Malwarebytes has recently uncovered evidence that a company called IOBit based in China is stealing and incorporating our proprietary database and intellectual property into their software. We know this will sound hard to believe, because it was hard for us to believe at first too. But after an indepth investigation, we became convinced it was true. Here is how we know.
We came across a post on the IOBit forums (cached version since they deleted the thread - well, now the cached version got deleted as well. Glad I still have a screenshot, see below) that showed IOBit Security 360 flagging a specific key generator for our Malwarebytes’ Anti-Malware software using the exact naming scheme we use to flag such keygens: Don’t.Steal.Our.Software.A.
Dont.Steal.Our.Software.A, File, G:\Nothing Much\Anti-Spyware\Malwarebytes’ Anti-Malware v1.39\Key_Generator.exe, 9-30501
Why would IOBit detect a keygen for our software and refer to it using our database name? We quickly became suspicious. Either the forum post was fraudulent or IOBit was stealing our database.
So we dug further. We accumulated more similar evidence for other detections, and we soon became convinced that this was not a mistake, it was not a coincidence, it was not an isolated event, and it persisted presently in their current database. They are using both our database and our database format exactly.
The final confirmation of IOBit’s theft occurred when we added fake definitions to our database for a fake rogue application we called Rogue.AVCleanSweepPro. This “malware” does not actually exist: we made it up. We even manufactured fake files to match the fake definitions. Within two weeks IOBit was detecting these fake files under almost exactly these fake names.
We can’t publicly show all the evidence we found, because it is still our intellectual property: proprietary information about our database internals. But we don’t want you to have to take our word for it either, so we found a way to show you an example illustrating an indisputable pattern of theft.
Consider the file, dummy.exe. It is a harmless dummy executable that runs, displays a “Hello World” message box, and exits. You can see from third-party scans on VirusTotal, that no other security vendor flags this executable as malicious or even suspicious.
We created this dummy executable, then manipulated it slightly so that it matches one of the signatures in our database. We emphasize that it is still not malicious! — the signature is perfectly benign, when not in the context of actual malware, as you can see from the VirusTotal results.
We scanned the file with our own Malwarebytes’ Anti-Malware software and indeed it was flagged as “Don’t.Steal.Our.Software.A”. We scanned it with IOBit using their current build and database version and it was flagged as the same “Don’t.Steal.Our.Software.A”. We have included log file file and a screenshot of the detection. You can verify by yourself using the dummy executable and their most recent database.
We have attached two other such dummy executables to this post, so you can see for yourself. One of them, “rogue.exe”, matches our fake Rogue.AVCleanSweepPro (screenshot) definition, the other “fake.exe”, matches our Adware.NaviPromo definition (screenshot). VirusTotal results for “fake.exe” and “rogue.exe” so you can see they are benign. You can see a screenshot of our detections here.
During the course of our investigation, we uncovered additional evidence that IOBit may have stolen the proprietary databases of other security vendors as well. We are in the process of contacting these vendors.
Malwarebytes intends to pursue legal action against IOBit. We demand IOBit immediately remove all traces of Malwarebytes’ proprietary research and database from their software. We also demand IOBit be delisted from Download.com due to Terms of Service violations. This is criminal: it is theft, it is fraud, and we will not stand for it.
What can you do to help? If you feel the same way we do about this theft, we encourage you to send an email to hosting services such as Download.com and Majorgeeks.com requesting that all IOBit software be removed.
Copy/paste of the original Article here
Update to this post: IOBit’s Denial of Theft Unconvincing
Monday, November 2, 2009
IOBit Steals Malwarebytes’ Intellectual Property
Tuesday, February 17, 2009
Virut and other File infectors - Throwing in the Towel?

I actually wanted to blog about this last week, but didn't find the time yet...
In the last couple of weeks, I noticed a HUGE increase of Virut present on computers. As a matter of fact, 30% of the infected computers I analyzed were infected with Virut. This is bad, really bad... :-(
Virut is a Polymorphic File Infector that infects .EXE and .SCR files. It opens a Backdoor by connecting to a predefined IRC Server and waits for commands from the remote attacker - for example to download/run more malware on the compromised computer. Emails may be harvested as well.
This latest variant may also search for htm, html, asp and php files on the drives and modifies them by inserting an iframe that points to a malicious website. So you can already imagine what may happen if the owner is a webdesigner and uploads the infected webpages.
An excellent write up on this latest variant (and previous one) can also be found here (by Nicolas Brulez): http://securitylabs.websense.com/content/Blogs/3300.aspx
Disinfection of the infected webpages should be easy - it's just a matter of deleting the iframe script in it.
The disinfection of the infected exe and scr files is something else...
Since Virut infects legitimate files, the files may not be deleted, but disinfected instead. And that's where the problems start...
Virut was known to be a buggy Virus in the past and it appears that this hasn't changed yet. We've seen this with other File infectors as well: To Junk Or Not To Junk.
And because of that, Virut may misinfect a proportion of executable files > result > corrupted file.
The same applies for other File infectors such as Sality.
If I guide someone with Virut (or any other File Infector) present and their Antivirus cannot properly disinfect it, then I recommend a format and reinstall.
And even though an Antivirus is able to disinfect the files, in a lot of cases, many files will be corrupted anyway > result > many programs won't work > loads of errors > corrupted Windows + there's still no guarantee that the Virus is really gone.
So why bother to clean this if a format and reinstall is the fastest and especially the safest solution?
