Translate To:
[code via DI]
Flash Updates
Making Of
Tips Tricks Hacks
Fantastic FREEBIES
Hacking Tips To Be Safe
Get Back 'Folder Options'
Capture Screenshots In Windows Media Player
Best Anti Virus
Checking Processor Speed
Computer Keeps Restarting
Orkut Scraps As RSS
Cheapest Data Recovery
Easy Fast Uploading
Convert Video Formats
Hidden Tool In XP
Secure Your Network
Notepad Alternative
Google Tips
Search Google Without Ads
Google Advanced Search
Hidden Google Pages
10 Google Myths
FREE Stuff Via Google
FREE Torrent Files Via Google
Firefox & IE Tweaks
Fullscreen in Firefox
20 Firefox Extensions
Preview Tabs In Firefox
Firefox Search Result In New Tab
Run Google Talk In Firefox Sidebar
Speed Up Internet In FireFox
Increase Number Of Simultaneous Downloads In IE7
Vulnerabilities Found
Use Google Video To Hack Password
YouTube Could Be Used To Hack Computer
Yahoo Messenger 8.0+ Vulnerability
A Note About
Reviewed
Beware: Malware Will Delete All Your MP3 Collection!
This Article Is Sponored By You! | Friday, August 3, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
A recent article on computerworld suggests that the creators of this malware are more likely to be teenage mischief-makers than the organized criminal gangs we typically see authoring financially motivated malware these days.
Symantec Corp., which calls the worm W32.Deletemusic, said in an advisory that the worm copies itself to all drives on a PC. It also creates an autorun file to start itself whenever a user accesses a drive.
The worm affects PCs running Windows 2000, 95, 98, Me, NT, Server 2003, XP and Vista, Symantec said. To block potential problems users could disable the autorun feature in Windows that automatically launches programs on CDs or USB drives.
Users could also exercise caution by holding down the SHIFT for a few seconds in order to deactivate the Autorun function when they plug in USB sticks or other removable media to their computers or when they insert a disk. Users should also make regular backups for their critical data by burning DVDs or using automated backup tools.
More:
Making of MP3
Must Read Hacking Tips To Be Safe
Use Google Video To Hack Password
YouTube Could Be Used To Hack Computer
Technorati Tags: Deletemp3, malware, worm
Labels: bugs found, security
Internet Explorer Hit With Another Vulenrability
This Article Is Sponored By You! | Monday, July 16, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
The vulnerability is caused due to an error in the handling of the "document.open()" method and can be exploited to spoof the address bar if e.g. the user enters a new website manually in the address bar, which is commonly exercised as best practice.
Older versions might be also be affected but there are no reports available yet. This vulnerability is extremely important for the Redmond company as its top browser, Internet Explorer 7 is involved into the battle with Firefox and other applications for the leader position of the category.
Solution:
Close all browser windows after visiting untrusted websites.
Technorati Tags: internet explorer vulnerability
Labels: bugs found, ie, microsoft
Warning: Google Video Could Be Used To Hack Your Password
This Article Is Sponored By You! | Tuesday, June 12, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
In short this users find says that Google is passing private information which includes MySpace, LiveJournal, Blogger, and TypePad login details over insecure channels. And since Blogger accounts sometimes use Google Accounts for login, such a flaw could expose a user’s GMail, Google AdWords, Google AdSense, and maybe even Google Checkout information (unless this information is encrypted).
When a friend sent me a link to this rather boring video http://video.google.co.uk/videoplay?...85184878490822 I immediately noticed the 'Email - Blog - Post to Myspace' link on the right side. As any curious person would do I decided to check it out to see how Google has integrated with MySpace.
So after clicking I was greeted with the following popup http://video.google.co.uk/blogpost?d...22&siteindex=3 and immediately noticed that the url of it was http, and not https. An insecure form... So I figured it must be posting the login details to a https url, so I pulled out live headers and this is what I got:
http://video.google.co.uk/blogpost
POST /blogpost HTTP/1.1
Host: video.google.co.uk
User-Agent: Mozilla/5.0 (Windows; U;
Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
Accept: text/xml,application/xml,application/xhtml+
xml,text/html;q=0.9,text/plain;q=0.8,
image/png,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Referer: http://video.google.co.uk/blogpost?d...22&siteindex=3
Content-Length: 42
Cookie: PREF=ID=26c938172fc51030:TM=1178041215:
LM=1138046118:S=Bw_pBCzx-opEyR3s; sloc=en_GB
Pragma: no-cache
Cache-Control: no-cache
req=login&name=myusername
&pass=mypassword&site=MySpace
The private and sensitive information is being passed without SSL, which is a basic and common step in the Internet security process.
