Saturday, January 19, 2008
Antivirus Protection
Many people wonder if they should pay for an anti virus protection program instead of purchasing one. The reason why these people want to know about a free anti virus protection program is because the Internet has conditioned us to think that everything should be free. However, when you are looking for an anti virus protection program, you need to understand that just because someone is telling you that you can have this program for free, does not necessarily mean that it is free. So, whenever you are choosing a good virus protection program, you should stop to think about this for a minute you will understand that a person who has spent a huge amount of time developing and maintaining an anti virus protection program will want to make money off of it somehow in order for them to be able to create new programs. Plus, with these programs you will more than likely not get any type of technical support because the person who designed the program is giving it away for free. If you still choose to use a free anti virus protection program, you should know that there are probably some type of spyware attached to it. This spyware will then allow your computer to be tracked for advertisement purposes. You may also have your computer scanned for e-mail addresses or other pertinent information that you would not want to give anyone. For these reasons alone, you need to be very careful whenever you install these free programs on your computer. Even better yet, you should pay for your anti virus protection program. These programs really are not that expensive and yet they will help keep you safe from any malicious attacks on your computer. Of course, you should also be using a firewall in order to ensure the complete safety of your computer. When you ready for shopping antivius protection software check for following things. Does it provide 24/7 suppport system. How regular they update antivirus software. Do they have high speed downloads Do they block Spyware, Spam and Popup-ad Filrewall feature available etc. spywareantivirus.info
Remove Blackworm
Blackworm started on the 3rd of February and has been programmed to attack an infected computer on the 3rd of every month thereafter. So far it has been estimated that over 300,000 computers have been infected. It can also disable the keyboard and mouse of infected computers. Some Internet users have already lost important files after becoming infected by the Blackworm mainly because the clock time on their computer was wrong. Like many Internet worms, Blackworm attempts to spread by mailing itself to contacts in a user s address book. The e-mails containing the worm can have a wide variety of Subject fields and attachment names. The worm also tries to add itself to the auto-start programs in the Windows registy. Once a computer in a network has been infected, Blackworm will try to infect all other systems in the network. To prevent getting infected by Blackworm you shouldn t open attachments or click on Web links within these e-mails, especially if these e-mails have a porn-related subject line. You should also backup any important files that you would like to preserve. Most antivirus products will detect Blackworm assuming the worm hasn t disabled the antivirus software. It is also recommended to scan your computer for viruses and use a firewall. About the Author: Edward is the owner of thespywareterminator.com where you can download the highest rated spyware remover for 2005. This superior software removes many unwanted Internet parasites such as viruses, trojans, popups, adware and spyware. It has been downloaded over 35 million times by people in over 100 countries. It really works!
iPhone Hacks and Threats to Personal Privacy
Weâ™ve been amazed by it since its introduction. Who canâ™t remember the address given by Steve Jobs of Apple when he introduced the revolutionary iPhone? Who wasnâ™t amazed at the device that was capable of surfing the web, taking pictures, listening to music and of course receiving and placing calls? Nothing new, right? Just as the iPhone was released, hackers around North America started to dig into what makes this tick. The primary reason was to unlock the phone so that you didnâ™t have to sign-up with ATandT but with any carrier that supported the technology. But could there me more nefarious reasons to hack the iPhone? Skilled hackers could now take their phone onto any carrier, but more importantly they could create and enable custom ring tones (without having to pay for buying ring tones), enable custom wallpapers and more. In process of hacking into the iPhone, several tidbits were gleaned - such as the fact that the software on the iPhone runs as root - in the Unix world this basically gives you full and complete access to the machine. You could bring down entire servers and even chains of servers if you have ROOT access to a Unix machine. So how does this impact you, the average user of the Apple iPhone that isnâ™t planning on hacking into their phone? Well someone may want to hack into your phone and they now have the blueprint to do it. While Apple is working hard to try and prevent hacking by playing cat and mouse game, it will always be a cat and mouse game. If you happen to surf into a questionable website that happens to download software to your iPhone you could end up in a whole heap of trouble. In an article in the New York Times Technology section from July 23, 2007, an iPhone flaw was found to let hackers take over the iPhone. Remember that most people store entire lives on their digital assistants (whether this is a Smart Phone, the iPhone or even a PDA). They keep names, addresses, phone numbers, e-mail addresses on them. Not to mention passwords, banking information (such as bank account numbers) and even digital images taken by the built-in camera. Now imagine if a hacker has access to all this data. The security firm, Independent Security Advisors found that through common flaws (and without even hacking into the phone) they were able to gain unauthorized access to the contents of the phone through a WiFi connection or by tricking users into visiting websites that insert malicious code onto the phone. The hack enabled the firm to gain a wealth of personal information that the phone contained. Dr. Miller, who was a former employee of the National Security Agency also demonstrated the hack by visiting a website of his own design, inserting some malicious code onto the phone and then proceeding to have the phone transmit data to the attacking computer. He went on to say that the attack could be used to program the phone to make calls thereby running up the phone bill of the user not to mention the phone could be used to spy on the individual by turning it into a portable bugging device - remember, it does have a built-in camera. How can you protect yourself? As with any device, common sense should prevail. Donâ™t open e-mails from people you donâ™t know - if you open them, and there are attachments avoid opening the attachments or visiting the websites in question. Since the Apple iPhone has automatic updates, always ensure your iPhone has the latest updates by visiting the manufacturerâ™s site. If you are very concerned about threats to your iPhone you may also want to visit the website exploitingphone.com/, which is run by Independent Security Evaluators to stay on top of hacks and threats to your personal data on the iPhone. Even doing simple searches in Yahoo, Google, or MSN with iPhone hacking threats will give you a wealth of information. Copyright © Mohammed Bhimji Get more information about adware, spyware, malware and viruses plus information on wireless wifi theft and securing your wireless connection at free-adware-spyware-virus-removal.com
Watch Heroes Online
You can become a real live Hero to yourself and your family, by taking part in the next technological revolution: Watch heroes online. Heroes are one of the most popular series fiction and drama series ever to hit the television screen. Since it was launched a year ago, it has really captured the imagination of the television viewing public of North America and all across the planet. You can now watch heroes online. The very concept that a simple group of average people suddenly discovering that they have been given super powers is an exciting concept, and one that all of us are inclined to daydream about. Heroes has become amongst the most-watched programs on television, and the current series continues to attract record breaking audiences. But let s say that you are one of the people who, for some reason or another, cannot be around to watch television when Heroes is airing. You have to work, you have to make a journey for business or pleasure. You can now watch heroes online. Until recently it was a lost cause and you had to wait for a rerun or listen to your friends and work mates telling you how last nights episode was so interesting. And how it was a shame that you missed it. You will be glad to know that these days can now be over for you and you can watch heroes online asap. You may have noticed if you surf the internet a new software program that has been developed that allows you to access hundreds if not thousands of television channels straight from the internet. The advert may have caught your eye, and in your sub-conscious you may have said too good to be true You may even have entered their web site and read a little and then decided Why be a hero! and moved on. And you may have become one of the many tens of thousands who have discovered that this software innovation is true and anyone who takes the steps of investing around fifty dollars to purchase and download has indeed become a real hero and blessed with special powers/ The special power to free themselves from the shackles of the cable and satellite programs suppliers who have been charging them a fortune for a less sophisticated version of this software technology for years. All you have to do is check it out and I guarantee you will be watching heroes online in no time. Many people here the word software and technology and they immediately panic Technology scares me and that s why I prefer to stick with the cable or satellite companies they say. Yet it is so simple to operate the software and enjoy the benefits of television viewing freedom all that is required is access to a broadband connection, and thousands of television channels are yours for the viewing. Once the purchase has been made and the software successfully downloaded and installed, then a whole new world of viewing pleasure will be available to you and your family. Not only watching football on your computer monitor or TV screen will become a matter of course, but also a wide range of other television programs and films as well as including watching heroes online of course. The day to day operation is very straightforward and the software comes with a user friendly interface that even the children will find easy to use. No doubt about it, with this new edition to your software collection, you can become a genuine Hero and watch TV series, news and current affairs and sporting events from all over the World around the clock. You can send the cable guy on his way never to darken your doorway again. Become a Hero to yourself and your family by installing a TV/PC connection. The following link will take you to watch heroes online .
