RSS RSS Subscribe

Posts tagged: oops

Spam with a bonus — ‘Oops’

By , December 10, 2009 08:12
Hot:

I received a rather interesting spam the other day and it would seem to have included some well private details.  It looks like this email contains login information for various mail systems but I honestly did not follow up with it.  I figured it may be of interest to the owners of these sites so I’m posting it here rather than attempt to start tracking abuse emails for various domains.

Continue reading 'Spam with a bonus — ‘Oops’'»

DiggRedditRead It LaterGoogle ReaderYahoo MailSlashdotWordPressIdenti.caStumbleUponMySpaceLinkedInDeliciousLiveJournalHotmailAsk.com MyStuffBlogger PostBookmark/FavoritesGoogle BookmarksFacebookTwitterOrkutShare

Google Chrome OS Is Available For Building Or Downloading

comments Comments Off
By , November 27, 2009 18:14
Hot:

I wasn’t going to get into this too much since the download is one you’ll have to build and I didn’t want to go through all the motions to make this happen.  But it appears someone has created a Virtual Machine (VM) you can use to try it out.

http://gdgt.com/google/chrome-os/download/ is the place to get it at.  You will need to create an account on the site (free), download a copy of Chrome OS which they offer a link to do that and you’ll need a VM platform to get it working.  VMWare is what it’s designed for, but VirtualBox can also use vmware images but there could be issues (not all work perfectly) as you’ll see from the site.

http://www.vmware.com/products/player — To Get Vmware Player.  If you have a Mac you can use Fusion, and it should work find on other VMWare products.

http://www.virtualbox.org — To get VirtualBox, but I’d recommend installing it from your distributions repository for full support, other wise you’re on your own updating it and all that fun stuff.

http://www.google.com/chrome/intl/en/eula_dev.html — Source from Google, may have to jump through some hoops to download it

http://gdgt.com/google/chrome-os — To Get Chrome OS ready to go.

Note: all these links can be found on gdgt.com directly from the first link in this article.  I include them for convenience.

Also you can review TechCrunch’s web site that will give you some step-by-step instructions along with a torrent link to download it from also

http://www.techcrunch.com/2009/11/19/guide-install-google-chrome-os/

Have fun!

DiggRedditRead It LaterGoogle ReaderYahoo MailSlashdotWordPressIdenti.caStumbleUponMySpaceLinkedInDeliciousLiveJournalHotmailAsk.com MyStuffBlogger PostBookmark/FavoritesGoogle BookmarksFacebookTwitterOrkutShare

Changed Site

comments Comments Off
By , August 31, 2009 17:46
Hot:

Well I finally have the site migrated over.  I can honestly say the testing was the hardest part, several weeks fiddling with problems on the test server, and when we went live, only one minor hiccup which I’m glad to say Tim from Hostpapa reminded us…check file permissions.  Doh!

Now that this is done this comes with good news and bad news.  First the good news.

Continue reading 'Changed Site'»

DiggRedditRead It LaterGoogle ReaderYahoo MailSlashdotWordPressIdenti.caStumbleUponMySpaceLinkedInDeliciousLiveJournalHotmailAsk.com MyStuffBlogger PostBookmark/FavoritesGoogle BookmarksFacebookTwitterOrkutShare

Kaspersky Anti Virus V6 Beta – Impressions

comments Comments Off
By , July 5, 2006 13:55
Hot:

Well everyone needs an antivirus solution don’t they?

 

No.  I don’t believe everyone NEEDS one anymore.  To be truly effective you will probably need two or three, but good luck running them all together.  Its not recommended, and you will probably have real issues.

As a consequence even software designers are realizing this and integrating their AV solution into a more comprehensive and complete solution, bringing other features that should not be part of a pure anti-virus solution.

 

Let me state some declarations for the security vendors out there who may read this.

First declaration.  We don’t want “vendor-specific” integrated solutions.  Period.  Anyone who thinks they do can email me directly or on the forums and we can discuss it. 

Second declaration.  No AV/Security Vendor has a ‘good’ integrated solution let alone a ‘excellent’ one.

Third declaration.  Stay out of endeavors unless your going to do them well.

Now even some AV products are moving into integrating other ‘features’ into their software.  Kaspersky v6 Beta is one of those.  This was supposed to be a pure Anti-Virus program but as I highlight it isn’t.

 

Since this is an article about my last 24 hours with this program I shall try not to pick on integrated solutions any more. 

Why I don’t believe you need AV products anymore?

