Monday, August 31, 2009

Fixing DLL Issues Related to Kernel32.dll



Fixing DLL Issues Related to Kernel32.dll


Kernel is the nucleus of an operating system. It provides basic services such as performing memory management, handling I/O operations, and handling interrupts. In Windows operating systems, such as Windows 98, ME, and XP, kernel operations are handled by the Kernel32.dll, which is a Dynamic Link Library (DLL) file. Kernel32.dll is loaded at startup in the protected memory area of the system, thereby preventing other programs from taking over this memory space.

Troubleshooting Kernel32.dll Errors

Since Kernel32.dll manages several core activities of Windows operating systems, there are several reasons why Kernel32.dll errors may occur.

Some of the common causes of Kernel32.dll errors are:

Damaged swap file, file allocation, password list, and registry
Low disk space
Incorrect or corrupt Kernel32.dll file
Improper power supply, faulty hard disk controller, and hot CPU
Hardware malfunctioning, over clocking, ground bounce, and RF noise
Improper BIOS Settings
Damaged or incorrectly installed third party software
Missing or corrupt Temp folder
Damaged or missing Control Panel’s .cpp file
Damaged JAVA machine, hardware drivers, .log files, and Msinfo32.exe file
Incorrect entries in History folder and damaged, missing, or incorrect dlls
Due to their crucial role in managing a number of tasks related to core functioning of an operating system, fixing dll problems related to kernel is very important. Here, we discuss steps to fix common Kernel32.dll problems.

Invalid Page Fault Error

Invalid Page Fault (IPF) errors occur when one or more programs try to gain access to the protected memory space. In case only a single program is causing the problem, then fixing this program by reinstalling or uninstalling it can help you fix the problem. However, in case multiple programs are the cause of the error, then faulty hardware may be the most likely cause. To fix this, you might have to replace the device causing the problem.

If IPF Kernl32.dll errors from different drivers such as Explorer, Msgsrv32, and Mprexe become a common affair, then a damaged password list might be the most likely cause of the problem.

For fixing dll error caused from different drivers, you might have to recreate the password file. Before doing this, remember to write down all the passwords saved on your PC. Next, open the Windows folder and search for the *.pwl file. Next, delete all the .pwl files displayed and restart your Windows system.

Damaged Memory Modules

To find out if frequent kernel32.dll errors are caused by problems in the memory module, run msconfig.exe and add the line ‘DEVICE=C:\WINDOWS\HIMEM.SYS /TESTMEM:ON’ in config.sys and restart you PC. If your screen displays the message ‘HIMEM has detected unreliable memory at address xx:xxxxxx’ at startup, it indicates memory problems.

Outdated or Damaged Drivers

Device drivers, especially video drivers, are updated on a regular basis. Therefore, you must keep your device drivers updated to avoid receiving Kernel32.dll errors.

Malware

Many times, malware can lead to dll errors. One of the best methods for fixing dll errors that occur due to malware is to regularly run antivirus scans on your PC. In doing this, it also becomes important for you to keep your antivirus software files updated.

Malware also tends to corrupt the system registry by adding invalid entries or removing important entries from it. Therefore, opting for a registry cleaner software and regularly running registry scans to keep the system registry healthy may also keep dll-related errors at bay.

The Kernerl32.dll file is important for normal functioning of your Windows system. Frequent occurrence of Kernel32.dll errors can stall your system and render it useless. To avoid these problems from occurring on your PC, it is important for you to ensure that your PC’s hardware and devices are well maintained, and are in good working condition. Also, you must keep your PC updated by regularly installing driver, antivirus, and security updates. Regular antivirus and registry scans also help you in preventing dll errors.

The Kernel32.dll file handles memory management, input/output operations, and interrupts. When you start Windows, Kernel32.dll is loaded into a protected memory space so that other programs do not take over that memory space.

On occasion, you may receive an invalid page fault (IPF) error message. This error message occurs when a program tries to access the Kernel32.dll protected memory space. Occasionally, the error message is caused by one particular program, and other times the error message is provoked by multiple files and programs.

If the problem results from running one program, the program needs to be replaced. If the problem occurs when you access multiple files and programs, the damage is likely caused by damaged hardware.

You may want to clean boot the computer to help you identify the particular third-party memory-resident software. Note that programs that are not memory-resident can also cause IPF error messages.

The following conditions can cause Kernel32.dll error messages:

Damaged swap file
File allocation damage
Damaged password list
Damaged or incorrect version of the Kernel32.dll file
Damaged registry
Hardware, hot CPU, over clocking, broken power supply, RF noise, ground bounce, or bad hard disk controller
BIOS settings for Wait states, RAM timing, or other BIOS settings
Third-party software that is damaged or incorrectly installed
.dll files that are saved to the desktop

Non-existent or broken Temp folder
A control panel (.cpl) file is damaged
Incorrect or damaged hardware driver
Incorrectly installed printer drivers or HP Jetadmin drivers
Damaged Java Machine

Damaged .log files
Damaged entries in the History folder
Incompatible or damaged dynamic link library files
Viruses
Damaged or incorrect Msinfo32.exe file
Low disk space
More on the possible causes:

Bad memory modules:

You can test your memory modules by inserting the command: DEVICE=C:\WINDOWS\HIMEM.SYS /TESTMEM:ON into your Config.sys file. You can use the System Configuration Utility:

Select Start>> Run and type: msconfig [Enter]

Next, select the Config.sys tab and add the HIMEM.SYS line (above) by pressing the New button.

Windows will tell you to reboot your computer.

Watch your screen for a message; "HIMEM has detected unreliable memory at address xx:xxxxxx" which will certainly indicate that there's a memory problem.


Note: Memory problems may not immediately surface from the result of this test. It may take many reboots or even a few days for the above message to appear.

CPU, bus speed or multiplier overclocking.

Graphic acceleration set too high:
Select Control Panel > System, then select the Performance tab, click the Graphics button. Turn down Hardware acceleration by moving the slider a notch to the left, reboot, try again.
Bad or outdated drivers, especially video drivers:

Check with your card manufacturer for an updated set of drivers. Video drivers are updated constantly, it pays to have the latest release, especially if you find yourself having problems with Internet Explorer.
--------------------------------------------------------------------------------
What to do if you have Kernel32.dll IPF ("Invalid Page Fault") error?
This error occurs when an application tries to access kernel32.dll's protected memory space. It may be one particular program or application, or multiple files and applications. Most kernel32.dll errors are NOT caused by a corruption of the kernel32.dll module.

If the error seems to arise when activating a certain program, application or device, you should try uninstalling and re-installing that program, application or device.

