Skip to main content

Melissa - Nothing but a virus



Melissa refers to a virus, that Written in macro language (visual basic for application languages that use to create MS excel and other word processing software) and disseminates through e-mail attachment. It was the first malicious software which contains the virus, worm, and Trojan as one package and it was found in 1998-1999 span. Melissa has the capability to affect over 1 million computers within 3 days. Once your device is infected by Melissa, receiving emails will be blocked.

The email which carries out the Melissa virus has subject line as “important message from someone” and body text starts with “here is that document you asked for… don’t show anyone else”. The email attachment typically stars as ‘LIST.Doc’. When the recipient opens the email or clicks on the attachment, the software will be immediately activated. Then it sends the same email to the emails addresses which are in the victim’s mail address book. And also it copies itself to documents that are in infected computer storage. Moreover, it propagates by itself like a worm. It will display Simpson cartoon quote “Twenty-two points, plus triple word score, plus fifty points for using all my letters. Game over. I am outta here” when triggered occurred.

Subsequently, undefined error messages, display a blue screen with errors, Interruption in system performance, unexpected removals in files and folders, unexpected termination of a process can be take placed. Since you cannot evade emails, be always cautious about the email you receive, whether the emails have the above characteristics. Besides, delete those suspicious emails and inform the sender too.  


Comments

  1. Very informative . Waiting for future articles😇

    ReplyDelete

Post a Comment

Popular posts from this blog

Change Language in Google Account

When we create an email address, sometimes we do not consider the language preferences. Afterward, when we log in to a google account, context will be shown as unfamiliar. So we can change the language preferences of google account by following steps.  1.  Click on the Google profile and select google account 2.  Select data & personalization settings. 3. Scroll down and go to general preferences for the web. And click language. 4. If you need to change the default language, click on the pen sign. 5. If you want to add more languages, click on add other languages.

Synchronizer Token Pattern

Synchronizer token pattern is one of the prevention methods for Cross-Site Request Forgery ( CSRF ). It uses a value called CSRF token which is unique for a session identifier. When the user login to a website, the server generates a random value called token for a particular session. The token is saved on the server as well as the browser (after obtained from the server). PHP identifies the session using the session variable ‘PHPSESSID’ which is also stored in the browser as the cookie to identify a particular session. The server validates the user when each request is made, via comparing the token value in the server and token value in the browser. Through this write up how synchronizer token pattern is implemented and how does it works will be described.  (Click on the images to view clearly) Source code of the implemented program can be downloaded from here .  I have implemented a login page called index.html to enroll a user to the server. T...

CSRF - Cross Site Request Fogery

Cross-site request forgery (CSRF) is an attack where the legitimate user trapped by an unauthorized user to perform an unintended task to a website where they are authenticated. Since HTTP is a stateless protocol, cookies are used to validate the request agent. Once the user login to a website, it will not require to type the username and password for each attempt. Hence, for the server to identify the user, the server generates a session identifier and sends it as a set-cookie header to the client browser with the very first response. The cookie set by the server will be saved in the client browser and, the cookie will be sent along with every request made to the server (Where the domain and path are matched). However, the server does not check any other attribute but session identifier. Although the request is made from another client, the website only verifies whether the requesting user is already authenticated or not, using a cookie. For example, if a person logged in...