It’s Offical, Bush is a failure!

August 28, 2006 on 11:01 am | In Misc | 1 Comment

Google Search: Failure

Just when I my love for Google started to fade off…

Searching google for the word, Failure. I was expecting to see my first relationship at number one with my attempt to fly off my parents deck at a close second. Little did I know, I wasn’t even close, out of 529,000,000 possibilities, you’ll notice President Bush is number one on the list! I have to admit, this is hands down the most honest result I have received from a search.

The only question is, Did bush pay Google AdWords too put him at the top of this search? It wouldn’t surprise me!

Firefox 1.5.0.3 - DoS / PoC / Simple Fix

May 18, 2006 on 11:28 am | In Downloads, Windows, Security News | 2 Comments

Firefox Process

Introduction:
Another successful day for the script kiddies. The firefox community has been blessed with another exploit released for the latest version of firefox (1.5.0.3). Once again this is more of an annoyance than anything. If you enjoy your browser crashing random as you surf unsafely through the internet, I recommend you do nothing differnet and don’t waste your time researching anything that has to do with security. Seriosuly, there are simple solutions to these types of “exploits.” Please read on for ‘Proof of Concept’ (meaning you can test and see if your browser will crash) and recommended solution.

Exploit:
Firefox 1.5.0.3 Denial of Service - Test me! (Note: Link will crash browser)

Recommended Solution:

No Script Logo

NoScript [info] [download] (exstension for Firefox)

IE 6.0 SP2 - DoS Exploit (Released 05/10/06)

May 10, 2006 on 9:27 am | In Downloads, Windows, Security News | 3 Comments

I was wondering how long we’d make it before being blessed with another delicious exploit for Internet Explorer. Atleast it was the day after Microsoft released the round of ‘May-Day’ patches. No need to panic this is more of an annoyance then a real problem….or is it?

Error & Debug:
Debug

Affected:
IE 6.0 SP1/SP2

Not Affected:
IE 7 beta 1/beta 2
Mozilla (all)

Exploit:
Enjoy (IE 6.0 only)

If this exploit affects you, it’s time to start thinking about the big move. Let go of Microsofts hand and learn to walk on your own. On a serious note, I use IE 7 SP2 for trusted sites only (Banking, etc…) and everything else I use Mozilla w/ Noscript.

Recommended Solution:
Mozilla Firefox 1.5.0.3 Final [ download ] w/ NoScript [ info] [download]

Icesword 1.16 English & Darkspy 1.0.4 (1.0.2 English)

May 8, 2006 on 8:04 pm | In Downloads, Windows, Security Programs | 1 Comment

IceSword 1.2

Anti-Rootkit programs are becoming a necessity in keeping your computer secure. I know Anti-Virus vendors are trying to implement rootkit detection. Personally I never believed in an “all-in-one” product for security. To be successful in preventing rootkits, you have to stay current with the latest leaders of this task. As of now, the leaders seem to be IceSword & Darkspy. Both of which just released new versions this month. My advice to anyone trying to get a handle on rootkits, would be to test them all. See which ones you feel comfortable with and which ones give you the best results.

IceSword 1.16 EN
http://www.xfocus.net/tools/200604/IceSword116en.rar

DarkSpy 1.0.2 EN (Test Evaluation)
http://lu0s1.3322.org/Utilitys/DarkSpy_En.rar

DarkSpy 1.0.4 CN
http://www7.spread-it.com/dl.php?id=5a7a4d6079e30f17270815bd2caac23231b08ae9

Note:
DarkSpy Author CardMagic says,
“sorry,i havent made a English version of DarkSpy 1.0.4.because this is a temporary version and will be updated soon.The new Engish version of DarkSpy will be pubished when some new functionalities are added.”

So We’ll be keeping an eye out for the latest version of DarkSpy as it’s released to the public. Just because these are the only two rootkit solutions I mention in this article, please don’t assume these are the only two out.

Other Anti-Rootkit Solutions:
Rootkit Revealer by Sysinternals
Blacklight by F-Secure

Gas War - We’ve lost the battle, lets win the war!

May 3, 2006 on 6:15 pm | In Misc, Personal | 2 Comments

Gas Chart

Intro:
Looks like we’re off to a killer “May Day” month. I don’t know about everyone else but I’m tired of sitting around watching the gas prices shoot up through the sky. A 100.00 gas refund from the government isn’t going to last nearly as long as these prices do. It’s time we as the consumers work together to do our part, otherwise you have no right to complain.I don’t know if it’s true, but I was told that Russia and China are working together with Iran to take away our oil shipments and reroute the oil to China and Russia. This leaving our country in an economic disaster. I’m sure we have plenty of oil in reserve as well as coming from IRAQ to where we shouldn’t be affected for sometime now.

The Plan:
Phillip Hollsworth offered this good idea.

