UA-9726592-1
Showing posts with label anti-virus. Show all posts
Showing posts with label anti-virus. Show all posts

Monday, May 21, 2012

Hacker goes after Rightardia


We noticed something unusual in one of our blog logs. Apparently, the security software we use defeated the attacks, but didn't log the incidents.

We discovered that someone tired to install a fake user account named Victor. Apparently the hacker believed the attack was successful because he or she tried to remote into the blog 11 times before giving up.

This is what we saw in our log:

file:///C:/Users/Victor/Desktop/AAA%20DISABILITY/R%20i%20g%20h%20t%20a%20r%20d%20i%20a%20%20The%20Veterans%20Affairs%20C&P%20Exam%20II.htm

Wirehead also discovered the IP address of the hacker: 72.130.114.10 which a Road Runner account in Huntington Beach, CA. 

If a hacker could create a fake administrator user account on your PC, he or she could install a Trojan or other malware to steal passwords, bank account information or files.

We know of at least two web sites of progressive posters that have been hit by hackers. In one case, numerous files were permanently deleted.

We recommend our readers check their Windows user accounts that are usually at C:\users to see if  any accounts exist that the reader did not create.

Delete the phantom user accounts immediately and upgrade or update you anti-virus and malware software.

Also, make sure you PC has an operational software firewall: see http://www.techsupportalert.com/best-free-firewall.htm

Most anti-virus programs include such a firewall that is superior to the firewall that Microsoft provides with it operating system.

Update: We got a quick response form Road Runner which indicated it has difffrent email addresses for complaints:

If you sent your message to an address other than abuse/security/fraud@rr.com or
childporncomplaints@rr.com, please be aware that your message was automatically forwarded to our centralized location at the address abuse@rr.com. You may wish to use abuse@rr.com, security@rr.com, fraud@rr.com or childporncomplaints@rr.com for all future issues.

graphic: http://www.bankofmalware.com/

Subscribe to the Rightardia feed:http://feeds.feedburner.com/blogspot/UFPYA

Creative Commons License


Rightardia by Rightard Whitey of Rightardia is licensed under a Creative Commons Attribution 3.0 Unported License.

Permissions beyond the scope of this license may be available atrightardia@gmail.com.

Subscribe to the Rightardia feed: http://feeds.feedburner.com/blogspot/UFPYA

Rightardia by Rightard Whitey of Rightardia is licensed under a Creative Commons Attribution 3.0 Unported License.

Permissions beyond the scope of this license may be available at rightardia@gmail.com.

Monday, March 7, 2011

Linux Notes on Codecs and Anti-virus

by Wirehead

My kingdom for the right codecs
First, let's talk about codecs.  If you ever tried to play a movie DVD on a PC, you probably ran into a Codec problem. The video wouldn't play unless you had codecs for both MP3 music and MPEG DVD movies.

Well, in the Linux world, a European company called Fluendo makes a product that provides MP3 codecs for audio and MPEG codecs for video.These codecs will works on both Linux and windows systems.

The MP3 audio format is hard to avoid as it is the format supported by most portable music players. In fact, many people have already converted their audio CD collections into MP3. The Fluendo MP3 plug-in project is a combination of multiple things.
  • It is an MIT licensed source code package implementing the MP3 codec.
  • It is a fully licensed binary GStreamer plug-in available for download.
  • It is a redistribution contract allowing distributions to distribute the binary Fluendo GStreamer MP3 plug-in free of charge.
The Fluendo DVD Player is a software application specially designed to reproduce DVDs on Linux/Unix and Windows platforms, which provides end users with high quality standards.It provides the video MPEG-2 codec and has:
  • Full DVD Playback
  • DVD Menu support
  • Full screen support
  • Dolby Digital pass-through
  • Dolby Digital 5.1 output and stereo downmixing support
Once I installed the Fleuendo codecs on a laptop that uses Fedora Linux, I could use videos that my wife had taken with my Kodak Z710 camera. Also, Adobe Flash starting worked on Firefox.

Ubuntu provides these third party Fluendo codecs, but Fedora does not. However, we have been unable to get Ubuntu to work on the Rightardia laptop because of a laptop BIOS issue that only Fedora can handle.