And that's why I am blogging about this in the first place, especially since Virut is a very common infection nowadays. It's a pity to see that so many people are struggling with it and whatever they try, nothing helps. Then they ask for support via the forums and in a lot of cases, the one who is helping/guiding won't give up either and posts a new set of instructions to deal with this one.
Unfortunately another failure as result, so again, new instructions are posted... and this may go on and on...sometimes for weeks....
Is this responsible?
I'm not saying it fails everytime, but from what I have seen so far and especially if you're helping someone else with this infection... don't guarantee them a "clean" and errorfree computer afterwards .
In anyway, that's how I see it. Imho, dealing with such infections is a waste of time and that's why I prefer the fastest and safest solution - which is a format and reinstall.
Many people may see this as "giving up", but I see this different.
After all, I think it would be irresponsible to let the malware "stew" (download/spread/run more malware) for another couple of days/weeks if you already know it's a lost case.
Monday, October 27, 2008
That was a stupid thing to say
I was helping someone yesterday with a SEVERLY infected computer. This computer was infected for at least 1 year since older malware was still active and running, with on top, newer malware including a File infector, some backdoors, random adware and god knows what else...
So you can imagine there wasn't much we could do about it, this computer was TOAST.
Then this user told me that he was actually PROUD of the fact that he managed to get 4 different computers infected/damaged in a short period of time.
Excuse me? 
That's where I ended my support - told him to format and reinstall Windows and never use a computer anymore.
This is once again an example why some people should be restricted to use computers and is a perfect addition to my previous rant: "The Neverending story".
Oh, and yes, I do agree with Eugene's Final thoughts - with the addition that Internet access should be restricted for such people as in above example.
Friday, September 19, 2008
Fujitsu Siemens Amilo - RIP..... for now.....

This was going to happen some day anyway...
I finally managed to spill a full mug of coffee (big size) all over my laptop.
In less than a second, the coffee had covered my entire computer desk. Luckily, my other laptop next to it was on a notebook cooler pad, so that one was saved.
The screen went black immediately, strange noises from underneath... and I sweared like never before.
Unfortunately, the swearing didn't work, so instead, I immediately disconnected the power supply and took out the battery.
I put the unit on its side and the coffee was dripping out. I left it in that position for at least an hour. I cleaned the rest of the mess I made, apart from the stains on the wall (Mr Proper can take care of that).
Then I turned it upside down, opened it and I'm going to let it dry for at least 24 hours.
In a way, I'm glad I don't like milk and sugar in my coffee, so maybe there's still hope... but I doubt it.
My dear Fujitsu Siemens Amilo, May The Force Be With You.
UPDATE! I couldn't wait any longer (waited for two days to let it dry)... so... it's up and running again!! No issues so far - everything works. I was really lucky :-)
Monday, August 4, 2008
I don't use an Antivirus, because I have never been infected...
... said the user while his computer was crippled with malware. His answer didn't make sense, because how would he know that he was (never been) infected if no scanner would alert him?
He asked for my help because his Internet Explorer browser crashed frequently and his computer was crawling. Although he did get popups as well, he didn't really see this as a problem because he had a good popup blocker. O_o
No way malware was causing this (according to him). It has always been like that..... (so you can imagine how long he was infected already...)
And yes, I've found malware from years ago: DollarRevenue crap, EliteMedia, leftovers from the Alcan worm, and a recent Zlob Media variant.
Time to make him aware that his computer really is infected, so the only way to show him the facts is to install an Antivirus....
He was shocked once the scanner started to detect and delete the files. Funny part here was, a HUGE amount of infected files were present in his Limewire shared/complete folder (because of the Alcan Worm, which was luckily already disabled). So it was an extra shock for him since more than 1000 files were already detected and deleted there.
After all, we could clean everything and I'm sure he would never uninstall his Antivirus again. :-)
A shocktherapy is really needed once in a while.

Recently I've been reading many articles, blogposts, discussions about Antivirus Software and Security Suites. Which one is the best and if it's really needed nowadays since a lot of malware can bypass Security software, or scanners don't even detect it.
If I read this, then I'm always wondering what these people actually do online if they are complaining that their Security Software couldn't prevent or detect the infection they are dealing with. Ofcourse you'll get infected if you use 4 different P2P managers and download everything from there. Ofcourse you'll get infected if you visit illegal sites. Ofcourse you'll get infected if you click every link in your mails.
Even with the best Security Software installed, you can get infected if you visit the sources where malware is lurking.
You can even get infected by visiting a (compromised) legit site.
So why blaming your Security software? Also, A LOT of people only install an Antivirus after they got infected... in order to remove the malware... and if it fails to remove the malware, then they complain.
So YES, an Antivirus / Security Software is really needed, not necessarily to remove the malware, but to PREVENT the malware in the first place. It can prevent/detect/delete a lot of malware, but can't prevent all since a lot of new malware is created everyday. After all, it's still better to prevent 80% of the malware than no detection/prevention at all.
Friday, June 27, 2008
Malware Removal - Where to draw the line
A little intro first...
As many of you know (or don't know), I guide people with removing malware from their computers, or help them with other Windows issues not related with malware. This mainly happens via forums and newsgroups. I used to guide people via mail as well, but quit that since I don't have the time for that anymore.
"Step by step" instructions are really needed since many people don't know much about computers and without detailed instructions, they could make things worse. Hence, even when detailed instructions are given, with screenshots/whatever included, some still have problems to perform the steps properly.