If you frequently receive Invalid Page Fault in Kernel32.dll Errors from different drivers (Explorer, Guide.exe, Msgsrv32, Commgr32, Mprexe and others), it is possible that a damaged password list file is the culprit. Try re-creating your password list file:
In Windows Explorer select your \Windows folder

Press F3. This will bring up the Find: All Files window

In the 'Named' box type: *.pwl

Click Find Now

When a list of found files is displayed, select Edit> Select All> Press Delete on your keyboard

Exit the Find window and restart Windows

Note: This procedure will cause you to lose all of your saved passwords. Be sure to write them down before deleting so that you can re-insert them as needed.


computer recently suffered Zelot-inflicted monitor failure and the corruption of my System32 file.

Thursday, August 20, 2009

Alert: JAVA SPY CODE USING PORT 6463

Alert: JAVA SPY CODE USING PORT 6463memt


Scanner.jar


The Scanner.jar is a simple client application which scans a server or an workstation for open ports from 1 - 65536.
The operating system used: Solaris x86 and the Java IDE: Netbeans !

Notice: The purpose of this exercise is pure educational, to learn about Java and networking. This application will run with any JDK 1.4.2_x version available from java.sun.com. It is working fine with the latest version, Java 5 too. However this package does not run with JDK 1.3 or previous versions.




Method 1: Single threaded application

Package: Scanner.jar
Source: Main.java

This is a single threaded application which will try to look for any open ports.
The main logic behind this is explained below: the scanner will try to access
the range 1 - 65536 looking for any open ports using the Socket() method


try {

InetAddress addr = InetAddress.getByName(host);
System.out.println("Searching for open ports between 1 - 65536");
System.out.println("Please wait...(CTRL-C to stop the process)");

for (int i = 1; i < 65536; i++) {
Socket s = null;
try {
s = new Socket(addr,i);
System.out.println("Port: " + i + " open on " + host );
}
catch (IOException ex) {

}
finally {
try {
if (s != null) s.close();
}
catch (IOException ex) {}
}

} //for
} //try
catch (UnknownHostException ex) {
System.err.println(ex);
}

}

Some results:


$ time java -client -jar Scanner.jar
Searching for open ports between 1 - 65536
Please wait...(CTRL-C to stop the process)
Port: 21 open on localhost
Port: 22 open on localhost
Port: 23 open on localhost
Port: 25 open on localhost
Port: 79 open on localhost
Port: 111 open on localhost
Port: 513 open on localhost
Port: 514 open on localhost
Port: 515 open on localhost
Port: 587 open on localhost
Port: 631 open on localhost
Port: 898 open on localhost
Port: 4045 open on localhost
Port: 4999 open on localhost
Port: 5987 open on localhost
Port: 5988 open on localhost
Port: 6000 open on localhost
Port: 7100 open on localhost
Port: 9010 open on localhost
Port: 32786 open on localhost
Port: 32787 open on localhost
Port: 32788 open on localhost
Port: 32789 open on localhost
Port: 32790 open on localhost
Port: 32791 open on localhost
Port: 32792 open on localhost
Port: 32795 open on localhost
Port: 32796 open on localhost
Port: 33221 open on localhost
Port: 36314 open on localhost
Port: 36317 open on localhost
Port: 36359 open on localhost
Port: 36360 open on localhost
Port: 36389 open on localhost
Port: 36391 open on localhost
Port: 36393 open on localhost
Port: 36394 open on localhost
Port: 36395 open on localhost
Port: 36396 open on localhost
Port: 36397 open on localhost
Port: 36400 open on localhost
Port: 36401 open on localhost
Port: 36402 open on localhost
Port: 36403 open on localhost
Port: 36406 open on localhost
Port: 36409 open on localhost
Port: 36455 open on localhost
Port: 36460 open on localhost
Port: 58787 open on localhost

real 1h32m7.01s
user 0m8.28s
sys 0m7.23s



Next the scanner will be implemented using threads to improve the performance, if any.



Method 2: An improved version: multi-threaded

Package: Scanner2.jar
Source: Main2.java

One thing many network client applications, or most likely servers, are using is: threads. To see if we can improve the performance of our scanner we will introduce threads and as well to make the things a bit easier and more flexible the scanner will ask for hostname, startPort, endPort and the number of threads from user.


stefan@nereid>java -jar Scanner2.jar
Usage: java -jar Scanner2.jar hostname startPort endPort noThreads





public class Main2 {
public static PortScannerWorker t = null;
public static String host = "localhost";

/** Creates a new instance of Main */
public Main2() {
}

/**
* @param args the command line arguments
*/
public static void main(String[] args) {
// TODO code application logic here

...

long startTime = System.currentTimeMillis();

try {

System.out.println("Searching for open ports between 1 - 65536");
System.out.println("Please wait...(CTRL-C to stop the process)");
host = InetAddress.getByName(args[0]);

System.out.println("host: "+host+" threads: "+threads);

ports = new PortHandler(firstPort, lastPort);
for (int i = 0; i < threads; i++){
t = new PortScannerWorker(("Worker"+i), ports);
t.start();
}

while(t.isAlive()) Thread.sleep(30);
} //try

catch (Exception ex) {
System.err.println("Error:" + ex);
ex.printStackTrace();
}


long endTime = System.currentTimeMillis();
System.out.println("Time spend for port scan:" + (millisecondsToString(endTime - startTime)));

}

public static String millisecondsToString(long time) {
// retunr the time as a String

}

}

class PortScannerWorker extends Thread {
PortHandler _ports = null;

public PortScannerWorker(String name, PortHandler ports)
{
super(name);
_ports = ports;
}

public void run() {
Port port = null;
boolean quit = false;

while (!quit) {
port = null;
synchronized(_ports)
{
if (!_ports.hasMoreElements()) {
quit = true;
return;
}
port = (Port) _ports.nextElement();
}

if (null != port) port.scan(this.getName());
}
}//run
}

class PortHandler implements Enumeration
{
InetAddress host = null;
int _firstPort = 0;
int _lastPort = 0;
int _nextPort = 0;

public PortHandler(int first, int last){
_firstPort = first;
_nextPort = first;
_lastPort = last;

}

public boolean hasMoreElements(){
return (_nextPort <= _lastPort);
}

public Object nextElement(){
return new Port(_nextPort++);
}
}//class PortHandler

class Port
{
int _port = -1;

Port(int port){
_port = port;
}

void scan(String name) {
try {
Socket s = new Socket(Main2.host, _port);
System.out.println("Port open " + _port + " discovered by thread "
+ name + " at " +
new GregorianCalendar().get(Calendar.HOUR_OF_DAY) + ":" +
new GregorianCalendar().get(Calendar.MINUTE) + ":" +
new GregorianCalendar().get(Calendar.SECOND));

s.close();
}

catch (IOException e) {
}
}//scan

public static String millisecondsToString(long time) {
int seconds = (int) ((time / 1000) % 60);
String secondsStr = (seconds < 10 ? "0" : "") + seconds;
return new String(secondsStr);
}
}//class Port



And at the end let's check some results: using the scanner with 500 threads.


