Showing posts with label windows security. Show all posts
Showing posts with label windows security. Show all posts

Monday, July 20, 2009

Mengatasi Virus bat dan vbs Tanpa Antivirus

Virus di Windows sebagian besar menggunakan scripting language seperti Batch dengan ekstensi file .bat dan Visual Basic Scripting dengan ektensi .vbs. Selain itu, terdapat juga ekstensi virus dengan .exe yang biasanya dibangun menggunakan bahasa pemrograman Visual Basic atau Visual Studio. Kenapa menggunakan bahasa pemrograman tersebut? Karena Windows dibangun dengan bahasa basic, sehingga sistem operasi Windows secara default menyediakan "penerjemah" terhadap sebagian bahasa-bahasa yang telah saya sebutkan diatas. Scripting languange dengan ekstensi file .bat dan .vbs serta file .exe hasil dari Visual Basic atau Visual Studio adalah file yang dapat dijalankan langsung tanpa intalasi program apapun.

Agar virus tidak dapat bekerja, sebenarnya cukup matikan (disable) .bat, .vbs, dan .exe agar tidak dapat berjalan. Untuk .bat dan .vbs dapat dimatikan, namun untuk .exe tidak bisa karena jika dimatikan akan membuat Windows anda tidak dapat berjalan dengan baik karena sebagian besar sistem Windows menggunakan file dengan ekstensi .exe.

Mematikan (Disable) batch file (bat)
Dengan mematikan ekstensi file .bat, maka Windows anda tidak dapat menjalankan command prompt. Dan sebelum mematikan .bat, lakukan backup terhadap registry anda. Langkah-langkah untuk disable adalah sebagai berikut:

1. Buka regedit dengan cara start->run->ketikkan regedit
2. Buka HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System
3. Buat registry baru dengan nama DisableCMD dan type-nya REG_DWORD
4. Isi value dengan nilai 1. Keterangan value apa saja yang dapat diisi, dapat dilihat di bawah ini:
Value: 0 mengaktifkan command prompt dan batch files
Value: 1 non-aktifkan command prompt dan batch files
Value: 2 non-aktifkan command prompt tetapi dapat menjalankan batch files

Mematikan (Disable) vbs
1. Buka Folder Options seperti pada gambar di bawah ini.


2. Cari File Type VBScript Script File seperti pada gambar di bawah ini. Kemudian setelah itu, tekan tombol Delete.


3. Kemudian Cari File Type VBScript Encoded Script File seperti gambar di bawah ini. Kemudian tekan tombol Delete.
Perlu diingat, dengan mematikan vbs atau batch file ada kemungkinan beberapa program anda yang membutuhkan file ekstensi .bat atau .vbs tidak dapat berjalan sebagimana mestinya. Oleh sebab itu, anda dapat mengembalikan seperti semula dengan mengaktifkan kembali intpreter atau penerjemah vbs dan bat file.

Monday, April 13, 2009

Situs Pendeteksi Worm Conficker

Conficker alias Downadup alias Kido telah diketahui melakukan block terhadap lebih dari 100 website anti-virus dan security.

Joe Stewart, direktur malware research untuk SecureWorks, membuat metode sederhana untuk mendeteksi Conficker yaitu berupa situs yang memiliki link ke situs-situs antivirus. Situs tersebut berisi gambar yang berada dalam suatu tabel dua baris. Baris pertama merupakan gambar/image link ke situs-situs anti-virus dan security, yaitu F-secure, SecureWork, dan TrendMicro. Sedangkan baris kedua ke situs-situs Linux, OpenBSD dan FreeBSD. Jika browser di komputer anda tidak dapat menampilkan seluruh gambar pada baris pertama, kemungkinan besar komputer anda telah terinfeksi Conficker.

Silahkan kunjungi situs yang bernama Conficker Eye Chart tersebut untuk mendeteksi Worm Conficker pada komputer anda.

artikel terkait:
- Lima Tool Basmi Conficker.
- Versi Baru Worm Conficker.

