NinjaServe.org Forums
Home | About Us | Contact Us  
Quick Member Login:
Forgot password?
Servers:
Forum Statistics:
Forum Members: 1,680
Total Threads: 7,617
Total Posts: 66,373


There are 2 users
currently browsing forums.
  Server Status Register FAQ Members List Arcade gXboxLive Ninja RPG! Calendar Mark Forums Read
Non Registered Member! Please take the time to register now!

NinjaServe.org Forums » General Chat » Off Topic Discussion » Security Advisory

Off Topic Discussion General chit-chat that doesnt fit anywhere else! :) No gaming related chat please.

Reply
 
LinkBack Thread Tools Display Modes
Old 04-16-2004, 05:02 PM   #1 (permalink)
Meltdown
Senior Member
 
Join Date: Mar 2004
Posts: 400


Security Advisory

Getting pop-ups, gatored, and other BS apps installed on your computer that you know for a fact you didn't say OK to? Still getting them even after locking down your firewall and you security settings in IE and OL? Here is why:

http://www.greymagic.com/security/advisories/gm001-ie/

Turns out there is a bug in IE/OL that is a VERY old bug that has not been patched by MS yet, and allows webpage programmers to force your system to run commands, install software, etc. regardless of your security settings. There is a registry change you can do to work around the issue, but man I wish Micro$haft would get on the ball and fix this shit, and that the gov't would pass some digital security rights preventing people from loading anything on your machine without your expressed permission under the penalty of getting a swift kick in the balls.
Meltdown is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 04-16-2004, 05:29 PM   #2 (permalink)
Eye
Member
 
Eye's Avatar
 
Join Date: Apr 2004
Location: I now live in Chile, south america and have done for the past year and a half
Posts: 56


Talking

lol,

man, if i could electronically kick someone in the balls, then you would probably see the worlds populatoin rise come to a screeching halt.
Eye is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 04-16-2004, 06:14 PM   #3 (permalink)
GroovyDude
Senior Member
 
GroovyDude's Avatar
 
Join Date: Apr 2004
Location: South Florida
Posts: 331


A little off topic, but what the hey...

For Windows I use MYIE2 which adds tab navigation to IE and includes a pop-up blocker which has been working great for me. There are all sorts of cool plugins and skins available for MYIE2 as well.

It's free:

http://www.myie2.com

If you don't like IE, I recommend trying the Firefox beta from http://www.mozilla.org which is what I use on my linux box and laptop, but a windows version is also available.
GroovyDude is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Sponsored links
Old 04-16-2004, 06:21 PM   #4 (permalink)
Packetloss
Senior Member
 
Packetloss's Avatar
 
Join Date: Mar 2004
Posts: 706


a lot of those free wonderful tools are tools for this crap anyways - Be careful
__________________
"Computer games don't affect kids; I mean if Pac-Man affected us as kids, we'd all be running around in darkened rooms, munching on magic pills and listening to repetitive electronic music."

-- Kristian Wilson, Nintendo, Inc. 1989
Packetloss is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 04-16-2004, 08:31 PM   #5 (permalink)
GroovyDude
Senior Member
 
GroovyDude's Avatar
 
Join Date: Apr 2004
Location: South Florida
Posts: 331


Quote:
Originally Posted by Packetloss
a lot of those free wonderful tools are tools for this crap anyways - Be careful
Yes, you do have to be careful. Here's a cool link for checking if that free download includes free spyware as well.

http://www.spychecker.com/
GroovyDude is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 04-16-2004, 08:46 PM   #6 (permalink)
toetag
Toot_Yes_Shower_No: Admin
 
toetag's Avatar
 
Join Date: Mar 2004
Location: PA
Posts: 797


if you want to detect spyware get 2 programs

spybot s&d for the lightweight stuff and go downlaoda 3 day trial of Netcop for the serious shit.

Another thing you can do is get nav 2004 with spyware detection.

Beleive me I know about this kind of stuff weeks and months before most people because I sell SPYWARE.....oooooooohohhhhhhhhhh! :p
toetag is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 04-16-2004, 08:58 PM   #7 (permalink)
toetag
Toot_Yes_Shower_No: Admin
 
toetag's Avatar
 
Join Date: Mar 2004
Location: PA
Posts: 797


there are laws that protect you.

If you own the computer and you call local law enforcement they can foresically determine that kind of stuff. (is it realy worth it to have the police raid your mp3 closet?) however, there are things you can do to protect yourself.

