<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Comprehensive Computer &#187; Online</title>
	<atom:link href="http://www.ledanet.org/tag/online/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ledanet.org</link>
	<description>www.ledanet.org</description>
	<lastBuildDate>Wed, 01 Feb 2012 11:40:48 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Random Scanning</title>
		<link>http://www.ledanet.org/random-scanning/</link>
		<comments>http://www.ledanet.org/random-scanning/#comments</comments>
		<pubDate>Thu, 29 Sep 2011 15:41:56 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[aggressiveness]]></category>
		<category><![CDATA[amount]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[attacker]]></category>
		<category><![CDATA[block]]></category>
		<category><![CDATA[Cable]]></category>
		<category><![CDATA[cable modem]]></category>
		<category><![CDATA[class]]></category>
		<category><![CDATA[Classically]]></category>
		<category><![CDATA[cleanup]]></category>
		<category><![CDATA[cleanup efforts]]></category>
		<category><![CDATA[cluster]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[corporate networks]]></category>
		<category><![CDATA[course]]></category>
		<category><![CDATA[coverage]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[generator]]></category>
		<category><![CDATA[hop]]></category>
		<category><![CDATA[host]]></category>
		<category><![CDATA[infect]]></category>
		<category><![CDATA[infestation]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[internet security]]></category>
		<category><![CDATA[island]]></category>
		<category><![CDATA[likelihood]]></category>
		<category><![CDATA[link]]></category>
		<category><![CDATA[maximum]]></category>
		<category><![CDATA[method]]></category>
		<category><![CDATA[middle]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[modem]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[network space]]></category>
		<category><![CDATA[node]]></category>
		<category><![CDATA[noisy]]></category>
		<category><![CDATA[number]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[pace]]></category>
		<category><![CDATA[pattern]]></category>
		<category><![CDATA[period]]></category>
		<category><![CDATA[persistence]]></category>
		<category><![CDATA[pool]]></category>
		<category><![CDATA[potential victims]]></category>
		<category><![CDATA[presence]]></category>
		<category><![CDATA[random network]]></category>
		<category><![CDATA[random number generator]]></category>
		<category><![CDATA[random walk]]></category>
		<category><![CDATA[random walks]]></category>
		<category><![CDATA[range]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[section]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sense]]></category>
		<category><![CDATA[space]]></category>
		<category><![CDATA[spread]]></category>
		<category><![CDATA[survivability]]></category>
		<category><![CDATA[target]]></category>
		<category><![CDATA[target network]]></category>
		<category><![CDATA[Thirdly]]></category>
		<category><![CDATA[time]]></category>
		<category><![CDATA[tracking]]></category>
		<category><![CDATA[traffic]]></category>
		<category><![CDATA[traffic issues]]></category>
		<category><![CDATA[type]]></category>
		<category><![CDATA[use]]></category>
		<category><![CDATA[value]]></category>
		<category><![CDATA[walk]]></category>
		<category><![CDATA[way]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.ledanet.org/?p=155</guid>
		<description><![CDATA[The spread of the worm in its most basic sense depends most greatly on how it chooses its victims. This not only affects the spread and pace of the worm network, but also its survivability and persistence as cleanup efforts begin. Classically, worms have used random walks of the Internet to find hosts and attack. [...]]]></description>
			<content:encoded><![CDATA[<p>The spread of the worm in its most basic sense depends most greatly on how it chooses its victims. This not only affects the spread and pace of the worm network, but also its survivability and persistence as cleanup efforts begin. Classically, worms have used random walks of the Internet to find hosts and attack. However, new attack models have emerged that demonstrate increased aggressiveness.</p>
<p>The simplest way for a worm to spread as far as it can is to use random network scanning. In this method, the worm node randomly generates a network to scan, typically a block of 65,000 hosts (a /16 network) or 256 hosts (a /24) in a target network block. This worm node then begins to search for potential victims in that network space and attacks vulnerable hosts. This random walk is the classic spread model for network-based worms.<br />
<span id="more-155"></span><br />
However, there are some issues with this method, of course. The first is that the pool of addresses in use on the Internet tends to cluster to the middle, typically between 128/8 and 220/8. However, sizable and interesting networks reside outside of this, such as cable modem networks in 24/4 and 64/4, along with several large, well-known corporate networks in this range. To be effective, the worm should focus its efforts on hosts that are likely to be vulnerable to its exploits as well as being widely found.</p>
<p>Secondly, it is easy to pick a network block that is sparsely populated. This then wastes the node’s time by scanning a network section that will contain few, if any, hosts it can attack or compromise. The likelihood of this is dependent on the network space chosen. Several of the class A networks below 127/8 that are almost completely unused. Some of these networks are used by researchers to study Internet security patterns or traffic issues.</p>
<p>Thirdly, it is important to have a good random number generator in use to achieve almost complete coverage of the chosen range. A weak random number generator will mean that some networks will be disproportionately scanned. Some networks may not be scanned at all when this occurs.</p>
