Re: [SWCollect] Spyware

2004-03-12 Thread Jim Leonard
Marco Thorek wrote:
Yeah, you are right. Thunderbird looks pretty neat. I don't seem to be
able to find the info on its website, so I am asking you: Can you use it
as a newsgroup reader and can I import my mails from Navigator to it?
Mail:  You should be able to, but I never have (all my email is IMAP). 
As for newsgroups, yes, but I think there are better newsreaders out 
there than Netscape/Thunderbird (many free, actually).

I certainly didn't know that. And, to be honest, I am still sticking to
NN 4.54 less for security reasons but because I'm so used to it ;-)
I was the same way, but I got tired of the crashing on goofy HTML mail 
(I don't like or prefer HTML mail, but I certain didn't want previewing 
the message to crash the mailer!)

I hope we can soon say the same about Germany. How did the US get rid of
them?
We all switched to broadband ;-)

Disclaimer:  I *am* a security engineer during the day ;-)
This list sure has some added benefits ;-)

If I may ask: Who do you work for? 
Check Point Software.  We make FireWall-1, if you've heard of it.
--
Jim Leonard ([EMAIL PROTECTED])
World's largest electronic gaming project:http://www.MobyGames.com/
A delicious slice of the demoscene:http://www.MindCandyDVD.com/
Various oldskool PC rants and ramblings:   http://www.oldskool.org/
--
This message was sent to you because you are currently subscribed to
the swcollect mailing list.  To unsubscribe, send mail to 
[EMAIL PROTECTED] with a subject of 'unsubscribe swcollect'
Archives are available at: http://www.mail-archive.com/[EMAIL PROTECTED]/



Re: [SWCollect] Spyware

2004-03-09 Thread Jim Leonard
Spybot Search and Destroy is slightly better than Ad-Aware, but has a 
slightly less intuitive interface.  It's the one I use.

[EMAIL PROTECTED] wrote:

I had a LOT of spyware on my computer as I've been using same 
drive/programs for a long time (like close to 100 spybots). If you'd 
like to check these sites are free (scan and REMOVE, many ask you to pay 
to remove). If anyone runs I'd be interested in hearing results (see if 
anyone has more than I did). I run both as spyware items are hard coded 
it seems, one might find some the other misses.

http://www.safer-networking.org/
http://www.lavasoftusa.com/
Tom



Visit my web page for many games for sale/trade and screen shots of 
Ultima Escape from Mt. Drash,  Tom's Ultima, Infocom and RPG page 
http://members.aol.com/tommage/UltimaPage/ultima.htm


--
Jim Leonard ([EMAIL PROTECTED])
World's largest electronic gaming project:http://www.MobyGames.com/
A delicious slice of the demoscene:http://www.MindCandyDVD.com/
Various oldskool PC rants and ramblings:   http://www.oldskool.org/
--
This message was sent to you because you are currently subscribed to
the swcollect mailing list.  To unsubscribe, send mail to 
[EMAIL PROTECTED] with a subject of 'unsubscribe swcollect'
Archives are available at: http://www.mail-archive.com/[EMAIL PROTECTED]/



Re: [SWCollect] Spyware

2004-03-09 Thread Jim Leonard
Don't enable preview for attachments, because some exploits have been 
written to take advantage of that behavior.  Instead, simply don't open 
any attachment at all unless you know what it is and who it came from.

BL wrote:

Spyware is really common now in days - if you've had an active PC for a 
while, then suddenly decide to run these programs, yes, you are 
absolutely going to find a lot of stuff, from tracking cookies and 
dialers to memory resident programs  hijacks you didnt even know were 
starting at boot-up.  I know first hand, since I'm the computer-savy one 
of the family, I've seen some seriously messed up computers, and it's 
gotten about 10 times as bad in the past 2 or 3 years.  Ad-aware is the 
best thing you can do for it, combined with educating yourself on a few 
tecniques for removal.  I run Ad-aware once a week after doing the 
online update to the definitions file and I find anywhere from 25-50 new 
malicious components -- for the most part, just cookies from blacklisted 
hosts.  That combined with checking my task manager's running processes 
every so often to make sure there's nothing i don't recognize running.  
Prevention is the best defense as always, and the best tips I can give 
are: Enable preview for attachments in Outlook Express, and never Open 
them, save them to disk.  When surfing websites, never click a windows 
pop-up box that gives you an Ok / Cancel choice or something like that 
-- malicious coders often spoof an approval to install something on your 
computer with such misleading dialogs.  When those pop-up, use ALT-F4 to 
close it, without choosing either.  And of course, make sure you are up 
to date with all the Windows XP / Explorer / Outlook security patches 
from Microsoft.com.

