Archive for June, 2007

Noooh Virus AKA W32.Alnuh – Removal Tool

Noooh Virus AKA W32.Alnuh – Removal Tool

I was watching my site logs and I noticed that there’s a huge number of people infected with Noooh Virus and searching for a cure. So, I programmed this removal so you can remove the virus in a single click.

Noooh Removal Screen shot

You can download the removal kit from here:

Download

Please note that this is a .NET application it requires Microsoft .NET framework 2 which you can download from Microsoft site if you don’t have it. Or just click here to go to the download site.

Rate this:
2.5
Share this article: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • StumbleUpon
  • Digg
  • del.icio.us
  • Technorati
  • Netvouz
  • Reddit
  • feedmelinks

If you enjoyed this post, make sure you subscribe to my RSS feed!

All what you need to know about passwords

All what you need to know about passwords

Introduction:

With the internet revolution and the millions of services on the Internet, you must be at least having ten accounts. Some other people may have hunderds of passwords. People usuall y chooses simple personal passwords like their children names, birthdates, telephone numbers or pet names. These passwords are really easy to guess especially from close friends. I’ve done it a lot of times and it’s really more popular than I even thought. I will ask in this article simple questions and answer them:

 

What’s a strong password?

A strong password is a combination of capital letters, small letters, numbers and special characters. Also, it must be more than 9 characters. This way will make difficult to password crackers like L0phtcrack, Cain and John the ripper.

Why do we need a strong password?

Usually we hide some private information in our accounts like financial information, bills , contact,..,etc. These information has be secure to protect them abusing.

Examples of stronger passwords include:

  • t3wahSetyeT4 — not a dictionary word, has both alpha and numeric characters
  • 4pRte!ai@3 — not a dictionary word, has both cases of alpha, plus numeric, and punctuation characters
  • MoOoOfIn245679 — long, with both alpha cases and numeric characters
  • Convert_100£ to Euros! — phrases can be long, memorable and contain an extended symbol to increase

 

Examples of weak passwords include:

  • admin — too easily guessed
  • 1234 — too easily guessed
  • susan — common personal name
  • password — trivially guessed, used very often
  • p@$$\/\/0rd — simple letter substitutions are pre-programmed into cracking tools
  • rover — common name for a pet, also a dictionary word
  • 12/3/75 — date, possibly of personal importance
  • December12 — Using the date of a forced password change is very common
  • nbusr123 — probably a user name, and if so, very easily guessed
  • asdf — a sequence of adjacent letters on many keyboards
  • aaaa — repeated letters, can be guessed

 

How to choose simple passwords that are really hard to guess or to crack?

A very simple way to choose create passwords is by using cypher easy sentences or phrases. Let’s say that I want to create a password for my hotmail. Simply, I will choose this sentence “Ghiath’s hotmail” and my password is going to be “Gh14th’5h07m41l”. You can also choose small words that’s related to your life fot i.e. if you are driving a Mercedes E320 your password could be M3rc3d3s3320.

What are the types of password cracking?

There are many types of attacks for passwords:

Dictionary Attack: is a technique for defeating a cipher or authentication mechanism by trying to determine its decryption key or passphrase by searching a large number of possibilities. In contrast with a brute force attack, where all possibilities are searched through exhaustively, a dictionary attack only tries possibilities which are most likely to succeed, typically derived from a list of words in a dictionary. Generally, dictionary attacks succeed because many people have a tendency to choose passwords which are short (7 characters or less), single words in a dictionary, or are simple variations that are easy to predict, such as appending a single digit to a word.

Hybrid Attack: A Hybrid Attack builds on the dictionary attack method by adding numerals and symbols to dictionary words.
Brute Force Attack: s a method of defeating a cryptographic scheme by trying a large number of possibilities; for example, exhaustively working through all possible keys in order to decrypt a message. In most schemes, the theoretical possibility of a brute force attack is recognized, but it is set up in such a way that it would be computationally infeasible to carry out. Accordingly, one definition of “breaking” a cryptographic scheme is to find a method faster than a brute force attack.

References:

http://www.wikipedia.org

http://www.javvin.com/networksecurity/HybridAttack.html

Rate this:
2.5
Share this article: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • StumbleUpon
  • Digg
  • del.icio.us
  • Technorati
  • Netvouz
  • Reddit
  • feedmelinks

If you enjoyed this post, make sure you subscribe to my RSS feed!

W32/Sober

W32/Sober
Name W32/Sober-AD
Type
How it spreads
  • Email attachments
Affected operating systems
  • Windows
Side effects
  • Sends itself to email addresses found on the infected computer
  • Uses its own emailing engine
  • Installs itself in the Registry
Aliases
  • Email-Worm.Win32.Sober.aa
  • WORM_SOBER.AX

W32/Sober-AD is a mass-mailing worm for the Windows platform.

When W32/Sober-AD is installed it copies itself to:

<Windows>\PoolData\csrss.exe
<Windows>\PoolData\services.exe
<Windows>\PoolData\smss.exe

and creates the following files:

<Windows>\PoolData\WinD.osa
<Windows>\PoolData\runnor.ssy
<Windows>\PoolData\spxttx1.xnt

These files can be deleted.

The following registry entries are created to run W32/Sober-AD on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
_WinData
<Windows>\PoolData\services.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WinData
<Windows>\PoolData\services.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
_WinData
<Windows>\PoolData\services.exe %1

The emails sent by W32/Sober-AD may have the following characteristics:

Subject line chosen from:
Ihr Passwort wurde geaendert!
Ihr Passwort wurde erfolgreich geaendert.
Ihre neuen Account-Daten und Passwort befinden sich gesichert im Anhang!
PDaten Fehlerhafte Mailzustellung Diese Nachricht wurde Automatisch generiert.
Ihre EMail konnte nicht empfangen oder gesendet werden.
Ihr Account wurde eingerichtet!
Danke das Sie sich fuer uns entschieden haben.
Passw_Data Um ihren neuen Account zu aktivieren, folgen sie der kurzen Anleitung im Anhang.
Es sind nur 2 Schritte noetig!
Anleitung
Your eMail has occurred an unknown error on our Server.
Please read your mail and check the text.
The full email is attached!

