Pages

Showing posts with label java. Show all posts
Showing posts with label java. Show all posts

Tuesday, December 28, 2010

Script & Macro Viruses

Script / Macro Viruses - Types and Habitats



Script Viruses - Types and Habitats

Script viruses (sometimes called macro viruses) generally travel embedded in email and office automation documents, although they can be found in web pages as well.

Old fashioned program viruses are usually implemented in executable system code, whereas script viruses are usually written in a powerful high-level language that is compiled and run on the fly. They often have sophisticated functionality and direct interfaces to high level applications such as word processing, spreadsheet, email, and web programs, and can wreak considerable havoc. Since they first surfaced in office automation programs, they are sometimes also called "macro" viruses. Script viruses can also propagate through IRC protocols.

On Microsoft computers, turning on your script checking virus protection is essential. However, keep in mind that there may be an associated performance hit for some applications. Many applications on Windows are written in Visual Basic, and real-time script virus checking can double the time it takes for their usual functions to run. If you find that ordinary functions take an inordinate length of time to complete, you can try temporarily turning this feature off in your anti-virus checker -- but don't forget to turn it back on afterwards!

Active threats. The following types of script viruses are currently the most active and dangerous, on the Windows platform:

Visual Basic is a flexible and powerful programming environment for Microsoft Windows, Office, and Internet applications. Script viruses written in Visual Basic can run throughout the Microsoft architecture, giving them considerable reach and power, and making them the primary virus threat today.

The first widespread Visual Basic script virus was Melissa, which brought down several of the large international corporations for several days in March 1999. Melissa traveled in a Microsoft Word document and ran when the document was opened, then opened the associated Microsoft Outlook email program, read the user's email address book, and then sent email copies of itself to the first fifty names it found. It spread very quickly.

The Melissa virus architecture was quickly followed by many similar variants programmed by hackers around the world, including the ground breaking KAK, the first Visual Basic script virus that triggered as soon as an email was opened. KAK was then followed by BubbleBoy, which triggered if an email was even viewed in the preview pane. A steady stream of Visual Basic script viruses continue to circulate to this day. There are even automated, point and click programs like VBS Love Generator to help hackers produce additional variants. Script viruses which use email to send themselves to others are also a form of worm.

The term "macro virus" is used less often, and generally refers to a virus in an office automation application macro, most commonly a Visual Basic macro in a Microsoft Word or Excel document. Macro viruses can cross system boundaries from Windows to Macintosh computers with MS Office documents. Current versions of Microsoft Office contain strong anti-macro protections to guard against known attacks.
ActiveX is one of Microsoft's distributed application technologies that enable web pages to download programs on the fly with the full power of any executable running on your machine. This makes ActiveX modules especially efficient and powerful, but also a security risk since they can create, change, and delete files, add system programming code, or take any other action your user account is allowed on your computer.

To help mitigate the risk, Microsoft provides a network architecture of encrypted security certificates for ActiveX modules. This network gives you the option of refusing the download of unsigned ActiveX modules from unknown authors, and at least disclosing the signed identity of those modules that you do accept in case they later cause problems. However, this approach is not universally accepted by the general user and professional security communities, and is sometimes called "trust me now, try to catch me later". Users running Internet Explorer on Windows machines should make sure that their browser security settings are set to "disable" for unsigned ActiveX applets, and to "prompt" for signed applets.
Hypothetical threats. The following script viruses are largely theoretical, but illustrate that they can turn up wherever there is scripting code:

Java is a standard cross platform development environment, and is often used to download scripts to add functionality like a clock or chat room interface to a web page. Java was written with a strong security model which protects your computer's data and resources, and it has so far proved remarkably resistant to script virus infection. You can turn Java off in your browser if you want to be extra careful, but it will disable some useful functionality on some web pages.
JavaScript is the standard web programming language. JavaScript also has a well-defined security model that protects data and resources, and the few JavaScript viruses that have been discovered have been mainly theoretical in nature. You can turn JavaScript off in your browser settings if you want to be extra careful, but it will disable functionality on many web pages.
MIME. The first script virus that triggered as soon as an email was opened was a MIME virus that applied to older versions of Netscape Mail, Microsoft Outlook, and Eudora Mail. In a variation on an old hacker technique, the attached MIME file was given a very long name that triggered a bug which allowed the end of the name to be run as a series of instructions, which could then be written to run the virus. However, a fix for the bug was quickly developed for each vulnerable email program, and MIME viruses have so far remained hypothetical.
Others. Several other scripting environments have also had viruses, including Corel Draw, Hypertext Preprocessor, Windows Help, Windows installation files, and Windows registry files. Anywhere there is a script interpreter there is an opportunity for a script virus to run.

Sunday, November 14, 2010

airtel free servers hacked for opera ucweb port 80 trick added full details

here are some sites which can become server of opera with dot trick and front query for uc,bolt,opera,gmap,shmessenger,mixit etc with cgi tricks(all this are working with default mo):

http://202.87.41.147
http://waptools.net4nuts.com (it uses divertion,redirection its nyc one)
http://airtel.bharatmatrimony.com
http://airtelprofit.mo2do.net
(like dis i have many others sites which can become front queris but i kept it secret because if airtel block dis trick i can share that fq again )


FOR OPERA 4.2 and OPERA 5.1


step 1:

write in both

custom http and socket server:

http://waptools.net4nuts.com.server4.operamini.com/


OR ANY OF THE BELOW:

http://202.87.41.147.server4.operamini.com/

http://airtel.bharatmatrimony.com.server4.operamini.com/

http://airtelprofit.mo2do.net.server4.operamini.com/

http://125.21.241.77.server4.operamini.com/

http://125.21.241.77.scarewar.com/cgi-bin/nph-get.cgi/000001A/http/server4.operamini.com/



step 2:


