Showing posts with label dangerous. Show all posts
Showing posts with label dangerous. Show all posts

Thursday, May 31, 2012

The Flame Virus


What makes Flame so unusual is its size. It's much larger than some of the largest malware instances that researchers have found. For instance, the infamous Stuxnet virus that was targeted at Iran’s uranium enrichment facilities several years ago was 500 kilobytes, according to Wired.
“Flame is a sizable beast," said Graham Cluley of Sophos Security, a publisher of digital security software. "With all its components in place, it's approximately 20MB. And this is one of the reasons why people have bandied phrases around like 'biggest' and 'most sophisticated.' Reverse engineering 20MB of code is a sizable piece of work."
Researchers have only scratched the surface of what is hidden in all that code. Stuxnet (and its sister DuQu) took researchers months to figure out exactly what it did and where it might have come from. Flame will take a lot longer.
Table comparing Flame and Stuxnet from CrySyS at Budapest University of Technology and Economics
Flame, at its core, is spyware. It has the ability to log key strokes from an infected user’s computer, use the computer’s sensors such as the microphone and Web cam to record what is being said around it, and take screenshots. It can also sniff a network to steal passwords, be spread through USB drives and local networks, and transfer data to command-and-control servers. It can infect Windows XP, Vista and Windows 7 computers.
This is not your ordinary spyware, though. While it does have some simple and basic elements of spyware (which can key log and use the microphone as well), its sheer girth betrays a more sophisticated approach.
Normal spyware is not hard to detect. It is usually some type of derivation of existing malware that has been repurposed by hackers and distributed through normal channels such as spam or infected websites. Antivirus companies such as Symantec (Norton), Kaspersky, Sophos, Bitdefender and others recognize the spyware shortly after it is discovered and issue a detection kit for it. Microsoft then comes out with a patch and the cat-and-mouse game between the malware writers and security companies goes on. To a certain extent, this is what has happened with Flame. Detection and removal kits have already been released by security companies including Sophos and Symantec, as well as the Iranian government.
But the size and uniqueness of Flame may prove to be more than the antivirus companies realize. Right now, the detector kits are looking for specific instances within the Flame code to help detect the virus. For instance, code samples with “flame” or “wiper” are detected and blocked. The thing is, Flame is not exactly new. It has been in the wild for more than five years, perhaps in varying forms that have been added to over time. Much of Flame may have been compiled in 2011, but bits of it may be older. Flame’s ability to avoid detection over time speaks to its unique properties. Those properties could also speak to its source.
Flame also uses a unique programming language to the malware world: Lua. Lua is used primarily by game developers to create cross-platform applications for iOS and Android. It is similar to C++ but easier to update and communicate with.
“Lua is normally used for convenience," said Liam O Murchu, operations manager of Symantec Security Response. "As a scripting language it is much more high-level than C++ and it is easier to write in. Also, it is very easy to update the Lua part of the code and change the behavior of the threat in a very fluid and fast way. Often the Lua portion can be updated without recompiling and redeploying the software in question.”
Flame (sKyWIper) startup sequence from CrySyS
Flame is well organized in how it communicates and translates data. In an infected machine, it can perform a variety of tasks including wiping out its own existence as well as any other malware on the machine. This is a tactic used by other sophisticated viruses – becoming their own antivirus programs – presumably because other, less sophisticated viruses could lead to the discovery of Flame itself. When Flame retrieves data, be it key logs or screen shots, it uses high- and low-level encryption and HTTPS to send data back to its command-and-control servers. That data is then organized into its database through MySQLite, a smaller version of MySQL database software.
In a nutshell: Flame can control almost every aspect of the computer, disappear without a trace, encrypt its own communications and organize the data it collects. That is one smart virus.
It is so large and smart that researchers have concluded that this was not created by a random group of hackers looking to make some money. (Now that its code is out in the wild, though, that may be part of its future.)
“The results of our technical analysis supports the hypotheses that sKyWIper [Flame] was developed by a government agency of a nation state with significant budget and effort, and it may be related to cyber warfare activities,” stated a technical report from the Laboratory of Cryptography and System Security (CrySyS) at Budapest University of Technology and Economics. 
Should average computer users worry about Flame? The short answer is no. Kaspersky Labs, which initially reported on Flame, only found several hundred instances of Flame among its client base, most of them in Iran and Middle Eastern countries. Whoever created Flame has been aiming it at specific targets, perhaps knowing that a virus like this left unchecked in the wild could do serious damage.
“I think run-of-the-mill malware is a much more significant threat to the vast majority of computer users than Flame,” Cluley said. “We have had zero reports of Flame from any of our customers' computers worldwide. Even Kaspersky, who appeared in the first media reports of Flame, only reported a couple of hundred infected PCs. Flame pretty much became the malware you didn't have to worry about because of the media hoopla and antivirus products being updated in the last 36 hours or so. You imagine that whoever was behind Flame is now pretty grumpy about their malware attracting so much attention.”

