Tuesday, November 14, 2006

Virus dances onto Mac OS X

Macarena more embarrassment than threat !

Malware authors have created a proof-of-concept virus that's capable, in theory at least, of infecting Mac PCs running OS X. The
Macarena virus isn't spreading and even in the highly unlikely event your Mac catches the infection it doesn't do any real harm.
The low-threat pathogen Illustrates the point that Macs, just like Linux boxes, aren't immune from computers viruses even though incidents of infection on these machines remains as rare as finding hen's teeth. Windows machines have for years been the principal target for virus writers and there's no sign that will change anytime soon, if ever.

Mac viruses were relatively common at the dawn of personal computing, but these days the overwhelming majority of viruses are Windows specific. Macarena isn't the first piece of malware capable of infecting Mac OS X machines. Of the handful of Mac OS X pathogens ever created only the Leap Trojan has been spotted in the wild.

Tags : , , .

Tuesday, October 03, 2006

Hacking via google

An old set of hacking via google .. !!

"http://*:*@www" domainname
This is a query to get inline passwords from search engines (not just Google), you must type in the query followed with the the domain name without the .com or .net"http://*:*@www" blabla or "http://*:*@www"blabla Another way is by just typing"http://bob:bob@www"
Click here for the Google search ==>

"http://*:*@www" bob:bob

index.of.password
These directories are named "password." I wonder what you might find in here. Warning: sometimes p0rn sites make directories on servers with directories named "password" and single html files inside named things liks "horny.htm" or "brittany.htm." These are to boost their search results. Don't click them (unless you want to be buried in an avalanche of p0rn...
Click here for the Google search ==>

index.of.password

"access denied for user" "using password"
Another SQL error message, this message can display the username, database, path names and partial SQL code, all of which are very helpful for hackers...
Click here for the Google search ==>

"access denied for user" "using password"

"AutoCreate=TRUE password=*"
This searches the password for "Website Access Analyzer", a Japanese software that creates webstatistics. For those who can read Japanese, check out the author's site at: http://www.coara.or.jp/~passy/Note: google intitle:"website to find the results of this software.
Click here for the Google search ==>

"AutoCreate=TRUE password=*"

passlist.txt (a better way)
Cleartext passwords. No decryption required! Click here for the Google search ==>
inurl:passlist.txt

Thursday, September 28, 2006

Unpatched PowerPoint Flaw Under Attack

A flaw in Microsoft Powerpoint
Microsoft's summer-long struggle to lock down gaping holes in its Office software suite has once again escalated with the discovery of a new zero-day attack targeting PowerPoint users.
ADVERTISEMENT
The Redmond, Wash., software maker confirmed reports from anti-virus vendors that another round of "extremely limited attacks" is exploiting a previously unknown PowerPoint vulnerability.
The e-mail-borne attack, which uses rigged .ppt attachments, is being used to plant a Trojan dropper on infected Windows machines.
According to an advisory from Symantec, the malicious file injects itself into several computer processes and uses rootkit techniques to hide its files and process.
It opens a back door and connects to Web sites hosted at the 6600.org and 9966.org domains, allowing a malicious hacker full control of the target machine.
The file names of the rigged PowerPoint files are "FinalPresentationF05.ppt," and "2006-Jane.ppt," according to Symantec's alert.
The tactics appear identical to a recent wave of zero-day PowerPoint exploits that experts believe are linked to corporate espionage in the Far East.
Symantec said the targeted attack could be used to perform network reconnaissance, search for files, download and upload files, create and remove folders, execute commands or update registry entries.
McAfee, an anti-virus software vendor in Santa Clara, Calif., said the exploit was aimed at "a single target," further confirming that the recent exploits against Microsoft Office users are part of well-targeted attacks.
A spokesperson for Microsoft said the company's investigation has concluded that the vulnerability affects users of Microsoft Office 2000, Microsoft Office 2003 and Microsoft Office XP.

"In order for this attack to be carried out, a user must first open a malicious Microsoft PowerPoint document that is sent as an e-mail attachment or otherwise provided to them by an attacker," the spokesperson said.
He said Microsoft is aware of an attack scenario that involves malware known as "Win32/Controlppt.W" and "Win32/Controlppt.X," and has added detection and removal signatures to its free Windows Live OneCare safety scanner.