Global Virus Threat Level

Internet Storm Center Infocon Status

26 February, 2008

technical Details series - 2 : Network Worms

Another tech. documentation on virus recognized as “network worms”

Too good…

This is one of the most dangerous in small office LAN & Corporate LAN…

 

Education is the most powerful weapon which you can use to change the World.

--- Nelson Mandela


From:
Sent: Monday, February 25, 2008 10:10 AM

Network Worms

Today everyone has heard of computer worms.

Worms can be classified according to the propagation method they use, i.e. how they deliver copies of themselves to new victim machines. Worms can also be classified by installation method, launch method and finally according to characteristics standard to all malware: polymorphism, stealth etc.

Many of the worms which managed to cause significant outbreaks use more then one propagation method as well as more than one infection technique. The methods are listed separately below.

Email worms

Email worms spread via infected email messages. The worm may be in the form of an attachment or the email may contain a link to an infected website. However, in both cases email is the vehicle.

In the first case the worm will be activated when the user clicks on the attachment.In the second case the worm will be activated when the user clicks on the link leading to the infected site.

Email worms normally use one of the following methods to spread:

  • Direct connection to SMTP servers using a SMTP API library coded into the worm
  • MS Outlook services
  • Windows MAPI functions

Email worms harvest email addresses from victim machines in order to spread further. Worms use one or more of the following techniques:

  • Scanning the local MS Outlook address book
  • Scanning the WAB address database
  • Scanning files with appropriate extensions for email address-like text strings
  • Sending copies of itself to all mail in the user's mailbox (worms may even 'answer' unopened items in the inbox)

While these techniques are the most common, some worms even construct new sender addresses based lists of possible names combined with common domain names.

Instant Messaging (ICQ and MSN) Worms

These worms have a single propagation method. They spread using instant messaging applications by sending links to infected websites to everyone on the local contact list. The only difference between these worms and email worms which send links is the media chosen to send the links.

Internet Worms

Virus writers use other techniques to distribute computer worms, including:

  • Copying the worm to networked resources
  • Exploiting operating system vulnerabilities to penetrate computers and/or networks
  • Penetrating public networks
  • Piggy-backing: using other malware to act as a carrier for the worm.

In the first case, the worms locate remote machines and copy themselves into folders which are open for read and write functions. These network worms scan all available network resources using local operating system services and/or scan the Internet for vulnerable machines. They will then attempt to connect to these machines and gain full access to them.

In the second case, the worms scan the Internet for machines that have not been patched, i.e. have operating systems with critical vulnerabilities still open to exploitation. The worm sends data packets or requests which install either the entire body of the worm or a section of the worm's source code containing downloader functionality. If this code is successfully installed the main worm body is then downloaded. In either case, once the worm is installed it will execute its code and the cycle continues.

Worms that use Web and FTP servers fall into a separate category. Infection is a two-stage process. These worms first penetrate service files on the file server, such as static web pages. Then the worms wait for clients to access the infected files and attack individual machines. These victim machines are then used as launch pads for further attacks.

Some virus writers use worms or Trojans to spread new worms. These writers first identify Trojans or worms that have successfully installed backdoors on victim machines. In most cases this functionality allows the master to send commands to the victim machine: such zombies which have backdoors installed can be commanded to download and execute files - in this case copies of the new worm.

Many worms use two or more propagation methods in combination, in order to more efficiently penetrate potential victim machines.

IRC Worms

These worms target chat channels, although to day IRC worms have been detected. IRC worms also use the propagation methods listed above - sending links to infected websites or infected files to contacts harvested from the infected user. Sending infected files is less effective as the recipient needs to confirm receipt, save the file and open it before the worm is able to penetrate the victim machine.

File-sharing Networks or P2P Worms

P2P worms copy themselves into a shared folder, usually located on the local machine. Once the worm has successfully placed a copy of itself under a harmless name in a shared folder, the P2P network takes over: the network informs other users about the new resource and provides the infrastructure to download and execute the infected file.

More complex P2P worms imitate the network protocol of specific file-sharing networks: they respond affirmatively to all requests and offer infected files containing the worm body to all comers.

BE SURE, Be Protected

25 February, 2008

The Keyboard Lover's Guide to IE7 & IE6

This one is too good…

Distribute this to your friends / developers / and users, if you are system admin… JJJ they love this…

 

Education is the most powerful weapon which you can use to change the World.

