Posts tagged attack
i hav been recieving constant port scan attack?
2Question : i hav been recieving constant port scan attack?
hey peeps………am usin sygate personal firewall……from past 2 days it has been notifying me about a constant port scan attack(3 to 5 in a day) from a ip 204.16.208.135…..i did a trace back n found the org as FAST COLOCATION SERVICES …….and server name server being SANDY.THEHIDEOUT.NET……..wats this all about…….am i at risk….kindly advice…..thanks
server colocation
Best answer:
Answer by Netasia Solutions
The best thing to do now is make sure your firewall is updated as well as your windows are patched with the latest security patches.
Disconnect your affected PC from the network to prevent it from spreading the attack elesewhere.
Run your antivirus, antispyware to make sure no trojan is been installed that might act as a backdoor to network attack.
Salt increases the risk of heart attack and stroke, the Harvard Men’s Health Watch
0Boston, MA (Vocus) 6 October 2010
The sodium salt causes more than 100,000 American deaths per year, about three times more prostate cancer. Most Americans consume is hidden salt in processed foods, an important reason why most of us much more sodium than we need. The main health effects of eating too much salt increases blood pressure, leading to an increased risk of heart attack and stroke, reports the October 2010 issue of Harvard Mena? S Health Watch.
Although
sodium has an important influence on blood pressure, the scientists do not know exactly how it works. It seems likely that consumption of salt increases blood volume and in turn the additional volume, the kidneys may signal a cascade of effects on hormones and blood vessels that cause increase blood pressure.
Most scientists agree that reducing salt intake lowers blood pressure, reduces the risk of heart attack and stroke, and saves lives. Itâ? S a reason sufficient to shake the salt, but Thereâ? S plus. Even a modest reduction improves the flexibility of blood vessels and reduces loss of urinary albumin, which protects the heart and kidneys. Salt restriction also reduces the risk of kidney stones by reducing the amount of calcium in the urine.
current guidelines, an upper limit of 2,300 milligrams (mg) of sodium per day. They even furtherâ? MGA 1500? For people with high blood pressure (hypertension), middle-aged and older adults, African-Americans, who tend to be particularly sensitive to the effects of salt. Next month, in Part II of the Serie A? Salt and your health? Harvard Mena? S Health Watch will help you achieve your goals for dietary sodium and advice to those goals.
>
clear = “all”
Firewall protection
Trusteer warns protect ISPs and enterprises, consumers face new pharming attack
0New York, NY (openPR) July 24 June 2007
Trusteer announced today that its CTO and security researcher Amit Klein has cracked random and showed a new BIND attack, most Internet users. In this “DNS forgery pharming attack fraudsters can remotely force consumers fraudulent websites, without having to go to a computer or network.
What
DNS and BIND?
When a user enters a domain address such as www.bank.com in the address bar of the browser associated with the operating system file to the IP address with this domain address available to connect users to the site. This is done transparently sending a Domain Name System (DNS) query to a DNS server, which is basically a large collection of domain addresses and their corresponding IP addresses. The DNS server returns a DNS response that contains the IP address of the requested site. The most popular DNS server is now developed BIND (Berkeley Internet Name Domain) and through the Internet System Consortium (ISC) is maintained.
About
RNG BIND
To DNS response forgery, an attack in which the fraudster sends a fake response with an incorrect IP address of the computer to avoid sets a standard BIND DNS security mechanism, based on a randomly generated number. This mechanism prevents fraudsters who do not know the road between the user and the DNS server from forging DNS responses and direct users to the wrong server.
How
RNG BIND can be injured
However, security expert and CTO, Amit Klein Trusteer has a serious flaw implementation of BIND, the fraudsters to efficiently random numbers without the need to create the route between the user control can be predicted, detected, and the DNS server. With this vulnerability fraudsters can remotely forge DNS responses and direct users to fraudulent websites. The fraudulent Web site, the user can access the sign stealing or alter the user’s communication with the site.
can
“This is a devastating attack,” said Small, “through targeted a specific ISP’s DNS server the fraudster simply direct all ISP users tried to a fraudulent website each time the user to access the correct website. There are nothing to do, the user can to prevent the attack. “
DNS manipulation attack is also known as pharming, and this common belief is that fraudsters should not inhibit the user’s computer or the DNS server itself to launch the attack known. This vulnerability enables an attack, pharming works even if the user’s computer and the DNS server is highly secured.
