Showing posts with label orkut virus. Show all posts
Showing posts with label orkut virus. Show all posts

10 Computer Threats You


Strong anti-virus software and firewalls do a great job of protecting our computer systems. But even when virus definitions are fully updated and firewalls properly configured, there are still insidious threats that can worm their ways in, stealing your data or hijacking your PC and leaving you none the wiser.
Fake Tech-Support Calls
That job isn't fixing your computer. In fact, he's really just after your personal information.
If you receive a call like this, hang up, call the company the bogus technician claimed to be from, and report the incident to a legitimate representative. If there really is a problem, they'll be able to tell you; if not, you just thwarted a data thief.
DNS Redirection
Internet service providers (ISPs) such as Time Warner Cable and Optimum Online claim they're trying to help with DNS redirection, but the reality seems to come down to money. Domain Name System (DNS) redirection overrides your browser's normal behavior when you can't reach a webpage. Instead of displaying the normal 404 "File Not Found" error, the ISP sends you to a page of the ISP's choosing — usually a page full of paid advertising and links.
Innocent though that practice may be, computer viruses can do the same thing, redirecting your browser to a hostile page the first time you misspell a domain. With ISPs, you can opt out of their DNS redirection (you'll find links below all the ads); with viruses, stay on your toes. Make sure you know what your browser's default 404 page looks like, and take action if you see anything different.
Open DNS Resolvers
Another danger lies in the way some DNS servers are configured. An "open resolver" can offer information it isn't authorized to provide. Not only are open resolvers exploited in distributed denial-of-service (DDoS) attacks, but an attacker can "poison" the DNS cache, providing false information and incorrect resolutions that must be detected to be corrected.
If your browser trips over a case of cache poisoning, the agents in charge of a hostile server can glean detailed information about your system — especially if you're in the middle of an important transaction. How can typical users solve this dilemma? The chilling answer: They can't. It's up to Internet service providers to address the problem.
Fraudulent SSL Certificates
A Secure Sockets Layer (SSL) certificate reassures your browser that the site you've connected to is what it says it is. If you're looking at "HTTPS" instead of plain old "HTTP," you know there's security involved, such as when you log in to your bank account or pay your phone bill. The most trusted SSL certificates are issued by designated Certification Authorities worldwide.
But what happens if that trust between browser and website is exploited? Acquiring or creating fake SSL certificates is unlawful, but happens often enough that we need to be aware of it. On multiple occasions in 2011, the discovery of false certificates suggested an attempt to spy on Iranian citizens as they used Gmail and Google Docs. According to the website of computer security firm F-Secure, "It's likely the government of Iran is using these techniques to monitor local dissidents."
Session Hijacking
If you spend afternoons using your laptop in a café with an open Wi-Fi network, you might not be the only person logged into your Facebook or eBay account. Firesheep, an add-on for Mozilla's Firefox browser, lets its users sneak a peek at other people's browser activity if they're all on the same wireless network.
While the illicit observers can't get a glimpse of secured pages, many sites secure only their login pages; once you're logged in, your presence is maintained purely through cookies, packets of data that your browser stores to keep track of your browsing needs. But Firesheep lets its users copy your cookies, and after that happens the site you're logged into can't tell the difference between you and them.
Though it can be used for darker purposes, Firesheep should serve more as a warning to websites with private user accounts: They need to take security seriously. Guarding the main gate isn't the limit of their responsibilities; attackers don't need to storm the castle when a guest leaves the door open.
Man-in-the-Middle Attacks
While you're still sipping your latte on that unsecured network, even your encrypted messages may not be all that safe. A Man-in-the-Middle (MTM) attack occurs when an attacker intercepts communications and proceeds to "relay" messages back and forth between the lawful parties.
While the messaging parties believe their two-way conversation is private, and might even use a private encryption key, every message is re-routed through the attacker, who can alter the content before sending it on to the intended recipient. The encryption key itself can be swapped out for one the attacker controls, and the original parties remain unaware of the eavesdropper the entire time.
SQL Injection
Databases using structured query language (SQL) rely on specially formatted queries to locate and return requested data. Human or automated attackers can send requests that exploit the database's internal codes to alter the query as it's processed. This year alone, SQL injection was the culprit behind a number of notorious security breaches, such as hacker group LulzSec's alleged theft of data from the Sony Pictures server.
Once again, the solution to this problem isn't in the user's hands.
"Well-designed software avoids the problem by weeding out any queries that don't meet strict standards," said Beth Paley, a software training consultant and co-founder of Acrotrex Medical Business Systems in northern New Jersey.
Paley advises those who create and maintain database apps to "use whitelisting, not blacklisting," letting only specific data through instead of keeping only specific data out. That way previously unseen SQL injections won't get through.
Disguised Filenames
Modern operating systems accommodate speakers of languages such as Arabic and Hebrew by featuring codes which can reverse the direction of type to display such languages correctly: written right-to-left instead of left-to-right.
Unfortunately, these "RTL" and "LTR" commands are special Unicode characters that can be included in any text, including filenames and extensions. Exploiting this fact, a malware purveyor can disguise ".exe" files as other files with different extensions. Your operating system will display the "disguised" name, though it still treats the file as an executable — launching it will run the program and infect your computer. Practice caution with any and all files from unknown sources.
Banking Trojans
A Trojan is malicious software that disguises itself as innocent program, counting on you to download or install it into your system so it can secretly accomplish its malicious tasks. The infamous ZeuS Trojan and its rival SpyEye take advantage of security holes in your Internet browser to "piggyback" on your session when you log in to your bank's website.
These monsters are in the Ivy League of computer malware; they avoid fraud detection using caution, calculating inconspicuous amounts of money to transfer out of your account based on your balance and transaction history.
While financial institutions continue to increase the layers of security involved in large transactions, such as requiring confirmation through "out-of-band" communications — such as your mobile device — digital crooks have lost no time adapting to the changes, with banking Trojans able to change the mobile number tied to your account and intercept that confirmation request. If you're a tempting target, fear is an understandable response. It's just another part of a digital arms race that shows no signs of slowing down.
Facebook Everywhere
It's hard to find an individual who or a corporation that isn't on Facebook. The social networking site has become an ever-present hub for everything online. For some less savvy users, Facebook is the Internet.
With developments like Facebook Connect and Open Graph, Facebook is virtually opening its doors to any third party that wants in on the action. You may have already noticed that Facebook displays ads targeting your specific demographic information, based on the personal information you've posted and activities you've participated in.
What you might not have noticed is that other sites have started targeting your Facebook demographics as well. Any time you browse the Web without first logging out of Facebook, other sites can get access to any profile information you've marked as fit for public consumption.
Don't want every site on the Internet to see you coming a mile away? Just remember to log out of Facebook every time.
This story was provided by SecurityNewsDaily, a sister site to LiveScience.
facebook virus, orkut virus, virus, virus protection, virus security

