Showing posts with label Software. Show all posts
Showing posts with label Software. Show all posts

Operating system vulnerability to viruses

Not much different from the human body which sometimes susceptible to disease due to no body's defense against attack. This is of special concern in the 1990s, when Microsoft gain market dominance in desktop operating systems and office suites. Users of Microsoft software (especially networking software such as Microsoft Outlook and Internet Explorer) is vulnerable to the spread of the virus. Microsoft software is targeted by virus writers because of their desktop dominance, and is often criticized for including many errors and holes for virus writers to exploit. Integrated and non-integrated Microsoft applications (like Microsoft Office) and applications with scripting languages with access to the system files (such as Visual Basic Script (VBS), and applications with networking features) are also very vulnerable. 

Although Windows is by far the most popular operating system is the target for virus writers, viruses also exist on other platforms. Any operating system that allows third parties to run the program can theoretically run viruses. Some operating systems more secure than others. Unix-based operating system (and NTFS-aware applications on Windows NT-based platforms) only allow users to run executables within their own protected memory space. 

Internet-based experiments revealed that there are cases when people are willing to press a certain button to download a virus. Security analyst Didier Stevens ran a half-year campaign on Google AdWords ads that say "Is your PC virus-free Get it? Infected in here!". The result is 409 clicks. 

In 2006, there were relatively few security exploits targeting Mac OS X (with Unix-based file system and kernel). Total viruses for Apple's operating system older, known as Mac OS Classic, varies from source to source, with Apple stating that there are only four known viruses, and independent sources stating there were 63 viruses. Many Mac OS Classic viruses targeted HyperCard authoring environment. Virus susceptibility difference between Mac and Windows is a chief selling point, one of which Apple used in their Get a Mac ad. In January 2009, Symantec announced the discovery of a trojan that targets the Mac. This discovery does not get the coverage that is until April 2009. 

Meanwhile, Linux, and Unix in general, always native blocked normal users from having access to make changes to the operating system environment, Windows users generally do not. These differences continue in part because of the widespread use of an administrator account in contemporary versions like XP. In 1997, when a virus for Linux was released - known as "Bliss" - leading antivirus vendors issued warnings that Unix-like system can be a victim of the same viruses as Windows. Bliss virus may be considered characteristic of viruses - as opposed to worms - on Unix systems. Bliss requires that the user run it explicitly, and can only infect programs that the user has access to modify. Unlike Windows users, most Unix users do not login as an administrator user except to install or configure software; as a result, even if the user ran the virus, it could not harm their operating system. Bliss virus never became widespread, and remains mainly curiosity research. Its creator later posted the source code to Usenet, enabling the researchers to see how it works.

Computer Virus Infection Strategy


In copies of itself to grow in your computer, the virus should be possible to execute code and write code into memory. For this reason, many viruses attach to executable files that can be part of legitimate programs. If a user tries to launch a program that is infected, the virus code can be run simultaneously. Viruses can be divided into two types according to their behavior when they run. non-resident viruses immediately search for other computers that may be infected, infect these targets, then transfer control to the program an infected application. Resident viruses do not search for hosts when they started. Instead, you load the memory resident virus in the execution and transfer control to host program. The virus remains active in the background and infects new hosts when files are accessed from another program or operating system itself. 



Non-resident viruses 
Non-resident viruses can be considered as composed of modules and module finder replication. Finder module is responsible for finding new files to infect. For each new executable file finder module meeting, she calls the replication module to infect files. 


Resident viruses
Resident viruses contain a replication module which is similar to what is used by the virus overseas. This module, however, is called a finder module. The cost in the form of virus replication in memory when running, however, and ensuring that this module runs every time you call the operating system to perform certain operations.Replication module can be called, for example, each time the operating system executing file. In this case, the virus infects all the right programs running on your computer. 


Resident viruses are sometimes divided into the category of fast infectors and a category slow infectors. Fast infectors are designed to infect as many files as possible. A fast infector, for instance, can infect every potential host file that is accessed. This poses a particular problem when using anti-virus software as a virus scanner will have access to all files that have the potential to accommodate the computer when you run the analysis at the system level. If the virus does not realize that this virus is present in memory, the virus can "piggy-back" on the virus scanner and in this way infect all files that were analyzed. Fast infectors rely on fasting levels of the spread of infection. 


