What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
Reply to this topicStart new topic
> Theory
Coyote
post Mar 4 2005, 10:10 AM
Post #101


AntiSlyware.com
Group Icon

Group: Malware Expert
Posts: 984
Joined: 10-May 03
From: Great Country Of Texas
Member No.: 5
Operating System: ...



If you want to point someone at this post:
http://TomCoyote.org/Theory/
that link will bring you to here

My appologies if anyone takes anything said against thier browser, their surfing, their computer, their dogs or their cats, this is just a conversation that needs to be thought about


[ 09:39:25 ]  [ @Efwis ] I had fun teh other night, was surfing the web for a neildiamond song, got nailed with a major hijacking
[ 09:39:33 ]  [ @Efwis ] *Neil Diamond
[ 09:39:43 ]  [ @Coyote` ] neil will do that to you
[ 09:39:54 ]  [ @Coyote` ] go with Pink Floyd next time
[ 09:40:45 ]  [ @Efwis ] heh, hit me with 180solutions, l2m, 10 viruses 2 trojan downloaders, a java exploit, and a hompage hijack, went right around Moz and nailed IE
[ 09:40:46 ]  [ @Coyote` ] it's a crying shame that no one is safe looking for things nowadays
[ 09:41:12 ]  [ @Efwis ] oh I forgot ISTVbar and sidesearch
[ 09:41:41 ]  [ @Coyote` ] let's say you have IE secure, and you use another browser
[ 09:42:31 ]  [ @Coyote` ] this other browser allows something to happen that bypasses the first block you have built into IE say Iespyads, thus IE is now a target again through this other browser
[ 09:42:44 ]  [ @Coyote` ] this IS just a theory btw
[ 09:42:51 ]  [ @Coyote` ] but it is possible
[ 09:43:31 ]  [ @Coyote` ] now if you go to that same site in IE, nothing happens because your first block stopped it
[ 09:43:45 ]  [ @Efwis ] i'm looked in my IE_Spyad files, this page isn't even listed, although it should be, I think i will contact Eric Howes adn he can add it to his next update
[ 09:44:11 ]  [ @Coyote` ] are you in the classroom?
[ 09:44:18 ]  [ @Efwis ] yeah, your theory has merit adn is probably quite accurate
[ 09:44:22 ]  [ @Efwis ] yes I am
[ 09:44:32 ]  [ @Coyote` ] have you been keeping up with wng_z3r0's problem that I have posted to?
[ 09:44:45 ]  [ @Efwis ] no, got a link?
[ 09:44:53 ]  [ @Coyote` ] http://forums.tomcoyote.org/index.php?act=...ndpost&p=137765
[ 09:45:08 ]  [ @Coyote` ] took 4 pages of posts to finally get to the root of the problem
[ 09:45:26 ]  [ @Efwis ] looking
[ 09:45:41 ]  [ @Coyote` ] his shell browser covering IE allowed something IE wouldn't
[ 09:46:31 ]  [ @Coyote` ] not so much a theory anymore
[ 09:48:00 ]  [ @bozodog ] are you saying that Mozilla can let stuff through to IE and beyond?
[ 09:48:50 ]  [ @Coyote` ] I am not saying anything about moz, I am saying it is a possibility that an alternate browser can let things bypass to IE and therefore cause problems
[ 09:49:44 ]  [ @Coyote` ] and by them bypassing to IE, IE's protections can be bypassed that normally wouldn't if IE was in use instead of the alternate
[ 09:50:29 ]  [ @bozodog ] err.. I think I understand
[ 09:51:01 ]  [ @Coyote` ] it's like a layer effect, you have layers of protections you set in place, using an alternate browser, you can possibly bypass a layer
or two which in turn can lead to your being infected
[ 09:51:36 ]  [ @Coyote` ] it may not go in the front door but it might find a side window
[ 09:51:37 ]  [ @bozodog ] Ahh..
[ 09:52:45 ]  [ @Coyote` ] I won't say that it is possible with any particular browser, I think in fact it may be possible with any browser
[ 09:53:03 ]  [ @Coyote` ] but this is only theory at this point
[ 09:53:24 ]  [ @Coyote` ] some script kiddie will strive to make it happen on a regular basis eventually
[ 09:54:10 ]  [ @bozodog ] sounds like a solid thought... they are getting better at mucking up our systems..
[ 09:54:36 ]  [ @Coyote` ] well, the problem itself goes back to windows,
[ 09:54:53 ]  [ @Coyote` ] windows is made to accomodate users of limited knowledge
[ 09:55:06 ]  [ @bozodog ] but doesn't your AV, etc... do it's job in that case?
[ 09:55:09 ]  [ @Coyote` ] so that in itself is preyed upon by the kiddies
[ 09:55:36 ]  [ @Coyote` ] AV is only one part of an overall solution and it lacks a great deal of the overall protection
[ 09:56:07 ]  [ @Coyote` ] the AV chosen also plays a part in how that is defined
[ 09:56:42 ]  [ @Coyote` ] several AV's have weak real time scanning engines that fail at the sight of any infection
[ 09:57:15 ]  [ @Coyote` ] real time scanning engines are the only way to truly combat virus and trojans
[ 09:57:28 ]  [ @bozodog ] I only use Avast free... and spywareblaster etc..
[ 09:57:42 ]  [ @Coyote` ] I have not tried Avast
[ 09:57:51 ]  [ @Coyote` ] so I cannot comment on it
[ 09:58:27 ]  [ @bozodog ] it sure updates often, (2-3 times a day at times)
[ 09:58:51 ]  [ @Coyote` ] I hope that is because they are adding to the database and not correcting mistakes
[ 09:58:58 ]  [ @bozodog ] and scares the heck outa me when some baddie trys to get in
[ 09:59:15 ]  [ @bozodog ] yeah, it's data
[ 09:59:34 ]  [ @Coyote` ] well, you can't tell from the updating
[ 09:59:53 ]  [ @Coyote` ] you would have to disect each dataflow
[ 10:00:03 ]  [ @Coyote` ] and know what coding they use
[ 10:00:51 ]  [ @Efwis ] from looking at that post, i wouold say you are correct Tom, no longer a theory but a proven fact
[ 10:01:15 ]  [ @bozodog ] of course I don't surf the back alleys, or p2p stuff
[ 10:01:24 ]  [ @Coyote` ] well, fact for his situation, theory for other browsers at this point
[ 10:01:52 ]  [ @Coyote` ] bozodog look at what happened to Efwis looking for a neil diamond song
[ 10:01:59 ]  [ @Efwis ] based on what happened to me its a fact for Moz too
[ 10:02:01 ]  [ @bozodog ] yep
[ 10:02:30 ]  [ @bozodog ] do you use Moz of FF?
[ 10:02:31 ]  [ @Coyote` ] I hate it when I am correct about some of these theories but I am right too many times
[ 10:02:48 ]  [ @Efwis ] i went there with my IE yesterday, nothing happened, all my protections worked correctly
[ 10:03:13 ]  [ @bozodog ] you're like a hound dog.. you can sniff out problems
[ 10:03:13 ]  [ @Efwis ] so I am inclined to believe it is something actually programmed into the html code
[ 10:03:40 ]  [ @Efwis ] he is good at what he does, and I like his info, because he usually is correct bd
[ 10:04:23 ]  [ @bozodog ] don't I know it... he knows I have the highest respect for what he says
Go to the top of the page
 