<p>The advantages of this type of scanning are that, when properly executed, near total coverage of the Internet can be accomplished within a brief period of time. This can be of value for an attacker who wishes to gain access to the maximum number of hosts in a reasonable amount of time. Second, this type of worm is bound to be more persistent than a directed or island based scanning worm. Not every network will be able to eradicate the worm infestation, and the worm will hop from one network to others randomly, constantly finding a host to infect.</p>
<p>While the worm is likely to find a vulnerable host it can compromise within a potentially rich network, it is likely to hop out of the network again as it randomly generates a new network to scan. Also, this type of scanning pattern is very noisy and highly visible. As described above, the scanning of sparsely populated networks is likely, and a simple tracking of this will reveal the presence of a worm. Get more details information of worms with searching it online or from other research <a href="http://essaysreasy.org/" target="_blank">link</a> or articles.</p>]]></content:encoded>
			<wfw:commentRss>http://www.ledanet.org/random-scanning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ramen worm</title>
		<link>http://www.ledanet.org/ramen-worm/</link>
		<comments>http://www.ledanet.org/ramen-worm/#comments</comments>
		<pubDate>Mon, 26 Sep 2011 09:51:19 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[address]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[author]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[banner]]></category>
		<category><![CDATA[case]]></category>
		<category><![CDATA[class]]></category>
		<category><![CDATA[com]]></category>
		<category><![CDATA[complexity]]></category>
		<category><![CDATA[cycle]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[default]]></category>
		<category><![CDATA[default installations]]></category>
		<category><![CDATA[Design]]></category>
		<category><![CDATA[dissection]]></category>
		<category><![CDATA[e mail]]></category>
		<category><![CDATA[Eat]]></category>
		<category><![CDATA[efficiency]]></category>
		<category><![CDATA[entry]]></category>
		<category><![CDATA[etermine]]></category>
		<category><![CDATA[evidence]]></category>
		<category><![CDATA[Examination]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[file]]></category>
		<category><![CDATA[file manipulation]]></category>
		<category><![CDATA[flexibility]]></category>
		<category><![CDATA[flooding]]></category>
		<category><![CDATA[format]]></category>
		<category><![CDATA[FTPd]]></category>
		<category><![CDATA[future]]></category>
		<category><![CDATA[garden]]></category>
		<category><![CDATA[generator]]></category>
		<category><![CDATA[host]]></category>
		<category><![CDATA[hotmail]]></category>
		<category><![CDATA[infection]]></category>
		<category><![CDATA[instance]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[intelligence database]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[kiddy]]></category>
		<category><![CDATA[lack]]></category>
		<category><![CDATA[library]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[life cycle]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[linux versions]]></category>
		<category><![CDATA[LPR]]></category>
		<category><![CDATA[magazine]]></category>
		<category><![CDATA[mail]]></category>
		<category><![CDATA[mail messages]]></category>
		<category><![CDATA[mail spool]]></category>
		<category><![CDATA[Manipulation]]></category>
		<category><![CDATA[manipulation methods]]></category>
		<category><![CDATA[Max Vision]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[network address]]></category>
		<category><![CDATA[novel]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[ownership]]></category>
		<category><![CDATA[package]]></category>
		<category><![CDATA[packet]]></category>
		<category><![CDATA[phrase]]></category>
		<category><![CDATA[portion]]></category>
		<category><![CDATA[potential]]></category>
		<category><![CDATA[problem]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[Ramen]]></category>
		<category><![CDATA[realm]]></category>
		<category><![CDATA[Reconnaissance]]></category>
		<category><![CDATA[RedHat]]></category>
		<category><![CDATA[redhat linux]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[RPC]]></category>
		<category><![CDATA[science]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[set]]></category>
		<category><![CDATA[shell]]></category>
		<category><![CDATA[spool]]></category>
		<category><![CDATA[spread]]></category>
		<category><![CDATA[statd]]></category>
		<category><![CDATA[string]]></category>
		<category><![CDATA[string format]]></category>
		<category><![CDATA[subject]]></category>
		<category><![CDATA[SYN]]></category>
		<category><![CDATA[system]]></category>
		<category><![CDATA[tar]]></category>
		<category><![CDATA[target]]></category>
		<category><![CDATA[target host]]></category>
		<category><![CDATA[TCP]]></category>
		<category><![CDATA[tgz]]></category>
		<category><![CDATA[usage]]></category>
		<category><![CDATA[variety]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[yahoo]]></category>

		<guid isPermaLink="false">http://www.ledanet.org/?p=143</guid>
		<description><![CDATA[Ramen worm which appeared in late 2000 to early 2001, and characterize this instance. Max Vision has written an excellent dissection of the Ramen worm, including the life cycle, which should also be studied. In mapping these components to a worm found in the wild, we can see how they come together to form a [...]]]></description>
			<content:encoded><![CDATA[<p>Ramen worm which appeared in late 2000 to early 2001, and characterize this instance. Max Vision has written an excellent dissection of the Ramen worm, including the life cycle, which should also be studied. In mapping these components to a worm found in the wild, we can see how they come together to form a functional worm.</p>