PID USERNAME SIZE RSS STATE PRI NICE TIME CPU PROCESS/NLWP
727 stefan 75M 47M sleep 59 0 0:00:59 2.4% thunderbird-bin/11
1160 stefan 102M 30M sleep 59 0 0:00:07 1.8% java/508
1095 stefan 64M 42M sleep 47 4 0:03:09 1.1% mozilla-bin/3
672 stefan 25M 13M sleep 59 0 0:00:24 0.8% metacity/1
729 stefan 73M 46M sleep 59 0 0:00:56 0.7% gnome-terminal/2

...


The scanner is represented by the 1160 PID number having 508 threads (8 internal JVM threads+ 500 our threads). The real size segment of the process got bigger a bit since each thread has its own stack occupying space.


stefan@nereid>time java -jar Scanner2.jar localhost 1 65536 500
Searching for open ports between 1 - 65535
Please wait...(CTRL-C to stop the process)
host: localhost/127.0.0.1 threads: 500
Port open 21 discovered by thread Worker3 at 14:31:4
Port open 25 discovered by thread Worker4 at 14:31:4
Port open 22 discovered by thread Worker2 at 14:31:4
Port open 111 discovered by thread Worker36 at 14:31:4
Port open 515 discovered by thread Worker171 at 14:31:4
Port open 587 discovered by thread Worker5 at 14:31:11
Port open 631 discovered by thread Worker1 at 14:31:14
Port open 898 discovered by thread Worker6 at 14:31:34
Port open 4045 discovered by thread Worker17 at 14:35:23
Port open 4999 discovered by thread Worker14 at 14:36:6
Port open 5987 discovered by thread Worker0 at 14:36:47
Port open 5988 discovered by thread Worker0 at 14:36:47
Port open 6000 discovered by thread Worker76 at 14:36:48
Port open 7100 discovered by thread Worker149 at 14:37:33
Port open 9010 discovered by thread Worker118 at 14:38:31
Port open 32775 discovered by thread Worker85 at 14:50:58
Port open 32776 discovered by thread Worker85 at 14:50:58
Port open 32777 discovered by thread Worker85 at 14:50:58
Port open 32778 discovered by thread Worker85 at 14:50:58
Port open 32779 discovered by thread Worker85 at 14:50:58
Port open 32780 discovered by thread Worker85 at 14:50:58
Port open 32781 discovered by thread Worker85 at 14:50:58
Port open 32784 discovered by thread Worker85 at 14:50:58
Port open 32785 discovered by thread Worker85 at 14:50:58
Port open 32789 discovered by thread Worker84 at 14:50:58
Port open 32786 discovered by thread Worker83 at 14:50:58
Port open 32831 discovered by thread Worker379 at 14:50:59
Port open 32832 discovered by thread Worker379 at 14:50:59
Port open 32865 discovered by thread Worker160 at 14:51:1
Port open 32866 discovered by thread Worker160 at 14:51:1
Port open 32868 discovered by thread Worker160 at 14:51:1
Port open 32869 discovered by thread Worker160 at 14:51:1
Port open 32870 discovered by thread Worker160 at 14:51:1
Port open 32871 discovered by thread Worker160 at 14:51:1
Port open 32872 discovered by thread Worker160 at 14:51:1
Port open 32875 discovered by thread Worker160 at 14:51:1
Port open 32877 discovered by thread Worker172 at 14:51:1
Port open 32879 discovered by thread Worker172 at 14:51:1
Port open 32882 discovered by thread Worker172 at 14:51:1
Port open 32883 discovered by thread Worker172 at 14:51:1
Port open 32885 discovered by thread Worker172 at 14:51:1
Port open 32876 discovered by thread Worker160 at 14:51:1
Port open 32918 discovered by thread Worker85 at 14:51:2
Port open 32923 discovered by thread Worker85 at 14:51:2
Port open 32947 discovered by thread Worker85 at 14:51:2
Port open 34119 discovered by thread Worker108 at 14:51:34
Port open 36208 discovered by thread Worker379 at 14:52:31
Time spend for port scan:00:35:21.728

real 36m28.94s
user 0m12.02s
sys 0m7.27s



So, the total execution time, using 500 threads, has been 35minutes compared with 1h and 30minutes as previous in Method 1. However the time of 30minutes is far too long. In the next section we will understand why.




--------------------------------------------------------------------------------

Conclusions:

Two scanners applications were presented: a single threaded and a multi-threading one. The multi-threading client was presented to show how can you use threads, sockets under Java.

Another open issue was: the time of the scanning process. Scanning for open ports under Solaris x86 took a very, very long time. Why ?

Solaris (x86 or SPARC) defends itself against a DoS - the SYN attack. By default Solaris has this protection ON (hmm ... very nice :)) comparing with RedHat 9 based on kernel 2.4.x where the scanning went in couple of seconds without to have this protection. To disable this protection as root try:
# ndd -set /dev/tcp tcp_rst_sent_rate_enabled 0

and you can put it on back:

# ndd -set /dev/tcp tcp_rst_sent_rate_enabled 1


To demonstrate the results after changing the RST parameter we started again Scanner2 to look for all open ports. The CPU consumption went very high and the total time was reduced to: 18seconds !


