• TalkBass has been independent since 1998. Add your voice.
    Create a free account to reply to discussions, view embedded media, and browse with fewer display ads.
    Join freeLog in
    Want zero display ads or expanded classifieds tools? Compare plans.

MALWARE--> http://results.google-analytics.com/ <--MALWARE

Do you take Wi-Fi-equipped devices to public places?

Have you ever experienced having your Internet connection suddenly hang, run rough, and then carry on--kinda like someone having trouble shifting gears on a standard? Then it might have been because of...

Man-in-the-middle attacks

"A man-in-the-middle attacker entices computers to log into a computer which is set up as a soft AP (Access Point). Once this is done, the hacker connects to a real access point through another wireless card offering a steady flow of traffic through the transparent hacking computer to the real network. The hacker can then sniff the traffic. One type of man-in-the-middle attack relies on security faults in challenge and handshake protocols to execute a “de-authentication attack”. This attack forces AP-connected computers to drop their connections and reconnect with the cracker’s soft AP. Man-in-the-middle attacks are enhanced by software such as LANjack and AirJack, which automate multiple steps of the process. What once required some skill can now be done by script kiddies. Hotspots are particularly vulnerable to any attack since there is little to no security on these networks."

:eyebrow:

The above is an excerpt from: Wireless security
 
What is a firewall and why do I need one?

"A firewall is a software and/or hardware tool for defending a computer or network of computers, from attacks via the network performed by malicious or curious computer users. It protects by restricting what hostile computers are permitted to do to the protected computers. It does this by filtering and blocking the network communication between the protected computers and the Internet at large.

With the arrival of fast, permanent, 24 hour/7 day, internet connections for home users, your computer is now exposed to constant attacks from anywhere in the world. You may ask yourself "why would anyone want to break into my computer? I don't have anything important". Actually you do, even a home computer stores usernames and passwords for connecting to the internet, personal email, possibly financial information and perhaps even credit card information. Even without these things, your computer can be used as a stepping stone by malicious users (often called 'crackers') to attack other computers. The worst part of this is that these further attacks will look like they are coming from you!..."[/QUOTE]

If you have an extra system, and a couple of nics this is a great firewall to run... Been using it for a while with great results plus the have a good modification community.

[Invalid or Expired Link Removed]
 
A man-in-the-middle attack won't *reach* to your computer. As the description says, the hacker will be able to sniff the traffic - namely, read what is happening on your network connexion.

Not doing your online banking in a cafe sounds like a good start. :p
 
A man-in-the-middle attack won't *reach* to your computer. As the description says, the hacker will be able to sniff the traffic - namely, read what is happening on your network connexion.

Not doing your online banking in a cafe sounds like a good start. :p

Correct. And this would include the passwords to every on-line account from TalkBass :eek: to one's e-mail:

[Invalid or Expired Link Removed]

BTW. Given the increasing incidence of router hijacks (as discussed earlier in this thread), it would be prudent to make sure that the DNS (Domain Name System) settings one's router is using are legitimate and that said router is secured with a very strong password.

Otherwise one could become the victim of a 'man-in-the-middle-attack' without leaving one's home.

One can vet the DNS settings one's router is using via:

WHOIS Lookup and Domain Name Search

Said DNS settings should be the ones which were provided by one's ISP.

If they are something else, like say.., these two...

Time: Aug 20 22:04:20 Source: 213.109.65.90 Destination: 192.168.0.180 In IF: eth1 Out IF: Port: 53 Length: 87 ToS: 0x00 Protocol: ICMP Service: DNS

Time: Aug 20 22:05:39 Source: 213.109.73.246 Destination: 192.168.0.180 In IF: eth1 Out IF: Port: 53 Length: 94 ToS: 0x00 Protocol: ICMP Service: DNS

...which my *neighbour's router is set to, then 'Houston, we have a problem'...