The disadvantage of this method is that infecting many files may make detection more likely, because the virus can slow down your computer or perform many suspicious actions that can be seen from anti-virus software. Slow infectors, on the other hand, are designed to infect hosts infrequently. Some slow infectious agent, for example, only infect files when they are copied. Slow infectors are designed to avoid detection by limiting their actions: this is less likely to reduce significantly the computer and at best, often trigger anti-virus software that detects suspicious behavior in the program. Slow infector approach, however, does not seem right.



ref: wikipedia.org

Changing MAC address In Windows XP/Vista and Linux

I guess you've never heard of this tutorial, but I am here just to repeat it.
Ok go directly to the problem...!!!!

There are two ways change MAC address on Windows.

Method #1: Changing MAC address by changing NIC properties from Device Management System.

This is depending on the type of Network Interface Card (NIC) you have. If you have a card that doesn’t support Clone MAC address, then you have to go to second method.

a) Go to Start->Settings->Control Panel and double click on Network and Dial-up Connections.

b) Right click on the NIC you want to change the MAC address and click on properties.

c) Under "General" tab, click on the "Configure" button

d) Click on "Advanced" tab

e) Under "Property section", you should see an item called "Network Address" or "Locally Administered Address", click on it.









f) On the right side, under "Value", type in the New MAC address you want to assign to your NIC. Usually this value is entered without the "-" between the MAC address numbers.

g) Goto command prompt and type in "ipconfig /all" or "net config rdr" to verify the changes. If the changes are not materialized, then use the second method.

h) If successful, reboot your system.

Method #2: This should work on all Windows 2000/XP/Vista systems

a) Go to Start -> Run, type "regedt32" to start registry editor. Do not use "Regedit".

b) Go to "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}". Double click on it to expand the tree. The subkeys are 4-digit numbers, which represent particular network adapters. You should see it starts with 0000, then 0001, 0002, 0003 and so on.

c) Find the interface you want by searching for the proper "DriverDesc" key.

d) Edit, or add, the string key "NetworkAddress" (has the data type "REG_SZ") to contain the new MAC address.

e) Disable then re-enable the network interface that you changed (or reboot the system).

Getting MAC address from command line

a) Go to Start -> Run (or win key   R) type "cmd" then press Enter.

b) type "getmac" at the console window. Windows will show you MAC address of all NIC (ethernet and wireless) NIC on your computer.

Spoof MAC address in Linux
To change/clone your MAC address in Linux (and most *nix system) is very easy to do. All it takes is two easy to script commands:

ifconfig eth0 down hw ether 01:02:10:B0:80:A1
ifconfig eth0 up

eth0 = enthernet 0
01:02:10:B0:80:A1 = new MAC address you want to change to.

Yes, it is very easy to change MAC address without use any third party script/application. You can change your MAC address anytime that you need.

good luck and success, do not never feel bored to increase knowledge
!!!!

Compression, Encryption, Deduplication, and Replication: Strange Bedfellows

One of the great ironies of storage technology is the inverse relationship between efficiency and security: Adding performance or reducing storage requirements almost always results in reducing the confidentiality, integrity, or availability of a system.

Many of the advances in capacity utilization put into production over the last few years rely on deduplication of data. This key technology has moved from basic compression tools to take on challenges in the fields of replication and archiving, and is even moving into primary storage. At the same time, interconnectedness and the digital revolution has made security a greater challenge, with focus and attention turning to encryption and authentication to prevent identity theft or worse crimes. The only problem is, most encryption schemes are incompatible with compression or deduplication of data!

Incompatibility of Encryption and Compression

Consider a basic lossless compression algorithm: We take an input file consisting of binary data and replace all repeating patterns with a unique code. If a file contained the sequence, “101110″ eight hundred times in a row, we could replace the whole 4800-bit sequence with a much smaller sequence that says “repeat this eight hundred times”. In fact, this is exactly what I did (using English) in the previous sentence! This basic concept, called run-length encoding, illustrates how most modern compression technology functions.
Replace the sequence of identical bits with a larger block of data or an entire file and you have deduplication and single-instance storage! In fact, as the compression technology gains access to the underlying data, it can become more and more efficient. The software from Ocarina, for example, actually decompresses jpg and pdf files before recompressing them, resulting in astonishing capacity gains!

