Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Topics - Dexter

Pages: [1] 2 3 ... 5
1
News / Happy St. Patrick's Day!
« on: March 17, 2005, 06:46:23 PM »
Hope you all have a fun and safe St. Pattie’s Day!  

I’ll be having a few Guinnesses tonight and watching something Irish on tv.

2
Tech Clinic / CWS, CoolWebSearch removal procedure...
« on: October 04, 2004, 06:13:53 PM »
Got this off of a mailing list... don't know if it really works or is just a scam but figured I might as well post it here incase anyone needs help.

----------------------------------------
Hello,

CWS, CoolWebSearch, is a particularly nasty incarnation of ad-ware.
Rossano Ferraris ([email protected]) and I have
collaborated to develop a simple procedure to remove it from an
NT4-W2K-WXP box.

CWS is widely discussed on the web, but it's poorly understood and
procedures to remove it are often lengthy, cumbersome and ineffective.
Users are sometimes forced to reformat the hard disk to remove it. CWS
comes in a variety of flavors. This post will only consider the most
insidious, which involves two components: a shield-DLL and a BHO
(Browser Helper Object).

Shield-DLL
----------

The shield-DLL installs itself to the following registry value in
NT4-type systems:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_Dlls

Per MSKB 197571, a .DLL listed there is "loaded by each Windows-based
application running within the current logon session." IOW, any
ad-ware found here runs concurrently with _every_ program launched. It
is truly astonishing that such a registry location exists.

Here's what the CWS shield-DLL manages to do:

1. It prevents almost all registry editors from displaying it as an
  AppInit_Dlls value. This list includes, but is not limited to:
  Regedit.exe (even if renamed), Regedt32.exe, Reg.exe, Autoruns,
  HijackThis, and, my favorite (because I wrote it), the "Silent
  Runners.vbs" script. The _only_ program known to display it, for
  unknown reasons, is the freeware Registrar Lite 2.0, available
  here: http://www.resplendence.com/reglite/

2. It prevents all GUI and command line tools from listing it or
  deleting it. This list includes, but is not limited to: Windows
  Explorer, DIR, ATTRIB, CACLS, and DEL.

3. The .DLL file has eccentric security permissions (SYNCHRONIZE
  and FILE_EXECUTE) and is READ-ONLY. Once the shield-DLL is removed
  from memory, an Admin must reset security to delete the file.

4. It has a unique name on every system it infects.

5. It ensures that a BHO starts up with IE at every boot.

6. If the BHO is deleted, it restores the BHO under a new name at
  the next boot.

This combination of features makes it a formidable adversary.

BHO
---

This is a .DLL that installs itself as a subkey of the following key:
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

The BHO is responsible for the ad-ware symptoms: change of home page,
profusion of popups, and anything else that foments the users' wrath.
The BHO registry key and the file are not protected; both can be
deleted. The BHO will simply be reloaded under a new name at the next
boot.

To eliminate CWS, we have developed a relatively simple procedure
(compared to everything else that's out there) that involves using
Registrar Lite 2.0 to record the name of the shield-DLL, a VBS script
to remove it from AppInit_Dlls, the "Silent Runners" script to
identify the BHO, and, after reboot, a second VBS script to delete the
shield-DLL and BHO files. The procedure and scripts can be found here:
http://www.silentrunners.org/sr_cwsremoval.html

MS please take note:

AppInit_Dlls is a gaping security hole. Unfettered access to this
value should be removed ASAP from NT4/W2K/WXP.

regards, Andrew Aronoff & Rossano Ferraris

                               *****
Want to know every program (well, almost every program -- CWS being
            the exception) that starts up with Windows?
                   Download "Silent Runners.vbs":
                   http://www.silentrunners.org/
                               *****

--
NTBugtraq Editor's Note:

Want to reply to the person who sent this message? This list is configured such that just hitting reply is going to result in the message coming to the list, not to the individual who sent the message. This was done to help reduce the number of Out of Office messages posters received. So if you want to send a reply just to the poster, you'll have to copy their email address out of the message and place it in your TO: field.
----------------------------------------

3
Idle Chat / Looking to get or share gmail invites?
« on: September 21, 2004, 02:34:59 PM »
This is for all you folks looking for G-Mail invites or looking to give away invites!

