<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>I Make Money Online by Blogging, SELaplana.COM &#187; Security</title>
	<atom:link href="http://www.selaplana.com/category/technology/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.selaplana.com</link>
	<description>Make Money Online, Technology Stories, Products Review. (Southern Leyte's First E-Marketing and Blogging Experience - Direct from Maasin</description>
	<lastBuildDate>Fri, 06 Nov 2009 03:25:35 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>How to Hack Yahoo, GMail, and HotMail Account?</title>
		<link>http://www.selaplana.com/2009/08/12/how-to-hack-yahoo-gmail-hotm/</link>
		<comments>http://www.selaplana.com/2009/08/12/how-to-hack-yahoo-gmail-hotm/#comments</comments>
		<pubDate>Wed, 12 Aug 2009 06:12:42 +0000</pubDate>
		<dc:creator>SELaplana</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.selaplana.com/?p=7091</guid>
		<description><![CDATA[Can you really hack the email system of Gmail, Yahoo and Hotmail? I guess you can't. Hackers couldn't really attack the email system that's why lots of them do the phishing.]]></description>
			<content:encoded><![CDATA[<h2>Visitor&#8217;s Question through His Email</h2>
<blockquote><p>Sir Sel pwede mo po ba akong turuan mag-hack ng Yahoo! Email? Kasi duda ako na may kabit ang asawa ko nakachat niya lagi. &#8230;</p></blockquote>
<h2>My Answer</h2>
<p>Thank you for requesting something from me. This shows that you trusted me.</p>
<p>However, I am afraid I couldn&#8217;t teach you how. To let you know, hacking someone&#8217;s email account is illegal. Secondly, email accounts from Yahoo, Gmail and Hotmail couldn&#8217;t actually be hacked by directly attacking the email system.</p>
<p>And I just want to warned you not to ask help from someone who offers a hacking service because they&#8217;re intention is not to do what you have requested but to get something from you.</p>
<p>You might ask me this: <strong>But I learned that you were a victim of hackers, isn&#8217;t it true that there are really hackers who can hack email accounts?</strong></p>
<p>It might be true that my selaplana@yahoo.com account was hacked last 2004. But I think, the real problem was not in the Yahoo Email system but in my password. I was using before a very simple password, and I think, the hacker successfully guessed it.</p>
<h2>My Advice</h2>
<p>If you really think that you&#8217;re wife has been dishonest to you, hacking her email account is not the solution. You must talk to her patiently. Show to her that you really careÂ  about your relationship. Don&#8217;t hurt her but show your love to her.</p>
<p>And pray to God for His guidance.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.selaplana.com/2009/08/12/how-to-hack-yahoo-gmail-hotm/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>WWW.PRC.GOV.PH &#8211; Harmful Website</title>
		<link>http://www.selaplana.com/2009/08/02/www-prc-gov-ph-harmful-website/</link>
		<comments>http://www.selaplana.com/2009/08/02/www-prc-gov-ph-harmful-website/#comments</comments>
		<pubDate>Sun, 02 Aug 2009 06:46:36 +0000</pubDate>
		<dc:creator>SELaplana</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Webmaster Central]]></category>
		<category><![CDATA[Google Webmaster Tools]]></category>
		<category><![CDATA[Harm]]></category>
		<category><![CDATA[Malicious Codes]]></category>
		<category><![CDATA[PRC]]></category>
		<category><![CDATA[Search Result]]></category>
		<category><![CDATA[Site Advisor]]></category>
		<category><![CDATA[Website]]></category>

		<guid isPermaLink="false">http://www.selaplana.com/?p=6453</guid>
		<description><![CDATA[This afternoon, I noticed that Google considered the official website of the Professional Regulation Commission or PRC as a harmful website.

Here's the screenshot of the SERP when searching for the "<a href="http://www.selaplana.com/">www.prc.gov.ph</a>".
