Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

The "other" end that is near....

0 views
Skip to first unread message

Stray Dog

unread,
Jun 13, 2009, 2:25:22 PM6/13/09
to

One of the guys here talked about losing internet newsgroups and some of
us said how he can still get them.

The "other" end of newsgroups is that -- particularly where there is any
chance of politics to be involved -- they are being taken over by kooks
and extremists who practice one form or the other of shouting,
huffing-and-puffing, yelling-and-screaming, beating-the-chest, posting one
liner insults (or even one or two word insults), name-calling, cussing,
trivia, superficialities, and other meaningless-purposeless
Neanderthalisms.

The commercialization of the internet (blogs and website chat rooms)
allows the owner of the blog to censor out the "noise" but then it might
not be all noise, just something the owner doesn't like.

One of the technical problems of blogs and websies is the chance that they
can download malicious code onto your computer (keystroke loggers, rootkits,
viruses, spyware, trojans, etc), and collect personal data on you, too.
Software firewalls and AV are helpful, but a lot of them, too, collect
data on you (so they are spyware, too).

With ID theft said to be the fastest growing crime, I'm wondering if the
degredation in the quality of internet security is, some few years in the
future, going to lead to another form of economic melt-down as people
start geting seriously hit in the wallet by the hackers.


Alan Ford

unread,
Jun 13, 2009, 4:33:56 PM6/13/09
to
Stray Dog wrote:

> One of the guys here talked about losing internet newsgroups and some of
> us said how he can still get them.
>
> The "other" end of newsgroups is that -- particularly where there is any
> chance of politics to be involved -- they are being taken over by kooks
> and extremists who practice one form or the other of shouting,
> huffing-and-puffing, yelling-and-screaming, beating-the-chest, posting
> one liner insults (or even one or two word insults), name-calling,
> cussing, trivia, superficialities, and other meaningless-purposeless
> Neanderthalisms.

??? How is this any different from what the newsgroups used to be 5, 10
or 15 years ago?

> The commercialization of the internet (blogs and website chat rooms)
> allows the owner of the blog to censor out the "noise" but then it might
> not be all noise, just something the owner doesn't like.

And? Who gives a shit? As if blogs and such are in any respect relevant
to anyone and anything.

And if you think that the newsgroups are full of illiterate idiots who
are hardly able to scramble together three or four coherent words, you
should read the comments sections below any Youtube video.

> One of the technical problems of blogs and websies is the chance that
> they can download malicious code onto your computer (keystroke loggers,
> rootkits, viruses, spyware, trojans, etc), and collect personal data on
> you, too. Software firewalls and AV are helpful, but a lot of them,
> too, collect
> data on you (so they are spyware, too).

The risk is minuscule. You run a bigger risk contracting a swine flu
virus from a phone conversation.

> With ID theft said to be the fastest growing crime, I'm wondering if the
> degredation in the quality of internet security is, some few years in
> the future, going to lead to another form of economic melt-down as
> people start geting seriously hit in the wallet by the hackers.

We've been hearing the same tired story ever since the Internet got
invented. The only thing that is the fastest growing in this whole story
is the news media bleating about this "huge threat" in between the
Cheerios and Viagra commercials, then it's off to another "huge threat"
for two minutes, then Cialis and Geico.

Stray Dog

unread,
Jun 13, 2009, 10:03:08 PM6/13/09
to

On Sat, 13 Jun 2009, Alan Ford wrote:

> Date: Sat, 13 Jun 2009 13:33:56 -0700
> From: Alan Ford <zzz...@qqq.net>
> Newsgroups: rec.radio.amateur.equipment
> Subject: Re: The "other" end that is near....


>
> Stray Dog wrote:
>
>> One of the guys here talked about losing internet newsgroups and some of us
>> said how he can still get them.
>>
>> The "other" end of newsgroups is that -- particularly where there is any
>> chance of politics to be involved -- they are being taken over by kooks and
>> extremists who practice one form or the other of shouting,
>> huffing-and-puffing, yelling-and-screaming, beating-the-chest, posting one
>> liner insults (or even one or two word insults), name-calling, cussing,
>> trivia, superficialities, and other meaningless-purposeless
>> Neanderthalisms.
>
> ??? How is this any different from what the newsgroups used to be 5, 10 or 15
> years ago?

I perused many NGs almost 20 years ago and the content was much more
thoughtful, substantial, and polite. Today its like the X and Y generation
have taken over.

>> The commercialization of the internet (blogs and website chat rooms) allows
>> the owner of the blog to censor out the "noise" but then it might not be
>> all noise, just something the owner doesn't like.
>
> And? Who gives a shit?

Well, me for one.

As if blogs and such are in any respect relevant to
> anyone and anything.

In technical areas there are serious authors and serious readers.

> And if you think that the newsgroups are full of illiterate idiots who are
> hardly able to scramble together three or four coherent words, you should
> read the comments sections below any Youtube video.

I don't go there, but have read from people who do and they say there is a
lot of rubbish there.
rub

>> One of the technical problems of blogs and websies is the chance that they
>> can download malicious code onto your computer (keystroke loggers,
>> rootkits, viruses, spyware, trojans, etc), and collect personal data on
>> you, too. Software firewalls and AV are helpful, but a lot of them, too,
>> collect
>> data on you (so they are spyware, too).
>
> The risk is minuscule.

Looks to me like you don't keep up with computer security news.

You run a bigger risk contracting a swine flu virus
> from a phone conversation.

Do you mean with a person at the other end who has the cold or by handling
a handset that was just used by a person who has the cold?

>> With ID theft said to be the fastest growing crime, I'm wondering if the
>> degredation in the quality of internet security is, some few years in the
>> future, going to lead to another form of economic melt-down as people start
>> geting seriously hit in the wallet by the hackers.
>
> We've been hearing the same tired story ever since the Internet got invented.
> The only thing that is the fastest growing in this whole story is the news
> media bleating about this "huge threat" in between the Cheerios and Viagra
> commercials, then it's off to another "huge threat" for two minutes, then
> Cialis and Geico.

My cc commpany did send me a new cc card because they said my old number
was hacked.

I have received several letters over the last few years giving notice that
a database was breeched and that I should be on alert for anything that
might involve.

One of the banks that I do business with put out a public notice about ID
theft and crime and being careful about bank data, account numbers, etc.

I have found two viruses on my computer disks using AV. Since then I am
more careful about a lot of things.

A personal friend who confessed that he visited some porno websites also
found his computer not working right afterwards and spent a couple of
hundred bucks in phone support to get the malicious code off his box.

Our garbage can, containing our garbage in black plastic bags, had those
bags removed by persons unknown and not the garbage truck. Fortunately we
had been shredding anything with numbers etc on it for some time.