Yes, a lot of patience is needed in many cases.
Many already asked me why I am doing this, offering almost all of my free time as a volunteer to help other people online. Well, there are several reasons why I am doing this...
1st... My hunger for knowledge. I love to learn and want to learn something new everyday. Fixing computers is like solving a puzzle for me, to find the cause and try different solutions. It's always a challenge to find and understand the cause in the first place. Without a cause, you can't offer a proper solution either.
In case of malware removal - it's a challenge to find the loading points, what it changes/modifies, how it behaves in general - and based on that you can give the proper instructions how to remove it and restore whatever it has broken/modified.
Next time if you see the same problem again, then you already know how to deal with this - something you've learned and remembered.
I don't want to give instructions/solutions if I don't understand them in the first place, because that wouldn't make sense and I learn nothing from this.
2nd... As I said, many people still don't know much about computers. I don't really see this as a problem, as long as they know how to secure their computer. Unfortunately many don't know anything about this. They don't even know what an Antivirus/Firewall is, why it is needed and what the dangers of the internet are. Many don't take this serious either and always think that this won't happen to them - until it happens (sooner as they think).
Another lesson learned I hope. Some will never learn as I explained here - or don't see the need why to secure their computer as explained here.
Prevention is better than removal... and that's what I try to teach these people. If more people would take this more seriously, secure their computers and always be careful where they surf, what links to click and what they download, then I'm sure that the internet would be a bit more safer place for anyone.
3rd... I just love to help people in general. If they ask for help and I know how it can be solved or where to find the solution, why wouldn't I help them then? A simple "Thank You" afterwards, the appreciation you get already means a lot to me. I'm always glad that I could teach something and hope that they will learn from it as well.
Also, Budfred's Rant: Volunteers and Malware Criminals sums it up nicely with more reasons why I am doing this and as you'll also read there, volunteers don't always get the appreciation for what they are doing.
Through the years, malware has become more difficult to find (rootkits etc..), more stubborn to remove and more nastier in general. One click on a file or link can already download and install a huge malware bundle where many different infections are installed.
You see popups all the time, your desktop wallpaper has been changed with a "fake alert", displaying that your computer is infected (well, it IS infected, but these "fake alerts" ask to purchase their own product in order to remove the malware they installed in the first place).
Although the fake alerts and popups/advertisements you get is the most annoying part and look the worst, as a matter of fact, it's the least of your concerns. What is hiding in the background is a more serious issue. Trojans in general, such as backdoors, password stealers, keyloggers etc.. all have their own purposes and may damage a lot!
And as I said, all of the above can be installed via one single click on one link or file! Hence, I've even seen file infectors/worms/bots joining the party as well.
Problem is still, many are not aware what the other malware does, or is capable of - and are already satisfied if the annoying popups don't display anymore, their desktop background has been fixed etc..
Then they don't need further help anymore because they think that their issue is already resolved while the biggest problem is still present, silently doing its job in the background. They are not aware that their computer is still severly infected and badly compromised... and responsible for infecting other computers on top.
And what is worrying me the most is that some don't even care - as long as the annoying popups are gone.
Malware compromises/damages a lot, that's a fact - and especially in case of a severly infected computer, even if I clean the malware off the computer, I cannot guarantee that the computer will be clean afterwards, because these infections/bundles leave a lot of leftovers behind that most scanners won't even recognise and logs won't show.
Also, I cannot promise that I can repair all the damage it caused... Even after cleaning the malware, errors may still be present afterwards because of the damage. Solving these is not always possible since it will be searching for a needle in a haystack to find the right cause and solution. Although I love to solve puzzles, I'm sometimes wondering if it's really worth it in such cases.
That's the main disadvantage if you guide people via forums etc, because instructions should be followed asap - and this is not always possible. Also, Internet connection is needed to read the instructions and in case of severly infected computers, I recommend that they disconnect from the internet asap and use another computer to read the instructions from. Unfortunately, this is not always possible either since not everyone has a spare computer.
If I guide someone with cleaning a severly infected computer, it is my responsibility to make them aware of what state their computer is in, how severly infected/compromised it is, they should change passwords afterwards etc etc.... and I won't promise them a clean computer afterwards - because that would be a lie.
I've seen cases where volunteers are helping a user with a severly infected computer, this already for weeks....
And that's why in such cases, I throw in the towel more often and ask to backup important data, then format and reinstall Windows. Not because I give up, but rather because it's really not worth it to clean this mess up manually and then on top restore (if possible) whatever the malware has broken/modified. In such cases, a format and reinstall is the fastest and especially the SAFEST solution.
As a matter of fact, I think it would be irresponsible of me to guide people with manual removal in such cases, knowing that removing the malware from severly infected computers takes a lot of time, especially if you're doing this via online instructions and every single minute that this computer is connected with the internet, it may download more malware, spread more malware, collect more info, send more SPAM etc....
Also, if file infectors are game, in 80% of the cases, I recommend a format and reinstall anyway if an AntiVirus scanner is not able to disinfect the files (properly). Unless the person knows what files are corrupted and knows how to replace them with a clean one. But then again, it's no guarantee that everything will work properly again and the infection will be really gone.
Another article regarding this is:
When Should I Format, How Should I Reinstall.
That's why.... Where to draw the line? When to recommend a format and reinstall?
