The Replica Prop Forum

The Replica Prop Forum
Very cool site I am also a member of
Showing posts with label Computer Security. Show all posts
Showing posts with label Computer Security. Show all posts

Thursday, February 19, 2015

Government Spying and Lies

"AMERICAN AND BRITISH spies hacked into the internal computer network of the largest manufacturer of SIM cards in the world, stealing encryption keys used to protect the privacy of cellphone communications across the globe, according to top-secret documents provided to The Intercept by National Security Agency whistleblower Edward Snowden.

The hack was perpetrated by a joint unit consisting of operatives from the NSA and its British counterpart Government Communications Headquarters, or GCHQ. The breach, detailed in a secret 2010 GCHQ document, gave the surveillance agencies the potential to secretly monitor a large portion of the world’s cellular communications, including both voice and data."


So no matter what precautions you take, they can still access your communications and your device. Meaning, you have NO privacy and they can go through your data, text messages, voice mails, videos and phots anytime they feel like it.

"(Reuters) - The U.S. National Security Agency has figured out how to hide spying software deep within hard drives made by Western Digital, Seagate, Toshiba and other top manufacturers, giving the agency the means to eavesdrop on the majority of the world's computers, according to cyber researchers and former operatives.

That long-sought and closely guarded ability was part of a cluster of spying programs discovered by Kaspersky Lab, the Moscow-based security software maker that has exposed a series of Western cyberespionage operations.

Kaspersky said it found personal computers in 30 countries infected with one or more of the spying programs, with the most infections seen in Iran, followed by Russia, Pakistan, Afghanistan, China, Mali, Syria, Yemen and Algeria. The targets included government and military institutions, telecommunication companies, banks, energy companies, nuclear researchers, media, and Islamic activists, Kaspersky said."


So you have an over 60% chance that the hard drive in your computer has a hidden back door allowing "A Security Agency" access to everything on your computer. Even if you have a clean drive in addition to the infected drive, they have access. Also depending on how this program interacts with the BIOS, any device you plug into your computer could become infected as well. Your Cell phone, Tablet, Kindle, Nook, Fire etc.

"A team of prominent researchers suggested Thursday that limited airborne transmission of the Ebola virus is "very likely," a hypothesis that could reignite the debate that started last fall after one of the scientists offered the same opinion.

"It is very likely that at least some degree of Ebola virus transmission currently occurs via infectious aerosols generated from the gastrointestinal tract, the respiratory tract, or medical procedures, although this has been difficult to definitively demonstrate or rule out, since those exposed to infectious aerosols also are most likely to be in close proximity to, and in direct contact with, an infected case," the scientists wrote. Their peer-reviewed study was published in mBio, a journal of the American Society of Microbiology.

The study's lead author, Michael T. Osterholm, an epidemiologist at the Center for Infectious Disease Research and Policy at the University of Minnesota, touched off a small furor and was condemned by some experts last Sept. 11 when he raised the same possibility in an op-ed piece in the New York Times as concern over the spread of the deadly disease was increasing rapidly....

"There was almost a rush to ensure the public that we knew a lot more than we did," Osterholm said in an interview Wednesday night, repeating a theme he has raised many times before. "But we're saying you can't rule out respiratory transmission."


Oh really?  A chance to inflate your sense of importance?  And you didn't take it?  How unusual.  And to do it with the lives of millions if not billions of people.  How do you people stand yourselves?

Sunday, June 15, 2014

Air Gap - Computer Security

"Hackers on the other side of the world could use cellphone-based malware to remotely access any data they want, using the electromagnetic waves emanating from computer or server hardware, with no need for an Internet connection."

So all that is needed, is for an infected phone to come between 3 and 6 meters of your computer.. And if it has a microphone and speakers hooked up, and your computer it can be successfully attacked by the cell phone.

That is just ONE of the reasons my own computers don't have microphones on them.  If I need a microphone, I'll pull out my headset and use it.

So if you want some more security for your computers and don't mind using a headset that loads it's own drivers like the following ones.

Microsoft Life Chat

Plantronics 478

Logitech H390

And no, I don't get anything from Amazon for posting those links.  I am not an Affiliate.

So you would go into your device manager and uninstall or disable the existing micro phone driver, then when you want to use a microphone you would plug in the USB Headset headset.  It should load it's own driver, which normally takes about 30-45 seconds, at least on my computer it does, then you can use it.