Website Security Rules Explained
2006-2007 has been the years that online shopping has come into its own with online consumers spending a record $65.1 billion in merchandise via the web. More and more people are getting comfortable with online shopping and are engaging in online shopping, research and exploration of various membership and subscription sites. Unfortunately, the chances of becoming a victim of Internet fraud also increases with every site where personal information is places. The Internet National Fraud Center Watch recently reported that the average loss due to fraud the first six months of 2006 was $2,579. This is compared to the $895 average for all of 2005. Complaints relating to general merchandise purchases (goods never received or misrepresented) accounted for 30% of Internet fraud complaints, and auction purchases (goods never received or misrepresented) topped the list at 44%. One of the big scams in 2006-2007 is the investment scam. Investing has always been thought of as a good way to build a nest egg for retirement, but there are so many investment schemes offered via the Internet that you don t really know which one is correct for you. Further, there are so many schemes that, while they appear legitimate, are pure scams. If you take your time, do a lot of research prior to signing on to something and don t get taken in by the hype, you can make wise decisions and avoid losing your money to fraud. Many e-commerce sites are trustworthy and have taken the necessary safety measures to shield you, but it still never hurts to proceed cautiously. If you decide to make an online purchase consider these simple steps: 1. Make all purchases with one credit card, preferably with a low credit limit. Avoid using an ATM or debit card because that s money taken directly from your account. 2. Be wary of unsolicited offers by sellers. If it looks too good to be true, it probably is. The Internet National Fraud Information Center Watch reported that email scams was up 22% in 2006. While the offer may seem legitimate, spammers and phishers like to use this tactic to side-step reputable sites that provide consumer protection for online purchases. They will send you to a site that looks just like the real thing. You put in your information and you are a victim in about 3 seconds. If you get an email asking you to confirm our Paypal, eBay or bank account information, whatever you do, DON T CLICK ON THE LINK IN THE EMAIL. Go to the site directly by typing in the site name, and see if there is anything related to the email. In 99.9% of the time, it is not. It s a fraud waiting to steal your personal information. You can also tell that the email is fake because it won t have your name in it. 3. Use only reputable e-commerce websites that list a street address and telephone number in case you need to contact them directly. If you look all over the website, and you can t find bona fide contact information, move cautiously. You wouldn t go into a store with no sign or street address, would you? Well, this is no different. If you can t find a number that connects to a human being and an address, keep on looking. 4. Read the website s privacy policy. Some websites may reserve the right to sell/give your information to a third party. Check the document to see if they allow an opportunity to opt-out of receiving special offers from third-party vendors or for permission to share your personal information. If you want your name sold to a ton of people you don t know, then don t take this extra precaution. If they do it, and there isn t a place to opt-out, move on. It s not worth the amount of spam you will receive. 5. In the lower right-hand corner of your browser should be a small lock icon which indicates that the site is secure. Also, do not provide your personal information if the website address doesn t start with https on that checkout page. This isn t on the whole site, but wherever you are putting your credit card must have these two things in place. If you can t find it or you see an unlocked lock icon, don t put your personal information and credit card information in there. While the company may be completely legitimate, it is not secure. On the web, you can t take that chance. Find an alternative way to shop with them if you really want to. 6. Choose only verified sellers. Check to see if the vendor is a verified member of a reputable third party such as the Better Business Bureau, VeriSign, or Guardian eCommerce. These third-party sites help to ensure online consumers will be protected when shopping or conducting e-commerce transactions. Shopping on the Internet can be both convenient and fun, if you take the proper precautions. Simply know the rules of the road and what you should be looking for on websites, and you should have no trouble. If you do, contact the Better Business Bureau. Alojate.com is the premier web hosting company in Mexico, offering a range or services for all business needs. alojate.com alojateextra.com
Threats To Online Trading Companies From Fraud And Hackers
There are many threats from hackers and con artists when a company does business online. Here are some of the main types of fraud: Supplying fake products: Fraud can occur at the very outset of your business when you try to contact a supplier for the product that you have chosen for your online business. The supplier turns out to be untrustworthy and disappears with your money leaving no trace and no hopes of a business. This type of fraud is similar to anything that can happen in the brick and mortar world of business as well. Remember that almost anything that can happen in the real world can happen in the virtual world too, so take the same precautions that you would as for an offline business. Clones: A common problem that more established businesses face is clone businesses that set up with similar sounding names and logos. These businesses will often target your trading companyâ™s clients, and make no mistake; they are after your business specifically. This can create a number of problems for the online trading business, since there is a lack of physical interaction with the customers and it is easier to pull this off. Customer can become confused and either leaves you for the other company unknowingly or be put off by the incompetence of the other company and blame your business. It is a headache for many companies that operate solely online. Credit card fraud: This is the most wide spread type of fraud by hackers and is not limited to the web. But operating online does make it easier for a hacker to find a weakness in your system and exploit it. Most times, hackers will gain access to secured financial information and credit card data and use this to purchase products and transfer money to their own accounts. This can be done so cleverly by an experienced hacker that the trail is impossible to follow. The FBI has been involved in many cases that involve large amounts being stolen in this way and often are unable to locate culprits. It is essential to have plenty of security and use the services of established players in the market such as Pay Pal, etc. Click fraud: Business Week has reported the sharp rise in click fraud as one of the growing problems with doing business online. It implies the software that is now available to fake clicks on an advertisement online, which results in incorrect statistics about the popularity of the site and the number of visitors. Since online business sites pay per click, the advertiser ends up paying much more money than he should. Many unethical affiliates and advertising agents use this type of fraud to make a lot of money. Phishing A common hacker practice online, Phishing or password harvesting has acquired a special name. It is a technique used by hackers via email or Instant Message to subtly and creatively find out an unsuspecting personâ™s financial and personal information. Sensitive data such as passwords, account names and numbers, credit card details, social security numbers are smoothly extracted with the help of a little social engineering practices. Phishing hackers are known to pose as government bodies to defraud even online businesses of access to their databases. William King is the director of UK Wholesalers and UK Wholesale Drop Shipping Suppliers Directory , Drop ship Dropshippers and Dropshipping Supplies and Pakistani Properties and Pakistan Real Estate Homes Plots Offices Property . He has 18 years of experience in the marketing and trading industries and has been helping retailers and startups with their product sourcing, promotion, marketing and supply chain requirements.
10 Easy Steps For Speeding up a Slow PC - Part 1
This is part 1 of a 10 part series on tuning up your PC. When you get a new PC you marvel at how fast it runs and handles all your tasks and applications. However, as time rolls on, your PC may start to gradually become slower and slower. Your PC also may bog down abruptly. Either way, there are a few easy steps the average computer user can take to get that PC back to its peak performance. Stop Viruses and Spyware Ensure that you have antivirus and anti-spyware software installed and up to date. Viruses and spyware can not only slow a computer down, they can be a security risk. Windows XP comes with Virus Protection software, but XP does not provide enough protection and a standalone program is best (note: ensure that the Virus Protection in XP is turned on). There are many choices for virus protection software, both commercial and free applications. One popular and effective anti-virus program is AVG. AVG Anti-Virus Free Edition 7.5.472 can be downloaded, installed and used for free from download.com. No matter which program you choose, ensure that you keep your software and definitions up-to-date. It is best to use the auto-update option in most programs. Whenever you use your computer to access the Internet, you will eventually receive spyware. Spyware can be harmless or malicious. The first thing is to make sure that you XP Firewall is running. Although not the perfect protection, it does provide some. Make sure that your XP is up-to-date and turn on the Auto-Updates option. Once again, there are many choices for spyware protection. For the home user, there are several free programs that will provide very good protection. One is Ad-Aware and can be downloaded at download.com. The other program is Spybot Search and Destroy at: safer-networking.org Ad-Aware and Spybot can be installed on the same computer and they both can run at the same time. NOTE: Do not install more than one third-party anti-virus program (it is okay to have Windows XP Virus Protection on with another anti-virus program running). As with the anti-virus, keep spyware software up-to-date. If after updating and running your anti-virus and spyware programs, you think that you still have some spyware or virus, run your computer in Safe Mode and run the programs again. The software mentioned above, along with keeping your operating system up to date, will provide reasonable protection from viruses and spyware. Author of simplepctalk.com blog James Owens has over 18 years experience with computers. He holds a BS in Computer Studies from University of Maryland UC and is currently employed by a major university in Indiana as an IT specialist.