Tuesday, June 10, 2008
Top Ten excuses why people don't want to secure their computer

1. I don't have anything valuable on my computer anyway, so I don't need to worry about someone taking it over.
Actually, you have something very valuable on your computer, especially if you are on a fast internet connection. You have bandwidth. A lot of malware is designed to take over your computer and use it as a server to attack other computer, distribute SPAM or even deliver more malware. It will also steal your data, passwords and account numbers, so the criminals can steal your identity and everything you own. Even if you only use your computer for gaming, there are people now stealing passwords for some computer games so they can steal any reserves you have built up online.
2. The antivirus companies are the ones who put out all those viruses so they can sell their programs anyway. If I install their program, it will install their viruses.
This is mostly one of the silliest myths on the web. It is true that there are rogues that try to trick people into buying their programs by claiming your computer is infected:
List of Rogue Programs
However, the legit companies wouldn't even consider risking their reputations to make a few extra dollars. If they are recommended by reputable sources, they are going to be safe and useful. You need to be sure the source is reputable though. The people that create viruses and other malware are criminals and many are now part of organized crime gangs that make millions by stealing from people like you.
3. Running a firewall slows down my games.
Most firewalls have settings to allow you to play games without removing that protection. Even a few minutes online without your firewall can leave you infected.
4. The programs are too complicated.
Most programs have simple modes that can be set to update automatically and protect you without you having to do much more than renew a subscription or download a major update about once a year.
5. I don't have any money and the programs are all expensive.
You can assemble a very effective set of security programs for free. Even if you pay a bit for a program, it is a lot less than what you will pay to get your computer fixed and possibly deal with having your accounts cleared out by criminals.
6. I have heard that WinXP Service Pack 2 and 3 will cause problems on computers and I don't want to risk it.
That is sort of like saying I will jump off of the cliff because I don't want to risk slipping on the rocks climbing down. SP2 is probably the most important security update that MicroSoft has released for any version of Windows to date. It is true that it caused problems in the first few months, but it has been out for more than 2 years and it is quite stable now. If you don't have it, you also don't have any number of other security updates and you are almost certain to get infected.
7. I have an illegal copy of WinXP and MS won't let me update it. It isn't fair because they make so much money anyway.
If you are running an illegal copy of Windows, do the rest of us a favor - buy a legal copy. When you get infected, you can become a zombie server for the criminals, distributing malware, SPAM and scams all over the web. If all the zombie systems were shut down today, the quantity of SPAM would slow from a tidal wave to a trickle. Don't contribute to the flood. If you don't believe you can afford a legal copy of WinXP, use a free install of Linux. There is no good reason to put yourself and the rest of us at risk.
8. I have never used security programs and I have never been infected.
Maybe, maybe not. Some of the most effective infections today are essentially invisible on your computer. They don't slow it down in a noticeable way, they don't popup ads and they don't do anything to attract your attention. They do quietly send your personal information to the criminals, they do use your computer as a zombie server and they do own your computer more than you do. The truth is, malware is getting more aggressive, harder to detect, harder to kill and almost unavoidable if you go online at all. If you are not armored, you are probably already infected or you will be.
9. It is my computer and it is only my problem if I get infected, so leave me alone!
Well, not really. It is your computer and it is mainly your problem if you get infected. However, if your computer becomes a server that sprays malware, SPAM and attacks against the rest of us, it becomes our problem too. As soon as you go online, you are part of a community and the decisions you make effect everyone in that community. If you don't mind people messing around with your personal information and possibly using it to steal all that you have, please at least consider the harm you may be doing to the rest of us.
10. I plan to install security programs, I just haven't had time yet.
If you are reading this, you are already online. If you are online, you are already at risk. I once fixed a problem with my firewall and had it uninstalled for a while. I went online for about 10 minutes to download a fresh copy and while I was online, my system was infected with the Welchia worm. TEN minutes I was online, only 10 minutes!! How long have you been running without security??
Copied/pasted with permission - Credit goes to Budfred (SWI Admin) - original article. For more similar articles/news/tips, subscribe to the SWI Newsletter.
Sunday, June 8, 2008
The Neverending Story

It's already more than 4 years that I clean severly infected computers.
In most of the cases, when I review the logs, I see more malware present than anything else.
Also, in most cases, many don't even have an Antivirus Scanner + Firewall installed and their Windows hasn't been updated for years.
Hence, they don't even know why the updates are needed for. Also, many of them don't have a genuine version of Windows installed anyway.
Some don't even know what an Antivirus Scanner or Firewall is.
For example, yesterday, I analysed a log from a severly infected computer and asked the guy why he didn't have an Antivirus and Firewall installed.
He: "Huh? I have an Antivirus and Firewall installed though"
Me: "Ok, can you tell me which one, because I can't see an Antivirus and Firewall present in your log"
He: "I have mailwasher!"
Mailwasher is a spam filter software - so not sure where he has read it was an Antivirus/Firewall.
And that's why we should "teach" these people about security. Why they need an Antivirus and Firewall and how to prevent malware. This is my main goal here... teach about prevention, how to keep their computer(s) clean/secure.
Unfortunately, many do know how to prevent malware, how to keep their computer(s) secure, but they just won't listen, mainly because they just don't care.
They also know how they got infected in the first place.. because they were warned many times before. But still, they just can't resist the use of illegal software/cracks/hacks whatever, even though they know that 80% of it is bundled with malware.
One single click on one of these "popular" crack sites may already download and install a huge malware bundle... and yes, they are also aware of this.
