Ramblings, meanderings, rants and discoveries.

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, May 30, 2011

Viruses and Facebook

I would like to say I am part of the cause for the new Facebook awareness of Viral banners, links and apps on their site.  But I am not that full of myself to think that my one voice actually got through in spite of my complaining for a year.  Last month I basically left Facebook. I got the third infection in less than 12 months.  It is time for me to move on and leave that site to the lowlifes on the internet.

The first was a stupid registry reviver one, easily spotted and cleaned.   The second was a basic speed up your computer one - eight months later.  Same idea, They want you to run out to their site, and BUY the product that is going off except of course it is not finding the 30 viruses and spyware it lists as finding on your machine, though it may be installing them.

 I noticed it because my drive started cranking , then Flash tried to start.  I was reading an article. No reason for flash unless it is a banner which I had blocked, yep it was payload drop time. 

The screens look like they could be official.  Perhaps it is a mutation. all I know is suddenly my files seemed to disappear. I started to panic then relaxed, it was only MY user directory affected. Fine, Easy solution - SYSTEM RESTORE.  Several hours later I had it found, removed it and then cleaned, recleaned and reupdated the machine.

This one was the last straw. It had attacked the FAT. The File Allocation Table could not FIND the files to tell me they were there.  I muttered steamed until I realized Trend was scanning them.They were there. Just not able to be found.

Trend Micro's Housecall took it out.  I then followed with Malwarebytes which traced the rest of the components and removed them.  Where exactly these came from, I am not certain to this day but most evidence points to Facebook and one of those crappy banners.  But hell for all I know Bleeping Computer, GamerDNA or even Major Geeks could have been the source.  All are sites I frequent.  So I cleaned it up  kept a component or two that were non functioning without the rest to test virus checkers with and moved on.

Last month I got hit again.  This time a bit more seriously.  Yes it was another crapware banner delivering a javascript to my machine.  As far as I can tell I had this..Vista Total Security 2011 the link is to a site describing it.  This one is a Royal pain.  Thank goodness no one codes for Opera.  It starts by setting off the Official looking Your computer is infected.  It looks like a Windows defender screen. Except.. Vista is no longer really supported, and they would not charge for the fix.

If you try to open defender it is blocked, if you try to go to a website it is blocked. Here is how it works,  it downloads a little .js that sits in your roaming directory. Every time you try to open a browser page, it calls the .js to put up the page that says that the site you are trying to go to is infected.  Solution - turn off  javascript right?  Well not exactly.  I do not know if it was Firefox 4.0 or the virus but  I would turn off the .js and it would still run.  When I reopend the tools in Firefox it was checked to allow .js again and again and again.  Firefox has a 4.01, perhaps it a was a glitch in their browser or perhaps it was the virus finding a way past that.

So I did what any geek would do. I opened Opera, opened a new tab, got the error and then opened Dragonfly.  I saw what it was being called and from where. So I typed in https://trendmicro.com in Firefox  and guess what it worked.  I got housecall to run  (I do NOT keep the component in a default directory)  and got it to start cleaning off the virus, except - it did not get the java script.  So I tried Panda.  Got a message that Activescan does not work with my version of Firefox or of course with Opera. Mutter. I downloaded the 30 day trial.  I will give my evaluation of that soon.

However to be fair it found the java script and zapped it, Can anyone tell me why Microsoft keeps people from accessing and clearing the java cache?   Last week my daughter came to me, guess what - it was going off on HER machine, Facebook is about the only place in common we go anymore.  She cleaned it, we think she got it all she tried the trend 30 day free download except it seems it does not like Malwarebytes.  Too bad it works!   I updated Firefox to 4.01 and Opera to 10.11.  Activescan still does not work with those according to their site.


So I log into Facebook last week  to leave a client a message. I see they have the HTTPS in full swing - except it does not work on any applications which are the biggest offenders.  I see they have their protection on for links, except it blocked a legitimate site I was trying to go to on information about a virus spread through Facebook. And last I see the same ads on the right hand side.  And the machine goes nuts, Yep it is trying it again! NOT THIS TIME BUDDY!

Sure they check the ads - the first time, but what about each subsequent ad.  Are you sure they have not been compromised by a third party?  Why are they placed on the right on the games and groups where a mis-click can potentially end in an infected user's machine.  Why are there ads for products and techniques already known to be scams or at the very least suspicious in their claims? You know how many Acai berry diet plan ads i saw there when that was the big fad?  Hey HERE IS AN IDEA FACEBOOK - Only accept ads from REPUTABLE companies and Websites instead of lining your pockets and including in your TOS that if any user's machine is damaged by the site it is their problem nay even their fault for trusting you to perform due diligence.  So in the mean time - you all can find me on MySpace or Twitter or the gaming sites. That is unless they all decide to follow the Facebook Model and put profits over their users.

