Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Sunday, 31 January 2010

How to beat a spammer

Spam messages are an incredible nuisance for most web users. But, now scientists claim to have developed an effectively "perfect" method for blocking the most common kind of spam, using spammers’ own trickery.

An international team, led by International Computer Science Institute in Berkeley and California University, has come up with a system that deciphers the templates a “botnet” is using to create spam. These templates are then used to teach filters what to look for, the ‘New Scientist’ reported. According to the scientists, the system works by exploiting a trick that spammers use to defeat email filters.

As spam is churned out, subtle changes are typically incorporated into the messages to confound spam filters. Each message is generated from a template that specifies message content and how it should be varied.

The team reasoned that analysing such messages could reveal the template that created them. And, since the spam template describes the entire range of the emails a bot will send, possessing it might provide a watertight method of blocking spam from that bot.

To test their idea, the team installed a previously captured software bot onto a machine. After analysing 1,000 emails generated by this compromised machine, less than 10 minutes’ work for most bots, the scientists were able to reverse-engineer the template.

Knowledge of that template then enabled filters to block further spam from that bot with 100% accuracy. The new system did not produce a single false positive when tested against more than a million genuine messages and the biggest advantage is this false positive rate, team member Andreas Pitsillidis said.

“This is an interesting approach which really differs by using the bots themselves as the oracles for producing the filters,” added Michael O’Reirdan , chairman of the messaging anti-abuse working group, a coalition of technology companies.
Share/Bookmark

Friday, 15 January 2010

Facebook to give McAfee security to all users

Facebook, in collaboration with McAfee is going to provide all of its 350 million users with a free six-month security trail pack of McAfee's INternet Security Suite.

The popular social networking site Facebook has taken this step after various cyber attacks such as the 'Koobface virus'.

Facebook said that a scanning tool will also be provided to its users whose computers have fallen prey or show signs of being attacked. This scanning tool is also being offered without any cost as such. The new scanning tool is available immediately for English-language users of Facebook, with versions for other languages coming soon.

After the 6-month trial period, the subscription will be available at a discount for Facebook users.

This will protect users from online threats such as hackers, viruses, trojans, spyware etc.

"We feel like we've done a great job in protecting our network and accounts on Facebook, but we're always looking at ways we can do better," said Facebook spokesman Barry Schnitt.

Facebook users in the United States, Britain, France and eight other countries have immediately access to the free version of McAfee Internet Security Suite, with additional countries to come through the first three months of the year. Those in India might have to wait just a little bit linger.
Share/Bookmark

Sunday, 6 December 2009

How a Denial-of-Service(DoS) attack works?

Investigators are piecing together details about one of the most aggressive computer attacks in recent memory -- a powerful Denial-of-Service (DoS) assault that overwhelmed computers at US and South Korean government agencies, companies and institutions, in some cases for days.

How does this type of cyber attack work? And how can people make sure their computers are safe? Here are some questions and answers about the attack.

What is a DoS attack?

Q: What is a DoS attack?

A: Think about what would happen if you and all your friends called the same restaurant over and over and ordered things you didn't even really want. You'd jam the phone lines and overwhelm the kitchen to the point that it couldn't take any more new orders.

That's what happens to Web sites when criminals hit them with denial-of-service attacks. They're knocked offline by too many junk requests from computers controlled by the attackers.

What are the main techniques of such attack?
Q: What is the main weapon of a DoS attack?

A: The bad guys' main weapon in such an attack is botnets, or networks of zombie personal computers they've infected with a virus. The virus lets the criminals remotely control innocent people's machines, which are programmed to contact certain Web sites over and over until that overwhelms the servers that host the sites. The servers become too busy to respond to anything, and the Web site slows or stops working altogether.

It's different from what usually happens when you try to access a Web site. Normally, you just make one request to see the site, and unless there's a crush of traffic from something like a big news event, the servers respond well. Hijacked PCs, on the other hand, are programmed to send way more traffic than a normal user could generate on his or her own.

How often do these attacks happen?
Q: How often do these attacks happen?

A: People try denial-of-service attacks all the time, many government and private sites report being hit every day. Often the assaults are unsuccessful, because Web sites have ways of identifying and intercepting malicious traffic. However, sites really want to avoid blocking legitimate Web users, so more often than not, Internet traffic is let through until a problem is spotted.