*I've repeatedly warned them but they've chosen to ignore me in favour of playing Farmville on Facebook. :rolleyes:
 
"Are you a power-user with 5 minutes to spare? Do you want a faster internet experience?

Try out namebench. It hunts down the fastest DNS servers available for your computer to use. namebench runs a fair and thorough benchmark using your web browser history, tcpdump output, or standardized datasets in order to provide an individualized recommendation. namebench is completely free and does not modify your system in any way. This project began as a 20% project at Google.

namebench runs on Mac OS X, Windows, and UNIX, and is available with a graphical user interface as well as a command-line interface."

%5BUNSET%5D.jpg


%5BUNSET%5D.jpg


[Invalid or Expired Link Removed]

Please note: while the "sudo add-apt-repository ppa..." works, the 'Download Ubuntu 10.04 Lucid 32/64 bits' link to namebench 1.3.deb does not.

However, one can download namebench_1.3.1~lffl~lucid~ppa_all.deb from this link.

A YouTube video:

Find the Fastest DNS Servers using NameBench by Britec
 
Surely, the guys from Nizhniy Novgorod, Pecherskiy syezd 22 in Russia can't be bad company :p

Hey, for all I know Nizhny Novgorod resident Nikolay N. Filimonov is a great guy! *waves* :D

800px-Nizhny_Novgorod_Circus.jpg


I just don't want him doing a reach-around on my neighbours router :eek:--especially since I started sliding them a few bucks to Wi-Fi onto their 'Net connect with my Ubuntu machines at the beginning of the month. (Why pay full price for something I only use part time I asked myself ever-so-naively? :rolleyes:)

Anyway, about an hour ago my neighbour's wife dropped off the Link Removed Windows-XP-is-the-end-of-the-line-for-this-baby PC I gave her husband early last month. He received it as an Edubuntu 10.04 box which ran smartly :), and I just got it back as a crippled POS Windows 7 Ultimate machine :atoz:--[DEL]running[/DEL] crawling an invalid install of Windows... :eyebrow:

Only 13% into an on-line, Windows Live OneCare safety scanner scan, and it's already registering "25 items detected, 7 issues found". :spit:

It too bad that every new virus a Windows machine acquires during a Facebook session wouldn't manifest itself as a cow paddy in Farmville. :D

BTW. In contrast to the above, my up-to-date Ubuntu 10.04.1 boxes augmented with...

- Adblock Plus 1.1.3
- Beef Taco 1.3.1
- BetterPrivacy 1.48.3
- Flagfox 4.0.8
- Ghostery 2.2.1
- NoScript 2.0.2.3
- Redirect Cleaner 1.3.0
- and WOT 20100503

...are all doing fine--for now... *crosses fingers* :ninja:
 
Invalid Link Removed

"A new variation on the Fake Anti-Virus scam actually launches legitimate uninstallers of anti-virus programs from Symantec, Microsoft, AVG and others.

The phony anti-virus scam keeps getting new wrinkles, the latest being a pop-up Anti-Virus alert that warns users that their security program is uncertified and must be replaced. When the alert is clicked, it launches the user's legitimate anti-virus uninstall program.

As Invalid Link Removed. The pop-up's close button is as malicious as its OK button.

Symantec notes that the Trojan carries uninstall launchers for "Symantec, Microsoft, AVG, Spyware Doctor, and Zone Labs." I would imagine that it won't be long before other security vendors find their products' uninstallers added to the payload..."

--------

How to remove various kinds of fake anti-virus programs on Windows machines:
http://www.bleepingcomputer.com/virus-removal/
 
From Firefox Support Forum poster 'cheepgeeze...'

Posted August 22, 2010 11:33:41 PM PDT:

"This redirection seems to be a router or DNS problem - buggered up by internet buttheads. Be nice if/when the footprint can get figured out by the antivirus companies and we can get a real fix/pteventive dat for it.

