<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1449811636556335442</id><updated>2011-11-27T18:47:56.705-05:00</updated><category term='annoyances'/><category term='spooks'/><category term='MS Vista'/><category term='viruses'/><category term='encryption'/><category term='Uber-Malware'/><category term='scams'/><category term='reviews'/><category term='warez'/><category term='spyware'/><category term='mac os x'/><category term='hacking'/><category term='privacy'/><category term='conspiracy theories'/><category term='rootkits'/><title type='text'>Hacked Nation</title><subtitle type='html'>Dystopian Ruminations on the State of Computer Security.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>21</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-5388602564833215490</id><published>2008-09-26T21:43:00.002-04:00</published><updated>2008-09-26T22:01:45.271-04:00</updated><title type='text'>Closure!</title><content type='html'>More than a year after the fact, I found the answer to the hacking of my PC: the article &lt;a href="www.eecs.umich.edu/virtual/papers/king06.pdf"&gt;SubVirt: Implementing malware with virtual machines&lt;/a&gt;.  Reading this article, I instantly recognized the symptoms in the proof-of-concept described in it as identical to what I had experienced.  A virtual machine monitor (VMM), running on a system such as VMware or Virtual PC, had supplanted my existing operating system, making it the guest (virtual) operating system running virtually in a directory of my hard drive.  This was done by changing the boot routine at startup.  After an initial reboot upon infection, the VMM is run as the core operating system, with the virtual operating system loading directly afterwards.  A barely noticeable lag results upon bootup.  Small differences will be noticed by the observant user, however.  When a user attempts to shut down their infected system, the virtual machine instead puts the computer into a hibernation mode, and makes it appear as if the computer has shut down.  (It is only upon an actual reboot that a user can detect the virtual machine malware, reinstall the operating system, etc.)  Since the machine is running a virtual operating system, any antivirus or antispyware utilities can be made to look like they are working, when they are in fact doing nothing.  I urge anyone who has experienced any problems such as the ones I've described in this blog to check out the SubVirt article.  It describes in detail how to circumvent and prevent these attacks.  I'll say again for the record that for the last year and a half, running a MacBook, I've been rid of these problems.  Windows computers seem to be extremely vulnerable to this difficult-to-diagnose and difficult-to-eradicate attack.  Good luck.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-5388602564833215490?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/5388602564833215490/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=5388602564833215490' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/5388602564833215490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/5388602564833215490'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2008/09/closure.html' title='Closure!'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-2681399436848352332</id><published>2008-09-23T13:27:00.006-04:00</published><updated>2008-09-24T01:31:31.807-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reviews'/><category scheme='http://www.blogger.com/atom/ns#' term='mac os x'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><title type='text'>3 Essential Mac OS X Security Software Programs for PC Converts (Part 2: Little Snitch)</title><content type='html'>Mac OS X Leopard has a fairly decent built-in firewall, but it's an incoming firewall, protecting you from the dangers from the outside (and it's turned off by default which blows my mind).  It does not prevent trojans already installed on your computer from sending all your data to a zombie computer somewhere in the cloud.  You'll remember that Windows XP had the same problem, leading to the proliferation of excellent third-party products like my favorite, ZoneAlarm.  Microsoft claims that Vista now offers outbound firewall protection, but as I (and I am sure many users) can attest, it's virtually worthless.  Don't just take my word for it, read the article at &lt;a href="http://www.pcworld.com/businesscenter/article/128834/analysis_new_windows_vista_firewall_fails_on_outbound_security.html"&gt;PC World&lt;/a&gt;). In all fairness, I should say that OS X does have the capability to turn on an outbound firewall using &lt;span style="font-weight: bold;"&gt;ipfw&lt;/span&gt;, but that requires Unix coding, much too advanced for me, and most of you I'd guess.  So, what software can Mac users use to plug this security hole?  While there are many out there, and I've tried a bunch, my favorite by far is &lt;span style="font-weight: bold;"&gt;Little Snitch&lt;/span&gt;.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;In essence, Little Snitch complements the inbound firewall in the Mac OS X operating system.  That firewall prevents hackers from getting in.  Little Snitch, meanwhile, prevents applications to send data outside your computer without being authorized.  Certainly, there are many applications that will want to access the internet at any time for a variety of legitimate reasons.  Many applications perform automatic updates, for example, and many others "phone home" to its developer to verify that you don't have a pirated product.  But suppose, God forbid, you were infected with malware from a torrent site, for instance, or something else that occurred before you figured out you were required to turn on the OS X firewall (it's turned off by default -- come on Apple, I just don't get that).  Or even something more mundane: suppose your jealous significant other has installed keyloggers and other spyware on your system (of course, he'll surely burn in hell, but that won't help you right now).  Without an outbound firewall, malware could be sending just about your whole computer's contents to someone in Kazakhstan and you'd never know it.  Enter Little Snitch.&lt;/p&gt;&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_VwuHozUF70U/SNkssT_poSI/AAAAAAAAAss/hlR-8SxEJu0/s1600-h/littlesnitch.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_VwuHozUF70U/SNkssT_poSI/AAAAAAAAAss/hlR-8SxEJu0/s400/littlesnitch.jpg" alt="" id="BLOGGER_PHOTO_ID_5249275980470133026" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div&gt;The main screen of little snitch is the Configuration panel, shown above.  Little Snitch is rule-based, with several rules pre-made to keep you from screwing things up on your Mac.  Those rules are locked.  You can unlock or lock rules at any time.  The lock key just prevents accidental changes to important rules.  As a new program starts to access the internet, Little Snitch interrupts is, and a pop-up screen asked you if you want to allow or deny that access, and at what degree you want to allow or deny (specific ports, domains, types of connections, etc).  The configuration panel shows in red text software that has been deleted so you can delete those rules if you want.  Some programs will have multiple rules, leading you to perhaps give a higher level of clearance to that program (on my computer, for example, the constant jumping around of Skype to different domains every few seconds eventually forced me to set its rule at "Allow any connection".  I just hope that doesn't come back to bite me on my butt.  Other programs I use have twenty rules with as many domains or IP addresses.  In such cases, perhaps allowing that program access to port 80 would be sufficient.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The menu bar on the Mac OS X screen shows a Little Snitch icon that displays a popup of activity when an application tries to access the internet.  It can be somewhat disconcerting to the average Mac user, since may of the program names are operating system components that could mean anything and scare people who don't know better, and because the nagging popup is nearly constantly appearing.  You can, however, turn that feature off, which I have.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It's a program that can really be learned through trial and error.  Rules can be changed at any time or reset to the original initial rules to start over.  For the sake or privacy, and based on my knowledge and personal history with the real danger of malware and hackers, Little Snitch is worth every penny.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-2681399436848352332?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/2681399436848352332/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=2681399436848352332' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/2681399436848352332'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/2681399436848352332'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2008/09/3-essential-mac-os-x-security-software_23.html' title='3 Essential Mac OS X Security Software Programs for PC Converts (Part 2: Little Snitch)'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VwuHozUF70U/SNkssT_poSI/AAAAAAAAAss/hlR-8SxEJu0/s72-c/littlesnitch.