Reading about safety, first about firewalls, anti-spyware programs and such, and then about virtual partitions, sandboxes and stuff, I came to
this page, saying:
Proof Of concept
Don’t Compromise – Virtualize!
Attention: By agreeing to perform the following PC vulnerability test, you will become subject to our “Cyber Attack”. This is only a demonstration and no actual damage will be caused to your PC or network.
We will, however, simulate a malicious file received, for example, via the Web, as an email attachment, from a memory stick, or from any other path by which an executable file can enter your system. We will attempt to prove that none of your security systems will identify or alert you to our intrusion attempt.
Step 1: Run our .exe Vulnerability Test File
As you run our .exe file, we will demonstrate how hackers can do as they like on your PC:
- A. Launch your Windows Calculator
- B. Abort your Internet Explorer
- C. Access several sensitive files (no harm will actually be done), and scan your ‘My
- Documents’ folder, where you probably keep your private information.
- D. We will then place your sensitive file names (names only!) on our server. During the
- process, your firewall may notify you of our demo trying to access the network; this means
- that our demo has successfully accessed your system and is trying to report its findings to
- our server.
Step 2: View your PC’s Vulnerability Test results
If you allow our Vulnerability Test File to connect to the Internet, you will receive a link that enables you to view your PC’s Vulnerability Test results. As soon as you refresh that Web page, the information we were able to collect from your PC will be immediately and automatically erased from our servers.
(...)
After reading and agreeing to the above, I want to launch the Vulnerability Test File -Buffer Zone
"I want to launch the Vulnerability Test File". I clicked the link to open the test file, and sure enough: My calculator did open, Explorer crashed, and the name of every file I have in MyDocuments was "published" on the Internet - with the headline "Process communication attack: SUCCESS!" and a last line declaring "
spy attack: SUCCESS!"!!
Of course no harm was done.
Suddenly I am even more interested in virtual sandboxes!!
Can you pass the Vulnerability Test from Buffer Zone?? (scroll all down to the last line)
Please first take the test and then come back and Vote and Post.
http://www.trustware...roof_of_concept.html