<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Dave&#039;s Tech Blog &#187; Security</title>
	<atom:link href="http://davestechsupport.com/blog/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://davestechsupport.com/blog</link>
	<description>A Third Eye on Technology</description>
	<lastBuildDate>Thu, 17 May 2012 10:34:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Some of Norton Antivirus&#8217; source code has leaked</title>
		<link>http://davestechsupport.com/blog/2012/01/07/some-of-norton-antivirus-source-code-has-leaked/</link>
		<comments>http://davestechsupport.com/blog/2012/01/07/some-of-norton-antivirus-source-code-has-leaked/#comments</comments>
		<pubDate>Sat, 07 Jan 2012 16:00:43 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/?p=1431</guid>
		<description><![CDATA[Heads up Norton users!  A headline hit the news last night about the confirmed leak of source code for the popular Norton Antivirus software by Symantec.  You can read the articles for yourself here and here. For those who aren&#8217;t tech savvy, the word &#8220;source code&#8221; refers to the so-to-speak &#8220;recipe&#8221; for the development/creation of [...]]]></description>
			<content:encoded><![CDATA[<p>Heads up Norton users!  A headline hit the news last night about the confirmed leak of source code for the popular Norton Antivirus software by Symantec.  You can read the articles for yourself <a title="Wired Magazine" href="http://www.wired.com/threatlevel/2012/01/symantec-source-code-leaked/" target="_blank">here</a> and <a title="Security Watch" href="http://securitywatch.pcmag.com/none/292432-report-symantec-confirms-theft-of-norton-antivirus-source-code" target="_blank">here</a>.</p>
<p>For those who aren&#8217;t tech savvy, the word &#8220;source code&#8221; refers to the so-to-speak &#8220;recipe&#8221; for the development/creation of a program.  It is literally the instructions that are more or less written by computer programmers.  This kind of information is proprietary and is often a trade secret, much like the coveted ingredients list for Coca Cola or my moms apple pie.  If one were able to obtain such information, say a competator or the creators of compuer viruses, one might use this information to one-up the software or, more importantly, exploit design flaws to circumvent the software.  In short this means it is quite likely there will be a new breed of viruses on the horizon that will be capable of outsmarting Norton, rendering it useless and crippled.</p>
<p><a href="http://davestechsupport.com/blog/wp-content/uploads/2012/01/symantecblueprint.png"><img class="aligncenter size-full wp-image-1432" title="symantecblueprint" src="http://davestechsupport.com/blog/wp-content/uploads/2012/01/symantecblueprint.png" alt="" width="500" height="333" /></a></p>
<p>Symantec has been trying to downplay the severity of this breach by stressing the age of the code, stating that the origin is a version of their software that dates back to 2006, or so we&#8217;ve been told thus far.  This is an attempt to defuse the concern by implying that their latest software is far different at its core and that there won&#8217;t be very much that is useful to virus writers because they still don&#8217;t have their hands on the latest blueprints.  But the reality of the situation is far less peachy than they would like to paint it.  In the world of computer programming software and even entire operating systems will retain a fair chunk of old code from previous versions simply because, well, it&#8217;s already been written and if it &#8220;works&#8221; then there&#8217;s little need to rewrite it from scratch.  I&#8217;m not saying source code is never rewritten, revised or updated from time to time, but when it comes to large programs such as Norton Antivirus that&#8217;s made up of tens of thousands of lines of code it could easily be argued that there is likely a good percentage of old code that has been retained for years without ever being modified.  It would be like having a castle or fortress that is under continuous construction and maintenance.  You can&#8217;t afford to tear the whole thing down every year and rebuild it from scratch, so instead what you do is build around and upon the existing structure and make repairs to the parts that need repairing the most.  This means that likely most of the fundamental structure is retained and knowledge of the construction of such a structure could be used by an enemy to find a previously unnoticed vulnerability.</p>
<p>In the interest of full disclosure I will have to admit that Norton hasn&#8217;t been on my list of recommended software since the late 90s when it was practically the only anti-virus software available.  It&#8217;s early bird status was followed by years of successful marketing and advertising, which lead to its continuous wide spread recognition of the software/brand name, giving the impression to novice computer users that Norton really is the best thing out there.  &#8221;How could it not be good when its so popular?&#8221; they might ask themselves.</p>
<p>I am here to tell you that the number one problem I fix for people in this line of work is virus removal and far too often I see systems that are running Norton that have become utterly trashed by multiple viruses while Norton gives inaccurate scan results, claiming the system is clean and virus free.  This is particularly irksome to me because when you consider the wide spread saturation of their software along with the monetary cost to the users for the renewal every year you would have to expect the company to use their position and resources to everyones benefit.  Despite its wide spread usage and price tag it fails to survey new viruses and develop new definitions for capturing and stopping them in an effective manner and so many users never seem to get their moneys worth.  I am willing to give the benefit of the doubt and accept the fact that there is no such thing as a &#8220;perfect&#8221; antivirus software, but you should expect to be given better treatment and results if you&#8217;re paying upwards of $70 a year for protection, especially when there are free alternatives out there that have been statistically shown to do a comparatively better job.  And to think these kinds of problems existed before some of their source code leaked.  Now that some source code has leaked and the potential for new viruses to be developed to exploit Norton itself are likely right around the corner I feel obligated to suggest that people avoid using it all together.  No amount of marketing or PR can change the consensus of most IT professionals who can see past all the BS and to me this incident is more than just one more nail in the coffin.</p>
<p>So what do I recommend instead of Norton?  I mentioned that there is &#8220;no such thing as a perfect antivirus&#8221; but there are alternatives that hold a higher reputation than Norton that cost a fraction of what Norton costs or even nothing at all.  In <a title="Strategies for removing viruses and malware" href="http://davestechsupport.com/blog/2011/11/06/strategies-for-removing-malware-and-viruses/" target="_blank">past blog entries</a> I&#8217;ve mentioned Microsoft Security Essentials, Malwarebytes and Combofix and still recommend them, so here&#8217;s a little information about them.</p>
<p><a href="http://davestechsupport.com/blog/wp-content/uploads/2012/01/mse1.jpg"><img class="aligncenter size-full wp-image-1433" title="mse1" src="http://davestechsupport.com/blog/wp-content/uploads/2012/01/mse1.jpg" alt="" width="500" height="415" /></a></p>
<p>Microsoft Security Essentials is a free antivirus solution that Microsoft itself actually produces and it&#8217;s quite popular in the IT community right now for a couple of reasons.  I already mentioned that its free but it is also effective and not as resource intensive as other software.  There&#8217;s also a new <a title="Microsoft Standalone System Sweeper" href="http://connect.microsoft.com/systemsweeper" target="_blank">stand-alone bootable version</a> of it that&#8217;s going through public beta testing right now which is handy to have for particularly difficult viruses.  You can read more about it <a title="Wikipedia" href="http://en.wikipedia.org/wiki/Microsoft_Security_Essentials" target="_blank">here</a>.  Be aware that there has, in the past, been a rogue malware impostor simply called &#8220;Security Essentials 2010/2011/2012&#8243; which people have confused with the real deal, falling victim to a trap.  You can download the real deal from <a title="MSE download" href="http://windows.microsoft.com/en-US/windows/products/security-essentials" target="_blank">here</a>.</p>
<p><a href="http://davestechsupport.com/blog/wp-content/uploads/2012/01/mbam.png"><img class="aligncenter size-full wp-image-1434" title="mbam" src="http://davestechsupport.com/blog/wp-content/uploads/2012/01/mbam.png" alt="" width="500" height="385" /></a></p>
<p>Along side MSE I also recommend users purchase the full copy of Malwarebytes for the one time payment of $25.  Some of the handy features it has is an active connection monitor which will automatically block your computer from attempting to connect to known malicious web servers.  It also features an active process monitor like a traditional antivirus and will help prevent a good number of rogue malware type software from infecting your system.  There is a free version of this available but its active monitoring features are disabled. I&#8217;ve been using it in the field for over 2 years now and it has worked incredibly well for helping clean systems that had already become infected.  You can read more about it <a title="Malwarebytes - Wikipedia" href="http://en.wikipedia.org/wiki/Malwarebytes'_Anti-Malware" target="_blank">here</a> and download/purchase it from <a title="Malwarebytes.org" href="http://www.malwarebytes.org" target="_blank">here</a>.</p>
<p><a href="http://davestechsupport.com/blog/wp-content/uploads/2012/01/combofix1.jpg"><img class="aligncenter size-full wp-image-1435" title="combofix1" src="http://davestechsupport.com/blog/wp-content/uploads/2012/01/combofix1.jpg" alt="" width="500" height="219" /></a></p>
<p>Finally a tool I use quite often to help clean systems that have already become infected is a program called Combofix, which is free.  This isn&#8217;t so much a traditional antivirus that runs in the background as it is a stand-alone utility for scanning a system after it has become infected.  It is regularly updated so it&#8217;s best to not bother downloading and using it until you actually have to.  You can read more about it <a title="Bleeping Computer - How to use Combofix" href="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" target="_blank">here</a> and download it from <a title="Combofix download" href="http://www.bleepingcomputer.com/download/anti-virus/combofix" target="_blank">here</a>.</p>
<p>In conclusion I strongly advise my clients to not use Norton Antivirus because it&#8217;s one of the most over-hyped, over-priced products out there right now and with the news of parts of its source code being leaked it only stands to become an even less effective product that will do less to protect you than other cheaper alternatives out there.</p>
<p>Speaking of alternatives, there is always the option of picking an alternative operating system such as Linux.</p>
<p><a href="http://davestechsupport.com/blog/wp-content/uploads/2012/01/ubuntu11.png"><img class="aligncenter size-full wp-image-1447" title="ubuntu11" src="http://davestechsupport.com/blog/wp-content/uploads/2012/01/ubuntu11.png" alt="" width="500" height="373" /></a></p>
<p>Linux is a free open-source OS that comes in many flavors.  We are already seeing Android being adopted by smartphone and tablet users like crazy and it is just one example of a Linux based OS that is taking the world by storm.  But for desktop and laptop users there remains a need for a full fledged desktop OS and there are many out there to choose from.  My personal favorite is Ubuntu Linux which you can check out at <a title="Ubuntu" href="http://www.ubuntu.com" target="_blank">ubuntu.com</a>.  It&#8217;s not for everyone but I can easily say that it is a very ideal choice for the average user.  Keep an eye out for future posts; I intend to record a new introductory video for Ubuntu 12.04 when it is released this coming April.</p>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2012/01/07/some-of-norton-antivirus-source-code-has-leaked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Strategies For Removing Malware and Viruses</title>
		<link>http://davestechsupport.com/blog/2011/11/06/strategies-for-removing-malware-and-viruses/</link>
		<comments>http://davestechsupport.com/blog/2011/11/06/strategies-for-removing-malware-and-viruses/#comments</comments>
		<pubDate>Sun, 06 Nov 2011 10:30:48 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/?p=1380</guid>
		<description><![CDATA[Update, March 18 2012:  I wanted to add the names of two more utilities I&#8217;ve found to work very well for some specific rootkits.  The names of the two programs are: Kaspersky TDSSKiller Avast Anti-Rootkit Use these two programs in addition to Microsoft Security Essentials, Malwarebytes and Combofix to help clean your system of an [...]]]></description>
			<content:encoded><![CDATA[<p>Update, March 18 2012:  I wanted to add the names of two more utilities I&#8217;ve found to work very well for some specific rootkits.  The names of the two programs are:</p>
<ul>
<li><a href="http://support.kaspersky.com/faq/?qid=208283363" target="_blank">Kaspersky TDSSKiller</a></li>
<li><a href="http://public.avast.com/~gmerek/aswMBR.htm" target="_blank">Avast Anti-Rootkit</a></li>
</ul>
<div>Use these two programs in addition to Microsoft Security Essentials, Malwarebytes and Combofix to help clean your system of an infection.  The above two were a life saver very recently and proved to be effective and easy to use.</div>
<div style="text-align: center;">
&#8212;&#8212;-[Begin original post]&#8212;&#8212;-</div>
<p>I don&#8217;t write blogs much these days but if there&#8217;s one thing I&#8217;ve learned about writing blogs the golden rule is to make them useful and valuable to people.  As a sort of philanthropic gesture I am now going to reveal a few tricks I use in the field when repairing systems that have already become infected with viruses or malware.  Perhaps these tips will save you some money during these dark economic times.  I can&#8217;t promise that these tips will work for you but for the DIY user who&#8217;s not afraid to get their hands dirty, it might prove to be very useful.  So lets get right to it:</p>
<h3>Phase 1:  Safe Mode (with networking?)</h3>
<p>Almost every version of Windows out there (from Windows 95 all the way up to the most recent Windows 7) have a hidden menu you can access at boot that gives you access to a diagnostic profile called Safe Mode.  Safe Mode is a sort of back door mode into Windows that loads the absolute (or nearly) bare minimum of device drivers and background services.  It&#8217;s sort of a bare bones environment that is suitable to start your repair from primarily because most viruses aren&#8217;t auto-started by the system in this mode, but it&#8217;s not perfect.  More on that in a moment.</p>
<p>To access Safe Mode you need to press the F8 key on your keyboard at a VERY specific time.  Typically when you turn your computer on you&#8217;ll see a screen that either has the logo of the manufacture of the PC or perhaps some generic startup relating to your BIOS.  At some point that all goes away, your screen will be black for about 3 seconds, and then Windows will proceed to boot with the little scroll bar loading away.  It&#8217;s during (or just before) that 3 second window of blackness that you need to start tapping the F8 key.  If done correctly, you&#8217;ll be presented with a menu that looks like this:</p>