FRONT QUERY:

waptools.net4nuts.com.t9space.com/power/m/http/

OR

125.21.241.77.scarewar.com/cgi-bin/nph-get.cgi/000001A/http/


(dowloading in opera works great with above scarewar frnt query)


OR

202.87.41.147.scarewar.com/cgi-bin/nph-get.cgi/000001A/http/

waptools.net4nuts.com.scarewar.com/cgi-bin/nph-get.cgi/000001A/http/

airtel.bharatmatrimony.com.scarewar.com/cgi-bin/nph-get.cgi/000001A/http/

airtelprofit.mo2do.net.scarewar.com/cgi-bin/nph-get.cgi/000001A/http/



step 3:

leave other field balnk ,,if there is extra option in handler menu like proxy then select no proxy

now initialize it(if initialization fails then initialize with balance later use it free)


FOR UC,BOLT,GMAP,MIXIT and SHMESSENGER(plz for shmessenger open shmessenger and select http ie wap connection)

step 1:

open software and

USE ANY OF THE FOLLOWING FRONT QUERIES:


125.21.241.77.scarewar.com/cgi-bin/nph-get.cgi/000001A/http/ (its working great with DOWNLAODING if not working in ur area then try below frnt qry)

202.87.41.147.scarewar.com/cgi-bin/nph-get.cgi/000001A/http/

waptools.net4nuts.com.scarewar.com/cgi-bin/nph-get.cgi/000001A/http/

airtel.bharatmatrimony.com.scarewar.com/cgi-bin/nph-get.cgi/000001A/http/

airtelprofit.mo2do.net.scarewar.com/cgi-bin/nph-get.cgi/000001A/http/



OR


202.87.41.147.www.flyproxy.com/nph-proxy.pl/0A/http/

202.87.41.147.lelook.com/cgi-bin/nph-get.cgi/000110A/http/

202.87.41.147.gowingo.com/cgi-bin/nph-get.cgi/000100A/http/




OR


waptools.net4nuts.com.scarewar.com/cgi-bin/nph-get.cgi/000001A/http/

waptools.net4nuts.com.www.flyproxy.com/nph-proxy.pl/0A/http/

waptools.net4nuts.com.lelook.com/cgi-bin/nph-get.cgi/000110A/http/

waptools.net4nuts.com.gowingo.com/cgi-bin/nph-get.cgi/000100A/http/



OR




airtel.bharatmatrimony.com.www.flyproxy.com/nph-proxy.pl/0A/http/

airtel.bharatmatrimony.com.scarewar.com/cgi-bin/nph-get.cgi/000001A/http/

airtel.bharatmatrimony.com.gowingo.com/cgi-bin/nph-get.cgi/000100A/http/





OR


airtelprofit.mo2do.net.www.flyproxy.com/nph-proxy.pl/0A/http/

airtelprofit.mo2do.net.lelook.com/cgi-bin/nph-get.cgi/000110A/http/

airtelprofit.mo2do.net.gowingo.com/cgi-bin/nph-get.cgi/000100A/http/


step 2:

now leave other field blank(if there is anything pre-written in middle and black query then erase it)

step 3:
uncheck remove port from string

(if thereis option of proxy then select it no proxy)

step 4;

now initialize it (if initialization fails then initialize it with balance later use it free)

IMP NOTE:

guyz plz perform network test in ucweb before using after that u r able to use it free( guyz dont try to surf directly without perfoming network test becoz with this trick page will open or load after performing network test in uc)





FOR OPERA 3.xx handler (( AND ALSO FOR OPERA 4.XX AND OPERA5.XX replace server.operamini.com BY server4.operamini.com/))

write in BOTH CUSTOM HTTP AND SOCKET SERVER:

http://202.87.41.147.www.fyproxy.com/nph-proxy.pl/0A/http/server.operamini.com/

http://waptools.net4nuts.com.www.flyproxy.com/nph-proxy.pl/0A/http/server.operamini.com/

http://airtel.bharatmatrimony.com.www.flyproxy.com/nph-proxy.pl/0A/http/server.operamini.com/

http://airtelprofit.mo2do.net.www.flyproxy.com/nph-proxy.pl/0A/http/server.operamini.com/

What is J2ME or Java ME?

Primary components of the Java Platform, Micro Edition (Java ME, formerly J2ME) include Connected Device Configurations, Connected Limited Device Configurations, Mobile Information Device Profiles, along with many other tools and technologies that address Java solutions for the consumer and embedded device markets. Take your first step into learning more about these technologies. Definitions of terms, and what these new concepts can mean to you are available on the java.sun.com web sites below:

J2ME Technologies
Mobility
 
Java ME (formerly J2ME) technologies contain a highly optimized Java Runtime Environment, that specifically addresses the vast consumer space. Java ME technologies cover a wide range of extremely tiny commodities, and enable security, connectivity, and useful utility programs inside smart cards, pagers, set-top boxes, and other small appliances. Java ME technologies are only one part of the Java software product family. Related Java platforms include the Java Platform, Standard Edition (Java SE, formerly J2SE platform), and the Java Platform, Enterprise Edition (Java EE, formerly J2EE platform). Java technology also provides ways to create Web services, XML information transfers, numerous networking protocols, toolkits, and the Java Web Start application.

For more information about Java software products, please visit:

Java Technologies.