--- Nelson Mandela


From:]
Sent
: Monday, February 25, 2008 9:48 AM
Subject: Internet Explorer 6 Keyboard Shortcuts

The Keyboard Lover’s Guide to IE7

Many are content to spend all day clicking fancy looking buttons or menu items in order to get their tasks accomplished, but those who know the correct keyboard and mouse shortcuts can often get around applications more efficiently: Browsing the web with Internet Explorer is no exception. I want to take a minute to discuss a few useful shortcuts already available in IE6 that will help you get around the web, and then list some great new shortcuts we are providing in IE7.

First: Getting around the web in Internet Explorer 6

Basic navigation

To do the following

Press this

Go Back to the last page*

Alt+Left Arrow

Go Forward to the next page*

Alt+Right Arrow

Stop the page from loading**

Escape (Esc)

Refresh the page***

F5 or Ctrl+F5

Go to your Homepage

Alt+Home

Give focus to the Address Bar

Alt+D

Add “www.” and “.com” to what you typed
in the address bar before navigating****

Ctrl+Enter

Scroll down/up the web page

Spacebar / Shift+Spacebar

Close the window

Alt+F4

Others:

Some interesting hotkeys you cannot see by simply looking in the menus…

To do the following

Press this

Immediately add this site to your favorites

Ctrl+D

Open your favorites in a folder window

Shift+Click on the “Organize Favorites”
menu item

Put focus on the Information Bar

Alt+N

Open a link in a new window

Shift+Click

Open the right click ‘context’ menu for the currently selected item

Shift+F10

Change the text size (will be Zoom in IE 7)

Ctrl+Mouse wheel Up/Down

* Shift+Mouse wheel up/down also navigates forward and back, so does Backspace and Shift+Backspace
** Did you know that hitting the stop button (or Esc) will also stop background sounds?
*** If F5 doesn’t refresh all content try Ctrl+F5.  This ensures no content is pulled from the cache.
**** In the Preview build we also added Ctrl+Shift+Enter when focus is in the address bar.  This works like Ctrl+Enter from the address bar does today but will append a suffix of your choice to the end of the string instead of “.com” (.org, .edu, .co.uk, etc…).  You can change the default suffix in the Internet Options control panel.

Note: In the Preview build we have changed the pop-up blocker override key from “Ctrl to “Ctrl+Alt” in order to avoid conflicts with our new “Ctrl” tabbed browsing hotkeys

New in Internet Explorer 7

Now that we have basic navigation down, let’s talk about some cool new shortcuts in IE 7. You will notice that for features that exist elsewhere (for example: Tabbed Browsing) we put effort into maintaining consistency where possible.

Tabs:

To do the following

Press this

Open links in a new tab in the background

Ctrl+Click

Open links in a new tab in the foreground

Ctrl+Shift+Click

Open a new tab in the foreground

Ctrl+T

Switch between tabs

Ctrl+Tab / Ctrl+Shift+Tab

Close current tab (or current window when there are no open tabs)

Ctrl+W

Open a new tab in the foreground from the address bar

Alt+Enter

Switch to the n’th tab

Ctrl+n (n can be 1-8)

Switch to the last tab

Ctrl+9

Close other tabs

Ctrl+Alt+F4

Open quick tabs

Ctrl+Q

Zoom:

To do the following

Press this

Increase zoom (+ 10%)

Ctrl+(+)

Decrease zoom (-10%)

Ctrl+(-)

Original size (100% zoom)*

Ctrl+0

* If you are using the recent Windows Vista preview you might notice that the 100% zoom hotkey changed from Ctrl+(*) to Ctrl+0

Search:

To do the following

Press this

Go to the Toolbar Search Box

Ctrl+E

Open your search query in a new tab

Alt+Enter

Bring down the search provider menu

Ctrl+Down Arrow

Favorites Center:

To do the following

Press this

Open Favorites Center to your favorites

Ctrl+I

Open Favorites Center to your history

Ctrl+H

Open Favorites Center to your feeds

Ctrl+J

Great new mouse actions in IE7

Even with all these cool keyboard hotkeys we’ve introduced a few helpful shortcuts for mouse users as well.

To do the following with a mouse

Press this

Open a link in a background tab

Middle mouse button

Close a tab

Middle mouse button on the tab

Open a new tab

Double click on empty tab band space

Zoom the page in/out 10%

Ctrl+Mouse wheel Up/Down

Tip:
My favorite shortcuts are the middle mouse button actions to close a tab and open links in the background (Those make using tabs fast and easy).