<p>Ramen was a monolithic worm, which is to say that each instance of an infected host has the same files placed on it with the same capabilities. There exists some flexibility by using three different attack possibilities and by compiling the tools on both RedHat Linux versions 6.2 and 7.0, but each set of files (obtained as the tar package “ramen.tgz”) is carried with each instance of the worm.<br />
<span id="more-143"></span><br />
The reconnaissance portion of the Ramen worm was a simple set of scanners for the vulnerabilities known to the system. Ramen combined TCP SYN scanning with banner analysis to etermine the infection potential of the target host. It used a small random class B (/16) network generator to determine what networks to scan.</p>
<p>The specific attacks known to Ramen were threefold: FTPd string format exploits against wu-ftpd 2.6.0, RPC.statd Linux unformatted strings exploits, and LPR string format attacks.</p>
<p>The system’s intelligence database was updated using e-mail messages from the system once it was infected to two central e-mail addresses. The e-mail contains the phrase “Eat Your Ramen!” with the subject as the network address of the infected system. The mail spool of the two accounts was therefore the intelligence database of infected machines.</p>
<p>Unused capabilities can be summarized as the other two exploits not used to gain entry into the system, which allow for some flexibility in targeting either RedHat 6.2 or 7.0 default installations. Ramen did not contain any additional attack capabilities, such as packet flooding techniques, nor did it contain any file manipulation methods.</p>
<p>In analyzing the complexity of the Ramen worm the author has cobbled together several well-known exploits and worm components and as methods utilizing only a few novel small binaries. Examination of the shell scripting techniques used shows low programming skills and a lack of efficiency in design.</p>
<p>These findings have two ramifications. First, it shows how easy it is to put together an effective worm with minimal coding or networking skills. Simply put, this is certainly within the realm of a garden variety “script kiddy” and will be a persistent problem for the foreseeable future. Second, it leaves, aside from any possible ownership or usage of the yahoo.com and hotmail.com e-mail accounts, very little hard evidence to backtrack to identify the worm’s author.</p>
<p>If you do need <a href="http://yourwritingassistant.com/" target="_blank">help writing essays</a> from above discussing, I believe online materials are widely spread on the internet, but in case you&#8217;d like to determine that was the correct sources, compare it with books and research on public library or science magazine.</p>]]></content:encoded>
			<wfw:commentRss>http://www.ledanet.org/ramen-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Attack Elements</title>
		<link>http://www.ledanet.org/attack-elements/</link>
		<comments>http://www.ledanet.org/attack-elements/#comments</comments>
		<pubDate>Wed, 21 Sep 2011 11:32:44 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[computer]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[admi]]></category>
		<category><![CDATA[administrator]]></category>
		<category><![CDATA[alert]]></category>
		<category><![CDATA[application]]></category>
		<category><![CDATA[area]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[aware application]]></category>
		<category><![CDATA[being]]></category>
		<category><![CDATA[buffer]]></category>
		<category><![CDATA[buffer overflows]]></category>
		<category><![CDATA[cannot]]></category>
		<category><![CDATA[client]]></category>
		<category><![CDATA[client socket]]></category>
		<category><![CDATA[clog]]></category>
		<category><![CDATA[component]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[credential]]></category>
		<category><![CDATA[cycle]]></category>
		<category><![CDATA[detection]]></category>
		<category><![CDATA[e mail]]></category>
		<category><![CDATA[element]]></category>
		<category><![CDATA[entry]]></category>
		<category><![CDATA[escalation]]></category>
		<category><![CDATA[example]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[factor]]></category>
		<category><![CDATA[gain entry]]></category>
		<category><![CDATA[generation]]></category>
		<category><![CDATA[Horse]]></category>
		<category><![CDATA[host]]></category>
		<category><![CDATA[infection]]></category>
		<category><![CDATA[instance]]></category>
		<category><![CDATA[intrusion]]></category>
		<category><![CDATA[intrusion detection systems]]></category>
		<category><![CDATA[latter]]></category>
		<category><![CDATA[macroscopic view]]></category>
		<category><![CDATA[mail client]]></category>
		<category><![CDATA[method]]></category>
		<category><![CDATA[migration]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[monitoring systems]]></category>
		<category><![CDATA[nature]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[network component]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[opencart]]></category>
		<category><![CDATA[platform]]></category>
		<category><![CDATA[presence]]></category>
		<category><![CDATA[prevalent element]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[session]]></category>
		<category><![CDATA[session hijacking]]></category>
		<category><![CDATA[shop]]></category>
		<category><![CDATA[signature]]></category>
		<category><![CDATA[signature generation]]></category>
		<category><![CDATA[socket]]></category>
		<category><![CDATA[system]]></category>
		<category><![CDATA[systems gain]]></category>
		<category><![CDATA[target]]></category>
		<category><![CDATA[target platforms]]></category>
		<category><![CDATA[theft]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[trojan horse]]></category>
