Tampilkan postingan dengan label internet security. Tampilkan semua postingan
Tampilkan postingan dengan label internet security. Tampilkan semua postingan

Selasa, 03 Mei 2011

Hacker Chatter Suggests Thieves Have Millions of PSN Customers' Credit Cards

Trying to sell stolen credit card numbers from 2200000 between 17 April and 19 and transmitted by hackers. Sony Corporation (NYSE: O), and your personal data in the time there was evidence that the stolen credit card data and Wednesday posted a blog pointing out that the encryption, the company is eliminating the possibility may not Tie.

On Thursday, a security researcher with the New York Times that, as we have seen in a forum on underground hacker wants to sell credit cards will show a lot of U.S. $ 10 million. Showed the comments on the forum, the name of pirates, address, user ID, the word, the code numbers credit card security credit cards. Not a single Sony pirates did not receive a response later admitted trying to sell. Have been many researchers can not verify the ownership of a database of information stolen from the discussion emphasized the basement.
Sony: It is possible

Forum Many of you are still bottom of the Playstation and put in and expressed anger at not being able to access. On Wednesday, Sony has said that within a week the sewage system. However, the company and answer questions, and provide details on how late a lot of personal information stolen by hackers.

"From the perspective of customer confidence, and show a legitimate interest in many of the people in the details" Richard Wang, manager Sofosuraboamerika, told TechNewsWorld. "Customers that information is lost and the possibility that contain credit card information, this is Sony, a company that appears in the credit card information is encrypted, your credit card information is concerned, did not confirm whether it was stolen. And they were told that it is accessed, whether it actually was access not less. "

Sony has been stolen credit card data, which pay attention to the details of the card the client is aware that it is possible we recommend that you review their credit reports.

"To break into the system that hackers have access to a database of addresses and passwords for Sony," said Wang. "Financial information, and once that the database may have had a different effect in the system to use it as a home and Sony has to obtain information on your credit card as well."

It took some time for Sony to reveal the full details of the crisis. If they were still withholding information about the company, as well as litigation, you may receive distorted picture.

"The number of those who depend on how Sony's recovery," said Wang. "They need to make sure to provide accurate information to customers. If you feel that the client may be compromised credit cards, and they had to contact the bank, and credit card customers who have stopped, so you can take Sony to provide useful information to customers. Banks and their actions."

Wang said Sony can not say everything is normal. The client does not yet have access to the network, and their credit card [OK] If you have, they do not know. "The degree is the audience of customers. You are the PlayStation, if you bind your system is all Sony."
Face slap

Exacerbate the situation and the reaction to this crisis is bad, Sony, and must do some serious damage control to repair its image.

The TechNewsWorld "Sony has become very difficult for them did not disclose quickly enough," said analyst Robuendaru Endarugurupu Home. "Hit taken on a very detailed picture of the image is very difficult, please see how to retrieve it difficult for companies to be aware of."

This piracy is not the first time being on the spot and not a Sony consumer.

He said Enderle ", before that, they had a problem with the battery." "The fire of their batteries, have been slow to recognize. A lot of work to slow this disclosure, and open them."

Most likely it will - can be confusing, Sony may take some time to get rid of piracy cases.

"The number of lawsuits, defense and should probably huge, "So far, everyone, and it was known that this attack, the risk had to go after the financial statements, and get more customers and clients live chat - White Paper free credit card account is likely to be compromised in the future, it is played the requirements of Sony notification . customers quickly, and it seems they do not meet the requirements. "

Kamis, 07 April 2011

Online Security is Very Bad and Getting Worse intermedietly

For many businesses and consumers, Symantec's news that cyberattacks are occurring with far greater frequency these days cannot be greeted with detachment, because they're striking so close to home. "At one point in time, hack attacks may have seemed theoretical to many people -- something that happened to someone else," observed SystemExperts consultant Philip Cox. The situation will only get worse -- the mobile onslaught hasn't even begun.


Rewriting the Startup Handbook
Starting up a new software company is not very hard, but making it successful requires a willingness to remake old rules to fit the Internet age. Getting venture capital or angel investor funds starts with nailing your story. [Download PDF: 5 pgs | 162k]

The state of Web security has never been pretty, and a new report from Symantec (Nasdaq: SYMC) discussing current and future threats only highlights just how risky the Internet environment has become.

The daily volume of Web-based attacks increased an eye-popping 93 percent from 2009 to 2010, the report says -- and that's a particularly significant increase given the high level of attacks prior to 2009.

Many of the latest attacks were targeted, Symantec noted -- in fact, targeted attacks were an overriding theme for the year.

Another development in 2010 was the apparent concentrated effort of malware writes to penetrate businesses, Kevin Haley, director with Symantec Security Response, told TechNewsWorld.

Hydraq, for example, attempted to steal intellectual property from major corporations -- none of which, except for Google (Nasdaq: GOOG), were willing to admit they had been targeted, Haley pointed out.

If nothing else, it served as a good wake-up call for companies that had been lax with security up to that point, he said. "That, and the Stuxnet attack raised the bar, so to speak. I think it will be a common event going forward for businesses to experience these attacks."
Plug-ins, URLS and Social Media

Not that consumers were ignored by malware writers. On the contrary, many of the vectors by which the attacks were delivered seemed to have been selected with the unsuspecting consumer in mind. Chief among these are shortened URLs, which are common in social media messaging.

Two-thirds of malicious links in news feeds used shortened URLs that redirected users to an attack website, Symantec found. Seventy-three percent of the links studied were clicked on at least 11 times, and 33 percent were clicked on as many as 50 times.

At one time, it was assumed that security tools would be developed to help users see where a link was directing them, Haley said.

That hasn't happened. Firefox does have a plug-in, he noted, "but it hasn't been universally adopted." Until that happens, shortened URLs "will remain a very useful social engineering tool for the bad guys."
Sheer Quantity

Much of the report covers familiar territory, at least for security experts, Philip Cox, a principal consultant with SystemExperts, told TechNewsWorld. "I think anyone in the industry could tell you that malware writers are getting more clever, using more sophisticated social engineering techniques."

That has become a given and will remain so, he said. What is astounding about the Symantec report is the sheer volume of attacks.

"Ninety-three percent is significant," said Cox. "What's more, it is starting to be felt firsthand by businesses and consumers. At one point in time, hack attacks may have seemed theoretical to many people -- something that happened to someone else."
Mobile Threats

Also surprising is the relative quietness of the mobile front, although that may change too, suggested Haley. "Really, we have all the ingredients necessary for a mobile onslaught, but it just hasn't happened yet."

These elements include growing mobile vulnerabilities, which increased 42 percent, a growing installed base, and sophisticated operating systems from which hackers can launch their attacks.

The reason so few have taken advantage of this environment is lack of financial payoff, Haley noted. "There just isn't an easy way to make a lot of money from mobile malware."

When smartphones turn into e-wallets using near-field communications technology -- something both Apple (Nasdaq: AAPL) and Google are expected to implement -- that is bound to change. "Then the environment will be very fertile for malware writers," Haley said.
Forest and Trees

Focusing on future scenarios or on elaborate techniques being deployed in the present may not be the best approach, at least for the masses, counseled Andres Kohn, VP of technology and product marketing for Proofpoint.

"Yes, it is important to look to the future to see where we are vulnerable," he said, "but such talk leads consumers to forget the plain vanilla techniques, such as standard phishing, that can trip them up."

The future attack scenarios are already here, and consumers must be warned about them, countered Catalin Cosoi, head of BitDefender's Online Threats Lab.

"The biggest issue right now is the false sentiment of security people have when using social networks or when installing smartphone apps," he told TechNewsWorld. "Since these services or devices are represented by known international institutions, they believe that they are safe."

Minggu, 27 Februari 2011

the new Ip v6 ready to change ip v4

Pv6 has been introduced, allowing a previously impossible variety of Internet addresses to be used now that the supply of useable addresses governed by the IPv4 standard has been exhausted. But what does this change mean for everyday surfers? Most computers will be able to process the new standard, but an IPv6-capable OS is needed.Many web surfers don't know it, but the introduction of new Internet address standards might change the way they get online.

Since the supply Relevant Products/Services of useable addresses governed by the IPv4 standard (Internet protocol, version 4) has been exhausted, IPv6 has now been introduced. This will allow a previously impossible variety of addresses, says Christoph Meinel, a professor at Germany's Hasso Plattner Institute.

But what does this change mean for everyday surfers? Here's an overview.

Why Are IP Addresses Necessary?

In order for Internet-capable devices to share information, they need a unique machine-readable address. These addresses are assigned based on a standard of Internet protocols.

But, since humans have a hard time remembering these strings of numbers, Web sites are also labeled with domain names, like www.google.com. When these addresses are typed into browsers, special servers translate them into IP addresses for the benefit of the computers.

What Is the Difference Between IPv4 and IPv6?