Recommendations
Trusteer advises ISPs and companies use to manage a BIND 9 DNS server in a cache configuration to the latest patch from the ISC. Existing desktop security solutions can not protect against such attacks since DNS forgery pharming does not the user’s computer or the DNS server, but the cached data on the DNS server. Mutual authentication solutions, such as Trusteer report, which strongly authenticates the destination website and prevents access to unauthenticated websites defeat the attack.
More information
Vulnerability to the ISC on 29 June 2007 reports.
A patch has been released 23rd July 2007. Administrators should update 9.2.8-P1, BIND 9.3.4-P1 BIND, BIND 9.4.1-P1 or BIND 9.5.0a6 BIND.
Affected systems: All versions of BIND 9 in the server configuration cache name
CVE: CVE-2007-2926
Trusteer research is available at: http://www.trusteer.com/docs/bind9dns_s.html
About
Trusteer
Trusteer is a privately held company by senior internet security with the special expertise in the enterprise and security of desktop computers, founded. The flagship product, Rapport protects online business “client-side attacks such as phishing, pharming, man, key logging, man-in-the-middle-in browser and all other threats to identity and client-side attacks against financial fraud. Unlike traditional approaches, which provide only partial solutions, revolutionary approach to prevention protects Trusteer control the risks associated with many client threats.
>
clear = “all”
DNS Server
New Pharming Attack Now Exploitable on Microsoft Windows DNS Server
0New York, NY (Business Wire) 13 November 2007
Trusteer announced today that the Microsoft Windows DNS Server vulnerable to a serious error DNS cache poisoning, the immediate execution is allowed pharming attacks on consumers. Attackers could steal user credentials and perform fraudulent transactions with this particular attack mechanism.
The attack was in July this year when Trusteer CTO, Amit Klein popular BIND DNS server cracked random. After these discoveries, the SAI, the consortium behind BIND, released a patch for BIND 9 and declared the end of life requires Version 8. It is now a Microsoft Windows DNS server, part of Windows Server was released in 2003 cracked the same time and is still vulnerable to attack for themselves.
The Domain Name System (DNS) translates domain IP addresses. It is a service consisting of a large number of DNS servers, memory addresses of fields and their associated IP addresses. DNS servers communicate with each other to address information exchange. To avoid message spoofing base their communication on randomly generated transaction IDs.
research published today by Amit Klein CTO Trusteer, discloses a method generated for predicting the transaction ID, Microsoft Windows DNS server. In anticipation of such transaction IDs, attackers can forge DNS messages and push bogus IP addresses in DNS. Accordingly, consumers would be redirected to fraudulent websites each time they try to access legitimate sites. The fraudulent website can be used to steal user data, and perform fraudulent transactions.
“This attack in particular for financial institutions and online retailers,” says Klein. “Hackers can target large ISP networks and direct all users of a particular bank of the network to a fraudulent website. There is nothing to the user or the bank can do to stop to this attack.”
Recommendations
Trusteer advises ISPs and companies that manage a Microsoft DNS server in a cache configuration to the latest patch from Microsoft will apply. existing anti-virus and desktop security solutions can not be against such attacks since DNS cache poisoning is not to protect the user’s computer or the DNS server, but the cached data on the DNS server. Report Trusteer solution for online banks, brokers and dealers who strongly authenticates the destination website and prevents access to unauthenticated websites, defeats this dangerous attack.
More information
The vulnerability in Microsoft was on 30 April 2007 reports.
A patch Microsoft released on 13h November 2007
Systems Affected: Microsoft Windows DNS server (part of Windows 2003 and Windows Server 2000)
Trusteer research is available at: http://www.trusteer.com/docs/microsoftdns.html
About
Trusteer
Trusteer is a privately held company by senior Internet security with specific expertise in the enterprise and security of desktop computers created. The flagship product, Rapport helps online banks, brokers and dealers to the office of consumers to identity theft and financial fraud protected against attacks such as Trojans financial keyloggers, phishing and pharming. Unlike traditional approaches, which provide only partial solutions, revolutionary approach to prevention protects Trusteer control the risks associated with many client threats.