My wife rents commercial office space. I decided to start making backup
copies of all working files, including those that needed confidentiality,
and deleting the copies on the HD and then over-writing all unassigned
spaces on the HD with zeros. That night her office was broken into, two
metal file cabinets broken into, and the computer stolen. I was glad they
did not get the confidential information.

In the last nearly ten years, several of my computers were hacked and
needed to have the HD nuked and all SW re-installed, and in one case they
put something on the HD that was not removed by blowing the partitions and
reformating. One box, running Linux, was also hacked.

I have lunch, once a month, with ham buddies in a club. Most of them have
at least one story like one of the above.

Another personal friend has a wireless network in his house in a suburban
neighborhood and he noticed something odd on his computer and looked
outside the house (at night) and saw a guy parked outside his house,
laptop screen lighting up his face (its called "war driving" and
offshoot of war dialing from BBS days). My friend decided to shut off
his home wireless network power switch and he look out again and the
guy drove off.

I'm not making this up.

Have you ever heard that story that the Titanic is unsinkable? I wonder if
there is some wisdom to that story?

dave

unread,
Jun 14, 2009, 9:55:13 AM6/14/09
to
Stray Dog wrote:
>
>
>
> A personal friend who confessed that he visited some porno websites also
> found his computer not working right afterwards and spent a couple of
> hundred bucks in phone support to get the malicious code off his box.
>
> Our garbage can, containing our garbage in black plastic bags, had those
> bags removed by persons unknown and not the garbage truck. Fortunately
> we had been shredding anything with numbers etc on it for some time.
>

Confessed? Are you a priest?

You should recycle the shredder output, not put it in the garbage.

Stray Dog

unread,
Jun 14, 2009, 3:07:35 PM6/14/09
to

On Sun, 14 Jun 2009, dave wrote:

> Date: Sun, 14 Jun 2009 06:55:13 -0700
> From: dave <da...@dave.dave>


> Newsgroups: rec.radio.amateur.equipment
> Subject: Re: The "other" end that is near....
>

> Stray Dog wrote:
>>
>>
>>
>> A personal friend who confessed that he visited some porno websites also
>> found his computer not working right afterwards and spent a couple of
>> hundred bucks in phone support to get the malicious code off his box.
>>
>> Our garbage can, containing our garbage in black plastic bags, had those
>> bags removed by persons unknown and not the garbage truck. Fortunately we
>> had been shredding anything with numbers etc on it for some time.
>>
>
> Confessed?

I don't understand the question.

> Are you a priest?

No.

> You should recycle the shredder output, not put it in the garbage.

It makes a mess at the recycling center. Plus, it represents less than 1%
by weight of our garbage. We do take our newspaper disposables, however,
to the recycling center, and is probably a good 75 pounds per three weeks.
We're starting to tear off the address labels, too, and shred them
separately.

What do you do?


dave

unread,
Jun 14, 2009, 3:27:41 PM6/14/09
to
The shredder output is bagged, then put in the mixed recycling bin.

dave

unread,
Jun 14, 2009, 3:39:23 PM6/14/09
to
Stray Dog wrote:
>
> On Sun, 14 Jun 2009, dave wrote:
>
>> Date: Sun, 14 Jun 2009 06:55:13 -0700
>> From: dave <da...@dave.dave>
>> Newsgroups: rec.radio.amateur.equipment
>> Subject: Re: The "other" end that is near....
>>
>> Stray Dog wrote:
>>>
>>>
>>>
>>> A personal friend who confessed that he visited some porno websites
>>> also found his computer not working right afterwards and spent a
>>> couple of hundred bucks in phone support to get the malicious code
>>> off his box.
>>>
>>> Our garbage can, containing our garbage in black plastic bags, had
>>> those bags removed by persons unknown and not the garbage truck.
>>> Fortunately we had been shredding anything with numbers etc on it for
>>> some time.
>>>
>>
>> Confessed?
>
> I don't understand the question.
>

"Confessed" implies wrongdoing. Are you a prude?

Alan Ford

unread,
Jun 14, 2009, 5:54:43 PM6/14/09
to
Stray Dog wrote:

>>> One of the guys here talked about losing internet newsgroups and some
>>> of us said how he can still get them.
>>>
>>> The "other" end of newsgroups is that -- particularly where there is
>>> any chance of politics to be involved -- they are being taken over by
>>> kooks and extremists who practice one form or the other of shouting,
>>> huffing-and-puffing, yelling-and-screaming, beating-the-chest,
>>> posting one liner insults (or even one or two word insults),
>>> name-calling, cussing, trivia, superficialities, and other
>>> meaningless-purposeless Neanderthalisms.
>>
>> ??? How is this any different from what the newsgroups used to be 5,
>> 10 or 15 years ago?
>
> I perused many NGs almost 20 years ago and the content was much more
> thoughtful, substantial, and polite. Today its like the X and Y
> generation have taken over.

Nothing to do with the generation gap. The stupidity index is a lot
higher today than at the beginning of the Internet/Usenet because today
every trailer trash moron and his mother has access to it.

>>> One of the technical problems of blogs and websies is the chance that
>>> they can download malicious code onto your computer (keystroke
>>> loggers, rootkits, viruses, spyware, trojans, etc), and collect
>>> personal data on you, too. Software firewalls and AV are helpful, but
>>> a lot of them, too, collect
>>> data on you (so they are spyware, too).
>>
>> The risk is minuscule.
>
> Looks to me like you don't keep up with computer security news.

The risk is minuscule, provided you:

- keep your OS and browser updated with security patches
- run a s/w or h/w firewall, preferably both
- are not stupid enough to download and run unknown files

>>> With ID theft said to be the fastest growing crime, I'm wondering if
>>> the degredation in the quality of internet security is, some few
>>> years in the future, going to lead to another form of economic
>>> melt-down as people start geting seriously hit in the wallet by the
>>> hackers.
>>
>> We've been hearing the same tired story ever since the Internet got
>> invented. The only thing that is the fastest growing in this whole
>> story is the news media bleating about this "huge threat" in between
>> the Cheerios and Viagra commercials, then it's off to another "huge
>> threat" for two minutes, then Cialis and Geico.
>
> My cc commpany did send me a new cc card because they said my old number
> was hacked.

By far, the majority of the credit card ID theft occurs at the vendor
end, by unscrupulous employees. There is no such thing as "hacking" a
credit card #.

> I have received several letters over the last few years giving notice
> that a database was breeched and that I should be on alert for anything
> that might involve.

Where the hell do you bank, the Al Capone Credit Union? I have accounts
in four different banks and I haven't received any such notice, ever.
Granted, this is a testimonial "evidence" like yours, but still...

> One of the banks that I do business with put out a public notice about
> ID theft and crime and being careful about bank data, account numbers, etc.