I give you the Automatic Gmail Invite Giver-Awayer.



This nice guy snakez has setup an automated gmail invite share system.  Basically, you send invites to a special email address and his system automatically puts the invite into a queue.  When a person visits the site and enters their own email address it sends the person a random invite.  Pretty cool isn’t it.  No begging on forums or using silly gmail matchup sites.  Just head on over and grab a free invite.

So, If you would like an invite and don’t have one yet visit the site: http://gmail.snakez.org/.

Or if you have invites you want to give away then visit the website and follow the instructions to send them into the system!

Share the url around the net.

4
News / Free Windows SP2 Update CD From Microsoft
« on: August 27, 2004, 08:23:04 AM »
Well this is for all you poor folks out in dialup land.  If you’re running Windows XP you should be upgrading to SP2 but I’m sure you don’t want to bother downloading a 100MB+ file either.

Microsoft said they would make a big push to get SP2 distributed to the masses and they’ve made good on their promise.  You can now order a SP2 CD directly from Microsoft free of change.  You don’t even have to pay shipping!

Now the one problem.  It’ll take 4 to 6 weeks for delivery.  That is a long time to wait considering even for dialup you could get the SP2 installer downloaded in less time.  But hey it’s free from Microsoft so why not take advantage of it?  It’ll be handy for the future should you reinstall your OS at some point or just to loan to family and friends.

Head on over to the Microsoft Website and order your CD today.  There’s no reason not to!

5
News / Windows XP SP2
« on: August 12, 2004, 09:10:22 PM »
Windows XP SP2 (Service Pack 2) has finally been released!

Currently only the network installer (aka the business version) is available weighing in at 266MB! This version is designed to update all XP based systems including home, pro, media center, tablet pc, etc and to be used in business environments by IT Professionals.

Soon there will be a consumer version put out on the windows update site as well as thru the automatic update service. I'd suggest home users just wait for this to become available as the network installer is very very very big!  The windows update version will only download the required updates so you don't waste your time downloading things you won't use.

You can read all about SP2 as well as get the download here:
http://www.microsoft.com/technet/prodtechn...n/winxpsp2.mspx

6
Software / Anyone try XP SP2 RC1 yet?
« on: March 20, 2004, 07:52:32 PM »
I see microsoft has opened up and is letting people download and try sp2 rc1 and just wondering if anyone has downloaded and tried it yet?

http://www.microsoft.com/technet/prodtechn...sp2preview.mspx

7
News / "Resident Evil: Would you survive?" Contest
« on: March 16, 2004, 07:40:42 PM »
I would like to give a shout out for a contest some friends are running. The fine fellows of Snackbar Games are holding a Resident Evil: Outbreak Contest. The winner gets a limited edition Resident Evil: Outbreak survival pack that contains a Resident Evil canteen and mask.  

Oooh, You know you want free swag people!

However, this isn't your run of the mill contest where you just sign up and forget about it.  You have to work for these prizes.  You're required to take a picture of yourself in a scary location equipped with gear you would need to survive Resident Evil.

Now everyone get out of your chairs and have some fun being creative and win the Resident Evil: Outbreak Contest.  You have till March 22nd to apply.

8
News / Get a free Windows update CD from Microsoft
« on: February 19, 2004, 08:12:39 AM »
Microsoft is giving away free patch CDs!

http://www.microsoft.com/security/protect/cd/order.asp

This is for all users of Windows XP Pro, Windows XP Home, Windows 2000 Pro, Windows ME, Windows 98 Second Edition, and Windows 98. It includes all hotfixes, patches and updates as of October 2003.

It’s totally free (free cd + free shipping) so all windows users might as well take advantage of it. It’s not going to cost you anything so why not spend a minute or two to order it. More importantly when you get the cd, use it!

Heck even non-windows users should order a copy because you all know windows users that don’t update their systems. Give copies to all your friends and families to promote safe computing.

If every person would help out 2 others to keep their systems more secure we would probably have half the problems with viruses, worms, trojans, etc.

Now do your civic duty and order the cd today!

http://www.microsoft.com/security/protect/cd/order.asp

9
News / DCOM RPC Worm in the Wild!
« on: August 12, 2003, 07:39:26 PM »
If you're running a Windows system please go to windows update and make sure you have downloaded and installed every critical patch listed. Don't be lazy, just do it right now! There is officially a worm out there that is taking control of windows based system right now.