+Quote Post

Posts in this topic
- Coyote   Theory   Mar 4 2005, 10:10 AM
- - The Computer Valet   If I buy new antivirus software today, perform a s...   Mar 20 2005, 09:07 PM
- - Zero   That depends on your defintion of 'infected...   Mar 20 2005, 10:05 PM
- - Zero   Thats a bummer, but I never charge anyone for fixi...   Mar 20 2005, 11:05 PM
- - Paperghost   Well, back to the install at hand. After some dis...   Mar 21 2005, 03:06 AM
- - Paperghost   okay, i think i found something. i just posted thi...   Mar 21 2005, 05:55 AM
- - Zero   Yea... because an applet doing what its told is a ...   Mar 21 2005, 07:05 AM
- - Paperghost   QUOTE(Zero @ Mar 21 2005, 01:05 PM)Yea... bec...   Mar 21 2005, 07:10 AM
- - ThaCrip   well i did NOT get ANY popups whatsoever when goin...   Mar 22 2005, 01:50 AM
- - Paperghost   Nod is VERY good at blocking most (if not all) of ...   Mar 22 2005, 11:38 AM
- - LostAccount   This is not a flaw in a browser, but what you are ...   Apr 9 2005, 10:43 PM
- - Paperghost   QUOTE(LostAccount @ Apr 10 2005, 04:43 AM)Thi...   Apr 11 2005, 01:06 PM
- - Paperghost   Okay, this is an amazing read - Wayne Porter of X-...   Apr 11 2005, 10:58 PM
- - Avohir   the saga continues? I thought this whole bloody J...   Apr 11 2005, 11:09 PM
- - Paperghost   QUOTE(Avohir @ Apr 12 2005, 05:09 AM)the saga...   Apr 12 2005, 02:13 AM
- - LostAccount   I still don't get how what the SpywareGuide we...   Apr 13 2005, 09:28 AM
- - Paperghost   QUOTE(LostAccount @ Apr 13 2005, 03:28 PM)I s...   Apr 14 2005, 12:03 AM
2 Pages V  < 1 2


Reply to this topicStart new topic

 

RSS Time is now: 19th March 2010 - 07:58 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy