|
| Mengatasi virus menginfeksi seluruh jaringan komputer |
| Di post Jun 20, 2006 |
Email ke teman
Cetak
|
Banyak virus yang tersebar lewat jaringan komputer di warnet maupun kantor terutama akibat adanya akses internet. Satu komputer client saja yang terinfeksi, akan bisa menginfeksi seluruh jaringan komputer yang mungkin hingga ratusan. Apalagi setiap komputer client men-share file/folder akan lebih mudah terkena virus yang notabene selalu mencari peluang untuk mengandakan diri dan kemudian menyebar.
Simak cara mengatasinya dari Norman antivirus di bawah ini:
Stopping network share infectors Many viruses today are share infectors. They infect open shares throughout the network. A single infected computer is capable of infecting hundreds of other machines. It is a common scenario that many sites have open shares on their servers where all users has unlimited access. The intention of these shares is to provide an universal area where all users can exchange common files and information. Other scenarios include shares that are not intended for common purposes, but they are open due to lack of planning and security. No matter the reason, these file shares are highly exposed to viruses like Pinfi and Funlove that have open file shares as a target for infection. A share infector scenario: The figure above illustrates an unprotected workstation (IP: 192.168.0.13) that is allowed to execute a file infected with the Pinfi virus. The infected workstation will propagate open file shares on computers in the network, look for files with .exe and .scr extension on these shares and then try to infect these files. All servers in this situation are protected with updated antivirus software, which monitors the file system on the servers. An attempt to infect files on these shares will be detected and infected files are instantly cleaned. The problem, however, is that the workstation is still infected and will re-infect the .exe and .scr files shortly after the antivirus software has performed the first clean operation. We now have an infect-clean-infect cycle that will go on forever unless something is being done with the original infection: the infected workstation. Finding the source of the problem In a large network with hundreds, even thousands of machines, it can be really hard to find this particular workstation. The Virus Alert message normally just points at the target file for the infection, which virus that was found, and what has been done to the file. There is obviously a need for some extra information to solve this problem. One way of solving the problem is to use an external tool to monitor a file that is likely to be infected. To avoid too many changes on any of the original servers it may be a good idea to set up a new test machine in the network, create an open share on this machine, and place a copy the .exe file here. In the Pinfi case we know that .exe files are attractive targets to infect, and we copy the file calc.exe from the \Windows directory to the new file share. The calc.exe file is now a “bait" for the infector. Before we connect the “bait" machine to the network, we need to install a “sniffer" program. We think Ethereal is a good alternative, but programs like Sniffer Pro and Etherpeek will do as well, but Ethereal can be downloaded free of charge. It contains a lot of functionality, so in this paper we will only cover functions relevant to solve this particular scenario. Install Ethereal You need two components: 1. Install and run the WinPCap driver that can be downloaded from winpcap.polito.it 2. Install and run Ethereal - can be downloaded from ethereal.com NOTE: Although our experience with Ethereal is good, we do not support it, so you use it at your own risk. Monitoring the activity on the network When Ethereal is installed, make sure that the NVC’s On-access scanner is running on the machine, and start the NVC Utilities program where you open the Messages window. Before you start monitoring the file, make sure that it gets infected by watching the virus alerts in the Messages window. If no virus alerts appear, then the bait does not work. Check again to make sure that the directory containing the bait really is shared, and that all users have full access to the share. If this still does not work, you may need to install Ethereal on one of the servers where the infection originally appeared. Some share infectors just infect shares that were available upon start of the infected program. In such a case, find a file here to use as bait for the infection. Now start Ethereal. We want to capture the activity that the machine receives via the network. But we only want to focus on activity related to the bait, which is the calc.exe test file. n the lower left corner there is a field labelled Filter: In this field type the string: smb.file contains “calc.exe" Select the command Capture/Start and then click OK. The capture window appears. From now on watch the activity in the NVC Utilities’ Messages window. As soon as there is a new infection on our bait, close the Ethereal capture window. The log from the capture appears in the main window. Make sure that our filter is active by clicking Apply. By watching the “Source" and “Destination" columns you should now be able to see the IP addresses used in manipulations of the calc.exe file. In our case the local address for our machine is 192.168.0.15. The other IP address involved in the transactions is 192.168.0.13. Obviously a machine with the address 192.168.0.13 is the infector. You can now solve the problem by isolating it and then perform a complete On-demand scan supplied with the relevant fix(es). Repeat the process to ensure that there are no other infectors in the network.
