Powered By

Powered by Blogger

Tampilkan postingan dengan label virus. Tampilkan semua postingan
Tampilkan postingan dengan label virus. Tampilkan semua postingan

Minggu, 13 Juni 2010

Linux Trojan Goes Unnoticed For Almost A Year (Unreal IRCd)

It seems the Linux version of the popular IRC server Unreal IRCd was contaminated with malware ever since November 2009, without anyone noticing it. The announcement was made on the Unreal IRCd forums:

This is very embarrassing...We found out that the Unreal3.2.8.1.tar.gz file on our mirrors has been replaced quite a while ago with a version with a backdoor (trojan) in it. This backdoor allows a person to execute ANY command with the privileges of he user running the ircd. The backdoor can be executed regardless of any user restrictions (so even if you have passworded server or hub that doesn't allow any users in). [...] It appears the replacement of the .tar.gz occurred in November 2009 (at least on some mirrors). It seems nobody noticed it until now.


This reminds us that an OS is as secure as the owner makes it. Remember to always check the source code before running a script / application. Better yet, only install applications from your distribution's official repositories and very trusted sources.


[via pcworld]

Rabu, 09 September 2009

Re-Enable CMD / Task Manager/ System Restore / Registry Editor in Windows

Most viruses and other malware disable any way you could try to remove them. That means you most probably won't have any access to the registry editor, command prompt, task manager and so on. But there is a freeware, portable application which re-enabels all these tools. The applications is called "Re-Enable" and it will re enable registry editing (Regedit) after a worm / trojan / malware / virus has disabled registry editing, this will also re enable Cmd / Taskmgr / System restore Config / Folder options config and Run command.

Image and video hosting by TinyPic

Using the applications is very easy, all you need to do is put a check on the checkbox that you want to enable and click the Enable button. The disable feature will be instantly enabled or if not, a reboot should do it!

Re-Enable is coded in .net but doesn't need .net installed because .net dependencies are included in the program making it fully portable.

Download Re-Enable Portable

Kamis, 03 September 2009

Adobe Flash Player 0.2, A New Trojan Affecting Firefox

Adobe Flash Player 0.2

Do not install anything called "Adobe Flash Player 0.2" into Firefox! This add-on uses a description that links itself to Adobe Flash Player 10 which does look legit at first glance. Only the low version number and the fact that it is listed under extensions and not plugins could cause suspicion by Firefox users.

The spyware add-on itself is distributed through forums and websites but not the main Firefox add-on repository. Users are once again reminded to only install add-ons from trustworthy sources. The spyware add-on injects ads into Google search results pages. More disturbing than that is the fact that the Google search history gets transferred to a third party website that is (most likely) run by the developers of the spyware add-on. This means that every Google search query is transferred to the third party server.

More info, HERE.

Thanks to reader dionis for sending us the tip!