Orrrrrrr you can pull the battery out of your phone or put it in a small anti-static bag or small Faraday Cage to block any and all signals.

H/t Claire Wolfe

Tuesday, November 5, 2013

Computer Virii through your soundcard?

Borepatch links to this one and it is scary.


"Ruiu said he arrived at the theory about badBIOS's high-frequency networking capability after observing encrypted data packets being sent to and from an infected laptop that had no obvious network connection with—but was in close proximity to—another badBIOS-infected computer. The packets were transmitted even when the laptop had its Wi-Fi and Bluetooth cards removed. Ruiu also disconnected the machine's power cord so it ran only on battery to rule out the possibility that it was receiving signals over the electrical connection. Even then, forensic tools showed the packets continued to flow over the airgapped machine. Then, when Ruiu removed the internal speaker and microphone connected to the airgapped machine, the packets suddenly stopped."

In the article it's stated that the original infection might have come in through an infected USB Thumb Drive ala STUXNET but there is still no way to fully trace it.  However the Virus /Malware/Rootkit whatever it is, appears to be able to use a computers speakers and microphone to transmit itself from one computer to another in addition to traditional methods for infection.


Also at Borepatch's there is a very interesting post about ObamaCare's Employer Mandate.

"But that mandate was for individuals, who make up less than 10% of the public.  People who get insurance via their employer make up the other 90%.  And when that mandate hits, it will be chaos.  The Administration knew back in 2010 that perhaps a hundred Million people would lose their coverage."

Click the link above and go read about it.

Monday, September 23, 2013

Cookies from FBI on my computer?

I'm doing my blogroll and browsing bookface and as usual after I log out of bookface I go in to delete the cookie they put on my computer as there are reports it can still track where you go after logging out.

And what do I see in my cookies?


A cookie from the FBI.  I didn't go to any site that is government affiliated.  So why do I have a cookie from the FBI on my computer?

ETA: I ran a trace on my system to see how I get to bookface and here are the results.

Microsoft Windows [Version 6.0.6002]
Copyright (c) 2006 Microsoft Corporation.  All rights reserved.

tracert facebook.com

Tracing route to facebook.com [173.252.110.27]
over a maximum of 30 hops:

  1    58 ms     2 ms     2 ms  *********[192.168.1.1]
  2     2 ms     2 ms     2 ms  192.168.0.1
  3    14 ms    13 ms    13 ms  adsl-75-9-223-254.dsl.crchtx.sbcglobal.net [**********]
  4    14 ms    13 ms    13 ms  dist1-vlan52.crchtx.sbcglobal.net [65.71.129.17]

  5    15 ms    13 ms    14 ms  12.83.54.41
  6    58 ms    57 ms    58 ms  ggr3.cgcil.ip.att.net [12.122.132.9]
  7    58 ms     *       58 ms  12.250.28.10
  8    60 ms    60 ms    61 ms  ae1.bb02.ord1.tfbnw.net [31.13.29.2]
  9    77 ms    77 ms    77 ms  ae12.bb02.atl1.tfbnw.net [31.13.27.150]
 10    86 ms    85 ms    84 ms  ae11.bb03.frc1.tfbnw.net [31.13.27.120]
 11    98 ms    82 ms    81 ms  ae39.dr01.frc1.tfbnw.net [31.13.27.55]
 12     *        *        *     Request timed out.
 13     *        *        *     Request timed out.
 14    83 ms    82 ms    83 ms  edge-star-shv-13-frc1.facebook.com [173.252.110.
27]

Trace complete.

Hops 8 through 11 are all in Ireland.  Why does my traffic have to go to Ireland when I'm in Texas and bookface's server is in Princeton, New Jersey?

Sunday, August 11, 2013

Evidently someone doesn't like me.


 I got drive by downloaded earlier evidently.  That is where while you are viewing a site a part of the site is downloading into your computer probably through a flash ad or a javascript script.  I was doing research on an issue I have posted on a couple of times before when my system went BSOD and kicked me out.  I was like Ok....

I rebooted and used my Dual Boot to find out what the heck happened.


 Someone or something tried to activate my camera and it caused their program to mess up.  And then that caused is what caused my BSOD.  Now if the program messing with my system had just left my camera alone it would have succeeded a lot better in what they were trying to do.  But what it DID do was pretty bad.