Oh well, not a big deal for them - They just post their problem at one of the forums/sites where they receive help for free. Once their system is "clean", they can hunt for more cracks/keygens again.
Yes! I've seen it too many times before.
"Hi, I visited a cracksite, downloaded and installed a crack - can you check if my computer is still clean?"
"Help! I downloaded and installed a crack from a torrent/P2P again and now my computer is acting weird.... again"
"I need help asap!! Keygen infected my computer again!"
Yes, in 80% of the cases, people get infected because of the use of illegal software/cracks/keygens/hacks... etc.
So I clean their computers and most important part, I tell them that they should stay away from illegal software, cracks, keygens etc, because they will get reinfected anyway if they don't change their surfing habits.
I also explain that there are many free alternatives and give them extra prevention tips.
I'm glad that many learn a lesson here, listen to my advise and make sure this won't happen again.
However, there are still a lot of others who don't listen and proceed with what they were doing before, even though they were warned.
Result.. 2 weeks later, they are back, asking for help to get rid of another infection, because they installed another crack which downloaded/installed malware again. Then they receive free help once again and one month later, they are back again. And this goes on and on and on...
I'm sorry, but I gave up on them. It's a waste of my time.
If they don't want to listen, they should take care of their own problems. In such cases, I recommend that they format and reinstall Windows (even though the malware can be cleaned easily).
Or I ask them to go to the local computer shop to get it fixed. It will cost them a lot of money and in most cases, they will just format and reinstall Windows anyway.
Maybe that will learn them since they have to pay for it - or since they have to start from scratch again.
"Was it really worth it??"
"Wanna use cracks/keygens again and go through the same scenario again?"
"Are you sure??"
- If there was an "Yes" button here, I'm sure some would click it - Ooh, they love to click Yes!
What I hear many times is:
"It's my computer - if I want to visit illegal sites/use cracks etc, it's my problem if I get infected."
Ok, so why are you asking for help in the first place? If it's your problem, you should take care of it.
And it isn't your problem ALONE. Your computer is responsible for infecting A LOT of other computers as well (depends on what malware is present).
"I blame my Antivirus because it didn't detect the malware".
You are the only one to blame!!!
Also, all their passwords and other sensitive data may be known... But do they really care???
Some will never learn, so this is a neverending story and unfortunately I can't help them anymore.
Oh well... maybe they will learn some day (when it's too late).
Thursday, April 24, 2008
Forum owners - Take your responsibility!!
After we had this, with a little update here, I'm still amazed how many website owners don't take responsibility.
I was researching/analyzing some SQL injection scripts a couple of days ago and a google search showed me how many websites, forums in particular are being hacked/compromised. A LOT!!
Example:
Above forum was not only hacked, but it was full with spam as well.
LACK OF RESPONSIBILITY!!
People hack forums/sites for different purposes. Some do it only to get attention, as a challenge - others do it for personal gain - for example, put malicious content on the site, so every visitor gets infected with a trojan/backdoor/whatever with their own purposes as well (steal data from your system, display ads..)
Or they post SPAM all over the place (as you see in above example). In other cases, you don't even see that the forum/site is hacked, but the scripts are doing its job anyway, silently in the background...
Some interesting info:
* http://www.prevx.com/blog/87/What-happens-when-your-Managed-Hosting-Server-Gets-Owned.html
* http://www.f-secure.com/weblog/archives/00001427.html
* http://ddanchev.blogspot.com/2008/04/united-nations-serving-malware.html
Anyway, when I saw the google results, I've contacted some of the forum owners + webhosting companies via mail to make them aware of the fact that they should take action asap.
Some replied and I was really suprised that many forum owners didn't know how to fix it, so that's why they left it as it was. ![]()
Luckily, we still have the webhosting companies who took action instead and took the forums offline or added a .htaccess to block access.
But then again, many didn't even reply to my mail and I see the compromised forums are still up and running. :(
This blogpost is mainly about forums/forum owners, because it's easy for anyone to install and run a forum, but maintaining it and keeping it secure is another story.
That's why, if you run a forum, take your responsibility!!!
Some tips to make your forum more secure:
*1. Install a forum - Read the documentation first!
Many install a forum without reading the documentation/tutorial how to properly install a forum.
This also involves how to CHMOD files and directories in order to properly install it - to set permissions for a file and/or directories. The most important part here is, make sure, after you installed your forum software, that you CHMOD your files and directories again, so it has restricted permissions.
Every forum software has (or should have) a tutorial available how to do this properly, even with support for several different FTP clients. So make sure you read it!
*2. Make sure you always use the latest forum software!
This is the most important part if you want to run a forum. The forum software is updated frequently, not only to fix some bugs in it, but mainly to fix security leaks/vulnerabilities.
In 80% of the cases, a forum was hacked/compromised because you were still running an outdated, vulnerable version of your forum software.
For most forum software, there's a mailing list available where you can subscribe to get notified about the latest updates. If your forum software is still running an older version, then update it ASAP!!!
Many forum owners also use a lot of plugins/mods. Make sure you're running the latest versions as well, because these plugins/mods may contain security leaks as well.
*3. Don't allow html
By default, if you install forum software, html is disabled to use in the forum. This is with a reason, because if html is enabled, it's a piece of cake to insert malicious content.
That's why BBcode takes its place.
However, some forum owners/administrators decide to allow html in the forum posts. If that is the case, make sure this option is only available for certain groups and not for everyone!