stefan@nereid>time java -jar Scanner2.jar localhost 1 65535 500
Searching for open ports between 1 - 65536
Please wait...(CTRL-C to stop the process)
host: localhost/127.0.0.1 threads: 500
Port open 21 discovered by thread Worker0 at 15:15:1
Port open 22 discovered by thread Worker0 at 15:15:1
Port open 25 discovered by thread Worker0 at 15:15:1
Port open 111 discovered by thread Worker0 at 15:15:1
Port open 515 discovered by thread Worker236 at 15:15:2
Port open 587 discovered by thread Worker236 at 15:15:2
Port open 631 discovered by thread Worker236 at 15:15:2
Port open 898 discovered by thread Worker208 at 15:15:2
Port open 4045 discovered by thread Worker212 at 15:15:3
Port open 4999 discovered by thread Worker247 at 15:15:3
Port open 5987 discovered by thread Worker248 at 15:15:3
Port open 5988 discovered by thread Worker248 at 15:15:3
Port open 7100 discovered by thread Worker385 at 15:15:4
Port open 9010 discovered by thread Worker440 at 15:15:4
Port open 6000 discovered by thread Worker248 at 15:15:4
Port open 32775 discovered by thread Worker245 at 15:15:9
Port open 32776 discovered by thread Worker245 at 15:15:9
Port open 32777 discovered by thread Worker245 at 15:15:9
Port open 32778 discovered by thread Worker245 at 15:15:9
Port open 32779 discovered by thread Worker245 at 15:15:9
Port open 32780 discovered by thread Worker245 at 15:15:9
Port open 32781 discovered by thread Worker245 at 15:15:9
Port open 32784 discovered by thread Worker456 at 15:15:9
Port open 32785 discovered by thread Worker456 at 15:15:9
Port open 32789 discovered by thread Worker315 at 15:15:9
Port open 32786 discovered by thread Worker261 at 15:15:9
Port open 32831 discovered by thread Worker297 at 15:15:9
Port open 32832 discovered by thread Worker297 at 15:15:9
Port open 32865 discovered by thread Worker462 at 15:15:9
Port open 32866 discovered by thread Worker462 at 15:15:9
Port open 32868 discovered by thread Worker462 at 15:15:9
Port open 32869 discovered by thread Worker462 at 15:15:9
Port open 32870 discovered by thread Worker462 at 15:15:9
Port open 32871 discovered by thread Worker462 at 15:15:9
Port open 32872 discovered by thread Worker462 at 15:15:9
Port open 32875 discovered by thread Worker494 at 15:15:9
Port open 32876 discovered by thread Worker494 at 15:15:9
Port open 32877 discovered by thread Worker494 at 15:15:9
Port open 32879 discovered by thread Worker252 at 15:15:9
Port open 32882 discovered by thread Worker280 at 15:15:9
Port open 32883 discovered by thread Worker280 at 15:15:9
Port open 32885 discovered by thread Worker281 at 15:15:9
Port open 32918 discovered by thread Worker32 at 15:15:9
Port open 32923 discovered by thread Worker66 at 15:15:9
Port open 34119 discovered by thread Worker158 at 15:15:10
Port open 36208 discovered by thread Worker486 at 15:15:10
Port open 63312 discovered by thread Worker303 at 15:15:16
Time spend for port scan:00:00:15.544

real 0m15.97s
user 0m8.48s
sys 0m5.67s



Trying as well to decrease the number of threads, by reducing the CPU and memory consumption, returned similar results, in fact got better results than the multi-threading one:


stefan@nereid>time java -jar Scanner2.jar localhost 1 65535 1
Searching for open ports between 1 - 65536
Please wait...(CTRL-C to stop the process)
host: localhost/127.0.0.1 threads: 1
Port open 21 discovered by thread Worker0 at 15:17:33
Port open 22 discovered by thread Worker0 at 15:17:33
Port open 25 discovered by thread Worker0 at 15:17:33
Port open 111 discovered by thread Worker0 at 15:17:34
Port open 515 discovered by thread Worker0 at 15:17:34
Port open 587 discovered by thread Worker0 at 15:17:34
Port open 631 discovered by thread Worker0 at 15:17:34
Port open 898 discovered by thread Worker0 at 15:17:34
Port open 4045 discovered by thread Worker0 at 15:17:35
Port open 4999 discovered by thread Worker0 at 15:17:35
Port open 5987 discovered by thread Worker0 at 15:17:36
Port open 5988 discovered by thread Worker0 at 15:17:36
Port open 6000 discovered by thread Worker0 at 15:17:36
Port open 7100 discovered by thread Worker0 at 15:17:36
Port open 9010 discovered by thread Worker0 at 15:17:36
Port open 32775 discovered by thread Worker0 at 15:17:41
Port open 32776 discovered by thread Worker0 at 15:17:41
Port open 32777 discovered by thread Worker0 at 15:17:41
Port open 32778 discovered by thread Worker0 at 15:17:41
Port open 32779 discovered by thread Worker0 at 15:17:41
Port open 32780 discovered by thread Worker0 at 15:17:41
Port open 32781 discovered by thread Worker0 at 15:17:41
Port open 32784 discovered by thread Worker0 at 15:17:41
Port open 32785 discovered by thread Worker0 at 15:17:41
Port open 32786 discovered by thread Worker0 at 15:17:41
Port open 32789 discovered by thread Worker0 at 15:17:41
Port open 32831 discovered by thread Worker0 at 15:17:41
Port open 32832 discovered by thread Worker0 at 15:17:41
Port open 32865 discovered by thread Worker0 at 15:17:41
Port open 32866 discovered by thread Worker0 at 15:17:41
Port open 32868 discovered by thread Worker0 at 15:17:41
Port open 32869 discovered by thread Worker0 at 15:17:41
Port open 32870 discovered by thread Worker0 at 15:17:41
Port open 32871 discovered by thread Worker0 at 15:17:41
Port open 32872 discovered by thread Worker0 at 15:17:41
Port open 32875 discovered by thread Worker0 at 15:17:41
Port open 32876 discovered by thread Worker0 at 15:17:41
Port open 32877 discovered by thread Worker0 at 15:17:41
Port open 32879 discovered by thread Worker0 at 15:17:41
Port open 32882 discovered by thread Worker0 at 15:17:41
Port open 32883 discovered by thread Worker0 at 15:17:41
Port open 32885 discovered by thread Worker0 at 15:17:41
Port open 32918 discovered by thread Worker0 at 15:17:41
Port open 32923 discovered by thread Worker0 at 15:17:41
Port open 34119 discovered by thread Worker0 at 15:17:42
Port open 36208 discovered by thread Worker0 at 15:17:42
Port open 63312 discovered by thread Worker0 at 15:17:47
Time spend for port scan:00:00:14.482

real 0m14.81s
user 0m7.21s
sys 0m5.33s



Disabling the RST protection makes the scan procedure very fast. In fact with the protection OFF and with a high number of threads Scanner2 performs worse than using only one thread !


REMEMBER: By default the protection is ON meaning your server is protected against such of DoS attack and when you are switching that OFF you are vulnerable to a DoS attack.

SPY APPLICATION & SPY HARDWARE

007 Spy Software - Secretly record user's activity and send log emails
We are awarding the Editor's Choice of local computer monitoring to 007 Spy Software, for being so full-featured, easy to use and reasonably priced. It allows you to secretly monitor and record user's activities on a computer, such as web sites visited, windows opened, every key pressed (including login/password of ICQ, MSN, AOL, AIM, and Yahoo Messenger or Webmail), application executed, Internet chats, Email sent, and even take snapshots of the entire Windows desktop at set intervals.