Trojans - What Are They And How Do They Work?
Trojans - What Are They And How Do They Work? There are many ways computer trojans are spread. The most common technique used for spreading computer trojans is to send files to unsuspecting users over chat systems. Files downloaded from the Internet using Ares P2P software may carry computer trojans, worms, or viruses that can potentially damage your computer or cause other harms. Trojans The named after the Trojan Horse of ancient Greek history, a trojan is a network software application designed to remain hidden on an installed computer. Trojans sometimes, access personal information stored locally on home or business computers, then send these data to a remote party via the Internet. Trojans may serve as a backdoor application, opening network ports to allow other network applications access to that computer. Unlike worms and viruses, trojans do not replicate themselves or seek to infect other systems once installed on a computer. A Trojan is a program that enters your computer undetected, giving the attacker who planted the Trojan unrestricted access to the data stored on your computer. A Trojan allows the hacker to take complete control over the infected computer. Criminals have all the reasons to create viruses, worms, and Trojans, ranging from being able to steal user information to being in control of a zombie network of thousands of infected computers. Worst case scenario: A third party may gain access to your computer and steal your identity or download so much spyware that it renders the computer useless. Security Trojans can transmit credit card information and other confidential data in the background. Trojans are often not caught by virus scanning, because this is focused on viruses, not Trojans. Trojans are the most common way of bringing a virus into a system. They are malicious codes that masquerade as harmless programs. They seldom do damage, as a virus would, because the master wants his control to remain hidden. Trojans can also be spread through email attachments. Once installed on your computer, Trojans have the ability to create, delete, rename, view, or transfer files to and from your computer. Keeping computer software collection up to date with patches is essential to keeping your computer clean and healthy. A combination of firewalls and antivirus software protect networks against trojans. If you really want to take the work out of looking for that right Spyware Protection from a Spybot go to the Internet and get a Free Spybot Download or a Spybot Search and Destroy Download to prevent your vital information from being ripped from your computer.
Technology and Techniques Used in Industrial Espionage
Industrial Espionage. These methodologies are being used on a daily basis by competitors maybe even against you. I knew a Private Investigator who used to break into other firm s voicemail boxes. He was suspected of erasing messages and stealing potential clients. I know you may be thinking that is not right. Maybe so but if a Private Investigator cannot protect him/herself than what use are they to a client. This happens all the time. If you think it is bad here in the United States try overseas. It is pretty much considered fair game and rarely enforced. Even the Concord was remembered for being heavily bugged . What you may find surprising is just how easy it is to do. You could even use off the shelf items, although fully assembled models are readily available and cheap. The best way to learn is to do. A little bit of paranoia and a lot of imagination goes a long way. Just look around your house and see what can be used. Baby monitors can be remotely activated and used to listen in on you. Your cell phone can be hacked through its Bluetooth Feature, so not only can all the data be copied, but also settings could be changed. Your phone could be called and answered without you knowing; thereby listening to your conversation. Your phone can also be used to make a call to someone else without you touching a button ideal for incrimination purposes. There was a technique originally developed to remotely view what you watch on your television, now adapted for computer screens. You can find the plans to build this on the Internet from many sites. This is used in Europe, particularly the Balkans all the time against ATMs. There is still the good old fashion radio scanner to listen to cordless phone calls. Then you can say, Well I use a digital, spread spectrum model using 2.4 or 5.8 frequencies. True that is good protection, but given time the packets of data (digital remember) can be reassembled and decoded. Thankfully that takes time, but you can buy a digital scanner to listen to real time conversations. You can also buy software overseas to work with scanners and laptops for listening to cell phone calls. An interesting side note: Some of these same companies that provide such equipment constantly steal from each other. Outside your house or in the basement of your apartment building are boxes where your land line phone service comes through. You just need a telephone/ linesman butt set or build one from a phone to listen in. So you say, What does this have to do with industrial security? Well usually certain people are targeted when looking for a means into an organization. Plus, they can make a convenient scapegoat and distraction to investigators. Believe it or not it is often I.T. and security personnel who are targeted. Although they may be more aware of security they also have higher privileges than most. Many times they use a popular and recognized remote access program when telecommuting. If you can capture their username and password that may be all that you need. Sometimes there may be more advanced authentication procedures. For instance, the server you will log into or firewall you wish to bypass may require extra authentication. Sometimes it may request a MAC address. This is the unique serial number burned into network cards. This can be copied and you can change yours to that one with a software application. If you have the IP Address, then you can switch your IP Address as well. When you access the victim s computer and place a remote access program of your own, don t use one with obvious hacker names like Back Orifice. Using one that they already have, such as PC Anywhere or Remote Desktop would be ideal. Don t worry about tackling a wireless computer network. Even with security enabled that could just be a speed bump to the dedicated. If probing a victim s computer then I recommend making it appear as spam. If they have a firewall, you can probe it and see what version they are using. Afterwards look around for data on cracking that firewall. Any firewall can be cracked and guess what? You can always break into their home and place whatever it is that needs to be placed. Alarm systems can be defeated rather easily if you know how. Many times these burglar alarm systems were installed by poorly trained or overworked employees who take short cuts to get the job done. Sometimes you will actually see the keypads mounted outside the door to a home or easily viewable through a window. What happens if they cut the phone line or cover the siren box? Locks can also be bypassed by means other than just lock picking. You could install a high security lock, but if all the hardware around it is weak than what good is it? Dogs can be tricky and are usually the toughest obstacle to overcome. Believe it or not, little dogs that are the worst. Big attack dogs can be overcome and sedated or contained; even the well trained ones. But little dogs that run around and make a racket are a menace. Once a dog starts barking, the rest neighborhood s dogs will join in. Even using a high frequency sound device to annoy the dog on a property you wish to enter can alert other dogs. If you do break in, check the bedroom and den first. Bedrooms are where the most important items usually are. You are not there to steal but to place bugs, software etc. and to copy anything of interest, such as a security card, hard drive or key. Bring a digital camera and photograph the scene before moving anything. If there is too much dust then leave it alone. Dust leaves a telltale sign, which is very noticeable when moved. Most locks used to secure desks are easy to pick so that s not a big deal. Bring a hard drive cloning devices and a Linux Boot Disk to copy entire hard drives. This way even if they are password protected and encrypted you can crack them later at your leisure. You can carry MP3 players and iPods to act as a second portable hard drive. That can be particularly handy when in a public environment. Someone thinks you are fiddling with a MP3 player but you are actually downloading somebody s hard drive. Carry all the cables you may need since some machines may not have a particular port like firewire. If they do have a faster transfer rate type port, then by all means use it. You can do something else while it is busy copying data. Remember to look under the keyboard for passwords and pay attention to Post-its. Those little pieces of paper are gold mines. Also, and maybe more importantly, copy data from cell phones and PDAs, if they are available. This can be done with cables to your own PDA or laptop. There are portable dedicated units for this purpose as well. The safe if they have one are usually in the bedroom. Use a metal detector to find it. Place the metal detector wand on its lowest setting, so only a significant metal object will trigger it. Sometimes a safe can contain something you can use as blackmail. There are devices which mount to a safe s dial which automatically attempt countless combinations; some are stand-alone, while others are connected via laptop. You can also try the basic combinations for that make and model. Some safe technicians use the default combination or may try to use some thing you can remember like a child s birthday. If all else fails try 36-24-36, it s very popular with certain bachelors. Placing bugs around the house is usually useless. Most people have a tendency to put the television set or stereo on when they are home. The only exception may be over the head of the bed and wait for pillow talk. You may as well concentrate on telephones lines. They may use a cell phone in the house but once again you may not be able to hear the conversation. Even when using a laser mike which focuses a beam against a window and picks up vibrations in a room may not work, especially if they have plush carpeting or heavy drapes. You can record a conversation on video you can always lip-read if audio is not available. If you have the time and they have a garage, see if it opens automatically. Go over to the garage door and make a copy of the remote for yourself. This works even with the rolling code models. This is just a general outline of what you can do. Make sure to check the soles of your shoes before and after a break in. I suggest wearing a popular brand in case the police make a cast of your footprints. You can also place a pair of hospital booties over your shoes to cover your tracks. It is not a bad idea to wear a jogging suit as opposed to being dressed as a ninja. If you have to run, you would not seem too suspicious. It is wise to take as few chances as possible. If you have more time, the best way to infiltrate an organization is to join it. If not