In Summary

Internet Explorer certainly has more than just these shortcut keys.  I’m sure you have some favorites I did not mention, but I hope you found something here that will make browsing the web easier for you. 

Until next time, keep browsing!

Good one: Life Is Like Hot Chocolate !!!

Good one… HOT Chocolate… &       "Life is Like an Ice-cream; Enjoy it before it melts!"


From:.com]
Sent: Monday, February 25, 2008 2:08 PM
To: Chirag Gandhi
Subject: Good one: Life Is Like Hot Chocolate !!!

 

Life Is Like Hot Chocolate

A group of graduates, well established in their careers, were talking at a reunion and decided to go visit their old university professor, now retired.  During their visit, the conversation turned to complaints about stress in their work and lives.

 

Offering his guests hot chocolate the professor went into the kitchen and returned with a large pot of hot chocolate and an assortment of cups - porcelain, glass, crystal, some plain looking, some expensive, some exquisite telling them to help themselves to the hot chocolate.

When they all had a cup of hot chocolate in hand, the professor said: "Notice that all the nice looking expensive cups were taken, leaving behind the plain and cheap ones.
While it is normal for you to want only the best for yourselves, that is the source of your problems and stress.  The cup that you're drinking from adds nothing to the quality of the hot chocolate.  In most cases it is just more expensive and in some cases even hides what we drink.  What all of you really wanted was the hot chocolate, not the cup; but you consciously went for the best cups... and then you began eyeing each other's cups.

Now consider this: Life is the hot chocolate; your job, money and position in society are the cups. They are just tools to hold and contain life.  The cup you have does not define, nor change the quality of life you have.  Sometimes, by concentrating only on the cup, we fail to enjoy the hot chocolate God has provided us.

God makes the hot chocolate and man chooses the cups.  The happiest people don't necessarily have the best of everything; they simply make the best of everything that they have.

Live simply.
Love generously.
Care deeply.
Speak kindly.
And, enjoy your hot chocolate!

 

FW: Create a Password Reset Disk

Very Useful…

 

Procrastination:

"Hard work often pays off after time, But laziness always pays off now."


From: net]
Sent
: Monday, February 25, 2008 9:29 AM
To: "Undisclosed-Recipient:;"@ahmedabad.mudra.com
Subject: Create a Password Reset Disk

 

Create a Password Reset Disk

If you’re running Windows XP Professional as a local user in a workgroup environment, you can create a password reset disk to log onto your computer when you forget your password. To create the disk:

1.Click Start, click Control Panel, and then click User Accounts.
2.Click your account name.
3.Under Related Tasks, click Prevent a forgotten password.
4.Follow the directions in the Forgotten Password Wizard to create a password reset disk.
5.Store the disk in a secure location, because anyone using it can access your local user account.

 

technical details : Trojan Programs

Trojan Programs

Trojans can be classified according to the actions which they carry out on victim machines.

Backdoors

Today backdoors are the most dangerous type of Trojans and the most widespread. These Trojans are remote administration utilities that open infected machines to external control via a LAN or the Internet. They function in the same way as legal remote administration programs used by system administrators. This makes them difficult to detect.

The only difference between a legal administration tool and a backdoor is that backdoors are installed and launched without the knowledge or consent of the user of the victim machine. Once the backdoor is launched, it monitors the local system without the user's knowledge; often the backdoor will not be visible in the log of active programs.

Once a remote administration utilitiy has been successfully installed and launched, the victim machine is wide open. Backdoor functions can include:

  • Sending/ receiving files
  • Launching/ deleting files
  • Executing files
  • Displaying notification
  • Deleting data
  • Rebooting the machine

In other words, backdoors are used by virus writers to detect and download confidential information, execute malicious code, destroy data, include the machine in bot networks and so forth. In short, backdoors combine the functionality of most other types of Trojans in one package.

Backdoors have one especially dangerous sub-class: variants that can propagate like worms. The only difference is that worms are programmed to propagate constantly, whereas these 'mobile' backdoors spread only after a specific command from the 'master'.

General Trojans

This loose category includes a variety of Trojans that damage victim machines or threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers create multi-functional Trojans rather than Trojan packs.

PSW Trojans

This family of Trojans steals passwords, normally system passwords from victim machines. They search for system files which contain confidential information such as passwords and Internet access telephone numbers and then send this information to an email address coded into the body of the Trojan. It will then be retrieved by the 'master' or user of the illegal program.

