Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - Dexter

Pages: [1] 2 3 ... 7
1
News / Happy St. Patrick's Day!
« on: March 17, 2005, 06:46:23 PM »
Hope you all have a fun and safe St. Pattie’s Day!  

I’ll be having a few Guinnesses tonight and watching something Irish on tv.

2
News / Server Glitches
« on: March 06, 2005, 11:40:11 PM »
well that isn't good http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/sad.gif\' class=\'bbc_emoticon\' alt=\':(\' />  hope things get worked out

3
Tech Clinic / CWS, CoolWebSearch removal procedure...
« on: October 04, 2004, 06:13:53 PM »
Got this off of a mailing list... don't know if it really works or is just a scam but figured I might as well post it here incase anyone needs help.

----------------------------------------
Hello,

CWS, CoolWebSearch, is a particularly nasty incarnation of ad-ware.
Rossano Ferraris ([email protected]) and I have
collaborated to develop a simple procedure to remove it from an
NT4-W2K-WXP box.

CWS is widely discussed on the web, but it's poorly understood and
procedures to remove it are often lengthy, cumbersome and ineffective.
Users are sometimes forced to reformat the hard disk to remove it. CWS
comes in a variety of flavors. This post will only consider the most
insidious, which involves two components: a shield-DLL and a BHO
(Browser Helper Object).

Shield-DLL
----------

The shield-DLL installs itself to the following registry value in
NT4-type systems:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_Dlls

Per MSKB 197571, a .DLL listed there is "loaded by each Windows-based
application running within the current logon session." IOW, any
ad-ware found here runs concurrently with _every_ program launched. It
is truly astonishing that such a registry location exists.

Here's what the CWS shield-DLL manages to do:

1. It prevents almost all registry editors from displaying it as an
  AppInit_Dlls value. This list includes, but is not limited to:
  Regedit.exe (even if renamed), Regedt32.exe, Reg.exe, Autoruns,
  HijackThis, and, my favorite (because I wrote it), the "Silent
  Runners.vbs" script. The _only_ program known to display it, for
  unknown reasons, is the freeware Registrar Lite 2.0, available
  here: http://www.resplendence.com/reglite/

2. It prevents all GUI and command line tools from listing it or
  deleting it. This list includes, but is not limited to: Windows
  Explorer, DIR, ATTRIB, CACLS, and DEL.

3. The .DLL file has eccentric security permissions (SYNCHRONIZE
  and FILE_EXECUTE) and is READ-ONLY. Once the shield-DLL is removed
  from memory, an Admin must reset security to delete the file.

4. It has a unique name on every system it infects.

5. It ensures that a BHO starts up with IE at every boot.

6. If the BHO is deleted, it restores the BHO under a new name at
  the next boot.

This combination of features makes it a formidable adversary.

BHO
---

This is a .DLL that installs itself as a subkey of the following key:
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

The BHO is responsible for the ad-ware symptoms: change of home page,
profusion of popups, and anything else that foments the users' wrath.
The BHO registry key and the file are not protected; both can be
deleted. The BHO will simply be reloaded under a new name at the next
boot.

To eliminate CWS, we have developed a relatively simple procedure
(compared to everything else that's out there) that involves using
Registrar Lite 2.0 to record the name of the shield-DLL, a VBS script
to remove it from AppInit_Dlls, the "Silent Runners" script to
identify the BHO, and, after reboot, a second VBS script to delete the
shield-DLL and BHO files. The procedure and scripts can be found here:
http://www.silentrunners.org/sr_cwsremoval.html

MS please take note:

AppInit_Dlls is a gaping security hole. Unfettered access to this
value should be removed ASAP from NT4/W2K/WXP.

regards, Andrew Aronoff & Rossano Ferraris

                               *****
Want to know every program (well, almost every program -- CWS being
            the exception) that starts up with Windows?
                   Download "Silent Runners.vbs":
                   http://www.silentrunners.org/
                               *****

--
NTBugtraq Editor's Note:

Want to reply to the person who sent this message? This list is configured such that just hitting reply is going to result in the message coming to the list, not to the individual who sent the message. This was done to help reduce the number of Out of Office messages posters received. So if you want to send a reply just to the poster, you'll have to copy their email address out of the message and place it in your TO: field.
----------------------------------------

4
Idle Chat / Looking to get or share gmail invites?
« on: September 21, 2004, 02:34:59 PM »
This is for all you folks looking for G-Mail invites or looking to give away invites!

