;,5 &lt;/b&gt;is the argument to the icon                         resource defining which icon to display.&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td colspan="2" bgcolor="#ffffff"&gt;                         &lt;p&gt;&lt;b&gt;Note: &lt;/b&gt;By default, the system looks for the file                           in the root directory of the inserted disk. If you want                           to access a file located in a specific folder or subdirectory,                           specify a path relative to the root. &lt;/p&gt;                         &lt;p&gt;Example: open = foldername\filename.exe This will not                           change the current directory.&lt;/p&gt;                         &lt;p&gt;Although AutoPlay is the default menu item, you can                           define a different command to be the default by including                           the following line. shell = verb&lt;/p&gt;                         &lt;p&gt;When the user double-clicks on the icon, the command                           associated with this entry will be carried out. &lt;/p&gt;                         &lt;p&gt;&lt;b&gt;Note:&lt;/b&gt; a more common method of defining the icon                           resouce is an explicit reference to a .ico file. Example:                           icon=autorun.ico&lt;/p&gt;                         &lt;p&gt;&lt;b&gt;Note:&lt;/b&gt; The icon defined representing your application's                           CD or DVD is the drive icon as viewed with My Computer                           or Explorer. Valid file types containing icons include                           .ICO .BMP .EXE .DLL If the file includes more than one                           icon, by default, the second icon in the files icon                           resource will be displayed. &lt;/p&gt;                       &lt;/td&gt;                     &lt;/tr&gt;                   &lt;/tbody&gt;&lt;/table&gt;                   &lt;p align="center"&gt; &lt;/p&gt;                   &lt;table width="100%" border="0" cellpadding="4" cellspacing="1"&gt;                     &lt;tbody&gt;&lt;tr valign="top" align="left" bgcolor="#e1e3ea"&gt;                       &lt;td width="225"&gt;&lt;b&gt;Example Autorun File:&lt;/b&gt;&lt;/td&gt;                       &lt;td colspan="2" width="317"&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#ffffff"&gt;[autorun.mips]&lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#f5f7fa"&gt;Defining the                         autorun items for a mips machine&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#ffffff"&gt;open=filenam2.exe&lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#f5f7fa"&gt;The platform                         specific application to run&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#ffffff"&gt;icon=filename2.ico&lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#f5f7fa"&gt;The platform                         specific autorun icon&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#f5f7fa" height="21"&gt;[autorun.alpha]&lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#ebedf3" height="21"&gt;Defining                         the autorun items for a DEC Alphamachine&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#f5f7fa"&gt;open=filenam3.exe&lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#ebedf3"&gt;The platform                         specific application to run&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#f5f7fa"&gt;icon=filename3.ico&lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#ebedf3"&gt;The platform                         specific autorun icon&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#ffffff"&gt;[autorun.ppc]&lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#f5f7fa"&gt;Defining the                         autorun items for a Power PC&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#ffffff"&gt;open=filenam4.exe&lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#f5f7fa"&gt;The platform                         specific application to run&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#ffffff"&gt;icon=filename4.ico&lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#f5f7fa"&gt;The platform                         specific autorun icon&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#f5f7fa"&gt;shell\install = &amp;amp;Install&lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#ebedf3"&gt;The Keyword                         defining a menu item and the Hot key for that item&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#ffffff"&gt;shell\install\command                         = setup.exe&lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#f5f7fa"&gt;The keyword                         defining the operation to perform when the user selects                         this item&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#f5f7fa"&gt;shell\uninstall = &amp;amp;UnInstall                       &lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#ebedf3"&gt;Additional                         menu item example&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#ffffff"&gt;shell\uninstall\command                         = Uninstall.exe &lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#f5f7fa"&gt;Additional                         menu item example&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#f5f7fa"&gt;shell\readme = &amp;amp;Read                         Me &lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#ebedf3"&gt;Additional                         menu item example&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#ffffff"&gt;shell\readme\command =                         notepad readme.txt&lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#f5f7fa"&gt;Additional                         menu item example&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#f5f7fa"&gt;shell\help = &amp;amp;Help&lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#ebedf3"&gt;Additional                         menu item example&lt;/td&gt;                     &lt;/tr&gt;                     &lt;tr valign="top" align="left"&gt;                       &lt;td width="225" bgcolor="#ffffff"&gt;shell\help\command = helpfilename.hlp&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;                       &lt;td colspan="2" width="317" bgcolor="#f5f7fa"&gt;Additional                         menu item example&lt;/td&gt;                     &lt;/tr&gt;                   &lt;/tbody&gt;&lt;/table&gt;                   &lt;!-- #EndEditable --&gt;&lt;/td&gt;               &lt;/tr&gt;             &lt;/tbody&gt;&lt;/table&gt;             &lt;p&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-5352723963371396647?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/5352723963371396647/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=5352723963371396647' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/5352723963371396647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/5352723963371396647'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/04/autoruninf.html' title='AUTORUN.INF'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-6105691089358317601</id><published>2009-02-03T23:09:00.000-08:00</published><updated>2009-05-03T23:12:18.585-07:00</updated><title type='text'>KEYLOGGER</title><content type='html'>Remote Keylogger - Is Your Computer Completely Safe?&lt;br /&gt; Attention! Your computer may not be as safe as you think it is at this moment. There are programs out there designed to keep track of what you do on your computer and access confidential information that you have entered on your computer. These programs are referred to as remote keyloggers in which they are usually sent through e-mail with an executable file attached to them.