Saturday, April 12, 2008

And now for something completely different...

... can anyone give me more information about the new Antivirus krepolsky ?

One of the newest members at my forum is using it: Click me

/me is puzzled.. Most probably new Polish version of Kaspersky... :P

Thursday, April 10, 2008

Dial-a-Fix -- Fix most common Windows issues

One of the tools I have been using a lot of times with success is Dial-a-fix (DAF), developed by DjLizard.
And that's why I wanted to blog about it - this to make people aware that most common Windows issues can actually be fixed with one single tool, instead of creating several different fixes such as registry fixes, batches etc...
Even though this tool is meant for Power users, technicians, it's safe to use without technical experience. However, guidance is still recommended.

Some examples of what it fixes:

* Windows Installer
* Windows Update
* Registration of ActiveX, Control Panel Applets, Explorer/IE/OE/Shell, OLE...
* Reinstall of BITS, Windows Firewall, WMI, Help and Support, defrag... and so many more.

Take a look at the following screenshots to find out what options/fixes it contains:



And the Tools option (Hammer below in the main screen):



Many programs/tools, or malware may change default settings, break applications, so the idea behind Dial-a-fix is to fix problems by resetting everything back to their original Microsoft defaults.
For example, if you have been using Registry Cleaners, System Tweaking tools which I do not recommend, then Dial-a-Fix may be the solution to restore what above tools have broken.

Dial-a-Fix is mainly developed for Windows XP, but it also works under 98, 98SE, ME, 2000 and Server 2003. It doesn't support Vista yet.

Important note.. Before you use Dial-a-fix, make sure you read the WARNINGS section on the Dial-a-fix site first.

And in case you need assistance with Dial-a-fix, or there are problems with Dial-a-fix, post your issues here.

Saturday, April 5, 2008

Webmasters... *sigh*

This is an update to my previous post here.

I received another phonecall from the guy who was having problems with his website..
This time, he was complaining about the fact that he couldn't access his admin panel anymore.
(This since the "Webmaster" passwordprotected it with .htaccess)

Me: "Ok, so what problem are you exactly having"
He: "There's a login box now and I don't know the login name and password. Whatever I try, it doesn't work."
Me: "Did, xxxx (name of the webmaster) contact you to tell you what login and password you have to use?"
He: "No"

Oh boy.. I started to swear in a non understandable Bruges dialect :)

So, once again, I called the Webmaster...

Me: "It's good you passwordprotected the admin directory now, but it's also a good idea to let your clients know what login and password they have to use"
He: "True, I forgot" The login is xxxx and pass is xxxxx" (yes, he really told me)
Me: "Why are you telling me this, you have to tell your clients!"

While I was on the phone, I did a Reverse IP domain check to see what other sites he created/was hosting..

7 of them... and they all had an admin directory. This time all passwordprotected. (Glad to see he really updated/changed that).
The login box appeared and I entered the login and password he gave me previously.. I was in!!
I mean, I was in for all the sites he created, this since all logins and passwords were the same...!

Should I start to cry or....

So I once explained him that it was a bad idea to give everyone the same login and password - and that he also should contact his clients to make them aware of the updates he made etc etc..
I really hope he'll take his responsibility as a webmaster now, since his clients pay for this!

Thursday, April 3, 2008

Admin directory.... for everyone?

A guy phoned me this morning and explained that he was having problems with his Internet Explorer.
He wanted to update his website with new pictures, but for some reason, the new pictures didn't appear in his browser after he submitted them.
He asked me if I could try it for him instead - this to figure out if it was an issue with Internet Explorer or with his website.
Since I was at my work, I couldn't try it, so I asked him to mail me the link to his site, so I could check it in the afternoon.
I also asked his login+password, because how would I be able to upload images to his site otherwise..? He knows he can trust me...

He: "There's no login and password needed"
Me: "Erm, if there's no login and password needed, how should I upload the pictures then?"
He: "You can do it via the admin panel at my website"
Me: "Ok, but I need the login and password for that"
He: "As I said, it's not needed"

Hmmmmmm... strange.. guess he's missing something...

Back at home, I received his mail with the link to his admin panel : http://*********/admin
(left out the sitename for obvious reasons :) )
Entered the url... and I was in. I mean, I was really in! I couldn't believe my eyes.
What I saw was a preview of his main site with several applications present - to edit text, add text, submit files/pictures whatever.
I still couldn't believe it, so I uploaded some stupid pictures via the applications, added some stupid text > submit > OK.
Went to the main site and it was there!!! I refreshed once again, to make sure.. I even closed and opened my browser again to doublecheck, it was still there what I submitted.
OMG! This is a REAL BAD idea!