Yes, because apparently there are still people out there who think it's
a good idea to write their PIN numbers on cards, leave doors unlocked
overnight and send money to Nigerian princes.


>
> I have found two viruses on my computer disks using AV. Since then I am
> more careful about a lot of things.

??? What, you mean you reduced the number of unknown exe files you
download now?

> A personal friend who confessed that he visited some porno websites also
> found his computer not working right afterwards and spent a couple of
> hundred bucks in phone support to get the malicious code off his box.

Iow, a computer illiterate clueless idiot gets surprised after the free
Underage Russian Midget Lesbian Amputee website downloads turn out to be
something else.
Tell your friend to look for Adam's apples on hookers *before* paying.

> Our garbage can, containing our garbage in black plastic bags, had those
> bags removed by persons unknown and not the garbage truck. Fortunately
> we had been shredding anything with numbers etc on it for some time.

Holy shit, you are like the Hercule Poirot of the ID theft world -
everywhere you turn, someone is stealing your ID.
The vast majority of ID theft occurs where it's convenient, low-risk and
profitable. Dumpster diving is all three at the malls and business.
Garbage diving in residential areas is none of those three.
Phishing for info is all three through massive e-mail spam effort.
Hacking computers individually and browsing for files is none of those
three.

> My wife rents commercial office space. I decided to start making backup
> copies of all working files, including those that needed
> confidentiality, and deleting the copies on the HD and then over-writing
> all unassigned spaces on the HD with zeros. That night her office was
> broken into, two metal file cabinets broken into, and the computer
> stolen. I was glad they did not get the confidential information.

Now you're just rambling. Low-level formatting of hard drives does fuck
all to protect from ID theft. The thieves who stole the computer chucked
it for a couple of bucks so that they can buy drugs. Their reseller is
more than likely interested in reselling the stolen goods quickly and
making a buck, not in wasting time browsing through millions of files on
hundreds of hard drives.
ID thieves are in the business of stealing IDs. This means getting
thousands of credit card, social security numbers and addresses at once,
using a fraction of them quickly and disappearing. It is a wholesale
business. They don't fuck around trying to get one number at a time -
hence nothing that you describe so far fits their modus operandi.


>
> In the last nearly ten years, several of my computers were hacked and
> needed to have the HD nuked and all SW re-installed,

Yeah, so? This only shows that you run totally unprotected, unsecured
and vulnerable systems.

> and in one case
> they put something on the HD that was not removed by blowing the
> partitions and reformating.

Bullshit. What day is it, an International Urban Legend Day?

> One box, running Linux, was also hacked.

Highly unlikely, unless of course you're a big enough idiot to install
the system with default passwords and logins.

> I have lunch, once a month, with ham buddies in a club. Most of them
> have at least one story like one of the above.

Then most of your buddies are clueless, too.

> Another personal friend has a wireless network in his house in a
> suburban neighborhood and he noticed something odd on his computer and
> looked outside the house (at night) and saw a guy parked outside his
> house, laptop screen lighting up his face (its called "war driving" and
> offshoot of war dialing from BBS days). My friend decided to shut off
> his home wireless network power switch and he look out again and the
> guy drove off.
>
> I'm not making this up.

This is getting better and better. Your friend has a home wireless
system that he doesn't even bother password-protecting, then both you
and him wonder how your systems get hacked and who knows what else?

Btw, I can easily tap into at least three or four of my neighbors'
wireless networks at any time, too - no passwords, as you can imagine.
So whose fault is it if their computers get hacked? You leave $1000 in
your driveway, you think it's going to be there the next day?

> Have you ever heard that story that the Titanic is unsinkable? I wonder
> if there is some wisdom to that story?

There is also some wisdom in the story of how you don't stick your dick
in the alligator's mouth unless you want to have it chopped off.


Stray Dog

unread,
Jun 14, 2009, 9:57:01 PM6/14/09
to

On Sun, 14 Jun 2009, Alan Ford wrote:

> Date: Sun, 14 Jun 2009 14:54:43 -0700


> From: Alan Ford <zzz...@qqq.net>
> Newsgroups: rec.radio.amateur.equipment
> Subject: Re: The "other" end that is near....
>

> Stray Dog wrote:
>
>>>> One of the guys here talked about losing internet newsgroups and some of
>>>> us said how he can still get them.
>>>>
>>>> The "other" end of newsgroups is that -- particularly where there is any
>>>> chance of politics to be involved -- they are being taken over by kooks
>>>> and extremists who practice one form or the other of shouting,
>>>> huffing-and-puffing, yelling-and-screaming, beating-the-chest, posting
>>>> one liner insults (or even one or two word insults), name-calling,
>>>> cussing, trivia, superficialities, and other meaningless-purposeless
>>>> Neanderthalisms.
>>>
>>> ??? How is this any different from what the newsgroups used to be 5, 10 or
>>> 15 years ago?
>>
>> I perused many NGs almost 20 years ago and the content was much more
>> thoughtful, substantial, and polite. Today its like the X and Y generation
>> have taken over.
>
> Nothing to do with the generation gap. The stupidity index is a lot
> higher today than at the beginning of the Internet/Usenet because today every
> trailer trash moron and his mother has access to it.

And, this access has certainly not improved the "quality of life" like it
has been promoted to do by all manner of leaders and commericial
interests.

>>>> One of the technical problems of blogs and websies is the chance that
>>>> they can download malicious code onto your computer (keystroke loggers,
>>>> rootkits, viruses, spyware, trojans, etc), and collect personal data on
>>>> you, too. Software firewalls and AV are helpful, but a lot of them, too,
>>>> collect
>>>> data on you (so they are spyware, too).
>>>
>>> The risk is minuscule.
>>
>> Looks to me like you don't keep up with computer security news.
>
> The risk is minuscule, provided you:
>
> - keep your OS and browser updated with security patches

You can hack any OS an browser; just google search on your favorites.

> - run a s/w or h/w firewall, preferably both

Not enough because the firewall will pass files (such as HTMLs, XMLs) that
a firewall would not be configured to reject based on signatures.

> - are not stupid enough to download and run unknown files

This is almost impossible to do in a world where automatic updates are
common and trojanized websites exist.

>>>> With ID theft said to be the fastest growing crime, I'm wondering if the
>>>> degredation in the quality of internet security is, some few years in the
>>>> future, going to lead to another form of economic melt-down as people
>>>> start geting seriously hit in the wallet by the hackers.
>>>
>>> We've been hearing the same tired story ever since the Internet got
>>> invented. The only thing that is the fastest growing in this whole story
>>> is the news media bleating about this "huge threat" in between the
>>> Cheerios and Viagra commercials, then it's off to another "huge threat"
>>> for two minutes, then Cialis and Geico.
>>
>> My cc commpany did send me a new cc card because they said my old number
>> was hacked.
>
> By far, the majority of the credit card ID theft occurs at the vendor
> end, by unscrupulous employees.