Truthfully virus’ are very very rare forms of malware these days.  They are making a bit of a comeback but mostly as rebuilt worms or trojans.  Worms and trojans are the big purveyors of nasty malware, and of course spam, phishing etc are even larger spreaders of the disease, BUT they are not virus either. 

 

So Anti-virus products simply waste resources and offer little to no actual protection?


Exactly.  Almost none are capable of “true” real-time protection unless you are being infected with very old malware.  However this is really where the value in Anti-virus software is.  Typically the value comes into play only after you discover that your already infected. [1]  Sure none of us like this, and we wish we would never get infected but it happens.  Our AV solution typically works good to excellent at removing and cleaning ‘known’ infections.  Sure, sometimes we need to do more than scan, quarantine, and delete, but our investment in the AV program should be able to assist at weeding out the ‘known’ malware and ensuring our data is clean. 

Only in the know…

It doesn’t stop unknown virus’.  Hence why you need to keep updating your software with new ‘signatures’ and additionally keep scanning your systems to keep up to date with what’s ‘known’.

Anti-virus software tends to be excellent at dealing with virus, pretty good at trojans and worms, but ‘only’ if the signature is up to date.  Besides nobody trades floppy disks much anymore so boot sector virus’ are dying out as malware matures in new forms[2].  So the AV product typically cannot stop trojans or worms from moving around, unless it has detection signatures for it.  But these definitely are acquired after the trojan or worm has typically ran it’s course.  Some worms have lifetimes in seconds.  How do you detect it, report it, confirm it, publish it, add it, update it, scan it all in a few seconds?  You can’t.  You would be infected during that phase with no trigger from your AV software.  

Since I don’t need to waste time and money getting little return on investment I choose not to install Anti-Virus tools.  Regardless of the solution though remember, “true” real time protection comes at a cost to performance.  On a home PC who wants to give up performance?  On a gaming machine, no WAY your giving up performance.  So don’t waste your time installing this software on these machines.  There are better solutions. 

Isn’t Kaspersky Anti-Virus v6 Beta different?

Yes.  Kaspersky v6 Beta was downloaded as I have always heard good things about this company and they tend to get fairly favorable reviews.  However most people hated v5 for a variety of reasons and I was led to believe (reading other reviews) that 6 was like a phoenix from the ashes type of release compared to v5.  It wasn’t.  It’s very like 5 and add new features you may love, but I guess you won’t, I sure didn’t.

From the beginning

Well the MSI installer was the first strike against this product. I’m no fan of the MSI installer, it creates numerous difficulties at installing software, and there should NEVER be a PROBLEM installing software. If there is, you shouldn’t have released it with the problem.

 

I attempted the installer on Vista RC2 and it completely failed with no real error (unknown error, didn’t I just type this…).  I then attempted to install this on a XP SP2 box I use that has ‘never’ seen an Anti-virus product before, and has been running for 6 months.  This installed fine requiring a reboot at the end.  However it attempted to update during the install, and this simply caused a hangup of both the installer and windows explorer.  I wasn’t impressed.  The reason for this hanging will be clear in a minute.

 

After a successful reboot, the software came up and started flagging various dll’s mostly, with nice smallish yellow popups,  and asking me what I wanted to do.  Folks, this is like many MANY other products out there, most are firewall solutions, but a few call themselves Anti-Virus solutions.   Now with all these packages the capabilities are morphing also.  Its an application tracking program that shows hooks into system routines, accesses and injections and changes of course.  This can be a very powerful tool to ensuring you stay protected.  However this!?!?!? In an AV product?  Give me a break.  Someone forgot to tell these folks ‘I only want my AV software bothering me IF IT’S A VIRUS OR OTHER MALWARE!!!!!!!’, we do need to remind them.

Why is this a problem?

I expect my anti-virus tool to ‘detect’ virus’.  Not tell me every little thing going on inside my system.  If I wanted an effective tool for active malware discovery I would use a serious appliance built for that purpose.  Maybe  the Anti-virus software guys and gals want to detect 0-days, something they never have done in the entire history of anti-virus tools.  Great lofty goal, but then they break trusted processes (detecting and removing virus’) with new features that can misplace trust, and then all bets are off.

So, question is.  Do I really want this level of protection?  Maybe. 


Do I want it from a trusted application like an anti-virus tool?