<p style="text-align: center;"><a rel="attachment wp-att-6454" href="http://www.selaplana.com/?attachment_id=6454"><img class="size-full wp-image-6454 aligncenter" title="wwwprcgovph" src="http://www.selaplana.com/wp-content/uploads/2009/08/wwwprcgovph.JPG" alt="wwwprcgovph" width="439" height="348" /></a></p>]]></description>
			<content:encoded><![CDATA[<p>This afternoon, I noticed that Google considered the official website of the Professional Regulation Commission or PRC as a harmful website.</p>
<p>Here&#8217;s the screenshot of the SERP when searching for the &#8220;<a href="http://www.selaplana.com/">www.prc.gov.ph</a>&#8220;.</p>
<p style="text-align: center;"><a rel="attachment wp-att-6454" href="http://www.selaplana.com/2009/08/02/www-prc-gov-ph-harmful-website/wwwprcgovph/"><img class="size-full wp-image-6454 aligncenter" title="wwwprcgovph" src="http://www.selaplana.com/wp-content/uploads/2009/08/wwwprcgovph.JPG" alt="wwwprcgovph" width="439" height="348" /></a></p>
<p>And right below the title of the website, Google placed this comment &#8220;<em>Ang site na ito ay maaring makasama sa computer mo (my translation: This site may cause harm to your computer)</em>&#8220;.</p>
<p><strong>But what really are the causes why Google considered the PRC&#8217;s official website as harmful?</strong></p>
<p>The flag, &#8220;This site may harm your computer&#8221;, is Google&#8217;s way of protecting its users from the harm brought by websites that install malicious codes in the background or the websites that are promoting harmful websites.</p>
<p>In other words, if your website is flagged in the search engine result page, then it only means either of the two: (1) contains or simply spreads malicious codes; (2) linking to a harmful websites.</p>
<p>But in the case of the <strong>PRC&#8217;s official website</strong>, the flag by Google to the website could mean that Google found malicious codes from the website itself especially that the said website offers documents and forms in ZIP and PDF files.</p>
<p>What I means is that maybe some of the files hosted by the site are infected by malicious programs like virus, trojan, worm, etc.</p>
<p>In the <strong>Google Safe Browsing &#8211; Diagnostic page for www.prc.gov.ph</strong>, we&#8217;ll find this information:</p>
<blockquote><p><strong>What is the current listing status for prc.gov.ph?</strong></p>
<p>Site is listed as suspicious &#8211; visiting this web site may harm your computer.</p>
<p>Part of this site was listed for suspicious activity 1 time(s) over the past 90 days.</p>
<p><strong>What happened when Google visited this site?</strong></p>
<p>Of the 89 pages we tested on the site over the past 90 days, 2 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2009-08-01, and the last time suspicious content was found on this site was on 2009-07-14.</p>
<p>Malicious software includes 4 scripting exploit(s), 4 trojan(s), 4 exploit(s).</p>
<p>Malicious software is hosted on 2 domain(s), including gamemaill.com/, f1y.in/.</p>
<p>1 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including f1y.in/.</p>
<p>This site was hosted on 1 network(s) including AS9658 (ETPI).</p></blockquote>
<p>But sometimes the flag is false. Maybe Google identified something from the site as malicious code but in reality it&#8217;s not.</p>
<p>However, we still need to check our site just to make sure that it&#8217;s really safe because while your site is still flagged by Google, then you might <strong>lose a lot of traffic</strong> that should be driven into your site.</p>
<p>Remember that when clickingÂ  a flagged website from the SERP, instead of redirecting you to the website, Google will direct you first to a warning page that is shown like the screenshot below:</p>
<p style="text-align: center;"><a rel="attachment wp-att-6458" href="http://www.selaplana.com/2009/08/02/www-prc-gov-ph-harmful-website/googlewarning/"><img class="size-full wp-image-6458 aligncenter" title="googlewarning" src="http://www.selaplana.com/wp-content/uploads/2009/08/googlewarning.JPG" alt="googlewarning" width="437" height="329" /></a></p>
<p>Those who understand what are written on that warning page will of course decide to return to the SERP instead of visiting your site.</p>
<p>And while you&#8217;re losing visitors, you&#8217;re also losing income.</p>
<p>In checking whether your site or blog is harmful or not, use a site-advisor tool. Here&#8217;s few of the site-advisors I knew:</p>
<ol>
<li><a rel="nofollow" href="http://www.siteadvisor.com/">McAfee Site Advisor</a>.</li>
<li><a rel="nofollow" href="http://safeweb.norton.com/">Norton Site Advisor</a>.</li>
</ol>