While I research a certain thing, I have to plug in my backup drive to shadow all my research.  This allowed something to get into BOTH of my drives and delete a LOT of the stuff I have researched..  It also scragged or tried to scrag my OS and all of my other files.



Well they didn't really succeed.because of other software I have on my system.  However I DID lose about 4 months of research, which included video's which are no longer available on youtube, webpages that no longer exist and the Wayback Machine at Archive.org doesn't have copies of.

That doesn't really bother me.  What DOES Bother me is they completely wiped out my book directory which had over 800 books in various formats, .TXT, .RTF, .DOC, .PDF and .HTML.  Those were book I have downloaded over the last 12 years, a lot of science fiction and military history, which I enjoyed reading.  And now they and a couple other of my directories are completely gone.

So even MY somewhat paranoid security settings can be gotten through just like Sir Knight's at the top of this post.

Friday, July 26, 2013

Wednesday, July 17, 2013

Physical computer security

"The target was at Fridayevening prayers at the local mosque. But rather than ransack the apartment and stealthe computer equipment and other valuables while he was away -- as any right-minded burglar wouldnormally have done -- one of the men pulled out a disk and loaded some programs onto the resident's laptop computer while the other man kept watch at thewindow. The whole operation took less than two minutes, then the two trespassers fled the way they came, leaving no trace that they had ever been there."

Many years ago there was an 8 bit ISA card that was installed into your computer that was an extra security measure for some computers.  The card logged every time the computer was turned on and required an additional password to be entered before it would allow access to the hard drive.  Does anyone know what the name of that card was?  And if there is a current iteration of it?  I think I should look into adding something like that to my computers.

Not that I'm doing anything illegal, however with what I'm seeing going on with our so called "Security" agencies and knowing what I write on my blog, I wouldn't put it past the current crop of idjits to try to find out what I keep on my hard drives.  And for those idjits, everything on my drives is legal, even if you don't think I should have some of it, it IS legal for me to possess it.  It only becomes Illegal if I have the INTENT of using the knowledge those files possess.  And I personally have no intent to do so.  I'd really like to see my kids grow up get married and have kids of their own, and I really want to dance at my grandkids weddings.  So NO, I have no intent on using the files you wish I and millions of others didn't have.  But it would tickle me silly if I added security hardware to my computers just to inconvenience you.  And you might ask yourselves why that would tickle me silly.  It's because you are over stepping your authority and abusing the public trust in the process.  If you quit doing the things which you KNOW are unconstitutional even though they are "technically" legal with the cover of judicial connivance.  You KNOW that it is wrong.  So stop doing it.

Thursday, May 2, 2013

Malware and anti-virus updates -UPDATED

Ok something weird is going on.  According to my logs my A/V program has pushed 11 updates today alone.  Normally it will update 2 or 3 times a day.  This time it has updated 11 times, changed it's start up settings, and has a completely new sub program it installed.  So I loaded my other protection software and all of them had updates 3 to 4 times the size of a normal update.  And all of these programs were just updated sunday. 4 days ago.

So something is up.  I went searching to see if there is any chatter on the A/V Anti-Malware forums that I can find.  So if you are in IT could you check your logs and maybe leave a comment here or drop me an e-mail.

This concerns me as I have to keep the 5 computers here plus my moms 2 and my cousins 3 computers.  If something is going on I would like to know about it before it becomes an issue, as my mom and cousins don't run scan as religiously as I do.

UPDATE:  Ok my netbook just decided it had to download all new install files for Malware Bytes all of a sudden. It was updated like I said "Sunday" and it hasn't even been turned on since then until 15 minutes ago when I figured I'd get everything updated before I left for Houston in the morning.  Sooo I'm running a full scan on it, and I might break out the USB Thumbdrive running Linux and do a full scan with it.

Something is going on.  And I don't like it.

Monday, April 15, 2013

Main Computer back up

This morning, someone tried to hack into my computer.  Well not tried they did.  And it took me from 7:00 am until now 10:50 am to get my system back up.  I wish to thank the Lord for giving me the foresight to have back recovery discs, factory install disks and a full back up of my system as of midnight last night.

