PCCare247.com Blog, PC Care 247 Tech Support Redefined
Showing posts with label Hackers. Show all posts
Showing posts with label Hackers. Show all posts

Thursday, 5 April 2012

6 Deadly techniques waiting to unleash mayhem on Web Applications


PCCare247 Spyware Removal
Hackers Inc. is always working hard to develop new techniques which would allow it to gain unauthorized access to Web applications. But then again somehow in spite of a slew of techniques out there; the ones that really end up standing out are:


SQL injection: Using this technique hackers end up creating database queries by copying Web client input. A one of those scenarios where hackers end up constructing input query strings which if not carefully inspected and if rejected by the application would end up returning confidential data.

Cross-site scripting: In this technique hackers tend to insert scripting code (such as JavaScript or ActiveX) into an input string; thereby causing a Web server to expose sensitive information such as usernames and passwords.

OS command injection: These are applications which tend to create operating system commands from Web input; such as accessing a file and displaying its contents. In a scenario where input strings are not carefully checked, hackers are successful in creating input which ends up displaying unauthorized data or modifies files or system parameters.

Session hijacking: Via this technique hackers end up gaining access to a logged-in session by guessing the contents of a session token based on knowledge of token format. The technique further ends up enabling a hacker to take over a session and access the original user's sensitive account information.

Parameter or URL tampering: Web applications end up embedding parameters or URLs in returned Web pages or otherwise work towards updating cookies with authorization parameters. Hackers can modify these parameters, URLs or cookies and cause a Web server to divulge sensitive information.

Buffer overflows: Application code should always keep a check on the input data lengths to input data doesn't overflow at the end of a buffer and modify adjacent storage. For hackers quickly end up learning about those applications which end up failing in checking for overflows and creating inputs which caused the error in the first place. www.pccare247.com

Monday, 5 March 2012

Beware!! For these processes have a Malicious Intent


Malware RemovalMalware – The term is so synonymous with everything that intends to shred the security of our PC into tatters. But then again, also on a flipside, in spite of the entire hullabaloo, not all malware is malicious in intent and is commonly referred to as spyware; malicious software truly hell bent on infiltrating computers every now and then.

A case wherein hackers end up refining the capabilities of malware, expanding the flux technologies in order to obscure the infrastructure and making it even harder to locate their servers. However, in the recent times recent variants have come out that are able to detect when someone is investigating an activity; in order to respond with a flooding attack against an investigator. In short, malware is becoming stickier on target machines and more difficult to shut down.

So, just in case to prepare PC users better, we ended up preparing a list of processes which need to be watched out for in order to take any malware threat head on. Starting with:

ISASS.EXE
A part of Optix.Pro virus, Isass.exe is also better known as the Optix.Pro Trojan that carries along with it a payload ability to disable firewalls, local security protections and the ability to open a backdoor capability for fairly unrestricted access into a PC. The Trojan was a brainchild of someone by the name of s13az3; who at the same instance also ended up being a part of the Evil Eye Software crew.

NVCPL.EXE
A component of W32.SpyBot.S Worm; Nvcpl.exe is a process that is registered as the W32.SpyBot.S worm (It at the same time is also associated with the Yanz.B worm which again is once again just another name). Taking advantage of the Windows LSASS vulnerability, the process creates a buffer overflow, forcing a PC to shut down. Although not necessarily considered to be a particularly destructive piece of malware, it is a nuisance since it continues to access an e-mail address books while at the same time sending spam to contacts.

CRSS.EXE
Crss.exe is a process-forming part of the W32.AGOBOT.GH worm. The spyware worm is distributed via the Internet through e-mail and acquires the form of an e-mail message, in the hope that a PC user would end up opening the hostile attachment. The worm has its own SMTP engine to gather E-mails from a local computer while at the same instance trying to re-distribute itself. Yet, at the same time in worst case circumstances, the worm also ends up allowing attackers to access a PC while stealing personal data and passwords.

SCVHOST.EXE
A part of the W32/Agobot-S virus family, the scvhost.exe file belongs to the Agobot (aka Gaobot) PC worm family. The Trojan ends up spreading itself via networks and allows attackers to access a PC from remote locations, steal their passwords and along with it all forms of Internet banking and personal data.

SVHOST.EXE
Svhost.exe is a process associated with the W32.Mydoom.I@mm worm. The worm is distributed as an e-mail message and requires a PC user to open a hostile attachment. Using the SMTP engine, the MyDoom worm is known to gather e-mails from a local computer in order to redistribute itself. Further, as it would go, the other payload carried by the process was a denial of service attack on the website of SCO Group. But that’s somehow not it, for the later versions of the worm have also been known to carry out denial of service attacks on other sites, and those popularly being Google and Lycos. http://www.pccare247.com/pc-security/malware-removal.html

Monday, 2 January 2012

How to make online criminals bite the dust?

Geeks, Freaks, Nerds and Weirdos are terms one would associate with a person boasting of an exceptionally high IQ quotient. Sadly, the same qualities would also describe hackers looking to exploit any cyber threat; be it a data breach in a network, data leakage by employees, or extracting data from a lost laptop or a mobile device.

Watch Out!! You may be in line next
With diversity of security attacks recording an unexceptional high across the globe, it is becoming an uphill task for small and medium-sized businesses to assemble the right in-house resources for protecting themselves. So, much so that there has been an uptick in the number of court cases where SMBs (Small and Medium-sized Businesses) were even robbed of six-figure amounts by cyber thieves.

Online Privacy
Scared!! Don’t be!! For as they do say prevention is better than cure, I would recommend you to not to jump the gun and instead stick to these 8 simple credos:
  • Employing a dedicated PC for financial matters related to online banking and bill pay. Refraining from using the same node for sending, receiving emails or surfing the Web. For as it goes Web exploits and Malicious E-mails are considered as two key infection vectors for malware.
  • Taking care and being extra cautious while clicking on links or attachments within emails. Even if you do end up recognizing the sender, confirm the email is authentic before clicking on any links or attachments.
  • Reconcile bank statements on a regular basis with an online bank account or credit-card for immediately identifying abnormal transactions indicative of an account takeover.
  • Cautioning employees against visiting small, hosted websites featuring community forums related to sports, computer games and anything deemed suspicious. All because a majority of community forums are hosted by ISP’s not really serious about securing their portal.
  • Put security protections in place throughout the organization and install regular updates for applications meant to boost the computer’s OS.
  • While visiting a website observe the quality of the site. If the site appears to be quickly put together, lack a browsing disclaimer, it indicates the authors are not liable to any danger to the PC.
  • Be cautious about installing any software (especially software such as download accelerators, spyware removal tools). Don’t click on pop ups asking for a download or execution of otherwise privileged operations. Often such software and pop-ups are malware embedded.
  • Select your anti-virus vendor with a lot of due deliberation, ensuring the application not only provides coverage for key threats but also responds quickly when threats are introduced. Trial versions of the application are a strict NO! Since, viruses introduced after a trial version would end up having an unhindered access to a PC. www.pccare247.com

PCCare247.com Copyright © 2012-2013 by PCCare247 Solutions (P) Ltd.