Until now, IP addresses have been assigned in blocks of four numbers with up to three numerals each: 217.79.215.248, for example. The new IPv6 standard won't convert the numbers into the decimal system Relevant Products/Services, rather a hexadecimal system, recognized by its combination of numbers and letters.

The new standard can be recognized by its eight blocks, separated by colons -- 2001:db8:0:0:0:0:1428:57ab, for example.

Will My Computer Be Able To Process the New Standard?

In most cases, yes. But an IPv6-capable operating system is a prerequisite. Those can be found in any Windows system post Vista. There are ways to install the functionality into Windows XP systems. Mac systems starting at 10.2 and Linux, in general, can support IPv6.

Will My DSL Access Support the New Standard?

In most cases, no. Contemporary routers, like the ones provided by telecommunications companies when DSL packages are ordered, are still set for the old IPv4 standard. In some cases, IPv6 can be added with a firmware update. When purchasing a new router, make sure it supports IPv6.

Should I Anticipate Problems During the Transition to the New Standard?

Generally, no. Internet use shouldn't be affected after the switch -- at least that's what providers are promising. Those providers have modified their network so that data Relevant Products/Services packets reach all users whether they are using IPv4 or IPv6 standards, a method called dual-stack application. Alternatively, software solutions, like those based on tunnel technology, can be used.

© 2011 Deutsche Presse-Agentur (dpa) under contract with MarketWatch. All rights reserved.

Kamis, 24 Februari 2011

What Can 3D Do for the Web?

Electronics manufacturers are still trying to pull together the right mix of conditions necessary to make 3D TV reach critical mass in consumer popularity -- price, content, standards, etc. Could the Web be an easier channel through which 3D can blossom? It may be easier to distribute content, but hardware runs into a familiar chicken-and-egg problem.In 2009, director James Cameron made people love seeing 3D movies in the theater again. In 2010, electronics companies began offering the first in-home stereoscopic 3D TV sets, and content providers launched Blu-ray 3D and broadcast 3D channels.

Now it's 2011, and there are still big changes happening in the 3D space, but there's one major source of media and entertainment that hasn't really come a-knocking to the 3D door yet.

It's surely only a matter of time before the Web starts going to a new dimension.
Early 3D Troubles

Despite all of the 3D stuff going on in the consumer electronics market these days, advances may be coming a little too fast for some consumers. 3D TV sales Increase sales with VerticalResponse. Free trial. last year were below expectations for manufacturers like Samsung, which threw considerable weight behind the new format. Many consumers shied away from this expensive new format that had almost no content.

Despite that, many are starting to take a different path. One of the emerging trends is glasses-free 3D technology, also known as "autostereoscopic 3D." LG has introduced a new iPad rival, the G-Slate, which can produce images that have the sense of depth, without the need for users to wear glasses. But something like that can only have high appeal if there is compelling content.

Obviously, 3D TV programming and Blu-ray 3D movies are out of the question there, so 3D content on the Internet would perhaps be the most compelling selling point.

Aside from glasses-free 3D tablets, computer makers that are manufacturing 3D hardware are finding it difficult to advertise exclusive 3D content. 3D computers are selling even worse than 3D TVs. At this point, it's up to online Create an online store today -- 30 day free trial. Click here to learn more. content providers to step up to the plate and bring this home media revolution to the cyber world.
Adding 3D to the Web

This isn't a completely new idea. There have been limited 3D streaming events online. NASCAR helped bring some of its races last year to 3D computer viewers via an exclusive online stream that was not broadcast on any 3D TV network. For the most part, though, 3D hasn't penetrated the Net.

It's a tough game of catch-22, Jordan Cressman, associate professor at The Ohio State University and a blogger for I4U News, told TechNewsWorld.

"Internet content providers don't want to spend resources creating 3D content unless there are a lot of people with Internet-connected 3D devices," she noted. "But by the same token, people don't want to buy expensive 3D devices unless there's a lot of 3D content."

Realistically, Cressman said, it's the content providers who need to make the first move. However, that might be an easier proposition for the Internet than it is for a traditional movie studio or satellite provider. Current 3D pioneers like DirecTV (Nasdaq: DTV) and ESPN have had to not only buy new 3D video equipment and transmission technologies, but they have to lobby advertisers to make 3D commercials and help manufacturers market their 3D hardware.
It's Not As Easy As It Sounds

For an Internet company, the only thing required is content. Distribution is easy, as Forrester analyst Josh Bernoff pointed out.

"The technology is there. Adobe (Nasdaq: ADBE) and Roxio have 3D video software, and there are already affordable 3D cameras on the market," Bernoff told TechNewsWorld. However, he said, there is still a hurdle with getting consumers to buy the hardware. "Sluggish sales of 3D TVs are sending a clear message that consumers don't really want 3D content in their homes, at least not yet."

That could be the message, or it could just be that consumers are confused by the whole 3D technology revolution. After all, there are a lot of things to consider when getting a 3D setup. It's not as easy as when the HD shift happened -- back then, consumers needed to buy an HDTV and an appropriate set of cables.

Now, they have to buy a 3D TV and 3D glasses that are made by the same manufacturer as the TV -- that is, if you buy a stereoscopic 3D TV. However, if you buy a Cinema 3D TV, like the one currently available from Vizio, you can buy any set of passive 3D glasses. Then again, there are new 3D TVs coming out that don't require any glasses. And to watch a Blu-ray 3D movie, you can't use any old Blu-ray player; you need one that specifically has 3D functionality.

Unfortunately, that same confusion applies to computers as well, with some displays that require 3D glasses and some that don't.

Also, many consumers have eye conditions that simply don't allow them to see 3D effects at all.

"Before launching, did [3D TV manufacturers] know that the thing can actually make roughly 20 percent of the audience sick to their stomachs? Did they take into account that an overwhelming majority of consumers say they are not interested in 3D TV? Or, at least, paying premium prices to bring one home?" said TVPredictions.com President Phillip Swann.

"If TV makers don't slow this train down, 3D TV could become the biggest -- and most costly -- mistake in the history of consumer electronics," he told TechNewsWorld.
Too Big to Fail?

In the end, it may be this variety of formats that kills 3D, but no one seems to want to stop trying. 3D is not a fad, Cressman contended, but merely a format experiencing growing pangs.

"There are a lot of problems with 3D in the marketplace, but with the entire consumer electronics and content industries in extreme support of it, there's no way it will die," she said.

AOL to buy Huffington Post in £222m deal

US internet firm AOL has agreed to a buyout of the Huffington Post online newspaper. The $315m (£222m) deal will create an internet media group with 270 million users, including 117 million in the US.

The purchase price - $300m of which will be in cash - will be paid to co-founders Arianna Huffington and Kenneth Lerer and a few minority shareholders.

Ms Huffington - currently editor of her namesake news service - will head the combined firm's content division. This means she will take on responsibility for AOL sites such as Engadget and Techcrunch, as well as retaining her current role at the intellectual centre-left website she helped set up in 2005.

"The Huffington Post will continue on the same path we have been on for the last six years - though now at light speed - by combining with AOL," said Ms Huffington in a joint statement.

AOL expects the purchase to help boost its flagging advertising revenues in a year that chief executive Tim Armstrong maintains will mark a turnaround for the company that divorced from Time Warner in 2009.

The Huffington Post is expected to contribute an additional 25 million users to the internet giant.

"The combination of AOL's infrastructure and scale with the Huffington Post's pioneering approach to news and innovative community-building among a broad and sophisticated audience will mark a seminal moment in the evolution of digital journalism and online engagement," said the two companies in their statement.

The transaction is expected to be completed in March or April and will need regulatory approval in the US.

Minggu, 20 Februari 2011

Symantec and Disaster Preparedness

Small and medium sized businesses are not taking disaster preparedness for their computers and networks as seriously as they should, according to survey results released by Symantec.

The Symantec 2011 SMB Disaster Preparedness Survey found that that most SMBs don't take action to prepare for disasters until after they have experienced loss from downtime, and that this lack of preparation has a significant impact on their customers and their business.
Disaster Plans
Only half (50 percent) of the respondents to the global survey said they already have a plan in place to deal with an outage or disruption to their computer or technology resources. That's up slightly from 47 percent in the 2010 survey, but 14 percent do not have a plan, nor do they have any intention to create one.

Fifty-seven percent of small businesses don't have a plan, compared to 47 percent of medium businesses. Of the respondents who plan to implement a plan in the future, 16 percent plan to do so within 30 days, 34 percent plan to do so between one and three months and 25 percent plan to do so between three and six months. Even though only half of respondents have a plan, 81 percent of all respondents are somewhat/very satisfied with their plans to deal with outages or disruptions, whether formal or informal; indeed, 84 percent state that their computer systems are somewhat/completely protected.

When those who do not have a plan were asked why not, roughly half (52 percent) don't think computer systems are critical to the business. Forty-one percent said that it never occurred to them to put together a plan, and 40 percent said that disaster preparedness is not a priority.

It is alarming that more SMBs do not have plans to help them deal with disasters and keep their computer systems up and running, especially when one considers that 65 percent of SMBs reside in regions that they consider susceptible to natural disasters.