W32/Sober Removal Tool Download

Rate this:
2.5
Share this article: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • StumbleUpon
  • Digg
  • del.icio.us
  • Technorati
  • Netvouz
  • Reddit
  • feedmelinks

If you enjoyed this post, make sure you subscribe to my RSS feed!

Top ten Viruses in 2007

Top ten Viruses in 2007

Top ten viruses reported  in May 2007

Top ten viruses reported  in April 2007

Top ten viruses reported  in March 2007

Top ten viruses reported  in February 2007

Top ten viruses reported  in January 2007

Rate this:
2.5
Share this article: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • StumbleUpon
  • Digg
  • del.icio.us
  • Technorati
  • Netvouz
  • Reddit
  • feedmelinks

If you enjoyed this post, make sure you subscribe to my RSS feed!

What to look for in Anti-Virus Software?

What to look for in Anti-Virus Software?
Top anti-virus software should be easy enough for a computer novice to both use and install. The software should effectively seek out and identify virus threats, as well as clean or isolate infected files. There should be understandable reporting available for each scan and plenty of help support available, so you can be well informed of the software’s activities and capabilities. Below are the criteria TopTenREVIEWS used to evaluate anti-virus software.
Ease of Use –Exceptional anti-virus software is simple to use, regardless of a person’s computer experience or knowledge of viruses.
Effective at Identifying Viruses and Worms – The best anti-virus products identify infected files quickly through real-time scanning, searching for viruses in a multitude of sources, including email, instant message applications, web browsing and so on.
Effective at Cleaning or Isolating Infected Files –Truly capable anti-virus software thoroughly cleans, deletes or quarantines infected files—keeping them from spreading throughout the hard drive or network.
Activity Reporting – Anti-virus programs should give immediate notification of viruses found by real-time scanners and should provide an easy-to-read report of scan results, including what it found and what it did with infected files.
Feature Set – A well-rounded feature set allows anti-virus software to provide absolute protection. The best programs are those that offer a wide variety of tools, from basic real-time scanning to more advanced, heuristic scanning and script blocking—when it comes to virus protection, the more options the better.
Ease of Installation and Setup – Anti-virus programs should be a breeze to install, making it easy to go from installation to initial scan in just a couple clicks of the mouse.
Help Documentation – High-end anti-virus software come with plenty of help, including support via email, online chat or over the telephone. There should also be online resources, such as knowledge bases and FAQs available for quick and convenient help.

So, no matter how serious a computer virus is or how quickly it is passed around, with today’s anti-virus software, you’ll always have a cure.

Top Ranked Antiviruses software for 2007  

Rate this:
2.5
Share this article: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • StumbleUpon
  • Digg
  • del.icio.us
  • Technorati
  • Netvouz
  • Reddit
  • feedmelinks

If you enjoyed this post, make sure you subscribe to my RSS feed!

New zero-day bugs crop up in IE, Firefox

New zero-day bugs crop up in IE, Firefox

Critical flaw in Internet Explorer and a major bug in Firefox

A noted security researcher disclosed four new zero-day vulnerabilities in Microsoft and Mozilla’s browsers, including a critical flaw in Internet Explorer (IE) and a major bug in Firefox.

Michael Zalewski, who regularly publishes browser flaw findings, posted details on the Full-disclosure mailing list for cookie-stealing, keystroke-snooping, malicious downloading and site-spoofing bugs.

The most serious of the four, said Zalewski, is an IE6 and IE7 flaw he rated “critical.” Dubbing it a “bait-and-switch” vulnerability, he said that the Microsoft browser gives hackers a window of opportunity to run malicious Javascript to hijack the PC.

“The entire security model of the browser collapses like a house of cards and renders you vulnerable to a plethora of nasty attacks,” Zalewski claimed in notes that accompanied a demonstration of the IE bug. Up-to-date IE6 and IE7 are both at risk, he said, although Firefox is not.

But Mozilla’s browser also suffered at Zalewski’s hands. A new IFrame vulnerability in Firefox 2.0 can let attackers plant keyloggers or drop malicious content into a legitimate web site. The flaw, rated as “major,” is related to a similar bug discovered last year; although Mozilla patched that problem, Zalewski said the fix hadn’t plugged all the holes.

Zalewski posted information about two other bugs, both rated “medium.” A Firefox vulnerability could lead to unauthorised downloads, while IE6 is open to yet another address bar-spoofing flaw. “IE7 is not affected because of certain high-level changes in the browser,” Zalewski said of the fourth vulnerability.

Mozilla is aware of both Firefox bugs — they have been posted to its Bugzilla management system — and a Microsoft spokeswoman said the company’s security team is looking into Zalewski’s claims. “Upon completion of this investigation, Microsoft will take the appropriate action, which may include issuing a security advisory or providing a security update,” she added.

Microsoft also said it knows of no ongoing attacks using the vulnerabilities.

http://reseller.co.nz/reseller.nsf/news/26C939EDD5BCE60BCC2572F000834E7F

Rate this:
2.5
Share this article: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • StumbleUpon
  • Digg
  • del.icio.us
  • Technorati
  • Netvouz
  • Reddit
  • feedmelinks

If you enjoyed this post, make sure you subscribe to my RSS feed!