We downloaded both the .deb format codecs for Ubuntu/Debian and the .rpm version that works on Fedora and Suse Linux.

The codecs cost $35 and you can order them online form Fluendo: see http://www.fluendo.com/ These codecs work great. Previously, the codec problem had been a major headache.


Yes, Virginia, Linux can now get virii  or viruses

Rightrdia had been detecting vuruses, malware and Trojans since we started using CLAMAV and its CLAMTK front end with Linux two years ago. Many virii were probably leftovers from Windows XP Pro that we had used.

CLAMAV is the actual anit-virus program, but CLAMTK is the graphical front end that makes CLAMAV command line program easy to use.


CLAMAV works perfectly in Ubuntu Linux, but not on Fedora. The AV signature file won't update from 30 Nov 2010. See the graphic above. Red Hat is aware of the problem.

So Wirehead started looking around for another AV program. He found Avast, formerly Alwil, developed in the Czech Republic.

Unfortunately, once you updated the Avast AV signatures, the program locked up and stopped working. According to Avast, this is a Linux kernel issue. Wirehead was able to change a value in a file by going into terminal mode, entering the SU (superuser) command and password, and then entering:

sysctl -w kernel.shmmax=128000000

Afterwards, we were able to upgrade the AV signature without Avast locking up. BTW, you will have to enter this code each time after you reboot.

Avast for Linux has a neat trick. If you have any network shares on your desktop, it will check them for virii. Rightardia uses network attached storage (NAS) so Avast gave us the means to check the folders on the NAS device for virii.



We like the Avast program on Linux and had used it in a Windows environment as well. It is faster than CLAMAV, but it can lock up when you scan Linux folders other than your home folder/desktop.

You do have to register the program for a one year license. it takes about 15 minutes to  couple of hours get the key from Avast.  A screen shot of the Avast AV program follows:


Subscribe to the Rightardia feed: http://feeds.feedburner.com/blogspot/UFPYA  

Netcraft rank: 6772 http://toolbar.netcraft.com/site_report?url=http://rightardia.blogspot.com
  Creative Commons License
Rightardia by Rightard Whitey of Rightardia is licensed under a Creative Commons Attribution 3.0 Unported License.

Permissions beyond the scope of this license may be available at rightardia@gmail.com.

Saturday, October 2, 2010

Time of India: Origen of Stuxnet worm/Tmphider rootkit

BEIJING: The much-feared new cyber-weapon, the 'Superbug', which has attacked over six million personal and almost 1,000 corporate computers in has been traced to the US, official media reported.

The Stuxnet cyberworm can break into computers and steal private information, especially from industrial firms, sending it back to a server in the , state-run quoted Wang Zhantao, an engineer at the Beijing-based , an anti virus service producer in China, as saying.

The super virus made use of a bug in Siemens auto-control systems used in industrial manufacturing to skip the security check, Wang who has been vastly quoted in the local media for the past few days, said.

The virus can copy itself and spread via USB drives in the network of a company and government. Any USB  drive plugged into an infected PC will pick up the Stuxnet malware. 

"Hackers may take control of a company's machinery run under computers infected by Stuxnet, and give dangerous orders causing serious damage," he said.
The company has developed softwares to kill the virus, which can be downloaded for free from the company's official website, he said.

Official media has been carrying reports about the superbug virus for the past few days said it contained sophisticated malicious software, or malware, believed to be a "new cyber-weapon," which infiltrates mainly factory computers in China threatening the country's national security.

The Stuxnet worm was first discovered in mid-June and was specially written to attack Siemens supervisory control and data (SCADA) systems commonly used to control and monitor industrial facilities - from traffic lights and oil rigs to power and nuclear plants, state run Global Times daily reported few days ago.

"This malware is specially designed to sabotage plants and damage industrial systems, instead of stealing personal data. It will seriously threaten pillar industries in China, which has 420 million internet users," Wang said.

"Once Stuxnet successfully penetrates factory computers in China, those industries may collapse, which would damage national security," he said adding that it posed no harm to personal computers or Internet surfers.

