|
-
January 9th, 2009, 08:36 AM
#7
Nothing comes for free.. Not even on the internet.. 
As far as the war and all that goes.. it sucks ..
I mean the minute Israel started their campaign against Gaza.. I could see cyber war start..
I also cannot forget after 26/11 attacks on Mumbai.. there were site's asking for donation for the injured but were actually infected and bla bla bla..
I don’t ever trust *users* to understand where to click and where not to click (hey we have click and hack software’s.. so if admins are dumb enough, you can’t expect a user to be smart [enough])..
In general block of stuff you KNOW is malicious (even if it doesn’t show signs of being malicious at the point of time) .. Here is an example :
http://isc.sans.org/diary.html?storyid=5638
Over the weekend another site popped up, www.help-israel-win.com which is down at the moment. According to what was posted on the site, it was built by "a group of students who are tired of sitting around doing nothing".
The embedded IRC client uses a well known (and legitimate) IRC client library SmartIrc4net. The binary has some commands embedded as well, which can help distinguish what it can do:
.connect
.close
.stop
.hide
.show
.update
.version
.refresh
.platform
.memory
.cpu
.login
Finally, it can retrieve a remote file and save it on the local machine as TmpUpdateFile.exe – certainly sounds fishy.
While at the moment it does not appear to do anything bad (it just connects to the IRC server and sites there – there also appeared to be around 1000 machines running this when I tested this) the owner can probably do whatever he wants with machines running this.
The uninstall process seems to be correct, as the author(s) say on the web page, but it is questionable if the binary will download something else.
In any case, and as always – be careful what you download and run on your machine, especially if it's coming from unknown sources that you can't trust.
Lastly, although I feel sad (in a way) saying this: Don't trust Indian Media.. Living in Mumbai and being cought up in the recent attacks I know what i'm saying..
Last edited by ByTeWrangler; January 9th, 2009 at 08:38 AM.
Parth Maniar,
CISSP, CISM, CISA, SSCP
*Thank you GOD*
Greater the Difficulty, SWEETER the Victory.
Believe in yourself.
Similar Threads
-
By Tedob1 in forum Cosmos
Replies: 9
Last Post: May 7th, 2006, 05:06 AM
-
By Networker in forum Miscellaneous Security Discussions
Replies: 5
Last Post: May 7th, 2003, 05:53 PM
-
By Mallam in forum Cosmos
Replies: 1
Last Post: July 25th, 2002, 02:31 PM
-
By drew_1791 in forum AntiOnline's General Chit Chat
Replies: 3
Last Post: July 5th, 2002, 06:01 AM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|