Posted By R8:24 AM

Tuesday, December 27, 2011

download windows 8 ISO file ( 32 bit & 64 bit)

download windows 8 ISO file ( 32 bit & 64 bit)

                                           Windows 8 is the codename for the next version of the Microsoft Windows computer operating system following Windows 7.[3] It has many changes from previous versions. In particular it adds support for ARM microprocessors in addition to the previously supported x86 microprocessors from Intel and AMD. A new Start Screen interface has been added that was designed for touchscreen input in addition to mouse, keyboard, and pen input. It is said to be released sometime around 2012[citation needed]. Microsoft has yet to announce the release date.


iso file download please click below
   32 bit iso   (2.8gb)

ilestone leaks

A 32-bit Milestone 1 build, build 7850, with a build date of September 22, 2010, was leaked to BetaArchive, an online beta community, which was soon leaked to P2P/torrent sharing networks on April 12, 2011.[6] Milestone 1 includes a ribbon interface for Windows Explorer,[7] a PDF reader called Modern Reader, an updated task manager called Modern Task Manager,[8] and native ISO image mounting.[9]
A 32-bit Milestone 2 build, build 7927, was leaked to The Pirate Bay on August 29, 2011[10] right after many pictures leaked on BetaArchive the day before.[11] Features of this build are mostly the same as build 7955.[12]
A 32-bit Milestone 2 build, build 7955, was leaked to BetaArchive on April 25, 2011.[13] Features of this build included a new pattern login and a new file system known as Protogon.[14]
A 64-bit Milestone 3 build, build 7959, was leaked to BetaArchive on May 1, 2011.[15] This build is notable for being the first publicly leaked Windows Server 8 build, as well as the first leaked 64-bit build.
A Milestone 3 build, build 7971, was released to close partners of Microsoft on March 29, 2011[16] but was kept under heavy security. However, a few screenshots were leaked. The "Windows 7 Basic" theme now uses similar metrics to the Aero style, but maintains its non-hardware accelerated design, and also supports taskbar thumbnails. The boxes that encase the "close, maximize, and minimize" buttons have been removed, leaving just the signs.[17]
A 64-bit Milestone 3 build, build 7989, leaked to BetaArchive on June 18, 2011 after screenshots were revealed the previous day. An SMS feature, a new virtual keyboard, a new bootscreen, transparency in the basic theme, geo-location services, Hyper-V 3.0, and PowerShell 3.0 were revealed in this build.[18]