<p>But the best thing to do is to use the <a href="http://www.google.com/webmasters/tools/">Google Webmasters&#8217; Tools</a>. It&#8217;s Google that flags websites in the search results, so it&#8217;s Google that can help us identify the file or the webpage in our site where it found something wrong.</p>
<p>Once you checked and corrected the problem, file a reconsideration request at <a href="http://www.google.com/webmasters/">Google Webmaster Central</a> and explain in your letter what have you done  to correct the problem and why Google should remove the flag on your site.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.selaplana.com/2009/08/02/www-prc-gov-ph-harmful-website/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Someone&#8217;s Making Money in Your Twitter Account</title>
		<link>http://www.selaplana.com/2009/07/13/someones-making-money-in-your-twitter-account/</link>
		<comments>http://www.selaplana.com/2009/07/13/someones-making-money-in-your-twitter-account/#comments</comments>
		<pubDate>Mon, 13 Jul 2009 14:32:43 +0000</pubDate>
		<dc:creator>SELaplana</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Computer Worm]]></category>
		<category><![CDATA[Koobface Worm]]></category>
		<category><![CDATA[Pandalabs]]></category>
		<category><![CDATA[Tweets]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://www.selaplana.com/?p=6374</guid>
		<description><![CDATA[Now, people with similar brain-content with those who hacked my email account are currently making money online by hijacking someone's twitter account using a worm called "<strong>Koobface</strong>".]]></description>
			<content:encoded><![CDATA[<p>Last month, I published a post telling you that my email account (selaplanadotcom[at]yahoo[dot]com) <a href="http://www.selaplana.com/2009/06/07/nimoyf-com-hacked-my-yahoo-email-account/">was hacked by someone</a> and used it to spam, sending all the people in my address book and then auto-responded to those who sent me email with this message:</p>
<blockquote><p>how are you<br />
I would like to introduce you a very good trade company . I bought the electronic products from them recently.<br />
All the products are original and high quality .and they have good after-sales-service.<br />
Please take some time to have a look: www.nimoyf.com .May be you can get more profit.<br />
E-mail:nimoyf@vip.188.com<br />
Sincerely<br />
Sustines</p></blockquote>
<p>Well, that&#8217;s how they <a href="http://www.selaplana.com/">make money online</a>.</p>
<p>Now, people with similar brain-content with those who hacked my email account are currently making money online by hijacking someone&#8217;s twitter account using a worm called &#8220;<strong>Koobface</strong>&#8220;.</p>
<p>Previously, Koobface worm targets facebook and MySpace users only. Now, the program of this worm has been modified so that it can manipulate twitter accounts.</p>
<p>Actually, the Koobface worm does not infect your twitter account but your PC only. However, once you are using a Koobface-infected PC in logging in to your Twitter account, then that will be the time that Koobface worm takes over your Twitter account and automatically publish tweets with links to malicious websites that have Koobface codec. If someone follow the links in the Koobface tweets in your Twitter, the Koobface codec will beÂ  automatically installed to his PC, thus the infection spreads.</p>
<p>Koobface worm is actually utilizing the shortened URLs used in tweets. So, you better be careful in following links from tweets.</p>
<p>For more info regarding the Koobface worm, kindly visit the <a rel="nofollow" href="http://selaplana.com/links/index.php?websitetitle=Panda Labs Blog&amp;url=http://pandalabs.pandasecurity.com/archive/Koobface.DU-returns-to-Twitter.aspx">blog of Pandalabs</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.selaplana.com/2009/07/13/someones-making-money-in-your-twitter-account/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Code Name Morro, Microsoft&#8217;s Free Anti-Virus</title>
		<link>http://www.selaplana.com/2009/06/11/code-name-morro-microsofts-free-anti-virus/</link>
		<comments>http://www.selaplana.com/2009/06/11/code-name-morro-microsofts-free-anti-virus/#comments</comments>
		<pubDate>Thu, 11 Jun 2009 14:55:23 +0000</pubDate>
		<dc:creator>SELaplana</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[McAffee]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Morro]]></category>
		<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://www.selaplana.com/?p=6323</guid>
		<description><![CDATA[After launching the latest version of the Microsoft's own search engine called <a href="http://www.selaplana.com/updates/2009/05/bing/">Bing</a>, it was reported that Microsoft is now testing with its own employees the early version of the free anti-virus software that will soon be released as trial version or beta product. The product is called with its codename as "Morro".