Here's the short and skinny on the worm.

1) It's being called "W32.Blaster.Worm" by Symantec, "W32/Lovsan.worm" by Mcafee, and "WORM_MSBLAST.A" by Trend.
2) It exploits the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135.
3) If infected a program called msblast.exe will be running.
4) It causes system instability and opens your computer to remote access.
5) It cannot automatically spread to windows NT or 2003 systems but they will crash if the worm tries to access them. If the worm is installed manually it will run in windows NT and 2003 though.
6) The worm also attempts to perform a DoS attack on the Windows Update site.

10
News / FreeBSD 5.0 Released
« on: January 20, 2003, 03:55:07 PM »
It took them long enough but FreeBSD 5.0 has finally be released.  Head on over to the FreeBSD Website and check it out.

Here are just a short list of new featuers:
-UFS2, the second generation UFS filesystem, shatters the current 1TB filesystem barrier.
-Background filesystem checking (bgfsck) and filesystem snapshots eliminate the need for downtime to do filesystem repair and backup tasks.
-Experimental support for Mandatory Access Controls (MAC) provide an extensible and flexible means for administrators to define system security policies.
-Fine-grained locking in the kernel paves the road for much higher efficiency of multi-processor systems.
-Support for Bluetooth, ACPI, CardBus, IEEE 1394, and experimental hardware crypto acceleration keeps FreeBSD at the forefront of new technology.
-The GCC 3.2.1 compiler provides the latest installment of the ever-improving GNU Compiler Collection.
-GEOM, the extensible and flexible storage framework, and DEVFS, the device virtual filesystem, simplify storage and device management while opening the door for new enterprise storage technologies.
-Support for the sparc64 and ia64 platforms expands FreeBSD\'s support of advanced 64-bit computing platforms.

11
News / Don\'t download NeoAudio mp3 ripper!
« on: August 09, 2002, 10:35:42 AM »
Saw this at the CDex website:

\"There is an application called NeoAudio, which is a straight CDex rip off. They changed some string (i.e. replace CDex with NeoAudio), changed the logo and added some nice SpyWare and Adware. I contacted Richard M. Stallman about this issue, but unfortunately I can not do much about it, except for the fact that they are removing/changing copyright strings which they should not. So please do not download and install NeoAudio (they probably make quite a few dollars by shipping the adware) and also advice other people NOT to download NeoAudio either, and warn innocent users not to download this application but download CDex instead.\"

The whole reason for open-source is so people can help improve software not steal it and claim it as their own!

12
News / ATi Day At [H]ardOCP
« on: July 18, 2002, 10:32:27 AM »
It appears that today is ATi day over at the [H].  Stop by to check out the latest scoops on the new line of Radeon video cards from ATi.

ATi Radeon 9000
You have heard the rumors and the speculation. Now see what the Radeon 9000, based on the RV250 Visual Processing Unit, is really all about. You might be surprised with what ATi has done.

ATi Radeon 9700 White Paper
A very well written white paper covering the major internal workings of the DX9 compliant ATi R300 Visual Processing Unit along with our thoughts.

ATi Radeon 9700 Gaming Experience
A subjective look at our Radeon 9700 gaming experience. We came, we saw, the Radeon 9700 conquered the benchmarks.

13
News / Supermicro Super P4DP8-G2 Review At 2CPU.Com
« on: July 18, 2002, 10:27:22 AM »
Once again the dual cpu lovers from have whipped up another great motherboard review.  This time it\'s the Supermicro Super P4DP8-G2 for dual Intel Xeons.

\"The Super P4DP8-G2 is a lot like the majority of E7500 based motherboards we are/will be seeing, but there are a few things that really set this one apart from the rest. If you\'re not familiar with the E7500 chipset, it, in a nutshell, brings dual channel DDR to the Intel Xeon server platform. DDR isn\'t the only new addition to the E7500 though. What would a fast new memory interface be without some complimentary features like GoC NIC(s) onboard and PCI-X to round out the package?\"

14
News / Iwill MPX2 Review At 2CPU.Com
« on: July 18, 2002, 10:24:04 AM »
well the guys over at have put out a nice little review of the Iwill MPX2 for dual AMD Athlon MPs.