I give you the Automatic Gmail Invite Giver-Awayer.



This nice guy snakez has setup an automated gmail invite share system.  Basically, you send invites to a special email address and his system automatically puts the invite into a queue.  When a person visits the site and enters their own email address it sends the person a random invite.  Pretty cool isn’t it.  No begging on forums or using silly gmail matchup sites.  Just head on over and grab a free invite.

So, If you would like an invite and don’t have one yet visit the site: http://gmail.snakez.org/.

Or if you have invites you want to give away then visit the website and follow the instructions to send them into the system!

Share the url around the net.

5
News / Free Windows SP2 Update CD From Microsoft
« on: August 27, 2004, 08:23:04 AM »
Well this is for all you poor folks out in dialup land.  If you’re running Windows XP you should be upgrading to SP2 but I’m sure you don’t want to bother downloading a 100MB+ file either.

Microsoft said they would make a big push to get SP2 distributed to the masses and they’ve made good on their promise.  You can now order a SP2 CD directly from Microsoft free of change.  You don’t even have to pay shipping!

Now the one problem.  It’ll take 4 to 6 weeks for delivery.  That is a long time to wait considering even for dialup you could get the SP2 installer downloaded in less time.  But hey it’s free from Microsoft so why not take advantage of it?  It’ll be handy for the future should you reinstall your OS at some point or just to loan to family and friends.

Head on over to the Microsoft Website and order your CD today.  There’s no reason not to!

6
News / Windows XP SP2
« on: August 12, 2004, 09:10:22 PM »
Windows XP SP2 (Service Pack 2) has finally been released!

Currently only the network installer (aka the business version) is available weighing in at 266MB! This version is designed to update all XP based systems including home, pro, media center, tablet pc, etc and to be used in business environments by IT Professionals.

Soon there will be a consumer version put out on the windows update site as well as thru the automatic update service. I'd suggest home users just wait for this to become available as the network installer is very very very big!  The windows update version will only download the required updates so you don't waste your time downloading things you won't use.

You can read all about SP2 as well as get the download here:
http://www.microsoft.com/technet/prodtechn...n/winxpsp2.mspx

7
Tech Clinic / LSASSER
« on: June 17, 2004, 08:15:48 AM »
well atleast just try the symantec tool... it can't hurt to try it.

http://securityresponse.symantec.com/avcen...moval.tool.html

8
News / Downloads Server Back Online
« on: May 13, 2004, 08:16:38 AM »
http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/ohmy.gif\' class=\'bbc_emoticon\' alt=\':o\' />

shesh that's a lotta bandwidth!  Need to put a bandwidth cap on that sucker! http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

9
Software / making win95 floppies from the cd
« on: April 14, 2004, 04:40:03 PM »
This is about the most convoluted and psycotic way of doing it but it does actually work!  Infact this is how I put windows 95 on an old epson ActionNote 650c(50mhz 486dx2, 20mb ram, 250mb hd, floppy, no-cdrom, 640x480px screen).

You're going to need a second computer and a laplink cable to pull this off.

1) Create a bootable floppy disk with all the required tools fdisk.exe, format.com, sys.com, emm386.exe, etc.  make sure to have a copy of interlnk.exe and intersvr.exe.  these two programs let you share drives over a laplink cable.

2) boot from the floppy and setup the laptop.  basically you want a clean install.  so fdisk, format, and run sys to make the laptop able to boot up into dos by itself (without the floppy). copy all the files over from the boot floppy just to make life easier.