&lt;br /&gt;&lt;br /&gt;When the receiver of these executable attachments runs the .exe file, the keylogger is then released into the computer just like that and now you basically have no privacy on your computer. The sender of this keylogger can now monitor your activities and just about anything that you do on your computer.&lt;br /&gt;&lt;br /&gt;They can monitor anything from internet activity, documents you have viewed, online chats, any information that you enter in your computer, and applications that you run. Sometimes you are not able to detect when a keylogger enters your computer and viola! Just like that you could be giving away any confidential information or documents that you may have.&lt;br /&gt;&lt;br /&gt;Once one of these suckers hits your computer you really can't keep anything confidential anymore. If you find that someone has been logging or viewing your private information then you should seek o have your computer sweeped and cleaned immediately. If your anti-virus/spyware software does not detect the material then you should have your computer cleaned and back up any important files that you may need in the future.&lt;br /&gt;&lt;br /&gt;There are people out looking for a way to make the quick dollar and they will sometimes do whatever it takes to make it. Even if it means hacking into your computer system and stealing any information that you may have. Whether it is a credit card number or a bank account.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-6105691089358317601?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/6105691089358317601/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=6105691089358317601' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/6105691089358317601'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/6105691089358317601'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/keylogger.html' title='KEYLOGGER'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-1567767212467673898</id><published>2009-02-03T22:45:00.000-08:00</published><updated>2009-05-03T22:48:24.593-07:00</updated><title type='text'>WINDOWS VISTA PROTECTION</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Tips to Protect Windows Vista Operating System&lt;/span&gt;&lt;br /&gt; So far, Windows Vista can be considered the safest operating system but not most perfect one. In its early configuration, Vista still uncovers the possibility of leaking out the user's data to Internet through Windows Firewall, or some bots which can change settings without letting you know.&lt;br /&gt;&lt;br /&gt;Consult the WINDOWS SECURITY CENTER&lt;br /&gt;&lt;br /&gt;In order to have an overview of security settings, come to Windows Security Center where you can see the status of firewall system, automatic updating, malware protection and other security settings. Press "Start" - "Control Panel" - "Security Center", or simply click the shield-shaped icon on the taskbar.&lt;br /&gt;&lt;br /&gt;If there are any red or yellow entries, it means that you are not completely protected. If you have not installed antivirus software, for example, or the existing antivirus program is expired, the "Malware" entry in Security Center will be marked yellow. Windows does not integrate any antivirus software so that you have to install yourself.&lt;br /&gt;&lt;br /&gt;Use WINDOWS DEFENDER as a diagnosis device&lt;br /&gt;&lt;br /&gt;Malware entry in Security Center is also supposed to report the anti-spyware capacity, and Vista depends on Windows Defender to do this job. Although anti-spyware capacity in security or anti-virus utilities is usually better than that of Windows, there are some good reasons to maintain the existence of Windows Defender. One of those is that each spyware utility uses a different definition to identify the spyware. Therefore, an abundant protection sometimes brings about practical benefit.&lt;br /&gt;&lt;br /&gt;Another reason to keep Windows Defender in standby status is diagnosis capacity. Click "Tools", select "Software Explorer". Here you will find a list of all programs by category: Currently Running Programs, Network Connected Programs and Winsock Service Providers, but Startup Programs seems to be the most useful. Click ant names in the left window, the full details will display on the right. By checking any listed program, you can uninstall, deactivate or reactivate that one.&lt;br /&gt;&lt;br /&gt;Deactivate the Start Up&lt;br /&gt;&lt;br /&gt;Windows Vista monitors all documents and programs you generate in Start Up. This is convenient for some users, but on the other hands, it can be harmful for your privacy if the computer is shared in office or family. Fortunately, Window Vista provides a simple way to change this setting. The steps should be taken as follow:&lt;br /&gt;&lt;br /&gt;Right-click the taskbar and select Properties, then select "Start Menu" tab&lt;br /&gt;Uncheck "Store and Display a list of recently opened files"&lt;br /&gt;Uncheck "Store and Display a list of recently opened programs"&lt;br /&gt;Press OK.&lt;br /&gt;&lt;br /&gt;2-way Firewall&lt;br /&gt;&lt;br /&gt;Almost every PC is equipped with Firewall software, currently. However, even when Security Center states that you are protected, you might not be protected at all.&lt;br /&gt;&lt;br /&gt;The Windows Firewall function in Vista is able to "block" any input data which can endanger system, and that is really a good thing. Nevertheless, the off-line security function is not activated by default, so that this may be a dangerous situation if some new harmful software finds a way to break into your PC.&lt;br /&gt;&lt;br /&gt;Microsoft has equipped Windows Vista with tools to deploy 2-way firewall feature, but finding these settings is a little complicated. In order to activate 2-way firewall feature of Windows Vista, press "Start", select "Run", then type "wf.msc", then press "Enter". Click the icon of "Windows Firewall with Advanced Security". This interface will display the principles of monitoring system inbound/outbound information. Select "Windows Firewalls Properties". You can see a dialog box containing some tabs. For the profiles: Domain, Private and Public, you should change the settings of "Block", then press "OK".&lt;br /&gt;&lt;br /&gt;However, 2-way firewall activation can prevent all the applications from connecting to Internet. Therefore, before getting out of "Windows Firewall with Advanced Security", scroll down, select "Outbound Rules" and "New Rules" on the top right of the screen. Select "Program", on the next screen. Then select the path for Internet Explorer, iTunes or some of your applications requesting to connect to Internet. For each program, on the next screen, select "Allow the Connection", then name each principle/rule created. You will have to set a new rule for all applications which have access to the Internet.&lt;br /&gt;&lt;br /&gt;Besides, you can use a firewall utility of third party such as Comodo Firewall Pro or ZoneAlarm, which are all free and able to offer other features in addition to firewall.&lt;br /&gt;&lt;br /&gt;Close the doors to unexpected guests&lt;br /&gt;&lt;br /&gt;If you share your computer with others (even if you don't), Windows Vista provides a good way to prevent unexpected guests from guessing your password of admin account. When you create a new user and assign someone to be admin (with full rights and authority), Windows Vista allows other users to guess your selected password. The following steps are to restrain the penetration of strangers:&lt;br /&gt;&lt;br /&gt;Select "Start", type "Local Security Policy".&lt;br /&gt;Press "Account Lockout Policy"&lt;br /&gt;Select "Account Lockout Threshold"&lt;br /&gt;At the prompt, fill the maximum allowed invalid log-on attempts (e.g.: 3).&lt;br /&gt;Press "OK" and close the window.