Get behind a firewall.
Most malicious software is not entirely run thry ie or html for that matter. Somewhere there is an app running, service renamed, or a .ocx .dll file thats gonna need to access the internet at one time or another.

if you lock it right it can log your pc all day long, but never access the internet to send information.

Get behind a router.
Another thing to consider is getting behind a router and close some ports. let the normal ports stay open, but make sure you have no high range ports open that you do not know about.

I work for the #1 Software Manufacturer of Internet monitoring software. I know just about every trojan,malware,spyware,and monitoring software made and know this kind of crap.

If you want to rid malware and spyware, loct the pc down.

Long Live MMC! :eek:
toetag is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 04-16-2004, 10:08 PM   #8 (permalink)
don_xvi
Junior Member
 
Join Date: Apr 2004
Location: Outside Detroit
Posts: 23


Interesting topic, actually!
So you're saying I need to run a firewall (I liked zonealarm back when) IN ADDITION TO being behind my router? Because I guess I can't count on my NAV keeping all the bad apps out.... it makes sense to me now, do I have it right?
Thanks!
don_xvi is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 04-16-2004, 10:19 PM   #9 (permalink)
Horsepower
Administrator
 
Horsepower's Avatar
 
Join Date: Mar 2004
Location: Port St. Lucie, FL
Posts: 4,634


basically...hardware firewall stops the incoming stuff, software firewall(zonealarm) stops the stuff from going out. say u download a file that contains a trojan. u unknowingly install it. that trojan can phone home easily if u dont have a software firewall installed.

why do i have the feeling that Packet will be by to tell us we're all noobs?
Horsepower is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Old 04-16-2004, 10:43 PM   #10 (permalink)
Packetloss
Senior Member
 
Packetloss's Avatar
 
Join Date: Mar 2004
Posts: 706


Hrm. Mixed emotion here - Everyone will have an opinion, mine may or may be more or less correct than the next yokel.

However, my 2 cents?

*Always* be behind nat - Network address translation - In the home world this is a 'router' - I dont care if you have a oc3 at the office or dialup - ALL users should be nat'd.

However - Should the average dork run a local firewall? no. you'll end up asking people like me all day what 'port 80 packets are for - am i getting attacked?' 'Why am i seeing all the port 53 udp?' blah blah blah - unless you know what the typical services and ports are, and how to properly manage them, screw it - You're going to have more problems than its worth, and you're going to think you're behing hacked every time your isp scans you, or you see some funny UDP.

Does this make you vulnerable? Maybe. Most spyware writers these days are using the above IE trickery - If i have you pull a file that replaces mplayer.exe, then trigger mms:// that then talks on port 80, or 53/udp, how will you ever know?

Security is not a tool, its a mindset. Run popup blocker (google toolbar is rad). Remember that NOTHING is free - Be it porn, spy scanners, or video games - If its free, it most likely has something embedded in it.

So, know where you're going, bock pops (most exploits/etc = via popunders), and always look over your shoulder - And remember - NOTHING IS FREE, and you'll be just as secure if you ran some zonealarm crap, and paniced 30 times a day about every packet it traps.

....However - If you know what you're doing, and are willing to take the time and develop working rulesets, and remove any bugs you may have - 'help! bfv server browser doesnt work anymore, and ive reinstalled 18 times!' comes to mind (I'll leave this person anonymous) - A firewall is a good tool.

...make sense?
__________________
"Computer games don't affect kids; I mean if Pac-Man affected us as kids, we'd all be running around in darkened rooms, munching on magic pills and listening to repetitive electronic music."

-- Kristian Wilson, Nintendo, Inc. 1989
Packetloss is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Stumble this Post!
Reply With Quote
Sponsored links
Reply



Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
social security ASH...HOUSEWARES Off Topic Discussion 1 03-20-2006 06:50 AM
home security system SSG Big Daddy Off Topic Discussion 10 12-20-2005 05:51 PM
Wireless security? Pvt m0nes Help Me! 22 09-24-2005 05:48 PM
Heads Up - Security Flaws in Firefox Browser Horsepower Help Me! 3 05-13-2005 08:04 PM
Social Security Fix ASH...HOUSEWARES Off Topic Discussion 16 02-12-2005 10:41 PM


All times are GMT -4. The time now is 05:41 PM.
Powered by vBulletin® Version 3.6.11
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.0.0
Ad Management by RedTyger Skin Purchased from CompletevB


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103