Now, listen closely - in XP go to START/Control Panel/Network Connections/(right mouse on the connection that's malfunctioning(properties)/TCP/IP (Properties) and now, click the "Use the following DNS Server addresses" button. Set Preferred to 208.67.222.222 Set Alternate to 208.67.222.220

Bingo, system shoots around the re-directs and works fine. You may get it back to working status by a hard reset and re-set-up of your router if you use one. Good luck. It worked for me. If you use Vista or Win7 I suppose the same type method would work."

Invalid Link Removed

EDIT:

Here are the whois searches of the DNS addresses suggested by 'cheepgeeze...': 208.67.222.222 and 208.67.222.220 both of which resolve to OpenDNS who offer a range of commercial and free DNS services.

Here are some other options offered as Ubuntu how-to's:

How To Change Your DNS Address In Ubuntu 10.04 Lucid Lynx
Invalid Link Removed

--------

Configure Ubuntu 10.04 Lucid Lynx To Use Google Public DNS
Invalid Link Removed

--------

Configure Ubuntu 10.04 Lucid Lynx to Use Comodo Secure DNS
Invalid Link Removed

--------

The Perfect Parental Control For Ubuntu 10.04 Lucid Lynx
Invalid Link Removed

BTW. Under Ubuntu these and any other web pages can be printed to .pdf files from Firefox by:

- Selecting and copying the web page's title to the clipboard (the name can't include '/' or other illegal characters)
- In Firefox click File-->Print
- In the pop-up dialog box's General tab click Print to File
- Output format: PDF
- Paste the web page's name into the name box to the left of the .pdf file name extension
- Click the Print button and your .pdf file will be printed to the root level of your Home folder.
 
"Is your browser configuration rare or unique? If so, web sites may be able to track you, even if you limit or disable cookies. :eek:

Panopticlick tests your browser to see how unique it is based on the information it will share with sites it visits.

Click below and you will be given a uniqueness score, letting you see how easily identifiable you might be as you surf the web.

Only anonymous data will be collected by this site.

Click here to test how trackable your browser is..."
 
Invalid Link Removed
By Joab Jackson, IDG News

"Canonical and Mandriva have both released advisories of this vulnerability, as well as updated their software to a fixed version. Red Hat has not updated this flaw, according to the company website.

Included in most Linux distributions, the GNU Wget is a program that can retrieve Web pages and other Internet files. A widely used command line tool, it is often embedded in scripts and programs for automatically downloading large numbers of Web pages, which can be useful for indexing the Web. It also works with FTP (File Transfer Protocol).

Versions 1.12 and older possess a vulnerability that attackers could use to inject malicious code into the host machine running the software. As the software downloads a file, the server provides it with a file name that can be substituted with a pointer to a file with executable code, which, in turn, can overwrite an existing file or be inserted into the start-up routine..." :eek:

--------

"The Openwall Project is a source for various software, including Openwall GNU/*/Linux (Owl), a security-enhanced operating system designed for servers. Openwall patches and security extensions have been included into many major Linux distributions.

As the name implies, Openwall GNU/*/Linux draws source code and design concepts from numerous sources, most importantly to the project is its usage of the Linux kernel and parts of the GNU userland, others include the BSDs, such as OpenBSD for its OpenSSH suite and the inspiration behind its own blowfish-based crypt for password hashing, compatible with the OpenBSD implementation..."
 
AVG LinkScanner

"You might be asking whether all these great things will slow down your PC and prevent you from doing all the fun things you normally do. The answer is NO.

* It's the only product that scans every web page just before you get there in real time, so it can identify short-lived threats.
* It doesn't rely solely on a blacklist of bad sites that can quickly go out of date.
* It can't be identified by poisoned websites, so they can't take evasive action.
* It doesn't rely on opinion - it looks at what's really on the web page.
* It's quick and easy to install.
* It works unobtrusively in the background and doesn't slow your PC down.
* It works smoothly alongside other major brands of security software.
* It's completely free."
 

Latest posts