Now let’s look at compression’s secretive cousin, encryption. It’s only a small intellectual leap to use similar ideas to hide the contents of a file, rather than just squashing it. But encryption algorithms are constantly under attack, so some very smart minds have come up with some incredibly clever methods to hide data. One of the most important advances was public-key cryptography, where two different keys are used: A public key used for writing, and a private key to read data. This same technique can be used to authenticate identity, since only the designated reader would (in theory) have the key required.
Cryptography has become exceedingly complicated lately in response to repeated attacks. Most compression and encryption algorithms are deterministic, meaning that identical input always yields the same output. This is unacceptable for strong encryption, since a known plaintext attack can be used with the public key to reveal the contents. Much work has focused on eliminating residues of the original data from the encrypted version, as illustrated brilliantly on Wikipedia with the classic Linux “tux” image. The goal is to make the encrypted data indistinguishable from random “noise”.
What happens when we mix these powerful technologies? Deduplication and encryption defeat each other! Deduplication must have access to repeating, deterministic data, and encryption must not allow this to happen. The most common solution (apart from skipping the encryption) is to place the deduplication technology first, allowing it access to the raw data before sending it on to be encrypted. But this leaves the data unprotected longer, and limits the possible locations where encryption technology can be applied. For example, an archive platform would have to encrypt data internally, since many now include deduplication as an integral component.
Why do we prefer compression to encryption? Simply because that’s where the money is! If we can cut down on storage space or WAN bandwidth, we see cost avoidance or even real cost savings! But if we “waste” space by encrypting data, we only save money in the case of a security breach.

A Glimmer of Hope

I had long thought this was an intractable problem, but a glimmer of hope recently presented itself. My hosting provider allows users to back up their files to a special repository using the rsync protocol. This is pretty handy, as you can imagine, but I was concerned about the security of this service. What happens if someone gains access to all of my data by hacking their servers?
At first, I only stored non-sensitive data on the backup site, but this limited its appeal. So I went looking for something that would allow me to encrypt my data before uploading it, and I discovered two interesting concepts: rsyncrypto and gzip-rsyncable.
rsync is a solid protocol, reducing network demands by only sending the changed blocks of a file. But, as noted, compression and encryption tools change the whole file even if only a tiny bit has been altered. A few years back, the folks behind rsync (who also happen to be the minds behind the Samba CIFS server) developed a patch for gzip which causes it to compress files in chunks rather than in their entirety. This patch, called gzip-rsyncable, hasn’t been added to the main source even after a dozen years, but yields amazing results in accelerating rsync performance.
The same technique was then applied to RSA and AES cryptography to create rsyncrypto. This open source encryption tool makes a simple tweak to the standard CBC encryption schema (reusing the initialization vector) to allow encrypted files to be sent more efficiently over rsync. In fact, it relies on gzip-rsyncable to work its magic. Of course, the resulting file is somewhat less secure, but it is probably more than enough to keep a casual snooper at bay.
Both of these tools are similar to modern deduplication techniques in that they chop files up into smaller, variable-sized blocks before working their magic. And the result is awesome: I modified a single word in a large word document that I had previously encrypted and stored at the backup site and was able to transfer just a single block of the new file in an instant rather than a few minutes. My only real issue is the lack of integration of all of these tools: I had to write a bash script to encrypt  my files to a temporary directory before rsyncing them. I wish they could be integrated with the main gzip and rsync sources!
If you are interested in trying out these tools for yourself, and if you use a Mac, you are in luck: Macports offers both tools as simple downloads! Just install macports, type “sudo port install gzip +rsyncable” to install gzip with the –rsyncable flag, then type “sudo port install rsyncrypto” and you’re done! I’ll post more details here if there is interest.