- Original Message -
*From:* [EMAIL PROTECTED] mailto:[EMAIL PROTECTED]
*To:* [EMAIL PROTECTED] mailto:[EMAIL PROTECTED]
*Sent:* Monday, March 08, 2004 8:22 AM
*Subject:* [SWCollect] Spyware
I had a LOT of spyware on my computer as I've been using same
drive/programs for a long time (like close to 100 spybots). If you'd
like to check these sites are free (scan and REMOVE, many ask you to
pay to remove). If anyone runs I'd be interested in hearing results
(see if anyone has more than I did). I run both as spyware items are
hard coded it seems, one might find some the other misses.
http://www.safer-networking.org/
http://www.lavasoftusacom/
Tom



Visit my web page for many games for sale/trade and screen shots of
Ultima Escape from Mt. Drash,  Tom's Ultima, Infocom and RPG page
http://members.aol.com/tommage/UltimaPage/ultima.htm 


--
Jim Leonard ([EMAIL PROTECTED])
World's largest electronic gaming project:http://www.MobyGames.com/
A delicious slice of the demoscene:http://www.MindCandyDVD.com/
Various oldskool PC rants and ramblings:   http://www.oldskool.org/
--
This message was sent to you because you are currently subscribed to
the swcollect mailing list.  To unsubscribe, send mail to 
[EMAIL PROTECTED] with a subject of 'unsubscribe swcollect'
Archives are available at: http://www.mail-archive.com/[EMAIL PROTECTED]/



Re: [SWCollect] Spyware

2004-03-09 Thread Marco Thorek
I have a personal firewall on my system, less of fear that someone might
try to come in, but that something might try to phone home. 

For example, a couple of weeks ago I installed a friend's OCR software
for testing and it installed a TSR along with it: even when the OCR
program wasn't running, the freaking thing tried to contact its makers.

The firewall also quarantines any suspicious mail attachments, but as
mail client I use good ole' Navigator 4.54 anyway. Some of those
attachments aim for weaknesses in OE, and my Navigator is simply too old
to understand all that fancy stuff. 

A program I can wholeheartedly reccommend in this context is Robin
Keir's K9, that uses a Bayes algorithm to weed out spam (and things like
the important update from Microsoft alongs with it):

http://www.keir.net/k9.html

BTW, the hottest issue regarding those little malicious buggers around
here in Germany were and are dialers - trojans that replace your
normal internet connection without your knowledge with 0190 numbers (for
you Americans: 1-900 numbers). For dial-up users this generated some
hefty bills.

The billing's done by the phone companies who own the lines and so they
send all their might and lawyers after you, if you don't pay. They don't
do that out of any unselfishness either, as a certain percentage of the
generated income goes to them for providing the line. 

It has been until now that a higher court here in Germany decided that a
user fooled that way must not pay and that the phone company cannot ask
for more than what would have been generated through use of the normal
internet connection. 

Is the rest of the world as ridden by those dialers as we are around
here?

Marco

[EMAIL PROTECTED] schrieb:
 
 I had a LOT of spyware on my computer as I've been using same
 drive/programs for a long time (like close to 100 spybots). If you'd
 like to check these sites are free (scan and REMOVE, many ask you to
 pay to remove). If anyone runs I'd be interested in hearing results
 (see if anyone has more than I did). I run both as spyware items are
 hard coded it seems, one might find some the other misses.
 
 http://www.safer-networking.org/
 http://www.lavasoftusa.com/
 
 Tom
 
 Visit my web page for many games for sale/trade and screen shots of
 Ultima Escape from Mt. Drash,  Tom's Ultima, Infocom and RPG page

--
This message was sent to you because you are currently subscribed to
the swcollect mailing list.  To unsubscribe, send mail to 
[EMAIL PROTECTED] with a subject of 'unsubscribe swcollect'
Archives are available at: http://www.mail-archive.com/[EMAIL PROTECTED]/



Re: [SWCollect] Spyware

2004-03-09 Thread Jim Leonard
Marco Thorek wrote:

For example, a couple of weeks ago I installed a friend's OCR software
for testing and it installed a TSR along with it: even when the OCR
program wasn't running, the freaking thing tried to contact its makers.
Yes, well, have you considered it was trying to look for a new/updated version 
of itself?  :-)  Not all phone home software is malicious.