I've got scans running on the main system, and I finished running scans on this netbook earlier.  I THINK I know how they did it, and the router is getting it's firmware upgraded in a few minutes with a special firewall tweak a friend of mine wrote.

According to the remains of my logs, (Most of them were wiped out) an IP originating in California, I can't narrow it down closer than that, all I got were the first 2 portions of the IP, got through my router firewall and attacked my desktop.  Evidently when I was trying out a game I inadvertently opened a port in my system I shouldn't have.  Allowing whoever it was into my system.

I'm not saying this is related to what I write on my blog, but people have tried to hack me before, after I wrote something and posted it on the blog. 

Well the main system is back up, scans are getting run to make sure whoever did this didn't leave a surprise on the hard drive.

And I'm really going to reconsider getting that RAID system.  Having a full complete back up on a separate drive saved me I don't know how many hours of toil trying to get my system back to where it should be.

And if you're reading this, do YOU have your system backed up?  To a totally SEPARATE hard drive?

Mine is completely external through a USB external enclosure, so if I needed to I could just pull the plug and take the drive with me.

Having that type of piece of mind is worth the $90.00 I spent for a 1 TB external drive.

In actuality I have 3 1 TB USB drives, I've been using the other 2 to transfer large files between computers and to back up pictures.  I think I'm going to condense the 2 into 1, and use the extra 1 TB drive as an extra back up drive until I can put together a RAID system.

So if you don't have your computer, laptop, or whatever setup to back itself up, onto an external drive, you really need to reconsider that.

I'll probably be off the rest of the day, making sure they desktop is up to snuff and there are no nasties awaiting me on the drive someone might have left there.

So back up your DATA!!  And make sure it's done on an EXTERNAL drive.  Also use your firewall.  I have 2 of them, the hardware on in the router plus a software one on the desktop, the netbook and my tablet.

Be Secure and protect your computer and your files.

Tuesday, January 15, 2013

Removable media- hidden viruses

As part of my KTD-Project I purchase several different type of Removable media.  USB drives, SD cards and the such.  I recently got one that was infected by "8 Gigabytes" of something which had virus like coding on it.

It was a simple 32 GB USB Thumb drive, but as I put it in my USB Port, my anti virus wouldn't let the driver for it load.   Hmmm, that's curious.  So I looked at the drive a different way.  I booted into safe mode and then put the drive in the port and opened it's properties.  It was a 32GB drive that already had 8.2 GB of "Something" on it.

Tha "Something" didn't show when the drive was open, even though my system is setup to show me ALL my files including hidden and system files.  But it wouldn't show me what was hidden on this particular thumbdrive.

I called a friend and following his advice I opened a Hex Editor and looked at the drive that way.

As I told my friend what I found, he told me "STOP!"  That drive is virused!

So together we worked out how to use one of my much older systems to low level format it like it was an old style IDE Drive, then format it with Windows.

I now have a "Blank" 32GB drive, and I contacted the company I bought it from to let them know.  They were so happy I let them know, they gave me a partial refund of the purchase price.

And No I won't give out their name as they are only purchasing this type of drive from 2 different suppliers, and reselling it.  They are now pulling spot checks on their stock and are contacting their suppliers to find out how this happened, and how to ensure it hopefully doesn't happen again.

So, if you don't have your Anti-virus setup to scan ALL of your drives, including your removable drives, you need to change your settings so it does.  Plus make sure you run DAILY Virus Scans.  I've posted about the various programs I use and the schedule I use.  In fact Next week I'll probably be on the netbook for a few days, as my detail scans are due for running, and they take 2 to 3 days to run with all the hard drive space I have (Over 5 TB).

If you don't know how to change your settings to scan all of your drives including removable storage devices, contact your A/V's company and check their support forums.

Or you can post a comment and I'll try to help you.

Remember you want Daily virus scans and you want ANYTHING that plugs into your computer scanned.  Yes it slows my computer down some by having everything scanned, but I'd rather my computer be a bit slower than to get hit with a virus or malware.

Sunday, January 13, 2013

Computer Security - Java hacked again


Hackers have figured out how to exploit Java to install malicious software enabling them to commit crimes ranging from identity theft to making an infected computer part of an ad-hoc network of computers that can be used to attack websites.

"We are currently unaware of a practical solution to this problem," the Department of Homeland Security's Computer Emergency Readiness Team said in a posting on its website late on Thursday.