Key Features:
Capability of overriding "Anti-Spy" programs such as "Ad-aware"
View logs remotely with your favourite browsers from anywhere at anytime
Full version is completely undetectable to most anti-spy programs
Start & stop time scheduling
Support user filter to spy on specific users
View all user's Logs with a Single Login
Capture screen at the highest speed
Automatically startup in active and stealth Mode
Suspend on system idle
Powerful keylogger engine to capture all passwords
Built-in slide show for screen snapshot pictures
Export log report in HTML format
Automatically clean outdated logs on disk quota
Password protection
Execute with a simple command in stealth mode
Extremely self-explanatory interface
Compatible with Windows XP/2000/Me/98/95/NT4




Logging Features
Keystroke Monitoring
007 Spy have a powerful keylogger engine to record all keystrokes typed in any application window, such as user name, password, e-mail, chat, instant message (MSN/AOL/ICQ/AIM ), etc. The records are time stamped and categorized by the window title they belong to, so you can tell when and what documents were being typed.
Websites Activity Logging
The amazing spy software even record all websites URL visited in Internet Explorer (Netscape Navigator and Opera will be supported in Pro Edition of 007 Spy Software). 007 Spy Software will log the website URL, the website title, and the time the website was visited! You can click on the link in the Log Viewer to launch the visited page in your browser immediately!

Application Activity Logging
007 Spy Software can record all applications' window activity taken place on your computer! It will log the window title, the opening and closing time of the window, and the current user name. By this you can find out what movies/games were played, what files were modified, what pictures were displayed, and so on.
Screen Shot Capturing
NOT like other spy products, 007 Spy Software can take picture of the Windows Desktop just like a automatic surveillance camera! It will capture images at few SECONDS instead of minutes in other spy programs. You have the option of taking pictures of the entire screen or just of active window, and saving the pictures in high quality or low quality JPEG format. 007 Spy Software will also log the active window name and the time stamp when the screen shot was taken. When you click the record in log viewer, 007 Spy Software will launch the selected screen picture in your default image viewer.
Disk Activity Logging
This powerful software spy on all file/folders change made by users within Windows Explorer, such as create file/folder, delete file/folder, rename and move file/folder, etc. These activities are logged by path and time stamp of first access.



Security Features
Password Protection
007 Spy Software is the most securely spy program since it is password protected to prevent others from starting or stopping the monitoring process, as well as changing 007 Spy Software configuration settings!
Stealth/Skilled Mode
007 Spy can remove its Desktop Icon, Start Menu Group, and all its help files by just single click! Also it will never appear in Add/Remove Programs Menu or Task Manager.

Windows Startup
007 Spy Software can load automatically and secretly when Windows boots up.

Automatic Active Startup
Configure the powerful spy program to start in "Active" monitoring mode when it is started, then 007 Spy Software will record everything as soon as it run!

Automatically Hide Itself
The smart spy software can be configured to start in "Stealth" mode when it is started, so it will NOT appear in Windows Task Bar, System Tray, and Task Manager.


Advanced Features
Remote Log Viewer
The powerful spy program is able to deliver logs to our remote online server at set intervals specified by you, then you can view logs with your browser through the Internet from anywhere! It's really much more convenient and simple to work than all other spy products on the Internet!


Log Delivery via FTP
The screen spy pictures may exceed several GBs (Giga byte) in total size, so it's really impossible to deliver them to your email box, and it will also make 007 very easy to be detected by firewall or anti-virus programs. The good news is we have built-in FTP module which allows 007 to transfer all screenshot pictures to your server automatically!
Time Scheduling
The smart spy program can be configured to start and stop at the set time specified by owner. This feature enables user to start monitoring at a reasonable time and avoid viewing too much useless log records.
User Filter
007 Spy Software can be configured to monitor a set group of users on the computer, for example, you can specify the program to monitor only user "Colin" and "Cathy", but stop monitoring when the user "Jason" login. Or, you can monitor all users EXCEPT the account "Administrator", etc.
Friendly Interface
007 Spy Software is also the most easy to use spy program. It provides a much more easy-to-use graphical user interface than any other spy program, which will allow you to familiarize yourself with the software in no time
Idle Detector
The smart spy program now can automatically halt screen shot when system is idle. With this detector, 007 Spy Software will minimize system resource usage and avoid capturing a large numbers of duplicate screenshots.
HTML Report
Like all other spy programs, 007 Spy Software allows you to export log records to a HTML file, so you can conveniently review them in a full-window browser such as Microsoft Internet Explorer. Especially, the exported screenshot log file contains a thumbnail of each picture captured, so you can locate a screenshot picture as soon as possible.
Sort Log Records
007 Spy Software allows you to sort the list of records in Log Viewer window. Most of other spy program do not allow you to do this. You can sort all records by User, Time, Action (Window) Name, and Content, etc. Records can be sorted by alphabetical order or reverse order.
Powerful Search Engine
The powerful software spy also allows you to search keywords in log records. You can find out the item you are interested in as soon as you click the "Search" button!
Automatic Log Clearing
007 Spy Software can automatically clear the most outdated logs when the log files exceed the size you specified. This will prevent 007 Spy Software from using too much of the disk space.



HD-Spy - The most simple way to record keystrokes under Windows/Linux/Unix


HD-Spy is a very compact physical electronic device to secretly record keystrokes of a computer, regardless of the operating system! It will work fine under Windows, Linux and Unix! NO keylogger software installation needed to capture keyboard activity now! All you need to do is just plugging it between the PS/2 keyboard and your computer as the picture left shows, that's all! It will NEVER been disabled by ANY anti-virus or anti-spyware programs! Hardware-Keylogger can store up to 64,000 keystrokes which is equal to about one week's worth of data!

All anti-virus and spyware-scanning programs will NOT be able to detect Hardware Spy

System Requirements
Windows 98, Me, NT4, 2000, XP or Vista
Pentium Class PC (133mhz or higher)
3MB Hard disk space for program files

Sunday, July 19, 2009

TROJAN AGE ON A CLOSE LOOK AT SYMBANION



!




SymbOS/Commwarrior.C
Trojan SubType PDA Device Discovery Date 10/13/2005 Length Minimum DAT 4605 (10/14/2005) Updated DAT 4605 (10/14/2005) Minimum Engine N/A Description Added 10/14/2005 Description Modified 10/17/2005 2:02 PM (PT) Type Type of threat.