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-5369232768842214907</id><published>2008-09-23T13:08:00.002-04:00</published><updated>2008-09-23T13:24:41.822-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MS Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='mac os x'/><category scheme='http://www.blogger.com/atom/ns#' term='viruses'/><title type='text'>VirusTotal Report:  Trojan.ByteVerify</title><content type='html'>VirusTotal's report on my uploaded virus was instantaneous and presented me with the following report on the virus that Symantec.com dubbed &lt;span style="font-weight: bold;"&gt;Trojan.ByteVerify&lt;/span&gt; (each antivirus vendor has slightly different names for the universe of viruses):&lt;br /&gt;&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan="4"&gt;File ms03011.jar-3847f8dc-50961bb6.zip received on 06.30.2008 14:04:16 (CET)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Antivirus&lt;/td&gt;&lt;td&gt;Version&lt;/td&gt;&lt;td&gt;Last Update&lt;/td&gt;&lt;td&gt;Result&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AhnLab-V3&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AntiVir&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;EXP/Java.Bytver.5.B&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Authentium&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Java/Trojan!8746&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Avast&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;JS:ClassLoader-7&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AVG&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Java/ByteVerify&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;BitDefender&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan.Exploit.Byteverify.V&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;CAT-QuickHeal&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;ClamAV&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Java.Openconnection&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;DrWeb&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;VBS.Siggen.1989&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;eSafe&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan-Downloader.Ja&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;eTrust-Vet&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Java/ByteVerify!exploit&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Ewido&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;F-Prot&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Java/Trojan!8746&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;F-Secure&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan-Downloader.Java.OpenConnection.ao&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Fortinet&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Java/ClassLoader.AU!tr&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;GData&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan-Downloader.Java.OpenConnection.ao&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Ikarus&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Kaspersky&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan-Downloader.Java.OpenConnection.ao&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Exploit-ByteVerify&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Exploit:Java/ByteVerify.C&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;NOD32v2&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Java/TrojanDownloader.OpenConnection&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Norman&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Panda&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Exploit/ByteVerify&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Prevx1&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Cloaked Malware&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Rising&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan.DL.Java.Jadoler.a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Sophos&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Troj/ByteVeri-X&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Sunbelt&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Symantec&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan.ByteVerify&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;TheHacker&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;TrendMicro&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;JAVA_BYTEVER.BJ&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VBA32&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan-Downloader.Java.Agent.a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VirusBuster&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Java.DL.OpenConn.C&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Webwasher-Gateway&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style="color: red;"&gt;Exploit.Java.Bytver.5.B&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;Symantec says the virus infects only computers using Microsoft's operation system (no surprise there), but my philosophy is that viruses are like cockroaches: kill them just because.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-5369232768842214907?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/5369232768842214907/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=5369232768842214907' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/5369232768842214907'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/5369232768842214907'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2008/09/virustotal-report-trojanbyteverify.html' title='VirusTotal Report:  Trojan.ByteVerify'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-7827873582485259191</id><published>2008-09-23T10:53:00.007-04:00</published><updated>2008-09-23T13:15:12.451-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reviews'/><category scheme='http://www.blogger.com/atom/ns#' term='mac os x'/><category scheme='http://www.blogger.com/atom/ns#' term='viruses'/><title type='text'>3 Essential Mac OS X Security Software Programs for PC Converts (Part 1: Clam Xav 1.1)</title><content type='html'>Coming from a PC background, I'm a bit paranoid when it comes to computer security.  It was a bit disconcerting for me to find not only the dearth of security products for Macs, and the lack of  marquee names (McAfee VirusScan and Webroot's SpySweeper, for instance) that even produce security products for Macs, but also the prevailing attitude among longtime Mac users that security products, specifically antivirus programs, are basically unnecessary in a Mac environment.  (I personally believe this is a false sense of security, although there is some truth in that assertion, but that will be the subject of another article.&lt;br /&gt;&lt;br /&gt;When I first purchased my MacBook, as a PC convert, I asked the salesman what I've since learned to be the most common question PC users ask when switching over to Macs:  What security products should I use?  The only product name given to me by the helpful Mac store sales rep was &lt;span style="font-weight: bold;"&gt;MacScan&lt;/span&gt;, an anti-spyware program (currently $29.99 for a single license from &lt;a href="http://macscan.securemac.com/buy/"&gt;http://macscan.securemac.com/buy/&lt;/a&gt;). No antivirus program was recommended at all, and my initial research indicated that, at the time, the commercial programs for Macs (specifically Norton) had a bad ratings and were used by very few people.&lt;br /&gt;&lt;br /&gt;Welcome to the Mac Paradigm!  I was also a bit shocked that my favorite financial software, Quicken, was essentially useless (at the time at least) on the Mac platform.  Reviews were dismall.  In the Mac Universe, most of the quality software in any given area are produced by names you've never heard of.  Finding what's worth the money is a little bit of a challenge.  Of course, these programs for the Mac by smaller developers also tend to cost less, so there's an upside to this phenomenon.  But I digress.&lt;br /&gt;&lt;br /&gt;After spending a while with my Mac, I settled on the following three security programs that I find indispensible, especially if you're a worrywart (as most of us who had PCs tended to be):  the afforementioned &lt;span style="font-weight: bold;"&gt;MacScan&lt;/span&gt;; a free antivirus application called &lt;span style="font-weight: bold;"&gt;ClamXav&lt;/span&gt; (you'll forgive the naming of this little gem. That's what you get when your marketing budget is $0), and &lt;span style="font-weight: bold;"&gt;Little Snitch&lt;/span&gt; ($29.95 for one license), an outbound firewall program whose closest analogous PC program is probably ZoneAlarm (also free for the PC).  This posting focuses on ClamXav.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ClamXav 1.1 Review&lt;/span&gt; (Mac OS X)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_VwuHozUF70U/SNkhPYEZBSI/AAAAAAAAAsc/glrpuYtSqA8/s1600-h/clamxav_4_.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_VwuHozUF70U/SNkhPYEZBSI/AAAAAAAAAsc/glrpuYtSqA8/s320/clamxav_4_.jpg" alt="" id="BLOGGER_PHOTO_ID_5249263388719645986" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The user interface of ClamXav is very utilitarian, and the initial warning when loading the program each time is a bit jarring.  If I can paraphrase, it basically says "Back up all your data before using me. You got this for free, so don't expect tech support, or any kind of restitution if things go wrong").  The program preferences deserve tweaking in order to get the program to actually do anything.  The default settings at the very least will not harm your system.&lt;br /&gt;&lt;br /&gt;ClamXav's icon displays in the OS X menu bar, so u can easily access the program to perform occassional real time searches, or see the progress bar scanning files that have been added to or changed in your watch folders.  This is pretty cool and definitely helpful.&lt;br /&gt;&lt;br /&gt;ClamXav has some limitations.  Chief among them, and mentioned in several popular websites, is the speed at which scans are performed compared to commercial programs in this field.  