Lima Tool Basmi Conficker

Worm Conficker telah menjadi fenomena beberapa bulan terakhir. Hingga membuat Organisasi Conficker Working Group alias Conficker Cabal dibentuk dan membuat Microsoft berani memberikan ratusan ribu dollar AS jika berhasil menangkap sang pembuatnya. Worm tersebut menyebarkan dirinya dengan memanfaatkan celah keamanan Microsoft’s Server service. Selain itu, Worm Conficker juga memanfaatkan File Sharing dan Flashdisk untuk melakukan penyebarannya.

Lima tool dibawah ini berdasarkan informasi yang saya dapatkan, dapat membersihkan komputer anda dari Worm Conficker:

1. F-Secure: Tool yang dibuat merupakan tool gratis yang bernama fseasyclean.

2. BitDefender: Tool yang dibuat BitDefender dapat anda download melalui http://bdtools.net

3. Nmap: Nmap merupakan open source network scanner. Versi terbarunya memungkinkan untuk deteksi Worm Conficker.

4. McAfee: McAfee' s stand-alone Avert Stinger utility telah memungkinkan untuk menghapus worm Conficker.

5. Symantec: Tool dari Symantec, dapat anda download di sini.

Artikel Terkait:
- Situs Pendeteksi Worm Conficker.
- Versi Baru Worm Conficker.

sumber:
eWeek

Versi Baru Worm Conficker

Berita tentang Conficker memang telah lama beredar, namun saya malah belum menulisnya satupun. Ini sebagai tulisan pertama saya tentang worm Conficker.

Worm Conficker telah memperbaharui dirinya. Versi terbaru dari worm Conficker adalah melakukan install malware yang membuat pengguna komputer melakukan download terhadap sotfware anti-virus palsu. Malware tersebut merupakan botnet yang bernama Waledac. Waledac memungkinkan untuk mencuri password anda dan membuat komputer anda menjadi bot untuk melakukan aktivitas spamming. File yang di-download dideteksi oleh Kaspersky Lab sebagai FraudTool.Win32.SpywareProtect2009.s.

Artikel Terkait:
- Lima Tool Basmi Conficker.
- Situs Pendeteksi Worm Conficker.

sumber:
- eWeek
- F-secure

Wednesday, January 7, 2009

Password Aman dari Ophcrack

Ophcrack adalah tool untuk melakukan crack terhadap password pada sistem Informasi Windows yang menggunakan Rainbow Tables. Prinsipnya adalah Password user yang telah di-hash, diambil dan dipotong-potong menjadi beberapa bagian, kemudian Ophcrack melakukan hash terhadap suatu karakter dan mencocokkan hasilnya terhadapt potongan-potongan hasil hash password user sampai ketemu. Walaupun banyak orang yang mengakui ketangguhan Ophcrack dalam mendapatkan password, ternyata ada tipe-tipe password yang belum bisa di-crack oleh Ophcrack. Info tersebut saya temukan baru-baru ini.

Tipe 1: Password Alphanumeric lebih dari 16 karakter.
Password yang Alphanumeric adalah password yang hanya terdiri dari huruf dan angka saja. Misal, games76hand, mypasswd, atau intrepidibex810. Jika panjang password tersebut lebih dari 16 karakter, maka Ophcrack belum dapat melakukan cracking untuk mendapatkan password. Misal, microsoftfreeware2009.

Tipe 2: Password yang memiliki simbol lebih dari 4
Walaupun password anda kurang dari 16 karakter, asalkan memiliki lebih 4 simbol, password tersebut belum dapat di-crack oleh Ophcrack. Contoh karakter simbol adalah @, #, *, dan %. Contoh yang bisa di-crack: tutorial#win%, dan tutorial**tux. Contoh yang belum bisa adalah @@@my@@pass dan !@#$%loginku.