The Christian Science Monotor thinks the virus may be Israeli in origen, The New York Times reported Thursday that Stuxnet contains a file named "Myrtus," which may reveal the virus's origin in a Da Vinci Code-esque fashion. The "Robert Langdon" on the case is a German computer security expert named Ralph Langner.

Although myrtus has several possible meanings – including being Latin for the plant myrtle – Mr. Langner noted that it may be an allusion to the Hebrew word for Esther. He pointed out that the Book of Esther features a plot by Persia against the Jews, who preemptively attacked in response.

Another clue toward the maker could be in the number "19790509," which appears in Stuxnet's code. It could be a reference to the 1979 execution of a prominent Jewish Iranian businessman, according to a research paper presented by researchers Thursday at the Virus Bulletin conference, Computerworld reported.

A column in today's Jerusalem Post praises Stuxnet as "a great achievement" if it is indeed an Israeli weapon.The suspicion over Israel also occurred during the Virus Bulletin Conference in Vancouver Canada.

During the conference China has shown more interest over the virus attack. China has stated it has suffered several such attacks recently.

It has been reported that Israel has been financially funding Unit 8200 heavily. Unit 8200 is a military facility where there has been recent research and development efforts in fighting cyber wars.

If the USA produced the worm, the National Security Agency (NSA) would have done the dirty deed. Now that the code is out in the open, Rightaradia would expect some copycat malware to appear.

We are also surprised that a big engineering form like Siemens would use the windows operating system. Linux is far more resistant to malware. 

See See this link for a technical discussion of how this malware works

Subscribe to the Rightardia feed: feeds.feedburner.com/blogspot/IGiu

Netcraft rank: 8363

http://toolbar.netcraft.com/site_report?u rl=http://rightardia.blogspot.com

Monday, September 27, 2010

Newsy.com: State-sponsored Computer Virus Infects Iranian Nuclear Site


Multisource political news, world news, and entertainment news analysis by Newsy.com




A computer virus attacked Iran’s Bushehr Nuclear Power Plant. Though no harm was done, some experts say the Stuxnet worm could mean a new age of cyber warfare. 

Rightardia agrees with Newsy. it is unlikely the US would launch such a complex virus because it could attack the US industrial base as well.

There is a high probability that Israel launched the attack to damage the Siemen's centrifuges used to harvest nuclear material. Such an attack would slow down the Iranian nuclear program. 

Apparently the attack used four undisclosed Windows vulnerabilities. Rightardia has to wonder why Siemen's German engineers would use the Windows Operating System in their industrial controls. Windows is far less secure than Linux.


Subscribe to the Rightardia feed: feeds.feedburner.com/blogspot/IGiu

Netcraft rank: 8665
http://toolbar.netcraft.com/site_report?url=http://rightardia.blogspot.com

Thursday, April 1, 2010

ClamTk anti-virus tip for Linux

Rightardia recently upgraded tothe Ubuntu Linux 10.4 Beta. We turned on a feature called encypted desktop duing the installation. This stopped the virus scan cold.

Looking around in the ClamTK fornt end, we discovered a whitlist option. We also noticed theat the scan stopped in a home | .encrypts folder. This is a hidden folder.


To see the .encrypts folder, you must go into View and check a Show Hidden Files option. You can also enter <ctrl>-h from the keyboard to see this hidden folder.

Omce the folder is visible, you can whitelist the .ecrypts folder in ClamTK under the Advanced | Whitelist options


Once we whitelisted the .ecryptfs folder, the ClamTK  front end worked perfectly.

Subscribe to the Rightardia feed: feeds.feedburner.com/blogspot/IGiu

Netcraft rank: 7793 http://toolbar.netcraft.com/site_report?url=http://rightardia.blogspot.com

Tuesday, January 12, 2010

Rightardia certified virus and malware free



Rightardia crossposts to Usenet and a right wing nut has not been happy with some of our excellent journalsitic content.  We found this on Usenet today:

From:
Sueki Tartridge <hoofhearted07@yahoo.com>  (http://groups.google.com)
  Date:
Tuesday 12 January 2010 14:50:49
  Groups:
alt.politics
On Jan 12, 12:18 pm, Middle Class Warrior <rightar...@gmail.com>
wrote:
> It looks the Tea Partiers are emulating the Nazi Brown shirts by meeting in
> secret. Why is Rightardia not surprised?
>
> Seehttp://tinyurl.com/yakrzsu
> --
> Rightardia: Progressive news with an international flavor. Visit us at http:
> rightardia.blospot.com.