So, I phoned the guy and asked him if he created the website and the admin application... and why he didn't password protect it. Nope, he didn't create the website - he actually paid a lot of money to create it for him instead. I explained him what a bad idea this was and asked "his" webmasters phonenumber.
So I phoned the Webmaster... creator of the site.

Me: "You think it's ok if people compromise the site(s) you created? Put malicious content on it? - so every visitor gets infected? Or if someone deleted the entire content of the site?" (and some extra rants).
He: "I have no clue what you are talking about"
Me: "Once again, you did create this website with the admin application?" (gave him the name of the site)
He: "Yes, I created that one"
Me: "Is there any reason why you didn't passwordprotect the admin directory or access to edit/update the site?"
He: "To make it easier for our clients, so they can update the site any time"

He just didn't get it...

Me: "To make it easier for your clients??? You make it easy for EVERYONE!! Everyone can access it, upload whatever they want, edit whatever they want.." (I didn't try it, but I'm sure that the editable text boxes there supported html as well)
He: "Erm, Ok, so what should I do then?"
Me: "Passwordprotect it!!!"
He: "How?"

OMG..! I was stumped.

Anyway, I explained the guy how to passwordprotect it - gave him a lot of options - hence, he didn't even know what .htaccess was.
I also told him that it is also a good idea to give the admin directory another name etc etc..
He finally understood my concerns (and not only my concerns) and said he would change/update it immediately for every website he created.

A Webmaster?? Yeah, sure.. And he's getting paid for this?? This is totally irresponsible!

Anyway, I just checked a couple of minutes ago and I'm glad to see that there's finally a login box present to enter the "admin site", where it's asking for login and password. Not sure if it works, if the loginname matches the password, but it is present at least... :)


After I experienced this - Imagine how many so called "Webmasters" are around there, making the same BIG mistakes.
/me *shivers*

Sidenote: The "not viewing images" issue is resolved now as well - Flushed IE cache and all was OK again. :)

Tuesday, April 1, 2008

April's fool or...

As expected, the Storm worm was present again today (actually in the last 24 hours), taking advantage of April 1st.
It's spreading through e-mails as an April Fool's day e-card. Subjects are random, such as : "Happy April Fools!", "Happy All Fools Day!", "Join the Laugh-A-Lot!" etc..

Contents of the mail:



The mail contains a link to a webserver, where it downloads an installer for the file aromis.exe.
More info about the file here.
So always be careful what you receive via mail!



Sidenote - offtopic - even though it's April 1st today, I received a mail from Microsoft today that I was re-awarded - the MVP Consumer Security award - this already for the third year.
So this was no joke! :)

Tuesday, March 25, 2008

Who iframed Easter Rabbit

In the last couple of days, a lot of threads were posted at several different forums where people were complaining about being infected via a trustworthy site.
What happened was, many of these sites were hacked and were injected with a malware embedded iframe. This iframe launched a javascript to infect the visitors of the site with a Trojan downloader.

It's still amazing how many people got infected with this, because this is actually an older exploit that was being used - the MS06-014 exploit - Vulnerability in the Microsoft Data Access Components (MDAC).
This means that MANY have not updated their Windows for years, since this was actually patched in april 2006 - almost 2 years ago!

So once again, I cannot stress enough how important it is to update your Windows - don't wait - update TODAY!

Monday, March 24, 2008

Time to draw again...

I currently don't have the inspiration to blog about Computer stuff, so let's add something else instead, reveal one of my other hobbies...



... one of the drawings I made.

I love to draw and used to draw a lot in the past, but unfortunately, I don't really find the time to draw anymore. I'm not *that good at it, but it relaxes me, so I guess I should start drawing again, because I really need a "computer break" once in a while :)

If you want to see some other drawings I made, look here.
Yes, I know, all dogs, that's because I love them. :)
I'll add more pictures there in the future.

Wednesday, March 5, 2008

Do, or do not. There is no try.

And now for something completely different - not computer or security related...
Some of you may recognise above quote (title). It's a famous quote from Star Wars - quoted by Yoda. (Yes, I am a Star Wars fan and yes, I know that sounds weird for a female :P )
Anyway, that's what this blogpost is about - about Jedi, the dog my mother is taking care of.
Since recently my mother has some serious health problems, so she can't take care of Jedi anymore. That's why we need to find a new home for Jedi.
Jedi is female, breed is American Staffordshire. She's now 6 years old. She's very social and smart.