This makes MUCH MORE SENSE than the “don’t buy gas on a certain day” campaign that was going around last April or May. The oil companies just laughed at that because they knew we wouldn’t continue to “hurt” ourselves by refusing to buy gas. It was more of an inconvenience to us than it was a problem for them.
Please read on and join with us! By now you’re probably thinking gasoline priced at about $1.50 is super cheap. Me too! It is currently $3.35 for regular unleaded in California. Now that the oil companies and the OPEC nations have conditioned us to think that the cost of a gallon of gas is CHEAP at $1.50 - $1.75, we need to take aggressive action to teach them that BUYERS control the marketplace….. not sellers.

With the price of gasoline going up more each day, we consumers need to take action. The only way we are going to see the price of gas come down is if we hit someone in the pocketbook by not purchasing their gas! And, we can do that WITHOUT hurting ourselves.

How? Since we all rely on our cars, we can’t just stop buying gas. But we CAN have an impact on gas prices if we all act together to force a price war.

Here’s the idea:
For the rest of this year, DON’T purchase ANY gasoline from the two biggest companies (which now are one), EXXON / MOBIL. If they are not selling any gas, they will be inclined to reduce their prices. If they reduce their prices, the other companies will have to follow suit.

But to have an impact, we need to reach literally millions of Exxon and Mobil gas buyers. It’s really simple to do! Now, don’t wimp out at this point…. keep reading and I’ll explain how simple it is to reach millions of people.

Acting together we can make a difference. If this makes sense to you, please pass this message on. I suggest that we not buy from EXXON/MOBIL UNTIL THEY LOWER THEIR PRICES AND KEEP THEM DOWN. If we show we have control, this will show we can’t be pushed around.

Your Part:
Spread the idea, promote the idea. Don’t sit around and wait for our government to take control of this issue. Please leave feedback and feel free to comment!!

Reference:
I orginally recieved this in an email from a friend. Instantly I thought this was a great idea and decided to turn that email into a blog. I remember paying .73 a gallon when I was 17, the sad thing is I’m only 24. Look at what happened over 7 years…

My Part:
I decided that blogging about this and not buying gas from Exxon/Mobil wasn’t enough. Currently my Google Adsense account (money I make off the ads on my site) is at 92.38. I’m going to donate that as well as 100.00 of my own money in promoting this idea on Google Adwords. I’m tracking all the stats via Google Analytics and will keep the blog updated with stats of how many visitors and what locations are helping. At the end of the month if this isn’t successfully generating hits I’ll stop promoting it on Google. However, until the Gas prices have dropped I’ll keep this post up.

Thank you for taking the time in reading about this!!

Secure Instant Messaging, File Transfers, and Chat Sessions

February 22, 2006 on 8:16 pm | In Windows, Security Programs | No Comments

Secure Instant Messaging, File Transfers, and Chat Sessions…

Something thats sounds so nice, who would have thought safe messaging… Having said the words ’safe messaging’ is going to give a lot of readers the sense of false security. Please note, setting up a secure certificate isn’t going to protect you from IM worms or even exploits. This is to encrypt the traffic between you and your destination assuming both parties are using a secure certificate. Personally, I use this as a layer of my security in protecting myself against phishing attempts, or if somebody was trying to impersonate someone on my buddylist. This is extremly important to businesses and people that share private information over the internet.

Let me describe one perfect example of how having an secure certificate would have prevented a security threat; A few years ago, my brother recieved a message from one of his friends (we’ll name the friend Newbert), “Hey Tyler check out this program, WinAmp2005.zip” claiming to be a limited edition version. Tyler assuming it was from Newbert, downloaded the file without hesitation, extracted the zip file and ran the install. To his surprised he was prompted with an error and no installation began. What he didn’t know is the person he thought was his friend Newbert was actually some cyber script kiddie that just infected innocent Tyler with a trojan or password stealer. A few minutes later his screen name was signed off, and someone has changed his password. When he tried to request his password to his email address, his email password was already changed too. See if Tyler and Newbert would have had a secure certificate, tyler would have been able to verify that Newbert really was Newbert. Even if cyber script kiddie stole Newberts AIM password, locally on Newberts computer, he has to input another password to access AIM using the SSL cerificate. I’m not stating that a secure certificate will protect you against virus and worms. However, it adds a nice layer to your security.

It’s very easy to tell the difference between a secure user and the average user. If a user on your buddylist is using a secure certifcate you’ll notice a grey lock next to their screen name. if they are not you’ll notice nothing.

Aim Secure

So, now that you understand the importance of secure communications, I’ll leave you with a few choices. You can get a certificate for FREE from a few sources, however I would have to accept your certificate before communicating with you (I personally wouldn’t accept). Or you can make your own certificate. Last you can pay verisign.com to issue you one. This is the route I went, for I trust verisign more than some random source as well as myself. So for the 15.00 a year, it was worth it to me. However, they offer a free 60 day trial, so atleast check it out!