Denial-of-service attacks are noisy by design, and they intend to make a statement. They're not subtle attempts to infiltrate a Web site's defenses, which can be much more insidious because that gives hackers access to whatever confidential information is stored there.

How companies fight these attacks?
Q: Some organizations appear to have fended off these recent attacks, while others saw their Web sites go down. How can this be?

A: The sites that went down probably were less prepared, because they are less accustomed to being hit or aren't sensitive enough to warrant extra precautions. Popular Web sites, like e-commerce and banking sites, have a lot of experience dealing with denial-of-service attacks, and they have sophisticated software designed to identify malicious traffic. Often that's done by flagging suspicious traffic flowing into the site, and if there's enough of it, preventing it from ever reaching the site's servers.

Another approach is to flag suspicious individual machines that seem to be behind an attack, and ban any traffic from them from reaching the site. That can often be difficult, though, because criminals use proxy computers to route their traffic, masking the source of the original requests. Proxy computers are often other infected computers that are part of a botnet.

What is the kind of evidence available against culprits?
Q: Is there usually evidence of who the culprits were? Or is the nature of the attack such that it leaves few fingerprints?

A: It's usually easier to stop a denial-of-service attack than it is to figure out who's behind it. Simply identifying where the malicious traffic is coming from won't get investigators very far, since the infected PCs that get roped into a botnet are owned by innocent people who don't know their computers are being used for nefarious purposes.

Pat Peterson, a security researcher and fellow at Cisco Systems Inc, says sophisticated attackers have also been adding a more subtle approach to evade detection. Instead of directing huge amounts of traffic at a target site, they'll make more complicated requests one at a time that eat up more of the site's computing power, like trying to log in using bogus usernames and passwords. If enough of those requests are made, on a site that requires a lot of computing power, the effect can be the same, and the site gets knocked out.

This type of attack is trickier because it doesn't involve the sort of massive traffic surge that would normally tip off network administrators. This advanced tactic wasn't necessarily used in the most recent attacks. In fact there are signs the attacks were relatively amateurish. The programming code appears to have been patched together largely from material that has been circulating in the criminal underground for several years, according to Jose Nazario, manager of security research for Arbor Networks.

How can I know if my PC is under botnet attack?
Q: If these attacks make use of compromised computers corralled into a botnet, should I be worried about whether my PC is one of them? What could I do to prevent that or fix it?

A: If your computer is being used in a denial-of-service attack, you're likely to see a significant slowdown, because your processing power is being siphoned for the assault. But there aren't always obvious signs that your computer has been infected.

So the best thing is to focus on prevention, namely by having up-to-date antivirus software. In particular, make sure your antivirus software gets updated over the next few days.

If you're concerned your machine might be infected, it's wise to run an antivirus scan. Many antivirus companies offer a free scan from their Web sites.
Share/Bookmark

Thursday, 3 December 2009

Why CAT crashed online

The trouble with the computer-aided CAT exam was diagnosed as ‘Conflicer’ and ‘W32 Nimda’, the two viruses that attacked the system display of the test, causing it to slow it down.

Efforts are now on to quarantine the systems from these viruses to ensure smooth conduct in the remaining days. Tests at 47 labs were called off on the first two days and 33 labs on Monday, on account of this problem affecting nearly 8,000 aspirants who will be rescheduled.

Samir Barua, director of IIM-A, which is the nodal agency for conducting CAT in the country, told reporters, "Though there were precautions taken, with so much of technology involved, it is hard to keep the system foolproof. The 47 centres which reported problems on Day one, were kept shut on Day 2 so that they could be checked. On Day 3, 33 were shut, which include some new centres also," said Barua.

"All efforts are right now diverted to further isolate and quarantine the individual servers, increase virus protection and control accessibility so that the test can be conducted smoothly on the remaining days. These security measures are being taken not only in the centres that have experienced problems but all the others that were operating smoothly," added Barua.

Charles Karnan, COO, Prometric, the US agency given the contract for CAT 2009 along with NIIT, said, "All the students who have suffered any difficulty in the taking the test will be accommodated, as all the centres were asked to keep a buffer in case of any such problem, right in the beginning. Of the 8,000 odd candidates that have faced problem, 62% have been rescheduled." "This is the biggest test we have conducted. Usually these many students take tests like GRE, GMAT or Toefl across the year, but here we had to complete the process in 10 days," he said.