<p><a href="http://davestechsupport.com/blog/wp-content/uploads/2011/11/safemode1.jpg"><img class="aligncenter size-full wp-image-1381" title="safemode1" src="http://davestechsupport.com/blog/wp-content/uploads/2011/11/safemode1.jpg" alt="" width="500" height="307" /></a>You&#8217;ll use the arrow keys on your keyboard to move the highlighting selector bar.  Typically I will select Safe Mode With Networking, as this allows me to access the Internet and download utilities as well as give these utilities access to definition updates for itself later.</p>
<p>After you select Safe Mode With Networking and press Enter your screen will be bombarded with a slathering of strange and mysterious words&#8230;</p>
<p><a href="http://davestechsupport.com/blog/wp-content/uploads/2011/11/safemode21.jpg"><img class="aligncenter size-full wp-image-1383" title="safemode2" src="http://davestechsupport.com/blog/wp-content/uploads/2011/11/safemode21.jpg" alt="" width="500" height="274" /></a>Don&#8217;t worry, this is normal.  (Note: If instead of this screen above you get another menu asking what version of Windows you want to boot, just press Enter again).</p>
<p>Eventually you will get to the familiar blue colored user login screen and you might see an account called Administrator shown there that you&#8217;ve never seen before.  If you do, go ahead and select it to log in as &#8220;Administrator&#8221;.  Otherwise, select your own user name.</p>
<p>Once you&#8217;re logged in you have a few options you can take.  The safest way to get started is to actually bring a copy of your utility software with you on a thumb drive or CD to install it from, instead of downloading via a web browser.  The reason it&#8217;s not a good idea to try and download via a web browser is because a lot of viruses tend to wrap themselves around a browser&#8217;s EXE file so that when the browser starts, so does the virus.  This could potentially happen with a lot of other software so it&#8217;s best to try and resist the temptation to run any programs except for the cleaning utilities we&#8217;re about to install.</p>
<h3>Phase 2:  Cleaning</h3>
<p>There are only three pieces of software I typically use with great success in the field for removing viruses and malware.  They are:</p>
<ul>
<li><a title="Malwarebytes" href="http://www.malwarebytes.org" target="_blank">Malwarebytes</a></li>
<li><a title="Combofix" href="http://www.bleepingcomputer.com/download/anti-virus/combofix" target="_blank">Combofix</a></li>
<li><a title="Microsoft Security Essentials" href="http://windows.microsoft.com/en-US/windows/products/security-essentials" target="_blank">Microsoft Security Essentials</a></li>
</ul>
<p>All of the above are free with the exception of Malwarebytes, which functions with all its features on a 30 day trial when you first install it (note that you will see an error message appear when you tell it to start the trial while in Safe Mode; this is normal and you can ignore the error by clicking the OK button when it appears).  To keep the full version running you have to buy it for the low one-time payment of $25 and I strongly recommend it.  Apart from these three the only other tool I use is Google, which I&#8217;ll use to lookup exact phrases found within suspicious malware to see if I can find other people talking about that particular virus somewhere online and hopeful discover what unique thing they did to remove it.  Fair warning:  Your mileage may vary.</p>
<p>I typically start by installing Malwarebytes first (however I have had one experience where I wasn&#8217;t able to do this until after I ran Combofix so you might need to flip the order of these two tasks), applying the most recent update for it and then running a full scan, removing all infected objects it finds.  A typical scan can take around a half hour to do.  When it&#8217;s finished, you just need to click the &#8220;Show Results&#8221; button and then make sure the results listed all have check marks next to them and then click &#8220;Remove Selected&#8221; in the bottom left.  If an object doesn&#8217;t have a check mark when you first view the results it means Malwarebytes thinks it could be a false-positive result.  Use your best judgment and google to determine if either the file is malicious and/or if the file is a necessary part that can be removed without grief.  A reboot will likely be required when it is finished.  Be ready to hit F8 again when you do this so you can come back into Safe Mode and continue your work.</p>
<p>One thing I&#8217;ll often do while I&#8217;m waiting for a Malwarebytes scan to complete is take a look at the MS Config utility and see what items are enabled to auto-start when you boot into the system.  To access this, click Start, then click Run (or just click into the search box if you&#8217;re using Windows 7) and type in &#8220;msconfig&#8221; without the quotes into the box and click OK.  Then click the Startup tab at the top.</p>
<p><a href="http://davestechsupport.com/blog/wp-content/uploads/2011/11/msconfig.jpg"><img class="aligncenter size-full wp-image-1389" title="msconfig" src="http://davestechsupport.com/blog/wp-content/uploads/2011/11/msconfig.jpg" alt="" width="458" height="304" /></a><br />
In this startup list are programs that are told to run right away when you first log into your system.  Almost all of these items are non-essential and to be on the safest side you could probably get away with unchecking all of these items, but that&#8217;s usually overkill and might rob you of some convenient feature you&#8217;d like to have.  Look carefully down the list for items that have empty path names, or very bizarre characters in their name&#8230; I have to admit that at this point experience with this stuff comes in to play.  If you don&#8217;t know what something is you could look it up by name with google on a separate computer before deciding to uncheck it  Alternatively, you could use the uncheck-all-the-things strategy and then go back later to add check marks back into the few items you know you need enabled.  You can also check out the Services tab which is to the left of the Startup tab, check the box that says &#8220;Hide all Microsoft items&#8221; and then use the same judgment to decide if there are third-party services running in the background that don&#8217;t need to be.  Google is your friend here for helping to determine if a service is useful or not.</p>
<p>Another thing I&#8217;ll do while waiting for a scan to complete is open the Add/Remove Program (Programs &amp; Features) applet from the Control Panel to view all the software that&#8217;s been installed on the system.  I target toolbars of any kind first, next by software that is unfamiliar to the user.  Again, google is a useful reference here because you don&#8217;t want to remove something that&#8217;s known to not be malicious.</p>
<p>The next step is to run Combofix which you can find a <a title="Combofix Tutorial" href="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" target="_blank">tutorial about by clicking here</a>.  It is pretty strait forward:  double-click on the combofix.exe file that you downloaded and follow the on screen instructions.  It&#8217;s own scan will also take about 30 minutes or so but it is very sensitive so once you kick it off, don&#8217;t touch the computer until its finished.   There is almost no interaction required with the software and it will automatically remove anything malicious it finds, producing a log with a lot of <em>interesting </em>jargon at the end that you can forward on to an expert for further analysis if you&#8217;d like.</p>
<p>After all this I&#8217;ll typically reboot the system and let it boot normally and then install Microsoft Security Essentials, running a full scan with it right after and checking to make sure the trial mode has been enabled on Malwarebytes.</p>
<p>If all of the above didn&#8217;t work, something I&#8217;ll try next is to reboot back into safe mode and use the control panel to create a new user account, then log off and log back in under that new account and repeat all the same steps above.  The reason this might help is because viruses tend to damage registry entries for accounts that existed when it found and infected the system.  Because we&#8217;re creating a new account in an environment that hopefully didn&#8217;t auto-launch the virus, we can then create a fresh account with it&#8217;s own default settings and preferences that hopefully won&#8217;t be manipulated by the virus.  This kind of problem could also be reversed using the System Restore utility but I&#8217;ve found that a lot of times (not always) I try to use this utility none of the restore points are any good.  I wouldn&#8217;t be surprised if previous restore points are destroyed by certain viruses making it even more difficult to undo the damage done.  In situations like that I&#8217;ve occasionally just created a new user account and migrated all the important user data (documents, etc.) from the old account to the new account, deleting the old one in the end because it&#8217;s irreversibly broken.</p>
<p>One last tip I&#8217;ve run across in a training video for a competitor of mine who will remain unnamed is to shut the system off by force instead of doing a soft reboot during this cleaning process.  In other words, hold the power button down for 5 seconds and then turn the computer back on after 20 seconds.  The reasoning behind this is that there are a few viruses out there that alter the shutdown script of events that take place during an ordinary shutdown and one of the events it injects into the script is to reinstall the virus during shutdown from a rogue location, as a Plan B so even if the live version of the virus is caught and removed it might be able to recreate the file from an encrypted copy of itself elsewhere.  If you decide to do this my only advice would be to backup the entire hard drive before doing so.  It&#8217;s technically dangerous&#8230; but probably not THAT dangerous&#8230; it&#8217;s best to remain on the safe side and not use shortcuts.</p>
<p>Finally a word about a couple of common viruses in particular I&#8217;ve run into in the last year:</p>
<p>A few of these viruses going around exhibit the symptom of making all your files and shortcut icons on the desktop vanish.  This is often done with a combination of changing the file attributes to enable the hidden flag, or by moving the files to a hidden location.  It is sometimes also conjoined with malware that tries to frighten you into thinking your hard drive is on the verge of failure, or at the least, claims to be antivirus software itself.  The goal of all such attempts is to get you to give up your credit card number.  Please don&#8217;t.</p>
<p>I&#8217;ve had great success removing the virus that causes these files to go missing but after it&#8217;s been removed it&#8217;s not always so easy to reverse the damage and restore the missing icons.  Fortunately there is one program out there that, for the most part, has been able to do this for me very simply and it&#8217;s simply called &#8220;Unhide&#8221;.  Use this program after going through all the above steps to be sure you&#8217;ve removed traces of the virus and hopefully it will get all of your stuff back for you.  You can download Unhide from <a href="http://www.bleepingcomputer.com/forums/topic405109.html" target="_blank">here</a>.</p>
<p>One other common symptom I&#8217;ve seen certain viruses exhibit is hijacking certain registry entries to alter file associations, specifically one which makes your computer forget what to run EXE files with, asking instead what program you&#8217;d like to open another program with.  I have found that in Windows 7 one trick of working around this is to right-click on a program shortcut and then click Run as Administrator.  This uses a separate registry association which hopefully has not been affected by the virus.  Using this Right-Click&gt;Run as Administrator trick you should be able to run your scanning utilities like Malwarebytes and Combofix from within Safe Mode.</p>
<h3>Phase 3: Prevention</h3>
<p>Now that we know how much of a pain these kinds of viruses can cause we should talk a little about where they come from and the different ways they can end up on your computer.  I wrote a much longer blog about this topic which you can read <a title="Malvertising" href="http://davestechsupport.com/blog/2010/12/05/malvertising-how-flash-ads-can-infect-your-pc/" target="_blank">here</a>.  Basically it boils down to this:</p>
<ul>
<li>Make sure you install all available software updates for Windows itself as well as 3rd party software and plugins like Adobe Flash, Acrobat and Java (among others).  Updates are your friend and help to patch recently discovered security vulnerabilities.</li>
<li>Pay attention to links people send you in emails.  It&#8217;s quite possible their email account has had its password stolen and is being used by a robot to send spam email with links to malicious websites out to everyone in their address book.  Warn your friends if you suspect their account has been compromised and suggest they change their email accounts password before following the steps above to attempt to remove a potential infection.</li>
<li>Use good anti-virus software.  As recommended above, I prefer MSE and Malwarebytes.  Combofix is only to be used as an emergency utility; it doesn&#8217;t have a real-time monitoring feature.</li>
<li>Consider using a software firewall to block unwanted inbound traffic and unexpected outbound traffic.  <a title="Click the download link button on the lefthand side." href="http://www.zonealarm.com/security/en-us/trialpay-za-signup.htm" target="_blank">Zone Alarm Free</a> is an excellent choice for this.</li>
<li>Use an ad-blocking plugin to further reduce the chances of a virus sneaking in through a flash-based advertisement.  <a href="https://addons.mozilla.org/en-US/firefox/addon/adblock-plus/" target="_blank">Ad-Block for Firefox</a> is a great option.  You can also get it for Google Chrome <a href="https://chrome.google.com/webstore/detail/gighmmpiobklfepjocnamgkkbiglidom" target="_blank">from here</a>.</li>
<li>Along with these plugins, consider using a better browser.  <a href="www.mozilla.org/en-US/firefox/new/" target="_blank">Mozilla Firefox</a> and <a href="http://www.google.com/chrome" target="_blank">Google Chrome</a> have both become superior to Internet Explorer, especially in terms of security.</li>
<li>Avoid installing &#8220;toolbars&#8221; for your browser.  If you install one by accident, disable it in your browser or better yet uninstall it via your control panel.</li>
<li>Avoid using P2P file-sharing software like Frostwire or MP3Rocket.  These methods of file sharing do not have any form of user moderation and anybody can wrap a virus inside a file then name it something innocent/sensational looking to trick people into downloading it and installing a virus.</li>
<li>Consider adding a parental filter to your computer; you don&#8217;t need kids for this.  Having a web filter like <a href="http://www1.k9webprotection.com/" target="_blank">K9 Web Protection</a> can be helpful to block your computer from accidentally trying to connect with a known malicious server.</li>
<li>Lastly, though this is too extreme for most people:  Consider switching to Linux on your desktop.  Linux is free, open-source and is even more secure than MacOS.  Seriously.</li>
</ul>