Ada kemungkinan Ophcrack versi yang akan datang memiliki kemampuan untuk melakukan cracking terhadap tipe 1 dan 2 diatas. Akhir kata, salah satu saran saya untuk menjaga keamanan komputer windows adalah sering melakukan pergantian password.

Sunday, December 21, 2008

Internet Explorer's Serious Problem.

A flaw in IE allow criminals to hack into your computer and steal your passwords. This flaw has already compromised over 10,000 sites since its discovery. According to the Microsoft report, the flaw was in all versions of Internet Explorer. I think it's very very serious problem.

Here are articles that explain about this situation.

http://www.eweek.com/c/a/Security/Hackers-Compromise-Legit-Web-Sites-to-Target-Microsoft-IE-Flaw/

http://news.bbc.co.uk/2/hi/technology/7784908.stm


http://computerworld.com/action/article.do?command=viewArticleBasic&articleId=9123338

Wednesday, December 10, 2008

Kismet - a wireless sniffer and detector

You can't hide your wireless Access Point (AP) from kismet's eye. Kismet will discover every AP within range although with AP has hidden SSID.

Description from site:

What is Kismet

Kismet is an 802.11 layer2 wireless network detector, sniffer, and
intrusion detection system. Kismet will work with any wireless card which
supports raw monitoring (rfmon) mode, and can sniff 802.11b, 802.11a,
802.11n, and 802.11g traffic (devices and drivers permitting).

Kismet identifies networks by passively collecting packets and detecting
standard named networks, detecting (and given time, decloaking) hidden
networks, and inferring the presence of non-beaconing networks via data
traffic.






Feature Overview

Kismet has many features useful in different situations for monitoring
wireless networks:
- Ethereal/Tcpdump compatible data logging
- Airsnort compatible weak-iv packet logging
- Network IP range detection
- Built-in channel hopping and multicard split channel hopping
- Hidden network SSID decloaking
- Graphical mapping of networks
- Client/Server architecture allows multiple clients to view a single
Kismet server simultaneously
- Manufacturer and model identification of access points and clients
- Detection of known default access point configurations
- Runtime decoding of WEP packets for known networks
- Named pipe output for integration with other tools, such as a layer3 IDS
like Snort
- Multiplexing of multiple simultaneous capture sources on a single Kismet
instance
- Distributed remote drone sniffing
- XML output


Typical Uses

Common applications Kismet is useful for:
- Wardriving: Mobile detection of wireless networks, logging and mapping
of network location, WEP, etc.
- Site survey: Monitoring and graphing signal strength and location.
- Distributed IDS: Multiple Remote Drone sniffers distributed throughout
an installation monitored by a single server, possibly combined with a
layer3 IDS like Snort.
- Rogue AP Detection: Stationary or mobile sniffers to enforce site policy
against rogue access points.

check out the documentation and download here

Thursday, December 4, 2008

NetStumbler - Wireless Scanner for Windows

I just want to give you information about wireless hacking tool.

This is a favorite tool of windows user to scan wireless network and found open WEP Access Point. although it can not crack WEP crack, I think this tool is useful.


What is NetStumbler?

NetStumbler is a tool for Windows that allows you to detect Wireless Local Area Networks (WLANs) using 802.11b, 802.11a and 802.11g. It has many uses:

* Verify that your network is set up the way you intended.
* Find locations with poor coverage in your WLAN.
* Detect other networks that may be causing interference on your network.
* Detect unauthorized "rogue" access points in your workplace.
* Help aim directional antennas for long-haul WLAN links.
* Use it recreationally for WarDriving.





General Requirements

The requirements for NetStumbler are somewhat complex and depend on hardware, firmware versions, driver versions and operating system. The best way to see if it works on your system is to try it.

Some configurations have been extensively tested and are known to work. These are detailed at http://www.stumbler.net/compat. If your configuration works but is not listed, or is listed but does not work, please follow the instructions on the web site.