&lt;br /&gt;&lt;br /&gt;Verify the attackers&lt;br /&gt;&lt;br /&gt;With proper Account Lockout policy, you can activate the feature of verifying attempts to attack your account. In order to start verify the invalid log-on, the steps are as follow:&lt;br /&gt;&lt;br /&gt;Select "Start", type "secpol.msc, click "secpol" icon.&lt;br /&gt;Press Local Policies then press "Audit Policy"&lt;br /&gt;Right-click "Audit account logon events policy" option and select "Properties".&lt;br /&gt;Check the dialog box "Failure" and press OK&lt;br /&gt;Close "Local Security Policy" window.&lt;br /&gt;Now, you can use Event Viewer feature (by typing the command: eventvwr.msc) to view the log-on history recorded in Windows Logs and Security.&lt;br /&gt;&lt;br /&gt;INTERNET EXPLORER settings security&lt;br /&gt;&lt;br /&gt;Windows Security Center also has function of reporting if security status of Internet Explorer 7 and Internet Explorer 8 is as required or not. If the status is marked red, you should rapidly modify the IE settings&lt;br /&gt;&lt;br /&gt;In the menu, select Tools, then select Internet Options&lt;br /&gt;Select Security tab&lt;br /&gt;Select Custom Level&lt;br /&gt;&lt;br /&gt;Now you will see a window containing all options relating to IE's security issue. If the options are lower than required (can be changed by some malwares), those will be marked red. To modify a setting, click the corresponding one. In order to reset the original settings, press "Reset" button at the bottom of the tab. If you want, you can change the general security settings of the browser from Medium - High (by default) to High or Medium as required. Press "OK" to save these changes&lt;br /&gt;&lt;br /&gt;Use OPEN DNS&lt;br /&gt;&lt;br /&gt;DNS (Domain Name System) servers play the role of a telephone directory. When you type a domain name dantri.com.vn, for example, in the address bar, Internet Explorer will send the requirement of common domain name to DNS servers of the your ISP, then these servers are supposed to transform the character sequence to a string of numbers or an IP address. The DNS servers have been attacked over the past few years because the hackers have tried every possible way to redirect the common DNSs to the servers which they can control. A solution to prevent this abuse is to use Open DNS.&lt;br /&gt;&lt;br /&gt;Click "Start" à "Control Panel" à "Network and Internet"&lt;br /&gt;Select "Network and Sharing Center". Under the taskbars listed on the left, select "Manage Network Connections". In the window of "Manage Network Connections", follow these steps:&lt;br /&gt;Right-click the icon of your network card&lt;br /&gt;Select Properties.&lt;br /&gt;Then select "Internet Protocol Version 4".&lt;br /&gt;Click "Properties" in the next displayed screen.&lt;br /&gt;Select "Use the following DNS server addresses".&lt;br /&gt;Input 208.67.222.222 into the primary address&lt;br /&gt;Input 208.67.220.220 into the secondary address&lt;br /&gt;Press OK&lt;br /&gt;&lt;br /&gt;Cohabit with USER ACCOUNT CONTROL&lt;br /&gt;&lt;br /&gt;There is a setting status that some users want it marked red. That is Vista's User Account Control (UAC) - the controversial security function of Vista operating system.&lt;br /&gt;&lt;br /&gt;Designed to prevent the remote malware/spyware from automatically installing or modifying system settings, UAC tends to block legal installations by stopping the ongoing process with unnecessary error messages. In Windows 7, you can set up UAC as you want. Up to then, you will have more options.&lt;br /&gt;&lt;br /&gt;There is an option of invalidating UAC. However, you should consider this risky choice because UAC can warn you of potential dangers. Instead, install Tweak UAC - a free utility that allows you to turn on or turn off UAC and simultaneously provides an intermediate "quiet" mode (this mode keeps UAC on but suppresses administration elevation prompts). With TweakUAC in "quiet" mode, UAC seem to be turned off to those who use administration accounts, but those who use standard account will still receive the warning messages.&lt;br /&gt;&lt;br /&gt;Verify the results&lt;br /&gt;&lt;br /&gt;By modifying the security settings of Windows Vista, now you can monitor the safety of system via System Health Report. This diagnosis tool receives the input date from Performance and Reliability Monitor and transforms them into a report with general information. To some extent, this report can provides you with information of potential security issues.&lt;br /&gt;&lt;br /&gt;Open Control Panel.&lt;br /&gt;Click System.&lt;br /&gt;In Tasks list, select Performance (near the bottom of the list).&lt;br /&gt;In resulting Tasks list, click Advanced tools (near the top of the list).&lt;br /&gt;Click the last item on the resulting Task list: Generate a system health report.&lt;br /&gt;This report will list any missing drivers which can cause errors, reporting to you if the antivirus protection is installed or not, or if the UAC is on or off. To make sure of the best condition of your Pc, run this report monthly.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-1567767212467673898?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/1567767212467673898/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=1567767212467673898' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1567767212467673898'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1567767212467673898'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/05/windows-vista-protection.html' title='WINDOWS VISTA PROTECTION'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-1804853433994153945</id><published>2009-02-02T23:10:00.000-08:00</published><updated>2009-08-07T03:16:49.940-07:00</updated><title type='text'>SVRCHOST.EXE</title><content type='html'>Summary :    Trojan.SVRCHost/SystemSavior.Process&lt;br /&gt;  &lt;br /&gt;Description :  Trojan.SVRCHost/SystemSavior.Process&lt;br /&gt;&lt;br /&gt;Trojans are programs that can appear to serve a legitimate purpose but actually have an unwanted or harmful effect.&lt;br /&gt;&lt;br /&gt;A large segment of trojan programs download other harmful software components to a user's PC without his/her knowledge.&lt;br /&gt;&lt;br /&gt;This application is most likely downloaded and installed by another application that is considered to be adware or spyware.&lt;br /&gt;  &lt;br /&gt;Company :  Unknown&lt;br /&gt;  &lt;br /&gt;Threat Level :  Threat Level : 8&lt;br /&gt;Category :  TROJAN&lt;br /&gt;&lt;br /&gt;The following threats are known to be associated with the file "svrchost.exe":&lt;br /&gt;Threat Alias Number of Incidents&lt;br /&gt;Mal/Generic-A [Sophos] 2&lt;br /&gt;W32.Imaut.CN [Symantec] 2&lt;br /&gt;W32/YahLover.worm [McAfee] 2&lt;br /&gt;Worm.AutoIt.s [PC Tools] 2&lt;br /&gt;Worm.Win32.AutoIt [Ikarus] 2&lt;br /&gt;Worm.Win32.AutoIt.bh [Kaspersky Lab] 2&lt;br /&gt;WORM_IMAUT.AT [Trend Micro] 2&lt;br /&gt;  &lt;br /&gt;Processes :  SVRCHOST.EXE&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-1804853433994153945?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/1804853433994153945/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=1804853433994153945' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1804853433994153945'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1804853433994153945'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/svrchostexe.html' title='SVRCHOST.EXE'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-5508741754753592101</id><published>2009-02-02T02:29:00.000-08:00</published><updated>2009-04-08T04:45:18.004-07:00</updated><title type='text'>IP SPOOFING ATTACKS: DESCRIPTION</title><content type='html'>The first vulnerability, spoofing IP packets, allows an intruder on the Internet to effectively impersonate a local system's IP address. If other local systems perform session authentication based on the IP address of a connection (e.g. rlogin with .rhosts or /etc/hosts.equiv files under Unix), they will believe incoming connections from the intruder actually originate from a local "trusted host" and will not require a password. This technique is especially damaging when root connections are permitted with no password.