		<category><![CDATA[type]]></category>
		<category><![CDATA[use]]></category>
		<category><![CDATA[vectors]]></category>
		<category><![CDATA[victim]]></category>
		<category><![CDATA[view]]></category>
		<category><![CDATA[weight]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[zencart]]></category>

		<guid isPermaLink="false">http://www.ledanet.org/?p=134</guid>
		<description><![CDATA[The worm’s attack components are their most visible and prevalent element. This is the means by which worm systems gain entry on remote systems and begin their infection cycle. These methods can include the standard remote exploits, such as buffer overflows, cgi-bin errors, or similar, or they can include Trojan horse methods. An example of [...]]]></description>
			<content:encoded><![CDATA[<p>The worm’s attack components are their most visible and prevalent element. This is the means by which worm systems gain entry on remote systems and begin their infection cycle. These methods can include the standard remote exploits, such as buffer overflows, cgi-bin errors, or similar, or they can include Trojan horse methods. An example of the latter would be the use of an infected executable being sent to an e-mail client by a worm as one of its attack vectors.</p>
<p>This component has to be further subdivided into two portions: the platform on which the worm is executing and the platform of the target. This attack element can be a compiled binary or an interpreted script, which utilizes a network component from the attacking host, such as a client socket or a network aware application, to transfer itself to its victim.<br />
<span id="more-134"></span><br />
A main factor of the attack component is the nature of the target being attacked, specifically its platform and operating system. Attack components that are limited to one platform or method rely on finding hosts vulnerable to only this particular exploit. For a worm to support multiple vectors of compromise or various target platforms of a similar type, it must be large.</p>
<p>This extra weight can slow down any one instance of a worm attack or, in a macroscopic view, more quickly clog the network. Other attacks include session hijacking and credential theft (such as passwords and cookies) attacks. Here the attack does not involve any escalation of privileges, but does assist the worm in gaining access to additional systems.</p>
<p>These attack elements are also most often used in intrusion detection signature generation. Since the attack is executed between two hosts and over the network, it is visible to monitoring systems. This provides the most accessible wide area monitoring of the network for the presence of an active worm. However, it requires a signature of the attack to trigger an alert. Furthermore, passive intrusion detection systems cannot stop the worm, and the administrator is alerted to the presence of the worm only as it gains another host.</p>
<p>The most important attack is online shop attack, when it happens, several things should be done such as migration <a href="http://www.shopping-cart-migration.com/shopping-cart-migration-options/868-opencart-to-zencart-migration" target="_blank">opencart vs zencart</a>, so it is important to keep your sites secure.</p>]]></content:encoded>
			<wfw:commentRss>http://www.ledanet.org/attack-elements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Threat Models</title>
		<link>http://www.ledanet.org/new-threat-models/</link>
		<comments>http://www.ledanet.org/new-threat-models/#comments</comments>
		<pubDate>Wed, 14 Sep 2011 11:42:42 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[computer]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[1990s]]></category>
		<category><![CDATA[active code]]></category>
		<category><![CDATA[advantage]]></category>
		<category><![CDATA[aggressiveness]]></category>
		<category><![CDATA[application]]></category>
		<category><![CDATA[application suites]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[book]]></category>
		<category><![CDATA[Broadband]]></category>
		<category><![CDATA[broadband technologies]]></category>
		<category><![CDATA[CAIDA]]></category>
		<category><![CDATA[center]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[concern]]></category>
		<category><![CDATA[connectivity]]></category>
		<category><![CDATA[course]]></category>
		<category><![CDATA[day]]></category>
		<category><![CDATA[dial up modems]]></category>
		<category><![CDATA[essay]]></category>
		<category><![CDATA[everyone]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[help]]></category>
		<category><![CDATA[high profile]]></category>
		<category><![CDATA[home]]></category>
		<category><![CDATA[hosts]]></category>
		<category><![CDATA[hour]]></category>
		<category><![CDATA[indiscriminacy]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[large scale]]></category>
		<category><![CDATA[minute]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[networking research center]]></category>
		<category><![CDATA[Nimda]]></category>
		<category><![CDATA[number]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[online book reports]]></category>
		<category><![CDATA[operating]]></category>
		<category><![CDATA[operating systems]]></category>
		<category><![CDATA[paper]]></category>
		<category><![CDATA[pool]]></category>
		<category><![CDATA[popularity]]></category>
		<category><![CDATA[problem]]></category>
		<category><![CDATA[profile systems]]></category>
		<category><![CDATA[Red]]></category>
		<category><![CDATA[red worm]]></category>
		<category><![CDATA[release]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[scale]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[several thousand]]></category>
		<category><![CDATA[sign]]></category>
		<category><![CDATA[situation]]></category>
		<category><![CDATA[Something]]></category>
		<category><![CDATA[study]]></category>