Official announcements

At the Microsoft Developer Forum in Tokyo on May 23, 2011, Microsoft CEO Steve Ballmer announced that the next version of Windows would be released the following year.[19]
"And yet, as we look forward to the next generation of Windows systems, which will come out next year, there's a whole lot more coming. As we progress through the year, you ought to expect to hear a lot about Windows 8. Windows 8 slates, tablets, PCs, a variety of different form factors."[19]
However, Microsoft quickly amended Ballmer's words in a statement issued that afternoon:
"It appears there was a misstatement. We are eagerly awaiting the next generation of Windows 7 hardware that will be available in the coming fiscal year. To date, we have yet to formally announce any timing or naming for the next version of Windows."[20]
On June 1, 2011, Microsoft officially unveiled Windows 8 and some of its new features at the Taipei Computex 2011 in Taipei (Taiwan) by Mike Angiulo and at the D9 conference in California (United States) by Julie Larson-Green and Microsoft's Windows President Steven Sinofsky.[21][22] The main feature that was shown was the new user interface.
On August 15, 2011, Microsoft opened a new blog called "Building Windows 8" for users and developers.[23]

Posted By R7:57 AM

Merry Christmas Virus

Merry Christmas Virus

The Merry Christmas virus is an email worm that started to emerge before Christmas of 2004. The worm spread via electronic mail as a small, executable file with a variety of names and extensions. The worm propagated by copying itself onto local and networked drives, as well as emailing itself as an attachment to any addresses it could harvest from the address book and files stored on the infected machine.
When executed, an infected file copies itself into the Windows system directory and registry disguised with the name “NortonUpdate.exe.” The registry entry ensures that a copy of the worm is launched each time the infected machine is booted. It also creates files in the system directory that are used to store the email addresses harvested from the Windows address book, text documents, web pages, emails and mailboxes stored on the machine.

Infected email messages are sent in a variety of languages depending on the geographical location of the recipient’s domain name. The messages arrive with the subject “Merry Christmas!” and body “Happy Holidays!” in the corresponding language. The attachment has the name “postcard” in the particular language, followed by a long string of random characters that obscure an executable extension.
The seemingly harmless text lures victims into downloading the attached file that is disguised as a holiday postcard.
Besides replicating furiously, the worm also opens a backdoor on infected systems that provides unauthorized remote access by malicious parties. This allows attackers full access to any stored personal information, along with the ability to download and launch files remotely on a victim’s machine. Furthermore, the worm bypasses installed security measures such as firewall or antivirus programs by overwriting their application files with an infected executable. Thus, while an email message may appear harmless, even one execution of an infected attachment can cause significant damage that is difficult to reverse.

 

Posted By R7:01 AM

Sunday, December 11, 2011

The 8 Most Dangerous Computer Viruses In History


The 8 Most Dangerous Computer Viruses In History

 

1 ) Jerusalem – 1987
This is one of the first MS-DOS viruses in history that caused enormous destructions, affecting many countries, universities and company worldwide. On Friday 13, 1988 the computer virus managed to infect a number of institutions in Europe, America and the Middle East. The name was given to the virus after one of the first places that got “acquainted” with it – the Jerusalem University.
Along with a number of other computer viruses, including “Cascade”, “Stoned”, “Vienna” the Jerusalem virus managed to infect thousands of computers while still remaining unnoticed. Back then the anti-virus programs were not as advanced as they are today and a lot of users had little belief of the existence of computer viruses.

2 ) Morris (a.k.a. Internet Worm) – November 1988
The Morris worm or Internet worm was one of the first computer worms distributed via the Internet. It is considered the first worm and was certainly the first to gain significant mainstream media attention. It also resulted in the first conviction in the US under the 1986 Computer Fraud and Abuse Act. Once the worm discovers an internet connection, all that it must do is download a copy of itself to that location, and continue running as normal.  Now it has been 7 years since the Worm was defeated, but it is still worth looking at what happened, both in terms of how the program operated, and as to what conditions allowed it to do what it did. With that in mind, there are a number of subtopics of interest.
 