\"This isn\'t new ground for Iwill, as they have been pushing both server and workstation-oriented dual boards down the assembly line for some time now. They\'re trying to service as many markets as possible with solutions built around all possible SMP-capable platforms: VIA, Serverworks, Intel, and of course AMD\'s 760MPX chipset is represented there.\"

15
News / Tyan Thunder i7500 Review At 2CPU.Com
« on: May 30, 2002, 09:38:30 AM »
Hooz from has posted a review of the Tyan Thunder i7500 motherboard based on the new Intel E7500 chipset.  So click the link and check it out!

\"I just put the finishing touches on my latest review, Tyan\'s Thunder i7500. I\'m pretty sure that this is the first review of the Thunder i7500 motherboard, and I\'m almost positive that it\'s the only article to use 2.4ghz Xeons. I compared the Xeons to AMD\'s finest in a bunch of benchmarks (even some new ones) and came up with some pretty interesting results.

As usual, it turned into a pretty nasty platform war instead of a \"normal\" motherboard review. But hey... I took a lot of pretty pictures to make up for it!\"

16
News / RIAA files suit against Audiogalaxy
« on: May 28, 2002, 03:50:58 PM »
ZDNet News posts that Audiogalaxy has been sued by RIAA.  Apparently they got bored and had to find someone new to pick on!

\"Filed in federal court in New York, the suit charges that Audiogalaxy\'s efforts to filter access to copyrighted songs have been ineffective. As a result, free-ranging access to copyrighted works through the system has gone unchecked--much as once happened with Napster, the industry group contends.

\"If they had demonstrated the ability to filter, we wouldn\'t be here,\" said Matt Oppenheim, an RIAA senior vice president. \"A first-year computer programmer could do better than they have.\"\"

17
News / Domain Name Scams
« on: April 17, 2002, 11:35:36 AM »
Apparently theres some domain name scams going around.  You can read the original story here.

Deceptive Domain Expiration Notices:
VeriSign Inc. (formerly Network Solutions) has been sending via postal mail false domain expiration notices. The purpose of these notices is to get the customer to unwittingly transfer and renew their domain names with VeriSign.

Domain Dispute Notifications:
Many domain name registrants are receiving \"Domain Dispute Notification\" mailings from an entity identifying itself as XChange Dispute Resolution. The mailings falsely state that XChange is an ICANN authorized arbitrator and that the registrant must mail in a security deposit fee to defend ownership of the domain name.

The sender of these notices has not been approved by ICANN as a provider of dispute-resolution services under ICANN\'s Uniform Domain Name Dispute-Resolution Policy (UDRP). Registrants should not send money as requested by this notice. Registrants who receive the notice should contact an appropriate governmental law enforcement/consumer protection agency to report the incident. Recipients can also fax the notice to ICANN at +1-310-823-8649.

18
News / A look at [H]ardOCP\'s Infrastructure
« on: April 12, 2002, 09:01:29 AM »
Kyle over at [H] has posted a short article on the [H]ardOCP Infrastructure.  So head on over and see what it takes to opperate one of the best tech sites on the web!

\"Been a while since we took a few moments to give you guys the 411 on what is going on around here behind the scenes.  And seeing how I am trying to find excuses to not work on this boring review (it really is a boring board), I figured now is the time we update you to why you might have seen some recent \"page not found\" errors here.\"

19
News / DIGN - HTPC Case Review
« on: April 11, 2002, 04:11:47 PM »
has released a rather cool review of the DIGN - HTPC Case.

\"Now case manufacturers have been improving the looks of computers for some time now, and even more people are starting to build pc\'s which plug in to their tv\'s and hifi\'s.

Now DIGN have taken the two ideas and moulded them into one. They have designed the HTPC. Hifi / TV PC ! Basically it is an aluminium computer case designed to match your current AV systems.\"

20
For Sale / Wanted / Domain name for sale! REAL CHEAP!
« on: April 09, 2002, 07:26:22 PM »
GOATS-N-SHEEP.COM  
Record expires on 07-May-2003

$25.00 USD or best offer.  Pay by paypal only.  Upon payment I\'ll give you the username and password for the 000domains.com account where I have the domain registered. (they charge 13.50 a year for registration)

Pages: [1] 2 3 ... 5