3) create a config.sys file with the following contents
-- config.sys --
device=c:\himem.sys
device=c:\emm386.exe
device=c:\interlnk.exe
-- end of file --

3) use the boot floppy for the second computer who's job will be to run intersvr.exe and share your windows 95 cdrom.  actually it works best if you can setup the second machine to have a fat partition and copy the contents of the windows 95 cdrom to that partition.

4) after booting up the second computer with the floppy run intersvr.exe so it will share the partition with the cdrom files on it.

5) connect the two computers via the laplink cable

6) boot up the laptop.  hopefully interlnk will start up, connect to the "server" and you will find you have a new drive on the laptop that has the contents of the windows disk.  just run setup from this new "drive" and you'll be good to go!

it's pretty slow installing over the laplink cable but it does work.  Like I said, I did it to my fathers old laptop that had windows 3.11 on it.  I wiped it clean, installed 95, and now use it as my chat box.  

Using that same laplink cable I setup windows xp to accept incomming connections via the parellel port and use the direct cable connection feature that windows 95 has.  they link up and talk just fine and the laptop then has full network access through my xp box.  The laptop is too slow and the screen limited to use it for surfing or email but I can fire up Mirc, plug in a full keyboard and chat all day long on it.  It's great to move chat over to a seperate machine to free up my main box to do real work.  Only complaint I have is I can't install trillian in win95 otherwise I could shift all my communication stuff onto a seperate machine.

Ok I've rambled enough http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

10
Hardware / Western digital HD 8 M cache
« on: March 22, 2004, 03:17:15 PM »
actually the windows defragger works just fine.  for some reason when you run it via the GUI it's terrible and only defrags the files but doesn't rearange the free space.

If you run defrag from the command line it actually does a very good job and will move everything to the begining of the HD.

11
Software / Anyone try XP SP2 RC1 yet?
« on: March 21, 2004, 12:21:47 PM »
coolies

Between being on dialup and the fact that I just did a complete system wipe and reinstall like 3 weeks ago I'm hesitant to install anything.  I'd hate spending 2 days downloading then have it totally hose my system http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

12
Software / Anyone try XP SP2 RC1 yet?
« on: March 20, 2004, 07:52:32 PM »
I see microsoft has opened up and is letting people download and try sp2 rc1 and just wondering if anyone has downloaded and tried it yet?

http://www.microsoft.com/technet/prodtechn...sp2preview.mspx

13
News / "Resident Evil: Would you survive?" Contest
« on: March 16, 2004, 07:40:42 PM »
I would like to give a shout out for a contest some friends are running. The fine fellows of Snackbar Games are holding a Resident Evil: Outbreak Contest. The winner gets a limited edition Resident Evil: Outbreak survival pack that contains a Resident Evil canteen and mask.  

Oooh, You know you want free swag people!

However, this isn't your run of the mill contest where you just sign up and forget about it.  You have to work for these prizes.  You're required to take a picture of yourself in a scary location equipped with gear you would need to survive Resident Evil.

Now everyone get out of your chairs and have some fun being creative and win the Resident Evil: Outbreak Contest.  You have till March 22nd to apply.

14
News / Get a free Windows update CD from Microsoft
« on: February 19, 2004, 08:12:39 AM »
Microsoft is giving away free patch CDs!

http://www.microsoft.com/security/protect/cd/order.asp

This is for all users of Windows XP Pro, Windows XP Home, Windows 2000 Pro, Windows ME, Windows 98 Second Edition, and Windows 98. It includes all hotfixes, patches and updates as of October 2003.

It’s totally free (free cd + free shipping) so all windows users might as well take advantage of it. It’s not going to cost you anything so why not spend a minute or two to order it. More importantly when you get the cd, use it!

Heck even non-windows users should order a copy because you all know windows users that don’t update their systems. Give copies to all your friends and families to promote safe computing.