*4. Only for registered users
If you run a forum, only allow registered users to post. If you allow guests to post, they can post anything they want, post a lot of SPAM (with malicious links in it) and you can't do much against it.
That's why, if you give permission for registered members only to post, you can already avoid a lot of problems.
Some basic rules for registration:
*5. Make sure captcha is enabled
captcha is a way to avoid SPAMbots. This to make sure the registration is not generated by a computer. However, many spambots already found a way to "crack" the captcha and avoid a proper registration anyway.
That's also why..
*6. Use e-mail validation to register
During registration, people should enter a valid e-mail address to validate their registration, because the validation link will be sent to that address. So an account can only be registered via the link sent in that e-mail. This is also a way to avoid spambots.
*7. Rename your admin directory
Most forum software use their own way of creating directories/files. If you're a forum administrator, in most cases, the administrator directory related with your forum will be called admin or administrator. By default, this access is passwordprotected.
But, even though it's passwordprotected, there are many ways to get it. Bruteforcing the login/password, or retrieve the login/password somewhere else (for example, if you got infected and your data was stolen, or if if you gave your login/password to someone else etc..)
That's why it's always a good idea to rename your admin directory to something else, so it's not that obvious anymore. Make sure you also adjust this in your - in most cases - config.php file.
Even better is, if you rename your admin directory and delete all "visible" links pointing to it on your forum. This can also be done via the "config.php" file (or whatever file your forum software is using for "main access" to your database).
Some forum owners love to have a Web counter and statistics tracker on their forum to see how much traffic the forum gets. In case you decided to change your admin directory and remove all "visible" links pointing to it - then make sure that the web counter/statistics tracker results are visible for you only! Because otherwise it won't make sense to rename directories if anyone can achieve it via the statistics page.
*8. Check your files in the forum directory frequently
If you install a forum, you should upload files via FTP this in order to make the forum "work".
If you update your forum, some files will be patched or added - make sure you are aware of that.
That's why, it's always a good idea to check your files in your forum directory and root directory (if possible) for any changes. This especially if some php files, script files, whatever are added which are not a part of the basic forum software or upgraded parts. Ofcourse if you allow users to upload avatars or attachements, that part will be changed/updated frequently, however, always be cautious!!!
If your webhosting company supports access via SFTP-SSH file transfer protocol and your FTP Client supports it as well, then I recommend you switch to that. This because "normal FTP access" doesn't show all files/folders present - SFTP (SSH) access does - so in case your website/forum is compromised, it's better to have "full" access and be able to view everything present there instead of "restricted access". You can also use PuTTY for that, to have the same access - but normally, every decent FTP Client should support it as well.
*9. Back up your database and files frequently!
If you run a big forum with lots of traffic and forum posts everyday, then I suggest you back up your database once a day. In other cases, I suggest a backup at least once a week.
A backup of the database is the most important part, however, I also recommend to backup your files (the ones you uploaded via FTP) frequently as well. This in case some files were patched by malicious scripts/contents.
*10. Don't give your login/password to anyone!!
Unless you can trust the person for 100%!
Keep in mind, if many people are aware of your login/password and they get infected with a password stealer (which is common nowadays), then it will be known as well.
*11. Disallow PM for new members
This is something I noticed a lot in the last couple of months - and that is - SPAM via PM (Private message).
A lot of spammers (sometimes spambots), manage to bypass the captcha, enter a valid mailaddress, so they are in! Then they start to spam the forums..
Moderators and administrators should catch these spamposts, delete them and ban the user. However, what if SPAM, or malicious links are being posted via PM (Private message)? So admins, mods don't know about these spam messages, since they are sent via PM.
That's why it's always a good idea to disable PM for guests in the first place! For registered members, there should be a policy present to accept PMs if they have posted at least 3 posts in public - this as an example.
*12. Don't let the people know what forum software/version you are running!
The best way to find vulnerable forum software is via Searchengines. Google for example..
Most (free) forum software require their Copyright signature below. You may not remove that!
In some cases, forum software also displays what version you are running (however, in most cases, that is also disabled by default now). In anyway, an easy way for hackers, mainly scriptkiddies to find out if your forum is vulnerable, is via a searchengine. They search for "powered by.. whateveverforumsoftware" and then they try to run their scripts against it to see if it's vulnerable or not.
As I already said, you may not remove the "forum copyright" and links, unless you paid for it to be removed. So that's why it's always a good idea to replace the copyright with an image (jpg/gif/png) instead. Ofcourse, if there are links involved, it's advised to use image maps so that you can retain the links to the copyright/forum.
*13. Still so many other tweaks to make your forum more secure...
I only made you aware of the most important ones. There are still a lot of other tweaks/modifications to make your forum much secure. You can find a lot of extra tips/tweaks on the main site of the forum software you are running.
In anyway.. If your forum was hacked/compromised, then it's YOU who should take action ASAP! Don't leave it as it is, because it's YOUR responsibility if people get infected when they visit your site/forum. It's YOU who should fix it and make your forum/site more secure.
In case you are pretty sure that your forum/site is secure, then try to find out how exactly it was hacked/owned. Contact your webhosting company and ask for the logs. If you can find the cause, then you can do something against it!
A good example.. My forum was once hacked/owned as well. And even though I had taken all precautions and the forum software was up to date as well, it appeared afterwards that there was still a vulnerability present in the forum software I was running. I've researched/investigated it and made the forum developers aware of it. Glad to see they have patched it now as well, even though it took them more than 2 weeks to release the patch! Imagine how many forums were compromised in between..... :(
That's why I changed forum software since I couldn't trust it anymore.