SubType Additional type information.
Discovery Date Date that AVERT discovered this threat.
Length File size, in bytes, of the threat.
Minimum DAT McAfee DAT files contain detection and repair information for threats. The Minimum DAT field specifies the lowest/oldest DAT version that is capable of detecting the first incarnation of a threat, and the release date. The highest/newest DAT version should always be used for the most complete protection and are available on the Anti-Virus Updates page.

Each description displays the minimum, fully tested, DAT version that includes regular detection for a particular threat. These fully tested DATs are released on a daily basis. If necessary, they are also released when a Medium, Medium On Watch, or High risk threat is discovered. An EXTRA.DAT will also be posted for these more prevalent threats, if necessary.

For each description listed, detection is always available. In the event that the DAT version specified is not yet available, an EXTRA.DAT file may be downloaded via the McAfee AVERT Extra.dat Request Page. Alternatively, minimally tested HOURLY BETA DAT files are available for downloading.


Updated DAT McAfee DAT files are constantly being updated to enhance detection capabilities. The Updated DAT field specifies the released DAT version that contains the most up to date detection.
Minimum Engine The scan engine uses the DAT files to detect threats. The Minimum Engine field specifies the lowest/oldest engine version that is capable of detecting this threat. The highest/newest engine version should always be used for the most complete protection and are available on the Anti-Virus Updates page.
Description Added Date/time this description was published using Pacific Time.
Description Modified Date/time this description was last modified using Pacific Time.
Risk Assessment

Corporate User Low
Home User Low Tab Navigation
Overview -

This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.


CharacteristicsCharacteristics -

SymbOS/Commwarrior.C is a new variant of the SymbOS/Commwarrior.A worm. It is an enhanced version of Commwarrior.A


The most important enhancements Commwarrior.C possesses over Commwarrior.A is that Commwarrior.C possesses a self-repairing and self-protection scheme.


SymptomsSymptoms -

Rapid battery drain Propagates via MMS to addresses in the user address book Propagates to nearby Bluetooth devices SymbOS/Commwarrior.C is distributed in a SIS file named “SymCommander_1_06.sis ”. This malware also travels via Bluetooth (referred to as “Network form” , hereafter) in a randomly named SIS file.


When distributed in the original SIS file , SymbOS/Commwarrior.C is set to be run upon install. The SIS file also installs a pirated copy of a 3rd party file manager.


When distributed in its network form, SymbOS/Commwarrior.C is also set to be run upon install. It claims to be a program entitled “CWOutcast ”.

Upon install, SymbOS/Commwarrior.C makes copies of itself and its SIS file to C:\System\Bootdata\lib and, if a memory card is installed, to E:\System\Bootdata\lib. It also copies its boot-hook ( cworec.mdl ) to C:\system\recogs and E:\system\recogs .

SymbOS/Commwarrior.C has a built in self-protection scheme:

If a boot hook is deleted, it will be replaced by the running worm If SymbOS/Commwarrior.C is deleted, its boot hook will replace the files If the cached copies of the malware are deleted, the device will reboot and then the MDL will replace the files. Its process is protected

Propagation via MMS has not been confirmed at this time.

SymbOS/Commwarrior.C contains slightly different text from Commwarrior.A:

CommWarrior Outcast: The dark side of Symbian Force.
CommWarrior v2.0-PRO. Copyright (c) 2005 by e10d0r
CommWarrior is freeware product. You may freely distribute it
in it's original unmodified form.
With best regards from Russia
OTMOP03KAM HET!
Method of InfectionMethod of Infection -

This malware requires that the user intentionally install it upon the device. As always, users should never install unknown or un-trusted software. This is especially true for illegal software, such as cracked applications—they are a favorite vector for malware infection.



Removal - Removal -
-

VariantsVariants -
N/A
This virus arrives on your phone as a sis file attached to a Bluetooth or MMS message, it may also arrive disguised as an installer for SymCommander or on an infected MMC card. Once installed on your phone, it sends itself to all Bluetooth devices in range, sends itself via MMS to all your contacts and spreads via MMC.
SymbOS/CommWarrior.C is a Symbian worm that propagates via Bluetooth networks, Multimedia Messaging Services (MMS), and Multimedia cards (MMC).

Arrival and Installation

CommWarrior.C arrives disguised as a trojanized installer for SymCommander, a file and disk management tool for Symbian.



It appears in the phone’s menu with the SymCommander icon:



Once installed, it drops the following components:


!:\system\apps\SymCommander\cwoutcast.exe
!:\system\apps\SymCommander\SymCommander.rsc
!:\system\apps\SymCommander\SymCommander.aif
!:\system\apps\SymCommander\SymCommander.app
c:\system\apps\SymCommander\SymCommander
* ! siginifies a user-defined drive (C or E)

cwoutcast.exe is immediately executed and it in turn drops the following files:

!:\system\Bootdata\lib\cwoutcast.exe
!:\system\recogs\cwrec.mdl
It also creates a randomly named SIS file which is a copy of SymbOS/CommWarrior.C. This SIS file is also dropped in the !:\system\apps\SymCommander\ and !:\system\Bootdata\lib\ folders and is used as the attachment during propagation.

When CommWarrior.C is active, the infected phone gets automatically rebooted at set intervals.

Propagation
Once installed and running, CommWarrior.C searches for available Bluetooth devices.
When it finds a target, it sends a copy of its SIS installer via Bluetooth:



Opening this message immediately installs the worm.







After a successful Bluetooth transfer, CommWarrior.C immediately searches for and infects new targets. Thus, it has the capability of quickly spreading and infecting all vulnerable phones within Bluetooth range.

CommWarrior.C also spreads via MMS messages. It monitors the device for incoming SMS messages and sends an infected MMS as a reply to intercepted messages. The reply has for its message body a copy of the original message received and the CommWarrior.C installer as attachment. Here is a copy of an intercepted MMS message being sent by CommWarrior.C:









CommWarrior.C also spreads through MMC cards. When one is inserted in an infected phone, the following components are copied onto the card:

e:\system\Bootdata\lib\cwoutcast.exe
e:\system\recogs\cwrec.mdl
When the infected MMC is then inserted into a clean device, it executes cwoutcast.exe and infects the new device.

Other Details

The following different sets of strings can be seen in its code:

CommWarrior Outcast: The dark side of Symbian Force.

CommWarrior v2.0-PRO. Copyright (c) 2005 by e10d0r

CommWarrior is freeware product. You may freely distribute it in it's original unmodified form.

With best regards from Russia.

SymbOS/CommWarrior.C only affects phones running Symbian S60 phones.