&lt;br /&gt;Services that are vulnerable to forged IP packets include:&lt;br /&gt;• SunRPC &amp; NFS&lt;br /&gt;• BSD Unix "r" commands, including rlogin&lt;br /&gt;• Services secured by TCP Wrappers using source address access control&lt;br /&gt;• X Windows&lt;br /&gt;&lt;br /&gt;It is possible for forged packets to penetrate firewalls based on filtering routers if the router is not configured to block incoming packets with source addresses in the local domain. It is important to note that this attack is possible even if no session packets can be routed back to the attacker. Note also that this attack is not based on the source routing option of the IP protocol.&lt;br /&gt;How did they get my address?&lt;br /&gt;Most spammers get your address by buying lists from other spammers. But how did someone get it in the first place? Often when you give your address to websites that you visit. Some of these sites pass your address on to other sites, who pass it on in turn. More often, your address is "scraped" form the webpage where it appears. For example, in your user profile. If you can see it online, so can the spammers.&lt;br /&gt;They can also get it by harvesting your address from chain messages -- you know -- the ones that have Fw: Fwd: Cute Joke (or whatever) as their Subject. Some people don't know how to forward messages without sending the whole "To:" list to everybody on the list. Eventually one of those messages lands in the web (pun intended) of some spammer. Tell your friend please take me off your humor distribution list, of at least please follow the advice below:&lt;br /&gt;"If you want to forward jokes and stuff properly, put all the "Fwd" addresses in the "Blind Copy" (BCC) line, not in the "To" line so that each recipient gets their own private message, with none of the other addresses in it. Also, it would be polite to edit the original message so that all the previous addresses are removed." See the tutorial by Somewhere in Time to learn more about how to "forward" properly using "BCC".&lt;br /&gt;Spammers also simply guess email addresses. How hard would it be to guess Robert87639@aol.com? It simply follows Robert 87638. Spammers can easily try all these common combinations. It doesn't take much effort with high speed computers doing the work. If you respond in anger, or even to "unsubscribe", they know they've hooked a live one.&lt;br /&gt;Some spam that doesn't even need your email address. This spam uses the Messenger "service" in Windows (not to be confused with Windows Messenger). It just pops up without warning in the middle of what you're doing. You can use a firewall to stop Messenger spam in Windows 98, or you can reconfigure your NetBIOS networking -- something you should do for security anyway. You can disable Windows Messenger in Windows XP, 2000 and NT to stop it.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-5508741754753592101?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/5508741754753592101/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=5508741754753592101' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/5508741754753592101'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/5508741754753592101'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/ip-spoofing-attacks-description.html' title='IP SPOOFING ATTACKS: DESCRIPTION'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-4039320975723255544</id><published>2009-02-02T02:25:00.000-08:00</published><updated>2009-02-02T02:28:10.565-08:00</updated><title type='text'>PACKET FILTER:</title><content type='html'>A packet-filtering firewall is a router or computer running software that has been configured to screen incoming and outgoing packets. A packet-filtering firewall accepts or denies packets based on information contained in the packets' TCP and IP headers. For example, most packet-filtering firewalls can accept or deny a packet based on the packet's full association, which consists of the following:&lt;br /&gt;• Source address&lt;br /&gt;• Destination address&lt;br /&gt;• Application or protocol&lt;br /&gt;• Source port number&lt;br /&gt;• Destination port number&lt;br /&gt;A packet-filtering firewall scans these rules until it finds one that agrees with the information in a packet's full association. If the firewall encounters a packet that does not meet one of the rules, the firewall will apply the default rule. A default rule should be explicitly defined in the firewall's table and, for strict security, should instruct the firewall to drop a packet that meets none of the other rules.&lt;br /&gt;&lt;br /&gt;The primary advantage of using a packet-filtering firewall is that it provides some measure of protection for relatively low cost and causes little to no delay in network performance. If you already have an IP router with packet-filtering capabilities, setting up a packet-filtering firewall will cost no more than the time it takes to create packet-filtering rules. Most IP routers, including those manufactured by Novell, Cisco Systems, and Bay Networks, can filter incoming and outgoing packets.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-4039320975723255544?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/4039320975723255544/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=4039320975723255544' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/4039320975723255544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/4039320975723255544'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/packet-filter.html' title='PACKET FILTER:'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-1627010284004334763</id><published>2009-02-02T02:21:00.000-08:00</published><updated>2009-02-02T02:29:24.329-08:00</updated><title type='text'>FIREWALL:</title><content type='html'>A system designed to prevent unauthorized access to or from a private network. Firewalls can be implemented in both hardware and software, or a combination of both. Firewalls are frequently used to prevent unauthorized Internet users from accessing private networks connected to the Internet, especially intranets. All messages entering or leaving the intranet pass through the firewall, which examines each message and blocks those that do not meet the specified security criteria.&lt;br /&gt;There are several types of firewall techniques:&lt;br /&gt;• Packet filters: Looks at each packet entering or leaving the network and accepts or rejects it based on user-defined rules.&lt;br /&gt;Packet filtering is fairly effective and transparent to users, but it is difficult to configure. In addition, it is susceptible to IP spoofing.&lt;br /&gt;• Application gateway: Applies security mechanisms to specific applications, such as FTP and Telnet servers. This is very effective, but can impose performance degradation.&lt;br /&gt;• Circuit-level gateway: Applies security mechanisms when a TCP or UDPconnection is established.&lt;br /&gt;Once the connection has been made, packets can flow between the hosts without further checking.&lt;br /&gt;• Proxy server: Intercepts all messages entering and leaving the network. The proxy server effectively hides the true network addresses.