The firewall also quarantines any suspicious mail attachments, but as
mail client I use good ole' Navigator 4.54 anyway. Some of those
You should switch to Thunderbird.  I finally did last year and it's great.

attachments aim for weaknesses in OE, and my Navigator is simply too old
to understand all that fancy stuff. 
Not true!  In fact, your version has a documented vulnerability!

A program I can wholeheartedly reccommend in this context is Robin
Keir's K9, that uses a Bayes algorithm to weed out spam (and things like
Yes, a Bayesian filter is built into Thunderbird.

Is the rest of the world as ridden by those dialers as we are around
here?
No, that was a very old thing back in 1994-1996 and I don't think Americans 
have seen them since.

Disclaimer:  I *am* a security engineer during the day ;-)
--
Jim Leonard ([EMAIL PROTECTED])http://www.oldskool.org/
Want to help an ambitious games project? http://www.mobygames.com/
Or check out some trippy MindCandy at http://www.mindcandydvd.com/
--
This message was sent to you because you are currently subscribed to
the swcollect mailing list.  To unsubscribe, send mail to 
[EMAIL PROTECTED] with a subject of 'unsubscribe swcollect'
Archives are available at: http://www.mail-archive.com/[EMAIL PROTECTED]/



Re: [SWCollect] Spyware

2004-03-09 Thread Marco Thorek
Jim Leonard schrieb:
 
 Yes, well, have you considered it was trying to look for a new/updated version
 of itself?  :-)  Not all phone home software is malicious.

Actually, no. I am probably getting a little paranoid.
 
  The firewall also quarantines any suspicious mail attachments, but as
  mail client I use good ole' Navigator 4.54 anyway. Some of those
 
 You should switch to Thunderbird.  I finally did last year and it's great.

Yeah, you are right. Thunderbird looks pretty neat. I don't seem to be
able to find the info on its website, so I am asking you: Can you use it
as a newsgroup reader and can I import my mails from Navigator to it?

  attachments aim for weaknesses in OE, and my Navigator is simply too old
  to understand all that fancy stuff.
 
 Not true!  In fact, your version has a documented vulnerability!

I certainly didn't know that. And, to be honest, I am still sticking to
NN 4.54 less for security reasons but because I'm so used to it ;-)
 
 No, that was a very old thing back in 1994-1996 and I don't think Americans
 have seen them since.

I hope we can soon say the same about Germany. How did the US get rid of
them?
 
 Disclaimer:  I *am* a security engineer during the day ;-)

This list sure has some added benefits ;-)

If I may ask: Who do you work for? 

Marco

--
This message was sent to you because you are currently subscribed to
the swcollect mailing list.  To unsubscribe, send mail to 
[EMAIL PROTECTED] with a subject of 'unsubscribe swcollect'
Archives are available at: http://www.mail-archive.com/[EMAIL PROTECTED]/



[SWCollect] Spyware

2004-03-08 Thread AvatarTom
I had a LOT of spyware on my computer as I've been using same drive/programs for a long time (like close to 100 spybots). If you'd like to check these sites are free (scan and REMOVE, many ask you to pay to remove). If anyone runs I'd be interested in hearing results (see if anyone has more than I did). I run both as spyware items are hard coded it seems, one might find some the other misses.

http://www.safer-networking.org/
http://www.lavasoftusa.com/

Tom



Visit my web page for many games for sale/trade and screen shots of Ultima Escape from Mt. Drash, Tom's Ultima, Infocom and RPG page 