		<category><![CDATA[support]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[Treat]]></category>
		<category><![CDATA[user]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[worms]]></category>
		<category><![CDATA[worry]]></category>

		<guid isPermaLink="false">http://www.ledanet.org/?p=118</guid>
		<description><![CDATA[Until recently, network security was something that the average home user did not have to understand. Hackers were not interested in cruising for hosts on the dial-up modems of most private, home-based users. The biggest concern to the home user was a virus that threatened to wipe out all of their files (which were never [...]]]></description>
			<content:encoded><![CDATA[<p>Until recently, network security was something that the average home user did not have to understand. Hackers were not interested in cruising for hosts on the dial-up modems of most private, home-based users. The biggest concern to the home user was a virus that threatened to wipe out all of their files (which were never backed up, of course).</p>
<p>Now the situation has changed. Broadband technologies have entered the common home, bringing the Internet at faster speeds with 24-hour connectivity. Operating systems and their application suites became network centric, taking advantage of the Internet as it grew in popularity in the late  1990s. And hackers decided to go for the number of machines compromised and not high-profile systems, such as popular Web sites or corporate systems.<br />
<span id="more-118"></span><br />
The threat of attack is no longer the worry of only government or commercial sites. Worms now heighten this threat to home-based users, bringing total indiscriminacy to the attack. Now everyone attached to the Internet has to worry about worms. </p>
<p>The aggressiveness of the Code Red II worm is a clear sign that compromise is now everyone’s worry. Shortly after the release of Code Red, a study conducted by the networking research center CAIDA showed just how large scale a worm problem can be. Their estimates showed that nearly 360,000 computers were compromised by the Code Red worm in one day alone, with approximately 2,000 systems added to the worm’s pool every minute. Even 8 months after the Code Red worm was introduced several thousand hosts remained active Code Red and Nimda hosts.</p>
<p>Thus this new treat are distributed online, and you could seek some help through <a href="http://bestonlineessays.com/" target="_blank">online book reports</a> for support in essay and terms paper online.</p>]]></content:encoded>
			<wfw:commentRss>http://www.ledanet.org/new-threat-models/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Integrity Check</title>
		<link>http://www.ledanet.org/integrity-check/</link>
		<comments>http://www.ledanet.org/integrity-check/#comments</comments>
		<pubDate>Thu, 01 Sep 2011 07:29:06 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[computer]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[allure]]></category>
		<category><![CDATA[anti virus software]]></category>
		<category><![CDATA[batch]]></category>
		<category><![CDATA[batch files]]></category>
		<category><![CDATA[behavior]]></category>
		<category><![CDATA[change]]></category>
		<category><![CDATA[checker]]></category>
		<category><![CDATA[checkers]]></category>
		<category><![CDATA[checksum]]></category>
		<category><![CDATA[Checksums]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[companion]]></category>
		<category><![CDATA[essay]]></category>
		<category><![CDATA[exception]]></category>
		<category><![CDATA[Executable]]></category>
		<category><![CDATA[executable file]]></category>
		<category><![CDATA[executable files]]></category>
		<category><![CDATA[execution]]></category>
		<category><![CDATA[file]]></category>
		<category><![CDATA[help]]></category>
		<category><![CDATA[integrity]]></category>
		<category><![CDATA[integrity checker]]></category>
		<category><![CDATA[interesting materials]]></category>
		<category><![CDATA[kernel]]></category>
		<category><![CDATA[Language]]></category>
		<category><![CDATA[language programs]]></category>
		<category><![CDATA[mechanisms]]></category>
		<category><![CDATA[Offline]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[original]]></category>
		<category><![CDATA[positioning]]></category>
		<category><![CDATA[problem]]></category>
		<category><![CDATA[scripting language]]></category>
		<category><![CDATA[Self-checking]]></category>
		<category><![CDATA[shell]]></category>
		<category><![CDATA[shell scripts]]></category>
		<category><![CDATA[shells]]></category>
		<category><![CDATA[system]]></category>
		<category><![CDATA[system kernel]]></category>
		<category><![CDATA[technique]]></category>
		<category><![CDATA[unauthorized changes]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[way]]></category>
		<category><![CDATA[week]]></category>
		<category><![CDATA[writing an essay]]></category>

		<guid isPermaLink="false">http://www.ledanet.org/?p=107</guid>
		<description><![CDATA[With the exception of companion viruses, viruses operate by changing files. An integrity checker exploits this behavior to find viruses, by watching for unauthorized changes to files.
Integrity checkers must start with a perfectly clean, 100% virus-free system, it is impossible to understate this. The integrity checker initially computes and stores a checksum for each file [...]]]></description>
			<content:encoded><![CDATA[<p>With the exception of companion viruses, viruses operate by changing files. An integrity checker exploits this behavior to find viruses, by watching for unauthorized changes to files.</p>
<p>Integrity checkers must start with a perfectly clean, 100% virus-free system, it is impossible to understate this. The integrity checker initially computes and stores a checksum for each file in the system it&#8217;s watching. Later, a file&#8217;s checksum is recomputed and compared against the original, stored checksum. If the checksums are different, then a change to the file occured.<br />