In fact, SMBs experienced a median of six outages in the past year. The top three reasons for downtime include cyber attacks, power outages, employee errors and upgrades, with each occurring a median of once per company in the last year.

Of SMBs with a disaster preparedness plan, half (50 percent) implemented the plan due to either an outage or data loss. Fifty-two percent put together their plans within the last six months. Again, there were some differences according to company size. Thirty-six percent of small businesses with a disaster preparedness plan implemented their plan within the last six months, compared to 58 percent of medium businesses.
Advice from Symantec: Don't Wait Until It's Too Late
It is critical for SMBs to not wait until after a disaster to think about what they should have done to protect their data. Not only is downtime costly from a financial perspective, but it could mean the complete demise of the business. SMBs can't wait until it is too late, and they need to begin mapping out a disaster preparedness plan today. A plan should include identification of key systems and data that is intrinsic to the running of the business. Basically, identify your critical resources.

Symantec also advises SMBs to test their disaster plan frequently. (Only 28 percent of respondents have actually tested their recovery plans.) If frequent testing is not feasible due to resources and bandwidth, SMBs should at least review their disaster preparedness plan on a quarterly basis.

After a disaster hits is the worst time to learn that critical files were not backed up as planned. Regular disaster recovery testing is invaluable. Test your plan anytime anything changes in your environment.
Information Protection
The survey also found that SMB information is not protected. Only half of companies surveyed back up at least 60 percent of their data, and less than half back up their data weekly or more frequently. Only 23 percent back up daily.

Of those surveyed, 31 percent do not back up email, 21 percent do not back up application data and 17 percent do not back up customer data. Respondents also reported that a disaster would cause information loss. Forty-four percent of SMBs said they would lose at least 40 percent of their data in the event of a disaster.
Advice from Symantec: Protect Information Completely
To reduce the risk of losing critical business information, SMBs must implement the appropriate security and backup solutions to archive important files, such as customer records and financial information for the long term. Natural disasters, theft and cyberattacks can all result in data and financial loss, so SMBs need to make sure important files are saved not only on an external hard drive and/or company network, but in a safe, off-site location.
The Consequences of Being Unprepared
Disasters can have a significant financial impact on SMBs. Downtime costs SMBs a median of $12,500 per day. It costs small businesses a median of $3,000 per day and medium businesses a median of $23,000 per day.

Outages also have a considerable effect on SMB customers. SMB customers reported that SMB outages cost them $10,000 per day, and 29 percent said they lost "some" or "a lot of" data as a result of disasters impacting their SMB vendors.

Downtime also causes customers to leave with 54 percent of SMB customer respondents reporting they have switched SMB vendors due to unreliable computing systems, a 12 percent increase compared with last year's survey.

For many SMBs, disasters could also put them out of business. Forty-four percent of SMB customers stated that their SMB vendors have temporarily shut down due to a disaster.
Advice from Symantec: Get Employees Invested in Protection
SMB employees play a key role in helping to prevent downtime and should be educated on computer security best practices and what to do if information is accidentally deleted or cannot easily be found in their files. Since SMBs have few resources, all employees should know how to retrieve the businesses' information in times of disaster.

Jumat, 18 Februari 2011

Scareware Scam

Scammers are apparently using Google's URL shortening service, goo.gl, to distribute bogus links. The links take users to a scareware sight that purports to find malicious software on the user's computer, then offers to sell the user an AV product to solve the supposed problem. URL shorteners are commonly used in Twitter, but they can disguise a malicious link's true nature.Twitter has been hit by fast-spreading spam using Google's (Nasdaq: GOOG) goo.gl URL shortening service.

The attack sends malicious links that take recipients clicking on them to a website hosting the "Security Shield" antivirus software program.

When users land on that site, they are essentially tricked into downloading and paying for the Security Shield application.

Twitter is resetting the passwords of accounts that are spreading the malicious link.
The Anatomy of the Fake AV Attack

The attackers send out tweets containing a link from the goo.gl shortened link service. This service and others like it compress long URLs into shorter ones, making them easier to fit into services like Twitter, which places a strict limit on the number of characters each tweet may contain. However, the services can also disguise the true nature of a link by hiding its actual URL.

Anyone clicking on the link is taken through two bounces to a website hosting the "Security Shield" fake antivirus program. Visitors are told they have suspicious applications running on their PCs and are urged to run a scan.

The scan shows the victim's PC is infected, and the website then asks the user to download and pay for the Security Shield application.

There's some uncertainty as to how the attacks were launched in the first place.

"It probably began by phishing of some sort," Adam Wosotowsky, principal engineer at McAfee Labs, told TechNewsWorld. "Possibly a social media worm like Koobface."

Variants of the Koobface worm have been used to attack Twitter for some time. This worm was initially targeted at Facebook, which it has attacked repeatedly over the years.

"It's not a worm," Graham Cluley, a senior technology consultant at Sophos, told TechNewsWorld. "It's a spam campaign that points to malicious software."

The attack could have occurred because users were using the same passwords on another website that was compromised, Cluley said.
Dynamite Comes in Small Packages

This fake AV attack is the latest in a series of attacks hitting Twitter in which shortened URLs were used.

In December, a Twitter worm using the goo.gl URL shortening service hit Twitter. In that attack, victims were reportedly first redirected to the compromised website of a French furniture company before being redirected to other domains.

In February of 2010, Twitter users were flooded with short URLs prefaced with the message "This you???" that led them to a fake Twitter login page, according to Andrew Brandt, a member of Webroot's threat research team.

"Twitter almost always involves shortened URLs -- whether they be good or bad," Sophos' Cluley said. "Shortened URLs can, of course, obscure from the unwary user the eventual destination that they will be taken to."

In November, a Symantec (Nasdaq: SYMC) blog post warned that hackers were substituting legitimate shortened URLs included in tweets with different ones pointing to malicious websites after scanning the Twitter homepage to pick the most trendy topics.
Between the Devil and the Deep Blue Sea

It's not as if people are oblivious to the danger posed by shortened URLs.

At least as early as 2009, security Enterprise Payment Security 2.0 Whitepaper from CyberSource experts were warning about the danger of URL shortening.

In September, McAfee launched a secure short URL service.

In December, University of Tulsa computer science student Ben Schmidt created his own URL shortening service, d0z.me, which he dubbed "The Evil URL Shortener," that doubles as a weapon for issuing distributed denial-of-service attacks as a proof-of-concept project.

McAfee Labs warned in its threat predictions for 2011 that social media sites with URL-shortening services will lead all other such sites in terms of cybercriminal activity.

"Shortened URLs can be a danger sign," David Harley, an ESET senior research fellow, told TechNewsWorld. "Black hats do use them to hide the real destination in a number of contexts."

Black hats are malicious hackers.

However, it's not feasible to ban shortened URLs outright.

"Shortened URL sites are not 100 percent malicious, so blocking the domain outright can cause false positives, which researchers generally try to avoid," McAfee's Wosotowsky pointed out. "Goo.gl is an example of a site that's associated with Google, which might frown upon blocking the domain. This allows spammers to continually abuse the site."

Anonymous Swarms

A security company has felt the wrath of Anonymous after its CEO told a newspaper he had discovered personal information about individuals he believes are high-ranking members of the hacktivist group. In retaliation, the group disabled the company's website, published thousands of its internal emails and posted an online rebuke to the executive's claims.Anonymous, an amorphous group of cyberactivists, has set its sights on HBGary Federal, a company claiming to provide security Enterprise Payment Security 2.0 Whitepaper from CyberSource expertise to the United States' federal government.

The group took down HBGary Federal's websites and posted a message denouncing the company online Create an online store today -- 30 day free trial. Click here to learn more..

Anonymous' attack followed statements by Aaron Barr, HBGary Federal's CEO, that the company had collected information on the group's main leaders.

Anonymous has previously attacked the websites of governments and firms that opposed or took action against WikiLeaks for publishing more than 250,000 U.S. government cables on the Internet.

HBGary Federal did not respond to requests for comment by press time.
HBGary's Misstep

During an interview the Financial Times published last week, Barr claimed to have put together information about various high-ranking members of Anonymous through various means, including Facebook profiles.

Barr did this to demonstrate the security risks to organizations from social media and networking, he claimed.

In the interview, he also identified the nicknames and locations of a few individuals he believed to be top members of Anonymous.

Giving an interview to the Financial Times was probably a mistake, Rob Enderle, principal analyst at the Enderle Group, told TechNewsWorld.

"One thing you quickly learn as a security company is that you don't go out and bait people," Enderle said. "You don't go out and seek news coverage or it will backfire on you," he added.

"That's the risk you take any time you challenge hackers," Mandeep Khera, chief marketing Increase sales with VerticalResponse. Free trial. officer at Cenzic, told TechNewsWorld. "They'll always find a way to get in."
Anonymous' Reaction

In addition to hijacking HBGary Federal's domain, Anonymous posted a message on the company's website.