&lt;br /&gt;&lt;br /&gt;  Network security usually is thought of in terms of securing your network against threats that originate from the Internet. Attacks that come from the Internet are common and relatively easy. The Internet was designed to be an open, free flowing system that encourages the unrestricted exchange of information. The Internet was not designed as a secure system that regulates information exchange. On top of the security problem inherent to the Internet is the fact that most TCP/IP based services are also not designed to provide their own security. In order to secure Internet services such as FTP or HTTP, administrators must put into place additional security methods. Despite these risks, the Internet is not the most common source for network attacks. The widespread distribution of hacking information on the Internet has allowed disgruntled or malicious employees to exploit the same vulnerabilities mentioned above on their own networks with little or no security in their way. That's the bad news. The good news is that the same methods used to protect your network from the Internet can be used to protect your network from itself. Implementing multiple DMZ's, strong authentication and digital certificates can help you protect your network (from within and without) as well as provide a more secure opportunity to increase your level of service. With strong authentication, for example, you can make sure that a user authentication attempt originates from a valid source. This also gives you a more secure opportunity to offer remote access into your network from business partners and/or remote employees. The first step toward network security starts with a firewall. After the firewall has been properly installed then other security measures can be more suitably put into place. There are no guarantees in any type of security (network or otherwise). So, if you have extremely sensitive information to protect, then the system storing that information should not be connected to any network (a pair of wire cutters is your best bet for network security). In all other cases, implementing a firewall (or multiple firewalls) is essential to protecting your network. In non-computer industries, a firewall is a specially designed wall that controls the spreading of a fire. In networking, a firewall could be described as a specially designed device that controls the spreading of a network threat. The most commonly talked about source of network threats is the Internet. The Internet is the home of many unknown people that we cannot trust. There are hackers on the Internet that may want to do our networks harm. We can use a firewall to impede an untrusted person from doing damage to our networks.&lt;br /&gt;A more textbook definition of a computer firewall is that it is a method or device that regulates the level of trust between two or more networks. A firewall can consist of software, hardware or a combination of both. A firewall can protect your network from the Internet as well as regulate the traffic between networks within the same company.&lt;br /&gt;&lt;br /&gt;For instance, a firewall can allow the legal department's network to have access to the marketing file server but the marketing department can be refused access to legal. In this example the firewall is positioned between the marketing and legal networks so that all communication must pass through the firewall. The firewall is then able to ensure that only authorized packets are allowed.&lt;br /&gt;&lt;br /&gt;STATEFUL INSPECTION FIREWALL&lt;br /&gt;                    A stateful inspection firewall combines aspects of a packet-filtering firewall, a circuit-level gateway, and an application-level gateway. Like a packet-filtering firewall, a stateful inspection firewall operates at the network layer of the OSI model, filtering all incoming and outgoing packets based on source and destination IP addresses and port numbers. A stateful inspection firewall also functions as a circuit-level gateway, determining whether the packets in a session are appropriate. For example, a stateful inspection firewall verifies that SYN and ACK flags and sequence numbers are logical.&lt;br /&gt;&lt;br /&gt;stateful inspection firewalls, like all firewalls are not 100 percent effective. So why bother implementing a firewall at all? You should implement a firewall for the same reason you protect your home by locking your doors, despite the fact that this safely measure does not guarantee that an intruder cannot enter your house. Leaving an Internet or intranet connection without a firewall is a careless, open invitation to would-be intruders.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-1627010284004334763?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/1627010284004334763/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=1627010284004334763' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1627010284004334763'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/1627010284004334763'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/firewall.html' title='FIREWALL:'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-9180200035899617692</id><published>2009-02-02T02:18:00.001-08:00</published><updated>2009-02-02T02:18:39.169-08:00</updated><title type='text'>COOKIES</title><content type='html'>A cookie is just a bit of text in a file on your computer, containing a small amount of information that identifies you to a particular Web site, and whatever information that site wanted to retain about the user when they are visiting.&lt;br /&gt;Cookies are a legitimate tool used by many Web sites to track visitor information. As an example, one might go to an online computer store and place an item in the basket, but decide not to buy it right away because he/she want to compare prices. The store can choose to put the information about what products he/she put into the basket in a cookie stored in the computer. This is an example of a good use of cookies to help the user experience.&lt;br /&gt;&lt;br /&gt;The only Web sites who are supposed to be able to retrieve the information stored in a cookie are the Web sites who wrote the information in that particular cookie. This should ensure your privacy by stopping anyone other than the site you are visiting from being able to read any cookies left by that site.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-9180200035899617692?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/9180200035899617692/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=9180200035899617692' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/9180200035899617692'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/9180200035899617692'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/cookies.html' title='COOKIES'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-5963420407855208053</id><published>2009-02-02T02:06:00.001-08:00</published><updated>2009-02-03T22:25:44.117-08:00</updated><title type='text'>ANTIVIRUS SOFTWARE</title><content type='html'>&lt;p&gt;&lt;span style="font-family:arial;"&gt;Top 20 Antivirus rankings. Tested using 174,770 virus samples.&lt;br /&gt;&lt;br /&gt;This is the list of the top 20 antivirus applications&lt;br /&gt;&lt;br /&gt;To Download any of these software, type the name of the anti-virus in google and you will get it.