<span id="more-107"></span><br />
There are three types of integrity checker:<br />
1. Offline. Checksums are only verified periodically, e.g., once a week. </p>
<p>2. Self-checking. Executable files are modified to check themselves when run. Ironically, modifying executables to self-check their integrity involves virus-like mechanisms. Self-checking can be done in a less-obtrusive way by adding the self-checking code into shared libraries.</p>
<p>In general, anti-virus software will perform integrity self-checking, regardless of the anti-virus technique it uses. The allure of attacking anti-virus software is too great to ignore.</p>
<p>3 Integrity shells. An executable file&#8217;s checksum is verified immediately prior to execution. This can be incorporated into the operating system kernel for binary executable files; the ideal positioning is less clear for other types of &#8220;executable&#8221; files, like batch files, shell scripts, and scripting language programs.</p>
<p>As viruses are interesting materials to be learn, you&#8217;ll might found it as a good one for your essay. But then you&#8217;ll know that writing an essay might not be so easy. If you need it, <a href="http://topessayhelp.com" target="_blank">essay help online</a> able to solve your problem.</p>]]></content:encoded>
			<wfw:commentRss>http://www.ledanet.org/integrity-check/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Reverse Firewalls</title>
		<link>http://www.ledanet.org/reverse-firewalls/</link>
		<comments>http://www.ledanet.org/reverse-firewalls/#comments</comments>
		<pubDate>Tue, 09 Aug 2011 23:00:05 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[computer]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[activity]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[alternative methods]]></category>
		<category><![CDATA[animation]]></category>
		<category><![CDATA[avi]]></category>
		<category><![CDATA[basis]]></category>
		<category><![CDATA[behavior]]></category>
		<category><![CDATA[bridge]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[bundle]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[case]]></category>
		<category><![CDATA[change]]></category>
		<category><![CDATA[checking]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[codec]]></category>
		<category><![CDATA[connection]]></category>
		<category><![CDATA[conversion]]></category>
		<category><![CDATA[decision]]></category>
		<category><![CDATA[destination]]></category>
		<category><![CDATA[destination ip addresses]]></category>
		<category><![CDATA[device]]></category>
		<category><![CDATA[Display]]></category>
		<category><![CDATA[Eltima]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[engineering]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[firewall filters]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Flash]]></category>
		<category><![CDATA[FLV]]></category>
		<category><![CDATA[format]]></category>
		<category><![CDATA[header]]></category>
		<category><![CDATA[host]]></category>
		<category><![CDATA[incoming traffic]]></category>
		<category><![CDATA[infect]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[input]]></category>
		<category><![CDATA[instance]]></category>
		<category><![CDATA[integrity]]></category>
		<category><![CDATA[interaction]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[key]]></category>
		<category><![CDATA[latter case]]></category>
		<category><![CDATA[mail]]></category>
		<category><![CDATA[mail program]]></category>
		<category><![CDATA[method]]></category>
		<category><![CDATA[movie]]></category>
		<category><![CDATA[name]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[network connections]]></category>
		<category><![CDATA[network directories]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[operation]]></category>
		<category><![CDATA[opportunity]]></category>
		<category><![CDATA[order]]></category>
		<category><![CDATA[outbound]]></category>
		<category><![CDATA[outbound traffic]]></category>
		<category><![CDATA[outgoing traffic]]></category>
		<category><![CDATA[packet]]></category>
		<category><![CDATA[packet header]]></category>
		<category><![CDATA[pause]]></category>
		<category><![CDATA[player]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[ports]]></category>
		<category><![CDATA[practice]]></category>
		<category><![CDATA[presence]]></category>
		<category><![CDATA[principle]]></category>
		<category><![CDATA[program]]></category>
		<category><![CDATA[restricting internet access]]></category>
		<category><![CDATA[result]]></category>
		<category><![CDATA[reverse]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Small]]></category>
		<category><![CDATA[Social]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[source]]></category>
		<category><![CDATA[spread]]></category>
		<category><![CDATA[store]]></category>
		<category><![CDATA[swf]]></category>
		<category><![CDATA[system]]></category>
		<category><![CDATA[theory]]></category>
		<category><![CDATA[Toolbox]]></category>
		<category><![CDATA[traffic]]></category>
		<category><![CDATA[traffic policy]]></category>
		<category><![CDATA[trouble]]></category>
		<category><![CDATA[unknown]]></category>
		<category><![CDATA[user]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[volume]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[web browser plug]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[worm activity]]></category>
		<category><![CDATA[worm code]]></category>

		<guid isPermaLink="false">http://www.ledanet.org/?p=78</guid>
		<description><![CDATA[A reverse firewall filters outgoing traffic from a network, unlike a normal firewall which filters incoming traffic. In practice, filtering in both directions would probably be handled by the same software or device.