Manual Disinfection

Scan your mobile device using UMU Scan and delete all files detected as SymbOS/CommWarrior.C.
Reboot your device to kill malware residue processes.
Download a third party File Explorer.
Locate and delete the following files and folders if they exist:
!:\system\apps\SymCommander\cwoutcast.exe
!:\system\apps\SymCommander\SymCommander.rsc
!:\system\apps\SymCommander\SymCommander.aif
!:\system\apps\SymCommander\SymCommander.app
c:\system\apps\SymCommander\SymCommander

!:\system\Bootdata\lib\cwoutcast.exe
!:\system\recogs\cwrec.mdl

* ! siginifies a user-defined drive (C or E)

Re-install SymCommander from a clean installer if needed.

Friday, June 19, 2009

WIRELESS BATTERY- LIMITED POWER SUPPLY



WIRELESS BATTERY- LIMITED POWER SUPPLY

pcheader4
True Wireless Power
Powercast’s products deliver true wireless power for continuous charging and power-over-distance for one or multiple devices. Enable your device to become finally untethered.

Low Power Charging System
Powercast components integrate seamlessly with power distribution and storage systems for low power electronic devices by delivering microwatts to milliwatts without wires.


Integrate our Technology
Powercast technology enables unique product enhancement, product differentiation, and market extensions. We are continually building a roster of strategic collaborations that benefit from wireless power and continuous charging. 04559


Experience the Future
Qualified potential partners can self-discover and rapidly prototype using Powercast's wireless power technology by purchasing a Lifetime Power Evaluation and Development Kit.
19_set_mk2_russian

A leader in partnering with the industry to enhance the end-user experience through wireless power
Powercast has developed proprietary methods to deliver unique powering solutions and holds an extensive cross-platform portfolio of related intellectual property. 19_sets_x_2_m3


IMPLEMENTATION FLEXIBILITY

Unique “Any-to-Any” broadcasting

Point-to-Point
Point-to-Multipoint
Multipoint-to-Point
Multipoint-to-Multipoint
INCREASED PRODUCT RELIABILITY

Hermetically Sealed
Continuous Charging
Battery-Free
MULTIPLE POWER OPTIONS

Continuous
Scheduled
On-Demand
Passive
True Wireless Power
Powercast recognizes there are several alternatives available for powering devices without the use of wires, each with different addressable markets. The alternative methods may seem similar on the surface, however, they offer limited solutions. Powercast is the only company with the technology and component-level products to deliver continuous charging, and provide its capability at a scalable distance.

wireless_flash trigger


Principle Limitations of Alternative Technology Performance:

Requires direct contact or close proximity
Difficult to integrate moving parts and bulky size
Inflexible deployment
Must follow specific handling process
Generates excess waste
Other limitations vary by technology type
Powercast Performance Differences:
z15i2s5t
Extends product life cycles
Reduces maintenance requirements
Easily integrated form factors
Any-to-Any configuration
Reduces or eliminates adverse environmental impact
Multiple power options: continuous, scheduled, on-demand, or passive
Low Power Charging System
The development and usage of wireless, portable electronic devices is rapidly expanding. Many of these devices share similar components which have been, or in the future will be, designed and optimized for low power consumption. These components and their suppliers constitute the low power ecosystem, and include components such as:
radio_babylon_web

Energy harvesting devices (e.g. Powerharvester Receiver)
Micro-power management
Low power microcontrollers
Low power radios (e.g. 802.15.4, ZigBee, ULP WiFi, WirelessHART)
Supercapacitors
Solid-state and thin film batteries
Powercast provides a core component in the low power ecosystem. Our energy harvesting and wireless power technologies are embedded in core interoperable components for creating low power charging systems. With safe, controllable, and scalable wireless power technology, Powercast’s products provide numerous benefits for low power charging systems, including:

Increases design-in flexibility and benefits: no contacts, no wires, sealable, and submersible
Promotes a battery-free architecture
Improves device longevity through maintenance-free operation
Powercast is seeking to continuously add additional collaborations with forward-looking members of the low power ecosystem for expanding product offerings and cross-optimizing components for performance improvements.

Integrate our Technology
Collaboration Partners
Powercast is continually building a roster of strategic collaborations that benefit from wireless power and continuous charging. Examples of collaborations include:

Technology:

Texas Instruments: RF modules, software, MSP 430 Third-Party Development Network
CAP-XX: Supercapacitor energy storage
CYMBET: Thin-film batteries
Infinite Power Solutions: Thin-film batteries
NTERA: Low-power, bi-stable displays
Esensors: Wireless sensors
Manufacturing and Design:
hk traker

TACH Technologies
Defense and Energy:

Department of Defense: Project funding
Department of Energy: Energy management
Government and Defense Contractors
Sponsored University Research:

University of Pittsburgh
University of Colorado

Complete the form below to inquire about becoming a collaborative partner with Powercast. A Powercast executive will contact you

Experience the Future
Powercast has development kits available for qualified designers, engineers, product developers and researchers to evaluate and prototype our wireless power technology.

Self-Discover Wireless Power Technology: Learn about Powercast’s patented wireless technology and all it has to offer.
Rapidly Prototype into Any Device: Quickly integrate into any prototype device using a plug-n-play solution for remote powering.
Explore Renewable Energy Possibilities: Expand the possibilities for true wireless power to become a renewable energy source for rechargeable batteries, and other energy storage devices.
Development Kit Options
battery


Lifetime Power Alkaline Starter Kit: A starter kit with Powerharvester components designed for rechargeable Alkaline batteries.
Lifetime Power Lithium Ion Starter Kit: A starter kit with Powerharvester components designed for rechargeable Lithium Ion batteries.
Lifetime Power Evaluation and Development Kit: The full kit that includes components for use with rechargeable Alkaline batteries, rechargeable Lithium Ion batteries, and non-battery energy storage (e.g. capacitors).
Products will be available in all common frequency bands.

w3


Wish you could know your Lipoly battery voltage while you are flying?
Want to be able to accurately know when your pack is about to drop voltage?

The New-&-Improved Hobbyking wireless battery tracker monitors your lipoly via the charge plug and sends back a signal to your reciever. Should one of your cells drop below 3.6v the LED for that cell will turn Red. Once the cell drops below 3v the LED will flash and the warning buzzer will beep, signaling you to land as soon as possible.
The transmitter operates on 870.0Mhz FM band and can monitor 2S to 6S batteries.

Spec.
Transmitter Weight: 7g
Receiver Weight: 35g (this is the part you keep in your pocket)
Signal distance: Around 300-400mtr
Battery: 7.4V/ 2 Cell (Included)


Usage;
Ensure the hand-held receiver is turned on and you have selected the number of cells first. Once this is done, then connect the transmitter inside the plane to the batteries balance plug. If you do not do it in this order, the reading will be incorrect.