Then you will find me curled up with a good book and on the MUD.

Thursday, May 19, 2011

Sony, hackers and identity security

I have avoided writing about the whole Sony debaucle, perhaps I will one day, but if nothing else it should have taught companies and consumers that data needs to be secure. As a consumer I do not want my info out there. If I am using the internet there is no reason for anyone to need my phone number unless i buying something with a credit card. Yet Google is still asking for phone numbers on accounts as can be seen on Geekwoman's blogs here and a solution for it here.

Now please look at this one by me. That is what can happen if your cellphone number gets in 'the wild'. Yep, a cellphone number can be used like a credit card in a way. So let's just get it straight. We are responsible for our identity security. One way to keep things secure is to not share them on the internet where anyone can read them. Assurances that my information is secure is not enough, it will not be Google that has to pay my cellphone bill when some hacker breaks in, gets it and sets up a skim account in another stolen identity name. It will not be Google that has to cancel all checking, credit cards and other things because their name and information is being used to apply for credit limits that are skipped out on and it will not them whose reputation is trashed.  Do not try the "oh, we will never be hacked." routine either it has happened before and I have every reason to believe it will happen again sometime in the future.

So please, anyone and everyone who reads my blatherings. Start telling these companies they do not need that information.  Email their tech support and customer service telling them you do not feel secure giving it.  Even if they are secure and you are ask them how they protect against man in the middle attacks? Against hacking? is their database encrypted? What type of encryption? and most of all WHY do they need that information?  I am sorry guys I do not want to be tracked, marketed to or even categorized.

First it seems people who think they know what is going on are telling me now what i must do and be interested in.  I do not play WoW stop trying to market MMOs that are WoW-like to me. I do not have an Xbox - stop trying to sell me games for one.  It seems that you all think if I type a word I must be needing to buy something for it. Well here is a word for you PRIVACY. I want that and I want to keep it and for me the easiest way to ensure that it is preserved is to just not tell anyone anything I do not want them to know.

Saturday, July 24, 2010

RU Botted? Dunno RU Working?

A few weeks ago I logged into TrendMicro for my weekly Housecall run. I noticed a Beta Utility call RU Botted. The copy pointed out the possibility of your machine being used as a server of files or in DOS without your knowledge.  Ok, so it is feeding into the present paranoia of users on virri and worms, but it is also not a bad idea to check.  Many virus checkers do not check for bots so I decided to DL this and give it a try.

Download and setup - Quick and painless as was the installation. Great job! Am not enamored of it setting itself to run at startup, but I can change that. It would be nice to have a when "connected to the internet" option though, because I still turn the modem and router off and work offline.  But it is beta and free so I am not complaining.

Function 
This seems to be a daemon. It does not seem to interfere often or eat too much ram (488K according to system). It is very quietly idling in the background until it detects bot like activity. Then it logs it and pops up a screen informing the user that activity has been detected, do you want to go to TrendMicro's site, run Housecall and check it?  Now is when I had a few issues.  It took me to Housecall, asked me if I want to dl it etc.  Then the launcher failed when I trird to run it. So I turned OFF RU Botted, closed the browser. At this time  I noticed there was a separate window open for Netflix. I muttered about damn marketeers. closed that,  opened the browser (Firefox,  Trend like most companies refuse to admit Opera and Chrome even exist.) Downloaded the file, install and voila, it worked!

I picked up a book to read.   Housecall finished quickly and returned a  there is nothing message.  Odd.  I  checked the log. It had an  entry of a DNS inquiry to a malicious site. How..  informative. From where, what site and what called it? I shrugged it off, decided maybe it was a probe, but firewall did not go off.

I go on my merry way, except next day when I fire up machine it gives me the same message.  I think this was because there is still something in the log. I opened the log and sure enough two entries said  "Detected DNS query of malicious domain." No further information.  I would like to know what domain, what app made the call  perhaps even what port. I checked my firewall logs. No outgoing. and as a matter of fact nothing at the exact time logged. That sort of makes sense. If the firewall had caught it it would have stopped it and RU Botted MAY not have gotten a chance to spot it.

Then I got another. Same error, different site, then another from my own site. Then another. I look, sure enough Netflix is open again in most cases.

Overall 
At this point I have no clue if the app is working or not.  I will be installing a different bot watcher and putting it through its paces.  In the meantime, anyone know anything about this? If you are interested in trying it be my guest, but there is presently no way to tell if it is working, and honestly - until they get the bugs out I would not recommend it at all.