]]></description>
			<content:encoded><![CDATA[<p>After launching the latest version of the Microsoft&#8217;s own search engine called <a href="http://www.selaplana.com/updates/2009/05/bing/">Bing</a>, it was reported that Microsoft is now testing with its own employees the early version of the free anti-virus software that will soon be released as trial version or beta product. The product is called with its codename as &#8220;Morro&#8221;.</p>
<p>Morro will directly compete with the anti-virus products of McAffee, Symantec, etc, but it will be a free to use product not like that of the McAffee or of the Symantect wherein you need to pay the yearly subscription.</p>
<p><strong>But, do we need the Morro when in fact there are already lots of free antivirus available online?</strong></p>
<p>According to the Microsoft, <em>Morro will offer basic features in fighting against the wide range of viruses</em> which is common to other paid antivirus products.</p>
<p>There are other free anti-virus products like that of the AVG, but there are limitations on it set by the company so that users of the free anti-virus will be forced to pay certain amount in exchange of getting more features on the anti-virus software.</p>
<p>With that, I can say that maybe you really need the Microsoft&#8217;s Morro Anti-Virus and that this anti-virus will be advantageous to you.</p>
<p>However, in my case, I think, I don&#8217;t need it anymore.</p>
<p>I am currently using the combination of <strong>DeepFreeze plus AVG Free Anti-Virus</strong>. With this combination, my computer is already safe to viruses, spywares, trojans, malicious bots, adwares, and any other malicious softwares.</p>
<p>The DeepFreeze software is responsible in freezing the harddrive so that those malicious softwares that successfully avoided the AVG (free) anti-virus will still be kicked off whenever the computer rebooted. While AVG free anti-virus software is responsible in detecting malicious softwares and then automatically quarantine them.</p>
<p>And if I want to visit harmful websites, I use another combination for the security of my computer. This time, this is the combination of the <strong>DeepFreeze</strong>, <strong>AVG Free Anti-Virus</strong> and <strong>Mozilla Firefox</strong>. With this setup, I am not worrying that my computer will be infected by adwares, spywares, or trojan that automatically install into the computer while visiting those harmful websites.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.selaplana.com/2009/06/11/code-name-morro-microsofts-free-anti-virus/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>nimoyf.com Hacked My Yahoo Email Account</title>
		<link>http://www.selaplana.com/2009/06/07/nimoyf-com-hacked-my-yahoo-email-account/</link>
		<comments>http://www.selaplana.com/2009/06/07/nimoyf-com-hacked-my-yahoo-email-account/#comments</comments>
		<pubDate>Sun, 07 Jun 2009 13:25:39 +0000</pubDate>
		<dc:creator>SELaplana</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[Hacker]]></category>
		<category><![CDATA[Yahoo Mail]]></category>

		<guid isPermaLink="false">http://www.selaplana.com/?p=6297</guid>
		<description><![CDATA[Yesterday, I was about to reply an email from a feed-email subscriber of this blog who was asking my advice regarding his blog. But I noticed that a message that I did not write was appended at the end part of email which goes:]]></description>
			<content:encoded><![CDATA[<p>Yesterday, I was about to reply an email from a feed-email subscriber of this blog who was asking my advice regarding his blog. But I noticed that a message that I did not write has been appended at the end part of the my letter which goes:</p>
<blockquote><p>how are you<br />
I would like to introduce you a very good trade company . I bought the electronic products from them recently.<br />
All the products are original and high quality .and they have good after-sales-service.<br />
Please take some time to have a look: www.nimoyf.com .May be you can get more profit.<br />
E-mail:nimoyf@vip.188.com<br />
Sincerely<br />
Sustines</p></blockquote>
<p>This message was actually set as the default message in my email signature. But the question is: <strong>who changed my email signature?</strong></p>
<p>I did check the WhoIs information of the domain, &#8220;NIMOYF.COM&#8221; and I found out that the registrant of this domain is coming from Beijing, China.</p>
<blockquote><p>Registrant Contact:<br />
