Wednesday, January 03, 2007

Adsense inside the article/post in new blogger(beta).

With due credit to Loui$$ who maintains the blogginsecret.blogspot.com here am providing you with the hack he has mentioned at his blog to put Google Adsense right at the beginning of your article or within the post in Blogger Beta or the newblogger. Also see some additional notes from me.

Ok, let us have look at the method and how I did it:

1. Login to your Adsense account and get the code for the Adsense lay out you prefer and copy and paste it into a note pad.

Hope most of you know how to get the code. Google adsense account>adsense for content>Ad Unit>text ads.

2. Next on the notepad you will see the code in the following form:
<script type="text/javascript"><!--
your ads code
//--></script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>

Now replace the <!-- and //--> as &lt;!-- and //--&gt;

3.Login to your new blogger and go to Layout > Edit HTML > and copy and paste the template into your notepad.

4. In the notepad in which you have saved the template search within the notepad (using Cntrl + F ) for the following term: post-header-line-1

This will enable you to find div class="post-header-line-1" which is just below the data:post.title

5.Now copy the whole Adsense code that you got from Google Adsense accout that was changed by replacing the <!-- and //--> as &lt;!-- and //--&gt; as mentioned in step 2 and paste it just under the "post-header-line-1"

6.Replace the template in your blogger with this changed template by deleting the template in your blogger template box andthen copying and pasting the template from your notepad into the blogger template box. You are done.

Additional notes:

1.Before you copy and paste the template check the "Expand widget templates" and then copy and paste the template on yournotepad. Only then you will see the div class="post-header-line-1"

2.Back up your templates before changing it.

3. Google allows only 3 Adsense layouts and one link unit. So if you already have some, make sure before you add more Adsense within your post, those ones are deleted. Google ensures that only 3 different Adsense layouts are shown even if you place more. But it is better to be on the safer side by ensuring that you have put in only 3 Adsense layouts and one link unit.

4. If you already have placed Adsense in your blogger using the Add HTML page element save that in your notepad before taking it off as this will enable you to put it back easily if you want to experiment with the Adsense layouts instead of going back to your Adsense account each time to generate codes.

5. Originally Loui$$ had mentioned about just deleting the tags within the google Adsense code. But later it was changed to replacing the tags as mentioned in step 2 as this would ensure that the Google TOS is not violated. This particular idea was suggested by bloggerdigest.

How to put Adsense at the end of an article/post:

The above mentioned method allows people to put the Adsense Ads at the beginning of an article in the new blogger (Prev. Beta). To put an Adsense Ad at the end of an article or a post use the same method mentioned above, the only difference being this time the Adsense code (just like the hack mentioned above) has to be put under the class= 'post-footer-line post-footer-line-1'

How to wrap Adsense around posts:

Monday, January 01, 2007

How safe is your password?

Recently as most of the people know some of the passwords of the myspace users was compromised by using a fake login page. And this is just a drop in the ocean when you take into account the phishing attacks that have been so rampant on the net lately along with the vast amount of Trojans that have been making the rounds.

This article at the securiteam website clearly shows how some basic techniques can be used to steal passwords especially at a website like Myspace.com and how the passwords were compromised. Also, it was not long back a Digg user posted some user name and passes of Myspace users.

Clearly it has come to a stage where not just using complex 8 character or alphanumeric passwords is gonna safeguard the Internet users from their passwords being hacked.

Even the Firefox version 2 had a flaw in it's password manager which could allow malicious people to collect the passwords of the unsuspecting users. Till now Firefox has not taken care of this vulnerability. This was known as the Reverse Cross Site Request vulnerability.

Recently I read an article by Bruce Schneier and according him among the list of the stolen myspace passwords there were even some 32-character password: "1ancheste23nite41ancheste23nite4."

Other long passwords were "fool2thinkfool2thinkol2think" and "dokitty17darling7g7darling7."

All that effort put in to get those long and complex passwords didn't succeed to keep it safe in the end. All because someone managed to fool the users into believing that they were actually logging in through the myspace when actually what was happening was that all the passwords were being stored in a fake server set up by the attacker.

Also according to Bruce Schneier the following were the 20 most common passwords used among the 34,000 compromised Myspace user passwords:

password1,
abc123,
myspace1,
password,
blink182,
qwerty1,
fuckyou,
123abc,
baseball1,
football1,
123456,
soccer,
monkey1,
liverpool1,
princess1,
jordan23,
slipknot1,
superman1,
iloveyou1
monkey.

Among these the most commonly used was password1

So in these days were security exploits are rampant along with phishing attacks there are also a wide range of password hacking tools available for free on the net. Tools like Access Diver, which is actually supposed to be used by security personnels to test their network are being used widely by hackers for various attacks like bruteforce, dictionary attacks etc:- Also, available freely and widely are tools like Brutus, Caine & Abel etc:- Add to it Trojans and keyloggers especially the christmas themed malwares and the New Year themed Postcard.exe trojan that have been making the rounds.

So the users have no other option but to build a strong defense. And how can you build a good defense? Ok, let me give you some input:

  • Use browsers with antiphishing tool bars like Firefox 2 (but disable the Password manager in FF2 because of the RCSR vulnerability I mentioned earlier) and Internet explorer 7 or Opera's new 9.1 browser with Real time Anti-fraud technique.
  • Also one can use Netcraft's Toolbar to protect oneself from the malicious websites. It was a Netcraft Toolbar who spotted the fake website that was stealing passwords of the Myspace users.
  • One can also use Mcafee's site advisor tool. You download it here.
  • Disable Java, Java scripts, cookies, Active X in your browser as much as you can.
  • Use complex and different Passwords for each sites using Password generators and Password storing tools, some of which even does the encrypted auto filling. You have a look at some of the best Password related tools here.
  • Anti-trojans-- Get a good Anti-Trojan. Read this article I wrote for more information.
  • Antispywares--You will find a list of some of the best Anti-spywares with a review here.
  • 27 steps to prevent viruses-- Read this article to get an idea about how one can protect themselves from getting a computer virus.
  • Anti-Rootkits--Check it out here.
And above all always use your judgement. Happy and safe surfing folks.