<p>I hope this advice has been helpful.  Please leave comments or suggestions about other tips and tricks you use to help remove malicious software in the comments section below!</p>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2011/11/06/strategies-for-removing-malware-and-viruses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malvertising:  How Flash Ads Can Infect Your PC</title>
		<link>http://davestechsupport.com/blog/2010/12/05/malvertising-how-flash-ads-can-infect-your-pc/</link>
		<comments>http://davestechsupport.com/blog/2010/12/05/malvertising-how-flash-ads-can-infect-your-pc/#comments</comments>
		<pubDate>Sun, 05 Dec 2010 11:00:10 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/?p=1231</guid>
		<description><![CDATA[I have encountered a good variety of computer problems this year, many of them classic textbook cases. Dead DVD burners that needed to be replaced; computers running slowly because they really needed a RAM upgrade; hard drives needing to be replaced with larger ones; networks with printers needing to be setup so multiple computers can [...]]]></description>
			<content:encoded><![CDATA[<p>I have encountered a good variety of computer problems this year, many of them classic textbook cases. Dead DVD burners that needed to be replaced; computers running slowly because they really needed a RAM upgrade; hard drives needing to be replaced with larger ones; networks with printers needing to be setup so multiple computers can send jobs to it&#8230;. these are the kinds of problems that we were taught how to resolve in school, primarily because they  were easy to recreate/simulate for lab assignments.  I remember the fun we had when students were split into pairs and told to &#8220;test&#8221; each other by breaking a system and not telling the other person HOW they broke it, as a challenge to see if they catch all the hidden problems.  Wanna make a computer run slow?  Pull a stick of RAM out of it, slightly.  Wanna make a network printer stop working?  Change its IP address.  Wanna stump someone with no video on the monitor?  Just turn the contrast/brightness all the way down to see if they can figure it out.  The goal was to reinforce the premises that you should never, ever dismiss the lowest common denominator when trying to think of different  diagnostics and best case solutions for a problem.  Even something as simple as &#8220;is it plugged in?&#8221; should never be assumed to have been checked until you&#8217;ve done it yourself.  In networking, you would say &#8220;start with the physical layer, and work your way up to the higher levels until you actually reach the application.&#8221;</p>
<p>These problems don&#8217;t strike me as novel or very interesting, mostly because you expect to see them occur at SOME point in time and at random.  Electronics wear out, lightning can strike at any moment, dust buildup shorts something out or jams a cooling fan; these things just happen from time to time.  But there was one issue I saw this year that really stood out as occurring more frequently than any other problem by far.  A problem  that seemed to happen so suddenly, so widely that you could almost call it &#8220;trend setting&#8221;.  So I wanted to take a look back and talk a bit about a problem I&#8217;ve seen more often than anything else this year:</p>
<h2>&#8220;Warning:  You&#8217;re infected!  Click here now!&#8221;</h2>
<p><a href="http://davestechsupport.com/blog/wp-content/uploads/2010/12/154257_0.jpg"><img class="size-full wp-image-1232 alignnone" title="Fake Security Software" src="http://davestechsupport.com/blog/wp-content/uploads/2010/12/154257_0.jpg" alt="" width="469" height="286" /></a></p>
<p>The most prominent problem I saw this year, more than any other problem I got calls about, were from people saying they had gotten alerts popping up on their system similar to the one pictured above.  Typically you would be intimidated by a popup that said your system had a LOT of viruses on it and to click on various buttons/links to remove them.  Unfortunately it was all a ruse as these alerts were themselves part of a virus masquerading around as anti-virus software, taking computers hostage.   Their names and appearance had some variation but most of their tactics were the same:</p>
<ul>
<li>Prevent user from opening any other applications (including Task Manager)</li>
<li>If you were able to open a web browser, any page you tried to visit would be replaced with a page that would fear-monger the user even further</li>
<li>Change the browser proxy settings to point to a non-existent server and in doing so prevent the user from accessing the Internet for downloading removal tools</li>
<li>Annoy the user with never-ending, obnoxious pop-ups that would invite the user to pay the developers of the fake anti-virus software ransom money</li>
<li>Replicate itself across multiple, random locations on the hard drive, making it more difficult to remove manually</li>
</ul>
<p>I began to get a lot of phone calls for this exact type of issue during the middle of the summer this year, and of course everyone wanted to know how their computer came to get this sort of junk software on their machine in the first place.  Along those lines:  Where do viruses come from, how could one have gotten on my computer and WHY on earth would someone create such an evil thing in the first place?</p>
<p>I don&#8217;t have the monetary resources to conduct an &#8220;official&#8221; study (and as such you should classify everything here to be anecdotal), so the next best thing I can do is look for things that were in common between PCs that fell victim to the same infection at about the same time.  The one thing that stood out the most to me was that Adobe Flash, Adobe Acrobat and/or Java were out of date and needed updates to be installed.</p>
<p><a href="http://davestechsupport.com/blog/wp-content/uploads/2010/12/adobe-flash-player-update-10.1-installer.jpg"><img class="aligncenter size-full wp-image-1235" title="adobe-flash-player-update-10.1-installer" src="http://davestechsupport.com/blog/wp-content/uploads/2010/12/adobe-flash-player-update-10.1-installer.jpg" alt="" width="480" height="326" /></a><br />
In the year 2010, <a href="http://trends.google.com/trends?q=adobe+security&amp;ctab=0&amp;hl=en&amp;geo=all&amp;date=ytd&amp;sort=0" target="_blank">Adobe has had to make multiple announcements about zero-day exploits found in their Flash plugin</a> that could allow Flash to do things like crash a computer or to take control of it (e.g., facilitate the installation of a malicious payload or virus).</p>
<p>Just what is Flash, anyway?  Flash is a plugin for web browsers that has been a mainstay in webpages for over a decade.  Youtube videos, for example, are played within Flash.  Most advertisements you see on the web use Flash to animate video, elements, buttons, letters, etc.  Some websites are made entirely in Flash.  In the early days Flash was designed as an alternative to animated gif images and cartoon-like animations because for some uses it could actually conserve bandwidth because instead of pixels and color pallets taking up file space, you would instead be working with vectors (think connect-the-dots to create a shape of something, like a stick-figure man, and move the dots/vertices to animate it).  An awesome example of cartoon flash animation using very little bandwidth is <a href="http://www.homestarrunner.com" target="_blank">www.homestarrunner.com</a> (a favorite cartoon series I used to follow in the old days).  Over time Flash has evolved into quite a feature rich plugin that many have attempted to clone and dethrone, but all attempts have failed (so far).</p>
<p>In any case, as a result of being more efficient than animated bitmaps and saving web hosts money on bandwidth and faster loading times while increasing the &#8220;eye-candy factor&#8221; during the days of dial-up, Flash became a preferred/common means of deploying advertisements on the web, and eventually advertising itself became so big that there are now companies that do nothing but produce and host Flash-based advertisements <em>for other websites. </em>What this means is that many websites do not actually host/serve the advertisements that you see on their website, as they have offset the bandwidth requirements for this function to third party companies.  Unfortunately, because advertising is a big deal online, it raises the bounty and incentive a malicious hacker might have to penetrate the advertising servers and replace clean advertisements with infected versions that would download and install Malware all by itself, taking advantage of security exploits in the plugin that have not been patched by the user.  This has been going on for at least the last 4 years or more and it&#8217;s a phenomenon knows as &#8220;Malvertising&#8221;.</p>
<p>So what are some ways to prevent this type of thing from affecting you?</p>
<h3>1. Make sure you apply updates for all software on your computer when presented with the opportunity</h3>
<p><a href="http://davestechsupport.com/blog/wp-content/uploads/2010/12/Java-Update-Available.jpg"><img class="aligncenter size-full wp-image-1236" title="Java-Update-Available" src="http://davestechsupport.com/blog/wp-content/uploads/2010/12/Java-Update-Available.jpg" alt="" width="407" height="308" /></a></p>
<p>If you see an alert like the one pictured above, address it immediately.  Far too often I see users just minimize the window or click &#8220;Later&#8221; and forget about it for the rest of the session.  The same thing goes for Windows updates, Adobe updates and generally speaking any updates for software that you use on a regular basis.  Updates happen because security vulnerabilities are found and patched, or slight tweaks resulted in an increase of the programs performance, or because they are adding a new cool feature.  Whatever the case may be, software updates are your friend and you should welcome them without hesitation.  If you are asked to update a piece of software you have never heard of before,  just type the name of that software into Google.  With just 30 seconds of reading you should be able to determine if the program that has an update pending is legit or malicious.</p>
<h3>2.  Use Anti-Virus software that is backed by a good reputation, not just hype and marketing</h3>
<p>The two most common anti-virus programs I&#8217;ve encountered  on computers THAT WERE ALREADY INFECTED has either been Norton or McAfee; both have never seemed to live up to their hype or justify the sponsorship of PC manufactures and Internet Service Providers.  Norton in particular spends gobs of money on absurd advertisements about how you should <a href="http://www.youtube.com/watch?v=za0-Q33rLtE" target="_blank">protect your oscillating fan from David Hasselhoff</a> or <a href="http://www.youtube.com/watch?v=L70I0vTwYxg&amp;NR=1" target="_blank">saving your unicorn from Dolf Lundgren</a>.  The use of silly metaphors in them are meant to parody the fact that most people don&#8217;t understand viruses anymore than they understand Dolf scorching My Little Pony with a flame thrower, purely for illustrative purposes of course.  Lets dumb it down so much that people will say, &#8220;This is so dumb, it&#8217;s smart (advertising).&#8221;  Now we know why a copy of their software costs around $60 or $70 per year&#8230;</p>
<p>The sad truth about anti-virus software is that NONE OF THEM are perfect or necessarily worth their weight in dollars, simply because virus programmers have the upper hand.  If a hacker discovers a vulnerability that no one else has discovered yet, he may just keep it in his &#8220;stash&#8221; for use later.  OR, he might sell that knowledge to the Russian mafia or any number of other interested parties who have their own stash and secret agendas.  It is suspected the <a href="http://en.wikipedia.org/wiki/Stuxnet" target="_blank">Stuxnet</a> worm that ran rampant through Iran earlier this year was the product of a government agency, due to the sheer amount of zero-day exploits it contained for propagating itself, along with its overall sophistication and extremely specific targeting.</p>
<p>Was it a coincidence that days after Adobe announced the discovery of a zero-day exploit in their Flash and Acrobat Reader software in early June that a lot of people started to call me for the exact same Malware problem?  It&#8217;s quite likely the vandalism on advertising servers was timed to correspond with these vulnerabilities to maximize exposure.  It takes Adobe around 2 weeks to release patches for vulnerabilities like this so there is a window of time users are exposed and at risk, and this window of time extends out further if you avoid applying updates.</p>
<p>Despite this sad and depressing fact, you&#8217;ll be happy to know that many anti-virus programs do provide generous protections that you cannot otherwise get without them.  There are two programs I recommend everyone check out:</p>
<ul>
<li><a href="www.microsoft.com/security_essentials/" target="_blank">Microsoft Security Essentials</a></li>
<li><a href="www.malwarebytes.org/" target="_blank">Malwarebytes</a></li>
</ul>
<p>Microsoft Security Essentials is produced by Microsoft itself and is a free program you can install on your system.  It will actively monitor your computers activity and help prevent virus infection.  I encounter network security professionals in web forums here and there and most of them have really begun to sing praise for this program, because of it&#8217;s small footprint and high level of virus detection and removal.  Malwarebytes is another program that comes in a free form (though there is a paid version that automates all of it&#8217;s functions so you don&#8217;t have to do manual scans and updates with it).  Malwarebytes has been an absolute life saver for me this year as it was able to effectively cure about 8 out of 10 PCs of all their woes with one scan.</p>
<p>There are many other commercial (pay) anti-virus programs out there that are good, such as AVG, Avira Anti-Virus, Avast, etc., but I don&#8217;t have the time or resources to review all that are available.  While you might be able to find other websites out there that post &#8220;comprehensive reviews&#8221; of this type of software, it should not surprise you that sometimes these articles are just advertisements for commercial anti-virus software dressed up to look legit and non-partisan.  In my opinion, the best reviews for these things come from individual users and a great place to find reviews for antivirus software is Amazon.com.  They sell some anti-virus software and each of them have their own collection of user reviews that are worth reading over if you decide you want spend money on extra protection not offered by free solutions.</p>
<h3>3.  Install A Software Firewall Solution</h3>
<p>If your computer is directly connected to the Internet (and does not pass through a router of any kind) then you are putting your computer on the front line and you should protect it with some armor if you want to stand a chance in the wild jungle that is the Internet.  Firewalls prevent unwanted network traffic from passing between your computer and the Internet.  In the same way Flash has it&#8217;s own flaws and vulnerabilities from time to time, so too does Windows itself and many vulnerabilities can be exploited with nothing more than a network connection.  Having a firewall in place helps eliminate this possibility.  A firewall can also prevent rogue software that is already on your system from &#8220;phoning home, contacting the mother ship&#8221; to update itself or otherwise expose your personal data to would be data thieves..  It&#8217;s not anti-virus software, but it does add a critical layer of protection.  Windows itself comes with a firewall built in but it&#8217;s not as feature rich as some third-party applications out there.  The most popular free firewall that I know of <a href="http://www.zonealarm.com/security/en-us/anti-virus-spyware-free-download.htm" target="_blank">Zone Alarm Free</a>.</p>