3 ) Solar Sunrise – 1998
Two Californian teenagers took American government by surprise, in 1998, when they intruded and took control of around 500 systems that belonged to the governmental as well as private sector. This was done with the help of a computer virus and the situation was given the name of Solar Sunrise, after an operating system called Sun Solaris. The computers that ran this OS had few weaknesses. US government took the incident as another golden opportunity to blame Iraqis but soon found out that the culprits were no other than their own Americans.
Initially it was believed that the attacks were planed by the operatives in Iraq. It was later revealed that the incidents represented the work of two American teenagers from California. After the attacks, the Defense Department took drastic actions to prevent future incidents of this kind.
 
4 ) Melissa – 1999
The Melissa virus, also known as “Mailissa”, “Simpsons”, “Kwyjibo”, or “Kwejeebo”, is a mass-mailing macro virus. As it is not a standalone program, it is not in fact a worm. Melissa can spread on word processors Microsoft Word 97 and Word 2000 and also Microsoft Excel 97, 2000 and 2003. It can mass-mail itself from e-mail client Microsoft Outlook 97 or Outlook 98.  If a Word document containing the virus, either LIST.DOC or another infected file, is downloaded and opened, then the macro in the document runs and attempts to mass mail itself.  When the macro mass-mails, it collects the first 50 entries from the alias list or address book and sends itself to the e-mail addresses in those entries.
Melissa computer virus was developed by David L. Smith in Aberdeen Township, New Jersey. Its name comes from a lap dancer that the programmer got acknowledged with while in Florida. After being caught, the creator of the virus was sentenced to 20 months in federal prison and ordered to pay a fine of $5,000. The arrest represented a collaboration of FBI, New Jersey State Police and Monmouth Internet.

The 8 Most Dangerous Computer Viruses In History


 
5 ) I Love You – May 2000
This is one of the most dangerous worms ever and spread worldwide in only one night. It infected around ten percent of all internet users, and the monetary loss was around $5.5 billion. The process started when a user received an email with the subject â€Å“ILOVEYOU” and an attachment â€Å“LOVE-LETTER-FOR-YOU.TXT.vbs”. As soon as the file was opened, the virus managed to send its copy to every address present in the Windows Address Book. This worm was written by a Filipino student who was punished as Philippines had no law related to such cyber crimes. Perhaps this incident triggered the creation of European Union’s global Cybercrime Treaty.
 

The 8 Most Dangerous Computer Viruses In History


6 ) The Code Red worm – July 2001
The Code Red worm was a computer worm observed on the Internet  on July 13, 2001. It attacked computers running Microsoft’s IIS web server.  The Code Red worm was first discovered and researched by eEye Digital Security employees Marc Maiffret and Ryan Permeh. The worm was named the .ida “Code Red” worm because Code Red Mountain Dew was what they were drinking at the time, and because of the phrase “Hacked by Chinese!” with which the worm defaced websites.
Although the worm had been released on July 13, the largest group of infected computers was seen on July 19, 2001. On this day, the number of infected hosts reached 359,000. The worm spread itself using a common type of vulnerability known as a buffer overflow. It did this by using a long string of the repeated character ‘N’ to overflow a buffer, allowing the worm to execute arbitrary code and infect the machine.
 
7 ) Nimda – 2001
Nimda is a computer worm, and is also a file infector. It quickly spread, eclipsing the economic damage caused by past outbreaks such as Code Red. Multiple propagation vectors allowed Nimda to become the Internet’s most widespread virus/worm within 22 minutes.  The worm was released on September 18, 2001. Nimda was considered to be one of the most complicated viruses, having up to 5 different methods of infecting computers systems and duplicating itself.
 
8 ) Downadup – 2009
The Downadup worm, also known as Conficker and Kido, has affected 6 million PCs in just the past three days, according to British officials. his malicious program was able to spread using a patched Windows flaw. Downadup was successful in spreading across the Web due to the fact that it used a flaw that Microsoft patched in October in order to distantly compromise computers that ran unpatched versions of Microsoft’s operating system. According to New York Times, conficker has more than 7 million computer systems under its control now. China, Argentina, Brazil, Russia, and India were the main affected nations.


The 8 Most Dangerous Computer Viruses In History



Posted By R1:20 PM