The following are rules of thumb that you can follow in case you cannot reach the web site for some reason.

* This version of NetStumbler requires Windows 2000, Windows XP, or better.
* The Proxim models 8410-WD and 8420-WD are known to work. The 8410-WD has also been sold as the Dell TrueMobile 1150, Compaq WL110, Avaya Wireless 802.11b PC Card, and others.
* Most cards based on the Intersil Prism/Prism2 chip set also work.
* Most 802.11b, 802.11a and 802.11g wireless LAN adapters should work on Windows XP. Some may work on Windows 2000 too. Many of them report inaccurate Signal strength, and if using the "NDIS 5.1" card access method then Noise level will not be reported. This includes cards based on Atheros, Atmel, Broadcom, Cisco and Centrino chip sets.
* I cannot help you figure out what chip set is in any given card.

Firmware Requirements

If you have an old WaveLAN/IEEE card then please note that the WaveLAN firmware (version 4.X and below) does not work with NetStumbler. If your card has this version, you are advised to upgrade to the latest version available from Proxim's web site. This will also ensure compatibility with the 802.11b standard.
Other Requirements and Compatibility Issues

* Your card must be configured in such a way that it can be seen by the management software that came with the card.
* The Microsoft-provided Orinoco drivers that come with Windows 2000 do not work with NetStumbler. Please visit Windows Update or www.proxim.com and upgrade to the latest drivers.
* When NetStumbler is in "auto reconfigure" mode (the default), it will occasionally disconnect you from your network. This enables it to perform its scans accurately, and is not a bug.
* If you have the WLAN card configured to connect to a specific SSID, NetStumbler may not report any accees points other than those that have that SSID. Configure your card with a blank SSID or, if a blank one is not permitted, "ANY" (without quotes).

click here to read more about NetStumbler.

Sunday, November 30, 2008

Virus Sality

Sality adalah suatu virus yang berfungsi sebagai keylogger dan memiliki fungsionalitas backdoor. Sekali tereksekusi, virus tersebut akan menginstall dirinya ke sistem, memerikwa waktu/jam di komputer dan menjalankan payload jika waktu menunjukkan jam = menit.

Sality menginfeksi file executable, menghapus seluruh file yang berhubungan dengan software keamanan komputer seperti anti-virus dan anti-spyware serta firewalls. Kemudian, virus tersebut akan menjalankan fungsinya sebagai keylogger sehingga memungkinkan virus tersebut mengumpulkan data dari komputer korban dan informasi jaringan komputer, meyimpan username dan password korban, mencuri informasi sensitif dan puncaknya adalah mengirim seluruh data tersebut ke email address sang pembuat.

Fungsionalitas backdoor pada sality memungkinkan komputer korban dikendalikan jarak jauh oleh penyusup. Penyusup tersebut kemudian dapat mengontrol sistem dan mencuri informasi sensitif dari korban.

Sality properties:
• Allows remote user connection
• Sends out logs by FTP or email
• Logs keystrokes
• Hides from the user
• Stays resident in background

Menghapus Sality:
- Hapus ketiga file berikut: oledsp32.dll, sysdll.dll, syslib32.dll

Info lainnya:
file-file Sality dapat ditemukan pada folder:
C:\Windows\System, C:\Windows\System32, C:\Winnt\System32 atau di salah satu folder berikut C:\Windows\Temp, C:\Winnt\Temp

Program Penghapus Sality:
Malwarebytes anti malware: download
Windows Defender: download

sumber:
http://2-spyware.com

Saturday, November 22, 2008

PuttyHijack V1.0

I don't know this is bad or good news. With this software, you can hijack SSH/PuTTY connection.

Description from Developer:

PuttyHijack is a POC tool that injects a dll into the Putty process to hijack an existing, or soon to be created, connection.

This can be useful during penetration tests when a windows box that has been compromised is used to SSH/Telnet into other servers. The injected DLL installs some hooks and creates a socket for a callback connection that is then used for input/output redirection.