<h3>4.  Use a proper Ad Blocking browser extension</h3>
<p>One of the great features of Zone Alarm Free is the ability to let it block advertisements for you, although its not very smart about it as it basically blocks all gifs or flash content embedded in a website.  This can break a lot of websites that have legit uses for Flash, like Youtube.  So you may want to look into a more proper ad-blocking plugin/add-on/extension for your browser.  A great one for Firefox is called <a href="https://addons.mozilla.org/en-US/firefox/addon/1865/" target="_blank">Adblock Plus</a>.</p>
<h3>5.  Use a safe web browser</h3>
<p>Recently I stumbled across a funny description of Internet Explorer:  &#8220;It&#8217;s a great tool for downloading Firefox or Google Chrome.&#8221;  And it&#8217;s the truth.  Internet Explorer has struggled to achieve a respectable reputation among security experts as being a secure browser, when compared to others that compete against it.  Among them are:</p>
<ul>
<li><a href="www.mozilla.com/firefox" target="_blank">Mozilla Firefox</a></li>
<li><a href="http://www.google.com/chrome" target="_blank">Google Chrome</a></li>
<li><a href="http://www.opera.com" target="_blank">Opera</a></li>
</ul>
<p>These are all very capable browsers that have a great reputation for handling security and also have shown impressive turnaround when vulnerabilities are discovered.  I would highly recommend you download and install one of the above browsers and start to use it instead of Internet Explorer.</p>
<h3>6.  Avoid And Uninstall Web Browser &#8220;Toolbars&#8221;</h3>
<p><a href="http://davestechsupport.com/blog/wp-content/uploads/2010/12/too_many_toolbars1.jpg"><img class="aligncenter size-full wp-image-1239" title="too_many_toolbars" src="http://davestechsupport.com/blog/wp-content/uploads/2010/12/too_many_toolbars1.jpg" alt="" width="500" height="375" /></a></p>
<p>The above image is an exaggeration of a point I would like to drill home:  Toolbars are 99% junk and often facilitate no additional functionality than a web browser already has built into itself.  Pop-up blocking and search bars are standard in all modern web browsers, for example.  Many times I have seen toolbars for &#8220;MyWebSearch&#8221; on computers that happened to be infected with a virus.  I can&#8217;t necessarily say there is a causal connection between that particular toolbar and an increase in exposure to malicious software, but its fair to suspect it because if you search for &#8220;mywebsearch&#8221; on google, every single link (except the first one) goes to instructions for how to remove it.  It&#8217;s clear that NOBODY wants this toolbar, and the same could easily be said for most toolbars.  Get rid of them, please!</p>
<p>The easiest way to remove most of these is to use the Add/Remove Software applet in your control panel (In Windows Vista/7, it&#8217;s called &#8220;Programs and Features&#8221;).  If this fails to work then you can often find instructions for manual removal by searching for them with Google.</p>
<h3>7.  Avoid P2P Filesharing Programs</h3>
<p>Limewire is dead, but the way it worked will live on in other programs like it.  The way Limewire worked mostly relied on you connecting to other peers like yourself and the mesh collective would commence to pass files back and forth in a decentralized fashion.  The problem for Limewire is that it wasn&#8217;t entirely decentralized, which is why they were able to shut it down like they did Napster several years ago.  But still, the primary way it worked was by letting anybody share pretty much ANYTHING they wanted, without any real fear if they did something like disguise a virus as a popular new song by some teen-pop musician and share it out to the world as a &#8220;joke.&#8221;  Using software like this is your call and any legal considerations involved weighs entirely on you.  If you do decide to use file sharing software of this nature, make sure you police all your downloads to be sure you haven&#8217;t downloaded a Trojan horse.</p>
<h3>8.  Consider Adding Parental Controls To Your PC</h3>
<p>Not everybody reading this (in fact, few people reading this) would be willing to walk forward and admit to visiting porn websites online, but such websites make up a large chunk of the web and due to the rogue nature of some of them you are more likely to find ads, script code laced with viruses or strait up automatic downloads for executable binaries with names like &#8220;Video.exe&#8221; that can lead to your computer being infected.  It&#8217;s quite plausible that you might even visit one of these sites &#8220;TOTALLY BY ACCIDENT!!!&#8221;  So one thing you might consider using is a parental control blocking application that filters out web addresses and reduces the chance of you visiting one by accident or otherwise.  A robust, free parental control program worth trying is <a href="http://www1.k9webprotection.com/" target="_blank">K9 Web Protection</a>.</p>
<h3>9. Consider Using Linux For Internet Stuff</h3>
<p><a href="http://davestechsupport.com/blog/wp-content/uploads/2010/12/malware_on_ubuntu.png"><img class="aligncenter size-full wp-image-1272" title="malware_on_ubuntu" src="http://davestechsupport.com/blog/wp-content/uploads/2010/12/malware_on_ubuntu.png" alt="Yes, we Linux users get these popups too, and they make us laugh with joy!" width="500" height="375" /></a></p>
<p>It would be hard for me to write all of the above out without making a passing mention of using a different operating system, at least part of the time.  I realize not many users are interested in making a big switch from one OS to another, but it is very easy to at least get your feet wet with a Live CD.  In the case of Ubuntu Linux you can boot the entire OS from a CD without making any changes to your computer.  It&#8217;s like playing a demo for a video game before deciding to install the full copy, for free.  Instructions for downloading, burning and booting are right on <a href="http://www.ubuntu.com/" target="_blank">Ubuntu&#8217;s website</a> so if you&#8217;re even SLIGHTLY tech savvy you may find you enjoy working in Ubuntu more than you do Windows and feel relief from not having to worry about viruses or malware infecting your system.</p>
<h2>Conclusion</h2>
<p>As I mentioned before, this Malvertising problem is not new but the spike in its frequency of occurrence this year was interesting to me.  It wouldn&#8217;t be far out to predict another wave of infections like this striking again, but with the above advice and your increased awareness of the possibility of being infected in such a way should help to drastically reduce the chances of you falling victim to something like this.</p>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2010/12/05/malvertising-how-flash-ads-can-infect-your-pc/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Huge Privacy Breach Involving Copy Machines</title>
		<link>http://davestechsupport.com/blog/2010/05/08/huge-privacy-breach-involving-copy-machines/</link>
		<comments>http://davestechsupport.com/blog/2010/05/08/huge-privacy-breach-involving-copy-machines/#comments</comments>
		<pubDate>Sat, 08 May 2010 10:35:40 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/?p=1058</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="385" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/iC38D5am7go&amp;hl=en_US&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="480" height="385" src="http://www.youtube.com/v/iC38D5am7go&amp;hl=en_US&amp;fs=1&amp;" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2010/05/08/huge-privacy-breach-involving-copy-machines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Five Internet Scams Detailed By FBI</title>
		<link>http://davestechsupport.com/blog/2010/03/16/five-internet-scams-detailed-by-fbi/</link>
		<comments>http://davestechsupport.com/blog/2010/03/16/five-internet-scams-detailed-by-fbi/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 20:01:18 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[Education]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/?p=1055</guid>
		<description><![CDATA[I came across an article in Network World magazine that goes over five common Internet scams and thought this needed to be shared with everybody.  Please click here to read the article.]]></description>
			<content:encoded><![CDATA[<p>I came across an article in Network World magazine that goes over five common Internet scams and thought this needed to be shared with everybody.  <a href="http://www.networkworld.com/news/2010/031210-layer8-fbi-internet-scams.html?page=1" target="_blank">Please click here</a> to read the article.</p>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2010/03/16/five-internet-scams-detailed-by-fbi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why You Don&#8217;t Need Anti-Virus Software For Linux</title>
		<link>http://davestechsupport.com/blog/2010/03/10/why-you-dont-need-anti-virus-software-for-linux/</link>
		<comments>http://davestechsupport.com/blog/2010/03/10/why-you-dont-need-anti-virus-software-for-linux/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 01:57:20 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[HOWTO: Ubuntu]]></category>
		<category><![CDATA[Rant]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/?p=1042</guid>
		<description><![CDATA[I was just browsing Ubuntu Forums recently and someone wanted to get a second opinion to see if it were indeed true that Linux doesn&#8217;t need anti-virus software.  I humbly obliged them with my own answer on the matter: You don&#8217;t need anti-virus for Linux. Others in here will do a better job at explaining [...]]]></description>
			<content:encoded><![CDATA[<p>I was just browsing <a href="http://ubuntuforums.org/showthread.php?t=1426848&amp;page=2">Ubuntu Forums</a> recently and someone wanted to get a second opinion to see if it were indeed true that Linux doesn&#8217;t need anti-virus software.  I humbly obliged them with my own answer on the matter:</p>
<p>You don&#8217;t need anti-virus for Linux. Others in here will do a better job at explaining why this is, but in short, the OS has a big advantage here due to it being open source. The operating system is a product of crowd-sourcing, much in the same way as Wikipedia has been since it first showed up several years ago. And much like the highly-moderated articles of Wikipedia that require membership and an approval process for changes made to locked articles, so to is a strict moderation that goes on with the source code for Linux before it&#8217;s allowed to become part of the official distribution. Everybody is out to identify possible flaws or weaknesses or bugs in the source code and it&#8217;s much easier for any single person to make a contribution because the OS and much of the software that runs on it is open-source.</p>
<p>In Windows, the users don&#8217;t have the luxury of being able to dig through the source code to look for flaws. All they can do is report symptoms of problems to Microsoft, and the limited number of paid programmers that do have access to the source code then have to decide what flaws are the most important and which ones don&#8217;t merit their attention. So with Windows, a bug that affects only 500 people won&#8217;t be as important as a bug that affects 500,000 and probably won&#8217;t be fixed at all. But if it were Linux and if just one or two of those 500 people were a programmer who had access to the source code and figured out how to fix the problem on their own, the other 498 would actually stand to benefit from a patch that ends up being released thanks to the work of that one developer who had some spare time on his hands and decided to do something about a bug simply because he could.</p>
<p>So throughout the long life of Linux there has been this much more diversified, seasoned, multi-cultured source for development feedback that has helped to make it a much stronger, more &#8220;mature&#8221; operating system, especially in terms of the way security was designed. If there was ever a person out there who found a way to circumvent that security, there is at least one other who knows exactly how to repair the flaw. The reason viruses are able to best Windows is because their developers can only patch so many holes, and the ones they don&#8217;t have time to get around to end up being exploited the most. Third-party software developers that make Anti-Virus software make a killing because Microsoft is unable to handle this responsibility all by themselves, and even still, the best anti-virus software isn&#8217;t perfect.</p>
<p>The reason anti-virus software isn&#8217;t necessary in Linux is simply because the OS and its updates that patch vulnerabilities do the exact job anti-virus software in Windows is meant for: Prevent unwanted, malicious software or network activity from compromising the system. If there were a flaw in Linux found that allowed something like that, it wouldn&#8217;t be the job of some third-party software to safeguard the user against but the job of the OS itself. The reason anti-virus software even exists is simply because Microsoft is unable to handle the immense work load of patching their own source code as well as a crowd of Linux geeks can.</p>
<p>Am I saying Linux is perfect and invincible to viruses? Might it become more susceptible to viruses in the future if it were to ever become as popular as Windows is today? I would think that with an increase in the number of users would also come a complimentary increase in the number of clever developers that would only help to increase the number of eyes available to find flaws and fix them. Saying that Linux would get a lot of viruses down the road because more people are going to use it is like saying Wikipedia will become rife with widespread, uncontrollable vandalism because more people visit it. It hasn&#8217;t happened yet, and very likely never will happen because of the way it is designed, moderated and improved upon by the hive mind.</p>
<p><strong>EDIT to add: </strong> As mentioned in the first comments below, I failed to acknowledge that while Linux is more robust in the area of security, nothing can compensate for the weakest link in this arrangement:  The User.  A novice user could easily be enticed by a sinister website  that tells them to download a deb file which might contain malicious code and absentmindedly install it or execute a destructive command from the terminal window because they didn&#8217;t know any better (like rm -rf ~/*).  Fortunately for novice users there is little if any need to actually venture out into uncharted territory like a terminal window or strange websites to get software, thanks to the official repositories that contain a HUGE collection of software which continues to grow.  I&#8217;ve even heard you will soon be able to purchase proprietary Linux-based software through it.  Unfortunately, little can really be done to compensate for user negligence, and trying to compensate for all possibilities would likely result in too many annoying alerts and prompts for the average user (like when Windows Vista sprang the UAC on its users).</p>