The message also included an excerpt from what it claims is one of Barr's emails in which he essentially said his actions were about publicizing HBGary Federal's expertise.

Anonymous' message states the information Barr discovered is publicly available on its IRC networks, and it implies that Barr meant to sell his research to the FBI. The message claims Anonymous has in fact already sent the information to the FBI itself.

The cyberactivist group also posted 66,000 of HBGary Federal's corporate emails onto the Web.

Members of the group are being targeted by various governments. The British authorities have reportedly arrested five people they claim are members of Anonymous, and the U.S. authorities are claimed to have carried out 40 court-authorized searches in connection with their investigation into Anonymous.
What Is HBGary Federal?

HBGary Federal was the U.S. government cybersecurity services arm of HBGary. It was spun off in December of 2009.

HBGary CEO and Founder Greg Hoglund hired cybersecurity experts Aaron Barr and Ted Vera as the spin-off's CEO and COO, respectively. Both are former employees of Northrop Grumman (NYSE: NOC).

Barr, whose interview triggered the retaliation from Anonymous, reportedly served as the director of technology for the cybersecurity and signal intelligence business unit in Northrop Grumman's Intelligence Systems Division.

HBGary Federal's targeted customers included the U.S. Department of Defense, the U.S. intelligence community and other government agencies.
Breaking Into HBGary Federal

Anonymous apparently hacked into HBGary Federal by first hacking a tech support server, then compromising an insecure Web server to get at the company's emails, Hoglund told the Financial Times.

Finding and getting into a relatively insecure server in order to penetrate the enterprise network is a pretty standard hacking technique. Shouldn't a company that specializes in security perhaps have all its servers secured?

"If you're in the security business you probably need to make sure your own stuff is secure," Enderle said. "But often it's a case of the cobbler's children not having new shoes -- a company puts out new technology but that technology isn't necessarily applied to its own operations."

That's because the workings of many security companies' operations and in-house IT are kept separate, Enderle elaborated.

"The general security posture across the industry is very low right now," Cenzic's Khera said. "Most companies, for example, are testing only a fraction of their Web applications for security."

However, it might not be feasible to harden all a company's systems, even if that company specializes in security, suggested Randy Abrams, director of technical education at ESET.

"Even security companies have budgets and resource limitations," Abrams told TechNewsWorld. "Security is all about managing risk and, in weighing how secure the least important servers need to be, public relations should be part of the risk assessment for a security company."

Malware Is on the Move

Mobile operating systems are the new favorite target of malware, and social engineering remains the favorite old standby for launching attacks. Tried-and-true preventive care works best. "Never give information via email, smartphone or on the Web, and verify independently before you click on any unknown text or email message, game, application or security update," advises UVa security expert Karen McDowell.Cybercriminals are following innocent consumers away from email Increase sales with VerticalResponse. Free trial. and toward more popular, smartphone-style platforms, McAfee reported Tuesday.

"New mobile malware in 2010 increased by 46 percent compared with 2009," noted McAfee spokesperson Joris Evers.

Among the likeliest targets in 2010, Symbian and Android platforms were splattered by Trojans and bots with names like "SymbOS/Zitmo.A" and "Android/Geinimi."

"Consumers need to realize that mobiles, whether smartphone or tablet, are mini computers," said David Gorodyansky, CEO of AnchorFree. "This means all the vulnerabilities of a computer exist, often with a less-protected OS."

"From a hacker's point of view, the large user base created by wide scale adoption of iOS (iPhone) and Android will increasingly make these platforms a target, and I definitely expect to see some high-profile mobile attacks in the coming year," Cenzic CMO Mandeep Khera told TechNewsWorld.

"Smartphone access should be a concern to corporations that don't want employees accessing company secrets via unsecured mobile networks," Khera told TechNewsWorld. "For consumers, as banks and e-commerce sites deploy apps that give customers unprecedented access to their bank accounts, security Enterprise Payment Security 2.0 Whitepaper from CyberSource becomes more important than ever."

Unlike their mobile partners in crime, spam bots -- including Bredolab, Lethic, Xarvester, and parts of the Zeus botnet -- have gone dormant in droves this year,.

"Concurrently, spam accounted for 80 percent of total email traffic in Q4 2010, the lowest point since the first quarter of 2007," McAfee's Evers told TechNewsWorld.
The Bot Pack

Like a flu pandemic, botnet infections were particularly acute in Q4 2010, with Rustock, Cutwail and Bobax leading the bot pack. Social media sites, like mosquitoes, often acted as disease vectors.

"Whether we are using smartphones or computers, social engineering attacks are still the primary attack vector, and a major vector in the spread of botnet infections," University of Virginia information security analyst Karen McDowell, PhD, GCIH, told TechNewsWorld.

McAfee advises tablet and smartphone users to watch out for Zeus-Murofet, Conficker, and Koobface botnets specifically, and more generally, phishing URLs from the IRS, gift cards, rewards accounts, and social networking accounts.

Phishing vectors spread bot diseases when users click on phishing emails, answer phishing phone calls, or click on text messages that "appear to come from your carrier," McDowell explained, adding that tried-and-true preventive care works best. "Never give information via email, smartphone or on the Web, and verify independently before you click on any unknown text or email message, game, application or security update."

More preventive options: "Don't log onto unprotected WiFi, and use a VPN to encrypt and secure your browsing, which acts as a secure, encrypted tunnel for your communications," AnchorFree's Gorodyansky told TechNewsWorld.
Malware's Mantra

Twenty million new pieces of malware -- nearly 55,000 new malware threats every day -- plastered the cybersphere in 2010, migrating toward smartphones because "cybercriminals are keeping tabs on what's popular and what will have the biggest impact from the smallest effort," said Vincent Weafer, senior vice president of McAfee Labs.

"Think globally, act locally" might be malware's new mantra, with threats that "now tend to match the types of users, habits and events that are specific to a region," McAfee's Evers added. Global criminal favorites include AutoRun malware such as Generic!atr; banking Trojans and downloaders such as PWS or Generic.dx; and Web-based exploits such as StartPage and Exploit-MS04-028, the McAfee report claims.

To avoid malware, treat search terms and Adobe (Nasdaq: ADBE) products with extra care, McAfee advises. Of the top 100 search results, 51 percent led to malicious sites. And throughout 2010, malware developers exploited weaknesses in Flash and PDF, a trend McAfee sees continuing.

Despite the advice, pests will persist, driven to infect by "a general lack of awareness towards the need for security," Gorodyansky explained.

"This is the same as it was for computers, when most people thought they were completely safe once they installed an antivirus program," he recalled.

"It really doesn't matter what type of device is used -- the steps to secure a Web application haven't changed," Sam Shelby, e-government coordinator for the City of Columbia, Missouri, told TechNewsWorld. "You can never trust input: always authenticate, validate and sanitize input data."

Make WiFi Noise To Breakthrough

A team of Stanford researchers have come up with "full duplex" radios that can talk and listen at the same time -- a feat that enables communications simultaneity over WiFi networks. Cutting through existing WiFi congestion could double network speeds and capacities, encourage ambitious new projects -- such as citywide WiFi -- and even help prevent plane crashes.Ten-4. Back to you. Over.

On a radio or over the TV airwaves, speakers have to rely on back-and-forth communications because radio traffic only flows in one direction at a time on a frequency. Or so said scientific conventional wisdom, until Stanford researchers developed so-called "full duplex" radios that can send and receive signals at the same time. Twice as fast as existing radio devices, the new technology promises less congested, more efficient networks.

"Textbooks say you can't do it," said the technology's principal investigator Philip Levis, assistant professor of computer science and of electrical engineering at Stanford. "The new system completely reworks our assumptions about how wireless networks can be designed."

Dreams of supercharged WiFi connections are already dancing.

"Full-duplex technology like this could literally double the speed of WiFi connections almost overnight," said Jason Katz, founder and CEO of instant messaging and wireless video technology provider Paltalk.com. "This could greatly enhance each and every WiFi user's Internet experience."
WiFi Workaround

Used to telephones and cellular phones, most people don't think about the inability to communicate simultaneously on radio. Perhaps they should, because cellphones route around the problem with expensive technologies whose costs get passed along to consumers -- and make similar fixes unfeasible for wireless networks that often come free, including WiFi.

The idea for communications simultaneity came virtually simultaneously among three Stanford electrical engineering graduate students -- Jung Il Choi, Mayank Jain and Kannan Srinivasan.

They wanted to answer this question: "What if radios could do the same thing our brains do when we listen and talk simultaneously: screen out the sound of our own voice?" Stanford science writer Sandeep Ravindran explained.

Simultaneous talk on a radio can build a Tower of Babel in no time.

"If both people are shouting at the same time, neither of them will hear the other," Levis told TechNewsWorld.

With help from Levis and Sachin Katti, an assistant professor of computer science and of electrical engineering, the grad students had to overcome an intrinsic flaw in radio communications. That is, a radio's own transmissions -- billions of times stronger than anything it might pick up from another radio -- overwhelm incoming signals, Levis explained.