wangxian<br />
xiang wang<br />
010-58344173 fax: 010-58987487<br />
beijin<br />
beijin beijin 160000<br />
cn</p>
<p>Administrative Contact:<br />
xiang wang<br />
010-58344173 fax: 010-58987487<br />
beijin<br />
beijin beijin 160000<br />
cn</p>
<p>Technical Contact:<br />
xiang wang<br />
010-58344173 fax: 010-58987487<br />
beijin<br />
beijin beijin 160000<br />
cn</p>
<p>Billing Contact:<br />
xiang wang<br />
010-58344173 fax: 010-58987487<br />
beijin<br />
beijin beijin 160000<br />
cn</p>
<p>DNS:<br />
ns1.4everdns.com<br />
ns2.4everdns.com</p>
<p>Created: 2009-03-23<br />
Expires: 2010-03-23</p></blockquote>
<p>Because of this information, I am suspecting that a hacker hacked my Yahoo Mail account. <strong>But how?</strong></p>
<p>I think, the hacker who hacked my Yahoo Mail account used a special program in hacking email accounts. This hacker is not just guessing on what might be the password that I was using for that Yahoo Mail account because I am using special characters as part of the password.</p>
<p>Now, if the hacker really used the software in hacking email accounts, then I might not be the only victim here. So, I googled the sentence below:</p>
<blockquote><p>I would like to introduce you a very good trade company . I bought the electronic products from them recently.</p></blockquote>
<p>It&#8217;s enclosed with the quotation mark so that Google will search webpages that contains exactly the texts above. And the result showed that there are other people in the internet who talked about it already. And they experienced what I experienced.</p>
<p>So, maybe the hacker used malicious programs in getting the username and password of the victim&#8217;s email accounts like Trojan, Keyword Logger, etc.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.selaplana.com/2009/06/07/nimoyf-com-hacked-my-yahoo-email-account/feed/</wfw:commentRss>
		<slash:comments>31</slash:comments>
		</item>
		<item>
		<title>KameraWorld.Com.PH</title>
		<link>http://www.selaplana.com/2009/03/30/kamera-world-com-ph/</link>
		<comments>http://www.selaplana.com/2009/03/30/kamera-world-com-ph/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 07:14:45 +0000</pubDate>
		<dc:creator>SELaplana</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Kamera World]]></category>
		<category><![CDATA[Site Warning]]></category>

		<guid isPermaLink="false">http://www.selaplana.com/?p=6111</guid>
		<description><![CDATA[Kamera World Philippine's website is considered by Google as unsafe to browse or visit by telling the Google Search Engine's users, "Babala- ang pagdalaw sa web site na ito ay maaaring makasama sa iyong computer!"]]></description>
			<content:encoded><![CDATA[<p>I was about to visit the Kamera World Philippines which can be accessed at kameraworld.com.ph. But before I finally landed to the website, Google showed this message to me:</p>
<blockquote><p>Babala- ang pagdalaw sa web site na ito ay maaaring makasama sa iyong computer!<br />
Mga mungkahi:</p>
<p>* Return to the previous page and pick another result.<br />
* Try another search to find what you&#8217;re looking for.</p>
<p>Or you can continue to kameraworld.com.ph at your own risk. For detailed information about the problems we found, visit Google&#8217;s Safe Browsing diagnostic page for this site.</p>
<p>For more information about how to protect yourself from harmful software online, you can visit StopBadware.org.</p></blockquote>
<p>Actually, Google showed this message to me because when I am going to visit the site, I searched it first through the Google Search Engine.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.selaplana.com/2009/03/30/kamera-world-com-ph/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trojan-Downloader</title>
		<link>http://www.selaplana.com/2008/06/15/trojan-downloader/</link>
		<comments>http://www.selaplana.com/2008/06/15/trojan-downloader/#comments</comments>
		<pubDate>Sun, 15 Jun 2008 03:02:28 +0000</pubDate>
		<dc:creator>SELaplana</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[PC Security Shield]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://www.selaplana.com/?p=4727</guid>
		<description><![CDATA[Trojan Downloader is another variant of Trojan that downloads another program via the Internet and launches it on the victim machine without his knowledge or consent. Trojan Downloader is an encrypted Java Script within an HTML document. Trojan Downloader is 14147 bytes in size.