<p>There are only a couple of circumstances that I believe anti-virus software on a Linux platform <span style="text-decoration: line-through;">would</span> might be worth having which involve helping to protect other Windows systems.  Say you got an email from someone that contained a virus but you never knew it was there and forwarded it onto someone else who uses Windows, resulting in their day being ruined and you being blamed.  So that&#8217;s one scenario.  You might also have a Linux server administrating a network of Windows based workstations which you have read/write access to and use the server to conduct scans of these machines over the network, but at the expense of finite network bandwidth and CPU cycles on the server.</p>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2010/03/10/why-you-dont-need-anti-virus-software-for-linux/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>How To Setup A Fingerprint Sensor In Ubuntu</title>
		<link>http://davestechsupport.com/blog/2009/05/20/how-to-setup-a-fingerprint-sensor-in-ubuntu/</link>
		<comments>http://davestechsupport.com/blog/2009/05/20/how-to-setup-a-fingerprint-sensor-in-ubuntu/#comments</comments>
		<pubDate>Wed, 20 May 2009 03:32:51 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[HOWTO: Ubuntu]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/?p=877</guid>
		<description><![CDATA[(Special thanks to this blog post for showing me how to get this working finally). About 2 months ago or so I read the tutorial in the above link to help get my fingerprint sensor setup in Ubuntu.  The problem was that it left one simple instruction out:  Paste a line of  text AT THE [...]]]></description>
			<content:encoded><![CDATA[<p>(Special thanks to <a href="http://aldeby.org/blog/index.php/howto-ubuntu-linux-on-hp-pavilion-dv2000-dv6000-dv9000-series-laptops#fingerprint" target="_blank">this blog post</a> for showing me how to get this working finally).</p>
<p style="text-align: center;"><img class="aligncenter" src="http://www.davestechsupport.com/blog/images/fprint.png" alt="" width="500" height="361" /></p>
<p>About 2 months ago or so I read the tutorial in the above link to help get my fingerprint sensor setup in Ubuntu.  The problem was that it left one simple instruction out:  Paste a line of  text AT THE TOP of a config file (and not at the bottom like I did).  The mistake has been corrected and I&#8217;m happy to say my finger print sensor is working in Ubuntu 9.04.  Based on the directions from the the link above, here&#8217;s how to set it up (these instructions are meant for version 9.04; see the above link for instructions for 8.04 and 8.10):</p>
<p><strong>Step 1:</strong> Click Applications&gt;Accessories&gt;Terminal and paste in the following command:</p>
<blockquote><p><em>sudo apt-get update &amp;&amp; sudo apt-get install aes2501-wy fprint-demo libfprint0 libpam-fprint</em></p></blockquote>
<p><strong>Step 2:</strong> Still in Terminal, paste in the following text:</p>
<blockquote><p><em>sudo gedit /etc/pam.d/common-auth</em></p></blockquote>
<p>This will open a text file called common-auth in Gnome Text Editor.  (Here&#8217;s where I screwed up last time).</p>
<p><strong>Step 3:</strong> If you want to use <span style="text-decoration: underline;">both</span> the password <span style="text-decoration: underline;">and</span> the fingerprint to authenticate (more secure) add  at the bottom:</p>
<blockquote><address><em>auth required pam_fprint.so</em></address>
</blockquote>
<p>If you want to use <span style="text-decoration: underline;">either</span> the fingerprint <span style="text-decoration: underline;">or</span> the password to authenticate (i.e. completely bypass the password through the fingerprint) the following string must be placed <strong>at the top of the file</strong>:</p>
<blockquote><p>auth sufficient pam_fprint.so</p></blockquote>
<p>Once pasted, save and close the file.</p>
<p><strong>Step 4: </strong> Press Alt-F2, type &#8220;fprint_demo&#8221; without the quotes and press enter.</p>
<p>This will launch the fingerprint utility that you can use to enroll the finger you wish to use for future authentications.</p>
<p>That&#8217;s basically it.  Special notes:</p>
<ul>
<li>If you happen to screw something up in the config file by mistake and lock yourself out of your PC by accident, you can boot into Recovery Mode from the GRUB boot menu to access a root command prompt and edit the above config file using nano (nano /etc/pam.d/common-auth).</li>
<li>Not all login screens are compatible with this feature.</li>
<li>To test your finger print in fprint_demo, click on the verify tab at the top and use the verify button to compare an enrolled fingerprint to another finger (or the same finger) and you&#8217;ll see the difference.</li>
</ul>
<p>As of Ubuntu 9.04, I&#8217;ve noticed the following quirks:</p>
<ul>
<li>Often you will not see an on-screen prompt asking you to swipe your finger across the sensor if the system is waiting for it.  Examples include the login screen, running Update Manager or Synaptic Package Manager, and otherwise most other programs that required your password to run them.</li>
<li>The only actual on-screen requests I&#8217;ve seen so far is when you are unlocking a screen-saver, or are running a program with sudo privileges in a terminal window.</li>
</ul>
<address><em></em></address>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2009/05/20/how-to-setup-a-fingerprint-sensor-in-ubuntu/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>April Fools Virus On Schedule</title>
		<link>http://davestechsupport.com/blog/2009/03/27/april-fools-virus-on-schedule/</link>
		<comments>http://davestechsupport.com/blog/2009/03/27/april-fools-virus-on-schedule/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 22:43:05 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/?p=798</guid>
		<description><![CDATA[I don&#8217;t normally pass along virus alerts because they are often outdated and obsolete, but this one is strait from my IBM inbox.  You may have heard about a virus that is set to strike on April 1st in the news recently.  It is called Conficker.C and you can read more about how it works [...]]]></description>
			<content:encoded><![CDATA[<p>I don&#8217;t normally pass along virus alerts because they are often outdated and obsolete, but this one is strait from my IBM inbox.  You may have heard about a virus that is set to strike on April 1st in the news recently.  It is called <strong>Conficker.C</strong> and you can read more about how it works by visiting these addresses:</p>
<p><a href="http://en.wikipedia.org/wiki/Conficker">http://en.wikipedia.org/wiki/Conficker</a><br />
<a href="http://mtc.sri.com/Conficker/addendumC/">http://mtc.sri.com/Conficker/addendumC/</a></p>
<p>As stated in the links above, the virus takes advantage of a buffer-overflow vulnerability of certain server services on Windows based machines.  Microsoft issued an update (<a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" target="_blank">MS08-067</a>) for Windows 2000 SP4, XP SP2 &amp; SP3, and Vista to patch this hole back in October of last year. So if you have installed all available Windows updates you should be fine and not need to worry.  It is highly recommended you install all available updates if you have not done so lately.  To force your PC to check for available updates, click <strong>Start&gt;All Programs&gt;Windows Update</strong> and follow the on-screen instructions.</p>
<p>If your computer is directly connected to the Internet it is advised that you have a quality software firewall installed and blocking unexpected inbound traffic.  A comparison of free firewall software can be found here:  <a href="http://www.techsupportalert.com/best-free-firewall.htm">http://www.techsupportalert.com/best-free-firewall.htm</a></p>
<p>In addition you should also have a quality anti-virus software solution in place.  Any of the following will suffice:</p>
<ul>
<li> <a href="http://shop.ca.com/virus/antivirus.aspx">CA 	Anti-Virus</a></li>
<li> <a href="http://www.symantec.com/index.jsp">Symantec 	Anti-Virus</a></li>
<li> <a href="http://www.f-secure.com/en_EMEA/downloads/">F-Secure 	Anti-Virus</a></li>
<li> <a href="http://www.pandasecurity.com/usa/homeusers/solutions/antivirus/">Panda 	Anti-Virus</a></li>
<li> <a href="http://usa.kaspersky.com/downloads/">Kaspersky 	Anti-Virus</a></li>
<li> <a href="http://www.mcafee.com/us/downloads/index.html">McAfee 	Anti-Virus</a></li>
<li><a href="http://www.bitdefender.com/">BitDefender Anti-Virus</a></li>
</ul>
<p>I personally recommend  <a href="http://free.avg.com/">AVG Free Edition</a></p>
<p>In summery:</p>
<ul>
<li> Be sure to apply all available 	updates for Microsoft Windows</li>
<li> Ensure you have some form of 	firewall blocking unwanted network traffic</li>
<li> Install a quality anti-virus solution</li>
</ul>
<p>Now lets all have a happy April Fools day!</p>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2009/03/27/april-fools-virus-on-schedule/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How To Remove Ubuntu&#8217;s Password Keyring</title>
		<link>http://davestechsupport.com/blog/2009/01/16/how-to-remove-ubuntus-password-keyring/</link>
		<comments>http://davestechsupport.com/blog/2009/01/16/how-to-remove-ubuntus-password-keyring/#comments</comments>
		<pubDate>Fri, 16 Jan 2009 22:00:53 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[HOWTO: Ubuntu]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/?p=690</guid>
		<description><![CDATA[UPDATE:  This post is almost 2 years old now and the method described below is somewhat obsolete (but still works).  Borrowing from the comments posted below, do the following to remove the keyring in a more simple fashion: 1) Go click Applications &#62; Accessories &#62; Passwords and Encryption keys 2) The should be entries there [...]]]></description>
			<content:encoded><![CDATA[<p><strong>UPDATE</strong>:  This post is almost 2 years old now and the method described below is somewhat obsolete (but still works).  Borrowing from the comments posted below, do the following to remove the keyring in a more simple fashion:</p>
<p>1) Go click<strong> Applications &gt; Accessories &gt; Passwords and Encryption keys</strong><br />
2) The should be entries there listing an array of keyring password.<br />
3) Right click on them and select change password<br />
4) Enter the old password if you have one then leave the new password blank. (A warning message should appear)</p>
<p>I&#8217;ve not done this personally (I haven&#8217;t had to) but if I&#8217;m guessing correctly, the &#8220;warning message&#8221; mentioned above in step 4 is likely the same warning message pictured below, asking if you are sure you want to use &#8220;Unsafe Storage&#8221;.  You can read more about what this means below.</p>
<p style="text-align: center;">&#8212;&#8212;&#8212;&#8212;&#8212;-[Begin old post]&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>I would have made the title of this post &#8220;How to remove the Keyring password manager in Ubuntu Linux&#8221; but that&#8217;s kinda long&#8230;  Anyway, you might be wondering what the keyring password manager is.  It is a built in feature of Ubuntu (specifically, a package called &#8220;<a href="http://projects.gnome.org/seahorse/" target="_blank">Seahorse</a>&#8220;) that remembers passwords for things like FTP account logins, Evolution Email accounts, your wireless network authentication passwords, etc., and locks them all behind a kind of Master Password of sorts.  So for example, lets pretend that the password for your wireless network was 64 characters long and was just a bunch of random numbers and letters that you&#8217;d only be able to remember if you were some kind of freak savant mathematician.  The keyring password manager would remember this for you, but will only allow the system to access and use that long password after you grant it access to the keyring.</p>
<p>As nice and handy as this might sound to security buffs, it&#8217;s struck me as a minor inconvenience.  For starts, if I were to configure Ubuntu to automatically login to my account after I turn the computer on, I would then also be asked to type in my keyring password so it would connect to my wireless network.  This becomes a bigger problem if, for instance, I were to connect to my computer remotely and had to reset it for some reason, like applying a recent kernel update.  The snag there would be that after restarting, my computer would boot up, but since I&#8217;m not physically sitting in front of it, it would sit there waiting for me to enter a keyring password before it would reconnect to my wireless network, and I&#8217;d have to go home or ask someone else to type in the password for me.</p>
<p>So what I&#8217;ve always wanted to have happen is this:</p>
<ul>
<li>I start or restart the computer by remote (such as through SSH or VNC).</li>
<li>After booting it automatically logs into my account and connects to my wireless network without asking for any passwords along the way so I can VNC right back into the system with no further trouble.</li>
</ul>
<p>I&#8217;ve finally learned how to do this, and it&#8217;s stupid easy to do.</p>
<p>There is of course a few security drawbacks about doing this.  For starts, if any person were to gain physical access to my machine they&#8217;d be able to connect to my wireless network without needing to enter a password. Then again, if someone I don&#8217;t trust has somehow gained physical access to my machine I might as well go ahead and consider it to be compromised.</p>
<p>Now, if the PC were in an office with a bunch of random co-workers always around, I&#8217;d be a lot more concerned.  If that were the case, I&#8217;d have that puppy locked down with a power on password, disable booting from the CD-ROM/Ethernet/USB in the BIOS, perhaps have a GRUB password and be working from an encrypted HD with the required /boot partition on a USB key, and of course auto-login would be disabled so I would be required to enter anywhere from 2 to 3 different passwords just to login to the system.  But this thing is in my house behind two large dogs and a dead-bolt locked door, functioning as a server that requires a password for me to access it by via SSH or VNC anyway.  So for this particular PC, I see little harm in opting out of using this security feature.</p>
<p>So here&#8217;s how you get rid of the keyring manager.  <strong>Please note:</strong> This will erase saved passwords you have so be sure you know or remember them before you make your computer forget them!</p>
<ol>
<li>Open up your Home Folder by clicking <strong>Places&gt;Home Folder</strong></li>
<li>Press <strong>CTRL-H</strong> (or click View&gt;Show Hidden Files)</li>
<li>Find a folder called<strong> .gnome2</strong> (it has a period at the beginning of the name) and open it by double clicking on it</li>
<li>Inside of the .gnome2 folder, there is another folder called <strong>keyrings</strong>.  Open it up.</li>
<li>Delete any files you find within the keyrings folder</li>
<li>Restart the computer</li>
</ol>
<p>After you restart and login (if you&#8217;re automatically logging in) you&#8217;ll probably be asked to enter your wireless networks WPA/WEP encryption key (because we made it forget).  After you type that password in, the keyring manager will appear to let you know that it would like to handle the storage of that password and lock it away with a new keyring.  The box looks like this:</p>
<p><img class="alignnone" src="http://www.davestechsupport.com/blog/images/keyring1.png" alt="" width="498" height="342" /></p>
<p>Instead of typing in a new password, leave both boxes completely empty and click Create.</p>
<p>You&#8217;ll then be asked if you know what the hell you&#8217;re doing:</p>
<p><img class="alignnone" src="http://www.davestechsupport.com/blog/images/keyring2.png" alt="" width="493" height="211" /></p>
<p>Go ahead and click <strong>Use Unsafe Storage</strong>.</p>