But its virus definitions are updated daily, and the reports I've read say that its ability to find viruses rivals or betters those you'd spend $60 on [citation needed].  Unlike antivirus solutions in the PC universe that I was used to, ClamXav does not have real-time scanning capabilities, except for the folders you select in what the program terms "Folder Sentry".  I have my Downloads folder set to be scanned as items are put there, and that's about it.  There is an option to delete or quarantine viruses upon detection, but that option is turned off by default, and is not recommended if you plan to scan e-mail (also turned off by default).  Indeed, a quick google search of ClamXav technical issues will lead to some quite disturbing issues people have had with the program deleting their entire inbox.  So conservative settings of the system preferences has the end result that emails are not scanned upon arrival for infected messages.   I have mine set to Not Scan Email, and to Quarantine (versus Delete) any found viruses.  That is what I recommend, especially because false positives do happen.&lt;br /&gt;&lt;br /&gt;Once a virus is found and moved to the quarantine folder, what does that mean exactly?  Generally speaking, any or most found viruses will only be able to infect PC Users (or so I've been told by complacent Mac users), but does that mean I can just delete the file with impunity?  Or, for that matter, leave them on my computer with impunity?  I am still trying to figure that out.  For my own edification, I'm going to submit the virus I recently found (the first in a year), a little ditty called  "ms03011.jar-3847f8dc-50961bb6.zip" to a site I just discovered called &lt;a href="http://www.virustotal.com/"&gt;Virus Total&lt;/a&gt; for analysis.  Results of the analysis will be forthcoming.&lt;br /&gt;&lt;br /&gt;You'll want to perform full system scans regularly (I scan the directory "/Users/[myusername]".) That's how I found the potentially harmful file above.  Somehow it appeared in the Java system files without my knowledge.  (Maybe it was that pirated version of Sim City 4 I downloaded.  I guess I'll never learn my lesson.)  Full scans do take quite a long time, but affect the performance of my MacBook only modestly.&lt;br /&gt;&lt;br /&gt;For now I see no reason to spend a lot of money on commercial antivirus programs for my Mac when ClamXav does just about everything I need, for the right price.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-7827873582485259191?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/7827873582485259191/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=7827873582485259191' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/7827873582485259191'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/7827873582485259191'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2008/09/3-essential-mac-os-x-security-software.html' title='3 Essential Mac OS X Security Software Programs for PC Converts (Part 1: Clam Xav 1.1)'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VwuHozUF70U/SNkhPYEZBSI/AAAAAAAAAsc/glrpuYtSqA8/s72-c/clamxav_4_.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-3297810437969866212</id><published>2007-11-04T14:04:00.000-05:00</published><updated>2007-11-04T14:31:44.334-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mac os x'/><category scheme='http://www.blogger.com/atom/ns#' term='viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='annoyances'/><title type='text'>Kernel Panic and Zip Bomb</title><content type='html'>My MacBook experienced what I think was called a Kernel Panic (see below screen capture) two days ago.  I was unable to boot into the Mac OS X operating system, and had to perform a system restore from my OS X disc. &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_VwuHozUF70U/Ry4ZZ3jLHqI/AAAAAAAAAdE/3giZj-NJEeU/s1600-h/kernel_panic.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_VwuHozUF70U/Ry4ZZ3jLHqI/AAAAAAAAAdE/3giZj-NJEeU/s320/kernel_panic.jpg" alt="" id="BLOGGER_PHOTO_ID_5129064957820477090" border="0" /&gt;&lt;/a&gt; Subsequently, I ran a virus scan using Sophos, which, according to the log, found a possible Zip Bomb (see below abridged scan log). This was recorded as an error but not a virus.  I've never even heard of a Zip Bomb before, but Wikipedia defines it in &lt;a href="http://en.wikipedia.org/wiki/Zip_bomb"&gt;this entry&lt;/a&gt;. Coincidence or unrelated? As my college Probability professor taught me, which I'll paraphrase, "correlation does not mean causation".  I can find very little info online on bootroot.loader -- is this a zip bomb or a legitimate linux/OS X function?&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:100%;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-weight: bold;"&gt;Error:&lt;/span&gt;  File not scanned (appears to be a ‘zip bomb’)&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;Joss Whedon:System:Library:PrivateFrameworks:MediaKit.framework: Versions:A:Resources:MKDrivers.bundle:Contents:Resources:bootroot.loader&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-weight: bold;"&gt;Info:&lt;/span&gt;  Immediate job completed at 1:39:36 PM on Saturday, November 3, 2007&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;512774 items scanned, 0 viruses detected, 5 errors&lt;/span&gt;&lt;/blockquote&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-3297810437969866212?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/3297810437969866212/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=3297810437969866212' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/3297810437969866212'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/3297810437969866212'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/11/kernel-panic-and-zip-bomb.html' title='Kernel Panic and Zip Bomb'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VwuHozUF70U/Ry4ZZ3jLHqI/AAAAAAAAAdE/3giZj-NJEeU/s72-c/kernel_panic.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-5277962932038119700</id><published>2007-10-21T02:53:00.000-04:00</published><updated>2007-10-21T03:04:30.876-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>SecurityFocus's "Attacking the Attackers"</title><content type='html'>There are a couple of very good, very hard to understand, articles on &lt;span style="font-weight: bold; color: rgb(153, 255, 153);"&gt;SecurityFocus's&lt;/span&gt; web site about fighting back against hackers.  The articles are titled &lt;a href="http://www.securityfocus.com/infocus/1856"&gt;Malicious Malware: Attacking the Attackers, Part One&lt;/a&gt;, and &lt;a href="http://www.securityfocus.com/infocus/1857"&gt;Part Two&lt;/a&gt;.  But can I tell you, they were so far over my head they could've been written in Chinese and I wouldn't know any more than I did when I started.  However, the more technically proficient among you may learn something valuable.  That you can then bring back to my site to help me catch my own bad guys. :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-5277962932038119700?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/5277962932038119700/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=5277962932038119700' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/5277962932038119700'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/5277962932038119700'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/10/securityfocuss-attacking-attackers.html' title='SecurityFocus&apos;s &quot;Attacking the Attackers&quot;'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-4798091762872943091</id><published>2007-10-16T23:03:00.000-04:00</published><updated>2007-10-16T23:26:09.386-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conspiracy theories'/><category scheme='http://www.blogger.com/atom/ns#' term='MS Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='rootkits'/><category scheme='http://www.blogger.com/atom/ns#' term='Uber-Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Portion of an interview with Jamie Butler on Rootkits</title><content type='html'>I just saw a pretty amazing video podcast available on iTunes from &lt;span style="font-weight: bold; color: rgb(153, 255, 153);"&gt;OnSecurity&lt;/span&gt; called &lt;span style="font-style: italic;"&gt;Rootkits: Detecting the Threat with Jamie Butler&lt;/span&gt;.  Mr. Butler is co-author of a book called &lt;a href="http://www.amazon.com/gp/product/0321294319?ie=UTF8&amp;amp;tag=hackednation-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=0321294319"&gt;Rootkits: Subverting the Windows Kernel (Addison-Wesley Software Security Series)&lt;/a&gt;&lt;img src="http://www.assoc-amazon.com/e/ir?t=hackednation-20&amp;amp;l=as2&amp;amp;o=1&amp;amp;a=0321294319" alt="" style="border: medium none  ! important; margin: 0px ! important;" border="0" height="1" width="1" /&gt;.  Here is some enlightening dialogue:&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold;"&gt;Mr. Butler: &lt;/span&gt;Normally what has to be done is a complete reinstall of the operating system itself.  And we've seen, um, over the last year, year to two years, the evolution of rootkits even into the hardware and bios spaces, where it's been demonstrated at Black Hat Federal and other conferences where a complete reinstall of the operating system may not be enough to get rid of the rootkit itself.&lt;/blockquote&gt;For months I could not understand why a complete wipe and reinstall of Windows Vista on my infected machine(s) resulted in the same damaged computer as before.  