"It's like trying to hear a whisper while you are shouting," he said. Filtering out the noise became the basis for the new solution, which Paltalk's Katz said should encourage further innovations.

"I would think enabling this technology would encourage more WiFi projects designed to blanket large areas such as cities," he told TechNewsWorld. "Networks should be far less congested, and cities would greatly benefit."
Double Time

Sending and receiving signals simultaneously doubles the amount of information sent, Levis said, which means faster home or office networks -- and a boost to air traffic controllers, a high pressure bunch often beleaguered by the demands of skyward communication critical to safety.

Presently, if two aircraft try to call the control tower at the same time on the same frequency, neither will get through. Such blocked transmissions have caused aircraft collisions, Levis said, a problem the new approach would resolve.

Provisional patent in hand, the Stanford group is trying to increase both transmission strength and distance, necessary before the technology is WiFi-ready.

With an instant messaging client that allows users to share video, audio and text with up to 10 people at any time for free, the thought of faster, cheaper networks that allow more people to communicate at once impresses Paltalk's Katz.

However, where the Stanford innovation goes from here depends "largely on how the inventors decide to commercialize it," he explained. "Regardless, it should cause a new cycle of hardware purchasing to enable the technology."


FBI, encryption back doors

The FBI said today that it's not calling for restrictions on encryption without back doors for law enforcement.

FBI general counsel Valerie Caproni told a congressional committee that the bureau's push for expanded Internet wiretapping authority doesn't mean giving law enforcement a master key to encrypted communications, an apparent retreat from her position last fall.

"No one's suggesting that Congress should re-enter the encryption battles of the late 1990s," Caproni said. There's no need to "talk about encryption keys, escrowed keys, and the like--that's not what this is all about."

Instead, she said, discussions should focus on requiring that communication providers and Web sites have legally mandated procedures to divulge unencrypted data in their possession.

As CNET was the first to report yesterday, the FBI says that because of the rise of Web-based e-mail and social networks, it's "increasingly unable" to conduct certain types of surveillance that would be possible on cellular and traditional telephones. Any solution, it says, should include a way for police armed with wiretap orders to conduct surveillance of "Web-based e-mail, social-networking sites, and peer-to-peer communications technology."

Caproni tried to distance the FBI from its stance a decade ago, when it was in the forefront of trying to ban secure encryption products that are, in theory, unbreakable by police or intelligence agencies.

"We are very concerned, as this committee is, about the encryption situation, particularly as it relates to fighting crime and fighting terrorism," then FBI director Louis Freeh told the Senate Judiciary committee in September 1998. "Not just bin Laden, but many other people who work against us in the area of terrorism, are becoming sophisticated enough to equip themselves with encryption devices."

In response to lobbying from the FBI, a House committee in 1997 approved a bill that would have banned the manufacture, distribution, or import of any encryption product that did not include a back door for the federal government. The full House never voted on that measure. (See related transcript.)

Even after today's hearing ended, it wasn't immediately clear whether the members of the House Judiciary crime subcommittee would seek to expand wiretapping laws as a result.

Rep. Bobby Scott, D-Va., said that the panel's members received a secret briefing last week from the FBI, but that the bureau should make its arguments in public. "It is critical that we discuss this issue in as public a matter as possible," he said. It's "ironic to tell the American people that their privacy rights may be jeopardized because of discussions held in secret."

Rep. John Conyers, D-Mich., said "to me this is a question of building back doors into systems...I believe that legislatively forcing telecommunications providers into building back doors into systems will actually make us less safe and less secure."

That was echoed by Susan Landau, a computer scientist at Harvard University's Radcliffe Institute for Advanced Study, who said "there aren't concrete suggestions on the table...I don't quite understand what the FBI is pushing for."

Caproni said her appearance before the panel was designed to highlight the problems, not call for specific legislation. But, she added, "it's something that's being actively discussed in the administration."

Under a 1994 federal law called the Communications Assistance for Law Enforcement Act, or CALEA, telecommunications carriers are required to build in back doors into their networks to assist police with authorized interception of conversations and "call-identifying information."

As CNET was the first to report in 2003, representatives of the FBI's Electronic Surveillance Technology Section in Chantilly, Va., began quietly lobbying the FCC to force broadband providers to provide more-efficient, standardized surveillance facilities. The Federal Communications Commission approved that requirement a year later, sweeping in Internet phone companies that tie into the existing telecommunications system. It was upheld in 2006 by a federal appeals court.

But the FCC never granted the FBI's request to rewrite CALEA to cover instant messaging and VoIP programs that are not "managed"--meaning peer-to-peer programs like Apple's Facetime, iChat/AIM, Gmail's video chat, and Xbox Live's in-game chat that do not use the public telephone network.

Also not covered by CALEA are e-mail services or social-networking sites, although they must comply with a wiretap order like any other business or face criminal charges. The difference is that those companies don't have to engineer their systems in advance to make them easily wiretappable.


Kamis, 17 Februari 2011

How To DDOS A Website

crash your target web .










Preparing Cyberwar Strategy

In a speech to the RSA security conference, Deputy Defense Secretary William Lynn said the U.S. is building a cyberstrategy. Lynn told RSA attendees that the time to build defenses is now, and he said the open nature of the web gives attackers an advantage. Lynn urged military training along with industry and government cooperation.
Deputy Defense Secretary William Lynn said Tuesday that the U.S. government is "moving aggressively" to counter evolving cyberthreats and is currently in the final stages of a comprehensive cyberstrategy review. The time to act is now while cyberattacks are still "relatively unsophisticated in nature, short in duration, and narrow in scope," he said.

The danger is that powerful cybertools already exist that one day could be deployed by the nation's adversaries to potentially cause severe economic damage, physical destruction, and even loss of life, Lynn said in a keynote address at the RSA security Relevant Products/Services conference in San Francisco.

"We must have the capability to defend against the full range of cyberthreats," Lynn said. "This is indeed the goal of the Defense Department's new cyberstrategy, and it is why we are pursuing that strategy with such urgency."

A New Domain of Warfare

FBI Director Robert Mueller, CIA Director Leon Panetta, and Director of National Intelligence James Clapper have already told the House Subcommittee on Emerging Threats and Capabilities that sophisticated cyberattacks could place the nation's security in jeopardy.

"Each of them said it was very serious," said subcommittee Chairman Mac Thornberry (R-Texas). "In fact, Clapper testified that 'The threat is increasing in scope and scale Relevant Products/Services, and its impact is difficult to overstate.' And our vulnerability is growing because our dependence on cyber is growing in just about every aspect of our lives."

Though the open, transparent and interoperable nature of the worldwide web has endowed it with undeniable dynamism, it has also given attackers a significant advantage that becomes obvious when comparing antivirus software to the malware it attempts to defeat, Lynn said. "Sophisticated antivirus suites now run on about 10 million lines of code, yet malware written with as little as 125 lines of code has remained able to penetrate antivirus software," he observed.

The Defense Department has already formally recognized cyberspace as a new domain of warfare -- like land, air, sea and space, Lynn explained. "Treating cyberspace as a domain means that the military needs to operate and defend its networks, which is why we established U.S. Cyber Command," Lynn told the RSA attendees.

Furthermore, U.S. military services need to be organized, trained and equipped to perform cyber missions. "Each of the services has recently created organizations to do just that," Lynn said. "In short, to maintain our national security, our military must be as capable in this new domain as it is in the more traditional domains."

A Cooperative Effort

Lynn suggested several avenues of industry-government cooperation need to be pursued under the Defense Department's forthcoming Cyber 3.0 strategy. "We need the scientific community to help strengthen our network architecture" even as Cyber 3.0 seeks to foster "the sharing of information" about potential threats between the U.S. government and the private sector.

Lynn also called for the development of active cyberdefenses that "operate at network speed using sensors, software and signatures derived from intelligence to detect and stop malicious code before it succeeds." Moreover, the military's evolving cybercapabilities will need to be built so they can be made available to civilian leaders to help protect the networks that support government operations and critical infrastructure.

"It is clear that securing our networks will require unprecedented industry and government cooperation," Lynn observed. "With the threats we face, working together is not only a national imperative -- it is also one of the great technical challenges of our time."

How to check password hacked

A security researcher today provided a way for users to see whether their e-mail addresses and passwords were among the 1.3 million compromised in a hack of Gawker Media's sites.

HD Moore, chief security officer at Rapid7 and the creator of the open source Metasploit penetration-testing toolkit, came up with a down-and-dirty way for users to search the list of purloined account information without having to download the massive 487MB file from the Internet.

On Sunday, Gawker, which operates several popular technology sites, including Gizmodo and Lifehacker, confirmed that its servers had been hacked, and that hundreds of thousands of registered users' email addresses and passwords had been accessed. A group calling itself "Gnosis" claimed credit for the attack, and said it had obtained more than 1.3 million accounts.