When I went into further detail with them, they told me where the
"compromise" took place and it was nowhere near me.

There is no such thing as "hacking" a
> credit card #.

They've even got chips that get replaced in walmart readers where they
grab the numbers and they get sent to a 3rd party which is the hackers.

They've got keyboard overlays at gas stations where they grab the cc
number and your PIN as soon as you enter it.

The old trick: the ATM machine. hacked so you put in your cc, then the
PIN, and no money comes out, but they have your numbers.

Yeah, your cc number can be hacked.

>> I have received several letters over the last few years giving notice that
>> a database was breeched and that I should be on alert for anything that
>> might involve.
>
> Where the hell do you bank, the Al Capone Credit Union?

A branch of one of the larger banks, international, too.

I have accounts
> in four different banks and I haven't received any such notice, ever.

Your tough luck.

> Granted, this is a testimonial "evidence" like yours, but still...

They just don't do dilligence.

>> One of the banks that I do business with put out a public notice about ID
>> theft and crime and being careful about bank data, account numbers, etc.
>
> Yes, because apparently there are still people out there who think it's
> a good idea to write their PIN numbers on cards,

Which proves my point.

leave doors unlocked
> overnight and send money to Nigerian princes.
>>

Also proves my point.

>> I have found two viruses on my computer disks using AV. Since then I am
>> more careful about a lot of things.
>
> ??? What, you mean you reduced the number of unknown exe files you
> download now?

Many more processes than that.

>> A personal friend who confessed that he visited some porno websites also
>> found his computer not working right afterwards and spent a couple of
>> hundred bucks in phone support to get the malicious code off his box.
>
> Iow, a computer illiterate clueless idiot gets surprised after the free
> Underage Russian Midget Lesbian Amputee website downloads turn out to be
> something else.

I'm trying to convey the idea that people need to be more careful.

> Tell your friend to look for Adam's apples on hookers *before* paying.

I tell guys to get their skin views, instead, from magazines from adult
bookstores.

>> Our garbage can, containing our garbage in black plastic bags, had those
>> bags removed by persons unknown and not the garbage truck. Fortunately we
>> had been shredding anything with numbers etc on it for some time.
>
> Holy shit, you are like the Hercule Poirot of the ID theft world - everywhere
> you turn, someone is stealing your ID.

I'd rather assume that than someone is getting free ballast for their
sailboat; particularly when the security media have talked (and have
statistics on) hacking garbage in garbage cans.

> The vast majority of ID theft occurs where it's convenient, low-risk and
> profitable. Dumpster diving is all three at the malls and business. Garbage
> diving in residential areas is none of those three.

The garbage can was in a commercial neighborhood. But, I'd even be careful
in residential areas.

> Phishing for info is all three through massive e-mail spam effort.
> Hacking computers individually and browsing for files is none of those three.

I've obtained a number of used computers, some from thrift stores, some by
gifts: all had personal information that the owners should have been
worried about.

And, there is quite a lot of articles on this in the media.

>> My wife rents commercial office space. I decided to start making backup
>> copies of all working files, including those that needed confidentiality,
>> and deleting the copies on the HD and then over-writing all unassigned
>> spaces on the HD with zeros. That night her office was broken into, two
>> metal file cabinets broken into, and the computer stolen. I was glad they
>> did not get the confidential information.
>
> Now you're just rambling. Low-level formatting of hard drives does fuck all
> to protect from ID theft.

Low-level formating is for head tracking. You never need to re-low level
format. You are talking about high level formating. You do that, and then
you have to re-install everything. You only need to zero out the
unassigned empty disk space. There are utilities to do this, such as
Norton's that writes zeros to all unassigned space. Its faster for me to
unzip a compressed file of zeros.

The thieves who stole the computer chucked it for a
> couple of bucks so that they can buy drugs.

It was never found so we don't know what they did, or why. However, word
around town (I know people) is that a lot of computers were being stolen.

Their reseller is more than
> likely interested in reselling the stolen goods quickly and making a buck,

Premature conclusion based on speculation.

> not in wasting time browsing through millions of files on hundreds of hard
> drives.

Most people put all their files under the folder "My Documents" and not
burried 27 directories deep in "system" folders.

> ID thieves are in the business of stealing IDs.

And, there is a lot of it going on. And, everyone I meet falls into one of
two categories: i) What, me worry? (most people) and ii) a few that take
precautions.

This means getting thousands
> of credit card, social security numbers and addresses at once, using a
> fraction of them quickly and disappearing.

This is only one of several approaches in the ID theft criminology.

> It is a wholesale business. They
> don't fuck around trying to get one number at a time - hence nothing that you
> describe so far fits their modus operandi.

There is a whole spectrum of ID theft. From opportunistic beginners to the
mass market. Articles say if you want good cc numbers, you can get them
now for as low as 50 cents per number and so crooks maybe buy ten or
twenty and start using them whereever they can.

>> In the last nearly ten years, several of my computers were hacked and
>> needed to have the HD nuked and all SW re-installed,
>
> Yeah, so? This only shows that you run totally unprotected, unsecured and
> vulnerable systems.

On the contrary but if you want to tell me you are running an invulnerable
system, then you really can't prove that.

For example, a few years ago I read Ed Skoudis' book "Malware--fighting
malicious code" and newer editions have come out. Basically, hackers can
do anything. You can never prove your system has never been hacked. All
you can say is something like "My AV has not detected anything" which
means your system may have a rootkit on it that the AV can't detect.

You are always vulnerable to infection if the virus comes to your box
before the AV signature comes, and if the virus can hide itself well, then
even after the signature comes, you're screwed.

>> and in one case they put something on the HD that was not removed by
>> blowing the partitions and reformating.
>
> Bullshit.

There are addresses on HDs that are not normally accessible by OSes.

> What day is it, an International Urban Legend Day?

You seem to prefer to be arrogant.

>> One box, running Linux, was also hacked.
>
> Highly unlikely, unless of course you're a big enough idiot to install the
> system with default passwords and logins.

No, but I know it was hacked.

>> I have lunch, once a month, with ham buddies in a club. Most of them have
>> at least one story like one of the above.
>
> Then most of your buddies are clueless, too.

No, they are responsible, careful guys who noticed fishy things and they
all managed to avoid, one way or the other, getting into deeper trouble.