Related:
Warning: YouTube Could Be Used To Hack Your Computer
Google Desktop Vulnerable To Attack
Search Google Without Google Ads
Awesome Hidden Google Pages
Labels: bugs found, google
Warning: YouTube Could Be Used To Hack Your Computer
This Article Is Sponored By You! | by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
"The other day we ran into a new technique that makes and attempt to distract the user into viewing a new YouTube video. The application uses the movie icon when it gets downloaded to the machine but strictly relies on deception to get you to run it.The file is called YouTube04567.exe and was hosted on a web server in the .SU domain (Soviet Union). Although we captured this code through on the web, our guess is that there are email and/or instant messaging lures for this URL in the wild," mentions the Websense Blog.
One should learn that executable files that are claiming to be YouTube clips can NOT be YouTube clips by any means. Also, keep in mind that YouTube is a clean website and it doesn't deliver any type of threat; so don't be afraid that you might get infected while you're viewing clips on the online video sharing service. Still, try to keep your antivirus updated and your firewall enabled.
Related:
Find Out Who Is Watching A Certain Video In YouTube
Want Fame? YouTube Will Give You That
Use Adobe Video Player To Watch Online Video Offline
Can You Predict YouTube's Age?
Labels: bugs found, youtube
IITk Website Hacked
This Article Is Sponored By You! | Thursday, June 7, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
NOTE: My intention behind posting this article is just to show to Internet users the innovation the hacker used and by no means I am challenging the name of IITs which I know will always remain the best. I love IITs.
Related:
Hacking - The Must Learn Tips To Be Safe
Hackers Attack Gorbachevs Website
Labels: bugs found, fun
WARNING: Yahoo Messenger 8.0 & Above Highly Vulnerable To Attacks
This Article Is Sponored By You! | Wednesday, June 6, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
Yahoo messenger, the most famous chatting messenger available is again providing open vector for hackers to gain access to your system and that too with minimal user interaction.Date Reported:
June 5, 2007
Vendor:
Yahoo, Inc
Description:
Multiple flaws exist within Yahoo! Messenger which allow for remote execution of arbitrary code with minimal user interaction.
Severity:
High
Remote Code Execution:
Yes
Software Affected:
Yahoo! Messenger 8.x
Operating Systems Affected:
Windows
Status:
June 5, 2007: Vulnerability reported to vendor
Reporter:
eEye Digital Security
UPDATE: [June 10, 2007]
Yahoo has has pushed out a fix to plug the bugs found. Go get them.
Related:
IE7 & FireFox SCARY Vulnerability
Linux Kernel Vulnerability
Adobe Vulnerability
MS Office Vulnerability
Labels: bugs found, yahoo
Google Desktop Vulnerable To Attack
This Article Is Sponored By You! | Tuesday, June 5, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
The attack scenario plays out like this: a user of Google Desktop makes a search query that is intercepted by an attacker. The attacker then injects Javascript that creates an invisible IFrame on the target URL page as well as makes the IFrame follow the user's mouse; the user is unaware. The attacker then injects more code to position a second query inside the user mouse IFrame. As the second query executes, the attacker then forces a meta-refresh to reload the page, and that forces Google Desktop to load as well as any program indexed by Google Desktop the attacker may desire. When user clicks the evil Google Desktop query, the malicious program executes.
Hansen writes: "This should drive home the point that deep integration between the desktop and the Web is not a good idea" since Google's site is unencrypted and therefore can be subverted by an attacker. But Hansen notes there are two caveats here: one, you need to have Google Desktop installed, and two, the attacker must be sophisticated enough to launch a man-in-the-middle attack upon you.
Related:
Search Google Without Ads
Hidden Google Pages
IE7 & FireFox SCARY Vulnerability
FREE Torrent Files Via Google
Labels: bugs found, google
Google Behaving Awkwardly
This Article Is Sponored By You! | Sunday, May 13, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
Check more bugs discovered at CompuWorld here.
Subscribe to CompuWorld by Email to receive cool latest updates.