Contact
:
Rakesh Loonkar
Trusteer
+1 (646) 247-5669
# # #
clear = “all”
DNS Server
Is Windows XP Safe Update or the Windows Zero Day Attack? Sch? Be More Secure Online
0Some w RDEN? Say, keep your Windows up to date to keep, is free as required in the newest, worst viruses and the like. Other w RDEN? Say that updating your Windows berbetont?, Unn? Tainable and a waste of time and with the Windows Zero-Day attack, it is safe to use it to update Windows XP? M? You need to your PC Tzen sch?
Microsoft has M possibilities? To detect whether your version of Windows is actually purchased or pirated. With so many copies of pirated Windows on the market, has ben such a move by Microsoft? Required to continue the OS market cornering. For example, if SP 1 (and 2) came out, you had to have an authentic Windows serial code to download the update. Nat? Natural, there are possibilities M? To circumvent this, but it deterred many illegal upgrade to the new service pack. H? You tten a pirated copy of Windows (and the majority were doing), then k? Nntest you a copy of Windows have downloaded SP 2.1, but you w? RDEN completely reinstall and have had m? Glicherweise format in order to . reinstall
If you have an original Windows had serial code that came with the product, you could have just downloaded the packages from the Windows Update servers.
So yes, with a non-pirated copy of Windows is a convenience. However, w RDEN? Remember some released me of a stunning virus that not too long ago, MyDoom. He succeeded his way to the Microsoft Windows Update to find servers. If you have the virus, w? RDEN you have 30 seconds before the computer shuts down. If you have formatted, only to Windows reinstall on with automatic updates (and they are by default) w? You RDEN the virus get back abd now there is the Windows XP zero-day attack, by Windows XP Big Support works on your PC.
Not to mention a large Windows updates are? he time factor. Some updates (especially the first time that you have Windows Update) colossal, and the download speeds are not always on the gr? Ten.
Well, you ask, what exactly is Windows XP update? It is simply Microsoft’s engineers are working hard to fix bugs, problems and backdoors in Windows. What are these problems, you ask? Well, if Microsoft Windows ver? It published not just been a perfect OS. With every version of Windows, it is more and more hi-tech. But it’s always been problems with Windows have been too insecure.
The only way to find zun that Windows is a certain Sicherheitsl? Bridge? chst f? r Sicherheitsl this? Bridge can be exploited. For example, Microsoft with white hat hackers en (the good), Windows-f, right? R infringe one? against hackers to break into a Windows version and it is reported.
F? R a home PC, even f? R a home network, Windows updates are really important. No one wants their computer hacked or are you full of malware. If you have a basic firewall, the Windows Firewall in their own home, you are only a few threats of gesch? Are protected. K windows updates can? Not really help to prevent all attacks, but they prevent k? Can hackers, crackers, viruses and similar penetration of its computers in the network error code in Windows or browser, and currently using Windows Update, is from the new Windows XP in Safe Zero-day attacks.
So to answer the question – should I use Windows Update? The answer is yes. You should also download a system scanner to be sure to make your PC for malware and spyware, which can on your PC without you knowing that, man? Fen berPR?. Click here to scan your PC now.
slow Windows computer a> to the speed of your computer now only click here a> p>
Flash Drive to US-led cyber attack
0Flash drive led to US cyber attack
The most significant breach of US military computers was caused by a flash drive inserted into a US military laptop on a post in the Middle East in 2008.
Read more on Hindustan Times
Pentagon computer with flash drive attack – Army News | News from Afghanistan and Iraq – Army Times
0Pentagon computers attacked with flash drive – Army News | News from Afghanistan & Iraq – Army Times
WASHINGTON — The Pentagon says a foreign spy agency pulled off the most serious breach of Defense Department computer networks ever by inserting a flash drive into a U.S. military laptop.
Read more on Army Times
Pentagon computer with flash drive attack – Army News | News from Afghanistan and Iraq – Army Times
0Pentagon computers attacked with flash drive – Army News | News from Afghanistan & Iraq – Army Times
WASHINGTON — The Pentagon says a foreign spy agency pulled off the most serious breach of Defense Department computer networks ever by inserting a flash drive into a U.S. military laptop.
Read more on Army Times