>> Another personal friend has a wireless network in his house in a suburban
>> neighborhood and he noticed something odd on his computer and looked
>> outside the house (at night) and saw a guy parked outside his house,
>> laptop screen lighting up his face (its called "war driving" and offshoot
>> of war dialing from BBS days). My friend decided to shut off
>> his home wireless network power switch and he look out again and the
>> guy drove off.
>>
>> I'm not making this up.
>
> This is getting better and better. Your friend has a home wireless system
> that he doesn't even bother password-protecting,

What this, and all of my other examples, show is that quite a large
fraction of the people are careless about their computer security.

then both you and him wonder
> how your systems get hacked and who knows what else?

Over recent years I've read four books on hacking to teach myself just
what these guys can do. In addition to my personal experience, plus
numberous articles in some five computer trade periodicals that I also
subscribed to, hacking comes up as a major problem that does not get
sufficient attention.

I take many precautions to reduce my vulnerability.

> Btw, I can easily tap into at least three or four of my neighbors' wireless
> networks at any time, too - no passwords, as you can imagine. So whose fault
> is it if their computers get hacked?

I'm not sure if you are trying to just be sarcastic, or sarcastic and
cynical.

You leave $1000 in your driveway, you
> think it's going to be there the next day?

Like my original post, I do recommend to everyone (and give examples) that
they need to tighten up their acts.

I also do not leave money in my driveway.

>> Have you ever heard that story that the Titanic is unsinkable? I wonder if
>> there is some wisdom to that story?
>
> There is also some wisdom in the story of how you don't stick your dick in
> the alligator's mouth unless you want to have it chopped off.

Most people have an intuitive notion to stay away from aligators, but you
missed my point that the Titanic was overpromoted as unsinkable and
everyone fell for it.

Coming back to your analysis that all the new stupidity on the internet is
due to the trailor trashs getting access (that maybe they should never
have gotten to begin with), I would say that your attitude should have
been more along the lines of trying to correct a bad situation instead of
just leaving it as a bunch of "clueless" people.

Of course, there really are sociological and marketing interests that
consider "X-gen" and "Y-gen" personalities as new phenomena and declines
in test scores of US kids over the last few decades represent objective
evidence of a general decline rather than your simplistic opinion.

Stray Dog

unread,
Jun 14, 2009, 10:03:28 PM6/14/09
to

On Sun, 14 Jun 2009, dave wrote:

> Date: Sun, 14 Jun 2009 12:39:23 -0700


> From: dave <da...@dave.dave>
> Newsgroups: rec.radio.amateur.equipment
> Subject: Re: The "other" end that is near....
>
> Stray Dog wrote:
>>
>> On Sun, 14 Jun 2009, dave wrote:
>>
>>> Date: Sun, 14 Jun 2009 06:55:13 -0700
>>> From: dave <da...@dave.dave>
>>> Newsgroups: rec.radio.amateur.equipment
>>> Subject: Re: The "other" end that is near....
>>>
>>> Stray Dog wrote:
>>>>
>>>>
>>>>
>>>> A personal friend who confessed that he visited some porno websites also
>>>> found his computer not working right afterwards and spent a couple of
>>>> hundred bucks in phone support to get the malicious code off his box.
>>>>
>>>> Our garbage can, containing our garbage in black plastic bags, had those
>>>> bags removed by persons unknown and not the garbage truck. Fortunately
>>>> we had been shredding anything with numbers etc on it for some time.
>>>>
>>>
>>> Confessed?
>>
>> I don't understand the question.
>>
>
> "Confessed" implies wrongdoing. Are you a prude?

Oh, your talking about the guy who told me he got his computer screwed up
by going to a porn website.

Yeah, its "wrongdoing" if he finds out afterwards that he could have
avoided trouble by not going there.

What is funny is that he did it a second time, and got his computer
screwed up again, so he didn't learn his lesson the first time around.

And, I remember reading an article which listed the kinds of websites that
are most loaded with malicious code. Good to stay away from them.


Stray Dog

unread,
Jun 14, 2009, 10:05:54 PM6/14/09
to

On Sun, 14 Jun 2009, dave wrote:

> Date: Sun, 14 Jun 2009 12:27:41 -0700

They should be happy getting my 99% of recyclable paper in the form of
unshredded newspapers and magazines. Our shredder output volume is pretty
small.


Michael Black

unread,
Jun 15, 2009, 11:40:14 PM6/15/09
to
On Sat, 13 Jun 2009, Stray Dog wrote:

>
>
> One of the guys here talked about losing internet newsgroups and some of us
> said how he can still get them.
>

The end of usenet is when idiots decide a newsgroup is a hangout and
they post all kinds of off-topic junk rather than go where the discussion
belongs.

Yes, it's bad enough that someone posted here about their usenet problem,
when there are plenty of newsgroups including local, where they could
have posted.

But now you start another thread of an even more off-topic nature, and
then let it slide further off topic, and you are the major poster in this
thread.

You've just helped to kill newsgroups, idiot.

Michael VE2BVW

Stray Dog

unread,
Jun 16, 2009, 7:44:49 AM6/16/09
to

On Mon, 15 Jun 2009, Michael Black wrote:

> Date: Mon, 15 Jun 2009 23:40:14 -0400
> From: Michael Black <et...@ncf.ca>


> Newsgroups: rec.radio.amateur.equipment
> Subject: Re: The "other" end that is near....
>

And you think what you posted above is less off topic?

And, what positive contribution did Alan Ford make besides his confused
rant full of Bart Simpson bratiness?

Oh, I get it now, you expect me to read your mind and come up with
exactly, perfectly, completely just what YOU wanted to hear in a post, and
on-topic exactly as you consider it and according to YOUR standards of
what is an acceptable topic?

And, the guy who was more interested in whether _I_ was a _prude_ than
whether the average computer user on the internet might consider that they
might be exposing themselves to malicious code more than they think.
Maybe that guy was really implying that having an insatiable need for
porno websites is normal?

Fine, you guys can just sit there and lurk until exactly what you want to
hear shows up. I try to inject something practical that contributs to an
awareness of a problem too many people ignore and what happens? The real
idiots come out of the woodwork.

I've been on newsgroups for more than 15 years and it never ceases to
amaze me how many guys out there want to be "net cops" and preach about
what is on or off topic, tell someone else essetially that they posted
something they didn't like, or complain that the content of a thread
drifts off the original topic. Why don't you guys get real and notice that
conversations in all social contexts, lunch groups, clubs, family get
togethers, etc., all drift all over the place.

Oh, maybe you want a moderated newsgroup? Just wait till the moderator
tells you to change something in a submitted post.

The other thing that may be causing the rise of blogs and chatrooms over
newsgroups is eye candy. With graphical content on websites totally
unlimited in terms of color, resolution, animation everyone is being
mezmerised/hypnotized to substitute superficial eye candy gratification
for intellectual content and substance. Funny I don't heare anyone
complaining about the malicious code they are exposing themselves to, or
the constant blast of pop-up advertising, or other advertising.