If every person would help out 2 others to keep their systems more secure we would probably have half the problems with viruses, worms, trojans, etc.

Now do your civic duty and order the cd today!

http://www.microsoft.com/security/protect/cd/order.asp

15
News / Mandrake 9.2 available for download!
« on: October 23, 2003, 11:03:41 AM »
someone needs to setup bittorrent for the files...

16
News / DCOM RPC Worm in the Wild!
« on: August 18, 2003, 02:11:17 PM »
from the AlanBarber.Org blog:
Quote
This is downright goofy folks! 

There's a new DCOM RPC worm running the rounds.  Officially tagged as
"W32.Welchia.Worm" by Symantec, "WORM_MSBLAST.D" by Trend, and "W32/Nachi.worm" by McAfee it's pretty much the same as the other DCOM RCP worms with one big difference.  It's designed to fix the problem!

Get this people.  When the worm finds an open system it infects the system and runs the worm on the new system.  On the new system the worm searches for the original MSBLAST worm and removes it if found.  It then automatically downloads the Microsoft patch to fix the DCOM RPC hole, installs the patch and reboots the machine.  It then runs in the background searching out other open systems to spread to until January 1st, 2004.  At that time it will delete itself.

There doesn't seem to be any trojan horse or payloads but as a virus/worm it should be considered dangerous.  However this has to be the first time in the history of computing that a virus/worm actually fixes the very hold it exploits.

The person that wrote this should get nominated for misguided humanitarian of the year or something.

This security hole is turning into a three ring circus!   http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/blink.gif\' class=\'bbc_emoticon\' alt=\':blink:\' />

17
News / DCOM RPC Worm in the Wild!
« on: August 13, 2003, 04:34:33 PM »
not really sure on the effects...  I run only winxp boxes and they've been patched since it was released.

18
News / DCOM RPC Worm in the Wild!
« on: August 12, 2003, 07:39:26 PM »
If you're running a Windows system please go to windows update and make sure you have downloaded and installed every critical patch listed. Don't be lazy, just do it right now! There is officially a worm out there that is taking control of windows based system right now.

Here's the short and skinny on the worm.

1) It's being called "W32.Blaster.Worm" by Symantec, "W32/Lovsan.worm" by Mcafee, and "WORM_MSBLAST.A" by Trend.
2) It exploits the DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135.
3) If infected a program called msblast.exe will be running.
4) It causes system instability and opens your computer to remote access.
5) It cannot automatically spread to windows NT or 2003 systems but they will crash if the worm tries to access them. If the worm is installed manually it will run in windows NT and 2003 though.
6) The worm also attempts to perform a DoS attack on the Windows Update site.

19
The Private Club / Q about site...
« on: July 05, 2003, 04:17:56 PM »

20
News / FreeBSD 5.0 Released
« on: January 20, 2003, 03:55:07 PM »
It took them long enough but FreeBSD 5.0 has finally be released.  Head on over to the FreeBSD Website and check it out.

Here are just a short list of new featuers:
-UFS2, the second generation UFS filesystem, shatters the current 1TB filesystem barrier.
-Background filesystem checking (bgfsck) and filesystem snapshots eliminate the need for downtime to do filesystem repair and backup tasks.
-Experimental support for Mandatory Access Controls (MAC) provide an extensible and flexible means for administrators to define system security policies.
-Fine-grained locking in the kernel paves the road for much higher efficiency of multi-processor systems.
-Support for Bluetooth, ACPI, CardBus, IEEE 1394, and experimental hardware crypto acceleration keeps FreeBSD at the forefront of new technology.
-The GCC 3.2.1 compiler provides the latest installment of the ever-improving GNU Compiler Collection.
-GEOM, the extensible and flexible storage framework, and DEVFS, the device virtual filesystem, simplify storage and device management while opening the door for new enterprise storage technologies.
-Support for the sparc64 and ia64 platforms expands FreeBSD\'s support of advanced 64-bit computing platforms.

Pages: [1] 2 3 ... 7