No, since they don’t know whether it’s malware or not, it asks you to make the decision.  I’m not sure if this would have an effect on scanning files against known attacks but I’m not about to either guess or take a chance.  Of course in my case I’m sure this is all innocent routine stuff, but it’s being treated inappropriately by Kaspersky so it’s possible one can make bad decisions.

 

Every little task generates this ‘alertwindow’ providing you only with:

 

A:  The classification of the alert;

B:  The location of the file causing the alert.

Then you have to make decisions as to:

C:  Whether to accept or deny it;

D:  Whether to make the above choice permanent, or just this time;

E:  Whether to simply trust this application to do what it wants, or not.

 

Lets look at each of these in more detail.

 

A:  The classification is a single word.  “Invader”  “Downloader”  “Threat”.  You can click on it to go to http://www.viruslist.com and check the definition in the encyclopedia, but don’t waste your time.   The definition you probably already formed in your head is more accurate and descriptive.

 

B:  The location is helpful, but in no way assists in decision making.  Does the software ‘belong’ there?  Are there other files called this also?  What is the manufacturers version information from the file?  Do we have a MD5 or SHA hash to verify it’s integrity?  Is this an essential windows file or not?  Is it a virus because my AV program displayed it to me?  Too many questions still and no definitive answers from the program that’s supposed to be definitive.

 

C:  Whether to
accept or deny this activity.  How am I supposed to make an intelligent decision based on the little panic information I have received so far?  Honestly you can’t.  So you flip a coin.  However chances are something ‘legit’ was trying to do something and if you deny it, very likely the application will now no longer have any communication back to the system including the calls and threads it already created and will typically crash the application or worse the desktop, or sadly, the entire machine.  So, the default choice is to accept it.  Why bother me then? 

 

D:  Now we have to make a choice that we will have to live with if we ever run this again.  Again same logic trail as C: above, so same conclusion.  Why bother me then?

 

E:  Should we just ‘trust’ this application to do what it wants? Now here’s the ‘stop annoying me’ choice, we can tell the program “look you annoying software, quit bugging me with popups and just trust the blasted application”.  Still we don’t know whether this is our photo gallery we wanted to start up to add some pictures from the weekend, or the latest worm/trojan file deletion tool.  But we can trust it and never hear from Kaspersky again. 

 

So the conclusion, this behavior from Kaspersky isn’t warranted or desired in an AV product because it doesn’t provide decent support.  It simply gives the user very powerful filtering capability which one can most simply avoid, and probably will.  This type of processing smacks of ‘host intrusion prevention systems (HIPS)’ but these are typically poor or overly complex applications.  Here with Kaspersky AV v6 Beta we have not overcome that hallmark.

 

The second contention I have with Kaspersky AV v6 Beta, is all the links direct one to a page to download the ‘trial version’ from, but with no way to activate the ‘trial version’.  The docs indicate that the activation tool (help -> activate) allows one to buy a license for this or activate later, or activate with a trial code.  Well the ‘trial version’ I downloaded from the ‘trial page’ does not have a ‘activate with trial code’ option.  So it’s either no updates or buy a license.  Well lets see how it does with it’s current database on my box that has never seen a anti-virus tool.  Aha, this is why my install hung up, it won’t allow the updater to update.  How silly.

 

Ok, I start the scan and I do like some of the options it provides like showing you all the exploits at theo >end f the scan.  I like this.  So, I run the scan, it estimates about two hours to scan everything (lots of partitions) and unbelievably it was done in just under two hours.  Very impressive.  Two little things I have seen before but they actually work as expected.  Wow.  It’s truly unfortunate that little else worked as great or made a positive lasting impression on me.

 

Remember we scanned a box that has XP SP2 installed patched semi regular (I let it inform and download, but I install manually) basis, no firewall except windows firewall, no antivirus ever until Kaspersky v6 Beta was installed, This has office 2003 installed runs Outlook as the mail client, has perl installed, IRC runs constantly, and most web browsing is done from this box, including this report being initially typed on it.

 

After a full two hour scan of my box I found one ‘threat’ on my PC.  Oh, that’s darn good I say to myself.  Just one file.  Considering some of the PC’s people have brought to me that I’ve cleaned up, repaired and rebuilt over the years, typically finding unbelievable amounts of malware  or a simple single infection still resulting in numerous files found during a scan.  Just one file infected.  Must have contained it…

So what one did I have?  I clicked on the result and was shocked.  The result was ‘Not-a-virus:mirc-616.exe’.  I couldn’t believe this.  It was showing me a backup copy of MIRC from my last update.  Hey I use MIRC daily, and rely upon it.  I bought the tool so I’m licensed, and when it did an upgrade it created a backup first.  How intelligent. 