It does not kill the current connection, and will cleanly uninject
if the socket or process is stopped. PuttyHijack was inspired by the work that Metlstorm did on SSHJack but at this release does not create a new SSH tunnel for the connection.

Details

1) Start a nc listener
2) Run PuttyHijack specify the listener ip and port
3) Watch the echoing of everything including passwords

Some basic commands in this version include;
!disco - disconnect the real putty from the display
!reco - reconnect it
!exit - just another way to exit the injected shell

Name: Putty Hijack
Released: 31 July Feb 2008
Author: Brett Moore, Insomnia Security
Original Link: http://www.insomniasec.com/releases/tools
Operating System: Windows


Monday, October 27, 2008

Virus Denzuko, Antivirus Pertama di Dunia

Virus Denzuko dibuat oleh orang indonesia yang bernama Denny Yanuar Ramdhani pada tahun 1988. Pada awalnya, tujuan virus ini adalah mencari dan menghancurkan virus Brain. Jika ada disket yang terinfeksi oleh virus Brain, maka virus Denzuko akan menghapusnya dan menggantinya dengan virus Den Zuk. Pada disket, Virus Den Zuk biasanya bersembunyi di track 40, namun disket yang berkapasitas 360K normalnya memiliki track 0 sampai 39. Virus ini tidak menginfeksi disket dengan kapasitas 1,2 MB atau disket 3,5" secara sempurna, tetapi akan menghancurkan data di dalamnya. Label volum disket "(c) Brain" pada disket yang terinfeksi virus Brain akan diganti dengan "YùCù1ùEùRùP". Hal ini dikarenakan YC1ERP adalah nama panggilan sang pencipta yaitu, Denny Yanuar Ramdhani.

Pada komputer yang telah terinfeksi virus Den Zuk, menekan Ctrl-Alt-Del membuat komputer tidak akan melakukan reboot / restart, tetapi akan menampilkan tulisan "DEN ZUK". Jika dengan cara lain komputer bisa reboot, virus ini akan tetap tinggal dalam memory komputer. Virus Den Zuk mengubah tombol reboot manjadi Ctrl-Alt-F5.

Virus Den Zuk memiliki varian, yaitu Ohio. Virus Ohio sendiri memiliki nama samaran Hacker. Virus ini merupakan versi lama dari virus Den Zuk dan dibuat oleh orang yang sama. Virus Den Zuk sendiri dapat menghapus virus Ohio ini.

Virus ini tercatat oleh semua lembaga yang terlibat dalam perkembangan virus. IBM sendiri mencatat virus Den Zuk merupakan anti virus pertama di dunia. Selain itu, semua setuju bahwa Den Zuk adalah salah satu peristiwa paling penting dalam sejarah virus komputer dunia. Setelah virus yang sekaligus antivirus ini muncul, anti virus seperti yang kita kenal sekarang mulai muncul. Publikasi tentang sang pencipta virus dimuat di Virus Bulletin edisi Januari 1991.

Deskripsi Virus
Nama : Denzuko
Alias : Den Zuk
Asal : Indonesia
Lahir : 1988
Tipe : Resident Boot Sectors
Repair : No

sumber:
- SDA magazine
- f-secure.com

Kaspersky, Anti-Virus Terbaik saat ini

Beberapa waktu lalu, saya membaca berita tentang antivirus Kaspersky dari koran tempo. Berita tersebut manyatakan bahwa dua produk Kaspersky, Kaspersky Anti-Virus dan Kaspersky internet Security 2009 mendapat nilai tertinggi yang diuji oleh AV-Test.org dan AV-Comparatives.org.

Selain itu, mereka juga menguji 30 anti virus lain. Pengujian dilakukan dengan 1,1 juta malware terbaru dan 95 program yang mengandung spyware dan adware pada sistem operasi Windows XP SP3. Hasilnya, dengan mesin dimiliki Kaspersky, yaitu HIPS (Hosted-based Intrusion Prevention System), mampu menghalau 97,6 % malware dan meraih skor 98,4.