 Working on orkut security, I know that fraudulent sites sometimes try to take advantage of orkut users like you and me. To help make sure that everyone is able to have a fun and safe experience on the site, I thought I'd share a few quick tips that I've picked up during my time on the orkut team. A bunch of these might seem like no-brainers, but hopefully you'll learn something new here as well:
  • Create a tough password: While "yourname123" is always a tempting password to create, keep in mind that it's just as easy for a malicious user to figure out as it is for you to remember. Try creating a password that involves a combination of letters and numbers that no one could easily guess, even if they know basic details about who you are. The same goes for your security question (the question that pops up if you forget your password)– you should try your best to pick a question that only you can answer.
  • Keep your private details private: Never share your orkut username and password with friends or on a site not authenticated by Google. orkut does not allow any external sites to store orkut login information and will never request that you enter it anywhere outside of the orkut login page. To be on the safe side, always check that your address bar reads "https://www.google.com/accounts/ServiceLogin?....." and nothing else when sharing your orkut user name and password.
  • Leave the coding to the engineers: Never copy and paste code into your address bar, no matter what it claims to be able to do. Typically these scripts actually send messages (in your name!) to your friends trying to trick them into giving up their personal information.
  • Downloads and orkut don't mix: Never download any file off of orkut, especially those that end in '.vb' or '.exe'. These files are often viruses that can infect your computer and start sending thousands of spam messages on your behalf. Sites offering special orkut themes or skins are particularly risky.
  • Think twice about external links: Links to sites outside of orkut that appear in scraps or posts have not been verified by the orkut team, and could lead you to harmful sites. We'd recommend only clicking on links that go to trusted sites or those that are from other orkut users you know well.
  • Anti-Virus software is always a good call: Even the most conscientious orkuteer can fall victim to a phishing attack, so it's important to always be alert and prepared. Regularly scanning your computer with updated anti-virus software is a great way to keep your computer secure.
  • For new orkut features, check out apps!: Sometimes an unofficial site may claim to offer special orkut features, but these sites are known for taking over orkut accounts and directly violate our Terms of Service. If you're looking for fun new orkut functionality, check out the thousands of applications that we have available. All of these apps have been built by talented developers according to standards that we believe will help to keep you safe online. If you haven't visited the app directory recently, take a look– you might be surprised at how much cool stuff you find.