Friday, February 22, 2008

The Vista Rebellion

"Service Pack 1 for Windows Vista is an important update for Windows Vista. Windows Vista Service Pack 1 (SP1) contains many security, reliability, and feature updates for Windows Vista. A program may experience a loss of functionality after you install Windows Vista SP1. However, most programs will continue to work as expected after you ..."

read more | digg story


It seems that Microsoft hasn't "gotten" it yet. There is a rebellion taking place and they are missing it. You see many users and developers hate Vista. Ok, maybe it is not so much Vista as the way in which Microsoft Corp seems to be railroading us into using it. Except they seem to have backed off that a bit.

I use a lot of utilities, freeware and shareware. I believe in supporting those who make a good tool or a neat gizmo. Vista has been out for over a year. Yet, a lot of both commercial and shareware apps do not support it. Why? Because we have finally had enough of being told what we MUST do.

I hit my first instance of that way back when helped develop proprietary software. We had hired a consulting firm to help us with a 'quick start' on an app we had to port over to Windows 95, The were a Microsoft Solutions provider so guess what they suggested we use? Yep a Microsoft product. It was a database app so they suggested Access. Except... When we attempted to recreate a lot of the queries we had built in Paradox for DOS we got a "query is too complex" Message.

Fine for use we knew how to work around it but for users who needed to create different reports, we needed an easy solution. We mentioned this to the Consultants who said, "They will have to deal with it." My answer was "no, they do not they can buy another company's product and services." For years, it seemed the companies, end users and even developers did not believe this. Finally the last straw seems to have been reached. The high-handed way in which Microsoft decided everything must be Vista started the rebellion. People refused to buy it. Developers refuse to develop for it. Microsoft seems to have relented a little.

Now the service pack. Guess what every one of those companies listed have put forth the effort to build a product that works on Vista or did in some way prior to the service pack. They spent money on developers' salaries, testing, hardware and software. Now they will not work. Zone Labs already has their fix out as does Trend Micro, but at what cost? And what happens when SP2 is realeased?

The companies who are listed above at least put forth the effort to create a package that works with Vista. Now Microsoft in their usual high-handed manner lists them as not working on the fixed O/S and says contact them for more information. It doesn't care if your preferred firewall doesn't work, if your emergency virus removal doesn't work. Why? Because they are Microsoft. Never mind that the consumer of THEIR product probably put out money for the packages.

Like it or not, there is a recession on. That means people do not have that extra money to spend. That means the next O/S upgrade that costs consumers up front and has hidden costs such as this will refuse to buy. Get the message Microsoft - We do not HAVE to there is always *nix and OS 10.

Saturday, June 30, 2007

Progress!

Vista is succumbing to my wiles! Yep I broke down and bought a 3.6 USB drive. Plugged her in, pulled the drivers onto a floppy and installed on the 98. Off she goes. So I start pulling data over.

Now for next thing I hate. The account I am using on Vista is a Admin equivelent account. I start by copying my files over. I run some tests, all looks good. Well, some minor annoyances, but hopefully I will figure them out. I suspect it is ME not Vista on those. POSSIBLY the application, but since app. was not meant for Vista or even for XP really, it's my problem to make it work.

I copy my daughter's school stuff over and go to drop it into her directory. I get the must confirm admin screen. That is annoying. Then i decide to break her stuff down by years, freshman, sophmore, etc. So I go to create the directories under her documents, it defaults to mine. I mutter a lot and force it to comply with my wishes. I move the files, I check one. Guess what? I can look at it but I cannot alter it. Now guess who shows as author? Yep, me - mainly because I type faster than she does and like most students she tends to wait until the night before an assignment is due to write it. So I go to change rights on the file and think hmm I wonder, Sure enough I do not have any but view rights to anything, so I check the directory, same. Odd I made the stupid thing, but no matter.


I reassign rights (just add myself as an all instead of as a view only) and tell it to apply to all child objects. It laughs and tells me it cannot because directory is in use. Well yeah kinda, is up in another window, but the OBJECTS are not in use. FINE. I pick a lower dir and reassign my rights. I click apply and yes and click through all the required if you started this message. EVERY SINGLE subdirectory and object within them returns a failure to reassign message. So I go in and look. They show they reassigned. I try to edit one. It laughs at me. So I sit there and reassign each object manually, clicking through. That works.

Uh Microsoft, let's talk about 2 things both apply to security. First I am signed in as and Admin equivelent. You know, that little click through of if you initiated this action is KINDA useless in many instances. Let's face it if I was dumb enough to leave the machine logged into a supervisor account, and some dishonest person came along and started doing stuff under my login you THINK they are going to be deterred by that? It is annoying.

Second. It's nice tht you are keeping me safe from documents that show to be authored by myself. Now I appreciate that perhaps WORD and the OS do not really communicate. I mean why not bring your business model into your software packages? (One day maybe I will bore y'all with old stories about beta testing MS stuff) BUT, i made the freaking directory, assigned rights and copied the files over. I STILL have to manually alter that with multiple click throughs for each document copied? There are times I miss Novell.