-
Posts
683 -
Joined
-
Last visited
Everything posted by curtis
-
WORM_LOCKSKY.Y is a memory-resident worm that propagates by sending a copy of itself as an attachment to email messages. It is currently spreading in-the-wild and infecting systems that run Windows NT, 2000, XP, and Server 2003. The email that it sends has the following details: Subject: Your mail Account is Suspended Message body: We regret to inform you that your mail account has been suspended due to the violation of our site policy, more info is attached. Attachment: acc_info{random number}.exe It spoofs the From: field in an attempt to trick users into thinking that the spammed email is from a trusted source. It bypasses an affected system's firewall thereby effectively lowering system security. This worm checks for an updated copy of itself by connecting to a specific Web site, and if an updates is available, downloads the update. It also logs keystrokes and saves the gathered information. Upon execution, it drops a copy of itself in the Windows folder, and also drops component files, and other copies of itself in the Windows system folder.
-
Happy New Year to everyone.
-
I know its a little early but Merry Christmas and Happy New Year to everyone. Now I'm off on my annual holiday 4 state journey to visit relatives. Have a safe holiday.
-
The Santa Claus worm doesn't care whether you've been naughty or nice, but it's making a list of PCs to infect this holiday season, according to a threat alert released by security firm IMlogic today. A new instant-messaging worm called IM.GiftCom.All is making the rounds this holiday season. Rated as a "medium" threat by IMlogic, the worm attempts to get users of the instant-messaging networks run by America Online, Yahoo, and Microsoft to visit a seemingly festive Web site featuring Santa Claus. The message comes from someone already present on a user's "buddy list," said Art Gilliland, vice president of products for IMlogic. It contains a supposed link to a URL starting with "santaclause.aol.com/a?|" However, clicking on that link takes users to a different Web site and triggers the download of a malicious file to a user's PC, Gilliland said. That file is created using rootkit techniques, making it extremely difficult to detect with conventional antivirus or operating system tools, he said. Once resident on a system, the file tries to shut down antivirus software and collects personal information that can be redistributed over the Internet. Users are advised to avoid clicking on anything sent through an instant-messaging system unless they have verified that the file or picture is legitimate and the sender intended to pass it along.
-
Thanks Bruce. Very concise instructions. I followed your instructions and it worked perfectly. I was using a script called Backup2Mail, a good script but I think I will use this one for now.
-
A simple Javascript like ><script LANGUAGE = "JavaScript"> <!-- if (navigator.appName=='Microsoft Internet Explorer') {myWindow=window.open(); myWindow.location.href="http://your_domain/redirect_page.htm"} //--> </SCRIPT> should work. Change the url to whatever page is ie only. Insert the script between the <head> </head> tags
-
Yep, 334.3 is all I could get.
-
There have been reports that the new year will start with a bang possibly on the 5th of January or 6th of January, when a new SOBER variant is suspected to be released by the same group that caused the recent WORM_SOBER.AG outbreak in November. The reports may have been based on the analysis that WORM_SOBER.AG will download an executable file Sober.exe) possibly on either January 5, 2006 or January 6, 2006 from certain URLs that are hard-coded and encrypted within the SOBER.AG worm. These "predefined" URLs are not the exact sites that may used - an algorithm based on the date is used to generate the exact URLs that will be used on the target date itself.
-
Another good one. http://www.learn4good.com/games/action/sling_shot_santa.htm
-
In the past week, much attention has been given to the Yahoo phishing scam that is advertised through instant messenger (IM) via Yahoo Messenger. The aim of the phisher is to entice a user to click on the given link and provide personal details by logging in through the spoofed Web site that it opens. The IM arrives with the following text: http://www.geocities.com/oxox0o_angel_oxox0o/'>http://www.geocities.com/oxox0o_angel_oxox0o/ ^^ guess where this pic was taken and guess who is behind me in the picture or http://www.geocities.com/oxox0o_cary_oxox0o/ ^^ guess where this pic was taken and guess who is behind me in the picture The spoofed Web site bears a close resemblance to the legitimate Yahoo! Photo’s online login page, and the phishers made no attempt to disguise the Phishing URL in the address bar. The page is hosted by Geocities so it is possible for user's to determine that the Web site is not legitimate. The Phishing Web site asks the user for a user name and password. Upon clicking on the Sign In button, the gathered information is then sent to the email address: oxox0o_angel_oxox0o@yahoo.com that can be found at the page source of the phishing web site, http://www.geocities.com/oxox0o_angel_oxox0o/.