Some PSW Trojans steal other types of information such as:

  • System details (memory, disk space, operating system details)
  • Local email client
  • IP-address
  • Registration details
  • Passwords for on-line games

Trojan-AOL are PSW Trojans that steal passwords for aol (American Online) They are contained in a sub-groups because they are so numerous.

Trojan Clickers

This family of Trojans redirects victim machines to specified websites or other Internet resources. Clickers either send the necessary commands to the browser or replace system files where standard Internet urls are stored (e.g. the 'hosts' file in MS Windows).

Clickers are used:

  • To raise the hit-count of a specific site for advertising purposes
  • To organize a DoS attack on a specified server or site
  • To lead the victim to an infected resource where the machine will be attacked by other malware (viruses or Trojans)

Trojan Downloaders

This family of Trojans downloads and installs new malware or adware on the victim machine. The downloader then either launches the new malware or registers it to enable autorun according to the local operating system requirements. All of this is done without the knowledge or consent of the user.

The names and locations of malware to be downloaded are either coded into the Trojan or downloaded from a specified website or other Internet location.

Trojan Droppers

These Trojans are used to install other malware on victim machines without the knowledge of the user. Droppers install their payload either without displaying any notification, or displaying a false message about an error in an archived file or in the operating system. The new malware is dropped to a specified location on a local disk and then launched.

Droppers are normally structured in the following way:

Main file
contains the dropper payload
File 1
first payload
File 2
second payload
...
as many files as the coder chooses to include

The dropper functionality contains code to install and execute all of the payload files.

In most cases, the payload contains other Trojans and at least one hoax: jokes, games, graphics and so forth. The hoax is meant to distract the user or to prove that the activity caused by the dropper is harmless, whereas it actually serves to mask the installation of the dangerous payload.

Hackers using such programs achieve two objectives:

  1. Hidden or masked installation of other Trojans or viruses
  2. Tricking antivirus solutions which are unable to analyse all components

Trojan Proxies

These Trojans function as a proxy server and provide anonymous access to the Internet from victim machines. Today these Trojans are very popular with spammers who always need additional machines for mass mailings. Virus coders will often include Trojan-proxies in Trojan packs and sell networks of infected machines to spammers.

Trojan Spies

This family includes a variety of spy programs and key loggers, all of which track and save user activity on the victim machine and then forward this information to the master. Trojan-spies collect a range of information including:

  • Keystrokes
  • Screenshots
  • Logs of active applications
  • Other user actions

These Trojans are most often used to steal banking and other financial information to support online fraud.

Trojan Notifiers

These Trojans inform the 'master' about an infected machine. Notifiers confirm that a machine has been successfully infected, and send information about IP-address, open port numbers, the email address etc. of the victim machine. This information may be sent by email, to the master's website, or by ICQ.

Notifiers are usually included in a Trojan 'pack' and used only to inform the master that a Trojan has been successfully installed on the victim machine.

Rootkits

A rootkit is a collection of programs used by a hacker to evade detection while trying to gain unauthorized access to a computer. This is done either by replacing system files or libraries, or by installing a kernel module. The hacker installs the rootkit after obtaining user-level access: typically this is done by cracking a password or by exploiting a vulnerability. This is then used to gather other user IDs until the hacker gains root, or administrator, access to the system.

The term originated in the Unix world, although it has since been applied to the techniques used by authors of Windows-based Trojans to conceal their actions. Rootkits have been used increasingly as a form of stealth to hide Trojan activity, something that is made easier because many Windows users log in with administrator rights.

ArcBombs

These Trojans are archived files coded to sabotage the de-compressor when it attempts to open the infected archived file. The victim machine will slow or crash when the Trojan bomb explodes, or the disk will be filled with nonsense data. ArcBombs are especially dangerous for servers, particularly when incoming data is initially processed automatically: in such cases, an ArcBomb can crash the server.

There are three types of ArcBombs: incorrect header in the archive, repeating data and a series of identical files in the archive.

An incorrect archive header or corrupted data can both cause the de-compressor to crash when opening and unpacking the infected archive.

A large file containing repeating data can be packed into a very small archive: 5 gigabytes will be 200 KB when packed using RAR and 480 KB in ZIP format.

Moreover, special technologies exist to pack an enormous number of identical files in one archive without significantly affecting the size of the archive itself: for instance, it is possible to pack 10100 identical files into a 30 KB RAR file or a 230 KB ZIP file.