Ref : http://blog.fosketts.net/2009/02/05/compression-encryption-deduplication-replication/

Computer Viruses


A virus is a program designed by a computer programmer (malicious hacker) to do a certain unwanted function. The virus program can be simply annoying like displaying a happy face on the user's screen at a certain time and date. It can also be very destructive and damage your computer's programs and files causing the computer to stop working.
The reason why hackers create viruses are open for speculation. The most quoted reason is simply to see if it can be done. Other reasons are Ludite based "smash the machine" motivations, antiestablishment/anti-corporate actions, criminal intent, and various others that range into the "conspiracy theory" realm.
Viruses take two basic forms
One is a boot sector viruses which infect the section of a disk that is first read by the computer. This type of virus infects the boot or master section of any disks that it comes in contact with. The second is a program virus that infects other programs when the infected program is run or executed. Some viruses infect both and others change themselves (polymorphic) depending on the programs they encounter.
Though viruses do not damage computer hardware there have been attempts to create programs that will do things like run the hard drive until it fails or lodge itself in the computer's clock (which has a rechargeable battery) allowing it to remain active even months after the computer has been unplugged. Other viruses affect certain microchips (BIOS chip for instance). These microchips need to be modified under normal computer use but the virus program can produce changes which cause them to fail. Other viruses will affect the characters or images displayed on the screen which may give the impression of monitor failure.
Viruses can cause a great deal of damage to the computers it infects and can cost a lot of time and money to correct it.
Computer viruses have been around for a long time, even before computers became widely used and they will likely remain with us forever. For that reason computer users will always need ways to protect themselves from virus programs. The main, common feature of a virus is that it is contagious! Their sole purpose is to spread and infect other computers.
A computer gets a virus from an infected file.
The virus might attach themselves to a game, a program (both shareware and commercial) or a file downloaded from a bulletin board or the Internet.
You cannot get a virus from a plain email message or from a simple text file! That is because the virus needs to be 'run' or executed before it can take effect. This usually happens when the user tries to open an infected program, accesses an infected disk or opens a file with an infected macro or script attached to it. A plain email message is made up of text which does not execute or run when opened.
Modern email programs provide the ability to allow users to format email messages with HTML and attach scripts to them for various purposes and it is possible for a malicious hacker to attempt to spread a virus by building a virus script into an HTML type of email message.
When you are accepting software or scripts on Internet sites or reading mail from unknown senders it is best not to run a program from that site or sender without checking it with an anti-virus program first.
Protect yourself
You can take safeguards against virus infection. The first thing is to get an anti-virus program. Most reputable companies that create virus protection programs release an evaluation copy that an Internet user can download for free and use for a certain amount of time. This anti-virus program will be able to check your computer for viruses and repair damage or delete files that are infected with viruses. You may have to replace infected files that cannot be repaired.
The second thing you can do is purchase a copy of the program. The reason for this is that viruses are constantly being created. When you purchase an anti-virus program you are also purchasing periodical updates which keep your anti-virus program up-to-date and able to deal with new viruses as they are encountered. Commercial virus programs also allow the user to customize when and how the program will check the computer for viruses. You will need to renew this updating service periodically.
If you find that your computer has been infected with a virus use an anti-virus program to clean your computer and make sure to check all the disks that you use. This includes all the hard drives on your computer(s) and all your floppy disks and CDs as well as any media that you save information on. Remember that the virus can easily re-infect your computer from one infected file!
If you have to reload your computer programs, use the original program disks. You may want to check your original disks before reinstalling the software. If your original disks are infected contact the distributor to get replacements.
Always take the time to ensure that your computer is properly protected. Spending money on a good virus checking program could save you hundreds of dollars and lots of time later.
A discussion of viruses would not be complete without mentioning hoaxes. Malicious people without programming skills will send out fake virus warnings causing people to take unnessary measures which often cause your computer harm. One example tries to get the unsuspecting computer user to delete an important system file by warning them that it is a virus. A legitimate virus warning will provide a link to a website operated by an anti-virus company with more information about that virus. Don't forward a virus warning until you have check out whether it is legitimate.

Measurements of Data Speed

Today there are generally 2 ways of describing data transfer speeds: in bits per second, or in bytes per second. As explained above, a byte is made of 8 bits. Network engineers still describe network speeds in bits per second, while your internet browser would usually measure a file download rate in bytes per second. A lowercase "b" usually means a bit, while an uppercase "B" represents a byte.