Related:
Hidden Google Pages - Awesome
10 Google Myths
Labels: bugs found, google
US Census Bureau Helps Hackers By Posting 63,000 Social Security Numbers Online
This Article Is Sponored By You! | Sunday, April 22, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
For more than a decade, the Census Bureau posted on a public Web site the Social Security numbers of 63,000 people who received financial aid, officials said yesterday. The apparent violation of federal privacy law prompted concerns about identity theft.Government officials removed the data from the Web site on April 13, the day they were alerted to the breach by an Illinois farmer who discovered the numbers while surfing the Internet. They did not publicize the matter until yesterday, saying they needed the delay to enable information-security officials to contact those whose numbers were revealed and to contact "at least a half-dozen" mirror sites.
"We take full responsibility for this and offer no excuses for it," said Terri Teuber, a spokeswoman for the U.S. Department of Agriculture. "We absolutely do not think it was appropriate."
A watchdog group countered that officials tried to suppress the news.
"The bottom line is the government screwed up," said Gary Bass, executive director of OMB Watch. "What's really important is that they now try to rectify the problem. Thousands of research groups have copies of this site."
Government officials said they knew of no misuse of the personal data, but the breach underscores the ease with which such data can be exposed in the digital age.
Image Source: uts
Technorati Tags: hacking, USA helps hackers
Labels: bugs found
Linux Kernel IPv6 Sockets DoS Vulnerability
This Article Is Sponored By You! | Friday, March 23, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
Affected Software
Linux Kernel versions 2.6.x
Description
This issue has been rated as low risk and can only be exploited locally and not remotely.
Workaround Available
http://www.marc.info/?l=linux-netdev&m=117406721731891
References
References for this kernel vulnerability can be found here and here.
See more bugs discovered in CompuWorld here. And helpful tips here.
Subscribe for latest updates here.
Labels: bugs found, linux, security, tips tricks and hacks
"Google Advisory" Points To Broken Link & Expects You To Learn About Computer Security From It
This Article Is Sponored By You! | Thursday, March 8, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
Now while searching for winantivirus pro on Google the first link as usual led me to the google advisory page and suggested me NOT to visit the website. That page asked me to visit StopBadware.org (the actual broken link) to learn about harmful web content and to secure my computer. But this actually led me to a broken link page of stopbadware's website.
So, good to see that Google is fighting with harmful web content they are missing out with something. They want there readers to learn about harmful web content and how to secure there computers from a "broken link"? I am in a state to say . . . nothing.
Related:
Google Searches In 0.00 Seconds
Hidden Google Pages - Awesome
Advanced Google Search For Better Search Results
10 Google Myths
Labels: bugs found, google
Scary Vulnerabilities In IE7 And Firefox 2.0
This Article Is Sponored By You! | Tuesday, February 27, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
This is scary. I could see my boot.ini file online? Huh. The common vulnerability makes it clear that the flaw in programming could be used for some dangerous works over the Internet.Affected Software
Internet Explorer 7
Internet Explorer 6
Internet Explorer 5.01
FireFox 2.0.0.2
FireFox 1.5.0.9
Description
"Both examples are Windows-specific, and require C:BOOT.INI to exist and be readable by users. The attack itself is not limited to a particular operating system, but I decided to provide a demonstration for most popular desktop OS - *nix versions that access /etc/hosts or /etc/passwd are easy to develop,” Zalewski, one who found the vulnerability, stated.Workaround Available
“In all modern browsers, <"INPUT TYPE=FILE"> form fields (used to upload user-specified files to a remote server) enjoy some added protection meant to prevent scripts from arbitrarily choosing local files to be sent, and automatically submitting the form without user knowledge. For example, “.value” parameter cannot be set or changed, and any changes to .type reset the contents of the field,” added Michal Zalewski.
User interaction is a must if both vulnerabilities are to be successfully exploited. In this context, the user would have to enter text in malformed areas on a web page, either from IE or FireFox. Zalewski explained that the keyboard input in unrelated locations can be selectively geared toward input fields by the attacker.
No real workaround looks to be available currently but we will keep you updated with the latest news.
Microsoft on one side was shouting that there IE7 is free of vulnerabilities while FireFox was busy releasing patches this month. Now this kick will surely add to there wounds. Let us wait and see how they react.