And, why is ham radio a dying hobby? Kids don't need to take a test and
get a license; just go out and buy a computer and plug it in to the
internet. Or the other big thing: cell phones (don't need a license there
either and they are smaller than handi-talkies) and I can drive around and
if there are more than five cars near me, then at least one of them has a
driver with one hand holding a cellphone up to his ear, and sometimes I
even see them looking down on the cellphone (texting).

Oh, yes, the kids are now (articles in the media saying this) doing
"sexting" (sending cellphone camera imiages of themselves naked) to each
other. I guess that is another thing for that non-prude guy to be happy
about.

Sorry to bother you guys in your hammocks down on your south sea island
beach under the balmy sun, far away from the depression, who don't have a
concern about anything in the world until it involves something you don't
want to hear about.


Michael Coslo

unread,
Jun 18, 2009, 4:27:56 PM6/18/09
to
Stray Dog wrote:

> And, I remember reading an article which listed the kinds of websites
> that are most loaded with malicious code. Good to stay away from them.


127.0.0.1 is your friend. Get and use a hostsfile, and your computer
will be a lot safer.

You'll also be amazed at the "legitimate" sites that are trying to put
stuff on your computer....... One needs not surf porn to get a jacked up
computer.

- Mike -

Michael Coslo

unread,
Jun 18, 2009, 4:30:02 PM6/18/09
to
Michael Black wrote:

> But now you start another thread of an even more off-topic nature, and
> then let it slide further off topic, and you are the major poster in this
> thread.
>
> You've just helped to kill newsgroups, idiot.

Should we send the posts to you for approval, Michael?


C'mon, do you think that OT posts just started?

- Mike -

Stray Dog

unread,
Jun 19, 2009, 3:29:14 PM6/19/09
to
On Thu, 18 Jun 2009, Michael Coslo wrote:

> Date: Thu, 18 Jun 2009 16:27:56 -0400
> From: Michael Coslo <mj...@psu.edu>


> Newsgroups: rec.radio.amateur.equipment
> Subject: Re: The "other" end that is near....
>

I totally agree.


Stray Dog

unread,
Jun 19, 2009, 3:33:35 PM6/19/09
to

On Thu, 18 Jun 2009, Michael Coslo wrote:

> Date: Thu, 18 Jun 2009 16:30:02 -0400


> From: Michael Coslo <mj...@psu.edu>
> Newsgroups: rec.radio.amateur.equipment
> Subject: Re: The "other" end that is near....
>

In every group there are a few individuals who would like to be "net cop"
and be a medieval king: everyone obey MY^ rules, but I don't have to obey
my own rules.

More seriously, what kills newsgroups is a less than critical mass of
people who are willing to author _any_ posts, including OT posts that draw
other people out of their lazyness through the principle of "I'm going to
let someone ELSE do all the work."

Michael Coslo

unread,
Jun 22, 2009, 2:21:06 PM6/22/09
to

I forgot to mention even equipment gets in the mix. Ever install an HP
printer? I spent a lot of time denying internet access to a lot of stuff
they installed on my computer. Too bad they make some really good
printers... Wonder just why 4 or 5 things need to go to the net every boot?

- 73 de Mike N3LI -

Stray Dog

unread,
Jun 23, 2009, 9:30:49 AM6/23/09
to

On Mon, 22 Jun 2009, Michael Coslo wrote:

> Date: Mon, 22 Jun 2009 14:21:06 -0400

I'll tell you another one. One of the hard drive manufacturers had, built
into some memory chip on the hard drive circuit board some code that
"phoned home" for reasons never really disclosed. The guy who found out
called the manufacturer but the rep he talked to couldn't say what the
story was.

A lot of this spyware crap came out in a lot of the computer trade
magazines back 2000 to 2005 or so (computerworld, infoweek, eweek, and
several others). Ed Foster had a "gripeline" column in one of the
magazines and spent a lot of time on what I call the tricky-cheaty-sneaky
crap (everything from spyware to shrinkwrap intimidations). He even had a
website. His magazine laid him off (maybe the advertizers were
intimidated and threatened to pull their ad contracts) so he set up his
own website where he continued to be a forum for user gripes about all
manner of things.

Another article speculated on the idea that a motherboard ROM-pack could
be a place to store a virus or other malicious code and that if you ever
got one there, you'd have to re-flash the ROM-pack to get it out. IIRC,
the same author speculated on other locations (eg. video cards) where
there is memory that can be a home for malicious code.

I bought two netbooks recently (another experience in initial frustration,
but they are working fine now and connecting to the internet through a
very new Sprint "mobile hotspot" model 2200, and it is pretty niffty). The
hotspot is a little box about 1/3 the volume of a pack of cigarettes, you
plug in the wall wart PS, and turn it on. It automatically connects
wirelessly to the Sprint cell phone tower across the street. I can turn on
any or all three of our XP computers (both netbooks and a XP desktop with
a wireless adapter) and they automatically connect to the hotspot. I don't
worry about wardrivers since the house is 700 feet from the public road
at the edge of our property and surely beyond the range of the hotspot,
but it also needs a hexkey put into the software or it doesn't work,
Also, it does NAT so your boxes are IP-address masqueraded.


One reason Microsofts software firewall is a PoC is that it lets any
outgoing packets go that want to go. So, I put on Zone Alarm on to find
out that half the pre-installed aps are probing back to the mothership for
updates. And, what else are they sending back at the same time? One
article said that Microsoft's OSes now send back to the mother ship the
serial number of any network card that you put into your slots.

And, I have a Java package that is trying to update itself and I can't
find it in the installed software list.

Then, we bought a $400 HP laser printer. The printer driver CDROM disk
says it needs 110 MB of HD space. Seems like a lot. After install....
ding, ding...the Zone Alarm pop-up tells me the printer driver is trying
to access the internet.

I read Ed Skoudis' book and wrote the following review. Its a serious
issue......firewalls and AV and anti-spyware are not enough.

One possible future danger is that the hackers and ID theft guys cause so
much degredation in the integrity of internet based business that people
leave the internet in such waves that it has a negative effect on our
economy (another recesson/depression?). Maybe an over-reaction on my part?
After all, so many people I know just are so ambivalent about computer
security, even the commercial entities (cc companies, databases, etc).

Are Macs any better? I did a google search on "hack osx" and got tens of
thousands of hits. After all, OS-X is based on Darwin which is based on
BSD, another unix clone and there are tens of thousands of rootkits for
all the unix flavors, too.