The Trojan Downloader activates when the infected page is opened using the [...]]]></description>
			<content:encoded><![CDATA[<p>Trojan Downloader is another variant of Trojan that downloads another program via the Internet and launches it on the victim machine without his knowledge or consent. Trojan Downloader is an encrypted Java Script within an HTML document. Trojan Downloader is 14147 bytes in size.</p>
<p>The Trojan Downloader activates when the infected page is opened using the web browser. You will know that the page is infected if the page shows the following message:</p>
<blockquote><p>Not Found<br />
The requested URL / was not found on this server.</p></blockquote>
<p>The Trojan then decrypts its body and launches the malicious script for execution. The Trojan then uses the vulnerabilities listed below:</p>
<ol>
<li> a buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 ActiveX control in DXTLIPI.DLL when processing &#8220;SourceUrl()&#8221; (CVE-2007-4336)</li>
<li>in the Windows Media Player plug-in, when processing an excessively long &#8220;src&#8221; parameter in the &#8220;embed&#8221; tag (MS06-006). The vulnerability is present when the plug-in is launched in browsers which are not Internet Explorer.</li>
<li>in the QuickTime.QuickTime&#8221; ActiveX object (CVE-2004-0431);</li>
</ol>
<p>This is to download a file called &#8220;ldr.exe&#8221; from the URL shown below:</p>
<blockquote><p>http://java62.com/load.php****</p></blockquote>
<p>This file is 48640 bytes in size. It will be detected by Kaspersky Anti-Virus as Backdoor.Win32.Agent.ich. This file will be saved to the Windows system directory under the following name:</p>
<blockquote><p>%System%\~.exe</p></blockquote>
<p>The file is then launched for execution. The Trojan then uses the &#8220;Msxml2.XMLHTTP&#8221; ActiveX object, and the objects which have the following unique identifiers in the system registry:</p>
<blockquote><p>{BD96C556-65A3-11D0-983A-00C04FC29E30}<br />
{BD96C556-65A3-11D0-983A-00C04FC29E36}<br />
{AB9BCEDD-EC7E-47E1-9322-D4A210617116}<br />
{0006F033-0000-0000-C000-000000000046}<br />
{0006F03A-0000-0000-C000-000000000046}<br />
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}<br />
{6414512B-B978-451D-A0D8-FCFDF33E833C}<br />
{7F5B7F63-F06F-4331-8A26-339E03C0AE3D}<br />
{06723E09-F4C2-43C8-8358-09FCD1DB0766}<br />
{639F725F-1B2D-4831-A9FD-874847682010}<br />
{BA018599-1DB3-44F9-83B4-461454C84BF8}<br />
{D0C07D56-7C69-43F1-B4A0-25F5A11FAB19}<br />
{E8CCCDDF-CA28-496B-B050-6C07C962476B}</p></blockquote>
<p>This is to download a file called &#8220;ldr.exe&#8221; from the link shown below:</p>
<blockquote><p>http://java62.com/load.php?MSIE</p></blockquote>
<p>It uses the &#8220;ADODB.Stream&#8221; ActiveX object to save this file under the following name:</p>
<blockquote><p>c:\sys.exe</p>
<p>rnd – four random Latin letters Example:<br />
syskmtz.exe<br />
syskqoq.exe</p></blockquote>
<p>The downloaded file will then be launched for execution.</p>
<p>To protect your computer from Trojan-Downloader, you need to install <a href="../links/shielddeluxe.php">Shield Deluxe</a> and <a href="../links/securityshield.php">Security Shield</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.selaplana.com/2008/06/15/trojan-downloader/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus.Win32.Gpcode</title>
		<link>http://www.selaplana.com/2008/06/15/viruswin32gpcode/</link>
		<comments>http://www.selaplana.com/2008/06/15/viruswin32gpcode/#comments</comments>
		<pubDate>Sun, 15 Jun 2008 02:23:54 +0000</pubDate>
		<dc:creator>SELaplana</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Blackmailer]]></category>
		<category><![CDATA[Gpcode]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false">http://www.selaplana.com/?p=4725</guid>
		<description><![CDATA[The new version of the &#8220;malicious blackmailer&#8217; Gpcode &#8211; Virus.Win32.Gpcode.ak is now on the wild. This new version of Gpcode encrypts files with extensions DOC, TXT, PDF, XLS, JPG, PNG, CPP, H etc. on hard drives using an RSA algorithm with a 1024-bit key. After encrypting files, the virus leaves a text file in the [...]]]></description>
