Girl Geekette dotNet

Where the Girl Ends and the Geekette Begins


Archive for September, 2005

PayPal Scam from guest@bf-l.ch

Heads up, once again, there is another PayPal Scam going around that might look legitimate to some. In it, the email states you have added a new email address to your PayPal account and wants you to be aware of this. If you don’t believe it is right, it gives you a link to log in and check and protest.

The email reads:

——– Original Message ——–
From:  - Tue Sep 20 17:36:28 2005
X-Account-Key:  account3
X-UIDL:  i^N"!og["!dld!!/l/!!
X-Mozilla-Status:  0001
X-Mozilla-Status2:  00000000
Return-Path:  guest@bf-l.ch
Received:  from smtp.bf-l.ch (194-158-242-54.adslpremium.ch [194.158.242.54]) 
Tue, 20 Sep 2005 16:32:07 -0500 (CDT) (envelope-from guest@bf-l.ch)
Received:  by smtp.bf-l.ch (Postfix, from userid 520) id 307652CDC2; Tue, 20 Sep 2005 23:31:55 +0200 (CEST)
To:  kyralea@tranquility.net
Subject:  New email address added to your PayPal account !
From:  service@paypal.com <service@paypal.com>
Content-Type:  text/html
Message-Id:  <20050920213155.307652CDC2@smtp.bf-l.ch>
Date:  Tue, 20 Sep 2005 23:31:55 +0200 (CEST)
X-milter-7bit-Pass:  YES
X-milter-date-PASS:  YES
X-UIDL:  i^N"!og["!dld!!/l/!!

As part of our security measures, we regularly screen activity in the
PayPal system. We recently noticed the following issue on your account:

We would like to ensure that your account was not accessed by an
unauthorized third party. Because protecting the security of your
account is our primary concern, we have limited access to sensitive PayPal
account features. We understand that this may be an inconvenience but please
understand that this temporary limitation is for your protection.
Case ID Number: PP-072-838-482

https://www.paypal.com/us/cgi-bin/webscr?cmd=complaint-view

For your protection, we have limited access to your account until
additional security measures can be completed. We apologize for any
inconvenience this may cause.




Search: Cosmos | BlogPulse
Submit: Digg This | Shout this! | Slashdot
Bookmark: Del.icio.us | Furl It | Spurl | Tag!RawSugar | Simpy This! | Shadows Tag! | Blink It | My Web
GirlGeekette dotNet Tags: , , ,
Technorati Tags: , , ,
Archived in Scams , PayPal
No Comments »

Top of the Page Top of the Page









Alternate Data Streams Windows 2003 Test

Needless to say, I was inspired by an article on Windows SecurityOpens in a new Window that did a test using Windows 2000 to try my own test with Windows XP using NTFS. Now, I have decided to test it using Windows 2003. Below are my findings and screen by screen snapshots (Thumbnails are shown, click them to see a larger picture that opens in a new window):

ADS test using Windows 2003

1. I begin by making a test directory and copying the c:\windows\system32\calc.exe to it. Notice the original date and timestamp (last modified time and date stamp) of the file is 4/3/2003 8:00AM and the size is 113KB.

ADS Test Picture 1

Here is a listing in DOS that shows the directory with the copied calc.exe file.

ADS Test Picture 2

2. I append an ADS (Alternate Data Stream) to the Windows Calculator program I copied to the test directory with another Windows program (Notepad - c:\windows\notepad.exe).

ADS Test Picture 3

Notice the size of the calc program did not change, bit the timestamp (last modified time and date stamp) DID change.

ADS Test Picture 4 Ads Test Picture 5

3. Next, I executed the new ADS notepad.exe using the standard command start.

ADS Test Picture 6

On the desktop, the NOTEPAD program popped up, even though I had executed the CALC program in the command line.

ADS Test Picture 7

4. By using CTRL + ALT + DELETE to get the Task Manager, I noticed that my test varied a bit. In the task manager, I could clearly see that calc.exe was running (which I had executed at the command prompt) but, unlike the simple demonstration using Windows 2000, Windows 2003 displayed the calc.exe name and ADS command, much like Windows XP.

ADS Test Picture 8

This is where I must stop and note that depending on the version of windows used, things can be displayed slightly different.




Search: Cosmos | BlogPulse
Submit: Digg This | Shout this! | Slashdot
Bookmark: Del.icio.us | Furl It | Spurl | Tag!RawSugar | Simpy This! | Shadows Tag! | Blink It | My Web
GirlGeekette dotNet Tags: , ,
Technorati Tags: , , , , ,
Archived in Security , Ramblings , 2003 , Windows
No Comments »

Top of the Page Top of the Page










About the Geekette

I am a Computer and Network Technician. I love what I do for a living, as my work is also my hobby.

All of the technical information from the original Aleeya.net site became this site - GirlGeekette dotNet - and the remaining became what is now known as Aleeya dotNet. This site is where I store all of my notes related to computers and Technology so I may share it with others.

  Google


Web This site

Feeds

Validations

Ratings

Computer Links

Blog Links

Security Links

Geek Links

You Are Here

You are currently browsing the Girl Geekette dotNet weblog archives for September, 2005.

Archives

Powered by WordPress with a modified version of Ragiels Dream theme.

35 queries complete in 0.227 seconds.