Source: Softpedia
Technorati Tags: internet explorer, firefox, vulnerability in IE and firefox
Labels: bugs found, firefox, firefox tips, ie, microsoft
Vulnerability In Versions 7.08 And Earlier Of Adobe Reader And Acrobat
This Article Is Sponored By You! | Wednesday, February 21, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
A vulnerability has been reported in Adobe Reader. It is caused due to an unspecified error when processing pdf files.Related Software Versions
Adobe Reader 7.0.8 and earlier versions
Adobe Acrobat Standard, Professional and Elements 7.0.8 and earlier versions
Adobe Acrobat 3D
Description
Workaround Available [via Adobe Security Advisories]
Related:Adobe Reader on Windows
Adobe strongly recommends upgrading to Adobe Reader 8, available from the following site:
http://www.adobe.com/go/getreader.Users with Adobe Reader 7.0 through 7.0.8, who cannot upgrade to Reader 8, should upgrade to Reader 7.0.9. Adobe Reader 7.0.9 is available as a full installation package and not a patch. It can be installed on top of any older version of Reader 7 and user preferences will be preserved:
http://www.adobe.com/go/getreader.If customers are using Adobe Reader 6.0–6.0.5 and are unable to upgrade to version 8 or 7.0.9 due to Operating System constraints for example, Adobe recommends upgrading to version 6.0.6 either via a series of patches from: http://www.adobe.com/downloads or by using the auto-update mechanism within the product when prompted.
Adobe Reader on Mac OS
Adobe strongly recommends upgrading to Adobe Reader 8, available from the following site: http://www.adobe.com/go/getreader.Users with Adobe Reader 7.0 through 7.0.8, who cannot upgrade to Reader 8, should upgrade to Reader 7.0.9. The Reader 7.0.9 update requires that Adobe Reader 7.0.8 is installed on your Mac system. To determine which version of Adobe Reader is installed, choose Adobe Reader > About Adobe Reader. The version number appears in the upper left corner below the Adobe Reader logo.
If version 7.0.8 is installed, download and install this incremental patch.
After downloading the update file, double-click it to begin the update process and access the file's contents.
If version 7.0, 7.0.1, 7.0.2, 7.0.3, 7.0.5, 7.0.7 or an earlier version of Reader is installed and customers cannot update to Reader 8, Adobe recommends that customers download the full Adobe Reader 7.0.9 installer from the Reader download page.Adobe Acrobat on Windows or Mac OS
For version 7.0–7.0.8, users should utilize the product's automatic update facility. The default installation configuration runs automatic updates on a regular schedule, and can be manually activated by choosing Help > Check For Updates Now. Alternatively, the update files can also be manually downloaded and installed from www.adobe.com/downloads.If customers are using Adobe Acrobat 6.0–6.0.5 for Windows and are unable to upgrade to version 8 or 7.0.9 due to Operating System constraints for example, Adobe recommends upgrading to Windows version 6.0.6 either via a series of patches from: http://www.adobe.com/downloads or by using the auto-update mechanism within the product when prompted.
Adobe Reader on UNIX
For version 7.0, users should upgrade to Adobe Reader 7.0.9 from http://www.adobe.com/go/getreader.For versions prior to 7.0, users should upgrade to 7.0.9 http://www.adobe.com/go/getreader.
Server-side workarounds for website operators
Adobe has provided workarounds for website operators to prevent the cross-site scripting vulnerability (CVE-2007-0045) from the server side. Please review Security Advisory APSA07-02 for more information.
Vulnerability In MS Office
25th Birthday Of Virus
Hackers Attacked Gorbachev's Website
Labels: adobe, bugs found, security, tips tricks and hacks
Vulnerability In MS Office Could Give Access To Your Computer
This Article Is Sponored By You! | Saturday, February 3, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
Related Softwares:
Microsoft Office 2000, Microsoft Office XP, Microsoft Office 2003, and Microsoft Office 2004 for Mac are the softwares found vulnerable.
What can cause the vulnerability:
When a user opens a specially crafted Office file using a malformed string, it may corrupt system memory in such a way that an attacker could execute arbitrary code.
An attacker can somehow request you to click on some link which will take them to attackers site to download some office document. Otherwise the office document could be sent via email. Downloading the office document to your machine would help attacker corrupt the system memory in such a way that it can gain access to your computer.
Workaround available:
Do not open or save Office files that you receive from un-trusted sources or that you receive unexpectedly from trusted sources. This vulnerability could be exploited when a user opens a specially crafted Office file.
Microsoft is developing a security update for Office that addresses this vulnerability. It should be available soon.