Bps 

Known as bits per second, bps was the main way of describing data transfer speeds several decades ago. Bps was also known as the baud rate, therefore, a 600 baud modem was one which could transfer data at around 600bps.

Kbps 

kilobits per second, or 1000 bits per second.

Mbps

1,000,000 bits per second (usually used in describing internet download/upload speeds).

Gbps

1,000,000 kilobits per second or 1,000,000,000 bits per second. This term is most commonly heard in local area networks, where the close proximity of machines allows for lightning fast data transfer rates.

Names for different sizes of data

When choosing a new computer we come across terms such as "300GB hard drive" and "500MB download", and to the uninitiated, this can be somewhat disconcerting. Data in a computer is represented in a series of bits. Since the birth of computers, bits have been the language that control the processes that take place inside that mysterious black box called your computer. In this article, we look at the very language that your computer uses to do its work.

Bit 

A bit is simply a 1 or a 0. A true or a false. It is the most basic unit of data in a computer. It's like the dots and dashes in Morse code for a computer. It's also called machine language.

Byte 

In computer science a byte is a unit of measurement of information storage, that equals '8 bits', can be used to represent letters and numbers. For example, the number 01000001 is 8 bits long, and represents the letter A in ASCII.

kB 

A kB is a unit of data that equals 1024 bytes. This is because 8 bytes cannot contribute into 1000.

MB 

Megabyte is 1024kB squared, 10242

GB

A gigabyte is a unit of data storage worth a billion bytes meaning either exactly 1 billion bytes (10243) or approximately 1.07 billion bytes. More often than not in advertising, Gigabytes are presented as 1 billion bytes and not 10243 (read the fine print in your adverts!). This explains why a freshly formatted 500GB hard drive shows up at a 450GB one instead. Not too long ago many people were discussing storage in Megabytes. These days, storage has become so cheap that having Gigabytes is considered the norm.

TB 

A terabyte is 10244 and is defined as about one trillion bytes, or 1024 gigabytes. Data centres such as those operated by Google handle thousands if not millions of terabytes of data each day. As storage becomes cheaper and faster, terabytes are becoming a commonly heard term.

PB 

 A petabyte is a unit of information or computer storage equal to one quadrillion bytes (10245). Microsoft stores on 900 servers a total of approximately 14 petabytes.

Software


Software, commonly known as programs, consists of all the electronic instructions that tell the hardware how to perform a task. These instructions come from a software developer in the form that will be accepted by the operating system that they are based on. For example, a program that is designed for the windows operating system will only work for that operating system. Compatibility of software will vary as the design of the software and the operating system differ. A software that is designed for Windows XP may experience compatibility issue when running under Windows 2000 or NT.
Software can also be described as a collection of routines, rules and symbolic languages that direct the functioning of the hardware.
Software is capable of performing specific tasks, as opposed to hardware which only perform mechanical tasks that they are mechanically designed for. Practical computer systems divide software systems into three major classes:
  1. System software: Helps run computer hardware and computer system. Computer software includes operating systems, device drivers, diagnostic tools and more.
  2. Programming software: Software that assists a programmer in writing computer programs.
  3. Application software: Allows users to accomplish one or more tasks.
The term "software" is sometimes used in a broader context to describe any electronic media content which embodies expressions of ideas such as film, tapes, records, etc. Software is the electronic instruction that tells the computer to do a task.

A Computer-based system

A Computer-based system is a system in which a computer is involved and consists of three major elements: Hardware, Software, and User. The elements of a computer based system are described in the three following scenarios:
1. Registration in a University

Hardware = Micro computers, Network platform, and a Server Computer
Software = Student Registration Application, Database, and Operating System
User = Operators, Administrators

2. Controlling a section of an Assembly Line

Hardware = A specially embedded system which is developed for this purpose
Software = The machine code Loaded on the Embedded system Memory
User = Other Machine, Supervisor

3. Playing a game with a Computer

Hardware = Game Console such as XBox, Playstation
Software = The Game itself
User = The little kid

Prepared by Seid ICT Sales & Service Somaliland