HYIP-Man: January 2006
Monday, January 23, 2006
attachment spoofing in Mozilla Thunderbird
attachment spoofing in Mozilla Thunderbird
SecuriTeam has reported a vulnerability that lies in the way that the mail reader Mozilla Thunderbird displays attachments, which allows an attacker to spoof them.
The security flaw in Mozilla Thunderbird occurs because attached files are displayed incorrectly in messages. This flaw can be used to spoof the extension and icon associated to the file using a combination of over long names with blank spaces and Content-Type headers that do not correspond to the file extension.
An attacker who successfully exploited this vulnerability could save malicious files to the desktop.
Users of Mozilla Thunderbird are recommended to update by installing version 1.5, which is not affected by this security problem.

Labels:

Tips on creating secure passwords
-Don't use passwords that are based on personal information that can be easily accessed or guessed.
-Don't use words that can be found in any dictionary of any language.
-Develop a mnemonic for remembering complex passwords.
-Use both lowercase and capital letters.
-Use a combination of letters, numbers, and special characters.
-Use different passwords on different systems.
HYIP.BIZ - Scammer. Do not invest
Do not invest in this program. I signed up before the new script and they issue me a default transaction code after they changed to a new script. I did not changed the transaction code. Now I want to withdraw my interest, the script refuse to release my interest due to invalid transaction code.Admin refused to reply my email and deleted my post at their forum.
HYIP Virus Warning
If you get an email saying to check out a new hyip called HYIPreal.com
DO NOT OPEN IT, DO NOT GO TO THAT LINK.

It just redirects to a page called newsiness.com which opens an iframe that links to another page which exploits the windows IMG glitch, allowing the user to exploit you and install an exe on your computer.
The virus image file installs this exe: www.chamberofgold.com
Sunday, January 22, 2006
Basic Security
- Create 3 and more e-gold accounts and spread the funds among them. All with different passwords
- Change your password as least once a month
- Different password for each of your HYIP investments
- Update your anti-virus daily and scan regularly
- Update your spyware detector program daily and scan daily
- Never trust any spam mail send to you.
- Never send your password to anyone !!

Labels:

Understanding E-gold
What is E-gold?
It’s an e-currency that is most widely used in HYIP sites. Don’t have an e-gold account? Go to www.e-gold.com and create an account now!
How to get e-gold?
After setting up an e-gold account, the next thing you need to do is to get gold into your e-gold account!
Newbies thought they can fund their e-gold account through the e-gold website. NO! It’s not like other payment gateway such as paypal, moneybookers, etc.you need an E-gold exchanger.
For a list of reliable e-gold exchanger visit
https://www.e-gold.com/unsecure/thelist.htm#marketmaker

The process of funding your e-gold account with gold
1. You pay cash to the exchanger.
2. The exchanger put gold into your e-gold account.

The process of getting cash by selling your gold to the exchanger
1. From your e-gold account, you send gold to the exchanger’s e-gold account.
2. The exchanger sends you cash.
HYIP or a High Yield Investment Program

HYIP-Man Started.