So why is Kaspersky bugging me about this innocent tool?

 

I guess someone could ‘run’ it and take advantage of the exploits to infect my box, so I deleted it afterwards.  Was it infected?  No.  Why does it flag me with a bunch of insignificant warnings when it’s harmless?  Why did it not say ‘look you should delete this old version or upgrade if this is the current version you are using’?  Because it’s not a patch management solution, nor is it an auditing solution.  So I cannot fathom why my Anti-Virus software is behaving like one. 

 

Maybe it’s trying to be more encompassing and deal with the latest threats, rootkits.   But then shouldn’t it promote itself as an anti-rootkit tool?   Well we all know that there isn’t any such thing (yes many are trying to build one, but nothing actually works in detection), even tools such as ‘Rootkit Revealer’ by F-secure simply tell you a bunch of stuff that may ‘look’ like a rootkit, but you’ll have to do much more system analysis to determine for real or not.

 

Lets do some work

So, I figure I’ll wait and see if I can get the 30 day activation code to use this product, check around to ensure I haven’t missed something in terms of getting the proper beta product.  In my travels I find this great RAR file I want to download.  Ok firefox causes numerous popups in Kaspersky as DLL’s are loaded to process the download.  Ok I get the download and click on open in my download window in firefox, get more including AdobeIEsomethingorother.dll I can’t see why it needs this and select deny.  Windows Explorer crashes.  Ooops.  Attempt to repeat, crashes again.  Turns out that the download window launches in explorer.exe space and any time it looks up how to handle extensions several dlls are loaded for that purpose, including the AdobeIEsomethingorother.dll that I denied.  I wasn’t running IE or Adobe, but Windows Explorer (explorer.exe) required it during it’s initialization and denying it made it quite unstable.

 

Ok, this is not why I have security products installed on my machines.  I install them to:

 

A:  Improve the security of my systems, and improve my ability to do said;

rr

B:  Improve the stability and reliability of my systems and the data that resides on them

C:  To protect and ensure the accuracy and validity and privacy of the data and software that resides on the machines.

 

If the software I’m installing/using interferes with ONE of those conditions it fails and gets removed.

 

Kaspersky failed on the first two accounts.  It did not improve my security, and it destabilized my system by halting processes in stream to popup windows.  This regularly caused issues and in some cases fails, or crashes or unrecoverable applications.  In one case it completely crashed my TCP/IP stack since the protocol doesn’t like waiting for responses.  As for the third I can say the installation/removal of the software did not adversely affect any system files.  It did not interfere with the accuracy of the files that presided, nor did it interfere with them (outside of the routine application issues)

 

I could not recommend this product since:

 

  1. It misleads the user about particular findings
  2. Activation was a major headache with no immediate solution attainable
  3. The product introduces so many additional points of failure that system stability could be a factor
  4. It wastes the users time with notices of things that are innocent additionally it doesn’t make notice of important things.
  5. Misuse of the tool by the user can render a machine or application useless.  Even to the point of crashing system kernel routines.

 

In my opinion this Anti-virus product is only 1/5th of it’s capabilities, and I was not seeking integrated solutions.  Since the AV portion does seem to work effectively it alerts you to non-virus files, which could cause one to delete something they use accidentally.


Installation Ranking: 3/5 – Using MSI and saying it installs on all windows but would not on Vista nor would it generate a decent error.  XP works fine.

Initial Setup and Patching: 1/5 – Unable to do anything except hang the machine attempting to make connections the
program blocks.  Unable to recify within test period, granted it was very short, so we give it a one.

Usability: 3/5 – Overall the program worked as we expected and did not cause issues or confusion when we asked it to do things.  It was not so clear when it prompted you with popups about app activity.

Dependability: 3/5 – Overall it’s engine scanned effectively and found all the planted malware on our test box.  It’s discovery of non-malware as malware concerned me greatly about it’s ‘cry wolf’ potential.  I would not rely on results singularily by this software I would have to confirm them with another more reliable package to ensure it is accurately determining valid malware, and not potential malware. 

Overall score: 2.5/5 – Software adequate.  Price to purchase unrealistic to it’s abilities.  Certainly has potential as a combo AV-Application Watcher, but why?

I don’t want to have to second guess my results, my AV software shouldn’t either.  If it does then it no longer has any ability to do what AV software is supposed to do….detect.