Thursday, June 18, 2009

JSP Processing Error

JSP Processing Error

JSP Processing Error

HTTP Error Code:   404

Error Message:
JSPG0036E: Failed to find resource /auctionhome/mstc/admin/admin_login.jsp
Root Cause:
java.io.FileNotFoundException: JSPG0036E: Failed to find resource /auctionhome/mstc/admin/admin_login.jsp
at com.ibm.ws.jsp.webcontainerext.AbstractJSPExtensionProcessor.findWrapper(AbstractJSPExtensionProcessor.java:370)
at com.ibm.ws.jsp.webcontainerext.AbstractJSPExtensionProcessor.handleRequest(AbstractJSPExtensionProcessor.java:333)
at com.ibm.ws.webcontainer.webapp.WebApp.handleRequest(WebApp.java:3622)
at com.ibm.ws.webcontainer.webapp.WebGroup.handleRequest(WebGroup.java:276)
at com.ibm.ws.webcontainer.WebContainer.handleRequest(WebContainer.java:927)
at com.ibm.ws.webcontainer.WSWebContainer.handleRequest(WSWebContainer.java:1566)
at com.ibm.ws.webcontainer.channel.WCChannelLink.ready(WCChannelLink.java:175)
at com.ibm.ws.http.channel.inbound.impl.HttpInboundLink.handleDiscrimination(HttpInboundLink.java:455)
at com.ibm.ws.http.channel.inbound.impl.HttpInboundLink.handleNewInformation(HttpInboundLink.java:384)
at com.ibm.ws.http.channel.inbound.impl.HttpICLReadCallback.complete(HttpICLReadCallback.java:83)
at com.ibm.ws.tcp.channel.impl.AioReadCompletionListener.futureCompleted(AioReadCompletionListener.java:165)
at com.ibm.io.async.AbstractAsyncFuture.invokeCallback(AbstractAsyncFuture.java:217)
at com.ibm.io.async.AsyncChannelFuture.fireCompletionActions(AsyncChannelFuture.java:161)
at com.ibm.io.async.AsyncFuture.completed(AsyncFuture.java:138)
at com.ibm.io.async.ResultHandler.complete(ResultHandler.java:204)
at com.ibm.io.async.ResultHandler.runEventProcessingLoop(ResultHandler.java:775)
at com.ibm.io.async.ResultHandler$2.run(ResultHandler.java:905)
at com.ibm.ws.util.ThreadPool$Worker.run(ThreadPool.java:1527)

Saturday, June 13, 2009

VARIOUS TYPES OF SCAM - Work at Home Scam, Check Scams, Shipping Scam, Airfare, Phishing Scam



Work at Home Scam, Check Scams, Shipping Scam, Airfare, Phishing Scam



What are Work at Home Scams?



These are positions that require jobseekers to work from home assembling crafts or processing data entry. The employer requires a payment to for an instruction booklet about the position, required software, or materials. Payment is taken with a credit card and the jobseeker is advised that the materials will be mailed to them within several business days. Jobseeker receives the materials/software needed to start employment. They are given instructions to assemble the products or transcribe data, when the task is completed, the employer rejects the work. The fraudulent employer states that the project submitted by the employee, did not pass their quality control test. Often these employers require a repurchase for another kit/software for a “discounted rate” to receive another payment from the jobseeker. However, all of the work submitted to the employer will never “meet quality standard” and the jobseeker is left without income




In some cases, the jobseeker will not receive any materials to start employment. Attempts to contact the employer will be unsuccessful, due to the lack of valid contact information provided for the company. Again, the jobseeker is left without any working materials and a debt on their credit card

What are the signs of a Work at Home Scam?
Company requires payment for materials or software. (Some legitimate companies will require a fee, however you should be very careful and fully investigate the opportunity)
Employer states they are overseas.
Information about company cannot be verified.
Employer offers large salary, for minimal work.
Employment starts without a formal interview.
If it sounds as if it is too good to be true, it probably is.


What are Check/Payment Processing Scams?
Fraudulent companies claim to offer positions such as “Accounts Receivable Clerk” or “Finance Manager”. These fraudulent positions involve laundering money. The fraudulent company states that you are to collect funds from their "clients" and wire money into theri bank. The fraudulent company mails the jobseeker checks (they can be cashiers, money orders or travelers checks) and provides instructions to cash the checks. The employer will request to have the funds deposited into a bank account, which is under the jobseeker’s name. The instructions state to keep a small percentage, usually between 5%-15%, as your commission. The bank wires the funds immediately and a few days later, finds out that the check is fraudulent. By that time, the scammer already has their money and the “employee” is left with a negative bank account. The bank holds the person on the account liable for the funds, and in certain cases will seek legal action. You are also in danger of being arrested at the moment you try to deposit or cash the check.



What are Shipping Scams?
These are opportunities that require the jobseekr to the receive packages such as, Electronics, DVD, CD’s or other materials to reship overseas to another location. The fraudulent company states that they would pay commission per shipment, along with any shipping fees. The jobseeker is to receive the materials at their home, fill out custom forms, and reship the package overseas. The employer sends a check to the jobseeker, and a few days later, the bank notifies them of a fraudulent check.



The goods received from this position are obtained from an unauthorized credit card purchase online. The fraudulent employer purchased these products illegally, and uses the jobseeker to “launder” the goods overseas. Not only is the jobseeker fined for fraudulent checks from their bank, but could face legal action from the credit card company for “laundering products” or criminal prosecution for receipt of stolen goods.





What are signs of a Air Fare Scam?
Phone number routes you directly to a automated message requiring you to leave your information
Company requests that you pay for half or all your air fare and states you will be rembursed at when you land
Payment is requested via wire/money order/pay pal
Company infomation cannot be verified



What is a Phishing Scam?
Phishing scams are cleverly hidden attempts to get your account information. These emails are sent with legitimate looking header information, company logos and formatting and often claim that there is an urgent need for you to login to your account. Any time you receive one of these emails, please be sure to check the destination URL on the link contained within BEFORE attempting to login or submit any information. These emails are cleverly disguised to appear as though they were sent by a legitimate company, however the links contained within lead the recipient to a false website. These false sites are usually identical (or very similar) to the site the recipient thinks they are traveling to. Once the recipient has logged in, the site owner (scammer/phisher) has their login information and can use it to their advantage. Sometimes the sites will contain fields to be completed, often requesting that the victim update their banking information or other sensitive information.





What are signs of a Phishing Scam?
Do not click on links or provide any information via email
Remember that Careerbuilder will NEVER ask you to update your account via email with a link requesting you to login
Hover over the link and it will reveal the true URL
_________________________________POST BY ALOKRAJ.