Also, even though you are responsible for your forum/site, if you have a good webhosting company, they will already make you aware of suspicious action/behavior and take action before you are even aware of it. I've had/used a lot of webhosting companies in the past, but the one I'm using now is SUPERB! Support is great and they take action asap! I never want to change anymore!
AFTER ALL, if you are running a site/forum/whatever, It's still YOUR responsibility for whatever happens on your site. If you don't want to take responsibility, or you don't know how to take action if something similar happens, then make sure you know someone who does - if not, then you shouldn't run a forum/site anyway!
Saturday, April 5, 2008
Webmasters... *sigh*
This is an update to my previous post here.
I received another phonecall from the guy who was having problems with his website..
This time, he was complaining about the fact that he couldn't access his admin panel anymore.
(This since the "Webmaster" passwordprotected it with .htaccess)
Me: "Ok, so what problem are you exactly having"
He: "There's a login box now and I don't know the login name and password. Whatever I try, it doesn't work."
Me: "Did, xxxx (name of the webmaster) contact you to tell you what login and password you have to use?"
He: "No"
Oh boy.. I started to swear in a non understandable Bruges dialect :)
So, once again, I called the Webmaster...
Me: "It's good you passwordprotected the admin directory now, but it's also a good idea to let your clients know what login and password they have to use"
He: "True, I forgot" The login is xxxx and pass is xxxxx" (yes, he really told me)
Me: "Why are you telling me this, you have to tell your clients!"
While I was on the phone, I did a Reverse IP domain check to see what other sites he created/was hosting..
7 of them... and they all had an admin directory. This time all passwordprotected. (Glad to see he really updated/changed that).
The login box appeared and I entered the login and password he gave me previously.. I was in!!
I mean, I was in for all the sites he created, this since all logins and passwords were the same...!
Should I start to cry or.... 
So I once explained him that it was a bad idea to give everyone the same login and password - and that he also should contact his clients to make them aware of the updates he made etc etc..
I really hope he'll take his responsibility as a webmaster now, since his clients pay for this!
Thursday, April 3, 2008
Admin directory.... for everyone?
A guy phoned me this morning and explained that he was having problems with his Internet Explorer.
He wanted to update his website with new pictures, but for some reason, the new pictures didn't appear in his browser after he submitted them.
He asked me if I could try it for him instead - this to figure out if it was an issue with Internet Explorer or with his website.
Since I was at my work, I couldn't try it, so I asked him to mail me the link to his site, so I could check it in the afternoon.
I also asked his login+password, because how would I be able to upload images to his site otherwise..? He knows he can trust me...
He: "There's no login and password needed"
Me: "Erm, if there's no login and password needed, how should I upload the pictures then?"
He: "You can do it via the admin panel at my website"
Me: "Ok, but I need the login and password for that"
He: "As I said, it's not needed"
Hmmmmmm... strange.. guess he's missing something...
Back at home, I received his mail with the link to his admin panel : http://*********/admin
(left out the sitename for obvious reasons :) )
Entered the url... and I was in. I mean, I was really in! I couldn't believe my eyes.

What I saw was a preview of his main site with several applications present - to edit text, add text, submit files/pictures whatever.
I still couldn't believe it, so I uploaded some stupid pictures via the applications, added some stupid text > submit > OK.
Went to the main site and it was there!!! I refreshed once again, to make sure.. I even closed and opened my browser again to doublecheck, it was still there what I submitted.
OMG! This is a REAL BAD idea!
So, I phoned the guy and asked him if he created the website and the admin application... and why he didn't password protect it. Nope, he didn't create the website - he actually paid a lot of money to create it for him instead. I explained him what a bad idea this was and asked "his" webmasters phonenumber.
So I phoned the Webmaster... creator of the site.
Me: "You think it's ok if people compromise the site(s) you created? Put malicious content on it? - so every visitor gets infected? Or if someone deleted the entire content of the site?" (and some extra rants).
He: "I have no clue what you are talking about"
Me: "Once again, you did create this website with the admin application?" (gave him the name of the site)
He: "Yes, I created that one"
Me: "Is there any reason why you didn't passwordprotect the admin directory or access to edit/update the site?"
He: "To make it easier for our clients, so they can update the site any time"
He just didn't get it... 
Me: "To make it easier for your clients??? You make it easy for EVERYONE!! Everyone can access it, upload whatever they want, edit whatever they want.." (I didn't try it, but I'm sure that the editable text boxes there supported html as well)
He: "Erm, Ok, so what should I do then?"
Me: "Passwordprotect it!!!"
He: "How?"
OMG..! I was stumped. ![]()
Anyway, I explained the guy how to passwordprotect it - gave him a lot of options - hence, he didn't even know what .htaccess was.
I also told him that it is also a good idea to give the admin directory another name etc etc..
He finally understood my concerns (and not only my concerns) and said he would change/update it immediately for every website he created.
A Webmaster?? Yeah, sure.. And he's getting paid for this?? This is totally irresponsible!
Anyway, I just checked a couple of minutes ago and I'm glad to see that there's finally a login box present to enter the "admin site", where it's asking for login and password. Not sure if it works, if the loginname matches the password, but it is present at least... :)
After I experienced this - Imagine how many so called "Webmasters" are around there, making the same BIG mistakes.