At times I blamed an infected installation disk, infected hidden partition (from which many computer companies perform system reinstalls, eschewing disks altogether). Finally I was convinced the malware was coming straight from my Cable Internet provider (paranoia I realize, but I was basing this on the statements of a nemesis's statement (who worked for Comcast) that "You would be amazed what we can do to your computer and what we can see." Over time my infected computer's security had essentially been completely wiped out.  Services I disabled automatically re-enabled themselves.  At certain points my system was visibly under the control of an unseen entity/hacker.  I described the problem to friends, and they told me what I was explaining to them was science fiction, and used the "P" word to describe me again.  Now thanks to Mr. Butler I have some explanation that the events I was experiencing was and are real, but am now pessimistic that my one remaining Windows machine will ever be viable and may have to be trashed completely.&lt;br /&gt;&lt;br /&gt;A relevant portion of the podcast can be seen below.&lt;br /&gt;&lt;br /&gt;&lt;object height="350" width="425"&gt; &lt;param name="movie" value="http://www.youtube.com/v/NzYsZLA_hZc"&gt;  &lt;embed src="http://www.youtube.com/v/NzYsZLA_hZc" type="application/x-shockwave-flash" height="350" width="425"&gt;&lt;/embed&gt;  &lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-4798091762872943091?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/4798091762872943091/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=4798091762872943091' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/4798091762872943091'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/4798091762872943091'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/10/portion-of-interview-with-jamie-butler.html' title='Portion of an interview with Jamie Butler on Rootkits'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-6829113833667081951</id><published>2007-10-16T18:54:00.000-04:00</published><updated>2007-10-21T03:02:58.666-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mac os x'/><category scheme='http://www.blogger.com/atom/ns#' term='encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Securing Your Mac</title><content type='html'>There's a pretty good article in the November 2007 issue of MacWorld called &lt;a href="http://www.macworld.com/2007/10/features/lockup_main/index.php"&gt;Secure Your Mac&lt;/a&gt;. Beyond the offensively obvious items such as "Choose Strong Passwords", there are a couple of really good tips.&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Change Your Keychain Password. &lt;/span&gt; Many people (myself included) don't realize your keychain of passwords is entirely accessible once you log in to your Mac. Your Mac login unlocks the keychain, so if you step away from your computer, anyone can access without restriction your passwords for Airport settings and even web site passwords that Safari  stores in the keychain.  &lt;span style="font-weight: bold;"&gt;Solution:&lt;/span&gt; open &lt;span style="font-style: italic; color: rgb(153, 255, 153);"&gt;Keychain Access&lt;/span&gt;, select&lt;span style="color: rgb(51, 204, 255);"&gt; &lt;/span&gt;&lt;span style="font-style: italic; color: rgb(153, 255, 153);"&gt;Show Keychains&lt;/span&gt;, select your default keychain (usually called 'login'), then choose&lt;span style="font-style: italic;"&gt; &lt;span style="color: rgb(153, 255, 153);"&gt;Edit&lt;/span&gt; | &lt;span style="color: rgb(153, 255, 153);"&gt;Change Password&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(153, 255, 153);"&gt; &lt;/span&gt;&lt;span style="font-style: italic; color: rgb(153, 255, 153);"&gt;for Keychain&lt;/span&gt;, and choose a different password from your login.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Encrypt Sensitive Files.&lt;/span&gt;  Acknowledging the instability inherent in Mac's FileVault, MacWorld describes a better way to encrypt your sensitive data, by creating an encrypted disk image: In &lt;span style="font-style: italic; color: rgb(153, 255, 153);"&gt;Disk Utility&lt;/span&gt;, create a new disk image by selecting &lt;span style="font-style: italic; color: rgb(153, 255, 153);"&gt;File&lt;/span&gt; | &lt;span style="font-style: italic; color: rgb(153, 255, 153);"&gt;New&lt;/span&gt; | &lt;span style="font-style: italic; color: rgb(153, 255, 153);"&gt;Blank Disk Image&lt;/span&gt;.  Under &lt;span style="font-style: italic; color: rgb(153, 255, 153);"&gt;Encryption&lt;/span&gt;&lt;span style="color: rgb(153, 255, 153);"&gt;,&lt;/span&gt; select 'AES-128'.  Select 'Sparse Disk Image' from &lt;span style="color: rgb(153, 255, 153);"&gt;the &lt;/span&gt;&lt;span style="font-style: italic; color: rgb(153, 255, 153);"&gt;Format&lt;/span&gt; popup box, specify a name and location, and move all your sensitive files to this location once you mount the disk.  Eject the disk when you're through editing/viewing these top-secret files.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-6829113833667081951?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/6829113833667081951/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=6829113833667081951' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/6829113833667081951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/6829113833667081951'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/10/securing-your-mac.html' title='Securing Your Mac'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-1373937248400033516</id><published>2007-10-13T00:39:00.000-04:00</published><updated>2007-10-14T10:07:03.390-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conspiracy theories'/><category scheme='http://www.blogger.com/atom/ns#' term='mac os x'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>My Mac, the Server?</title><content type='html'>I admit I don't know Macs, I don't know networking, but is it normal that when I connect to the internet via my Airport Extreme my entire home folder becomes a server?  Am I just not "getting" the way my Mac operates?  When I connect to the Internet, the &lt;span style="font-weight: bold;"&gt;Server&lt;/span&gt; icon shows the following: Does that mean I am sharing my home folder (all users, all info) or that it is public? If my computer is a server, who is the client?  I honestly hope I am being ignorant and paranoid here, but something seems amiss. &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_VwuHozUF70U/RxBOsIgm-AI/AAAAAAAAAYE/pd5-Ts2gEmk/s1600-h/my_computer_the_server.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_VwuHozUF70U/RxBOsIgm-AI/AAAAAAAAAYE/pd5-Ts2gEmk/s320/my_computer_the_server.jpg" alt="" id="BLOGGER_PHOTO_ID_5120679296425719810" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-1373937248400033516?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/1373937248400033516/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=1373937248400033516' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/1373937248400033516'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/1373937248400033516'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/10/my-mac-server.html' title='My Mac, the Server?'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VwuHozUF70U/RxBOsIgm-AI/AAAAAAAAAYE/pd5-Ts2gEmk/s72-c/my_computer_the_server.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-7202731178854514795</id><published>2007-10-11T22:37:00.000-04:00</published><updated>2007-10-11T22:57:33.110-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conspiracy theories'/><category scheme='http://www.blogger.com/atom/ns#' term='MS Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='mac os x'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Red Herrings</title><content type='html'>When one's computer is &lt;span style="font-style: italic;"&gt;routinely&lt;/span&gt; hacked -- even though I still can't "prove" that it was -- one starts to think it's a personal vendetta at work, not a random act.  It seems clear to me that the person or persons who perpetrated these attacks on me knew me; that they probably even had physical access to my computer. I have theories of how this was accomplished.  So-called "social engineering" is the most probable: leaving an unmarked computer DVD for me to pop into my PC, unwittingly running a malware installer, for example. But the truth is, I still don't know when or how I was initially targeted (though I have some pretty good guesses as to why). If that's the case -- if a person is indeed "targeted" by a hacker, how can he be safe?  Especially when both Windows and Mac computers come out-of-the-box essentially defenseless against such inrusions, with minimum security in place and, in the case of Windows (any variant), running a host of unneeded, security-reducing services by default.&lt;br /&gt;&lt;br /&gt;Unfortunately, the paranoia such thoughts bring about are maddening.  One sees "evidence" everywhere, signs pointing to one person or the other.  Red herrings, as they call them in detective novels and movies.  I've been led down several wrong paths, but have narrowed the list of suspects down to three serious ones.  Each one has had opportunity (access to my machine), motive (let's just say I've made my share of enemies), and the amorality required to commit such an offense.  I used to hang around with a group of people with let us say ... questionable scruples. What can I say, it's true: You lay down with dogs, you get fleas.  But no one deserves to be put through what I've gone through.  I plan in a later post to enumerate the direct and indirect costs -- such as time spent troubleshooting and reinstalling software -- this crap has cost me.  I expect the figure to be astounding.  I plan also on profiling (though not naming) each of these three Horsemen of the Apocalypse.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-7202731178854514795?