&lt;br /&gt;&lt;br /&gt;1. Kaspersky version 7.0.0.43 beta - 99.23%&lt;br /&gt;2. Kaspersky version 6.0.2.614 - 99.13%&lt;br /&gt;3. Active Virus Shield by AOL version 6.0.0.308 - 99.13%&lt;br /&gt;4. ZoneAlarm with KAV Antivirus version 7.0.337.000 - 99.13%&lt;br /&gt;5. F-Secure 2007 version 7.01.128 - 98.56%&lt;br /&gt;6. BitDefender Professional version 10 - 97.70%&lt;br /&gt;7. BullGuard version 7.0.0.23 - 96.59%&lt;br /&gt;8. Ashampoo version 1.30 - 95.80%&lt;br /&gt;9. eScan version 8.0.671.1 - 94.43%&lt;br /&gt;10. Nod32 version 2.70.32 - 94.00%&lt;br /&gt;11. CyberScrub version 1.0 - 93.27%&lt;br /&gt;12. Avast Professional version 4.7.986 - 92.82%&lt;br /&gt;13. AVG Anti-Malware version 7.5.465 - 92.14%&lt;br /&gt;14. F-Prot version 6.0.6.4 - 91.35%&lt;br /&gt;15. McAfee Enterprise version 8.5.0i+AntiSpyware module - 90.65%&lt;br /&gt;16. Panda 2007 version 2.01.00 - 90.06%&lt;br /&gt;17. Norman version 5.90.37 - 88.47%&lt;br /&gt;18. ArcaVir 2007 - 88.24%&lt;br /&gt;19. McAfee version 11.0.213 - 86.13%&lt;br /&gt;20. Norton Professional 2007 - 86.08%&lt;br /&gt;&lt;br /&gt;Followed by:&lt;br /&gt;21. Rising AV version 19.19.42 - 85.46%&lt;br /&gt;22. Dr. Web version 4.33.2 - 85.09%&lt;br /&gt;23. PC-Cillin 2007 version 15.00.1450 - 84.96%&lt;br /&gt;24. Iolo version 1.1.8 - 83.35%&lt;br /&gt;25. Virus Chaser version 5.0a - 79.51%&lt;br /&gt;26. VBA32 version 3.11.4 - 77.66%&lt;br /&gt;27. Sophos Sweep version 6.5.1 - 69.79%&lt;br /&gt;28. ViRobot Expert version 5.0 - 69.53%&lt;br /&gt;29. Antiy Ghostbusters version 5.2.1 - 65.95%&lt;br /&gt;30. Zondex Guard version 5.4.2 - 63.79%&lt;br /&gt;31. Vexira 2006 version 5.002.62 - 60.07%&lt;br /&gt;32. V3 Internet Security version 2007.04.21.00 - 55.09%&lt;br /&gt;33. Comodo version 2.0.12.47 beta - 53.94%&lt;br /&gt;34. Comodo version 1.1.0.3 - 53.39%&lt;br /&gt;35. A-Squared Anti-Malware version 2.1 - 52.69%&lt;br /&gt;36. Ikarus version 5.19 - 50.56%&lt;br /&gt;37. Digital Patrol version 5.00.37 - 49.80%&lt;br /&gt;38. ClamWin version 0.90.1 - 47.95%&lt;br /&gt;39. Quick Heal version 9.00 - 38.64%&lt;br /&gt;40. Solo version 5.1 build 5.7.3 - 34.52%&lt;br /&gt;41. Protector Plus version 8.0.A02 - 33.13%&lt;br /&gt;42. PcClear version 1.0.4.3 - 27.14%&lt;br /&gt;43. AntiTrojan Shield version 2.1.0.14 - 20.25%&lt;br /&gt;44. PC Door Guard version 4.2.0.35- 19.95%&lt;br /&gt;45. Trojan Hunter version 4.6.930 - 19.20%&lt;br /&gt;46. VirIT version 6.1.75 - 18.78%&lt;br /&gt;47. E-Trust PestPatrol version 8.0.0.6 - 11.80%&lt;br /&gt;48. Trojan Remover version 6.6.0 - 10.44%&lt;br /&gt;49. The Cleaner version 4.2.4319 - 7.26%&lt;br /&gt;50. True Sword version 4.2 - 2.20%&lt;br /&gt;51. Hacker Eliminator version 1.2 - 1.43%&lt;br /&gt;52. Abacre version 1.4 - 0.00%&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;      Antivirus software consists of computer programs that attempt to identify, thwart and eliminate computer viruses and other malicious software (malware).&lt;br /&gt;&lt;/p&gt;Antivirus software typically uses two different techniques to accomplish this:&lt;br /&gt;• Examining (scanning) files to look for known viruses matching definitions in a virus dictionary&lt;br /&gt;• Identifying suspicious behavior from any computer program which might indicate infection. Such analysis may include data captures, port monitoring and other methods.&lt;br /&gt;Most commercial antivirus software uses both of these approaches, with an emphasis on the virus dictionary approach.&lt;br /&gt;Usually, the term antivirus has also been used for benign computer viruses that spread and combated malicious viruses. This was common on the Amiga computer platform.&lt;br /&gt;&lt;br /&gt;There are competing claims for the innovator of the first antivirus product. Perhaps the first publicly known neutralization of a wild PC virus was performed by European Bernt Fix (also Bernd) in early 1987. Fix neutralized an infection of the Vienna virus. First edition of Polish antivirus software mks_vir starten in 1987. Program was only available in Polish language version. Fall 1988 also saw antivirus software Dr. Solomon's Anti-Virus Toolkit released by Briton Alan Solomon. By December 1990 the market had matured to the point of nineteen separate antivirus products being on sale including Norton AntiVirus and ViruScan from McAfee.&lt;br /&gt;Tippett made a number of contributions to the budding field of virus detection. He was an emergency room doctor who also ran a computer software company. He had read an article about the Lehigh viruses were the first viruses to be developed, but it was Lehigh that Tippett read about and he questioned whether they would have similar characteristics to viruses that attack humans. From an epidemiological viewpoint, he was able to determine how these viruses were affecting systems within the computer (the boot-sector was affected by the Brain virus, the .com files were affected by the Lehigh virus, and both .com and .exe files were affected by the Jerusalem virus). Tippett’s company Certus International Corp. then began to create anti-virus software programs. The company was sold in 1992 to Symantec Corp, and Tippett went to work for them, incorporating the software he had developed into Symantec’s product, Norton AntiVirus.&lt;br /&gt;&lt;br /&gt;Some antivirus-software use other types of heuristic analysis. For example, it could try to emulate the beginning of the code of each new executable that the system invokes before transferring control to that executable. If the program seems to use self-modifying code or otherwise appears as a virus (if it immediately tries to find other executables, for example), one could assume that a virus has infected the executable. However, this method could result in a lot of false positives.&lt;br /&gt;Yet another detection method involves using a sandbox. A sandbox emulates the operating system and runs the executable in this simulation. After the program has terminated, software analyzes the sandbox for any changes which might indicate a virus. Because of performance issues, this type of detection normally only takes place during on-demand scans. Also this method may fail as viruses can be nondeterministic and result in different actions or no actions at all done when run - so it will be impossible to detect it from one run.&lt;br /&gt;An emerging technique to deal with malware in general is whitelisting. Rather than looking for only known bad software, this technique prevents execution of all computer code except that which has been previously identified as trustworthy by the system administrator. By following this default deny approach, the limitations inherent in keeping virus signatures up to date are avoided. Additionally, computer applications that are unwanted by the system administrator are prevented from executing since they are not on the whitelist. Since modern enterprise organizations have large quantities of trusted applications, the limitations of adopting this technique rest with the system administrators' ability to properly inventory and maintain the whitelist of trusted applications. As such, viable implementations of this technique include tools for automating the inventory and whitelist maintenance processes.&lt;br /&gt;&lt;br /&gt;• User education can effectively supplement antivirus software. Simply training users in safe computing practices (such as not downloading and executing unknown programs from the Internet) would slow the spread of viruses and obviate the need of much antivirus software. The ongoing writing and spreading of viruses and of panic about them gives the vendors of commercial antivirus software a financial interest in the ongoing existence of viruses. Some theorize that antivirus companies have financial ties to virus writers, to generate their own market, though there is currently no evidence for this. Some antivirus software can considerably reduce performance. Users may disable the antivirus protection to overcome the performance loss, thus increasing the risk of infection. For maximum protection the antivirus software needs to be enabled all the time — often at the cost of slower performance (see also software bloat).&lt;br /&gt;• It is important to note that one should not have more than one antivirus software installed on a single computer at any given time. This can seriously cripple the computer and cause further damage. This is not always obviously stated in terms of usage for these programs.&lt;br /&gt;• It is sometimes necessary to temporarily disable virus protection when installing major updates such as Windows Service Packs or updating graphics card drivers. Having antivirus protection running at the same time as installing a major update may prevent the update installing properly or at all.