 
 
-------------------------------------------------------------------------------------------------------------------------------------------------------------

BAPS Swaminarayan Mandir - Canada in Snow 2008

Too good...

-----Original Message-----
From:.com]
Sent: Monday, February 25, 2008 10:36 AM
To:.com
Subject: Mandir in Snow 2008


Disclaimer
----------------------------------------------------------------------------------------------
This email is intended only for the named person or entity to which it is addressed and contains valuable business information that is privileged, confidential and/or otherwise protected from disclosure. Dissemination, distribution or copying of this email or the information herein, by anyone other than the intended recipient or an employee or an agent responsible for delivering the message to the intended recipient, is strictly prohibited. All contents are the copyright property of Mudra Communications Pvt. Ltd. (Mudra) or its group Companies or its clients. If you are not the intended recipient, you are nevertheless bound to respect the sender's legal rights. We require that unintended recipients delete the email and destroy all electronic copies in their system, retaining no copies in any media. Information in this message that do not relate to the official business of sender or its group Companies shall be understood to be neither given nor endorsed by the Company. If you
have received this e-mail in error, please notify us immediately by email to it@mudra.com.

The email has been successfully scanned for presence of virus. It is recommended to scan along with attachment, if any, before launching. We do not accept any liability for any errors, omissions, viruses or computer problems experienced by any recipient as a result of this email.
----------------------------------------------------------------------------------------------

21 February, 2008

FW: samay nathi...

Very very santy

If you don’t know gujarati then please ask someone to read this & translate this who knows gujarati in your circle.

 

Regards,

chirag

Education is the most powerful weapon which you can use to change the World.

--- Nelson Mandela


From: telecom.com]
Sent
: Thursday, February 21, 2008 10:53 AM
To:
Subject: samay nathi...

 

Good Morning and Have a Nice Day 

18 February, 2008

!!!!!!!!Toooo Good!!!!!!!!

 

Education is the most powerful weapon which you can use to change the World.

--- Nelson Mandela

-----Original Message-----
From: Subject: !!!!!!!!Toooo Good!!!!!!!!

                                                                           

     è  When things in your life seem almost too much to handle, when 24         

  hours in a day are not enough, remember the mayonnaise jar and the 2     

  cups of coffee.                                                          

                                                                           

  A professor stood before his philosophy class and had some items         

  in front of him. When the class began, he wordlessly picked up a very    

  large and empty mayonnaise jar and proceeded to fill it with golf balls. 

  He then asked the students if the jar was full. They agreed that it was. 

                                                                           

                                                                           

  The professor then picked up a box of pebbles and poured them            

  into the jar He shook the jar lightly. The pebbles rolled into the open  

  areas b etween the golf balls. He then asked the students again if the   

  jar was full. They agreed it was.                                         

                                                                           

  The professor next picked up a box of sand and poured it into            

  the jar. Of course, the sand filled up everything else. He asked once     

  more if the jar was full. The students responded with an unanimous       

  "yes."                                                                   

                                                                           

  The professor then produced two cups of coffee from under the            

  table and poured the entire contents into the jar effectively filling    

  the empty space between the sand. The students laughed.                  

                                                                            

  "Now," said the professor as the laughter subsided, "I want you          

  to recognize that this jar represents your life. The golf balls are the  

  important things---your family, your children, your health, your friends 

  and your favorite passions---and if everything else was lost and only    

  they remained, your life would still be full.                            

                                                                           

  The pebbles are the other things that matter like your job, your         

  house and your car.                                                      

                                                                           

  The sand is everything else---the small stuff. "If you put the           

  sand into the jar first," he continued, "there is no room for the        

  pebbles or the golf balls. The same goes for life. If you spend all your 

  time and energy on the small stuff you will never have room for the      

  things that are important to you.                                        

  "Pay attention to the things that are critical to your                   

  happiness. Spend time with your children. Spend time with your parents.  

  Visit with grandparents. Take time to get medical checkups. Take your    

  spouse out to dinner. Play another 18. There will always be time to      

  clean the house and fix the disposal. Take care of the golf balls        

  first---the things that really matter. Set your priorities. The rest is  

  just sand."                                                              

                                                                            

  One of the students raised her hand and inquired what the coffee         

  represented. The professor smiled and said, "I'm glad you asked."        

                                                                           

  The coffee just shows you that no matter how full your life may          

  seem, there's always room for a couple of cups o f coffee with a friend."

                                                                           

                                                                            

  Please share this with someone you care about..                          

  I JUST DID