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/7202731178854514795/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=7202731178854514795' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/7202731178854514795'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/7202731178854514795'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/10/red-herrings.html' title='Red Herrings'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-1907493818962603945</id><published>2007-10-11T07:44:00.000-04:00</published><updated>2007-10-13T00:50:27.878-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conspiracy theories'/><category scheme='http://www.blogger.com/atom/ns#' term='MS Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='Uber-Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Norton Security Scan Clues (part 3)</title><content type='html'>Here are a couple of more-recent clues gleened from the neutered but still-helpful Norton Security Scan.  By this time I had ditched Comcast cable internet service in favor of AT&amp;amp;T's mobile broadband service (another expense, another dead end).  First, &lt;span style="font-weight: bold;"&gt;Keyhost.exe&lt;/span&gt;, a &lt;a href="http://www.processlibrary.com/directory/files/keyhost"&gt;normal process according to ProcessLibrary.com&lt;/a&gt;, or a &lt;a href="http://www.bleepingcomputer.com/startups/Keyhost.exe-6641.html"&gt;Hijacker, hailing from jraun.com, says bleepingcomputer.com&lt;/a&gt;.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_VwuHozUF70U/Rw4Rkogm98I/AAAAAAAAAXk/tumDDyZKCnU/s1600-h/keyhost.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_VwuHozUF70U/Rw4Rkogm98I/AAAAAAAAAXk/tumDDyZKCnU/s320/keyhost.jpg" alt="" id="BLOGGER_PHOTO_ID_5120049147413985218" border="0" /&gt;&lt;/a&gt;Next up: &lt;span style="font-weight: bold;"&gt;StaffCop&lt;/span&gt;.  It's &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-031310-2131-99&amp;amp;tabid=2"&gt;spyware that captures screenshots and logs activity&lt;/a&gt;, storing the compromised confidential information inside the &lt;span style="font-style: italic;"&gt;%System%\CSRSS folder&lt;/span&gt;, says Symantec.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_VwuHozUF70U/Rw4VSYgm99I/AAAAAAAAAXs/A9p5SvjMpZg/s1600-h/staffcop.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_VwuHozUF70U/Rw4VSYgm99I/AAAAAAAAAXs/A9p5SvjMpZg/s320/staffcop.jpg" alt="" id="BLOGGER_PHOTO_ID_5120053231927883730" border="0" /&gt;&lt;/a&gt;Lastly, Symantec categorizes the program &lt;span style="font-weight: bold;"&gt;Surf Sidekick&lt;/span&gt;, shown in the following screen capture, as &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2004-112118-0309-99"&gt;Adware&lt;/a&gt;.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_VwuHozUF70U/Rw4XvIgm9-I/AAAAAAAAAX0/Xtr5yMKU5N4/s1600-h/surfsidekick.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_VwuHozUF70U/Rw4XvIgm9-I/AAAAAAAAAX0/Xtr5yMKU5N4/s320/surfsidekick.jpg" alt="" id="BLOGGER_PHOTO_ID_5120055924872378338" border="0" /&gt;&lt;/a&gt;What's troublesome is that these latest screen captures were taken a little more than a month ago, after I started using my MacBook almost full-time and had only recently put the Windows machine back on the Web.  More troublesome of course is that my current Antivirus (Kaspersky) and Antispyware (Spyware Doctor) solutions aren't finding any infections at all, though if my machine &lt;span style="font-style: italic;"&gt;was&lt;/span&gt; already infected with Uber-Malware, and if it works as I suspect it does, then theoretically any legitimate download would be filtering through a the Malware Host machine, which could then "neuter" or alter the program so that it becomes inert.  Anyone out there know a Trojan or Rootkit with those properties?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-1907493818962603945?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/1907493818962603945/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=1907493818962603945' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/1907493818962603945'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/1907493818962603945'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/10/norton-security-scan-clues-part-three.html' title='Norton Security Scan Clues (part 3)'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VwuHozUF70U/Rw4Rkogm98I/AAAAAAAAAXk/tumDDyZKCnU/s72-c/keyhost.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-7118487408867429880</id><published>2007-10-10T13:18:00.000-04:00</published><updated>2007-10-10T14:29:14.677-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MS Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='mac os x'/><category scheme='http://www.blogger.com/atom/ns#' term='encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Encryption in Vista and OS X: Not Worth It?</title><content type='html'>I read an article not long ago in Details magazine about white-hat hackers. I lost the issue, and I can't find a link, so I'm working from memory here. Anyway, a government security guy who recruits white-hat (i.e., ethical) hackers stated that he was worried about the heavy-duty encryption (called BitLocker) found in Vista Ultimate (&lt;a href="http://www.microsoft.com/windows/products/windowsvista/editions/choose.mspx"&gt;no other versions of Vista include this feature&lt;/a&gt;). He said he was worried about it from a National-security perspective, but BitLocker is also supposed to make it much harder for your PC to be hacked into.&lt;br /&gt;&lt;br /&gt;I bought a Toshiba laptop (a great machine, really) with Vista Ultimate, one of my many purchases (this one roughly $1,400) in an attempt to foil my already-hacked home network. No sooner had I plugged the machine into the ethernet cable to my modem than it seemed to be hacked again. I ran all the Microsoft security updates as soon as possible, but it was too late. Very quickly, my PC looked like it was running a copy of Virtual PC or something. Windows showed me being on a "network" which was composed of an intermediary computer between me and the internet.  I wasn't on a network at all.  When I tried to download and install BitLocker (although it's a Vista Ultimate feature, it still requires a download) a weird error denied my enabling the feature.  Drive wipes and reinstalls didn't help. Was my mystery hacker to blame, or is Microsoft?&lt;br /&gt;&lt;br /&gt;I ran into similar, though less paranoia-inducing, problems with OS X's File Vault (the Mac version of this strong disk encryption).  My computer kept freezing, unable to recover from Sleep Mode, requiring constant restarts. Apparently this corrupted the FileVault, resulting in the below message.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_VwuHozUF70U/Rw0Y2Igm94I/AAAAAAAAAXA/0aAiT5wXXVI/s1600-h/filevault_error.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_VwuHozUF70U/Rw0Y2Igm94I/AAAAAAAAAXA/0aAiT5wXXVI/s320/filevault_error.jpg" alt="" id="BLOGGER_PHOTO_ID_5119775669666379650" border="0" /&gt;&lt;/a&gt;I ended up losing a lot of data, and found a bunch of common threads on the topic stating that the system freeze issue was a common one but pretty much unexplained at this time. Of course Apple takes no responsibility for this. As with all software companies, the warranty for the software excludes them from any sort of liability to damage that their bugs cause the end user. Bottom line of those threads was not to use FileVault on an administrator account at all. Thanks for the heads-up Apple! I've given up on FileVault altogether, though don't get me wrong, I'm still an Apple convert. Compared to Microsoft, Apple's products are far and above superior.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-7118487408867429880?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/7118487408867429880/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=7118487408867429880' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/7118487408867429880'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/7118487408867429880'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/10/encryption-in-vista-and-os-x-not-worth.html' title='Encryption in Vista and OS X: Not Worth It?'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VwuHozUF70U/Rw0Y2Igm94I/AAAAAAAAAXA/0aAiT5wXXVI/s72-c/filevault_error.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-3317204277074403419</id><published>2007-10-09T20:15:00.000-04:00</published><updated>2007-10-11T07:33:37.283-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conspiracy theories'/><category scheme='http://www.blogger.com/atom/ns#' term='mac os x'/><category scheme='http://www.blogger.com/atom/ns#' term='Uber-Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>"In the end there can only be one..."</title><content type='html'>After more than a year and at least a couple grand spent trying to outwit the hackers who were intent on terrorizing me, I took several friends' advice and went out to buy a Mac. I was at my wit's end, sure that the Uber-Malware was entering directly from Comcast, my cable provider (a former "friend" of mine who worked for Comcast alluded to that fact).  I took all the cash I had, and went to the local Apple store and bought a MacBook, spending $1800, at least $800 more than I would spend for a comparable PC.  But if it was secure, as all my friends contended, then it would be worth it.&lt;br /&gt;&lt;br /&gt;The same day I brought my MacBook home, a friend-of-a-friend Mac "expert" took a look at it and said "This computer isn't behaving very Mac-like," a frown creasing his forehead.  I didn't know what "Mac-like" behavior was of course -- I had nothing to compare it to.  Of course the statement scared me, especially since this person supposedly knew nothing of my ridiculously unfixable PC security issues.  