directly then as one of it s support people such as food services or building maintenance. Cleaning crews usually work after hours under little scrutiny. These companies have such a high turnover that they are always hiring and do no background checks. If you do show up for an interview or to do some sort of sales pitch come mentally prepared. Hang around the places where the target organization s employees are and pretend to be a headhunter. Hand someone your demo CD. Of course that CD should have more on it than they expect. Anti-virus protection can be completely by-passed using this method. I will even guess that you have done this countless times without a second thought. If the job interview is for a technology-based position, they will tip their hand by asking you what do you know about such and such. A good skill to pick up will be the ability to read documents facing away from you on a desk. While you are at it develop an excellent memory for detail, especially numbers. Taking a few acting classes could help here, too. What I like about situations like this is that these are the ideal times to place bugs. If you think it may be discovered, then just dispose of something in their wastebasket. Blow your nose while placing a micro-transmitter in it. I doubt any one will inspect the contents of a used tissue. They will end up getting rid of it for you. There is a chance that said item could be discovered by personnel who do paper shredding services. Most companies do not use this service. This could also be a good idea to do some dumpster diving later and see what they throw out. You can carry a micro digital camera and record everything you see. Just pretend to be listening to an iPod or something. Whatever you do, pretend that you belong. If someone tries to stop you, start grooving to some imaginary tunes and head for the elevator. Always have an excuse ready. You can also use something known as video ham radio. This transmits video images via radio signals; more commonly used by rescue crews. This is different from the more conventional covert video systems used out there. Video systems tend to use a lot of battery power so bring spares. Ideally it would be nice to place cameras in the copy machine but usually a copy machine technician best accomplishes this. Some operators have gone as far as replace whole machines. The FAX machine is the best for tapping. No one seems to ever suspect that is tapped but will scrutinize everything else. You may think that that is an oversized DSL filter on it but maybe it is not. If there is a damaged door with a lock still attached try to remove it. A good locksmith can build master keys by analyzing the pin tumblers. With some practice you can do this as well. Cut a key for both before and after removing spacers from pins if they have them. This is what is called a master keying system. What you would want to make is the grandmaster key. This will allow you total access. If you do start opening doors, be aware that there may be door contacts. These are magnetic switches used in burglar alarm and access control systems. You can use basic electronic tools to locate the magnet and use your own magnet to fool the door. There are different devices out there which can record and analyze security/ prox/access control cards Weigand output. The Weigand output is when a card reader emits a radio wave, which energizes the card. The card then sends out a unique identifier. This is what you want to catch. With another device you can replicate this identifier, mostly using a PDA. Laptops are better but conspicuous compared to a PDA. Smart cards and the magnetic strips from more conventional credit card types can be duplicated on the spot. Just be aware that with most modern access control software the face will show up on the computer screen that accompanies the card being used so enter with a group. If there is a numeric keypad you can use ultraviolet light to check for smudges and you can guess from there. If you have access to a thermal imagery device, you can see the heat signatures. These are so cheap now that they are popping up in the most unlikely places. Hunters are using them for the slight advantage it gives them. Usually the stronger trace is the most recent. That will be the last one pressed. From there you can guess accordingly. Many systems have a three strikes and you are out policy, so proceed with caution. Otherwise, if you are in a mantrap the doors will stay locked and you are trapped and security will be alerted. Biometrics is growing in popularity but as you probably guessed by now, can be defeated. It is rare for somebody to wipe their prints off. A lot of these devices are fingerprint based so get copies of fingerprints. One way is to get them from the biometric reader itself. Some crime scene photographers have special software or film that accentuates photos of fingerprints. Some scanners that check for retinas and such can occasionally be tricked by trying out a bunch of well-made fake eyeballs and a flashlight. You can remotely access the security and camera system either by the Internet or through a phone line (pre-paid cell phone included). You can give yourself privileges on a blank access card and erase video files of your activities. Sometimes the video files may be also network storage based. Once again you should access anything with any trace of your existence. You can also defeat the cameras individually. Strong light devices can blur an image or anything that emits strong electrical signals can cause static or snow. If the camera is too far you can use a HERF (hi-energy radio frequency) gun. This can send a focused burst which can either be disruptive or destructive. Think of using your cell phone next to a clock radio for an analogy. These are not as hard to acquire as you might think. If you are this close you should monitor the security guards radio frequency. You can use a radio that can communicate with theirs try not to talk to them for any reason. Many sites are now recording radio transmissions for insurance reasons. Voice print recognition has come a long way. Be aware of their call signs and any related lingo. If you have a crazy notion of knocking out a guard just be aware that their radios have a tilt feature so if a guard goes down there is an alert. If you are thinking about doing a late night sneak and peek consider the perimeter defenses. The use of fiber optics in fencing is common and almost invisible to the intruder. Break a branch onto it so that part of the fencing system is deactivated or simply overlooked. In and around can also be seismic intrusion detection, which basically is sensitive to footsteps. This can be tricked with a device called a thumper. It is basically a box that stamps its foot at whatever pace. Certain cameras may be programmed to react to the disturbance. If you are looking for infrared sources use a passive night vision scope/goggle. You are looking for IR emissions; you are trying not to create your own which an active model could do. There are little badges you can wear that can alert you if you are under IR observation. Do not wear divers watches since the tritium will light you up like a ghost to any nocturnal observer with night vision goggles. If the facility is using thermal imagery, than you will need to really do your homework; chances are they are serious about protecting whatever it is they are tasked with. One way to defeat that is by wearing different types of neoprene suits. Everything must be covered not a very comfortable way to spend an evening. Otherwise you will have to wait for a storm to hit before you make a move. Now you may not approve of the disclosure of such information. The truth is such knowledge is freely available to anyone. Just buy a video game to get the latest inventions and their use. Remember this: the most successful operations are the kind that go undetected. Maybe a little bit of paranoia is a good thing. The author of this article is a freelance security consultant contracted by competitive intelligence firms, such as BHE Security, and private investigators. There seems to be a decided lack of knowledge on the techniques and technology of Industrial Espionage .
Firewalls: What They Are And Why You MUST Have One!
A firewall is a system or gateway that prevents unauthorized access to your computer or private network. It is usually the first line of defense in protecting your private information or data. A good firewall will help protect you from malicious attacks of spyware, adware, malware, worms, trojans, and hackers. Firewalls are security mechanisms that control who can access and send data thru your network or computer. They can be applied to both hardware and software on your computer; many systems use a combination of each for greater protection. All data or messages entering or leaving your computer has to pass thru the firewall, which checks all messages and blocks those that don t meet your specified security criteria or rules. To put it in simple terms: think of a firewall as a security guard or a security scanner for your computer or network. Anything going in or out must be checked thru this system and must obey your rules! Of course, this is just a simple explanation, firewalls can be very complex; consisting of a whole combination of techniques that can be used in concert depending on the level of security you wish to achieve. These firewall techniques may include: Application gateway -- places security mechanisms on specific applications (FTP, Telnet, etc.) Packet filters -- examines each packet using your computer and accepts or rejects according to your rules Circuit-level gateway -- security measures for such connections as TCP (Transmission Control Protocol) or UDP (User Datagram Protocol) Proxy server -- all messages entering or leaving your network must go thru this proxy server, effective for hiding your true network or computer address Also, for greater security, many networks use encrypted data. If you are operating a computer or a server, putting up firewalls will provide protection for your data and information that s passed along your network. If you regularly surf the Internet, placing a firewall on your own personal computer is a must. There is no reason not to have a firewall in place, you can download a free firewall from zonealarm.com for your own personal use. Keep in mind, no system is foolproof; any computer or network hooked up to the Internet can be hacked! Therefore, most people in the know, always keep a back-up of their important data/information on a secure off-line source: floppy disks, CDs, or on a computer that s not connected to the Internet. Do daily or weekly back-ups to make sure your data and programs are safe. Still, a good firewall will go a long way in protecting yourself from any unauthorized access to your computer. With the occurrences of spyware, adware, and other more invasive scumware increasing daily; putting up a firewall and protecting yourself should be your first line of defense against such unwanted and rude visitors. Nuke them at the gate and save yourself from some major headaches. Put that firewall up right now! To learn more about Spyware and Adware Click Here: Spyware Remover Guide Copyright © 2005 Titus Hoskins of Internet Marketing Tools . This article may be freely distributed if this resource box stays attached.