Gawker apologised for the breach, and urged users to change their passwords. If that password was used for accessing other sites, Gawker recommended that users change it for those destinations as well.

"It's best to assume that your username and password were included among the leaked data," Gawker said in an FAQ it posted on the Lifehacker site.

Moore had a better idea, and has assembled a way for people to check whether their account, including their password, has been compromised.

In an email to Computerworld Monday, Moore spelled out the technique:

Step 1: Go to http://pajhome.org.uk/crypt/md5/, enter an email address in the 'Input' field, click the 'MD5' button, then copy the hash from the 'Result' field.

Step 2: Go to http://www.google.com/fusiontables/DataSource?dsrcid=350662, click 'Show Options,' then paste the already-obtained hash in the field to the right of the '=' symbol. Change the left-most field to 'MD5.' Click 'Apply.'
If the email address is among those compromised, the search will show a result.

Although Gawker said it encrypted users' passwords, some passwords have already been decrypted by Gnosis.

Moore used MD5 hashes of the email addresses in the list he posted as a Google Fusion Table so users could check whether their accounts had been compromised without exposing the addresses a second time.


Fecebook With HTTPS Connections

How important is your Facebook account? Do you consider it as important as, say, your bank account? If you happen to feel this way about Facebook, then you'll like the latest news regarding the social network service.
Earlier this week, Facebook rolled out a new feature which allows users to connect with a HTTPS connection.

What is a HTTPS connection?

Basically it's an encrypted link, which is very similar to what most banks provide their customers. The connection type will be able to curb the problems with "sidejacking". Which is the act of cracking into connections over open Wi-Fi networks.

Considering many people keep up with their social networking in public places, this could be a huge privacy move for some users. For those who travel on a consistent basis, this is a huge improvement.

This security feature is added to a long list of updates Facebook has rolled out recently. With one such featured being the "social authentication" feature. This makes it so users have to verify photos of their friends in order to verify their account status.

It's perhaps coincidence, or maybe not, that this feature has released the day after an API error was used to hack into Mark Zuckerberg's account page. The error has been patched, alongside with the release of the HTTPS feature.

The update has also released a day before the Data Privacy Day. Which is an international time to boost awareness for data privacy.

With HTTPS, Facebook continues to try and improve its security image. Many people have criticized them through the years for not protecting users' security and privacy enough. This update is certainly taking a step in the right direction to help boost their image.

Hackers Go To Exploit

Pwn2Own is a contest put together which pits hackers against the major web browsers. Their goal is to successfully exploit the browsers and find bugs which allow for these hacks. The hackers aren't just doing this to be nice either, there's a prize pool worth $125,000. Cash, laptops, and desktops will all be available to win.
The contest features all the major browsers (Firefox, Internet Explorer, Safari, and Chrome), and will be functioning on both Windows 7 PC's and Mac OS X machines. The contest is hosted by TippingPoint, a research organization who works to provide protection against system vulnerabilities.

There are a couple of new additions to the contest, both of which will pay prize money. First, there will be a mobile hacking event. This will pit researchers against the likes of Apple's iOS, Google Android, Microsoft's Windows 7 Phone, and RIM's Blackberry OS.

The news which is really drawing attention to the event is Google Chrome joining in on the action. Not only are they participating, but they're ponying up their own dough to award the hackers. $20,000 will go to the hacker who can find an exploit in Google Chrome first.

Google has been very confident in their belief that Chrome cannot be hacked. This is due to their using of a 'sandbox' anti-exploit defense. This type of defense isolates a program from other system processes, and requires hackers to take an additional step to truly perform a successful breach.

Only on the first day will Google be providing their $20,000 prize. This is due to the fact that on the first day only the browsers themselves will be available to the contestants. On the second and third day, they are allowed to utilize system bugs on the operating systems to perform their hacks. For the last two days Google will still provide a $10,000 award, which will be matched by Tipping Point. So no matter what day a hacker might successfully exploit Chrome, they'll still receive $20,000.

This is the contest's fifth running, and the award money has never been higher. The contest itself is about helping the browser developers better implement security strategies that keep malicious hackers from fulfilling their exploits.

Rabu, 16 Februari 2011

internet explorer can't better

The time has come to dump Internet Explorer. I know, I know – you may have heard the same thing before from those that think it’s cool to hate Microsoft; but I’m not one of those guys. I’m actually an MCSE and I happen to like quite a few of Microsoft’s products. Rather than lump me into the Microsoft-basher category, consider for a moment why you use the browser you use, and humor me by entertaining the notion – if even for a second – that switching to another might be worth your while.

My argument is simple: the benefits of using IE are too few – and the faults too great – to put off the adoption of an alternative any longer.

Security

Since information security is my hobby/job/obsession, this particular topic is near and dear to my heart. Just about everyone reading this has seen computers that have been beaten down with spyware – the evil junk that hijacks IE and renders a system virtually useless. How many times have you been called to a family member’s house to clean up their system? Or had to call your techie friend to come clean yours? It’s often quite awkward – the system slows to a crawl and every other mouse click conjures up some species of perverse, obscene image. What most people don’t realize, however, is that there is a very simple and powerful way to defend your system (and/or the systems of your loved ones) in one fell swoop.

Don’t use Internet Explorer.

What makes other browsers better than IE at protecting vs. spyware and other attacks? Well, it’s simple really – most other browsers don’t make it so easy to install malicious software on your system without you knowing about it. IE makes it relatively trivial through two features called ActiveX and Active Scripting. These technologies were designed specifically for the purpose of giving Web sites more control over a user’s computer. Unfortunately, as we have seen with exploit after exploit – that’s not always a good thing.

In addition to the spyware issues, IE in general has had a terrible track record when it comes to all types of serious security issues. For years now, it’s seemed like every time you turn around there is a new way to have your computer taken over via Internet Explorer. Put “internet explorer” and “allow an attacker to execute commands” (with the quotes) into Google and you’ll see what I mean.

In IE’s defense, many anti-Microsoft types will claim that it’s not possible to lock down IE at all. This is not true. It is possible – but if and only if you have a fair amount of technical know-how on the subject, and the time to do it. My personal view, however, is that tools such as Internet browsers should not require expertise and configuration time to be able to use them safely.

Standards

This is likely to get me in some hot water with my fellow security enthusiasts, but I find this issue to be of even more concern than that of IE’s security. The Internet works for one simple reason – everything at its core has been built on agreements that bind it together. Whether a computer is connected from California or Sri Lanka, it’s going to speak the same language and obey the same rules – the rules defined by standards. If this weren’t the case there would be no Internet at all. These agreements are forged by a body of people whose goal is nothing short of designing a better and more efficient Internet for everyone. Microsoft, for some odd reason, seems bent on breaking stride with these agreed-upon standards. Case in point: the next time you’re in a bookstore, head over to the technology section and pick up a book on XHTML or CSS. These are two major Web standards that deal with how Web pages are displayed to users, and within any book on the subjects you will find one common theme:

The absolute worst browser when it comes to supporting the standards is Internet Explorer.

Page after page in these books will reveal features supported in other browsers, but not in IE. Ask yourself why a company would choose not to support standards that benefit everyone? The way I see it, it’s for precisely one of two reasons – either they are unable to, or they don’t want to. Given the fact that they are a multi-billion dollar company (one of the richest on the planet), I can’t help but lean toward the second option. Without going into too much detail (See Longhorn), they have their own plans, and those plans involve implementing their own standard and forcing it upon the world. Call me a geek/hippie, but the idea of a multi-billion dollar corporation snubbing its nose at agreed-upon standards is nothing short of infuriating.

Options

Lucky for us, we have alternatives. The good news is that the alternative browsers are actually as good or better than IE. There are many out there, but in my opinion the Mozilla products are the best. I personally prefer and recommend Mozilla Firefox. Not only does it keep your browsing sessions a lot more secure and spyware-free, but it also supports the standards religiously and has a wide range of powerful features. Arguably the biggest benefit to using a Mozilla-based product is something called tabbed browsing. What this allows you to do is have multiple pages open within a single browser window. Rather than going from window to window in the taskbar, you can simply switch between clearly visible tabs, all within the same view. You can even do this and many other commands via the keyboard if you are into that sort of thing.

Using Firefox will not require any major shift in your daily browsing habits. It’ll import your favorites automatically, and you can benefit from the improved security starting the first time you open it. With the popup blocking enabled, you can breath quite a bit easier when browsing to unknown sites. Attempts to install garbage on your system that could have easily succeeded if you were using IE will simply be ignored by Firefox. Plus, the whole time you’re browsing you’ll know that you are doing your part to keep the soul of the Internet alive by choosing to use a browser whose developers actually care about standards.

Of course, I still use IE. (pause for effect) …it’s how I get my Windows security updates. : Seriously though – Windows Update is a must, and it only works in IE, so that in itself is a good reason to fire up IE once in a while. Aside from Windows Update though, there is still the occasional site that I go to that doesn’t look right in any other browser. Those sites, by the way, are all the more reason to not use IE. They weren’t written according to the standards, and they look bad in any browser other than IE as a result of that fact. Using IE all the time just because the occasional site is designed so poorly as to look like crap in other browsers is utterly bad form. I implore you not to give into this temptation.