			<content:encoded><![CDATA[<p>The new version of the &#8220;malicious blackmailer&#8217; Gpcode &#8211; Virus.Win32.Gpcode.ak is now on the wild. This new version of Gpcode encrypts files with extensions DOC, TXT, PDF, XLS, JPG, PNG, CPP, H etc. on hard drives using an RSA algorithm with a 1024-bit key. After encrypting files, the virus leaves a text file in the folder next to the encrypted files with following message:</p>
<blockquote><p>Your files are encrypted with RSA-1024 algorithm.<br />
To recovery your files you need to buy our decryptor.<br />
To buy decrypting tool contact us at: ********@yahoo.com</p></blockquote>
<p>Experts recommend that all Internet users enable maximum protection from malicious code and network attacks on their computers and refrain from executing suspicious programs received from untrustworthy sources.</p>
<p>Detection of Virus.Win32.Gpcode.ak was added to Shield Deluxe and Security Shield signature databases yesterday, on June 4th, at 15:39 GMT. Please make sure to update if you haven’t already.</p>
<p>If you haven&#8217;t installed yet <a href="http://www.selaplana.com/links/shielddeluxe.php">Shield Deluxe</a> and <a href="http://www.selaplana.com/links/securityshield.php">Security Shield</a>, then you need to download it now.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.selaplana.com/2008/06/15/viruswin32gpcode/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spammer Used My Email Address</title>
		<link>http://www.selaplana.com/2008/02/08/spammer-used-my-email-address/</link>
		<comments>http://www.selaplana.com/2008/02/08/spammer-used-my-email-address/#comments</comments>
		<pubDate>Fri, 08 Feb 2008 05:05:15 +0000</pubDate>
		<dc:creator>SELaplana</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Email address]]></category>
		<category><![CDATA[Online Store]]></category>
		<category><![CDATA[Scammers]]></category>
		<category><![CDATA[Spam Email]]></category>
		<category><![CDATA[Spammers]]></category>

		<guid isPermaLink="false">http://www.selaplana.com/2008/02/08/spammer-used-my-email-address/</guid>
		<description><![CDATA[Yesterday, I received an email coming from my email address. Yes! I didn&#8217;t send email to my own but I received an email coming from me. Here&#8217;s the content of this email:
Best Way To Shop Online (note: these keywords is linked to an online store)
These are our lowest prices of the year — but they [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday, I received an email coming from my email address. Yes! I didn&#8217;t send email to my own but I received an email coming from me. Here&#8217;s the content of this email:</p>
<blockquote><p>Best Way To Shop Online <strong><em>(note: these keywords is linked to an online store)</em></strong></p>
<p>These are our lowest prices of the year — but they won&#8217;t last long. So take advantage of these incredible savings now and stock up on all your favorite products.</p>
<p>SAVE BIG on holiday gifts too with gift subscriptions for everyone on your list — family, friends and co-workers.</p>
<p>At just $5 these are terrific as main gifts or stocking stuffers. Click here to start shopping now and don&#8217;t forget to pass this offer along and let everyone know what a great deal you&#8217;ve found. Happy saving!</p>
<p>Limited-time offer&#8230;Act now!</p></blockquote>
<p>Well, it&#8217;s a spam-email. Spammers use my email address as the sender of this spam-email. But why? Am I really popular for them to use my email to fool the people that I am endorsing their poor company?</p>
<p>If you received similar email using my email address, FYI, I am not the real sender of it. I&#8217;m sorry but spammers love my email address.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.selaplana.com/2008/02/08/spammer-used-my-email-address/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Yahoo! eMail Scam, Beware!</title>
		<link>http://www.selaplana.com/2008/01/21/yahoo-email-scam-beware/</link>
		<comments>http://www.selaplana.com/2008/01/21/yahoo-email-scam-beware/#comments</comments>
		<pubDate>Mon, 21 Jan 2008 05:05:46 +0000</pubDate>
		<dc:creator>SELaplana</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Yahoo]]></category>
		<category><![CDATA[Email Scam]]></category>
		<category><![CDATA[Hacker]]></category>
		<category><![CDATA[Scammer]]></category>

		<guid isPermaLink="false">http://www.selaplana.com/2008/01/21/yahoo-email-scam-beware/</guid>
		<description><![CDATA[I receive an email from customerdata_service@yahoo.com asking me to verify my email account or else it will be terminated.