<p><strong><span style="color: #ff0000;">WARNING:</span></strong> Doing this creates a new file in your ~/.gnome2/keyrings/ folder called <strong>default.keyring</strong> and it will now house passwords IN CLEAR TEXT and not in an encrypted form.  So it is imperative that you are certain no untrustworthy persons can access your user account (either physically or by remote) or they will be able to easily open and read this file and obtain many passwords (for things such as FTP accounts, SSH, e-mail accounts, etc).  <span style="color: #ff0000;">Proceed with caution.</span></p>
<p>From here on all keyring-stored passwords you enter will not safeguarded behind a master password or encryption.  Whether or not you want to do this is entirely up to you.  I personally have had enough of the keyring manager and consider it kind of annoying.  But as I said before, you may have certain environmental factors that make having a master password over the rest of your passwords a good idea.  Keep in mind that the keyring password manager has absolutely nothing to do with your administrative/root privilages password that has to be entered any time you want to apply updates, or add/remove software.  You will still have to type your account password in for these actions, and that is something I am quite comfortable with. I&#8217;m just happy I don&#8217;t have to have to ask my girlfriend to type in a keyring password every time I want to restart the computer while I&#8217;m away from home.</p>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2009/01/16/how-to-remove-ubuntus-password-keyring/feed/</wfw:commentRss>
		<slash:comments>117</slash:comments>
		</item>
		<item>
		<title>&#8220;CRITICAL&#8221; Internet Explorer Flaw!  AGAIN!</title>
		<link>http://davestechsupport.com/blog/2008/12/17/critical-internet-explorer-flaw-again/</link>
		<comments>http://davestechsupport.com/blog/2008/12/17/critical-internet-explorer-flaw-again/#comments</comments>
		<pubDate>Wed, 17 Dec 2008 01:47:07 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[CCNA]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Rant]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/?p=605</guid>
		<description><![CDATA[As much as it would probably sooth the stiffness in my neck and shoulders from doing busy work inventorying computer equipment today, I&#8217;m going to try to not turn this into a sarcastic sounding slam against Microsoft&#8230; although they damn well deserve it. I&#8217;ll just keep this very short.  Internet Explorer has once again dropped [...]]]></description>
			<content:encoded><![CDATA[<p>As much as it would probably sooth the stiffness in my neck and shoulders from doing busy work inventorying computer equipment today, I&#8217;m going to try to not turn this into a sarcastic sounding slam against Microsoft&#8230; although they damn well deserve it.</p>
<p>I&#8217;ll just keep this very short.  Internet Explorer has once again dropped the ball in the realm of Internet security and it&#8217;s something that&#8217;s been present for over 48 hours already.  You can read about the problem via BBC&#8217;s website by <a href="http://news.bbc.co.uk/2/hi/technology/7784908.stm" target="_blank">clicking here</a>.</p>
<p>The article states in bold letters at the top, &#8220;Security experts recommend switching to a rival browser until the problem is fixed.&#8221;  Need a rival web browser?  Download Firefox at <a href="http://www.firefox.com" target="_blank">www.firefox.com</a>.  It&#8217;s free, faster and much more secure than Internet Explorer ever will be.  Seriously.  Why is it more secure, you ask?  Because it&#8217;s <a href="http://en.wikipedia.org/wiki/Open_source" target="_blank">open-source</a>, just like Linux.  But again&#8230; don&#8217;t wanna turn this into a &#8220;Microsoft sucks&#8221; bashing post.</p>
<p>Also, on the side, I should mention that I&#8217;ve see a LOT of Windows systems get hit with viruses in the last 3 weeks, a good chunk of which have come in from emails on Facebook.  Which isn&#8217;t to say that Facebook is bad.  It just doesn&#8217;t have much of an effective spam filter or virus scanner built into it.  You would think that after a few people have recieved the same spam from their friend whose computer was compromised, they&#8217;d start filtering messages with the same links, the same stupid subject line, and all the rest that comes along with basic social engineering-based viruses.  It&#8217;s what Yahoo and Google do.  So to you Facebook/Myspace users out there (and everyone else who doesn&#8217;t uses these services), be VERY cautious about clicking on links to websites you&#8217;ve never visited to before in email sent to you by a friend.  They may not have actually sent you something.  In fact, it&#8217;s possible their account password was phished, changed, and their account used as a lauch pad for spreading the same infection to other people (like you).  So be careful.</p>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2008/12/17/critical-internet-explorer-flaw-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is Social Engineering?</title>
		<link>http://davestechsupport.com/blog/2008/05/24/what-is-social-engineering/</link>
		<comments>http://davestechsupport.com/blog/2008/05/24/what-is-social-engineering/#comments</comments>
		<pubDate>Sat, 24 May 2008 18:33:12 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/?p=88</guid>
		<description><![CDATA[I came across a funny screenshot today that provides a pretty clear example of how social engineering is used to con people (in this case, Windows users) while browsing the Internet (click for full size): Clearly, this user is not running Windows XP but Ubuntu Linux.  Yet with their pop-up blocker disabled in Firefox 3, [...]]]></description>
			<content:encoded><![CDATA[<p>I came across a funny screenshot today that provides a pretty clear example of how social engineering is used to con people (in this case, Windows users) while browsing the Internet (click for full size):</p>
<p style="text-align: center;"><a href="http://www.davestechsupport.com/blog/images/xpscanner.png" target="_blank"><img src="http://www.davestechsupport.com/blog/images/xpscanner500.png" alt="" width="500" height="313" /></a></p>
<p>Clearly, this user is not running Windows XP but Ubuntu Linux.  Yet with their pop-up blocker disabled in Firefox 3, a malicious website presents a window that mimics a &#8220;real&#8221; warning.  But it&#8217;s actually a trap.  This is probably the most common reason viruses find their way into Windows systems &#8212; by exploiting a users lack of expertise and susceptibility to intimidation on a technical level.  So fair warning to you Windows users out there.  Fortunately for our Linux user, he&#8217;ll just laugh and close this window.  If you&#8217;re a Windows user and you see an alert like this, you should close it too (but run a virus scan using something like <a href="http://free.grisoft.com/" target="_blank">AVG</a> immediately afterwords).</p>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2008/05/24/what-is-social-engineering/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spoofing Holiday Inn Part 2</title>
		<link>http://davestechsupport.com/blog/2008/05/20/spoofing-holiday-inn-part-2/</link>
		<comments>http://davestechsupport.com/blog/2008/05/20/spoofing-holiday-inn-part-2/#comments</comments>
		<pubDate>Tue, 20 May 2008 22:05:55 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[Nintendo Wii]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/?p=86</guid>
		<description><![CDATA[In my previous blog, I wrote about staying at Holiday Inn and attempting to use their wireless networks to give my girlfriends&#8217; Nintendo Wii access to the Internet.  Gateway access to the Internet is not typically granted until you click on a button that binds you to terms of usage. Well, it turns out the [...]]]></description>
			<content:encoded><![CDATA[<p>In my previous blog, I wrote about staying at Holiday Inn and attempting to use their wireless networks to give my girlfriends&#8217; Nintendo Wii access to the Internet.  Gateway access to the Internet is not typically granted until you click on a button that binds you to terms of usage.</p>
<p>Well, it turns out the Wii itself is causing quite a bit of mystery.  Spoofing it&#8217;s MAC address, I was able to get the agreement page to re-appear on my laptop.  But after shutting Backtrack down and trying again, the Wii still couldn&#8217;t gain access to the Internet for some odd reason.</p>
<p>I went ahead and contacted their IT department and within a couple minutes, they had granted the MAC address of the Wii access to the Internet.  Yet it still doesn&#8217;t work.  Which&#8230; doesn&#8217;t exactly surprise me, especially after the IT guy told me I was the first person to attempt to connect a Wii while staying at a Holiday Inn.  We sat on the phone for about 15 minutes testing and testing, power cycling and testing again, but the Wii wasn&#8217;t doing anything except giving up.  It would seem that the IT department and myself are both stumped about this.  So for the time being, the spoofing tutorial is useless.  But still, it was a fun experiment.</p>
<p>In the meantime, I&#8217;m going to sit down with Google and see if I can find an alternate solution.  If I find one, I&#8217;ll be sure to write about it here.</p>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2008/05/20/spoofing-holiday-inn-part-2/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Spoofing Holiday Inn&#8217;s WiFi For Nintendo Wii</title>
		<link>http://davestechsupport.com/blog/2008/05/20/spoofing-holiday-in/</link>
		<comments>http://davestechsupport.com/blog/2008/05/20/spoofing-holiday-in/#comments</comments>
		<pubDate>Tue, 20 May 2008 07:36:33 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[Nintendo Wii]]></category>
		<category><![CDATA[Rant]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/?p=85</guid>
		<description><![CDATA[My girlfriend works as a manager for a major restaurant chain that has a catchy theme song about ribs. About a month ago, one of the restaurants located in a city about 50 minutes west of where we live lost three managers. I&#8217;m not very clear on the details, but I understand two walked out [...]]]></description>
			<content:encoded><![CDATA[<p>My girlfriend works as a manager for a major restaurant chain that has a catchy theme song about ribs.  About a month ago, one of the restaurants located in a city about 50 minutes west of where we live lost three managers.  I&#8217;m not very clear on the details, but I understand two walked out without giving advanced notice (why oh why, I <em>wonder</em>) and a third was fired for breaking a serious policy (I mean a federal law, but its been dealt with).  As a result, the place is essentially in a state of needing emergency life support.  They&#8217;ve called upon my girlfriend to help pick up the pieces (hopefully with the intention of letting her go someday, and not use this as an opportunity to coerce her to stay permanently).  So far, she&#8217;s been scheduled to stay through till the end of July, and this was a very recent revelation on the part of her boss.  I would not be surprised if &#8220;the end of July&#8221; becomes &#8220;the end of August&#8221; sometime soon.</p>
<p>Fortunately she is being put up in nice hotels (which I would imagine is coming out of her bosses bonus checks this year, and that sort of makes me feel a tad bit better about the whole long-distance relationship mini-drama).  But there are many days I can&#8217;t stay with her, and spending time in a hotel alone can get really boring after a month or two or three (hopefully not four, but I&#8217;m a little pessimistic at this point).</p>
<h3>Holiday Inn&#8217;s WiFi Meets Nintendo Wii</h3>
<p>One of the things my girlfriend purchased before this stretch of work was delivered to her was a Nintendo Wii.  I showed her at my house how to configure the wireless network connection settings and talked her through it over the phone when the time came.  But for some reason, it just wouldn&#8217;t connect.  By &#8220;connect&#8221;, I don&#8217;t mean wireless association followed by authentication (which, in this case, means nothing because the network does not use encryption).  What I mean is, you&#8217;re not granted gateway access to external IP addresses until you&#8217;ve clicked on a link indicating that you agree to certain legal usage terms.  Once you click the &#8220;I agree&#8221; button, you are then given full access to the Internet.</p>
<p style="text-align: center;"><img src="http://www.davestechsupport.com/blog/images/holidayinn.png" alt="" width="500" height="308" /></p>
<p>What the Nintendo Wii is trying to do is phone home (access Nintendo&#8217;s servers) immediately after it&#8217;s assigned a default gateway with the assumption that the gateway is not blocking traffic to external IP addresses.  If it were to ping the gateway, it would likely get a reply.  Any other site, nothing.  The Wii assumes your router to be working, but the cable modem is broken, so it gives up and asks you to try a different network.</p>
<p>Since I&#8217;ve already agreed to a certain group of usage terms I shouldn&#8217;t be required to click &#8220;agree&#8221; again so as to personally access the Internet.  But it&#8217;s the MAC address that acts as my identity, more like a name-badge, and the MAC on the Wii will be different from the MAC on the laptop.  Your MAC address is a hard-coded number used to uniquely identify your wireless networking adapter.  No two MAC addresses are said to be the same.  So at first, it would seem there&#8217;s nothing I can do with the Wii to get it to connect to the Internet&#8230;  Or is there?</p>
<h3>What can be done about this?</h3>
<p>There are a couple solutions.  The first is to contact customer service and see if they can get their IT guy on the phone.  I would then ask him if he could manually add the MAC address of the Wii to their routing tables and grant the device access.  For some, this would be the simpler solution&#8230; though your mileage may vary.  How long do you think it would take?  Because I really don&#8217;t feel like placing bets on them being immediately available.  I&#8217;m just telling you right now that the IT people at this particular hotel are not very advanced.  The reason I say this is because the channels they picked for their 3 routers are all within the same frequency range (channels 1, 2 and 3) instead of spread out (channels 1, 6 and 11).  In other words:  They&#8217;re not very professional.  Bandwidth is being lost because the routers are overlapping each others frequencies, and this is basic wireless network design technique we&#8217;re talking about here.</p>
<p>The other solution is to trick their wireless networks into thinking my laptop is the Wii and click &#8220;I agree&#8221; a second time, and then disconnect.  I would do this by changing the MAC address of my wireless adapter.  This is what is known as &#8220;MAC address spoofing&#8221;, the act of using a networking device to appear to be another (not to be confused with a &#8220;spoofing attack&#8221;, because we&#8217;re not going to attack anybody).  Not all networking devices can do this.  I happen to be using one that contains an Atheros chipset (it&#8217;s a <a href="http://www.google.com/products?q=D-Link+WNA-2330&amp;btnG=Search+Products&amp;hl=en" target="_self">D-Link WNA-2330</a> to be exact), which can be made to do anything I want it to do in the world of Linux.  (Another blog I&#8217;m going to write in the future about Wireless Adapter hacking is turning my laptop into a Wireless router, and then share my cellphone&#8217;s Internet access wirelessly).</p>
<h3>The Trick</h3>