Avoid this clown's website like the plague !! It's infected with
trojans and adware. Visit at your own risk. I found out the hard way !!

Just to be sure, we ran another virus and malware scan which was negative.

The only malware we have ever found on the Rightardia site are PUA-packed files which can install Trojans. Since we use the Linux OS, Rightardia is immune to Trojans.  In addition, the Google blogspot server blocks the upload of virii and malware. Shame on Sueki Tartridge

Usenet is a wild and woolly place. it looks like the right wing is getting pretty desperate to lie about the integrity of a web site that doesn't reflect its point of view.

Subscribe to the Rightardia feed: feeds.feedburner.com/blogspot/IGiu

Netcraft rank: 4455 http://toolbar.netcraft.com/site_report?url=http://rightardia.blogspot.com

Friday, June 12, 2009

Microsofts new free AV product: Morro or Lesso?

Rightardia reported on this Microsoft development once before. We have learned that Microsoft plans to use novel approach to provide its free anti-virus service, codenamed Morro. Morro should be available in a public beta version shortly.

"Microsoft Corp is getting ready to unveil a long-anticipated free anti-virus service for personal computers reports Reuters. Unfortunately, it doesn't give a date. It just says it's "testing an early version of the product with its own employee." The trial version or product beta, will be available on its website".

We've been waiting for Morro, code-named after Morro de Sao Paolo beach in Brazil for some time.

Because of the political involvement of the European Commission. Symantec Corp and McAfee have already shown their willingness to go after Microsoft in Europe. The EU is more than willing to discipline misbehaving corporate giants like Microsoft.

It is not clear what impact Morro will have on the security market because it last Microsoft AV product, OneCare was a failure. The new AV product will be hosted on the Internet. Trend Micro HouseCall is another cloud based free service, but it is quite slow.

Morro will work by routing all of a users Internet traffic to a Microsoft data center, where the web-based Morro application will process the traffic and identify and block viruses and malware in real-time, by examining all of the rerouted traffic.

This raises serious questions about performance, off-line security problems and privacy for starters. An Internet based service will introduce latency on a PC during an AV scan. Since Google probably tracks your every move using its toolbar and advertising network, there is reason to route everything through Microsoft. Of course, Google did not cooperate with the Bush Administration when is started bugging the Internet using the fiber optic networks that InterExhange Carriers like AT&T and Verizon operated.

There is one reason why Microsoft will use the Internet. It can probably get away with a cloud-based service, whereas it would be sued in the EU and perhaps in the US if it bundled an AV product with Windows 7.

As one AV competitor, AVG boss JR Smith, said about Morro: "At this point, we're watching in Brussels to ensure they don't bundle it with Windows and trigger about a trillion lawsuits."

And, of course, in Brussels, Neelie Kroes, The European Commissioner for Competition, is solely concerned about competition. Symantec, McAfee, AVG and others will not be driven out of business as other Microsoft competitors were when Microsoft reversed engineered and bundled add-on features with new releases of the operating system.

There are already free versions of AV products that consumers can download such as free AVG, free Avira Antivir and Avast Home Edition. One product is even open source: ClamWin and will run on both servers and clients.

www.clamwin.com/

www.guardian.co.uk/technology/blog/2009/jun/11/microsoft-morro-antivirus

Thursday, June 11, 2009

Microsoft to unveil free anti-virus software

Microsoft announced that they're going to stop selling their consumer security product OneCare, and instead they're going to give away for free an anti-virus (AV) product based on the same technology.

With traditional anti-virus protection perhaps becoming obsolete, maybe it's time that Symantec and McAfee start offering free versions of their own anti-virus products.

A more complete solution is needed to provide complete client side protection. AV, malware and Trojan protection as well as a firewall that is superior to the basic firewall in Windows Vista is what a user really needs.