But at the end of the session he seemed convinced my computer was okay. Then a few days later, my outbound firewall popped up the below message.&lt;span style="text-decoration: underline;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_VwuHozUF70U/Rw1EH4gm95I/AAAAAAAAAXI/zUKV9diYg2k/s1600-h/thequickbrownfox.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_VwuHozUF70U/Rw1EH4gm95I/AAAAAAAAAXI/zUKV9diYg2k/s320/thequickbrownfox.jpg" alt="" id="BLOGGER_PHOTO_ID_5119823253609052050" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;Along with the ordinary request for permission of a program to have outbound internet access, there was this message at the end: "In the end there can be only one. The quick brown fox jumped over the lazy dog."&lt;span style="text-decoration: underline;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_VwuHozUF70U/Rw1Ecogm96I/AAAAAAAAAXQ/pr3_9ejVECE/s1600-h/thequickbrownfox_closeup1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_VwuHozUF70U/Rw1Ecogm96I/AAAAAAAAAXQ/pr3_9ejVECE/s320/thequickbrownfox_closeup1.jpg" alt="" id="BLOGGER_PHOTO_ID_5119823610091337634" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;To this day I am not sure how or why that message popped up.  It happened several times before I deleted the software (Internet Cleanup 4.0) and replaced it with LittleSnitch. The first line I believe is from &lt;span style="font-weight: bold;"&gt;Highlander&lt;/span&gt;. The second if I am not mistaken is from &lt;span style="font-weight: bold;"&gt;The Matrix&lt;/span&gt;, but I could be wrong.  Was someone trying to tell me something, or was this some glitch in the code of the software? Googling the term yielded no result, so my instincts lead me to believe it was the former.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-3317204277074403419?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/3317204277074403419/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=3317204277074403419' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/3317204277074403419'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/3317204277074403419'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/10/in-end-there-can-only-be-one.html' title='&quot;In the end there can only be one...&quot;'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VwuHozUF70U/Rw1EH4gm95I/AAAAAAAAAXI/zUKV9diYg2k/s72-c/thequickbrownfox.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-6554787350399011407</id><published>2007-10-04T22:29:00.000-04:00</published><updated>2007-10-16T23:45:27.547-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conspiracy theories'/><category scheme='http://www.blogger.com/atom/ns#' term='MS Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='Uber-Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Norton Security Scan Clues (part 2)</title><content type='html'>I think it's a bit ironic that I spent hundreds of dollars on antivirus and antispyware software, yet the one that really gave me "clear and convincing evidence" of a breach to my Vista PC's security was a little freebie utility called &lt;span style="font-weight: bold;"&gt;Norton Security Scan&lt;/span&gt;, (included in Blogger's parent company's self-titled &lt;a href="http://pack.google.com/"&gt;&lt;span style="font-weight: bold;"&gt;Google Pack&lt;/span&gt;&lt;/a&gt;). But don't get me wrong, it's not like Norton Security Scan really worked, and actually discovered the malware I contend my PC was infected with. Like all the other products, it loudly proclaimed my computer to be &lt;span style="font-style: italic;"&gt;free of all viruses and spyware&lt;/span&gt;.  But the following screen captures show a couple of other gems apparently either hiding on my PC or -- more likely in my opinion -- residing on the host computer.  It became my theory, and still is, that my machine became (and probably still is) a client to a hacker's host computer, with him pulling all the strings.  I am guessing that I connected to his machine transparently upon log-on if there was an internet connection.  And if there was no connection, my computer synced with his at the first opportunity.&lt;br /&gt;&lt;br /&gt;The first of two more incriminating screen captures from Norton Security Scan shows a file called &lt;span style="font-weight: bold;"&gt;dnsrxpob.exe&lt;/span&gt;, below, in the c:\windows\system32 folder. I knew from my limited knowledge that the &lt;span style="font-style: italic;"&gt;system32&lt;/span&gt; folder is where a lot of malware likes to hide out.  Googling the file name, I found out that it's evidence of a mass-mailing Worm that Symantec calls &lt;span style="font-weight: bold;"&gt;W32.Stration.DD@mm&lt;/span&gt; (how do they come up with these names?). &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-102311-3614-99&amp;amp;tabid=2"&gt;Info about this worm&lt;/a&gt; can be found on Symantec's site.&lt;span style="text-decoration: underline;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_VwuHozUF70U/RxWE8Ygm-BI/AAAAAAAAAYM/l_ge3Yq5Xu0/s1600-h/dnsrxpob.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_VwuHozUF70U/RxWE8Ygm-BI/AAAAAAAAAYM/l_ge3Yq5Xu0/s320/dnsrxpob.jpg" alt="" id="BLOGGER_PHOTO_ID_5122146324110047250" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;The second screen capture, below, shows &lt;span style="font-weight: bold;"&gt;Swartax&lt;/span&gt;.  This one's name alone kind of made me think "malware", and sure enough, it's a Trojan/Backdoor according to &lt;a href="http://www.sophos.com/virusinfo/analyses/trojbdooraml.html"&gt;Sophos's threat analysis&lt;/a&gt;. Pausing the scanner to take screen captures and notes led, again, however, to a "spontaneous" reboot of my Vista PC. I felt a mixture of elation to finally be "onto him" (whoever "he" was/is), and dread that no software I installed seemed capable to actually discover these files themselves (I had to &lt;span style="font-style: italic;"&gt;google them&lt;/span&gt;?!) and disinfect my machine. My theories on that will be forthcoming. &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_VwuHozUF70U/RxWFP4gm-CI/AAAAAAAAAYU/eCGCcC7z4n0/s1600-h/swartax_web.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_VwuHozUF70U/RxWFP4gm-CI/AAAAAAAAAYU/eCGCcC7z4n0/s320/swartax_web.jpg" alt="" id="BLOGGER_PHOTO_ID_5122146659117496354" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-6554787350399011407?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/6554787350399011407/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=6554787350399011407' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/6554787350399011407'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/6554787350399011407'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/10/norton-security-scan-clues-part-2.html' title='Norton Security Scan Clues (part 2)'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VwuHozUF70U/RxWE8Ygm-BI/AAAAAAAAAYM/l_ge3Yq5Xu0/s72-c/dnsrxpob.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-6083450239193975631</id><published>2007-10-04T13:49:00.001-04:00</published><updated>2007-10-13T01:23:05.160-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conspiracy theories'/><category scheme='http://www.blogger.com/atom/ns#' term='MS Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='Uber-Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Video Evidence?</title><content type='html'>I've posted two videos on my &lt;a href="http://www.youtube.com/hackednation"&gt;YouTube channel&lt;/a&gt;.  I hope the resolution is good enough that you'll be able to see what I see in the videos.  You tell me, is this evidence of hacking or not?  The videos show a view of certain log files on my Vista media center PC (all my main computing is performed on my Mac, which hopefully has still remained uncompromised).  As I scrolled and clicked through the entries, I knew that something "just wasn't right". It seemed to show a lot of weird stuff going on, but I am not a techie, and have no way to tell whether there's any real evidence there.  Check these videos out.  I will upload a higher-def version of the complete 17 minute-long video on a free FTP server, TBD.&lt;br /&gt;&lt;center&gt;&lt;object height="350" width="425"&gt; &lt;param name="movie" value="http://www.youtube.com/v/1vEh0rsJHrc"&gt; &lt;embed src="http://www.youtube.com/v/1vEh0rsJHrc" type="application/x-shockwave-flash" height="350" width="425"&gt;&lt;/embed&gt;  &lt;/object&gt;&lt;/center&gt;&lt;br /&gt;And finally, this is part two. Again, the quality sucks I realize. &lt;center&gt;&lt;object height="350" width="425"&gt; &lt;param name="movie" value="http://www.youtube.com/v/xfezGmJQUh8"&gt;  &lt;embed src="http://www.youtube.com/v/xfezGmJQUh8" type="application/x-shockwave-flash" height="350" width="425"&gt;&lt;/embed&gt;  &lt;/object&gt;&lt;/center&gt;&lt;br /&gt;&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Update [10/5/07]:&lt;/span&gt; It took some time since I am fairly new to video editing, but the first of two higher-def videos is posted online at a free hosting site called Files Upload.  Direct link to part one: &lt;a href="http://files-upload.com/files/541570/hacking_evidence_or_not_1.mov"&gt;hacking_evidence_or_not_1.mov&lt;/a&gt;.  Direct link to part two: &lt;a href="http://files-upload.com/files/558208/hacking_evidence_or_not_2.mov"&gt;hacking_evidence_or_not_2.mov&lt;/a&gt;.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-6083450239193975631?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/6083450239193975631/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=6083450239193975631' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/6083450239193975631'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/6083450239193975631'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/10/video-evidence.html' title='Video Evidence?'