Anti-Spyware Software - Is There A Way You Can Do Without It?
Anti-Spyware Software - Is There A Way You Can Do Without It? You may be one of those people who keep on wondering what all the fuss about getting anti-spyware software is all about. Whatâ™s more you may even have managed to survive for quite a long time without seeing any spyware trouble. Now that is the most dangerous position to be in because it makes you very vulnerable because at any moment you can fall victim of credit card fraud or identify theft and as those who have been through it will tell you, it certainly is not fun at all. But what exactly is spyware software and what is the truth about the sort of damage that it is capable of causing? How can you get anti-spyware and how can you be sure that it is genuine stuff? Spyware is computer software that collects personal information and data about every web site you visit as well as every secret password you use to access every sensitive and non-sensitive account that you operate from the computer that has been secretly infested with the spyware software. This information is then automatically sent to the remote location where the spyware originated. You can imagine what kind of damage can be caused when a nasty guy gets hold of the sort of information that I have just described. Huge amounts of funds can be transferred from your accounts and in fact you identity can be stolen meaning that somebody takes over access to all your online accounts. Spyware is for real and you should take the threat very seriously indeed before it is too late. A good idea is to use an established website that deals in anti-spyware software. Go now to an established site that deals with anti-spyware software .
Implementing Vulnerability Remediation Strategies Within the Web Application Development Lifecycle
Once you ve completed a security assessment as a part of your web application development, it s time to go down the path of remediating all of the security problems you uncovered. At this point, your developers, quality assurance testers, auditors, and your security managers should all be collaborating closely to incorporate security into the current processes of your software development lifecycle in order to eliminate application vulnerabilities. And with your Web application security assessment report in hand, you probably now have a long list of security issues that need to be addressed: low, medium, and high application vulnerabilities; configuration gaffes; and cases in which business-logic errors create security risk. For a detailed overview on how to conduct a Web application security assessment, take a look at the first article in this series, Web Application Vulnerability Assessment: Your First Step to a Highly Secure Web Site . First Up: Categorize and Prioritize Your Application Vulnerabilities The first stage of the remediation process within web application development is categorizing and prioritizing everything that needs to be fixed within your application, or Web site. From a high level, there are two classes of application vulnerabilities: development errors and configuration errors. As the name says, web application development vulnerabilities are those that arose through the conceptualization and coding of the application. These are issues residing within the actual code, or workflow of the application, that developers will have to address. Often, but not always, these types of errors can take more thought, time, and resources to remedy. Configuration errors are those that require system settings to be changed, services to be shut off, and so forth. Depending on how your organization is structured, these application vulnerabilities may or may not be handled by your developers. Oftentimes they can be handled by application or infrastructure managers. In any event, configuration errors can, in many cases, be set straight swiftly. At this point in the web application development and remediation process, it s time to prioritize all of the technical and business-logic vulnerabilities uncovered in the assessment. In this straightforward process, you first list your most critical application vulnerabilities with the highest potential of negative impact on the most important systems to your organization, and then list other application vulnerabilities in descending order based on risk and business impact. Develop an Attainable Remediation Roadmap Once application vulnerabilities have been categorized and prioritized, the next step in web application development is to estimate how long it will take to implement the fixes. If you re not familiar with web application development and revision cycles, it s a good idea to bring in your developers for this discussion. Don t get too granular here. The idea is to get an idea of how long the process will take, and get the remediation work underway based on the most time-consuming and critical application vulnerabilities first. The time, or difficulty estimates, can be as simple as easy, medium, and hard. And remediation will begin not only with the application vulnerabilities that pose the greatest risk, but those that also will take the longest to time correct. For instance, get started on fixing complex application vulnerabilities that could take considerable time to fix first, and wait to work on the half-dozen medium defects that can be rectified in an afternoon. By following this process during web application development, you won t fall into the trap of having to extend development time, or delay an application rollout because it s taken longer than expected to fix all of the security-related flaws. This process also provides for excellent follow-up for auditors and developers during web application development: you now have an attainable road map to track. And this progression will reduce security holes while making sure development flows smoothly. It s worth pointing out that that any business-logic problems identified during the assessment need to be carefully considered during the prioritization stage of web application development. Many times, because you re dealing with logic - the way the application actually flows - you want to carefully consider how these application vulnerabilities are to be resolved. What may seem like a simple fix can turn out to be quite complicated. So you ll want to work closely with your developers, security teams, and consultants to develop the best business-logic error correction routine possible, and an accurate estimate of how long it will take to remedy. In addition, prioritizing and categorizing application vulnerabilities for remediation is an area within web application development in which consultants can play a pivotal role in helping lead your organization down a successful path. Some businesses will find it more cost effective to have a security consultant provide a few hours of advice on how to remedy application vulnerabilities; this advice often shaves hundreds of hours from the remediation process during web application development. One of the pitfalls you want to avoid when using consultants during web application development, however, is failure to establish proper expectations. While many consultants will provide a list of application vulnerabilities that need to be fixed, they often neglect to provide the information that organizations need on how to remedy the problem. It s important to establish the expectation with your experts, whether in-house or outsourced, to provide details on how to fix security defects. The challenge, however, without the proper detail, education, and guidance, is that the developers who created the vulnerable code during the web application development cycle may not know how to fix the problem. That s why having that application security consultant available to the developers, or one of your security team members, is critical to make sure they re going down the right path. In this way, your web application development timelines are met and security problems are fixed. Testing and Validation: Independently Make Sure Application Vulnerabilities Have Been Fixed When the next phase of the web application development lifecycle is reached, and previously identified application vulnerabilities have (hopefully) been mended by the developers, it s time to verify the posture of the application with a reassessment, or regression testing. For this assessment, it s crucial that the developers aren t the only ones charged with assessing their own code. They already should have completed their verification. This point is worth raising, because many times companies make the mistake of allowing developers to test their own applications during the reassessment stage of the web application development lifecycle. And upon verification of progress, it is often found that the developers not only failed to fix flaws pegged for remediation, but they also have introduced additional application vulnerabilities and numerous other mistakes that needed to be fixed. That s why it s vital that an independent entity, whether an in-house team or an outsourced consultant, review the code to ensure everything has been done right. Other Areas of Application Risk Mitigation While you have full control over accessing your custom applications during web application development, not all application vulnerabilities can be fixed quickly enough to meet immovable deployment deadlines. And discovering a vulnerability that could take weeks to rectify in an application already in production is nerve-wracking. In situations like these, you won t always have control over reducing your Web application security risks. This is especially true for applications you purchase; there will be application vulnerabilities that go unpatched by the vendor for extended periods of time. Rather than operate at high levels of risk, we recommend that you consider other ways to mitigate your risks. These can include segregating applications from other areas of your network, limiting access as much as possible to the affected application, or changing the configuration of the application, if possible. The idea is to look at the application and your system architecture for other ways to reduce risk while you wait for the fix. You might even consider installing a web application firewall (a specially crafted firewall designed to secure web applications and enforce their security policies) that can provide you a reasonable interim solution. While you can t rely on such firewalls to reduce all of your risks indefinitely, they can provide an adequate shield to buy you time while the web application development team creates a fix. As you have seen, remedying web application vulnerabilities during the web application development lifecycle requires collaboration among your developers, QA testers, security managers, and application teams. The associated processes can seem laborious, but the fact is that by implementing these processes, you ll cost-effectively reduce your risk of application-level attacks. Web application development is complex, and this approach is less expensive than reengineering applications and associated systems after they re deployed into production. That s why the best approach to web application security is to build security awareness among developers and quality assurance testers, and to instill best practices throughout your Web application development life cycle - from its architecture throughout its life in production. Reaching this level of maturity will be the focus of the next installment, Effective Controls For Attaining Continuous Application Security . The third and final article will provide you with the framework you need to build a development culture that develops and deploys highly secure and available applications - all of the time. About Caleb Sima Caleb Sima is the co-founder of SPI Dynamics a web application security products company. He currently serves as the CTO and director of SPI Labs, SPI Dynamics RandD security team. Prior to co-founding SPI Dynamics, Caleb was a member of the elite X-Force RandD team at Internet Security Systems, and worked as a security engineer for S1 Corporation. Caleb is a regular speaker and press resource on web application security testing methods and is a co-author of the book titled, Hacking Exposed Web Applications: Web Security Secrets and Solutions, Second Edition About Vincent Liu Vincent Liu, CISSP, CCNA, is the managing director at Stach and Liu ( stachliu.com) a professional services firm providing advanced IT security solutions. Before founding Stach and Liu, Vincent led the Attack and Penetration and Reverse Engineering teams for the Global Security unit at Honeywell International.