Students facing problems at individual levels, have been asked to report to the Candidates Care Service at each centre. “Once their credentials are confirmed, they will be given a new test date and slot when they can appear for the test," Satish Deodhar, convenor of CAT Centre said.

Asked how the three centres at Ahmedabad were glitch-free, Prof Deodhar, said, "The centres here were able to keep their servers quarantined better."

Virus claim may trigger litigation
With the online CAT to the IIMs turning chaotic — admission tests were cancelled at nearly 14% centres across the country owing to technical glitches — cyber experts say pinning of the blame on a virus attack may have worsened things for applicants.

Cyber guru Vijay Mukhi said the official explanation of a virus would open the doors for students to question the exams and approach courts to have it cancelled. ‘‘It could set a dangerous precedent if anyone goes to the court and court grants a stay,’’ he told, even as he questioned the virus claim. Cyber law advocates said a technical glitch is one thing, but admitting to a virus attack shows the online system may be tough to handle for authorities. Rajiv Kumar, a well-know lawyer, said the cancelled exams would give rise not only to question of inequality, but also denial of equal opportunity.
Share/Bookmark

Wednesday, 2 December 2009

Top 10 riskiest Web domains

Web DomainsEver wondered which are the most riskiest Web domains? Domains which host (or are rather used to host) maximum malware or codes that can launch a virus, phising or a botnet attack on your PC?

Security agency McAfee has released its annual "Mapping the Mal Web" report that names the riskiest Web domains across the globe. Alarmingly, as many as seven out of the top 20 riskiest domains are from the APAC region.

Here's over to top 10 riskiest Web domains.

Cameroon (.cm)
CameroonTopping the list is Africa's Cameroon (.cm) which has overthrown Hong Kong (.hk) as the Web's riskiest domain. Entering for the first time in the list, Cameroon, a small African country that borders Nigeria, jumped to the number one spot this year with 36.7% of the .cm domain posing a security risk.

According to the report, because the domain .cm is a common typo for .com, many cyber criminals set up fake typo-squatting sites that lead to malicious downloads, spyware, adware and other potentially unwanted programmes.

Last year's riskiest domain, Hong Kong (.hk) dropped to 34th place with a risk rating of only 1.1%.

Commercial (.com)
CommercialWorld's most common domain has just got more dangerous. From being the ninth most riskiest domain last year, .Com domain has become the second most dangerous domain this year. Falling in the generic category, Commercial (.com) domain has a weighted risk of 32.2%.

According to the report, .com is also the most risky generic top level domain (TLD).



China (.cn)
ChinaAt No. 3 is People's Republic of China (.cn) which poses a risk level of 23.4%, as compared to 11.8% in 2008.

According to McAfee, the risky or malicious activity associated with sites registered with the .cn (China) overwhelmingly relates to spam sites as opposed to malicious downloads.

Samoa (.ws)
SamoaFourth most riskiest Web domain is Samoa (.ws) with an overall risk percentage of 17.8%. Last year the domain posed a security risk of 3.8%.

The report rates Samoan-registered domains risky primarily for their phishing and malicious download activity. Among country domains, the People's Republic of China (.cn) and Samoa (.ws) have remained in the top 5 riskiest domains since last year.

Information (.info)
InformationThe information (.info) domain is the most "spammy," domain with 17.2% of its sites generating junk mail.

The domain has an overall risk of 15.8%, as compared to 11.7% in 2008. The risk associated with .info registered domains is largely spam related.



Philippines (.ph)
PhilippinesAt No. 6 on the riskiest Web domains list is Philippines (.ph). The domain has an overall risk level of 13.1%, compared to 7.7% last year.

Philippines (.ph) registered sites are more similar to China than Samoa, with risk weighted towards spam and phishing than related to downloads.

Network (.net)
NetworkSeventh riskiest web domain is Network (.net) with the overall risk percentage of 5.8%. As compared to this year's figure, the domain recorded a higher security risk of 6.3% last year.





Former Soviet Union (.su)
Soviet UnionEntering for the first time in the top 10 list is Former Soviet Union (.su) domain. Ranked at no. 8, the domain poses a security risk of 5.2%.

The report says risky registrations using the former Soviet Union (.SU) domain are evenly distributed between phishing and risky download activity.

Russia (.ru)
RussiaNinth riskiest Web domain is Russia (.ru) with an overall risk percentage of 4.6%. Last year, the domain posed a security risk of 6%.