Technorati Tags: zero day, Microsoft Office vulnerability
Labels: bugs found, microsoft, security, tips tricks and hacks
25th Birthday of Virus
This Article Is Sponored By You! | Sunday, January 28, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
First thought: "25 years? Aaaah I'm old!"
Fortunately I still regularly get the feeling I had back when I wrote cloner.
"Why did I do it", a reporter asked. "Was it malicious?"
No, not malicious. It was a practical joke combined with a hack. A wonderful hack.
Back then nothing was networked. We had these computers in a lab, and there was software for them on floppy disks. You stick in the disk and run the software. Simple.
The aha moment was when I realized I could essentially get my program to move around by itself. I could give it its own motive force, by having it hide in the resident RAM of the machine between floppy changes, and hitching a ride onto the next floppy that would be inserted. Whoa. That would be cool.
Insight without implementation is worthless, so to work I went.
Elk Cloner: The program with a personality
It will get on all your disks
It will infiltrate your chips
Yes it's Cloner!
It will stick to you like glue
It will modify RAM too
Send in the Cloner!
Technorati Tags: Elk Cloner, 25th Birthday of Virus, virus, hacking
Labels: announcements, bugs found, security
Hackers Attack Gorbachevs Web site
This Article Is Sponored By You! | Sunday, January 21, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
There you go, another victim of hacking for revenge.Hackers attacked the Web site of a foundation run by former Soviet leader Mikhail Gorbachev, accusing him of brutally suppressing a pro-independence demonstration in Soviet Azerbaijan in 1990.
The perpetrators posted photographs of the suppressed rally on the Web site and published an open letter to the former leader, blaming him for the deaths of more 130 people — a tragedy known in Azerbaijan as the Black January.
The site was down by Saturday afternoon.
Fueled by the conflict over the disputed territory of Nagorno-Karabakh, a mountainous region inside Azerbaijan populated mostly by ethnic Armenians, pogroms broke out against Armenians in Azerbaijan's capital Baku in January 1990, forcing Soviet troops to intervene and evacuate many Armenians.
Thousands rallied in Baku demanding the ouster of communist officials and independence from the Soviet Union, causing Soviet troops to storm the capital late at night on Jan. 19, 1990.
Shootings and violent clashes lasted several days, leaving 134 people dead and more than 770 wounded. International rights groups said the force used against the demonstrators was excessive and disproportionate.
Azerbaijan gained independence in 1991 after the Soviet collapse.
Awarded the Nobel Peace Prize in 1990, Gorbachev maintains an active public life running the Gorbachev Foundation — an organization that deals with international issues including globalization, security, weapons of mass destruction, environmental and natural resources and poverty.
Technorati Tags: Gorbachevs website hacked
Labels: announcements, bugs found
Google Searches In 0.00 Seconds
This Article Is Sponored By You! | Monday, January 1, 2007 by Salman Siddiqui | CommentsI am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
Now it seems that the time is not far away when google will return search results in negative time i.e. even before you think of searching! I hope here I havent made any blunder as I really trust google a lot.
Update (14th March 2007): Google has corrected the bug in there book search and now it displays the proper timings.
Related:
Hidden Google Pages - Awesome
Labels: bugs found, google
I Left Google Blogger! - Posted on Wednesday, September 5, 2007
Meet A Huge New World Of Bloggers And Get Paid For... - Posted on Saturday, August 11, 2007
Windows Vista SP1 Screenshots Leaked - MS Won't Co... - Posted on Wednesday, August 8, 2007
Earn "6 Times" More With Your AdSense Very Easily - Posted on Tuesday, August 7, 2007
Qualtiy Cartridges With Prices Cheaper Than Your F... - Posted on Tuesday, August 7, 2007
xxxdisc.net is Google's Look Like By All Means - Posted on Monday, August 6, 2007
Mac Games And "A Lot" More Is A Must Stop For Appl... - Posted on Sunday, August 5, 2007
Buy iPhone For "99 cents" On August 9th 2007 At 99... - Posted on Saturday, August 4, 2007
Your Site 'Listed On Top' In Google Search Results... - Posted on Saturday, August 4, 2007
This Article Is Sponsored By YOU! - Posted on Saturday, August 4, 2007
Moved
I am now blogging on my self hosted blog CompuWorld and started another blog of mine the Senorita
Money Makers
Get Paid For Blogging..Yess! Stumble & Earn
JobThread
GoalGuru
BlogsVertise
ReviewMe!
Copeac
BidVertiser
AdBrite