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-6895323212464101933</id><published>2007-10-01T10:34:00.000-04:00</published><updated>2007-10-11T07:30:54.173-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MS Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='Uber-Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Norton Security Scan Clues (part 1)</title><content type='html'>I'm going to start calling the virus or other malware that attacked me less than 12 months ago (and possibly recently)&lt;span style="font-weight: bold;"&gt; Uber-Malware&lt;/span&gt;.  Right now there's really no description more apt, it certainly won't get confused with other topics on this blog, and it sounds kinda cool.  One thing this "Uber-Malware" did was, as it slowly infected my PC, it began disabling all my security applications.  Every single one.  This is commonplace behavior for a Trojan, I am sure.  However, it made the apps &lt;span style="font-style: italic;"&gt;appear&lt;/span&gt; to be working 100% correctly. But the spyware-finding and cleaning abilities in all of them was as fake as Joan Rivers'... pick a body part.  They'd essentially been neutered.  The only "problem" was, every antispyware and antivirus app I used would always result in zero viruses found, zero spyware applications, zero infections with malware... even, it turns out,&lt;span style="font-style: italic;"&gt; zero cookies found from bad sites&lt;/span&gt;. In other words, the Uber-Malware was essentially &lt;span style="font-style: italic;"&gt;too good&lt;/span&gt; at disabling my defenses, since I noticed right away that my antispyware program, which routinely returned dozens of "spyware" cookies from "bad sites" for me to delete, now returned &lt;span style="font-style: italic; font-weight: bold;"&gt;none&lt;/span&gt;, yet my surfing habits had not changed.  This was one clue something subversive was going on with my machine.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_VwuHozUF70U/RwEMkVKmDfI/AAAAAAAAAUk/vgLkvhgMRlQ/s1600-h/nortonscan1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_VwuHozUF70U/RwEMkVKmDfI/AAAAAAAAAUk/vgLkvhgMRlQ/s400/nortonscan1.jpg" alt="" id="BLOGGER_PHOTO_ID_5116384469965999602" border="0" /&gt;&lt;/a&gt;Next, I noticed that if I ran Norton Security Scan (available as part of the Google Pack) and paid close attention to the destinations it was scanning, it was scanning entire folders and files &lt;span style="font-weight: bold;"&gt;that did not reside on my computer&lt;/span&gt; -- or so I thought.  I was able to slow down Norton Security Scan considerably by running memory and processor-intensive applications at the same time, and by randomly performing screen captures.  I caught one screen capture (below) that showed a shortcut for a program called PC Activity Monitor Standard on the Administrator's desktop.  I was running the Administrator account when I found it, and that program was not on my desktop; in fact I had never even heard of it.  I performed subsequent identical scans, and was able to see that on the desktop of this other person's PC ("host PC"?) there were maybe half a dozen Remote Administration programs or other programs that could be used as Trojans!  My PC seemed truly screwed.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_VwuHozUF70U/RwUfIYgm9wI/AAAAAAAAAVE/hinYskx6Ryo/s1600-h/pc_activity_monitior_std.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_VwuHozUF70U/RwUfIYgm9wI/AAAAAAAAAVE/hinYskx6Ryo/s400/pc_activity_monitior_std.jpg" alt="" id="BLOGGER_PHOTO_ID_5117530780455073538" border="0" /&gt;&lt;/a&gt;I knew I was on to something when my computer mysteriously, spontaneously rebooted when I had an incriminating screen capture like the one above paused on my screen.  Could it be someone on the other side of a monitor somewhere, viewing my computer and terrorizing my life, figured out I was onto him?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Afterward:&lt;/span&gt;  I did a google search for the program PC Activity Monitor Standard and found no information on their site for how to detect or remove the program once it was installed.  I find this infuriating, and think there's probably a consumer law about it that would apply.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-6895323212464101933?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/6895323212464101933/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=6895323212464101933' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/6895323212464101933'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/6895323212464101933'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/10/super-virus-clue-one-computer-defenses.html' title='Norton Security Scan Clues (part 1)'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VwuHozUF70U/RwEMkVKmDfI/AAAAAAAAAUk/vgLkvhgMRlQ/s72-c/nortonscan1.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-1278062989972880632</id><published>2007-09-30T11:36:00.000-04:00</published><updated>2007-10-01T10:33:50.096-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='annoyances'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Unidentified Virus: x86_wcf-system.io.log~.zip</title><content type='html'>ClamXav discovered the following unidentified virus on my Mac, which no other antivirus program I have used has claimed is a virus.  I am not sure whether it is a false positive or evidence of something insidiary going on on my PC.  It originated from my PC, where I did a search for all files containing the word "LOG" in them, and zipped them up to keep them as "evidence" in case something in there could later be used to track the hacker(s) I've mentioned before.  I then transferred the .zip file to my Mac, where ClamXav said there was a virus contained in the zip file.  The possibly infected file has the unweildy name of  &lt;span style="font-size:85%;"&gt;x86_wcf-system.io.log_b03f5f7f11d50a3a_6.0.6000.16386_none_da9913e6bac66516.zip~RF478b4d4.TMP&lt;/span&gt;.   If anyone has any info about the above file let me know. I plan on submitting it to McAfee or some other antivirus software vendor for analysis. Any recommendations on who to submit the file to would be appreciated as well.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Update: &lt;/span&gt;Apparently the virus was a &lt;a href="http://vil.nai.com/vil/content/v_876.htm"&gt;null virus&lt;/a&gt;.  I have no clue really how this relates to me and the incredibly sophisticated hacking that went on with my PC.  This looks like a BB gun when what I need to find is a bazooka.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-1278062989972880632?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/1278062989972880632/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=1278062989972880632' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/1278062989972880632'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/1278062989972880632'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/09/unidentified-virus-x86wcf.html' title='Unidentified Virus: x86_wcf-system.io.log~.zip'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-7995173912361071006</id><published>2007-09-28T23:57:00.000-04:00</published><updated>2007-09-29T03:51:11.579-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='warez'/><category scheme='http://www.blogger.com/atom/ns#' term='scams'/><title type='text'>Warez Scam of the Century</title><content type='html'>I got scammed on a warez site yesterday, and have only myself to blame.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Background:&lt;/span&gt; I recently decided to pay for all my software, after the hacking issues that plagued my PC made the concept of "nothing in life is free" take on new meaning.  Not to mention the fact that software developers need to get paid too, and I have always considered stealing wrong -- only that morality didn't seem to cover digital media. Go figure.  However, I've had a financial crisis of late, and really wanted to replace the truly awful SierraWatcher software for Mac OS X (it connects my laptop to the internet via my AT&amp;amp;T AirCard 875U) with something better, and AT&amp;amp;T (nee Cingular) doesn't support Macs, so their superior software is unavailable to me.   My only option seems to be a program called launch2net, made by a finnish company I believe, and I tried a trial and it's way superior to SierraWatcher.  Yet maybe it's the exchange rate, but it costs 75 euros, currently $106 USD, and I don't think you'll find anyone out there arguing that a modem dialing piece of software is worth that much. $25 maybe... but over $100?  Give me a break.  So I had a slip in my "no pirated software" philosophy and did a Google search for "launch2net warez" which resulted in a site with an incredible scam.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_VwuHozUF70U/Rv4Dv1KmDeI/AAAAAAAAAUE/2jA9Fvnt3mw/s1600-h/dollarwarez.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_VwuHozUF70U/Rv4Dv1KmDeI/AAAAAAAAAUE/2jA9Fvnt3mw/s320/dollarwarez.jpg" alt="" id="BLOGGER_PHOTO_ID_5115530346999713250" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;The Scam:&lt;/span&gt; The site, dollarwarez.com, claims you can pay $1 to get access to the site by buying a 3-day trial membership to any of its porn affiliates, which costs only $1, natch.  Make a successful purchase and return to dollarwarez and enter the code you're provided by the porn affiliate to get access. Only, the code doesn't work.  