&lt;br /&gt;• When purchasing antivirus software, the agreement may include a clause that your subscription will be automatically renewed, and your credit card automatically billed at the renewal time without your approval. For example, McAfee requires one to unsubscribe at least 60 days before the expiration of the present subscription, yet it does not provide phone access nor a way to unsubscribe directly through their website. In that case, the subscriber's recourse is to contest the charges with the credit card issuer.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-5963420407855208053?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/5963420407855208053/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=5963420407855208053' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/5963420407855208053'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/5963420407855208053'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/antivirus-software.html' title='ANTIVIRUS SOFTWARE'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-8551943722271087767</id><published>2009-02-02T02:05:00.000-08:00</published><updated>2009-02-21T02:51:37.615-08:00</updated><title type='text'>PREVENT A VIRUS FROM INFECTING MY COMPUTER.</title><content type='html'>&lt;span style="font-family:arial;"&gt;A virus scanner is the most common tool for prevention. This utility attempts to scan a computer program before it runs, and if it recognizes the signature of a malicious code, it shuts it down. Many scanners also evaluate programs to determine if it contains any virus-related characteristics.&lt;br /&gt;&lt;br /&gt;The best way to stop viruses is to use common sense. If an executable computer program is attached to your e-mail and you are unsure of the source, then it should be deleted immediately. Do not download any applications or executable files from unknown sources, and be careful when trading files with other users.&lt;br /&gt;&lt;br /&gt;• Two of the biggest concerns for computer users today are viruses and spyware. In both cases, we have seen that while these can be a problem you can defend yourself against them easily enough with just a little bit of planning:&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;• Keep your computer’s software patched and current. Both your operating system and your anti- virus application must be updated on a regular basis.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;• Only download updates from reputable sources. For Windows operating systems, always go to http://windowsupdate.microsoft.com and for other software always use the legitimate Web sites of the company or person who produces it.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;• Always think before you install something, weigh the risks and benefits, and be aware of the fine print. Does the lengthy license agreement that you don’t want to read conceal a warning that you are about to install spyware?&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;• Install and use a firewall. If you are running Windows XP you can use the built-in software firewall under Control Panel, and there are free versions of firewalls that work on all versions of Windows.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;• Prevention is always better than cure.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-8551943722271087767?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/8551943722271087767/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=8551943722271087767' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/8551943722271087767'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/8551943722271087767'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/prevent-virus-from-infecting-my.html' title='PREVENT A VIRUS FROM INFECTING MY COMPUTER.'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-513619933160753569</id><published>2009-02-02T02:04:00.000-08:00</published><updated>2009-02-02T02:09:24.671-08:00</updated><title type='text'>WHAT EXACTLY IS A VIRUS? IS A “WORM” ALSO A VIRUS?</title><content type='html'>Viruses are computer programs or scripts that attempt to spread from one file to another on a single computer and/or from one computer to another, using a variety of methods, without the knowledge and consent of the computer user. A worm is a specific type of virus that propagates itself across many computers, usually by creating copies of itself in each computer’s memory.&lt;br /&gt;Many users define viruses simply as trick programs designed to delete or move hard drive data, which, strictly speaking, is not correct. From a technical viewpoint, what makes a virus a virus is that it spreads itself. The damage it does is often incidental when making a diagnosis.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Obviously, any incidental damage is important, even when authors do not intend to create problems with their viruses; they can still cause harm unintentionally because the author did not anticipate the full effect or unintentional side effects. The most common method used for spreading a virus is through e-mail attachment. Sending a virus, even if designed to be harmless, can cause unforeseen damage.&lt;br /&gt;&lt;br /&gt;Viruses and Worms &lt;br /&gt;&lt;br /&gt;The term virus has long been used generically to describe any computer threat, but in actuality it refers specifically to malware that inserts malicious code into existing documents or programs, and then spreads itself by various means. &lt;br /&gt;&lt;br /&gt;The reason people often call every computer threat a "virus", is because viruses are the original type of malware, actually predating the public Internet. Today, viruses are still by far the most common type of network security threat, and over 90 percent of viruses are spread through attachments on emails. Often the attacker will combine a virus with a "zombie" attack (discussed below) so that you will receive an email with an attachment from a friend that actually contains a virus. &lt;br /&gt;&lt;br /&gt;Prevention &lt;br /&gt;The good news about viruses, is that they require a user action to insert themselves onto your computer. So, training your office staff to never open an email attachment that they weren't expecting, no matter who the sender is, will go a very long way to keeping your network free of viruses. Unfortunately, educating your staff about what attachments to open will do little to stop worms from infecting your network. That is because although worms are also often initially delivered in email, they don't need a host file (i.e., no attachment is needed for an email to be infected) and they can propagate themselves. Worms, unlike viruses, spread on their own. So once a computer is infected, the worm can often make quick copies of itself and infect an entire network within a few hours. Because of this unique opportunity to multiply themselves quickly across a network, worms are responsible for a good number of companies’ widespread network failures. &lt;br /&gt;&lt;br /&gt;Both viruses and worms often work to open up new holes in your network security in order to allow even more dangerous security threats to infect your network. Consequently, it should be an essential priority of every company and individual to use virus protection software to limit the incoming malware, and then to educate employees to make sure those worms and viruses that slip through never get opened.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-513619933160753569?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/513619933160753569/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=513619933160753569' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/513619933160753569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/513619933160753569'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/what-exactly-is-virus-is-worm-also.html' title='WHAT EXACTLY IS A VIRUS? IS A “WORM” ALSO A VIRUS?'