Nigerian Scams - New Versions Of The Notorious Nigerian Scam Are Doing The Rounds
Have you been contacted by someone from Nigeria asking for your help in transferring money out of the country? If so, then you are one of thousands of people all over the world, including doctors, lawyers engineers and professors, who have been targeted by what is sometimes called the Nigerian letter scam or Nigerian advance fee fraud . Although Nigerian is the name given to it, this scam is international. The letter or email you get may also pretend to come from another country. It is estimated that Australians lose $2.5 million every month to the Nigerian scam! How the scam works The scam varies, but usually you will receive a letter, or more often, a fax or email offering you a business proposal or transaction. The Nigerian scam typically involve a letter or email from a person overseas claiming to need help transferring a large sum of money. They typically offer to provide a significant portion of that money in exchange for bank account details Once you are hooked, you will be asked to pay all sorts of advance fees (eg. customs, taxes, bribes, legal fees) to facilitate the transfer. Of course, there is no wealth to be transferred and they just use your bank account details to swipe your hard-earned money from your account. New versions of the notorious Nigerian scam circulating via email The Nigerian scam letter is popping up everywhere using slightly different names and different con stories. Regardless of what name is used, position they say they have, or what story is spun, these offers of quick wealth are fraudulent and will only result in lost time and money, and the awful feeling of knowing you have been fooled. Below we have listed the some of the recent versions of the Nigerian scam in circulation: Request to use a bank account to deposit a large sum of money. This scam requests the victim to allow them to use their bank account so a large sum of money may be deposited into. Initial contact with the victim is made by a mass produced email. The money offered may be from a secret bank account, unexpected inheritance, overpaid Government contract or a forgotten sum of money left in a Nigerian bank. In each instance, before the money is placed into the victims bank account, a series of fees and charges are required to be paid before the money can be released, eg. taxes, legal fees etc. Despite the victim making numerous payments to individuals in different countries, there are always delays which prevent the money being sent and require a further payment to be made. A key ingredient of this scam is the victim is required to keep the money transfer secret. Business Opportunity. A business may receive a request from a Nigerian person posing as a public official offering the opportunity to become involved in a large commercial operation being undertaken in Nigeria. The most common example involves projects in the Nigerian oil industry although other examples have been identified in the telecommunications industry. The offer will involve very large financial returns and will require the victim to finance a portion of the Nigerian contract. All payments will be required to be forwarded via money transfer agencies such as Western Union in amounts between $5,000.00 and $10,000.00. Examples of the requests for money include: legal fees, taxes, money transfer fees etc. In each instance, the money will be required to be sent to numerous individuals in different countries such as Benin, Togo, United Arab Emirates and the United Kingdom. Online relationship. This scam targets victims, who are met through internet dating sites, chat rooms or Instant Messenger services. The fraudster may present one of a variety of scenarios including: * Australian citizen in Nigerian hospital - A common scenario begins with the victim chatting online with an Australian citizen living in Nigeria. Communication suddenly stops until contact is made by a Nigerian doctor saying their friend has been in a car crash and needs money to pay for urgent surgery. The victim wishing to help their friend commences sending money to Nigeria via a money transfer facility such as Western Union and as each sum of money is forwarded, a further request for more funds is made. * Internet Romance - With the internet dating scam, the fraudster represents they wish to travel to Australia however needs help to pay for airfares, visa charges or a passport. Once these costs have been paid, the fraudster requests more money to pay for their local taxes, family hospital bills and other costs. In each instance, the fraudster represents they have missed their flight to Australia and requests more money to be sent to Nigeria to pay for further airfares. The fraudster continues this scam until the victim runs out of money or refuses to send any more to Nigeria. Fraudulent cheque/ credit card scam. This scam targets small business owners and persons who have been caught in the internet dating scam. In this example, the fraudster requests goods be sent to him in Nigeria and sends a bank cheque to pay for the goods. The cheque is usually from a foreign bank and is for an amount in excess of the value of the goods and freight forwarding charges. The victim also pays for all the freight forwarding charges and sends the balance of the funds to the fraudster using a money transfer system such as Western Union. When the cheque is deposited into the victims bank account in Australia, depending on the quality of the forgery, it may initially clear. This provides the victim with the assurance the cheque is of good value as represented and they purchase the goods and sends them to Nigeria. Several weeks later, the cheque is identified as being fraudulent and the victim ends up bearing the cost of the whole transaction. The credit card scam involves the fraudsters contacting Australian businesses and requesting the purchase of goods or services. The orders often are significantly higher than that the business would usually receive and appears to be a financial windfall for the business owner. Accommodation providers are regularly asked to provide quotes for Nigerian representatives seeking to attend Queensland for businesses reasons and wishing to book accommodation and conference facilities. Once the quote is provided, the fraudster provides a series of credit cards for the payment to be made from. If a card is not active, then alternative credit card numbers are supplied. Once the payment has been made, the fraudster cancels the accommodation and conference and requests the funds be refunded via a money transfer service such as Western Union. Once the business has refunded the money, they may be notified by the credit card company the transactions were fraudulent and the business must refund the money. Charity Scam. The charity scam differs to the other Nigerian scam as victims are not seeking anything in return. The fraudsters seek victims amongst Church related web sites and chat rooms seeking persons to make regular donations to themselves to run a specific charity. The fraudster represents themselves to be a Reverend or Pastor who operates an orphanage or Church and is desperately seeking funds. There are no means provided to identify whether the charity actually exists or whether the person seeking the funds is who they represent themselves to be. What can you do? Never reply. Throw the offer in the bin or delete the email. Do not forward them on to your friends as they suggest, as you will only be creating trouble for them too. Never give your bank account number or other personal details to unauthorised people. If you have got caught yourself, or if you come across any evidence of Australian involvement in this scam, contact your state or territory police. Do not become the latest victim of these scams They are not only illegal, but they may also be life-threatening as there have been unsubstantiated reports in the past that people with healthy bank accounts were flown overseas first class to meet with the scammers, but on arrival were promptly kidnapped and held for ransom. When the scam is based overseas, it is outside our jurisdiction so the Office of Fair Trading cannot investigate or assist if you find you have lost your money. Consumers are also warned to beware of other scams, including fake requests for donations, bogus bank emails, phoney lotteries, chain letters, pyramid schemes, envelope stuffing schemes and invoice fraud. Remember if it sounds too good to be true, it s probably a lie. The author recommends AVG Internet Security as a solid and reliable choice for protection against today s evolving Internet security threats. Visit avg-antivirus.com.au for more information or to download your FREE 30 day AVG trial. AVG editions are available for you to trial as fully functional products, with no obligation. During the evaluation period, you will be able to test the functions, features and capabilities of AVG software, as well as having access to technical support. David Furlong is a qualified and experienced IT specialist and Technical Trainer. His list of credentials includes a Masters in Networking and Systems Administration, MCSE, and MCSA. He is the founder of the computer consultancy firm, Axiom Networking Solutions .