via orkut blog 

Orkut Virus(BOM SABADO)

 Now a days orkut became a soft target of hackers and virus(like BOM SABADO) this is because orkut has huge network where he(virus(BOM SABADO),hackers) can spread easily.One more thing why orkut,this is because orkut members belongs to each section of society like professionals and non-professionals,young guys and child(from 8 to15).business man and technical expert behined this lot of guys dont know how set security and privacy on profile,some guys yet dint know why  they will set security level,they came on orkut for enjoyment or nothing else what ever you will post his scarpbook they will click what they will get or lost on click this not matter for him,hackers and virus(BOM SABADO) make him target first after that they spreading his infected content on network.BOM SABADO is one of the virus.Here sintuhack try to expalin about---.
  1.What is Bom Sabado
   2.How Bom Sabado virus attacked or Hacked Orukt users?
   3.What to do if my Orkut account has been hacked by Bom Sabado Virus?                                                                        
What is Bom Sabado?
In Portuguese language Bom Sabado means ‘Good Saturday’. But it was really a very bad Saturday for most of the Orkut users as this Bom Sabado virus hacked the user accounts of many Orkut users, mostly of India and Brazil. Portuguese is the also the official language of Brazil. So the Virus was mostly targeted on Brazilian users.
How Bom Sabado virus attacked or Hacked Orukt users?
Orkut users affected by Bom Sabado virus are automatically posting virus scraps on the other orkut users’ scrapbook and also adding them to new Orkut groups. Within a short period of time this virus was spread to the accounts of many Orkut users. You don’t need to click any links to be infected by this Virus, but a near watching of an infected orkut profile or scrapbook with Bom Sabado virus is more than enough to get your account hacked.
What to do if my Orkut account has been hacked by Bom Sabado Virus?
If you found that your Orkut account has been hacked:---
Do not login Orkut from PC at this time.
Clear cache, cookies and history from web browser
Login Orkut by visiting http://m.orkut.com/ only from your mobile phone.
Revert your theme/style back to the old Orkut layout
Delete all the scraps with the message ‘Bom Sabado’
Un-join from Brazilian communities if you have any doubts on them.
Change your Orkut account password
Logout from Orkut
Have a coffee and relax
How to stay safe from Bom Sabado Orkut Virus?
The best thing to be stay safe from this new orkut virus Bom Sabado is not to login orkut, till Orkut team has fixed this security loophole.
Do not tell your friends to login orkut till Orkut team has fixed this.
Spread this article to all your Orkut friends through email, facebook, twitter etc and help them to be stay safe from this new Orkut vulnerability.

Orkut Auto Scrap Virus Security


Orkut is getting targeted by a new Brazilian scrap virus, the virus infects users on clicking of the scrap message claiming to show some kind of video but it contain some exe file wich will be install  in your system on click.So Please dont Click simply delete this scrap.If you have clicked by mistake please follow following steps and uninstall this exe
This virus that claimes to be a video is a .exe file which infects users computer and sends the same scrap to all your friends on Orkut, the virus installs "orkutkut exe" and "imglog exe" on the infected computer, the virus can easily be disabled by following the steps below:
1.Kill both("orkutkut exe" and "imglog exe") the process from the 2.task manager (CTRL+SHIFT+ESC).
3.Remove startup entries using msconfig exe
4.Delete the two above mentioned files from system32 folder.
To secure yourself from such threats never click on unknown links in your scrapbook.!!!!HAPPY ORKUTING