Free:
- Whitsoft Dev : http://www.whitsoftdev.com/aimcert/ - Very Simple to setup.

Pay:
- Verisign : https://digitalid.verisign.com/client/enroll.htm ( 19.95 1 yr. / 60 day free trial)

Once you’ve requested your certificate in either .p12 or .pfx format we can move forward with adding importing the SSL certificate into AIM.

Note: AIM Trinton doesn’t offer support for the SSL certificate. On a personal level you don’t want AIM Trinton.

Installation:
1) Copy the .p12/.pfx file to your desktop.
2) From your buddy list, go to ‘My AIM’ > ‘Edit Options’ > ‘Edit Preferences’
3) On the left side, select ‘Security’
4) Click the Advanced button.
5) Click the Import button under “Import a certificate.”
6) Browse to where you saved your SSL certificate and select the .p12/.pfx file listed and click Open.
7) When it asks for a “security” password, enter one. (This is the password you’ll be asked for everytime you sign on AIM for the first time)
8) When it asks for the password of the certificate, enter the same as above.
9) Make sure the box is checked next to “This certificate can identify mail users.” and press OK.
10) Click OK on all dialogs that come up, until you see one that says Certificate successfully imported, click OK on that one too.
11) Exit and re-start AIM.
12) Enjoy your SSL certificate and piece of mind while chatting with your online friends.

Ending Notes: Please let us know if you have trouble with creating or setting up your secure communication. Other than that, any feed back or different methods you might use for secure communications is welcome!

TextPayMe - The paypal for 2006?

February 22, 2006 on 8:15 pm | In Misc, Uncategorized | No Comments


SignUp at TextPayMe

Well, what can I say about this handy little service. When I first read it, I thought this is pointless. Then I sat and thought about it for a few days. Yeah! This is useful, How many times have I been busy working or on the road and my girlfriend says, “Jordan, can you please transfer me 100.00 for my hair and nails?” True, normally I would laugh it off and advise to get a part time job, however on a special day I might feel so inclined.

Good news? Of course, the good news is they’re going to give you a free 5.00 for signing up. Not that 5.00 makes me start to river dance, but the fact that I can sign up for free and transfer money for free all from my cell phone. So if nothing more give it a try, if you think it’s pointless give it a try for FREE and prove yourself right!

I enjoy it. If this is something you enjoy click on the banner below and let the txt being!


SignUp at TextPayMe

0-Day : IE 6.0 SP2 (mshtml.dll) DoS exploit (PoC)

December 29, 2005 on 11:35 am | In Windows, Security Programs, Security News | 1 Comment

Another exicting day for Internet Explorer surfer!

This morning we’re going to list a DoS exploit released in the wild early this morning. This exploit isn’t as serious as the one we went over yesterday regarding WMF. I concider this DoS exploit more of an annoyance than a threat. Not to mention this only effects IE users, however it affects all of you at this point. First we’re going to list the code for this exploit, discovered by rgod and then we’ll go over recommended solutions and followup with the PoC.

Code:

< .head.>
< .style.>< .!--
#page div p:first-child:first-letter {
border-bottom: 2px ridge #F5DEB3;
}
//-->
< ./style.>
< ./head.>
< .body.>< .div id="page">

< .strong.>suntzu< ./strong.>< ./p.>< ./div.>< ./p.>< ./div.>

As you can see this is a very simple attack and very easy to create. The good news is, I don’t see many people using this exploit for any benefits at most and annoyance, but who knows this could escalate into something bigger. However, since the WMF exploit is public now, I think the malicious users will be focusing on that bad boy.

Recommended Solution:
Mozilla Firefox 1.5 Final [ download ] w/ NoScript [ info] [download]

I know this isn’t a solution for die hard Internet Explorer users. However regardless the reason, we recommend using multiple browsers for different browsing habits. If your extra patanoid you can even go as far as running VMWARE Workstation 5.5.

Proof Of Concept:
Crash Internet Explorer 6.0

Note: clicking this link using Internet Explorer is pointless unless you actually want to crash you browser. We are unaware of any way around this using Internet Explorer as of now. If you know otherwise, please advise…

0-Day Exploit : MS/IE - WMF Remote Code - Fix!

December 28, 2005 on 1:53 pm | In Downloads, Windows, Security Programs, Security News | 1 Comment

A little spice to the end of 2005… Christmas was nice spending it with family, securing their computers, the usual for holidays with the family. Only if it was that easy this year, as of this morning a new exciting exploit was released. The good news is my current configuration wasn’t affected by this annoyance. So, we’re going to list the advisory released by FrSIRT and let you review that, then we’ll move forward to steps to take for protecting yourself. Also, look at the end for references.