source: Norman antivirus |
|
Berita Singkat |
| | |
Kirim SMS Mesum di China Bisa Dihukum? Feb 08, 2010
Pemerintah China baru-baru ini mengeluarkan aturan yang mengancam para penyebar SMS mesum bakal kena hukuman. Rupanya, aturan itu membuat sejumlah pasangan suami istri atau kekasih ketakutan saling berkirim SMS mesra. Terkait ketakutan tersebut, otoritas China pun berupaya meyakinkan kalau SMS bernuansa mesum antara pasangan atau teman tidak akan berujung sanksi apapun. Namun syaratnya antara pengirim dan penerima SMS tak ada yang merasa terganggu.
|
Hati-hati Anda Bisa Kecanduan Internet Feb 04, 2010
Studi terbaru dari Dr Catriona Morrison mengatakan, Internet saat ini memainkan peran besar dalam kehidupan modern. Tetapi memiliki sisi gelap lain. Semua kemudahan dengan internet bisa didapat, hanya ada sisi gelap bila dilakukan berlebihan sampai menganggu kegiatan sehari hari. Banyak penguna internet mengalami kecanduan, ketika masuk ke dunia sex di internet. Atau masuk ke dunia game online atau komunitas online dan terlama berada disana. Dampaknya akan mengalami depresi akibat kecanduan internet.
|
Twitter Diblok China Jan 31, 2010
Upaya China membatasi kebebasan berinternet seolah tak ada habisnya. Setelah menutup sejumlah situs yang dianggap menyebarkan kekerasan, dan pronografi, kini giliran mikroblogging, Twitter yang menjadi korban. Pendiri Twitter Evan Williams sebelumnya mengungkapkan bahwa layanan mikrobloggingnya tak dapat diakses oleh sebagian pengguna di China.
|
Ruby Alamsyah Lebih Beken Dari Roy Suryo di Twitter Jan 26, 2010
Panasnya perseteruan antara Roy Suryo dan Ruby Alamsyah ternyata meluas hingga ke ranah Twitter.
Kendati tak menjadi trending topic, banyak tweeps (pengguna twitter) yang mengomentari perseteruan dua orang yang banyak disebut media sebagai 'pakar TI'. Namun tweeps ternyata lebih banyak memberi porsi dukungan terhadap Ruby ketimbang Roy Suryo. "Let's swap Roy Suryo for Ruby Alamsyah (ahli forensik IT bersertifikat satu2nya) all in favor of Ruby raise ur hand!" ujar Pandji Pragiwaksono, tokoh Twitter yang mempopulerkan gerakan #IndonesiaUnite.
|
13 Penjahat ATM Berhasil Curi 264.000 Data Kartu Jan 23, 2010
Kepala Divisi Humas Mabes Polri Irjen (Pol) Edward Aritonang mengatakan, dari 13 pelaku pembobolan dana nasabah beberapa bank yang berhasil ditangkap, sebagian merupakan profesional yang sangat menguasai pembobolan uang nasabah melalui ATM. Ia menjelaskan, dari para tersangka ditemukan data digital kartu ATM milik nasabah di beberapa bank yang berhasil didapatkan secara ilegal. Tak tanggung-tanggung, mereka berhasil mencuri data digital kartu ATM berserta nomor PIN dari 264.000 kartu.
|
McDonald Perluas Pemasangan WIFI di Amerika Jan 22, 2010
Kalau makan McDonald di Amerika, jangan lupa pasang Wireless di notebook atau smartphone. Minggu ini McDonald telah memasang jarigan Wireless Network di 11.500 ribu restoran. McDonald memiliki total 14.000 restoran yang tersebar diseluruh negara Amerika Serikat. Kecepatannya sampai 1.27Mb/s. Sedangkan kecepatan upstream hanya 0.31Mb/s. Dari hasil tet, mendownload format file MP3 sebesar 5MB hanya membutuhkan waktu 32 detik saja. Atau mendownload 1 VCD hanya 85 menit.
|
|