<p>I intend to use a copy of <a href="http://en.wikipedia.org/wiki/BackTrack" target="_blank">Backtrack</a> 3 beta to carry out this little experiment.  But it&#8217;s late, I&#8217;m away from home and have to download a fresh ISO and burn it to a disc first before I can try this out.  By the way, spoofing a MAC address can be done in Windows, but I&#8217;m not going to write about Windows software that does this in here (because I&#8217;m lazy.  But if you&#8217;re really curious, <a href="http://www.google.com/search?hl=en&amp;q=spoof+mac+windows&amp;btnG=Google+Search" target="_blank">google can help</a>).</p>
<p>In Backtrack (or even Ubuntu if I install the MadWifi drivers, which is not as easy as burning a Backtrack Live CD) the commands to change the MAC are as follows (<a href="http://backtrack.offensive-security.com/index.php/Howto:_How_to_connect_to_the_internet_on_BT2_using_a_spoofed_MAC_address" target="_blank">reference link</a>):</p>
<ul>
<li><strong>wlanconfig ath0 destroy</strong></li>
</ul>
<p>You can use any mac address you like. In this example: 00:11:22:33:44:55</p>
<ul>
<li><strong>macchanger -m 00:11:22:33:44:55 wifi0<br />
</strong></li>
<li><strong>wlanconfig ath0 create wlandev wifi0 wlanmode managed </strong></li>
<li><strong>ifconfig wifi0 up</strong></li>
</ul>
<p>After this, I can just use a plain old connection manager to connect to the network.  I could also use this command to do it manually:</p>
<ul>
<li><strong>iwconfig ath0 essid [NetworkName] key [WepKeyHere]</strong></li>
</ul>
<p>Pretty simple.  Note though that if your card uses a chipset other than Atheros, you might not be able to do this with your card, and the first command &#8220;wlanconfig ath0 destroy&#8221; might be slightly different (like &#8220;eth1&#8243; for instance), depending on the device name Linux assigns your wireless adapter.</p>
<h3>Isn&#8217;t this a little extreme?</h3>
<p>If by &#8220;extreme&#8221; you mean &#8220;illegal&#8221;, the answer is no.  Spoofing doesn&#8217;t become illegal until you use it in  to acquire private information you&#8217;re not supposed to have access to (which requires a lot more work anyway).  The Nintendo Wii is flawed in that it doesn&#8217;t included a web browser with it by default, and even if it were installed, it wouldn&#8217;t believe it was actually able to connect to the Internet.  Perhaps I&#8217;ll send Nintendo a little suggestion so they&#8217;ll release a patch in their next update sweep.  Though it surprises me that they&#8217;ve not encountered this problem, considering they sell Nintendo <a href="http://images.google.com/images?q=wii%20carrying%20case&amp;ie=UTF-8&amp;oe=utf-8&amp;rls=com.ubuntu:en-US:unofficial&amp;client=firefox-a&amp;um=1&amp;sa=N&amp;tab=wi" target="_blank">Wii carrying cases</a> for smug Wii-owners to take their Wii&#8217;s to their non-Wii-owning friends&#8217; house so they can show it off over and over&#8230; though this probably doesn&#8217;t take place in nice Hotels with moderate network security in place. And Nintendo would probably ignore me because they charge people to buy their web browser (you have to be able to download it from their servers anyway), which is required to agree to view Holiday Inn&#8217;s agreement page.</p>
<p>So I suppose the next best place to put the blame is on Holiday Inn&#8230;.and we know that IT guy isn&#8217;t in the mood to revamp company policy (and I can&#8217;t really think of an easy solution, other than unblocking the MAC).  You see, it becomes this dilemma of, &#8220;Just how out of my way should I have to go?&#8221;  If I had a backtrack CD with me right now, I&#8217;d hopefully be able to solve this problem in 5 minutes.  To me, that&#8217;s the opposite of extreme.  I&#8217;d call it practical (for me).  For most people, they&#8217;re either stuck with a design flaw in their game console, or hotel Internet policies that were not designed to accommodate these kinds of dumb devices.  Quite a double-bind we have here.</p>
<p>Well, I&#8217;ve got some sleep to get&#8230;  At least they have nice pillows here and the bathroom sink is to die for!</p>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2008/05/20/spoofing-holiday-in/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Friendly Reminder:  Backup Your Data!</title>
		<link>http://davestechsupport.com/blog/2008/04/02/a-friendly-reminder-backup-your-data/</link>
		<comments>http://davestechsupport.com/blog/2008/04/02/a-friendly-reminder-backup-your-data/#comments</comments>
		<pubDate>Wed, 02 Apr 2008 02:25:28 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[Education]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/2008/04/02/a-friendly-reminder-backup-your-data/</guid>
		<description><![CDATA[A client of mine recently wiped his computer clean when they accidentally initiated a destructive recovery via the F10 key during POST. This caused their hard drive to be formated and their OS to be reinstalled as it was when it was originally installed at the factory. The lost files on the system were not [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center"><img src="http://www.davestechsupport.com/blog/images/gravewarning.png" height="196" width="500" /></p>
<p>A client of mine recently wiped his computer clean when they accidentally initiated a destructive recovery via the F10 key during <a href="http://en.wikipedia.org/wiki/Power-on_self-test" target="_blank">POST</a>.  This caused their hard drive to be formated and their OS to be reinstalled as it was when it was originally installed at the factory.  The lost files on the system were not recoverable, and the only alternative would be to have an advanced data forensics lab extract the old data off, the cost of which could go up as high as a couple thousand dollars.</p>
<p>There are some simple things you should get in the habit of doing if you want to decrease your odds of facing such a horrid situation as the one above:</p>
<h3 align="center">Unplug your PC when there is lightning outside</h3>
<p align="center"><img src="http://www.davestechsupport.com/blog/images/ifthen1.png" height="113" width="500" /></p>
<p>I shouldn&#8217;t have to tell people this, but some of you uber-nerds out there think that the bigger their basement-computer-bedroom-cave-hermit dwelling is, the more invincible they are.  It&#8217;s not a matter of probability of being struck, but probability of surviving a lightning strike unscathed.  Like the Black Knight from Monty Python.</p>
<p>Don&#8217;t let the price tag on that expensive Uninterrupted Power Supply fool you.  Its purpose isn&#8217;t to safe-guard you from a lightning strike, but to sustain power to your PC in the event of an unexpected outage and to compensate for brownouts and power spikes.  Lightning can still penetrate it and make its way to your computer.  Once there, it&#8217;s up in the air how much damage it might inflict, and hard to diagnose the extent of damage after the fact.  Every time I&#8217;ve seen a system that&#8217;s been hit by lightning, I&#8217;ve ended up having to tell people to buy a new computer, because so many parts were damaged in a split second.</p>
<p>Do what most people do during severe weather:  Watch TV till the power goes out, grab a radio and flash light, salvage the remaining beer from the unpowered refrigerator, and hope for the best when you regain consciousness in the morning.  Or whatever floats your boat.  If you have an Internet addiction like I do, use a wireless device like a laptop or a cell phone to get your info fix.</p>
<h3 align="center">Backup to an external storage device</h3>
<p align="center"> <img src="http://www.davestechsupport.com/blog/images/externalstorage.png" height="110" width="500" /></p>
<p>Here&#8217;s what I&#8217;ve got pictured above from left to right:</p>
<ul>
<li>An external USB hard drive.  Advantages:  Cheap for price per megabyte, easy to setup and use.  Disadvantages:  Subject to failure from old age after several years of use (see your warranty), and sometimes bulky (depends on how cheap you are).</li>
<li>A USB Flash Drive.  Advantages:  Small, handy, convenient,  instant plug-and-play capable (usually).  Disadvantages:  Must be replaced after about 250 uses, easy to misplace and lose (get a nice 4 dollar lanyard like I did). Costly if you have lots of data to backup.</li>
<li>A cell phone with a MicroSD card.  Same as the USB flash drive, but slower.  The advantage is that it&#8217;s in your phone, and you probably aren&#8217;t as likely to misplace that thing.</li>
<li>Network Attached Storage.  Network attached storage is basically a &#8220;computer-less&#8221; hard drive that attaches to your local network (router) and shares hard drive space to other computers on the network.  Advantage:  Highest fault tolerance (there are multiple copies of files spread across hard drives, so if one drive fails, the file is not lost).  Disadvantage:  Expensive.</li>
</ul>
<p>You can also backup data to external CD&#8217;s or DVD&#8217;s and keep them in a dark place.  Doing so will keep your data safe for a long time.  But it&#8217;s good to shed old storage media after several years of data sitting on them and move data to a fresher medium that is less likely to suddenly flake out unexpectedly.</p>
<p>You can also use software to automate backing data up.  A good one is <a href="http://amanda.zmanda.com/" target="_blank">Amanda Open Source Backup</a>.   I&#8217;ll write more about it sometime in the future.  But for now, you should consider using one of the external devices above and practice good habits to protect your computer and your documents from being lost.</p>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2008/04/02/a-friendly-reminder-backup-your-data/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Something Funny&#8230;</title>
		<link>http://davestechsupport.com/blog/2008/02/27/something-funny/</link>
		<comments>http://davestechsupport.com/blog/2008/02/27/something-funny/#comments</comments>
		<pubDate>Wed, 27 Feb 2008 14:22:28 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/2008/02/27/something-funny/</guid>
		<description><![CDATA[Click on the image below to see the entire screenshot]]></description>
			<content:encoded><![CDATA[<p>Click on the image below to see the entire screenshot  <img src='http://davestechsupport.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p align="center"><a href="http://www.davestechsupport.com/blog/images/computeratrisk.jpg" target="_blank"><img src="http://www.davestechsupport.com/blog/images/computeratrisk2.jpg" height="502" width="500" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2008/02/27/something-funny/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What if George Orwell had written about Net Neutrality?</title>
		<link>http://davestechsupport.com/blog/2007/11/25/what-if-george-orwell-had-written-about-net-neutrality/</link>
		<comments>http://davestechsupport.com/blog/2007/11/25/what-if-george-orwell-had-written-about-net-neutrality/#comments</comments>
		<pubDate>Sun, 25 Nov 2007 17:54:11 +0000</pubDate>
		<dc:creator>david_steinlage</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Internet Neutrality]]></category>
		<category><![CDATA[Piracy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://davestechsupport.com/blog/2007/11/25/what-if-george-orwell-had-written-about-net-neutrality/</guid>
		<description><![CDATA[(The Great Singularity will be continued in a later blog)&#8230; The Early Days of Wireless Networking The 1990&#8242;s was a period of great excitement for computer hobbyists and nerds alike. Particularly the few who enjoyed building electronic toys on breadboards with little capacitors and microchips from Radio Shack. As rare as such people are, I [...]]]></description>
			<content:encoded><![CDATA[<p><em>(<a title="The Great Singularity, Part 1" href="http://davestechsupport.com/blog/2007/11/24/the-great-singularity-part-1/">The Great Singularity</a> will be continued in a later blog)&#8230;</em></p>
<p><strong>The Early Days of Wireless Networking</strong></p>
<p>The 1990&#8242;s was a period of great excitement for computer hobbyists and nerds alike.  Particularly the few who enjoyed building electronic toys on <a title="What the hell is a breadboard?" href="http://en.wikipedia.org/wiki/Breadboard" target="_blank">breadboards</a> with little capacitors and microchips from Radio Shack.  As rare as such people are, I once knew a man named Rick who had actually built his own serial cable adapter to hook his 66Mhz  computer up to a CB radio and use it to send data over the air to someone else with the same setup on their end, using only radio frequencies to transmit data for miles and miles.  This little idea of wireless data sharing wasn&#8217;t all that ground breaking at the time, mostly because it was SLOWWWW.</p>
<p>Still, it was the early 90&#8242;s, and just plain <em>dial-up</em> Internet access was THE wet dream of nerds like myself and the fellow I mentioned above.  The Internet came late in the rural area I grew up in, so the next best thing was to connect directly to someone else&#8217;s computer via one means or another, usually a phone modem.  (I have many very fond memories of playing Duke Nukem with a friend by using our phone lines to dial each others&#8217; computers and start playing head to head.  It was a degree more personal, direct, instant and consequently more fun than most of today&#8217;s impersonal multi-player games played against strangers, I think, but that&#8217;s just my opinion).</p>
<p>Fortunately, dial-up (and later DSL and cable) availability soon swept the nation, and most computer users now had a dependable method to access this so-called Internet.  The old lost hobby of transmitting data from one computer wirelessly to another located miles away &#8212; seemingly for nothing more than a tiny fraction of your electric bill &#8212; became obsolete compared to the fast speed of 14.4 baud modem that was always available (unless you were using the busy-signal service provider AOL).  It also had the added benefit of being a network with many millions of regular and increasingly diverse users.  Suddenly, you didn&#8217;t have to be a student in a university to get access to hundreds of thousands of interesting websites and anybody could get an e-mail address from Yahoo with their very own 2 MB mailbox for free.  The Internet was in the early stages of flowering, and many ISP services popped up to offer access for about 20 or 30 bucks a month.</p>
<p>Trying to build your own private network wirelessly with a CB radio wasn&#8217;t a bad idea. But if you had tried to do what Rick had done with a CB radio, and attempted to send a file the size of a 3 1/2 floppy over the air, it would have probably of taken at least an hour to send the whole thing. By comparison today, the same file can be downloaded via standard cable Internet in just 2 seconds (even over today&#8217;s wireless networks).  In fact an increasing number of home users are now installing wireless networks in their homes for the convenience of being able to put their laptop anywhere in the house and get access to the Internet.  This makes me wonder:  What if the entire Internet were to be rebuilt (theoretically) with wireless radio signals instead of copper and fiber optics?  We&#8217;ll come back to this idea later&#8230;</p>
<p><strong>Net Neutrality</strong></p>
<p>You have probably heard the term Net Neutrality come across the news on occasion, but not really have much of an understanding of what it is.  In short, Net Neutrality is exercised when an ISP such as Cox, Road Runner or Comcast refuse to interfere with your Internet bandwidth based upon the types of traffic sent over the wire to your computer.  An example of what a non-neutral ISP might do is if they sell their Internet in tiered packages, sold the same way cable companies sell their TV channel packages.  You get the standard cable for X dollars, the premium channels for X dollars more, then there&#8217;s pay per view, etc.  Do you want the Internet to be sold and regulated like that?</p>