Kalo menurut saya sendiri, lebih baik pakai sistem operasi Linux, 99% komputer anda tidak akan pernah ber-virus. Sebelum kenal dengan Linux, saya biasanya membuat duplikasi terhadap file penting saya sebagai backup jika terkena virus. Dan sejak kenal dengan Linux, saya tidak perlu lakukan duplikasi file.

Tuesday, October 14, 2008

Haxor

Komputer yang tidak dilindungi tembok api (firewall) rawan terkena serangan Haxor.

Istilah cracker atau hacker merupakan istilah yang sering kita dengar. Bagaimana denga haxor? Meski tidak sepopuler dua istilah sebelumnya, dampak perbuatan haxor kadang justru lebih merusak ketimbang cracker atau hacker. Haxor adalah sebutan untuk orang-orang yang memiliki kemampuan yang tinggi di bidang komputer dan gemar berbuat prank, alias usil melalui jaringan atau internet. Kesimpulannya, Tidak peduli firewall, siap-siap saja kehilangan data penting.

referensi:
PCmag

Artikel Terkait

Tuesday, July 8, 2008

IE 8 To Include New Security Tools

Selama ini, Internet Explorer memiliki masalah security. IE6 telah menjadi browser paling tidak aman. Namun, Microsoft telah memperhatikan masalah keamanan pada web browser-nya tersebut. IE 8 versi beta baru yang akan dirilis bulan Agustus memiliki beberapa fitur-fitur security baru, termasuk perlindungan terhadap Type-1 cross-site scripting attacks, filter terhadapt phising yang lebih baik dan sekuritas yang lebih baik untuk ActiveX controls.

Tuesday, June 24, 2008

Lubang Keamanan pada Firefox 3

Walapun firefox 3 sangat diperhatikan keamanannya, ternyata lubang keamanan ditemukan di web browser firefox 3. Tentu saja hal ini akan mempengaruhi 8 juta komputer yang telah men-download dan meng-install-nya. Berikut ini adalah berita yang saya kutip dari softpedia


Since the new release of popular web browser Mozilla Firefox 3.0, over 14 million downloads have been registered by the counter posted on the Spread Firefox website. But just in a few hours (about five) after the Mozilla Firefox 3.0 was made available to the public, security flaws have been reported.
TippingPoint, a provider of network-based intrusion prevention systems, was informed about existing security issues in Mozilla Firefox 3.0 through its program Zero Day Initiative (ZDI) that rewards security researchers for exclusive information disclosing vulnerabilities founded in software products.

Even the new security features of Firefox 3.0 have the main priority to maintain personal information safe and to protect users from phishing and malware, TippingPoint confirms the existence of a critical vulnerability of high severity that affects Mozilla Firefox 3.0 (ZDI ID: ZDI-CAN-349) and prior versions of Firefox 2.0.x: "We verified the vulnerability in our lab, acquired it from the researcher, then promptly reported the vulnerability to the Mozilla security team shortly after. Successful exploitation of the vulnerability could allow an attacker to execute arbitrary code. Not unlike most browser based vulnerabilities that we see these days, user interaction is required such as clicking on a link in email or visiting a malicious web page."

In response to this security report, Mozilla Security Blog posted, "This issue is currently under investigation. To protect our users, the details of the issue will remain closed until a patch is made available. There is no public exploit, the details are private, and so the current risk to users".

If other security reports are taken into account, like the one found on SecurityFocus website which deals with an unspecified buffer overflow vulnerability (boundary condition error), the new security improvements from Firefox 3.0 are not powerful enough for present pishing and malware threats. In conclusion, having in mind that over 14 millions downloads of Mozilla Firefox 3.0 have been performed, users' computers are in potential danger until the security patches are released to fix the existing vulnerabilities.