As with firewalls, the key to an effective reverse firewall is its policy: what outbound connections should be permitted? The principle is that [...]]]></description>
			<content:encoded><![CDATA[<p>A reverse firewall filters outgoing traffic from a network, unlike a normal firewall which filters incoming traffic. In practice, filtering in both directions would probably be handled by the same software or device.</p>
<p>As with firewalls, the key to an effective reverse firewall is its policy: what outbound connections should be permitted? The principle is that a worm&#8217;s connections to infect other machines will not conform to the reverse firewall policy, and the worm&#8217;s spread is thus blocked. The decision is based on the same packet header information as was used for a firewall, including source and destination IP addresses and ports.<br />
<span id="more-78"></span><br />
A host-based reverse firewall can implement a finer-grained policy by restricting Internet access on a per-application basis. Only certain specified applications are allowed to open network connections, and then only connections in keeping with the reverse firewall&#8217;s outbound traffic policy. A worm, as a newly-installed executable unknown to the reverse firewall, could not open network connections to spread.</p>
<p>In theory. Still, worm activity is possible in the presence of a host-based reverse firewall:<br />
• A worm can use alternative methods to spread when faced with a reverse firewall, such as placing itself in shared network directories. As a result, no worm code is run on the host being monitored by the reverse firewall.<br />
• Legitimate code that is already approved to access the Internet can be subverted by a worm. A worm can simply fake user input to an existing mail program to spread via email, for instance. A worm could exhibit viral behavior, too, infecting an existing &#8220;approved&#8221; executable by indirect means, like a web browser plug-in, or more direct means that a virus would normally use. To guard against the latter case, a host-based reverse firewall can use integrity checking to watch for changes to approved executables.<br />
• Social engineering may be employed by a worm. A host-based reverse firewall may prompt the user with the name of the program attempting to open a network connection, for the user to permit or deny the operation.</p>
<p>Firewalls are required for your security bridge, especially if you have online store or any business based on internet connection. For examples, in order to secure your software, you&#8217;ll need certain security method and firewall setting to ensure no one enter and steals your software.</p>
<p>Adobe Flash files are usually used for videos, animation, games and interactive applications streamed online. Small Web Format (swf) and Flash Video (flv) are Adobe Flash movies and animations that can be viewed on most browsers. Yet, you may see that your video player have trouble viewing these files. This is why you may need to convert into video or most popular graphic formats. Eltima SWF &#038; FLV Toolbox allows you to <a href="http://www.convert-flv.net/convert-flv-to-avi/" target="_blank">convert FLV to AVI</a> video format using any codec installed in your system. It is a great opportunity to create interaction video or frame-by-frame video out of your SWF or FLV files. You can also convert any FLV to SWF file and play it with all controls, applying additional features you bundle the movie with during the conversion. Display movie controls fast-forward, pause, change volume.</p>]]></content:encoded>
			<wfw:commentRss>http://www.ledanet.org/reverse-firewalls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Choosing Quality web hosting</title>
		<link>http://www.ledanet.org/choosing-quality-web-hosting/</link>
		<comments>http://www.ledanet.org/choosing-quality-web-hosting/#comments</comments>
		<pubDate>Mon, 31 Jan 2011 11:51:53 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[computer]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[account]]></category>
		<category><![CDATA[Addon]]></category>
		<category><![CDATA[address]]></category>
		<category><![CDATA[administration]]></category>
		<category><![CDATA[age]]></category>
		<category><![CDATA[bandwidth]]></category>
		<category><![CDATA[best solution]]></category>
		<category><![CDATA[best web]]></category>
		<category><![CDATA[bind]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[capacity]]></category>
		<category><![CDATA[case]]></category>
		<category><![CDATA[client]]></category>
		<category><![CDATA[communication]]></category>
		<category><![CDATA[company]]></category>
		<category><![CDATA[comparing prices]]></category>
		<category><![CDATA[Comparison]]></category>
		<category><![CDATA[competition]]></category>
		<category><![CDATA[completeness]]></category>
		<category><![CDATA[conclusions]]></category>
		<category><![CDATA[cry]]></category>
		<category><![CDATA[customer]]></category>
		<category><![CDATA[day]]></category>
		<category><![CDATA[dollar]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[domain name]]></category>
		<category><![CDATA[Domains]]></category>
		<category><![CDATA[download]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[everyone]]></category>
		<category><![CDATA[extension]]></category>
		<category><![CDATA[feature]]></category>
		<category><![CDATA[function]]></category>
		<category><![CDATA[good features]]></category>
		<category><![CDATA[Hosting]]></category>
		<category><![CDATA[issue]]></category>
		<category><![CDATA[Lets]]></category>
		<category><![CDATA[load]]></category>
		<category><![CDATA[loading]]></category>
		<category><![CDATA[location]]></category>
		<category><![CDATA[lot]]></category>
		<category><![CDATA[lovebirds]]></category>
		<category><![CDATA[marketing]]></category>
		<category><![CDATA[Match]]></category>
		<category><![CDATA[Medium]]></category>
		<category><![CDATA[name]]></category>
		<category><![CDATA[number]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[order]]></category>
		<category><![CDATA[patient]]></category>
		<category><![CDATA[phone]]></category>
		<category><![CDATA[place]]></category>
		<category><![CDATA[price]]></category>
		<category><![CDATA[price comparison]]></category>
		<category><![CDATA[problem]]></category>
		<category><![CDATA[program]]></category>
		<category><![CDATA[provider]]></category>
		<category><![CDATA[publisher]]></category>
		<category><![CDATA[Purchase]]></category>
		<category><![CDATA[quality]]></category>
		<category><![CDATA[quality feature]]></category>
		<category><![CDATA[question]]></category>
		<category><![CDATA[range]]></category>
		<category><![CDATA[reflection]]></category>
		<category><![CDATA[remote administration]]></category>
		<category><![CDATA[rent]]></category>
		<category><![CDATA[Requirement]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[service]]></category>
		<category><![CDATA[site]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[solution]]></category>
