jeudi 1 janvier 2015

8 best SMS apps for Android: make text messaging better



Not everyone likes the default Android SMS app, so we've listed the best SMS apps for looks, functionality, security and more.



(This is a preview - click here to read the entire entry.)





Website hacked. How to deal with it?



How to deal with a compromised website running on shared hosting?


I'm looking answers for:



  • What are the steps should I follow in order to take back the control and block any future attacks by the same vulnerabilities?

  • How to know what vulnerability was used by the hacker to exploit? (I guess, this is not going to be a straight answer but I'm expecting best possible).

  • Any scanning or ways to identify the malicious codes?


Some of the technical details here -



  • Shared PHP web hosting.

  • The account contains multiple add-on domains including the ones running wordpress and custom PHP.

  • Hosted on one of the popular web hosting companies running on Linux.


Some of the symptoms noticed -



  • The homepage is being redirected to some other URL where advertisements are hosted.

  • Homepage is defaced.

  • Some of the source code has been changed. The file has been updated with a lot of code encrypted by regular expression.

  • .htaccess is updated.


I've looked at How do I deal with a compromised server?


Please free to comment to ask me more details if required.


TIA, Pavan





How do spammers create fake pages on certain websites



Whilst looking through apache logs I found a number of peculiar referrers - visting those pages showed that the sites have been compromised and are hosting pages created by spammers full of spam keywords and links. My question is how do they create these pages on various websites?





Running untrusted Python code



I have a small OpenWRT router, on which I wish to run a daemon which is a python script. However, even though it is open-source and plain Python, I still don't trust it and I would like to isolate it from the rest of the system as much as possible. It has to do the following:



  • Bind and listen on a single TCP port

  • Read/write some files in its working directory


Apart from that, it should not be able to do anything. I've thought of doing the following:



  • Start a wrapper script as root, bind the port, then drop group membership and drop into a new user before importing and executing the actual script

  • Run it in chroot


Did I miss anything that would help to make it run more securely?





The 5 best Android widgets you should try right now



Widgets are great, but they can easily get out of control. Here are our five best widgets for Android and how they can help simplify your Android experience.



(This is a preview - click here to read the entire entry.)





What kind of cryptography is this



In a website called "Chatzy", when you post a message you send a POST request containing the message and your name and color, the name and color are sent in this form



MzEwMzk4ODgyNTIxNTQmMzEwMzk4ODgyNTIxNTQmMCZYMTY4JjE0MTE4NjkzNDUmSVFTQVhZT1MmRXZl​cmdyZWVu4oCMJjMyQ0QzMiYmMSYzJjEmdWJ1Z2dAemV0bWFpbC5jb20mZ3JpbTMyNzFvaCYxNDExNjAz​NTI5JiYyJg%3D%3D



That code gives the name "Evergreen" in this color http://ift.tt/1vJdjCc and here is the post in HTML



<P class="a"><B style="color:#32CD32;">Evergreen‌</B>: derp</P>


Can anyone tell me what that kind of cryptography is? I can provide more information if needed.





Can folders [alone] have viruses?



I know that files can be infected, but can a Folder itself have a virus/trojan?