Windows 7 will have a more robust bi-directional firewall that keeps unwanted incoming traffic from invading your network and also prevent Trojans and zombies from setting up a small server on the your PC that transmits you password and credit card information to criminals.

AVG, Avast and Avira already provide free AV software, but they just provide basic protection.
You need the version you pay for to provide comprehensive protection. As an alternative, you download a free program called Spybot to provide spyware and malware protection and a free firewall called Comodo that is an improvement over the basic XP Pro and Vista unidirectional firewalls. Of course, you now have three different programs you have to mange and update.

Anti-virus vendors certainly were worried when Microsoft entered the AV market. They assumed they would follow the old business practice in which they would drive competition out. That is what they may be now doing with a free AV package that will bundled with Windows 7 or provided with a free download.
The big vendors knew Microsoft could trounce their small office/home office (SOHO) business, but they would not be in a good position to meet enterprise needs because Microsoft does not have a global server AV solution that can handle a large enterprise network and push agents and updates out to desktops automatically.
Symantec began moving into new markets to diversify and improve its enterprise business. While McAfee already had a strong enterprise offering, it protected its consumer market share by striking big OEM pre-install deals with major PC manufacturers like Dell in the hopes of retaining market share. McAfee had invented anti-virus software so it had been in this business for a long time.

 
Microsoft's entry into the AV market flopped. It's not for lack of trying on Microsoft's part. In January 2007, they were struggling to claim just one per cent of the market. There is no evidence that Microsoft has made any strides since then. Its AV business has been a resounding failure.
In short, Microsoft spent the money, and in relatively short order had a product that was just as good as any of their competitors but not really any better. They built a large team. They spent a lot on marketing. But the people never came.

What went wrong? First, the world has long held the perception that Microsoft is bad at security because they are constantly patching their operating systems (OS) and network operating systems (NOS).

When Microsoft was going through anti-trust hearings during the Clinton Administration era, the standard joke was the company would be split into two companies: Microsoft who would give the OS away for free and the second company, Patchsoft, would charge for the innumerable patches that Microsoft produced during the life cycle of an OS.
Microsoft may want to give away a free version is for community goodwill and to prove they are good at security. Rightardia is skeptical about the goodwill motive. In the past Microsoft would reverse engineer the intellectual property of competitors and bundle it with the OS for free to destroy competition. Netscape built on of the first commercial browsers and was selling it to enterprise customers until Microsoft fielded Internet Explorer (IE) and gave it away for free.
This destroyed Netscape, but it had its revenge when it created the open source product called Firefox, which most IT people consider to be a better, more versatile and secure browser than IE.
Even when Microsoft came in at low price points, people still thought that security was important enough that they should go with a more trusted name. For those people that were really concerned by price, they started moving to other cheap options, but ones offered by dedicated security companies like AVG, Avira and Avast. Many Savvy IT people buy AV products on Ebay.
Keep in mind that Microsoft has also lost 15 per cent of its desktop market share to Linux and Apple. There are a variety of free and low cost AV products for Linux. ClamAv is one that that can be used on desktops and servers. It can scan the file system as well as incoming and outgoing email and has many other features. Why buy the new Windows 7 when one can get OpenOffice, a broad selection of firewalls, AV products, an excellent Firefox browser and the Evolution email client for free in Linux?
In addition, after upgrading to Windows 7 in the SOHO environment, all of the XP Pro applications such as Microsoft Office, Adobe Acrobat, a CD/DVD burner such as Nero Burning ROM and other other software that I bought when I installed XP Pro on a PC would have to be upgraded.

If a PC had not been updated to Microsoft Vista, one would have to backup all of the user data and reformat the hard drive to install Windows 7. There is no upgrade path from XP Pro to Windows 7.

Try Ubuntu Linux 9.04 or Fedora 10 before you invest some big bucks in the Windows 7 OS and all the new applications you are going to have to upgrade. This article was written using the OpenOffice 3.0 Word Processor with the Ubuntu 9.04 OS.
Windows is for kids with big wallets who like to play games. Linux rocks!