===========
March 27, 2004

This review is composed of a collection of possibly useful
information from the book:

Malware: Fighting Malicious Code
by Ed Skoudis and Lenny Zeltser
Prentice Hall, ISBN 0131014056, c 2004, 647 pp.
$44.99 and, sorry, Amazon says it did not get permission from the
publisher to let you get a "look inside the book" (I was thinking
of putting page references along with some of my comments below but
that won't work now).

After having read Hacking Exposed (McClure etal., c 1999) and
Hacking Linux Exposed (Hatch etal., c 2001), and paging through
Hack Attacks Revealed (Chirillo, c 2001), I thought I should get at
least one good recent overview of the problems in computer-internet
security to figure out where we are these days. When I read the
earlier dated books, it was clear that the internet is very vulnerable.
After reading this newest book, the situation is even worse.
Most of this report is a summary of what I read. At the end of
this post is a list of URLs that may be of use to some of you who
wish to pursue in more detail what is going on out in the internet
jungle. Unix and Windows are given about equal time.

Today, all code and/or instructions that can be used to compromise
your computer are being more and more referred to as _malware_ or
_malicious code_ instead of _virus_. Spyware is one example of
malicious code and, according to the authors' definition, is not
most properly called a virus. I will avoid the discussion about
definitions (they have changed in the last couple of years) to
focus on the main story: anti-virus software and firewalls (such as
ZoneAlarm) are not enough. It may occur to people that spyware
generally gets past both AV and firewall defenses (although the
book acknowledges that some AV software will find some spyware and
other malicious code) so here is the first indication that AV
and firewalls are not enough. Viruses are now defined as,
generally, needing some human action (eg. clicking on an
attachement) to activate them. Worms are now defined as code that
propagates over the net without human intervention.

What else is out there besides viruses and spyware? Attackers
(sometimes called either hackers or crackers) have two categories
of methodologies to use against you besides viruses and spyware: i)
rootkits, and ii) a wide variety of what I will call "control
signals" and "tricks."

A rootkit is at least one file which, once placed on your box,
creates a backdoor that the attacker can use at any time to log
onto your box and use it any way he wants. Rootkits have many
functions including everything they need to make them extremely if
not impossible to detect. At the minimum, rootkits allow attackers
to communicate with your box (even though you have a strong
firewall) and allow the attacker to cover or erase ALL
traces of its existence including any entry or monitoring logs.
Moreover, a rootkit causes the operating sytem to lie to you when
you ask it questions about what files are on the box, their
identity, size, etc. Attackers can even alter the rootkit so that
your antivirus package wont be able to detect the rootkit even if
the rootkit definition is in the antivirus package (the so-called
polymorphic viruses also can change their signature and get past
AVs because the definition in the AV doesn't match the new virus
code). Rootkits can take as little as ten seconds to be placed on
your box. There are more rootkits for the UNIX OS and their clones
than for Windows, but in recent years attackers and developers have
been making rootkits for all of the Windows flavors from 95 up to
XP. Rootkits (as well as some viruses) can deactivate AVs and
disable existing security features, as well as block access to AV
update websites, in the OS.

Under the category I call _tricks_ I place not only spyware (which
gets installed usually without your knowledge or permission) but a
whole range of approaches (often also called _exploits_ [this is to
distinguish them from _vulnerabilities_ which are due to
programming sloppiness]) to gaining access to your box. Many
tricks are not new but many have been developed in the last few
years. Tricks involve the use of very widely available and standard
and quite necessary network analysis tools. They have been
available for network troubleshooting and analysis for years. When
abused, these tools become very powerful tools for hacking. You have
heard of FTP but did you know about TFTP? Trivial File Transfer Protocol
can be used to send code to your box WITHOUT authentication! The Nimda
worm got onto computers of users if they had Internet Explorer and
visited an infected Website. The HTTP page, including the code of
the worm, came onto your computer and as soon as it was displayed,
it got activated and spread again (page 88-91). Firewalls normally
allow HTTP/html protocols/files to pass without interference.
Another trick is to use ICMP (pings) and hook onto the tail of the
ping code a backdoor or other maleware package.

Other tricks include "Trojanized" websites. In other words, the
attackers sneaked their backdoor codes into good programs that
people download voluntarily and install voluntarily on their boxes.
the author documented many cases of this. Do you trust the websites
you go to and download from? Tricky (sorry for the pun) question.

Spyware was not even in the index of my older hacker books but it
is in the 2004 book but is in the category now called "mobile code"
under malware or malicious code.

Skoudis thinks the super-worms are yet to come (p.95). These will
include multi-platform worms that will spread on both Windows and
non-Windows boxes. The SadminD/IIS worm, released in May 2001
propagated on both Windows and Solaris boxes. Clever worms such as
SQL Slammer were very small and used a different trick to
propagate: UDP (User Datagram Protocol) instead of TCP/IP
(Transmission Control Protocol/Internet Protocol). UDP does not
need two way authentication. Taking over a web browser can also
take place with special embedded scripts in a web page. "Browser
hijacking" is where the attacker actually takes over control of the
browser. At a minimum, this can result in your browser going to a
different website and you can't change it back. The book gives
several examples of scripts that you can type into the URL window
and you get interesting and weird displays that you would not
expect. These scripts can also launch an "invisible" browser in
addition to the one you are viewing with, and instruct the
invisible browser to go to another website and download malicious
code. This approach can also be used to steal your cookie file.
With that and your identity, they can go order anything they want
from anywhere and you get stuck with the bill. Another way
malicious code can get on your box is with scripts embedded in the
reflected URL that you often get when you visit a home page. You
type in www.xxx.com and what comes back is something like
www.xxx.com/etc/blah-blah?=xzq/??/java.script/etc and it causes
your browser to do something you don't want it to do. There were
some 30 pages of details on this, not including many pages on
spyware plug-ins and many more pages on JAVA exploits. Another
trick is called Web bugs. They can be tiny images in an HTML
document and when the file is loaded into the browser, it can send
out a call to an attacker's web site and download a backdoor,
rootkit, or virus, or whatever. The book says that some AV packages
will detect some web bugs, but the variabilities are so high that
new bugs will not be detected.

It should be pointed out that the Mac OS-X was mentioned in the
book in a number of places. OS-X is a derivative of BSD, a Unix
clone itself. A large fraction of the URLs below deal with Unix
and/or Unix clones, if not OS-X directly. Skoudis spent some time
discussing the possibility of JAVA viruses which could enter the
Mac browser and attack the platform just as easily as they could in
other Unix browsers or Windows browsers. He did not document a
known case, but it may only be a matter of time. At one point in
the book, rootkits were said to be available for the OS-X. OS-X will
certainly be immune to viruses targeted to Windows, but it will not
necesarily be immune to the other malware out there and if a
rootkit is available (there is one called a universal rootkit that
was said to work on all flavors of Unix) then a Mac owner is going
to be as vulnerable to hackers as any box with Unix on it.