Wrapping It Up

So, in closing, I leave you with two thoughts:

1. Due to the combination of ActiveX, scripting, and its integration with the Windows operating system, Internet Explorer is more vulnerable to attack than many other browsers.
2. The designers of Internet Explorer have purposely turned their back on the standards designed to benefit the Internet as a whole. They have done this for years, continue to do it today, and appear to have nothing but their own interests at heart.

I ask that you consider these points and pull down a copy of Firefox, Opera, or another alternative browser. Run it for a week and see how it feels. As mentioned above, I personally recommend Firefox due to its excellent development team and large user base. Once you have had some time to get to know your new onramp to the Web, I think you’ll find that you’ll wish you had switched sooner. No longer will you have to worry about garbage clogging up your system because of your browser, or having to make a mad rush for a patch every time an IE vulnerability is released.

Finally, and most importantly – spread the word. It’s time now for us to put alternative browsers on the map and let it be known that we are aware of our choices. We need not settle for what we are being fed when there are better, more secure alternatives out there.

Selasa, 11 Januari 2011

How To Secure PC

Step 1. Use a strong password

The danger: malicious computer users can gain access to your computer over the Internet, stealing and deleting data and potentially implanting viruses and Trojan horses.

The cause:
The major irony of Microsoft's shift from non-password protected home operating systems like Windows 98 and ME to the password and access-list based 'security' of Windows 2000 and XP is that your data is actually less secure by default.

Sure, the new operating systems give security conscious users all the tools they need to protect their data, but what if the users are not aware of the risks? During the install process, you are prompted to create a password for the built-in 'administrator' user account. Users accustomed to Windows 9X/ME's pointless passwords often decide to bypass this by entering a blank password, thus opening up their entire computer to anyone who takes the trouble to look twice at their Internet address.

There are two reasons for this vulnerability: One, every Microsoft Windows XP and 2000 system has a built-in account called 'administrator' which has full access to all files and configuration settings of the computer. Anyone who is remotely familiar with these operating systems knows of this account's existence. This definitely includes anyone who might try to break into your computer.

The other factor in Windows 2000 and XP's vulnerability is the presence of hidden administrative shares. Each logical drive (C:, D:, etc.) on your system, plus the Windows directory, is actually shared (made available for remote access) by default. These hidden shares are only accessible to Users with administrative privileges, but once an intruder has your administrator account password, he has your entire system laid open for him.

By using one of a multitude of free and legal software tools, a potential intruder can easily locate and gain access to your data by finding your IP address and attempting to connect using the administrator account. Obviously, if there is no password on the account, you are defenseless.

Even if you have put a password on the account, you may not be safe. Simple passwords can easily be discovered by an intruder using a 'dictionary attack' software tool, which can try words and combinations of letters until your password is compromised.

The administrator account is uniquely open to this style of attack, because while other user accounts can be 'locked' by the operating system if an incorrect password is entered too many times, the administrator account cannot be locked out. This means that an intruder is free to try as many password possibilities as he or she wants, without worrying about losing access to your system.

The Cure to Step 1.

The cure: Set effective passwords for all users

The best way to protect yourself from malicious users is to effectively password protect all your user accounts. An effective password, according to Microsoft, is at least seven characters long and contains a mix of upper and lower case letters, numbers and symbols. While you can cut corners a bit here in the interests of memorization, make sure to use six or more characters and include at least some numbers and upper case letters in the middle of the word. By using several characters and a mix of upper and lower case letters and numbers, you can make your password effectively uncrackable to intruders who do not possess super computers capable of predicting the weather...

To change user passwords make sure you are logged in as a user with administrative privileges (the first user created during the XP install process has these). Right click on 'my computer' and select 'manage.' Expand 'local users and groups' then 'users.' Right click on each user and select 'set password.'

Note the ominous warning message. If you have used XP's built-in file encryption to protect any of your files, you must remove it before you change your password or you will lose access to the files. Otherwise, proceed and set a secure password for each account.

The accounts you should set passwords for are the administrator account, and any accounts you created during or after the installation of Windows.

Step 2. Make sure your system is protected by a firewall

The Danger: Malicious users may locate and attempt to break into your computer from the Internet.

The Cause: All computers that communicate over the Internet must have a valid IP address, such as 61.232.252.6. These addresses allow computers to exchange data with other computers over the 'net. Your system also leaves a variety of ports open to listen for incoming data. Ports are access points for certain kinds of data to enter and leave your computer. For example, while you are viewing this website, your computer and our web server are communicating through port 80, the default port for the HTTP language that web pages generally use.

The trouble is that anyone can use freely available software like GFI's LANguard security scanner to scan a range of IP addresses for computers and gather information about these systems. If your computer is poorly password protected these utilities provide remote users with the ability to directly access your files.

This happens because by default, many ports in your system are fully prepared to listen and respond to any data request from the Internet. This means that your system is fully visible, the equivalent of wearing glow-in-the dark clothes in a blackout…

The Cure to Step 2.

The cure: Use a firewall program or device.

A firewall is a software program or hardware device which blocks remote access to your computer. It does this by closing all ports to data unless the communication is initiated from inside the firewall first. So you could, for example, surf this page without problems through a firewall since your computer sends the request for data to our web server first.

The firewall would note the Internet address that your request was sent to, and allow return communications from that specific address back through the firewall. However, anyone trying to scan a range of IP addresses for vulnerable computers would turn up a blank for your address, since the firewall blocks all unsolicited communication from the Internet.

Almost all home Internet sharing devices include firewalls, so if you are using a router to share your Internet connection within your home, you are likely already protected. Otherwise you need to use a software firewall. Windows XP comes included with one, though you need to activate it. Several free third-party software firewalls are also available, most notably Zone Lab's Zonealarm.

To activate the Windows XP firewall go to 'start/control panel/network and Internet connections/network connections' then right click on your Internet connection and select 'properties'.

Go to the 'advanced' tab and check the 'internet connection firewall' box.

The windows XP firewall is now active and will block most non-requested data from entering your system.See PCSTATS Beginner's guide to Firewalls and Internet security for more details on configuring the XP firewall.
If you have installed Service Pack 2 for Windows XP, the firewall works a little differently. Unless you have another form of firewall software like Zonealarm installed, the XP firewall should be active by default.

To check this, go to 'start\control panel\windows firewall' and ensure that the firewall is set to the 'on (recommended)' position. The 'windows firewall' icon in control panel is only available to Service Pack 2 users, so if it's not there, simply follow the directions given in the last paragraphs. For more information about the changes to Windows XP made by Service Pack 2, see PCSTATS article on WinXP-SP2 right here.

To use Zonealarm first download and install the software.
Go to 'alerts and logs' and change the 'alert events shown' setting to off. This is just to prevent the program informing you every time it blocks data remotely.

The main advantage of Zonealarm over the XP firewall is its ability to block data coming from inside your system out to the Internet. This enables it to catch Trojan horse viruses and spyware in the act and prevent them from sending privacy and security compromising data from your system. Zonealarm will pop up a permission box every time a program attempts to access the Internet.
Step 3

Step 3. Use antivirus software

The Danger: Computer viruses can cripple your computer and destroy your data.

The cause: There are an incredible variety of computer viruses on the Internet, with many different ways of infecting your system. The stereotypical vector for viruses is the email attachment, and this is still the most common source of infection for unwary users. Opening up a seemingly innocent attachment from a friend can have disastrous consequences. There are few computer users who have not experienced the effects of a computer virus at some point, and malicious coders keep churning them out.

The cure: Install and use a professional antivirus program

Using an antivirus software package from a reputable manufacturer like Symantec or MacAfee provides an effective defence against viruses. You should scan your system for viruses once a week at least, and use the software to examine any email attachments you are unsure about. Many packages, like Norton Antivirus, come with auto-protection features which will scan any files entering or leaving your system for viruses.

While this is fairly self explanatory, a couple of extra tips: if you're going to buy and install anti-virus software, do it now, before you get infected with a virus, rather than waiting until your system starts to act up. The reason for this is that many viruses have components that can disable or subvert popular antivirus programs like Norton's and MacAfee's software. So if your system is infected before you install the antivirus software, it may not be able to help you.

Secondly, make sure you keep the program updated. Antivirus software manufacturers are constantly creating new sets of virus definitions to keep up with new threats. Without updated definitions, the software will not stop newer viruses from infecting your PC. Most reputable antivirus programs will update themselves automatically when you are connected to the Internet, but it doesn't hurt to make sure you have the latest update before you scan for viruses.

Step 4. Check your PC for spyware and adware

The Danger: Spyware and Adware programs can quickly infest your PC, compromising privacy and performance.