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-4006020487274274294</id><published>2009-02-02T02:03:00.000-08:00</published><updated>2009-02-02T02:15:56.469-08:00</updated><title type='text'>MALWARE</title><content type='html'>"Malware" is short for malicious software and is typically used as a catch-all term to refer to any software designed to cause damage to a single computer, server, or computer network, whether it's a virus, spyware, etc.&lt;br /&gt;&lt;br /&gt;Malware, a portmanteau from the words malicious and software, is software designed to infiltrate or damage a computer system without the owner's informed consent. The expression is a general term used by computer professionals to mean a variety of forms of hostile, intrusive, or annoying software or program code.[1] The term "computer virus" is sometimes used as a catch-all phrase to include all types of malware, including true viruses.&lt;br /&gt;&lt;br /&gt;Software is considered malware based on the perceived intent of the creator rather than any particular features. Malware includes computer viruses, worms, trojan horses, most rootkits, spyware, dishonest adware, crimeware and other malicious and unwanted software. In law, malware is sometimes known as a computer contaminant, for instance in the legal codes of several American states, including California and West Virginia.[2] [3]&lt;br /&gt;&lt;br /&gt;Malware is not the same as defective software, that is, software which has a legitimate purpose but contains harmful bugs.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-4006020487274274294?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/4006020487274274294/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=4006020487274274294' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/4006020487274274294'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/4006020487274274294'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/malware-viruses-spyware-and-cookies.html' title='MALWARE'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-2891029103261246328</id><published>2009-02-02T01:58:00.000-08:00</published><updated>2009-02-02T02:03:43.860-08:00</updated><title type='text'>NETWORK SECURITY</title><content type='html'>Computer security protects your computer and everything related with it. Most importantly, the protection of the information you have stored in your system That`s why computer security is sometimes called as “information security’ or network security. It is defined as the prevention of network resources against unauthorized users or any user on network can access the data, modify or destruct if proper security is not provided. In a network data is safe only when restrictions are placed for unauthorized access.&lt;br /&gt;&lt;br /&gt;Protection of information safely in the computer, under the operating system`s control can be implemented efficiently. Usually physically securing the computer system, providing authentication mechanisms to perform log-ins and managing resource access based on authentication is enough when there is just one computer. But, in the world of networks, multi-vendor configurations and open systems, information is increasingly on the move and being shared by different users on different systems. Information that`s protected securely by an operating system becomes much more vulnerable when it is being transmitted and shared via network connections. Instead of being available to only a relatively small population of users within your own organization, your computer system potentially open to attack by anyone. The number of possible users, the ease of access from remote and sometimes anonymous locations and the oppurtunity for error intruduced by the incresing complexity of networked systems all contribute to this vulnerability.&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-2891029103261246328?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/2891029103261246328/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=2891029103261246328' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/2891029103261246328'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/2891029103261246328'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/02/network-security.html' title='NETWORK SECURITY'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5074766823662728299.post-4798272190131259447</id><published>2009-02-01T05:50:00.000-08:00</published><updated>2009-04-08T04:39:25.723-07:00</updated><title type='text'>IE SECURITY THREAT</title><content type='html'>&lt;p&gt;&lt;strong&gt;Gopher Attacks Are Latest IE Security Threat&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The Gopher protocol has been forced underground since the advent of the World Wide Web. But the original Internet surfing technology can still put a nasty bite on users of Microsoft's Internet Explorer browser, a security researcher warned today.&lt;br /&gt;&lt;br /&gt;A Gopher client nestled in the darkest corners of IE's code contains an exploitable buffer overflow bug that could allow a malicious server to run arbitrary code on a victim's computer, according to an advisory issued today by Jouko Pynnonen of Finland's Online Solutions.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The Web's Latest Threat: Smarter 'Zombies'&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;As if zombie PCs -- computers taken over by hackers and used to distribute spam and malware -- weren't already bad enough, they are now harder to prevent than ever before.&lt;br /&gt;&lt;br /&gt;That's because they're getting smarter and harder to track down, according to security software vendor Commtouch. New zombies now routinely request new IP addresses from their ISPs, so anti-spam software that works by blocking spam based the originating IP addresses can no longer effectively halt them, the company said in its most recent quarterly Internet Threats Trend Report.&lt;br /&gt;&lt;br /&gt;While some ISPs deny their request to change IP address, others accede, giving them new IP addresses in real time, Amir Lev, chief technology officer at Commtouch (NASDAQ: CTCH), told InternetNews.com. The result is that zombies can change addresses much faster than most security services and software can respond, which means their users are not protected, Lev said.&lt;br /&gt;&lt;br /&gt;Commtouch's findings signal the latest setbacks in the war on spam and botnets -- networks of zombie PCs. Spam and botnet activity fell sharply late last year after major spam host McColo was shut down in November.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;click=1&amp;rsrc=3" target="_blank"&gt;&lt;img src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=228683&amp;bid=559670&amp;PHS=228683559670&amp;rssimage=1&amp;rsrc=3" border="0"/&gt;&lt;/a&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5074766823662728299-4798272190131259447?l=networksecurity2008.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://networksecurity2008.blogspot.com/feeds/4798272190131259447/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5074766823662728299&amp;postID=4798272190131259447' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/4798272190131259447'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5074766823662728299/posts/default/4798272190131259447'/><link rel='alternate' type='text/html' href='http://networksecurity2008.blogspot.com/2009/01/latest-news.html' title='IE SECURITY THREAT'/><author><name>SHEIK FIRAZ</name><uri>http://www.blogger.com/profile/14448254799592431757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://2.bp.blogspot.com/_Q92aoloWYdM/TIcsklwuy8I/AAAAAAAAAPg/IKPnqEOIP6U/S220/shahid_kapoor1.jpg'/></author><thr:total>0</thr:total></entry></feed>