Wireless Security 101
In todays modern world wireless networks have now become commonplace. With wireless networking you can connect multiple computers together without the need for cables. Wireless networking also allows you to share resources such as printers, Internet and files. To set up your Wireless Local Area Network or (WLAN) for short you will need a Wireless Router. A Router is actually 3 network device in 1. It acts as a Wireless access point, which allows several wireless devices to connect to each other. A switch which essentially directs information over the LAN, and allows computers or printers to communicate with each other as well as share their resources. Finally most routers nowadays provide a firewall, which helps protect your network from outside intrusions by filtering incoming data. Protection and security of your wireless network is vital. Fortunately, it can be achieved by the average home user with a little bit of know how. Here are some simple steps that you can do to help protect your wireless home network form hackers and keep your personal data secure. As you follow the directions provided with your router you will come across a section, which provides you with the routers user name and password. It is usually marked as admin for the user name and password for, yes you guessed it password. Now this information is publicly known and leaving this information, as its default is the 1st mistake many home users make. Use something original for the user name and password and write it down on a separate piece of paper for your records. Next, Change the Default SSID. The SSID is a name, which basically identifies your network. Every computer in your network must have the same SSID name. Assign your SSID a name that is familiar to you and write it down for future reference. Now we come to your WLAN security options. This is where people usually make another mistake. I have seen countless WLAN that were using WEP, (wireless equivalent privacy) encryption which is a weak form of encryption. The FBI has recently reported that WEP can be hacked within 3minutes. WPA or the newer WPA 2 provide much stronger security. All wireless network equipments support some kind of encryption. Encryption allows your data to be encrypted before sending it out to the Internet. The computer, which receives the information, must know how to unscramble the data to read it. You must use the strongest encryption technology that your router and or Network card allows.If you are able to see the options for WPA 2 then that in most cases it is your best bet, however if your computer needs to support older legacy devices then WPA or even WEP might be your only option. I hope this guide has given you a basic understanding of the security that is needed to keep your WLAN safe from outside intrusions. Have a Tech question you want answers to? Computers at a Glance will answer your questions within 24 hours! Do you have a subject you want to see coverd in the next article? Click here and submit your topic today!
Malware - Preventing Hidden Attacks
As more computer owners learn about spyware and its damaging effects on our PC s, there is still a hidden threat that hasn t made front-page news yet. Sure, some of us have heard of the growing malware problem, but in order to prevent such an occurrence from affecting us, it s vital to know the basics of this nasty, new PC predator. ⢠Malware is like a computer virus. They re hard-to-find and at times, difficult to remove. ⢠It drastically slows down our PC speed-As a result of ad-buildup and tracking devices, your computer may run noticeably slower. ⢠File sharing is a huge source of harmful malware, especially in instances like illegal music downloading. ⢠Unintentionally visiting harmful websites masking as legitimate pages can increase your chances of picking up malware. ⢠Your Internet search habits can be recorded and distributed to unknown sources through the use of malware. ⢠If you surf to a site and notice you re consistently being redirected, this is a symptom of malicious malware. ⢠Malware often tries to steal your personal information. For instance, Voice Over IP Provider Skype just reported a malware stunt whereby users were asked for log-on information on a phony sign-in screen. In many ways, malware is like the big brother of spyware. It often bundles many unseen threats together, increasing your chances of being attacked. Installing an anti-spyware software program such as STOPzilla is one measure we can take to diminish the risk posed on our PC s. 6StarReviews.com cites that STOPzilla not only protects you from spyware, it blocks phishing attempts (those browser hijacks commonly associated with malware.) Spyware Doctor provides comprehensive threat detection through their Spider Scanning Technology, a great feature. Many spyware removal programs offer great deals for you to save: such as 15% off on Spyware Doctor products as exclusively reported by 6StarReviews.com. Though research on malware and its effects are in the early stages, protecting your PC now is an action all computer owners should make. Kelly Liyakasa is staff writer for 6StarReviews.com, a site dedicated to giving YOU, the consumer, the best product and web service reviews around. If you like saving time and money by having someone else review leading sites and products, then Visit our site at 6StarReviews.com
Protecting Your Data in an Insecure World
We have all heard those horror stories about large companies, from banks and insurance companies to credit card processing firms, losing track of tons of customer data, putting themselves and their customers at risk. While these incidents certainly capture the headlines, the truth is that data loss is a risk for every computer user, not only for those large companies. Anyone who uses a computer is at risk for data loss, and that loss of personal data can be just as devastating to the individual as to the corporation. It is important therefore for every person who uses a computer to take the steps necessary to protect their important data from loss or theft. One of the first lines of data defense is a strong virus protection program. There are many virus protection programs on the market, and most do an excellent job at protecting computers from both established and emerging threats to your personal data. In addition, a good anti-spyware program, combined with virus protection, is a great way to make sure your personal data stays that way. Learning to avoid phishing scams and similar email swindles is another important part of personal data protection. There are many unscrupulous individuals and organizations out there seeking to steal personal data by pretending to be banks, online auction houses and other legitimate businesses. If you receive an email asking for personal data, even if it seems legitimate, it is a good idea to verify its authenticity with the company claiming to have sent it, and never to click on the link within the email until you are sure your data is safe. With so much personal data stored on computers around the world these days, the challenges to the safety of that data are only expected to grow. It is important therefore to pay attention to data protection, and to take data protection seriously. Protecting your personal data from theft starts with your own common sense and vigilance. Protecting personal data means many things to many different people. To the business executive, protecting the important personal information of employees, customers and others is a vital business interest, and companies have been sued for millions of dollars for losing track of that vital personal information. On the consumer level, loss and theft of personal data is one of the fastest growing crimes in the world, and it is important for everyone, from corporate CEO to individual consumer, to protect themselves in an insecure world. For more information on data go to datado.com
Strengthening the Bench - Building Platforms for Information Leakage Prevention
CIOs, CSOs, and anyone else with a C in his or her title is acutely aware of the daily dose of data leaks, virus infections, and laptop thefts that land on the front page or are broadcast over the airwaves. The business community s response has been an urgent demand for a remedy for data threats. Industry research firm, Datamonitor, recently estimated that enterprises world-wide will have invested $15.8 billion into securing their networks and systems by the end of this year. In response to this demand, information security vendors have been more than happy to glut the market with products, competing to develop the all-inclusive, end-to-end, magic formula for securing all data on all fronts from all threats. But the unfortunate reality is that there is no silver bullet. As daily headlines indicate, companies continue to be victimized by data thieves, hackers, and disgruntled employees, yet the miracle cure-all has not materialized. Instead, IT departments are deploying multi-faceted products that include firewalls, internet security, email monitoring, content control, and disk encryption but continue to ignore the vulnerabilities presented by employee misuse of data. A better strategy for securing corporate information is the development of wider security platforms or âœbenchesâ that are based on solid information leakage prevention (ILP) capabilities such as those offered by endpoint ILP solution provider, Safend. Safendâ™s products, Safend Protector and Safend Auditor were developed to integrate well with most network, internet, and systems security products and allow companies to customize their security strategy by monitoring and controlling who has access to sensitive data and how it is transported. Of course, technology cannot take the place of strict, clearly communicated, corporate policies. However, once these policies are established and mandated, information leakage prevention tools can sharply decrease the likelihood of a data leak, data theft, or loss of sensitive information. Deploying a wide security bench that monitors and enforces corporate data access policies at the endpoint, then seating integrated, risk-specific products on the bench, enables an organization to craft an environment-specific approach based on their individual needs rather than using only a portion of an expensive, and oftentimes complex, end-to-end solution. The bench approach has the added benefit of scaling well to the growth of an organization. Any IT manager will agree that todayâ™s information security threats are a drop in the bucket when compared to the ones about to emerge. Similarly, the security risks and compliance mandates encountered by a small to medium business may drastically change as the company grows, their capital accumulates and their information assets increase. Vendors that make the choice to ensure the interoperability of their solutions will reap the benefits of a changing market landscape. According to the industry research firm Enterprise Strategy Group, of the organizations they recently surveyed that had deployed a data loss prevention solution, approximately one-fourth had implemented an integrated network and host based solution. ESG predicts this number will grow as additional threats to corporate data emerge. Building a defense system from the inside out, starting at the place where users interact with data-the corporate endpoint-appears to be the most efficient and cost-effective way to provide a solid foundation for expanding a protective net as enterprise needs change and technology evolves. Susan Callahan is the Vice President, Marketing and Business Development of Safend, a leading provider of endpoint information leakage prevention (ILP) solutions based in Tel Aviv, Israel, with US headquarters in Philadelphia. Safendâ™s security solutions protect against corporate data loss via physical, wireless, and removable media ports while ensuring compliance with regulatory data security and privacy standards. Safend s products, available through resellers worldwide, are deployed by multinational enterprises, government agencies and small to mid-size companies across the globe. For more information, visit safend.com