		<category><![CDATA[space]]></category>
		<category><![CDATA[speed]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[support]]></category>
		<category><![CDATA[target]]></category>
		<category><![CDATA[term]]></category>
		<category><![CDATA[thing]]></category>
		<category><![CDATA[time]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[upload]]></category>
		<category><![CDATA[uptime]]></category>
		<category><![CDATA[USA]]></category>
		<category><![CDATA[versatile]]></category>
		<category><![CDATA[way]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[web hosting company]]></category>
		<category><![CDATA[web hosting provider]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[week]]></category>
		<category><![CDATA[wit]]></category>
		<category><![CDATA[world]]></category>
		<category><![CDATA[year]]></category>

		<guid isPermaLink="false">http://www.ledanet.org/?p=27</guid>
		<description><![CDATA[Do not ever choose a website hosting without certain facts that it is a quality one, especially if you&#8217;re using it for doing your business. Only choose the best web hosting that can run smoothly. Tips on choosing hosting this time hopefully be useful for you who will choose the hosting or hosting has never [...]]]></description>
			<content:encoded><![CDATA[<p>Do not ever choose a <a href="http://www.thetop10bestwebhosting.com/" target="_blank">website hosting</a> without certain facts that it is a quality one, especially if you&#8217;re using it for doing your business. Only choose the best web hosting that can run smoothly. Tips on choosing hosting this time hopefully be useful for you who will choose the hosting or hosting has never before bought but turned out disappointing results. Less fitting it would be like to talk about hosting without a domain. Both are like two lovebirds who can not be separated. Hosting as a publisher of data, while their own domain name is the name of the address where your files are placed.</p>
<p>Lets have look below tips before you choose the best one: <span id="more-27"></span><br />
<strong>1. Features Quality</strong></p>
<p>Feature is the main thing you should look into buying hosting. Currently, there are so many hosting providers that seek to improve the quality of their features in order to face competition with other providers. If not, the customer confirmed immediately fled to other providers. Well, with this increasing feature, could bind and lock their client not to migrate somewhere else.</p>
<p>So what features should be considered?<br />
Here are the main features you should check in web hosting provider:</p>
<p>- SPACE (Large hosting capacity, the bigger the better).<br />
- Bandwidth (Large load data from either the upload or download, the bigger the better).<br />
- Uptime (For websites not often down list, select the hosting uptime which is stable, at least 98% to the above)<br />
- My SQL (more is better)<br />
- Addon Domains (useful for those who want to have more than 1 domain on 1 hosting account)</p>
<p><strong>2. Price Comparison</strong></p>
<p>Once you see its features, if you do not care about the price issue it does not really matter. Another case if you are really considering this issue, then the best solution other than seeing the features offered is by comparing prices from one provider to another provider. This way you can draw conclusions Which web hosting company you use decent.</p>
<p>But remember! Do not be fooled by cheap price with good features then you take for granted. Conversely, it does not mean it is with the price of cheap web hosting cheap and not necessarily be good, there are other considerations that you should look. Do not forget also a price that is usually temporary. Usually some web hosting provides cheap prices only in the first year alone. Medium time extension prices soaring, you&#8217;ll want to ask this problem.</p>
<p><strong>3. Number of Clients</strong></p>
<p>Number of clients is a reflection of a hosting judged good or bad by his client. More and more clients, the hosting company usually reliable quality. For that, it would not hurt you also ask this problem to the relevant customer service.</p>
<p><strong>4. Match Requirement</strong></p>
<p>Do not be fooled by hosting also provides versatile features unlimited and that provider has been trusted by clients.<br />
Which means what?</p>
<p>Purchase (rent) hosting your online business needs. Because it would be useless if you require only 50 MB of which only worth several dollar rather than buying others cause you&#8217;re tempted unlimited features that you won&#8217;t used with higher price. Certainly a far cry from the price comparison, and a lot of unused space will be wasted. Unless you intend to make a lot of websites at once or for long-term business, which does require a large space.</p>
<p>5. Server Location</p>
<p>If you target your marketing in certain countries. We recommend that you have to adjust with the provider you use. Because this will affect the speed of access to your target in question. If they are too long to wait for your web loading, it is not impossible they just run away. Usually the USA servers are lighter and can be easily accessed around the world.</p>
<p>6. Support</p>
<p>The characteristics of web hosting that is professionally managed support is responsive, patient, and always online 24 hours a day 7 days a week. Especially if you&#8217;re new to dealing with hosting issues, usually a lot of obstacles you will encounter. This is where the function of the responsive support it means a lot. You will be assisted until your site has really online. They usually also provide a complete range of communication media such as IM, email, phone, or directly come to the place.</p>
<p>7. Complete Address</p>
<p>As mentioned earlier, a good web hosting provider usually also indicate the completeness of the address. Although the client does not have to come into place, but at least will make the client feel safe with that address, so they need not fear that provider only fictitious or afraid to be left vague at times.</p>
<p>8. Company Age</p>
<p>The more older the age of the web hosting provider, usually the more experienced they are dealing with hosting issues.<br />
Old age also showed the higher their flying hours to handle the hosting. They maintain strict program, the software until the contents are allowed to use. Because there is rarely a hosting provider out of business due to not be able to manage their hosting.</p>
<p>Last but not least, everyone would dream on fast hosting with age, then try out <a href="http://www.thetop10bestwebhosting.com/uk-hosting-reviews/fasthosts" target="_blank">fasthosts</a>. Great price and offer other features such as free scripts, site builder, and many more, it is mention on <a href="http://www.thetop10bestwebhosting.com/uk-hosting-reviews/ipage" target="_blank">ipage host review</a>. </p>]]></content:encoded>
			<wfw:commentRss>http://www.ledanet.org/choosing-quality-web-hosting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