One thing missing from the book was some kind of evaluation of the
references given.

So, where do we go with all of this information? There seem to be two
kinds of internet miscreants. First, the so-called
'script kiddies' who just play with hacker tools out of immature interests
in creating mischeif but are othewise clueless about responsibility to
society. Second, the really serious hackers that are out to steal your
identity, steal data but are probably even more interested in
working on getting financial information from large
corporation/govt/institutional systems and use what they find to
commit crimes (at least one case was documented in the book). The former
may number in the tens of thousands, the latter may be in the mid to high
hundreds. I went to the www.rootkit.com website and registered myself to
see what was there. They indicate that they have about 14,000 registered
users. You can't get past the homepage without registering (If all of the
downloadable files were rootkits, then there must have been 30 or
so but I didn't actually count them). You can probably estimate
that maybe one tenth of those 14,000 are really serious hackers. The rest
are probably curious like me. At the time I was logged on, the website
reported that there were five other people visiting the website.
Everyone there has a hacker-type userid name (you don't think I gave them
my real name, do you?). With us simple users in the high tens of millions,
each one of us may be a relatively small target.

A second fact that protects us a little is that probably most if
not all of us are logging onto servers or accounts where our IP
address is assigned on a rotating basis. Thus, it would be
difficult for them to locate any one of us out of maybe thousands
if not at least tens of thousands of subscribers to that ISP (millions
for big ISPs like AOL, MSN, etc). Also, if we are logged on for relatively
short periods of time, hacking into our boxes will be more difficult. For
people on fixed IP addresses and continuous connections, you have to worry
about being hacked. Other than that, I think the really bad guys are after
targets that are much bigger than a home desktop or home network.

Damaging viruses (don't click on anything) or worms (can't be
stopped unless you have a definition) that appear before you have
a definition can hurt you. The book makes it pretty clear that
efforts to detect (non virus) malware on our boxes may not be so
practical. Spyware is constantly changing so definitions for it
will have to be upgraded, too. Spyware (as far as I know, mostly
targeting Windows boxes) routinely gets past firewalls and even AV
protection (is there anyone out there that has never gotten any
spyware on their Windows boxes? I don't recall hearing much about
spyware on non-Internet Explorer browsers). It may simply be most
practical to have all of your working files in one directory and
the OS and applications in all the other directories and do a mass
backup in case you detect weird behavior or altered functions on
your box. Then, reformat and reinstall everything. You should plan
for this.


References:
I HAVE NOT CHECKED THE URLS BELOW. I HAVE LISTED THEM AS A PARTIAL
LIST OF RESOURCES REFERENCED IN THE BOOK. IN VIEW OF THE FACT THAT
EVEN WEBSITES HAVE BEEN TROJANIZED, ONE MAY WANT TO BE HESITANT
ABOUT VISITING ANY OF THESE WEBSITES AND/OR DOWNLOADING CODE. IT
DOESN'T MATTER IF YOU PAY FOR STUFF OR GET IT FOR FREE; IT MIGHT
HAVE A VIRUS OR TROJAN IN IT.

ROOTKITS ARE AVAILABLE AT:

www.rootkit.com.

SPYWARE (beware-I've heard that some of these might not be free or
simple or fully disclose what they are doing, I've seen 'adaware'
in URLs and its not the same outfit that puts out 'ad-aware'):
security.kolla.de (spybot)
www.____usa.com (ad-aware)
www.webroot.com
www.pestpatrol.com
www.itcompany.com
www.wilderssecurity.com

TRICKS:
www.peacefire.com/security/iecookies
dslweb.nwnexus.com/mclain/ActiveX/Exploder/FAQ.htm
www.phrack.org

EMAIL WIRETAPPING:
www.lawyerware.com/article.asp?article=20

DEFENSES AGAINST ATTACKS:

www.tripwire.com
www.tripwire.org
www.chkrootkit.org
www.securityfocus.com
www.cs.tut.fi/~rammer/aide.html
osiris.shmoo.com
www.atstake.com
www.founstone.com
www.sysinternals.com
www.megasecurity.com
packetstormsecurity.org
www.bo2k.com
www.md5summer.org
www.sourceforge.com (snort, an IDS tool)
monkey.org (hacks)
www.outguess.org/detection.php
www.cert.org
store.sans.org
www.anticracking.sk
www.cisecurity.org
www.geocities.com/fcheck2000/fcheck.html
www.insecure.org
www.sOftpj.org/en/tools.ntml
SOFTWARE FIREWALLS

www.zonealarm.com
www.tinysoftware.com
blackice.iss.net
www.symantec.com

MORE ON VIRUSES/WORMS:

www.viruslist.com/eng/viruslistbooks.html?id=36
lcamtuf.core-dump.cx/worm.txt
www.silicondefense.com/flash/

ANONYMIZING WEBSITES:
www.anonymizer.com
www.idmask.com
www.inetprivacy.com
www.the-cloak.com
anon.inf.tu-dresden.de
www.megaproxy.com

UNIX HARDENING:

www.bastille-linux.org

WEBSITES LISTING HOAXES:

www.truthorfiction.com
hoaxbusters.ciac.org
www.vmyths.com

EASTER EGGS (benign trojans, documented easter eggs in MS Excel 97,
2000, there are thousands of Easter Eggs)
www.eeggs.com

MACINTOSH RELATED
www.uk.research.att.com/vnc
www.connectix.com
bochs.sourceforge.net
packetstormsecuruty.nl/UNIX/penetration/rootkits
--------------------------------------------


Kevin Alfred Strom

unread,
Dec 7, 2009, 10:49:12 AM12/7/09
to
Stray Dog wrote:
>
[...]

>
> I'll tell you another one. One of the hard drive manufacturers had,
> built into some memory chip on the hard drive circuit board some code
> that "phoned home" for reasons never really disclosed. The guy who found
> out called the manufacturer but the rep he talked to couldn't say what
> the story was.
>
> A lot of this spyware crap came out in a lot of the computer trade
> magazines back 2000 to 2005 or so (computerworld, infoweek, eweek, and
> several others). Ed Foster had a "gripeline" column in one of the
> magazines and spent a lot of time on what I call the
> tricky-cheaty-sneaky crap (everything from spyware to shrinkwrap
> intimidations). He even had a website. His magazine laid him off (maybe
> the advertizers were intimidated and threatened to pull their ad
> contracts) so he set up his own website where he continued to be a forum
> for user gripes about all manner of things.
>
[...]

Thanks for the extensive information! I find that using the Noscript
addon with Firefox blocks a _lot_ of unwanted and unnecessary and
malicious garbage on the Web.


With all good wishes,


Kevin, WB4AIO.

0 new messages