Computer Security - A Matter of Concern and Tips to Avoid Trouble
With so much of todayâ™s business being transacted online, computer security is a major issue affecting businesses and consumers. For online businesses, there can be problems in the form of stolen credit card information, mailing or personal information. If you are selling information, your content may be hacked into and copied. This affects the business and customer adversely, since the customer is likely to blame the online business. This erodes the image of your business and discourages other customers from trusting you with their information. No one likes their email inbox to be bombarded with viruses and spam. If they feel that your site has something to do with it, your business and reputation will suffer long term damage. To avoid problems with your businessâ™s computer security, follow the guidelines listed below. Never allow external storage devices â" Do not permit anyone to take data out of your system in any form of external storage device, such as floppy disks, CDs etc. for any reason. Obviously, this compromises your safety and that of your customers. Limit employee access â" Restrict employee access to files, folders and areas within the system that they require in their day to day work. Do not allow anyone to gain access to any information that they do not require. Make sure that you install systems that lock out employees who do not have authorization. Third party outsourcing â" Outsource your payment system to a third party such as PayPal, so that your liability is reduced in case of any computer security problems. This third party will have the necessary technological support to ensure that the customer and your business are safe. But to be sure of this, you will need to do a thorough check on your selected provider or choose a reputable one. Check on your technology vendor â" It is important to ensure that your technology vendor has taken steps to protect the server and the software in your system appropriately with firewalls etc. If it is possible and affordable, look into getting a third party security audit of the system from both ends â" the server provider and the software at your end since leaks may be from either end. Pages that contain sensitive data should be appropriately protected with software security locks. Newsletter email lists â" If you have a newsletter, make sure that your online business keeps its mailing list secure and that no recipient can tamper with it or gain access to the list. This is essential in protecting the privacy of your customer information. Affiliations with reputable associations â" Form affiliations with trusted business and computer security organizations, such as BBBOnline, to ensure that customers feel safe coming to your site. The additional benefit of this is the identification of any flaws in the security through a check up. Educate customers â" It is imperative to educate your customers about computer safety. Ensure that they know your online business will not send them emails soliciting information and that if they receive any such mail, they should report it to you at once. Content â" Protect your content by ensuring that it is safe behind firewalls and other applications that prohibit unauthorized entry. As for public content, simply provide your visitors with updated and informative content regularly since good quality cannot be copied. William King is the director of UK Wholesalers Drop Shippers and Trade Suppliers , Wholesalers Suppliers and Drop Shipping Trade Directory , and Dropshippers and Wholesale Drop Shipping Products Directory . He has 18 years of experience in the marketing and trading industries and has been helping retailers and startups with their product sourcing, promotion, marketing and supply chain requirements.
Why Information Security Software Isn t Enough to Protect You Online
Why Information Security Software Isn t Enough to Protect You Online People who constantly transact business over the internet should be in fear of losing their financial details and thus should focus on information security at all times. One of the worst things that can happen to you over the Internet is for you to lose your money and credit rating overnight. How it can happen is anyone s guess but do you want to lose the entire money and credit reputation you spent years building overnight and to some crooks? Millions of people suffer from the scourge of Internet crime in the form of identity theft and other financially motivated crimes annually. The bad news is that everyone on the Internet is a prime target for these criminals and if you re a businessperson you stand to suffer from greater consequences due to your unique position. You may find a lot of material on the Internet similar to this article offering you advice on how to cope and prevent yourself by ensuring information security at all times. Despite these efforts identity and information theft is still constantly on the increase. Information security isn t all about buying the latest software packages to secure your computer system, although this is of course necessary. When someone takes the time to look through your trash and can get revealing information from the contents, that s poor information security. Use a shredder or incinerator. Make sure that you never reveal information to anybody demanding fro it except if it s absolutely essential. In terms of software however you also have to make sure that you have prime protection. If you accidentally install malware such as a keylogger on your system, anything that you do may be recorded and forwarded to these criminals. They can virtually steal anything that you type by using your keyboard. These keyloggers are responsible for most of the theft that occurs online this day. Ensure that your antivirus programs are the best in the business and that they are constantly up to date, the mere tens of dollars extra that you shell out for better protection could save you a whole lot more in costs later on. Despite their best efforts software developers still have problems combating and handling malware. However in recent times software developers have started using more innovative and ingenious methods to track down and eliminate potentially harmful computer malware. However such products have not hit the mainstream but when they will hackers and Internet criminals will find it more of a challenge to invade computer systems. You can visit information-security-guide.com for further information about information security. In order to protect yourself however it is essential that you carry out all the necessary and current measures in order to secure yourself and your financial and private information. Never assume or take anything for granted as this may be the beginning of your problems. Prevention of a potential problem is always better than look for the culprits when they succeed in defrauding you. Never assume that you have nothing of interest to criminals, some of these people will use something small to cause great danger. The mere revelation of your social security number may be room enough for them to carry out criminal acts posing as you. Kelly Hunter operates information-security-guide.com and writes about Information Security
Cisco PIX/ASA Security Appliance - How to Configure Banners
Banners can be configured to display when a user first connects (MOTD), when a user logs in (login), or when a user accesses privileged mode (exec). Banners are used for legal warnings such as when a user is cautioned not to access a restricted system or that their access of a system is subject to monitoring and logging. Banners are also used on locked systems placed at customer locations by service providers to provide contact information for device access or technical support. The Cisco security appliance supports the use of login banners in console sessions and Telnet sessions, but not in SSH sessions. Exec and MOTD banners are supported in console, Telnet, and SSH sessions. Banners can be up to 510 characters in length. You can create multiple line banners either by creating multiple banner statements or by using the keystroke sequence of n which inserts a carriage return. Here s how banners are displayed: MOTD Banners--When usernames are not configured, MOTD displays at login in a serial console session and before login in Telnet sessions. When usernames are configured, MOTD displays before login in a Telnet session and after login in a serial console session. Login Banners--The login banner displays before login in Telnet and serial console sessions. Exec Banners--The exec banner displays upon login in all sessions. How to Configure a Banner Note: The following procedures were tested on an ASA 5505 Security Appliance running software version 7.22. Other hardware or software platforms may require modification of these procedures in order to function properly. To configure a banner, use the following configuration mode commands: asa(config)#banner motd This is a restricted system. asa(config)#banner motd Do not attempt unauthorized access. Notice the use of two banner motd statements to create a multi-line banner. As mentioned previously, you can also use the n key sequence to insert a carriage return. You can view the banners you created with the following privileged mode command: asa#show running-config banner Hands-On Exercise: Creating Banners on the Security Appliance The following procedures are for training purposes only and should only be performed on devices in a laboratory environment. Under no circumstances should these procedures be performed on equipment in a live, production environment without first verifying their suitability in a laboratory environment. In the following hands-on exercise, you will create MOTD, login, and EXEC banners. Step 1: In configuration mode, enter the following commands: asa(config)#banner motd This is the MOTD banner asa(config)#banner login This is the login banner asa(config)#banner exec This is the EXEC banner Step 2: Display the banners you just created with the following command: asa(config)#show running-config banner Step 3: Type exit repeatedly until you are logged out of your laboratory security appliance. Notice which banners are displayed. Step 4: Enter privileged mode with the command enable and notice which banners are displayed. Step 5: From your laboratory computer, start a Telnet session and again observe which banners are displayed. When you are finished, exit the Telnet session. Step 6: Also from your laboratory computer, start an SSH session and again observe which banners are displayed. When you are finished, exit the SSH session. Note: The above procedures are similar to the procedures used to configure banners on other Cisco devices including routers. Copyright (c) 2007 Don R. Crawley Visit soundtraining.net to learn more about soundtraining.net s business skills training programs for IT professionals, plus accelerated technical training programs for IT professionals in the areas of Cisco, Microsoft, and Linux products. To learn more about soundtraining.net s Two-Day Cisco PIX/ASA Firewall hands-on seminar, visit soundtraining.net s Cisco PIX/ASA training page
Subscribe to:
Posts (Atom)