<p style="text-align: center;"><img class="aligncenter" src="http://www.davestechsupport.com/blog/images/censoredinternet.png" alt="Net Neutrality down the shitter" width="500" height="365" /></p>
<p style="text-align: center">(Don&#8217;t worry.  It&#8217;s fake&#8230;.for now)</p>
<p>The current debate going on in congress is whether or not regulations should be put in place that would prevent companies like Cox or Comcast from establishing such tiered packages.  Since the debate was brought to Congress in the middle of 2006, every bill proposed thus far <a title="History of attempted legislation" href="http://en.wikipedia.org/wiki/Network_neutrality_in_the_United_States#Attempted_legislation" target="_blank">has been killed</a>.   In a world where the Internet is packaged and sold under dubious terms and conditions such as limiting which websites you are allowed to visit, you&#8217;d soon realize that restricting access in such a manner would brush up against violating the First Ammendment.</p>
<p>One of the overlooked reasons behind cable based ISPs wanting to restrict and split Internet access into more controllable tiers is bandwidth usage by P2P file-sharing protocols such as the popular <a title="Wikipedia: Bittorrent" href="http://en.wikipedia.org/wiki/BitTorrent" target="_blank">Bittorrent</a>, which uses an efficient <a title="Wikipedia: Mesh-Toplogy" href="http://en.wikipedia.org/wiki/Mesh_topology" target="_blank">mesh-topology</a> for sharing files.  It allows users to upload and download files to each other in &#8220;swarms&#8221;, spreading the overhead of file transfer across many users at once, instead of relying on one individual to get stuck with the overhead of sending the whole file to multiple users one after another.  The end result: You could theoretically share a file with thousands (if not millions) of people in the same amount of time as it used to take to share it with just 2 or 3 users.</p>
<p style="text-align: center"><img src="http://upload.wikimedia.org/wikipedia/commons/3/3d/Torrentcomp_small.gif" alt="Bittorrent in action" width="357" height="334" /></p>
<p style="text-align: center" align="left">(Above: Bittorrent in action, starting with one &#8220;seed&#8221; and seven &#8220;leeches&#8221; which all become seeds themselves in the end)</p>
<p style="text-align: center" align="left">
<p align="left">While a majority of Bittorrent traffic on the web is currently used for illegal file-sharing, it is also a technology that is used for legitimate purposes and poses unlimited potential to TV program producers.  So much so that large TV networks will <a title="Video:  The future of Bittorrent" href="http://video.google.com/videoplay?docid=2479010476120721247" target="_blank">inevitably use it to distribute their programs</a> (new value chain = Producer&lt;Advertiser), instead of through tradition means (Producer&lt;Distributor&lt;Broadcaster&lt;Advertiser); effectively cutting out middle men like Direct TV or Cox and replacing them with the Internet in general.  The term used to describe TV distributed via Bittorrent or similar file sharing protocols is called &#8220;hyper distribution,&#8221; and it&#8217;s a threat Cable companies are <a title="Comcast controversy" href="http://en.wikipedia.org/wiki/Comcast#Blocking_Internet_Access" target="_blank">attempting to squash</a>.</p>
<p>So what do you do when your ISP starts to block your downloads when ABC start to distribute Desperate Housewives over the Internet for free?  Well, you&#8217;d do the natural thing, and choose a competing ISP who doesn&#8217;t filter your traffic&#8230; But what if that wasn&#8217;t a very easy thing to do?  In a world where you are forced to seek out an alternative method of accessing an uncensored Internet, it might be difficult to find an outlet.  Because if one ISP practices such traffic filtering, what would stop others from following suit in some form?  What if DSL Internet access suddenly cost a lot more money so you could access and download legitimate, legal torrent files?  What then?</p>
<p><strong>Municipal Wireless Internet </strong></p>
<p>There are many metropolitan areas in the US that have established or are attempting to build what is called a <a title="MuniWifi" href="http://en.wikipedia.org/wiki/Municipal_broadband" target="_blank">Municipal Broadband</a> Wireless Internet.  This is essentially a government supported infrastructure that allows anyone in the public free or low-cost wireless Internet access from anywhere within city limits.  You could be sitting on a park bench reading Yahoo News for instance and it would be paid for by tax dollars.  The flaw with this setup (from an Orwellian perspective) is that it was built by the government, or at least heavily subsidized by it.  This defaults to them the ability to regulate and/or monitor that particular avenue of Internet access more quickly and at their discretion.  After all, they built it via tax dollars you gave them in the first place, which governments like ours so often use in our best interests&#8230; right?</p>
<p><strong>Enter Orwell&#8217;s Internet (Tinfoil hats optional)<br />
</strong></p>
<p>At this point I will attempt to introduce elements of a hypothetical scenario that George Orwell would have likely written into his classic novel <a title="Info about the book, " href="http://en.wikipedia.org/wiki/Nineteen_Eighty-Four" target="_blank">1984</a> had he known the Internet would exist on such a global scale as it does today.  Granted, it is hard to picture what such a world would be like &#8212; where the information you are allowed to download to your computer is sanctioned and closely monitored by your own government.  But all you have to do is look at the <a title="Wikipedia: Internet Censorship" href="http://en.wikipedia.org/wiki/Internet_censorship" target="_blank">many places</a> in the world that actually practice heavy Internet censorship, like <a title="The great Firewall of China." href="http://en.wikipedia.org/wiki/Golden_Shield_Project" target="_blank">China</a> or <a title="Burma.  A place of state-run media and Internet blackouts during the killing of many monks..." href="http://www.dailymail.co.uk/pages/live/articles/news/worldnews.html?in_article_id=484903" target="_blank">Burma</a>, to see that such restrictions exist in many places and are very scary to think about.</p>
<p>Could such restrictions and unwarranted surveillance be visited upon the general public here in America?   To a degree, <a title="Wikipedia:  NSA warrantless surveillance controversy" href="http://en.wikipedia.org/wiki/NSA_warrantless_surveillance_controversy" target="_blank">it already does occur</a>, though it&#8217;s exercised under the banner of national security and anti-terrorism efforts.  There is a remote possibility that it could get a lot worse, but that strongly depends on the public&#8217;s misunderstanding about topics like <a title="Wikipedia: Net Neutrality in the US" href="http://en.wikipedia.org/wiki/Network_neutrality_in_the_United_States" target="_blank">Net Neutrality</a>, combined with the heavy lobbying efforts put forth by the nations largest media corporations, not to mention who ever happens to be President at the time and what the FCC has to say about it. So what I&#8217;d like to bring up is this remote possibility of such intense government regulations over the Internet taking place, and why such a scenario would never actually fly if it were implemented in the US.</p>
<p>So far I&#8217;ve touched base on the boom of the Internet, followed by Net Neutrality and now the dawn of Municipal WiFi, with a warning that it&#8217;s not so delightful a thing in a typical Orwellian dystopia:  Googleing the word &#8220;democracy&#8221; would get you no search results.  Personal privacy would be complete fantasy, everybody would be their own brothers policeman, so on and so forth.  You&#8217;d be surprised what a government might be able to get its own citizens to do with enough fear propaganda.  Ask any German who lived when Hitler was in power, or anyone from China who is accustomed to reading state sanctioned &#8220;news.&#8221;</p>
<p>Fortunately, things are much better off for us today.  We have an Internet that is still very very neutral and open and booming.  Blogging and alternative channels of news are replacing mainstream news, and criticism of the Iraq war and our current President (for instance) are at an all time high.  I believe the Internet is the primary reason for such rapid disapproval percentages.  Back in the days of Vietnam, you didn&#8217;t see hundreds of thousands of people protesting in the streets of New York <em>before </em>the invasion.  You didn&#8217;t see approval ratings of the war and the president drop until after 20,000 of our men were killed.  And you likely didn&#8217;t hear any open commentary on the TV about whether or not the <a title="Wikipedia:  Gulf of Tonkin Incident" href="http://en.wikipedia.org/wiki/Gulf_of_Tonkin_Incident" target="_blank">Gulf of Tonkin Incident</a> had actually occurred, since such news was dictated down to the media by the government, who simply transcribed and repeated the line.  Why?  Well, probably because the Internet as we know it today didn&#8217;t exist, nor anything like it at that time.</p>
<p>Now the tables are turned, as there is an infinite choice of outlets to get information at the click of a mouse.  The Internet isn&#8217;t just a great resource for finding information, but also for finding diverse opinions, instead of canned opinions espoused by pundits.  You see, news papers and TV stations and magazines are essentially owned by their advertisers.  That doesn&#8217;t sound quite right at first but that&#8217;s the way it&#8217;s always been in the mainstream.  What you see reported or discussed on TV is strongly influenced by the money that is coming in from advertisers.  If a news report holds a potential for dramatically affecting the bottom line of a company that pays the news outlet money to advertise, it might choose to take it&#8217;s money elsewhere, lest the news outlet leave certain bits out, or <a title="Monsanto and Fox News in 1997" href="http://video.google.com/url?docid=7716141285497881772&amp;esrc=sr2&amp;ev=v&amp;len=599&amp;q=monsanto%2Bfox&amp;srcurl=http%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DaxU9ngbTxKw&amp;vidurl=%2Fvideoplay%3Fdocid%3D7716141285497881772%26q%3Dmonsanto%2Bfox%26total%3D17%26start%3D0%26num%3D10%26so%3D0%26type%3Dsearch%26plindex%3D1&amp;usg=AL29H21qOqVfIRNO2-a-RT-Tc-tQgVR-AQ" target="_blank">drop a story all together</a>.  The increased use of the Internet for gathering and cross-referencing the veracity behind a headline or article or even an opinionated blog (like this one) is a sign of great change in our culture.  Whether it be by leaving a comment, starting their own blog, using Digg to bring attention to something important, organizing a grassroots organization, whatever, the bottom line is the public now feels an increased sense of empowerment and participation and ability to be more involved with political movements.</p>
<p>But what if access were suddenly limited?  What if, in a perfect George Orwell dystopia, the Internet as we know it died, and was replaced with one where public dissent is censored, its authors secretly jailed, and all the rest that goes with living within an absolute monarchy?  How might a freedom-willed public which has roots going back to the Constitution or Bill of Rights counter act such an anti-democratic place when the most popular form of communication is swept out from under them and controlled by some invisible overlord?</p>
<p><strong>Wireless Darknet </strong></p>
<p>Remember Rick?  The guy who had successfully sent data to someone else using a computer and his own CB radio?  We&#8217;ve come a long way from that kind of technology.  Today, we have Wireless B and G, soon to be Wireless N, and others yet to be invented.  Wireless N is pretty noteworthy as it will be able to go about 4-8 times faster than Wireless G.  Let&#8217;s put this in perspective.  The average cable modem can download ~5 megabits of data per second and upload ~0.60 per second.  Wireless N is capable of uploading <em>and </em>downloading ~240 Megabits per second simultaneously.  That&#8217;s 48 times faster than cable!</p>
<p>Now, think back on how Bittorrent works.  Every person (or node) on the network uploads and downloads to a few other people simultaneously as a collective swarm.  This is called a mesh-topology, where each users acts as a client/server and pseudo-router at the same time.  Lets say you were to build a network of a few thousand computers on a Wireless N backbone, combining the bandwidth of all nodes together, and you&#8217;d have yourself one damn fast network of computers.  Those computers could all share their own resources with each other if they wish, such as files or other networks they&#8217;re connected to that are off the grid (such as the &#8220;real&#8221; Internet), acting as a source or simply an intermediary between two points.</p>
<p style="text-align: center"><img src="http://upload.wikimedia.org/wikipedia/en/4/4e/Self-form-self-heal.gif" alt="Self-Repairing Wireless Mesh" width="500" height="251" /></p>
<p>So what does Orwell have to say about all this?  Well, he&#8217;d probably pipe up and start asking about security.  If your data is being transmitted over the web through dozens, if not thousands of other computers in the public, whats keeping someone from capturing your data out of the air and stealing information from you?  The same question could be asked about the Internet as it exists today, but doesn&#8217;t come up much because you&#8217;re supposed to trust your ISP not to spy on you.  One answer to this problem is strong encryption.  In addition, cypher keys could shift at random intervals, making the task of locking onto one for the purposes of exploiting it extremely difficult, if not entirely pointless.</p>
<p>There are obviously more details and concerns that arise from attempting to build such a wireless darknet of sorts, but simply knowing that you could easily get it off the ground with the right software speaks volumes.  Especially to the millions of people in America who already own wireless adapters on their home PC&#8217;s and Laptops.  You theoretically wouldn&#8217;t even have to purchase any new hardware; it&#8217;s already in place if you live in the right neighborhood.  The difference would be in how you use it, and a simple piece of software could take care of that.</p>
<p>The idea of a wireless darknet being built in a country where Internet censorship is exercised is not new, just unconventional for us at the moment.  However, China is one country that has all the right ingredients for seeing such a technology take off:  high-tech culture, dictatorship, aggressive suppression of political dissent, and most importantly a high population density.  Now all they need is a little motivation.  It doesn&#8217;t take much for us Americans to get motivated though. We&#8217;d more likely embrace a darknet of sorts simply to save a lot of money than we would to read the news or post a blog.  Nevertheless, it is an option we have at our disposal.</p>
]]></content:encoded>
			<wfw:commentRss>http://davestechsupport.com/blog/2007/11/25/what-if-george-orwell-had-written-about-net-neutrality/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