/me *shivers*
Sidenote: The "not viewing images" issue is resolved now as well - Flushed IE cache and all was OK again. :)
Wednesday, February 20, 2008
What's up with McAfee lately?
I am active at several different forums where people ask for help with malware removal. They start with posting a HijackThislog or other logs and then we give "step-by-step" instructions what to remove and how to remove it.
Malware is one of the most common reasons why a computer becomes slow and unstable - However, many people do believe that every computer problem is a malware related problem, so they post their logs and ask for help.
In 40% of the cases, there's no malware present, so we have to look somewhere else what is causing these problems...
In most cases, it's like searching for a needle in a haystack - but after a while, it's becoming obvious what is causing these problems if you're dealing with them everyday. And such example is McAfee.
Not sure what happened with latest McAfee, but many people are having A LOT of problems with it. The most common problem I notice with McAfee is a severly slowed down system. I did the test, installed McAfee Security Suite (1024MB memory) and after reboot, my system was crawling!!
That's why, If people are complaining about a slow computer/slow internet - if there are no traces of malware present and they do have McAfee installed, then the first step I ask is to uninstall McAfee and replace it with another Antivirus/Security Suite. 90% success!
But the slow down issue is not the only problem that McAfee may cause. Other problems I've noticed with McAfee as well are:
* Programs freezing
* Explorer crashing
* Internet Explorer crashing
* Outlook crashing
* Only able to boot in Windows Safe mode
* ..... you name it.
McAfee already made its own incompatibility list and I am sure it's still missing a lot of Products there. It's normal that you shouldn't have more than 1 Antivirus/Firewall installed, because they are not compatible with eachother, even though they are disabled. But if it's up to McAfee, people should uninstall the most commonly used Antispywarescanners as well, such as Ad-Aware and Spybot S&D. Hence, they even recommend to uninstall SpywareBlaster. Huh?
And even though you uninstalled them all.... the problem remains....
In general, if there are no traces of malware present and McAfee is installed - uninstall McAfee first and see if that solves your problem (whatever problem you are having). Believe me, in most cases, it is the solution!
In some cases, it's hard to convince people that McAfee is responsible for the problems they are having, they just won't believe it since it worked fine in the past. Reference here. The guy believed he had a terrible Virus causing all these problems and couldn't believe it was his McAfee causing all these problems. I already explained to him a couple of times that I was pretty sure his McAfee was the cause, it took me 2 pages to convince him... and he still wouldn't believe.. until he decided to uninstall it after all as a test. And guess what? :)
Ofcourse, there are also a lot of computers where McAfee runs smoothly - where there are no issues at all - but unfortunately, nowaday posts at forums show that McAfee just won't run properly on a lot of systems. That's why, if you want to use McAfee, use the trial first before you decide to purchase McAfee.
There are some other Security Products that may cause similar issues as McAfee, such as Norton Internet Security, Zonealarm, but I'll rant about that later :)
Wednesday, February 13, 2008
Registry Cleaners and System Tweaking Tools

I am still wondering why so many people use Registry Cleaners and System Tweaking Tools while they don't even understand what the Windows Registry is, and/or don't understand Windows basics.
"Fix errors now!" and "Make your Windows fast again!", that's how all these tools are advertised.
People download and install it - click the "Fix it all" - Button (since many of these tools have such button available) and then notice that suddenly some programs won't work anymore, errors appear and in worst case, their Windows won't boot anymore...
Yes, I've seen it all... and many still won't believe that this may be a result of these tweaking tools, because after all, they are "supposed" to improve system performance, prevent errors and make a system more stable. Huh?
In most cases, people don't have any problems in the first place - but want to use these tools anyway.
I have to admit that there are some good "tweaking tools" around as well, but you shouldn't use these if you don't have basic knowledge about the registry and Windows in general. Only delete keys if you're certain that they can be deleted. Disable services if you're certain that you don't need them, let it set policies if you understand what they do etc..
Registry Cleaning won't really improve system speed anyway. Even though there are a lot of orphaned keys/values present, you won't notice a difference in system speed. The only difference you'll notice is when you actually search in your registry - but how many people do this?
On the contrary, as a matter of fact, if you "clean" the registry frequently, it actually becomes more fragmented after a while - and *that may* result in slower system performance, although you won't notice much difference.
I rather prefer to have a lot of orphaned keys in the registry, instead of keys/values that were deleted by a registry cleaner, which were not supposed to be deleted in the first place. And that's the risk of these Registry Cleaners, because many list keys/values as orphaned or unneeded while they are actually needed.
After all, a broken registry is a broken Windows.
The same goes for tweaking tools. Tools where you can select to disable certain services and add certain policies. The "Fix it all" button is also available in most cases, or an option where you can check/select several settings - and the more settings present, the more people believe that checking/selecting them all will result in a superfast computer...
Oh yes, check them all .... and complain aftwards:
* "Help! I'm having problems with Windows updates/Automatic Updates!"
Yes, because you disabled BITS, you disabled Automatic updates, or you have set some restrictive policies related with Windows update
"Help! My add/remove programs list is empty!"
Yes, because some Registry Cleaners unfortunately delete the Uninstall key in the registry - reference here. Only new programs installed will be listed there... (See picture above)
And so many more... Check out this thread for more opinions.
So, don't use them if you don't understand these tools.
After all, Don't fix when it ain't broken!