The email address on the site for support doesn't work. You've just been screwed, and dollarwarez has made a big profit off you by the payment the porn affiliate will send them for signing up a new customer. What's worse, if you forget to cancel your three-day trial membership (and a high percentage of people probably do), then your credit card will be billed monthly every month until cancellation, which results in a perpetual payout for dollarwarez for operating a bogus site.  Of course, you (or I, whatever) surfed there looking for free (illegal) software warez downloads, so who's going to call the BBB on them?  It's a scam that works because the scammed party (in this case myself) basically "deserved" it.  Still, they're scum.  Be warned.&lt;br /&gt;&lt;br /&gt;Guess I'll have to settle for using the sucky SierraWatcher for Mac OS X for the time being, until the guys who make launch2net learn how to price competitively.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-7995173912361071006?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/7995173912361071006/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=7995173912361071006' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/7995173912361071006'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/7995173912361071006'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/09/warez-scam-of-century.html' title='Warez Scam of the Century'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VwuHozUF70U/Rv4Dv1KmDeI/AAAAAAAAAUE/2jA9Fvnt3mw/s72-c/dollarwarez.jpg' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-306024089101473201</id><published>2007-09-27T20:14:00.000-04:00</published><updated>2007-09-28T23:08:29.192-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conspiracy theories'/><category scheme='http://www.blogger.com/atom/ns#' term='spooks'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>U.S. Government Hacking</title><content type='html'>The identity of the hacker who targeted me is of course unknown; hence the reason for this blog. But the possibility that it could have been the U.S. government itself is truly disturbing.  It's hard to believe we are living in an Orwellian police state in this country, but the evidence is all around us: the government's use of &lt;a href="http://news.zdnet.com/2100-1009_22-6197020.html"&gt;spyware or "fedware"&lt;/a&gt; that can bypass a computer's security software altogether; the Bush Administration's program of &lt;a href="http://blog.wired.com/27bstroke6/2007/09/us-warrantless-.html"&gt;wiretapping without obtaining a warrant&lt;/a&gt;; the FBI's use of &lt;a href="http://www.news.com/FBI-snoop-tool-old-hat-for-hackers/2100-1001_3-276145.html?tag=item"&gt;trojan horses&lt;/a&gt; to get information on would-be drug dealers and other criminals (not just terrorists); and the Patriot Act, which has let all the above occur unchecked.  I thought the Patriot Act was supposed to help in finding and fighting terrorists, not in prosecuting America's own citizens without due process.  I never really thought movies such as &lt;span style="font-style: italic;"&gt;Enemy of the State&lt;/span&gt; and &lt;span style="font-style: italic;"&gt;Minority Report&lt;/span&gt; were realistic.  Certainly they were pessimistic views of the future.  But it seems the future is here, and it's more &lt;span style="font-style: italic;"&gt;V for Vendetta&lt;/span&gt; than even Alan Moore would have predicted when he based the idea on Thatcher-era England in the '80s.&lt;br /&gt;&lt;br /&gt;All may not be lost, however.  The Courts seem to be striking down the above provisions of the Patriot Act as &lt;a href="http://blog.wired.com/27bstroke6/2007/09/court-strikes-2.html"&gt;unconstitutional&lt;/a&gt; with more regularity. Big Brother is here, but perhaps with enough light on this issue, he'll become a bit smaller.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-306024089101473201?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/306024089101473201/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=306024089101473201' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/306024089101473201'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/306024089101473201'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/09/us-government-hacking.html' title='U.S. Government Hacking'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-7772067782616630105</id><published>2007-09-27T18:45:00.000-04:00</published><updated>2007-09-29T03:44:28.755-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mac os x'/><category scheme='http://www.blogger.com/atom/ns#' term='annoyances'/><title type='text'>MacBook Firmware Upgrade Annoyance</title><content type='html'>Mac annoyances pop up almost as frequently as with my PC.  Today, for instance, I upgraded my MacBook's firmware to 1.1 using the downloaded "MacBook EFI Firmware Update" patch, available today from Apple.  After reboot I was greeted with yet another opportunity to enter an old password.  I changed the computer name from [name redacted to protect my identity] some time ago... yet there it appears on the screen.  Of course entering old passwords doesn't work.  Canceling the dialog box altogether seems to be a stopgap measure for now.&lt;span style="text-decoration: underline;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_VwuHozUF70U/Rv4BzFKmDdI/AAAAAAAAAT8/b51AM1xXSHs/s1600-h/dsc00646_1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_VwuHozUF70U/Rv4BzFKmDdI/AAAAAAAAAT8/b51AM1xXSHs/s320/dsc00646_1.jpg" alt="" id="BLOGGER_PHOTO_ID_5115528203811032530" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Update [9/28/07]: &lt;/span&gt;The dialog box has stopped appearing altogether. That's one thing Macs seem to do a lot better than PCs: fix themselves. How they do so, beats the hell out of me. I guess I should just be grateful, albeit confused.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-7772067782616630105?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/7772067782616630105/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=7772067782616630105' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/7772067782616630105'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/7772067782616630105'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/09/macbook-firmware-upgrade-annoyance.html' title='MacBook Firmware Upgrade Annoyance'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_VwuHozUF70U/Rv4BzFKmDdI/AAAAAAAAAT8/b51AM1xXSHs/s72-c/dsc00646_1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1449811636556335442.post-2495451985903029720</id><published>2007-09-26T12:25:00.000-04:00</published><updated>2007-10-16T19:19:48.945-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conspiracy theories'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Figure Out Who Hacked Me... Win $1,000,000</title><content type='html'>Okay so that's stretching it, but you will at least win my undying admiration.  Here's the puzzle: for a year and a half or more I was (and may currently still be) under constant relentless attack by unnamed hacker(s).  Why? I have no clue... maybe it was a personal vendetta, maybe it was industrial sabotage, or maybe it was just sheer boredom.  But the attacks were real, yet everyone around me thought I was losing it.  People thought I was becoming Unabomber-paranoid, and almost everyone gently amused me but steered the conversation elsewhere should I ever bring it up in their presence (which was, like, constantly).  I spent thousands of dollars on new computer equipment, every antivirus and anti-spyware application in existence (or so it seemed), new routers, a firewall.... yet these unseen menaces kept getting in my friggin' computer.  Finally I heeded the advice of several people to "Go get a Mac".  I thought things would be simple, that I'd finally be hacker-free.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;The very first day I set up my Mac&lt;/span&gt;, &lt;span style="font-weight: bold; color: rgb(153, 255, 153);"&gt;it was hacked as well&lt;/span&gt;&lt;span style="color: rgb(153, 255, 153);"&gt;.&lt;/span&gt;  Or so I claimed to everyone.  I bitched out my friends who touted the almighty Mac as the holy grail to fix my problems.  I'd spent $1800 on what -- a pretty MacBook just as or possibly even more susceptible to intentional hacking and malware.  (Truth be told, however, I &lt;span style="font-weight: bold;"&gt;am&lt;/span&gt; now a Mac convert).&lt;br /&gt;&lt;br /&gt;This begins the story, vague though this prologue is.  Hopefully you guys out there will be able to help me figure out, &lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(153, 255, 153);"&gt;Was I hacked... or just paranoid?&lt;/span&gt;  &lt;/span&gt;I've kept many log files, screen captures, and a few notes in order to supplement my oh-so-fallible memory.  I'll post my recollections, supplemented by these logs and screenprints, in no particular order, in the hope of raising awareness and, just maybe, catching the damn bastard that made my life hell for two years plus.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1449811636556335442-2495451985903029720?l=hackednation.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://hackednation.blogspot.com/feeds/2495451985903029720/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1449811636556335442&amp;postID=2495451985903029720' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/2495451985903029720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1449811636556335442/posts/default/2495451985903029720'/><link rel='alternate' type='text/html' href='http://hackednation.blogspot.com/2007/09/solve-puzzle-win-1000000.html' title='Figure Out Who Hacked Me... Win $1,000,000'/><author><name>Paul</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