The cause: Spyware and adware are generic names for a variety of programs designed to collect data and/or advertise products. Sound innocent? The catch is that these programs are often installed on your PC from websites or as part of 'free' software like Kazaa, and work from inside your computer, gathering information about your surfing habits for marketing purposes. Worse, this is only the tip of the iceberg.

Programs in this category may call up extra pop-up advertising while you are surfing, or even redirect your browser to websites of their own choosing. While makers of this type of software need to obtain your consent to install their programs, they are often presented in misleading ways, or hidden within the license agreements of other software.

There is a second category of programs involved as well, browser hijackers. These malicious programs can subvert your web browser's home page and links and generally cannot be removed without great difficulty. At their worst, these programs can make using your computer a trial. System and Internet performance can be slowed due to the extra data being sent from your computer, and floods of (often obscene) advertisements may dog your Internet surfing experience.

For more details, see PCSTATS guides on spyware, adware and browser hijackers.

The Cure to Step 4

The cure: Install and use a reputable spyware finding/removal tool.

Fortunately, certain individuals have devoted a lot of time and effort to create free software which is specifically aimed at removing these (legal) pests from your system. One software system we tend to use is Ad-Aware, freely available from the Lavasoft website as it is the most popular and frequently updated removal tool. Ad-Aware functions much like any antivirus program, so it should seem instantly familiar to most users.

Use the 'check for updates now' function to make sure you have the latest updates. Hit the 'start' button and choose 'next' to scan your system with the default options.

Once the scan is complete, you will be shown any suspicious files, registry entries or cookies detected. You can now delete or quarantine these files.

If Ad-aware found and removed malicious software, you should empty your recycling bin and restart your computer and scan again to make sure it is completely removed. Make sure to rescan your computer weekly.

Step 5

Step 5. Update update update

The Danger: Viruses and malicious users may exploit newly discovered security holes within Windows and Internet Explorer.

The Cause: Windows XP is an extremely complex operating system, and as such has a number of bugs and design holes which are constantly in the process of being fixed by Microsoft. On the other side of the fence, there are users who are enthusiastically trying to discover these flaws, either for the purpose of informing Microsoft or just for the heck of it.

Generally, major vulnerabilities or flaws are patched almost immediately after their existence is made known, or even before. However, users who do not update their systems with the new patch are at the mercy of anyone using software tools designed to exploit the vulnerability.

A recent example of this would be the infamous 'blaster' worm which used a weakness in Window's RPC (Remote Procedure Call) handling to infest an enormous number of systems across the world. Once on a system, the virus could spread itself out to other vulnerable PCs and also force its host to shut down automatically. Microsoft quickly patched the security hole and provided a tool to remove the worm, but since many users did not patch their systems, the infestation spread and slowed down Internet traffic worldwide.

The Cure: Keep your Windows computer up-to-date with the latest Microsoft security patches.

Windows XP includes an automatic updating feature which will periodically check Microsoft for updates and download them to your system, ready for installation. To use automatic update, right click on 'my computer' and select properties, then choose the 'automatic updates' tab.

If it is not already, check the 'keep my computer up to date…' checkbox to enable automatic updating. PCSTATSNow run Windows update from 'start\all programs\windows update' to make sure you are fully patched for now. Windows update will now periodically check Microsoft's site for updates and download them to your PC. You will be prompted with an icon in the task bar when new updates are available.

Advanced security steps: The following five procedures will provide you with an extra blanket of security to complement the essential changes you just made to your system.

Step 6.

Step 6. Change the name of the administrative account

The Danger: Malicious users may attempt to use the built-in 'administrator' user account to gain access to your PC.

The cause: As mentioned above, every Windows 2000 and XP installation includes an 'administrator' user account which has full control over files and system settings. This account cannot be locked or disabled and is thus the first target for anyone trying to hack into your computer. While the account should already have a password, provided you followed the procedure above, this does not protect it from attack.

The Cure: rename the administrator account.

Renaming the administrator account adds an extra layer of security by removing the standard user name 'administrator' which any malicious user will try first when attempting to gain access to your PC.

Make sure you are logged in as a user with administrative privileges - the first user created during the XP install process has these, as does the administrator. Right click on 'my computer' and select 'manage.' Expand 'local users and groups' then 'users.' Highlight the 'administrator' account and right click. Choose 'rename' and change the account to a name of your choosing.

Step 7. Disable 'hidden' shares within XP and 2000

The Danger : malicious users can easily gain access to every file and folder in your computer.

The Cause: Windows 2000 and XP both use a system of hidden administrative shares. Every drive on your computer system is shared under the name '(drive letter)$.' These shares exist to allow users with the correct username and password to remotely administer files on your computer. Of course, if a malicious user obtains a username and password with administrative rights to your system, all your files and folders are available to them over the Internet. They would be free to copy, change or delete as much of your data as they saw fit.

The cure: Disable the hidden shares.

Unless you are in a business environment, it is unlikely you will have a need for the hidden shares. Disabling them will considerably reduce the danger of your data being compromised remotely.

You will need to edit the Windows registry using REGEDIT in order to carry out this step. Please ensure that you backup your registry to a file before editing it.

To disable the hidden shares first start REGEDIT ('start\run' and type 'regedit') and then navigate to: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lanmanserver\parameters
Add the Dword value 'AutoShareWks' with a value of '0' and restart your computer.

Step 8. Change Internet Explorer security settings

The Danger: Viruses and browser hijacking programs can infect your system through the use of ActiveX code on certain websites.

The Cause: By default, Internet Explorer will run certain content, including small programs embedded in the code of a website. An example of this sort of thing would be a pop-up ad asking you whether you wish to install so-and-so's software. Say yes and you may have just saddled yourself with a spyware problem. Certain malicious software may not even have the courtesy to ask before it has its way with your browser.

The cure to Step 8

The cure: Raise Internet Explorer's default security level.

Fortunately, IE can be set to a more restrictive level of security. At this setting, the browser will not run certain types of content found on websites. This includes potentially malicious ActiveX code. Of course, this can also change your web browsing experience, as it will cut off certain content from safe websites also. To get around this, you can add known safe sites that you regularly visit to Internet Explorer's 'trusted sites' list.
To raise IE's security level:

Open Internet Explorer, go to the 'tools' menu and select 'Internet options.' Now select the 'security' tab.

PCSTATS

Set the Internet zone to the 'high' security setting. This will ensure that IE will not run activeX instructions, the means by which most browser hijackers get access to your computer. You can place trusted websites that you regularly visit into the 'trusted sites' Internet zone.

PCSTATS

Site addresses that you enter here will be mostly unrestricted, allowing them to display their content properly.

Step 9

Step 9. Secure your shared files

The Danger: Intruders may access your shared files

The Cause: By default, Windows XP uses the simple file sharing system. This allows any user that has authenticated to your computer to have full access to all shared files. In Windows XP Home, the 'guest' user account is the account used by all remote users to access shared files. Of course, the guest account has no password by default, allowing unlimited, non-password access to your shared files for virtually anyone who finds your IP address.

While a firewall will block this type of access in most cases, it still pays to limit your venerability by configuring simple file sharing and the guest user account more securely than the default.

The Cure: Secure and configure the guest user account

If you are using Windows XP Professional, you should password protect and disable the guest account. This will force any intruder to use one of the user accounts you created or the administrator account, both of which should now be secure if you followed the above procedures.

Make sure you are logged in as a user with administrative privileges (the first user created during the XP install process has these, as does the administrator).

Right click on 'my computer' and select 'manage.' Expand 'local users and groups' then 'users.' Highlight the 'guest' account and right click. Choose 'set password' and provide the account with a secure password. Now right-click the guest account again and choose 'properties.'

PCSTATS

Check the 'account is disabled' box.If you are using Windows XP Home, you cannot truly disable the guest account, as it is used as an integral part of the file sharing system. You can password protect it though… Bring up the command prompt (start/run and type 'cmd') and type 'net user guest password' where 'password' is the password you want to use to secure the account.

Step 10

Step 10. Stop using Internet Explorer and Outlook Express

The Danger: many viruses and malicious programs target Internet Explorer and Outlook Express specifically.

The Cause: IE and OE are unquestionably the most popular web browser and email client in the world. They are the default applications that a majority of Windows users are familiar with. Because of this, many viruses and other malicious programs are created to target specific vulnerabilities in these two programs. Since the user base is so huge, they can afford to be specific. These viruses generally will not affect systems which employ other products for their web browsing and email retrieval.

The Cure: Learn to use a new web browser and email client.

There are several free browsers and email clients available that can easily replace IE and Outlook Express. The trick is to get used to using them. By not using IE and OE, you considerably reduce the danger of infecting your system with a virus.

Some examples of alternate browsers and mail clients include;Mozilla the makers of this popular browser also offer Thunderbird, a free email client.Opera. Eudora which is an ad-supported mail client with a long and successful history.

If you have any comments or questions, please post them in the PCSTATS Forums. Find out about this and many other reviews by joining the Weekly PCSTATS Newsletter today! Catch all of PCSTATS latest hardware reviews right here.