Dear Account User,
This Email is from Yahoo! Customer Care and we are sending it to every Yahoo! Email User Accounts Owner for safety. we are having congestions due to the anonymous registration of Yahoo! accounts so we [...]]]></description>
			<content:encoded><![CDATA[<p>I receive an email from customerdata_service@yahoo.com asking me to verify my email account or else it will be terminated.</p>
<blockquote><p>Dear Account User,</p>
<p>This Email is from Yahoo! Customer Care and we are sending it to every Yahoo! Email User Accounts Owner for safety. we are having congestions due to the anonymous registration of Yahoo! accounts so we are shutting down some Yahoo! accounts and your account was among those to be deleted.We are sending you this email to so that you can verify and let us know if you still want to use this account. If you are still interested please confirm your account by filling the space below. Your User name,Password,Date Of Birth (DOB) and your Country information would be needed to verify your account.</p>
<p>Due to the congestion in all Yahoo! users and removal of all unused Yahoo! Accounts, Yahoo! would be shutting down all unused Accounts, You will have to confirm your E-mail by filling out your Login Information below after clicking the reply button, or your account will be suspended within 24 hours for security reasons.</p>
<p>* User name: &#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;</p>
<p>* Password: &#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;..</p>
<p>* Date of Birth: &#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;.</p>
<p>* Country Or Territory: &#8230;&#8230;&#8230;&#8230;&#8230;.</p>
<p>After following the instructions in the sheet, your account will not be interrupted and will continue as normal. Thanks for your attention to this request. We apologize for any inconveniences.</p>
<p>Warning!!! Account owner that refuses to update his/her account after two weeks of receiving this warning will lose his or her account permanently.</p></blockquote>
<p>Of course it looks like legitimate email especially if the email user who receive this email will consider the email address where this email is coming from. If you&#8217;ll read the last part of it, it says, &#8220;<em>Warning!!! Account owner that refuses to update his/her account after two weeks of receiving this warning will lose his or her account permanently</em>&#8221; it seems that the email users will get nervous and will immediately reply it by sending their personal information.</p>
<p>Now, if you already had replied this, then you&#8217;ll definitely loss your precious email account.</p>
<p><strong>Why? </strong></p>
<p>It&#8217;s because, it is another email scam. Just look at the information they&#8217;re asking you: &#8220;username, password, date of birth and teritory.&#8221; If you freely give your username and password, then scammers can easily access your account and own them.</p>
<p><strong>Now what will happen next?</strong></p>
<p>First, scammers will scan the entire content of your email to find ways on how to utilize them. They can use this in black-mailing you&#8230; for extortion&#8230; to access your personal financial accounts&#8230; and a lot of things. Now, what if your email is the one used in your paypal account. Once they have your email account, then your paypal will be next.</p>
<p>For your information, my Pasugo-Online.NET website was hacked in 2004  because the <a href="http://www.selaplana.com/2007/01/15/the-hacker-is-who/">hackers successfully hacked</a> my email account (selaplana@yahoo.com) which is connected to that website. And not only that, I also lost my personal website which I started building since 1999 (geocities.com/selaplana).</p>
<p>My other posts related to this:</p>
<ul>
<li><a href="http://www.selaplana.com/2007/01/22/won-euro-millones-lottery-international-email-address-draw/">Won Euro Millones Lottery International Email Address Draw</a></li>
<li><a href="http://www.selaplana.com/2007/01/23/i-won-from-lottery-again/">I Won From Lottery Again?</a></li>
<li><a href="http://www.selaplana.com/2006/10/30/links-in-emails-be-careful/">Links in Emails? Be Careful!</a></li>
<li><a href="http://www.selaplana.com/2007/03/19/scams-through-the-email/">Scams Through the Email</a></li>
<li><a href="http://www.selaplana.com/2007/04/20/sms-scam-again/">SMS Scam Again</a></li>
<li><a href="http://www.selaplana.com/2007/06/02/ms-enriquez-impostor-is-making-money-online/">Ms. Enriquez Impostor is Making Money Online</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.selaplana.com/2008/01/21/yahoo-email-scam-beware/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