Russian (.RU) registered site risk is distributed in a roughly 3:2:1 ratio for malicious downloads, phishing and spam.

Singapore (.sg)
SingaporeNext APAC country on the list is Singapore (.sg) at No 10. The .sg domain has an overall risk of 4.6%, compared to 0.3% last year.

According to the report, Singapore (.sg) registered sites were evenly distributed between spam and download activity.
Share/Bookmark

Wednesday, 3 June 2009

Now its Swine flu computer virus

Japan has reported no human cases of deadly swine flu so far -- but a computer virus of the same name has been spreading on the Internet in recent days, authorities warned Thursday.

Japan's National Institute of Infectious Diseases (NIID) said on its website that a suspicious Japanese-language email message with an attached file called "information on swine flu" had been circulating in cyberspace.

"The institute has received reports that the email message falsely identifying itself as coming from the NIID is circulating," it said.

"The email is carrying a file titled 'information on swine flu', which has been recognised as an illegal programme by the institute's virus-checking software," the NIID statement said.

The institute did not say what kind of malware was hidden inside the file or what harm it might do. The email, originating from senders in the "@yahoo.co.jp" domain, seemed to be sent to random Internet users, the institute said.

"It is obviously a suspicious message falsely identifying itself," it said. Japan has so far reported no human cases of swine flu, which is believed to have killed up to 84 people in Mexico -- eight of them confirmed -- and has spread to the United States, Europe, Israel and New Zealand.
Share/Bookmark

Thursday, 15 January 2009

Top tech threats of 2009

It’s been a maelstrom of a year. Besides some of the fiercest financial and personal storms during 2008, we have also seen hackers making their way into our systems through browser and OS glitches -- and sometimes just by the foolhardy way we click on links and attachments.

While most of the holes have been plugged, there are still a few bad eggs out there that are looking forward to making 2009 harder for us. The tech-threat landscape looks bleak, but nothing that can’t be changed if we take a few well-timed precautions...



Portable threats
Portable storage devices, such as flash drives and standalone hard disks, will be one of the biggest risk factors of 2009. These devices are easily shared amongst a group of users; so, if one such device is infected, it could end up compromising entire networks and groups. End Point Security is going to be a major concern area for both networks and home users.

And then, of course, there are PDA phones. These devices provide a new gateway to hackers through malicious codes in spam emails and websites around the Internet.

Social networking
Sites such as Facebook, MySpace and Orkut are sitting ducks for cyber criminals. Their goal: To collect information from user profiles that can later be used in other targeted attacks.

Using the information, scammers could send messages that resemble legitimate correspondence from trusted sources, such as friends and relatives.

Pod slurping
The term describes the act of using a portable data storage device such as an iPod to illicitly download confidential data by directly plugging it into a computer where the data is held.

As MP3 players become smaller -- coupled with an increase in their storage capacity -- they become an increasing security risk to companies, wherein employees could use them to copy classified information.

Most companies in 2009 would find it prudent to have rules in place with regards to cellphones, MP3 players and personal flash drives.

Share/Bookmark
Share/Bookmark

Monday, 15 December 2008

How can you test your antivirus software...??

Creating A Test Virus:
Have you ever wondered if your anti-virus software is really working? Would you like to see what happens when it detects a virus? Here's a safe way to test your computer's virus protection that doesn't require you to have a real virus.

First, open Notepad. Then copy and paste into it the text on the line below. (It should all be on one line.)

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

Then select File, Save, select All Files for the file type, then save the file as eicar.com

Your anti-virus software may prevent you from saving the file as eicar.com, which is a sign that it is working effectively. If it doesn't raise an alert, try scanning the folder where you saved eicar.com. To see what happens if you try to run a file containing a virus, double-click eicar.com to open it.

Explanation:
The file eicar.com you have created is completely safe. It is not a virus. It is a standard test file developed by the European Institute for Computer Anti-virus Research (EICAR). All anti-virus products are programmed to detect this file as if it was a real virus. Therefore you can safely use it to test whether your anti-virus software works, without fear of infecting your computer.

Conclusion:
If your anti-virus product should fail to prevent you from running the file, it will simply display the text "EICAR-STANDARD-ANTIVIRUS-TEST-FILE" in a DOS box. No harm will have been done, but you should probably consider using a better anti-virus product, because if it had been a real virus, your computer would by now be infected!
Share/Bookmark