Rated as : Critical
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-12-28

Technical Description

A vulnerability has been identified in Microsoft Windows, which could be exploited by remote attackers to execute arbitrary commands. This flaw is due to an error in the rendering of Windows Metafile (WMF) image formats, which could be exploited by attackers to remotely take complete control of an affected system by convincing a user to open a malicious WMF file using a vulnerable application (e.g. Windows Picture and Fax Viewer), or visit a specially crafted Web page that is designed to automatically exploit this vulnerability through Internet Explorer.

Note : This unpatched vulnerability is currently being exploited in the wild.

Exploits

http://www.frsirt.com/exploits/20051228.ie_xp_pfv_metafile.pm.php

Affected Products

Microsoft Windows XP Service Pack 1
Microsoft Windows XP Service Pack 2
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003
Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 for Itanium-based Systems
Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
Microsoft Windows Server 2003 x64 Edition

Solution

The FrSIRT is not aware of any official supplied patch for this issue.

References

http://www.frsirt.com/english/advisories/2005/3086
http://www.frsirt.com/exploits/20051228.ie_xp_pfv_metafile.pm.php

Credits

Vulnerability reported in the wild by noemailpls

ChangeLog

2005-12-28 : Original Advisory

Tech-Security Explains:
As shown by FrSIRT, there is no real solution for this until we receive a patch to fully resolve the issue. However, there are steps you can take in protection yourself. I’m running Firefox 1.5 Final w/ NoScript extension and configured browser settings (mentioned in an early thread) and when I went to one of the infected site, I wasn’t hit by the exploit.

Want to start thinking about secure browsing?? Good it’s about time…

Update your anti-virus software 1-3 times a day, this way if you do get infected by this exploit, you’ll have protection shortly afterwards. not good enough? I agree…

Tech-Security Recommended Fix:
For safe browser…I would recommend installed VMWARE and install a fresh copy of Windows. This enables you to browser within the VMWARE isntance of Windows, allowing nothing to enter into your production OS version. This is a great idea for browsing and testing exploits/infected programs. Just be sure you keep your VMWARE Workstation updated too.

Protect yourself:
VMWARE Workstation 5.5
[ more info ] . [ download ]

Easiest Fix:
Windows Media File Viewer | [disable] . [enable]

This is more of a temp solution, which is why we recommend VMWARE, it might seem like a hassle at first, but no more than if you get infected with a serious virus. Atlease VMWARE is a one-time deal.

IceSword…The Best Rootkit Defender?

December 13, 2005 on 4:04 am | In Downloads, Windows, Security Programs, Security News | 17 Comments

IceSword 1.2

Look out people! Over the past few months people have heard more and more about rootikits. I’ve been dealing with rootkits for some time now and after having numerous friends infected by Sony’s rootkit, I decided it’s time to help educate the prey. Now, hopefully you’re not sitting there saying, “Prey?? I use Norton Internet Security and if your suggestion that a rootkit can bypass that, I have news for you!” My response would be a standard “laugh out loud” followed by blocking your IP from my website. No, seriously regardless of your current protection, it’s not enough. Rootkits change on a regular basis to bypass AntiVirus software along with the popular antirootkit software.

I recommend using 3 useful rootkit utilties in your hunt for the invisable rootkit. I do not recommend only using one of the three, or even two of the three. I say three, for the fact that incase the nifty rootkit infecting your system was updated to bypass one or two of my recommendation, you would have a 3rd opinion. Now that I’ve explained myself and hopefully conveinced you to install, update, and run these utilties on a weekly basis we’ll move forward with testing.

Note: Click links below to download software.

Our Test Enviornment:
- Windows XP SP2 (fully updated)
- Sygate Personal Firewall Professional (.dll injection detection)
- Kaspersky AntiVirus Professional (script detection)
- All-Seeing Eye (Best system monioring tool around)
- Spyware and other tools not listed.

Programs under the spotlight:
- Rootkit Revealer [info] | [download]
- BlackLight [info] | [download]
- IceSword English [info] | [download]

Rootkit under oath:
Lil Rob’s album “Twelve Eighteen” released by Upstairs Records.

Results:
All 3 softare programs detect the rootkit, however none of them removed it. Blacklight allows you to rename the files, but the junk is still there. Rootkit Revealer lets you know where all the files are so you can manually remove the files in DOS and the registry entries using PSEXEC. Finally my personal favorite IceSword, this program displays a lot more information than the other two, however it’s for more advance users. On this note, exactly why I recommend using ALL three for detection and IceSword for advance removal.

I’m interested to hear what others think about IceSword and your techniques for battling rootkits!

Next Page »

Powered by WordPress with Pool theme design by Borja Fernandez.
Entries and comments feeds. Valid XHTML and CSS. ^Top^