Since I already have 3 dogs (also American Staffordshires), I can't have another one anymore.
Although I used to breed them, since I moved, I don't have the space and time anymore for a 4th dog.
That's why I thought that, maybe this blogpost may help to find someone who wants to adopt Jedi.
Since I live in Belgium (Bruges), it would be ideal to find someone nearby.

Keep in mind, a dog is for life - that's why I used "Do, or do not. There is no try." as the title of my blogpost here - this since you'll have to think twice before you make the decision to adopt/get a dog.
If you're interested and need more info about Jedi, contact me via my "dog"site or drop a comment below.
(Only serious candidates - the rest will be ignored)

UPDATE: I've found someone to take care of Jedi. I'm sure she'll be in good hands :)

Saturday, March 1, 2008

Windows Vista - Backup pleasseeeee....




Even though Windows Vista is much more secure than XP (if UAC is enabled), people still allow many programs from dubious resources (p2p resources/crack-hacksites) and run/install it. Yes, people love to click the "OK" button even though it's not OK.
That was a bad idea.. wasn't it? So I hope you'll read the notifications/messages next time....
Anyway, if you indeed managed to install malware and the malware already compromised your system where it also damaged a lot - then the fastest and especially safest solution is a format and reinstall.
I actually do not really recommend a format and reinstall anyway, but in some cases, you really have no other option if you want to trust your system ever again..
Unfortunately, nowadays malware is more advanced and nastier than a couple of years ago.
After all, it would be irresponsible of me if I proceed with giving instructions for manual removal and tell the user afterwards his/her system is clean - because it is NOT! So in such cases, I always make the user aware of with what s(he) is dealing and let them decide what to do - a format and reinstall or manual removal. If they choose for the manual removal, then I will assist them, but make them aware that they may never trust this system anymore, it's compromised and many issues may still appear afterwards.

And that's where the problems start...
"Sorry, I can't do a format/reinstall, because I have so many important documents, pictures etc present that I don't want to lose"
And in most cases, the malware present already damaged so much > result > computer won't even boot anymore. Ofcourse there are still a lot of methods to access your important files in such cases anyway to back them up...

And that's why Windows Vista made it a lot easier for you.... By default, it contains the option to backup your important files. So if it's present by default? Why not use it? No need to install additional tools for this, just run the backup wizard.
Start orb > Control Panel > System and Maintenance > Back up your computer.
There you can select to create a backup of your files and folders and store them wherever you want.
Easy huh? So why don't you backup right now? Because you never know what the future may bring. After all, not only malware, but a corrupted program install/updates may cause a system unstable/unbootable as well.

MEDION AKOYA MD 96630 Premium - I'm impressed

I was already looking for a new laptop since last year, but couldn't decide which one to buy.
My current laptop Fujitsu siemens Amilo M1425 XP SP2 installed is great, but I needed an extra one with Windows Vista installed, because it's easier for me to properly troubleshoot Windows Vista issues when I have the operating system in front of me. I actually already had Windows Vista installed in a Virtual machine (Vmware), but since it needs so much resources, you can imagine that it was really crawling and I actually could have a cup of coffee while Vista was loading in Vmware.
I also could have a dual boot - one with XP, one with Vista, but then again, I'm a bit lazy and don't like to switch everytime :)

So, that's why I decided to buy a new laptop.....

Since the public release of Vista, many laptops were already preinstalled with Vista and there were still many incompatibility issues with other hardware and software installed. Most software - at that time - were not "vista ready" yet, so that's why I decided to wait a bit longer.

Nowadays, most software/hardware should be Vista compatible, so I've waited long enough, time to get myself a new OS, new laptop.

I was actually going to wait until april/may this year for the new laptop, this to make sure everything was REALLY Vista compatible (hardware related).
But I've changed my mind when I received a mail with this. Hmm Medion, I've heard some weird things about it....

Anyway,
699 euro.. I thought they were joking. So, I went to Aldi and bought it anyway, and guess what - it was no joke. I've uninstalled the preinstalled Bullguard and some other "goodies", reinstalled my "own" programs and everything works great and incredibly fast - even faster than my Fujitsu siemens Amilo M1425! (what do you expect with 3GB of ram) :)

So medion isn't so bad after all - on the contrary....