I only use Firefox so I can't tell you how to disable Java on any other platform, but in Firefox click on Tools, then Ad ons, then go to Plugins.  Look and see if you have Java or Java tools.  If you do click on Disable and close your tab.

Now you have Java Script also, however many cloud E-mail  accounts REQUIRE Javascript to load, so if you turn Java "Script" off you may not be able to access your e-mail.

Tuesday, October 23, 2012

Computer Maintenance and Security and YOU

About once a month my Ex-wife asks me to "Fix" her computer, at the same time my mother asks me to "Fix" her computer about 3 sometimes 4 times a year.  They are always concerned because their computers have gotten slower and are acting weird.

On my Ex-wife's computer, it is usually a combination of factors almost always related to the fact she lets our kids use her computer whenever they want and we have 4 boys who LOOOOOOOOOOVE  computer games.  And downloading patches and cracks.  Yes, most of the time her computer is Virused up with so many Virii I just pull her hard drive out of her computer and hook it up to one of my external drive enclosures and start letting my various A/V, Anti-Malware and drive maintenance programs go to work on it.  The full scans usually take 2 days.  Seriously, for a 320GB hard drive it takes 2 days to run all the scans I do on it.  The last time I pulled full maintenance on my computer I was on the laptop for a full week, 3.4 TB spread out over 5 drives takes a long time to scan fully.

My mothers computer isn't usually as bad but some of the Virii and other Malware she has gotten have been rather bad.  I actually had to do a wipe and full re-install once on her laptop it was so bad.

Both my Ex and my mom try to keep up with their computer maintenance, but with me just a phone call away they don't really stay up on it like they should.

However it does get old after the 7th or 8th time.

This isn't directed at my mother or my Ex, but to everyone in general.

The following are the list of programs I use.  And the schedule I follow for my personal computer systems.

CCleaner  I run this program every time I close my browser

Registry Mechanic  This is run once a day, I have a subscription that covers my two desktops and my netbook, which all run different versions of Windows, Windows XP Professional, Windows Vista Home Premium 64 Bit, and Windows 7 Business.

Malwarebytes Which is run every Saturday after being updated, and run in Chameleon Mode once a month.

Spybot Search and Destroy  Is also run every Saturday after updating and run in detail full scan mode once a month as well.  Be sure to re-immunize your system after every update.

Advanced System Care  This is run once a week after update, usually Sunday morning.

 AVG Anti Virus This is my main AntiVirii Program  They also have a Free version for home/Student use at Free.AVG.com  This is also a decent program.

There are other Free and low cost Anti Virus Programs but I don't use them as I have had problems with them in the past, usually related to browser setting they didn't like and kept trying to change and I didn't want them changed.  So the programs got changed.

Also, I reboot my computers once a day, normally after it finishes it's daily virus scan.

File Back up - I use the built in Windows Back for my Vista desktop and the Win7 Netbook, for the Win XP Pro I use Filefort File back u.  And all of my computers are backed up twice a week, on Tuesday and Saturday.

Defrag I use the built in Defrag program for the XP and Vista systems once a month.  Still haven't found a Defrag I like for the Win7 yet.

Now those are just the scans I do offline to protect my system.  Lets get into what add on I use to protect myself when I am on line.

First my browser.

Firefox  is the browser I use  and I use several add-ons/plugins to protect my system.

Adblock Plus to block ads

Adblock Plus Pop up Addon to help adblock block pop ups

Better Privacy which removes pesky Flash Cookies that track your browsing

Do Not Track Plus which blocks even more tracking cookies and such

Element Hiding Helper for Adblock Plus hides pesky page elements I don't want to see and can load malicious code on your computer through Javascript.

Ghostery add on blocks even more cookies and trackers.

No-Script Blocks scripts from running until you authorize them.

install and configure those addons to make it a LOT harder for malicious and rogue code to get loaded on your computer.  Of course they can all be undone by clicking on the wrong thing.  But I can't sit over your shoulder to tell you what to not click on.

With a little effort and some commonsense you can protect your computer from virii and other assorted nasties, however the best program or add on in the world won't protect you from your own stupidity.

So be sure what you click on, and remember.

If it's too good to be true, it probably is.

or TANSTAAFL  There Ain't No Such Thing As A Free Lunch