Sunday, December 31, 2006

Letterpop--Create amazing newsletters for free.

I came across this amazing site today where you can create your own creative and unique newsletters. Now instead of going to various sites to pick a greeting card you can create your own. Once you sign up for a free registration you can even use your own pics and photos and thus customize it.

There is a 12 month free premium membership available for users registering now.

One can even use this to create wedding cards, newsletters for small businesses etc:- All you will need is a printer if you want to have a hard copy of the newsletter. But if you just want to send your custom made newsletter or cards to someone over the internet just click on the email button.

There are currently 14 templates available and once you are upgraded to premium (which as I mentioned is free now) you will get a wider range of templates. All users signing up now will be upgraded to premium soon. And there are six pre-set images. But like I mentioned earlier one can upload their own images once you sign up. You can upload upto 25 images.

You can drag and drop the template and then your images. By clicking on the "Headlines" and "Text here" you get to see the composer and you can choose a variety of fonts and colors.

The news letters are auto saved and you can always go back to the newsletters that you have been working on even if happen to accidentally close a page.

This site was started recently and you can expect a lot of upgrades.

So, pay a visit to the Letterpop and let your creative juices flow.

Anti Rootkit for Windows Vista.

F-secure has on 29th Dec released a beta version of it's Black light AntiRootkit software which supports Windows vista. This also supports the Windows 2003 server and will work with all other supported platforms too.

Currently it supports 32 bit versions. But F-secure is adding support for 64 bit OS.

There are currently no known rootkits for the 64 bit operating systems. But since it is not impossible to create rootkits for the 64 bit operating systems F-secure is will be adding support for that too.

As I had mentioned in an earlier article about Kaspersky and Vista, Kaspersky also has released a beta version of it's Antivirus software which supports Windows vista.

You can download the new beta BlackLight here.

Related reading:-
What are rootkits and AntiRootkits.

Worm sends massive amounts of fake NewYear greetings.



Luder.A also known as Tibs.jy is an email worm, a dropper for a trojan downloader and a file infector and it has been reported by F-Secure that this worm is sending out mass emails in the form of fake New year greetings.

The numbers are big enough for F-secure to raise the threat level for this worm to Radar Alert Level 2.
The attachments mostly comes in the form of Postcard.exe and is always themed around New year even though the text might vary.

According the report, before spreading the worm collects e-mail addresses from an infected computer. It locates and reads the WAB (Windows Address Book) file. The worm avoids sending e-mails to e-mail addresses that contain any of the following:

* microsoft
* .mil
* .gov

To learn how to disinfect the worm go here.

Kaspersky and Vista.

On the 22nd of this monthKaspersky has announced support for the Vista operating system through it's Anti-Virus 6.0 and Internet Security 6.0 personal software products. The new feature added to these products which is Maintenance Pack 2 is the support for Vista.


It was only recently that Jim Allchin of Microsoft was misinterpreted by the Media and was reported that Vista is such a secure OS that it will not need any additional antivirus protection.

In an article written by the CEO of Kaspersky, Natalya Kaspersky, she makes some good points about how Vista is far from being a fully secured OS on it's own.

Vista comes with Windows Defender but this is just an Antispyware and it does not protect against all malwares. Users can also choose to use One Care provided by Microsoft but this does not come as a part of Vista and has to be purchased separately. This new commercial Antivirus program by Microsoft still has it's limitations. And there are three points that Natalya makes regarding that aspect:

1. Microsoft’s reputation in the security field. Microsoft still does not have a good reputation in this area. By default, Microsoft solutions are perceived as being insecure or full of security loopholes. These loopholes in Windows and MS Office applications are due, above all, to extraordinary popularity – hackers across the world are going to hack programs used by the majority. Given this, I am afraid that Microsoft’s new antivirus solutions may suffer the same fate; virus writers will create malware that is designed primarily to evade detection by OneCare.

2. Another important factor is the speed at which vendors have to respond to new threats. All vendors face the same dilemma – either detect the maximum possible number of malicious programs (even at the risk of false positives) or avoid false positives at the risk of failing to detect malicious programs. Just remember the media fuss which broke out when Microsoft's antivirus detected Gmail as being malicious, with only a few journalists failing to pick up on the story. Another slightly less well-known case was when a Microsoft product detected the Russian antivirus product Dr. Web. Given Microsoft’s brand and reputation, the company simply cannot allow itself to make such mistakes. As Microsoft will need to check each potential false positive with its legal department, response to new threats will inevitably be slow.

3. The detection rate is an important characteristic of any antivirus. AV-Test GmbH at the University of Magdeburg tested OneCare in September and November 2006. The results from both tests indicated a detection rate that would be considered fairly low for your average antivirus product (the most recent – 81.22%).

Natalya clearly states that Windows Vista does have a number of features that improve security, but it still cannot guarantee protection against malware. A standalone antivirus solution is therefore a must.

Natalya's article gives some insight into the Vista security aspects. Read the article here.

So Vista needs to be protected by an Antivirus solution from an expert and experienced Antivirus vendor. And the beta versions of Kaspersky Antivirus 6.0 and Kaspersky Internet Security 6.0 with the Maintenance Pack 2 does just that.

You can download the beta version here and can be downloaded for free now.






Google