Make Money

Freelance Jobs Freelance Jobs
Showing posts with label windows Xp. Show all posts
Showing posts with label windows Xp. Show all posts

16.12.11

ICS-CERT Warns of Hardcoded Backdoors in Industrial Control Systems

Delicious Digg StumbleUpon Reddit Subscribe to RSS Feed

Independent security researcher Rubén Santamarta has published details of hardcoded backdoors in the Schneider Electric NOE771 Quantum Ethernet Module. Subsequently the US Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) has published an alert warning of the multiple vulnerabilities in the module.
The backdoors are as follows:
  • Telnet port – May allow remote attackers the ability to view the operation of the module’s firmware, cause a denial of service, modify the memory of the module, and execute arbitrary code.
  • Windriver Debug port – Used for development; may allow remote attackers to view the operation of the module’s firmware, cause a denial of service, modify the memory of the module, and execute arbitrary code.
  • FTP service – May allow an attacker to modify the module website, download and run custom firmware, and modify the http passwords.
Rubén’s research shows are creditionals are hardcoded in Java Jar files stored on the device. For example Rubén shows the ftp username (‘sysdiag’) and password. The result is that:
  • Modicon PLCs can be compromise via the NOE Ethernet modules through ftp, telnet, modbus, WDB, snmp, web etc.
  • An attacker could load their own trojanized firmware.
  • There are non-documented hidden accounts that can be used to compromise a PLC.
The affected products are:
Quantum
  • 140NOE77101 Firmware Version 4.9 and all previous versions.
  • 140NOE77111 Firmware Version 5.0 and all previous versions.
  • 140NOE77100 Firmware Version V3.4 and all previous versions.
  • 140NOE77110 Firmware Version V3.3 and all previous versions.
  • 140CPU65150 Firmware Version V3.5 and all previous versions.
  • 140CPU65160 Firmware Version V3.5 and all previous versions.
  • 140CPU65260 Firmware Version V3.5 and all previous versions.
Premium
  • TSXETY4103 Firmware Version V5.0 and all previous versions.
  • TSXETY5103 Firmware Version V5.0 and all previous versions.
  • TSXP571634M Firmware Version V4.9 and all previous versions.
  • TSXP572634M Firmware Version V4.9 and all previous versions.
  • TSXP573634M Firmware Version V4.9 and all previous versions.
  • TSXP574634M Firmware Version V3.5 and all previous versions.
  • TSXP575634M Firmware Version V3.5 and all previous versions.
  • TSXP576634M Firmware Version V3.5 and all previous versions.
M340
  • BMXNOE0100 Firmware Version V2.3 and all previous versions.
  • BMXNOE0110 Firmware Version V4.65 and all previous versions.
  • BMXP342020 Firmware Version V2.2 and all previous versions.
  • BMXP342030 Firmware Version V2.2 and all previous versions.
STB DIO
  • STBNIC2212 Firmware Version V2.10 and all previous versions.
  • STBNIP2311 Firmware Version V3.01 and all previous versions.
  • STBNIP2212 Firmware Version V2.73 and all previous versions.

Schneider Electric has created a fix for the Telnet and Windriver debug port vulnerabilities for the BMXNOE0100 and 140NOE77101 modules by removing them from the firmware. The fixes will be published on the Schneider website.

9.12.11

5 Steps To Securing Your Windows XP Home Computer

Delicious Digg StumbleUpon Reddit Subscribe to RSS Feed

Most people are aware that there are continuous security issues with Microsoft’s Windows operating system and other programs. However, what most people do not realize is how easy it is to significantly improve your computer’s security and reduce the likelihood of becoming a victim to ever increasingly sophisticated threats that lurk on the internet. These steps should take less than a couple of hours to complete and should not clean out your wallet.
1) Windows Update – the first crucial step you need to take to make sure that all your Microsoft applications have all the latest product updates installed. These updates or “patches” address security vulnerabilities and other issues. Microsoft usually issues these updates on a monthly cycle. Visit the Microsoft website or switch on automatic updates from the Windows Control panel. Even if your “new” computer is second hand this is still a critical first step. If you buy a used computer with Windows XP make sure Service Pack 2 or SP2 is installed.
2) Strong Passwords – people often overlook this but having well thought through passwords is an important element of your computer security. A strong password should include at least 8 characters with a mixture of text, symbols and numbers. As a minimum you need to make sure the services most at risk have a strong log-in password. These services include your bank, credit card, other financial services like PayPal, your email address and any other services like Ebay which hackers can use to generate profit.
3) Anti Virus Protection – while it is fair to say the threat of the computer virus has receded during the last couple of years they can still inflict serious damage on your computer. Part of the reason why the threat has reduced is because PC manufactures are now more frequently bundling anti virus packages with their new computers. For example last year my new Dell shipped with a 90-day trial of McAfee’s Internet Security Suite. The best bet here is to purchase a security package which includes firewall and anti virus software as a minimum. Top brands include McAfee and Symantec Norton products. However, Microsoft has recently entered the market with their “OneCare” offering which is very aggressively priced.
4) Firewall – if you are using a broadband connection then a firewall is definite requirement to manage the traffic flowing between your computer and the internet. A firewall monitors the inbound internet traffic passing through the ports of your computer. Better products also monitor outbound traffic from your computer to the internet. As per above the best bet here is buy a firewall application as part of a security package which most vendors offer as standard. If a hardware firewall is included as part of your router package then you do not need anything else. A company called Zone Labs offer a great free firewall product called Zone Alarm which should be used as a minimum. Windows XP does now ship with a free firewall but the product does not monitor outbound communication and therefore I believe does not offer adequate protection.
5) Anti Spyware Tool – this software is the last piece in your basic internet security set up. This tool helps combat spyware and adware. There is a good mixture of free and paid versions on offer. Good free software include Microsoft’s Windows Defender, Spybot S&D or Ewido Anti-Malware. Ewido Anti-Malware is frequently recommended in computer help forums. Be careful if you decide to purchase a solution. There are a number of rogue vendors out there which aggressively push products which offer you little value. Stick to trusted names like Webroot’s Spy Sweeper or PC Tool’s Spyware Doctor. These products always come out well on independent tests.

3.12.11

Windows Xp Sp3 DarkLite Edition (2011)

Delicious Digg StumbleUpon Reddit Subscribe to RSS Feed


Release Information :-

The best XP OS in 2011
have all update at December
have a great graphic from "Catalog" designer
Original, updateable and activated
no need serial , bootable

VIP Note :-

The Develpoer made two versions
* SATA Version (have all updates and SATA driver only)
* Driver Version (have all updates, SATA driver and all cheapest driver only)

This one here is SATA Version cuz its smaller (510 MB)
and more faster than anther version
download

 

HOW TO HACK Copyright © 2010 LKart Theme is Designed by Lasantha