Re: [SWCollect] Spyware

2004-03-08 Thread Christopher Forman
Tom,

I've been using Ad-Aware (LavaSoft) for awhile now. The basic version is free and removes most known spyware. I run it about once a week.
[EMAIL PROTECTED] wrote:
I had a LOT of spyware on my computer as I've been using same drive/programs for a long time (like close to 100 spybots). If you'd like to check these sites are free (scan and REMOVE, many ask you to pay to remove). If anyone runs I'd be interested in hearing results (see if anyone has more than I did). I run both as spyware items are hard coded it seems, one might find some the other misses.http://www.safer-networking.org/http://www.lavasoftusa.com/TomVisit my web page for many games for sale/trade and screen shots of Ultima Escape from Mt. Drash, Tom's Ultima, Infocom and RPG page 

Re: [SWCollect] Spyware

2004-03-08 Thread BL



Spyware is really common now in days - if you've 
had an active PC for a while, then suddenly decide to run these programs, yes, 
you are absolutely going to find a lot of stuff, from tracking cookies and 
dialers to memory resident programs  hijacksyou didnt even know were 
starting at boot-up. I know first hand, since I'm the computer-savy one of 
the family, I've seen some seriously messed up computers, and it's gotten about 
10 times as bad in the past 2 or 3 years. Ad-aware is the best thing you 
can do for it, combined with educating yourself on a few tecniques for 
removal. I run Ad-aware once a week after doing the online update to the 
definitions file and I find anywhere from 25-50 new malicious components -- for 
the most part, just cookies from blacklisted hosts. That combined with 
checking my task manager's running processes every so often to make sure there's 
nothing i don't recognize running. Prevention is the best defense as 
always, and the best tips I can give are: Enable preview for attachments in 
Outlook Express, and never Open them, save them to disk. When surfing 
websites, never click a windows pop-up box that gives you an Ok / Cancel choice 
or something like that -- malicious coders often spoof an approval to install 
something on your computer with such misleading dialogs. When those 
pop-up, use ALT-F4 to close it, without choosing either. And of course, 
make sure you are up to date with all the Windows XP / Explorer / Outlook 
security patches from Microsoft.com.

  - Original Message - 
  From: 
  [EMAIL PROTECTED] 
  To: [EMAIL PROTECTED] 
  Sent: Monday, March 08, 2004 8:22 
AM
  Subject: [SWCollect] Spyware
  I had a LOT of spyware on my computer as I've been 
  using same drive/programs for a long time (like close to 100 spybots). If 
  you'd like to check these sites are free (scan and REMOVE, many ask you to pay 
  to remove). If anyone runs I'd be interested in hearing results (see if anyone 
  has more than I did). I run both as spyware items are hard coded it seems, one 
  might find some the other 
  misses.http://www.safer-networking.org/http://www.lavasoftusacom/TomVisit 
  my web page for many games for sale/trade and screen shots of Ultima Escape 
  from Mt. Drash, Tom's Ultima, 
  Infocom and RPG page 


Re: [SWCollect] Spyware

2004-03-08 Thread Lee K. Seitz
Dan Chisarick stated:

And last, run a web browser (Mozilla, Safari, whatever) that has=
integrated popup-blocking.  Anything but IE.  Spare yourself some pain
before it starts.

I can't argue against not using IE, except that some sites don't
always work well with something else.  I use the Google toolbar in IE,
which now includes popup blocking.

-- 
Lee K. Seitz
[EMAIL PROTECTED]

--
This message was sent to you because you are currently subscribed to
the swcollect mailing list.  To unsubscribe, send mail to 
[EMAIL PROTECTED] with a subject of 'unsubscribe swcollect'
Archives are available at: http://www.mail-archive.com/[EMAIL PROTECTED]/



Re: [SWCollect] Spyware

2004-03-08 Thread AvatarTom
In a message dated 03/08/2004 7:48:11 PM Central Standard Time, [EMAIL PROTECTED] writes:


Spybot seek  destroy is also excellent. A 
previous post had both links.


You have to be careful with this one. Here's why, someone told me to get spybot. So I searched for it. Took me to site spybot.com (and came up first at google I think). But that site is NOT spybot!! Some people taking advantage of the good name. THEY make you PAY for the removal. Owner of the "real" spybot is trying to do something about it. So if you get something that asks you to pay, it is NOT the real spybot, I listed the true link earlier.

Tom
Visit my web page for many games for sale/trade and screen shots of Ultima Escape from Mt. Drash, Tom's Ultima, Infocom and RPG page