 


[1]This happens as a result (typically) by being infected during the ‘unknown’ phase, and once the signatures were updated, you now ‘detect’ the infection running around doing whatever it wants until now.

[2]Traditionally you got virus from copying files usually from a floppy disk.  Over time as other file transfer methods developed, the ways for virus to spread changed also.  However malware creators also realized that in order to get the virus around, they needed to figure out how to spread it.  Email, news, IRC protocals were used and the development of hiding virus in (even legit) programs was developed, now commonly referred to as trojans or trojan horses.  Worms also are an effective spreader technology since it’s whole concept in life is to move around the internet.

DiggRedditRead It LaterGoogle ReaderYahoo MailSlashdotWordPressIdenti.caStumbleUponMySpaceLinkedInDeliciousLiveJournalHotmailAsk.com MyStuffBlogger PostBookmark/FavoritesGoogle BookmarksFacebookTwitterOrkutShare

World of Warcraft SUCKS … your bandwidth when you don\’t know it

comments Comments Off
By , April 3, 2006 10:56
Hot:

I have played, well I did play World of Warcraft (WoW) when it first was released.  Not much anymore even though I’m thinking I may get back into it again.

However when I hear stories such as this, I recall why I quit playing WoW in the first place.  For those who don\’t know me, I’m an avid beta tester and MMORPG gamer.  I’ve played nearly every game ever released, ever.  Well except those I did not want to play.  If enough people ask me I may sit down and count all the games I’ve played.

Right, now why did I quit playing Wow?  Well the game was fun, easy if not as painful as others when it came to moving around the planet, the graphics were great, and there are enough elements to make this very entertaining.  Guilds and teams were well designed but the PvP could have been improved but it works for not creating two parts to the same world.

No it wasn’t even the cost.  I loved the game card idea, since it saved one from having to risk a credit card on the internet (certainly not a wise idea).

So what was it?

Read more..

It was the constant patching. 

Yes Blizzard in their ignorance decided that bit-torrent would be the way to go.  This way they prevent entire nations populations from having to download patches from them.  Let everyone leech from each other.  Sounds good except.

It’s slower than molasses!  It takes forever to patch!  If you have a firewall (and who doesn’t these days) you have to open half the internet to the download.  Totally *censored*ing stupid!

The lead developer during E3 a few years back explained that it would be state of the art.  Well it’s only saved money for Blizzard, it certainly hasn’t bid them many friends or supporters.  However like most gamers I know..you don’t complain you just jump through the hoops.  Its a shame that such a good game is marred by one really bad design flaw, even though it means a large $$$ savings for the company. 


[Editors note: it could be worse, you could be downloading from premium pay websites WITHOUT a pay account]

[Writers note: it is...read more]

Blizzards latest patch is trying to improve this, but, yep you guessed it, *censored*ing it up even worse.

It appears that now the downloader is running contantly, and stealing bandwidth doing what bit torrents do…move torrents.  ISP’s especially have not been ignoring this increase in traffic, and you shouldn’t either.

Yes there is NOW a forum on DSLREPORTS.COM dealing with WoW.  What does this tell you.

Blizzard get a clue and replace this hapless method with something that doesn’t steal from your customers.

Arenasoft have the RIGHT idea…streaming updates…YES!! That is the way to go.

Until WoW patches get exploited….we’ll be here chuckling at all the stupidity
called ‘state of the art’.

Oh, and here’s the report from DSLREPORTS.com

There’s been ample grumbling this week about the 1.10 patch for World of Warcraft, because the Bit-Torrent based WOW game downloader now apparently runs all the time, slowly leeching your bandwidth, even when the updater isn’t running (a problem clearly for capped users). Blizzard responded to complaints by allowing users to disable the function, though some have had trouble getting it to work.

 

Blizzard responded to complaints by allowing users to disable the function, though some have had trouble getting it to work. Blizzard has also updated their FAQ on the matter.

In Other words…We aren’t doing a thing to make it better.  Suck it up paying (L)user!!
Now submit your credit card to me…yes you cannot resist even though you’ll have to spend 40 hours updating a month!!

Comments welcome.

DiggRedditRead It LaterGoogle ReaderYahoo MailSlashdotWordPressIdenti.caStumbleUponMySpaceLinkedInDeliciousLiveJournalHotmailAsk.com MyStuffBlogger PostBookmark/FavoritesGoogle BookmarksFacebookTwitterOrkutShare

Theme by Themocracy